ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

AI threats: should we fight fire with fire?

Trevor Dearing at Illumio outlines the new threats from generative AI and suggests methods for combatting them

 

Alongside positive applications of AI such as medical diagnostics, we’re sadly seeing the emergence of AI cyber-threat techniques.

 

Often, unskilled "script kiddies" use generative AI tools to aid in creating malware. Tools like ChatGPT will block harmful requests. However, more malicious versions like WormGPT and FraudGPT are now circulating. Organisations are now plagued by the more sophisticated threat groups using AI to explore new attack techniques. 

 

Why AI-powered cyber-attacks are such a threat 

AI is not new – we have seen it coming for a long time. However, the worry now is that it is increasingly being used to facilitate the evasion of existing security tools. AI-based attacks can easily find vulnerabilities and open and exploit ports to run malicious code or move to high-value assets.

 

One particularly effective tactic we see in the wild is “phone home morphing." Once malware has successfully penetrated the target network, this technique uses an API to call back to an AI tool to report its progress and receive updates to help it progress.

 

So, for example, ransomware blocked by an Endpoint Detection and Response (EDR) tool will ‘phone home’ to explain what stopped it and then receive an update to overcome the obstacle. This happens repeatedly until the malware succeeds, and, on account of the AI engine running it, the whole process can happen very rapidly. 

 

Even more dangerous than this is the concept of a self-generating polymorphic code. Rather than calling back to base, this AI malware can learn from its environment independently and adapt its tactics to ‘live off the land’ and progress its attack. This approach is currently too resource-intensive to be viable, but it’s only a matter of time as computing power advances. 

 

The danger of AI poisoning

Alongside the threats from AI, there are also threats to AI, known as AI poisoning. This is where bad actors manipulate AI tools that learn from information to identify patterns and trends. By poisoning this data with false information, it’s possible to trick AI into learning the wrong lessons. This could mean deceiving systems into thinking malicious activity sets are actually benign, enabling attackers to go unnoticed. 

 

Research has already shown this to be possible. Using a technique termed ‘split-view poisoning’ researchers at Cornell University determined they would easily be able to poison 0.01% of the most prominent deep-learning datasets. The research team concluded that even this small percentage would be sufficient to poison a learning model and influence its decision-making. 

 

The answer to AI threats is not more AI

"Fighting fire with fire” has become one of the most common responses to AI-powered threats. What better way to counter an inhumanly fast threat than with an equally dynamic, defensive AI?

 

However, while AI undoubtedly has its place in the security tech stack, relying entirely on this approach to combat new threats is a mistake. The ability for adversaries to poison and subvert defensive tools means that there’s always a risk that AI-powered security solutions will be tricked into overlooking malicious activity. 

 

Wider deployment of AI threat detection means more opportunities for threat actors to understand how tools work and counteract them. As such, AI should be used judiciously, just as we use antibiotics with caution to bring about the greatest effect when fighting infection. The best strategy is to limit the impact of AI-powered attacks by tightly controlling the environment they can access. 

 

Limit the learning surface

Reducing the attack surface is already a mainstay security strategy for keeping attackers out. Now we also need to think in terms of limiting the “learning surface” available to offensive AI tools already within the network. Blocking invasive malware from accessing resources means the AI behind it will have less opportunity to learn, adapt, and progress the attack. 

 

One proven strategy for doing so is breach containment. This focuses on limiting and containing how malicious actors can spread through the network using microsegmentation. Rather than trying to outpace and catch an intruder, the threat is halted in its tracks until it can be eliminated. This has a knock-on effect of improving incident recovery as the impact radius of an attack is far more limited. 

 

While AI is a burgeoning threat, the capabilities needed to fight it are nothing new. Principles such as the NCSC’s Cyber Assessment Framework (CAF) already highlight the need for awareness of how systems communicate and the use of network segmentation.

 

However, the problem is traditional network segmentation approaches do not provide the control and agility needed to fight AI-powered threats. They offer no ability to change security rules per asset, based on status and context, which makes it increasingly difficult to keep up.

 

As a result, we need a step change in security strategy – one that moves away from the static, network-based cyber-security approaches of the past, to a more dynamic approach that applies security controls on a much granular level based on risks identified. 

 

Using Zero Trust Segmentation to limit AI threats

Zero Trust is a strategy based on “never trust, always verify’. Very simply this means a shift from trying to identify the millions of bad things and stopping them to identifying the few good things and allowing them. 

 

Zero Trust Segmentation moves the control away from static legacy firewalls to the individual asset where an agile approach can be used to create a more responsive security environment. By providing improved visibility, the interconnections between resources can be identified and the required dependencies can be allowed with all other communications denied. 

 

In the event of an attack the systems can effectively be locked down while the threat is managed, allowing for a more targeted use of AI defences to clean the environment. Using a more dynamic approach, organisations can respond and recover more quickly in the event of a breach.

 

This approach will restrict the ability of an AI attack to learn about the defences and systems thus reducing the effectiveness of any attack. The result of this approach is that organisations can continue to deliver critical services during an AI generated attack.

 


 

Trevor Dearing is Director of Critical Infrastructure at Illumio

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543