Project Prototype: Next-Gen Autonomous AI Threat Mitigation Dashboard
Lead Researcher: Audrey Rah | ECE, University of Houston
Organization Profile Not Saved
Short setup reminder: save your organization profile, AI inventory, and current security controls before refreshing intelligence.
Assessment Snapshot
High-level status for the current organization profile and latest refresh. Detailed findings, validation, and reports stay in their dedicated workspaces.
Organization Profile Setup
Save the organization name, manager name, AI technologies, and current security controls once. The dashboard will remember these selections in this browser and use them for refreshes, reports, threat filtering, governance risk context, compliance impacts, and security advisories.
Select the AI Technologies Used in Your Organization
To improve accuracy and reduce information overload, this dashboard only displays threats, vulnerabilities, governance risks, compliance impacts, and security advisories that are relevant to the AI technologies currently used in your organization.
Select Current Security Controls
Select the AI-specific and enterprise security controls currently used in the organization.
AI Security Controls
Controls specifically designed to secure AI systems, LLMs, Agents, RAG platforms, model interactions, prompt security, AI governance, and AI supply chains.
Enterprise Security Controls
Traditional cybersecurity controls protecting networks, endpoints, cloud, identity, infrastructure, and enterprise systems.
Identity & Access Management
Endpoint Protection / EDR / XDR
SIEM & Security Monitoring
Firewall & Network Security
Network Infrastructure
Email Security
Vulnerability Management
Cloud Security
Data Protection & DLP
Backup & Recovery
Zero Trust & Secure Access
CASB
Web Security
Security Awareness & Phishing Protection
Mobile Security
OT / ICS Security
Generate Executive Risk Report
Selected-Inventory Intelligence Sources
Source types that cannot be retrieved or verified in this standalone file remain Data Unavailable.
Selected AI Footprint Intelligence Status
Every selected technology remains visible after refresh. Verified records are linked to NVD/NIST; unavailable source findings are not replaced with generic AI threats.
What Should We Do Next?
Simple actions based on the evidence shown above.
Risk Signal Summary
These numbers are calculated only from the current live security database response. Missing values are not replaced.
Start Here: Which Known Security Issue Needs Review?
This section uses only live security evidence for the selected AI technologies and highlights items that may need review first.
Critical Security Problems Reported
Source: NVD severity score. Critical means the highest reported risk level.
Highest Risk Level Found
Source: NVD severity score.
Latest modified date
Source: NVD cve.lastModified.
Known Security Issue -> Affected Evidence -> Risk Level -> What To Do
The pathway follows only live database fields or shows Data Unavailable.
Known Security Issue
Issue ID, description, published date, and modified date.
Affected Evidence
Affected product or setup evidence when available.
Risk Level
Reported seriousness score and level when available.
What To Do
Review the item, check whether it affects your company, and apply vendor fixes when available.
Known Security Issues Mapped to Executive Decisions
Filter by risk level. Table records appear only when returned by the live security database.
CVE Validation / Human Review
Optional human review for each CVE-to-technology match. System classification is generated automatically from NVD evidence. Human validation is stored separately and does not replace the system classification.
Assessment Performance & Validation
Automatic evaluation metrics for each completed intelligence refresh. Evidence Coverage and retrieval counts are measured directly from NVD results. Validated Precision requires human review. Recall and F1 require an independent ground-truth dataset. These metrics are not interchangeable and retrieval success is never reported as accuracy.
Controlled Assessment Instrumentation
Benchmark mode is active via ?benchmark=1. Timing and export data are recorded locally for reproducible evaluation. Validated Precision uses human review labels; Recall/F1 require an imported ground-truth dataset.
Benchmark Evaluation Metrics
Validated Precision and evaluation metrics for the active benchmark run. Human validation labels are saved in CVE Validation / Human Review above. Recall and F1 appear only when a complete independent ground-truth dataset is available.
NIST AI RMF Practice Assessment
Organizational AI governance practices against NIST AI RMF 1.0 functions GOVERN, MAP, MEASURE, and MANAGE. This is not live NVD cybersecurity intelligence.
Security Intelligence = live NVD vulnerability evidence. AI Governance Assessment = organizational governance practices evaluated against NIST AI RMF. Governance gaps are not CVEs and are not vulnerabilities.
- Implemented — This practice is established and currently used.
- Partially Implemented — Some parts exist, but the practice is incomplete.
- Not Implemented — This practice is not currently in place.
- Not Applicable — This practice does not apply to this organization's AI environment.