Bidda Sovereign Intelligence · 10,108 Verified Nodes · 39 Sovereign Pillars

NIST AI 100-2 E2023 - Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (January 2024)

NIST AI 100-2 E2023 (final published January 4, 2024) establishes a standardised taxonomy and common terminology for adversarial machine learning (AML)…

What NIST AI 100-2 E2023 - Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (January 2024) requires

NIST AI 100-2 E2023 (final published January 4, 2024) establishes a standardised taxonomy and common terminology for adversarial machine learning (AML) attacks and mitigations. The document organises the AML landscape along three primary attacker dimensions and across two AI paradigms - Predictive AI (PredAI) and Generative AI (GenAI). The three attacker dimensions are: (1) Stage of learning (training time vs deployment time), (2) Attacker goals and objectives (availability, integrity, privacy compromise), and (3) Attacker capability and knowledge (white-box, black-box, grey-box; control over training data, model, query access). The taxonomy enumerates attack classes including evasion attacks, poisoning attacks (data poisoning, model poisoning, targeted vs untargeted), privacy attacks (membership inference, model inversion, model extraction/stealing, attribute inference), and abuse attacks specific to GenAI (prompt injection, jailbreaks, indirect prompt injection, abuse of LLMs for malicious purposes). For each class, the document describes attack mechanisms, real-world examples, and known mitigations along with their limitations. NIST AI 100-2 is the foundational reference for the Measure and Manage functions of the NIST AI Risk Management Framework when applied to security-relevant risks; it is co-cited with the NIST AI 600-1 GenAI Profile and serves as the technical baseline for federal agency AI security assessments.

Pillar: AI Governance & Law · Authority: National Institute of Standards and Technology - NIST AI 100-2 E2023 (Final), January 2024 · Version: 1.0.0 · Last updated:

Primary source: https://csrc.nist.gov/pubs/ai/100/2/e2023/final

SHA-256 integrity: d18674083bb0f84710b1856159947cb1dc6e4faf2c24570df62b00f65c986a93

Primary Citations — 8 traced to source

  • NIST AI 100-2 E2023 (Final, January 2024), Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations
  • NIST AI 100-2 Taxonomy structured along three dimensions - stage of learning, attacker goals, and attacker capability and knowledge

+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.