AI Risk Scoring Using Attack Trees and Specification Elements

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing AI systems face challenges in enhancing security against various attacks, particularly those that are new or indistinguishable from normal operations, as existing security analysis methods struggle to effectively evaluate and counter potential threats.

Innovation Solution

A risk calculation program and method that calculates a risk score for AI systems by storing weights for attack conditions and presence rates of specification elements, allowing for the identification and quantification of potential threats based on the AI system's specifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If attack tree analysis is performed with predefined nodes and branches, then security analysis efficiency is improved, but the ability to detect new or unknown attacks deteriorates

Engineering Contradiction:
Improvesecurity analysis efficiencyVSAvoiddetection capability for new attacks
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent pre-calculates and stores attack condition information, usage rates, and risk scores for various attack scenarios before actual security assessment. This preliminary preparation enables rapid analysis during runtime while maintaining the ability to evaluate both known and potential new attacks by comparing against the pre-established attack tree structure

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system collects actual attack data and usage rates from multiple AI systems, feeds this information back into the attack tree structure, and updates the risk scores accordingly. This feedback mechanism allows the system to adapt to new attack patterns while maintaining the structured analysis framework

Inventive Principle:
Principle #23Feedback

2Reliability

If specification modification is used as a security measure, then resistance to known attacks is improved, but adaptability to new attack types deteriorates

Engineering Contradiction:
Improveresistance to known attacksVSAvoidadaptability to new attack types
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent calculates risk scores based on multiple parameters including attack condition usage rates, specification element presence rates, and attack tree structure. By dynamically adjusting these parameters based on collected data, the system maintains resistance to known attacks while adapting to new attack types without requiring specification modifications

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If comprehensive vulnerability information is collected from multiple sources, then detection accuracy is improved, but information processing complexity deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoidinformation processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts only the essential and relevant vulnerability information from multiple sources that directly relate to the pre-defined attack tree structure. By filtering and extracting only the necessary data elements, the system maintains high detection accuracy while avoiding the complexity of processing all available information

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20260111550A1Computer-readable recording medium, risk calculation method, and risk calculator
Publication Date: 2026.04.23 FUJITSU LTD
  • US20260111550A1 patent drawing
  • US20260111550A1 patent drawing
  • US20260111550A1 patent drawing

AI summary

A non-transitory computer-readable recording medium stores therein a risk calculation program that causes a computer to execute a process including, storing a weight for every attack condition, calculated with reference to a usage rate of each of the attack conditions, and a presence rate of each of a plurality of specification elements contained in a specification of the AI system, regarding the conditions for establishing the attack, the presence rate being defined in specifications of a plurality of existing AI systems, identifying an establishment status of the attack condition, with reference to information regarding the specification element extracted from information regarding the specification of an AI system subject to the risk determination, and calculating a risk score for every attack tree of the AI system subject to the risk determination, with reference to the weight for every attack condition, and the identified establishment status of the attack condition.