top of page
    Search

    Understanding How Vulnerabilities in the Human Condition can be Manipulated by the Threat of the Weaponisation of Artificial Intelligence and Generative Adversarial Networks

    Sep 5
    10 min read
    Understanding How Vulnerabilities in the Human Condition can be Manipulated by the Threat of the Weaponisation of Artificial Intelligence and Generative Adversarial Networks to Develop Solutions in Strengthening Military and Critical Infrastructure Cybersecurity
    Understanding How Vulnerabilities in the Human Condition can be Manipulated by the Threat of the Weaponisation of Artificial Intelligence and Generative Adversarial Networks to Develop Solutions in Strengthening Military and Critical Infrastructure Cybersecurity


    Statement of Interest and Rationale


    I am fascinated how the interplay between human emotions and behaviour, social groups and nations, AI and machine learning poses serious threat to national infrastructure and society. I am motivated to find valuable solutions that will fortify cybersecurity, military defence, and intelligence to protect the public from manipulation of human weaknesses being taken advantage of to benefit malicious cyber actors. 


    I am excited about this research because in order for us to analyse cybersecurity threats and formulate solutions as technology advances, we must understand how humans interact with technology because existing and emerging cyber threats cannot exist without humans interacting on either side of the system. I see that emerging future threats can merge with one another forming hybrid risks but it is humans that present the weaknesses in the system that allow such threats to penetrate. My innate understanding of human emotion and behaviour will help us uncover what vulnerabilities malicious actors prey on that exposes humans to cyber threats and attacks to benefit those manipulating the system at the detriment to humans. I feel that the dangers of false information masquerading as the truth used as cyber weapons is the biggest threat to humans and society.




    Introduction


    Advancing technology leaves individuals, organisations, society, and governments under potential threat of cyber attacks at every level. All kinds of data, finances, and digital identity to name a few are at serious risk of exposure, manipulation, theft and fraud as technology advances faster than at a rate we can identify and formulate solutions to all potential risks. Meanwhile our nation is on high alert for a ‘substantial risk’ of a terrorist attack. A joint alert from the United States Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) and the United Kingdom’s National Cyber Security Centre (NCSC) revealed that the COVID-19 pandemic is being exploited by cybercriminal and advanced persistent threat (APT) groups using social engineering methods taking advantage of human traits such as curiosity and concern via phishing messages to take advantage of victims by acting as ‘trusted entities’. Victims inadvertently download phishing messages/malware/ransomware enabling such malicious cyber actors to conduct espionage, “hack-and-leak” operations or obtain commercial gain. There is much we can learn from the impact COVID-19 has had on society and we must use this to protect us against future pandemics, especially as the WHO have warned us already that ‘this is not the main pandemic’. People and healthcare organisations will become more vulnerable to attack as health data becomes digitalised.


    More so, many countries, have equipped their military with offensive and intelligence-gathering cyber weapons. Information about a country’s defence infrastructure as well as their potential attacks against another nation can be leaked by military hackers stealing classified documents. I have identified the ‘gap’ in our defence against cyber weapons consisting of AI, and Generative Adversarial Networks (GANs) that I aim to contribute to with my research proposal.


    Deepfake technology has been proposed to be the greatest cybersecurity risk that we face. If GANs can be used to produce Deepfake, the potential threat of disruption to humans and society is immense and must be acted on. I feel that right now the Deepfake current threats revolve around audio and visual content such as social media images and videos but the real future risk is the potential to adapt GAN to distort the truth of every format of information material in the future that can manipulate people’s trust to benefit the malicious actor. Deepfake could be extended to conduct financial cyber fraud; spread cyber violence in the form of scams, harassment, distribute malware; digital identity fraud; phishing scams eg. emails, texts in light of Covid-19 and future pandemics; the use of media to frame or manipulate individuals and organisations in the courts of justice; cyber vandalism regarding covert political disinformation and defamation of governments to distort public opinion in propaganda campaigns; the spread of fake news in pandemics. GAN could be used to gain political power from rising terrorist groups to instil the turning of social groups or nations against one another. I feel that in the future it will become increasingly harder for the public to decipher what information is real leading to massive financial consequences for individuals and organisations, and violation of critical infrastructure and the UK’s defence and security systems. I predict that we will need to develop AI to detect the patterns in information utilised in all developing formats constituting future GAN Deepfake production, and detect vulnerabilities in the system and patterns in human cognition, emotion and behaviour that could be open to manipulation. Such algorithms can be used to safeguard the public, organisations and our future national defence and security.


