NVIDIA Corporation (NVDA) Earnings Call Transcript & Summary

January 31, 2024

NASDAQ US Information Technology Semiconductors and Semiconductor Equipment special 23 min

Earnings Call Speaker Segments

Unknown Executive

executive
#1

Hi, everyone, thanks for joining us today for our webinar; Improve Spear Phishing Detection with AI. Before we begin, we wanted to cover a few housekeeping items. More information can be found in the upper right corner of the window. All windows open on the screen are resizable and movable. If you have any questions during the webcast, you can submit them to the Q&A window. We'll try to answer these at the end of the event. A copy of today's slide deck and additional help materials are available in the resource list. We encourage you to download any resources or bookmark any links that you may find useful. There are some tips that can help make this event as best as it can be. To maximize the quality of this audio stream, please close any open applications aside from your browser window. Also, a good old-fashioned browser refresh can cure many ills. So if your audio stutter or the slides seem to be lagging, give that a try. You can also try opening this event in a different browser. If you encounter any other technical issues today, please let us know in the Q&A box, and we'll help you troubleshoot. Now without further ado, we'll turn the event over to our speakers to begin the presentation.

Nicola Sessions

executive
#2

Thanks for joining us today. My name is Nicola and I'm the host of today's webinar, where we'll discuss how generative AI can be used to improve the speed and accuracy of detecting Spear Phishing e-mails. I'm joined by Adam, who will walk through NVIDIA's AI workflow for Spear Phishing, a reference example, which can be used as a starting point for building this type of solution. Krist has also joined us to talk about how organizations are applying this technology to build solutions that better defend against Spear Phishing attacks. As you listen to the session, please feel free to submit your questions in the Q&A window and we'll be sure to address them either via the Q&A window or live at the end of the session. The number of cyber attacks continues to increase dramatically every year. Phishing represents the most prevalent and the most expensive cyber threat costing U.S. organizations $2.7 billion in 2022 alone and that's up from $2.4 billion in 2021. While generative AI is being used by attackers to create more frequent and more targeted Spear Phishing attacks, much more can be done to leverage AI to defend against these attacks. Organizations have traditionally relied on employee training to better recognize phishing e-mails or they write rules to filter out suspicious e-mails. With AI, phishing e-mails can be more accurately detected and blocked before they reach a user's inbox. In fact, organizations using AI and automation save nearly $1.8 million in data breach costs and reduce the time to detect and contain a breach by over 100 days on average. Organizations are recognizing the need to implement AI-based cybersecurity solutions as evidenced by the fact that cybersecurity is the fastest AI software growth category. In a survey of hundreds of security industry business leaders, the Security Industry Association found that 89% had active AI projects in their research and development pipeline. Real-time monitoring and response to attack is the primary focus area for cybersecurity AI. Organizations now understand the need to leverage AI to bolster cybersecurity, but spear phishing brings some unique challenges. Phishing e-mails are more generic, designed to scan large numbers of people, and generally, people are aware enough to spot them. However, spear phishing e-mails are customized for specific individuals, they're written for low volume, high click-through. In a spear phishing attack, an e-mail is tailored to a specific persona, job role or industry. For example, a CEO or CIO or someone in the finance department. Because the spear phishing e-mail is so targeted, it tends to be extremely convincing, Often, the only difference between the legitimate email and a spear phishing e-mail is the intent of the user. Spear phishing is at its core, a data visibility problem. These e-mails are difficult to defend against due to the lack of available training data. Because the attacks are highly personalized, an individual organization will not observe the requisite number of e-mails to train an accurate AI model. The types of spear phishing attacks on financial institutions are very different from health care, for example. Similarly, a spear phishing email targeted at a CFO includes different content than one targeting