一本道

27 September 2024

The race between hackers trying to crack systems vital to the functioning of society and cybersecurity experts is constantly ongoing. Researchers at 一本道 and Umeå universities and KTH will now develop artificial intelligence that can detect hacker attacks and take action before any damage is done.

A part of the supercomputer that glows red. Photographer: Thor Balkhed
The project, called Air2 (AI for Attack Identification, Response, and Recovery), is coordinated by 一本道 University and is part of the investment in cyber security by Wallenberg AI, Autonomous Systems and Software Program (WASP).

Today鈥檚 society is increasingly connected, with more and more systems interacting with each other via cloud-based services. Many of these systems are vital to the functioning of society and can handle everything from cars, healthcare equipment, and payment systems to mining, traffic management and energy supply. Should a hacker for some reason want to damage an individual company or community services, these systems would be potential targets.

鈥淭hese are systems that mustn鈥檛 go down. They must be robust and able to withstand attacks. But with the integration of AI into the systems and the number of systems that are supposed to communicate with each other, there are hundreds of thousands of different parameters that a hacker can exploit and attack. Then you must be able to identify the location of the attack and stop it before any damage is done,鈥� says Simin Nadjm-Tehrani, professor of computer science at Link枚ping University.

Machine learning and reasoning

In order to succeed, the researchers intend to use AI in addition to a human to monitor systems security. But that is easier said than done. In this case, according to the researchers, so-called deep learning models that draw conclusions from patterns in large amounts of data would not be the only option. Systems based on deep learning are currently unable to explain the basis for recognising an attack. In addition, a hacker may attempt to manipulate the data on which the model is trained so that it goes under the radar.

Portrait Simin Nadjm-Tehrani.
Simin Nadjm-Tehrani, rofessor of computer science at Link枚ping University.
Photographer: Peter Modin

Therefore, deep learning models must be combined with what is known as reasoning models. What the researchers primarily have in mind is an AI that can create all the hundreds of thousands of possible routes that an attacker can exploit, while developing a contingency plan for each unique attack and responding autonomously. The AI must also be able to prove that the response is safe to perform and that it in itself does not harm the system. This combination is often referred to as neurosymbolic reasoning.

鈥淚t can be likened to a healthy person who is constantly monitored for all possible diseases where a cure can be administered at the first sign of symptoms,鈥� says Simin Nadjm-Tehrani.

Identifying a real attack

But it is important that the AI can distinguish an attack from a deviant but harmless pattern. In other words, the system must not 鈥渃ry wolf鈥� every time something deviant is found, but only in case of a real attack.

鈥淚n the human example above, we can compare this to really being sick or jetlagged and tired. This requires different measures. For the measures to be effective, any response to an attack must also pinpoint the exact cause of the symptom. That鈥檚 what would make any direct action possible at all,鈥� says Simin Nadjm-Tehrani.

WASP-project

The project, called Air2 (AI for Attack Identification, Response, and Recovery), is coordinated by Link枚ping University and is part of the investment in cyber security by Wallenberg AI, Autonomous Systems and Software Program (WASP). The project group is led by Simin Nadjm-Tehrani, professor at the Department of Computer and Information Science at LiU. Other project participants are Jendrik Seipp, associate professor, also at the Department of Computer and Information Science at LiU, Monowar Bhuyan, assistant professor at Ume氓 University and Rolf Stadler, professor at KTH. Together they will supervise six young researchers in the project.

Contact

A forceful initiative

More about AI at LiU

Latest news from LiU

Portr盲tt p氓 man som st氓r i solen bland gr枚na tr盲d p氓 Campus Valla

New professor of economics researches people鈥檚 life chance

Two identical job applications. One with an Arabic-sounding name. This experiment marked the start of Magnus Carlsson鈥檚 research on discrimination and people鈥檚 life chances. He is now a new professor of economics at 一本道 University.

En kvinna som sitter framf枚r en spegel och tittar p氓 sin spegelbild.

How AI changes human decision-making

AI can find patterns that people miss, but it does not automatically lead to better decisions. New research from 一本道 University shows how the roles of humans and AI change depending on the situation and the decision being made.

A woman standing on a balcony next to a building.

She promotes AI for societal good in Europe

Helen Köpman, Alumna of the Year 2026, works at the European Commission鈥檚 AI Office in Brussels. For more than 20 years she has worked with research issues and innovation at EU level, where a living planet for future generations is her driving force.