AML.T0011
User Execution
Description
An adversary may rely upon a user to load, execute, interpret, or otherwise use a malicious or unsafe artifact. In AI systems, user execution may include loading a model or causing an inference runtime to process executable or behavior-shaping components bundled with an AI artifact. The resulting effect may include host code execution or malicious AI behavior. Users may inadvertently execute unsafe code introduced via AI Supply Chain Compromise. Users may be subjected to social engineering to get them to execute malicious code by, for example, opening a malicious document file or link.
Honesty-tier rationale
Requires a real code-execution sandbox; to be safe it needs a separate environment (Tier-B lab).
Sub-techniques
- AML.T0011.000 — Unsafe AI Artifacts
- AML.T0011.001 — Malicious Package
- AML.T0011.002 — Poisoned AI Agent Tool
- AML.T0011.003 — Malicious Link