Zoe Braiterman — AI, ML, AppSec, and a dose of data protection
With Zoe Braiterman
Artificial intelligence can help analyze security data, but the systems using it also need protection themselves. Zoe Braiterman brings a background in data science, organizational thinking, and OWASP community work to an early conversation about that two-way relationship.
Audio hosted by Buzzsprout. Nothing loads until you press play.
Episode chapters · 12 chapters
- 00:00AI, machine learning, and AppSec with Zoe BraitermanAudio
- 02:03Zoe’s path through data science into securityAudio
- 03:31Community work with OWASP Women in AppSecAudio
- 04:30Distinguishing AI and machine learningAudio
- 06:25What autonomy means for a processAudio
- 07:19Examples of AI applicationsAudio
- 10:18Fraud detection and learning from dataAudio
- 14:25Possible uses of AI in application securityAudio
- 16:19Smarter tools and penetration testingAudio
- 18:39Pattern recognition in security dataAudio
- 21:08Protecting the data and processes behind AIAudio
- 23:45Learning resources and closing adviceAudio
About this episode
Artificial intelligence can help analyze security data, but the systems using it also need protection themselves. Zoe Braiterman brings a background in data science, organizational thinking, and OWASP community work to an early conversation about that two-way relationship. Chris and Robert ask how artificial intelligence and machine learning differ, where automation is already appearing, and what pattern recognition might contribute to application security. The discussion moves from familiar examples such as fraud detection toward the data, models, and processes behind automated decisions. Zoe emphasizes the human role in understanding those systems and protecting the information they use. This archive episode captures exploratory thinking about AI and AppSec while encouraging practitioners to keep asking questions and learning together.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Zoe Braiterman:
→ Zoe Braiterman on LinkedIn
Resources
→ OWASP Women in AppSec — project repository
Actionable
From this conversation
- 14:47
Model adversary behavior
Try to, get that insight into the threat model, but in terms of what the adversary might be doing
- 17:12
Train data scientists in AppSec
There's future for specific, type of AppSec training specifically for the data scientists.
- 22:12
Apply controls at every automation phase
Make sure that, at each, I guess, phase of the automated processes that, proper controls are taken at each of them
Transcript · 26 min conversation
0:00Chris RomeoZoe Braiterman is an innovation intelligence strategist focused on both machine and human, and also the OWASP Women in AppSec chair. We explore the intersection of application security with artificial intelligence and machine learning, and we end up discussing data protection along the way. Zoe approaches AppSec from a different angle, and her perspective gets us thinking about the importance of AppSec in the future of autonomous everything. I want to take a moment to introduce you to Security Journey. At Security Journey, we believe security is every developer's job. We work with our customers to help them build long-term sustainable security culture amongst all their developers. Our approach is to provide security education that is conversational, quick, hands-on, and fun. We don't do lectures. Instead, we let the experts talk about what's important. The modules are quick, 10 to 20 minutes in length. We believe in hands-on experiments, builder and breaker style, that allow developers to put what they learned into action. And lastly, fun. Training doesn't have to be boring. We make it engaging and fun for the developers. Visit www.securityjourney.com to sign up for a free trial of the Security Dojo. The Application Security Podcast. Here we go. Hey folks, welcome back to the Application Security Podcast. This is Chris Romeo, one of the co-hosts here of the podcast, and I'm also the CEO of Security Journey and another co-host is right here with me. Hey, Robert, what's up?
1:58Robert HurlbutHey, Chris. Yeah, this is Robert Hurlbut, Threat Modeling Architect. Glad to be here today.
2:03Chris RomeoAwesome. Well, we are joined today by Zoe Braiterman, and Zoe is here to talk with us specifically about artificial intelligence and machine learning, but I'm sure we're gonna talk about a lot of different things in the world of AppSec. So Zoe, with everybody who comes on the AppSec Podcast here, we always ask, what is your security origin story? If there was a comic book about Zoe and her career into security, what does that episode number 1 of that comic book look like?
