Skip to content
Back to journal
AI & DetectionApr 15, 2026 7 min read

AI vs. AI: When Attackers Use the Same Tools as Defenders

Offensive AI moved from research to operational in 2025. Here's what we are seeing from ARIA's detection telemetry — and how defense has to evolve.

AN
Adaeze Nwosu
Chief Security Officer

We crossed an uncomfortable threshold in late 2025. For the first time, ARIA's detection telemetry showed campaigns where every observable step — from initial recon to lateral movement — looked like it had been authored by an LLM. Not just the phishing copy. The infrastructure. The timing. The decision tree.

What 'AI-native attacks' actually look like

We see three patterns far more than the others:

  • Polymorphic phishing where every recipient receives a different lure tied to their actual project graph (scraped from LinkedIn and GitHub).
  • Reconnaissance scripts that adapt as they fail — pivoting from one IDP to another based on response headers.
  • Lateral movement that delays itself by humanlike intervals to evade behavioral heuristics.

Why classical detection is losing

Most SIEMs and EDRs were designed around indicators-of-compromise (IOCs) and behavioral signatures. AI-native attacks don't reuse IOCs because each attack is freshly generated. They don't trip behavioral signatures because the behaviors look reasonable in isolation.

What works

The honest answer is also the harder one: only AI catches AI, and only if the AI reasons over the full graph — identity, network, workload, and code together. We trained ARIA on 41 billion attack patterns, but the architectural breakthrough is that it ingests every domain in one model. A signal that looks innocuous in identity becomes obvious when reasoned against the workload graph.

99.92%
ARIA detection rate on MITRE ATT&CK v15 in 2026 Q1

The new tradeoff: explainability

An AI defender that can't explain itself is a liability. We invested heavily in ARIA's explainability layer for exactly this reason. Every decision ships with the reasoning trail. A SOC analyst can defend any block in writing — which matters when your auditors arrive.

#AI defense#offensive AI#ARIA

Continue reading

All posts
Cryptography

The Quantum Computing Threat: Why 2026 Is the Tipping Point

In 2026 we crossed three quiet thresholds in quantum hardware. Each one shortens harvest-now-decrypt-later timelines. Here's the math and what to do about it.

May 8, 2026 · 9 min
Cryptography

Inside CRYSTALS-Kyber: How Lattice-Based Cryptography Works

A practitioner's walkthrough of Kyber — the cryptographic substrate of the post-quantum era. No PhD required. We promise.

May 1, 2026 · 11 min
Zero Trust

Zero Trust in Practice: Lessons from 50+ Enterprise Deployments

Five anti-patterns we now refuse to repeat, plus the deployment runway we ship to every new customer.

Apr 22, 2026 · 8 min
Secure your infrastructure

Move to quantum-safe in a quarter — not a decade.

Talk with a Lumix architect about a 90-day post-quantum rollout, a live SpectraShield demo on your stack, and the breach math that should be on your board agenda this week.