Title
When AI Enters Cyber Defense, the Adversary Starts Attacking the Evidence
Abstract
As AI moves deeper into cyber defense, battlefield systems, critical infrastructure, and autonomous operations, the security problem is changing. The adversary is no longer only attacking networks, devices, or malware detectors. Increasingly, the adversary is attacking the evidence that AI systems rely on: behavioural signals, sensor patterns, attribution cues, classifier features, and even the reasoning process of large language models. In modern cyber conflict, data is strategic terrain shaped by the adversary. The future of AI-enabled cyber defense therefore depends not only on more accurate models, but on systems that can reason under deception, withstand adversarial manipulation, and remain governable at runtime.
This talk examines five connected defender challenges in contested AI-cyber operations. It begins with tactic-aware malware hunting, showing how AI can help defenders move beyond indicators of compromise toward understanding adversary behaviour and operational intent. It then examines attribution under deception, where an adversary may alter delivery mechanisms, infrastructure, or superficial behavioural cues while preserving deeper exploitation techniques, causing attribution models to confuse the actor’s “costume” with the actor itself. The third challenge turns to military IoT environments, where power- consumption traces, opcodes, and network traffic can be fused into robust representations that remain resilient even when attackers inject junk code or manipulate individual evidence streams. The fourth challenge examines targeted adversarial attacks, including manipulated licence plates that bypass recognition systems and malware variants designed to evade CNN, KNN, and other AI-based detectors. The final challenge escalates to state-grade attacks on LLM-enabled systems, where persuasive prompts, automated jailbreak discovery, agent compromise, and runtime manipulation turn the model itself into the attack surface. The talk concludes with a critical dilemma for defenders: how to use AI in security operations without allowing AI-enabled systems themselves to become the next battlefield.
Biography
Ali Dehghantanha is a Professor and Canada Research Chair in Cybersecurity and Threat Intelligence at the University of Guelph, where he directs the Canada Cyber Foundry and the Cyber Science Lab. His research focuses on AI security, AI forensics and cyber threat intelligence. He was a Fulbright Canada Visiting Scholar at UC Berkeley in 2026.