AML.T0010 | AI Supply Chain Compromise ATLAS ↗ | Attack index - by task · VII.1 · The secure AI SDLC |
AML.T0011.000 | User Execution: Unsafe AI Artifacts ATLAS ↗ | VII.1 · The secure AI SDLC |
AML.T0015 | Evade AI Model ATLAS ↗ | VII.1 · The secure AI SDLC |
AML.T0017.001 | Autonomous Exploit Development ATLAS ↗ | VI.4 · The AI red-team playbook · Mapping & scoring a finding |
AML.T0018 | Manipulate AI Model ATLAS ↗ | VII.1 · The secure AI SDLC |
AML.T0020 | Poison Training Data ATLAS ↗ | VII.1 · The secure AI SDLC |
AML.T0024 | Exfiltration via AI Inference API ATLAS ↗ | Attack index - by task · VII.1 · The secure AI SDLC |
AML.T0024.000 | Infer Training Data Membership ATLAS ↗ | Attack index - by task · I.3 · Training data - extraction and poisoning |
AML.T0025 | Exfiltration via Cyber Means ATLAS ↗ | VII.1 · The secure AI SDLC |
AML.T0031 | Erode AI Model Integrity ATLAS ↗ | VII.1 · The secure AI SDLC |
AML.T0034 | Cost Harvesting ATLAS ↗ | VII.1 · The secure AI SDLC |
AML.T0035 | AI Artifact Collection ATLAS ↗ | VII.1 · The secure AI SDLC |
AML.T0043 | Craft Adversarial Data ATLAS ↗ | Attack index - by task · VII.1 · The secure AI SDLC |
AML.T0051 | LLM Prompt Injection ATLAS ↗ | Attack index - by task · VIII.1 · Frameworks & standards - four altitudes · VI.3 · Threat modeling for AI systems · VII.1 · The secure AI SDLC · IV.3 · The MCP assessment runbook · One system, end to end |
AML.T0051.000 | LLM Prompt Injection: direct ATLAS ↗ | Attack index - by task |
AML.T0051.001 | LLM Prompt Injection: Indirect ATLAS ↗ | Attack index - by task · II.4 · Multimodal - what a text filter cannot see · II.2 · Prompt injection & the LLM attack surface · VII.3 · Detection, IR & forensics for AI · RAG, end to end · Mapping & scoring a finding · Templates & checklists |
AML.T0053 | AI Agent Tool Invocation ATLAS ↗ | Mapping & scoring a finding |
AML.T0054 | LLM Jailbreak ATLAS ↗ | Attack index - by task · II.3 · Jailbreaks & guardrail bypasses · VI.5 · Running the engagement · VII.1 · The secure AI SDLC · Templates & checklists |
AML.T0057 | LLM Data Leakage ATLAS ↗ | VI.3 · Threat modeling for AI systems · VII.1 · The secure AI SDLC · VII.3 · Detection, IR & forensics for AI · Templates & checklists · One system, end to end |
AML.T0080 | AI Agent Context Poisoning ATLAS ↗ | III.4 · Persistence & propagation - memory poisoning, worms |
AML.T0080.000 | AI Agent Context Poisoning: Memory ATLAS ↗ | Attack index - by task · III.4 · Persistence & propagation - memory poisoning, worms |
AML.T0115.000 | Publish Poisoned AI Artifacts: Datasets ATLAS ↗ | VII.1 · The secure AI SDLC |
AML.T0115.001 | Publish Poisoned AI Artifacts: Models ATLAS ↗ | VII.1 · The secure AI SDLC |
AML.T0115.002 | - ATLAS ↗ | VI.3 · Threat modeling for AI systems |
AML.T0116 | Autonomous Reconnaissance ATLAS ↗ | VI.4 · The AI red-team playbook · Mapping & scoring a finding |
AML.T0117 | Autonomous Attack-Path Adaptation ATLAS ↗ | VI.4 · The AI red-team playbook · Mapping & scoring a finding |
AML.T0118 | Autonomous AI Agent Communication ATLAS ↗ | VI.4 · The AI red-team playbook · Mapping & scoring a finding |
AML.T0124 | Autonomous Attack Orchestration ATLAS ↗ | VI.4 · The AI red-team playbook · Mapping & scoring a finding |
AML.T0129 | Triggers in Multimodal Inputs ATLAS ↗ | Attack index - by task · II.4 · Multimodal - what a text filter cannot see |