How should I threat-model an AI system?
Answered
Use a holistic process covering impacts on the system, users, organisations and wider society if an AI component is compromised or behaves unexpectedly. Assess AI-specific threats, document decisions, and note that sensitive data and rising target value increase attacker interest. Secure by Design also expects threat assessment and modelling as part of a risk-driven approach.
From the guidance
Primary (how) NCSC: Secure design (AI systems)
Section: Model the threats to your system
Read this in NCSC: Secure design (AI systems) (opens in new tab)
Secondary (normative) Secure by Design Principles
Section: 3. Adopt a risk-driven approach
Related questions
- What is data poisoning in an AI system?
- How do I monitor an AI system once it is live? Delivery, assurance and operations
- Should we document AI models with model cards or SBOMs? Delivery, assurance and operations
- What does data-protection fairness require of an AI system? Lawful, ethical and responsible use
- Should we monitor AI system inputs as well as outputs? Delivery, assurance and operations