Vitalik Buterin Says AI Could Strengthen Cybersecurity

Vitalik Buterin argues AI could strengthen cybersecurity by formally proving software security, while Vlad Tenev says AI will prove code is correct.

Vitalik Buterin Says AI Could Strengthen Cybersecurity
Vitalik Buterin Says AI Could Strengthen Cybersecurity

Vitalik Buterin is challenging the notion that better AI hacking inevitably signals the end of cybersecurity. The co-founder of Ethereum argued in a post on September 16 that the same technology that can assist attackers in identifying weaknesses may ultimately provide defenders with a more powerful tool, i.e., mathematical proof that software operates as intended.

Using Signal as an example of how a complex program could be tested against well-defined security features, he focuses on formal verification, where security claims can be exactly described and mathematically verified.

Buterin’s Answer to the AI Hacking Fear

The problem is simple, i.e., attackers may be able to find flaws faster than developers if AI becomes more proficient at doing so. Buterin challenges the idea that this will always put defenders at a disadvantage.

He argues that software itself may become more verifiable as AI develops. Developers may use AI to generate mathematical proofs proving the validity of specific security features rather than relying only on humans to evaluate increasingly complicated code.

Moreover, Buterin reduced the idea to a much broader question, i.e., why couldn't AI finally prove that a computer program meets a certain security criterion if it can prove difficult mathematical theorems?

He is not arguing that AI simply becomes a better cybersecurity assistant. His point is that AI could help turn security claims into something that can be mathematically checked.

Signal Shows Why “Secure” Needs a Definition

Buterin used Signal to clarify where the real challenges lie. It may seem simple to say that Signal is "secure," but depending on what is being protected, security can imply a variety of things.

One fundamental characteristic would be that a message's contents shouldn't be readable by someone without the recipient's private key. The property that a program must meet can be derived from the mathematical expression of that assertion.

His more general argument is that a proof is only valuable if the intended security attribute has been explicitly established. While the property being examined may be quite basic, a program may be very complex.

Buterin has previously examined this concept in great length, outlining formal verification as a method of using automatically verified mathematical proofs to show the characteristics of computer systems. In particular, he talked about cryptographic software verification and demonstrated how an end-to-end proof may demonstrate that the code users actually execute satisfies a specified security property.

The Same Idea Could Matter More for Crypto

As software frequently has direct control over assets, this argument is especially relevant in the crypto space. Buterin has frequently highlighted how challenging it is to secure systems where a code error could have negative financial effects.

In his post from September, he links the concern to his own choice to keep cryptocurrency. He stated that cryptocurrency accounts for almost 90% of his wealth, characterising this as an implicit bet that cybersecurity will continue to be defence-focused even as AI advances.

The crucial aspect of his argument is not that proofs assure the safety of every application. The relevant property must be established by a proof, and the underlying presumptions must likewise be true.

Buterin's earlier definition of formal verification revolves around this criterion. He pointed out that developers might prove the wrong thing, remove important parts of a system from the proof, or rely on assumptions that prove to be incorrect.

Vlad Tenev Adds to the Optimistic View

Vlad Tenev, CEO of Robinhood, made a brief prediction in response to a discussion: "AI will prove your code is correct." His remark clearly summarises the argument's trajectory.

Combining AI-generated software with automated verification is an intriguing option for cryptocurrency developers. Large volumes of code could be produced by AI, and before that code is trusted, formal verification could be employed to validate certain qualities.

Instead of viewing AI as a stand-alone security solution, Buterin has framed this relationship as complementary. He made the case in his May talk that AI may speed up formal verification by assisting in the creation of programs as well as the proofs required to verify their attributes.

This raises a more focused challenge for the industry: to what extent can software that secures wallets, blockchains, and cryptographic systems eventually be accompanied by independently verifiable evidence for users and developers?

That is Buterin's more promising response against AI-powered attacks. Developers could increasingly make the key components of software mathematically verifiable rather than try to outrun more skilled hackers solely by discovering problems first.


If you find any issues in this article or notice missing information, please feel free to reach out at team@etherworld.co for clarifications or updates.

To promote your Web3 articles, events, and projects, you may reach out anytime via EtherWorld PR for submissions and collaboration.

Related Articles

  1. Vitalik’s Bitcoin-Inspired Plan for Ethereum
  2. Vitalik Buterin Outlines Ethereum's Lean Vision
  3. Vitalik Buterin Explains Cryptography’s “Final Boss”
  4. Vitalik Buterin Says Options-Based DeFi Is Already Taking Shape
  5. Vitalik Buterin Unveils Analysis on Ethereum's Diverse Layer 2 Landscape

To follow blockchain news, track Ethereum protocol progress, and read our latest stories, subscribe to our weekly today.

Join the EtherWorld & Avarch Internship Program and build your career in blockchain, content, social media, video, podcast editing, or operations. Send your resume and brief introduction to contact@etherworld.co.


Disclaimer: The information contained in this website is for general informational purposes only. The content provided on this website, including articles, blog posts, opinions, & analysis related to blockchain technology & cryptocurrencies, is not intended as financial or investment advice. The website & its content should not be relied upon for making financial decisions. Read full disclaimer & privacy policy.

To stay updated on blockchain news, Ethereum protocol progress, and our latest stories, subscribe to our weekly digest and YouTube channel for ELI5 content.

To promote your Web3 articles, events, project updates, and Press Releases, reach out anytime via EtherWorld PR for submissions and collaboration. For other queries, email contact@etherworld.co.

If you’d like to support our work, share the content and consider donating at avarch.eth.

Join our community on Discord and follow us on Twitter, Facebook, LinkedIn & Instagram.

Sponsored
ETHShala

Understand Ethereum. Shape the Future — learn EIPs with ETHShala.

Inviting Web3 projects to partner with EtherWorld and increase visibility across the Ethereum ecosystem.

EIPs Insight

Track Ethereum protocol upgrades, EIPs & governance — all in one place.

EtherWorld.co × Avarch

Gain hands-on Web3 experience with our internship program.

Subscribe to join the discussion.

Please create an account to become a member and join the discussion.

Already have an account? Sign in

Sign up for EtherWorld.co newsletters.

Stay up to date with curated collection of our top stories.

Please check your inbox and confirm. Something went wrong. Please try again.
0/5 free articles read this week
Sign up free