AI-Powered Attacks on ICS SBOMs
About This Session
Findings, the Limits of De-Identification, and a Call to Action
SBOM sharing is becoming an expectation across critical infrastructure, and for good reason — visibility into third-party and open-source components is the foundation of modern vulnerability management. But the same transparency creates a disclosure surface that did not previously exist. In early 2026 we presented AI-driven re-identification of ICS SBOMs to the Cybersecurity Developmental Test Cross‑Service Working Group (CyberDT XSWG) and Software Assurance communities as an emerging threat. Since then, we have built the attack and run it.
This presentation reports what we found. An AI adversary can attribute an SBOM to its manufacturer with high accuracy from component data alone and can narrow further to a specific firmware build. Partial redaction of the fields carrying that signal does not resolve that threat: leaving even a small fraction of them intact preserves most of the adversary's advantage. In our experiments the attacker was rarely constrained by the data available to them. The binding constraint was the sophistication of their method. Most consequentially, our results speak to the scope of de-identification rather than to its value. De-identification is a necessary control, and in our modeled deployment environment the redaction we applied performed exactly as designed. What we observed is that protecting the document alone does not by itself avert the threat that attackers can successfully discover device locations, link to vulnerabilities, and plan their attacks — because those findings can be obtained along adjacent paths as well. The implication is not that de-identification is ineffective. It is that its coverage must be measured and deliberately extended across the full set of routes available to an adversary if it is to deliver the protection it promises.
This session will present these findings, be explicit about what we have measured on real SBOM corpora versus what we have measured in a modeled environment, and translate the results into practical guidance for manufacturers, integrators, asset owners, and policymakers. We close on the work that still needs to be done, and on the specific ways ICS manufacturers can help make it real.
SBOM sharing is becoming an expectation across critical infrastructure, and for good reason — visibility into third-party and open-source components is the foundation of modern vulnerability management. But the same transparency creates a disclosure surface that did not previously exist. In early 2026 we presented AI-driven re-identification of ICS SBOMs to the Cybersecurity Developmental Test Cross‑Service Working Group (CyberDT XSWG) and Software Assurance communities as an emerging threat. Since then, we have built the attack and run it.
This presentation reports what we found. An AI adversary can attribute an SBOM to its manufacturer with high accuracy from component data alone and can narrow further to a specific firmware build. Partial redaction of the fields carrying that signal does not resolve that threat: leaving even a small fraction of them intact preserves most of the adversary's advantage. In our experiments the attacker was rarely constrained by the data available to them. The binding constraint was the sophistication of their method. Most consequentially, our results speak to the scope of de-identification rather than to its value. De-identification is a necessary control, and in our modeled deployment environment the redaction we applied performed exactly as designed. What we observed is that protecting the document alone does not by itself avert the threat that attackers can successfully discover device locations, link to vulnerabilities, and plan their attacks — because those findings can be obtained along adjacent paths as well. The implication is not that de-identification is ineffective. It is that its coverage must be measured and deliberately extended across the full set of routes available to an adversary if it is to deliver the protection it promises.
This session will present these findings, be explicit about what we have measured on real SBOM corpora versus what we have measured in a modeled environment, and translate the results into practical guidance for manufacturers, integrators, asset owners, and policymakers. We close on the work that still needs to be done, and on the specific ways ICS manufacturers can help make it real.
Speaker
Juan Lopez JR
Lead Technical SME, Critical Infrastructure Security & Resilience Research - Oak Ridge National Laboratory
Dr. Juan Lopez Jr. is a cybersecurity leader serving as the Lead Technical SME for the DHS Science & Technology Directorate’s Critical Infrastructure Security & Resilience Research (CISSR) program, where he focuses on industrial control systems and open‑source software security. He previously led ORNL’s Energy and Control Systems Security group and managed its Cyber‑Physical R&D portfolio, advancing national‑level research in critical infrastructure protection, nuclear cybersecurity, and RF‑DNA fingerprinting. Dr. Lopez holds a Ph.D. in Computer Science from the Air Force Institute of Technology along with multiple professional certifications including CISSP, CSSA, and Scrum Master, and is a retired U.S. Marine Corps veteran with 27 years of service.
