When Defense Becomes the Attack: A Hypothesis on Defensive Action Amplification in Autonomous AI Cyber Defense
Abstract
Autonomous cyber defense systems increasingly perform threat detection, decision making, andresponse execution with minimal human intervention. While existing research has primarilyfocused on improving the accuracy, robustness, and efficiency of these systems, comparativelyless attention has been given to the organizational consequences of autonomous defensivedecisions under adversarial influence. This paper introduces the Defensive Action Amplification(DAA) Hypothesis, a conceptual perspective proposing that autonomous defensive actions may,under specific conditions, amplify the operational impact of an otherwise limited cyber attack.Rather than presenting a defensive framework or implementation, the paper develops a theoreticalmodel supported by a review of existing literature, a conceptual decision-making mechanism, andillustrative scenarios involving Security Operations Centers, cloud infrastructures, and criticalinfrastructure environments. The proposed hypothesis complements existing research inadversarial machine learning and AI security by shifting attention from the compromise ofautonomous defenders to the organizational consequences of their autonomous responses. Finally,the paper outlines key research implications and future directions for evaluating, validating, andgoverning increasingly autonomous cyber defense systems.
// Source
Authors: Swethana Reddy Kallam, Udai Sai Kiran Yarlagadda, Mohana Roopa Y