1 of 20

CAMP 11th Annual Meeting

Will AI Change Everything?

Predictions & recommendations for fighting internet abuse at scale

David Freeman | Principal Scientist, Delphi Research

Seoul, Korea · 7 July 2026

2 of 20

2

SETTING THE STAGE

What is “Cybersecurity”?

Wikipedia:

Protecting software, systems, and networks from threats that lead to unauthorized disclosure, theft, or damage.”

My definition:

“Preventing people from using computers to cause harm.”

Financial loss

Denial of service

Data leakage

Physical harm

3 of 20

3

SETTING THE STAGE

What do I know about Cybersecurity?

3.5B

fake accounts disabled

Meta Transparency Report

5B

malicious ads blocked

Google Ads Safety Report

Millions

of advertisers verified

Meta / Google

Trillions

of scraping requests blocked

Meta Press

14 years working on high-volume adversarial problems:

  • Fraud & scams
  • User authentication & impersonation
  • Unauthorized data scraping
  • and others…

Incidence will never go to zero.

The goal is to get the problem under control.

(2012-17) (2017-26)

4 of 20

Principles for Fighting Abuse at Scale

1. What gets measured gets fixed

2. Everything is a tradeoff

3. Change the economics

4. Focus on behavior

5 of 20

5

PRINCIPLE #1

What gets measured gets fixed

Example: Verifying advertisers

Which of these events should we count to size the problem?

These are all bad things. Only one reflects a bad user outcome.

Fake IDs accepted

Ads from unregistered businesses

Scam ads viewed

Advertiser location mismatches

Unverified advertiser actions

Scam ads viewed

6 of 20

6

PRINCIPLE #1, CONTINUED

Measure using multiple techniques

📣 User

reporting

Reflects what users

care about

Noisy, biased, can be

gamed

Best for: attack discovery

🏷️ Expert

labeling

High quality,

statistically robust� Expensive to scale

Best for: assessing interventions

📊 Proxy

metrics

Easy to scale� Loosely coupled with

the real goal

Best for: continuous monitoring

No single method is enough — monitor & set goals on as many as possible.

🎯 Red-� teaming

Uncovers complex

vulnerabilities

Doesn’t reflect attacker

behavior “in the wild”

Best for: proactive defense

7 of 20

7

PRINCIPLE #1, CONTINUED

Segment to find the low-hanging fruit

…breakdown after reducing unverified population

Solve one problem at a time. Focus on the segment with the biggest opportunity.

Example: Verifying advertisers

FICTIONAL breakdown of scam ads by advertiser segment:

initial breakdown…

8 of 20

  • Don’t count how many things you blocked.

8

PRINCIPLE #1, CONTINUED

Avoid common measurement mistakes

Takeaway: constantly re-measure, re-segment, re-prioritize.

  • Don’t “grade your own homework.”

  • Don’t assume your metric quality is constant.

9 of 20

9

PRINCIPLE #2

Everything is a tradeoff

High Security

Low Friction

  • Every “bad user outcome” metric has a “user friction” countermetric.
    • accounts compromised ↔️ users locked out
    • sensitive data scraped ↔️ benign actions blocked
    • loss due to fraud ↔️ loss of subscription revenue
  • Countermetrics are different from harm metrics:

Not adversarially controlled

Requires counterfactual assessment (holdout)

10 of 20

10

PRINCIPLE #3

Change the economics — Raise attack cost

Attackers are economically motivated.

Make the attack more expensive to run. For example:

Require login to access data.

Require verification to perform risky actions.

Adjust requirements based on probability of bad outcomes.

Go after financial chokepoints (see Kondrashin et al, McCoy et al)

Do all of the above (“defense in depth”)

11 of 20

11

PRINCIPLE #3, CONTINUED

Change the economics — Reduce attack value

Attackers are economically motivated.

If you can’t make the attack more expensive, make it pay off less per success.

Limit the number of actions a single account can perform.

Limit the amount of data returned per request.

Limit potential financial loss per user.

(& vary limits across segments)

12 of 20

12

PRINCIPLE #4

Don’t play “Whack-a-mole”

13 of 20

13

PRINCIPLE #4

Focus on behavior, not content

Attackers will always be anomalous in some dimension — the key is to

collect enough data to identify the anomaly.

Do less of these things:

Do more of these things:

Invest in content classifiers to find violating instances.

Invest in clustering algorithms & cluster classification to find violating groups.

Block specific IP addresses, app versions, text strings, etc.

Dynamically assess IP activity, app usage, content generation, etc. vs. benign baseline.

Engage in an arms race to stop deep fakes.

Corroborate multiple identity sources against each other.

14 of 20

14

PRINCIPLE #4, CONTINUED

Use information asymmetry in your favor

  • Graph data
    • users
    • devices
    • locations

  • Baseline distributions
    • action type
    • request latency
    • system parameters

15 of 20

Now AI is Here!

What Changes?

1. What gets measured gets fixed?

2. Everything is a tradeoff?

3. Change the economics?

4. Focus on behavior?

16 of 20

16

HOW AI CHANGES THE GAME

Both sides get better at their jobs

Attackers can

  • Produce realistic (fraudulent) images & video
  • Engage in native-language (fraudulent) conversation
  • Automate everything at low cost

Defenders can

  • Scale high-quality expert labeling (better visibility, faster iteration)
  • Identify anomalous patterns in unstructured data
  • Automate everything at low cost

Attacker’s job: Look like a benign user.

Defender’s job: Distinguish attack traffic from benign traffic.

But their jobs don’t change!

measure everything

malicious content

behavior analysis

economic motivation

17 of 20

17

HOW AI CHANGES THE GAME, CONTINUED

What AI doesn’t change

Attackers are still economically motivated.

Attackers never sleep!

Attack patterns still differ from normal behavior.

You still need objective, ground-truth observations to measure

opportunity and impact.

18 of 20

18

HOW AI CHANGES THE GAME, CONTINUED

A cautionary tale

You still need experts to determine whether the AI is correct!

(June 8 2026)

19 of 20

19

WRAPPING UP

Takeaways

1

Measure the bad user outcome — use many sources to get the complete picture.

2

Everything is a tradeoff put numbers on both sides of the equation.

3

Shift the attacker’s cost/benefit calculation — raise cost or cut value.

4

Focus on behavior, not content — it’s expensive to fake consistently across all surfaces and dimensions.

AI increases speed and quality on both sides. It doesn’t change the fundamentals.

20 of 20

Thank You / 감사합니다

Questions?

David Freeman · www.delphiresear.ch

Opinions expressed in this talk are my own and do not represent the views of any current or past employer.