Publication date: 
2026/07/02
Artificial intelligence (AI)-based protection against cyberattacks was programmed by Muris Sladić, a doctoral student at the Faculty of Electrical Engineering (FEE) of the Czech Technical University in Prague, and Sebastian Garcia, head of Stratosphere Lab, a research group at the Center for Artificial Intelligence at the same institution. The project, called Decor, uses the principles of cyber deception defense enhanced with AI to detect, confuse, and deter cyberintruders.

Deceptive defense in cyberspace works on the basis of imitating the software environment of a given company, which should be indistinguishable from the real company for the attacker in terms of design and program code.

The hacker thinks that he has hacked into the company directly, while in reality he has fallen into a trap that faithfully imitates his potential victim.

The cybercriminal will thus ideally leave behind evidence for the police of his intention to attack the company, but the real data of the selected company will remain untouched. It also provides defenders with a more timely overview of the attackers' activities and more time to react.

Decor won the Get Spin-off/Start-up Ready! program organized by CTU Technology Transfer, which helps students and researchers turn research ideas into future startups and spin-offs. "The project responds to increasingly frequent situations where an attacker obtains an employee's access data and gets inside the corporate network without arousing the suspicion of traditional security systems," confirmed Muris Sladić.

“Current security tools are very good at defending against attacks from the outside. The problem arises when an attacker gets inside the network using stolen credentials. Our goal is to create an environment that looks like the real infrastructure of the company, but is actually a controlled trap that will detect and detain the attacker,” added the FEL student.

Trapped intruders
“In traditional conflicts, deceiving the adversary has been part of defense for thousands of years. In cybersecurity, this approach is only just beginning to gain traction. Our goal is to help organizations take control of what the attacker sees and believes,” says Sebastian Garcia, head of Stratosphere Lab.

According to him, time can decide whether an attack ends in a minor incident or millions in damage. “If we can keep the attacker busy for two or three hours in a controlled environment, it can be the difference between a successful defense and a large-scale data leak.”

Artificial intelligence plays a significant role in the entire solution. While AI helps defenders create convincing deception environments, it is increasingly being used by attackers themselves.

“AI today significantly enhances the capabilities of both defenders and attackers. Attacks are faster and more sophisticated than ever before. That is why we believe that AI must be part of the defense – human teams alone can no longer react quickly enough to everything that is happening in networks,” adds Garcia.

The first versions of the solution were created as individual AI honeypots – fake services designed to detect attackers. However, they gradually grew into a comprehensive system that can be deployed in a corporate environment.

The team is currently finalizing the so-called minimum viable product (MVP) and is talking to potential customers about pilot deployment. “The technology is already working and has been tested both in laboratory conditions and in a limited real-world environment. Now we are focusing on making it ready for deployment in companies and meeting high requirements for security and trust,” says Sladić.

According to him, the biggest challenge today is gaining customer trust. The technology itself already works, but companies need to be sure that the new security solution will not pose an additional risk.

Author: 
Jan Šponar
Source: 
Novinky.cz