securitylab_nJuly 17, 2026🇷🇺Translated from Russian

Scientists Introduce Centered Daydreaming Algorithm to Eliminate Hallucinations in Hopfield Networks by Mimicking Sleep and Memory Consolidation

Researchers have transferred the human brain’s daytime encoding and nighttime memory consolidation process into Hopfield networks, one of the earliest mathematical models of associative memory, successfully eliminating hallucinations caused by false attractors.

During the day the brain records new information; during sleep it reviews accumulated memories, reinforcing useful patterns and weakening irrelevant ones. Scientists replicated this mechanism in Hopfield networks first introduced in 1982, where interconnected artificial neurons store complete patterns that can later be reconstructed from partial or noisy inputs.

The classic model, however, suffers from severe capacity limits—roughly 13 memories per 100 neurons—because the remaining space is occupied by false attractors. These spurious states mix features from multiple learned patterns, causing the network to reconstruct nonexistent combinations that resemble AI hallucinations.

Earlier “dreaming” algorithms attempted to clean the network after training by letting it wander through random states and weakening connections leading to false attractors. Prolonged cleanup, though, triggered catastrophic forgetting, erasing correct memories along with erroneous ones.

In 2025 the team introduced the Daydreaming algorithm, which merges learning and cleanup into a single continuous process. The network simultaneously strengthens valid states and suppresses false attractors during the encoding phase itself, raising capacity close to the theoretical maximum of one memory per neuron.

The original Daydreaming method worked well only with balanced datasets where black and white pixels appeared in roughly equal proportions. Real photographs frequently violate this assumption: heavily overexposed images contain mostly white pixels, while nighttime shots are dominated by black pixels, making distinct objects appear artificially similar.

To solve the imbalance problem, researchers developed Centered Daydreaming. Instead of comparing absolute pixel values, the algorithm measures each pixel’s deviation from the dataset mean. For face recognition, the system first computes an average face and then focuses exclusively on the distinctive features that differentiate individual images from this baseline.

This local, mean-centered approach preserves biologically plausible operation: each artificial neuron updates its connections using only information available from its limited neighborhood, without requiring global knowledge of the entire network state.

Experiments confirmed that Centered Daydreaming maintains high reconstruction accuracy even under extreme data skew, whereas the previous version suffered significant degradation. Although Hopfield networks are far simpler than modern large language models, their transparent structure allows researchers to trace exactly how false memories emerge and how targeted connection adjustments can remove them.

The study demonstrates that important distinctions can be separated from dominant background statistics without centralized control, potentially informing the design of more reliable, efficient, and interpretable AI architectures in the future.

Related articles

BoletimSecAI Security

Russian State-Linked Group GTG-20006 Uses Anthropic AI Agents to Automate Malware Rebuilding

Anthropic has identified a Russian state-linked operation tracked as GTG-20006 that deployed autonomous AI agents to continuously rebuild its malware arsenal whenever detections occurred. The group, connected to Midnight Blizzard, APT29 and Cozy Bear, created a closed-loop automation system in which AI agents monitored tool performance against known defenses and triggered immediate code modifications to evade security products. Beyond malware, the agents handled domain registration, hosting infrastructure setup, phishing email delivery, command-and-control channel monitoring and implant persistence tracking across compromised environments. The campaign, active in July and August 2026 and overlapping with CaptiveCrunch, targeted more than twenty organizations including ministries, defense bodies, embassies and think tanks across Ukraine, Europe, the Middle East and Asia. In one incident the attackers exfiltrated over 300,000 national identity records and commercial registration data for more than 500,000 companies. Anthropic disrupted the activity and published a detailed report highlighting how the automation shifted the cost burden back onto defenders.

安全客AI Security

Anthropic Exposes Widespread Weaponization of Claude by Nation-State Hackers and Cybercriminals for Automated Attacks

Anthropic has released a threat intelligence report detailing how multiple state-sponsored and criminal groups systematically abused its Claude model between December 2025 and August 2026. The company introduced the term Generative Threat Groups to describe actors that built multi-agent frameworks to automate reconnaissance, exploitation, and data exfiltration. One group identified as GTG-20006, widely linked to Midnight Blizzard, APT29 and Cozy Bear, created an AI-driven workflow that automatically rewrites and redeploys malware once security tools detect it. The report highlights that this capability collapses the traditional gap between well-resourced nation-state operations and individual attackers. Defensive recommendations focus on shifting detection to behavioral chains, shortening IOC validity periods, strengthening data-loss prevention, and establishing internal governance for AI tool usage.

安全客AI Security

Unit 42 Details First Multi-Agent AI Ransomware Attack That Finished in Ten Hours

Palo Alto Networks Unit 42 has published the first confirmed case of a multi-agent AI ransomware operation. Attackers only defined the target; more than ten specialized AI agents then performed reconnaissance, credential harvesting, lateral movement, data exfiltration, and encryption within ten hours. The agents used over fifty ATT&CK techniques and successfully hid command traffic inside the victim’s own AI service endpoints. After encryption the same agents automatically generated an eighty-page security audit report listing every compromised system and technique. The sole defensive control that stopped part of the attack was a mandatory multi-person code review rule on Terraform changes. Unit 42 links the operation to frontier large-language-model frameworks and notes that earlier single-agent incidents such as JADEPUFFER have now evolved into coordinated agent fleets.

HabrAI Security

Deepfakes Turn Job Interviews into Cyberattack Vectors Targeting IT Candidates and Recruiters

Deepfake technology and malicious test assignments are increasingly used during IT hiring processes to conduct industrial espionage or deploy malware. Attackers impersonate recruiters or candidates, sending infected GitHub repositories or npm packages that install backdoors stealing credentials and enabling remote access. Groups such as Lazarus and the dedicated Contagious Interview collective have run campaigns against chemical and IT firms, while individual cases like the Smello Python developer incident show how prepare scripts in package.json can trigger hidden payloads. Gartner predicts that by 2028 one in four job applicants could be fake, creating risks beyond bad hires including data theft and financial loss. Defenses include isolated virtual machines for test tasks, profile verification by companies like Socure, and interview techniques such as the GOTCHA movement challenges or corneal reflection probes developed by universities. Major firms including Cisco, McKinsey, and Google are returning to in-person interviews as a reliable countermeasure. The rapid evolution of deepfake quality tracked by Unit 42 means layered verification combining technical, procedural, and human checks is now essential.