S0110RS3-T06-S0110-Z · Full risk code

Reconstruction Risk from Vector Representations

向量表示的逆推風險

Design & Development
Risk Description

When an organization converts internal documents to vectors and stores them in a less protected environment, assuming vectors are not themselves sensitive; due to unmitigated control gaps, an attacker obtains the vector data and successfully reconstructs portions of the original content, prompting the organization to recognize that vector storage requires protection equivalent to the source documents, triggering compliance exposure and operational reputational costs.

Framework Mappings

OWASP Top 10 for LLMLLM08
NIST AI 600-1Information Security
MITRE ATLASAML.T0024
ISO/IEC 5338運作與監控
MIT AI Risk RepositoryDomain 2

Risk Treatment & Implementation Guidance

Protect vector data with access control and encryption at the classification level of the source documents; Assess embedding-inversion risk, applying perturbation or dimensionality-reduction defenses where needed; Establish in classification policy that derived representations inherit the source's sensitivity level