Establishing Minimum Elements for Effective Vulnerability Management in AI Software

📅 2024-11-18
🏛️ arXiv.org
📈 Citations: 2
✨ Influential: 0
📄 PDF
🤖 AI Summary
The absence of a unified framework for identifying, assessing, and mitigating vulnerabilities in AI systems hinders systematic AI security governance. Method: This paper proposes the first minimal-element framework for AI software vulnerability management and designs a standardized Artificial Intelligence Vulnerability Database (AIVD). It formally defines four core vulnerability management phases—disclosure, analysis, cataloging, and documentation—and develops an AI-adapted severity scoring model, a weakness enumeration taxonomy, and multi-dimensional mitigation strategies. To support heterogeneous AI models, it introduces a standardized description language, an AI-specific classification ontology, and cross-modal representation techniques. Contribution/Results: The work yields a draft AIVD construction specification, identifies critical capability gaps, and provides a technical foundation for international standards bodies—including NIST—to institutionalize and scale AI security governance.

Technology Category

Philosophy and Ethics of AI: Privacy & SecurityHumans and AI: AI for AccessibilityComputer Vision: Adversarial Attacks & Robustness

Application Category

Security and Privacy: Security and privacy of machine learning and AI applicationsSystems and Infrastructure for Web, Mobile and WoT: Applied ML and AI for Web-based mobile applicationsSemantics and Knowledge: Provenance, trust, security and privacy, and ethical issues in managing semantic data
📝 Abstract
In the rapidly evolving field of artificial intelligence (AI), the identification, documentation, and mitigation of vulnerabilities are paramount to ensuring robust and secure systems. This paper discusses the minimum elements for AI vulnerability management and the establishment of an Artificial Intelligence Vulnerability Database (AIVD). It presents standardized formats and protocols for disclosing, analyzing, cataloging, and documenting AI vulnerabilities. It discusses how such an AI incident database must extend beyond the traditional scope of vulnerabilities by focusing on the unique aspects of AI systems. Additionally, this paper highlights challenges and gaps in AI Vulnerability Management, including the need for new severity scores, weakness enumeration systems, and comprehensive mitigation strategies specifically designed to address the multifaceted nature of AI vulnerabilities.
Problem

Research questions and friction points this paper is trying to address.

Establishing minimum elements for AI vulnerability management systems
Creating standardized protocols for AI vulnerability documentation and disclosure
Addressing unique AI system vulnerabilities beyond traditional security approaches
Innovation

Methods, ideas, or system contributions that make the work stand out.

Establishes AI Vulnerability Database for cataloging
Standardizes formats for AI vulnerability disclosure
Proposes new severity scores for AI weaknesses
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
University of Hawaii at Manoa
M
Mohamad Fazelnia
University of Hawaii at Manoa, HI, USA
S
Sara Moshtari
University of Hawaii at Manoa, HI, USA
M
M. Mirakhorli
University of Hawaii at Manoa, HI, USA