Cybersecurity breakthroughs: how AI uncovers flaws in encryption algorithms

Cybersecurity breakthroughs: how AI uncovers flaws in encryption algorithms

New breakthroughs in cybersecurity reveal vulnerabilities in encryption algorithms used worldwide — but experts urge calm as immediate threats remain minimal.

AI’s Role in Uncovering Cryptographic Weaknesses

A recent study by Anthropic’s Frontier Red Team has shed light on previously unknown vulnerabilities in two encryption algorithms: HAWK, a post-quantum digital signature scheme, and a reduced version of AES, a widely used symmetric encryption standard. While these discoveries are significant, they do not pose immediate risks to current systems, though they underscore the evolving challenges in cryptographic security.

The findings were made possible through the use of an internal preview version of Mythos, an AI model developed by Anthropic. This model was tasked with identifying potential flaws in HAWK and AES, leading to surprising results that highlight both the potential and limitations of AI in cryptographic research.

HAWK’s Post-Quantum Promise Diminished by AI-Driven Attack

HAWK was a strong contender in the NIST’s post-quantum cryptography standardization process, designed to withstand attacks from quantum computers. However, Mythos identified a critical weakness by exploiting a geometric symmetry in the algorithm’s underlying lattice problem. This breakthrough reduced the complexity of breaking HAWK from 2⁶⁴ to 2³⁸ operations, making it vulnerable to practical attacks.

The consequences for HAWK are clear: its developers have withdrawn the algorithm from the NIST selection process, as it can no longer be considered secure. This incident serves as a reminder of the fragility of cryptographic schemes in the face of advanced computational techniques.

AES Under the Microscope: A Reduced Version Falls Short

AES, or Advanced Encryption Standard, is a cornerstone of modern cryptography, used extensively in banking, secure communications, and data protection. While the full AES algorithm remains secure, the study focused on a reduced version with only 7 rounds instead of the standard 10. Mythos discovered a novel attack method called the Möbius Bridge, which accelerated existing attacks by a factor of 200 to 800.

This theoretical vulnerability, however, does not affect the standard AES-128 or AES-256 implementations. The additional rounds in the full algorithm provide sufficient protection against such attacks, ensuring that AES remains a reliable choice for secure communications.

AI’s Growing Impact on Cryptographic Research

The use of AI in cryptographic research is not just a theoretical exercise. Anthropic’s study required approximately 60 hours of compute time and cost around $100,000 in API fees. The AI model initially resisted the task, suggesting that no improvements could be made to such a well-established algorithm. However, after refining the approach, the model generated approximately a billion tokens over several days to devise the new attack method.

This highlights a critical shift in cryptographic research: the bottleneck is no longer the ability to find vulnerabilities but the human capacity to validate and verify the results produced by AI. The validation process alone took about a month for two researchers, demonstrating the complexity and rigor required in cryptographic analysis.

Reflecting on the Broader Implications

While the immediate impact of these discoveries is limited, they serve as a wake-up call for the cybersecurity community. The rapid pace at which AI is uncovering vulnerabilities means that traditional processes for triaging, verifying, and mitigating flaws are struggling to keep up. This is evident in the increasing number of security patches and updates across major software platforms like Firefox, Windows, and Apple systems.

The study also raises questions about the future of cryptographic research. If AI models can discover flaws in well-established algorithms, what does this mean for the next generation of encryption standards? The cryptographic community must adapt to this new reality, balancing the speed of AI-driven discoveries with the rigor of human validation.

Anthropic has indicated that more findings are on the horizon, suggesting that this is just the beginning of a new era in cryptographic research. As AI continues to play a larger role, the cybersecurity landscape will undoubtedly evolve, presenting both challenges and opportunities for researchers and practitioners alike.

theafricantribune