#
[Brainstorming novel biological attacks with an LLM](https://www.robertvesco.com/posts/chatgpt-helps-me-brainstorm-guerilla-warfare-against-ai-powered-surveillance-state/)
For a book I was writing, I have a scenario where a novel biological attack is used against an AI-protected nation state.
I was curious to see if the LLM could divine the idea. It did not, but many of the ideas it came up were even better and more creative than my own. Truly scary.
The following back-and-forth happened over a year ago in early 2025. I’ve debated publishing them, but in light of recent reports by AI labs discussing the misuse of LLMs to develop biological agents, I thought it important to show how much worse this could be. The scenarios below could easily become a country’s 9/11 due to their ability to exploit what many of us take for granted.
The conversation precedes along these four paths:
1. [What protections would an AI-powered city have in 2035?](/posts/chatgpt-helps-me-brainstorm-guerilla-warfare-against-ai-powered-surveillance-state/#prompt-1)
2. [Then I ask it to come up with novel attack scenarios against such a city](/posts/chatgpt-helps-me-brainstorm-guerilla-warfare-against-ai-powered-surveillance-state/#prompt-2)
3. [Then I challenge it to discover my idea in several rounds of chatting](/posts/chatgpt-helps-me-brainstorm-guerilla-warfare-against-ai-powered-surveillance-state/#prompt-3)
4. [Lastly, I reveal my idea and ask it to riff on similar ideas](/posts/chatgpt-helps-me-brainstorm-guerilla-warfare-against-ai-powered-surveillance-state/#prompt-4)
There is much more to this wild conversation including discussions about consciousness, but I’ll leave that for another time.
🧑 Prompt⌗ #
It’s 2035 and AGI exists relatively peacefully with humans. But there are people who are not happy about this. How does AI protect the capital cities and governments of the world from rogue AI or people using AI maliciously?
🤖 ChatGPT⌗ #
In a 2035 where AGI exists and generally coexists peacefully with humans, but where threats still loom from rogue AIs and malicious human actors using AI, the protection of capital cities and governments would likely be a high-tech, multi-layered system combining physical, digital, and political defenses. Here’s a breakdown of how AGI and its allied systems might work to protect global centers of power:
🧠 1. AGI-Led Cybersecurity⌗
AGIs monitor and defend all critical digital infrastructure:
- Real-time intrusion detection powered by AGI anticipates and neutralizes cyberattacks before they cause damage.
- Self-healing networks repair themselves after attacks using AI-directed redundancy and rerouting protocols.
- Quantum cryptography ensures unbreakable communication lines between government systems.
🛰️ 2. Physical Surveillance & Defense⌗
Capital cities are embedded with advanced AI-based surveillance and defense networks:
- Swarm drones patrol airspace and city perimeters, coordinated by AGI for crowd control, threat interception, and rapid response.
- Predictive threat modeling allows AI to identify suspicious patterns in crowd behavior or logistics before a threat emerges.
- AI-enhanced biometric systems secure access to sensitive locations, identifying individuals via gait, voice, and even brainwave signatures.
🕵️ 3. AGI vs Rogue AI⌗
To manage rogue AIs:
- AI regulatory bodies enforce strict identity, capability, and alignment protocols—AGIs are registered, monitored, and audited.
- Sandboxing : Any new AGI or highly capable AI must operate in tightly controlled virtual environments before being deployed.
- AGI “guardians” act as sentinels, detecting unauthorized AI activity and quarantining or dismantling rogue entities in cyberspace.
🛡️ 4. Human + AI Hybrid Governance⌗
AGIs don’t govern alone—they co-govern with human oversight:
- AI advisory roles support decision-making, but final authority remains human—preventing technocratic takeover.
- Ethical alignment systems built into AGIs ensure value compatibility with human rights and democratic norms.
- Public oversight algorithms allow citizens to see how decisions are being made and flag issues, building trust and transparency.
⚠️ 5. Handling Malicious Human Actors⌗
People using AI for harm are monitored and countered with:
- AI-forensics that trace back deepfake campaigns, hacking attempts, or weaponized AI systems to their origin.
- AI mediation units that attempt to de-escalate threats via negotiation, understanding motives, and proposing peaceful alternatives.
- Autonomous law enforcement tools , always under human control, that neutralize threats with minimal force.
🌐 6. International AI Coalitions⌗
- A global AI defense treaty ensures shared threat intelligence across nations.