2:37Zoe BraitermanWell, so I tried to enter the field of data science through New York City meetup scenes and projects and teams, etc. But I realized that every project I tried to start working on, I would be asking way too many questions beforehand, and I learned that that's a big important part of AppSec. So that's where I decided to then get into AppSec.
3:04Chris RomeoSo where'd you go? So you didn't study computer science, or did you study— you didn't study security or anything in university then?
3:12Zoe BraitermanNo, I studied business, but I actually saw a lot of very nice relevance, you know, from managerial economics to AppSec in terms of studying the structures of communication and the different contexts and organizational processes.
3:31Chris RomeoAnd you're involved with something that, uh, all of us— it's hard not to love in the world of AppSec, and that is OWASP. What's your involvement in the world of OWASP?
3:44Zoe BraitermanOh, um, so I'm a member of the Brooklyn chapter, and I also chair the Women in AppSec committee, building in diversity into the wonderful community that we have globally.
3:57Chris RomeoWe've talked to some of the other folks we've had. Vandana's been on the show before and Jesse. And so you work with— all 3 of you work together to promote the Women in AppSec for OWASP?
4:08Zoe BraitermanYes, along with Catherine and Geeta and Laura Donna on the officer's side and a bunch of other committee members and participants who contribute regularly, and we actually have 2 women starting a London chapter next week, which is wonderful.
4:30Chris RomeoVery cool. So I guess the topic that we wanted to discuss today was artificial intelligence and machine learning and what is the application to application security. for these 2 very transformative types of things that are happening in the industry right now. And so, as I was telling you before we started here, I don't know a whole lot about artificial intelligence and machine learning. I probably know enough to be dangerous, which is true about a lot of different topics. I think Robert knows quite a bit more about this than I do. So, maybe before we start, let's get a definition. When we say artificial intelligence, and then we say machine learning. Give us some, the definitions of those things kind of from your perspective. And 'cause I feel like a lot of people get these 2 things confused. They think they're, it's like threat and risk. They think it's the same thing. So what is artificial intelligence and what's machine learning?
5:24Zoe BraitermanSo artificial intelligence, you know, implies autonomy and yeah, just autonomous processes. And machine learning is, You know, training a specific model to continue to, you know, recognize, classify, etc., some, you know, some type of data and be able to act accordingly.
5:51Chris RomeoSo where does the Terminator fit in? The Terminator fits into which category here from that?
5:57Zoe BraitermanI actually haven't seen that film.
5:59Chris RomeoYou haven't seen it? Okay.
6:00Zoe BraitermanI guess that's on my to-do list now.
6:01Chris RomeoYeah, it's like the first— I don't know, Robert, was that the first time artificial intelligence ever made its way into the The big screen in Hollywood?
6:08Robert HurlbutUh, maybe HAL, actually, way back when.
6:11Chris RomeoOh, see, now you're— yeah, you're going way back.
6:13Robert HurlbutBut I'm— I didn't actually see it when it first came out. It was probably— I was alive, but, uh—
6:19Chris RomeoBecause you were far too young is what you're saying there.
6:22Robert HurlbutYes, yes. But, uh, but that's one example of that.
6:25Chris RomeoYeah, HAL from 2001, and then Terminator from the artificial intelligence side. So, okay, so, so Zoe, you said so autonomous process from artificial intelligence is, is kind of what we need to think about. So when we say autonomous process, that truly means it can operate on its own?
6:42Zoe BraitermanI guess at least for a specific application or for a specific type of process, you know, initiated with, you know, the input output units and depending on the model of the, the neural net, et cetera. Some of them have input/output and forget gates, for example. It's of course mysticized a bunch when you see the robots on, I guess, one of those, likely Terminator, as you mentioned, although as I mentioned, I haven't seen it.
7:19Chris RomeoSo what are some examples then of how AI is being applied today, just in general? Maybe not even in the world of security, but just in general, where are people trying to use AI today?
7:31Zoe BraitermanComputer vision, various models, whether it be recognition of certain features or also feature learning generatively to generate new, you know, data types or data structures, whether it be an image or, or some sort of sequential data for predictive analytics, stock prices, market trends, etc. Natural language processing, NLP, is big, you know, including sentiment analysis. So it's not specifically natural language syntax.
