Skip to main content
Cognitive Revolution

The Great Security Update: AI ∧ Formal Methods with Kathleen Fisher of RAND & Byron Cook of AWS

99 min episode · 2 min read
·
Kathleen Fisher Of Rand

Episode

99 min

Read time

2 min

Topics

Fundraising & VC, Artificial Intelligence, Software Development

AI-Generated Summary

Key Takeaways

  • Formal Methods Spectrum: Type checkers in Java represent simple formal methods proving basic properties like integer operations, while interactive theorem provers like CompCert verify full functional correctness of C compilers down to assembly code, requiring PhD-level expertise but providing complete semantic guarantees with explicit assumptions about hardware.
  • AWS Security Implementation: Amazon applies formal verification across critical infrastructure including TLS handshake protocols in s2n, policy interpreters handling over one billion calls per second, and the new isolation engine hypervisor for Graviton five processors, using tools like SAT solvers and Isabelle theorem prover to prove cryptographic correctness and separation properties.
  • AI-Assisted Proof Generation: Generative AI models now find inductive invariants and ranking functions needed for proving program correctness with loops and termination, reducing previously intractable problems to combinatorial reasoning that automated tools handle efficiently, enabling one-to-one ratios of engineers to formal methods experts instead of requiring dedicated PhD specialists.
  • Automated Reasoning Checks: AWS translates natural language policies like HR handbooks into formal logic using multiple LLM translations verified for equivalence by theorem provers, achieving 99% verification accuracy by checking AI agent outputs against formalized rules, iteratively refining specifications through corner case analysis with domain experts providing ground truth validation.
  • Security Rewrite Timeline: Current software vulnerabilities remain equivalent to unlocked doors and open windows, but combining formal methods with AI code generation enables superhuman secure code production within two model generations, with memory safety, input validation, and parser-generated protocols eliminating entire vulnerability classes if society prioritizes deployment over feature velocity.

What It Covers

Kathleen Fisher of RAND and Byron Cook of AWS explain how formal methods—mathematical techniques that prove software correctness—can dramatically improve cybersecurity before AI-powered attacks become ubiquitous, including AWS's automated reasoning systems.

Key Questions Answered

  • Formal Methods Spectrum: Type checkers in Java represent simple formal methods proving basic properties like integer operations, while interactive theorem provers like CompCert verify full functional correctness of C compilers down to assembly code, requiring PhD-level expertise but providing complete semantic guarantees with explicit assumptions about hardware.
  • AWS Security Implementation: Amazon applies formal verification across critical infrastructure including TLS handshake protocols in s2n, policy interpreters handling over one billion calls per second, and the new isolation engine hypervisor for Graviton five processors, using tools like SAT solvers and Isabelle theorem prover to prove cryptographic correctness and separation properties.
  • AI-Assisted Proof Generation: Generative AI models now find inductive invariants and ranking functions needed for proving program correctness with loops and termination, reducing previously intractable problems to combinatorial reasoning that automated tools handle efficiently, enabling one-to-one ratios of engineers to formal methods experts instead of requiring dedicated PhD specialists.
  • Automated Reasoning Checks: AWS translates natural language policies like HR handbooks into formal logic using multiple LLM translations verified for equivalence by theorem provers, achieving 99% verification accuracy by checking AI agent outputs against formalized rules, iteratively refining specifications through corner case analysis with domain experts providing ground truth validation.
  • Security Rewrite Timeline: Current software vulnerabilities remain equivalent to unlocked doors and open windows, but combining formal methods with AI code generation enables superhuman secure code production within two model generations, with memory safety, input validation, and parser-generated protocols eliminating entire vulnerability classes if society prioritizes deployment over feature velocity.

Notable Moment

The DARPA HACMS program demonstrated formal methods effectiveness by letting red teams attack a Boeing helicopter mid-flight with test pilots aboard after proving separation kernel properties. The pilots survived unharmed and could not detect they flew the high-assurance version, while the compromised camera partition crashed repeatedly without affecting flight operations.

Know someone who'd find this useful?