    Machine learning and Deepfake capabilities are becoming steadily more accessible and there are ways of making it more cost effective such as using a cloud server to host GANs that anyone will eventually be able to utilise this. Facebook and Microsoft have AI algorithms to detect a large proportion of AI-manipulated audio-visual content, yet there are hardly any tools for the general public to harness this. If this technology can be harnessed by anyone then this could be seriously damaging in the hands of other great powers which could threaten UK national interests by affecting foreign affairs, national security and the national economy by sabotaging trade deals. The Council on Foreign Relations quote that “the best defence against deep fakes would be.. highly credible alibis” regarding where people eg. Political figures, have been and what they have said and life-logging services vs. encouraging the public to become skeptical of media. I feel this is not realistic as it impedes privacy enforcing heightened surveillance and even an alibi could be manipulated via Deepfake. Plus the public could become skeptical of what lies the truth. Another problem lies in evolving techniques like Style transfer or ‘StyleGAN’ which transfers characteristics of one individual to another, to make a new unique, synthetic image. This can be used to create authentic online personas making online social media campaigns believable and credible giving the impression they are led by genuine people. This will make it increasingly hard for existing AI algorithms to detect such content as a Deepfake. StyleGan techniques could be extended for use outside of social media such as telecommunications between organisations, in healthcare and anything constituting national defence and security. I would like to research what information malicious actors choose to formulate Deepfakes and how we can develop blockchain and private keys to authenticate information. This can be extended to protecting sensitive military information on a decentralised blockchain system.


    There are no international boundaries for malicious cyber actors to use offensive cyber weapons Cyber criminals are going for higher value pay-outs from UK citizens, organisations and institutions. Terrorists can carry out low low-level cyber attacks but the risk is they will carry out more significant acts.


    Cyber crimes are based on:

    • Cyber-dependent crimes - use of IT eg. Malware, developing and propagating malware for financial gain, hacking to steal, damage, distort or destroy data and/or network (or activity)


    • Cyber-enabled crimes - larger scale targeting networks, IT systems eg. Fraud, data theft


    But I have researched that these cyber crimes could be extended to use cyberweapons that involve the development of GANs to produce Deepfake material that can manipulate human emotion and behaviour to then drive human decision making that allows these these weapons to penetrate the cyber space.


    The most serious cyber crime against the UK like fraud, theft and extortion comes from financially motivated Russian-language organised criminal groups (OCGs) in Eastern Europe.

    Cyber Threats can exist within the UK. Emerging threats come from South Asia and West Africa.


    It’s hard to prosecute cyber criminals and it becomes ever more difficult if material to be used for this becomes distorted via GANs.


    These OCG attacks are becoming increasingly aggressive and confrontational using ransomware, and threats of distributed denial of service (DDoS) for extortion.



    BIGGEST WORLDWIDE CYBER ATTACKS:


    1. 2013 - breach of 3 billion yahoo accounts

    2. 2021 700 million LINKED IN USERS posted on a dark web forum impacting >90% of its user base.


    1. Eg. October 2015, UK TELECOMMUNICATIONS provider TalkTalk reported a successful cyber attack and a possible breach of customer data. Employees were subject to ransom demand payments in bitcoin. But talk talk’s report and liaise with the police and national crime agency, helped prosecute these cyber criminals


    1. Internet banking fraud rose by 64% to £133.5m in 2015 targeting business and highnet-worth customers

    2. BANKING Malware was installed on the SWIFT system. In 2016 attacker accessed the SWIFT The Society for Worldwide Interbank Financial Telecommunication payment system of the Bangladesh Bank and instructed the New York Federal Reserve bank to transfer money from Bangladesh Bank’s account to accounts in the Philippines. The attempted fraud was US$951 million but still US$101m went through


    1. CRITICAL INFRASTRUCTURE eg. 2015 UKRAINE POWER GRID ATTACK BlackEnergy3 malware enabled the attackers to gather credentials that allowed them to gain direct remote control of aspects of the network


    There are regular cyber attack attempts against the UK by states and state-sponsored groups for political, diplomatic, technological, commercial and strategic advantage + these groups focus on the government, defence, finance, energy and telecommunications sectors.


    The most advanced nations stay covert by integrating encryption and anonymising + They can deploy attacks because of the weak defences of victims.


    RISKS TO THE UK

    • Sophisticated cyber attacks:

    • Cyber espionage

    • Critical national infrastructure and industrial control systems.- And states can get away with this because there are no current international laws.

    • TERRORIST groups - defacements and leaking hacked info, enable terrorist groups and their supporters to attract media attention and intimidate their victims

    • Terrorists can use cyber systems to launch more widescale attacks against the UK for maximum harmful effect.

    • INSIDERS

    • HACKERS


    Insider threats remain a cyber risk to organisations in the UK. Malicious insiders, who are trusted employees of an organisation and have access to critical systems and data, pose the greatest threat. They can cause financial and reputational damage through the theft of sensitive data and intellectual property. They can also pose a destructive cyber threat if they use their privileged knowledge, or access, to facilitate, or launch, an attack to disrupt or degrade critical services on the network of their organisations, or wipe data from the network. - Style GAN is currently being used to create new identities for people in organisations to conduct meetings and give presentations. Style GAN could be used to form malicious insiders acting as such new identities. This can make it harder to identify who the insider is in an organisation making it easier for them to evade the law.

