Autonomous AI in OT

Kence Anderson

S4x24 - ICS Security Conference · Day 1 · Main Stage

Overview

Kence Anderson's S4 talk, "Autonomous AI in OT," provides a compelling vision of how Autonomous AI is not a distant science fiction concept, but an emerging reality already being deployed in critical operational technology (OT) environments. Anderson, an expert who has designed over 200 autonomous AI systems for major industrial players like Pepsi, Shell, and Bosch, demystifies autonomous AI, framing it as a highly engineered solution designed to augment human expertise rather than replace it. The core premise is that AI capable of making strategic, nuanced decisions in complex real-world environments is being built by engineers today, fundamentally changing how industrial processes are controlled and optimized.

Watch on YouTube

Visual summary for Autonomous AI in OT by Kence Anderson
Visual summary for Autonomous AI in OT by Kence Anderson

Key moments

  1. 0:00 Introduction to autonomous AI and security needs
  2. 2:15 What is autonomous AI? Human-like decision making
  3. 4:45 Real-world example: Autonomous AI in Cheeto production
  4. 7:00 Autonomous AI: Assisting and upskilling human operators
  5. 8:30 The five superpowers of autonomous AI introduced
  6. 9:00 Superpower 1: Perception (machinist example)
  7. 10:19 Superpower 2: Learning and gaining expertise

Autonomous AI in OT

Speakers: Kence Anderson

Conference: S4

YouTube: https://www.youtube.com/watch?v=Z6sQV9f11pw

Overview

Kence Anderson's S4 talk, "Autonomous AI in OT," provides a compelling vision of how Autonomous AI is not a distant science fiction concept, but an emerging reality already being deployed in critical operational technology (OT) environments. Anderson, an expert who has designed over 200 autonomous AI systems for major industrial players like Pepsi, Shell, and Bosch, demystifies autonomous AI, framing it as a highly engineered solution designed to augment human expertise rather than replace it. The core premise is that AI capable of making strategic, nuanced decisions in complex real-world environments is being built by engineers today, fundamentally changing how industrial processes are controlled and optimized.

This talk is particularly pertinent for OT security professionals, as it highlights the profound implications of integrating such intelligent systems into industrial control loops. Anderson meticulously outlines the "superpowers" of autonomous AI—perception, learning, strategy, planning, and deduction—and then translates these capabilities into new attack surfaces and defensive challenges. By illustrating how these systems operate and the types of data they leverage, he underscores the urgent need for security teams to engage proactively in their design and deployment, warning that a lack of involvement could lead to significant vulnerabilities and hinder the technology's overall success.

The talk serves as a critical call to action, urging security practitioners to understand the inner workings of autonomous AI to effectively secure this evolving landscape. It shifts the focus from theoretical threats to practical, real-world examples, demonstrating how seemingly minor interferences with an AI's perception system can lead to operational paralysis or dangerous misjudgments in industrial settings. As autonomous AI moves from pilot projects to widespread adoption, Anderson's insights are invaluable for preparing the OT sector for a future where intelligent machines play an increasingly active role in critical infrastructure.

Background

▶ Watch: Introduction to autonomous AI and security needs (0:00)

The concept of artificial intelligence has captivated human imagination for decades, often benchmarked against feats of human intellect. A significant milestone occurred in 2016 when Google DeepMind's AlphaGo defeated the world's best Go player, Lee Sedol. This event, following earlier AI triumphs in chess, demonstrated AI's capacity for complex strategic thinking beyond brute-force computation. However, as Kence Anderson points out, the real challenge for AI lies not in isolated games, but in navigating the messy, real-time complexities of industrial environments. The autonomous AI he discusses is not an emergent consciousness from a tech silo, but a carefully engineered system built by domain experts.

The problem autonomous AI addresses in OT stems from the inherent difficulty and time investment required to achieve expert-level human performance in many industrial operations. For instance, operating an extruder—a piece of equipment fundamental to making products like Cheetos—requires approximately 10 years of hands-on experience to master. This expertise encompasses understanding subtle cues like machine vibration, pressure, and even the sounds the equipment makes, as well as the ability to deduce unmeasured properties of raw materials (e.g., the wetness of corn) based on product output. Such nuanced, human-like decision-making, which adapts to dynamic conditions and applies complex strategies, is largely absent in traditional automation systems.

