paper-with-me

홈 › Papers

Quantifying Security Vulnerabilities: A Metric-Driven Security Analysis of Gaps in Current AI Standards

2025-02-12 · Keerthana Madhavan, Abbas Yazdinejad, Fattane Zarrinkalam, Ali Dehghantanha

As AI systems integrate into critical infrastructure, security gaps in AI compliance frameworks demand urgent attention. This paper audits and quantifies security risks in three major AI governance standards: NIST AI RMF 1.0, UK's AI and Data Protection Risk Toolkit, and the EU's ALTAI. Using a novel risk assessment methodology, we develop four key metrics: Risk Severity Index (RSI), Attack Potential Index (AVPI), Compliance-Security Gap Percentage (CSGP), and Root Cause Vulnerability Score (RCVS). Our analysis identifies 136 concerns across the frameworks, exposing significant gaps. NIST fails to address 69.23 percent of identified risks, ALTAI has the highest attack vector vulnerability (AVPI = 0.51) and the ICO Toolkit has the largest compliance-security gap, with 80.00 percent of high-risk concerns remaining unresolved. Root cause analysis highlights under-defined processes (ALTAI RCVS = 033) and weak implementation guidance (NIST and ICO RCVS = 0.25) as critical weaknesses. These findings emphasize the need for stronger, enforceable security controls in AI compliance. We offer targeted recommendations to enhance security posture and bridge the gap between compliance and real-world AI risks.

📄 PDF Abstract BibTeX arXiv:2502.08610

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Large Language Model-driven Security Assistant for Internet of Things via Chain-of-Thought

2025-05-08 · Mingfei Zeng, Ming Xie, Xixi Zheng, Chunhai Li 외

The rapid development of Internet of Things (IoT) technology has transformed people's way of life and has a profound impact on both production and daily activities. However, with the rapid advancement of IoT technology, …

Language ModelingLanguage ModellingLarge Language Model

Enabling Automatic Repair of Source Code Vulnerabilities Using Data-Driven Methods

2022-02-07 · Anastasiia Grishina

Users around the world rely on software-intensive systems in their day-to-day activities. These systems regularly contain bugs and security vulnerabilities. To facilitate bug fixing, data-driven models of automatic progr…

Bug fixingProgram Repair

From Detection to Prevention: Explaining Security-Critical Code to Avoid Vulnerabilities

2026-01-31 · Ranjith Krishnamurthy, Oshando Johnson, Goran Piskachev, Eric Bodden arxiv

Security vulnerabilities often arise unintentionally during development due to a lack of security expertise and code complexity. Traditional tools, such as static and dynamic analysis, detect vulnerabilities only after t…

Data Agents Under Attack: Vulnerabilities in LLM-Driven Analytical Systems

2026-06-07 · Kuncan Wang, Ziting Wang, Peizhuo Lv, Haoyang Li 외 arxiv

Data agents integrate LLM-driven reasoning with relational data access, executable analytical tools, and multi-step workflow orchestration, making them increasingly central to enterprise analytics. This integration intro…

Enforcing Cybersecurity Constraints for LLM-driven Robot Agents for Online Transactions

2025-03-17 · Shraddha Pradipbhai Shah, Aditya Vilas Deshpande

The integration of Large Language Models (LLMs) into autonomous robotic agents for conducting online transactions poses significant cybersecurity challenges. This study aims to enforce robust cybersecurity constraints to…

Anomaly Detection