{"id":92972,"date":"2026-07-02T07:00:12","date_gmt":"2026-07-02T07:00:12","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/92972\/"},"modified":"2026-07-02T07:00:12","modified_gmt":"2026-07-02T07:00:12","slug":"when-ai-turns-against-the-machine-the-emerging-threat-of-llms","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/92972\/","title":{"rendered":"When AI Turns Against the Machine: The Emerging Threat of LLMs"},"content":{"rendered":"<p>                    <a href=\"#\" rel=\"nofollow\" onclick=\"window.print(); return false;\" title=\"Printer Friendly, PDF &amp; Email\"><br \/>\n                    <img decoding=\"async\" class=\"pf-button-img\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/04\/printfriendly-pdf-email-button-md.png\" alt=\"Print Friendly, PDF &amp; Email\" style=\"width: 194px;height: 30px;\"\/><br \/>\n                    <\/a><br \/>\n                Abstract<\/p>\n<p>The rapid integration of large language models and autonomous artificial intelligence (AI) systems into defense, critical infrastructure, and enterprise environments has created a fundamentally new attack surface\u2014one that existing cybersecurity frameworks were not designed to address. This article examines the emerging threat of AI systems being leveraged to target AI infrastructure itself, with particular focus on four documented attack classes: sponge examples for resource exhaustion; neural trojan backdoor attacks; adversarial workload scheduling; and model extraction through black-box querying. Drawing on published academic research and documented adversary behavior from state-sponsored threat actors including Russia\u2019s Sandworm unit and China\u2019s People\u2019s Liberation Army (PLA) Cyberspace Force, the article argues that AI infrastructure has become strategic infrastructure\u2014requiring security treatment commensurate with that status. Defensive countermeasures exist for each attack class but remain largely unimplemented in operational environments.<\/p>\n<p>The Attack That Looks Like Nothing<\/p>\n<p>In October 2022, Russia\u2019s Sandworm\u2014GRU Unit 74455\u2014timed a <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/sandworm-disrupts-power-ukraine-operational-technology\/\" rel=\"nofollow noopener\" target=\"_blank\">cyberattack against Ukrainian power infrastructure<\/a> to coincide with a mass missile strike on Ukrainian cities. The attack did not breach the grid with brute force. Sandworm had spent months learning the decision logic of the industrial control systems governing Ukrainian substations. When the moment came, it used that logic against itself\u2014tripping circuit breakers through the grid\u2019s own management software while operators watched dashboards that showed nothing obviously wrong. The lights went out. The source of the disruption was concealed. By the time engineers understood what had happened, the missiles had already landed.<\/p>\n<p>That operational template\u2014patient study of a target system\u2019s decision architecture, embedding within its management layer, weaponizing its own logic\u2014did not end with Ukrainian power infrastructure.<\/p>\n<p>It is coming for AI.<\/p>\n<p>The AI systems now embedded in American defense logistics, military supply chains, and critical infrastructure are making consequential operational decisions around the clock. They are also largely undefended against an adversary who understands that the same methodology Sandworm applied to industrial control systems also applies with equal precision to the orchestration platforms, inference pipelines, and training data ecosystems that govern modern AI. The attack surface is different. The operational concept is identical.<\/p>\n<p>What Makes AI Infrastructure a Target<\/p>\n<p>Modern AI systems depend on extraordinarily complex ecosystems: vast networks of accelerators, storage arrays, orchestration platforms, cooling systems, power distribution systems, firmware layers, and cloud environments operating in synchronization. These are not servers in a rack. They are specialized computational ecosystems optimized for parallel processing and massive data movement.<\/p>\n<p>AI clusters now represent some of the most valuable and resource-intensive infrastructure on the planet. In many organizations, AI compute resources are becoming as strategically important as financial systems, telecommunications infrastructure, or energy grids. These resources are being integrated into military logistics, intelligence analysis, and command support functions at a pace that has significantly outrun the security frameworks meant to protect them.<\/p>\n<p>An adversary does not need to destroy an AI system to create catastrophic disruption. Simply degrading performance, exhausting resources, or manipulating outputs may be enough. A targeted operation against AI infrastructure could simultaneously compromise healthcare systems, financial models, logistics operations, intelligence analysis, and military planning without a single shot fired, without a ransom note appearing, without a network intrusion alert triggering.