Paper Type

ERF

Abstract

While organizations are rapidly adopting generative AI systems, AI security governance remains underdeveloped, creating security risks. Two primary threat management frameworks guiding the AI threat landscape are the OWASP Top 10 for LLM Applications, which identifies priority vulnerability categories, and MITRE ATLAS, which documents adversary tactics and techniques across AI systems. Using directed content analysis, we examine 52 MITRE ATLAS case studies against the OWASP Top 10 to assess alignment. Results show substantial but uneven alignment. We identify three types of coverage gaps: OWASP categories underrepresented in ATLAS, modality-specific vulnerabilities, and adversary preparation behaviors not captured by OWASP. We provide an empirical assessment of framework coherence, highlight structural gaps in AI threat intelligence, and inform modality-aware AI security governance.

Paper Number

1467

Comments

SIG SEC

Share

COinS
 
Aug 15th, 12:00 AM

Governing AI Threats Through Adversarial Threat Frameworks

While organizations are rapidly adopting generative AI systems, AI security governance remains underdeveloped, creating security risks. Two primary threat management frameworks guiding the AI threat landscape are the OWASP Top 10 for LLM Applications, which identifies priority vulnerability categories, and MITRE ATLAS, which documents adversary tactics and techniques across AI systems. Using directed content analysis, we examine 52 MITRE ATLAS case studies against the OWASP Top 10 to assess alignment. Results show substantial but uneven alignment. We identify three types of coverage gaps: OWASP categories underrepresented in ATLAS, modality-specific vulnerabilities, and adversary preparation behaviors not captured by OWASP. We provide an empirical assessment of framework coherence, highlight structural gaps in AI threat intelligence, and inform modality-aware AI security governance.

When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.