Graph of Effort: Quantifying Risk of AI Usage for Vulnerability Assessment

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Mehra, Anket, Aßmuth, Andreas, Prieß, Malte
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909568041222144
author Mehra, Anket
Aßmuth, Andreas
Prieß, Malte
author_facet Mehra, Anket
Aßmuth, Andreas
Prieß, Malte
contents With AI-based software becoming widely available, the risk of exploiting its capabilities, such as high automation and complex pattern recognition, could significantly increase. An AI used offensively to attack non-AI assets is referred to as offensive AI. Current research explores how offensive AI can be utilized and how its usage can be classified. Additionally, methods for threat modeling are being developed for AI-based assets within organizations. However, there are gaps that need to be addressed. Firstly, there is a need to quantify the factors contributing to the AI threat. Secondly, there is a requirement to create threat models that analyze the risk of being attacked by AI for vulnerability assessment across all assets of an organization. This is particularly crucial and challenging in cloud environments, where sophisticated infrastructure and access control landscapes are prevalent. The ability to quantify and further analyze the threat posed by offensive AI enables analysts to rank vulnerabilities and prioritize the implementation of proactive countermeasures. To address these gaps, this paper introduces the Graph of Effort, an intuitive, flexible, and effective threat modeling method for analyzing the effort required to use offensive AI for vulnerability exploitation by an adversary. While the threat model is functional and provides valuable support, its design choices need further empirical validation in future work.
format Preprint
id arxiv_https___arxiv_org_abs_2503_16392
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Graph of Effort: Quantifying Risk of AI Usage for Vulnerability Assessment
Mehra, Anket
Aßmuth, Andreas
Prieß, Malte
Cryptography and Security
Artificial Intelligence
Distributed, Parallel, and Cluster Computing
With AI-based software becoming widely available, the risk of exploiting its capabilities, such as high automation and complex pattern recognition, could significantly increase. An AI used offensively to attack non-AI assets is referred to as offensive AI. Current research explores how offensive AI can be utilized and how its usage can be classified. Additionally, methods for threat modeling are being developed for AI-based assets within organizations. However, there are gaps that need to be addressed. Firstly, there is a need to quantify the factors contributing to the AI threat. Secondly, there is a requirement to create threat models that analyze the risk of being attacked by AI for vulnerability assessment across all assets of an organization. This is particularly crucial and challenging in cloud environments, where sophisticated infrastructure and access control landscapes are prevalent. The ability to quantify and further analyze the threat posed by offensive AI enables analysts to rank vulnerabilities and prioritize the implementation of proactive countermeasures. To address these gaps, this paper introduces the Graph of Effort, an intuitive, flexible, and effective threat modeling method for analyzing the effort required to use offensive AI for vulnerability exploitation by an adversary. While the threat model is functional and provides valuable support, its design choices need further empirical validation in future work.
title Graph of Effort: Quantifying Risk of AI Usage for Vulnerability Assessment
topic Cryptography and Security
Artificial Intelligence
Distributed, Parallel, and Cluster Computing
url https://arxiv.org/abs/2503.16392