Who are we?

The Cyber Autonomy Initiative is a research initiative focused on creating the scientific foundations of autonomous cybersecurity, hosted by researchers at Carnegie Mellon University.

What do we do?

Our work aligns with four primary research thrusts:

1. Algorithmic Foundations.

Objective: Establish foundational algorithmic techniques for autonomous cyber offense and defense.

Today, the design, development, and evaluation of novel attack and defense systems is difficult because they are comprised of low-level tools. We need higher-level system design, algorithmic strategy, and analytics abstractions to accelerate the design, implementation, and evaluation of future autonomous attack and defense capabilities. We also envision novel security-focused AI capabilities based on foundation models, in-context learning, reinforcement learning, and game theory.

2. System-Level Support.

Objective: Contribute systems advances and experimental work to inform the autonomous operations envisioned above.

To handle the rapidly shifting frontier of autonomous cybersecurity, we need practical tools that can support cyber operations in settings of all shapes and sizes. The Cyber Autonomy Initiative provides open-source systems and datasets for emulation and model training, sandboxing and system verification, scalable telemetry and log analytics toolkits, and novel software-defined data-plane and control-plane capabilities.

3. Human-AI Collaboration.

Objective: Improve human interpretability and usability of autonomous cybersecurity systems.

As attack and defense become increasingly autonomous, we need to develop a better understanding of the real-world constraints on operators in order to design better systems that they will trust and deploy. The Cyber Autonomy Initiative explores several aspects of Human-AI collaboration in an autonomous world, including understanding and debugging attack & defense systems, and Human-AI collaborative penetration testing.

4. High-Fidelity Evaluation.

Objective: Evaluate and understand the behavior of autonomous cybersecurity systems in realistic settings.

Autonomous attack and defense systems, especially those utilizing LLMs, can behave in diverse and unpredictable ways. To shed light on the competitive interplay between autonomous attack and defense systems, the Cyber Autonomy Initiative runs real, system-level competitive evaluations of attackers versus defenders in high-fidelity network settings.