AI Threat Model

AI Threat Model A workflow diagram generated by Archify. 01 / Layer 01 Govern-as-Code 02 / Layer 03 Evals & Red Teaming as Evidence 03 / Risk register EX / Design review fails Scope Enumerate + decide Test + gate Design record · data-flow diagram · Layer 01 Govern-as-Code › Scope Design record data-flow diagram STRIDE per element · trust boundaries · Layer 01 Govern-as-Code › Enumerate + decide STRIDE per element trust boundaries AI-specific classes · ATLAS, NIST, OWASP · Layer 01 Govern-as-Code › Enumerate + decide AI-specific classes ATLAS, NIST, OWASP Rate and decide · mitigate or accept · Layer 01 Govern-as-Code › Enumerate + decide Rate and decide mitigate or accept Test per mitigation · red-team case, eval · Layer 03 Evals & Red Teaming as Evidence › Test + gate Test per mitigation red-team case, eval Design review gate · every threat tested · Layer 03 Evals & Red Teaming as Evidence › Test + gate · pass / fail Design review gate every threat tested pass / fail Accepted threats · named acceptor · Risk register › Test + gate Accepted threats named acceptor Review fails · threat without a test · Design review fails › Test + gate Review fails threat without a test rate accept mitigate decompose untested threat extend test ids Legend Agent logic Policy Context / trace External system

Scope the AI surface

  • • Decompose data sources, training, model artefact, corpus, prompts, tools and the inference API
  • • Training data stores and the model registry are in scope
  • • Keep the model as a versioned data file next to the design record

STRIDE, extended

  • • Walk each element with the six STRIDE categories
  • • Add poisoning, evasion, extraction, prompt injection and unsafe model files
  • • Name catalogue ids from MITRE ATLAS and the OWASP lists

Every threat resolves

  • • Mitigated threats carry the id of the test that proves the control
  • • Accepted threats go to the risk register with a named acceptor
  • • A new tool, data source, model or technique reopens the model