Pith. sign in

REVIEW 3 major objections 6 minor 1 cited by

The Impact of AI on the Cyber Offense-Defense Balance and the Character of Cyber Conflict

T0 review · 3 major / 6 minor · reviewed 2026-08-16 · deepseek-v4-flash

Pith's one-line read No single answer exists for whether AI will tip cyber conflict toward offense or defense.

desk verdict A useful disaggregated policy synthesis; the mixed conclusion is partly a product of the method, not an empirical discovery, but the framework deserves serious engagement. read the letter →

arxiv 2504.13371 v1 pith:XVY7CLKT submitted 2025-04-17 cs.CR cs.AIcs.CY

classification cs.CRcs.AIcs.CY
keywords AIcyberoffense-defensebalancetheoryconflictdefenseoffenseadvancementlevelsdeterrence
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper asks whether advances in artificial intelligence will shift the cyber offense-defense balance, and answers that the question has no single answer. It collects the main arguments in the literature for why offense or defense has the edge in cyber, adds 48 propositions about what gives cyber conflict its character, and works through how each would change at different levels of AI progress. The result is a list of 44 distinct ways AI could push cyber in conflicting directions, helping some attackers, helping some defenders, and leaving many aspects unchanged. The central result is therefore a map of the terrain, one that makes it possible to see why any blanket claim about an AI-driven tilt is unsupported.

What carries the argument

The load-bearing apparatus is an enumeration, not a theorem. The paper assembles nine arguments for defensive advantage, nine arguments for offensive advantage, and 48 statements from a forthcoming compilation on what gives cyber conflict and competition its character. Each item is then evaluated against five levels of AI advancement (status quo, reliable and independent, expert, hard limits, with limit-breaking treated as out of scope) and against three access scenarios for AI capability (controlled, limited control, proliferated). Those evaluations are grouped into 44 AI-impact pathways across five categories: changes to the digital ecosystem, hardening of digital environments, tactical aspects of digital engagements, incentives and opportunities, and strategic effects on conflict and crisis. The enumeration carries the argument because the argument's content is that these pathways do not point in a common direction.

What would settle it

A structured scoring of the paper's own 44 pathways, assigning each a directional advantage (offense, defense, or neutral) for each AI level and actor type, would show whether the signs actually conflict as claimed. The conclusion would collapse if one mechanism—say, AI that finds previously unknown hard-to-patch vulnerabilities at expert level—could be shown to dominate all countervailing defensive gains across every actor and access scenario. Short of that, the paper's claim predicts that no such uniform mechanism will be found.

Watch

Extended reading notes

Core claim

On the paper's own terms, the central claim is that the cyber offense-defense balance is too multifaceted for a single verdict about AI. The paper does not settle whether offense or defense currently has the advantage, and it does not predict which side AI will favor overall. It asserts that AI will improve some aspects of offense, improve some aspects of defense, hinder others, and leave still others essentially unchanged, with the net comparison depending on threat actor, defender, level of AI advancement, and control of access to AI. That conclusion follows from the enumeration: the nine offensive arguments, nine defensive arguments, and 48 character-of-cyber propositions yield assessments that point in different directions rather than converging.

Load-bearing premise

The load-bearing premise is that the 48 character-of-cyber statements and the 18 offense-defense arguments are the right and sufficiently complete set of questions; the paper takes them as given rather than testing their truth, so a major omission or factual error in that list would propagate through the 44 AI-impact pathways.

Editorial extensions

If this is right

  • Analysts should abandon the single-balance question and instead ask which mechanism, which attacker or defender, and which AI capability level is at issue.
  • Reliable and independent AI that reviews code and configurations would mainly help small organizations and open-source projects, narrowing the current defensive skill gap.
  • Faster vulnerability discovery without corresponding progress in provably secure design would leave defenders behind, because the historical bottleneck is implementing patches, not writing them.
  • Delegating tactical decisions to AI, even reliable AI, increases the variety of attacks defenders face and raises the probability of accidents and collateral damage on both sides.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If the paper's claim is right, the next analytical step is weighting: 44 opposing pathways say nothing about net magnitude, so the framework points to measurement of each pathway before drawing policy conclusions.
  • The paper's level-of-AI structure yields testable conditional forecasts, for example that status-quo AI should mostly harden small targets while expert-level AI should favor offense in vulnerability discovery unless design-time verification catches up.
  • Widely proliferated reliable-and-independent agents would weaken the strategic logic of persistent engagement and prepositioned access, since attackers could generate capabilities on demand instead of preserving them.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 6 minor

Summary. This paper reviews the literature on cyber offense-defense balance and the character of cyber conflict, compiling nine offense-favoring arguments, nine defense-favoring arguments, and forty-eight propositions from a forthcoming paper by Healey, Jervis, and Nandrajog. It then qualitatively assesses how varying levels of AI advancement might strengthen or weaken each item, and aggregates the result into forty-four AI-impact pathways grouped into five thematic areas. The paper's central claim, stated in the abstract and conclusion, is that the cyber domain is too multifaceted for a single answer about whether AI will broadly favor offense or defense: AI will improve some aspects, hinder others, and leave some unchanged.

Significance. If accepted in a suitably qualified form, the paper makes a valuable contribution by systematically mapping a large set of mechanisms through which AI could affect cyber conflict. Its main strengths are the breadth of the collected arguments, the explicit differentiation across threat actors, targets, and AI capability levels, and the transparent separation of collected claims from the author's assessments. The paper is also commendably honest about its limitations, including the possibility of omitted literature and the preliminary nature of individual evaluations. Because it does not rest on a formal derivation or dataset, its significance lies in providing a structured agenda for future research and policy analysis rather than in establishing a quantitative result.

