Part VI: AI in attack and defense

Claims about AI in cybersecurity require separate evidence for attacker assistance, defensive value, and deployment cost.

Claims that AI helps an attacker or defender need a comparison with work performed without that assistance. Chapter 17 separates demonstrated capabilities from evidence of actual attacks. Chapter 18 measures defensive benefit and errors while retaining analyst judgment and service authorization. Chapter 19 compares model and hosting choices for a fixed task, required quality, permissions, and operating budget. A result from one task or deployment does not settle the other comparisons.

Part 6 overview with the retained title 'Assessing AI in Cybersecurity'. Three panels map to current Chapters 17-19. The harmful-activity panel groups separate evidence questions under an 'Evidence ladder' label qualified by the caption, not ranked evidence levels. The defensive panel pairs an analyst with an assistant using security data. The deployment panel compares external, managed, and internal options. Lower strips list evaluation units and risks.
Figure 1: The retained title ‘Part 6: Assessing AI in Cybersecurity’ maps to Part 6, ‘AI in attack and defense’. Panels 17, 18, and 19 correspond to ‘AI-assisted attacks’, ‘Evaluating AI for defense’, and ‘Comparing AI deployment options’. The label ‘Evidence ladder’ does not describe a cumulative scale. Demonstrated capability, observed incidents, prevalence, and attribution answer separate questions. Uplift needs a relevant comparison, while prevalence needs a population and denominator. Chapter 18 measures defensive work with analyst judgment and action authority visible. Chapter 19 compares deployments under the same task, permissions, quality target, and adversarial conditions before measuring full operating cost.

Chapters in this part

  • AI-assisted attacks: Different evidence supports capability, observed AI use, prevalence, and measured improvement, guiding controls for verified attack paths.
  • Evaluating AI for defense: A defensive AI assessment measures useful security work while keeping human judgment, data access, and action authority visible.
  • Comparing AI deployment options: A deployment comparison holds task, data access, quality target, and action limits constant, then measures results and full operating cost for each option.