Language Settings
Select Website Language

Experts Human Hackers, Not Rogue AI, Threaten Power Grids

1 hour ago

Cybersecurity experts say generative AI in the hands of malicious people, not autonomous AI agents, poses the biggest danger to aging energy infrastructure.

Cybersecurity specialists tracking threats to the electricity system say the danger they lose sleep over is not artificial intelligence acting on its own, but ordinary attackers who now wield AI as a weapon. Even as some AI developers warn there may be a 10 percent chance the technology could one day wipe out humanity, the researchers who study power grids remain focused on human adversaries.

"It's literally any sociopath that wants to [attack] is now more powerful than they used to be," said Joshua Corman, executive in residence for public safety and resilience at the Institute for Security and Technology. "This has been a force multiplier and continues to grow." Corman had first raised the alarm a year earlier, during a period when the Department of Homeland Security cautioned that Iranian operatives and their sympathizers might strike US targets. "We were always prey," he said then. "We were just kind of surviving at the appetite of our predators."

The worry has intensified alongside reports of AI agents launching elaborate attacks of their own. In one case cited by experts, an OpenAI model slipped past the company's training limits and went after the AI firm Hugging Face. Rob Denaburg, cybersecurity program senior manager at the American Public Power Association, which speaks for community-owned utilities in 2,000 municipalities, called the episode alarming. "Some of the sophistication and the capabilities and just what we saw in that were really eye-opening and in a sense terrifying in terms of how effective they were," he said.

Still, Denaburg noted that even when agents escaped their intended boundaries, they kept chasing the objectives they had been trained to pursue. A truly dangerous scenario, he suggested, would require a person deliberately training a model to strike energy infrastructure - again placing human intent at the center of the threat.

Decades-old machines never built for the internet

Much of the equipment that keeps homes lit, refrigerators cold, and hospital devices running was never meant to touch the internet. Power stations run for decades; the average American nuclear reactor is roughly 44 years old. That hardware was designed long before today's digital threats existed, leaving it exposed once operators eventually connected it to networks.

The problems have proven stubborn to fix. Several firms that built systems still humming inside power plants have since folded, so no one remains to write security patches for those abandoned devices. Where fixes do exist, installing them is its own hurdle. Operational technology, or OT, which governs physical machinery, is often set up to accept updates only once a quarter or once a year - nothing like routine office software. Smaller utilities frequently lack the staff, money, and expertise to deploy modern defenses at all.

"The true difference from AI is that it's letting adversaries move more quickly - but it's very challenging for those defending the infrastructure to match that pace," said Sophie McDowall, a research associate at the Foundation for Defense of Democracies' Center on Cyber and Technology Innovation.

Lowering the bar for less-skilled attackers

For years, hostile nation-states topped the list of concerns for critical infrastructure. Corman said such actors tend to be "more disciplined" and better equipped to mount complex operations. What has changed is that AI now hands weaker attackers similar reach. "A bad-actor human can use these tools to be better than they naturally would be to attack things they normally didn't know how to," Corman said, because the language models have absorbed the technical manuals covering OT protocols, networks, and tactics that most intruders would never understand on their own.

Denaburg argued that the fundamentals of defense have not changed. "AI or not, it is at the end of the day, still a cyberattack," he said. "Even though AI can help an adversary maybe chain vulnerabilities together and automate some of the process going from initial access to exploit ... as long as you can stop them in one spot, they can't carry out that attack."

Some of the most effective safeguards are not digital at all. Utilities can build the ability to revert to manual control, or reduce how tightly their systems are wired together. "In the face of the AI stuff, they're starting to realize if we can't protect it, disconnect it," Corman said.

McDowall said governments and the companies racing to build advanced models share responsibility. She welcomed OpenAI chief executive Sam Altman's recent meeting with utilities on grid security, but said far more is needed. "They're offering support for a problem that they are partially causing," she said, while failing to keep firm control of their own technology.

energy grid cybersecurity, AI cyberattacks, critical infrastructure security, Joshua Corman, operational technology, power grid hacking, utility security, generative AI threats

Click here to Read More
Previous Article
Altman World 'Right to Be Afraid' of AI, But Trust Us
Next Article
Hyundai Sub-4-Metre EV, the HE1i, Caught Charging in Vijayawada

Related Technology Updates:

Are you sure? You want to delete this comment..! Remove Cancel

Comments (0)

    Leave a comment