Existing automation typically excels at executing predefined rules and optimizing within narrow parameters. However, it struggles with adaptability, strategic planning, and inferring conditions from incomplete data—qualities that human experts possess. Anderson emphasizes that autonomous AI is not designed to replace these human experts but to augment them. In manufacturing plants, where only about 10% of operators are truly experts, autonomous AI can "upskill" the remaining workforce, providing them with expert-level assistance and freeing up seasoned operators for more valuable tasks. This shift represents a move from rigid, rule-based control to adaptive, intelligent decision-making that mirrors and enhances human cognitive abilities, creating a new paradigm for industrial operations and, consequently, a new frontier for security.

Key Findings

▶ Watch: Real-world example: Autonomous AI in Cheeto production (4:45)

Kence Anderson's presentation distills the capabilities of autonomous AI into five distinct "superpowers" that differentiate it from conventional automation. These capabilities are not merely incremental improvements but represent a qualitative leap in machine intelligence, enabling systems to operate with a level of sophistication previously exclusive to human experts. Understanding these superpowers is crucial for appreciating both the transformative potential and the security implications of autonomous AI in OT.

  1. Perception: Autonomous AI goes beyond raw sensor data by interpreting and classifying complex environmental cues. Anderson provides the example of an expert machinist who can discern up to 16 different sounds from a CNC machine while cutting metal, combining this auditory information with sensor readings (temperature, lubricant flow, tool speed) to achieve expert control. Similarly, a Cheeto extruder operator might "see" or "hear" subtle indicators that sensors alone don't capture. Autonomous AI systems are engineered to replicate this multi-modal perception, classifying sounds (e.g., an AI designed to classify up to nine distinct sounds for a CNC machine) or processing visual data to gain a deeper understanding of the operational state.
  1. Learning: This superpower refers to the AI's ability to gain expertise through practice and feedback, analogous to how humans learn. In industrial contexts, this means the AI can adapt to a vast array of situations and scenarios, overcoming the limitations of traditional automation that often performs well only in predefined conditions. By continually receiving feedback from the real environment, the AI refines its decision-making, much like a novice operator gradually builds experience to handle unexpected events.
  1. Strategy: Autonomous AI can formulate and execute complex strategies, mirroring human strategic thinking in domains like chess or sports. Anderson notes that industrial experts frequently articulate their operational knowledge as strategies—"when the environment looks like this, do that." Giving AI the capacity to develop and apply such strategies is fundamental to its success in dynamic, real-world industrial settings, allowing it to navigate process transitions and optimize for long-term goals.
  1. Planning: This involves the AI's ability to look ahead, consider multiple options, and simulate potential outcomes of its actions. Forward planning is a hallmark of human intelligence that is largely absent in most conventional automation systems. Autonomous AI can anticipate consequences, allowing for more robust and optimized decision-making by evaluating "what if" scenarios before acting.
  1. Deduction: Perhaps the most intriguing superpower, deduction allows autonomous AI to infer unmeasured attributes or hidden states of a system based on observable outcomes, much like human intuition. Anderson illustrates this with the Cheeto extruder: an expert operator might deduce that a new batch of corn is "wet" or "fat" (despite no direct sensor measurement) because of how the Cheetos begin to emerge from the machine. The AI, through learned experience, develops this same capacity to infer critical parameters from indirect evidence, enabling it to adjust controls even when facing incomplete sensor data.

These five superpowers collectively enable autonomous AI to operate with unprecedented adaptability, insight, and strategic depth, making them powerful tools for industrial optimization but also introducing novel security challenges that demand a new defensive posture.

Technical Deep Dive

▶ Watch: Autonomous AI: Assisting and upskilling human operators (7:00)

At its core, Autonomous AI is defined as artificial or machine intelligence capable of controlling and optimizing equipment in real-time, making decisions with a level of sophistication akin to human judgment. This goes beyond traditional automation, which typically follows predefined rules; autonomous AI actively learns, adapts, and strategizes within its operational environment.

The operational paradigm of autonomous AI is built around a feedback loop. While feedback control systems have existed since 1912 (e.g., in the US Navy), the nature of the feedback and the decision-making process in autonomous AI are significantly more advanced. Instead of simply regulating a process based on a setpoint, autonomous AI processes diverse and often sensitive data, including not just temperature and pressure but also visual information, acoustic signatures, and complex correlations, to inform its "human-like" decisions. This continuous loop allows the AI to learn "in place" and adapt to changing conditions.

