RSAC If Amazon's Alexa+ works as intended, it could show how an AI assistant helps with everyday tasks like making dinner reservations or arranging an oven repair. Or things could go terribly wrong: it might fire up the oven and turn dinner plans into a house fire. This is why the e-commerce giant brought in security engineers, including both red teams and penetration testers, to work alongside product developers from the beginning, according to Amazon CISO Amy Herzog. Their job was to anticipate what could go wrong and ensure safety and security guardrails were in place to prevent Alexa+ from jumping the track. "It's funny how, having been in both seats, the product engineer thinks about making the intended thing work, and the security engineer thinks about all the ways that you can game that system," Herzog told The Register on the outskirts of RSA Conference in San Francisco this week. "Whenever you're talking about a system that can take actions on behalf of someone our immediate [reaction is]: Wouldn't it be good if, like me, as someone who's running this household could just say, This is what I need to go shopping for. These are the dinner reservations I need to make. Go make that happen. Schedule a delivery window," she said. "And then my kid comes into the kitchen and says, and also 50 pepperoni pizzas for me and my friends." The product engineer thinks about making the intended thing work, and the security engineer thinks about all the ways that you can game that sys...
Amazon CISO: How AWS red-teamed Alexa+ AI assistant
The Register
·Jessica Lyons
·Published May 1, 2025
·Updated
Affected Software
1 affected component
Amazon Alexa+
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses Amazon's red teaming efforts on the Alexa+ AI assistant, highlighting its potential benefits and security risks.
2
What security implications are discussed in the article?
The article raises concerns about the risks associated with AI assistants potentially malfunctioning or being exploited, leading to unintended actions.
3
What products or software are affected according to the article?
The primary product affected is the Amazon Alexa+ AI assistant.
4
What is the purpose of red teaming in the context of Amazon Alexa+?
Red teaming is utilized to identify vulnerabilities in the Alexa+ AI assistant before they can be exploited by malicious actors.
5
How might the Alexa+ AI assistant improve user experience?
If functioning correctly, Alexa+ could assist users with everyday tasks such as making dinner reservations and managing household repairs.