Privacy loss
Privacy loss - Unwarranted exposure of an individual’s private life or personal data through cyberattacks, doxxing, etc.
ENTITY
1 - Human
INTENT
1 - Intentional
TIMING
2 - Post-deployment
Risk ID
mit966
Domain lineage
2. Privacy & Security
2.2 > AI system security vulnerabilities and attacks
Mitigation strategy
1. Implement robust encryption for all sensitive data, both at rest and in transit, coupled with stringent Role-Based Access Controls (RBAC) to enforce the principle of least privilege across all AI system components. 2. Establish continuous, real-time monitoring and threat detection systems across the AI pipeline and associated data repositories, complemented by regular security audits and penetration testing to proactively identify and remediate vulnerabilities. 3. Develop and enforce a comprehensive data governance framework that includes mandatory employee security awareness training on cyber threats (e.g., phishing and social engineering) and ensure strict adherence to all relevant data protection regulations (e.g., GDPR).