MITRE ATLAS 2026.09 / technique reference
AML.T0040
AI Model Inference API Access
MITRE source definition
Adversaries may gain access to a model via legitimate access to the inference API. Inference API access can be a source of information to the adversary ([Discover AI Model Ontology](/techniques/AML.T0013), [Discover AI Model Family](/techniques/AML.T0014)), a means of staging the attack ([Verify Attack](/techniques/AML.T0042), [Craft Adversarial Data](/techniques/AML.T0043)), or for introducing data to the target system for Impact ([Evade AI Model](/techniques/AML.T0015), [Erode AI Model Integrity](/techniques/AML.T0031)).
Many systems rely on the same models provided via an inference API, which means they share the same vulnerabilities. This is especially true of foundation models which are prohibitively resource intensive to train. Adversaries may use their access to model APIs to identify vulnerabilities such as jailbreaks or hallucinations and then target applications that use the same models.
Source modified 2026-05-27. Reproduced from the pinned ATLAS release; inline technique links resolve to local reference pages.
Parent, sub-techniques and ATT&CK references
No explicit relationship in this pinned source.
Source-backed defensive context
MITRE mitigations
- AML.M0019 Control Access to AI Models and Data in Production
- AML.M0024 AI Telemetry Logging
- AML.M0039 AI Honeypots
MITRE case studies
- AML.CS0005 Attack on Machine Translation Services · Exercise
- AML.CS0010 Microsoft Azure Service Disruption · Exercise
- AML.CS0011 Microsoft Edge AI Evasion · Exercise
- AML.CS0012 Face Identification System Evasion via Physical Countermeasures · Exercise
- AML.CS0022 ChatGPT Package Hallucination · Exercise
- AML.CS0024 Morris II Worm: RAG-Based Attack · Exercise
- AML.CS0056 Model Distillation Campaigns Targeting Anthropic Claude · Incident
- AML.CS0057 Storm-2139 Azure OpenAI Guardrail Bypass · Incident
- AML.CS0069 GTG-1002 Claude Code Espionage Campaign · Incident
- AML.CS0070 Threat Actor Uses a DeepSeek-Powered Hermes Agent in Langflow and n8n Exploitation Attempts · Incident
These are explicit source relationships, not independently reproduced incidents or validated detection coverage.
Simulation and telemetry boundary
This is a technique reference page, not a runnable simulation. No ATLAS-specific telemetry mapping, local attack execution or detector validation is asserted. MITRE maturity describes its source evidence, not a 1200km lab result.
For broader context—not technique-specific control mappings—see AI Security, AI Security Course, and detection-validation methodology.
Provenance and attribution
Immutable MITRE ATLAS source · Import provenance · Attribution and transformation notice · Apache License 2.0
Copyright 2021-2026 MITRE. Source text and explicit relationships are retained; navigation, formatting and local links are provided by 1200km.
No explicit relationship in this pinned source.