Petty Proteins When Molecules Go Rogue& Why Cyberbiosecurity

Tia Pope

Blacks in Cyber Village @ DEF CON 33 · Day 1 · Blacks in Cyber Village

Overview

In an era where technological advancements rapidly reshape our world, the intersection of artificial intelligence and biotechnology presents both unprecedented opportunities and grave, often overlooked, security risks. Tia Pope's compelling talk, "Petty Proteins When Molecules Go Rogue & Why Cyberbiosecurity," delivered at the Blacks in Cyber Village conference, serves as a critical wake-up call to the emerging field of cyberbiosecurity. Pope, a cybersecurity expert nearing her PhD, argues that humanity is at a "Twilight Zone" moment, distracted by less significant issues while the silent, microscopic world of proteins, now manipulable by AI, poses an existential threat.

Watch on YouTube

Visual summary for Petty Proteins When Molecules Go Rogue& Why Cyberbiosecurity by Tia Pope
Visual summary for Petty Proteins When Molecules Go Rogue& Why Cyberbiosecurity by Tia Pope

Key moments

  1. 0:00 Introduction to cyber bio space and its importance
  2. 2:00 Extending 'code' concept to protein sequences
  3. 3:20 Non-traditional background finding cracks in cyber-bio
  4. 4:40 Emphasizing the value and unknowns of proteins
  5. 6:00 Proteins as 'workers': impact on medicine, health, environment
  6. 6:50 The 'war' of proteins: beneficial vs. harmful roles

Petty Proteins When Molecules Go Rogue & Why Cyberbiosecurity

Speakers: Tia Pope, PhD Candidate

Conference: Blacks in Cyber Village

YouTube: https://www.youtube.com/watch?v=ZqjADCvE5UQ

Overview

In an era where technological advancements rapidly reshape our world, the intersection of artificial intelligence and biotechnology presents both unprecedented opportunities and grave, often overlooked, security risks. Tia Pope's compelling talk, "Petty Proteins When Molecules Go Rogue & Why Cyberbiosecurity," delivered at the Blacks in Cyber Village conference, serves as a critical wake-up call to the emerging field of cyberbiosecurity. Pope, a cybersecurity expert nearing her PhD, argues that humanity is at a "Twilight Zone" moment, distracted by less significant issues while the silent, microscopic world of proteins, now manipulable by AI, poses an existential threat.

The talk meticulously dissects how the accelerated pace of AI-driven protein engineering, epitomized by tools like AlphaFold and generative models, has dramatically lowered the barrier to creating novel biological agents. Pope highlights the alarming reality that many of these powerful tools, readily accessible to anyone with computational resources, completely lack guardrails or ethical safeguards. This oversight creates a fertile ground for malicious actors, disgruntled individuals, or even accidental generation of "superbugs" and bioweapons, transforming proteins—the fundamental "workers" of life—into potential instruments of mass disruption. Pope’s unique interdisciplinary background, bridging traditional cybersecurity with computational biology, offers a fresh perspective on identifying and addressing these critical vulnerabilities before they escalate into global crises.

Background

▶ Watch: Introduction to cyber bio space and its importance (0:00)

The premise of Pope's research is rooted in a profound observation: while the world grappled with the COVID-19 pandemic, a "small virus" that had global repercussions, the underlying mechanisms and future vulnerabilities in the biological realm were not being adequately addressed from a security standpoint. She draws a powerful analogy to the Twilight Zone episode where a man, engrossed in reading, misses the apocalypse, only to find his glasses broken in a world where reading is now impossible. Pope suggests we are similarly focused on the wrong things, neglecting the impending "cyberbio" apocalypse.

Pope's personal journey into this space, inspired by a Friday movie reference about getting "fired on your day off," underscores the idea of individuals with time and motive exploring new, potentially dangerous avenues. She likens the intricate nature of protein sequences to "code" – a concept familiar to cybersecurity professionals but often overlooked in biological contexts. Just as a small script like "Mosart's ghost" in the movie The Net can have a huge impact, a minor alteration in a protein sequence can fundamentally change its function and biological effect.

