Researchers at the Commonwealth Scientific and Industrial Research Organisation's Data61 division have created a set of techniques that act as a "vaccination" to protect artificial intelligence and machine learning algorithms from adversarial attacks, according to an announcement from the organisation. The scientific group's digital arm called the capability a significant advancement in machine learning research. The techniques train algorithms on modified data sets to build immunity against attempts to deceive AI systems into making dangerous misclassifications.

The vaccination approach works by introducing a weak version of an adversary into the training process, according to Data61. Researchers apply small modifications or distortions to a collection of images to create a more challenging training data set. When an algorithm learns from data exposed to a small dose of distortion, the resulting model becomes more robust and immune to adversarial attacks. Because the vaccination techniques are built from the worst possible adversarial examples, they should theoretically be able to withstand very strong attacks, the organisation said.

Dr Richard Nock, who leads Data61's machine learning group, explained that attackers can deceive machine learning models by adding a layer of noise over an image. "Adversarial attacks have proven capable of tricking a machine learning model into incorrectly labelling a traffic stop sign as speed sign, which could have disastrous effects in the real world," he said. Data61 CEO Adrian Turner called the research "a significant contribution to the growing field of adversarial machine learning," adding that the new techniques "will spark a new line of machine learning research and ensure the positive use of transformative AI technologies."

The vulnerability matters because algorithms now perform critical tasks by learning from training data to classify images and emails accurately, diagnose diseases from X-rays, predict crop yields, and identify spam messages, the organisation noted. These same techniques will soon drive cars, making the stakes of misclassification potentially fatal. Without focused research into adversarial defences, AI and machine learning can't safely help solve major social, economic, and environmental challenges, Turner said. The announcement follows Data61's November investment of AU$19 million into an Artificial Intelligence and Machine Learning Future Science Platform aimed at AI-driven solutions for food security, health and wellbeing, sustainable energy, resilient environments, and regional security. The vaccination research positions Australia's national science agency at the forefront of defensive AI development as the technology moves into safety-critical applications. The approach mirrors biological immunisation by exposing systems to weakened threats during training rather than waiting for attacks in production environments. Organisations deploying AI in high-stakes settings now face a choice between accepting vulnerability or investing in hardening techniques that slow development cycles but prevent catastrophic failures.