What Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations requires
This NIST Trustworthy and Responsible AI report develops a taxonomy of concepts and defines terminology in the field of adversarial machine learning (AML), which may aid in securing applications of artificial intelligence (AI) against adversarial manipulations. The taxonomy is built on surveying the AML literature and is arranged in a conceptual hierarchy that includes key types of ML methods, lifecycle stages of attack, attacker goals, and attacker capabilities and knowledge. It applies to both Predictive and Generative AI systems. The data-driven approach of machine learning introduces security and privacy challenges, including the potential for adversarial manipulation of training data, exploitation of model vulnerabilities to affect performance, and malicious interactions to exfiltrate sensitive information. AML is concerned with studying the capabilities of attackers and their goals, as well as the design of attack methods that exploit vulnerabilities during the ML lifecycle. It is also concerned with the design of ML algorithms that can withstand these challenges. The intended audience includes individuals and groups responsible for designing, developing, deploying, evaluating, and governing AI systems. The taxonomy and terminology are meant to inform other standards and future practice guides for assessing and managing the security of AI systems by establishing a common language and understanding of the rapidly developing AML landscape.
Pillar: AI Governance & Law · Authority: National Institute of Standards and Technology · Version: 1.0.0 · Last updated:
Primary source: https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-2e2023.pdf
SHA-256 integrity: e5644571b146aca64a332beda240fd3b9e53afbc436cdc75fac616e1e441a477
Primary Citations — 8 traced to source
- Section 1: The taxonomy and terminology are meant to inform other standards and future practice guides for assessing and managing the security of AI systems by establishing a common language and understanding for the rapidly developing AML landscape.
- Section 2.1.1: Attacks during the ML training stage are called POISONING ATTACKS. In a DATA POISONING attack, an adversary controls a subset of the training data by either inserting or modifying training samples.
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/nist-ai-adversarial-machine-learning.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/nist-ai-adversarial-machine-learning.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/nist-ai-adversarial-machine-learning
- Back to registry: Browse all 10,090 compliance nodes