Home / Current Issue / Paper 1710353
Artificial Intelligence in Offensive and Defensive Cybersecurity: Opportunities, Risks, and Ethical Boundaries
Subject area: Science,Engineering and Technology · Area of research: Cybersecurity
Abstract
Artificial Intelligence (AI) has become a transformative force in cybersecurity, offering powerful capabilities for threat detection, anomaly recognition, and predictive defense, while also exhibiting a dual-use nature that makes it equally capable of being leveraged for offensive cyber operations. It can greatly enhance digital resilience through advanced defense mechanisms. At the same time, the very same technology can be exploited for offensive purposes, such as adversarial attacks, deepfake-enabled fraud, and automated intrusions. This paper critically examines the opportunities, risks, and ethical dilemmas posed by AI in cybersecurity, drawing on both academic literature and recent case studies, including deepfake fraud incidents and empirical insights. The discussion highlights key risks and ethical challenges, including algorithmic bias, transparency gaps in explainability, the dual-use dilemma of AI in penetration testing, and governance voids stemming from the absence of harmonized global standards. The case studies illustrate both offensive and defensive deployments, emphasizing the urgency for governance and ethical frameworks that operationalize fairness, accountability, and transparency within AI systems. The analysis integrates policy insights from compliance frameworks such as NIST, ISO, and GDPR, positioning them as anchors for building trustworthy AI ecosystems. The paper concludes that while AI should not be regarded as a panacea for cybersecurity, it is an indispensable evolving tool that requires responsible deployment, human-in-the-loop oversight, and collaborative governance to ensure resilience. The proposed research roadmap identifies explainable AI, AI forensics, and cross-sector collaborations as priority areas for advancing both academic and industry understanding. The paper positions AI as both an asset and a liability, providing a balanced foundation for future governance models that safeguard innovation while mitigating systemic risks.
Keywords
Artificial Intelligence, Cybersecurity, Dual-Use Dilemma, Algorithmic Bias, Governance, Ethical Frameworks, Explainable AI, AI Forensics, Compliance (NIST, ISO, GDPR)
References
[1] Aaron, David & John, Ada & Racheal, Jonathan & Richard, Jane. (2025). Leveraging Machine Learning for Anomaly Detection and Proactive Threat Intelligence in Cloud BI Data Access Patterns.
[2] Ailyn, Diana. (2024). Explainability and Interpretability in Deep Learning Models.
[3] Ajakaye Oluwabiyi Oluwawapelumi. (2025). The Cyber Ai Arms Race: The Future Of Ai In Cybersecurity Offense And Defense. International Research Journal of Modernization in Engineering Technology and Science,Volume:07/Issue:04. https://www.
[4] Alexander, Alina, (2025). The New Identity Theft: Deepfakes and the Rise of Synthetic Impersonation Scams Available at SSRN: https://ssrn.com/abstract=5368947
[5] Almansoori, Mohamed. (2024). "AI-Driven Anomaly Detection in Cybersecurity". Thesis. Rochester Institute of Technology. Accessed from https://repository.rit.edu/cgi/viewcontent.cgi?art icle=13138&context=theses
[6] Anderson, Michael & Rahman, Sadia & Tanaka, Hiroshi & Dominguez, Carlos & Yue, Lin & James, Andrew & Mohammed, Faisal. (2025). AI-Based Detection of Polymorphic Malware.
[7] Atlam, H. F. (2025). LLMs in Cyber Security: Bridging Practice and Education. Big Data and Cognitive Computing, 9(7), 184. https://
[8] Avhankar, Madhavi & Pawar, Janardan & Kumbhar, Vijaya. (2025). A Comprehensive Survey on Polymorphic Malware Analysis: Challenges, Techniques, and Future Directions. Communications on Applied Nonlinear Analysis. 34. 2765 -2776. 10.52783/cana.v32.4554.
