构建可量化AI风险的分类体系,打通技术与合规之间的沟通鸿沟。
Standardized Threat Taxonomy for AI Security, Governance, and Regulatory Compliance
- 提出9大风险领域+53个可操作子威胁,统一技术与业务语言。
- 133起真实事件验证全覆盖,实现威胁到财务损失的精准映射。
- 适配欧盟法案、NIST框架等,适合安全、合规与保险从业者使用。
人工智能在受监管领域的快速部署暴露出风险评估方法的严重碎片化。当前,技术安全团队(如MITRE ATLAS)关注算法漏洞,而法律合规人员(如欧盟《人工智能法案》、NIST AI RMF)聚焦监管要求,二者间存在显著“语言壁垒”,导致无法将技术漏洞转化为财务责任,使从业者难以回答关于应急储备、控制投资回报率及保险暴露等核心经济问题。为此,本文提出AI系统威胁向量分类法,一种专为定量风险评估(QRA)设计的结构化本体。该框架将AI特有风险划分为九个关键领域:滥用、投毒、隐私、对抗、偏见、不可靠输出、漂移、供应链及知识产权威胁,并整合53个可操作定义的子威胁。其独特之处在于,每个领域均直接映射至业务损失类别(机密性、完整性、可用性、法律、声誉),实现从抽象威胁到可度量财务影响的转化。该分类法通过2025年133起已记录的AI事件分析得到实证验证,达到100%分类覆盖率,并与主流AI风险框架对齐。此外,其明确对接ISO/IEC 42001控制项与NIST AI RMF功能,以增强审计可行性。
原文摘要 · Abstract (English)
The accelerating deployment of artificial intelligence systems across regulated sectors has exposed critical fragmentation in risk assessment methodologies. A significant "language barrier" currently separates technical security teams, who focus on algorithmic vulnerabilities (e.g., MITRE ATLAS), from legal and compliance professionals, who address regulatory mandates (e.g., EU AI Act, NIST AI RMF). This disciplinary disconnect prevents the accurate translation of technical vulnerabilities into financial liability, leaving practitioners unable to answer fundamental economic questions regarding contingency reserves, control return-on-investment, and insurance exposure. To bridge this gap, this research presents the AI System Threat Vector Taxonomy, a structured ontology designed explicitly for Quantitative Risk Assessment (QRA). The framework categorizes AI-specific risks into nine critical domains: Misuse, Poisoning, Privacy, Adversarial, Biases, Unreliable Outputs, Drift, Supply Chain, and IP Threat, integrating 53 operationally defined sub-threats. Uniquely, each domain maps technical vectors directly to business loss categories (Confidentiality, Integrity, Availability, Legal, Reputation), enabling the translation of abstract threats into measurable financial impact. The taxonomy is empirically validated through an analysis of 133 documented AI incidents from 2025 (achieving 100% classification coverage) and reconciled against the main AI risk frameworks. Furthermore, it is explicitly aligned with ISO/IEC 42001 controls and NIST AI RMF functions to facilitate auditability.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。