[{"data":1,"prerenderedAt":17},["ShallowReactive",2],{"$f1mOa9wmOsn6-WmrldCL_ZwjkQC-Z7WC1IqlKemkpxGo":3},{"slug":4,"title":5,"excerpt":6,"html":7,"publishedAt":8,"updatedAt":9,"author":10,"tags":11,"featureImage":14,"readingTime":15,"canonical":16},"do-we-use-ai-to-defend-from-ai","Do we use AI to defend from AI?","AI-assisted attacks are not yet being uniquely defended by AI-aware systems. Most defensive tools using AI are blind to whether the adversary used AI at…","\n\u003C!--kg-card-begin: html-->\n\u003Cdiv id=\"elevenlabs-audionative-widget\" data-height=\"90\" data-width=\"100%\" data-frameborder=\"no\" data-scrolling=\"no\" data-publicuserid=\"ae3cda78c4a99172f99dbfb050207098d88a71401457ade2c9f5329e0b9185ed\" data-playerurl=\"https://elevenlabs.io/player/index.html\" >\u003C/div>\u003Cscript src=\"https://elevenlabs.io/player/audioNativeHelper.js\" type=\"text/javascript\">\u003C/script>\n\u003C!--kg-card-end: html-->\n\u003Ch2 id=\"introduction-the-marketing-mismatch\">\u003Cstrong>Introduction: The Marketing Mismatch\u003C/strong>\u003C/h2>\u003Cp>In today’s cybersecurity landscape, it’s common to see AI-powered attacks and AI-powered defenses packaged together as two sides of the same coin. Vendors frame this as an “AI arms race”—as if every threat is matched by a purpose-built AI shield.\u003C/p>\u003Cp>But the reality is more nuanced—and less symmetrical.\u003C/p>\u003Cp>AI-assisted attacks are not yet being uniquely defended by AI-aware systems. Most defensive tools using AI are blind to whether the adversary used AI at all. So what’s really happening beneath the surface?\u003C/p>\u003Cp>Let’s take a closer look at how AI is being used—on both sides of the battlefield.\u003C/p>\u003Ch2 id=\"what-ai-is-being-used-for-in-attacks\">\u003Cstrong>What AI Is Being Used for in Attacks\u003C/strong>\u003C/h2>\u003Cp>AI is giving attackers new advantages in \u003Cem>scale\u003C/em>, \u003Cem>deception\u003C/em>, and \u003Cem>adaptability\u003C/em>. These tools aren’t breaching systems by exploiting flaws in AI—they’re exploiting flaws in people and processes.\u003C/p>\u003Cp>\u003Cstrong>Key characteristics:\u003C/strong>\u003C/p>\u003Cul>\u003Cli>\u003Cstrong>Offensive by design\u003C/strong>: Built using generative or predictive models to deceive or evade.\u003C/li>\u003Cli>\u003Cstrong>Examples\u003C/strong>:\u003Cul>\u003Cli>Deepfake voice and video to impersonate trusted individuals\u003C/li>\u003Cli>AI-generated phishing emails crafted for persuasion and personalization\u003C/li>\u003Cli>Polymorphic malware that evolves beyond static signatures\u003C/li>\u003Cli>LLM-driven reconnaissance and social engineering\u003C/li>\u003C/ul>\u003C/li>\u003Cli>\u003Cstrong>What they exploit\u003C/strong>: Human trust, system access controls, content filters—not AI weaknesses\u003C/li>\u003C/ul>\u003Cp>These threats leverage AI not for sophistication in code, but for sophistication in \u003Cem>interaction\u003C/em>—making them faster, more scalable, and harder to distinguish from legitimate behavior.\u003C/p>\u003Ch2 id=\"what-ai-is-being-used-for-in-defense\">\u003Cstrong>What AI Is Being Used for in Defense\u003C/strong>\u003C/h2>\u003Cp>Defensive AI is largely focused on making internal operations more efficient. It enhances detection and triage, but it does not fundamentally “recognize” whether an attack itself is AI-generated.\u003C/p>\u003Cp>\u003Cstrong>Key characteristics:\u003C/strong>\u003C/p>\u003Cul>\u003Cli>\u003Cstrong>Defensive by design\u003C/strong>: Built to automate detection, modeling, and triage workflows\u003C/li>\u003Cli>\u003Cstrong>Examples\u003C/strong>:\u003Cul>\u003Cli>EDRs using ML to baseline behavior and detect anomalies\u003C/li>\u003Cli>LLMs summarizing and clustering alert data for faster analyst review\u003C/li>\u003Cli>Automated workflows in SOC platforms for initial triage\u003C/li>\u003C/ul>\u003C/li>\u003Cli>\u003Cstrong>What they enhance\u003C/strong>: Speed, scale, and correlation—not specific AI-attribution\u003C/li>\u003C/ul>\u003Cp>In other words, these tools make the defenders more efficient—but they’re not necessarily fighting AI with AI. They are \u003Cem>process accelerators\u003C/em>, not \u003Cem>AI adversaries\u003C/em>.\u003C/p>\u003Ch2 id=\"no-symmetric-arms-race%E2%80%94yet\">\u003Cstrong>No Symmetric Arms Race—Yet\u003C/strong>\u003C/h2>\u003Cp>Despite what some narratives suggest, there’s no strong evidence that AI defense is evolving \u003Cem>in direct response\u003C/em> to AI threats.