[9] Balogh, Š., Mlynček, M., Vraňák, O., & Zajac, P. (2024). Using Generative AI Models to Support Cybersecurity Analysts. Electronics, 13(23), 4718. https://
[10] Batool, A., Zowghi, D. & Bano, M.(2025). AI governance: a systematic literature review. AI Ethics 5, 3265 –3279 (2025). https://
[11] Berrios, S., Leiva, D., Olivares, B., Allende- Cid, H., & Hermosilla, P. (2025). Systematic Review: Malware Detection and Classification in Cybersecurity. Applied Sciences, 15(14), 7747. https://
[12] Blessing, Moses. (2024). Predictive analytics in cybersecurity: Identifying and preventing threats.
[13] Brenneis, A. (2024). Assessing dual use risks in AI research: necessity, challenges and mitigation strategies. Research Ethics, 21(2), 302-330. https:// (Original work published 2025)
[15] Business Research Company. (2025). Artificial intelligence in cybersecurity global market report 2025. https://www.thebusinessresearchcompany.com/r eport/artificial-intelligence-in-cybersecurity- global-market-report
[16] Chauhan, M., & Shiaeles, S. (2023). An Analysis of Cloud Security Frameworks, Problems and Proposed Solutions. Network, 3(3), 422 -450. https://
[17] Chukwujekwu, Damian & Ikemefuna, Damian & Orekha, Precious. (2024). International Journal of Research Publication and Reviews Predictive Cyber Defense: Harnessing AI and ML for Anticipatory Threat Mitigation. 3122- 3132.
[18] Clarity. (2024). $25M deepfake CEO scam shakes Hong Kong firm. https://www.getclarity.ai/ai-deepfake-blog/25m- deepfake-ceo-scam-shakes-hong-kong-firm
[19] CNN. (2024). Finance worker pays out $25 million after video call with deepfake ‘chief financial officer’. https://edition.cnn.com/2024/02/04/asia/deepfak e-cfo-scam-hong-kong-intl-hnk
[20] CyberProof. (n.d.). Google Chronicle and its usage of AI in SecOps. CyberProof. https://www.cyberproof.com/siem/google- chronicle-and-its-usage-of-ai-in-secops/
[21] Danilo Ribeiro, Thayssa Rocha, Gustavo Pinto, Bruno Cartaxo, Marcelo Amaral, Nicole Davila, Ana Camargo. (2025). Toward Effective AI Governance: A Review of Principles https://arxiv.org/abs/2505.23417
[22] EC-Council University. (2025). Generative AI in cybercrime: A new era of deepfakes, phishing, and social engineering. EC-Council University. https://www.eccu.edu/blog/generative-ai-in- cybercrime-a-new-era-of-deepfakes-phishing- and-social-engineering
[23] Edris, E. K. K. (2025). Utilisation of Artificial Intelligence and Cybersecurity Capabilities: A Symbiotic Relationship for Enhanced Security and Applicability. Electronics, 14(10), 2057. https://
[24] Ejjami, Rachid. (2024). Enhancing Cybersecurity through Artificial Intelligence: Techniques, Applications, and Future Perspectives. Journal of Next-Generation Research 5 0. 1. 10.70792/jngr5.0.v1i1.5.
[25] Ferrara, E. (2024). Fairness and Bias in Artificial Intelligence: A Brief Survey of Sources, Impacts, and Mitigation Strategies. Sci, 6(1), 3. https://
[26] Fredrik Heiding, Bruce Schneier, Arun Vishwanath, Jeremy Bernstein, Peter S. Park. (2023). Devising and Detecting Phishing: Large Language Models vs. Smaller Human Models. https://arxiv.org/abs/2308.12287
[27] Goel, P. K. (2024). Ethical Considerations in Implementing Artificial Intelligence in Cybersecurity: Balancing Security and Privacy Concerns. In M. Omar & H. Zangana (Eds.), Redefining Security With Cyber AI (pp. 73-92). IGI Global Scientific Publishing. https:// 5.ch005
[28] Gomez, A. (2024). Cybersecurity ethics: Everything you need to know. Our Lady of the Lake University. https://www.ollusa.edu/blog/cybersecurity- ethics.html
[29] Google Cloud. (2023). Introducing AI-powered investigation in Chronicle Security Operations. https://cloud.google.com/blog/products/identity- security/rsa-introducing-ai-powered- investigation-chronicle-security-operations
[30] Goswami, Maloy Jyoti. (2024). AI-Based Anomaly Detection for Real -Time Cybersecurity. 3006-1075.
