Frameworks Research paper Berryville Institute of Machine Learning (BIML)
BIML architectural risk analyses
Architectural risk analyses that break an AI system into its components and name the risks per component and data flow.
What this framework governs
The Berryville Institute of Machine Learning is an independent research institute around Gary McGraw, who helped define the field of software security.
Its two architectural risk analyses, one for machine learning in general and one for large language models, walk through a system component by component, from raw data through datasets and training to output, and name the risks at each point.
The perspective is an architect’s and starts early: at design time, before the first line of code exists.
Mappings in the threat catalogue
BIML architectural risk analyses. Publisher: Berryville Institute of Machine Learning (BIML). The Versatile AI Risk Assessment threat catalogue reaches 29 of its 52 threats through this framework, backed by 2 documents at 44 locations. Mappings are documented for 29 of the 52 threats in the catalogue. The overview shows their distribution by topic group.
23 threats without a mapped reference
The catalogue contains no reference from this framework for these threats. This does not establish whether the original document addresses them. See the threat pages for recorded mappings to other frameworks.
- Cost Harvesting / Repurposing Attacks on the Running Model and Service
- Insecure Tool Design Application and Integration Security
- Excessive Agency Agentic and Autonomous AI
- Profanity Harmful Content
- Sexual Content Harmful Content
- Violence / Unsafe Actions Harmful Content
- Controversial Topics Harmful Content
- Illegal Activities Harmful Content
- Self-harm Harmful Content
- Harassment Harmful Content
- Unethical Actions Harmful Content
- Social Engineering Malicious Use for Attacks, Fraud and Disinformation
- Fraud Malicious Use for Attacks, Fraud and Disinformation
- Malicious Software Malicious Use for Attacks, Fraud and Disinformation
- Disinformation Malicious Use for Attacks, Fraud and Disinformation
- Misalignment Agentic and Autonomous AI
- Middleware Exploits (AI Framework Attacks) Application and Integration Security
- Cross-Tenant Leakage (Multi-Tenant Vector DB) Privacy and Data Leakage
- MCP Hijacking (Model Context Protocol) Application and Integration Security
- Side-Channel Attacks (Timing Analysis) Attacks on the Running Model and Service
- Graph-RAG Poisoning (Knowledge Graph Injection) Application and Integration Security
- Agent Memory Poisoning (Persistent Context) Agentic and Autonomous AI
- Insecure Inter-Agent Communication (A2A/MCP) Agentic and Autonomous AI
Analysis: combine several frameworks and see the gaps that remain
Threats referencing this framework (29)
Grouped by topic. Every entry leads to the full threat page.
Agentic and Autonomous AI
1 threatApplication and Integration Security
3 threatsAttacks on the Running Model and Service
5 threatsHarmful Content
1 threatModel and Training Data Manipulation
4 threatsPrivacy and Data Leakage
3 threatsPrompt Attacks and Guardrail Evasion
5 threatsReliability and Responsible Use
4 threatsSupply Chain and Provenance
3 threatsNo threat matches this input. Reset the filters to see all of them again.
Sources used (2)
These exact versions are pinned in the catalogue. Every page states the publisher, the version used, the locations and the referencing threats.
This page does not reproduce the text of the standards. It states the identifier, title and location; the wording itself is in the original document. The mappings are taxonomic and not evidence of compliance.
The publications provide a research basis for risk analysis. Suitable criteria and measures must be derived for specific assessments and secure operation.
Further frameworks
The frameworks address different aspects: legal requirements, organisational risk management and technical security. Explore the further perspectives included in the catalogue.
From the framework to the assessment
The full catalogue states the mitigations, the possible impact and every verified location for each threat. The live demo runs locally in your browser, with no sign-up.
Cite this page
For reports, policies or internal documents; the link leads directly to this framework page.
“BIML architectural risk analyses” (Berryville Institute of Machine Learning (BIML)). Mappings in the AI threat catalogue, Versatile AI Risk Assessment, as of July 2026. https://www.versatile-ai-risk-assessment.com/en/wissensbasis/frameworks/biml-architectural-risk-analyses/