Without artificial intelligence, the near future is inconceivable, as is probably clear to everyone by now. As is the fact that what we depend on is under attack. But how?
and how can we defend the technology itself against attacks?
We will now focus on the latter, giving us the opportunity to present The MITRE Corporation’s MITRE ATLAS™ Matrix, which summarises the threats to machine learning solutions. Why is this important to us? It’s because machine learning is the most widely used of all artificial intelligence solutions, and by the way, it’s also the basis for cyber defence, the basis of almost all services visible to ordinary people.
The first phase, known as poisoning, can be experienced during the design and development of the data models on which the algorithm is based. The second phase, when we talk about evasion and/or data theft, can be detected during the deployment and monitoring phases. For example, in cybersecurity solutions using AI, the first phase is to make the model learn something incorrectly, such as accepting certain malicious activities as normal, and the second phase is to bypass the defence controls developed for AI and steal the data models therein, in order to allow the attacker to learn how the defence works and to target the attack against the organisation.
Of course, this is a theoretical, rather abstract risk until we see machine learning algorithms attacked in real attacks. MITRE Corporation has therefore created the ATLAS™ matrix, modelled on their ATT&CK® framework, to help cybersecurity professionals work to protect artificial intelligence, a field probably unknown to most.
The matrix maps the attack steps to each step in the attack chain in a familiar way from MITRE, but after the Initial Access phase, the ML Model Access step is a new addition and one of the specialties of this matrix. The description, which currently includes 44 attack techniques, also covers general attacks such as the misuse of Valid Accounts, but also mentions machine learning specific examples such as Discover ML Model Ontology and ML Artifact Collection.
Perhaps more interesting for those on the defence side, however, is the Mitigations list of proposed protection measures. And we have to admit that this list is rather short and general. In total there are 19 protection measures listed that MITRE experts recommend, including user education or vulnerability testing. However, ML specific proposals such as Sanitize Training Data or Restrict Number of ML Model Queries could provide a very interesting new perspective on the protection of models. One thing is for sure, this list will grow very quickly in the coming years, so it will be worth checking the ATLAS website regularly.
As Sun Tzu wrote in The Art of War, 2500 years ago,
If you know the enemy and know yourself, you need not fear the result of a hundred battles. If you know yourself but not the enemy, for every victory gained you will also suffer a defeat. If you know neither the enemy nor yourself, you will succumb in every battle.
Cybersecurity professionals working in the age of artificial intelligence are currently characterised by the situation described in the last sentence. We neither know the enemy, i.e. we don’t know what attacks he will launch against ML, but in return we don’t know our own capabilities, as AI is a completely new field that most of us are not yet trained in. MITRE’s matrix can provide some help in this regard, and we think it should be required reading for all experts.
In any case, until such time as this knowledge is transferred into everyday life, it is worth working with managed security service providers who are already familiar with the opportunities and threats that AI presents on a daily basis. And time may (MAYBE) solve this problem.
Why are there more and more cyber attacks on software development environments and how is software company security becoming a key issue in the supply chain?
This week’s CVE of the Week is CVE-2026-24301, also known as CoSnitch, an exfiltration method in Microsoft Copilot that could allow an unauthorized attacker to steal sensitive information and data. With a CVSS score of 8.8, deserves serious attention. It is a combination of three different vulnerabilities that could allow an attacker to pull data ...
AI has been a hotspot for everything recently and that’s true for attacks too proven by the recently discovered and also exploited IBM Langflow OSS (versions 1.0.0 through 1.10.0) vulnerability CVE-2026-9198, our #CVEoftheWeek. The issue was addressed in the release of version 1.10.1 on 24th June, which contained many security updates, but known Proof-of-Concepts (PoC) ...
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.