Episode Transcript

Hello, and welcome back to the Cognitive Revolution. Two quick notes before we jump in today. First, again, applications for the MATS 2026 summer program are now open. At NeurIPS this year, MATS fellows presented many papers at at mechanistic interpretability and alignment workshops, and six MATS Fellows had spotlight papers. So if you're interested in a career in AI safety research, you should definitely consider applying. I'm also excited to say that I've booked MATS executive director, Ryan Kidd, for a full episode early in the new year. So listen to that and be prepared to submit your application by the January 18 deadline. Second, we're planning to record another AMA episode probably in the 2026. Visit our website, cognitiverevolution.ai, and click the link at the top to submit your questions, or feel free to DM me on your favorite social network. With that, today, we're diving into the world of automated reasoning and formal verification of software. My guests, Kathleen Fisher and Byron Cook, are legends in this underappreciated but increasingly important field. Kathleen famously led the High Assurance Cyber Military Systems or HACMS project at DARPA, is currently the director of the cybersecurity initiative at RAND. And starting in February, will take over as CEO of The UK's Advanced Research and Invention Agency, ARIA, which is often described as The UK's DARPA, though its mission goes beyond military technology with the goal of unlocking scientific and technological breakthroughs that benefit everyone. Byron, meanwhile, is vice president and distinguished scientist at Amazon, where he's made a major contribution to cloud security by leading the application of formal methods to distributed systems at AWS, which despite being arguably the world's biggest target for cyber attackers, has maintained an amazingly strong security record. In all honesty, I don't think I've ever felt more outclassed by my guest than I did in this conversation. My own math career topped out at differential equations and complex analysis in college, and I've never been strong when it comes to mathematical proofs or formal logic. Nevertheless, I'm hearing more and more in AI circles, not just about the need to harden critical infrastructure against cyber attacks before AI powered hacking becomes ubiquitous, but specifically about the unique power of formal methods to deliver true information security guarantees. And so I was really eager to learn as much as I could and honored that these masters were willing to answer my remedial questions. We cover a lot of ground in this conversation, from the nature of the cybersecurity threats that AI poses to the relationship between software specifications and the proofs generated by formal methods to the critical role of assumptions and how it is that we can be confident that many low level logical statements do in fact add up to system level guarantees. We also discuss how these methods can be used to create a reward signal for coding models and why, despite what we've seen from AI coding assistance to date, we …

Get the full transcript (19,100 words) + summary by email — free

One-time email with the complete transcript and AI summary of this episode. No account needed.

One email, no spam. We’ll also show you what SignalCast does.

Browse all Cognitive Revolution transcripts →

You just read a 3-minute summary of a 96-minute episode.

Get Cognitive Revolution summarized like this every Monday — plus up to 2 more podcasts, free.

Pick Your Podcasts — Free

Keep Reading

Books, tools, and gear mentioned in this episode

SignalCast may earn commission on purchases via these links.

Tools

  • interactive theorem provers like CompCert verify full functional correctness of C compilers down to assembly code, requiring PhD-level expertise but providing complete semantic guarantees
  • using tools like SAT solvers and Isabelle theorem prover to prove cryptographic correctness and separation properties
  • by Amazon

    Amazon applies formal verification across critical infrastructure including TLS handshake protocols in s2n, policy interpreters handling over one billion calls per second

other

  • by DARPA

    The DARPA HACMS program demonstrated formal methods effectiveness by letting red teams attack a Boeing helicopter mid-flight with test pilots aboard after proving separation kernel properties

More from Cognitive Revolution

We summarize every new episode. Want them in your inbox?

Similar Episodes

Related episodes from other podcasts

Explore Related Topics

This podcast is featured in Best AI Podcasts (2026) — ranked and reviewed with AI summaries.

Read this week's AI & Machine Learning Podcast Insights — cross-podcast analysis updated weekly.

You're clearly into Cognitive Revolution.

Every Monday, we deliver AI summaries of the latest episodes from Cognitive Revolution and 192+ other podcasts. Free for one show.

Start My Monday Digest

No credit card · Unsubscribe anytime