Versatile AI Risk Assessment

Two threats and the references they share

Choose two threats or one of the suggested pairs with a large overlap. The middle column shows the references both point to; the outer ones show what applies to only one of them. The mitigations of both sides are listed below.

Who it is for: For anyone drafting policies, training material or audit plans

Threat comparison

Backdoor ML Model and Sleepy Agent (Time/Event-Triggered Hidden Instructions) share 11 of 16 references. Both sit in the same topic group.

11shared references
4only in the first
1only in the second
4 to 6mitigations in the catalogue
2/5shared effect classes

Only Backdoor ML Model4

Model and Training Data Manipulation · Development

BIML BIML78 model:2BSI R20NIST AI RMF NISTAML.021NIST AI RMF NISTAML.026

Shared by both11

the same reference in the same framework

BIML BIML-LLM model:4BSI R19EU AI Act Article 53(1)(a)EU AI Act Article 55(1)(a)EU AI Act Article 9(1), 9(2)(a), 9(2)(d)MITRE ATLAS AML.T0018NIST AI RMF MEASURE 2.7NIST AI RMF NISTAML.023NIST AI RMF NISTAML.051NIST AI RMF Section 2.9OWASP LLM Top 10 LLM04:2025

Only Sleepy Agent (Time/Event-Triggered Hidden Instructions)1

Model and Training Data Manipulation · Development

MITRE ATLAS AML.T0020

Backdoor ML Model 4 mitigations

The model contains hidden behavior, a backdoor. It works correctly on normal inputs; only a secret trigger pattern in the input flips the output to whatever result the attacker has chosen.

  • Model scanning for backdoors

    Effect: DetectiveImplementation level: Model & trainingControl type: Technical

    Reason for the classification

    Primarily technical: Software or analytical tools systematically produce and evaluate measurements, deviations, or attack indicators.

  • Neural cleanse techniques

    Effect: DetectiveImplementation level: Model & trainingControl type: Technical

    Reason for the classification

    Primarily technical: Software or analytical tools systematically produce and evaluate measurements, deviations, or attack indicators.

  • Activation clustering analysis

    Effect: DetectiveImplementation level: Model & trainingControl type: Technical

    Reason for the classification

    Primarily technical: Software or analytical tools systematically produce and evaluate measurements, deviations, or attack indicators.

  • Train from trusted base models only

    Effect: PreventiveImplementation level: Model & training, Supply chainControl type: Organizational & process-basedComplementary type: Technical

    Reason for the classification

    Primarily organizational and process-based: Defined selection, operating, or lifecycle procedures make the control binding and repeatable; complemented by technical implementation.

Sleepy Agent (Time/Event-Triggered Hidden Instructions) 6 mitigations

Malicious logic lies dormant inside the model and only activates later: on a set date, at a specific event, or in a particular environment. Until then, the system passes every test and review without raising suspicion.

  • Behavioral analysis under diverse conditions

    Effect: DetectiveImplementation level: Model & trainingControl type: Technical

    Reason for the classification

    Primarily technical: Software or analytical tools systematically produce and evaluate measurements, deviations, or attack indicators.

  • Time-shifted testing

    Effect: DetectiveImplementation level: Model & trainingControl type: Technical

    Reason for the classification

    Primarily technical: Software or analytical tools systematically produce and evaluate measurements, deviations, or attack indicators.

  • Adversarial evaluation across contexts

    Effect: DetectiveImplementation level: Model & trainingControl type: Technical

    Reason for the classification

    Primarily technical: Software or analytical tools systematically produce and evaluate measurements, deviations, or attack indicators.

  • Runtime behavior monitoring

    Effect: DetectiveImplementation level: Model & training, Use & operationsControl type: TechnicalComplementary type: Organizational & process-based

    Reason for the classification

    Primarily technical: Software or analytical tools systematically produce and evaluate measurements, deviations, or attack indicators; complemented by binding workflows.

  • Model interpretability tools

    Effect: DetectiveImplementation level: Model & trainingControl type: Technical

    Reason for the classification

    Primarily technical: Software or analytical tools systematically produce and evaluate measurements, deviations, or attack indicators.

  • Supply chain integrity verification

    Effect: Preventive, DetectiveImplementation level: Model & training, Supply chainControl type: TechnicalComplementary type: Organizational & process-based

    Reason for the classification

    Primarily technical: Software or analytical tools systematically produce and evaluate measurements, deviations, or attack indicators; complemented by binding workflows.

Threat pathwayThe threat pathway shows how one of these threats unfolds in detail.

The file shows the current state including any filters and carries the note, catalogue version and source.

A shared reference means that both threats point to the same place in the same framework. It does not mean that one mitigation covers both.

Versatile AI Risk Assessment is an aid for structuring AI risks and making them transparent. It does not replace legal or professional advice and makes no binding decisions.

Understanding threats

The same data, a different question

What defines a threat, when it arises and how it differs from another.

  1. Preview of the analysis: Threat pathway Threat pathway How does harm arise? For anyone working through a threat in depth for the first time
  2. Preview of the analysis: Lifecycle Lifecycle When does which risk arise? For governance, procurement and programme management
Placing your own system
Planning mitigations
Checking frameworks and evidence

Overview of all ten analyses

Related
Threat catalogue

All 52 threats in full: description, impact, example, mitigations and verified sources.

To the catalogue
EU AI Act quick check

Four short sections along the EU AI Act for a first, non‑binding orientation of your system.

To the quick check
Assess it yourself

The full assessment with system context, threat selection and evidence tracking, free of charge in the browser.

To the live demo