an engineer. This illustrates the challenge, lack of training data, when addressing spear phishing defense with AI. With NVIDIA NeMo and Morpheus, this lack of available training data to create such spear phishing detectors can be addressed. The NVIDIA Morpheus cybersecurity AI framework provides an NLP model that has been trained using synthetic e-mails generated by NeMo to identify spear phishing attempts. Morpheus is able to infer whether an e-mail is spear phishing or not by first determining the intent of e-mail, whether it's seeking financial information, requesting cryptocurrency or asking for personal financial information, such as account or routing members. Morpheus then combines the intent of the message with anonymized historical data of the center, including syntactic analysis, message timing and previous intentions. The spear phishing model incorporates all of this data into an actionable result. Before we talk about our approach to addressing the spear phishing problem with AI, let me introduce some of the technology. Let's start with NVIDIA NeMo. NeMo is the end-to-end cloud-native solution for building, customizing and deploying generative AI models. As enterprises start to take advantage of the transformative power of generative AI, a robust platform is needed to construct and manage these sophisticated models. That's where NVIDIA NeMo comes into play. For the spear phishing detection use case, NeMo's generative AI capabilities can help with creating training data to improve the accuracy and speed of spear phishing e-mail detection. Now I'd like to introduce NVIDIA Morpheus, a cloud-native cybersecurity SDK, which uses AI to identify, capture and react to threats and anomalies that were previously impossible to identify. We believe there's truly nothing out there like Morpheus. The first and most important thing to understand is that NVIDIA doesn't aim to be a cybersecurity company, and we aren't building a cybersecurity solution. Rather, we provide Morpheus to help our partners and customers build better cybersecurity solutions, and here's how we do that. Morpheus is GPU accelerated, enabling the highest performance and massive scale. With Morpheus, all network traffic can be inspected in real time and with massive data reduction enabled by AI, Morpheus can help to flag anomalies and provide insights so that threats can be detected and addressed much faster. The AI tools integrated with Morpheus make it easier for developers to build cybersecurity solutions that use AI, including RAPIDS, Triton Inference Server and TensorRT. Morpheus simplifies the analysis of logs and telemetry to help detect and mitigate security threats. Morpheus is data agnostic and can send and receive realtime telemetry from multiple sources, including any NVIDIA GPU and BlueField DPU accelerated server in the data center without impacting performance, integrating the framework into a third-party cybersecurity offering brings the world's best AI computing to communication networks. With our prebuilt models and AI tools, developers can get a jump start in building applications to leverage AI to address a multitude of cybersecurity use cases, including behavioral AI and sensitive information detection, phishing, fraud detection and ransomware reduction. Some of our Morpheus use cases have been assembled into AI workflows. Before Adam talks about our spear phishing detection workflow, I wanted to take a minute to talk about what AI workflows are. NVIDIA AI workflows provide reference examples that illustrate how NVIDIA's AI frameworks can be used to build solutions that address various use cases, include AI chatbots with retrievable augmented generation, speech-enabled intelligent virtual assistance, audio transcription, route optimization, insider threat detection and of course, spear phishing detection, the topic of today's webinar. And our goal in creating AI workflows is to help developers find a faster and easier path to delivering AI solutions. Using our prepackaged customizable reference applications, which includes best-in-class AI software with cloud native deployable packaging, you can reduce development time and accelerate the deployment of AI solutions. The accuracy and performance of AI solutions has improved with the use of NVIDIA's framework and containers that are performance-tuned and tested for NVIDIA GPUs. And when you're ready to transition from pilot to production, you can leverage NVIDIA AI enterprise software, which provides API's stability, security and support for all of the AI framework and pretrained models needed for production-grade AI applications. Now I'm going to hand it over to Adam to walk through the spear phishing detection AI workflow.

