The US government is building an AI sandbox to tackle cybercrime

Representational image depecting cybersecurity protection
(Image credit: Shutterstock)

Top US security agencies are developing a virtual environment that uses machine learning in an effort to gain insight on cyberthreats and share findings with both public and private organizations. 

A joint effort between the Science and Technology Directorate (S&T) - housed within the Department of Homeland Security (DHS) - and the Cybersecurity and Infrastructure Security Agency (CISA), an AI sandbox will be designed for researchers to collaborate and test analytical approaches and techniques in combating cyber threats. 

CISA's Advanced Analytics Platform for Machine Learning (CAP-M) will be used in both on-premise and in multi-cloud scenarios for this purpose.

Learning threats

"While initially supporting cyber missions, this environment will be flexible and extensible to support data sets, tools, and collaboration for other infrastructure security missions", the DHS said.

Various experiments will be conducted in CAP-M, and data will be analyzed and correlated to assist all kinds of organizations in protecting themselves against the ever-evolving world of cybersecurity threats.

The experimental data will be made available to other government departments, as well as academic institutions and firms in the private sector. The S&T assured that privacy concerns will be taken into account. 

Part of the experiments will involve testing AI and machine learning techniques in their analytical capabilities of cyberthreats and their effectiveness as tools in helping to fight them. CAP-M will also create a machine learning loop to automate workflows, such as exporting and tuning data.

Speaking to The Register, Monti Knode, a director at pentesting platform Horizon3.ai, said that such a plan is long overdue, but welcomed the ability for analytical skills to be tested.

Knode commented on past failures that have "contributed overwhelmingly to alert fatigue over the years, leading analysts and practitioners on wild goose chases and rabbit holes, as well as real alerts that matter but are buried."

He added that "labs rarely replicate the complexity and noise of a live production environment, but [CAP-M] could be a positive step."

Speculating on how it might work, Knode suggested that simulated attacks could be run automatically to train the AI on them to learn how they work and how to spot them.

Sami Elhini, biometrics specialist at Cerberus Sentinel, was also optimistic that the learning and analyzing of threats could lead to deeper understanding about them, but cautioned that models may become too generalized and so miss threats on smaller targets, filtering them out as insignificant.

He also raised security concerns, claiming that "When... exposing [AI/ML] models to a larger audience, the probability of an exploit increases". He said that other nations could target CAP-M to learn about or even interfere with its workings. 

Mostly, however, it seems there is positivity around the federal project. Craig Lurey, co-founder and CTO of Keeper Security, also told The Register that "Research and development projects within the federal government can help support and catalyze disparate R&D efforts within the private sector. … Cybersecurity is national security and must be prioritized as such."

Tom Kellermann, a VP at Contrast Security, echoed these sentiments, stating that CAP-M is a "critical project to improve information sharing on TTPs [tactics, techniques, and procedures] and enhance situational awareness across American cyberspace."

Lewis Maddison
Reviews Writer

Lewis Maddison is a Reviews Writer for TechRadar. He previously worked as a Staff Writer for our business section, TechRadar Pro, where he had experience with productivity-enhancing hardware, ranging from keyboards to standing desks. His area of expertise lies in computer peripherals and audio hardware, having spent over a decade exploring the murky depths of both PC building and music production. He also revels in picking up on the finest details and niggles that ultimately make a big difference to the user experience.

Read more
connection
UK Government reveals all on its new bid to boost AI Security Research
Cartoon Phishing
Hackers use GenAI to attack more frequently and effectively
An abstract image of a lock against a digital background, denoting cybersecurity.
Why AI is playing a growing role in helping SOC teams keep up with cyber threats
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Sounding the alarm on AI-powered cybersecurity threats in 2025
An abstract image of digital security.
Identifying the evolving security threats to AI models
Abstract image of cyber security in action.
Protectors of the modern world: defending against Shadow ML and Agentic AI
Latest in Security
Woman using iMessage on iPhone
Apple to take legal action against British Government over backdoor request
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Major ransomware attack sees Tata Technologies hit - 1.4TB dataset with over 730,000 files allegedly stolen
Security
Broadcom releases fixes for multiple VMware security flaws
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Latest in News
Microsoft UK CEO Darren Hardman AI Tour London 2025
Microsoft - UK can help drive the global AI future, but only with the proper buy-in
Asus Prime OC RTX 5070 graphics card with three fans, shown at an angle
Asus reveals Nvidia RTX 5070 launch pricing, and while one model is at MSRP – thankfully – the others make me want to give up my search for a next-gen GPU
Philips Hue lights being dimmed
Got Philips Hue lights? A free app update delivers these 3 improvements
Woman using iMessage on iPhone
Apple to take legal action against British Government over backdoor request
iPad Air M3
The new iPad Air M3 is good value – but I’d still buy this iPad Pro model instead
An image of the Samsung Galaxy S25 Ultra from a hands-on event
Samsung's One UI 7 update is finally launching in April – these are the 5 new features I can't wait to try