November 10, 2024

Opinion: The Trust Trap — AI Manipulation and User Exploitation

By Luis Garcia
@redlineproject

Art direction by Luis Garcia | Illustration By DALL-E

AI disclosure: ChatGPT was used to outline a portion of this paper and to generate research on the topic. DALL-E 3 & LensGo.AI were used to create images. The summary and podcast were generated by SummarizeWise custom GPT and NotebookLM, respectively.

Summary: The paper “The Trust Trap: AI Manipulation and User Exploitation,” addresses the risks and ethical concerns associated with AI’s role in cybersecurity and surveillance, specifically exploring AI’s capability to undermine privacy, increase data vulnerability and facilitate cybercrime.

—-

AI Password Cracking

How many times do we change our passwords? Every month? Every year? Or until we forget and are required to change it.

Passwords tend to be a hassle to manage and remember but are important to maintain our accounts secure and provide us with the security that only the user has access to. Many media companies had their data leaked and compromised people’s priviate information, eventually forcing us to change our passwords or requiring more enforced security methods like two-step verifications apps. However, this war against cybercriminals seems to never end, but rather escalate, with the development of more advanced tools. Now AI is being used to automatize the work for hackers, by using supported guessing apps and data bases that have become more accurate and quicker with AI. The development of these tools is a real concern for everyone, including private sectors, organizations, media, and even the government because it represents a new warfare in the internet that no one expected to occur so quickly.

Art direction by Luis Garcia | Illustration By DALL-E

AI Cybersecurity and Surveillance

It is no secret that surveillance has been in our lives since the invention and implementation of security cameras in government or commercial commercial buildings and now houses. This device helps us to see what’s happening in our surroundings when we are not around or are away from the space that is being monitored by the camera. A well-placed camera can record events where an accident occurs, when a trespasser enters private or restricted property. However, as with every digital tool in the last 30 years, its function had to adapt and upgrade for a more efficient task,such as smart detection and camera movement, like the traffic cameras that track speeding and red lights. It was only a matter of time before cameras would also use facial recognition software, such technology that has been in service and further developed and deployed in countries like China. These facial surveillance cameras are used to keep an eye on the streets for safety and security of the population and can almost immediately recognize and identify the people. Now imagine if these cameras and networks were powered and assisted by AI. Not only will it be an automated system of vigilance, but also a double-point blade that whoever has access to the system can use it to its convenience, either for security or illicit activities.

Art direction by Luis Garcia | Illustration By DALL-E

Automated AI Malware pollution
Have you ever checked your email accounts and noticed that your junk mail section is full of ads and messages of sites or mails that you don’t recognize? The issue is that our mails and data have been leaked for years by companies and media like Facebook, X/Twitter, Instagram, WhatsApp, etc. intentionally or not our data is a business, and as any business it generates a revenue of billions of dollars that attract investors, stockholders, corporations, and advertisers. This is why cybercriminals are so attracted to and determined to get our data because it is also a way for them to steal information or infect systems. Imagine if one of these hackers had access to your email, it will start to get information about accounting and websites for revenue to steal. Usually if you have verifications and security passwords you can recover and report the account. Now imagine if an AI was the one doing the attack, it would be a real time cyberwar where the AI performs multiple tasks to infect as many systems as possible, send mails with viruses, send disinformation, extortion mails, and steal information of sensitive and personal matter. A true nightmare for cybersecurity agents and common people like us.

PODCAST: Listen to the AI-generated podcast of this article about the increasing use of AI in cybercrime, particularly in password cracking, surveillance, and malware propagation

AI Surveillance
This piece has explored data trafficking by companies in order to generate revenue in expense of our personal information. However, the real question lies on if we have privacy or our information is already in the commercial domain? There are many ways in which this question can be answered, but the short version is yes, our information is already owned by companies and agencies we just didn’t know and neglected to notice the cause of it until it really affected our daily lives. In an interview with a well respected and known cybersecurity and writer Bruce Schneier explained that we are already in an era where we are monitored by the private companies and government alike to market us as income in the data collection race. He explained that they do this to gain advantage over other markets and justify any spamming of ads as targeting advertisements.

This would explain why so many websites have ads of products that we searched or talked about with someone. The fact that our privacy is just an illusion and we have accepted by neglecting ourselves the time to read privacy policies when we sign up for websites or social media. Schneier also mentions that countries like China use surveillance as a way to control the population while other countries like the U.S doesn’t directly surveil its citizens but rather collect data with the help of corporations. He also mentions the possibility of these powers to start using AI to enhance their systems and make it easy for them to collect the previously mentioned private information of every person. Nonetheless, he also remains optimistic about how the people can stop this way of spying, that humanity has always found a way to stop oppressive totalism and move forward towards more ethical practices that don’t compromise the safety of the people.

