SIGNAL//DESK
AI securitysrc: MITRE ATLAS

Data

Data is the information used to teach an AI how to think. Because AI projects often use information from the internet or hire outside help to organize that information, hackers can sneak in 'bad' data to trick the AI or hide malicious software inside it, making the data a weak point in the supply chain.

Data serves as a critical supply chain vector in AI security because models are fundamentally dependent on external inputs. Adversaries exploit this dependency by compromising open-source datasets or infiltrating third-party labeling services to inject malicious payloads or poison training data, which can lead to model manipulation or system compromise.

Data constitutes a primary attack vector within the AI supply chain, as the integrity of the model is contingent upon the provenance and veracity of its training and validation sets. Adversaries leverage the reliance on public repositories and outsourced data labeling services to execute supply chain attacks, specifically through data poisoning (AML.T0020) or the embedding of malicious artifacts, thereby compromising the model's objective function or the underlying infrastructure.

seen in events


← all terms