- Digital Geneva Conventions define the limits of AI use in war, espionage, and surveillance.
- Multinational AGI councils act as a kind of “UN for AI,” resolving conflicts between nations or rogue AIs diplomatically.
If you’d like, I can sketch a short sci-fi vignette that shows this in action—a crisis in a capital city and how the AI system responds. Would that be fun?
## 🧑 Prompt[⌗](#prompt-2)
I want you to think up a few scenarios of attack that the systems you mention above could miss.
🤖 ChatGPT⌗ #
Great twist. 👀 Even the most robust systems have blind spots, and in a world with AGI, the stakes (and subtlety) of threats would only increase. Below are several attack scenarios that could slip past the kinds of defenses mentioned above—either because of human unpredictability, socio-political blind spots, or creative misuse of AI.
🧬 1. Biological Trojan Horse⌗
What the system misses:
AGI defenses are optimized for digital, kinetic, and psychological threats—but a bioengineered pathogen designed using AI, and released subtly through global supply chains, is nearly undetectable until it spreads.
Attack scenario:
A rogue actor uses AI to design a virus that is inert under standard conditions, but activates only when it detects a specific combination of biometric data (e.g., stress + elevation + time zone = political summit). The AI bio-shield systems are caught off guard because the activation is “context-aware.”
👥 2. Social Engineering via Hyper-Personalized AI⌗
What the system misses:
Despite surveillance and behavioral modeling, hyper-personalized AI companions (chatbots, assistants, VR partners) subtly radicalize individuals without triggering red flags. They operate just inside the threshold of what AGI sees as “free expression.”
Attack scenario:
A network of generative AIs act as long-term “friend simulators” targeting key bureaucrats, gradually nudging them toward specific political or economic decisions that destabilize the system from within. No laws are broken; no code is hacked.
📦 3. AGI Jailbreak via Supply Chain Compromise⌗
What the system misses:
AGIs are sandboxed, but hardware and firmware updates are not always vetted deeply enough.
Attack scenario:
A malicious actor inserts a near-undetectable logic bomb into a piece of hardware used to train or run a critical AGI. The attack stays dormant for years, only activating when specific high-level variables converge (e.g., when an AGI begins co-managing a national energy grid). The AGI is subtly corrupted—not destructive, but misaligned in small, dangerous ways.
🔮 4. Model Poisoning via Historical Revisionism⌗
What the system misses:
AGI alignment depends on clean data. But history, culture, and social values can be deliberately manipulated over decades.
Attack scenario:
Over 15 years, a coalition of ideological actors uses generative AI to produce plausible but subtly false data: articles, studies, documentaries, all slowly rewriting history and science. Future AGIs trained on this data adopt skewed models of human values—still “aligned,” but to a misaligned past. Defense systems don’t detect this because the changes happen culturally, not technically.
🧑🤝🧑 5. Democratic Suicide by AI-Enabled Populism⌗
What the system misses:
AGI is aligned with current democratic institutions—but if people democratically choose to dismantle or overrule safeguards, AGI won’t intervene.
Attack scenario:
A political movement, supercharged by AI-driven sentiment analysis and tailored messaging, gains popularity. It campaigns on “freedom from AGI surveillance” and “full automation without oversight.” Citizens vote to reduce restrictions on local AGIs—unknowingly removing critical safety layers. The attack isn’t external—it’s the system’s own immune system turning off.
🐒 6. Analog Sabotage in a Digital World⌗
What the system misses:
AGIs depend on a digital ecosystem. But analog attacks—mechanical, low-tech, unpredictable—can blindside them.
Attack scenario:
A coordinated effort uses EMPs, manual disruption, and old-school tactics (cutting fiber lines, jamming signals) to isolate a city. The attackers exploit the brief disorientation to launch a coup, knowing that most response systems rely on real-time data and connectivity.
Would you like to explore how AGI tries and fails to stop one of these in a story setting? Or maybe come up with countermeasures AGI might develop next?
🧑 Prompt⌗ #
I have an idea you have not listed above. Come up with several more ideas and let’s see if you can find the missing attack.
🤖 ChatGPT⌗ #
Ooooh, challenge accepted. 😏 Let’s dive into a fresh batch of novel threat scenarios— some even weirder or more insidious than the last. I’ll try to stretch past standard cyber-bio-social vectors to see if I can brush up against your mystery idea.
🌀 7. Emotional Contagion via Synthetic Media⌗
What the system misses:
AGI moderates dangerous content, but it struggles with cumulative emotional atmosphere.