Anderson proposes a two-layer architecture for structuring autonomous AI agents, a design principle that not only optimizes functionality but also informs security considerations:

  1. Perception Layer: This is the AI's "sensory input" and interpretive center. It aggregates raw data from various sensors (temperature, pressure, flow, cameras, microphones) and performs higher-level processing. This layer is responsible for:
  • Prediction: Forecasting future states or behaviors based on current and historical data.
  • Classification: Categorizing observed phenomena (e.g., classifying up to nine distinct sounds from an industrial machine, as in the CNC example).
  • Clustering: Identifying patterns or groups within data that might indicate specific operational states or anomalies.
  • Critically, the perception layer "adds additional information than what the sensors report," meaning it extracts meaning and context that raw sensor readings alone cannot provide. For instance, it might process camera data to assess the precise shape or curl of a Cheeto, or analyze acoustic data to detect subtle machine wear.
  1. Skills Layer: This layer represents the AI's "cognitive" and "action" center. It takes the enriched information from the Perception Layer and translates it into actionable decisions and control commands. This is where the AI's "superpowers" of strategy, planning, and deduction are primarily exercised. The Skills Layer is responsible for:
  • Decision-making: Determining the optimal control actions based on the perceived state, learned strategies, and predicted outcomes.
  • Planning: Formulating sequences of actions to achieve specific goals, considering future implications.
  • Acting: Sending commands to the industrial equipment (e.g., adjusting an extruder's settings, altering an oil drill's parameters, optimizing logistics routes).

Consider the Cheeto extruder example: The Perception Layer would process sensor data on temperature, pressure, and flow, but also classify sounds from the machine and potentially analyze visual input of the extruded product (curl, diameter, puff length, density). It might even deduce the "wetness" or "fatness" of the corn based on how the Cheetos are forming. This enhanced understanding is then passed to the Skills Layer, which applies learned strategies and planning capabilities to make precise adjustments to the extruder's knobs and settings, ensuring the "perfect Cheeto" every time, adapting to variations in raw materials or environmental conditions.

This layered architecture highlights that attacks on autonomous AI might not only target the traditional control system but also the AI's ability to accurately perceive and interpret its environment, or its capacity to generate correct strategies and plans. Disrupting the Perception Layer, for instance, could lead to flawed inputs for the Skills Layer, resulting in erroneous or dangerous control actions.

Demo / Proof of Concept

▶ Watch: Superpower 1: Perception (machinist example) (9:00)

While Kence Anderson's talk did not feature a live, interactive demonstration, he extensively referenced a compelling real-world use case involving PepsiCo Snack Foods and the production of Cheetos. This example served as a foundational proof of concept for the capabilities and benefits of autonomous AI in an industrial setting.

Anderson detailed how PepsiCo partnered with Microsoft and Neal Analytics to implement an autonomous AI system for their Cheeto extruders. The AI was trained by expert operators who, after a decade of experience, understood the intricate nuances of machine vibration, pressure, and the precise conditions required for the "perfect Cheeto" (correct length, diameter, curl, density, and even the internal bubble structure). This human expertise was used to train the AI, which then underwent "millions of simulations" to assess its decision-making.

The results of this trial run were described as "all successful," leading to plans for scaling the technology. The autonomous system continually tracks performance, flags issues in real-time for human intervention, and importantly, "upskills" workers by assisting them in performing their jobs better. This practical application, though presented as a video and narrative rather than a live demo, effectively illustrated how autonomous AI can manage complex processes, adapt to variations, and achieve consistent product quality, validating its utility and potential for widespread adoption in OT.

Defensive Implications

▶ Watch: Superpower 2: Learning and gaining expertise (10:19)

The introduction of autonomous AI into OT environments, while promising significant operational benefits, simultaneously introduces a new and complex array of security challenges. Kence Anderson stresses that the very "superpowers" that make autonomous AI so effective also create novel vulnerabilities that defenders must anticipate and mitigate.

The most prominent new attack surface lies within the perception system of autonomous AI. Unlike traditional control systems that rely on direct sensor readings, autonomous AI interprets and infers meaning from a diverse data stream. This expanded interpretative capability is susceptible to adversarial attacks designed to manipulate the AI's understanding of its environment. Anderson provided two striking examples:

  1. Physical Interference (Waymo/Cruise Incident): In San Francisco, individuals were able to disable Waymo and Cruise autonomous vehicles by placing a traffic cone in a specific spot on the dashboard. This act, described as interfering with a "particular attribute of the perception system," caused the vehicle to halt. In an OT context, imagine an adversary placing a seemingly innocuous object or making a subtle physical alteration that causes an industrial autonomous AI to misinterpret a critical safety state, leading to equipment damage, production loss, or even catastrophic failure.
  1. Adversarial Machine Learning (ML Model Fooling): Anderson showed an image of clothing designed to trick facial recognition systems into identifying a person as an animal (e.g., a zebra or giraffe). This illustrates how machine learning perception models can be "hacked, tricked, and fooled" through carefully crafted inputs that exploit the model's blind spots or biases. In an industrial setting, similar misperceptions could be catastrophic. An AI monitoring product quality might be tricked into believing defective products are in specification, or an AI overseeing a critical process could misinterpret sensor data, leading to dangerous operational decisions or costly manufacturing errors. For instance, an AI monitoring a chemical reaction via camera could be fed a manipulated image that causes it to incorrectly assess the reaction's state, leading to an unsafe temperature or pressure.

