Skip to content
Scale To Zero by Cloudanix
BK

Guest

Behnaz Karimi

Cybersecurity Engineer & Independent Researcher, Tramarena

Behnaz Karimi is a cybersecurity engineer and independent researcher who specializes in AI security, with a focus on ransomware and agentic systems. She is the founder of Tramarena and co-leader of the OWASP AI Exchange, and has more than 14 years of global experience in cybersecurity.

Episode with Behnaz

Questions Behnaz answered

  • How has ransomware changed compared to five years ago?

    Behnaz Karimi says encryption is becoming almost secondary: many groups now steal sensitive data and apply pressure through legal, compliance and reputational threats, DDoS attacks, or by contacting customers, partners and regulators. Attackers also go after managed service providers to hit thousands of organizations at once, and the human factor, including insiders, is growing. Even strong backups no longer make you safe.

  • What are the stages of a ransomware attack on an AI system?

    She describes three acts. First, the supply chain: a malicious model on a public repository passes your benchmarks and your team pulls it in. Second, persistence: it weaves itself into the ML pipeline, through preprocessing hooks and model checkpoints, and waits, around 72 hours or less, long enough to clear anomaly detection. Third, detonation: checkpoints are encrypted, endpoints go down and the ransom note surfaces through your own API and dashboard, and recovery means full pipeline reconstruction and retraining from scratch.

  • What is the most overlooked entry point for ransomware in AI systems?

    The AI supply chain: model repositories, public repositories, third-party pre-trained models and ML framework dependencies. Security teams focus on perimeter firewalls and endpoint detection, while a model pulled in during a routine cycle passes benchmarks with malicious logic sitting dormant inside. Many organizations still lack basic AI-specific controls such as integrity monitoring and validation of model artifacts.

  • Are small and mid-sized companies at risk of AI ransomware?

    Yes. Behnaz calls the idea that smaller organizations are overlooked a dangerous myth: they have data, and ransomware as a service lets people with little technical skill launch complex attacks. Smaller companies adopt third-party AI tools quickly without the same protection, often without tracking where models come from or monitoring what enters their systems. She recommends treating AI models and data as critical security assets, with proper validation and continuous monitoring.

  • How can an organization assess its exposure to AI ransomware?

    Ask whether a normal IT attack can reach your AI systems, and whether a compromised AI component can affect the rest of your IT environment. Then walk through your systems step by step, honestly and thinking like an attacker: do you only use trusted models, can models run code, can a compromise spread, and do you have clean backups? Check that you know which models and ML libraries run in production and where they come from, and adapt existing security frameworks as a baseline.

  • How should incident response change when ransomware hits AI systems?

    Isolating and eradicating is a good starting point but not enough, because attackers can quietly poison a model and it may behave incorrectly long before you notice. Behnaz says you need a way to verify models, such as tracking where they come from and confirming they have not been changed, and an investigation into how the model was trained, what dependencies it used and how it has behaved over time. If you are not fully confident the model is clean, do not restore it: retrain from scratch in a clean environment using trusted data.

New episodes twice a month

No security question left unanswered.

Follow Scale To Zero wherever you listen, or send us the question your team is stuck on and we will put it to an expert.