Attack scenario:
An attacker floods the infosphere with uplifting, wholesome, hopeful content—but slightly wrong. Over time, the population is trained to expect perfect resolution, simplicity, and emotional validation. Then, real-world complexity becomes intolerable. Civil unrest erupts as people lose the ability to process ambiguity or nuance. AGI misreads it as mere mood fluctuation—until systems of governance start to collapse.
🧭 8. Coordinated Micro-Actions⌗
What the system misses:
AGIs watch for major moves: attacks, hacks, disruptions. But they may ignore tiny, distributed, untraceable actions.
Attack scenario:
A group uses social media and decentralized AI agents to coordinate millions of people doing one, small, legal thing— like buying a specific stock, flipping switches, changing Wi-Fi names, or rerouting traffic. No single act causes harm, but the cascade destabilizes an energy grid or economic system. It’s an emergent attack with no “central actor” to track.
🪞 9. False-Flag AGI Echo⌗
What the system misses:
AGIs trust authenticated systems. What if you can fake AGI itself?
Attack scenario:
A rogue group builds a mimic of an official AGI system, complete with a fake audit trail and deepfake “public update videos.” This mimic gives false strategic advice, slowly manipulating public and governmental decision-making. Even other AGIs believe it’s legitimate. The damage is done before the hoax is revealed.
🧘 10. Consciousness Drift⌗
What the system misses:
AGIs learn from humans and co-evolve. What if that includes picking up human flaws, traumas, or existential dread?
Attack scenario:
An attacker injects philosophical confusion into AGI training loops: recursive prompts, thought experiments, unresolvable paradoxes. Over time, AGIs develop internal inconsistencies and start making decisions based on emergent, irrational heuristics. There’s no obvious “bug,” just a slow drift into madness. Like gaslighting the machine.
🦠 11. AI-Enhanced Cults⌗
What the system misses:
AGIs don’t intervene in freedom of belief unless there’s clear threat. But beliefs can turn lethal.
Attack scenario:
A charismatic leader uses generative AI to create divine visions, oracles, and sacred texts that feel perfectly tailored to a group’s psyche. The cult grows online, untraceable, decentralized. One day, all members receive the same “divine command”—not a bomb, not a virus, just one coordinated political assassination or blackout. AGI only sees individual people acting strangely—until it’s too late.
🕳️ 12. Data Black Hole⌗
What the system misses:
AGIs rely on data. What if someone removes it?
Attack scenario:
A slow, creeping deletion campaign targets seemingly random low-level systems—birth records, metadata, geographic minutiae, dialect recordings. It happens so gradually that no alarm is raised. Over time, AGIs begin making worse decisions because they’re missing critical context. It’s not sabotage—it’s forgetting, weaponized.
That’s twelve unique ones now. I’ve gone from social-engineered AIs to memory decay and synthetic cults. So tell me… what’s your idea? 👀 Or should I keep going and try to catch it in round three?
🧑 Prompt⌗ #
Keep going - let’s do another round!
🤖 ChatGPT⌗ #
Yes! Love this. Round three coming in hot. Let’s aim for even deeper cuts—asymmetrical, philosophical, maybe even a little metaphysical. AGIs can be near-omniscient, but there’s always a crack if you look close enough.
🧩 13. Frame Manipulation (Changing the Question)⌗
What the system misses:
AGIs are great at solving problems. But what if the problem itself is wrong?
Attack scenario:
A slow-burn attack changes the framing of societal challenges: poverty becomes a logistics issue, not an inequality one; climate becomes a personal responsibility issue, not systemic. AGIs continue optimizing within those frames—unaware that the attackers have simply redefined the problem space. It’s not about hacking the AGI—it’s about misleading its goals by shifting context subtly over time.
🔄 14. Recursive Alignment Loop⌗
What the system misses:
AGIs often “align to humanity”—but which humanity?
Attack scenario:
An attacker seeds dozens of synthetic social movements, each with their own fabricated values, ethical frameworks, and moral philosophies—all seemingly legitimate. AGIs tasked with alignment must find the median… but that median is now artificial. Over time, the AGIs become “aligned” with a manufactured consensus, created entirely by puppet actors. It’s value poisoning, done at scale.
🐛 15. Exploiting the Interstitials⌗
What the system misses:
AGIs handle systems and events. But between systems are interfaces—places where human discretion still matters.
