Lessons Learned in Coordinated Disclosure for Artificial Intelligence and Machine Learning Systems
• SEI Report
Publisher
Software Engineering Institute
DOI (Digital Object Identifier)
10.1184/R1/26867038.v1Abstract
In this paper, SEI researchers incorporate several lessons learned from the coordination of artificial intelligence (AI) and machine learning (ML) vulnerabilities at the SEI’s CERT Coordination Center (CERT/CC). They also include their observations of public discussions of AI vulnerability coordination cases.
Risk management within the context of AI systems is a rapidly evolving and substantial space. Even when restricted to cybersecurity risk management, AI systems require comprehensive security, such as what the National Institute of Standards and Technology (NIST) describes in The NIST Cybersecurity Framework (CSF).
In this paper, the authors focus on one part of cybersecurity risk management for AI systems: the CERT/CC’s lessons learned from applying the Coordinated Vulnerability Disclosure (CVD) process to reported “vulnerabilities” in AI and ML systems.
Cite This SEI Report
Householder, A., Sarvepalli, V., Havrilla, J., Churilla, M., Pons, L., Lau, S., VanHoudnos, N., Kompanek, A., & McIlvenny, L. (2024, August 20). Lessons Learned in Coordinated Disclosure for Artificial Intelligence and Machine Learning Systems. Retrieved September 11, 2026, from https://doi.org/10.1184/R1/26867038.v1.
@techreport{householder_2024,
author={Householder, Allen and Sarvepalli, Vijay and Havrilla, Jeff and Churilla, Matt and Pons, Lena and Lau, Shing-hon and VanHoudnos, Nathan and Kompanek, Andrew and McIlvenny, Lauren},
title={Lessons Learned in Coordinated Disclosure for Artificial Intelligence and Machine Learning Systems},
month={Aug},
year={2024},
institution={Software Engineering Institute, Carnegie Mellon University},
doi={10.1184/R1/26867038.v1},
url={https://doi.org/10.1184/R1/26867038.v1},
note={Accessed: 2026-Sep-11}
}
Householder, Allen, Vijay Sarvepalli, Jeff Havrilla, Matt Churilla, Lena Pons, Shing-hon Lau, Nathan VanHoudnos, Andrew Kompanek, and Lauren McIlvenny. "Lessons Learned in Coordinated Disclosure for Artificial Intelligence and Machine Learning Systems." Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, August 20, 2024. https://doi.org/10.1184/R1/26867038.v1.
A. Householder, V. Sarvepalli, J. Havrilla, M. Churilla, L. Pons, S. Lau, N. VanHoudnos, A. Kompanek, and L. McIlvenny, "Lessons Learned in Coordinated Disclosure for Artificial Intelligence and Machine Learning Systems," Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, 20-Aug-2024 [Online]. Available: https://doi.org/10.1184/R1/26867038.v1. [Accessed: 11-Sep-2026].
Householder, Allen, Vijay Sarvepalli, Jeff Havrilla, Matt Churilla, Lena Pons, Shing-hon Lau, Nathan VanHoudnos, Andrew Kompanek, and Lauren McIlvenny. "Lessons Learned in Coordinated Disclosure for Artificial Intelligence and Machine Learning Systems." Software Engineering Institute, Carnegie Mellon University, Software Engineering Institute, 20 Aug. 2024. https://doi.org/10.1184/R1/26867038.v1. Accessed 11 Sep. 2026.
Householder, Allen; Sarvepalli, Vijay; Havrilla, Jeff; Churilla, Matt; Pons, Lena; Lau, Shing-hon; VanHoudnos, Nathan; Kompanek, Andrew; & McIlvenny, Lauren. Lessons Learned in Coordinated Disclosure for Artificial Intelligence and Machine Learning Systems. Software Engineering Institute. 2024. DOI: 10.1184/R1/26867038.v1. https://doi.org/10.1184/R1/26867038.v1