Full AI Model Access
Full model access is like a thief stealing the entire blueprint and instruction manual for a high-security vault. Because they have the exact design, they can practice breaking into it privately at home without anyone noticing, making their eventual real-world attack much harder to stop.
Full AI model access, or white-box access, occurs when an adversary obtains the complete model architecture, weights, and class ontology. This level of access allows the attacker to exfiltrate the model to perform offline adversarial machine learning, such as crafting evasion samples or verifying attack efficacy, entirely outside the view of the defender's monitoring systems.
Full AI model access denotes a white-box threat model where an adversary possesses complete knowledge of the model's architecture, parameter values, and class ontology. This state enables the adversary to exfiltrate the model weights, facilitating offline adversarial data crafting (AML.T0043) and attack verification (AML.T0042) in an environment where the adversary's iterative optimization processes remain undetectable by the model owner's telemetry.