Search arXivSearch

arXiv subjects

Andreas Wespi

Publications and source records attributed to Andreas Wespi.

2 recordsLinked to original sources

Beyond Predictable Paths: Redefining AI Security Incident Reporting for Agents

AI agents are being deployed rapidly, accompanied by a growing number of AI-specific attacks and corresponding incidents. As incident reporting becomes increasingly important for legal compliance, governance, accountability, and security; current frameworks must be adapted to the unique characteristics of AI agents. In this paper, two editorial authors compare AI systems and AI agents and, drawing on input from 23 experts in academia and industry, identify the information required for reporting incidents where the security of AI agents is harmed. %involving AI agents. Potential reporting elements include, for example, agent memory and memory accesses, actual and potential levels of autonomy, and tool usage. Based on these findings, we identify several open research questions, including how to efficiently record incidents and how to determine whether vulnerabilities and incidents generalize. Expert feedback also highlighted potential reporting weaknesses, such as risks of data leakage and attacks targeting the reporting infrastructure itself, creating additional research needs. Lastly, we summarize privacy requirements and outline research directions for the secure and trustworthy deployment of AI agents.

cs.CR

Practice-Informed, Practice-Ready: An AI security incident taxonomy

With the increasing prevalence of AI systems, several real-world AI security incidents have been reported. However, despite forthcoming legal mandates, the reporting and collection of these incidents still lacks practical standards and proposals. We bridge this gap by establishing a rigorous foundation based on discussions with a diverse group of AI practitioners spanning industrial, non-profit, research, and governmental sectors. Our proposed taxonomy provides concrete guidance to identify affected parties, recommend relevant security measures, and gain an actionable overview of the evolving AI security landscape. Our tests show that different coders consistently identify similar topics, but that automating incident tagging via an LLM like ChatGPT is of limited use. Notably, our framework has already served as the scientific basis for an established industry standard, proving its utility and readiness for widespread adoption.

cs.CR