Lessons Learned in Coordinated Disclosure for Artificial Intelligence and Machine Learning Systems

SEI Report
In this paper, the authors describe lessons learned from coordinating AI and ML vulnerabilities at the SEI's CERT/CC.
Publisher

Software Engineering Institute

DOI (Digital Object Identifier)
10.1184/R1/26867038.v1

Abstract

In this paper, SEI researchers incorporate several lessons learned from the coordination of artificial intelligence (AI) and machine learning (ML) vulnerabilities at the SEI’s CERT Coordination Center (CERT/CC). They also include their observations of public discussions of AI vulnerability coordination cases.

Risk management within the context of AI systems is a rapidly evolving and substantial space. Even when restricted to cybersecurity risk management, AI systems require comprehensive security, such as what the National Institute of Standards and Technology (NIST) describes in The NIST Cybersecurity Framework (CSF).

In this paper, the authors focus on one part of cybersecurity risk management for AI systems: the CERT/CC’s lessons learned from applying the Coordinated Vulnerability Disclosure (CVD) process to reported “vulnerabilities” in AI and ML systems.

SHARE

This post has been shared 1 times.

Cite This SEI Report

Householder, A., Sarvepalli, V., Havrilla, J., Churilla, M., Pons, L., Lau, S., VanHoudnos, N., Kompanek, A., & McIlvenny, L. (2024, August 20). Lessons Learned in Coordinated Disclosure for Artificial Intelligence and Machine Learning Systems. Retrieved September 11, 2026, from https://doi.org/10.1184/R1/26867038.v1.

@techreport{householder_2024,
author={Householder, Allen and Sarvepalli, Vijay and Havrilla, Jeff and Churilla, Matt and Pons, Lena and Lau, Shing-hon and VanHoudnos, Nathan and Kompanek, Andrew and McIlvenny, Lauren},
title={Lessons Learned in Coordinated Disclosure for Artificial Intelligence and Machine Learning Systems},
month={Aug},
year={2024},
institution={Software Engineering Institute, Carnegie Mellon University},
doi={10.1184/R1/26867038.v1},
url={https://doi.org/10.1184/R1/26867038.v1},
note={Accessed: 2026-Sep-11}
}

Householder, Allen, Vijay Sarvepalli, Jeff Havrilla, Matt Churilla, Lena Pons, Shing-hon Lau, Nathan VanHoudnos, Andrew Kompanek, and Lauren McIlvenny. "Lessons Learned in Coordinated Disclosure for Artificial Intelligence and Machine Learning Systems." Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, August 20, 2024. https://doi.org/10.1184/R1/26867038.v1.

A. Householder, V. Sarvepalli, J. Havrilla, M. Churilla, L. Pons, S. Lau, N. VanHoudnos, A. Kompanek, and L. McIlvenny, "Lessons Learned in Coordinated Disclosure for Artificial Intelligence and Machine Learning Systems," Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, 20-Aug-2024 [Online]. Available: https://doi.org/10.1184/R1/26867038.v1. [Accessed: 11-Sep-2026].

Householder, Allen, Vijay Sarvepalli, Jeff Havrilla, Matt Churilla, Lena Pons, Shing-hon Lau, Nathan VanHoudnos, Andrew Kompanek, and Lauren McIlvenny. "Lessons Learned in Coordinated Disclosure for Artificial Intelligence and Machine Learning Systems." Software Engineering Institute, Carnegie Mellon University, Software Engineering Institute, 20 Aug. 2024. https://doi.org/10.1184/R1/26867038.v1. Accessed 11 Sep. 2026.

Householder, Allen; Sarvepalli, Vijay; Havrilla, Jeff; Churilla, Matt; Pons, Lena; Lau, Shing-hon; VanHoudnos, Nathan; Kompanek, Andrew; & McIlvenny, Lauren. Lessons Learned in Coordinated Disclosure for Artificial Intelligence and Machine Learning Systems. Software Engineering Institute. 2024. DOI: 10.1184/R1/26867038.v1. https://doi.org/10.1184/R1/26867038.v1