{"id":75301,"date":"2025-08-11T10:11:52","date_gmt":"2025-08-11T17:11:52","guid":{"rendered":"https:\/\/in.nau.edu\/news\/?p=75301"},"modified":"2025-08-11T10:11:52","modified_gmt":"2025-08-11T17:11:52","slug":"zhang-cybersecurity","status":"publish","type":"post","link":"https:\/\/in.nau.edu\/news\/zhang-cybersecurity\/","title":{"rendered":"How AI helps\u2014and hurts\u2014cybersecurity"},"content":{"rendered":"<p>When it comes to cybersecurity, AI is a double-edged sword.<\/p>\n<p>On one hand, it can be used to find weak points and identify bugs, especially if it is well-trained. On the other, not only can it miss errors, it can be weaponized or tricked by bad actors.<\/p>\n<p>Research led by <strong>Lan Zhang<\/strong>, an assistant professor in the School of Informatics, Computing, and Cyber Systems at Northern Arizona University, is examining the various roles AI plays in cybersecurity. Her team\u2019s work ranges from how to leverage AI to enhance cybersecurity, AI\u2019s impact on everyday users and the security risks that come with using AI, and she recently received a grant from the National Science Foundation to study adversarial malware can trick artificial intelligence.<\/p>\n<p>\u201cAI shows promise in enhancing cybersecurity by modeling complex threats and identifying vulnerabilities, but real-world effectiveness depends on precise problem definitions, quality data, human oversight and addressing security risks like adversarial attacks, membership inference attacks and poisoning attacks,\u201d Zhang said.<\/p>\n<h3><strong>Enhancing cybersecurity through AI<\/strong><\/h3>\n<p>Researchers have had success adopting mathematical formulas of cybersecurity challenging and then using AI to solve those formulas. Zhang said that in lateral movement attacks, which enable attackers to move through a compromised network after gaining initial access, researchers can model a network as a graph. AI has shown strong potential for detection and defense in these instances.<\/p>\n<p>That\u2019s research, though, not a real attack. Large language models (LLMs) can successfully identify and fix bugs in programs with fewer than 100 lines of code, but as the database gets larger, the LLM has to be taught with much greater specificity. Human oversight is essential.<\/p>\n<p>\u201cReal-world environments are far more complex than controlled scenarios,\u201d Zhang said. \u201cEffective deployment of AI in practice requires more precise problem formulations and algorithms tailored to specific challenges. AI is not a magic solution\u2014it depends on the availability of high-quality training data, well-scoped problem definitions and effective learning methodologies.\u201d<\/p>\n<h3><strong>AI in your daily life<\/strong><\/h3>\n<p>Long before ChatGPT, most of us interacted with AI somewhat regularly\u2014talking to Siri and Alexa, using our faces to unlock our smartphones, autopilot in cars. They\u2019re valuable but also pose security risks for users\u2014facial recognition can be fooled, Tesla\u2019s AI can misread altered traffic signals and Siri can be trigged by hidden commands in audio.<\/p>\n<p>\u201cAs reliance on AI grows, so do the risks, making security and robustness critical for protecting everyday users,\u201d Zhang said.<\/p>\n<p>Her research is looking into security gaps coming up as people increasingly rely on LLMs for decision-making and tech support.<\/p>\n<h3><strong>Security risks in AI systems<\/strong><\/h3>\n<p>There are established algorithmic biases in AI, such as racism or sexism in responses, but security challenges extend beyond that.<\/p>\n<p>\u201cBlind spots can be exploited by adversaries and pose real risks to the general public,\u201d Zhang said. \u201cOur current research aims to identify and understand these AI blind spots, with the long-term goal of building more secure, resilient and robust models that can withstand adversarial manipulations.\u201d<\/p>\n<p>There\u2019s also a risk of jailbreaking LLMs, which refers to manipulating the system into bypassing their built-in safety constraints. Zhang said a model like ChatGPT can be \u201ctricked\u201d\u2014it\u2019s prohibited from offering instructions on building explosives, but attackers can embed malicious prompts within innocuous-looking text to trick the LLM into generating prohibited content. Hackers also use this method in conducting cyberattacks.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft  wp-image-56007\" src=\"http:\/\/in.nau.edu\/news\/wordpresst\/uploads\/sites\/153\/wp-content\/uploads\/2019\/06\/NAU_primary-281_3514-300x213.png\" alt=\"Northern Arizona University Logo\" width=\"96\" height=\"68\" srcset=\"https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/402\/2019\/06\/NAU_primary-281_3514-300x213.png 300w, https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/402\/2019\/06\/NAU_primary-281_3514-768x546.png 768w, https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/402\/2019\/06\/NAU_primary-281_3514-600x426.png 600w, https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/402\/2019\/06\/NAU_primary-281_3514.png 905w\" sizes=\"auto, (max-width: 96px) 100vw, 96px\" \/><\/p>\n<p>Heidi Toth | NAU Communications<br \/>\n(928) 523-8737 | <a href=\"mailto:heidi.toth@nau.edu\">heidi.toth@nau.edu<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><a class=\"search-results-excerpt-link\" href=\"https:\/\/in.nau.edu\/news\/zhang-cybersecurity\/\">When it comes to cybersecurity, AI is a double-edged sword. On one hand, it can be used to find weak points and identify bugs, especially if it is well-trained. On the other, not only can it miss errors, it can be weaponized or tricked by bad actors. Research led by Lan Zhang, an assistant professor&hellip;<\/a><\/p>\n","protected":false},"author":59,"featured_media":75304,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[11],"tags":[],"class_list":["post-75301","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-research-academics"],"acf":[],"_links":{"self":[{"href":"https:\/\/in.nau.edu\/news\/wp-json\/wp\/v2\/posts\/75301","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/in.nau.edu\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/in.nau.edu\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/in.nau.edu\/news\/wp-json\/wp\/v2\/users\/59"}],"replies":[{"embeddable":true,"href":"https:\/\/in.nau.edu\/news\/wp-json\/wp\/v2\/comments?post=75301"}],"version-history":[{"count":0,"href":"https:\/\/in.nau.edu\/news\/wp-json\/wp\/v2\/posts\/75301\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/in.nau.edu\/news\/wp-json\/wp\/v2\/media\/75304"}],"wp:attachment":[{"href":"https:\/\/in.nau.edu\/news\/wp-json\/wp\/v2\/media?parent=75301"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/in.nau.edu\/news\/wp-json\/wp\/v2\/categories?post=75301"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/in.nau.edu\/news\/wp-json\/wp\/v2\/tags?post=75301"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}