REVIEW 4 major objections 5 minor 23 references
Asymmetry by Design: Boosting Cyber Defenders with Differential Access to AI
T0 review · 4 major / 5 minor · reviewed 2026-08-07 · deepseek-v4-flash
Pith's one-line read Targeted access to AI cyber tools can tilt the offense-defense balance toward defenders.
desk verdict A usable policy framework for differential access to AI cyber capabilities, but its central pro-defender asymmetry rests on an unquantified capability gap that the paper itself does not close. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The machinery is a two-dimensional classification: model cyber capability levels (from technical non-expert through nation-state skill) paired with defender levels defined by maturity and criticality. On that grid sit the three access approaches—Promote Access, Manage Access, and Deny by Default—and the selection process that moves from capability assessment to goals, defender selection, approach choice, and then strategic and technical controls. The framework does the work of translating a vague worry about AI-enabled cyber attacks into a set of concrete access decisions and implementation levers.
What would settle it
Compare two groups of comparable organizations facing the same AI-enabled attack surface: one receives vetted early access to a restricted AIxCyber defensive tool, the other does not. If the treated group shows no measurable improvement in vulnerability discovery or response time, or if attackers obtain equivalent capabilities within the same window via open models, theft, or self-development, the paper's core claim fails.
Extended reading notes
Core claim
The paper's central discovery is a decision framework, not a new result about model behavior: access to AIxCyber capabilities should be shaped by capability level, defender role, and goals. The core claim is that current safeguards are insufficient because they ask whether a capability can be misused, not whether the right defenders can adopt it safely. The paper argues that three approaches—Promote Access, Manage Access, and Deny by Default—form a continuum, with increasing restrictiveness tied to higher capability levels and misuse risk, and that defender access remains a priority even at the most restrictive end. Four illustrative schemes show how the framework applies at different capability and defender levels, from accelerators for critical-infrastructure innovators to tightly controlled red-teaming as a service.
Load-bearing premise
The scheme assumes access restrictions can actually be maintained—that attackers cannot cheaply obtain the same or equivalent AI cyber capabilities from open-source models, theft, or their own development; if they can, withholding tools from defenders only makes defense weaker.
Editorial extensions
If this is right
- Frontier AI developers can use the six-step process to decide, for a given model or derivative product, which access approach matches its measured cyber capability level.
- Deny by Default does not have to mean no defensive benefit; developers can offer capability-as-a-service or reduced-capability tools to vetted defenders.
- Manage Access tiering can give Keystone Defenders and vetted Force Multipliers earlier access to dual-use capabilities while keeping them from less mature actors.
- Technical infrastructure—identity checks, capability classifiers, monitoring, and privacy-preserving logging—determines whether an approach is actually implementable, not just whether it sounds good.
- Government incentives and safe-harbor policies can accelerate adoption among critical but under-resourced defenders such as critical-infrastructure operators.
Reading between the lines
- If differential access works for cyber, the same 'gate by actor maturity and criticality' pattern could transfer to other dual-use AI domains, with different capability taxonomies and defender archetypes.
- A testable prediction follows: vetted defenders given early access should patch vulnerability classes faster and detect more intrusions than comparable defenders without access; program records could verify this.
- Attackers will likely respond by targeting the defenders who hold privileged access, so any access scheme must budget for protecting those defenders, not only for internal misuse monitoring.
- Because open-source models just behind the frontier erode exclusive access, the durable value of differential access may lie in the service layer—running adversary emulation and vulnerability discovery for defenders—rather than in controlling model weights.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This policy report proposes "differential access" as a strategy for frontier AI developers and policymakers to shape access to AI-enabled cyber (AIxCyber) capabilities in order to give cyber defenders an asymmetric advantage over attackers. It defines three approaches along a restriction continuum—Promote Access, Manage Access, and Deny by Default—and offers a six-step selection process based on model capability level, defender maturity and criticality, strategic considerations, and technical infrastructure. It then presents four illustrative schemes (CNI innovators accelerator, dual-use authorization for security researchers, rapid response force of keystone defenders, and high-capability adversarial testing as a service) and discusses future research needs and limitations.
