AI Supply Chain Compromise: Model AML.T0010.003
AI-enabled systems often rely on open sourced models in various ways. Most commonly, the victim organization may be using these models for fine tuning. These models will be downloaded from an external source and then used as the base for the model as it is tuned on a smaller, private dataset. Loading models often requires executing some saved code in the form of a saved model file. These can be compromised with traditional malware, or through some adversarial AI techniques.
MITRE ATLAS technique. Tactics: Initial Access. View on atlas.mitre.org
Rules tagged with this technique
Every catalog rule tagged with this ATLAS technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.