major comments (3)
  1. [§8 and §9] The forty-eight character-of-cyber propositions from Healey, Jervis, and Nandrajog are used as direct inputs without any validity screening. Section 8 states that the source paper 'do[es] not try to assess the validity of those pronouncements, simply compile them,' and the present paper likewise does not validate them. Since Section 9's forty-four pathways are explicitly derived from Sections 7 and 8, any bias or error in those propositions propagates into the paper's central evidence. The abstract's unqualified claim that the cyber domain is 'too multifaceted for a single answer' therefore rests on an unvalidated list. The authors should either qualify the conclusion to 'based on the compiled propositions and arguments we collected' or provide a sensitivity discussion showing that plausible screening and weighting of the propositions would not reverse the mixed-direction finding.
  2. [§7 and §10] The paper deliberately refuses to weigh the arguments it collects: Section 7 says 'We do not try to defend or refute these arguments, nor do we try to weigh them.' An unweighted aggregation of a heterogeneous list cannot establish that the domain is 'too multifaceted for a single answer' in an absolute sense; it can at most establish that the collected list points in mixed directions. The conclusion is phrased as a property of the cyber domain rather than a property of the method. The introduction contains the caveat that the review may have unintentionally omitted aspects, but the abstract presents the conclusion without that caveat. The recommendation is to temper the central claim (for example, 'Based on the arguments we collected, we find no single answer') or to add an explicit robustness discussion covering weighting and plausibility of the inputs.
  3. [§2 and §10] The paper itself argues in Section 2 that 'it is probably not feasible or even desirable to define a single offense-defense balance' and that the balance can be framed in terms of cost, damage, vulnerability, coercion, and other measures. This framing makes the 'no single answer' conclusion partly definitional rather than an empirical discovery about AI's effects. The authors should clarify whether the negative claim concerns the concept of the offense-defense balance itself or AI's specific empirical effects. If the former, the conclusion is less novel; if the latter, the paper needs to demonstrate that AI's effects are mixed across a validated and weighted set of relevant measures rather than merely across an unweighted list of arguments.
minor comments (6)
  1. [§1 and §4.2] There are typographical errors: 'nefit' in the introduction should be 'benefit,' and 'beneifts' in Section 4.2 should be 'benefits.'
  2. [§6] The paper says 'We do not make any assertions about which will be true' after listing strengths and weaknesses, which is in tension with the later 'We find' statements in the conclusion. Please clarify that the strengths/weaknesses lists are brainstorming prompts rather than predictions.
  3. [§7.2] The subsection headings in Section 7.2 are inconsistently capitalized: for example, 'Attackers Only Need One Success' versus 'Attackers choose when to strike.' Please unify the capitalization style.
  4. [§7.1.1] The phrase 'It gives them their rule-of-thumb three attackers to every one defender advantage' is awkwardly worded and should be rewritten for clarity.
  5. [§9] The paper claims forty-four pathways, and counting the bullets in Section 9 indeed yields forty-four, but the count is not transparent to the reader. Consider numbering the bullets or presenting them in a labeled table so the count is verifiable at a glance.
  6. [References] The forthcoming Healey, Jervis, and Nandrajog paper is cited as 'Jason Healey, n.d.' with no stable identifier or working title. If possible, provide a more complete reference or a version link so readers can access the source of the forty-eight propositions.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: the paper's mixed-effect conclusion is a synthesis of independently catalogued arguments, not a result forced by fitting or by self-citation.

full rationale

The report is a qualitative literature review rather than a derivation with fitted parameters. It assembles eighteen offense-defense arguments from the literature and forty-eight character-of-cyber propositions from Healey, Jervis, and Nandrajog, then assesses how AI might affect each. The central conclusion — that "the cyber domain is too multifaceted for a single answer" — is an inductive summary of those assessments, and nothing in the paper defines the inputs in terms of that conclusion. Section 7's explicit refusal to weigh the arguments ("We do not try to defend or refute these arguments, nor do we try to weigh them") and Section 8's acknowledgment that the forty-eight propositions are compiled without validity assessment are methodological limitations, not circular reductions: a heterogeneous list could in principle have produced a uniform direction, and the paper reports that it did not. The author's self-citations (e.g., on AI error-proneness or vulnerability discovery rates) support specific empirical background claims and are not the load-bearing justification for the overall mixed-effect finding. The Healey et al. input is explicitly labeled as a compilation and is used as a prompt for analysis rather than as a proof of the conclusion. Thus there is no step where a prediction is equivalent by construction to its input, and no circularity score above zero is warranted.

Assumptions & free parameters 0 free parameters · 4 assumptions · 0 invented entities

The paper contains no mathematical derivation and fits no data, so the free-parameter inventory is empty. It rests on qualitative domain assumptions: the AI level taxonomy, the list of collected arguments, the access scenarios, and the AI strengths/weaknesses primer. None of these assumptions is empirically verified in the paper, so they are listed below.

assumptions (4)
  • domain assumption The five AI advancement levels (status quo, reliable and independent, expert, hard limits) are a sufficient taxonomy for reasoning about AI's cyber effects.
    Section 4 introduces these levels and the evaluations are organized around them, but the levels are typifications rather than validated categories.
  • domain assumption The 48 propositions compiled by Healey, Jervis, and Nandrajog adequately capture the character of cyber conflict.
    Section 8 says Healey et al. do not assess the validity of the pronouncements; this paper also takes them as given and builds AI-impact analysis on them.
  • domain assumption The AI strengths and weaknesses listed in Section 6 cover the relevant ways AI could change cybersecurity.
    The author says the lists were used as primers for structured brainstorming, so the resulting 44 impact pathways inherit the coverage of these lists.
  • domain assumption Access to AI advances can be represented by the three scenarios of controlled, limited control, and proliferated.
    Section 5 defines these scenarios and later conclusions about which threat actors benefit depend on which access scenario is assumed.

how reviews work

0 comments
Cite this review

Pith. "Pith review of The Impact of AI on the Cyber Offense-Defense Balance and the Character of Cyber Conflict." pith.science (2026). https://pith.science/paper/XVY7CLKT

@misc{pith2026250413371,
  author       = {Pith},
  title        = {Pith review of: The Impact of AI on the Cyber Offense-Defense Balance and the Character of Cyber Conflict},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/XVY7CLKT}},
  note         = {Machine review of arXiv:2504.13371}
}
read the original abstract

