sophisticated attack
Securing AI Agents Against Prompt Injection Attacks
Ramakrishnan, Badrinath, Balaji, Akshaya
Retrieval-augmented generation (RAG) systems have become widely used for enhancing large language model capabilities, but they introduce significant security vulnerabilities through prompt injection attacks. We present a comprehensive benchmark for evaluating prompt injection risks in RAG-enabled AI agents and propose a multi-layered defense framework. Our benchmark includes 847 adversarial test cases across five attack categories: direct injection, context manipulation, instruction override, data exfiltration, and cross-context contamination. We evaluate three defense mechanisms: content filtering with embedding-based anomaly detection, hierarchical system prompt guardrails, and multi-stage response verification, across seven state-of-the-art language models. Our combined framework reduces successful attack rates from 73.2% to 8.7% while maintaining 94.3% of baseline task performance. We release our benchmark dataset and defense implementation to support future research in AI agent security.
Strategic Deployment of Honeypots in Blockchain-based IoT Systems
Commey, Daniel, Hounsinou, Sena, Crosby, Garth V.
--This paper addresses the challenge of enhancing cybersecurity in Blockchain-based Internet of Things (BIoTs) systems, which are increasingly vulnerable to sophisticated cyberat-tacks. It introduces an AI-powered system model for the dynamic deployment of honeypots, utilizing an Intrusion Detection System (IDS) integrated with smart contract functionalities on IoT nodes. This model enables the transformation of regular nodes into decoys in response to suspicious activities, thereby strengthening the security of BIoT networks. The model focuses on understanding and predicting sophisticated attacks that may initially appear normal, emphasizing strategic decision-making, optimized honeypot deployment, and adaptive strategies in response to evolving attack patterns. The Internet of Things (IoT) has revolutionized numerous sectors through its vast network of interconnected devices. However, the rapid expansion of the IoT introduces significant security and privacy concerns, as these devices often have limited computational resources, making them vulnerable to attacks [1]. Traditional security solutions, which sometimes rely on centralized systems, encounter scalability issues and introduce further vulnerabilities [1], [2].
Does AI materially impact cybersecurity strategies?
Artificial intelligence (AI) has been deployed across multiple industries to increase security, improve productivity or enhance user experiences. AI arrived in the cybersecurity space claiming to cyber leaders that it was the solution to detecting and stopping advanced attacks. According to a global survey released in September 2021, just under half of executives think artificial intelligence is the best tool to counter nation-state cyberattacks. It's true that AI technologies can continually learn and improve, generalizing observations from past attacks to discover new malicious behaviors. However, while AI is lathered across almost every marketing campaign involved in promoting cybersecurity products, the promise of AI is generally hollow until the models can meet or exceed human levels of intelligence.
How businesses can safeguard against rogue AI - Raconteur
Three decades after a US university student called Robert Tappan Morris was convicted of launching the first widely known malware attack on the internet, cybercrime has become big business, costing the global economy an estimated ยฃ2.1m a minute. Internet service provider Beaming reports that cybercriminals are launching increasingly sophisticated attacks on an "unprecedented scale". The pandemic has exacerbated the situation because it has prompted a sharp rise in remote working, which has enabled them to target vulnerabilities in domestic internet connections to attack corporate systems. In 2020, the average UK business faced 686,961 attempts to breach its systems โ 20% up on the previous year's figure โ according to Beaming. That equates to an attack every 46 seconds.
Mastercard cyber chief on using AI in the fight against fraud - Raconteur
The fight against fraud has always been a messy business, but it's especially grisly in the digital age. To keep ahead of the cybercriminals, investment in technology โ particularly artificial intelligence โ is paramount, says Ajay Bhalla, president of cyber and intelligence solutions at Mastercard. Since the opening salvo of the coronavirus crisis, cybercriminals have launched increasingly sophisticated attacks across a multitude of channels, taking advantage of heightened emotions and poor online security. Some ยฃ1.26 billion was lost to financial fraud in the UK in 2020, according to UK Finance, a trade association, while there was a 43% year-on-year explosion in internet banking fraud losses. The banking industry managed to stop some ยฃ1.6 billion of fraud over the course of the year, equivalent to ยฃ6.73 in every ยฃ10 of attempted fraud.
AI a new and 'frightening' battlefield in cyber war, experts warn
Unbeknownst to the CEO of a company who was interviewed on TV last year, a hacking group that was trailing the CEO taped the interview and then taught a computer to perfectly imitate the CEO's voice -- so it could then give credible instructions for a wire transfer of funds to a third party. This "voice phishing" hack brought to light the growing abilities of artificial intelligence-based technologies to perpetuate cyber-attacks and cyber-crime. Using new AI-based software, hackers have imitated the voices of a number of senior company officials around the world and thereby given out instructions to perform transactions for them, such as money transfers. The software can learn how to perfectly imitate a voice after just 20 minutes of listening to it and can then speak with that voice and say things that the hacker types into the software. Get The Start-Up Israel's Daily Start-Up by email and never miss our top stories Free Sign Up Some of these attempts were foiled, but other hackers were successful in getting their hands on money.
4 Cyberattacks That You Would Miss Without AI
Moore's Law, advocated by Gordon Moore of Intel fame, says that the computational capabilities will double every 18 to 24 months. And we've seen that really unfolding over the last 30 years (see chart). It's really stoked people's imagination, so much so that many believe that the promise of artificial intelligence (AI) could become reality, and computers could actually learn to think like humans. I believe it's still a number of years away, but it is fueling a lot of hype regarding AI. What it's truly capable of, where it can be effective, and what it takes to implement it, all of which have become somewhat inflated in the market today.
Why AI is the key to robust anti-abuse defenses
This post explains why artificial intelligence (AI) is the key to building anti-abuse defenses that keep up with user expectations and combat increasingly sophisticated attacks. This is the first post of a series of four posts dedicated to provide a concise overview of how to harness AI to build robust anti-abuse protections. The remaining three posts will delve into the top 10 anti-abuse specific challenges encountered while applying AI to abuse fighting, and how to overcome them. Following the natural progression of building and launching an AI-based defense system, the second post covers the challenges related to training, the third will delve into classification issues and the last one will look at how attackers attempt to attack AI-based defenses. This series of posts is modeled after the talk I gave at RSA 2018.
Machine vs. Machine: A War in the Offing
The rise of artificial intelligence (AI) is the great story of our time, thanks to the low cost of computing, storage, and off-the-shelf machine algorithms. However, cyber criminals also have access to these resources and are able to build smarter malware. This means that the attackers of the future will be machines that think, as hackers will look for new ways to use AI to their own benefit. We will witness sophisticated attacks launched on a large scale both quickly and intelligently, with little human intervention. As the digital economy expands, cybersecurity threats will also grow.