Appendix A — Implementation and research resources

Tools, case collections, and research groups that support the book’s controls and evidence methods.

A team may need software to test an attack, a policy engine to decide whether an operation is allowed, or a source of documented cases. The resources below serve those different purposes. Inclusion is not an endorsement or evidence that a tool fits a particular deployment. The entries distinguish software, standards, reporting services and research communities.

A.1 Tools and security standards

The testing tools run selected probes. Policy and identity software supports decisions made by the application. The standards describe requirements or record formats rather than running a check. Each needs a defined task, configuration and evaluation before it supports a security claim.

  • Adversarial Robustness Toolbox (ART), started by IBM and hosted by LF AI & Data. Primary docs at https://adversarial-robustness-toolbox.readthedocs.io/en/latest/. Python library that tests and defends models against evasion and poisoning and other attacks.
  • Microsoft PyRIT, built by the Microsoft AI Red Team. Primary docs at https://microsoft.github.io/PyRIT/. Automation for AI red teaming against generative AI endpoints.
  • NVIDIA garak, supported by NVIDIA. Primary docs at https://docs.garak.ai/garak. Scanner that probes large language models with crafted prompts and checks outputs.
  • Giskard, from Giskard. Primary docs at https://docs.giskard.ai/. Red teaming and testing platform for language model agents.
  • Open Policy Agent (OPA), a Cloud Native Computing Foundation project. Primary docs at https://www.openpolicyagent.org/docs. Policy engine that evaluates rules written in Rego, its policy language. It returns decisions, including structured results, for the calling application to enforce.
  • SPIFFE and SPIRE, Cloud Native Computing Foundation projects. Primary docs at https://spiffe.io/docs/latest/. SPIFFE specifies workload identities. SPIRE implements identity issuance and checks about the workloads requesting identities.
  • Sigstore, backed by Open Source Security Foundation and developed and maintained by its community. Primary docs at https://docs.sigstore.dev/. Signing and transparency log service for software artifacts.
  • SLSA, an Open Source Security Foundation project. Primary docs at https://slsa.dev/. Framework that defines build integrity levels for supply chains.
  • C2PA, maintained by Coalition for Content Provenance and Authenticity. Primary docs at https://c2pa.org/. Standard that binds statements about source and edits to digital content.

A.2 Cases and vulnerability reporting

ATLAS organizes techniques and cases, the incident database collects reports of harm, and CERT/CC offers a vulnerability-reporting route. A report may describe a controlled demonstration or a reported incident. Its evidence determines which conclusions are justified. These resources do not detect or prevent incidents by themselves.

  • MITRE ATLAS, maintained by MITRE. Primary docs at https://atlas.mitre.org/. Knowledge base of tactics and techniques that target AI systems mapped to ATT&CK.
  • AI Incident Database, maintained by Responsible AI Collaborative. Primary docs at https://incidentdatabase.ai/. Public index of reported AI harms and near harms.
  • CERT Coordination Center reporting, maintained by Carnegie Mellon University Software Engineering Institute. Primary docs at https://www.kb.cert.org/vuls/report/. Public route for reporting software vulnerabilities for coordination.

A.3 Research groups and communities

These groups publish research, guidance or evaluations, or coordinate responses to reported vulnerabilities. Their home pages help locate current work. A group’s research focus does not by itself establish the effectiveness of a particular method.

  • ETH Zurich SRI Lab, based at ETH Zurich Department of Computer Science. Home page at https://www.sri.inf.ethz.ch/. Reliable and secure machine learning with focus on large language models and robustness.
  • CMU SEI AISIRT, based at Carnegie Mellon University Software Engineering Institute. Home page at https://www.sei.cmu.edu/history-of-innovation/aisirt/. Operational team that responds to AI vulnerabilities and coordinates disclosure.
  • Berkeley CLTC AI Security Initiative, based at University of California Berkeley Center for Long-Term Cybersecurity. Home page at https://cltc.berkeley.edu/program/ai-security-initiative/. Risk management profiles and standards for general-purpose and agent AI.
  • Georgetown CSET, based at Georgetown University. Home page at https://cset.georgetown.edu/. Analysis of security implications of emerging technologies including AI and cybersecurity.
  • RAND CAST, based at RAND Corporation. Home page at https://www.rand.org/global-and-emerging-risks/centers/ai-security-and-technology.html. Center for AI security and technology, including security of advanced AI systems and assessments of AI capabilities.
  • Alan Turing CETaS, based at Alan Turing Institute. Home page at https://cetas.turing.ac.uk/. Study of generative AI risks and evaluation including disinformation and safety assessment.