Crucially, Pope approaches this domain not as a biochemist or structural biologist, but as a cybersecurity expert with extensive experience in healthcare, software engineering, embedded systems, and machine learning. This non-traditional background, she contends, provides a distinct advantage, enabling her to identify "cracks" and vulnerabilities that specialists within traditional biological fields might miss. She even recounts "doing a lot of damage just by Google searching alone," demonstrating the accessibility of information that, when combined with computational tools, can reveal significant risks.

Proteins, as Pope explains, are the "workers" of the body, far more complex and harder to control than DNA or RNA, which are often the focus of biological research. While DNA serves as the blueprint and RNA as customization, proteins execute diverse functions, from fighting viruses as antibodies and enzymes, to building and repairing tissues, or even forming hair, skin, and nails. Their diverse roles also encompass dangerous aspects, such as the structures used by viruses like COVID-19, mutations leading to cancer, or misfolded proteins causing diseases like Alzheimer's. Proteins, while not inherently malicious, become dangerous when their behavior is altered by environmental factors like pH, inflammation, or oxygen levels.

The concept of cyberbiosecurity emerges from this understanding. Pope envisions a future where biological threats are monitored with the same vigilance as network intrusions, akin to a 24/7 Security Operations Center (SOC). While dashboards from organizations like the CDC track respiratory viruses, these are largely reactive. National frameworks, such as those from MITRE, have begun to bridge cyber and bio, incorporating elements like automation in hacking, genetic treatment, and pathogen tracking into their models. However, Pope stresses that biological vulnerabilities are dynamic, "morph[ing] over time" in as little as 10 seconds, posing a significant challenge to traditional security paradigms. The prediction of emerging "superbugs" and the role of recent technological advancements in their potential creation further amplify the urgency of this new security domain.

A pivotal development in this context is the rise of AI. Pope highlights AlphaFold, a tool that can predict the 3D structure of a protein in minutes or even seconds—a process that historically took weeks, months, or years and formed the basis of entire careers. This acceleration dramatically reduces the time and resources needed for protein research and engineering. Furthermore, the advent of transformer architectures, as seen in models like GPTs and BERT, has revolutionized natural language processing by allowing parallel processing of inputs, significantly outperforming older recurrent neural networks that processed information sequentially. These AI advancements, while used for good (e.g., in COVID-19 vaccine development), have also been implicated in generating proteins that led to outbreaks, underscoring their dual-use potential. The widespread accessibility of these generative AI models means that "little Chrises"—disgruntled or curious individuals—can now easily explore and potentially exploit biological systems, making it increasingly difficult for defenders to keep pace.

Key Findings

▶ Watch: Non-traditional background finding cracks in cyber-bio (3:20)

Tia Pope's research and presentation reveal several critical findings concerning the intersection of AI and protein engineering, emphasizing the urgent need for robust cyberbiosecurity measures:

  • Pervasive Lack of Guardrails in AI Protein Models: A central and alarming finding is that 100% of the AI models evaluated by Pope for protein generation and analysis completely lack built-in guardrails. These models, including widely accessible open-source tools, offer no flags or warnings to indicate the potential maliciousness of a generated protein sequence, its impact on specific demographics, or even basic usage restrictions (e.g., "wait 10 seconds before generating another sequence"). This absence of ethical or safety controls creates a significant vulnerability.
  • Dual-Use Potential of Engineered Proteins: Pope explicitly highlights the inherent dual-use nature of many engineered proteins. She cites the example of conotoxins from sea snails, which are being researched for neural-based treatments but could also be weaponized as agents of mass destruction. The same AI tools developed for therapeutic innovation can, with slight modifications or different intentions, be repurposed for harmful ends, often without any explicit indicators within the models themselves.
  • Rapid Generation of Malicious Biological Agents: The talk underscores the frightening speed and ease with which potentially dangerous biological agents can be created using these AI tools. Pope personally attests to having "created a pretty nasty version of HIV" within 30 minutes using these models. This anecdote, while startling, concretely demonstrates the low barrier to entry for generating highly impactful biological sequences, even for individuals without deep biological expertise.
  • High Real-World Translation Accuracy: Pope's research includes a crucial validation step: she developed 40 wet lab assays, involving both E. coli and human tests, to evaluate the real-world efficacy of proteins generated in silico. Her findings indicate a 90% accuracy in translating these computationally designed proteins into tangible biological effects in a laboratory setting. This high rate of translation eradicates any notion that AI-generated sequences are purely theoretical, confirming their potential for real-world impact, whether beneficial or harmful.
  • Difficulty in Tracing Origins and Attributing Malicious Creations: With the proliferation of generative AI models, identifying the origin of a novel, potentially malicious protein sequence becomes a significant challenge. Without mechanisms to "reverse engineer" or attribute a sequence to a specific model or source, it becomes nearly impossible to track, respond to, or prevent the spread of such agents. This lack of attribution capability leaves defenders perpetually playing catch-up.
  • Exploitable Knowledge Gaps in Public Databases: Pope points out that while public databases like UniProt contain vast amounts of protein information, many proteins remain poorly studied or have only generic annotations ("name unknown"). These gaps in collective biological knowledge present opportunities for malicious actors to engineer and deploy proteins whose functions are not yet fully understood or cataloged, making detection and mitigation more difficult.

