Generative AI (GenAI)

What is generative AI (GenAI)?

Generative AI applications like ChatGPT and DALL-E are designed to mimic human creativity by generating text, images, videos, and other types of content upon request.

GenAI technologies and their applications vary across industries and use-case. Many people are familiar with large language models (LLMs) like GPT-4 and Claude, but these represent just one type of GenAI. Other models and tools are used to create content in different forms:

GenAI Technology
Application
Unique Features

GenAI differs from other forms of artificial intelligence (AI) because it learns relationships, patterns, and other characteristics within a dataset. These datasets vary based on the technology and application. In the case of LLMs, the datasets contain massive amounts of human-generated content taken from books, articles, web pages, and other text formats. Billions of parameters are applied to these datasets during the learning process. These parameters control how the models learn from the data and what types of responses the models can provide.  Ideally LLMs will produce new and original content upon request, but the response will be based on the parameters used in the training. Compare ChatGPT and Claude for an example on how parameters influence the output of the LLM. 

LLMs are a core subset of GenAI, which in turn is one subset of artificial intelligence:

  • Machine Learning (ML) enables machines to learn from data to improve their performance over time. It includes subfields such as neural networks, deep learning, and reinforcement learning.
  • Deep Learning is a form of ML that uses neural networks to analyze complex data and identify patterns in ways that are beyond human capabilities.
  • Natural Language Processing (NLP) capabilities allow machines to understand and generate human language. This is only language, not spoken words.
  • Speech Recognition technologies enable computers to recognize and translate spoken language into text. This is a separate set of technologies from NLP.
  • Generative AI creates content that is based on what it has previously learned. Applications like ChatGPT and Microsoft Co-pilot are GenAI technologies.

More subsets of GenAI and artificial intelligence will be created as use-cases continue to grow. AI technologies are maturing and companies across all sectors are embracing AI solutions and creating their own purpose-built applications. GenAI and ML will be significant drivers in this growth.

How is GenAI used in business?

All sectors in the economy use generative AI in some way. The most widely known uses are chatbots that provide tech support and customer service functions prior to sending a request to a human representative. This type of GenAI is public facing and easily accessible to the public. Other applications may work behind the scenes, unnoticed by customers or other external parties.
Sector Use of generative AI

How is GenAI used in critical infrastructure?

GenAI is also experiencing widespread adoption throughout critical infrastructure. Synthetic data allows infrastructure management teams to plan for natural disasters, cyberattacks, system failures, and other scenarios. This helps teams improve the response and reduce the time to recovery.
Sector Generative AI Applications

What are the cybersecurity risks of using GenAI?

Proper use of GenAI can improve business efficiencies, customer service, and even quality of life through healthcare and health-related applications. Many will argue that the benefits of GenAI outweigh the risks, but those risks should be considered and mitigated as much as possible.

The cybersecurity risks associated with using Generative AI (GenAI) are multifaceted and stem from both the inherent characteristics of the technology and the ways in which it is deployed and utilized. These risks can broadly be categorized into several key areas:

  • Privacy and data protection: GenAI systems require access to vast amounts of data that most users cannot control. Some of this data may include sensitive or personal information that might be publicly shared in response to a request. 
  • Input and output: Threat actors have used the request/prompt process of GenAI LLMs to inject malicious data or exploit vulnerabilities in the system. This can cause a data breach if the system is purpose-built for a controlled use, like healthcare or finance. GenAI can also respond to requests with outputs that are inappropriate and harmful. These outputs can be influenced by training, parameters, and malicious action by threat actors. Most users will not know what caused the output.
  • Compliance and legal risks: GenAI can complicate compliance with data protection and privacy regulations. For example, the European Union's General Data Protection Regulation (GDPR) imposes strict requirements on the processing of personal data, and GenAI's data handling practices could potentially conflict with these regulations.
  • Automated Social Engineering attacks: GenAI is designed to imitate human communication styles, making it a perfect tool for sophisticated phishing and social engineering campaigns. Malicious actors could leverage GenAI to automate the creation of highly convincing phishing emails or messages, making it harder for individuals to distinguish between legitimate and fraudulent communications. Several LLMs have already been stolen and repurposed for malicious use:
    • FraudGPT: A subscription based malicious GenAI tool that creates content for cyberattacks like phishing and impersonation. operates similarly to OpenAI's ChatGPT but lacks the built-in controls and limitations that prevent misuse.
    • WormGPT: An open-source system that is designed to help criminals write malware and malicious code, create phishing content, and find system vulnerabilities.
    • PoisonGPT: This tool spreads misinformation online by inserting false details into political and historical narratives, creating fake news, and manipulating public opinion.
    • XXXGPT: This application was developed to help criminals deploy botnets, malware, keyloggers, infostealers, remote access trojans, and cryptostealers.

Generative AI also creates new risks when it is deployed with an application programming interface (API). APIs enable the integration of separate technologies and are required components in many of the use-cases described above. APIs can create significant risk across the organization. These must be managed and secured like any other component in the digital infrastructure.

Learn more about GenAI

Further reading

How Barracuda can help

Barracuda provides a comprehensive cybersecurity platform to protect organizations from all major attack vectors that are present in today’s complex threats. Barracuda offers best value, feature-rich, one-stop solutions that protect against a wide range of threat vectors, and is backed up by complete, award-winning customer service. Because you are working with one vendor, you benefit from reduced complexity, increased effectiveness, and lower total cost of ownership. Hundreds of thousands of customers worldwide count on Barracuda to protect their email, networks, applications, and data.