SIGNAL//DESK
AI securitysrc: MITRE ATLAS

Discovery

Discovery is like a burglar who has just broken into a house and is quietly looking around to see where the valuables are kept, what the security system looks like, and how the rooms are connected before they decide what to steal.

Discovery refers to the post-compromise phase where an adversary maps out the AI environment, including internal network topology, system configurations, and available AI model interfaces, to identify potential attack vectors and pivot points that align with their objectives.

The adversary is trying to figure out your AI environment. Discovery consists of techniques an adversary may use to gain knowledge about the system and internal network. These techniques help adversaries observe the environment and orient themselves before deciding how to act. They also allow adversaries to explore what they can control and what's around their entry point in order to discover how it could benefit their current objective. Native operating system tools are often used toward this post-compromise information-gathering objective.

evolution

  1. 2016 · history
    Model Inversion Attacks

    Researchers demonstrated that adversaries could reconstruct training data or sensitive features by querying a model's API.

  2. 2017 · history
    Black-box Adversarial Attacks

    The discovery that models could be probed to create substitute models allowed attackers to map decision boundaries without internal access.

  3. 2020 · history
    Model Extraction Formalization

    Techniques were standardized for adversaries to systematically query and replicate proprietary model architectures and weights.

  4. 2023 · history
    MITRE ATLAS Framework

    The formalization of 'Discovery' as a distinct tactic in the adversarial machine learning threat landscape provided a structured taxonomy for reconnaissance.


← all terms