MIT's new AI platform, which incorporates input from human experts, can predict 85% of cyberattacks, which is 3x better than previous benchmarks
Adam Conner-Simons / MIT News :
Context & Ripple Effects
In 2016, MIT's bet was that machine learning alone wasn't enough: pairing models with human-expert input pushed attack prediction to 85%, triple the prior benchmark. At the time, the offensive side was already stirring — IBM Research would later warn that AI makes phishing, already used in roughly 90% of attacks, more effective at scale even before widespread attacker adoption showed up.
A decade on, the corpus shows the arc this paper started: models now clear expert-level capture-the-flag challenges no model could finish before April 2025 Claude Mythos Preview hit 73% on those tests, and Microsoft has moved from prediction to action with a purpose-trained cyber model and an agentic system that patches vulnerabilities itself MAI-Cyber-1-Flash and Project Perception. MIT's 2016 result reads as the early template for that defender-side automation.
First-order effects
- Security teams running MIT-style predictive platforms gain pre-execution warning on most attacks, but the 85% rate depends on continuous human-expert input, making analyst time a core operating cost rather than a backstop.
- Vendors selling conventional threshold- and signature-based detection now face a published academic baseline claiming 3x better prediction, forcing them to defend their own detection rates by comparison.
Second-order effects
- The same capability cuts both ways: IBM Research's finding that AI amplifies phishing at scale means every defensive gain raises the payoff for attackers who adopt equivalent models, accelerating an AI-on-AI arms race.
- Microsoft's later entry with a dedicated cybersecurity model and autonomous patching shows where competitors were pushed — from alerting tools toward closed-loop systems that act on predictions without waiting for analysts.
Third-order effects
- If the pattern holds, security operations consolidate around platforms that predict, decide, and patch end-to-end, shrinking the market for point products whose output is merely another alert for a human queue.
- Human experts shift from monitoring dashboards to supplying the judgment that trains these models — the scarce resource becomes the labeled expertise, not the software.
The trend: Cybersecurity is migrating from reactive detection toward AI systems that predict attacks and increasingly patch them autonomously, with human experts recast as the training input rather than the last line of defense.