AI & Computingpreprint2026-08-08

When Defense Becomes the Attack: A Hypothesis on Defensive Action Amplification in Autonomous AI Cyber Defense

Open access0 citations

Abstract

Autonomous cyber defense systems increasingly perform threat detection, decision making, andresponse execution with minimal human intervention. While existing research has primarilyfocused on improving the accuracy, robustness, and efficiency of these systems, comparativelyless attention has been given to the organizational consequences of autonomous defensivedecisions under adversarial influence. This paper introduces the Defensive Action Amplification(DAA) Hypothesis, a conceptual perspective proposing that autonomous defensive actions may,under specific conditions, amplify the operational impact of an otherwise limited cyber attack.Rather than presenting a defensive framework or implementation, the paper develops a theoreticalmodel supported by a review of existing literature, a conceptual decision-making mechanism, andillustrative scenarios involving Security Operations Centers, cloud infrastructures, and criticalinfrastructure environments. The proposed hypothesis complements existing research inadversarial machine learning and AI security by shifting attention from the compromise ofautonomous defenders to the organizational consequences of their autonomous responses. Finally,the paper outlines key research implications and future directions for evaluating, validating, andgoverning increasingly autonomous cyber defense systems.

// Source

View paper (DOI)Open access versionOpenAlexZenodo (CERN European Organization for Nuclear Research)Published 2026-08-08

Authors: Swethana Reddy Kallam, Udai Sai Kiran Yarlagadda, Mohana Roopa Y