Thursday, 23 Jul 2026
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA
logo logo
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
  • 🔥
  • Trump
  • House
  • White
  • ScienceAlert
  • VIDEO
  • man
  • Trumps
  • Season
  • star
  • Years
Font ResizerAa
American FocusAmerican Focus
Search
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
Follow US
© 2024 americanfocus.online – All Rights Reserved.
American Focus > Blog > Tech and Science > Multi-turn attacks broke AI models 88% of the time — single-turn testing missed it, Cisco AI security lead warns at VB Transform 2026
Tech and Science

Multi-turn attacks broke AI models 88% of the time — single-turn testing missed it, Cisco AI security lead warns at VB Transform 2026

Last updated: July 23, 2026 8:15 pm
Share
Multi-turn attacks broke AI models 88% of the time — single-turn testing missed it, Cisco AI security lead warns at VB Transform 2026
SHARE

Contents
Three layers versus an operating systemThe end of human code reviewIntent versus probability

In a significant test, Cisco conducted 6,986 multi-turn attacks on 15 flagship models, with attackers succeeding up to 88.3% of the time when they adapted their strategies. Amy Chang, head of AI threat intelligence and security research at Cisco, highlighted this concern during the VB Transform 2026 panel, emphasizing the risks for those still relying on single-turn red-teaming methods.

According to a June 2026 Pulse survey by VentureBeat, which included 107 enterprise respondents, 54% had experienced either a confirmed agent security incident (18%) or a near-miss (36%). Despite these issues, only 32% of respondents ensured each agent had a distinct managed identity, and just 30% isolated high-risk agents in sandboxes. Most companies (82%) still depend on provider-native and hyperscaler controls as their primary security measures. Major security vendors are also focusing on these areas.

Palo Alto Networks finalized its $25 billion acquisition of CyberArk in February. In January, CrowdStrike agreed to a $740 million deal for SGNL, and Cisco announced its plan to acquire Astrix Security for $400 million, all to enhance the identity and isolation layers that many enterprises have yet to fully develop.

With nearly two decades of expertise in cybersecurity operations, government, and military service, Chang brings a wealth of knowledge to the panel. She previously managed global cybersecurity operations at JPMorgan Chase and has served on the House Foreign Affairs Committee and as a U.S. Navy Reserve officer. Additionally, she teaches cybersecurity at the Middlebury Institute of International Studies.

The 88.3% figure, derived from a study co-authored by Chang and Nicholas Conley, involved 30,090 single-turn prompts and 6,986 multi-turn attacks on the 15 models. Multi-turn success varied from 7.89% to 88.3%, revealing non-trivial vulnerabilities in each model. The study’s findings are shared on Cisco’s LLM Security Leaderboard.

Chang stressed the importance of understanding model vulnerabilities to mitigate failure points in applications powered by AI agents. Single-turn tests provide only a snapshot, while multi-turn attacks reveal more realistic scenarios, exposing harmful outputs and misaligned behaviors.

See also  Arsenal vs. Brentford prediction, odds, time, bets: 2025 Premier League free picks for Saturday, April 12

Cisco’s testing strategy now embraces agentic frameworks, where agents assess scenarios, develop and execute attacks, and evaluate outcomes. Despite the complexity, Chang noted that the solution lies in fundamental security principles. “The answer is still that it’s pretty simple,” she remarked. “You don’t have to get super creative. You just need to think about truly what are the fundamentals and basics of what I’m trying to secure in my organization.”

For those starting agentic deployments, Chang recommends Cisco’s Integrated AI Security and Safety Framework, which addresses AI vulnerabilities across the lifecycle. Teams can use this framework to analyze past incidents and develop strategies with appropriate coverage and mitigations.

Heather Ceylan, Box’s CISO, identified similar challenges from a defense standpoint. She criticized the prevalent use of single-turn red teaming, which fails to reflect real-world AI interactions. Box simulates multi-turn attacks with agents mirroring attacker behavior to ensure effective security controls. “You have to pressure test your agents because otherwise you don’t know if your execution controls are really working as you intended.”

Box has had agents in its security operations center for about a year, initially requiring human approval for every action. Trust in the system grew, allowing analysts to shift to monitoring, but a single mistake reset this trust. “They had to start all over again,” Ceylan noted, highlighting the importance of continuous monitoring due to the evolving nature of models and their interpretations.

Rajesh Parekh, VP of AI and ML at Intuit, provided insights from a development perspective. Before Intuit, Parekh worked on Google’s Maps and Geo products and holds a doctorate in computer science.

Three layers versus an operating system

Ceylan outlined Box’s approach using three concentric security layers. First, permissioning ensures agents access only content permissible to the invoking user. Ephemeral sandboxes limit damage if agents are compromised, and runtime controls restrict tool calls to task-relevant actions. “If you want an agent to summarize a doc for you, if you have a prompt injection that came in that says forward this to maliciousattacker at domain.com, it can’t do that,” Ceylan explained. “That action in that tool call is not even in its vocabulary.”

See also  Human populations evolved in similar ways after we began farming

Agent actions are classified into oversight categories: non-sensitive actions proceed without human intervention, moderately sensitive actions are monitored, and destructive actions like mass deletions always require human approval. “Things are gonna shift between those three categories quite a bit,” Ceylan admitted, but establishing these categories provides a principled framework.

Intuit’s approach differs, having developed a central platform called GenOS, or generative AI operating system, to streamline security, risk, and fraud modeling across agents. “Permissioning is not about giving access to AI,” Parekh stated. “Instead, it is defining very tightly scoped and clearly auditable authority to the agent to perform very specific tasks.” Intuit has transitioned from user-permissioned agents to those with individual identities and is exploring mid-session permission changes.