These findings collectively paint a stark picture of a rapidly evolving threat landscape where technological prowess in biology has outpaced security considerations, creating an urgent imperative for new defensive strategies and ethical frameworks.

Technical Deep Dive

▶ Watch: Emphasizing the value and unknowns of proteins (4:40)

Tia Pope's talk delves into the technical underpinnings of AI-driven protein engineering, emphasizing how advancements in machine learning are transforming the biological landscape and simultaneously introducing novel security challenges. At its core, her argument hinges on the analogy of protein sequences as a form of "code," programmable and manipulable much like software.

The fundamental unit of this biological code is the amino acid, which combine in specific sequences to form proteins. The sequence dictates the protein's unique 3D structure, which in turn determines its function. Historically, deciphering this structure and predicting function was an arduous, time-consuming process. However, recent breakthroughs in AI have drastically changed this.

Pope highlights AlphaFold, developed by DeepMind, as a groundbreaking tool that can predict the 3D structure of a protein from its amino acid sequence with remarkable accuracy and speed—often in minutes or seconds, a task that once consumed years of research. This capability is critical because a protein's structure is directly linked to its function; understanding the structure is a prerequisite for understanding what a protein does.

Beyond structure prediction, Pope focuses on generative AI models that can create new protein sequences. She introduces two key types of transformer-based models pertinent to her research:

  1. ESM (Evolutionary Scale Model): This is primarily an encoder model, designed for classification and discriminative tasks. Given a protein sequence, ESM can predict its potential function, such as whether it's an enzyme, has therapeutic properties, or other characteristics. It can also analyze the effects of mutations on protein function and identify potential binding sites, which are crucial for understanding how proteins interact with other molecules or receptors. Pope demonstrated how an AI-generated sequence could be run through ESM to predict its enzymatic properties, providing insights that traditionally would require extensive wet lab experimentation. ESM effectively helps to "take you out of the wet lab for a little bit" by providing rapid computational assessment.
  2. ProGPT2: This is a decoder model, specifically used for generating novel protein sequences. Akin to how large language models generate human-like text, ProGPT2 takes a "seed" (a short sequence of amino acids) and extrapolates, creating entirely new, potentially functional protein sequences. Pope notes that it can even generate sequences from no input, underscoring its autonomous generative capability. The models leverage transformer architectures, which process inputs in parallel, allowing for much faster and more comprehensive sequence generation and analysis compared to older recurrent neural networks that process data sequentially.

The workflow for a malicious actor, or even an unwitting researcher, could involve using ProGPT2 to generate a vast database of novel protein sequences. These sequences could then be fed into ESM to quickly classify their potential functions, identifying those with desirable (or undesirable, from a defensive perspective) properties like enzymatic activity, neurotoxic effects, or therapeutic potential. Public databases like UniProt can then be used to cross-reference known information about similar sequences or functions, filling in gaps or validating predictions.

Pope also mentions Neurosap as a cloud-based repository of models that can predict protein-substrate interactions, allowing researchers to computationally assess how a generated protein might interact with other biological components. While these computational predictions still ideally require wet lab validation, the AI tools significantly streamline the initial design and screening phases, making the creation of novel biological entities faster and more accessible than ever before. This technical ease, combined with the lack of ethical oversight in the models themselves, forms the core of the cyberbiosecurity challenge.

