Google Cloud BlogSandra Joyce11 min readintermediate
Cloud CISO Perspectives: How Google monitors AI threats and advances AI defenses
Summary
Google’s Threat Intelligence team outlines three AI‑driven shifts—software build changes, expanded attack surface, and enhanced threat capabilities—then describes their multi‑model, graph‑based defense stack (AI Threat Tracker, in‑editor “spellcheck”, Wiz Security Graph, Gemini‑powered AI Threat Defense) and concrete threat examples like supply‑chain poisoning, LLMJacking, and AI‑orchestrated cre…
- AI accelerates code delivery, creating a “machine‑speed” threat landscape that requires security baked into the AI‑assisted development pipeline (real‑time editor guardrails).
- Google monitors AI threats via an AI Threat Tracker and adopts a multi‑model approach (Gemini + commercial + open‑source) to cross‑validate findings and reduce false positives.
- A unified, dynamic security graph that ties code, models, data lineage, and runtime identities is central to Google AI Threat Defense (AITD) and feeds into Security Operations for rapid response.
- Observed adversary techniques include supply‑chain poisoning of AI‑suggested packages, prompt injection, LLMJacking to hijack GPU resources, and AI‑driven multi‑agent attack pipelines for credential harvesting.
As AI tools become integral to software development, attackers can exploit the same pipelines at scale. Embedding security directly into AI‑assisted workflows and leveraging a multi‑model, graph‑centric view gives defenders contextual awareness and machine‑speed response, which is essential to coun…
6/10