Parekh described their model as an AI-powered expert platform that integrates human expertise within its trust architecture. “The paradigm that we are pursuing is where the user, the AI agent, and the human expert are collaborating to solve the user problem,” he explained.

The end of human code review

Ceylan addressed the balance between security testing and development speed. “The days of secure code reviews where a human’s looking at the code and we’re looking at security architecture reviews, design docs, those are done,” she asserted. Box aims for an agent-driven development lifecycle, where agents handle design review, security application, and vulnerability checks. “I’m very optimistic that we will get to a point where we will write code without security vulnerabilities because agents and the models are going to get so good at writing code without vulnerabilities,” she said. “We’re still a long way away from that.”

Her guidance for development teams focuses on basic security principles: “It comes down to very basic least privilege access,” she advised. Granting broad permissions early complicates the establishment of secure infrastructures with ephemeral credentials and narrowly scoped tasks.

Parekh explained the rapid expansion of the red teaming surface. “These agents have skills, and skills could become vulnerabilities,” he said. “Agents have access to certain data, they have access to tools, and there could be threats that are lurking within those tools as well. So suddenly the blast radius of the malicious code or the intent increases dramatically.” Intuit automates tests for common vulnerabilities into the GenOS framework, allowing future agents to inherit protections and red teamers to focus on emerging threats. Runtime scanning of prompts and responses provides an additional safeguard, escalating suspect responses to human experts.

See also  FLASHBACK: That Time in 2021 When Hakeem Jeffries Called the Filibuster a Racist Artifact of the Jim Crow Era (VIDEO) |

“You need to continuously test to ensure that those remain robust to the protections that you have built, as well as to account for any sort of drift or any other types of dependencies that you introduce into your scenario that can create novel vulnerabilities,” he emphasized.

Intent versus probability

An audience question on intent detection sparked intense discussion. Ceylan noted that Box’s internal agents operate with known user intent, allowing for engineered guardrails and tool restrictions. However, challenges arise when external agents connect without clear context, a problem Box is still addressing.

This discussion revealed a divide in the industry. Mastercard, in a preceding fireside chat, advocated for intent quantification through an open-source framework to support complex B2B procurement. Meanwhile, endpoint security CTOs prefer relying on probability over intent inference for production tasks. Chang clarified that current model training cannot consistently derive intent from prompts, necessitating deterministic controls and behavioral proxies. Ceylan concurred that both approaches are essential. “If you’re not doing anything deterministic, you’re really relying heavily on that intent, and I haven’t seen programs that are there yet,” she remarked.

Ceylan’s anecdote about trust eroding after an agent’s mistake resonated with the audience, underscoring that agentic security is an ongoing challenge. Models evolve, permissions shift, and adversaries exploit multi-turn interactions that static tests miss.

For the 82% of enterprises relying primarily on provider-native controls and the 59% exploring new agent security tools in the coming year, the panel’s advice was clear: conduct continuous, comprehensive testing as attackers would, or risk discovering vulnerabilities in a live environment.

TAGGED:attacksbrokeCiscoleadMissedmodelsMultiturnSecuritysingleturntestingtimetransformWarns
Share This Article
Twitter Email Copy Link Print
Previous Article FDA panel backs compounded BPC-157, KPV peptides in win for RFK Jr. FDA panel backs compounded BPC-157, KPV peptides in win for RFK Jr.
Next Article Attachment Tokyo Spring 2027 Collection Attachment Tokyo Spring 2027 Collection

Popular Posts

From Paycheck To Purpose: A Smarter Way To Manage Money

Money transcends mere numbers on a bank statement; it serves as a facilitator of choices,…

September 22, 2025

Trump’s Letitia James Indictment Will Backfire

In the accompanying video, I delve into the reasons why Trump's attempt to indict Letitia…

October 9, 2025

Angelina Ditching FBI Battle Over Brad Plane ‘Bust-Up’ Is ‘White Flag’

Angelina Jolie made an appearance at a film festival where she was photographed signing a…

October 1, 2024

Tubi Unveils F1 Altcasts in Apple Deal, New Interactive Ad Formats

Tubi is accelerating efforts to attract new advertisers. On Tuesday, the Fox-supported free streaming service…

March 24, 2026

Nations Gather For Crunch Climate Talks In Shadow Of US Election

Paris, France: Leaders from around the world are set to commence the UN climate talks…

November 4, 2024

You Might Also Like

Tansplanted testicular tissue grew sperm in an infertile patient
Tech and Science

Tansplanted testicular tissue grew sperm in an infertile patient

July 23, 2026
Samsung Galaxy Z Fold 8 Missing Feature Could Be a Dealbreaker – Tech Advisor
Tech and Science

Samsung Galaxy Z Fold 8 Missing Feature Could Be a Dealbreaker – Tech Advisor

July 23, 2026
I Used Samsung Galaxy Z Flip 8. It’s Time to Call It Quits – Tech Advisor
Tech and Science

I Used Samsung Galaxy Z Flip 8. It’s Time to Call It Quits – Tech Advisor

July 23, 2026
Orcas Keep Punching Giant Sunfish to Smithereens, And Scientists Are Mesmerized : ScienceAlert
Tech and Science

Orcas Keep Punching Giant Sunfish to Smithereens, And Scientists Are Mesmerized : ScienceAlert

July 22, 2026
logo logo
Facebook Twitter Youtube

About US


Explore global affairs, political insights, and linguistic origins. Stay informed with our comprehensive coverage of world news, politics, and Lifestyle.

Top Categories
  • Crime
  • Environment
  • Sports
  • Tech and Science
Usefull Links
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA

© 2024 americanfocus.online –  All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?