\u003C/p>\u003Cp>Instead, both sides are moving in parallel—but independently.\u003C/p>\u003Cul>\u003Cli>\u003Cstrong>Attackers\u003C/strong> use AI to boost existing techniques (e.g., phishing, malware obfuscation)\u003C/li>\u003Cli>\u003Cstrong>Defenders\u003C/strong> use AI to streamline workflows and detection pipelines\u003C/li>\u003C/ul>\u003Cp>For example, a phishing email generated by a language model might succeed because it’s well-written—not because it bypassed an AI detector. Meanwhile, the AI-powered defense might catch it \u003Cem>incidentally\u003C/em> based on pattern analysis or keyword flags.\u003C/p>\u003Cp>Most current defenses are still tuned for traditional detection models. They don’t recognize “this is AI-generated.” That attribution layer doesn’t yet exist in a meaningful way.\u003C/p>\u003Cdiv class=\"kg-card kg-signup-card kg-width-wide \" data-lexical-signup-form=\"\" style=\"background-color: #F0F0F0; display: none;\">\n            \n            \u003Cdiv class=\"kg-signup-card-content\">\n                \n                \u003Cdiv class=\"kg-signup-card-text \">\n                    \u003Ch2 class=\"kg-signup-card-heading\" style=\"color: #000000;\">\u003Cspan style=\"white-space: pre-wrap;\">Sign up for Fluency Security\u003C/span>\u003C/h2>\n                    \u003Cp class=\"kg-signup-card-subheading\" style=\"color: #000000;\">\u003Cspan style=\"white-space: pre-wrap;\">News, research, and insights from Fluency — the cybersecurity platform redefining real-time detection and AI-driven analysis.\u003C/span>\u003C/p>\n                    \n        \u003Cform class=\"kg-signup-card-form\" data-members-form=\"signup\">\n            \n            \u003Cdiv class=\"kg-signup-card-fields\">\n                \u003Cinput class=\"kg-signup-card-input\" id=\"email\" data-members-email=\"\" type=\"email\" required=\"true\" placeholder=\"Your email\">\n                \u003Cbutton class=\"kg-signup-card-button kg-style-accent\" style=\"color: #FFFFFF;\" type=\"submit\">\n                    \u003Cspan class=\"kg-signup-card-button-default\">Subscribe\u003C/span>\n                    \u003Cspan class=\"kg-signup-card-button-loading\">\u003Csvg xmlns=\"http://www.w3.org/2000/svg\" height=\"24\" width=\"24\" viewBox=\"0 0 24 24\">\n        \u003Cg stroke-linecap=\"round\" stroke-width=\"2\" fill=\"currentColor\" stroke=\"none\" stroke-linejoin=\"round\" class=\"nc-icon-wrapper\">\n            \u003Cg class=\"nc-loop-dots-4-24-icon-o\">\n                \u003Ccircle cx=\"4\" cy=\"12\" r=\"3\">\u003C/circle>\n                \u003Ccircle cx=\"12\" cy=\"12\" r=\"3\">\u003C/circle>\n                \u003Ccircle cx=\"20\" cy=\"12\" r=\"3\">\u003C/circle>\n            \u003C/g>\n            \u003Cstyle data-cap=\"butt\">\n                .nc-loop-dots-4-24-icon-o{--animation-duration:0.8s}\n                .nc-loop-dots-4-24-icon-o *{opacity:.4;transform:scale(.75);animation:nc-loop-dots-4-anim var(--animation-duration) infinite}\n                .nc-loop-dots-4-24-icon-o :nth-child(1){transform-origin:4px 12px;animation-delay:-.3s;animation-delay:calc(var(--animation-duration)/-2.666)}\n                .nc-loop-dots-4-24-icon-o :nth-child(2){transform-origin:12px 12px;animation-delay:-.15s;animation-delay:calc(var(--animation-duration)/-5.333)}\n                .nc-loop-dots-4-24-icon-o :nth-child(3){transform-origin:20px 12px}\n                @keyframes nc-loop-dots-4-anim{0%,100%{opacity:.4;transform:scale(.75)}50%{opacity:1;transform:scale(1)}}\n            \u003C/style>\n        \u003C/g>\n    \u003C/svg>\u003C/span>\n                \u003C/button>\n            \u003C/div>\n            \u003Cdiv class=\"kg-signup-card-success\" style=\"color: #000000;\">\n                Email sent! Check your inbox to complete your signup.\n            \u003C/div>\n            \u003Cdiv class=\"kg-signup-card-error\" style=\"color: #000000;\" data-members-error=\"\">\u003C/div>\n        \u003C/form>\n        \n                    \u003Cp class=\"kg-signup-card-disclaimer\" style=\"color: #000000;\">\u003Cspan style=\"white-space: pre-wrap;\">No spam. Unsubscribe anytime.\u003C/span>\u003C/p>\n                \u003C/div>\n            \u003C/div>\n        \u003C/div>","2025-08-26T09:03:32.000-04:00","2025-08-26T09:03:36.000-04:00","Chris Jordan",[12,13],"AI","Cybersecurity","https://storage.ghost.io/c/40/d4/40d450c8-df95-4dae-b590-5f6312e7dcb7/content/images/2025/08/offenceVdefense.png",2,"https://fluencysecurity.com/blog/do-we-use-ai-to-defend-from-ai/",1787330593735]