Managing Security Risks in AI Deployment
摘要
Artificial intelligence (AI) systems introduce a rapidly evolving security landscape in which conventional cybersecurity approaches are no longer sufficient. Because AI applications are data-dependent, statistically driven, and continuously updated, they expose novel attack surfaces including data poisoning, backdoor insertion, model inversion and extraction, adversarial perturbations, and privacy-compromising inference attacks. This chapter proposes a structured taxonomy of these risks across data, model, infrastructure, human governance, and societal levels, demonstrating how adversaries exploit vulnerabilities throughout the AI lifecycle from compromised data pipelines and unverified training sources to misconfigured cloud deployment and insecure model supply chains. Existing governance frameworks, including the European Union AI Act, the National Institute of Standards and Technology (NIST) AI Risk Management Framework, and the OECD AI Principles, reflect increasing regulatory convergence yet lack harmonized operational security requirements and standardized evaluation metrics. To address these gaps, this chapter presents a Secure AI Development Lifecycle (AI-SDLC) that incorporates risk-aware design, trustworthy data governance, adversarial robust model training, secure MLOps deployment, and post-deployment monitoring. Empirical case studies across healthcare, autonomous systems, financial platforms, and pharmaceutical R&D illustrate the real-world consequences of insecure AI deployment. This chapter concludes by emphasizing the imperative for defense-in-depth security, sustained human oversight in high-risk environments, and international cooperation to ensure that AI technologies remain trustworthy, safe, and aligned with public welfare.