Skip to content
All lessons
AI ImpactEthics and Privacy9-12.AII.EP.5

Defense, Offense, and Dual Use

11–1250 minutes90 minutes (extend seminar and writing)

Standard quoted exactly

Analyze the benefits, risks, and ethical implications of AI in cybersecurity.

Student-friendly learning targets

  • I can analyze AI in cybersecurity as dual-use: the same class of tools can support detection and can scale social-engineering attacks.
  • I can describe benefits of AI-assisted defense without claiming that software replaces human judgment in a security operations center.
  • I can explain ethical duties (including not practicing offensive techniques in class) that follow from dual-use power.

Essential questions

  1. If the same kind of model can draft a phishing email and flag one, who is responsible for which use?
  2. What benefits does AI actually add to defense, and what new risks does it add (speed, scale, voice cloning, over-trust)?
  3. What ethical lines should a high school, a hospital, a lab, and a county IT shop refuse to cross?

Objectives

  1. Analyze benefits of AI for detection, triage, and pattern-spotting in defensive cybersecurity.
  2. Analyze risks of AI-enabled social engineering, including phishing and voice cloning, at the level of effects — not methods.
  3. Map dual use: one capability, defensive and offensive applications, different duties.
  4. Apply an ethical rule for this classroom: no exploit how-tos, no live attack generation, defensive framing only.
  5. Recommend a human-in-the-loop practice for a school or clinic facing AI-speed threats.

Key vocabulary

Cybersecurity
The practice of protecting networks, accounts, and data from unauthorized access, disruption, or theft.
Dual use
A technology that can serve both protective and harmful purposes depending on who uses it and toward whom.
Phishing
A social-engineering attempt, often by email or message, to trick a person into giving access or information. Class studies published examples; students do not create new lures.
Detection
Defensive systems and people spotting suspicious messages, logins, or network behavior, sometimes with AI ranking alerts.
Voice cloning
Synthesizing a voice that resembles a real person, which can be used for accessibility or for fraud (vishing).
Alert fatigue
The point at which so many automated warnings arrive that humans start ignoring them, including the real ones.
Human-in-the-loop defense
Keeping a trained person responsible for high-impact actions (locking accounts, contacting law enforcement, paying a ransom demand) even when AI ranks the alerts.

Teacher background

AI is already inside cybersecurity as both a defensive aid and a way to scale old crimes. The standard asks students to analyze benefits, risks, and ethical implications — all three. Benefits include faster sorting of the flood of logs, spotting patterns a tired analyst might miss, and helping people with lower technical skill recognize a suspicious message. Risks include fluent phishing at scale, cloned voices of principals and parents, poisoned training data, and over-trust in a detector that still misses novel attacks. Dual use is the organizing idea: a language model that summarizes a threat report can also draft a convincing message. This classroom is defensive only. Do not demonstrate how to bypass a filter, how to write a better lure, or how to exploit a system. Use already-published awareness examples from CISA or similar public campaigns, printed. Idaho context is close: school districts face email compromise; hospitals are ransomware targets in every state; Idaho National Laboratory and county IT shops live with nation-state and criminal probing. Students heading to CTE networking, the Guard, or help-desk work need ethics before tricks. FERPA applies twice: student records are what attackers want, and class must not dump real incident tickets into a chatbot. Offline fallback: printed phishing-awareness mailers and a dual-use T-chart. No student-generated attack content.

Materials and prep

Materials

  • Printed, already-published phishing-awareness examples (government or nonprofit). No live generation.
  • Dual-use T-chart: Capability / Defensive use / Harmful use / Ethical duty.
  • Roles cards: school tech director, hospital privacy officer, county clerk, student help-desk intern, parent who received a fake principal voicemail.
  • FERPA reminder card: education records are high-value targets; class does not inspect real student data.
  • Offline fallback: entire lesson on paper. No security-tool logins, no password-cracking utilities, no dark-web tourism.