<\/p>\n<p>This is what changes AI infrastructure from an IT asset into a national security concern.<\/p>\n<p>The Adversaries<\/p>\n<p>China\u2019s <a href=\"https:\/\/cyberdefensereview.army.mil\/Portals\/6\/Documents\/CDR%20Journal%20Articles\/The%20Strategic%20Support%20Force_Kania_Costello.pdf?ver=2018-07-31-093713-580\" rel=\"nofollow noopener\" target=\"_blank\">PLA Cyberspace Force<\/a>, formed in April 2024 from the network warfare components of the former Strategic Support Force, is one significant threat to American AI infrastructure. The Cyberspace Force\u2019s is \u201csystems destruction warfare\u201d\u2014a strategy prioritizing disabling an adversary\u2019s decision-making networks before and during conflict. AI systems are decision-making networks. China\u2019s Military-Civil Fusion strategy creates direct pipelines between civilian AI research, commercial technology firms, and PLA capability development, meaning adversarial research into the attack classes described below is not confined to academic labs. It is plausibly underway within an ecosystem with direct pathways to operational application.<\/p>\n<p>Russia\u2019s APT44\u2014Sandworm\u2014provides the <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/apt44-unearthing-sandworm\" rel=\"nofollow noopener\" target=\"_blank\">operational proof of concept<\/a>. Its decade-long progression from the 2015 Ukrainian power outages through Industroyer and Industroyer2 demonstrates a consistent and improving capability to learn target system architecture, embed within management layers, and manipulate operational logic to produce physical-world effects while concealing the source. Every element of that progression translates directly to AI infrastructure. The protocols are different. The methodology is the same.<\/p>\n<p>In 2022, Sandworm used living-off-the-land techniques to<a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/sandworm-disrupts-power-ukraine-operational-technology\/\" rel=\"nofollow noopener\" target=\"_blank\"> trip substation circuit breakers<\/a> in coordination with Russian missile strikes on Ukraine, timing the cyber effect to amplify the operational impact of kinetic action. The group did not defeat Ukrainian power infrastructure with brute force. It learned the decision logic of the systems governing that infrastructure and turned that logic against itself.<\/p>\n<p>Iran rounds out the threat picture. Its Islamic Revolutionary Guards Corps (IRGC)-affiliated cyber program has demonstrated consistent willingness to target infrastructure systems other actors treat as off-limits, and its documented preference for disruption over espionage places it in this threat category even as its AI-specific capabilities lag China and Russia.<\/p>\n<p>Four Ways the Attack Arrives<\/p>\n<p>Understanding how Sandworm operated against Ukrainian power infrastructure makes the following four attack classes immediately recognizable\u2014not as novel cyber threats, but as the same operational concept applied to a new target set.<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\" wp-image-150565 aligncenter\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/image-7-300x234.png\" alt=\"\" width=\"613\" height=\"478\"  \/><\/p>\n<p>Figure 1. The Sandworm operational template maps step-for-step onto adversarial AI attack techniques. The methodology is established. Only the target has changed. Sources: MITRE ATT&amp;CK Campaign C0034; MITRE ATLAS adversarial AI framework.<\/p>\n<p>The Training Phase: Poisoning What the AI Believes<\/p>\n<p>Sandworm did not tamper with Ukrainian grid infrastructure in real time. It corrupted the operational environment the grid\u2019s management systems depended on\u2014so that when operators made decisions based on those systems, the decisions were wrong.<\/p>\n<p>Data poisoning <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/sandworm-disrupts-power-ukraine-operational-technology\/\" rel=\"nofollow noopener\" target=\"_blank\">attacks against AI systems<\/a> work identically. An adversary who gains access to training pipelines\u2014through supply chain compromise, a third-party data annotation service, or a compromised model repository\u2014introduces precisely engineered examples that teach the model something specific and false. The poisoned model performs normally on standard evaluation benchmarks. It passes every test. It earns operational trust. Then, under the specific conditions the attacker has engineered, it does exactly what the attacker intended: passing defective components, ignoring warning signals, misclassifying threats. Research by Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg in 2017 <a href=\"https:\/\/arxiv.org\/abs\/1708.06733\" rel=\"nofollow noopener\" target=\"_blank\">established<\/a> that triggers can be embedded so precisely that the compromised behavior activates only in the presence of a specific input condition\u2014invisible to operators, indistinguishable from normal operation in every other context.