MITRE ATLAS v5.5.0
Adversarial Threat Landscape for AI Systems
AML.TA0002 Reconnaissance 8
ATT&CK TA0043The adversary is trying to gather information about the AI system they can use to plan future operations.
AML.TA0003 Resource Development 13
ATT&CK TA0042The adversary is trying to establish resources they can use to support operations.
AML.TA0004 Initial Access 7
ATT&CK TA0001The adversary is trying to gain access to the AI system.
AML.TA0000 AI Model Access 4
The adversary is attempting to gain some level of access to an AI model.
AML.TA0005 Execution 6
ATT&CK TA0002The adversary is trying to run malicious code embedded in AI artifacts or software.
AML.TA0006 Persistence 9
ATT&CK TA0003The adversary is trying to maintain their foothold via AI artifacts or software.
AML.TA0012 Privilege Escalation 4
ATT&CK TA0004The adversary is trying to gain higher-level permissions.
AML.TA0007 Defense Evasion 15
ATT&CK TA0005The adversary is trying to avoid being detected by AI-enabled security software.
AML.TA0013 Credential Access 6
ATT&CK TA0006The adversary is trying to steal account names and passwords.
AML.TA0008 Discovery 9
ATT&CK TA0007The adversary is trying to figure out your AI environment.
AML.TA0015 Lateral Movement 2
ATT&CK TA0008The adversary is trying to move through your AI environment.
AML.TA0009 Collection 4
ATT&CK TA0009The adversary is trying to gather AI artifacts and other related information relevant to their goal.
AML.TA0001 AI Attack Staging 6
The adversary is leveraging their knowledge of and access to the target system to tailor the attack.
AML.TA0014 Command and Control 3
ATT&CK TA0011The adversary is trying to communicate with compromised AI systems to control them.
AML.TA0010 Exfiltration 6
ATT&CK TA0010The adversary is trying to steal AI artifacts or other information about the AI system.
AML.TA0011 Impact 9
ATT&CK TA0040The adversary is trying to manipulate, interrupt, erode confidence in, or destroy your AI systems and data.