Develop Capabilities
When attackers want to cause trouble, they often have to build their own custom tools or resources to get the job done. Think of it like a burglar who doesn't just buy a lockpick, but instead builds a custom device or sets up a fake storefront to trick people into letting them inside.
Adversaries create custom tooling or infrastructure to facilitate their objectives against AI systems. This lifecycle involves defining operational requirements, engineering the necessary software or environment, and deploying these assets. These capabilities are not limited to AI-specific tools and often include supporting infrastructure like malicious websites or obfuscated scripts designed to bypass security controls.
The process of developing capabilities involves the systematic identification of operational requirements, the engineering of bespoke solutions, and the deployment of assets to support adversarial objectives against AI-enabled systems. This process is agnostic to the underlying technology of the capability itself; while the target is an AI system, the capability may consist of non-AI-based infrastructure, such as command-and-control servers, obfuscated exfiltration payloads, or social engineering environments, developed to support the full lifecycle of an attack.