Deploy Securely

How should we track AI vulnerabilities?

StackAware

The Cybersecurity and Infrastructure Security Agency (CISA) released a post earlier this year saying the AI engineering community should use something like the existing CVE system for tracking vulnerabilities in AI models.

Unfortunately, this is a pretty bad recommendation.

That's because:

- CVEs already create a lot of noise
- AI systems are non-deterministic
- So things would just get worse

In this episode, I dive into these issues and discuss the way ahead.

Check out the full blog post: https://blog.stackaware.com/p/how-should-we-identify-ai-vulnerabilities