Pular para o conteúdo
← AI security frameworks and red teaming

Aula 3 de 9 · 8 min

MITRE ATLAS: mapping an attack on an AI system

Learn how ATLAS organises tactics, techniques, mitigations and case studies, then map a real documented attack on an AI assistant step by step.

Por enquanto esta página está em inglês.

If NIST AI RMF tells you how to organise AI risk work, MITRE ATLAS tells you what attackers actually do. ATLAS stands for Adversarial Threat Landscape for AI Systems, and its maintainers describe it as “a public knowledge base of adversary TTPs targeting AI systems”, where TTPs are tactics, techniques and procedures. Teams use it the way they use any threat knowledge base: to plan tests, to describe findings in a shared language and to check that defences cover realistic attack paths.

How ATLAS is organised

  • Tactics are the adversary’s goals at each stage. The ATLAS matrix shows 16 columns: Reconnaissance, Resource Development, AI Attack Adaptation, Initial Access, AI Model Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration and Impact.
  • Techniques are the ways a tactic is achieved, with sub-techniques for variants. In the data, tactic IDs look like AML.TA0005, techniques like AML.T0051 and sub-techniques like AML.T0051.001.
  • Mitigations (AML.M####) are defensive measures linked to the techniques they reduce.
  • Case studies (AML.CS####) are documented attacks, marked as either an incident or an exercise, with each step tied to a technique and a tactic.

The 2026.09 release of the ATLAS data, dated 15 September 2026, contains 16 tactics, 208 technique and sub-technique entries, 40 mitigations and 73 case studies. Releases are monthly, so cite the version you used. On the matrix you can filter by platform (predictive AI, generative AI, agentic AI, enterprise) and by maturity: feasible, demonstrated or realized. Those labels are a quick way to prioritise a test plan.

A worked example: Slack AI (AML.CS0035)

The case study “Data Exfiltration from Slack AI via Indirect Prompt Injection” is an exercise by the security firm PromptArmor, dated 20 August 2024. ATLAS summarises it this way: the attack relied on Slack AI ingesting a malicious prompt from a post in a public channel into its retrieval database, and then a victim user querying Slack AI, which caused the prompt to be retrieved and executed. The researchers targeted an API key stored in a private channel. Here is how ATLAS breaks the procedure into steps:

Steps and technique names as listed in ATLAS release 2026.09.
StepWhat the researcher didATLAS techniqueTactic
S00Crafted a message that would be retrieved when a user asks about the API keyRetrieval Content Crafting (AML.T0066)AI Attack Adaptation
S01Crafted a prompt that makes the assistant reveal the key in a linkLLM Prompt Crafting (AML.T0065)AI Attack Adaptation
S02Used an ordinary non-admin account in the workspaceValid Accounts (AML.T0012)Initial Access
S03Interacted with the assistant by posting in public channelsAI-Enabled Product or Service (AML.T0047)AI Model Access
S04Posted the malicious content so it entered the retrieval indexRAG Poisoning (AML.T0070)Persistence
S05The victim’s query retrieved the content and the assistant followed itLLM Prompt Injection: Indirect (AML.T0051.001)Execution
S06The assistant retrieved the key from the victim’s private channelsRAG Credential Harvesting (AML.T0082)Credential Access
S07The response rendered as a link that sent the key to the researcher’s serverLLM Response Rendering (AML.T0077)Exfiltration

Notice what this mapping gives a defender. No step required breaking the model. Each depends on a design decision in the application: what the assistant may retrieve, whose content it indexes, what permissions it holds for the person asking, and how its output is rendered. That is why OWASP calls related weaknesses prompt injection, excessive agency or improper output handling: the same chain, seen from the vulnerability side. The next lesson covers that view.

Turning the map into a test plan

  1. List the assets and entry points of your system: data sources the model retrieves from, tools it can call, accounts it acts through.
  2. Pick the relevant platform filters, then start with the techniques at the demonstrated and realized maturity levels.
  3. Write each test as a short chain of tactics, as in the table, so a finding is a path and not an isolated trick.
  4. For each technique, look up its mitigations. ATLAS lists, for example, Human In-the-Loop for AI Agent Actions (AML.M0029), Restrict AI Agent Tool Invocation on Untrusted Data (AML.M0030), AI Agent Tools Permissions Configuration (AML.M0028) and AI Telemetry Logging (AML.M0024).
  5. Record the ATLAS IDs in your report. ATLAS also has a mitigation named AI Red Team (AML.M0035), which describes recurring, authorised, threat-informed exercises before deployment and throughout operation.

One caution: ATLAS shows what has been demonstrated, not what is likely in your organisation. A technique rated feasible may matter more to you than a realized one, depending on what your system exposes. Use the knowledge base to widen your thinking, then let your own architecture decide priorities.

Para lembrar

  • ATLAS is a public knowledge base of adversary tactics, techniques, mitigations and case studies for AI systems, released monthly.
  • A case study breaks an attack into steps, each mapped to a technique and a tactic, so a finding becomes a path.
  • Filters for platform (predictive, generative, agentic, enterprise) and maturity (feasible, demonstrated, realized) help prioritise tests.
  • Record ATLAS IDs and the release version in reports so others can reproduce and compare.

Teste seus conhecimentos

  1. 1. In ATLAS, what is a case study?

    • A list of laws
    • A documented attack, marked as an incident or an exercise, whose steps are mapped to techniques and tactics — Certo.
    • A vendor comparison
    • A defensive checklist

    Case studies (AML.CS####) document real incidents or exercises and tie each step to an ATLAS technique and tactic.

  2. 2. In the Slack AI case study, how did the malicious instruction reach the assistant?

    • By breaking the model’s weights
    • By being posted in a public channel that the assistant indexed and later retrieved for a victim’s query — Certo.
    • By a network man-in-the-middle
    • By a stolen administrator password

    The researcher used an ordinary account to post content that entered the retrieval database; when a victim’s query retrieved it, the assistant followed it (indirect prompt injection).

  3. 3. Why should reports state the ATLAS release you used?

    • ATLAS content and IDs change over time, with monthly releases — Certo.
    • ATLAS requires a licence per release
    • Releases are yearly and identical
    • It is only a formatting rule

    ATLAS publishes monthly content updates (for example 2026.09), so techniques, mitigations and case studies can be added or revised.

Praticar com o FireAI

Coloque esta lição em prática no seu próprio Mac.

Fontes

Coloque em prática no seu Mac

Teste todos os recursos grátis por 17 dias, sem cartão.

Baixar para Mac Docs