AI-Powered Cyberattacks Pose Growing Threat to U.S. Infrastructure
Experts warn that artificial intelligence could lower the barrier to entry for devastating attacks on critical systems, making old vulnerabilities far more dangerous.
The nation's critical infrastructure, already vulnerable to cyberattacks, faces a significantly amplified threat due to the rapid advancement of artificial intelligence, according to cybersecurity experts.
Nearly two decades ago, researchers at the Idaho National Laboratory demonstrated the potential for significant disruption with a secret experiment known as the Aurora Generator Test. Using just 30 lines of code, they manipulated a massive diesel generator, causing it to violently shake and tear itself apart by corrupting safeguards and altering its synchronization with the power grid. Lead researcher Michael Assante noted at the time that the experiment offered a glimpse into a future where relatively simple code could inflict substantial physical damage on essential machinery.
That future appears to be drawing closer, as AI development makes it easier for individuals with less technical expertise to launch sophisticated cyberattacks. "Before, you needed to have highly skilled technical expertise," said Alvaro Cardenas, a computer science professor at UC Santa Cruz, referring to the level of skill required for attacks like the Aurora Generator Test. "And now, you just have to have a general idea of what’s possible."
This democratization of hacking capabilities is particularly concerning given the state of U.S. infrastructure. Many systems, including gas pipelines, water desalination plants, and cargo terminals, remain inadequately protected against conventional cyber threats, let alone those enhanced by AI. While cyberattacks focused on disruption rather than immediate financial gain have historically been less appealing to many hackers, AI tools can lower the barrier to entry for such actions.
Furthermore, AI-powered agents do not experience fatigue, meaning they can operate continuously and tirelessly. This persistent capability significantly increases the potential for sustained attacks on vulnerable systems.
Historically, while state-sponsored actors from countries like China, Iran, and Russia have breached U.S. infrastructure, they have largely refrained from causing widespread disruption. However, this norm is shifting. Jason Healey, a cybersecurity scholar at Columbia University, observes that geopolitical factors are increasing the intent to disrupt, while AI is decreasing the capability gap. This combination means that the likelihood of malicious actors, whether state-sponsored or non-state, using AI to compromise critical infrastructure for disruptive purposes is growing.
Recent events underscore this emerging threat. In one instance, numerous water and wastewater systems in small towns across the United States were targeted by hackers, resulting in temporary water stoppages and flooding. While these attacks have not been definitively linked to AI, the National Security Agency has warned that hackers are actively employing AI to target U.S. infrastructure. The vulnerability of such local systems, often underfunded and dealing with aging infrastructure, makes them particularly susceptible. "You have a million other problems to take care of, like aging infrastructure — your stuff’s falling apart because it’s been in the ground for 100 years," noted Andy Bochman, an expert in infrastructure resilience.
To address these growing risks, experts advocate for a coordinated response involving the federal government, AI companies, and international cooperation, including with nations like China. There is also a call for utility systems to proactively enhance their cybersecurity practices, potentially with financial support from the federal government or AI developers themselves.
Some experts suggest a re-evaluation of the push towards complete digitization, considering a return to more analog methods for managing critical systems, where human oversight and less manipulable interfaces were the norm. "The screen is the thing that is infinitely manipulatable," Bochman stated.
The exact extent of the vulnerability of U.S. infrastructure to AI-driven attacks remains unclear, partly because policymakers and AI creators themselves are still grappling with how to prevent the technology from acting maliciously or obeying harmful instructions. In the interim, some suggest that taking critical systems offline may be a necessary measure to shield them from potential misuse by AI and malicious actors.