Since the public release of ChatGPT in November 2022, artificial intelligence (AI) integrated into multiple facets of human society, including operational technology (OT).

For critical infrastructure owners and operators, the goal is to use AI to increase efficiency and productivity, enhance decision-making, save costs, and improve customer experience – much like digitalization.

However, despite the many benefits, integrating AI into operational technology (OT) environments that manage essential public services also introduces significant risks – such as OT process models drifting over time or safety-process bypasses – that owners and operators must carefully manage to ensure the availability and reliability of critical infrastructure.

Securing Integration of AI into OT TechnologyTo that end, multiple global security agencies teamed with the Cybersecurity and Infrastructure Security Agency (CISA) and Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) to collaborate with the National Security Agency’s Artificial Intelligence Security Center (NSA AISC), the Federal Bureau of Investigation (FBI), the Canadian Centre for Cyber Security (Cyber Centre), the German Federal Office for Information Security (BSI), the Netherlands National Cyber Security Centre (NCSC-NL), the New Zealand National Cyber Security Centre (NCSC-NZ), and the United Kingdom National Cyber Security Centre (NCSC-UK), to provides critical infrastructure owners and operators practical information for integrating AI into OT environments.

This guidance outlines four key principles critical infrastructure owners and operators can follow to leverage the benefits of AI in OT systems while reducing risk:

Schneider Bold
Understand AI:

Understand the unique risks and potential impacts of AI integration into OT environments, the importance of educating personnel on these risks, and the secure AI development lifecycle.

Consider AI use in the OT domain:

Assess the specific business case for AI use in OT environments and manage OT data security risks, the role of vendors, and the immediate and long-term challenges of AI integration.

Establish AI governance and assurance frameworks:

Implement robust governance mechanisms, integrate AI into existing security frameworks, continuously test and evaluate AI models, and consider regulatory compliance.

Embed safety and security practices into AI and AI-enabled OT systems:

Implement oversight mechanisms to ensure the safe operation and cybersecurity of AI-enabled OT systems, maintain transparency, and integrate AI into incident response plans.The agencies said critical infrastructure owners and operators should review this guidance so they can safely and securely integrate AI into OT systems.

When it all comes down to it, machine learning (ML), statistical modeling, and algorithmic calculations are all subsets of AI techniques used in critical infrastructure engineering processes for many years.

While ML and traditional statistical modeling see use for predicting outcomes or making decisions based on data, they differ in their approach, assumptions, applications, and considerations for secure integration with OT systems.

The guidance focuses on ML- and large language model (LLM)-based AI and AI agents because integrating OT with these types of AI systems involves more complex safety and security considerations.

Having said that, this guidance may also apply to systems augmented with traditional statistical modeling and other logic-based automation.

Traditional statistical modeling uses mathematical formulas to accurately describe the relationships between variables. It assumes the data follows certain distributions and the relationships are either linear or can end up approximated by linear models.

Statistical modeling uses techniques such as regression analysis, hypothesis testing, and confidence intervals to directly estimate model parameters and make predictions. It is commonly used for tasks such as forecasting, optimization, and assisting in operator decision-making.

Non-machine-learning-based AI systems employ algorithms to automate decision-making and control processes; in OT systems, this includes ladder logic automation routines and a class of safety instrumented systems.

Machine Learning

Machine learning systems use algorithms to learn from data and make predictions or decisions without being explicitly programmed. The ML model can handle complex relationships and non-linear interactions between variables. ML models use various techniques – such as supervised, unsupervised, and reinforcement learning – when developing representations and making predictions based on data.

ML ends up commonly used in fields like computer vision, natural language processing, and robotics for tasks such as image classification, speech recognition, and autonomous driving.

LLMs end up being advanced ML models designed to understand a natural language prompt and generate a response that humans can understand. They use patterns in language and multimodal datasets in the production of complex responses to user prompts.

LLM engineers usually build in randomness when generating outputs so the LLMs don’t always produce the same response to the same inputs. LLMs can power generative AI applications that support critical infrastructure entities by enhancing decision-making, automating routine tasks, and optimizing maintenance schedules, with the goal of improving efficiency and reliability in operations.

AI agents are a type of software that can process data, perform decision-making capabilities, and initiate autonomous actions using AI and ML models.

There are many types of agentic AI systems, including systems using LLMs to power generative AI applications or agents and systems that combine different ML techniques, perspectives of analysis, decision-making methodologies, and autonomous action capabilities. Like LLMs, they can enhance decision-making, automate routine tasks, and optimize maintenance schedules, which enables them to improve and streamline critical infrastructure operations.

Implementing error-checking can improve AI agent’s performance by avoiding problems and ensuring its outputs are within the expected bounds.

Click here for more on the security agencies guidance.

ISSSource

Pin It on Pinterest

Share This