Adam Wood

executive
#3

Thanks, Nicola. To accelerate your path to building the solution, we have developed the spear phishing detection AI workflow. This workflow leverages NVIDIA Morpheus, the open source post-fixed mail server, a post [ grasp ] through our database as well as a series of pretrained models using generative AI techniques. Model inference occurs within the Morpheus pipeline, where score is generated, correlating the classification of the messages intent based upon its content. The end user is then notified to verify the safety of the e-mail, which was flagged by the AI model for intent confirmation. This feedback can then be used to retrain the model and generate additional training e-mails. This workflow has built to top the NVIDIA cloud-native stack with the cloud-native service add-on pack. Cloud native stack gives enterprises a solid foundation to build and deploy AI solutions on Kubernetes. The add-on pack provides a selection of enterprise-ready services for the workflow, specifically Prometheus and Grafana for monitoring the pipeline's health and throughput, Cert Manager for providing the necessary security certificates and a database operator used to store statistical information. The core components of this NVIDIA AI workflow are 4 natural language processing, pre-trained models to analyze and classify e-mails for identifying spear phishing attempts, the inference pipeline to provide the plumbing from the mail server to inference and back out for delivery, a reference solution for deployment and production, including components like logging and monitoring the workflow, and all of which is available in a cloud-native deployable bundle packaged as a single helm chart. Using these assets, the NVIDIA AI workflow provides a reference for you to get started and build your own AI solution with minimal preparation and includes enterprise-ready implementation best practices, helping you achieve the desired AI outcome more quickly while still allowing a path for you to deviate. NVIDIA AI workflows are designed as micro services, which means they can be deployed on Kubernetes alone or with other micro services to create production-ready application for seamless scaling in your enterprise environment. The workflow uses many cloud native Kubernetes services, including NVIDIA Morpheus, the post-fixed mail server, ML flow, Prometheus, Grafana and PostgreSQL. These components are packaged together into a deployable solution for detecting spear phishing e-mails. The spear phishing workflow components were used to build and deploy the spear phishing inference pipeline shown here. In this reference example pipeline, e-mail is first sent by the Source SMTP mail server and then accepted by an instance of the postfixed mail server. Postfix then sends the mail to the NVIDIA Morpheus pipeline, which is configured as a post-fixed content filter. At this stage in the process, the e-mail is enriched with intention analysis and statistical information from the centers past messages and then inferenced against the pretrained model to get a spear phishing result. Once processed by Morpheus, the mail is resubmitted to the postfix mail queue for final delivery at the next top mail server, for example, Google Mail, On-Premise Exchange or Office 365. Email intentions play a crucial role in deciding whether the center's e-mail is benign or spear phishing. To tap into this signal, large language models were trained to infer intent using generated samples of enterprise e-mail content. The NVIDIA Spear Phishing AI workflow includes three intention models, whether the email is acting for a payment, discussing cryptocurrency or requesting personal financial information such as account and routing members. Additionally, the Morpheus pipeline maintains a sketch database to perform historical analysis on a per center basis. The sketches consider factors like time of day, e-mails were sent, grammatical syntax and the intention analysis of previous messages. To give an example, it answers the question, if it is common for Nicola, just an example, to send me e-mails at 2:00 a.m. on a Saturday with poor grammar asking about Bitcoin. It isn't. These become features of the spear phishing detection pretrained model, which is included in this phishing detection AI workflow. Note that the pretrained models provided were trained using generative AI in such a way that no personal identifiable information or sensitive information are included. The spear phishing detection AI workflow can be easily integrated into your e-mail solution. However, we've also included a demo e-mail environment for convenience. Here's an example e-mail, identified as spear phishing and you can see the modified subject line indicating the result. The pipeline has also included some additional information in the form of status headers. The status headers indicate the inference result from the overall model, in this case a 99% confidence, the configured minimum threshold to identify spear phishing e-mails and the result of each intention classification. In this case, the e-mail was flagged as both banking information and cryptocurrency, a zero indicates a positive result. Rules can be easily configured in your mail system to automatically quarantine or block mail identified as spear phishing. Using generative AI and the NVIDIA Morpheus cybersecurity AI framework, developers can build solutions that detect spear phishing attempts more effectively and with extremely short training times. In fact, in our testing, we were able to detect 90% of targeted spear phishing e-mails after less than 24 hours of training, a 20% improvement compared to a typical phishing detection solution. Morpheus also enables profiling of interactions between individual users, adding another layer of protection in detecting anomalies and threats. You can apply to try the spear phishing detection AI workflow in our hosted environment, NVIDIA LaunchPad. Now I'd like to introduce Kris who will talk to you about how he's working with organizations to implement faster, more accurate spear phishing detection with NVIDIA AI.