<\/p>\n<p>When foundation models are shared across applications, a trojan embedded at the foundation level propagates to every downstream system built on top of it\u2014simultaneously, without any of those organizations knowing the ground has shifted beneath them.<\/p>\n<p>The Inference Phase: Fooling the Model at the Moment of Decision<\/p>\n<p>If the training phase attack is the long game, adversarial input attacks are the tactical strike.<\/p>\n<p>Small, precisely engineered modifications to inputs\u2014invisible or nearly invisible to human observers\u2014can cause a deployed AI system to misclassify what it is examining with complete confidence. A defective component carrying a specific surface modification passes quality inspection. A machine approaching failure generates sensor data that the maintenance AI categorizes as healthy. A suspicious pattern in logistics data presents itself in a form the monitoring system reads as routine. Detection techniques <a href=\"https:\/\/ieeexplore.ieee.org\/document\/8835365\/\" rel=\"nofollow noopener\" target=\"_blank\">including Neural Cleanse and STRIP<\/a> exist and are documented in the open-source literature. They are rarely implemented in operational environments.<\/p>\n<p>These attacks require no access to training infrastructure. They require only understanding how the target model makes decisions\u2014information that can often be inferred by systematically observing its responses. Any AI system whose inputs can be influenced by an adversary is structurally exposed.<\/p>\n<p>The Orchestration Layer: Turning the System Against Itself<\/p>\n<p>This is where the Sandworm parallel is most direct.<\/p>\n<p>Sandworm did not overpower Ukrainian grid defenses. It learned the ICS protocols, embedded within the control layer, and used the grid\u2019s own operational logic to trip circuit breakers\u2014with the grid\u2019s own management software executing the attack. Modern GPU clusters rely on scheduling systems\u2014Kubernetes, SLURM, proprietary equivalents\u2014that make placement decisions based on real-time utilization metrics and thermal telemetry. These schedulers are optimization algorithms. They are trying to keep the system efficient, balanced, and healthy.<\/p>\n<p>An attacker with access to the orchestration layer can subvert that optimization by manipulating the metrics the scheduler consumes. Report falsely low utilization on thermally stressed nodes, and the scheduler\u2019s own efficiency logic concentrates workloads onto those nodes rather than distributing them. Cooling systems face localized thermal loads they were not designed to handle while cluster-wide averages look normal. Balancing algorithms designed to protect the system begin amplifying the instability. The attack does not look like an attack. It looks like an engineering anomaly\u2014which is exactly what Sandworm\u2019s operations looked like to Ukrainian grid operators\u2014until they did not.<\/p>\n<p>The Query Interface: Stealing AI Without Breaking In<\/p>\n<p>The final attack class requires no infrastructure access at all.<\/p>\n<p>If an adversary can query a deployed model and observe its outputs, they can use those input-output pairs to train a surrogate that approximates the original\u2019s behavior. Given a black-box model, an attacker builds a dataset of queries and responses and trains a surrogate to minimize divergence from the original. For many model classes, a surprisingly small number of queries produces a high-quality functional equivalent\u2014effectively stealing a proprietary AI system without accessing underlying infrastructure, weights, or training data. LLM-powered automation can conduct this at a <a href=\"https:\/\/www.nist.gov\/publications\/artificial-intelligence-risk-management-framework-ai-rmf-10\" rel=\"nofollow noopener\" target=\"_blank\">scale and speed<\/a> that would take human operators weeks to match, while distributing queries across IP ranges and timing them to evade rate limiting. The theft leaves no obvious forensic signature.<\/p>\n<p>Why This Is a Gray Zone Problem<\/p>\n<p>Strip away the technical vocabulary and what remains is a gray zone operator\u2019s checklist.<\/p>\n<p>Deniable: A quality inspection AI that passes defective components produces no forensic signature distinguishable from a software defect or ordinary model drift. A scheduling system that creates thermal hotspots looks like an engineering problem. Attribution requires capabilities most organizations do not currently deploy against AI-specific threat signatures.<\/p>\n<p>Persistent: Unlike ransomware, which announces itself, a poisoned model operates in a compromised state for months or years without triggering alerts. Damage accumulates silently across interconnected systems.<\/p>\n<p>Scalable: A neural trojan in a widely used foundation model propagates to every downstream application built on top of it. One insertion point. Unlimited reach.