AI’s Impact on Software Security: Rethinking the Cost of Attacks
In the evolving landscape of cybersecurity, the fundamental economics of software protection is being challenged. Ansgar Dodt, the Vice President of Product Management for Software Monetization at Thales, elaborates on how advancements in artificial intelligence (AI) are transforming the way software attacks are conducted, shifting the dynamics of security for software vendors.
Historically, not all software has been deemed worthy of attack. The time, expertise, and resources needed to reverse engineer applications provided a considerable barrier to would-be attackers. This cap on accessibility meant that many lesser-known or lower-value software products remained relatively safe. However, the advent of AI is changing this calculation significantly. No longer are potential attackers deterred by the daunting initial investments of time and skills; AI shifts the balance dramatically, enabling a wider range of software to come under scrutiny.
AI-driven security incidents from notable organizations like OpenAI and Anthropic showcase this shift as a systematic trend rather than an isolated event. While discussions surrounding AI in cybersecurity have primarily focused on how it enhances the speed and sophistication of attacks, it is witnessing a monumental economic shift. The reduction of time and human effort needed to pinpoint and exploit vulnerabilities expands the attack surface, making it a rich hunting ground for cyber adversaries.
The Shift in Target Selection
As attackers leverage AI to assist in their endeavors, the capacity to meticulously select targets diminishes. Software that once seemed unlikely to merit extensive examination may now be investigated more thoroughly, as AI can automate much of the preliminary work. This shift means that attackers are not only focusing on high-profile, lucrative targets but can expend their resources on a broader array of applications.
AI’s capabilities are evolving, allowing it to interact effectively with decompilers, debuggers, and other security tools. It can analyze unfamiliar code and test various methods without needing constant human intervention. Therefore, attackers can explore alternate strategies if one path proves fruitless. While AI-driven tools do not eliminate the need for a skilled hacker, they do enable adversaries to canvass more potential targets simultaneously, thus increasing the risk for software vendors.
Dangers Beyond Vendor Control
Another critical aspect of software security arises when applications are distributed beyond a vendor’s control. Although cloud-native applications tend to remain within the controlled environments of their providers, desktop applications, on-premise installations, industrial equipment, and edge software present significant vulnerabilities. Once attackers obtain executable binaries, they have the luxury of time to dissect the software for vulnerabilities, proprietary algorithms, and privileged functionalities, among other things.
This dissection process can lead to serious repercussions beyond mere data breaches—intellectual property theft, operational disruptions, regulatory fines, and the erosion of customer trust become real threats. As automated analysis technology continues to evolve, software vendors must prepare for the high likelihood that their products will be subjected to AI-assisted reverse engineering once they leave the protection of the vendor’s infrastructure.
The Imperative of Proactive Security Measures
Despite the ever-evolving threat landscape, fundamental security practices remain essential. Secure development, thorough vulnerability testing, and rapid patch deployment are foundational to defending against cyber threats. However, vulnerabilities must first be identified before they can be addressed. With the rise of AI, defenders face intensified pressure to locate and rectify weaknesses before malicious actors can exploit them.
To effectively guard against evolving threats, patching must work in tandem with application protection. While patching addresses known vulnerabilities, application protection renders any remaining weaknesses more difficult to detect and exploit, thus fortifying the software further against potential breaches.
Enhancing Defensive Measures
The objective is not to render reverse engineering an impossible task but to complicate it for potential attackers. By layering protection mechanisms, software vendors can obscure how their systems function, thereby complicating analysis, alteration, or reproduction efforts.
Techniques that obscure code and data, in conjunction with measures to detect tampering, create formidable barriers for attackers. The combined effect is cumulative—each new layer requires greater investments of time and computational resources from attackers. Thales recently illustrated this principle through a practical test. An autonomous AI reverse-engineering agent analyzed two iterations of the same application, each containing vulnerabilities. In a direct comparison, the unprotected binary revealed eight vulnerabilities in roughly three minutes, while the protected version frustrated the AI’s attempts for over six hours, consuming a staggering 970 times more resources without yielding actionable information.
Such measures not only complicate breach attempts but also provide vendors with precious time to identify vulnerabilities, develop patches, and deploy updates before malicious exploitation can occur at scale.
Rethinking the Economic Equation for Attackers
AI’s ongoing refinement obliterates historical constraints on software attacks. Organizations may struggle to dictate the pace at which AI capabilities advance or to whom they are distributed. However, they can mitigate risks by making their software less attractive and hence more resource-intensive for attackers. While eliminating vulnerabilities remains a priority, it is equally vital to increase the time, effort, and resources required to uncover and exploit the remaining flaws.
As attackers become equipped to explore a broader array of software targets, making applications a costly endeavor to breach emerges as a viable defensive strategy. By calculating the risks effectively, organizations can fortify themselves against the imminent realities posed by an increasingly sophisticated threat landscape.
This profound evolution in software security underscores the necessity for vendors to adapt continually, ensuring that their defensive strategies are as dynamic and progressive as the threats they seek to thwart.

