When AI Attackers Become Careful Instead of Noisy
Dia daoibh from Japan.
One common assumption in cybersecurity is that attacks are becoming "bigger." But I think an equally important question is whether AI-powered attacks may become quieter.
Recently, I asked ChatGPT the following question.
Question:
Traditional cyberattacks (for example, bot-based attacks) are characterized by their large volume. Could generative AI used for offensive purposes instead become careful?
The answer was surprisingly interesting.
From Quantity to Quality
Traditional automated attacks typically rely on overwhelming numbers.
Examples include:
- Internet-wide vulnerability scanning
- Password spraying
- Credential stuffing
- Massive phishing campaigns
- Botnet-based DDoS attacks
The strategy is simple:
Try millions of times and accept a low success rate.
What Changes with Generative AI?
An AI-assisted attacker does not necessarily need to maximize the number of attempts.
Instead, it could optimize for the probability of success.
For example, an AI system might reason:
- "This organization appears to have a mature SOC. Skip it for now."
- "This administrator usually logs in after business hours."
- "Today's login attempt would look suspicious."
- "Rewrite this phishing email to better match the recipient's writing style."
- "Wait another week before attempting lateral movement."
In other words, instead of making one million attempts with a tiny success rate, the attacker may prefer making only one hundred carefully selected attempts with a dramatically higher chance of success.
Less Noise Means Harder Detection
Most modern security monitoring systems are very good at detecting obvious anomalies such as:
- Thousands of login attempts
- High-rate port scanning
- Large traffic spikes
- Repeated authentication failures
However, detecting an attacker who behaves almost like a human is much more difficult.
Imagine activity such as:
- One login attempt per day
- Different IP addresses every time
- Timing aligned with employee working hours
- Human-like browser interaction
- Long periods of inactivity between actions
Each individual event appears perfectly normal.
The danger emerges only when viewed as part of a larger pattern.
A Shift in Defensive Thinking
Historically, security teams often associated risk with volume.
More events = Higher risk.
Generative AI may challenge this assumption.
Future attacks may instead look like:
Fewer events, but much higher quality.
This suggests that defenders should increasingly evaluate:
- Behavioral consistency
- Context
- Timing
- Intent
- Small anomalies accumulated over time
rather than simply counting alerts.
A Personal Observation
One idea I have been exploring is that AI changes not only how attacks are executed, but also how attackers make decisions.
Instead of maximizing the number of attacks, AI can optimize return on investment.
That may produce attackers who are not louder—
but significantly more patient.
Sometimes, the most dangerous attacker is the one who does almost nothing until the perfect moment.
Cybersecurity is becoming less about detecting noise, and more about understanding intent.
Anois, rith Joyce liom, trí Bob Dylan.











