{
  "node_id": "mitre-atlas-infer-training-data-membership",
  "title": "MITRE ATLAS Infer Training Data Membership (AML.T0024.000) - Adversarial Infer Training Data Membership threat to AI systems",
  "domain": "AI Governance & Law",
  "version": "1.0.1",
  "last_updated": "2026-07-22",
  "bluf": "This node addresses MITRE ATLAS technique AML.T0024.000 (Infer Training Data Membership). Adversaries may infer the membership of a data sample or global characteristics of the data in its training set, which raises privacy concerns. Some strategies make use of a shadow model that could be obtained via Train Proxy via Replication, others use statistics of model prediction scores. This can cause the victim model to leak private information, such as PII of those in the training set or other forms of protected IP. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0024. ATLAS-mapped mitigations: AML.M0002 Passive AI Output Obfuscation, AML.M0004 Restrict Number of AI Model Queries, AML.M0024 AI Telemetry Logging.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-ai-rmf-1-0",
    "eu-ai-act-2024",
    "iso-iec-42001-ai-management-system-2023",
    "mitre-atlas-mitigation-passive-ai-output-obfuscation",
    "mitre-atlas-mitigation-restrict-number-of-ai-model-queries",
    "mitre-atlas-mitigation-ai-telemetry-logging"
  ],
  "primary_citations_count": 8
}