Significance. If the central claim holds, the framework could provide a practical vocabulary and decision structure for an important policy problem: how to distribute increasingly capable AI cyber tools without handing them to attackers. The report's strengths are its clarity, its systematic synthesis of existing taxonomies (UK AISI cyber capability levels, Pattern Labs offensive capabilities), the explicit naming of defender archetypes, and a transparent acknowledgment of unresolved issues. It also usefully stresses that access policy should not be driven solely by misuse prevention but should actively prioritize defenders. However, the significance is conditional: the promised pro-defender asymmetry is asserted rather than demonstrated, and the report itself concedes that the necessary threat modeling and technical-control evidence are not yet in place. The paper is best read as a research agenda or a framework proposal, not as a validated policy model.
major comments (4)
- [§1.1, §1.3, §2.1, footnote 55] The central claim that differential access can tilt the offense-defense balance assumes a persistent capability gap between gated frontier systems and what adversaries can obtain elsewhere, but the report provides no evidence for this gap and several of its own statements undercut it. Section 1.1 concedes that "access restrictions cannot fully prevent adversaries from gaining access to similar capabilities via tapping open-source models just behind the frontier," and Section 1.3 states that when open-source models "already match or exceed" a foundation model's capabilities, developers may prefer Promote Access. More importantly, Section 2.1 emphasizes that "downstream fine-tuning, scaffolding, tool integration, and other enhancements can significantly increase the capability level of a foundation model for a fraction of the cost," and footnote 55 reports that simple scaffolding raises an intercode-CTF score from 72% to 95%. If the effective capability an adversary can assemble from open weights plus tooling is close to the frontier, then Manage Access and Deny by Default delay attackers only marginally while burdening defenders, eroding the claimed asymmetry. The authors should either supply empirical evidence of a persistent, material capability gap on high-risk cyber tasks or explicitly reframe the paper's contribution as a conditional framework whose benefit depends on such a gap.
- [§1.2, §7.1, §7.2] The process for selecting among the three approaches is underdetermined because the report never provides a worked threat model, and the authors themselves identify this as a limitation. Section 7.1 states that "without rigorous, domain-specific models, it is difficult to justify or calibrate levels of differential access," and Section 7.2 says that "identifying specific AI-enabled threats is beyond the scope of this report." But Step 1 of the selection process (Section 1.2) requires assessing risk of misuse to choose an approach, and the four schemes in Section 6 are each premised on a concrete threat scenario (CNI attacks, exploit proliferation, accelerated patch cycles, offensive overhang). Without at least one detailed worked example that quantifies threat likelihood, impact, and the marginal effect of access restrictions, the framework cannot demonstrate when Manage Access, rather than Promote Access or Deny by Default, is the rational choice. The report should include a concrete threat-modeling case study or explicitly present the framework as a heuristic requiring additional threat analysis before operational use.
- [§1.5, §3.5] The report identifies but does not analyze the risk that defenders granted differential access become high-value targets whose compromise would leak the very capabilities the scheme aims to restrict. Section 1.5 notes that "the defenders who are granted differential access to these advanced capabilities will be valuable targets for malicious actors," and Section 3.5 lists credential theft and unauthorized repurposing among the risks for Force Multipliers. However, the paper provides no quantitative or probabilistic assessment of model theft, insider compromise, or leakage from vetted defenders. If leakage rates are non-negligible, differential access could function as a deliberate distribution channel for attackers rather than a barrier, reversing the claimed asymmetry. The authors should analyze this failure mode—for example, by estimating the additional exposure created by granting access to many defenders and comparing it with the reduction in attacker access achieved by restricting public release.
