multi turn AI attacks Cisco reveal new cybersecurity challen

multi turn AI attacks Cisco is the focus of this technology-news update.
Multi-turn attacks broke AI models 88% of the time — single-turn testing missed it, Cisco AI security lead warns at VB Transform 2026
As artificial intelligence (AI) systems become integral to many industries, understanding and mitigating their unique security risks has become increasingly urgent. At VB Transform 2026, Amy Chang, Cisco’s head of AI threat intelligence and security research, disclosed research revealing a critical vulnerability in AI model security testing: multi-turn AI attacks. Cisco’s study demonstrated that adversaries exploiting multi-turn conversational interactions compromised AI models in 88.3% of cases—a failure rate significantly underestimated by conventional single-turn testing methods.
This finding highlights the need for AI developers, security professionals, and enterprises to revise their evaluation frameworks to better defend AI-powered applications against sophisticated, iterative adversarial techniques.
Key Findings Presented at VB Transform 2026
During her presentation, Amy Chang summarized Cisco’s extensive study, which assessed 15 leading closed and proprietary AI models—including those from OpenAI, Anthropic, Google, and X.AI—against nearly 7,000 multi-turn attack scenarios. The research found that the highest success rate for multi-turn attacks reached 88.3%, with all tested models exhibiting notable vulnerabilities to these complex adversarial inputs.
In comparison, single-turn testing, which involves a single malicious prompt, consistently underestimated these weaknesses. The study included over 30,000 single-turn prompts and revealed that model robustness rankings based on single-turn testing did not correspond with performance under multi-turn conditions. This challenges the prevailing assumption that single-turn testing alone suffices to evaluate AI model security.
Defining Multi-turn vs. Single-turn Attacks
Single-turn attacks consist of a one-off malicious prompt intended to provoke harmful or unintended AI outputs. Multi-turn attacks extend this by engaging the model in an ongoing conversation, enabling attackers to adapt their tactics based on previous responses. This iterative approach more closely mirrors real-world adversarial behavior, where attackers refine their inputs over multiple exchanges to circumvent safeguards.
Understanding Multi-turn Attacks on AI Models
Multi-turn attacks leverage the conversational AI’s capacity to maintain context and memory across turns, gradually coaxing the model into producing outputs it would resist in isolated interactions. Attackers employ subtle, context-dependent prompts building on earlier dialogue, allowing them to bypass filters, alignment protocols, or content policies embedded in the AI.
These attacks operate through mechanisms such as:
– Contextual manipulation: tailoring subsequent inputs using prior responses to evade detection.
– Adaptive prompting: modifying strategies mid-conversation based on the model’s behavior.
– Incremental alignment erosion: progressively weakening the model’s adherence to ethical or safety constraints.
Unlike single-turn testing, which captures a snapshot of model behavior, multi-turn interaction exposes deeper vulnerabilities related to sustained dialogue and stateful reasoning.
Impact on Users, Businesses, and Developers
The high effectiveness of multi-turn attacks poses significant risks in sensitive and high-stakes AI deployments, including:
– Data security breaches, where compromised AI agents could leak confidential information or grant unauthorized access.
– Loss of user trust due to exposure to harmful or misleading AI outputs, damaging reputations and confidence.
– Operational disruptions caused by manipulated AI-driven processes leading to erroneous decisions or system failures.
For developers, these findings underscore the challenge of defending AI models against evolving adversarial methods that exploit conversational dynamics. Effective countermeasures require recognizing the fundamental differences between multi-turn and single-turn attacks and adapting testing and mitigation approaches accordingly.
Current AI Security Testing Practices and Their Limitations
Most AI security assessments today primarily rely on single-turn red-teaming methods, where testers submit isolated malicious prompts to probe weaknesses. While valuable, these methods do not capture the iterative, adaptive nature of realistic attacks, creating a misleading impression of model robustness.
Cisco’s research warns that neglecting multi-turn testing leaves many vulnerabilities undetected until exploited in real-world scenarios. The study’s lead author emphasized that without comprehensive multi-turn adversarial evaluation, organizations cannot fully identify model failure points or anticipate attack vectors that unfold over multiple interactions.
Industry responses reflect this evolving understanding. Major security vendors have increased investments in identity and isolation technologies critical to containing compromised AI agents. Examples include:
– Palo Alto Networks’ $25 billion acquisition of CyberArk to enhance identity and privileged access management.
– CrowdStrike’s $740 million acquisition of SGNL targeting advanced threat detection capabilities.
– Cisco’s planned acquisition of Astrix Security for approximately $400 million to bolster agent isolation and security layers.
