Head of AI Threat Intelligence and Security Research
AI Software & Platform
Amy Chang is a renowned AI security and cybersecurity expert with almost two decades of practitioner, academic, and government experience. She currently leads the AI Threat Intelligence and Security Research team at Cisco, developing first-in-class AI threat intelligence capabilities to monitor the threat landscape and to build defensive capabilities to secure enterprises from AI risk. Amy's work also focuses on developing scalable and sustainable frameworks for AI security.
Amy is also Adjunct Faculty in Cybersecurity & Emerging Threats at Middlebury Institute of International Studies. Prior, Amy also served numerous senior roles at start-ups, corporations, government, military, and non-profits, including as an Executive Director for Global Cybersecurity Operations at JPMorgan Chase, where she led cyber threat intelligence teams and uplifted JPMorgan's intelligence-driven cybersecurity defense. She was formerly a Staff Director in the House Foreign Affairs Committee and worked on Asia policy and legislation. She also served as an officer in the U.S. Navy. Amy is a graduate of Harvard University and Brown University.
When we launched the Cisco LLM Security Leaderboard earlier this year, the goal was simple: give organizations clear, tested data on how models hold up against attacks, so they know the risks before they deploy one. That matters because AI models...
Nine months ago, we introduced the Integrated AI Safety and Security Framework as a unified and comprehensive taxonomy to help organizations identify and mitigate the security and safety risks unique to AI systems. Existing frameworks remained.....
When you look at an AI model’s repository page, you see the name of the model and an associated publisher. In policy and industry conversations, the publisher often gets collapsed into a country label—a “U.S. model” or a “Chinese model”—used as.....
Open source AI has never been more accessible. The rapidly growing scale and diversity of AI models available to developers worldwide is unprecedented. The harder question begins after download: when you bring a model into your environment, what....
The dominant safety benchmarks for frontier large language models share a structural assumption: that a single prompt and a single model response are enough to characterize how a model behaves under adversarial attack. These benchmarks inform model..
This post is Part 2 of a two-part series on multimodal typographic attacks.
In Part 1 of “Reading Between the Pixels,” we demonstrated that text–image embedding distance correlates with typographic prompt injection success: conditions that push....
When it comes to AI models, one of the hardest questions to answer is deceptively simple: where did this model actually come from?
We addressed part of this problem with Model Provenance Kit, an open-source tool that fingerprints models at the.....
The importance of understanding a model’s origins has been a frequent topic of discussion among researchers and industry experts, and our own AI research confirms that AI supply chain security remains a weak link. Tracking where models come from....
This post is Part 1 of a two-part series on multimodal typographic attacks.
This blog was written in collaboration between Ravi Balakrishnan, Amy Chang, Sanket Mendapara, and Ankit Garg.
Modern generative AI models and agents increasingly treat...