Demo / Proof of Concept

▶ Watch: Proteins as 'workers': impact on medicine, health, environment (6:00)

While Tia Pope's talk did not feature a live, interactive demonstration in the traditional sense, she provided compelling evidence of the capabilities and risks associated with AI-driven protein engineering through her personal research and experiences, effectively serving as a powerful proof of concept.

Pope described a practical workflow that exemplifies the ease with which novel proteins can be generated and their functions predicted. She explained taking a sequence generated by a model like ProGPT2—which can create new protein sequences even from minimal or no input—and then feeding it into an analysis model like ESM (Evolutionary Scale Model). In one instance, she explicitly stated that she took a sequence generated by ProGPT2, put it through ESM, and it predicted the sequence as an enzyme. ESM further provides detailed information that can be cross-referenced with public databases like UniProt to gain deeper insights into its potential properties, mutation effects, and binding sites. This process, which can be done entirely computationally, bypasses the need for initial, time-consuming wet lab work, dramatically accelerating the discovery and design of novel proteins.

Perhaps the most striking "proof of concept" shared by Pope was her personal revelation: "within 30 minutes, I created a pretty nasty version of HIV." This stark confession powerfully illustrates the rapid and effortless generation of highly dangerous biological agents using these accessible AI tools. It underscores that the theoretical threat is not only real but achievable by individuals with moderate computational skills and access to open-source models, without requiring extensive biological expertise or specialized lab equipment. Her immediate concern and struggle to find "proper channels" to report this discovery further highlight the current vacuum in ethical guidelines and reporting mechanisms for such findings.

Furthermore, Pope's rigorous validation work adds significant weight to the real-world implications of these AI capabilities. She revealed that her research involved developing 40 wet lab assays, conducted with both E. coli and human tests, to experimentally validate the functions of proteins generated in silico. These experiments demonstrated a 90% accuracy in translating the computationally predicted properties into actual biological effects in a laboratory setting. This high accuracy rate is critical; it moves the discussion beyond theoretical risks to tangible, demonstrable threats. It confirms that AI-designed proteins are not merely abstract digital constructs but can manifest with predictable and potent biological activity in the real world, solidifying the urgency of cyberbiosecurity.

Defensive Implications

▶ Watch: The 'war' of proteins: beneficial vs. harmful roles (6:50)

The urgent need for robust cyberbiosecurity measures is a central theme of Tia Pope's talk, which outlines several critical defensive implications and proposed solutions to mitigate the risks posed by AI-driven protein engineering.

The most pressing defensive implication is the absence of guardrails in current generative AI protein models. Pope explicitly states that 100% of the models she has analyzed lack any built-in flags or warnings for potentially malicious output. This necessitates the development and integration of ethical safeguards directly into these tools. These guardrails should, at a minimum, identify sequences with known toxic properties, flag potential for weaponization, or even implement rate limiting to prevent rapid, large-scale generation of novel sequences.

To address this, Pope is actively developing two prototype models:

  1. Craig: Named after a character from Friday, Craig is envisioned as a framework and model designed to flag risks associated with generative protein models. Its purpose is to serve as an add-on or wrapper for existing models, providing an immediate assessment of potential hazards in newly generated protein sequences. This would empower users, especially those aiming to act ethically, to identify and halt the creation of dangerous biological agents before they progress further.
  2. Debo: Also drawing inspiration from Friday, Debo is a model focused on attribution and origin discrimination. Its goal is to reverse engineer AI-generated protein sequences or 3D predictions to identify their source model. By analyzing patterns and characteristics unique to different generative AI architectures, Debo aims to create a forensic capability, allowing defenders to trace the lineage of a malicious sequence back to the specific AI model that created it. This would be a crucial step in understanding the spread of biothreats and potentially holding malicious actors accountable.

Beyond these technical solutions, Pope emphasizes the importance of a multi-faceted defense strategy:

  • Community Involvement and Open-Source Contribution: Pope advocates for cybersecurity experts, developers, and researchers to actively engage with the open-source biological AI community. She urges them to identify "mom and pop models" on platforms like GitHub that lack controls and to contribute by adding ethical checks, improving model evaluation, and scrutinizing training data for biases or vulnerabilities. This collaborative approach can help embed security by design into the foundation of these tools.
  • Public Database Validation and Gap Filling: Pope highlights the numerous "holes" in public biological databases, where many proteins are either poorly studied or lack detailed annotations. She suggests computationally running existing analysis tools against these databases to fill in missing information, thereby reducing the unknowns that malicious actors could exploit. Increasing the collective knowledge base makes it harder for novel threats to go unnoticed.
  • Regulatory and Policy Frameworks: While acknowledging that some governments, including the US, recognize the defensive potential of AI against these threats, Pope points out the significant lag in establishing effective mitigations or regulations. She notes that existing guidance, such as the FDA's directives on AI-generated biologics, primarily focuses on development and residual use rather than biosecurity implications. There is an urgent need for global collaboration to establish international regulations and restrictions on the development and application of these powerful tools, preventing a "race to the bottom" in weaponization.
  • Public Awareness and Education: Pope encourages "lay people" to become "people who Google"—to understand basic biological concepts like amino acids, familiarize themselves with public databases, and critically validate information about new pathogens. Increased public awareness can foster vigilance, encourage critical thinking, and potentially surface early warnings of novel threats that might otherwise be missed by official channels.

Ultimately, Pope stresses that in the "race" against malicious actors, traditional distinctions between "white hat," "black hat," or "grey hat" become less relevant; everyone is in the same race to prevent catastrophic outcomes. Her call to action is for collective effort, innovation, and ethical responsibility to build a robust cyberbiosecurity posture before the "Debo" of biological threats overwhelms our defenses.

Key Takeaways

  • AI-driven protein engineering represents a critical and under-addressed cyberbiosecurity threat, capable of generating novel biological agents with unprecedented speed and ease.
  • A fundamental flaw in current AI protein generation models is the complete absence of built-in guardrails, allowing for the creation of potentially malicious sequences without any ethical or safety flags.
  • Engineered proteins possess significant dual-use potential; innovations developed for therapeutic or beneficial purposes can be readily repurposed and weaponized by malicious actors.
  • Traditional cybersecurity expertise is indispensable for identifying vulnerabilities, developing defensive strategies, and establishing ethical frameworks within the rapidly evolving biological domain.
  • New proactive defensive models, such as Craig (for risk flagging) and Debo (for origin attribution), are urgently needed to embed security into the AI protein engineering lifecycle and enable effective threat response.
  • Mitigating these emerging biological risks requires a multi-pronged approach involving community collaboration, open-source contributions, regulatory frameworks, and increased public awareness and validation of biological information.

About the Speaker(s)

Tia Pope is a distinguished PhD candidate, slated to defend her dissertation in December, bringing her extensive expertise to the nascent field of cyberbiosecurity. Uniquely positioned at the intersection of traditional cybersecurity and computational biology, Pope holds a robust background in cybersecurity, healthcare, software engineering, interoperability, embedded systems, and machine learning. Unlike many researchers in this domain, she does not come from a traditional biochemistry or structural biology background, an aspect she views as an advantage, enabling her to identify overlooked "cracks" and vulnerabilities in biological systems from a security perspective.

Pope computationally studies proteins, focusing on the security implications of AI-driven protein engineering. Her pioneering research involves developing innovative models like "Craig," designed to flag risks in generative protein models, and "Debo," aimed at discriminating the origins of AI-generated biological sequences for attribution purposes. A passionate advocate for interdisciplinary collaboration, Pope actively encourages individuals from diverse backgrounds, particularly those with cybersecurity expertise, to engage with and contribute to the crucial work of building a robust cyberbiosecurity defense. Her work underscores a profound commitment to addressing the urgent, global challenges posed by the convergence of AI and biotechnology.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Pope is doing real, original work at an intersection most of this community has never seriously engaged with — and she's validating it in wet lab, not just vibes. The 90% translation accuracy across 40 assays is the number that makes this more than a thought experiment, and the 'zero guardrails across 100% of evaluated models' finding is the kind of concrete, reproducible claim that justifies conference airtime.

Heather Calloway (CISO) — SOLID

Pope identifies a real and underexamined threat surface — unguarded AI protein generation tools with demonstrated real-world translation accuracy — and backs it with original research that goes beyond theoretical alarm. The talk earns its credibility through the 40-assay validation study and the 90% in-silico-to-wet-lab accuracy finding, but it stops well short of giving institutional decision-makers anything to act on.

→ Top-rated talks at Blacks in Cyber Village @ DEF CON 33

All talks from Blacks in Cyber Village @ DEF CON 33