
Multi-Modal Forensics Analysis of AI Artifacts for Cyber Threat Attribution
A 5-year NSERC Discovery program building a made-in-Canada capability to detect, fingerprint, and attribute AI-generated cyberattacks and foreign interference across text, code, and multimedia.
Canada’s security environment is being reshaped by escalating geopolitical tensions and the reality that conflicts abroad are only milliseconds away in cyberspace. Adversaries now weaponize AI to scale and conceal campaigns—from AI-written phishing and AI-assisted malware to deepfake influence operations—eroding trust, targeting critical infrastructure, and polluting our information space. This Discovery program answers that shift by developing a made-in-Canada attribution capability that can detect and fingerprint AI-generated artifacts across text, code, and multimedia, then fuse that evidence in an explainable engine to identify responsible threat actors with calibrated confidence. The long-term objective of this research program is to deliver a multimodal AI forensics and attribution framework that can detect, fingerprint, and trace AI-enabled cyberattacks and foreign interference to protect Canadian industry, government, the public, and democratic values. This 5-year research program will bridge cutting-edge AI forensics with cyber threat intelligence to uncover unique "AI utilization fingerprints" left in malicious content and use them to identify the responsible threat actors. The program is organized into two complementary themes:
- Attribution Intelligence and Modeling, which focuses on algorithms and frameworks to fuse multi-modal evidence and infer threat actor identities. It delivers the first truly end-to-end attribution framework that treats AI both as an investigative lens and as a threat vector. At its core is a unified Attribution Engine that ingests heterogeneous evidence—from phishing lures and exploit binaries to deep-fake videos—and embeds every artifact in a shared graph/attention space. By marrying this representation with a continuously updated knowledge graph of nation-state and criminal actors, enriched with new "AI-tool fingerprints", the engine produces a calibrated probability distribution over known and emerging adversaries while generating human-readable explanations that analysts can audit and refine.
- AI Forensics and Fingerprinting, which focuses on techniques to detect and characterize AI-generated malicious artifacts across modalities. Complementing the reasoning layer is a forensics pipeline that pioneers reliable detection and fingerprinting of AI-generated artifacts across text, code and multimedia. The research advances cross-lingual stylometric analysis that can not only separate humans from machine prose but also identify the most likely model family.
The two themes reinforce one another: every forensics detector outputs a confidence-weighted fingerprint that becomes evidence for the Attribution Engine, while attribution needs to inform which fingerprints are worth refining. Knowledge gleaned from one project has the potential for cross-applicability to the other. This approach not only enhances student learning but also prepares students with versatile skills needed in the fast-changing AI industry.