[31] Hamdani, Syed Wasif Abbas & Abbas, Haider & Janjua, Abdul & Shahid, Waleed & Amjad, Muhammad & Malik, Jahanzaib & Murtaza, Malik & Atiquzzaman, Mohammed & Khan, Abdul. (2021). Cybersecurity Standards in the Context of Operating System: Practical Aspects, Analysis, and Comparisons. ACM Computing Surveys. 54. 1-36. 10.1145/3442480.
[32] Hernandez Felix. (2025). AI vs. AI: The Evolution of Offensive and Defensive AI Techniques in Cybersecurity.
[33] Ibrar, W., Mahmood, D., Al-Shamayleh, A.S. et al. (2025). Generative AI: a double-edged sword in the cyber threat landscape. Artif Intell Rev 58, 285 (2025). https:// 025-11285-9
[34] ICAEW Insights. (2025). How to guard against voice cloning and deepfake scams. ICAEW. https://www.icaew.com/insights/viewpoints-on- the-news/2025/jan-2025/how-to-guard-against- voice-cloning-and-deepfake-scams
[36] ISC2. (2025). 2025 AI Adoption Pulse Survey: Cybersecurity teams cautiously embrace AI tools. https://www.isc2.org/Insights/2025/07/2025- isc2-ai-pulse-survey
[37] Ismail, Kurnia, R., Brata, Z. A., Nelistiani, G. A., Heo, S., Kim, H., & Kim, H. (2025). Toward Robust Security Orchestration and Automated Response in Security Operations Centers with a Hyper-Automation Approach Using Agentic Artificial Intelligence. Information, 16(5), 365. https://
[38] Jampani, Siva Krishna. (2025). Social Engineering 2.0 Deepfake and Deep Learning- Based Cyber-Attacks (Phishing). International Journal For Multidisciplinary Research. 10.36948/ijfmr.2025.v07i01.35527.
[39] JPMorgan Chase. (2025). Global Security – Building Security Operations Center Lead. Built In NYC. https://www.builtinnyc.com/job/global-security- building-security-operations-center- lead/3710130
[40] Kemp, Matthew & Kalutarage, Harsha & Al- Kadri, M. Omar. (2025). AI -Powered Spearphishing Cyber Attacks: Fact or Fiction?. 10.48550/arXiv.2502.00961.
[41] Kevin Harrington. (2025). The Double-Edged Sword: How Cybercriminals Are Using AI to Launch More Sophisticated Attacks.
[42] Kharvi, Prakash. (2024). Understanding the Impact of AI-Generated Deepfakes on Public Opinion, Political Discourse, and Personal Security in Social Media. IEEE Security & Privacy. PP. 2 -9. 10.1109/MSEC.2024.3405963.
[43] Kinyua, Johnson & Awuah, Lawrence. (2021). AI/ML in Security Orchestration, Automation and Response: Future Research Directions. Intelligent Automation & Soft Computing. 28. 527-545. 10.32604/iasc.2021.016240.
[44] Klover. (2025). JPMorgan AI strategy: Chasing AI dominance. Klover. https://www.klover.ai/jpmorgan-ai-strategy- chasing-ai-dominance/
[45] Lee, Tim & Oladele, Sunday & Noah, Asher. (2025). The Application of Machine Learning and Natural Language Processing (NLP) in Automating Threat Intelligence Analysis and Dissemination for Enhanced Risk Management.
