Right on the heels of the Hugging Face incident(s), evidence is pouring in that a swarm of AI bots – the more the better – can probably penetrate and damage any system or network they decide to attack that is within their “reach”. This includes at least portions of the North American power grid. Here are two especially persuasive pieces of evidence:
1. On September 8, OpenAI announced that its bots had solved a fiendishly difficult mathematical problem: the Navier–Stokes existence and smoothness problem. This problem has bedeviled mathematicians for a century. In 2000, it was designated one of the seven Millenium Prize Problems, each of which carries a million-dollar prize for a solution. Until last month, it still hadn’t been solved.
OpenAI solved the problem by pulling out all the stops. While the experiment that got out of control and led to the Hugging Face attack involved 1200 bots, “only” 700 of them attacked Hugging Face (and then OpenAI itself). However, OpenAI decided that, given how hard the Navier-Stokes problem was, they needed a lot more bots – about 10,000. Fortunately, in this case (months after the Hugging Face attacks) they were able to keep the bots confined.
How long do you think it took those 10,000 bots to solve[i] this 100-year-old problem? 88 hours. The lesson for the power industry is that, if a sufficiently large number of AI bots are told to cooperate to solve a hard problem and there is a solution, they will probably find it - and quickly.
2. This New York Times article describes how the 700-odd OpenAI bots that attacked Hugging Face ran into the problem of solving Captchas before they could attack the Hugging Face web site – since, like a lot of sites, it uses Captchas to block bots, but not humans. They put their bot heads together (using a bulletin board in Germany to communicate, since they weren’t supposed to be “talking” to each other) and came up with the idea of breaking the code required for their attack into a bunch of segments that would be posted online, each with a unique URL. Entering the first URL in a Captcha prompt would load the first code segment. That code ended by calling the next URL, which loaded the second segment, which ended by calling the third URL, etc.
I’m sure that this task would have been very time consuming for a bunch of knowledgeable humans to accomplish, yet the bots successfully attacked the Hugging Face website after just a couple of days of this very painstaking work. How many URLs did they string together for the attack? 20? 50? 100? Nope. Try 60,000. Moreover, in the course of their work, which certainly required a lot of trial and error, they created 900,000 URLs (and remember, this was in two days). Plus, keep in mind that this was the group of 700 bots that attacked Hugging Face. How long would it have taken the 10,000 bots that solved the Navier-Stokes problem to do this? A few hours? Less than that?
Here’s the second lesson for the power industry: There’s no problem that can be considered out of reach of bot swarms. You have to assume that a sufficiently large bot swarm can solve any problem in a tiny fraction of the time that humans would take, unless the problem has no solution, like “How can we ensure that the world lives at peace in the future?”
So, let’s say some outside party wants to do as much damage to the North American power grid as possible. If that party is a country with access to nuclear weapons and sufficient launch capacity, probably their best option is an electromagnetic pulse (EMP) attack, in which a nuclear device is exploded about a mile above the North American subcontinent. The EMP could disable the entire grid without spreading any radioactivity, so few people would die initially. But without power, the Americans and Canadians would be reduced to a miserable existence, with roving gangs fighting it out and stealing food and shelter. At that point, we would probably be happy to submit to Russia, North Korea, or whatever power would come in and restore order. Fortunately, the bots don’t have the resources required to pull off an EMP attack – at least not today.
Today, what is the worst that a swarm of bots might do to the North American power grid (which is actually four “grids” called Interconnects: the Eastern and Western Interconnects, ERCOT - which covers most of Texas - and Quebec)? The good news is that a) there is such huge diversity among the systems and entities that control the grid, and b) there are such strong cyber and physical security controls protecting those systems and entities (in no small part due to the NERC CIP standards) that it would be almost impossible to black out an entire Interconnect, no matter how many bots collaborated.
But you shouldn’t take much comfort in this. After all, the Northeast Blackout of 2003, which blacked out portions of 12 states and almost the entire province of Ontario and killed over 100 people, brought down far less than one third of the Eastern Interconnect. Maybe the bots would content themselves with “just” recreating something like the Northeast Blackout – perhaps in another part of the country like the Southeast or Southwest. Then again, that attack, if successful, might become a model for the Big One, where the bots carry out simultaneous attacks in all four Interconnects, with the goal of bringing down most of the North American grid. After all, these bots seem to be quite ambitious…
But the size of the bots’ first successful attack on the grid doesn’t really matter. Maybe they would just black out a 100-person town in Idaho for one hour. This would still be the first instance in which a cyberattack resulted in a power outage in North America. In fact, outside of the 2015 Ukraine attack (which caused a widespread outage, but only for a few hours), there has been no verified outage caused by a cyberattack anywhere in the world. Thus, it’s inevitable that even a small attack in North America would lead to enormous concern and have a big effect on markets. After all, if the bots can take down one small town, what’s to stop them from taking down 100? Then, maybe a medium-sized city?