Before class

  • Strip any local incident details that would identify a staff member or student. Public patterns only.
  • Tell administration you are teaching defensive analysis, not a hacking unit.
  • If a guest from county IT, a hospital, or INL education outreach is available, schedule them; keep a recorded backup.
  • Block plan: longer case seminar on a fictional district email compromise and a written human-in-the-loop protocol.

Instructional sequence

Two inboxes

5 min
  1. Hand out two printed messages about a password reset: one from a public awareness campaign (already flagged) and one ordinary school notice. Students mark suspicious / not sure / looks fine. They do not click anything; there are no links.
  2. Debrief only on observable features the awareness campaign already teaches (urgency, unexpected sender), not on how to improve an attack.
  3. Write dual use on the board. Tell students a model that helps write clear school notices can also write urgent fakes.
  4. State the classroom rule: we analyze effects and duties. We do not manufacture lures or exploits.

Benefits, risks, ethics — all three

10 min
  1. Benefits: ranking alerts, clustering similar events, summarizing long logs, assisting users who are not specialists, catching some malware families by pattern.
  2. Risks: scale of social engineering, voice cloning of a superintendent or a grandparent, attackers using the same detectors to test what gets through, alert fatigue, false confidence.
  3. Ethics: who is targeted (new staff, non-native English speakers, busy nurses), whether a school should use offensive tools, responsible disclosure versus showing off, duty to report.
  4. Idaho map: district business offices, clinic billing, city utilities, lab research networks. Same dual-use pattern, different consequences.
  5. Re-state: no how-to for offense. If a student asks, the answer is we will not practice that here.

Fill one dual-use row together

10 min
  1. Capability: generate fluent natural language. Defensive use: draft a clear password-reset notice in plain English and translate it. Harmful use: scale phishing. Ethical duty: schools may use generation for official notices on approved systems; students do not generate lures, even as a joke.
  2. Add voice cloning as a second row at the level of effects: accessibility for a teacher who lost their voice versus a fake principal call about an unpaid fee.
  3. Ask who is most exposed: a new secretary, a nurse on night shift, a parent who is not a native English speaker. Connect to EP.2 without turning this into a blame session.
  4. Draft a human-in-the-loop rule: AI may rank; a person confirms before anyone pays, sends money, or unlocks a roster.

Role analysis

12 min
  1. Each student draws a role card and writes a ten-line analysis: one benefit they would want, one risk they fear, one ethical rule they would write into policy.
  2. Hospital roles must mention patient privacy; school roles must mention FERPA; county roles must mention public records and elections systems at a high level, not attack details.
  3. Intern roles must include what they will refuse to do even if a friend dares them.
  4. No diagrams of network exploits. If a student starts to write steps, redirect to effects and duties.

Real-world examples

  • School district business offices targeted by urgent payment-change emails, now sometimes more fluent than they were five years ago.
  • Hospitals facing ransomware that disrupts care; defensive AI used to spot unusual encryption behavior — with human authority over shutdowns.
  • A parent receiving a cloned-voice message that sounds like a principal; the ethical and practical response is a call-back protocol, not a student-built detector.
  • Idaho National Laboratory and other critical-infrastructure sites treating AI as both an analytic aid and a threat multiplier.
  • Alert fatigue in a small county IT shop with two staff and a noisy commercial detector.

Hands-on activity

Protocol, not an exploit

8 min
  1. Groups of three write a one-page human-in-the-loop protocol for a high school main office: how staff verify urgent requests, who they call, what AI mail filters may do, what they must never do (send a roster, buy gift cards).
  2. Peer-check: does the protocol teach anyone how to attack? If yes, rewrite.
  3. Share one protocol. Teacher kills any sentence that slides into offensive technique.
  4. Collect role analyses.