Unlike other domains of conflict, and unlike other fields with high anticipated risk from AI, the cyber domain is intrinsically digital with a tight feedback loop between AI training and cyber application. Cyber may have some of the largest and earliest impacts from AI, so it is important to understand how the cyber domain may change as AI continues to advance. Our approach reviewed the literature, collecting nine arguments that have been proposed for offensive advantage in cyber conflict and nine proposed arguments for defensive advantage. We include an additional forty-eight arguments that have been proposed to give cyber conflict and competition its character as collected separately by Healey, Jervis, and Nandrajog. We then consider how each of those arguments and propositions might change with varying degrees of AI advancement. We find that the cyber domain is too multifaceted for a single answer to whether AI will enhance offense or defense broadly. AI will improve some aspects, hinder others, and leave some aspects unchanged. We collect and present forty-four ways that we expect AI to impact the cyber offense-defense balance and the character of cyber conflict and competition.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Defending Against Intelligent Attackers at Large Scales

    cs.CR 2025-04 conditional novelty 5.0 of 10

    Small linear increases in the number or quality of defense layers can repel exponential increases in the number or speed of independent intelligent cyber attacks, within an idealized defense-in-depth model.

Reference graph

Works this paper leans on

105 extracted references · 61 canonical work pages · cited by 1 Pith paper

  1. [1]

    \ Bogart, A

    ablon2017zero APACrefauthors Ablon, L. \ Bogart, A. APACrefauthors \ 2017 . Zero Days, Thousands of Nights: The Life and Times of Zero-Day Vulnerabilities and Their Exploits Zero days, thousands of nights: The life and times of zero-day vulnerabilities and their exploits \ . RAND

  2. [2]

    , Temsah, M H

    aljamaan2024hallucinations APACrefauthors Aljamaan, F. , Temsah, M H. , Altamimi, I. , Al-Eyadhy, A. , Jamal, A. , Alhasan, K. Malki, K H. APACrefauthors \ 2024 . Reference Hallucination Score for Medical Artificial Intelligence Chatbots: Development and Usability Study Reference hallucination score for medical artificial intelligence chatbots: Developmen...

  3. [3]

    , Mann, B

    allyn2024what APACrefauthors Allyn, B. , Mann, B. , Chappell, B. \ Al-Kassab, F. APACrefauthors \ 2024 . What we know about the computer update glitch disrupting systems around the world What we know about the computer update glitch disrupting systems around the world . National Public Radio

  4. [4]

    \ Healey, J

    alperovitch2020understand APACrefauthors Alperovitch, D. \ Healey, J. APACrefauthors \ 2020 . Understanding and Disrupting Offensive Innovations. Understanding and disrupting offensive innovations. https://www.rsaconference.com/Library/presentation/USA/2020/understanding-and-disrupting-offensive-innovations

  5. [5]

    APACrefauthors \ 2016

    dticDiodes APACrefauthors Arnold, R D. APACrefauthors \ 2016 . STRATEGIES FOR TRANSPORTING DATA BETWEEN CLASSIFIED AND UNCLASSIFIED NETWORKS Strategies for transporting data between classified and unclassified networks \ \ \ ARWSE-TR-15037 . U.S. ARMY ARMAMENT RESEARCH, DEVELOPMENT AND ENGINEERING CENTER . APACrefURL https://apps.dtic.mil/sti/tr/pdf/AD100...

  6. [6]

    , Albert, R

    barabasiScaleFree APACrefauthors Barabási, A L. , Albert, R. \ Jeong, H. APACrefauthors \ 1999 . Mean-field theory for scale-free random networks Mean-field theory for scale-free random networks . Physica A . APACrefURL https://doi.org/10.1016/S0378-4371(99)00291-5 APACrefURL

  7. [7]

    \ Kausik, A K

    rashid2024ai APACrefauthors Bin Rashid, A. \ Kausik, A K. APACrefauthors \ 2024 . AI revolutionizing industries worldwide: A comprehensive overview of its diverse applications Ai revolutionizing industries worldwide: A comprehensive overview of its diverse applications . Hybrid Advances

  8. [8]

    APACrefauthors \ 2016

    navigatebystars APACrefauthors Brumfiel, G. APACrefauthors \ 2016 . U.S. Navy Brings Back Navigation By The Stars For Officers U.s. navy brings back navigation by the stars for officers . National Public Radio . https://www.npr.org/2016/02/22/467210492/u-s-navy-brings-back-navigation-by-the-stars-for-officers

Show all 105 references
  1. [9]

    , Avin, S

    brundage2020trustworthy APACrefauthors Brundage, M. , Avin, S. , Wang, J. , Belfield, H. , Krueger, G. , Hadfield, G. Anderljung, M. APACrefauthors \ 2020 . Toward Trustworthy AI Development: Mechanisms for Supporting Verifiable Claims Toward trustworthy ai development: Mechan...

  2. [10]

    APACrefauthors \ 2017

    buchanan2017cybersecurity APACrefauthors Buchanan, B. APACrefauthors \ 2017 . The Cybersecurity Dilemma: Hacking, Trust and Fear Between Nations The cybersecurity dilemma: Hacking, trust and fear between nations . Oxford University Press . APACrefDOI doi:10.1093/acprof:oso/978...

  3. [11]

    APACrefauthors \

    cisacritical APACrefauthors CISA. APACrefauthors \ . Critical Infrastructure Sectors. Critical infrastructure sectors. https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors

  4. [12]

    APACrefauthors \ 2022

    cisa2022russia APACrefauthors CISA. APACrefauthors \ 2022 . Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure Russian state-sponsored and criminal cyber threats to critical infrastructure \ . United States Cybersecurity and Infrastructure Agency . A...

  5. [13]

    APACrefauthors \ 2024

    cisa2024top APACrefauthors CISA. APACrefauthors \ 2024 . 2023 Top Routinely Exploited Vulnerabilities 2023 top routinely exploited vulnerabilities \ . Cybersecurity and Infrastructure Security Agency

  6. [14]

    , Kilian, K

    corsi2024considerations APACrefauthors Corsi, G. , Kilian, K. \ Mallah, R. APACrefauthors \ 2024 . Considerations Influencing Offense-Defense Dynamics From Artificial Intelligence Considerations influencing offense-defense dynamics from artificial intelligence . arXiv preprint...

