NIST Seeks Blueprint for AI-Era National Vulnerability Database Overhaul
TL;DR. NIST began collecting public feedback to modernize the National Vulnerability Database for AI systems and AI-generated vulnerabilities. - The current NVD primarily handles software vulnerabilities, proving inadequate for the unique risks posed by AI/ML models. - NIST seeks input on how to classify, identify, and address AI vulnerabilities, including data poisoning and adversarial attacks. - The agency also wants to define roles for AI developers and third-party researchers in the disclosure process.
- NIST initiated a Request for Information (RFI) to update the National Vulnerability Database (NVD) for AI.
- The NVD currently lacks suitable categories and mechanisms for AI-specific security vulnerabilities.
- Feedback is sought on identifying, classifying, and mitigating AI/ML risks like data poisoning and model manipulation.
- The RFI aims to clarify responsibilities for reporting and addressing AI vulnerabilities across the ecosystem.
Sources
- NIST Seeks Blueprint for AI-Era Overhaul of National Vulnerability Database — securityboulevard.com