Skip to main content
Guidance

Machine learning principles

These principles help developers, engineers, decision makers and risk owners make informed decisions about the design, development, deployment and operation of their machine learning (ML) systems.

Page 3 of 22

1.1 Raise awareness of ML threats and risks




Technical team members working on model development should be familiar with a range of attacks on ML systems. Some of these attacks are highlighted in:

Enable and encourage a security-centred culture

Developers aren't necessarily security or usability experts, but understanding where decisions affect security, and how to design and implement a solution that works for its intended users, are crucial parts of ensuring that security works in practice. It's therefore important to establish a positive security culture, supported by leaders, providing sufficient credibility so that security is considered right from the start of a project. 

In addition, security is not always part of formal data science or ML course curricula, and expertise in these areas may not translate to knowledge of system security. Encourage a cross-discipline culture that recognises the need to work collaboratively with security specialists and subject matter experts, and put in place processes and procedures to share knowledge and experience where disciplines meet and overlap. 

A security-centric culture recognises the importance of training and requires all stakeholders involved in the ML life cycle, from requirements to operational use, to understand the threats to a system, including ones unique and inherent to ML. You should therefore be prepared to invest time and resources to promote this. The NCSC has guidance on growing a positive security culture and secure development and deployment. In addition, the European Union Agency for Cybersecurity (ENISA) has published a framework for good cybersecurity practices for AI.

Encourage best security practices by making sure security reviews are integrated into your system life cycle processes. Each application's development life cycle will be different and it's important to integrate security reviews appropriately.

For example:

  • if you take an agile approach to development, consider integrating security reviews into each sprint 

  • if you use a machine learning operations (MLOps) approach to automate workflows, ensure that this includes the security of the products you are developing

If teams are aware of and accountable for security-related responsibilities through the life cycle, it encourages a positive security culture. Depending on your specific development process, automated security testing may be an option, although it's still important to have a security-centred culture.

Published

Reviewed

Version

2.0