MIT AI Risk Repository · Risk Sub-Category · 19.01.04
Vulnerability of AI systems to attacks and misuse
Category: Technological, Data and Analytical AI Risks
Description
—
From Governance of artificial intelligence: A risk and guideline-based integrative framework (Wirtz2022), as extracted by the MIT AI Risk Repository (CC BY 4.0).
Classification
- Domain
- 2. Privacy & Security
- Causal entity
- Other
- Intent
- Intentional
- Timing
- Other
Subdomain definition: Vulnerabilities in AI systems, software development toolchains, and hardware that can be exploited, resulting in unauthorized access, data and privacy breaches, or system manipulation causing unsafe outputs or behavior.
Real-world incidents in this subdomain
- COEMPT Quality Assurance Engineers Allegedly Violated Indian CBSE Student Data Privacy Rights by Processing It with Google Gemini
- Hidden Prompt Injection in Brazilian Labor-Court Petition Reportedly Tried to Manipulate Galileu
- Meta Internal AI Agent Reportedly Gave Advice That Allegedly Exposed Sensitive Data to Unauthorized Employees
- CodeWall's Autonomous Agent Reportedly Obtained Unauthorized Access to McKinsey's Lilli AI Platform Database
- Anthropic Said DeepSeek, Moonshot, and MiniMax Used Fraudulent Accounts and Proxies to Illicitly Distill Claude Capabilities at Scale
- DJI Romo Cloud Authorization Bug Reportedly Exposed Camera, Microphone, and Home-Mapping Data From Nearly 7,000 Robot Vacuums
How other frameworks describe this risk
Other entries from Wirtz2022
- Technological, Data and Analytical AI Risks
- Loss of control of autonomous systems and unforeseen behaviour due to lack of transparency and self-programming/ reprogramming
- Programming error
- Lack of data, poor data quality, and biases in training data
- Lack of AI experts with comprehensive AI knowledge
- Immaturity of AI technology can cause incorrect decisions
- High investment costs of AI hinder integration
- Informational and Communicational AI Risks
- Manipulation and control of information provision (e.g., personalised adds, filtered news)
- Disinformation and computational propaganda
- Censorship of opinions expressed in the Internet restricts freedom of expression
- Endangerment of data protection through AI cyberattacks