  7. [15]

    APACrefauthors \ 2017

    crowdstrike2016use APACrefauthors CrowdStrike. APACrefauthors \ 2017 . Use of Fancy Bear Android Malware in Tracking of Ukrainian Field Artillery Units Use of fancy bear android malware in tracking of ukrainian field artillery units \ . CrowdStrike . https://www.crowdstrike.co...

  8. [16]

    APACrefauthors \ 2025

    securityCopilot APACrefauthors Cruz, M. APACrefauthors \ 2025 . Security Copilot use cases for security and IT roles Security copilot use cases for security and it roles \ . Microsoft . APACrefURL https://learn.microsoft.com/en-us/copilot/security/use-case-role-overview APACrefURL

  9. [17]

    APACrefauthors \ 2022

    canada2022introduction APACrefauthors Cyber Centre . APACrefauthors \ 2022 . An Introduction to the Cyber Threat Environment An introduction to the cyber threat environment \ . Canadian Centre for Cyber Security

  10. [18]

    APACrefauthors \ 2023

    darpaAICC APACrefauthors DARPA. APACrefauthors \ 2023 . AIxCC: AI Cyber Challenge. Aixcc: Ai cyber challenge. APACrefURL https://www.darpa.mil/research/programs/ai-cyber APACrefURL

  11. [19]

    , Han, Q L

    ding2017survey APACrefauthors Ding, D. , Han, Q L. , Xiang, Y. , Ge, X. \ Zhang, X M. APACrefauthors \ 2017 . A survey on security control and attack detection for industrial cyber-physical systems A survey on security control and attack detection for industrial cyber-physical...

  12. [20]

    , Jayatilaka, A

    patchPrioritization APACrefauthors Dissanayake, N. , Jayatilaka, A. , Zahedi, M. \ Babar, M A. APACrefauthors \ 2021 . Software Security Patch Management - A Systematic Literature Review of Challenges, Approaches, Tools and Practices Software security patch management - a syst...

  13. [21]

    APACrefauthors \ 2024

    dni2024infrastructure APACrefauthors DNI. APACrefauthors \ 2024 . Recent Cyber Attacks on US Infrastructure Underscore Vulnerability of Critical US Systems, November 2023–April 2024 Recent cyber attacks on us infrastructure underscore vulnerability of critical us systems, nove...

  14. [22]

    APACrefauthors \ 2011

    dod2011offense APACrefauthors DoD. APACrefauthors \ 2011 . Department of Defense Cyberspace Policy Report: A Report to Congress Pursuant to the National Defense Authorization Act for Fiscal Year 2011, Section 934 Department of defense cyberspace policy report: A report to cong...

  15. [23]

    heartbleed2020 APACrefauthors Durumeric, Z. , Li, F. , Kasten, J. , Amann, J. , Beekman, J. , Payer, M. Halderman, J A. APACrefauthors \ 2014 . The Matter of Heartbleed The matter of heartbleed . Proceedings of the 2014 Conference on Internet Measurement Conference Proceedings...

  16. [24]

    \ Fanning, T

    easterly2023attack APACrefauthors Easterly, J. \ Fanning, T. APACrefauthors \ 2023 . The Attack on Colonial Pipeline: What We’ve Learned and What We’ve Done Over the Past Two Years. The attack on colonial pipeline: What we’ve learned and what we’ve done over the past two years...

  17. [25]

    , Netzer, R H B

    fischer1992race APACrefauthors Fischer, C N. , Netzer, R H B. \ Miller, B P. APACrefauthors \ 1992 . What are race conditions?: Some issues and formalizations What are race conditions?: Some issues and formalizations . ACM Letters on Programming Languages and Systems . APACref...

  18. [26]

    , Bottinger, K

    fischer2017stack APACrefauthors Fischer, F. , Bottinger, K. , Xiao, H. , Stransky, C. , Acar, Y. \ Backes, M. APACrefauthors \ 2017 . Stack Overflow Considered Harmful? The Impact of Copy and Paste on Android Application Security Stack overflow considered harmful? the impact o...

  19. [27]

    , Goldman, E O

    fischerkeller2022cyber APACrefauthors Fischerkeller, M P. , Goldman, E O. \ Harknett, R J. APACrefauthors \ 2022 . Cyber Persistence Theory: Redefining National Security in Cyberspace Cyber persistence theory: Redefining national security in cyberspace . Oxford University Press

  20. [28]

    APACrefauthors \ 2018

    shodanSummary APACrefauthors Franklin, C. APACrefauthors \ 2018 . 7 Steps to Start Searching with Shodan. 7 steps to start searching with shodan. APACrefURL https://www.darkreading.com/iot/7-steps-to-start-searching-with-shodan APACrefURL

  21. [29]

    \ Dafoe, A

    garfinkelODScaling APACrefauthors Garfinkel, B. \ Dafoe, A. APACrefauthors \ 2021 . How does the offense-defense balance scale? How does the offense-defense balance scale? Routledge . https://www.taylorfrancis.com/chapters/oa-edit/10.4324/9781003179917-10/offense-defense-balan...

  22. [30]

    , Bace, R

    geer2003cyber APACrefauthors Geer, D. , Bace, R. , Gutmann, P. , Metzger, P. , Pfleeger, C P. , Quarterman, J S. \ Schneider, B. APACrefauthors \ 2003 . CyberInsecurity: The Cost of Monopoly. Cyberinsecurity: The cost of monopoly

  23. [31]

    APACrefauthors \ 2024

    googleBigSleep APACrefauthors Google. APACrefauthors \ 2024 . From Naptime to Big Sleep: Using Large Language Models To Catch Vulnerabilities In Real-World Code. From naptime to big sleep: Using large language models to catch vulnerabilities in real-world code. https://googlep...

