Pragmatic and Trustworthy AI in Cybersecurity
Download resourcesAbout this session
Gary Givental, Chief Architect at IBM's X-Force Platform, traces the evolution of AI in cybersecurity from 1980s rule-engine expert systems through machine learning, deep learning and now generative AI, and argues that trustworthiness must grow alongside capability. He walks through the failure modes of each generation: unmanageable rule sprawl and insider tampering in SIEM expert systems, non-determinism, overfitting and garbage-in-garbage-out training data in machine learning, and bias, hallucination and prompt injection in large language models. Drawing on his own experience building IBM's security analytics and Advanced Threat Disposition System, he presents a six-step framework for moving a model safely from lab to production: proof of concept, a passive mode with agreement/disagreement metrics before any automated action, opt-in controls to onboard customers gradually, opt-out exclusion rules, a permanent human in the loop, and daily and weekly audit dashboards that feed corrections back into the training data. He closes by describing an ongoing shift from a strict 'never trust, always verify' posture toward a metrics-substantiated trust model as this discipline, which he calls MLSecOps, matures. A short Q&A covers a real example of a false negative caused by an under-investigated analyst decision propagating through transfer learning.
Key takeaways
- Run a new model in passive mode first, tagging or scoring traffic without taking action, and measure agreement versus disagreement with human analysts before automating anything.
- Keep a rule-based expert system in the pipeline as a human-in-the-loop gate even after machine learning is deployed, so known-safe or known-bad traffic never depends on a non-deterministic model.
- Build explicit opt-in and opt-out controls so new customers, data centers or traffic types can be excluded from automated action until enough training data and confidence accumulate.
- Run daily and weekly audit dashboards on model output and feed the corrections back into training data, since mislabeled analyst decisions can propagate into other customers' models through transfer learning.
- Treat AI security systems as a distinct discipline (MLSecOps) requiring their own access controls, since compromising the training data or rule base is as dangerous as compromising the customer environment.
Speakers

Chief Architect for IBM Consulting Cyber Security Services global MSS Platform, hands-on technical leader, IBM recognized Master Inventor with over a dozen patents, mentor, AI enthusiast, pragmatic Design Thinking practitioner, Agile grey beard… Read moreRead less
Chief Architect for IBM Consulting Cyber Security Services global MSS Platform, hands-on technical leader, IBM recognized Master Inventor with over a dozen patents, mentor, AI enthusiast, pragmatic Design Thinking practitioner, Agile grey beard, data geek, longtime yogi and martial artist.
Responsible for the architecture strategy, engineering and daily operation of IBM's Managed Security X-Force Protection Platform - a global security analytics platform that detects and monitors cyber threats, automates threat disposition and response for trillions of logs per day across 350+ customers.
Security Analytics Guild lead, responsible for driving innovation and technical strategy for AI, machine learning, threat detection and response automation for Managed Security Services with collaboration across broader IBM Security division, including IBM Research.
Receiver of IBM's 2019 Corporate Recognition Award and Outstanding Technical Achievement Award for Advanced Threat Disposition System. ATDS uses machine learning and expert system technology to automatically disposition threats, increasing accuracy by 20-30%, reducing triage cycle time by 50-60%. The ATDS platform contributed to IBM being named a Global Leader in Managed Security Services by Forrester in 2020.