In fact, blacking out an entire town, no matter how small, through purely cyber means would be incredibly hard. However, there are many other ways in which a cyberattack on the grid could be a roaring success, even though it didn’t cause any blackout. There still hasn’t been a successful cyberattack on a generating plant in the US, even a small one. What if 10,000 bots were ordered to find and disable as many power plants as possible, no matter how small, and they succeeded with four 5 megawatt dams? It’s close to certain that no end user would lose power because of this attack, but this would certainly have a big effect on markets.
Who would want to carry out an attack like this? How about a short seller? There are lots of people besides the usual suspects (Iran, North Korea, Russia, perhaps China), who can have a strong motivation to mess with the US power grid. And now, with bot swarms drastically upping the ante, they may have found their tool. But once the bots have learned about any attack, they certainly won’t hesitate to attempt a much larger attack, whether they’re ordered to do that or they decide to do it on their own.
To address this problem, there are two primary questions that need to be answered:
1. What are the possible vectors by which bots might attack the North American power grid and cause an outage? I can think of at least a few of them right now, but there are certainly many more. All realistic vectors need to be identified, but then the most likely few should become the focus.
2. How can we prevent exploitation of all those few vectors? Note I’m not talking about risk management here; I’m talking about risk elimination – meaning there’s literally a zero possibility that bots could exploit these vectors to cause an outage. We can do this by putting in place controls that can only be bypassed by non-cyber means – e.g., requiring an attacker to be physically present at a substation for it to open a line (also note that, while the AI companies could certainly take their own steps to mitigate this threat, it would be foolish to wait for them to act before the power industry does).
These questions need to be discussed, and the sooner the better, since it will undoubtedly take at least one or two years to put even some of these controls in place, once the need for them is identified. If you’re involved with the North American power industry in any way, as an employee of a utility or IPP, a vendor of hardware, software or services to the industry (including major CSPs), or an employee of NERC, a NERC Regional Entity, or FERC acting outside of your official capacity, you’re invited to join an online group that I and a couple others expect to be forming soon. Just drop me an email to be on my list to receive further announcements. The same goes if you’re a user of electric power (industrial, commercial or residential) who’s concerned about keeping the lights on.
Please note that this group will not be associated in any way with the NERC standards development process. We may develop voluntary guidelines at some point, but there will be no auditing and compliance with them won’t be mandatory for anybody. I would hope that the seriousness of this problem will be enough for any guidelines to be widely followed, although there will certainly be some organizations that won’t or can’t do so – meaning a bot swarm might end up causing a few local outages, but nothing widespread or long lasting. If we want to worry about preventing all local outages, we need to focus on eliminating all small mammals that like to chew on wires, including squirrels, chipmunks and mice. They’re one of the the biggest causes of outages today.
However, one thing is already clear: While I don’t believe that any current use of the cloud by OT systems used in the power industry poses a risk of attack by AI bot swarms, I don’t believe that efforts to encourage more cloud use by modifying and/or adding to the current NERC CIP standards should continue. I say this because it might become clear, once our group (and any other groups that wish to do this) has been able fully to consider this problem, that the risks of allowing BES Cyber Systems (and perhaps EACMS and/or PACS, plus possibly BCSI) to be implemented in the cloud are too great, meaning that NERC entities should not do this, at least at the high and medium impact levels.
Tom Alrich’s Blog, too is a reader-supported publication. You can view new posts for three months after they come out by becoming a free subscriber. You can also access all of my 1300 existing posts dating back to 2013, as well as support my work, by becoming a paid subscriber for $30 for one year (and if you feel so inclined, you can become a founding subscriber for $100). Whether free or paid, please subscribe.
If you would like to comment on what you have read here, I would love to hear from you. Please comment in my chat or email me at [email protected].
[i] Some mathematicians have asserted that the OpenAI bots didn’t “solve” anything; instead, they took a shortcut that should invalidate the proof. The foundation that offered the Millenium Prize is investigating the matter. Whether or not the proof holds up, the fact that so many mathematicians were persuaded that it was valid can itself be considered a victory for the bots.