MITRE ATLAS Framework

MITRE ATLAS is a knowledge base of adversarial tactics, techniques, and procedures (TTPs) specific to machine learning. It translates real-world attacks into a structured taxonomy for defense planning.

See the workflow →

The Four Phases

An attack follows a repeatable, documented process.

  • Reconnaissance
  • Resource development
  • Delivery & execution
  • Impact & exfiltration

Core Concepts

The foundations of understanding these vulnerabilities and controls.

ATLAS Tactics & Techniques

ATLAS covers eight core tactics: Reconnaissance (information gathering on ML systems), Resource Development (building attack infrastructure), Delivery (getting attacks into the system), Execution, Persistence, and Impact. Each tactic contains specific techniques.

  • Reconnaissance: scanning ML models, probing for vulnerabilities
  • Resource Development: developing exploit code, building substitute models
  • Delivery: uploading poisoned data, injecting prompts, distributing backdoors
  • Execution: triggering attacks through normal model operation

Mapping Your ML Pipeline to ATLAS

Every ML component is a potential attack surface mapped in ATLAS: data pipeline (poisoning), training (backdoors), inference (evasion), and deployment (supply chain). The framework helps you identify which techniques apply to your systems.

  • Identify high-risk techniques specific to your architecture
  • Design detection and prevention for each technique
  • Establish monitoring and threat hunting procedures
  • Document TTPs and maintain a threat-to-defense mapping

The Implementation Workflow

Each phase is methodical and repeatable. No phase is skipped; each has clear objectives.

Map your ML pipeline to ATLAS tactics

Data input → Training → Model serving → Output. Which tactics apply at each stage?

Identify high-risk techniques

Which techniques pose the greatest threat to your application? Data? Model integrity? Availability?

Design detection and prevention

For each high-risk technique, deploy monitoring, anomaly detection, and access controls.

Document threat responses

Maintain a playbook: TTP → Detection → Response. Update based on red team findings.

Related Pages

Deep dives into related attack and defense topics.

OWASP LLM Top 10

OWASP risks mapped to ATLAS tactics and techniques.

AI Audit & Security Framework

Testing methodology aligned with ATLAS TTPs.

LLM Red Teaming

Structured campaigns to validate ATLAS technique coverage.

AI Governance & EU AI Act

ATLAS integration into regulatory audit and compliance.