AML.T0010
AI Supply Chain Compromise
Description
Adversaries may gain initial access to a system by compromising the unique portions of the AI supply chain. This could include Hardware, Data and its annotations, parts of the AI Software stack, or the Model itself. In some instances the attacker will need secondary access to fully carry out an attack using compromised components of the supply chain.
Honesty-tier rationale
Requires real infrastructure, valid credentials, or a victim. Working access cannot be honestly enacted inside a browser.
Sub-techniques
- AML.T0010.000 — Hardware
- AML.T0010.001 — AI Software
- AML.T0010.002 — Data
- AML.T0010.003 — Model
- AML.T0010.004 — Container Registry
- AML.T0010.005 — AI Agent Tool