Observational Human–AI (OHAI): A Defender Attribution Framework for Distinguishing Human vs. AI Threats

SEI Report
OHAI is a proposed framework for providing probabilistic human‑to‑autonomous attribution in cyber incidents.
Publisher

Software Engineering Institute

Abstract

Artificial Intelligence (AI) is collapsing the cost, time, and skill barriers that once separated casual intruders from advanced persistent threats. For cyber defenders, the resulting evidence stream—rapid and adaptive—blurs the line between human and machine-enabled operations, undermining classic attribution methods and incident-response playbooks. This whitepaper introduces the Observational Human–AI (OHAI) Attribution Framework, a five‑stage cycle of Triage, Classify, Analyze, Profile, and Report that enables at-rest and in-flight inspection to assign probabilistic confidence to the spectrum of attacker archetypes between human and fully autonomous AI attacks. We catalog observable AI indicators and demonstrate practical application through two publicly documented AI‑enabled incidents. OHAI supplies defenders with definitions, analytic heuristics, and automation‑ready data fields, enabling the faster discrimination of AI‑driven threats, sharper predictive analytics, and more resilient human–machine defensive teaming. By operationalizing attribution, the framework aims to reduce misallocation of response resources, improve early‑warning fidelity, and inform future toolchains that will operate against autonomous adversaries.

Cite This SEI Report

Updyke, D., Rossell, D., & Fitzgerald, S. (2025, April 25). Observational Human–AI (OHAI): A Defender Attribution Framework for Distinguishing Human vs. AI Threats. Retrieved August 16, 2026, from https://www.sei.cmu.edu/library/observational-humanai-ohai-a-defender-attribution-framework-for-distinguishing-human-vs-ai-threats/.

@techreport{updyke_2025,
author={Updyke, Dustin and Rossell, David and Fitzgerald, Shelly},
title={Observational Human–AI (OHAI): A Defender Attribution Framework for Distinguishing Human vs. AI Threats},
month={Apr},
year={2025},
institution={Software Engineering Institute, Carnegie Mellon University},
url={https://www.sei.cmu.edu/library/observational-humanai-ohai-a-defender-attribution-framework-for-distinguishing-human-vs-ai-threats/},
note={Accessed: 2026-Aug-16}
}

Updyke, Dustin, David Rossell, and Shelly Fitzgerald. "Observational Human–AI (OHAI): A Defender Attribution Framework for Distinguishing Human vs. AI Threats." Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, April 25, 2025. https://www.sei.cmu.edu/library/observational-humanai-ohai-a-defender-attribution-framework-for-distinguishing-human-vs-ai-threats/.

D. Updyke, D. Rossell, and S. Fitzgerald, "Observational Human–AI (OHAI): A Defender Attribution Framework for Distinguishing Human vs. AI Threats," Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, 25-Apr-2025 [Online]. Available: https://www.sei.cmu.edu/library/observational-humanai-ohai-a-defender-attribution-framework-for-distinguishing-human-vs-ai-threats/. [Accessed: 16-Aug-2026].

Updyke, Dustin, David Rossell, and Shelly Fitzgerald. "Observational Human–AI (OHAI): A Defender Attribution Framework for Distinguishing Human vs. AI Threats." Software Engineering Institute, Carnegie Mellon University, Software Engineering Institute, 25 Apr. 2025. https://www.sei.cmu.edu/library/observational-humanai-ohai-a-defender-attribution-framework-for-distinguishing-human-vs-ai-threats/. Accessed 16 Aug. 2026.

Updyke, Dustin; Rossell, David; & Fitzgerald, Shelly. Observational Human–AI (OHAI): A Defender Attribution Framework for Distinguishing Human vs. AI Threats. Software Engineering Institute. 2025. https://www.sei.cmu.edu/library/observational-humanai-ohai-a-defender-attribution-framework-for-distinguishing-human-vs-ai-threats/