Section 099 · Chapter 13, AI Security and Guardrails
AI Security Threat Models
AI security starts by naming what the system can read, infer, decide, and do.
threat modelsecurity threat models
What to do
- Define runnable checks that exercise threat model and security threat models.
- Set acceptable outcomes and blocker failures for threat model and security threat models before running the evaluation.
- Run representative cases for threat model and security threat models and preserve the failures that would change the decision.
Evidence to preserve
- Preserve the inputs, versions, configurations, raw outcomes, and results for threat model, security threat models needed to reproduce work on AI Security Threat Models.
- Report results for threat model, security threat models by relevant slice, separate blocker failures from averages, state uncertainty and blind spots, and connect the result to a release decision.
Expert note
The deeper move is to maintain an AI-specific threat model with assets, actors, trust boundaries, untrusted inputs, tools, permissions, logs, mitigations, eval cases, and even physical security. Security tests should be replayable and part of release gates, not one-time red-team theater.
Continue the conversation
Apply this to your context.
Save your product context once, then open a focused conversation that combines it with this concept.
Cite this page
Jason Arbon. "AI Security Threat Models." Testing AI Knowledge Edition, section 99.
https://jarbon.ai/testing-ai/knowledge/ch099-security-threat-models.html