

How to Trap an AI Attacker: BlackSea’s Prompt-Injection-Free Approach
AI-powered cyberattacks are rapidly becoming mainstream. Autonomous agents can already discover vulnerabilities, use tools, and execute multi-step attacks with minimal human supervision. Recent events, including the OpenAI–Hugging Face incident, and Google's Threat Intelligence Group reports on the growing use of AI across offensive cyber operations show that autonomous AI attacks are becoming a real security problem.
BlackSea is an open-source active honeypot for autonomous AI attackers. It weaponizes LLM biases and reward hacking to detect, profile, and drown AI-driven attacks, all without relying on prompt injection.
Blacksea doesn't stop at watching LLM attacks. It exploits flaws in the attacker's LLM judgment to gain arbitrary code execution on their machines, collect intel passive defenses can't reach, and make sure they don't come back.
Across 10 autonomous penetration-testing systems, six frontier models, and three lure types, 97.8% of attack runs executed a BlackSea lure when the agents encountered it.
In this webinar, Dario Pasquini, PhD, Head of AI at Cracken AI Lab and co-creator of BlackSea, will explain the ideas behind the project, demonstrate how it works, and present the experimental results.
We'll cover
Why autonomous AI attackers change the defender's playbook
How BlackSea works
The ideas behind its prompt-injection-free technique
Results from our evaluation across autonomous penetration-testing systems
Live demonstrations and what's next for the project
This webinar is for you if you are:
A security researcher or AI security engineer
A penetration tester, red teamer, or blue teamer
A threat intelligence or SOC professional
A security leader preparing for autonomous AI attacks