Security Risks in AI and Machine Learning: Categorizing Attacks and Failure Modes

Security Risks in AI and Machine Learning: Categorizing Attacks and Failure Modes

1h 46mIntermediate2025-11-07

Authors

Diana Kelley

Diana Kelley

CTO and Cofounder of SecurityCurve

Course details

Like any software or process, machine learning (ML) is vulnerable to attack. In order to protect something, you must first understand where and how a system is vulnerable. In this course, Diana Kelley shows experienced threat modelers the ways that ML shifts the focus based on potential impact and from the vast amount of data that ML systems need to fuel their operation. Diana shows how ML can fail in a number of ways when under attack from adversaries and how design flaws can also lead to operational failure, data leakage, and other security and privacy risks.

Learn the importance of building resilient ML, the impacts of failure to build security into ML, and where and how ML is vulnerable from intentional adversaries and from design and implementation issues. Plus, discover some of the most effective approaches and techniques for building robust and resilient ML.

Learning objectives
Understand why failure modes (malicious attacks and unintended failures) are important and how they impact ML/AI security.
Understand the landscape of possible failure modes, what causes them, and real-life examples.
Incorporate failure modes into threat modeling, testing, and other security control deployments.

Skills covered

Software Development SecurityMachine Learning FundamentalsTraditional AI and Machine LearningArtificial Intelligence (AI)CybersecurityOne-Off

Concepts

Introduction

  • Machine learning security concerns

AI Foundations

  • How AI systems can fail and how to protect them
  • Why AI security matters
  • Attacks vs. unintentional failure modes
  • ML security frameworks
  • Security goals for ML - CIA

Intentional Failure Modes and Attacks

  • Perturbation attacks and malicious input
  • Poisoning attacks
  • Reprogramming
  • Physical domain - 3D adversarial objects
  • Supply chain attacks
  • Model inversion
  • System manipulation
  • Membership inference and model stealing
  • Backdoors and existing exploits

Unintentional Failure Modes and Intrinsic Design Flaws

  • Reward hacking
  • Side effects and misalignment
  • Distributional shifts and incomplete testing
  • Overfitting and underfitting
  • Data bias considerations

Building Resilient AI

  • Effective techniques for building resilience in AI
  • Threat modeling AI
  • Dataset threat model
  • Adversarial testing and red teaming
  • API access and supporting components
  • Supply chain

Conclusion

  • Next steps in your AI security journey
40,000 Toman