Glossary

These terms are explained following English reading conventions, with links to examples in the report. Near-synonymous concepts are kept separate — for example, distillation and unauthorized distillation are two separate entries.

AI-enabled cyberattacks

Cyberattacks that embed AI into reconnaissance, tool development, and data processing — the underlying techniques are mostly still the old ones.

AI misuse

A general term for activities that use AI systems to deceive, harm others, or violate service policies.

API key theft

Stealing the keys or login sessions needed to call AI services, turning someone else's quota, data, and identity into your own attack resources.

Attribution confidence

A wording the report uses for how certain it is about 'who did it', such as high confidence or medium confidence. It is not a rating from this site.

Capability uplift

AI lets the same actor go beyond what their original resources could achieve in speed, scale, or depth.

Dual-use

The same type of knowledge, item, or software can be used for legitimate purposes or potentially for harm.

Indicators of compromise

Technical clues defenders use to identify related activity, such as domains, addresses, or file signatures. This site does not reproduce specific values.

Influence operations

Using AI to produce or distribute content while hiding identity, sponsorship, or sources, so audiences misjudge who is speaking.

Model distillation

Training a smaller model to reproduce the outputs of a larger one. When done without authorization, it becomes unauthorized distillation.

Non-consensual profiling

Building profiles of individuals without their knowledge or consent, often using scraped personal data.