🤖 AI Summary
The absence of a unified framework for identifying, assessing, and mitigating vulnerabilities in AI systems hinders systematic AI security governance. Method: This paper proposes the first minimal-element framework for AI software vulnerability management and designs a standardized Artificial Intelligence Vulnerability Database (AIVD). It formally defines four core vulnerability management phases—disclosure, analysis, cataloging, and documentation—and develops an AI-adapted severity scoring model, a weakness enumeration taxonomy, and multi-dimensional mitigation strategies. To support heterogeneous AI models, it introduces a standardized description language, an AI-specific classification ontology, and cross-modal representation techniques. Contribution/Results: The work yields a draft AIVD construction specification, identifies critical capability gaps, and provides a technical foundation for international standards bodies—including NIST—to institutionalize and scale AI security governance.
📝 Abstract
In the rapidly evolving field of artificial intelligence (AI), the identification, documentation, and mitigation of vulnerabilities are paramount to ensuring robust and secure systems. This paper discusses the minimum elements for AI vulnerability management and the establishment of an Artificial Intelligence Vulnerability Database (AIVD). It presents standardized formats and protocols for disclosing, analyzing, cataloging, and documenting AI vulnerabilities. It discusses how such an AI incident database must extend beyond the traditional scope of vulnerabilities by focusing on the unique aspects of AI systems. Additionally, this paper highlights challenges and gaps in AI Vulnerability Management, including the need for new severity scores, weakness enumeration systems, and comprehensive mitigation strategies specifically designed to address the multifaceted nature of AI vulnerabilities.