[46] Lupovici, A. (2021). The dual-use security dilemma and the social construction of insecurity. Contemporary Security Policy, 42(3), 257 –285. https://
[47] Maanak Gupta, CharanKumar Akiri, Kshitiz Aryal, Eli Parker, Lopamudra Praharaj. (2023). From ChatGPT to ThreatGPT: Impact of Generative AI in Cybersecurity and Privacy. https://arxiv.org/abs/2307.00691
[48] Madanchian Mitra, Hamed Taherdoost. (2025). Ethical theories, governance models, and strategic frameworks for responsible AI adoption and organizational success. Front. Artif. Intell.,Sec. AI in Business. Volume 8 - 2025 | https://
[49] Majumdar, Subhabrata & Pendleton, Brian & Gupta, Abhishek. (2025). Red Teaming AI Red Teaming. 10.48550/arXiv.2507.05538
[50] Marinho, Renato & Filho, Raimir. (2023). Automated Emerging Cyber Threat Identification and Profiling Based on Natural Language Processing. IEEE Access. PP. 1-1. 10.1109/ACCESS.2023.3260020.
[52] Mathavan, Arul Selvan. (2025). AI - AUGMENTED RED TEAMING: LEVERAGING EVOLUTIONARY ALGORITHMS IN PENETRATION TESTING METHODOLOGIES. 9. 1.
[53] Matthew G. Hanna, Liron Pantanowitz, Brian Jackson, Octavia Palmer, Shyam Visweswaran, Joshua Pantanowitz, Mustafa Deebajah, Hooman H. Rashidi. (2025). Ethical and Bias Considerations in Artificial Intelligence/Machine Learning. Modern Pathology, Volume 38, Issue 3, 100686, . https://
[54] Medium. (2024). Ethical AI in cybersecurity: Governance and accountability for autonomous cyber defense. https://medium.com/@RocketMeUpCybersecuri ty/ethical-ai-in-cybersecurity-governance-and- accountability-for-autonomous-cyber-defense- 420b7ae4d1bf
[55] Microsoft. (2024). Red Team: Microsoft poses as hackers to test AI vulnerabilities. Microsoft News Center CEE. https://news.microsoft.com/en- cee/2024/07/06/red-team-microsoft-poses-as- hackers-to-test-ai-vulnerabilities
[56] Mohamed, N. (2025). Artificial intelligence and machine learning in cybersecurity: a deep dive into state-of-the-art techniques and future paradigms. Knowl Inf Syst 67, 6969–7055. https://
[58] Nobles, Calvin. (2023). Offensive Artificial Intelligence in Cybersecurity: Techniques, Challenges, and Ethical Considerations. 10.4018/978-1-6684-8691-7.ch021.
[59] Noshi, Afzal & Blaser, Frank. (2024). Integrating Artificial Intelligence and Machine Learning for Advanced Cyber Security in SOC Operations. 10.13140/RG.2.2.21176.05121.
[60] Nur Alyyana Sofeya Binti Mohd Jefryy, Nurfarah Izzati Binti Arman, Nurfarah Najwa Binti Mohd Takri. (2025). AI in Cybersecurity: A Double-Edged Sword-Case Studies on Its Defensive and Offensive Applications. TechRxiv. 10.36227/techrxiv.175393681.17996361/v1
[61] Nwachukwu, Chukwuemeka & Durodola - Tunde, Kehinde & Chukwuebuka, Akwiwu- Uzoma. (2024). AI-driven anomaly detection in cloud computing environments. International Journal of Science and Research Archive. 13. 692-710. 10.30574/ijsra.2024.13.2.2184.
[62] Olusegun, John & Fathia, A. (2024). Predictive Analytics in Cybersecurity: Using AI to Prevent Threats Before They Occur".
[63] Qamar T, Bawany NZ. (2023). Understanding the black-box: towards interpretable and reliable deep learning models. PeerJ Comput Sci. 2023 Nov 29;9:e1629. PMID: 38077598; PMCID: PMC10702969.
[64] Palo Alto Networks. (2025). What is AI prompt security? Secure prompt engineering guide. Palo Alto Networks Cyberpedia. https://www.paloaltonetworks.sg/cyberpedia/wh at-is-ai-prompt-security
[65] Patil, Dimple & Rane, Nitin & Rane, Jayesh. (2024). The future of customer loyalty: How ChatGPT and generative artificial intelligence are transforming customer engagement, personalization, and satisfaction. 10.70593/978- 81-981367-8-7_2.
