NSA’s Artificial Intelligence Security Center Releases Joint Guidance on AI Data Security
FORT MEADE, Md. – The National Security Agency’s (NSA) Artificial Intelligence Security Center (AISC) has released a joint Cybersecurity Information Sheet (CSI) titled “AI Data Security: Best Practices for Securing Data Used to Train & Operate AI Systems.” This document provides critical best practices and recommendations for ensuring the data security of AI systems.
The data used throughout the development, testing, and operation of AI systems is a vital component of the AI supply chain. Protecting this data is essential for the successful development and deployment of AI systems. As organizations increasingly rely on AI-driven outcomes, ensuring data security becomes crucial for maintaining accuracy, reliability, and integrity.
The CSI outlines general best practices that organizations can implement to secure and protect AI system data. These include:
- Employing digital signatures to authenticate trusted revisions
- Tracking data provenance
- Leveraging trusted infrastructure
The guidance emphasizes the need for robust data protection strategies throughout the entire AI system lifecycle. It also highlights potential risks to AI data security, including:
- Data supply chain risks
- Maliciously modified data
- Data drift
For each of these risks, the CSI provides detailed information and mitigation strategies. This guidance is particularly relevant for organizations that already use AI systems, especially system owners and administrators within:
- Department of Defense
- National Security Systems
- Defense Industrial Base
These organizations are encouraged to adopt the recommended best practices and mitigation strategies to fortify their AI systems and safeguard sensitive and critical data.
The CSI is being released jointly by multiple cybersecurity authorities, including:
- National Security Agency (NSA)
- Cybersecurity and Infrastructure Agency (CISA)
- Federal Bureau of Investigation (FBI)
- Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)
- New Zealand’s National Cyber Security Centre (NCSC-NZ)
- United Kingdom’s National Cyber Security Centre (NCSC-UK)
For more information, the full report is available [here](link to report).
Additional cybersecurity information and technical guidance can be found in the NSA’s full library.