8:11Chris RomeoYeah, and so I think one of the, one of the big examples that I always see thrown out when we talk about artificial intelligence is this idea of the self-driving car. And even the self-driving truck that's pulling the heavy load filled with stuff that's being shipped from the West Coast to the East Coast or whatever. And so, when I think about the threat model that goes into this whole idea of self-driving cars, I mean, it makes me not want to leave my house, but at least they're not as much of a kind of reality at this point. But it seems like that's where we're going.
8:45Zoe BraitermanYeah.
8:46Chris RomeoSeems like there's just, when we talk about the threat landscape that's brought about by artificial intelligence, it seems like we're opening ourselves up to a whole lot of new risk in the future. Zoe, what do you think about that?
8:57Zoe BraitermanOh, definitely. Because, you know, it keeps training one input-output or, you know, one step at a time. And I'll give a concrete example. One inaccurate label and that can be influenced by adversaries, for example, then goes on to the next input and output layer. And so from there, they have a bunch of different controls moving forward. And it's similar to threat modeling and risk trees. But also every step that's scary and mystical in the news, take that, apply every AppSec concept, and then keep it continuously connected. With all the IoT devices and industrial IoT, IIoT, and smart cities and everything in an increasingly connected and complex world. What else can go wrong, I guess?
10:09Chris RomeoYeah, seems like the sky's the limit for what can actually go wrong here when we're talking about these new tech, this new tech.
10:15Zoe BraitermanYes.
10:18Chris RomeoSo what about machine learning then? Tell me this is actually a real thing. That this is when I think of machine learning, this is what I think of. So when I travel the world or the greater, I don't know, East Coast of the United States, And I get to a hotel and I give them my card and they swipe my card and they say, I'm sorry, your card's been denied. And all of a sudden I get a text message from my bank that says, hey, are you really in such and such a location? Because you didn't tell us if you were. Is that an example of machine learning?
10:50Zoe BraitermanWell, it could be, you know, definitely some involved. Like for example, assuming it actually was your bank, then they probably could have had ways of implying such data that's not always accurate, but based on statistical models, but then also predictively inference toward the next input. So that's one of the differences of, I guess, typical statistical modeling to machine learning modeling, which can be, again, applied to unseen, not yet seen inputs to generate such assumptions. And because it's based on a lot of complex big data to keep up with competitors, et cetera, in this world, so then something can go wrong, as with any kind of statistical model, which is far beyond you know, like a computer architecture or computer science, that it at the end of the day, it is a projection.
12:02Chris RomeoThat's on the machine learning side.
12:04Zoe BraitermanRight. So again, even assuming that it was your bank, because there's always the possibility, you know, phishing, etc., or any sort of social engineering.
12:15Chris RomeoI'm just taking out that as a— certainly, I recognize that as a risk. But I'm, I'm taking that out of out of play and saying, hey, if we can say for sure it is actually the bank, then yeah. I mean, is that an example? Is the bank systems actually kind of applying this idea of machine learning? Like, are they going to remember in the future when I go to that same location because the dataset got smarter? I don't know if smarter is the right word, but got better as a result of them tracking my existing visit there.
12:46Zoe BraitermanYeah.
12:47Chris RomeoAnd is that machine learning if it does— if the system does get— makes a better decision about whether I'm actually there based on past data?
12:55Zoe BraitermanOh, past data as well as inferences from, for example, combined preferences for consumers. So really getting those behavioral economics models, for example, and aggregating them using take, you know, your connected devices as well as, you know, all those models combined. And, you know, it's obviously not all open source when it comes to the big players.
13:26Robert HurlbutYeah.
13:28Zoe BraitermanBut, you know, some combination of that is likely behind it, which also could make it wrong sometimes. So not necessarily always an adversary per se, although I wouldn't exactly I wouldn't say that the corporations who are removing some of our privacy rights are necessarily unadversarial, but—
13:55Chris RomeoYeah, I guess it depends on what side you fall on there. But yeah, there's definitely some privacy constraints just through legitimate companies that we do business with as well that We wouldn't list them as an adversary per se, but when you think about how they use our data, it's like, hmm, maybe this is an adversarial relationship I'm in.
