ossf / ai-ml-security

Potential WG on Artificial Intelligence and Machine Learning (AI/ML)
Apache License 2.0
45 stars 6 forks source link

Map AIML WG outputs to MLSecOps diagram #16

Open sevansdell opened 1 month ago

sevansdell commented 1 month ago

I really like the MLSecOps document shared by Ericson: https://www.ericsson.com/en/reports-and-papers/white-papers/mlsecops-protecting-the-ai-ml-lifecycle-in-telecom

  1. I would like to show where in the MLSecOps lifecycle security artifacts/artifact checking helps improve security.
  2. I would like to map how OWASP ML top 10 are mitigated using MLSecOps in the same diagram https://owasp.org/www-project-machine-learning-security-top-10/#:~:text=Top%2010%20Machine%20Learning%20Security%20Risks%201%20ML01%3A2023,Learning%20Attack%208%20ML08%3A2023%20Model%20Skewing%20More%20items.
  3. I would like to identify where open source or closed source data, models and code impact the AI supply chain/ ML Lifecycle.

I would like to discuss in a future call if the team feels this is an interesting visual/written output on which to collaborate, if is already duplicating an existing industry effort, or if it's a good idea but doesn't fall into the scope of the AIML WG.

TheFoxAtWork commented 1 month ago

Yes! This is along the lines of my ask on the call yesterday. I believe @camaleon2016 had mentioned working on something related in another group and would report back/share.

Jay - is this the same or different than what you mentioned on the call?

camaleon2016 commented 1 month ago

Yes! This is along the lines of my ask on the call yesterday. I believe @camaleon2016 had mentioned working on something related in another group and would report back/share.

Jay - is this the same or different than what you mentioned on the call?

This is different but equally good!

sevansdell commented 3 days ago

Have started work on this. Will share a v1 in a couple weeks with the team.