risk
AI privacy leakage and re-identification
Model inversion and membership-inference attacks reconstruct training data or reveal individuals in the training set; AI inference re-identifies anonymized data and infers sensitive attributes; training on data without consent/legal basis creates regulatory liability.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- ai_governance
- domain
- AI Governance
- Data Protection & Privacy
- taxonomy
- nist-ai-rmf-risk
- nist-privacy-risk
- inherent_rating
- high
Details
- risk_id
- ai-privacy-leakage
- category
- ai_governance
- likelihood
- medium
- impact
- high
- inherent_rating
- high
- treatment
- mitigate
- taxonomies
- nist-ai-rmf-risk
- nist-privacy-risk
Source
No record-specific source URL is provided.
Connections
- UC-AI-09 — Govern AI data quality, provenance, and preparation mitigates AI privacy leakage and re-identification
- strength
- related
- rationale
- Governing lawful data acquisition and provenance addresses training on data without consent or legal basis.
- UC-AI-17 — Define customer data-use and output-rights policies for AI services mitigates AI privacy leakage and re-identification
- strength
- related
- rationale
- Declared training-use and retention limits reduce the volume of customer data an AI system can later leak, but the operative defenses are the output and isolation controls.
- UC-AI-22 — Prevent leakage of credentials and secrets through AI systems mitigates AI privacy leakage and re-identification
- strength
- related
- rationale
- The same redaction pipeline that catches secrets in logs and outputs also reduces exposure of personal data held alongside them.
- UC-AI-18 — Defend AI interfaces against adversarial input, injection, and endpoint abuse mitigates AI privacy leakage and re-identification
- strength
- related
- rationale
- Blocking injected instructions that try to exfiltrate context reduces one avenue for personal-data leakage.
- UC-AI-20 — Prevent harmful, out-of-scope, hallucinated, and over-exposed AI outputs mitigates AI privacy leakage and re-identification
- strength
- related
- rationale
- Withholding internal data and over-exposed content from outputs reduces personal-data leakage at the response boundary.
- UC-DATA-12 — De-identify, mask, or pseudonymize personal data mitigates AI privacy leakage and re-identification
- strength
- related
- rationale
- Robust de-identification reduces AI inference re-identifying anonymized data and inferring sensitive attributes.