SearcharxivSearch

arXiv subjects

Tooba Aamir

Publications and source records attributed to Tooba Aamir.

5 recordsLinked to original sources

SoK: How Frontier AI Reshapes System-Level Security Risk Dynamics in Critical Infrastructure

Frontier artificial intelligence (FAI), encompassing large-scale, general-purpose AI systems, including large language models, multimodal foundation models, and agentic systems, is increasingly integrated into critical infrastructure (CI). This challenges long-standing security assumptions of bounded behavior, segmented networks, component transparency, and human-paced decision-making. Existing AI-security literature typically organizes risks by attack type, lifecycle stage, or asset class, but fails to capture the system-level dynamics, such as how risk emerges, spreads, and is controlled, through which FAI reshapes CI security outcomes. This Systematization of Knowledge (SoK) introduces a five-dimensional risk-dynamics framework that characterizes how FAI reconfigures CI security across the lifecycle: (i) Capability Emergence through new FAI-enabled attack and defense capabilities, (ii) Infiltration Pathways through data, models and AI supply chains, (iii) Cross-System Propagation across interconnected infrastructures and dependencies, (iv) degradation of effective technical and human Control Authority, and (v) strain on institutional Response Capacity under operational pressure. Rather than enumerating threats, the framework identifies recurring mechanisms that jointly determine system-level risk. We further identify a structural mismatch between academic AI-security research and CI operational constraints, and derive a deployment-oriented research agenda grounded in system-level assurance criteria. Collectively, this work shifts attention from model-centric robustness to lifecycle-structured, system-level assurance in interconnected CI environments.

cs.CR

From Frontier to Shadow AI: A Simmering Threat to Assurance and Security in Critical Infrastructure

Frontier AI systems, including large language models and emerging agentic AI tools, offer significant operational benefits but present unique challenges to critical infrastructure (CI) environments due to their non-deterministic and emergent properties. While formal adoption is inherently cautious and tightly controlled due to strict regulatory oversight, widespread accessibility has catalysed shadow AI: the unsanctioned use of frontier AI outside established organisational controls. In CI settings, shadow AI bypasses established assurance and oversight mechanisms, amplifying risks to data protection, decision reliability, and regulatory compliance, with potential consequences for essential service delivery. We present the first empirical study of shadow AI in CI environments, characterising it as a systemic socio-technical condition of assurance erosion. Drawing on semi-structured interviews with senior executives and functional leaders across 27 Australian CI organisations (Communications, Energy, and Water and Sewerage sectors), we analyse how shadow AI manifests in practice, how it interacts with existing technical and governance controls, and the resulting security, assurance, and compliance risks. We develop an empirically derived threat model identifying three primary mechanisms of security degradation: (i) boundary bypass, where data flows circumvent established perimeters; (ii) unassessed capability expansion, where embedded AI features introduce latent risks; and (iii) loss of observability via governance circumvention, undermining forensic auditability and least-privilege enforcement. Our findings demonstrate that shadow AI introduces unmanaged risks that fundamentally challenge existing security and compliance frameworks, necessitating tailored, pathway-aligned governance and control strategies.

cs.CR

From misinformation to climate crisis: Navigating vulnerabilities in the cyber-physical-social systems

Within the cyber-physical-social-climate nexus, all systems are deeply interdependent: cyber infrastructure facilitates communication, data processing, and automation across physical systems (such as power grids and networks), while social infrastructure provides the human capital and societal norms necessary for the system's functionality. Any disruption within any of these components, whether due to human error or system mismanagement, can propagate throughout the network, amplifying vulnerabilities and creating a significantly scaled impact. This chapter explores the critical role of human vulnerabilities within the cyber-physical-social-climate nexus, focusing on the interdependencies across cyber, physical, and social systems and how these interdependencies can scale in a climate context. While cyber and physical vulnerabilities are readily apparent, social vulnerabilities (such as misinformation, resistance to policy change, and lack of public awareness) often go unaddressed despite their profound impact on resilience and climate adaptation. Social infrastructure, including human capital, societal norms, and policy frameworks, shapes community responses and underpins adaptive capacity, yet it is also a significant point of failure when overlooked. This chapter examines how human cognitive biases, risk misperception, and decision-making silos within interconnected systems can lead to resource misallocation and weakened policy effectiveness. These factors are analyzed to demonstrate how inadequate responses across cyber-physical-social layers can cascade, amplifying climate-related risks. By addressing these human factors and aligning decision-making frameworks, we aim to strengthen resilience and foster cohesive adaptation strategies that account for the intricate interrelations of cyber-physical-social-climate systems.

cs.CR

Heuristics based Mosaic of Social-Sensor Services for Scene Reconstruction

We propose a heuristics-based social-sensor cloud service selection and composition model to reconstruct mosaic scenes. The proposed approach leverages crowdsourced social media images to create an image mosaic to reconstruct a scene at a designated location and an interval of time. The novel approach relies on the set of features defined on the bases of the image metadata to determine the relevance and composability of services. Novel heuristics are developed to filter out non-relevant services. Multiple machine learning strategies are employed to produce smooth service composition resulting in a mosaic of relevant images indexed by geolocation and time. The preliminary analytical results prove the feasibility of the proposed composition model.

cs.CV

Social-Sensor Composition for Tapestry Scenes

The extensive use of social media platforms and overwhelming amounts of imagery data creates unique opportunities for sensing, gathering and sharing information about events. One of its potential applications is to leverage crowdsourced social media images to create a tapestry scene for scene analysis of designated locations and time intervals. The existing attempts however ignore the temporal-semantic relevance and spatio-temporal evolution of the images and direction-oriented scene reconstruction. We propose a novel social-sensor cloud (SocSen) service composition approach to form tapestry scenes for scene analysis. The novelty lies in utilising images and image meta-information to bypass expensive traditional image processing techniques to reconstruct scenes. Metadata, such as geolocation, time and angle of view of an image are modelled as non-functional attributes of a SocSen service. Our major contribution lies on proposing a context and direction-aware spatio-temporal clustering and recommendation approach for selecting a set of temporally and semantically similar services to compose the best available SocSen services. Analytical results based on real datasets are presented to demonstrate the performance of the proposed approach.

cs.MM