Sberbank Publishes Updated Threat Model for AI Systems
Сбер
Сбербанк
Sberbank has publicly released an updated threat model for artificial intelligence systems, describing 37 threats and 51 attack methods. The document is aimed at developers, MLOps engineers, and cybersecurity specialists, and is available on the Kibrary portal.
Sberbank has opened access to its updated threat model for AI systems, published on the Kibrary portal in the 'For Experts' section. The model reflects changes in the cyber threat landscape caused by the widespread adoption of generative models, multi-agent systems, RAG, LLM adapters, and increasingly complex AI architectures. It describes 37 threats and 51 implementation methods, each with possible consequences, affected information properties, related objects, and lifecycle stages. The threats can lead to data leaks, data corruption, availability breaches, model compromise, and unauthorized AI agent actions. The model maps threats to potential attacker types with varying awareness, technical capabilities, and access levels, and expands the list of protection objects to include previously unconsidered critical attack points. It is designed for AI developers, MLOps engineers, architects, cybersecurity specialists, and risk managers, helping to systematically address cybersecurity threats throughout the lifecycle of AI solutions. The document is based on current threat analysis, global practices, and Sberbank's own experience in securing AI development and operation infrastructure.
- Сокращения
- RAG = Retrieval-Augmented Generation — генерация с дополнением через поиск
- LLM = Large Language Model — большая языковая модель
- MLOps = Machine Learning Operations — операции машинного обучения
Source: CNews —
original
