AI Security: The Risks of Multi-Turn Attacks on Models

Recent findings reveal that multi-turn attacks on AI models have a staggering success rate of 88.3%. This article explores the implications for organizations relying on AI and how they can strengthen their security measures.

0
AI Security: The Risks of Multi-Turn Attacks on Models

As artificial intelligence (AI) becomes increasingly integrated into business operations, the security of these models has come under scrutiny. A recent study conducted by Cisco revealed alarming statistics about the vulnerability of AI systems to multi-turn attacks, where attackers adapt their strategies over the course of a conversation. With a staggering success rate of 88.3%, these attacks represent a significant threat to organizations that rely on AI for critical functions. As businesses grapple with the implications of these findings, understanding the nature of these attacks and implementing robust security measures is essential.

Amy Chang, Cisco's head of AI threat intelligence, presented these findings during the VB Transform 2026 conference, highlighting a gap in the current security practices employed by many organizations. The results of the study serve as a wake-up call, especially for those still relying on single-turn red teaming, which fails to capture the dynamic and evolving nature of real-world interactions with AI. In this article, we'll delve deeper into the study's findings, the challenges organizations face, and the strategies they can adopt to enhance their AI security.

cybersecurity conference

Understanding Multi-Turn Attacks

Multi-turn attacks are characterized by their complexity and adaptability. Unlike single-turn attacks, which involve a straightforward input to an AI model, multi-turn attacks simulate a more realistic dialogue that can exploit vulnerabilities over time. Cisco's study analyzed 15 flagship AI models through 6,986 multi-turn attacks and 30,090 single-turn prompts, revealing that every model tested exhibited non-trivial exposure to multi-turn attacks.

The Mechanics of Multi-Turn Attacks

Attackers engaging in multi-turn scenarios can adjust their tactics based on the AI's responses, allowing them to bypass defenses that a single-shot prompt might not exploit. This iterative process mirrors how users interact with AI, making it a genuine reflection of real-world usage. The findings emphasize that organizations must understand how their AI models can be compromised in a conversation, as failing to do so leaves them vulnerable to sophisticated threats.

AI model interaction

The Current State of AI Security Practices

Despite the clear risks, many organizations are lagging in implementing comprehensive security measures for their AI systems. According to a survey by VentureBeat, over 54% of enterprise respondents have already experienced an AI-related security incident, while 32% of organizations provide each AI agent with a scoped, managed identity. Furthermore, only 30% isolate high-risk agents in sandbox environments, a crucial step in mitigating potential damage from attacks.

Challenges in AI Security

  • Identity Management: Many enterprises struggle with adequately managing the identities of their AI agents, which increases the risk of unauthorized access and exploitation.
  • Sandboxing: The lack of sandbox environments limits organizations' ability to test AI agents in controlled settings, making it difficult to evaluate their security posture.
  • Reactive Measures: Most companies rely on provider-native and hyperscaler controls, which may not be sufficient for the unique challenges presented by AI systems.
cybersecurity measures

Strategies for Enhancing AI Security

To combat the risks associated with multi-turn attacks, organizations must adopt a proactive and layered approach to AI security. Chang and other industry experts recommend several strategies that can help strengthen defenses:

1. Implementing Integrated Security Frameworks

Cisco advocates for the use of its Integrated AI Security and Safety Framework, which outlines various ways AI can be compromised throughout its lifecycle. Organizations should utilize this framework to trace real incidents, understand how attacks occurred, and develop comprehensive security strategies.

2. Adopting Multi-Turn Red Teaming

Companies should transition from single-turn red teaming to multi-turn red teaming exercises to simulate realistic attack scenarios. This approach allows organizations to identify vulnerabilities that may not be evident during one-off testing.

3. Establishing Permissioning Protocols

As emphasized by Heather Ceylan, CISO of Box, setting up permissioning protocols is critical. Agents should only have access to the data and functionalities necessary for their tasks, minimizing the risk of malicious exploitation. Actions should be categorized by sensitivity, with more sensitive tasks requiring human oversight.

4. Leveraging Centralized Platforms

Companies like Intuit are developing centralized platforms, such as GenOS, that abstract security and risk management. This allows developers to focus on creating AI functionalities while ensuring built-in security measures are consistently applied across all agents.

Key Takeaways

  • Multi-turn attacks on AI models have an alarming success rate of 88.3%, highlighting significant security vulnerabilities.
  • Many organizations are ill-prepared for the complexities of multi-turn interactions, with inadequate identity management and sandboxing practices.
  • Adopting integrated security frameworks, multi-turn red teaming, and stringent permissioning protocols can help mitigate risks.
  • Centralized security platforms can streamline the development process while ensuring robust security measures are applied consistently.
cybersecurity strategy

Frequently Asked Questions

What are multi-turn attacks and why are they more dangerous than single-turn attacks?

Multi-turn attacks involve a series of interactions with an AI model, allowing attackers to adapt their strategies based on the model's responses. This iterative process mirrors real user interactions, making it more challenging to detect and defend against compared to single-turn attacks, which are one-off inputs that may not exploit vulnerabilities effectively.

How can organizations assess their vulnerability to multi-turn attacks?

Organizations can assess their vulnerability by conducting multi-turn red teaming exercises that simulate realistic attack scenarios. By analyzing how their AI models respond to these scenarios, companies can identify weaknesses and implement necessary defenses. Additionally, adopting frameworks that outline potential attack vectors can help organizations understand their exposure.

What does effective AI security look like?

Effective AI security encompasses a layered approach that includes identity management, permissioning protocols, centralized security platforms, and ongoing monitoring. Organizations should prioritize building robust security frameworks that account for the unique challenges presented by AI systems, ensuring that all agents operate within clearly defined boundaries to minimize risk.

Why is it essential for organizations to evolve their AI security practices?

As AI technology continues to evolve, so do the tactics employed by malicious actors. Organizations must stay ahead of these threats by evolving their security practices to address emerging challenges, such as multi-turn attacks. Failing to do so can result in significant operational and reputational damage, making it crucial for businesses to prioritize AI security as part of their overall risk management strategy.

Comments

Read next

Bridging the Agent Security Gap: AI Incidents on the Rise

A significant number of enterprises are facing security incidents involving AI agents. Despite this, many organizations lack the necessary controls to mitigate these risks, raising serious concerns about the future of AI security.

Bridging the Agent Security Gap: AI Incidents on the Rise

Related articles