For Heads-of · Practitioner

Adversarial evasion attacks

Crafted adversarial input causes a model to misclassify or mis-generate, evading a downstream security or safety control.

  • high
  • adversarial-ml
  • evasion
  • mitre-atlas

How it happens

An attacker crafts input, an image with imperceptible perturbations, a rephrased malicious prompt, a synthetic voice sample, that is specifically engineered to be misclassified or mishandled by a model while looking unremarkable to a human reviewer.

Why it matters

Evasion attacks target the exact control that's meant to catch them, whether that's a content filter, a fraud model, or a malware classifier, so a successful evasion is invisible by design until something downstream breaks.

Mitigating controls

The controls that address this risk, ranked by effectiveness.

Framework and clause references

FrameworkClauseTitle
MITRE ATLASAML.T0015Evade AI Model

Related resources

The external sources behind this risk, from the Resources library.