arXiv · 2412.14855
Practice-Informed, Practice-Ready: An AI security incident taxonomy
Abstract
With the increasing prevalence of AI systems, several real-world AI security incidents have been reported. However, despite forthcoming legal mandates, the reporting and collection of these incidents still lacks practical standards and proposals. We bridge this gap by establishing a rigorous foundation based on discussions with a diverse group of AI practitioners spanning industrial, non-profit, research, and governmental sectors. Our proposed taxonomy provides concrete guidance to identify affected parties, recommend relevant security measures, and gain an actionable overview of the evolving AI security landscape. Our tests show that different coders consistently identify similar topics, but that automating incident tagging via an LLM like ChatGPT is of limited use. Notably, our framework has already served as the scientific basis for an established industry standard, proving its utility and readiness for widespread adoption.
Explore related subjects
Keep this discovery
Lukas Bieringer, Sean McGregor, Nicole Nichols, Kevin Paeth, Andrew Paverd, Jonathan Petit, Jochen Stängler, Andreas Wespi, Alexandre Alahi, Kathrin Grosse. 2024-12-19. Practice-Informed, Practice-Ready: An AI security incident taxonomy. https://arxiv.org/abs/2412.14855
Cite the original work for its findings. Save a collection to share your selection of sources.