MITRE ATLAS Framework
MITRE ATLAS is a knowledge base of adversarial tactics, techniques, and procedures (TTPs) specific to machine learning. It translates real-world attacks into a structured taxonomy for defense planning.
See the workflow →The Four Phases
An attack follows a repeatable, documented process.
- Reconnaissance
- Resource development
- Delivery & execution
- Impact & exfiltration
Core Concepts
The foundations of understanding these vulnerabilities and controls.
ATLAS Tactics & Techniques
ATLAS covers eight core tactics: Reconnaissance (information gathering on ML systems), Resource Development (building attack infrastructure), Delivery (getting attacks into the system), Execution, Persistence, and Impact. Each tactic contains specific techniques.
- Reconnaissance: scanning ML models, probing for vulnerabilities
- Resource Development: developing exploit code, building substitute models
- Delivery: uploading poisoned data, injecting prompts, distributing backdoors
- Execution: triggering attacks through normal model operation
Mapping Your ML Pipeline to ATLAS
Every ML component is a potential attack surface mapped in ATLAS: data pipeline (poisoning), training (backdoors), inference (evasion), and deployment (supply chain). The framework helps you identify which techniques apply to your systems.
- Identify high-risk techniques specific to your architecture
- Design detection and prevention for each technique
- Establish monitoring and threat hunting procedures
- Document TTPs and maintain a threat-to-defense mapping
The Implementation Workflow
Each phase is methodical and repeatable. No phase is skipped; each has clear objectives.
Map your ML pipeline to ATLAS tactics
Data input → Training → Model serving → Output. Which tactics apply at each stage?
Identify high-risk techniques
Which techniques pose the greatest threat to your application? Data? Model integrity? Availability?
Design detection and prevention
For each high-risk technique, deploy monitoring, anomaly detection, and access controls.
Document threat responses
Maintain a playbook: TTP → Detection → Response. Update based on red team findings.
Related Pages
Deep dives into related attack and defense topics.
OWASP LLM Top 10
OWASP risks mapped to ATLAS tactics and techniques.
AI Audit & Security Framework
Testing methodology aligned with ATLAS TTPs.
LLM Red Teaming
Structured campaigns to validate ATLAS technique coverage.
AI Governance & EU AI Act
ATLAS integration into regulatory audit and compliance.