Section 099 · Chapter 13, AI Security and Guardrails

AI Security Threat Models

AI security starts by naming what the system can read, infer, decide, and do.

threat modelsecurity threat models

What to do

  1. Define runnable checks that exercise threat model and security threat models.
  2. Set acceptable outcomes and blocker failures for threat model and security threat models before running the evaluation.
  3. Run representative cases for threat model and security threat models and preserve the failures that would change the decision.

Evidence to preserve

  • Preserve the inputs, versions, configurations, raw outcomes, and results for threat model, security threat models needed to reproduce work on AI Security Threat Models.
  • Report results for threat model, security threat models by relevant slice, separate blocker failures from averages, state uncertainty and blind spots, and connect the result to a release decision.

Expert note

The deeper move is to maintain an AI-specific threat model with assets, actors, trust boundaries, untrusted inputs, tools, permissions, logs, mitigations, eval cases, and even physical security. Security tests should be replayable and part of release gates, not one-time red-team theater.

Continue the conversation

Apply this to your context.

Save your product context once, then open a focused conversation that combines it with this concept.

Cite this page

Jason Arbon. "AI Security Threat Models." Testing AI Knowledge Edition, section 99.

https://jarbon.ai/testing-ai/knowledge/ch099-security-threat-models.html

Shared across the Knowledge Edition

Adapt every concept to your world.

Describe your product, role, users, risks, constraints, or current quality problem. This stays in this browser until you choose to send it to ChatGPT.

Saved only in this browser.0 / 2400