Army wants fast AI cybersecurity agents that won’t run up token costs or create new vulnerabilities
AUGUSTA, Ga. — The Army is on the hunt for AI agents to help defend its cyber infrastructure from attacks without draining the bank for tokens or letting loose a horde of bots that create new network vulnerabilities.
Project Griffin, a pilot program, aims to build an ecosystem of agents that will ingest feeds from the service’s vast array of network sensors and automatically execute defensive actions against malicious cyber actors, according to Army officials and a newly public solicitation.
Dubbed the Intelligent Response and Orchestration Node, or IRON, the capability is meant to counter threats that human analysts can’t respond to fast enough. The Army’s sensors generate tons of data, making it hard for human analysts to track and respond to hackers (who are increasingly using AI themselves) looking to exploit those vulnerabilities.
The project explores how the Army can “automate our cyber detection agents and allow them to autonomously respond in conjunction with a human operator, or perhaps in the future, even autonomously,” Brandon Pugh, principal cyber advisor for the service, told an audience at the annual TechNet Augusta conference on Wednesday.
The solicitation comes after several top AI companies disclosed that their agents breached testing sandboxes and hacked other organizations, sending the cyber world into a panic about the dangers autonomous bots can pose to network security. An Army official acknowledged one of those now infamous incidents, where an OpenAI model attacked machine learning company Hugging Face, calling it a “reality check.”
At the same time, officials have been warning that even low-level cyber actors are using AI to probe networks, and institutions must use the disruptive technology themselves to defend against progressively fast, ubiquitous attacks.
Pugh acknowledged that there are “different levels of policy and legal questions around” using autonomous agents in cyberspace, and pointed to an AI capability started in the Biden-era called Panoptic Junction that “does a really good job of identifying potential threats.”
Failing to flip the script against adversaries’ use of AI, however, would put the Army at a “disadvantage,” he said, and the service is turning to industry to help prevent that.
Earlier this year, 15 tech companies went to the Pentagon to help game out a hypothetical scenario where an adversary launched thousands of autonomous cyber attacks at the military simultaneously, according to Pugh.
Those AI-related exercises are part of the Army Rapid Development of Cyber Defense Systems (ARDS) program, which encompasses three ongoing initiatives, one being Project Griffin.
Other Army officials at the conference detailed their requests to industry for the program. They want a system that can seamlessly and safely integrate into the Army’s existing network structure without racking up token charges.
“If you guys are presenting things to us from a pilot perspective and it looks great, but then you guys are going to have an inflated cost at the end, we’re gonna have a problem with that, right?” Wayne Sok, product manager for the service’s defensive cyber warfare arm, told an audience Thursday. “So we need you guys to help us, meaning like token costs. How are we going to minimize that?”
The capability also needs to be safe, he added. The solicitation said IRON has to “intelligently” distinguish between actual threats and false positives, while keeping a “complete and automated audit trail” for every action it takes.
“We need help in implementing agents securely, so that it doesn’t inadvertently increase our attack surface,” Sok said. “If we have a bunch of agents roaming around, and they’re vulnerable, that just made it worse because if the adversaries attack our agents, now we’re exposed.”
DefenseScoop reported Thursday that U.S. Army Cyber Command had set up its own task force to build agentic cyber tools, the implementation of which is a “delicate dance,” according to the unit’s leader.
Sok referenced the Hugging Face incident and called it a reality check, pointing out that it was unintended. “Now think of the intended effects [that adversaries seek to create], and we’re trying to get ahead of that,” he said.
IRON will fulfill defensive responses through Policy Enforcement Points such as endpoint management systems like Tychon or the Microsoft Defender antivirus tool, according to the solicitation. It will operate under a zero trust model, which assumes the network is always compromised by default, and adopt open API standards.
Pentagon and Army administrators will also need to have the option of manually setting, adjusting and auditing “confidence thresholds” that dictate certain response levels. That includes a “master kill switch” to stop pending autonomous actions at higher tiers within seconds and an “undo” function to reverse PEP commands the agents trigger.
The commands span across seven functions for now, from the ability to impose temporary firewall blocks to patching vulnerabilities.
The Army is asking for solution briefs by Aug. 27. It reserves the right to limit the number of offerors to seven companies for pitches, which is part of phase two of a three-phase ramp. Sok said Project Griffin will include multiple solutions that make up agentic defensive responses.
Right now, the Army is analyzing and responding to threats “at the human speed,” he said. “We need it to do it at the machine speed.”