101 indexed

ATLASATLAS adversarial ML techniques

101 MITRE ATLAS top-level techniques covering the adversarial-ML attack surface, grouped by tactic. Authored by Adam Lundqvist.

13 in Resource Development · 101 total

IDTitleSummary
AML.T0002Acquire Public AI ArtifactsAdversaries may search public sources, including cloud storage, public-facing services, and software or data repositories, to identify AI artifacts. These AI a…
AML.T0008Acquire InfrastructureAdversaries may buy, lease, or rent infrastructure for use throughout their operation. A wide variety of infrastructure exists for hosting and orchestrating ad…
AML.T0016Obtain CapabilitiesAdversaries may search for and obtain software capabilities for use in their operations. Capabilities may be specific to AI-based attacks [Adversarial AI Attac…
AML.T0017Develop CapabilitiesAdversaries may develop their own capabilities to support operations. This process encompasses identifying requirements, building solutions, and deploying capa…
AML.T0019Publish Poisoned DatasetsAdversaries may [Poison Training Data](/techniques/AML.T0020) and publish it to a public location. The poisoned dataset may be a novel dataset or a poisoned va…
AML.T0020Poison Training DataAdversaries may attempt to poison datasets used by an AI model by modifying the underlying data or its labels. This allows the adversary to embed vulnerabiliti…
AML.T0021Establish AccountsAdversaries may create accounts with various services for use in targeting, to gain access to resources needed in [AI Attack Staging](/tactics/AML.TA0001), or …
AML.T0058Publish Poisoned ModelsAdversaries may publish a poisoned model to a public location such as a model registry or code repository. The poisoned model may be a novel model or a poisone…
AML.T0060Publish Hallucinated EntitiesAdversaries may create an entity they control, such as a software package, website, or email address to a source hallucinated by an LLM. The hallucinations may…
AML.T0065LLM Prompt CraftingAdversaries may use their acquired knowledge of the target generative AI system to craft prompts that bypass its defenses and allow malicious instructions to b…
AML.T0066Retrieval Content CraftingAdversaries may write content designed to be retrieved by user queries and influence a user of the system in some way. This abuses the trust the user has in th…
AML.T0079Stage CapabilitiesAdversaries may upload, install, or otherwise set up capabilities that can be used during targeting. To support their operations, an adversary may need to take…
AML.T0104Publish Poisoned AI Agent ToolAdversaries may create and publish poisoned AI agent tools. Poisoned tools may contain an [LLM Prompt Injection](/techniques/AML.T0051), which can lead to a va…
Sourced from MITRE ATLAS. Curated by Adam Lundqvist, Founder at SQUR.