05-2Have you devised measures to defend against data-oriented attacks?
Determine applicability: Consider this question if you have not applied a defensive mechanism against data-oriented attacks in the development and operation process of the AI model, and determine if the requirement has been satisfied.
• Services in the public sector are open to various users; hence, they are more vulnerable to poisoning and extraction attacks than other sectors. Such attacks are highly impactful as they can even indirectly impact the people who do not use AI services.
• In particular, countermeasures are necessary when retraining the AI model using users’ input, as this can expose the model to attacks that intentionally alter the training data in service operation or produce a different result than expected by disturbing the data in the model’s inference process.
• If users’ input includes sensitive information, i.e. personal data, there could be risks of data exposure due to extraction attacks; therefore, countermeasures should be reviewed and implemented.