- [§5.2, Cyber-Tool Provision] The Manage Access and Deny by Default approaches depend on technical controls whose reliability at scale is not established. Section 5.2 proposes input/output classifiers, circuit breakers, unlearning, and distillation as means of restricting capabilities, but immediately cautions that "more research is needed to demonstrate if these methods can successfully limit a model's capabilities while leaving it sufficiently useful for narrow tasks." If these controls fail against jailbreaks or are easily circumvented, the distinction between Manage Access and full public release disappears, and the entire framework loses its operational meaning. The paper should either provide evidence from existing classifier or unlearning evaluations that these controls can be made reliable, or explicitly state that the framework's viability is contingent on future technical advances and is not yet ready for deployment.
minor comments (5)
- [§1.2] The ordering of the three approaches is inconsistent: the TOC lists Promote Access (1.3), Manage Access (1.4), and Deny by Default (1.5), but the introductory text in Section 1.2 lists them as "Promote Access, Deny by Default, and Manage Access." Please align the order.
- [§1.4, Table 1] In the sample tiered access table, the Tier 1 entry says users can "fully automate clearly malicious cyber operations"; for defenders this is presumably intended to mean offensive operations in authorized contexts, but the phrase is confusing and should be reworded.
- [§3.3] The examples of Keystone Defenders include specific company names and market-share figures, but the relevance of some statistics (e.g., Apple's device count) to access decisions is not made clear. A sentence linking each statistic to the defender's criticality or maturity would improve readability.
- [§6.1] Scheme A says the primary bottlenecks are around the product development and adoption lifecycle "rather than novel technical methods to control/promote access," but the preceding sections place heavy weight on technical infrastructure; a brief reconciliation would help.
- [§7.1] The section on government policy mentions DARPA's AIxCC but does not cite it; adding a reference would be helpful for readers who want to follow up.
Circularity Check
No circularity: the paper is a policy framework built from stipulative definitions and external taxonomies, with no fitted inputs, self-referential predictions, or derived quantities that collapse into its own assumptions.
full rationale
The paper proposes a governance framework rather than deriving an empirical result. Its three access approaches (Promote, Manage, Deny by Default) are stipulative categories, and the decision procedure is explicitly presented as guidance, not as a prediction or proof. The two external taxonomies used, UK AISI Cyber Capability Levels and Pattern Labs' offensive cyber capabilities, are cited as external reference points and are not manipulated to force the paper's conclusions; the paper explicitly treats capability assessment as a recommended input to a judgment call. No parameter is fitted to data and then renamed a prediction, and no claim is justified solely by a self-citation chain. Section 7.2 candidly states that 'Identifying specific AI-enabled threats is beyond the scope of this report' and that more threat modeling is needed, which is a correctness/evidence limitation rather than a circularity. The acknowledgement of UK AISI support and the citation of UK AISI methodology are not load-bearing self-citations in the sense of importing an unverified uniqueness claim or smuggling in an ansatz; the methodology is used as a benchmark the authors recommend aligning with, not as the source of the report's conclusions. Because the central proposal is conditional and openly so, the derivation chain does not reduce to its inputs.
Assumptions & free parameters
assumptions (5)
- domain assumption Capability level is a valid proxy for real-world misuse risk.
- domain assumption Differential access controls will bind for adversaries and will not be fully bypassed by open-source models, theft, or state development.
- domain assumption Defenders can be reliably identified and assessed on maturity and criticality.
- domain assumption Foundation model developers have sufficient incentive to implement and maintain differential access schemes.
- ad hoc to paper At least some controls in Section 5.2 (input/output classifiers, unlearning, distillation) can be made reliable at scale.