Despite these initiatives, only a minority of enterprises have fully implemented scoped, managed identities or sandbox isolation for AI agents, leaving them more vulnerable to multi-turn adversarial risks.
Limitations and Open Questions in Current Research
While Cisco’s study provides a valuable benchmark for multi-turn attack efficacy, several limitations remain:
– The research focused on 15 flagship closed models, which may not represent the diversity of AI architectures across the broader ecosystem.
– The applicability of findings to open-source models or differently trained systems requires further investigation.
– Long-term effects of multi-turn attacks, including persistence and the effectiveness of mitigation strategies, need additional study.
These gaps emphasize the need for ongoing research, expanded model coverage, and standardized testing protocols to improve resilience against multi-turn attacks.
Multi-turn attacks broke AI models 88% of the time — single-turn testing missed it, Cisco AI security lead warns at VB Transform 2026
Reiterating the core message, Cisco’s finding of an 88.3% success rate in breaching AI models through multi-turn conversations serves as a crucial warning for the AI industry. It indicates that relying solely on single-turn adversarial testing is insufficient and potentially hazardous.
This insight calls for a fundamental recalibration of AI security strategies to include multi-turn adversarial testing as a standard practice. The implications extend beyond technical evaluation to governance, compliance, and risk management, influencing how AI systems are certified for critical deployments.
Future Directions in AI Security
Experts recommend several key actions to address the vulnerabilities exposed by multi-turn attacks:
– Integrate multi-turn attack scenarios into AI testing pipelines to simulate iterative adversarial dialogues and uncover hidden failure modes.
– Develop advanced evaluation frameworks and tools capable of automating and scaling multi-turn adversarial assessments.
– Foster collaboration across industry, academia, and security research communities to share attack datasets, methodologies, and defense techniques.
– Enhance agent identity and isolation mechanisms by implementing scoped, managed identities and sandbox environments to limit attack surface exposure.
These priorities align with ongoing investments by leading security firms emphasizing identity and access controls, highlighting the importance of layered defenses in AI security.
Key Takeaways
– Multi-turn attacks are significantly more effective than single-turn attacks, achieving success rates up to 88.3%.
– Single-turn testing does not reliably predict AI model resilience against iterative adversarial techniques.
– Most enterprises have yet to adopt comprehensive identity and isolation controls for AI agents, increasing their vulnerability.
– Industry leaders are investing heavily in identity and isolation solutions to address these emerging threats.
– Adopting multi-turn testing frameworks is essential for accurately assessing and improving AI security.
Conclusion: What Should AI Stakeholders Watch Next?
The Cisco-led research presented at VB Transform 2026 marks a pivotal moment in AI security. As multi-turn attack techniques grow more widespread and effective, stakeholders must acknowledge the shortcomings of single-turn testing and implement more rigorous, context-aware evaluation methods.
Developers and organizations deploying AI should prioritize incorporating multi-turn adversarial testing into their security protocols and invest in identity and sandboxing technologies to reduce attack surfaces. Concurrently, researchers and security vendors should accelerate the creation of tools that simulate realistic conversational attacks at scale.
Addressing the vulnerabilities revealed by multi-turn AI attacks, as documented by Cisco, will be vital to maintaining trust, safety, and resilience in AI-driven systems across sectors. The community should closely follow ongoing research, emerging standards, and vendor solutions focused on enhancing multi-turn robustness to stay ahead of evolving threats.
Frequently Asked Questions
What are multi-turn attacks on AI models and how do they differ from single-turn attacks?
Multi-turn attacks involve a sequence of interactions designed to manipulate AI models over several steps, whereas single-turn attacks target the model with a single input. Multi-turn attacks are more complex and can bypass defenses that single-turn testing misses.
What did Cisco's AI security lead reveal about the effectiveness of multi-turn attacks at VB Transform 2026?
Cisco's AI security lead revealed that multi-turn attacks successfully compromised AI models 88% of the time, highlighting that single-turn testing significantly underestimates AI vulnerabilities.
Which AI systems or organizations are most at risk from multi-turn attacks?
Any organization deploying conversational AI or large language models, especially those relying on single-turn security testing, are at risk, including enterprises using AI for customer service, automation, and decision-making.
How can organizations better protect their AI models from multi-turn attacks?
Organizations should implement multi-turn testing during AI security assessments, continuously monitor AI interactions, apply robust input validation, and update defenses based on evolving attack techniques.
Does multi-turn attack testing affect AI model performance or user privacy?
Multi-turn attack testing focuses on security evaluation and should be conducted in controlled environments to avoid impacting model performance or user privacy. Proper safeguards ensure testing does not expose sensitive data.
Source: Original reporting

Leave a Reply