Secure AI Atlas mark Secure AI Atlas SECURITY & GOVERNANCE

Framework

MITRE ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems)

A globally recognised knowledge base of adversary tactics, techniques, and case studies for AI systems, modelled after the MITRE ATT&CK framework and maintained by the MITRE Corporation.

Threat IntelligenceAdversarial MLTacticsMitigation

MITRE ATLAS applies the proven ATT&CK methodology to AI systems. It documents real-world attack patterns against machine learning models, pipelines, and applications through an open, community-contributed knowledge base of tactics, techniques, and procedures (TTPs).

Tactical categories

TacticDescription
ReconnaissanceGather information about the target AI system, its training data, model architecture, APIs, and guardrails
Resource DevelopmentAcquire or build infrastructure, datasets, or tools to support the attack
Initial AccessGain an initial foothold into the AI system, its training pipeline, or its deployment environment
ML Model AccessObtain access to the model itself — its weights, inference endpoints, or training process
ExecutionRun adversary-controlled code or commands within the AI environment
PersistenceMaintain access across restarts, updates, or credential rotations
Defence EvasionAvoid detection by security controls, logging, or monitoring
DiscoveryLearn about the AI environment: model type, API structure, data schemas, connected systems
CollectionGather information from the AI system: prompts, outputs, embeddings, or training data
ML Attack StagingPrepare the model or its inputs for exploitation — crafting adversarial examples, poisoning data, or tampering with the supply chain
ExfiltrationTransfer data, model artefacts, or intellectual property out of the target environment
ImpactManipulate, disrupt, or destroy AI system outputs, availability, or integrity

ATLAS connection

MITRE ATLAS directly informs the ATLAS Risk Catalogue and Controls Catalogue. The Prompt Injection, Sensitive Data Disclosure, and Agentic Supply Chain Compromise entries are structured around attack paths documented in ATLAS case studies. The Input and Output Validation for AI Agents control is a direct translation of MITRE ATLAS mitigation AML.M0033. Together they provide the “what could happen” and “what to do about it” parts of the operational risk analysis.

Official website →

Official source: MITRE