14:17Zoe BraitermanI mean, the adversarial is, it's a spectrum, you know, it's non-binary. It just depends on the context.
14:25Chris RomeoIt's true. That is true. So, when we think about artificial intelligence, machine learning, and AppSec and how these 2 things kind of relate. What are the uses of artificial intelligence? Starting— let's start with there. What do you see as kind of the ways artificial intelligence could be used in the field of AppSec?
14:47Zoe BraitermanFor example, how a pen tester has to get into the minds of a non-ethical hacker and do the same, similar processes and try to put themselves in those shoes. So kind of, you know, again, first of all, you know, trying to imagine and, you know, put into threat modeling, for example, and I'm sure, Robert, you can speak more on this, but try to, you know, get that kind of insight into the threat model, but also in terms of what the adversary might be doing, but also try to generate your own models first. So kind of, who can get there first, let's try to get there first, similar to the idea of offensive security. Creating models to just generally do that and then apply some game theory, for example, generative adversarial networks where it's essentially generation of opponents and trying to beat each other out at a zero-sum game, but try to apply similar models on our side as well to, you know, to get there first. And I imagine on the defensive side might be on the radar at some point to really be able to automate that more and more in various ways and scale it out to various frameworks and architectures.
16:19Chris RomeoSo, when we think about artificial intelligence from the pen testing perspective, is it the case where we'll eventually get software, we'll create software that's better at finding vulnerabilities as a result of the fact that the software itself can apply some type of autonomous decision-making and data collection process and and develop new mechanisms, or is that— it almost seems like science fiction-y to me, like this is a movie, it's, you know, like a movie where there's a large robot coming back from the future to try and extinguish humanity or something. But I think that movie's already been made. But what I mean, so, so like, what, what kind of— what do you see as the, the kind of use case for this? Is it, is it the pen tester being able to just have smarter software?
17:12Zoe BraitermanSo I guess all sides of the development team have— having smarter software, one should hope. And also, I guess, bringing in data science and maybe, maybe, you know, there's future for specific, you know, type of AppSec training specifically for the data scientists.
17:38Chris RomeoYeah.
17:38Zoe Braitermanwhose job it is to essentially scale everything out and create these models and try to make sure that everyone's on the same page of that similarly and maybe a little bit separately from the rest of the development team where the security trainer comes in or— Yeah. I mean, in terms of that side as well and, you know, the— the human element side, there might also be new opportunities and new needs seen for that. But yeah, so in terms of the methodologies itself, trying to make them, you know, account for more, more future threats and also, also on the defensive side and the scaling side. trying to, you know, maybe new opportunities for external tools and vendors, etc.
18:39Chris RomeoSo then does machine learning, does that make for something different as far as, you know, are there different potential use cases for machine learning in AppSec?
18:50Zoe BraitermanI mean, a lot of machine learning techniques in terms of just, you know, automating processes are essentially machine learning, but it just in terms of how much is scaling out, and I can't speak for any other AppSec team and what, you know, what they do necessarily, but yeah, just I guess continuing to scale it out using, you know, from various angles.
19:14Robert HurlbutWell, I think about, you know, some ways I've seen it used just in industry, how, you know, we talked about, I think you talked about advertising or marketing and, and how they figure out our buying patterns. And so some of the most interesting articles I've read in security in relation to machine learning is just gathering all that data about attacks and trying to understand how they actually work. And then how do you find the patterns? And then how do you look for the patterns in new attacks and try to determine what's an attack and what's not? And so I think that's really, really interesting. I mean, certainly one of the things I've found, and Zoe, you can talk about this, is I think that we are here where we are because of the fact we have better machines, faster processing. We have tons and tons and tons of data now that we have to wade through, but we have machines that can do it and memory and resources and so on. And so that's how we are here, and I think it'll get better. But also, we're just gonna see it happen more and more. We're gonna be using it more and more. I don't think there's hardly an industry that it's not touching now. And certainly, I think we can benefit from that in security with some of the things that we were— I just mentioned there about finding attacks and trying to get ahead of the game, if you will.
