SECURING GENERATIVE AI PIPELINES IN CRITICAL INFRASTRUCTURE ENVIRONMENTS: A CONCEPTUAL ARCHITECTURE FOR IDENTITY, DATA INTEGRITY, AND ADVERSARIAL RISK
Keywords:
generative AI, large language models, critical infrastructure, identity, data integrity, adversarial machine learning, pipeline security, conceptual frameworkAbstract
The deployment of generative artificial intelligence in critical infrastructure introduces a security and governance challenge that classical machine learning practice does not fully address. Large language models, multi modal foundation models, and retrieval augmented pipelines are being integrated into critical infrastructure operations for tasks ranging from documentation assistance and procedure summarization to operator decision support and incident response. The security properties of these pipelines differ in important ways from those of classical machine learning systems. Inputs can be open ended natural language. Outputs can affect downstream systems through plugins, tools, or human relayed actions. Training and reference data may include sensitive operational information. Adversaries can manipulate models through prompt injection, retrieval poisoning, model extraction, and indirect data flows that bypass traditional perimeter controls. This conceptual paper presents an architecture for securing generative artificial intelligence pipelines in critical infrastructure environments, structured around three concerns. Identity addresses the authentication and authorization of users, agents, models, and data sources, including the auditable identity of each model invocation. Data integrity addresses the provenance, validation, and freshness of training, retrieval, and prompt data. Adversarial risk addresses the threat surface introduced by prompt injection, jailbreaking, output exfiltration, and supply chain attacks against foundation models. The architecture maps controls to the National Institute of Standards and Technology artificial intelligence risk management framework, the National Institute of Standards and Technology Special Publication 800 207 zero trust architecture, the Open Web Application Security Project top ten for large language models, and the European Union artificial intelligence regulation. Three reference scenarios drawn from energy, water, and emergency response illustrate the architecture in practice. The paper closes with a discussion of governance, evaluation, and future research directions.