Initial Access
Initial access is the first step an attacker takes to break into a computer system or device that uses AI, acting like a burglar trying to find an unlocked window or door to get inside your home.
Initial access refers to the tactical phase where an adversary employs various entry vectors—such as exploiting software vulnerabilities, phishing, or misconfigurations—to establish a foothold within a target environment, whether it is a network, mobile device, or edge sensor platform, to begin interacting with its AI capabilities.
The adversary is trying to gain access to the AI system. The target system could be a network, mobile device, or an edge device such as a sensor platform. The AI capabilities used by the system could be local with onboard or cloud-enabled AI capabilities. Initial Access consists of techniques that use various entry vectors to gain their initial foothold within the system.
evolution
- 2017 · historyAdversarial Machine Learning Formalization
The publication of foundational research on adversarial examples established the theoretical basis for manipulating AI inputs to gain unauthorized system control.
- 2020 · historyMITRE ATLAS Framework Launch
MITRE introduced the Adversarial Threat Landscape for Artificial-Intelligence Systems (ATLAS) to categorize initial access and exploitation techniques specific to AI.
- 2023 · historyOWASP Top 10 for LLMs
The release of the OWASP Top 10 for Large Language Models formally identified prompt injection as a primary vector for gaining unauthorized initial access to AI-integrated systems.
- 2024 · historyNIST AI Risk Management Framework Adoption
NIST integrated AI-specific security controls, formalizing the need to defend against initial access threats targeting the AI supply chain and model weights.