SoK: How Frontier AI Reshapes System-Level Security Risk Dynamics in Critical Infrastructure
2026/08/03 by Chandra Thapa, Mohan Baruwal Chhetri, Marthie Grobler +2
Computer Science · #cs.CR
paper · pdf
19 pages
arxiv created 2026/08/03 · arxiv updated 2026/08/06
Abstract
Frontier artificial intelligence (FAI), encompassing large-scale, general-purpose AI systems, including large language models, multimodal foundation models, and agentic systems, is increasingly integrated into critical infrastructure (CI). This challenges long-standing security assumptions of bounded behavior, segmented networks, component transparency, and human-paced decision-making. Existing AI-security literature typically organizes risks by attack type, lifecycle stage, or asset class, but fails to capture the system-level dynamics, such as how risk emerges, spreads, and is controlled, through which FAI reshapes CI security outcomes. This Systematization of Knowledge (SoK) introduces a five-dimensional risk-dynamics framework that characterizes how FAI reconfigures CI security across the lifecycle: (i) Capability Emergence through new FAI-enabled attack and defense capabilities, (ii) Infiltration Pathways through data, models and AI supply chains, (iii) Cross-System Propagation across interconnected infrastructures and dependencies, (iv) degradation of effective technical and human Control Authority, and (v) strain on institutional Response Capacity under operational pressure. Rather than enumerating threats, the framework identifies recurring mechanisms that jointly determine system-level risk. We further identify a structural mismatch between academic AI-security research and CI operational constraints, and derive a deployment-oriented research agenda grounded in system-level assurance criteria. Collectively, this work shifts attention from model-centric robustness to lifecycle-structured, system-level assurance in interconnected CI environments.
Citations
- Standardized Threat Taxonomy for AI Security, Governance, and Regulatory Compliance
- Watchdogs and Oracles: Runtime Verification Meets Large Language Models for Autonomous Systems
- Data Poisoning Vulnerabilities Across Healthcare AI Architectures: A Security Threat Analysis
- Agentic AI Frameworks: Architectures, Protocols, and Design Challenges
- Agentic AI for autonomous anomaly management in complex systems
- Autonomous AI-based Cybersecurity Framework for Critical Infrastructure: Real-Time Threat Mitigation
- Military AI Cyber Agents (MAICAs) Constitute a Global Threat to Critical Infrastructure
- TRiSM for Agentic AI: A Review of Trust, Risk, and Security Management in LLM-based Agentic Multi-Agent Systems
- From Transformers to Large Language Models: A systematic review of AI applications in the energy sector towards Agentic Digital Twins
- Large Language Models and Their Applications in Roadway Safety and Mobility Enhancement: A Comprehensive Review
- AI Agents vs. Agentic AI: A Conceptual Taxonomy, Applications and Challenges
- Securing Agentic AI: A Comprehensive Threat Model and Mitigation Framework for Generative AI Agents
- Large Language Models integration in Smart Grids
- Frontier AI's Impact on the Cybersecurity Landscape
- Agentic Large Language Models, a survey
- A Framework for Evaluating Emerging Cyberattack Capabilities of AI
- Alignment, Agency and Autonomy in Frontier AI: A Systems Engineering Perspective
- Agentic AI and the Cyber Arms Race
- On Large Language Models in Mission-Critical IT Governance: Are We Ready Yet?
- Risk thresholds for frontier AI
- Generative AI in Cybersecurity: A Comprehensive Review of LLM Applications and Vulnerabilities
- A Survey on the Applications of Frontier AI, Foundation Models, and Large Language Models to Intelligent Transportation Systems
- ChatGPT and Other Large Language Models for Cybersecurity of Smart Grid Applications
- Managing extreme AI risks amid rapid progress
- Poisoning and Backdooring Contrastive Learning
- Extracting Training Data from Large Language Models
- Explainable Artificial Intelligence (XAI): Concepts, Taxonomies, Opportunities and Challenges toward Responsible AI