HomeMalware & ThreatsAI-Driven Stress Tests Reveal Flaws in Cryptographic Systems

AI-Driven Stress Tests Reveal Flaws in Cryptographic Systems

Published on

spot_img

Artificial Intelligence & Machine Learning,
Encryption & Key Management,
Governance & Risk Management

Cryptographers Welcome LLM-Driven Results, Including to Test Quantum-Safe Crypto

AI-Driven Stress Tests Reveal Flaws in Cryptographic Systems
Researchers discovered working attacks against two cryptographic algorithms using Anthropic’s Claude LLM. No real-world systems are at risk, and cryptographers say the LLM-driven stress testing is needed for quantum-safe cryptography. (Image: Shutterstock)

In a recent development highlighting the rapid evolution of large language models (LLMs), researchers have successfully utilized Anthropic’s Claude LLM to identify practical vulnerabilities in two significant cryptographic algorithms. This breakthrough is indicative of how LLMs are becoming invaluable tools in the ongoing quest for enhanced cryptographic security.

Specifically, the researchers achieved a more efficient method of attacking HAWK, a contender for post-quantum digital signatures currently under evaluation by the U.S. National Institute of Standards and Technology (NIST). Additionally, they illustrated a technique that allows attackers to compromise a weakened version of the Advanced Encryption Standard (AES) at speeds up to 800 times faster than previously possible.

Alan Woodward, a computer science professor at the University of Surrey in England, remarked on these findings, advising against immediate alarm. “Before you panic, it’s not going to render everything useless overnight,” he cautioned. Woodward emphasized that the results could provide invaluable insights into both new cryptographic candidates and established algorithms, contributing positively to the field.

Anthropic itself reinforced that while the outcomes of these LLM-driven stress tests are noteworthy, they do not pose a real threat to existing systems. “To be clear, neither of these results has a practical impact on today’s computer systems; no production software will have to change as a result,” the company stated in a blog post that accompanied the research announcement.

The company further clarified that HAWK is merely a candidate signature scheme, not yet deployed in real-world applications, and that the attack on AES affects a reduced version rather than the full cipher. “Nevertheless, both results show the potential for frontier AI models to help discover flaws in important cryptographic algorithms, both before and after real-world deployment,” the blog post continued.

Collaborating with institutions like ETH Zurich, Tel Aviv University, and TU Berlin, Anthropic has developed a tool called CryptanalysisBench. This tool aims to monitor the implications of AI-driven cryptanalysis, allowing researchers to stress-test cryptographic schemes pre-deployment and assess the robustness of already implemented security protocols.

Access to these sophisticated capabilities is relatively democratized. Notably, the researchers who uncovered the vulnerabilities in AES and HAWK were primarily computer scientists rather than specialized cryptographers, which underscores the LLM’s user-friendly interface.

Investigating AES Vulnerabilities

The Advanced Encryption Standard (AES) is pivotal in securing various digital communications, including Wi-Fi traffic and cloud storage solutions. It remains a focal point for cryptanalysis due to its widespread application. Researchers often analyze a deliberately weakened version of AES to seek potential attack methodologies.

The CLAUDE-found attack could not be effectively utilized against the non-weakened versions of AES. Woodward assured, “It’s not panic time, but it shows a very interesting direction of travel.” The sheer complexity and size of these advanced LLMs, which now feature trillions of weights, imply they possess the computational power required to explore cryptographic vulnerabilities from less conventional angles.

The Path Ahead

It’s important to note that many modern ciphers have not undergone the rigorous scrutiny they warrant. This suggests there may be latent weaknesses awaiting discovery by LLMs in the future. The findings from Anthropic have received considerable attention and interest from the cryptographic community, with experts acknowledging the significance and implications of this research.

Technologist Bruce Schneier describes the initial results from the LLMs as “early” but emphasizes their potential, urging continued monitoring of their capabilities. Matthew D. Green, a cryptographer at Johns Hopkins University, expressed his thoughts on the findings, deeming them “sobering” due to the impressive results achieved by the LLMs and their substantial improvements since earlier, less effective versions.

This breakthrough engenders a timely development as the world increasingly adopts quantum-safe cryptography. Green underscores that the emergence of LLM-driven cryptanalysis resources is optimally timed alongside a seismic shift in public-key cryptography. Additionally, the low personnel requirements for conducting such research is a notable advantage, as exemplified by the relatively brief commitment needed by researchers from Anthropic to execute these intricate attacks.

Despite the promise shown by these AI models, they still face challenges regarding verification. Existing models can produce erroneous results that require extensive scrutiny by experts, creating additional hurdles in the practical deployment of these capabilities.

Furthermore, while the expenses associated with these attacks are considerable (approximately $100,000 each using Claude tokens), they remain within the reach of certain governmental and organizational bodies, prompting the potential for increased interest from those with the appropriate resources.

Source link

Latest articles

Data Loss Risks in Microsoft 365 Migration and Prevention Strategies

Preventing Data Loss in Microsoft 365 Migration In the realm of digital transformation, migrating to...

Ransomware Report: VPNs Targeted and AI Attacks

In a comprehensive report released by Comparitech, government entities have come under siege with...

Top 10 Security Configuration Assessment Tools for 2026

In the intricate digital environment of 2026, organizations recognize that a robust cybersecurity posture...

LogoKit Phishing Kit: Real-Time Screenshots of Victim Sites

New Phishing-as-a-Service Platform Innovates with Real-Time Deception Tactics In a groundbreaking development within the realm...

More like this

Data Loss Risks in Microsoft 365 Migration and Prevention Strategies

Preventing Data Loss in Microsoft 365 Migration In the realm of digital transformation, migrating to...

Ransomware Report: VPNs Targeted and AI Attacks

In a comprehensive report released by Comparitech, government entities have come under siege with...

Top 10 Security Configuration Assessment Tools for 2026

In the intricate digital environment of 2026, organizations recognize that a robust cybersecurity posture...