MITRE ATLAS 2026.09 / technique reference
AML.T0018.001
Modify AI Model Architecture
MITRE source definition
Adversaries may directly modify an AI model's architecture to re-define it's behavior. This can include adding or removing layers as well as adding pre or post-processing operations.
The effects could include removing the ability to predict certain classes, adding erroneous operations to increase computation costs, or degrading performance. Additionally, a separate adversary-defined network could be injected into the computation graph, which can change the behavior based on the inputs, effectively creating a backdoor.
Source modified 2026-05-27. Reproduced from the pinned ATLAS release; inline technique links resolve to local reference pages.
Parent, sub-techniques and ATT&CK references
Source-backed defensive context
MITRE mitigations
- AML.M0005 Control Access to AI Models and Data at Rest
- AML.M0008 Validate AI Model
- AML.M0013 Code Signing
- AML.M0035 AI Red Team
MITRE case studies
- AML.CS0013 Backdoor Attack on Deep Learning Models in Mobile Apps · Exercise
- AML.CS0028 AI Model Tampering via Supply Chain Attack · Exercise
These are explicit source relationships, not independently reproduced incidents or validated detection coverage.
Simulation and telemetry boundary
This is a technique reference page, not a runnable simulation. No ATLAS-specific telemetry mapping, local attack execution or detector validation is asserted. MITRE maturity describes its source evidence, not a 1200km lab result.
For broader context—not technique-specific control mappings—see AI Security, AI Security Course, and detection-validation methodology.
Provenance and attribution
Immutable MITRE ATLAS source · Import provenance · Attribution and transformation notice · Apache License 2.0
Copyright 2021-2026 MITRE. Source text and explicit relationships are retained; navigation, formatting and local links are provided by 1200km.
No explicit relationship in this pinned source.