AI Is Rewriting Cybersecurity's Rules

Georgia Institute of Technology

Top 3 Takeaways

  • AI is accelerating cyberattacks.
  • The same technology can strengthen defenses.
  • The biggest risk is falling behind.

Artificial intelligence is changing cybersecurity on both sides of the battlefield. The technology helping organizations improve efficiency also enables cybercriminals to identify vulnerabilities, develop exploits, and launch attacks at unprecedented speed.

Researchers in the School of Cybersecurity and Privacy (SCP) say the greatest concern is not that AI is creating entirely new forms of cyberattacks. Instead, it is accelerating activities that attackers already perform, making existing threats quicker, cheaper, and harder to stop.

"AI is dramatically speeding up cyberattacks," said Brendan Saltaformaggio, associate professor in the SCP and the School of Electrical and Computer Engineering (ECE). "AI can identify vulnerabilities far faster than humans and often in places humans wouldn't think to look."

Hackers Are Moving Faster

Most cyberattacks include several stages: finding vulnerabilities, developing ways to exploit them, gaining access to systems, and pursuing a goal such as stealing information or disrupting operations. According to Frank Li, associate professor in the SCP and ECE, AI is having its biggest impact on the early phases of that process.

"AI can help attackers explore potential decisions and implement attacks faster than in the past, whether it's identifying software bugs or constructing social engineering hooks," Li said.

The pace of attacks has already changed dramatically. Peter Swire, J.Z. Liang Chair in the SCP and professor of law and ethics in the Scheller College of Business, says attackers are moving from vulnerability discovery to exploitation much faster than in the past.

"The average time until an exploit is detected even a couple of years ago was measured in months," Swire said. "Now it is measured in hours."

That compressed timeline is forcing organizations to rethink how quickly they identify, prioritize, and patch vulnerabilities.

The Risk Reaches Everyone

Healthcare systems, critical infrastructure providers, government agencies, and small businesses remain attractive targets because they often manage sensitive information or essential services while relying on legacy technology. But experts emphasize that no organization is immune.

"Unfortunately, everyone is at risk," Saltaformaggio said. "AI is not creating new victims; AI is making attackers faster and more effective at targeting the same organizations they have always pursued."

Organizations with outdated systems or limited cybersecurity resources face particular challenges because AI allows attackers to identify weaknesses in less time and at lower cost than ever before.

Fighting AI With AI

Cybersecurity defenders also have access to the same technology.

Experts say AI can strengthen defenses before, during, and after a cyberattack. Defenders can use AI to identify and patch vulnerabilities more quickly, reducing opportunities for attackers to gain access. AI can also detect subtle signs of intrusion by correlating activity across networks and recognizing patterns that would be difficult for humans to spot in real time.

Once an attack occurs, AI can support rapid investigation and response by analyzing how the compromise happened, identifying root causes, and helping deploy targeted protections.

"AI can help defenders in every step of stopping a cyberattack," Saltaformaggio said.

Researchers at Georgia Tech are already demonstrating AI's defensive potential. Saltaformaggio pointed to Georgia Tech's recent success in the Defense Advanced Research Projects Agency's (DARPA) Artificial Intelligence Cyber Challenge, which highlighted how AI systems can autonomously discover and reason about software vulnerabilities at large scale. Swire also noted that a Georgia Tech team led by Professor Taesoo Kim won a $4 million DARPA prize for developing advanced AI-based cybersecurity defenses.

Speed Is the New Defense

Despite the promise of AI-powered security, significant challenges remain. Security teams need AI tools they can trust, ones that explain how they reached conclusions and provide evidence that analysts can verify. Attackers may also attempt to manipulate AI systems, creating new risks for organizations that rely heavily on automated tools.

Li says organizations cannot rely on traditional, human-paced security processes to keep up.

"AI's primary impact on cyberattacks is enhancing speed and scale," Li said. "Organizations need to adapt to more agile defenses and processes that account for this, in many cases relying on AI as well to help speed up defensive actions."

Organizations also need to rethink how they respond to vulnerabilities. Swire argues that traditional patch management is no longer fast enough in a world where exploits can emerge within hours.

"The entire process for patching systems will have to be re-engineered," he said.

The cybersecurity landscape has always been an arms race between attackers and defenders. AI hasn't changed that reality. It has simply accelerated it. The organizations that will be best positioned are those that adopt AI as quickly as the adversaries they are trying to stop.

/Public Release. This material from the originating organization/author(s) might be of the point-in-time nature, and edited for clarity, style and length. Mirage.News does not take institutional positions or sides, and all views, positions, and conclusions expressed herein are solely those of the author(s).View in full here.