Machine learning applied to defence and attack.
WHAT IT IS USED FOR DEFENSIVELY
Detecting anomalous behaviour Classifying malware Prioritising alerts Detecting phishing Summarising incidents for analysts
WHAT IT DOES WELL
Finding patterns across volumes no human could examine.
WHAT IT DOES POORLY
Explaining why Handling situations unlike its training data Resisting deliberate manipulation
WHAT ADVERSARIAL MANIPULATION MEANS
Crafting input specifically to evade a model.
WHY THAT MATTERS MORE HERE THAN ELSEWHERE
Your adversary is actively trying to defeat the system.
WHAT THAT REQUIRES
Defence in depth, never relying on a model alone Continuous retraining Monitoring for evasion
WHAT ATTACKERS USE IT FOR
Generating convincing phishing at scale, in any language Voice and video impersonation Discovering vulnerabilities Automating reconnaissance
WHAT THAT MEANS PRACTICALLY
Poor grammar no longer identifies a fraudulent message, and voice no longer confirms identity.
WHAT DEFENDS AGAINST THOSE
Verification through independent channels Process controls that do not depend on recognising a person Phishing-resistant authentication
WHAT TO TELL USERS
That confidence and fluency are no longer evidence of legitimacy.