[66] Pattanayak, Suprit Kumar & Bhoyar, Manoj & Adimulam, Thejaswi. (2024). Unsupervised Learning for Anomaly Detection in Cybersecurity. 8. 56-63.
[67] Pedersen, K. T., Pepke, L., Stærmose, T., Papaioannou, M., Choudhary, G., & Dragoni, N. (2025). Deepfake -Driven Social Engineering: Threats, Detection Techniques, and Defensive Strategies in Corporate Environments. Journal of Cybersecurity and Privacy, 5(2), 18. https://
[68] Pissanidis, Dimitrios. (2023). Integrating AI/ML in Cybersecurity: An Analysis of Open XDR Technology and its Application in Intrusion Detection and System Log Management. 10.20944/preprints202312.0205.v1.
[69] Polaris Market Research. (2025). AI in cybersecurity market size, share, trends, industry analysis report: 2025–2034. https://www.polarismarketresearch.com/industr y-analysis/ai-in-cybersecurity-market
[70] Precedence Research. (2025). AI data centers market size to hit USD 165.73 billion by 2034. https://www.precedenceresearch.com/ai-data- centers-market
[72] Rehan, S. (2025). Understanding Attacker Tactics and Framework-Aligned Defense Strategies in the Cloud Era of AI. In: Cybersecurity with AWS. Apress, Berkeley, CA. https:// 6_3
[73] Ricciardi Celsi, L., & Zomaya, A. Y. (2025). Perspectives on Managing AI Ethics in the Digital Age. Information, 16(4), 318. https://
[74] Schmitt, Marc & Flechais, Ivan. (2023). Digital Deception: Generative Artificial Intelligence in Social Engineering and Phishing. SSRN Electronic Journal. 10.2139/ssrn.4602790.
[75] Schmitt, M., Flechais, I. (2024). Digital deception: generative artificial intelligence in social engineering and phishing. Artif Intell Rev 57, 324 (2024). https:// 024-10973-2
[76] SentinelOne. (2025). What is polymorphic malware? Examples & challenges. SentinelOne. https://www.sentinelone.com/cybersecurity- 101/threat-intelligence/what-is-polymorphic- malware
[77] Shewale V. (2025) The Ethics of Cybersecurity: Balancing Security and Privacy in the Digital Age, European Journal of Computer Science and Information Technology,13(15),11-20. https:// 20
[79] Siyan, Abu & Sans, Marta. (2024). Machine Learning in Cyber Security: Enhancing SOC Operations with Predictive Analytics. 10.13140/RG.2.2.18554.61123.
[80] Siva Kumar Mamillapalli. (2024). Adversarial and Offensive AI in Cyber Security. International Journal on Science and Technology (IJSAT) E-. Volume 15, Issue 4. https://www.ijsat.org/papers/2024/4/1904.pdf
[81] Skopik, Florian & Akhras, Benjamin & Woisetschläger, Elisabeth & Andresel, Medina & Wurzenberger, Markus & Landauer, Max. (2024). On the Application of Natural Language Processing for Advanced OSINT Analysis in Cyber Defence. 1 -10. 10.1145/3664476.3670899.
[82] Statista. (2024). Artificial intelligence (AI) in cybersecurity - statistics & facts. https://www.statista.com/topics/12001/artificial- intelligence-ai-in-cybersecurity
[83] Sufficient HM, Mohammed AM, Danjuma B. (2025). Ethical Implications of AI-Driven Ethical Hacking: A Systematic Review and Governance Framework. J Cyber Secur. 7(1):239–253. https://
[84] Teemu Birkstedt, Matti Minkkinen, Anushree Tandon, Matti Mäntymäki. (2023). AI governance: themes, knowledge gaps and future agendas. Internet Research 18 December 2023; 33 (7): 133–167. https:// 01-2022-0042
[85] Tong, Y., Liang, H., Ma, H., Zhang, S., & Yang, X. (2025). A Survey on Reinforcement Learning-Driven Adversarial Sample Generation for PE Malware. Electronics, 14(12), 2422. https://
[86] Udofot, Akpan & Oluseyi, Omotosho & Edim, Edim. (2024). Explainable AI for cyber security. Improving transparency and trust in intrusion detection systems. International Journal of Advances in Engineering and Management. 06. 229-240. 10.35629/5252-0612229240.
