Deceive, Disrupt, Disclose: The 3D Model for AI Security
摘要
The evolving Artificial Intelligence (AI) landscape necessitates a maturation of the frameworks, processes, and policies for visibility and management of AI risk. Adversarial machine learning (AML) is the academic field that represents the offensive side of AI security and provides methodologies for AI security risks. While frameworks and guidelines currently exist for AI safety and cybersecurity risk, there exists a gap in the practical management of AI security risks. This paper therefore conducts a systematic analysis of AML attacks and defenses and places these techniques in the context of existing AI risk frameworks. We present and recommend a novel threat-centric security model for AI Security, the 3D model, which maps those AML techniques to three axes—Disruption, Deception, and Disclosure. Through the vehicle of a real AI incident, we substantiate the distinction between safety and security risks. We also demonstrate the benefit of applying the 3D model for organizations to prioritize and apply AI security mitigations alongside those for AI safety and information security.