SEC536: Adversarial AI - Penetration Testing AI Systems


My work starts after something has gone wrong. A phone arrives on my desk, and my job is to find out what happened on it: who reached out, when the money left, which app the conversation lived in. After more than two decades of doing this for courts and law enforcement, the hardest part of the job is seeing, in the timeline, the exact moment where one conversation at home would have changed everything.
This year's Cybersecurity Awareness Month theme, from the National Cybersecurity Alliance, is “Don’t Make It Easy for Them.” Not because families are careless. Because the people running these scams are counting on nobody at home ever having talked about them.
So this hub has four conversations, one a week. None of them require new software. Each one takes an evening or less, and each one closes with something your family takes action on that night.
The families who stay off my caseload didn’t do anything fancy. They talked about it before the phone rang.
A scam where AI recreates a family member's voice from a few seconds of public audio, then uses that cloned voice in a phone call to fake an emergency and pressure a relative into sending money.
As little as three to ten seconds, often pulled from a public social media video, according to reporting on the FBI's 2025 data.
A family code word agreed on in person and never shared digitally, combined with hanging up and calling the person back on a known number.
TWO HABITS, NOT ONE
The code word. Agreed face to face, never shared digitally.
The callback. Hang up. Call the person back on a number you already have. Scams run on panic and speed; a callback removes both.
RESOURCE LINK
Report scams at ic3.gov. International families: see Get Help Now below.
Source: FBI Internet Crime Complaint Center, 2025 Annual Report (April 2026)
Tell them directly: “You will never be in trouble for telling me.” Said once, in advance, this removes the fear of punishment that keeps kids silent.
Do not pay — paying does not end it. Do not delete messages; block the account and screenshot instead. Report it at CyberTipline.org.
FOR REMOVAL
Take It Down (takeitdown.ncmec.org) helps minors get explicit images removed from participating platforms, free, and never requires uploading the image itself.
If a young person is struggling, call or text 988. International families: see Get Help Now below.
Source: NCMEC CyberTipline 2025 data; NCMEC, “The Work Never Stops,” March 2026
Yes. Generative AI can fabricate explicit images even when a teen never sent a real photo, according to NCMEC's 2025 data.
72% of US teens have used an AI companion, and about half use one regularly, according to a 2025 Common Sense Media survey of 1,060 teens.
Source: Common Sense Media, “Talk, Trust, and Trade-Offs,” July 2025 (n=1,060 teens, ages 13–17)
Which ones do you use? What do you talk about? Has one ever said something that made you uncomfortable? Open questions surface more than a yes-or-no rule.
Real names, locations, school names, and photos should stay out of any AI companion conversation.