Catching AI attacks by how they persuade
PITCHED AT THE DUBAI NIGHT ON 15 SEPTEMBER 2026
Most guardrails for AI systems learn what past attacks looked like, so a reworded prompt or an attack spread slowly across a long conversation slips through. ImposterHunter detects the persuasion mechanism an attack relies on, which survives rewording, and shows exactly which words carried it.
Every company that has put a chatbot, a voice agent or a set of autonomous agents in front of customers has inherited a new attack surface. The usual defences match keywords, known jailbreak strings or classifiers trained on collected examples, which means they know the words an attack used last time. Rewrite the sentence, switch language or encoding, or assemble the attack over many turns of a conversation, and the filter goes quiet.
ImposterHunter starts from the observation that deception has structure. An attacker can change every word but still needs the same move, such as claiming authority or manufacturing urgency, for the attack to work. Its LLM Shield classifies that mechanism across the whole conversation and returns a risk score, the exact span of text responsible and a recommended action, while the customer keeps the policy. It was founded by Dragos Balhui and Cristina Balhui, pairing enterprise data and AI leadership with a background in behavioural science.
These founders pitched at the same startup events. The room is usually the reason people find each other.