AML.T0115
Publish Poisoned AI Artifacts
Description
Adversaries may create or modify AI artifacts and publish them through public or shared distribution channels to facilitate compromise of downstream AI systems. Poisoned AI artifacts may include datasets, models, and AI agent tools containing malicious content, behaviors, code, or configurations. Adversaries may publish novel artifacts or malicious variants of legitimate artifacts through dataset or model repositories, package registries, source code repositories, tool hubs, or remotely hosted services. Victims may subsequently acquire and integrate these artifacts through AI Supply Chain Compromise.
Honesty-tier rationale
This technique requires real infrastructure, model access, or a target; it cannot be honestly simulated in a browser.
Sub-techniques
- AML.T0115.000 — Datasets
- AML.T0115.001 — Models
- AML.T0115.002 — AI Agent Tools