[87] UNICRI & INTERPOL. (2024). Principles for responsible AI innovation. United Nations Interregional Crime and Justice Research Institute. https://unicri.org/sites/default/files/2024- 02/02_Principles_Resp_AI_Innovation_Feb24.p df
[88] Verizon. (2024). 2024 Data Breach Investigations Report. Verizon Business. https://www.verizon.com/business/resources/rep orts/2024-dbir-data-breach-investigations- report.pdf
[89] WebAsha Technologies. (2025). AI in cyber defense vs. AI in cyber offense: The battle for cybersecurity dominance. https://www.webasha.com/blog/ai-in-cyber- defense-vs-ai-in-cyber-offense-the-battle-for- cybersecurity-dominance
[90] WebAsha Technologies. (2025). AI in Open- Source Intelligence (OSINT): How it works, benefits, and challenges in cybersecurity. WebAsha. https://www.webasha.com/blog/ai- in-open-source-intelligence-osint-how-it-works- benefits-and-challenges-in-cybersecurity
[91] WebAsha Technologies. (2025). How AI is transforming red team operations: The future of automated cybersecurity testing. WebAsha. https://www.webasha.com/blog/how-ai-is- transforming-red-team-operations-the-future-of- automated-cybersecurity-testing
[92] Xiaoling Tao, Jianxiang Liu, Yuelin Yu, Haijing Zhang, Ying Huang. (2025). An insider threat detection method based on improved Test-Time Training model. High-Confidence Computing, Volume 5, Issue 1, 100283, . https://
[93] Yadav, Gauri. (2025). Improving Cloud Security Using Artificial Intelligence: Challenges and Opportunities. Available at SSRN: https://ssrn.com/abstract=5141130
How to cite this paper
@article{1710353,
author = {Zechariah Oluleke Akinpelu},
title = {Artificial Intelligence in Offensive and Defensive Cybersecurity: Opportunities, Risks, and Ethical Boundaries},
journal = {Iconic Research And Engineering Journals},
year = {2025},
volume = {9},
number = {2},
pages = {1024-1042},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1710353.pdf},
abstract = {Artificial Intelligence (AI) has become a transformative force in cybersecurity, offering powerful capabilities for threat detection, anomaly recognition, and predictive defense, while also exhibiting a dual-use nature that makes it equally capable of being leveraged for offensive cyber operations. It can greatly enhance digital resilience through advanced defense mechanisms. At the same time, the very same technology can be exploited for offensive purposes, such as adversarial attacks, deepfake-enabled fraud, and automated intrusions. This paper critically examines the opportunities, risks, and ethical dilemmas posed by AI in cybersecurity, drawing on both academic literature and recent case studies, including deepfake fraud incidents and empirical insights. The discussion highlights key risks and ethical challenges, including algorithmic bias, transparency gaps in explainability, the dual-use dilemma of AI in penetration testing, and governance voids stemming from the absence of harmonized global standards. The case studies illustrate both offensive and defensive deployments, emphasizing the urgency for governance and ethical frameworks that operationalize fairness, accountability, and transparency within AI systems. The analysis integrates policy insights from compliance frameworks such as NIST, ISO, and GDPR, positioning them as anchors for building trustworthy AI ecosystems. The paper concludes that while AI should not be regarded as a panacea for cybersecurity, it is an indispensable evolving tool that requires responsible deployment, human-in-the-loop oversight, and collaborative governance to ensure resilience. The proposed research roadmap identifies explainable AI, AI forensics, and cross-sector collaborations as priority areas for advancing both academic and industry understanding. The paper positions AI as both an asset and a liability, providing a balanced foundation for future governance models that safeguard innovation while mitigating systemic risks.},
keywords = {Artificial Intelligence, Cybersecurity, Dual-Use Dilemma, Algorithmic Bias, Governance, Ethical Frameworks, Explainable AI, AI Forensics, Compliance (NIST, ISO, GDPR)},
month = {August},
}