概要: IRGCとつながりのあるイラン政府支援の組織「コットン・サンドストーム」は、サイバー空間における影響力行使活動に生成AIを統合している。2023年12月には、「フォー・ヒューマニティ作戦」を開始し、AIが生成したメッセージを用いて米国のIPTVストリーミングサービスを乗っ取り、イスラエルとハマスの対立に関するプロパガンダを流した。同組織は選挙関連の偵察活動も行っており、2024年の米国大統領選挙を前にAIを活用した影響力行使活動を行っていたことが示唆されている。
Editor Notes: Other associated names of Cotton Sandstorm: Emennet Pasargad; Aria Sepehr Ayandehsazan (ASA) (since the middle of 2024, reportedly); Haywire Kitten; Al-Toufan; Anzu Team; Cyber Cheetahs; Cyber Flood; For Humanity; Menelaus; Market of Data; and NEPTUNIUM. Some other notes: (1) Cotton Sandstorm has been expanding its cyber influence operations by incorporating deepfakes and image manipulation, along with voice modulation techniques, to spread propaganda. (2) They are also associated with having compromised a French commercial display provider during the 2024 Olympics in Paris with the goal of broadcasting anti-Israel messages. (3) In May 2024, the first reported instances of their work performing reconnaissance on U.S. election and media sites was found; the purported aim was to begin laying the groundwork for operations in advance of the November 2024 elections in the United States. (4) They have also allegedly stolen data from IP cameras while harvesting information on Israeli fighter pilots and UAV operators. The date of this incident ID, 05/02/2023, is based off of the Microsoft Threat Analysis Center's report "Rinse and repeat: Iran accelerates its cyber influence operations worldwide," which points to earlier attacks attributed to Cotton Sandstorm between 2020 and the publication of the report.
Alleged: Islamic Revolutionary Guard Corps (IRGC) , Government of Iran , Cotton Sandstorm と Unknown generative AI developers developed an AI system deployed by Islamic Revolutionary Guard Corps (IRGC) , Government of Iran と Cotton Sandstorm, which harmed U.S. elections , political candidates , Media organizations , General public of the United States , Electoral integrity , Democracy と American voters.
インシデントのステータス
Risk Subdomain
A further 23 subdomains create an accessible and understandable classification of hazards and harms associated with AI
4.1. Disinformation, surveillance, and influence at scale
Risk Domain
The Domain Taxonomy of AI Risks classifies risks into seven AI risk domains: (1) Discrimination & toxicity, (2) Privacy & security, (3) Misinformation, (4) Malicious actors & misuse, (5) Human-computer interaction, (6) Socioeconomic & environmental harms, and (7) AI system safety, failures & limitations.
- Malicious Actors & Misuse
Entity
Which, if any, entity is presented as the main cause of the risk
Human
Timing
The stage in the AI lifecycle at which the risk is presented as occurring
Pre-deployment
Intent
Whether the risk is presented as occurring as an expected or unexpected outcome from pursuing a goal
Intentional
