SIGNAL//DESK
AI securitysrc: MITRE ATLAS

Manipulate AI Model

Manipulating an AI model is like a hacker sneaking into a factory to change the blueprints or the machinery itself. Instead of just tricking the AI with a fake input, the attacker physically alters the AI's 'brain' so that it is permanently broken or programmed to do something harmful whenever it runs.

Model manipulation involves unauthorized modification of an AI system's internal parameters or structural components to force a persistent change in output. This includes techniques like weight poisoning, architectural tampering, or injecting malicious payloads into model files, ensuring the compromise remains active even after the input data changes.

Adversaries may directly manipulate an AI model to change its behavior or introduce malicious code. Manipulating a model gives the adversary a persistent change in the system. This can include poisoning the model by changing its weights, modifying the model architecture to change its behavior, and embedding malware which may be executed when the model is loaded.


← all terms