商品描述
Design, Build, and Secure Dependable AI Systems Across the Enterprise Lifecycle
AI is rapidly becoming part of core enterprise systems but most security programs were not designed for systems that are probabilistic, adaptive, and increasingly autonomous. AI Security Engineering provides a foundational, engineering-first playbook for designing, operating, and scaling secure AI systems across the enterprise lifecycle.
Written by Ashish Rajan, a CISO advising Fortune 500 organizations on AI security, this book focuses on security for AI systems not AI used as a security tool. It examines how AI changes traditional security assumptions and how organizations must adapt their architectures, pipelines, governance models, and operating practices to manage AI risk effectively in production environments.
Rather than focusing on tools or point solutions, AI Security Engineering applies security engineering principles to modern AI systems. It covers AI threat models, secure AI pipelines, runtime detection and incident response, governance and compliance at scale, and the emerging challenges of agentic and multi-model systems. Readers are guided through how to evolve existing security programs to support AI-enabled applications without slowing delivery or becoming the "department of no".
This book shows how to:
- Design and operate secure AI systems across their full lifecycle from architecture and delivery to operations and scale
- Defend production AI applications against adversarial, emergent, and agent-driven threats
- Embed governance and risk controls into AI pipelines using engineering-first approaches
- Operate AI security in dynamic environments, including third-party and agentic systems
- Balance regulatory compliance, system performance, and engineering velocity
CISOs seeking strategic clarity for AI security investments, security architects designing resilient systems, and engineers responsible for operating AI in production will find this book a durable reference for building dependable AI systems at enterprise scale.
商品描述(中文翻譯)
**設計、建構並保護企業生命周期中的可靠 AI 系統**
AI 正迅速成為核心企業系統的一部分,但大多數安全計劃並未針對概率性、自適應且日益自主的系統進行設計。《AI 安全工程》提供了一本以工程為先的基礎手冊,用於設計、運營和擴展安全的 AI 系統,涵蓋整個企業生命周期。
本書由 Ashish Rajan 撰寫,他是一位為《財富》500 強企業提供 AI 安全建議的首席資訊安全官(CISO)。本書專注於 AI 系統的安全,而非將 AI 作為安全工具的使用。它探討了 AI 如何改變傳統的安全假設,以及組織必須如何調整其架構、管道、治理模型和運營實踐,以有效管理生產環境中的 AI 風險。
《AI 安全工程》並不專注於工具或特定解決方案,而是將安全工程原則應用於現代 AI 系統。它涵蓋了 AI 威脅模型、安全的 AI 管道、運行時檢測和事件響應、大規模的治理和合規性,以及代理性和多模型系統所帶來的新挑戰。讀者將學習如何演進現有的安全計劃,以支持 AI 驅動的應用程序,而不會減緩交付或成為「拒絕部門」。
本書展示了如何:
- 設計和運營安全的 AI 系統,涵蓋其完整生命周期,從架構和交付到運營和擴展
- 防禦生產 AI 應用程序免受對抗性、新興和代理驅動的威脅
- 使用以工程為先的方法將治理和風險控制嵌入 AI 管道
- 在動態環境中運營 AI 安全,包括第三方和代理系統
- 平衡合規性、系統性能和工程速度
尋求 AI 安全投資戰略清晰度的 CISO、設計韌性系統的安全架構師,以及負責在生產中運營 AI 的工程師,將會發現本書是構建企業級可靠 AI 系統的持久參考。