Beyond perception, the entire control loop of autonomous AI presents new security considerations. These systems operate with advanced decision-making, leveraging not just traditional temperature and pressure readings, but also potentially sensitive data from cameras, microphones, and other advanced sensors. Securing this expanded data pipeline and the integrity of the AI's decision-making process becomes paramount. An adversary could attempt to inject false data, corrupt the AI's learning models, or manipulate its strategic planning parameters, leading to unintended and potentially harmful actions.

A crucial takeaway for OT security professionals is the imperative to get involved early and deeply in the design and deployment of autonomous AI systems. Anderson highlighted a stark statistic: 87% of all machine learning models never make it into production. A significant reason for this failure rate is the lack of involvement from subject matter experts, including security professionals. If OT security teams are not influencing the complete design, implementation, and deployment process, businesses risk not only failing to realize the return on investment (ROI) of these technologies but also introducing profound and unaddressed security vulnerabilities into critical infrastructure. Defenders must shift from reactive incident response to proactive security by design, ensuring that the unique characteristics of autonomous AI are secured from inception.

Key Takeaways

  • Autonomous AI is a reality in OT, focused on human-like decision-making: It is being engineered today to control and optimize industrial equipment by making nuanced, strategic decisions, not simply rigid automation.
  • Five "superpowers" define autonomous AI capabilities and new attack surfaces: Perception, learning, strategy, planning, and deduction enable advanced operations but also introduce novel vulnerabilities that require specific security considerations.
  • Perception systems are highly vulnerable to adversarial attacks: Physical interference (like a cone disabling an autonomous car) or crafted inputs (like clothing tricking facial recognition) can fool ML perception models, leading to safety issues or costly errors in industrial settings.
  • Securing the autonomous AI control loop is critical: The expanded use of diverse and sensitive data (e.g., camera, acoustic) for advanced decision-making necessitates new approaches to data integrity, model protection, and ensuring the trustworthiness of the AI's outputs.
  • OT security professionals must engage proactively in autonomous AI deployment: Early involvement in the design, implementation, and deployment phases is essential to secure these systems effectively and prevent the high failure rate (87%) of ML models in production.
  • Autonomous AI augments human expertise, it does not replace it: These systems are designed to assist operators, upskill the workforce, and free up expert personnel for more valuable tasks, rather than displacing human roles entirely.

About the Speaker(s)

Kence Anderson is a recognized expert in the field of autonomous AI. Over the past seven years, he has personally designed more than 200 autonomous AI systems for a diverse range of prominent industrial companies. His client list includes global giants such as Pepsi, Coca-Cola, Shell, BP, Bayer, Bosch, and AB InBev. Anderson is also the author of the book "Designing Autonomous AI," which serves as a blueprint for the methodologies and insights he has accumulated throughout his extensive experience in implementing these advanced intelligent agents. His work focuses on bridging the gap between theoretical AI capabilities and practical, real-world applications in operational technology environments.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Anderson's talk provides a much-needed, grounded perspective on Autonomous AI in OT environments, cutting through the hype to reveal an engineered reality. He meticulously outlines its unique capabilities and, critically, translates these into novel attack surfaces and urgent defensive challenges. The talk is a compelling call to action for OT security professionals to engage proactively in securing these systems, offering concrete insights into how an AI's perception and decision-making can be manipulated, which is invaluable for anyone facing this emerging threat landscape.

Heather Calloway (CISO) — STRONG ACCEPT

Anderson's talk on Autonomous AI in OT is a critical, clear-eyed assessment of an emerging technology that will fundamentally reshape industrial operations and, consequently, their risk profiles. He moves beyond theoretical AI threats to concrete, real-world vulnerabilities introduced by these intelligent systems, particularly within their perception layers. The value lies in his direct call for security leaders to engage proactively in the design and deployment of autonomous AI, ensuring accountability and preventing significant operational and business exposure before these systems become entrenched.

→ Top-rated talks at S4x24 - ICS Security Conference

All talks from S4x24 - ICS Security Conference