Generative artificial intelligence cybersecurity risks
Üretken yapay zekâ siber güvenlik riskleri
- Tez No: 1017569
- Danışmanlar: DOÇ. DR. DERYA YILTAŞ KAPLAN
- Tez Türü: Yüksek Lisans
- Konular: Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve Kontrol, Computer Engineering and Computer Science and Control
- Anahtar Kelimeler: Belirtilmemiş.
- Yıl: 2026
- Dil: İngilizce
- Üniversite: Bahçeşehir Üniversitesi
- Enstitü: Lisansüstü Eğitim Enstitüsü
- Ana Bilim Dalı: Bilgisayar Mühendisliği Ana Bilim Dalı
- Bilim Dalı: Siber Güvenlik Bilim Dalı
- Sayfa Sayısı: Belirtilmemiş.
Özet
Bu tez, Üretken Yapay Zekâ (Generative Artificial Intelligence – GenAI) teknolojilerinin siber güvenlik alanında ortaya çıkardığı riskleri, özellikle kimlik avı (phishing) saldırılarındaki saldırgan kullanımlarını ve bu tehditlere karşı makine öğrenmesi tabanlı tespit yöntemlerini incelemektedir. Büyük Dil Modelleri (Large Language Models – LLMs) ve üretken modellerin hızlı gelişimi, siber saldırıların daha gerçekçi, ölçeklenebilir ve hedefe yönelik şekilde gerçekleştirilmesini mümkün kılmıştır. Çalışmada, üretken yapay zekânın saldırganlar tarafından nasıl kötüye kullanılabileceği sistematik olarak analiz edilmiş ve bu tehditler Cyber Kill Chain çerçevesi içerisinde değerlendirilmiştir. Ayrıca, kimlik avı ve spam e-postalarının tespitinde geleneksel makine öğrenmesi modellerinin etkinliği deneysel olarak incelenmiştir. Bu kapsamda Multinomial Naive Bayes, Lojistik Regresyon ve Lineer Destek Vektör Makineleri (Linear SVM) modelleri kullanılarak karşılaştırmalı bir analiz gerçekleştirilmiştir. Deneysel çalışmalar SpamAssassin veri kümesi üzerinde yürütülmüş, metinler TF-IDF özellik çıkarımı yöntemiyle sayısal hale getirilmiş ve modeller doğruluk, kesinlik, duyarlılık, F1-skoru ve ROC-AUC metrikleri ile değerlendirilmiştir. Elde vii edilen sonuçlar, Lineer SVM modelinin en yüksek performansı gösterdiğini, Lojistik Regresyonun güçlü bir temel model sunduğunu ve Multinomial Naive Bayes'in ise daha düşük ancak kabul edilebilir sonuçlar verdiğini ortaya koymuştur. Bu çalışma, üretken yapay zekânın siber güvenlikte yarattığı tehditlerin ciddiyetini vurgulamakta ve klasik makine öğrenmesi yöntemlerinin, uygun ön işleme ve değerlendirme süreçleri ile birlikte kullanıldığında, kimlik avı saldırılarının tespitinde halen etkili çözümler sunabileceğini göstermektedir.
Özet (Çeviri)
The recent and rapid proliferation of Generative Artificial Intelligence (GenAI), including Large Language Models (LLMs) like ChatGPT and Google Gemini, and architectures such as Generative Adversarial Networks (GANs), has introduced a paradigm shift in the digital landscape. This technological advancement presents a significant“dual-use dilemma,”offering powerful new capabilities for both fortifying and compromising cybersecurity infrastructures. This thesis provides a comprehensive analysis of the cybersecurity risks associated with GenAI, examining how adversaries can exploit these technologies to create more sophisticated, automated, and scalable cyberattacks. Through a systematic review of contemporary research, this work delineates the evolving threat landscape by structuring the analysis of offensive GenAI applications within frameworks such as the Cyber Kill Chain (CKC). The study investigates the spectrum of GenAI-enabled threats, categorizing risks by modality including text, image, audio, and code generation and by adversarial strategy. Key findings reveal that GenAI significantly enhances social engineering and phishing attacks by automating the creation of context-aware, grammatically flawless, and highly personalized malicious content, thereby exploiting the human factor, which remains the weakest link in the security chain. The analysis demonstrates that GenAI lowers the barrier to entry for adversaries, enabling even unskilled actors (“script kiddies”) to generate sophisticated and polymorphic malware, automate hacking processes, and create attack payloads with minimal effort. The emergence of malicious LLMs like WormGPT and FraudGPT further exacerbates this threat. The v proliferation of deepfakes and synthetic media for disinformation campaigns, fraud, and identity theft is identified as another critical risk area. Furthermore, the thesis examines the inherent vulnerabilities within GenAI models themselves, including susceptibility to data poisoning, hallucinations, and manipulation through techniques like prompt injection and jailbreaking to bypass ethical safeguards. In conclusion, while GenAI also offers powerful defensive applications such as automated threat intelligence, secure code generation, and synthetic data generation for training robust intrusion detection systems, the rapid weaponization of this technology by adversaries creates an urgent need for new defense paradigms. This research underscores the necessity for developing advanced countermeasures, robust ethical guidelines, and innovative, adaptive security frameworks to mitigate the multifaceted risks posed by generative AI and ensure a secure digital future.
Benzer Tezler
- Üretken yapay zeka modelleri kullanılmasındaki etik sorunlar ve kullanıcı görüşlerinin değerlendirilmesi
Ethical problems in the use of generative artificial intelligence models and evaluation of user opinions
SEMAHAT GÜRSOY
Yüksek Lisans
Türkçe
2025
Bilim ve TeknolojiGazi ÜniversitesiAdli Bilişim Ana Bilim Dalı
DOÇ. DR. NURSEL YALÇIN
- Promptshıeld: polıcy-aware data loss preventıon framework for generatıve AI prompts
Promptshıeld: Politika farkındalıklı üretken yapay zekâ istemleri için veri kaybı önleme çerçevesi
EZGİ KELEŞ
Yüksek Lisans
İngilizce
2026
Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve Kontrolİstanbul Teknik ÜniversitesiBilgisayar Mühendisliği Ana Bilim Dalı
PROF. DR. ŞERİF BAHTİYAR
- A survey: Cyber security in connected and automated vehicles
Bağlantılı ve otonom araçlarda siber güvenlik çalışması
AYŞEGÜL KANDEFER
Yüksek Lisans
İngilizce
2024
Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve KontrolGalatasaray ÜniversitesiBilgisayar Mühendisliği Ana Bilim Dalı
PROF. DR. TANKUT ACARMAN
- Adapting Cybersecurity Governance Frameworks to Manage Risks in Generative AI Systems
Yapay Zekâ Sistemlerinde Riskleri Yönetmek Için Siber Güvenlik Yönetişim Çerçevelerinin Uyarlanmasi
OLUWAREMILEKUN JACOBS ADEOPATOYE
Yüksek Lisans
İngilizce
2025
Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve KontrolKadir Has ÜniversitesiYönetim Bilişim Sistemleri Ana Bilim Dalı
PROF. DR. HASAN DAG
- Yapay zekânın siber terörizm üzerindeki etkisi
The impact of artificial intelligence on cyber terrorism
CUMALİ CEM DOĞAN
Yüksek Lisans
Türkçe
2025
Kamu Yönetimiİnönü ÜniversitesiGüvenlik ve Terör Bilim Dalı
DR. ÖĞR. ÜYESİ EMİN GİTMEZ