MITRE ATLAS 2026.09 / technique reference
AML.T0015
Evade AI Model
MITRE source definition
Adversaries can [Craft Adversarial Data](/techniques/AML.T0043) that prevents an AI model from correctly identifying the contents of the data or [Generate Deepfakes](/techniques/AML.T0088) that fools an AI model expecting authentic data.
This technique can be used to evade a downstream task where AI is utilized. The adversary may evade AI-based virus/malware detection or network scanning towards the goal of a traditional cyber attack. AI model evasion through deepfake generation may also provide initial access to systems that use AI-based biometric authentication.
Source modified 2026-05-27. Reproduced from the pinned ATLAS release; inline technique links resolve to local reference pages.
Parent, sub-techniques and ATT&CK references
No explicit relationship in this pinned source.
Source-backed defensive context
MITRE mitigations
- AML.M0003 Predictive AI Model Hardening
- AML.M0006 Predictive AI Ensembles
- AML.M0009 Predictive AI Multi-Sensor Fusion
- AML.M0010 Predictive AI Input Restoration
- AML.M0015 Predictive AI Adversarial Input Detection
- AML.M0034 Deepfake Detection
- AML.M0035 AI Red Team
MITRE case studies
- AML.CS0000 Evasion of Deep Learning Detector for Malware C&C Traffic · Exercise
- AML.CS0001 Botnet Domain Generation Algorithm (DGA) Detection Evasion · Exercise
- AML.CS0003 Bypassing Cylance's AI Malware Detection · Exercise
- AML.CS0004 Camera Hijack Attack on Facial Recognition System · Incident
- AML.CS0005 Attack on Machine Translation Services · Exercise
- AML.CS0008 ProofPoint Evasion · Exercise
- AML.CS0010 Microsoft Azure Service Disruption · Exercise
- AML.CS0011 Microsoft Edge AI Evasion · Exercise
- AML.CS0012 Face Identification System Evasion via Physical Countermeasures · Exercise
- AML.CS0013 Backdoor Attack on Deep Learning Models in Mobile Apps · Exercise
- AML.CS0014 Confusing Antimalware Neural Networks · Exercise
- AML.CS0017 Bypassing ID.me Identity Verification · Incident
- AML.CS0028 AI Model Tampering via Supply Chain Attack · Exercise
- AML.CS0032 Attempted Evasion of ML Phishing Webpage Detection System · Incident
- AML.CS0033 Live Deepfake Image Injection to Evade Mobile KYC Verification · Exercise
- AML.CS0034 ProKYC: Deepfake Tool for Account Fraud Attacks · Incident
- AML.CS0043 Malware Prototype with Embedded Prompt Injection · Incident
- AML.CS0058 Google Photos AI Model Extraction · Exercise
These are explicit source relationships, not independently reproduced incidents or validated detection coverage.
Simulation and telemetry boundary
This is a technique reference page, not a runnable simulation. No ATLAS-specific telemetry mapping, local attack execution or detector validation is asserted. MITRE maturity describes its source evidence, not a 1200km lab result.
For broader context—not technique-specific control mappings—see AI Security, AI Security Course, and detection-validation methodology.
Provenance and attribution
Immutable MITRE ATLAS source · Import provenance · Attribution and transformation notice · Apache License 2.0
Copyright 2021-2026 MITRE. Source text and explicit relationships are retained; navigation, formatting and local links are provided by 1200km.
No explicit relationship in this pinned source.