Artificial intelligence and cybersecurity

In our previous articles we saw what AI is and how it can be applied in different industrial fields. But what are the consequences of this technology for cybersecurity?
AI can serve both those who seek to compromise systems and those who protect them. In today's article, we look at AI-related cybercrime.
How AI can compromise cybersecurity
Experts say attackers can use generative AI and large language models to scale up attacks at a speed and complexity never reached before. In particular, they can find new ways to take advantage of geopolitical tensions to carry out advanced attacks. AI also allows hackers to optimize their ransomware and phishing techniques and make them far more sophisticated.
AgencePDN gets pirated content removed: see our solutions by sector.
Thanks to AI, cybercriminals can indeed lie dormant and go unnoticed in a company's network for long periods, during which they set up tools that give them access to the organization's critical infrastructure. Then, when they are ready to launch an attack against the whole company, they can eavesdrop on meetings, extract data, spread malware, create privileged user accounts to access other systems and/or install ransomware.
AI is a particularly effective tool for cybercriminals because of its ability to learn by collecting data and to anticipate reactions, which makes attacks more effective. Automated and targeted attacks, such as phishing attacks and AI-generated malware, can be harder to detect and counter. AI generally makes it possible to improve existing hacking techniques: stealth attacks, password cracking, CAPTCHA cracking, and identity theft.
However, AI-powered cybercrime also has its own specific features; here are a few.
Creation of fake data (deepfakes), data manipulation
If data is altered or corrupted, an AI-powered tool can produce unexpected or even malicious results. It is currently perfectly possible to corrupt a model with malicious data in order to alter its results, which can be very dangerous for the company or its customers.
Attackers use machine learning and AI to compromise environments by poisoning models with inaccurate data. Machine learning models rely on correctly labelled data samples to build accurate, repeatable detection profiles. By introducing benign files that look like malware or by creating behaviour patterns that turn out to be false positives, attackers can make attack behaviours appear non-malicious. Attackers can also poison AI models by introducing malicious files that AI training has classified as safe.
For example, slightly modified images can mislead an image recognition model. This can have serious implications in areas such as autonomous vehicle safety and facial recognition.

AI-assisted attacks are among the emerging threats identified by the European Union Agency for Cybersecurity
Malware and advanced malicious bots
AI-powered tools could allow developers with basic programming skills to create automated malware, such as advanced malicious bots. A malicious bot can steal data, infect networks and attack systems with little or no human intervention.
Sophisticated malware, for example, can modify local system libraries and components, run processes in memory and communicate with one or more domains belonging to the attacker's command-and-control infrastructure. All of these activities combined create a profile known as tactics, techniques and procedures (TTPs). Machine learning models can observe TTPs and use them to develop detection capabilities.
Learning from existing AI models
Attackers are actively seeking to map the existing and in-development AI models used by cybersecurity vendors and operations teams. By learning how AI models work and what they do, criminals can actively disrupt machine learning operations and models during their cycles. This can allow hackers to influence the model by tricking the system into favouring the attackers and their tactics. It can also allow hackers to evade known models altogether by subtly modifying data to avoid detection based on recognized patterns.

Join us in two weeks for the final part of our article. We will see how AI can be beneficial for cybersecurity. In the meantime, if you have content to protect, whether a film, series, book, music album or software, don't hesitate to contact us, and one of our account managers will be happy to help. We have been pioneers in cybersecurity and intellectual property protection for more than ten years. Happy back-to-school to all!
Share this article


