SIGNAL//DESK
AI securitysrc: MITRE ATLAS

Physical Environment Access

Physical environment access means that instead of just hacking a computer through the internet, an attacker can trick an AI by changing things in the real world where the AI gets its information. Think of it like putting a piece of tape on a stop sign to confuse a self-driving car's camera; the attacker isn't hacking the car's software directly, but they are manipulating what the car sees to force a mistake.

This refers to an attack vector where an adversary manipulates the physical inputs—such as light, sound, or physical objects—that an AI system perceives through its sensors. Because the model relies on real-world data collection, the adversary exploits the physical environment to inject malicious data at the source, effectively bypassing digital security perimeters to influence the model's decision-making process.

Physical environment access denotes an adversarial capability to influence an AI model's inference or training pipeline by manipulating the physical phenomena from which input data is derived. By exploiting the sensor-environment interface, the adversary introduces perturbations into the data acquisition process, enabling the execution of adversarial attacks—such as evasion or poisoning—that manifest as digital artifacts within the model's input space despite originating from physical-domain manipulation.


← all terms