Defense Evasion
Defense evasion is when a hacker tries to hide their tracks so that smart security programs, which use AI to spot suspicious activity, don't notice them sneaking around the system.
Defense evasion encompasses the specific tactics and procedures an adversary employs to bypass or subvert AI-driven security controls, such as machine learning-based malware classifiers or behavioral analytics, to maintain persistence and avoid detection during an intrusion.
The adversary is trying to avoid being detected by AI-enabled security software. Defense Evasion consists of techniques that adversaries use to avoid detection throughout their compromise. Techniques used for defense evasion include evading AI-enabled security software such as malware detectors.
evolution
- 2017 · historyAdversarial Examples Formalized
Research by Goodfellow et al. demonstrated how small, intentional perturbations can cause neural networks to misclassify inputs, effectively bypassing detection.
- 2018 · historyBlack-Box Evasion Attacks
Researchers demonstrated that evasion techniques could succeed against AI models without prior knowledge of the model's internal architecture or training data.
- 2021 · historyMITRE ATLAS Framework
MITRE released the Adversarial Threat Landscape for Artificial-Intelligence Systems (ATLAS), formally documenting defense evasion as a core tactic in AI-specific cyberattacks.
- 2023 · historyLLM Jailbreaking Emergence
The rise of large language models introduced prompt injection and jailbreaking as primary methods for evading safety filters and content moderation systems.