Systematizing System-Level Security Risks of Integrating Frontier AI into Critical Infrastructure

A systematization of knowledge study published on arXiv examines the evolving system-level security risks introduced when integrating frontier artificial intelligence into critical infrastructure, such as power grids and telecommunication networks. Rather than simply adding isolated software vulnerabilities, the deployment of autonomous AI agents fundamentally restructures established security boundaries and trust models across entire systems, creating new propagation paths for attacks. Traditional critical infrastructure security heavily relies on static, rule-based defenses and deterministic system behaviors. However, the introduction of autonomous reasoning processes and dynamic feedback loops in AI agents transitions system operations into unpredictable states, rendering conventional defensive assumptions obsolete. The study details how malicious interference with training data or real-time inference can propagate directly to physical-layer disruptions. To address these emerging threats, security teams must transition from component-level protection to dynamic, system-wide risk management. While this paper provides a robust theoretical framework for understanding these shifting security boundaries, implementing concrete mitigations and verifying their efficacy in specific infrastructure environments will require dedicated, case-by-case empirical validation.
Related tools
Recommended tools for this topic
These picks prioritize high-intent tools relevant to this topic. Some links may include partner or affiliate tracking.
A strong security and edge platform match across CDN, Zero Trust, and app protection.
View CloudflareA high-relevance security pick for identity, secret management, and team access control.
View 1PasswordStrong for identity, OIDC, and B2B auth readers evaluating implementation tradeoffs.
View Auth0Comparison
| Aspect | Before / Alternative | After / This |
|---|---|---|
| Defense Paradigm | Static, rule-based perimeter security | Dynamic, adaptive trust models and continuous monitoring |
| System Predictability | Deterministic state changes and predictable operational patterns | Non-deterministic behaviors driven by autonomous AI reasoning |
| Primary Attack Surface | Software vulnerabilities in discrete operational technology components | Data poisoning, adversarial inference, and systemic feedback manipulation |
| Risk Management Focus | Isolating individual failing components and hardware redundancy | System-wide orchestration of interconnected AI-physical dependencies |
Source: arXiv
This page summarizes the original source. Check the source for full details.


