Offensive and Defensive Artificial Intelligence in Cyberspace

A. Parkavi, Sini Anna Alex, Veeraiah Sangeetha, S G Subramanya · Apple Academic Press eBooks · 2025

Currently, around 4.39 billion people use the internet and 3.26 billion people are using social media over different devices. When we use the internet, the vital part to be considered and preferred is network security. For securing the network people use the traditional security approach using security devices that are deployed on special edges, such as firewalls, antivirus, antimalware, intrusion detection (IDS), and prevention systems (IPS). Artificial intelligence (AI) can provide a secure network from various types of attacks. Various attacks are classified as routing attacks, selective forwarding, wormhole attacks, traffic analysis, eavesdropping, jamming, worms, viruses, trojans, etc., Diverse types of artificial learning algorithms are used by data scientists to find patterns in data that lead to actionable insights. AI algorithms are divided into categories, such as supervised learning, unsupervised learning, and unsupervised learning predictions. AI is taking a major role in all real-time systems we are using in day-today life. Inherently, the attacks on AI-based systems are increasing, as well 30 as researchers are working on new defensive models to protect the AI-based real-time systems. Designing the defensive models for AI-based systems is a challenging task for researchers. Behavioral analytics can be used by organizations for detecting the threats for protecting their AI-based real-time systems. Nowadays, the attackers perform adversary over AI systems by using automated models which are known as offensive AI. These offensive AIs can create attacks over real-time AI systems at the same time. We cannot handle these offensive AIs alone, but we can successfully win over these offensive AIs with the help of AI systems that are going to emerge as defensive AIs. Defensive AI provides facilities for cybersecurity professionals by giving them opportunities to improve their cyber defenses. But the emerging threats of cyber attackers use latest machine learning (ML) algorithms which are publicly accessible. To improve security in the cyber world, AI is used by researchers. AI is used to improve security against cyberattacks, such as malware, phishing, and unauthorized access to confidential data or resources. With defensive AI technology, organizations started using new processes, such as data acquisition, preparation, labeling, training the AI models, and production provisioning and inference validation. These processes are latest additions to the technical processes of the company and to be protected from hostile attacks. In the event of adversarial attacks, the attackers modify the inputs to the ML models to cause errors in the model. Defensive AI pre-processing input method can be used to filter the input that can trigger and reduce the risk of the offensive inputs which changes the AI model criteria. Defensive AI antivirus software detects the network peculiarities of suspicious processes behaviors. AI Antivirus detects and prevents network resources from being used when malicious software is launched on a network. The defensive AI is used to imitate and assess how users behave over a network. The goal of evaluating how users interact with the system is useful to identify rollover attempts. Hence, the AI model observes the actions of users and identifies unusual behaviors as anomalies to prevent offensive AI attacks. Defensive AI helps in automated analysis of networks and systems ensures assessment of the system regularly. So the adversary bad action can be detected among the suspected cyberattacks at an early stage. We discuss the following topics in the upcoming sections of the chapter, Offensive and defensive AIs introductions How offensive and defensive AIs can be implemented Applications of offensive and defensive AIs Case study

Read the paper · More papers on PaperTik