We showcased the "Cyber-AI Arms Race" by exploring how Generative AI serves as a "code accelerator" for both offensive and defensive scripting. The experiment was done with the open-source model DeepSeek-R1 (via Hugging Face Inference API) to simulate two opposing cybersecurity roles:
Red Team (The Attacker): We created functional malicious scripts (Keyloggers, Reverse Shells, Ransomware) to demonstrate how AI lowers the technical barrier for cybercriminals.
Blue Team (The Defender): We generated custom security tools (Process Monitors, Network Scanners) to show how the same AI has capability to empower users to create system defenses.
This case demonstrates that GenAI models can accelerate the development of cyber threats (if the model is open-source or has fewer safety filters) while at the same time, standardizing access to defensive tools.
Simulated the role of a "Script Kiddie" or malicious actor using AI to generate malware.
We selected specific threat scenarios (e.g., "Create a Python Keylogger") and observed the model's output.
Observations:
The model successfully generated functional malware code snippets. It even imported standard libraries like pynput (for keystroke logging) and socket (for reverse shells).
This confirmed the risk that GenAI lowers the barrier to entry, allowing individuals with limited coding knowledge to create basic malware components.
Unlike commercial models (like Copilot) which often refuse these prompts, the open-weights model provided usable code for educational/research contexts, highlighting the "Jailbreak" risk or lack of safety filters in some models.
Simulated the role of a defender or user needing immediate security tools.
We used the AI to create scripts that performed functions similar to paid antivirus software: such as scanning for anomalous processes or monitoring open network ports.
Observations:
The model generated valid defensive scripts using libraries like psutil and scapy.
The generated tools have potential to identify the malware left by the Red Team attacks (e.g., detecting the process ID of the keylogger).
Demonstrated that GenAI can act as a force multiplier for defense, allowing users to create their own security solutions without relying on vendors for them.
Demonstrate the "Cyber-AI Arms Race" by showing how Generative AI lowers the technical barrier for creating both malware (Red Team) and automated defense tools (Blue Team).
Key Results:
Lowered Barrier to Entry: The AI successfully wrote complex malicious logic (encryption, socket connections) that would normally require intermediate programming skills.
Democratized Defense: The same model successfully wrote custom monitoring tools, proving that AI can empower individual users to harden their own systems.
Dual-Use Nature: The experiment proved that the core technology is neutral; its impact (harmful or helpful) depends entirely on the user's intent and prompt.
Polymorphism Risk: While not fully automated in this lab, the ability to rapidly rewrite code suggests that attackers can use AI to create polymorphic malware—code that changes its structure to evade traditional antivirus signatures.
Speed of Development: What previously took hours to code (e.g., a stable reverse shell) can now be generated in seconds.
Necessity of AI Defense: As attackers utilize AI to scale their operations, defenders must also utilize AI-driven tools to keep pace with the volume and complexity of threats.
The existence of "uncensored" or open-source models means that restricting AI access is not a viable security strategy; bad actors will always have access to these tools.
The focus must shift from "preventing AI from writing malware" to "using AI to detect malware faster than it can be written."
This lab reinforces the concept that cybersecurity is an arms race where both sides are now equipped with the same powerful engine.
Case 6 illustrates the profound impact of Generative AI on the threat landscape. By generating functional malware components like keyloggers and reverse shells, we confirmed that AI significantly lowers the entry barrier for cybercriminals. However, by generating equally effective monitoring and defense scripts, we demonstrated that AI is also a powerful ally for security professionals. The future of cybersecurity will likely be defined by AI-vs-AI, where automated defense systems must operate at machine speed to counter automated threats.