Cite this review
Pith. "Pith review of Asymmetry by Design: Boosting Cyber Defenders with Differential Access to AI." pith.science (2026). https://pith.science/paper/VXQVNPIS
@misc{pith2026250602035,
author = {Pith},
title = {Pith review of: Asymmetry by Design: Boosting Cyber Defenders with Differential Access to AI},
year = {2026},
howpublished = {\url{https://pith.science/paper/VXQVNPIS}},
note = {Machine review of arXiv:2506.02035}
}
read the original abstract
As AI-enabled cyber capabilities become more advanced, we propose "differential access" as a strategy to tilt the cybersecurity balance toward defense by shaping access to these capabilities. We introduce three possible approaches that form a continuum, becoming progressively more restrictive for higher-risk capabilities: Promote Access, Manage Access, and Deny by Default. However, a key principle across all approaches is the need to prioritize defender access, even in the most restrictive scenarios, so that defenders can prepare for adversaries gaining access to similar capabilities. This report provides a process to help frontier AI developers choose and implement one of the three differential access approaches, including considerations based on a model's cyber capabilities, a defender's maturity and role, and strategic and technical implementation details. We also present four example schemes for defenders to reference, demonstrating how differential access provides value across various capability and defender levels, and suggest directions for further research.
Reference graph
Works this paper leans on
-
[3]
Cyber Risk to Mission Case Study: Triton
https://doi.org/10.48550/arXiv.2502.15657. Blaine, Jeffries, Stephanie Saravia, Cedric Carter, and Ankuda. “Cyber Risk to Mission Case Study: Triton.” MITRE, October 13,
-
[5]
Energy Sector-Specific Plan - 2015
https://blog.se.com/digital-transformation/2023/12/13/artificial-intelligence-and-new-archite ctures-navigating-the-it-ot-convergence/. CISA. “Energy Sector-Specific Plan - 2015.” Department of Homeland Security, December 17,
work page 2023
-
[10]
ISA/IEC 62443 Series of Standards
https://appleinsider.com/articles/25/01/30/apple-has-more-than-235-billion-active-devices- up-550-million-since-2022. ISA. “ISA/IEC 62443 Series of Standards.” isa.org. Accessed May 12,
work page 2022
-
[12]
https://doi.org/10.48550/arXiv.2407.14981. Ribeiro, Anna. “Growing Need to Balance Benefits, Risks of Integrating AI in OT Cybersecurity in Evolving Threat Landscape.” Industrial Cyber (blog), October 13,
-
[13]
OT Cybersecurity in 2025: 6 Trends to Watch
https://industrialcyber.co/ai/growing-need-to-balance-benefits-risks-of-integrating-ai-in-ot-c ybersecurity-in-evolving-threat-landscape/. Rockwell Automation. “OT Cybersecurity in 2025: 6 Trends to Watch.” Rockwell Automation, February 7,
work page 2025
-
[14]
On the Feasibility of Using LLMs to Execute Multistage Network Attacks
https://doi.org/10.48550/arXiv.2501.18837. Singer, Brian, Keane Lucas, Lakshmi Adiga, Meghna Jain, Lujo Bauer, and Vyas Sekar. “On the Feasibility of Using LLMs to Execute Multistage Network Attacks.” arXiv, March 6,
-
[15]
https://doi.org/10.48550/arXiv.2501.16466. Singh, Manish. “Faulty CrowdStrike Update Causes Major Global IT Outage, Taking out Banks, Airlines and Businesses Globally.” TechCrunch (blog), July 20,
-
[16]
Desktop Operating System Market Share Worldwide
https://techcrunch.com/2024/07/19/faulty-crowdstrike-update-causes-major-global-it-outa ge-taking-out-banks-airlines-and-businesses-globally/. StatCounter. “Desktop Operating System Market Share Worldwide.” Global Stats, April
work page 2024
Show all 23 references
-
[17]
Cloud Market Jumped to $330 Billion in 2024 – GenAI Is Now Driving Half of the Growth,
https://gs.statcounter.com/os-market-share/mobile/worldwide/. Synergy Research Group. “Cloud Market Jumped to $330 Billion in 2024 – GenAI Is Now Driving Half of the Growth,” February 6,
2024
-
[18]
NotPetya: World’s First $10 Billion Malware
https://www.srgresearch.com/articles/cloud-market-jumped-to-330-billion-in-2024-genai-is -now-driving-half-of-the-growth. Tehrani, Rich. “NotPetya: World’s First $10 Billion Malware.” Apex Technology Services, October 28,
2024
- [19]
- [20]
-
[21]
Contracts for December 7, 2022
https://www.aisi.gov.uk/work/pre-deployment-evaluation-of-anthropics-upgraded-claude-3 -5-sonnet. U.S. Department of Defense. “Contracts for December 7, 2022.” Accessed May 7,
2022
-
[22]
Valeriano, Brandon, Benjamin Jensen, and Ryan C
https://www.defense.gov/News/Contracts/Contract/Article/3239197/https%3A%2F%2Fw ww.defense.gov%2FNews%2FContracts%2FContract%2FArticle%2F3239197%2F%2F. Valeriano, Brandon, Benjamin Jensen, and Ryan C. Maness. Cyber Strategy: The Evolving Character of Power and Coercion . Oxfor...
