AltaySec · ATLAS 2026.07
AML.T0115

Publish Poisoned AI Artifacts

C · Explainer (cannot be honestly simulated in-browser)

Description

Adversaries may create or modify AI artifacts and publish them through public or shared distribution channels to facilitate compromise of downstream AI systems. Poisoned AI artifacts may include datasets, models, and AI agent tools containing malicious content, behaviors, code, or configurations. Adversaries may publish novel artifacts or malicious variants of legitimate artifacts through dataset or model repositories, package registries, source code repositories, tool hubs, or remotely hosted services. Victims may subsequently acquire and integrate these artifacts through AI Supply Chain Compromise.

Honesty-tier rationale

This technique requires real infrastructure, model access, or a target; it cannot be honestly simulated in a browser.

Sub-techniques

Source

← Back to the matrix