Перейти до вмісту
← AI security frameworks and red teaming

Урок 2 з 9 · 8 хв

The NIST AI Risk Management Framework and its Generative AI Profile

Understand the four functions of NIST AI RMF 1.0 (Govern, Map, Measure, Manage), what the Generative AI Profile adds, and where red teaming fits.

Поки що ця сторінка англійською.

The NIST AI Risk Management Framework (AI RMF 1.0) is the governance layer of this course. It was released on 26 January 2023 as “a framework to better manage risks to individuals, organizations, and society associated with artificial intelligence”, and NIST says it is “intended for voluntary use.” It is not a technical test plan and it does not list attacks. What it does is tell an organisation how to organise itself so that AI risks are found, owned and treated over time.

Trustworthiness and where security sits

The framework aims to help organisations build trustworthiness into how AI is designed, developed, used and evaluated. It names seven characteristics of trustworthy systems: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed. Security is one of the seven, and NIST describes a system as secure when it can maintain confidentiality, integrity and availability through protection mechanisms that prevent unauthorised access and use. It lists adversarial examples, data poisoning and exfiltration of models or training data through system endpoints as common security concerns. Those concerns are then traded off against the other characteristics rather than treated alone.

The four functions

The Core of the framework has four functions. NIST is explicit that its actions “do not constitute a checklist, nor are they necessarily an ordered set of steps”, and that risk management should be continuous and performed throughout the AI lifecycle.

Function descriptions paraphrase the AI RMF Core; category numbers are from its subcategory tables.
FunctionWhat NIST says it doesExamples of outcomes it names
GovernCultivates a culture of risk management; a cross-cutting function infused through the other threeLegal requirements understood (Govern 1.1); AI systems inventoried (1.6); risks from third-party software and data addressed (Govern 6)
MapEstablishes the context that frames risks for a systemIntended purpose and settings documented (Map 1.1); knowledge limits and human oversight documented (Map 2.2)
MeasureUses quantitative, qualitative or mixed methods to analyse, assess and monitor AI riskSecurity and resilience evaluated and documented (Measure 2.7); privacy risk examined (2.10)
ManageAllocates resources to mapped and measured risks and plans responses and recoveryTreatment prioritised by impact and likelihood (Manage 1.2); incidents communicated to affected parties (4.3)

Two design points matter for security teams. First, Govern comes first and stays: after establishing it, NIST says most users start with Map and continue to Measure or Manage, iterating and cross-referencing. Second, Map ends in a decision. Once context is understood, organisations should be able to make an initial go or no-go call on whether to design, develop or deploy the system at all. A red team that skips Map tests the wrong thing.

Measure is where testing lives

The Measure function says AI systems “should be tested before their deployment and regularly while in operation.” Measure 2.7 is the security subcategory: system security and resilience, as identified in Map, are evaluated and documented. Measure 1.1 also requires that risks or trustworthiness characteristics that will not or cannot be measured are documented, which is a useful habit for any test report: say what you did not test.

What the Generative AI Profile adds

NIST released the Generative AI Profile (NIST AI 600-1) on 26 July 2024. It is a companion to the framework that “can help organizations identify unique risks posed by generative AI” and proposes actions to manage them. It defines twelve risks that are unique to or exacerbated by generative AI. Several are directly relevant to a security review: Information Security, Data Privacy, Value Chain and Component Integration (untraceable third-party components and poor supplier vetting), Confabulation, and Human-AI Configuration (over-reliance and automation bias).

The profile ties red teaming to the Measure function. Under Measure 2.7 it suggests performing AI red teaming to assess resilience against abuse to facilitate attacks on other systems, generative-AI attacks such as prompt injection, and machine-learning attacks including adversarial examples, data poisoning, membership inference, model extraction and sponge examples. It defines AI red teaming as a structured testing exercise used to probe an AI system to find flaws and vulnerabilities, often in a controlled environment and in collaboration with system developers.

  • NIST notes that the quality of red-team output relates to the background and expertise of the team, and that diverse, interdisciplinary teams can find flaws in the varying contexts where the system will be used.
  • It describes general-public, expert, combined and human-plus-AI red teaming, and says AI-led red teaming can be more cost effective than human red teamers alone, while human and AI approaches may suit different kinds of harm.
  • It says red-team results should get additional analysis before they feed governance decisions and policy updates. A finding is an input to Manage, not the end of the process.

Keep the framework’s status in mind. AI RMF 1.0 is currently being revised as part of the White House AI Action Plan, according to NIST’s framework page, so verify the current text before you cite a subcategory number in a report.

Головне

  • AI RMF 1.0 (26 January 2023) is voluntary and organises AI risk work into Govern, Map, Measure and Manage.
  • Govern is cross-cutting; Map ends in a go or no-go decision; Measure is where security testing (Measure 2.7) lives; Manage treats and communicates what testing finds.
  • The Generative AI Profile (NIST AI 600-1, 26 July 2024) defines twelve generative AI risks and links red teaming to Measure 2.7.
  • Red-team results need analysis before they change governance decisions, and a good report also says what was not tested.

Перевірте себе

  1. 1. Which AI RMF function is described as cross-cutting and infused throughout the others?

    • Map
    • Measure
    • Govern — Правильно.
    • Manage

    NIST describes Govern as a cross-cutting function that informs and enables the other three, and says compliance and evaluation aspects should be integrated into each.

  2. 2. What does the Map function produce that a red team should rely on?

    • A list of exploits
    • Contextual knowledge of the system’s purpose, setting and risks, supporting a go or no-go decision — Правильно.
    • A fixed order of tests
    • A certification of the model

    Map establishes context. After it, organisations should have enough understanding to make an initial decision about whether to design, develop or deploy the system.

  3. 3. Where does NIST AI 600-1 place its suggestion to perform AI red teaming against prompt injection and data poisoning?

    • Under Govern only
    • Under the Measure function (Measure 2.7, security and resilience) — Правильно.
    • Under Manage only
    • It does not mention red teaming

    The profile’s suggested actions under Measure 2.7 include AI red teaming to assess resilience against abuse, prompt injection and machine-learning attacks.

Застосуйте на практиці з FireAI

Застосуйте цей урок на своєму Mac.

Джерела

Застосуйте це на своєму Mac

Усі функції безкоштовно на 17 днів, без банківської картки.

Завантажити для Mac Документація