Art direction by Luis Garcia | Illustration By DALL-E

AI Surveillance Concerns
As previously discussed, surveillance is already a reality and not just science fiction like Skynet  from “The Terminator” movies, Ultron (from “Avengers: The Age of Ultron” movie), where AI had a way to help humanity but turned against it. The key concepts of these movies are applied to the advances in surveillance technologies driven by AI. Technologies that are rapidly changing and learning its way to perform better in their tasks as any AI has been programmed to do so.

Many countries are improving their national security with systems that can catalog and identify people with smarter facial recognition, smart policing and data tracking systems. According to the AI Global Surveillance (AIGS) Index a total of 176 countries are adopting these forms of new governance and transformations of technology to create new policies of state control over the people. Technologies that one day will be able to track every person’s day, minute, and seconds of its activity and location. The article also mentions some solutions to these rapid changes like the need for international agreement and policies about the ethics of the use of surveillance systems to avoid its misuse to create authoritarian regimes. However, these advances and changes should be discussed by the population and voted on because in the end the public is the one getting recorded and categorized. Everyone must be informed and concerned about these rapid changes because it will reach the point where our privacy will cease to exist because we allowed it without protesting.

AI Cybersecurity Risk
In the rapid race of technological advances in AI and the adaptations of systems of security and revenue, there is always a concern for security. As technologies in security advance, cybercriminals always try to stay a few steps ahead and easily steal information that is converted into revenue without having to resort to violence. How many times have there been reports of accounts being hacked, bank foundings being redirected or withdrawn without anyone noticing until it is too late? The truth is that many tools have been created to steal information over the decades, and this rapid development has been a surging problem that does nothing but worsen with every year.

AI tools that are capable of cracking encrypted data, unlocking accounts, bypassing security, are only getting smarter and better because unethical use of AI has been unchained by cybercriminals. This brings the concern of the need for policies that regulate AI use and find a way to counter the rampant cyberattacks that people and corporations are facing alike. Now imagine if these attacks were directed to the previously mentioned ways of surveillance that many governments are implementing. An infected network that has not only gathered the information of the data bases, but the identity of the people that it was supposed to protect. A total paranoia and distrust would arise resulting in the change of how AI is internationally structured, but this is only a hypothetical point of view of a possible case scenario if AI cybersecurity doesn’t find a way to stop malicious malware from infecting the systems.

Art direction by Luis Garcia / Art by LensGo.AI

There is potential in development of AI systems that can help improve the management of data, and how it is distributed. Private companies and organizations already make a profit with the people’s data, but they must develop tighter security systems and protocols to protect the sensitive information that they all manage.

Many leaks of data have already been recorded in the last decade where people’s information has been compromised, but if an AI starts to automate these attacks, then everyone will be compromised to lose valuable data or currencies that are digitally managed. There are few case scenarios to take into account when policies about AI regulations needs to be made, and of them is that international regulations for AI should be applied to this new technology that is rapidly changing and adapting to the human activity for illicit or morally purposes. Experts need to train people in how to prevent attacks, and what ways of security could they take to ensure their data safety. The governments should also be transparent and inform the population of any implementation of programs that include AI use, and ask for approval on these matters. Nonetheless, it is up to the people to inform themselves about these arising issues with AI development by ethical and unethical use, either cybercriminals or organizations. The ways people can really protect themselves is if they are careful with what applications they use.

—-

AI and Security FAQ

1. What are the concerns regarding AI-powered surveillance?

  • Automated systems of vigilance that can be misused
  • Potential for abuse by those with access to the systems
  • Increased capability to recognize and identify people in real-time
  • The possibility of creating authoritarian regimes through extensive surveillance

2. Is our personal information already in the commercial domain?

Yes, according to the report, our personal information is already owned and traded by companies and agencies. Many people have unknowingly agreed to this through neglecting to read privacy policies when signing up for websites or social media.

3. What solutions are proposed to address the challenges of AI in cybersecurity and surveillance?

  • Developing international agreements and policies on the ethical use of surveillance systems
  • Encouraging public discussion and voting on the implementation of new surveillance technologies
  • Improving cybersecurity measures to counter AI-powered attacks
  • Educating people about safe internet practices and data protection
  • Implementing transparent government policies regarding AI use and seeking public approval

4. How can individuals protect themselves from AI-powered cyber-threats?

  • Be cautious about which applications they use
  • Be careful about which websites they visit
  • Be mindful of what they download
  • Generally, be more conscious about how they navigate the web to avoid falling into AI-powered traps

5. How is AI impacting malware and cyber-attacks?

AI is being used to automate and enhance cyber attacks, including:

  • Creating more sophisticated phishing emails
  • Developing adaptive malware that can evade detection
  • Automating the process of infecting systems and stealing information
  • Conducting real-time cyberwarfare with multiple simultaneous tasks

—–

Editor’s note: Students in Mike Reilley’s AI Journalism (COMM 294) Fall 2024 undergraduate course experimented with AI storytelling tools to create these stories, following the AI use guidelines on The Red Line Project’s Principles page.

Bookmark the permalink.

Leave a Reply

Your email address will not be published. Required fields are marked *