>

Cybersecurity Assessment of AI Solutions

Find out whether your AI system can be manipulated, tampered with or compromised before attackers do.

What it is and why it matters

Cybersecurity is one of the key dimensions of trustworthy AI and a requirement for high-risk AI systems under Article 15 of the EU AI Act. AI systems are exposed to threats that traditional security testing doesn't cover. Their safeguards can be bypassed with carefully crafted prompts, and any stage of the model pipeline can be compromised: training data can be poisoned to create hidden backdoors, model files can be altered, and third-party components can introduce vulnerabilities. Testing for these risks gives you evidence that your system is secure. It also helps you demonstrate compliance and build trust with users, customers and regulators.

This service is delivered by the Luxembourg Institute of Science and Technology (LIST).

How can Luxembourg AI Factory help 

1. Security testing of the entire AI model pipeline
This service tests every stage of the AI model pipeline, from training data sources through model weights and dependencies to deployment. The goal is to detect tampering, poisoning or malicious modifications. It covers:

  • Training data poisoning detection: checks whether the model has been exposed to poisoned training data that creates backdoors.
  • Model weight tampering detection: verifies the cryptographic signatures and checksums of model files.
  • Dependency vulnerability scanning: tests all AI framework libraries, pre-trained models and third-party components for known vulnerabilities.
  • Reproducibility and provenance auditing: verifies that deployed models match their claimed training procedure.

2. Cybersecurity testing with the AI Assessment Sandbox Configurator
Cybersecurity tests are included in the Sandbox Configurator's catalogue, so you can run them alongside your other trustworthiness and compliance tests.

What you can expect 

  1. Integrated results
    Sandbox cybersecurity test results are stored in the same database, dashboards and reports as all your other trustworthiness and compliance tests, such as accuracy, robustness, bias, explainability and human oversight.
  2. Independent, rigorous evaluation 
    You get a thorough technical assessment supported by independent experts from Luxembourg's largest public research institute.
  3. Expert-led pipeline assessment
    The pipeline security project is led by LIST's research team on AI cybersecurity.

Who it is for

This service is intended for startups, SMEs, large companies and public administrations that are developing or deploying AI systems and want to assess and strengthen their security.