Stage Capabilities
Staging capabilities is like a burglar setting up their tools near a target before breaking in. Instead of carrying everything at once, they place their equipment in a hidden, nearby spot so they can easily grab what they need to complete the job quickly.
Staging capabilities involves moving developed or acquired AI artifacts—such as poisoned datasets, malicious models, or prompt injection payloads—onto infrastructure controlled by the adversary. This ensures these assets are ready for deployment during the targeting phase, utilizing platforms like model registries, code repositories, or compromised servers to facilitate the attack.
Stage Capabilities refers to the tactical positioning of AI-specific artifacts—including but not limited to poisoned datasets, malicious models, and adversarial prompt payloads—onto adversary-controlled or compromised infrastructure. This process bridges the gap between capability development or acquisition and operational execution, enabling rapid deployment during the targeting phase. Staging may leverage legitimate web services, model registries, or container repositories, often employing obfuscation techniques such as typosquatting or the exploitation of LLM hallucinations to maintain persistence and evade detection.