From ChatGPT to ThreatGPT: Impact of Generative AI in Cybersecurity and Privacy

Undoubtedly, the evolution of Generative AI (GenAI) models has been the highlight of digital transformation in the year 2022. As the different GenAI models like ChatGPT and Google Bard continue to foster their complexity and capability, it’s critical to understand its consequences from a...

Full description

Bibliographic Details
Main Authors: Maanak Gupta, Charankumar Akiri, Kshitiz Aryal, Eli Parker, Lopamudra Praharaj
Format: Article
Language:English
Published: IEEE 2023-01-01
Series:IEEE Access
Subjects:
Online Access:https://ieeexplore.ieee.org/document/10198233/
_version_ 1797746127066365952
author Maanak Gupta
Charankumar Akiri
Kshitiz Aryal
Eli Parker
Lopamudra Praharaj
author_facet Maanak Gupta
Charankumar Akiri
Kshitiz Aryal
Eli Parker
Lopamudra Praharaj
author_sort Maanak Gupta
collection DOAJ
description Undoubtedly, the evolution of Generative AI (GenAI) models has been the highlight of digital transformation in the year 2022. As the different GenAI models like ChatGPT and Google Bard continue to foster their complexity and capability, it’s critical to understand its consequences from a cybersecurity perspective. Several instances recently have demonstrated the use of GenAI tools in both the defensive and offensive side of cybersecurity, and focusing on the social, ethical and privacy implications this technology possesses. This research paper highlights the limitations, challenges, potential risks, and opportunities of GenAI in the domain of cybersecurity and privacy. The work presents the vulnerabilities of ChatGPT, which can be exploited by malicious users to exfiltrate malicious information bypassing the ethical constraints on the model. This paper demonstrates successful example attacks like Jailbreaks, reverse psychology, and prompt injection attacks on the ChatGPT. The paper also investigates how cyber offenders can use the GenAI tools in developing cyber attacks, and explore the scenarios where ChatGPT can be used by adversaries to create social engineering attacks, phishing attacks, automated hacking, attack payload generation, malware creation, and polymorphic malware. This paper then examines defense techniques and uses GenAI tools to improve security measures, including cyber defense automation, reporting, threat intelligence, secure code generation and detection, attack identification, developing ethical guidelines, incidence response plans, and malware detection. We will also discuss the social, legal, and ethical implications of ChatGPT. In conclusion, the paper highlights open challenges and future directions to make this GenAI secure, safe, trustworthy, and ethical as the community understands its cybersecurity impacts.
first_indexed 2024-03-12T15:32:37Z
format Article
id doaj.art-94b115387cad4222ab2dce65dbb01b96
institution Directory Open Access Journal
issn 2169-3536
language English
last_indexed 2024-03-12T15:32:37Z
publishDate 2023-01-01
publisher IEEE
record_format Article
series IEEE Access
spelling doaj.art-94b115387cad4222ab2dce65dbb01b962023-08-09T23:00:19ZengIEEEIEEE Access2169-35362023-01-0111802188024510.1109/ACCESS.2023.330038110198233From ChatGPT to ThreatGPT: Impact of Generative AI in Cybersecurity and PrivacyMaanak Gupta0https://orcid.org/0000-0001-9189-2478Charankumar Akiri1Kshitiz Aryal2Eli Parker3Lopamudra Praharaj4Department of Computer Science, Tennessee Tech University, Cookeville, TN, USADepartment of Computer Science, Tennessee Tech University, Cookeville, TN, USADepartment of Computer Science, Tennessee Tech University, Cookeville, TN, USADepartment of Computer Science, Tennessee Tech University, Cookeville, TN, USADepartment of Computer Science, Tennessee Tech University, Cookeville, TN, USAUndoubtedly, the evolution of Generative AI (GenAI) models has been the highlight of digital transformation in the year 2022. As the different GenAI models like ChatGPT and Google Bard continue to foster their complexity and capability, it’s critical to understand its consequences from a cybersecurity perspective. Several instances recently have demonstrated the use of GenAI tools in both the defensive and offensive side of cybersecurity, and focusing on the social, ethical and privacy implications this technology possesses. This research paper highlights the limitations, challenges, potential risks, and opportunities of GenAI in the domain of cybersecurity and privacy. The work presents the vulnerabilities of ChatGPT, which can be exploited by malicious users to exfiltrate malicious information bypassing the ethical constraints on the model. This paper demonstrates successful example attacks like Jailbreaks, reverse psychology, and prompt injection attacks on the ChatGPT. The paper also investigates how cyber offenders can use the GenAI tools in developing cyber attacks, and explore the scenarios where ChatGPT can be used by adversaries to create social engineering attacks, phishing attacks, automated hacking, attack payload generation, malware creation, and polymorphic malware. This paper then examines defense techniques and uses GenAI tools to improve security measures, including cyber defense automation, reporting, threat intelligence, secure code generation and detection, attack identification, developing ethical guidelines, incidence response plans, and malware detection. We will also discuss the social, legal, and ethical implications of ChatGPT. In conclusion, the paper highlights open challenges and future directions to make this GenAI secure, safe, trustworthy, and ethical as the community understands its cybersecurity impacts.https://ieeexplore.ieee.org/document/10198233/Generative AIGenAI and cybersecurityChatGPTGoogle bardcyber offensecyber defense
spellingShingle Maanak Gupta
Charankumar Akiri
Kshitiz Aryal
Eli Parker
Lopamudra Praharaj
From ChatGPT to ThreatGPT: Impact of Generative AI in Cybersecurity and Privacy
IEEE Access
Generative AI
GenAI and cybersecurity
ChatGPT
Google bard
cyber offense
cyber defense
title From ChatGPT to ThreatGPT: Impact of Generative AI in Cybersecurity and Privacy
title_full From ChatGPT to ThreatGPT: Impact of Generative AI in Cybersecurity and Privacy
title_fullStr From ChatGPT to ThreatGPT: Impact of Generative AI in Cybersecurity and Privacy
title_full_unstemmed From ChatGPT to ThreatGPT: Impact of Generative AI in Cybersecurity and Privacy
title_short From ChatGPT to ThreatGPT: Impact of Generative AI in Cybersecurity and Privacy
title_sort from chatgpt to threatgpt impact of generative ai in cybersecurity and privacy
topic Generative AI
GenAI and cybersecurity
ChatGPT
Google bard
cyber offense
cyber defense
url https://ieeexplore.ieee.org/document/10198233/
work_keys_str_mv AT maanakgupta fromchatgpttothreatgptimpactofgenerativeaiincybersecurityandprivacy
AT charankumarakiri fromchatgpttothreatgptimpactofgenerativeaiincybersecurityandprivacy
AT kshitizaryal fromchatgpttothreatgptimpactofgenerativeaiincybersecurityandprivacy
AT eliparker fromchatgpttothreatgptimpactofgenerativeaiincybersecurityandprivacy
AT lopamudrapraharaj fromchatgpttothreatgptimpactofgenerativeaiincybersecurityandprivacy