Why AI needs its own model

Traditional cyber frameworks describe attacks on software and networks. Machine-learning systems introduce new attack surfaces — training data, model weights, and the inference pipeline — that conventional ATT&CK does not cover.

Techniques, not just vulnerabilities

ATLAS organizes adversarial-ML behavior into tactics and techniques: data poisoning, prompt injection, model extraction, and supply-chain compromise. Case studies link these to published incidents, giving the taxonomy real-world grounding.

The emerging pattern

Recent case studies cluster around supply-chain reuse — poisoned models, reclaimed namespaces, and malicious MCP tools — rather than exotic mathematical attacks. The practical risk is now in the software delivery path around models.

What this means

AI/ML risk is increasingly an operational concern, not a research topic. The ATLAS techniques and case studies in H3XA are a first-class intelligence feed because the attack surface is now in production systems.