  24. [32]

    APACrefauthors \ 2013

    gray2013making APACrefauthors Gray Dr., C S. APACrefauthors \ 2013 . Making Strategic Sense of Cyber Power: Why the Sky Is Not Falling Making strategic sense of cyber power: Why the sky is not falling . United States Army War College Press

  25. [33]

    , Welburn, J W

    greenfield2023cybersecurity APACrefauthors Greenfield, V A. , Welburn, J W. , Schwindt, K. , Ish, D. , Lohn, A J. \ Hartnett, G S. APACrefauthors \ 2023 . Cybersecurity and Supply Chain Risk Management Are Not Simply Additive Cybersecurity and supply chain risk management are ...

  26. [34]

    APACrefauthors \ 2024

    harknett2024america APACrefauthors Harknett, R J. APACrefauthors \ 2024 . America’s allies are shifting: Cyberspace is about persistence, not deterrence America’s allies are shifting: Cyberspace is about persistence, not deterrence . Cyberscoop

  27. [35]

    APACrefauthors \ 2021 1

    healey2021offense APACrefauthors Healey, J. APACrefauthors \ 2021 1 . Understanding the Offense’s Systemwide Advantage in Cyberspace Understanding the offense’s systemwide advantage in cyberspace . Lawfare . https://www.lawfaremedia.org/article/understanding-offenses-systemwid...

  28. [36]

    APACrefauthors \ 2021 2

    healey2021understanding APACrefauthors Healey, J. APACrefauthors \ 2021 2 . Understanding the Offense’s Systemwide Advantage in Cyberspace Understanding the offense’s systemwide advantage in cyberspace . Lawfare

  29. [37]

    \ Jervis, R

    healey2020escalation APACrefauthors Healey, J. \ Jervis, R. APACrefauthors \ 2020 . The Escalation Inversion and Other Oddities of Situational Cyber Stability The escalation inversion and other oddities of situational cyber stability . Texas National Security Review 3 4 ? APAC...

  30. [38]

    APACrefauthors \ 2017

    hern2017wannacry APACrefauthors Hern, A. APACrefauthors \ 2017 . WannaCry, Petya, NotPetya: how ransomware hit the big time in 2017 Wannacry, petya, notpetya: how ransomware hit the big time in 2017 . The Guardian

  31. [39]

    APACrefauthors \ 2024

    hulme2024state APACrefauthors Hulme, G V. APACrefauthors \ 2024 . The State of Artificial Intelligence and Machine Learning in Cybersecurity The state of artificial intelligence and machine learning in cybersecurity \ . Dark Reading

  32. [40]

    \ Shives, T

    huntley2024offense APACrefauthors Huntley, W. \ Shives, T. APACrefauthors \ 2024 . The Offense-Defense Balance in Cyberspace The offense-defense balance in cyberspace . Proceedings of the 23rd European Conference on Cyber Warfare and Security. Proceedings of the 23rd european ...

  33. [41]

    APACrefauthors \ 2023

    ibm2023what APACrefauthors IBM. APACrefauthors \ 2023 . What is a threat actor? What is a threat actor? APACrefURL https://www.ibm.com/think/topics/threat-actor APACrefURL

  34. [42]

    , Santurkar, S

    ilyas2019bugsfeatures APACrefauthors Ilyas, A. , Santurkar, S. , Tsipras, D. , Engstrom, L. , Tran, B. \ Madry, A. APACrefauthors \ 2019 . Adversarial Examples Are Not Bugs, They Are Features. Adversarial examples are not bugs, they are features. APACrefURL https://arxiv.org/a...

  35. [43]

    , Romanosky, S

    jacobs2023enhancing APACrefauthors Jacobs, J. , Romanosky, S. , Suciu, O. , Edwards, B. \ Sarabi, A. APACrefauthors \ 2023 . Enhancing Vulnerability Prioritization: Data-Driven Exploit Predictions with Community-Driven Insights Enhancing vulnerability prioritization: Data-driv...

  36. [44]

    , Rattray, G

    cybertask2017build APACrefauthors Janow, M E. , Rattray, G. \ Venables, P. APACrefauthors \ 2017 . Building a Defensible Cyberspace Building a defensible cyberspace \ . New York Cyber Task Force

  37. [45]

    APACrefauthors \

    healeyCharacter APACrefauthors Jason Healey, D N., Robert Jervis. APACrefauthors \ . The Dynamics of Cyber Conflict and Competition The dynamics of cyber conflict and competition

  38. [46]

    APACrefauthors \ 1978

    jervis1978cooperation APACrefauthors Jervis, R. APACrefauthors \ 1978 . Cooperation Under the Security Dilemma Cooperation under the security dilemma . World Politics 30 2 ? APACrefDOI doi:10.2307/2009958 APACrefDOI

  39. [47]

    APACrefauthors \ 2024

    jetBrains2024Ecosystem APACrefauthors JetBrains. APACrefauthors \ 2024 . State of Developer Ecosystem Report 2024. State of developer ecosystem report 2024. APACrefURL https://www.jetbrains.com/lp/devecosystem-2024/ APACrefURL

  40. [48]

    , Goldstein, J A

    ji2023controllingLLMs APACrefauthors Ji, J. , Goldstein, J A. \ Lohn, A J. APACrefauthors \ 2023 . Controlling Large Language Model Outputs: A Primer. Controlling large language model outputs: A primer

  41. [49]

    APACrefauthors \ 2024

    kerner2024openai APACrefauthors Kerner, S M. APACrefauthors \ 2024 . OpenAI and Apple's partnership, explained Openai and apple's partnership, explained . TechTarget

  42. [50]

    APACrefauthors \ 1977

    kozen1977rice APACrefauthors Kozen, D C. APACrefauthors \ 1977 . Automata and Computability Automata and computability . ( \ Rice's Theorem). Springer . APACrefURL https://link.springer.com/chapter/10.1007/978-3-642-85706-5_42 APACrefURL

  43. [51]

    APACrefauthors \ 2021

    krebsDisengage APACrefauthors Krebs, B. APACrefauthors \ 2021 . Try This One Weird Trick Russian Hackers Hate. Try this one weird trick russian hackers hate. https://krebsonsecurity.com/2021/05/try-this-one-weird-trick-russian-hackers-hate/

  44. [52]

    APACrefauthors \ 2013

    stuxnetDiscovery APACrefauthors Kushner, D. APACrefauthors \ 2013 . The Real Story of Stuxnet: How Kaspersky Lab tracked down the malware that stymied Iran’s nuclear-fuel enrichment program The real story of stuxnet: How kaspersky lab tracked down the malware that stymied iran...

