Industry AI threat taxonomies
AI threat taxonomies is an active and evolving field that is attempting to provide a standard. There are three leading taxonomies, each with a different focus:
- MITRE ATLAS: This follows MITRE’s ATT@CK example with a catalog of tactics, techniques, and procedures (TTPs) that are used by threat actors against AI systems. MITRE ATLAS helps organizations identify and understand potential AI-specific threats, facilitating the development of effective defense strategies.
It helps understand the attack kill chain by relating tactics and techniques. Because it uses industry-standard Structured Threat Information eXpression (STIX), it integrates with threat intelligence (TI) tools. This, in turn, helps connect threat models to TI and monitor when a solution is deployed.
You can find out more about ATLAS at https://atlas.mitre.org/.
- NIST AI 100-2 E2023: This is from the National Institute of Standards and Technology (NIST) and provides a catalog...