Techniqueai-model-accessATLAS

AML.T0040AI Model Inference API Access

What it is

Adversaries may gain access to a model via legitimate access to the inference API. Inference API access can be a source of information to the adversary ([Discover AI Model Ontology](/techniques/AML.T0013), [Discover AI Model Family](/techniques/AML.T0014)), a means of staging the attack ([Verify Attack](/techniques/AML.T0042), [Craft Adversarial Data](/techniques/AML.T0043)), or for introducing data to the target system for Impact ([Evade AI Model](/techniques/AML.T0015), [Erode AI Model Integrity](/techniques/AML.T0031)). Many systems rely on the same models provided via an inference API, which means they share the same vulnerabilities. This is especially true of foundation models which are prohibitively resource intensive to train. Adversaries may use their access to model APIs to identify vulnerabilities such as jailbreaks or hallucinations and then target applications that use the same models.

References

  1. https://atlas.mitre.org/techniques/AML.T0040

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

ATLAS tactic
AI Model Access
ATLAS
Exfiltration via AI Inference API
ATLAS
Full AI Model Access
ATLAS
Search Open AI Vulnerability Analysis
ATLAS
AI Agent Tool Invocation
ATLAS
Discover AI Model Ontology
Sourced from MITRE ATLAS — Adversarial Threat Landscape for AI Systems. Curated by Adam Lundqvist, SQUR.