Mitigate the threat of AI-assisted vulnerability detection and exploit creation

The relentless advance of artificial intelligence is creating new reverse engineering methods and attack vectors for software. Developers are faced with new challenges to protect their IP, revenue streams and customers.


Historically, on-premises software packages—whether that be productivity applications, video editing suites, or even games—have been sold and distributed as binaries. Not only did these precompiled executables improve runtime performance, but they also didn’t expose the high-level source code, thus protecting the most valuable asset for a software vendor: unique intellectual property. 

While it was possible to reverse engineer software and access the source code to bypass copy protection, extract IP or find vulnerabilities, the level of knowledge, skill and effort were significant. Reverse engineering an application or software suite, required a level of skill and determination that rivalled the efforts needed to develop the software in the first place. And even with that expertise, it could take months to complete and require hundreds of man-hours.

But AI has changed all that, with tools now available that can reverse engineer software in minutes, without the need for specialised teams, knowledge or skills.

The AI effect

When Anthropic unveiled Claude Mythos, it ushered in a new era of risk for both software developers and their customers. 

Mythos proved highly capable at reverse-engineering binaries and identifying production code vulnerabilities.

While Mythos was being positioned as a vital tool to protect against vulnerabilities and exploits, it highlighted that the right AI tools in the wrong hands could be disastrous.

Suddenly, reverse engineering software binaries, or finding vulnerabilities within them, no longer required significant investment, resources, man-power and commitment. Instead, anyone with access to the right AI tools and the right prompts, could achieve their goal in minutes.

Hacking before and after AI
Hacking before and after AI

Clearly, this is a serious threat to software vendors and the unique IP that they spent years developing. Bad actors being able to reverse engineer on-premises software, could result in both core IP theft and significant revenue loss for the developer as licensing models are made redundant and access controls bypassed. 

The new risk landscape

Reduced license revenue is, of course, a major issue for any software vendor, but that potential theft of unique IP is far more damaging. Any proprietary code or algorithms developed by a software house must be protected, and access to decompiled code could result in a loss of competitive advantage, or even the market being flooded with counterfeit applications. Either way, the damage wouldn’t just affect revenue, it would have a direct impact on the overall value and standing of the business. 

Meanwhile, the vulnerabilities and attack vectors that AI can potentially uncover in compromised code, could result in serious security risks, not just for the software vendor, but also its customers. If a piece of software becomes an entry point for malicious actors, resulting in data theft or even a ransomware attack, all fingers will point to the developer for not adequately securing their code. And when it comes to security breaches, nobody forgets whose software caused the issue.

It wouldn’t stop at finger pointing, either. The potential reputational damage would be another massive blow, while the regulatory scrutiny could result in significant fines if a data breach proves to be a direct result of an unknown or unpatched vulnerability. Additionally, potential litigation from affected customers could spell yet more reputational and financial damage.

And even if the worst doesn’t happen, just having exploits and vulnerabilities in software products exposed, would result in vendors having to work as fast as possible to fix the issues, essentially taking resources away from developing new features or building the next version of an application or platform. 

Compiled binaries are no longer enough

In the new AI landscape, distributing commercial software as binary executables is not sufficient – the risk of vulnerability discovery or even full reverse engineering and extraction of IP is simply too high. But while there’s no way to completely remove that risk, it can be significantly mitigated, leaving malicious actors more likely to give up and look for an easier target. 

Thales Sentinel Envelope provides a protection wrapper for on-premises software, making life as difficult as possible for any potential crackers looking for vulnerabilities to exploit or attempting to reverse engineer the binary code to extract IP or bypass license enforcement, especially if they’re using AI. 

One of the core barriers that Sentinel Envelope implements is control flow obfuscation, which scrambles the execution path of a program – the software still runs as intended, but the flow is jumbled and disconnected, meaning that any kind of automated decompilation will not be able to follow the execution path. This makes any attempt to accurately analyse the flow incredibly slow and difficult. 

Both binaries and libraries are also encrypted at rest, ensuring that attempts to analyse and disassemble the code in a static state is not possible. Only after an authorised execution call is detected, will the code be decrypted, reverting to an encrypted state once more, at rest. 

Sentinel Envelope doesn’t just protect the code at rest, it also employs proprietary technology to protect against runtime attacks, when the code is in an unencrypted state. Meanwhile the anti-tampering feature heads off any attempt to modify the code—potentially to inject exploits—by inserting integrity checkers throughout the application, which in turn must be verified at runtime.

Real world results

To highlight just how vulnerable unprotected binaries are in this new AI era, Thales created a test scenario, turning an AI powered reverse engineering agent loose on a custom bytecode VM with 10 planted vulnerabilities. In just over three minutes, the AI agent found eight of the 10 vulnerabilities, using 342,000 tokens.

Tokens consumed vs vulnerabilities found

By contrast, the same test was run under the same conditions, with the only difference being that the binary was protected by Sentinel Envelope. After six hours, the AI agent had discovered none of the 10 vulnerabilities, with a recommendation to cease analysis, having spent nearly 1,000 times the tokens of first test (332,000,000).

Preparation beats reparation 

The risk landscape for software vendors has changed dramatically, and that risk extends far beyond lost sales revenue. The potential fallout and repercussion from compromised commercial code—stolen IP, vulnerabilities and exploits, data breaches and attacks on customers, reputational damage—are impossible to fully quantify. 

The protection provided by shipping compiled binaries is no longer there, and additional, new protective layers must be put in place to ensure that on-premises software applications and platforms do not fall victim to AI-assisted analysis and reverse engineering. 

Thales Sentinel Envelope can provide that protective layer, making the task of compromising and reverse engineering code too arduous, time consuming and expensive to entertain, leaving hackers to focus their efforts elsewhere. 

To learn more about Thales Sentinel Envelope and how it can protect your software, IP and business, watch the in-depth webinar.

More from our cybersecurity section

About The Author

Avatar photo
Riyad Emeran

Riyad is a highly experienced writer and editor who has spent over 30 years writing about the technology industry. He co-founded and edited the website Trusted Reviews in 2003, having previously been Editor-in-Chief of Personal Computer World magazine, affectionately known as PCW.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.