Cybersecurity Awareness Month: Start something that lasts

Get 15% off

CYBERREADY15

Elevation of Machine Learning Security Game

Regular price £24.00

EU customers: Taxes included. No additional charges (including duties) on delivery.

Description

If you’re looking to understand AI/ML security risks, get the whole team involved and discover threats before they become incidents, Elevation of MLSec gives you a practical, engaging way to do it.

Created by Elias Brattli Sørensen, Elevation of MLSec is a threat modeling card game inspired by Adam Shostack’s Elevation of Privilege game, and based on the risk framework published by the Berryville Institute of Machine Learning (BIML). 

Each card captures a specific AI or machine learning security threat, based on recognised research from BIML and OWASP, and turns it into a practical prompt your team can apply to the system in front of them.

Elevation of MLSec has been carefully designed for security teams, developers, ML engineers, architects, consultants and anyone responsible for building or deploying AI systems securely. No specialist AI security expertise is required. The cards help mixed teams explore threats together, share knowledge and ask better security questions.

Elevation of MLSec is © 2024 Kantega AS

Bulk Pricing

Automatically applied at checkout:

Buy Discount
5 or more decks 5% off
10 or more decks 10% off
20 or more decks 15% off
30 or more decks 20% off

Specifications

  • Suits
    Dataset risks (Raw, Training, Assembly), Model risks (Algorithm, Evaluation, Model), Input risks , Output risks
  • # Cards
    68
  • Created by
    Elias Brattli Sørensen

Try a branded version

If you'd like to encourage the use of this technique within your team or organisation, a branded deck is a great way to demonstrate your support and commitment to the process.

Created from established AI and machine learning security research

The content is based primarily on security research from the Berryville Institute of Machine Learning (BIML), including its BIML-78 Architectural Risk Analysis of Machine Learning Systems and BIML-LLM24 analysis of Large Language Models.

These risks are supplemented with LLM-specific threats from the OWASP Top 10 for Large Language Model Applications.

For Elevation of MLSec, this research has been distilled into four practical areas that are easier to explore during a threat modelling session:

Dataset Risks · Input Risks · Model Risks · Output Risks

Together, these four areas form the DIMO framework, helping teams examine security risks across the key parts of an AI or machine learning system, including the interactions between them.

Rather than asking your team to work through lengthy security frameworks during a workshop, Elevation of MLSec puts individual threats directly into their hands, one card at a time.

How to play?

  • Set up

    Start by creating a visible model of the ML system you’ll be threat modelling, this could be a lifecycle, pipeline, or any system with an ML component.

  • Deal the cards

    Remove the instruction, strategy, and threat summary cards. Just keep the threat cards.

    Shuffle and deal the entire deck to players in small groups (3–6 people per deck).

  • Let the game begin

    The player with the lowest Input Risk card goes first. Others must follow suit (the risk category) if they can.

  • Winning

    Each round, players play one card, matching the suit (risk type) of the first card if possible. The highest card wins, unless a Dataset Risk card is played, as these are always trump.

    Scoring: +1 for a relevant threat, +1 for winning the trick.

  • Additional rules

    Aces let players introduce a new, unlisted threat based on the system, showing insight and creativity.

    When all cards have been played, the player with the most points wins.

Hybrid teams? No problem

Play our threat modeling games remotely
with the power of physical cards!