Databricks 的阿里·戈德西:网络安全与数据正被推向同一市场
Databricks' @alighodsi on the clock that's forcing cyber and data into the same market: "It used to...
Databricks 的阿里·戈德西讲了点有意思的,他说现在公司内部的 AI 代理会产生很多数据,这些数据需要被分析,而且漏洞被武器化的速度越来越快,从几年缩短到几小时,挺值得关注的。
Databricks 的阿里·戈德西指出,过去数据与 AI 运行在独立领域,而网络安全则是另一套体系。如今,公司内部运行的 AI 代理会产生大量数据日志,这些数据需要被分析。从漏洞发布到被武器化的时间从几年前缩短到如今几小时。他强调,网络安全是他最关注的领域,因为组织尚未准备好应对 AI 代理能力的提升。
Databricks' @alighodsi on the clock that's forcing cyber and data into the same market: "It used to...
Databricks' @alighodsi on the clock that's forcing cyber and data into the same market: "It used to be like, okay, we have data and AI... you have a bunch of data and you run AI and machine learning, and that just lives separately." "And then you have the cyber world. Cyber world is, you know, we want to detect if bad people are trying to hack us." "But now on the data and AI side, we have agents running internally in the company. And the agents are also doing things with other people's agents, and they're producing a lot of data. Logs, trails, fingerprints that are being left." "All the data that's being produced needs to be analyzed. And the scale at which you need to do that is many, many orders of magnitude more than just one or two years ago." "2018, 2019, the time it would take from a CVE, a vulnerability being published, until you see it actually weaponized in the industry would be like two, three years." "That went down in 2022 significantly, but it was still like eight, nine months. So that's kind of fine, you have eight, nine months." "Now if you look at this curve from 2022 until now, it's down to basically hours, basically no time. Things get immediately weaponized." @alighodsi Your browser does not support the video tag. 🔗 View on Twitter a16z @a16z Databricks' @alighodsi on AI risk and adoption: Ali isn't losing sleep over the existential risk debate. He says a number of conditions would all have to be true simultaneously to enable an actual runaway takeoff scenario, and currently several opposite conditions exist. Each frontier training run requires significantly more resources. Power, GPUs, engineers - and some attempts fail, burning up huge piles of money with them. Until that reverses, he doesn't see the self-improving loop happening. Cyber is what he's watching most closely and where he anticipates real impact. Most orgs are not equipped for the coming change in agentic capabilities. The time between a vulnerability being published and being weaponized has collapsed from years to hours. On adoption, he believes most companies don't need a smarter model. The models are already smart enough. The gap is context they don't absorb - the things an employee who's worked at a company for five years learned by osmosis. If the frontier stopped advancing today, he thinks it wouldn't meaningfully change the value most are extracting from AI anyway. In conversation with a16z's Martin Casado and Sarah Wang: 00:00 Intro 00:48 Why Ali places the AI risk near zero 05:05 The word "pacing" was a mistake 10:50 What 10k agents and $100m can do 12:20 What would change his mind on AI risk 14:20 More GPUs, more ways to fail 18:05 US export controls on PlayStations 20:10 The damage everyone expected by now 24:30 Public vulnerabilities weaponized in hours 30:15 Why labs can't grade each other 37:15 Why most of RSI isn't actually RSI 40:05 Why nobody really needs a smarter model 41:50 The AI use cases nobody argues about 47:30 Google Search solved this 25 years ago 50:55 Nobody has privileged knowledge now 55:10 Same model, new harness, 2x cost 58:15 Open source: 5% of spend, 60% of tokens 1:05:30 90% of new databases are created by agents YouTube: youtu.be/GzEtpAKYRvE @databricks @martin_casado @sarahdingwang Your browser does not support the video tag. 🔗 View on Twitter 🔗 View Quoted Tweet 💬 3 🔄 1 ❤️ 11 👀 6356 📊 3 ⚡