[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-116876-en":3,"doc-seo-116876-105":30,"detail-sidebar-cat-0-en-105":90},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},116876,687207017582,"Himbo","https://ap-avatar.wpscdn.com/davatar_994ba38a5ba835b3df7d355c54d3ed8d",6,"Technology","MLSMM - Machine Learning Security Maturity Model","Assessing the maturity of security practices for Machine Learning (ML) development has received less attention than traditional software security. This Blue Sky paper introduces an initial Machine Learning Security Maturity Model (MLSMM) that structures security practices across the ML-development lifecycle and defines three maturity levels for each stage. MLSMM aims to support organizations in evaluating current practices, building targeted roadmaps, improving prioritization, and increasing security awareness across teams.","arXiv :2306 . 16127v1 [ cs . SE] 28 Jun 2023  \nMLSMM: Machine Learning Security Maturity Model  \nFelix Viktor Jedrzejewski 1 Davide Fucci 1 Oleksandr Adamov 1  \nAbstract  \nAssessing the maturity of security practices during the development of Machine Learning (ML) based software components has not gotten as much attention as traditional software development. In this Blue Sky idea paper, we propose an initial Machine Learning Security Maturity Model (MLSMM ) which organizes security practices along the ML-development lifecycle and, for each, establishes three levels of maturity. We envision MLSMM as a step towards closer collaboration between industry and academia.  \n1. Introduction  \nThe release of ChatGPT and its fast popularity greatly contribute to the discussion about the role of AI in our society. For example, several studies conducted on behalf of the German Federal Of􀀂ce for Information Security 1 discuss the importance of regulations requiring industry to demonstrate their effort in addressing Machine Learning (ML) Security in their development practices. The last decade of Adversarial Machine Learning (AML) research (Biggio & Roli, 2018; Cin􀀞a et al., 2022) introduced multiple attacks and defense strategies. While attackers seem to use publicly-available resources (Tidjon & Khomh, 2022), multiple interviews with ML practitioners show that the industry is ill-prepared to handle potential attacks to its ML-based systems (Kumar et al., 2020) and reluctant to introduce security measures. In a few instances, AML researchers have directly approached industry practitiones (Boenisch et al., 2021; Mink et al., 2023; Grosse et al., 2023), conducted more realistic (e.g., in vivo) studies (Apruzzese et al., 2022), and proposed actionable ML development models incorporating security measures (Zhang & Jaskolka, 2022) . In the traditional  \n1Department of Software Engineering, Blekinge Institute of Technology, Karlskrona, Sweden. Correspondence to: Felix Jedrzejewski \u003C[felix.jedrzejewski@bth.se](felix.jedrzejewski@bth.se)>.  \n2 nd AdvML Frontiers workshop at 40th International Conference  \nsoftware development community, the need for companies evaluating and incorporating security in their lifecycle has been addressed by several security maturity models (Teodoro & Serrao, 2011; Lipner, 2004; Weir et al., 2021) . Nevertheless, besides the heavyweight ISO21827, there is a lack of ML security maturity models studied in academia and adopted in the industry. Based on the perspective regulations, attackers using AML, and the current low awareness about it in the industry based on empirical evaluations, we propose a lightweight domain-agnostic Machine Learning Security Maturity Model (MLSMM ) . The goals of the model are to i) evaluate the state-of-practice concerning the security of ML-development process within an organization, ii) support the organization in creating aroadmap to improve and prioritize their ML security stance in speci􀀂c areas, and iii) increase ML security awareness across different teams (e.g., developers, architects, quality assurance) . MLSMM is based on the established Security Assurance Maturity Model (SAMM2 ) proposed by the Open Worldwide Application Security Project (OWASP) and the Adversarial Threat Landscape for Arti􀀂cial Intelligence Systems (ATLAS) taxonomy3 by MITRE. We foresee that MLSMM will reduce the gaps between academia and industry fostering closer collaboration in which the 􀀂rst develops supportive tools and the latter provides real case scenarios, data, and study validation opportunities. Additionally, the roadmap MLSMM can represent a starting point for compliance and certi􀀂cation procedures in the future.  \nOWASP SAMM is a state-of-practice maturity model facilitating the measurement, analysis, and improvement of software products’ security and addressing essential stages in the software development process. Its content is based on the experience and domain knowledge of industry security experts ","cbCaigu4NsG5Da3m","https://ap.wps.com/l/cbCaigu4NsG5Da3m","pdf",74495,1,3,"English","en",105,"# Introduction\n# MLSMM Prototype\n## Table 1 Excerpt of the Proposed Machine-Learning Security Maturity Model","[{\"question\":\"What problem does MLSMM address?\",\"answer\":\"MLSMM addresses the limited attention given to assessing how mature security practices are during the development of ML-based software components.\"},{\"question\":\"How does MLSMM organize security practices?\",\"answer\":\"MLSMM organizes security practices along the ML-development lifecycle and assigns three maturity levels to each phase.\"},{\"question\":\"What is the purpose of the MLSMM roadmap?\",\"answer\":\"The roadmap helps an organization evaluate its current ML security state-of-practice and create a prioritized plan to improve specific security areas.\"}]","MLSMM - Machine Learning Security Maturity Model | PDF",1785672183,8,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":85,"head_meta":87,"extra_data":89,"updated_unix":28},"mlsmm-machine-learning-security-maturity-model","",{"@graph":36,"@context":84},[37,53,67],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,50],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":21},"https://docshare.wps.com/document/technology/",{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/mlsmm-machine-learning-security-maturity-model/116876/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":23,"description":14,"dateModified":61,"datePublished":61,"encodingFormat":60,"isAccessibleForFree":62,"interactionStatistic":63},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-08-02",true,{"@type":64,"interactionType":65,"userInteractionCount":4},"InteractionCounter",{"@type":66},"ViewAction",{"@type":68,"mainEntity":69},"FAQPage",[70,76,80],{"name":71,"@type":72,"acceptedAnswer":73},"What problem does MLSMM address?","Question",{"text":74,"@type":75},"MLSMM addresses the limited attention given to assessing how mature security practices are during the development of ML-based software components.","Answer",{"name":77,"@type":72,"acceptedAnswer":78},"How does MLSMM organize security practices?",{"text":79,"@type":75},"MLSMM organizes security practices along the ML-development lifecycle and assigns three maturity levels to each phase.",{"name":81,"@type":72,"acceptedAnswer":82},"What is the purpose of the MLSMM roadmap?",{"text":83,"@type":75},"The roadmap helps an organization evaluate its current ML security state-of-practice and create a prioritized plan to improve specific security areas.","https://schema.org",{"og:url":51,"og:type":86,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":88,"canonical":51},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":91},[92,96,100,104,109,112,117,121,126,129,133],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":93,"show_sort_weight":94,"slug":95},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":97,"show_sort_weight":98,"slug":99},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":101,"show_sort_weight":102,"slug":103},"Exam",70,"exam",{"id":105,"doc_module":4,"doc_module_name":46,"category_name":106,"show_sort_weight":107,"slug":108},5,"Comic",60,"comic",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":110,"slug":111},50,"technology",{"id":113,"doc_module":4,"doc_module_name":46,"category_name":114,"show_sort_weight":115,"slug":116},7,"Healthcare",40,"healthcare",{"id":29,"doc_module":4,"doc_module_name":46,"category_name":118,"show_sort_weight":119,"slug":120},"Research & Report",30,"research-report",{"id":122,"doc_module":4,"doc_module_name":46,"category_name":123,"show_sort_weight":124,"slug":125},9,"Religion & Spirituality",20,"religion-spirituality",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":127,"show_sort_weight":124,"slug":128},"World Cup","world-cup",{"id":130,"doc_module":4,"doc_module_name":46,"category_name":131,"show_sort_weight":130,"slug":132},10,"Lifestyle","lifestyle",{"id":134,"doc_module":4,"doc_module_name":46,"category_name":135,"show_sort_weight":105,"slug":136},19,"General","general"]