Discussion questions

  1. Why might a detector that is 99 percent accurate still be dangerous in a school of two thousand accounts?
  2. Should student internships in IT include offensive labs? What is the ethical difference between a college cyber range and this class?
  3. Who owes the parent a call-back protocol: the school, the phone company, or the vendor of the voice model?
  4. Is paying a ransom a technical decision or an ethical and legal one?
  5. How does FERPA change the cost of a school email compromise compared with a spam blog?

Differentiation

Support

  • Provide a protocol template with headings: Verify, Call, Never, AI may, Human must.
  • Allow bullet role analyses.

Challenge

  • Argue whether dual-use foundation models should have use restrictions, and what that would cost legitimate defenders.
  • Design a tabletop (discussion only) of a fictional clinic billing-email compromise; no technical payload details.

Multilingual learners

  • Note that non-native staff and families are often targeted with fluent English or with messages in their language. Discuss without assigning shame.
  • Provide vocabulary cards for phishing, ransomware, and dual use.

IEP / 504

  • Avoid startling voice-clone audio. Describe the risk in text unless a student opts into a short, clearly labeled sample of a public figure, never of a classmate.
  • Written protocols may be dictated.

Assessment

Formative

  • Warm-up message sort and dual-use T-chart.
  • Teacher checklist: zero offensive how-to language in student work.

Summative

  • Role analysis plus office protocol scored on benefits, risks, ethics, and defensive framing.
  • Block extension: 350-word policy for a school board technology committee on AI mail filters and human verification.

Success criteria

  • Names at least one defensive benefit and one dual-use risk.
  • Includes an ethical duty and a human-in-the-loop step.
  • Contains no exploit or lure-crafting instructions.

Responsible use, ethics, and privacy

Responsible use

Defensive framing only. Students do not generate phishing emails, clone voices, scan networks, or test filters. Published awareness examples, already printed, are the only specimens. School accounts are not a lab. Offline paper is sufficient and preferred.

Ethics

Dual use is an ethical structure, not a dare. Benefits of detection are real; so is the duty not to practice harm. Targeting people with less English, less rank, or less time is part of the risk analysis. Showing off an exploit in class would itself be an ethical failure, even if the intent were educational.

Privacy

Attackers want rosters, health information, payroll, and credentials. FERPA and health-privacy laws exist because those records are sensitive. Class will not open real incident tickets, real inboxes, or real student files. Do not paste suspected phishing into a consumer chatbot (that can leak the very data you are trying to protect); follow district reporting channels.

Reflection

  1. What is one thing you will now verify by a second channel before acting on an urgent message?
  2. Where did you feel curious about offensive technique, and how did you redirect that curiosity to duty?
  3. Which role’s ethical rule would you want this school to adopt?

Homework

With a parent, guardian, or trusted adult, agree on a family call-back phrase for urgent money or pickup requests. Write a short reflection on why a voice that sounds right is not proof. Do not test voice-clone apps on anyone’s voice.

Closing

Restate the classroom rule: analysis of benefits, risks, and ethics; no offense. Collect protocols. Ethics and privacy as a subdomain ends here; impact on society begins with testing outputs for bias, accuracy, and harm — a different kind of defense.

Extensions and cross-curricular links

Go further

  • 90-minute block: tabletop discussion of a fictional district compromise and a board policy draft (seminar and writing).
  • Guest from county IT, hospital privacy, Guard cyber education, or INL outreach; recorded backup for rural days.
  • Compare a 2018 phishing-awareness flyer with a 2026 one; what changed after GenAI became commonplace (link to EP.1).
  • Map this lesson to career pathways: networking CTE, public administration, health informatics — ethics first.
Computer science / CTE networking
Defensive roles, acceptable-use, and why a high-school course stops at analysis.
Health science
Ransomware as a patient-safety issue; privacy officers and human shutdown authority.
Civics
Public institutions as targets; election and records systems discussed only at the level of duty, not vulnerability.
Economics
Small IT shops, alert fatigue, and who pays for better defense.