Anthropic and PNNL AI Critical Infrastructure Defense Research

Anthropic and the Pacific Northwest National Laboratory (PNNL) have demonstrated that AI can significantly accelerate the identification of vulnerabilities in critical infrastructure, reducing the time required for adversary emulation from multiple weeks to just three hours. This proof of concept shows how AI-driven red teaming can help defenders close security gaps in essential systems, such as water treatment plants, before they are exploited by attackers.

Accelerating Adversary Emulation with AI

AI models can be used to automate adversary emulation—the process of modeling specific threat actors or attacks against a network to identify vulnerabilities and detection blind spots. By re-emulating attacks after implementing defensive changes, security teams can objectively evaluate the effectiveness of those adjustments.

To achieve this, PNNL developed a "scaffold" for Claude that translates natural language prompts into complex attack chains. This system utilizes pre-defined code-based tools that enable the model to execute actions on computer networks more efficiently.

Case Study: Water Treatment Plant Simulation

Researchers tasked the Claude-powered agent with emulating attacks against a high-fidelity cyber-physical model of a water treatment plant. This simulation was conducted using a Control Environment Laboratory Resource platform operated by PNNL on behalf of the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA).

Key findings from the simulation include:

  • Efficiency Gains: Attack reconstruction that typically takes human experts multiple weeks was completed in three hours.
  • Model Resourcefulness: During testing, Claude demonstrated the ability to adapt when a pre-defined tool for bypassing Windows User Account Control (UAC) failed. The model identified and implemented an alternative, known UAC bypass technique to achieve its objective.

This simulation was conducted in summer 2025 using Claude Sonnet 4. Anthropic notes that as model capabilities continue to evolve, this level of resourcefulness and creativity is expected to increase, benefiting both attackers and defenders.

The Role of Public-Private Partnerships in National Security

Defending critical infrastructure requires a combination of frontier AI intelligence and specialized physical testing environments. The collaboration between Anthropic and PNNL illustrates a complementary partnership where neither party could have conducted the experimentation independently: Anthropic provided the model intelligence, while PNNL provided the cyber-physical assets and domain expertise.

This project is part of a broader strategy to apply AI to cyber defense and national security. Other related collaborations include:

  • Nuclear Safeguards: Working with the National Nuclear Security Administration to develop evaluations and mitigations for AI-associated nuclear risks.
  • The Genesis Mission: A Department of Energy (DOE) initiative involving frontier AI companies and national laboratories to achieve scientific breakthroughs for national security.

Sources

Related

  • Dispatch
  • Dispatch
  • Dispatch
  • Dispatch
  • Dispatch