paper

Practice-Informed, Practice-Ready: An AI security incident taxonomy

arXiv:2412.14855

Abstract

With the increasing prevalence of AI systems, several real-world AI security incidents have been reported. However, despite forthcoming legal mandates, the reporting and collection of these incidents still lacks practical standards and proposals. We bridge this gap by establishing a rigorous foundation based on discussions with a diverse group of AI practitioners spanning industrial, non-profit, research, and governmental sectors. Our proposed taxonomy provides concrete guidance to identify affected parties, recommend relevant security measures, and gain an actionable overview of the evolving AI security landscape. Our tests show that different coders consistently identify similar topics, but that automating incident tagging via an LLM like ChatGPT is of limited use. Notably, our framework has already served as the scientific basis for an established industry standard, proving its utility and readiness for widespread adoption.

Paper underlying ETSI AICIEC, under submission. Related Position paper accepted to SatML 2026: see previous version,

Practice-Informed, Practice-Ready: An AI security incident taxonomy · wovepaper