An AI that only accepts the unknown


A development team programs an AI for a security system that is supposed to recognize only unknown or unusual patterns in network data as potential threats.

The AI is trained to ignore known and frequently occurring patterns in order to minimize false alarms and focus on truly new attacks.

However, in operation it turns out that the AI does not recognize many legitimate but rare activities and instead constantly reports new, harmless patterns as threats.

The team wonders: Why does focusing on the unknown cause the AI to overlook many important cases while simultaneously producing numerous false alarms?


Question:
What challenges arise with AI systems that are supposed to respond exclusively to unknown patterns, and why is it difficult to reliably distinguish rare legitimate events from actual threats?

Solution follows tomorrow.