    Individuals in organisations are often the victims of social engineering – they can unwittingly provide access to the networks of their organisation or carry out instructions in good faith that benefit the fraudster




    In most cases, it continues to be the vulnerability of the victim, rather than the ingenuity of the attacker, that is the deciding factor in the success of a cyber attack


    We also need to develop the specialist skills and capabilities that will allow us to keep pace with rapidly evolving technology and manage the associated cyber risks - we can do this by learning what the vulnerabilities are in human emotion and the driving forces behind human decision making that lie open to manipulation by cyber criminals using cyber weapons.



    BIGGEST RISKS TO UK CYBER DEFENCE.


    1. Cyber security is vital to our defence. Our Armed Forces depend on information and communications systems, both in the UK and on operations around the world. The infrastructure and personnel of the Ministry of Defence (MoD) are prominent targets. Defence systems are regularly targeted by criminals, foreign intelligence services and other malicious actors seeking to exploit personnel, disrupt business and operations, and corrupt and steal information. We will enhance cyber threat awareness, detection, and reaction functions, through the development of a Cyber Security Operations Centre (CSOC) that uses state-of-the-art defensive cyber capabilities to protect the MoD’s cyberspace and deal with threats.


    1. Cyber attack on certain private or public sectors which would have the severest impact on the country’s national security. Affecting the lives of UK citizens, the stability and strength of the UK economy, or the UK’s international standing and reputation. 


    2. Critical national infrastructure (CNI), which provides essential services to the nation. 

      CNI include:

      UK’s most successful companies that hold our future economic strength in the value of their research and intellectual property; 

      Data holders – on the public inc vulnerable people; 

      Media organisations, where an attack could harm the UK’s reputation, damage public confidence in the Government, or endanger freedom of expression;

      Digital service providers that enable e-commerce + digital economy, and who depend on consumer trust in their services; 

      Those organisations that influence the whole economy to improve their cyber security, such as insurers, investors, regulators and professional advisors. 


    Problems - hard to keep track of businesses and organisations failing to take the right steps to protect themselves against cyber threats.



    What do we have in place?

    • Government’s Cyber Essentials scheme

    • The Cyber Essentials scheme was developed to show organisations how to protect themselves against low-level “commodity threat”. It lists five technical controls (access control; boundary firewalls and Internet gateways; malware protection; patch management and secure configuration) that organisations should have in place. The vast majority of cyber attacks use relatively simple methods which exploit basic vulnerabilities in software and computer systems that can be done by even low ability cyber actors.

    • Cyber Aware campaign targets the public eg. Educating them on how to construct good passwords


    The government is at the centre at defending the country and national Critical infrastructure against sophisticated emerging cyber threats and must define what good cybersecurity looks like.

    Technological advances = benefits aiding human decision making VS. biggest threat to humans to cause harm to individuals, businesses, organisations and the UK’s defence systems BECAUSE human decision making is open to manipulation.


    Cyber threats are continually evolving at a rapid rate but these threats can not exist without humans being at the interface, whether they be the malicious cyber actor/cyber criminal VS. cyber victim. 


    To understand and mitigate cyber threats and fortify the UK’s defence and security and national critical infrastructure we need to understand how and why vulnerabilities in the human condition eg. Emotion, cognition and behaviour drive human decision making that allows these cyber threats to PENETRATE cyber systems and CAUSE HARM. 



    Bibliography


    United Nations Office of Counter-Terrorism (UNOCT), 2021. COUNTERING TERRORISM ONLINE WITH ARTIFICIAL INTELLIGENCE An Overview for Law Enforcement and Counter-Terrorism Agencies in South Asia and South-East Asia A Joint Report by UNICRI and UNCCT


    C. Satapathy. (2000). Impact of Cyber Vandalism on the Internet. Economic and Political Weekly, 35(13), 1059-1061. Retrieved August 26, 2021, from http://www.jstor.org/stable/4409073


    Guihua Tang, Lei Sun, Xiuqing Mao, Song Guo, Hongmeng Zhang, Xiaoqin Wang, "Detection of GAN-Synthesized Image Based on Discrete Wavelet Transform", Security and Communication Networks, vol. 2021, Article ID 5511435, 10 pages, 2021. https://doi.org/10.1155/2021/5511435


    Tim Hwang, Center for Security and Emerging Technology. Deepfakes A Grounded Threat Assessment, JULY 2020. doi: 10.51593/20190030. https://cset.georgetown.edu/wp-content/uploads/CSET-Deepfakes-Report.pdf



    Deloitte. COVID-19: The impact of cyber on critical infrastructure in the next normal


    Cybersecurity and Infrastructure Security Agency. COVID-19 Exploited by Malicious Cyber Actors. April 08 2020.


    ITPRO. Jane Macallion 5 Aug 2021 What is cyber warfare?



    By DR KATY WIN

    ADAPTED SOUTHAMPTON SECURITY & DEFENCE PhD RESEARCH PROPOSAL CREATED SEPT 2021

    PUBLISHED ONLINE 5TH SEPT 2026 @19:29


     
     
     

    Comments


    Commenting on this post isn't available anymore. Contact the site owner for more info.

    ©2023 The Mind Skin Coach 

    bottom of page