  45. [53]

    APACrefauthors \ 2023

    lee2023russian APACrefauthors Lee, C. APACrefauthors \ 2023 . Russian Cyber Operations Against Ukrainian Critical Infrastructure Russian cyber operations against ukrainian critical infrastructure . Stanford International Policy Review

  46. [54]

    , Sarkar, A

    lee2025impact APACrefauthors Lee, H P. , Sarkar, A. , Tankelevitch, L. , Drosos, I. , Rintel, S. , Banks, R. \ Wilson, N. APACrefauthors \ 2025 . The Impact of Generative AI on Critical Thinking: Self-Reported Reductions in Cognitive Effort and Confidence Effects From a Survey...

  47. [55]

    APACrefauthors \ 2009

    libicki2009cyberdeterrence APACrefauthors Libicki, M C. APACrefauthors \ 2009 . Cyberdeterrence and Cyberwar Cyberdeterrence and cyberwar \ . RAND Corporation

  48. [56]

    APACrefauthors \ 2013

    ispi2013offense APACrefauthors Locatelli, A. APACrefauthors \ 2013 . The Offense-Defense Balance in Cyberspace The offense-defense balance in cyberspace \ . Institute for Strategic Policy Research . https://www.ispionline.it/sites/default/files/pubblicazioni/analysis_203_2013.pdf

  49. [57]

    APACrefauthors \ 2025

    lockheedcyberkill APACrefauthors Lockheed Martin . APACrefauthors \ 2025 . The Cyber Kill Chain. The cyber kill chain. https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html

  50. [58]

    APACrefauthors \ 2018

    lohn2018meltdown APACrefauthors Lohn, A. APACrefauthors \ 2018 . What do Meltdown, Spectre and RyzenFall mean for the future of cybersecurity? What do meltdown, spectre and ryzenfall mean for the future of cybersecurity? TechCrunch

  51. [59]

    APACrefauthors \ 2019

    lohn2019defense APACrefauthors Lohn, A. APACrefauthors \ 2019 . Defense in Depth: The Basics of Blockade and Delay Defense in depth: The basics of blockade and delay . arXiv preprint arXiv:1910.00111 . APACrefDOI doi:10.48550/arXiv.1910.00111 APACrefDOI

  52. [60]

    \ Jackson, K A

    lohn2022sword APACrefauthors Lohn, A. \ Jackson, K A. APACrefauthors \ 2022 1 . Will AI Make Cyber Swords or Shields Will ai make cyber swords or shields \ . Center for Security and Emerging Technology . APACrefDOI doi:10.51593/2022CA002 APACrefDOI

  53. [61]

    \ Jackson, K A

    lohn2022will APACrefauthors Lohn, A. \ Jackson, K A. APACrefauthors \ 2022 2 . Will AI Make Cyber Swords or Shields: A Few Mathematical Models of Technological Progress Will ai make cyber swords or shields: A few mathematical models of technological progress \ . Center for Sec...

  54. [62]

    , Knack, A

    lohn2023autonomous APACrefauthors Lohn, A. , Knack, A. , Burke, A. \ Jackson, K. APACrefauthors \ 2023 . Autonomous Cyber Defense: A Roadmap from Lab to Ops Autonomous cyber defense: A roadmap from lab to ops \ . Center for Security and Emerging Technology

  55. [63]

    APACrefauthors \ 2020 1

    lohn2020brittleness APACrefauthors Lohn, A J. APACrefauthors \ 2020 1 . Estimating the Brittleness of AI: Safety Integrity Levels and the Need for Testing Out-Of-Distribution Performance Estimating the brittleness of ai: Safety integrity levels and the need for testing out-of-...

  56. [64]

    APACrefauthors \ 2020 2

    lohn2020primer APACrefauthors Lohn, A J. APACrefauthors \ 2020 2 . Hacking AI: A Primer for Policymakers on Machine Learning Cybersecurity Hacking ai: A primer for policymakers on machine learning cybersecurity \ . Center for Security and Emerging Technology

  57. [65]

    APACrefauthors \ 2023

    lohn2023scaling APACrefauthors Lohn, A J. APACrefauthors \ 2023 . Scaling AI: Cost and Performance of AI at the Leading Edge Scaling ai: Cost and performance of ai at the leading edge \ . Center for Security and Emerging Technology . APACrefURL https://cset.georgetown.edu/wp-c...

  58. [66]

    , Surani, F

    magesh2024hallucinations APACrefauthors Magesh, V. , Surani, F. , Dahl, M. , Suzgun, M. , Manning, C D. \ Hoy, D E. APACrefauthors \ 2024 . Hallucination-Free? Assessing the Reliability of Leading AI Legal Research Tools. Hallucination-free? assessing the reliability of leadin...

  59. [67]

    APACrefauthors \ 2018

    mcquade2018untold APACrefauthors McQuade, M. APACrefauthors \ 2018 . The Untold Story of NotPetya, the Most Devastating Cyberattack in History The untold story of notpetya, the most devastating cyberattack in history . WIRED

  60. [68]

    APACrefauthors \ 2024

    rabbi2024AIvulns APACrefauthors Md Fazle Rabbi, M Z., Arifa Champa. APACrefauthors \ 2024 . AI Writes, We Analyze: The ChatGPT Python Code Saga Ai writes, we analyze: The chatgpt python code saga . ACM 21st International Conference on Mining Software Repositories. Acm 21st int...

  61. [69]

    APACrefauthors \ 1989

    mearsheimer1989assessing APACrefauthors Mearsheimer, J J. APACrefauthors \ 1989 . Assessing the Conventional Balance: The 3:1 Rule and Its Critics Assessing the conventional balance: The 3:1 rule and its critics . International Security 13 4 54-89 . APACrefDOI doi:10.2307/2538...