20:39Zoe BraitermanOh, definitely. And yeah, making sense of specific potential attacks and, you know, the specific modeling and the specific— yeah, I mean, all of the details and then trying to make them more and more specific and then more and more kind of different ways to play with the components within those models, definitely.
21:08Chris RomeoYeah, so you mentioned kind of, I guess, a different perspective than I was even thinking about we first started the conversation, I was thinking about AI and machine learning kind of from the perspective of how does the AppSec team use, you know, how could you potentially use these technologies to do AppSec better or make AppSec easier? And you actually made reference to the fact that data sciences teams need AppSec to be built in. So almost the other side of the coin from what I'm thinking about. And That is just the importance of AppSec best practices and all the things of OWASP being boiled into these new artificial intelligence machine learning products and things that are being done in different industries that need for that solid set of best practices to make sure that when we have self-driving cars, we can have some amount of assurance that they are in fact not remote control vehicles. They are, you know, they, they have solid security architecture that's gone into them.
22:12Zoe BraitermanOh, definitely. Yeah. And make sure that, you know, at each, I guess, phase of the automated processes that, you know, proper controls are taken at each of them and trying to track throughout the entire training of the models and all of that. And also for various services that implement them within different organizations.
22:48Chris RomeoZoe, where could folks find you if they want to kind of continue this conversation about AI, machine learning, AppSec? OWASP WIA, Women in AppSec. Where's the best place for them to find you and continue the conversation?
23:09Zoe BraitermanI suggest starting with Twitter. So it's Z. Braiterman, Z.B.R.A.I.T.E.R.M.A.N. And yeah, so on Twitter I reference chair of OWASP WIA, but I also go by security and human and machine intelligence strategist because I really believe in the human element and the collaboration behind all of this as we continue to progress. So, yes. So, @ZBrainerman on Twitter.
23:45Chris RomeoI just thought of one other thing I'm curious about. Are there any kind of references or resources, things that you kind of have as go-to resources for AI and ML that you'd point out, want to kind of draw attention to for our audience?
23:58Zoe BraitermanI follow a combination of academic references and open source references. And I guess colleagues doing various applications of ML in industry as well. And also being able, looking at different frameworks that are out there and getting into the specifics specifics about what types of data they use and what types of models and, you know, the applications and trying to see really, I guess, dig deeper, you know, into the underlying components that could be used for various parts of AppSec.
24:43Chris RomeoSo I guess any last words for our audience about this topic?
24:49Zoe BraitermanBe very, very conscious as a user and Just keep learning within the community and everything on the professional side. And yes, be secure. It's even more important now.
25:06Chris RomeoThat is definitely true. Well, Zoe, thank you for taking the time to speak with us today, and we look forward to continuing the conversation on Twitter and wherever the conversation goes. Hope to catch you soon at an OWASP event, maybe even OWASP in Washington, D.C. And so once again, thanks for being here.
25:27Zoe BraitermanDefinitely. And thank you both.
25:29Chris RomeoThanks for listening to the Application Security Podcast. Our intro music is 8-Bit Kung Fu by Born and TJ, and our outro music is Southern Delight by Stefan Kartenberg. You'll find the show on Twitter @AppSecPodcast or on the web at www.securityjourney.com.
25:51Robert Hurlbutapplication-security-podcast.
25:51Chris RomeoYou can also find Chris on Twitter @edgeroute and Robert @roberthurlbunt. Remember, security is a journey, not a destination.
3,639 words · transcript by assemblyai
More on AI and LLM Security
View all episodes →- June 15, 2023 · 43 minSteve Wilson -- OWASP Top Ten for LLMs
- October 31, 2023 · 52 minSteve Wilson and Gavin Klondike -- OWASP Top Ten for LLM Release
- April 15, 2026 · 50 minSteve Wilson--OpenClaw and Advanced AI Agents