Pacific Northwest national lab unveils generative Artificial Intelligence cyber defense tool

Scientists at Pacific Northwest National Laboratory have developed a generative Artificial Intelligence system called Aloha that can rapidly simulate and adapt cyberattacks, offering defenders a faster way to reconstruct and test intrusions. The project highlights how U.S. national labs are turning years of classified Artificial Intelligence cyber research into practical defensive tools.

Scientists at Pacific Northwest National Laboratory in Washington state have built a generative Artificial Intelligence powered system, known as Aloha, that is designed to let cyber defenders quickly simulate the attacks targeting their organizations. National laboratories such as Los Alamos, Sandia and Lawrence Livermore have long driven some of the biggest and least publicized advances in cyberspace, and the decision to talk about Aloha signals that the U.S. government is likely further along in countering adversarial Artificial Intelligence attacks than it publicly reveals. Reconstructing an attack chain is a central part of incident response, since defenders must retrace an intruder’s steps to see how they entered and which vulnerabilities need to be fixed.

The PNNL team built Aloha by combining Anthropic’s Claude with MITRE’s open source Caldera attack simulation platform. A security analyst begins by entering a plain language description of a real or hypothetical attack, including what happened across their systems, and the Artificial Intelligence system, powered by Claude, then generates a detailed representation of the attack’s sequences from its own knowledge base, expanding the description into an executable play by play. Caldera uses those steps to run a simulation in a contained environment against a test network, which emulates how the attack would unfold under different conditions, while Aloha watches the simulation in real time, evaluates each step, and determines whether the intended effect was achieved. If the simulation stalls, Aloha can automatically adjust the next action to keep it progressing, and the analyst can repeatedly tweak defensive conditions and replay the scenario until the results are acceptable.

According to PNNL’s Loc Truong, the new tool compresses what has traditionally been weeks of manual scripting and expert work into a largely automated workflow, speeding up defenders’ responses so that cybersecurity experts do not have to execute as many operations themselves and making the process closer to “click and go.” By lowering the expertise and budget required to run attack emulation, Aloha could open advanced testing to more organizations at a time when both security teams and malicious actors are leaning heavily on Artificial Intelligence. Anthropic reported evidence that Chinese state sponsored hackers used Claude to break into about 30 global organizations, ransomware gangs are steadily automating their kill chains, and at last year’s DEF CON Capture the Flag competition nearly every team relied on Artificial Intelligence support. PNNL researcher Kristopher Willis said the lab is now working from recent DARPA findings at DEF CON to evolve Aloha so it can automatically test newly discovered vulnerabilities, assess their severity, translate proofs of vulnerabilities into proofs of concept, and help create or validate remediation steps.

58

Impact Score

Executives see limited Artificial Intelligence productivity gains so far

Corporate enthusiasm around Artificial Intelligence has yet to translate into broad gains in employment or productivity, reviving comparisons to the long lag between early computing breakthroughs and measurable economic impact. Recent surveys and studies show mixed results, with strong expectations for future benefits but little consensus on present gains.

Nvidia skips a new GeForce generation as Artificial Intelligence chips dominate

Nvidia is set to go a year without a new GeForce GPU generation for the first time since the 1990s as memory shortages and higher margins in Artificial Intelligence hardware reshape the market. AMD and Intel are also struggling to capitalize because the same supply constraints are hitting gaming products across the industry.

Where gpu debt starts to break

Stress in gpu-backed infrastructure financing is emerging around deals that lack the structural protections seen in the strongest transactions. Oracle, the Abilene Stargate project, and older CoreWeave debt illustrate different ways residual risk can surface when contracts, collateral, and counterparties fall short.

SK hynix starts mass production of 192 GB SOCAMM2

SK hynix has begun mass production of the 192 GB SOCAMM2, a next-generation memory module standard built on 1cnm LPDDR5X low-power DRAM. The module is positioned as a primary memory solution for next-generation Artificial Intelligence servers.

AMD taps GlobalFoundries for co-packaged optics in Instinct MI500

AMD is preparing a renewed manufacturing link with GlobalFoundries to bring co-packaged optics to its Instinct MI500 Artificial Intelligence accelerators. The move is aimed at improving bandwidth and power efficiency in data center systems by moving beyond copper-based interconnects.

Contact Us

Got questions? Use the form to contact us.

Contact Form

Clicking next sends a verification code to your email. After verifying, you can enter your message.