<\/p>\n<p>Below threshold: No kinetic action. No obvious breach. No clear act of war. Just a gradual, invisible erosion of the operational reliability of the systems an adversary depends on: the gray zone objective in its purest form.<\/p>\n<p>Sandworm demonstrated that this operational concept works against industrial control systems. The AI layer of American defense infrastructure is the next logical target set, and it is currently more exposed than Ukrainian power grids were in 2014.<\/p>\n<p>The Gap Between What Exists and What Is Being Used<\/p>\n<p>MITRE\u2019s Adversarial Threat Landscape for AI Systems <a href=\"https:\/\/atlas.mitre.org\" rel=\"nofollow noopener\" target=\"_blank\">catalogs the attack classes<\/a> described above, maps real-world case studies, and identifies corresponding mitigations. The NIST AI Risk Management Framework provides <a href=\"https:\/\/www.nist.gov\/publications\/artificial-intelligence-risk-management-framework-ai-rmf-10\" rel=\"nofollow noopener\" target=\"_blank\">structured guidance for AI risk<\/a> governance. Both exist. Neither is being systematically implemented across operational defense AI environments.<\/p>\n<p>The solutions are simple. AI systems with operational decision-making authority in defense-relevant contexts need adversarial testing before deployment. This is not just penetration testing of surrounding networks, but testing of the model itself against the attack classes above. AI models procured for use in defense need verifiable chain of custody for training data and model weights. Supply chain integrity requirements that govern hardware and software need to be extended explicitly to AI systems. Accelerator hardware entering defense environments needs firmware integrity verification. CISA\u2019s current AI guidance does not adequately address adversarial workload scheduling or inference-layer attacks as distinct threat categories. That needs to change.<\/p>\n<p>The workforce gap at the intersection of AI systems knowledge and advanced cybersecurity architecture needs to be treated as a national security priority. The organizations that build that workforce now will be far better positioned when adversaries who have already invested in these capabilities choose to employ them.<\/p>\n<p>Conclusion: Before the Lights Go Out<\/p>\n<p>In 2014, Sandworm was an unknown threat actor conducting early reconnaissance against Ukrainian infrastructure. By 2015, it had produced the world\u2019s first confirmed malware-induced power outage. By 2022, it was coordinating cyberattacks with missile strikes.<\/p>\n<p>The progression from capability to operational employment happened faster than defenders anticipated, through methods they had not fully prepared for, against infrastructure they believed was adequately protected.<\/p>\n<p>The AI systems running inside American defense infrastructure were built to be accurate. They were not built to be resilient against an adversary who has read the same academic literature we have, observed the same operational templates we have documented, and is applying them to a target set that is currently undefended.<\/p>\n<p>The doctrine, acquisition regulations, workforce pipelines, and defensive architectures required to operate securely in this environment need to be built now\u2014by the people reading this\u2014before an adversary demonstrates the capability operationally and takes that decision out of our hands.<\/p>\n<p>The views expressed in this article are the author\u2019s own and do not represent the official position of the United States Army, Army Reserve, or Department of Defense.<\/p>\n","protected":false},"excerpt":{"rendered":"Abstract The rapid integration of large language models and autonomous artificial intelligence (AI) systems into defense, critical infrastructure,&hellip;\n","protected":false},"author":2,"featured_media":92973,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[48759,32276,24,48760,25,111,5970,1393,23710,26900,2845,48761,48762,369,48763,2225,699,213],"class_list":["post-92972","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ai","tag-2026-iran-conflict","tag-adaptive-malware","tag-ai","tag-apts","tag-artificial-intelligence","tag-artificial-intelligence-ai","tag-cyber-attacks","tag-cyber-security","tag-cyber-warfare","tag-disruptive-technologies","tag-drones","tag-great-power-competition","tag-hybrid-warfare","tag-iran","tag-irregular-warfare","tag-llms","tag-russia-ukraine-war","tag-ukraine"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/92972","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=92972"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/92972\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/92973"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=92972"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=92972"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=92972"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}