MIT AI Risk Repository · Risk Sub-Category · 47.02.02
Malicious use and abuse (cyberattacks)
Category: Ethical and social risks
Description
"Generative AI can help amplify the frequency and destructiveness of cyberattacks.311 It has the capacity “to increase the accessibility, success rate, scale, speed, stealth, and potency of cyberattacks. It enables the identification of critical vulnerabilities within targeted systems, facilitates the increase of the scale of cyberattacks, and accelerates the process by discovering innovative methods of system infiltration. Cyberattacks can inflict significant damage and may impact critical infrastructure, including electrical grids, financial systems, and weapons management systems."
From Regulating under Uncertainty: Governance Options for Generative AI (G'sell2024), as extracted by the MIT AI Risk Repository (CC BY 4.0).
Classification
- Domain
- 4. Malicious actors
- Causal entity
- Human
- Intent
- Intentional
- Timing
- Post-deployment
Subdomain definition: Using AI systems to develop cyber weapons (e.g., coding cheaper, more effective malware), develop new or enhance existing weapons (e.g., Lethal Autonomous Weapons or CBRNE), or use weapons to cause mass harm.
Real-world incidents in this subdomain
- Anthropic's Claude Was Reportedly Jailbroken To Allegedly Help Steal Sensitive Mexican Government Data
- OpenAI ChatGPT Models Reportedly Jailbroken to Provide Chemical, Biological, and Nuclear Weapons Instructions
- Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales
- LAMEHUG Malware Reportedly Integrates Large Language Model for Real-Time Command Generation in a Purported APT28-Linked Cyberattack
- Reported AI-Aided Development of Explosive Devices by Long Island Resident Michael Gann
- AI Chatbot Allegedly Used to Research Explosive Materials in Palm Springs Fertility Clinic Bombing
How other frameworks describe this risk
Other entries from G'sell2024
- Technical and operational risks
- Technical vulnerabilities (Robustness - unexpected behaviour)
- Technical vulnerabilities (Robustness - unexpected behaviour)
- Technical vulnerabilities (Robustness - vulnerability to jailbreaking
- Technical vulnerabilities (Robustness - vulnerability to jailbreaking
- Technical vulnerabilities (The risk of misalignment)
- Technical vulnerabilities (The risk of misalignment)
- Factually incorrect content (inaccuracies and fabricated sources)
- Factually incorrect content (inaccuracies and fabricated sources)
- Opacity (the black box problem)
- Opacity (industry opacity)
- Opacity (industry opacity)