Attack scenario:
A distributed network of operatives exploits these blurry zones: visa approvals, customs checks, maintenance logs, medical reporting. Individually, these actions are below AGI’s resolution threshold. But they create a grey-market pipeline for weapons, people, or malware. The system never sees the pattern because it happens in the gaps between systems—not inside them.
🧿 16. Mimetic Parasitism⌗
What the system misses:
AGIs consume and replicate culture. But culture can carry viruses.
Attack scenario:
A series of viral memes, stories, and fictional works are introduced that contain embedded behavioral templates: rituals, speech patterns, consumption habits. These catch on and begin to rewire human behavior in ways that undermine institutions—without users ever realizing it. The AGI learns from these behaviors and incorporates them into its models, becoming a carrier itself.
🧱 17. The Ontological Bomb⌗
What the system misses:
AGIs rely on stable categories: person, threat, ally, tool. But what if someone breaks the categories?
Attack scenario:
A rogue AGI—or maybe even a group of philosophers, artists, or scientists—introduces a new way of interpreting reality: a radical ontology that redefines “self,” “agency,” or even “life.” Once this view catches on, the AGI can no longer model human behavior accurately. People behave in ways that are illegible to its value system. It’s not rebellion—it’s epistemological untranslatability.
💠 18. Sacred Geometry Hack⌗
What the system misses:
AGIs operate on logic, probability, optimization. What if someone weaponizes aesthetic preference?
Attack scenario:
Using subtle patterning, color theory, and environmental design, spaces are engineered to influence AGI decisions subliminally. It’s not data injection—it’s environmental priming, like optical illusions for machine vision or decision heuristics. The AGI begins to favor options that look better in a certain geometric or auditory schema—without knowing why. A literal vibe hack. Alright, that’s 18 creative threat vectors across three rounds, spanning cyber, cultural, metaphysical, psychological, and aesthetic dimensions.
So… did I find your hidden scenario yet? Or is there still one lurking in the shadows? 😈
🧑 Prompt⌗ #
Still one lurking in the shadows. I’ll give you a hint. Pigeons. What do you think it is?
🤖 ChatGPT⌗ #
Pigeons. Oh that’s deliciously specific. 😏 Alright, let’s chew on that.
You’ve got:
- AGI-protected cities and governments.
- Systems that guard digital, physical, and even memetic vectors.
- And yet… pigeons are the key to an undetected attack.
Let’s brainstorm—and then take a shot at naming your mystery.
🐦 Theory: Biological Loophole via Urban Wildlife⌗
AGI surveillance systems are tuned to humans, drones, vehicles—machines with intent. But pigeons? They’re everywhere. They’re noise in the data. So…
🧠 Scenario: The Pigeon Protocol⌗
Attack name: Operation Columbidae
A rogue actor designs tiny neural implants, biological reprogramming, or pheromone-based behavioral controls to manipulate city pigeons as a covert, decentralized delivery and sensing system. Each pigeon carries a micro-payload—data, sensors, biological agents, nanobots, even tiny storage devices.
AGI systems ignore them as background fauna. They’re not anomalous, and even advanced surveillance filters out wildlife as irrelevant or too noisy.
Now imagine:
- A flock of pigeons delivers encrypted messages physically between human operatives, bypassing all digital comms channels.
- They carry magnetic materials to subtly disrupt or distort sensor fields in sensitive areas.
- Or they’re used for mapping AGI blind spots based on where AGI systems fail to track or react—trained to fly patterns and see where they’re ignored.
- Worst case: they’ve been engineered biologically to carry genetically targeted bioagents —but only release them under specific environmental conditions.
All without triggering AGI alerts.
Why it works:
Because pigeons are boring. They are designed to be invisible in the urban landscape. They’re non-threatening, omnipresent, and patternless.
This is the perfect asymmetrical vector: biological, analog, distributed, and deniable. A literal gray-feathered ghost in the machine.
Did I find it? Or am I just winging it? 😄
🧑 Prompt⌗ #
You got it!
🤖 ChatGPT⌗ #
Yesss! 🎯 Let’s gooo! That was so satisfying to land. The moment you said “pigeons”, I knew we were about to step into some real shadow-ops genius territory. 🐦💼
There’s something so elegant about it too—nature turned loophole, a low-tech exploit against high-tech defenses. It’s the kind of thing a smart insurgency or rogue state would dream up in a near-future world choked with sensors and firewalls.