  62. [70]

    APACrefauthors \ 2025

    mitreattack APACrefauthors MITRE. APACrefauthors \ 2025 . ATT&CK Matrix For Enterprise. ATT&CK matrix for enterprise. APACrefURL https://attack.mitre.org/ APACrefURL

  63. [71]

    , Kenneally, E

    moore2019valuing APACrefauthors Moore, T. , Kenneally, E. , Collett, M. \ Thapa, P. APACrefauthors \ 2019 . Valuing Cybersecurity Research Datasets Valuing cybersecurity research datasets . 18th Workshop on the Economics of Information Security (WEIS). 18th workshop on the eco...

  64. [72]

    APACrefauthors \ 2017

    ccdcoe2021wannacry APACrefauthors NATO. APACrefauthors \ 2017 . NotPetya and WannaCry Call for a Joint Response from International Community. Notpetya and wannacry call for a joint response from international community. APACrefURL https://ccdcoe.org/news/2017/notpetya-and-wann...

  65. [73]

    , Alain, P

    nguyen2024fast APACrefauthors Nguyen, D D A. , Alain, P. , Autrel, F. , Bouabdallah, A. , François, J. \ Doyen, G. APACrefauthors \ 2024 . How Fast Does Malware Leveraging EternalBlue Propagate? The case of WannaCry and NotPetya How fast does malware leveraging eternalblue pro...

  66. [74]

    APACrefauthors \ 2024

    NISTCSF APACrefauthors NIST. APACrefauthors \ 2024 . The NIST Cybersecurity Framework (CSF) 2.0 The NIST cybersecurity framework (csf) 2.0 \ . National Institute of Standards and Technology . APACrefURL https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf APACrefURL

  67. [75]

    APACrefauthors \ 2003

    orman2003morris APACrefauthors Orman, H. APACrefauthors \ 2003 . The Morris worm: a fifteen-year perspective The morris worm: a fifteen-year perspective . IEEE Security & Privacy 1 5 35-43 . APACrefDOI doi:10.1109/MSECP.2003.1236233 APACrefDOI

  68. [76]

    APACrefauthors \ 2024

    pratt2024advantages APACrefauthors Pratt, M K. APACrefauthors \ 2024 . 24 advantages and disadvantages of AI 24 advantages and disadvantages of ai . TechTarget

  69. [77]

    \ Siddiqui, M

    radoini2021wmd APACrefauthors Radoini, A. \ Siddiqui, M. APACrefauthors \ 2021 . THE CYBER-THREAT AGAINST CHEMICAL, BIOLOGICAL, RADIOLOGICAL AND NUCLEAR (CBRN) FACILITIES The cyber-threat against chemical, biological, radiological and nuclear (cbrn) facilities \ . United Natio...

  70. [78]

    APACrefauthors \ 2024

    linuxLivePatching APACrefauthors RedHat. APACrefauthors \ 2024 . What is Linux kernel live patching? What is linux kernel live patching? APACrefURL https://www.redhat.com/en/topics/linux/what-is-linux-kernel-live-patching APACrefURL

  71. [79]

    \ McBurney, P

    rid2012weapons APACrefauthors Rid, T. \ McBurney, P. APACrefauthors \ 2012 . Cyber-Weapons Cyber-weapons . The RUSI Journal . APACrefURL https://doi.org/10.1080/03071847.2012.664354 APACrefURL

  72. [80]

    APACrefauthors \ 2020

    riggi2020ransomware APACrefauthors Riggi, J. APACrefauthors \ 2020 . Ransomware Attacks on Hospitals Have Changed Ransomware attacks on hospitals have changed . AHA Center for Health Innovation

  73. [81]

    APACrefauthors \ 2023

    rohlf2023memory APACrefauthors Rohlf, C. APACrefauthors \ 2023 . . Center for Security and Emerging Technology . APACrefURL https://cset.georgetown.edu/article/memory-safety-an-explainer/ APACrefURL

  74. [82]

    \ Martynova, E

    cyberSanctions APACrefauthors Rusinova, V. \ Martynova, E. APACrefauthors \ 2024 . Fighting Cyber Attacks with Sanctions: Digital Threats, Economic Responses Fighting cyber attacks with sanctions: Digital threats, economic responses . Israel Law Review 57 1 135–174 . APACrefDO...

  75. [83]

    , Azzam, S M

    salem2024advancing APACrefauthors Salem, A H. , Azzam, S M. , Emam, O E. \ Abohany, A A. APACrefauthors \ 2024 . Advancing cybersecurity: a comprehensive review of AI-driven detection techniques Advancing cybersecurity: a comprehensive review of ai-driven detection techniques ...

  76. [84]

    APACrefauthors \ 2012

    schneier2012how APACrefauthors Schneier, B. APACrefauthors \ 2012 . How Changing Technology Affects Security How changing technology affects security . IEEE Computer and Reliability Societies

  77. [85]

    APACrefauthors \ 2018

    schneier2018artificial APACrefauthors Schneier, B. APACrefauthors \ 2018 . Artificial Intelligence and the Attack/Defense Balance Artificial intelligence and the attack/defense balance . IEEE Computer and Reliability Societies

  78. [86]

    , Smethurst, R

    seldmeir2021DigitalID APACrefauthors Sedlmeir, J. , Smethurst, R. , Rieger, A. \ Fridgen, G. APACrefauthors \ 2021 . Digital Identities and Verifiable Credentials Digital identities and verifiable credentials . Bus Inf Syst Eng . APACrefURL https://doi.org/10.1007/s12599-021-0...

  79. [87]

    APACrefauthors \ 1949

    shannonNoise APACrefauthors Shannon, C. APACrefauthors \ 1949 . Communication in the Presence of Noise Communication in the presence of noise . Proceedings of the IRE 37 1 10-21 . APACrefDOI doi:10.1109/JRPROC.1949.232969 APACrefDOI

  80. [88]

    APACrefauthors \ 2022

    pewCyber APACrefauthors Silver, L. APACrefauthors \ 2022 . Americans see different global threats facing the country now than in March 2020 Americans see different global threats facing the country now than in march 2020 . Pew . APACrefURL https://www.pewresearch.org/short-rea...