Kristopher Keith

executive
#4

Thank you, Adam, and thank you, Nicola, and hello, everyone. My name is Kristopher Keith, and I'm on the NVIDIA public sector team. And I'm excited to be speaking with you today about how generative AI is unlocking new ways to defend against an evolving threat, and that is spear phishing. I also want to thank our federal customers and partners for dialing into the webinar. I encourage you to ask questions in the Q&A. This is my personal invitation to join me at GTC in March. It is our annual conference. It's going to be held in San Jose, California, again, and we're back to being in person, so I'm expecting it to be a sold-out conference this year, and there will be plenty of cybersecurity content and guest speakers. Hope to see you there. So let's take what Nicola and Adam have already shared and bring that into the public sector. For those of you who are new to working with NVIDIA and cybersecurity in the public sector, let me first share that we view cybersecurity as a data problem. In spear phishing examples, there simply isn't enough data to train effective AI models, so we leverage the power of generative AI to fill that gap. Now I've spent a lot of time recently talking to federal customers who are implementing Zero Trust solutions, and this capability aligns perfectly with the pillars around AI and ML requirements for automating things like threat detection. And the topic of leveraging generative AI has come up a lot as well lately. The rise in spear phishing attacks against government agencies and critical infrastructure, we're seeing demands for new technologies like NVIDIA's Morpheus. I was at a Zero Trust Cybersecurity Summit in Washington recently. And one of the agency CISOs, was on the panel, and he said it plainly, if AI is being used to create attacks, we have to use AI to defend. Now if we zoom out across all of the federal government, let's talk about how big of a vulnerability this really is. We're dealing with sophisticated attacks, convincing e-mails that can be created faster and easier and just about any level of adversary can deploy this. What's more, we're talking millions of potential victims. Think of all the [ .mail ], all the .gov, the supporting supply chain of contractors and vendors. This is a complicated problem and conventional defenses of training and awareness, looking for poorly created e-mails or misspellings or software with rules, it's no longer sufficient. We need to stop malicious e-mails from getting into inboxes, so our employees aren't left making the decision if this e-mail is malicious or not. So I'm sure by now, you're probably already thinking about your own use case. Here are just a few that we've been looking into as well. You may have seen alerts from CISA and IRS. CISA is the Cybersecurity and Information Security Agency. They published warnings to tax professionals and IRS employees to be extra vigilant during tax season and don't click on any links and e-mails. For how many of us at this time of year are getting e-mail saying, "Click here to download your W-2" but aren't we all trained not to click on links? Is this a well-written e-mail from HR or an AI-generated spear phishing e-mail. It's just getting harder and harder to tell. Think about someone's stealing credentials of a tax professional or us as employees and having that information in the hands of adversaries with all of that PII data. Another example, what about the end of the government fiscal year. When everyone is under pressure to process last-minute activities, we've got government contracting officers, contracts administrators, vendors, subcontractors, accounts payable, receivable. There's a lot of opportunity to fall victim to an adversary who wants to do something like change payment routing information for a government contract. Yes, these are real-life examples I'm talking about. Key here is to basically reduce the number of phishing e-mails that ever get into employee inboxes. Once someone clicks on a link, that just might be too late. They compromise their credentials, open themselves to a ransomware attack or worse. So I encourage every organization in the public sector supply chain to be thinking about how to deploy the best defenses to keep their data secure and protect against financial loss against this evolving adversary capability. So with that, I'm really looking forward to working with our customers and partners to do amazing work to defend our most critical data. And I hope to see you at GTC. We're going to take some time now to answer questions you submitted during our session. But before we do that, I'd like to highlight some resources that you'll find helpful as you embark on your cybersecurity AI journey. The week of [ March 18 ], NVIDIA's GTC AI conference is going to be held. It's in person at the San Jose Convention Center in California. We've planned over 600 sessions, 200 plus exhibits, networking events around AI and accelerated computing. For more information, visit nvidia.com/gtc, that's nvidia.com/gtc. I hope you'll join us. We'd like to give more information about our AI-based cybersecurity. Visit our webpage at nvidia.com/morpheus. And lastly, if you're ready to get started with spear phishing detection AI workflow that Adam reviewed today and you want to try it hands on, you can visit our LaunchPad site at nvidia.com/try-morpheus. Try, hyphen Morpheus. Thank you. Speaking of GTC, we have a ton of great content planned around cybersecurity and generative AI. Sign up to hear our Head of Cybersecurity Engineering, Bartley Richardson talk about how we're helping our organizations to apply generative AI to improve their cybersecurity posture. And if you liked what you saw today with Adam's walk through of our spear phishing detection AI workflow, sign up for the hands-on lab experience and bring your own laptop to our solutions architects, Adeola and [ JB ]. They can walk you through how to build an application for AI-based spear phishing detection on your own. Hear from two machine learning developers, Colin and David, who are in the U.S. Navy and how they tackle the issue of deploying long context LLMs. Stop by our connect with the expert sessions, where our cybersecurity and generative AI and threat hunting experts are going to be on standby to answer all of your burning questions. And lastly, registered to attend our Cybersecurity Developer Day. You'll learn about how we're creating workflows that apply generative AI and LOMs to address different cyber security challenges.

This call discussed

For developers and AI pipelines

Programmatic access to NVIDIA Corporation earnings transcripts and 248,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.