Why AI needs its own model
Traditional cyber frameworks describe attacks on software and networks. Machine-learning systems introduce new attack surfaces — training data, model weights, and the inference pipeline — that conventional ATT&CK does not cover.
Techniques, not just vulnerabilities
ATLAS organizes adversarial-ML behavior into tactics and techniques: data poisoning, prompt injection, model extraction, and supply-chain compromise. Case studies link these to published incidents, giving the taxonomy real-world grounding.
The emerging pattern
Recent case studies cluster around supply-chain reuse — poisoned models, reclaimed namespaces, and malicious MCP tools — rather than exotic mathematical attacks. The practical risk is now in the software delivery path around models.
What this means
AI/ML risk is increasingly an operational concern, not a research topic. The ATLAS techniques and case studies in H3XA are a first-class intelligence feed because the attack surface is now in production systems.