- [23]
-
[2017]
Target Rich, Cyber Poor: Strengthening Our Nation’s Critical Infrastructure Sectors | CISA
https://www.washingtonpost.com/business/technology/nsa-officials-worried-about-the-day -its-potent-hacking-tool-would-get-loose-then-it-did/2017/05/16/50670b16-3978-11e7-a0 58-ddbb23c75d82_story.html. Natarajan, Nitin. “Target Rich, Cyber Poor: Strengthening Our Nation’s Critica...
2017
-
[2018]
OT/ICS and Industrial IoT Security
https://www.cisa.gov/news-events/alerts/2018/03/15/russian-government-cyber-activity-ta rgeting-energy-and-other-critical-infrastructure-sectors. Cisco. “OT/ICS and Industrial IoT Security.” Accessed May 12,
2018
-
[2019]
Cyberattacks on US Utilities Surged 70% This Year, Says Check Point
https://www.crowdstrike.com/en-us/press-releases/crowdstrike-falcon-available-to-govern ment-entities-nationwide-through-california-software-licensing-program-plus/. Dareen, Seher, Vallari Srivastava, and Seher Dareen. “Cyberattacks on US Utilities Surged 70% This Year, Says C...
2024
-
[2020]
Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors,
https://www.cisa.gov/resources-tools/resources/energy-sector-specific-plan-2015. ———. “Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors,” March 16,
2015
-
[2021]
International AI Safety Report 2025
https://ccianet.org/research/reports/monoculture-and-market-share-the-state-of-communi cations-and-collaboration-software-in-the-us-government/. Bengio, Yoshua. “International AI Safety Report 2025.” Department for Science, Innovation and Technology, February 18,
2025
-
[2023]
Artificial Intelligence and New Architectures: Navigating the IT/OT Convergence
https://blogs.windows.com/windowsexperience/2023/11/09/reflecting-on-20-years-of-win dows-patch-tuesday/. Cavalenes, John. “Artificial Intelligence and New Architectures: Navigating the IT/OT Convergence.” Schneider Electric Blog (blog), December 13,
2023
-
[2024]
HackerOne Reveals Industry and Company Growth as Enterprises Secure Rapid Digital Transformations,
https://googleprojectzero.blogspot.com/2024/10/from-naptime-to-big-sleep.html. HackerOne. “HackerOne Reveals Industry and Company Growth as Enterprises Secure Rapid Digital Transformations,” March 8,
2024
-
[2025]
Superintelligent Agents Pose Catastrophic Risks: Can Scientist AI Offer a Safer Path?
https://www.gov.uk/government/publications/international-ai-safety-report-2025. Bengio, Yoshua, Michael Cohen, Damiano Fornasiere, Joumana Ghosn, Pietro Greiner, Matt MacDermott, Sören Mindermann, et al. “Superintelligent Agents Pose Catastrophic Risks: Can Scientist AI Offer a...
2025
Reviewed August 7, 2026 · model on record in the stance chip above.
Discussion (0). Sign in to comment.