AI Is Rewriting Cybersecurity's Rules Top 3 Takeaways - AI is accelerating cyberattacks. - The same technology can strengthen defenses. - The biggest risk is falling behind. Artificial intelligence is changing cybersecurity on both sides of the battlefield. The technology helping organizations improve efficiency also enables cybercriminals to identify vulnerabilities, develop exploits, and launch attacks at unprecedented speed. Researchers in the School of Cybersecurity and Privacy (SCP) say the greatest concern is not that AI is creating entirely new forms of cyberattacks. Instead, it is accelerating activities that attackers already perform, making existing threats quicker, cheaper, and harder to stop. "AI is dramatically speeding up cyberattacks," said Brendan Saltaformaggio, associate professor in the SCP and the School of Electrical and Computer Engineering (ECE). "AI can identify vulnerabilities far faster than humans and often in places humans wouldn't think to look." Hackers Are Moving Faster Most cyberattacks include several stages: finding vulnerabilities, developing ways to exploit them, gaining access to systems, and pursuing a goal such as stealing information or disrupting operations. According to Frank Li, associate professor in the SCP and ECE, AI is having its biggest impact on the early phases of that process. "AI can help attackers explore potential decisions and implement attacks faster than in the past, whether it's identifying software bugs or constructing social engineering hooks," Li said. The pace of attacks has already changed dramatically. Peter Swire, J.Z. Liang Chair in the SCP and professor of law and ethics in the Scheller College of Business, says attackers are moving from vulnerability discovery to exploitation much faster than in the past. "The average time until an exploit is detected even a couple of years ago was measured in months," Swire said. "Now it is measured in hours." That compressed timeline is forcing organizations to rethink how