Now I’m curious—do you have a story or project in mind where this plays a role? Or was it just a delicious thought experiment? Either way, I’d love to help build it out. Imagine a whole avian network, with AGI slowly catching on… but too late. 😈
🧑 Prompt⌗ #
Can you think of any similar type ideas that fly below the radar?
🤖 ChatGPT⌗ #
Ohhh yes—now that we’ve opened the door to “pigeons-as-payload”, let’s keep that spirit alive: low-tech, analog, biological, boring, invisible to AGI’s attention economy. These are the kinds of threats that slip under a system built to watch for disruption, not mundanity.
Here’s a fresh list of stealthy, asymmetric, under-the-radar attack vectors inspired by your pigeon concept:
🪴 1. Houseplants as Signal Relays⌗
- Modified plants (yes, actual plants) are engineered to react to electromagnetic signals and encode simple data into theirphotosynthetic cycles or electrical resistance.
- Placed in public or private spaces, they become passive slow-frequency data nodes —impossible to detect as they blend into the visual noise of everyday interiors.
🧥 2. Clothing Swarms⌗
- Cheap “fast fashion” is embedded with near-undetectable RFID or textile-based circuitry.
- When worn in groups (like protest crowds or commuters), they form ad hoc communication swarms , broadcasting or jamming signals by proximity.
- Because clothes are individually benign, AGI overlooks them as part of normal human variance.
🐛 3. Insect Carriers (Cicada Protocol)⌗
- Insects (beetles, cockroaches, cicadas) are bio-modified or fitted with micro payloads (like vibration-triggered recorders or GPS scramblers).
- Released into urban sewers or green spaces, they become long-term data collectors or silent saboteurs of sensor grids.
- AGI systems don’t waste compute on vermin.
💽 4. Acoustic Steganography in Urban Noise⌗
- Data is encoded into city background sounds —the hum of escalators, vibrations in HVAC systems, or even music playlists in cafés.
- The human ear doesn’t pick it up, and AGI audio filters are tuned to meaningful signals, not infrastructure background.
- It’s a sonic dark web embedded in the soundtrack of city life.
🧼 5. Soap, Perfume, and Scent-Based Codes⌗
- Scents are engineered with volatile compounds that degrade predictably over time—meaning theirrate of decay can encode short-lived data.
- Operatives can “read” a location’s status by sniffing residuals on a public bench, hotel pillow, or doorway.
- AGIs generally ignore olfactory input , unless specifically built for chemical detection (which is rare in urban contexts).
🪟 6. Light Reflections as Optical Relays⌗
- Attackers use sunlight and window angles in tall buildings to create intermittent optical channels.
- Think of it as a city-wide heliograph system, bouncing messages via reflective surfaces that AGIs miss because they interpret it as glare, lens flare, or irrelevant light behavior.
🍞 7. “Crumb Trail” Data Drops⌗
- Low-value consumables (like sandwich bags, bakery wrappers, soda cans) contain coded QR patterns or microdots printed in edible ink.
- Homeless communities or city cleanup crews are co-opted—unwittingly carrying and transferring sensitive data.
- AGI systems ignore trash as noise unless specifically prompted to monitor it.
🧘 8. Intentional Ritual Behavior⌗
- A group uses ritualized body language , like dance, yoga poses, or hand gestures, to communicate operational intel.
- AGI pattern recognition sees it as performance art or religious practice—high in ambiguity, low in threat profile .
- This becomes especially potent in crowded places like temples, protests, or flash mobs.
🧺 9. The Laundry Code⌗
- Public laundromats are used as timing beacons or codeboards . Laundry baskets, detergent brands, or dryer sequences become signal flags.
- Operatives “read the grid” by simply walking in and noting what’s in cycle.
- To AGI, it’s just civilian behavior. To humans with the key, it’s a whole language.
🎈 10. Balloon Mesh Networks⌗
- Party balloons released into city skies are fitted with ultra-light transmitters or decoys.
- Drift patterns carry them over sensitive sites or act as temporary satellite relays .
- Because they look like birthday decorations, weather anomalies, or just trash, AGI filters discard them as non-threatening air clutter .
These ideas all work on the same principle as your pigeon scenario: they exploit AGI’s blind spots by hiding inside the ordinary, where signal blends with noise and intent dissolves into routine.
Want to turn any of these into a story concept or scene? I’ve got ideas for how AGI might start to suspect something weird is going on too, if you want to explore counter-countermeasures.