  81. [89]

    , Lucas, K

    anthropic2025 APACrefauthors Singer, B. , Lucas, K. , Adiga, L. , Jain, M. , Bauer, L. \ Sekar, V. APACrefauthors \ 2025 . On the Feasibility of Using LLMs to Execute Multistage Network Attacks. On the feasibility of using llms to execute multistage network attacks. APACrefURL...

  82. [90]

    APACrefauthors \ 2017 1

    slayton2017balance APACrefauthors Slayton, R. APACrefauthors \ 2017 1 . What Is the Cyber Offense-Defense Balance? Conception, Causes, and Assessment What is the cyber offense-defense balance? conception, causes, and assessment . International Security 41 3 72-109 . APACrefURL...

  83. [91]

    APACrefauthors \ 2017 2

    slayton2017why APACrefauthors Slayton, R. APACrefauthors \ 2017 2 . Why Cyber Operations Do Not Always Favor the Offense Why cyber operations do not always favor the offense . International Security

  84. [92]

    , Greaves, F

    greaves2023confabulations APACrefauthors Smith, A L. , Greaves, F. \ Panch, T. APACrefauthors \ 2023 . Hallucination or Confabulation? Neuroanatomy as metaphor in Large Language Models Hallucination or confabulation? neuroanatomy as metaphor in large language models . PLoS Dig...

  85. [93]

    APACrefauthors \ 2021

    smith2021wmd APACrefauthors Smith, S. APACrefauthors \ 2021 . Cyber Threats and Weapons of Mass Destruction Cyber threats and weapons of mass destruction . Center for the Study of Weapons of Mass Destruction . APACrefURL https://wmdcenter.ndu.edu/Portals/68/Documents/wmd-proce...

  86. [94]

    APACrefauthors \ 2020

    smythe2020cult APACrefauthors Smythe, C. APACrefauthors \ 2020 . Cult of the Cyber Offensive: Misperceptions of the Cyber Offense/Defense Balance Cult of the cyber offensive: Misperceptions of the cyber offense/defense balance . Yale Journal of International Affairs . APACrefU...

  87. [95]

    , Saade, T

    tang2024implications APACrefauthors Tang, J. , Saade, T. \ Kelly, S. APACrefauthors \ 2024 . The Implications of Artificial Intelligence in Cybersecurity: Shifting the Offense-Defense Balance The implications of artificial intelligence in cybersecurity: Shifting the offense-de...

  88. [96]

    APACrefauthors \ 2022

    terajima2022ukraine APACrefauthors Terajima, A. APACrefauthors \ 2022 . Ukraine war latest: Power deficit still ‘significant’ after Russia launches ‘more than 1,000 missiles and drones’ at Ukrainian energy since October Ukraine war latest: Power deficit still ‘significant’ aft...

  89. [97]

    APACrefauthors \ 2021

    log4shell APACrefauthors TrendMicro. APACrefauthors \ 2021 . What Is Apache Log4J (Log4Shell) Vulnerability? What is apache log4j (log4shell) vulnerability? APACrefURL https://www.trendmicro.com/en_us/what-is/apache-log4j-vulnerability.html APACrefURL

  90. [98]

    APACrefauthors \ 2022

    valeriano2022failure APACrefauthors Valeriano, B. APACrefauthors \ 2022 . The Failure of Offense/Defense Balance in Cyber Security The failure of offense/defense balance in cyber security . The Cyber Defense Review

  91. [99]

    \ Jensen, B

    valeriano2019myth APACrefauthors Valeriano, B. \ Jensen, B. APACrefauthors \ 2019 . The Myth of the Cyber Offense: The Case for Restraint The myth of the cyber offense: The case for restraint . Policy Analysis

  92. [100]

    villalobos2024run APACrefauthors Villalobos, P. , Ho, A. , Sevilla, J. , Besiroglu, T. , Heim, L. \ Hobbhahn, M. APACrefauthors \ 2024 . Will we run out of data? Limits of LLM scaling based on human-generated data. Will we run out of data? limits of llm scaling based on human-...

  93. [101]

    APACrefauthors \ 2021

    vonEschenbach2021transparency APACrefauthors von Eschenbach, W J. APACrefauthors \ 2021 . Transparency and the Black Box Problem: Why We Do Not Trust AI Transparency and the black box problem: Why we do not trust ai . Philosophy and Technology 1607-1622 . APACrefURL https://do...

  94. [102]

    , Gorm Larsen, P

    woodcock2009formal APACrefauthors Woodcock, J. , Gorm Larsen, P. , Bicarregui, J. \ Fitzgerald, J. APACrefauthors \ 2009 . Formal methods: Practice and experience Formal methods: Practice and experience . ACM Computing Surveys 41 4 . APACrefURL https://dl.acm.org/doi/abs/10.11...

  95. [103]

    APACrefauthors \ 2023

    gallupCyber APACrefauthors Younis, M. APACrefauthors \ 2023 . In U.S., Cyberdisruption Most Critical Threat In u.s., cyberdisruption most critical threat . Gallup . APACrefURL https://news.gallup.com/poll/472544/cyber-disruption-critical-threat.aspx APACrefURL

  96. [104]

    APACrefauthors \ 2014

    zetter2014unprecedented APACrefauthors Zetter, K. APACrefauthors \ 2014 . An Unprecedented Look at Stuxnet, the World's First Digital Weapon An unprecedented look at stuxnet, the world's first digital weapon . WIRED

  97. [105]

    APACrefauthors \ 2016

    zetter2016nsa APACrefauthors Zetter, K. APACrefauthors \ 2016 . NSA Hacker Chief Explains How to Keep Him Out of Your System Nsa hacker chief explains how to keep him out of your system . WIRED

Pith tools

Reviewed August 16, 2026 · model on record in the stance chip above.