Source directoryBerryville Institute of Machine Learning (BIML)v1.0 (2024-01-24)
An Architectural Risk Analysis of Large Language Models: Applied Machine Learning Security
“An Architectural Risk Analysis of Large Language Models: Applied Machine Learning Security”. Publisher: Berryville Institute of Machine Learning (BIML). Version used: v1.0 (2024-01-24). The Versatile AI Risk Assessment threat catalogue backs 25 of its 52 threats with this document, at 20 verified locations.
Document details
- Publisher
- Berryville Institute of Machine Learning (BIML)
- Version used
- v1.0 (2024-01-24)
- Year
- 2024
- Licence
- CC BY-SA 4.0 International
- Framework
- BIML
Open the original document at the publisher External link; the publisher’s version always takes precedence.
References in the catalogue (20)
Every row states the clause, its title, the exact location in the document and the threats that refer to it.
| Clause | Title and location | Referencing threats |
|---|---|---|
BIML-LLM inference:1 |
Prompt Manipulation (Aka Prompt Injection) PDF p. 18, [inference:1:prompt manipulation (aka prompt injection)] | Jailbreaks |
BIML-LLM inference:10 |
User Risk PDF p. 19, [inference:10:user risk] | Sensitive Information DisclosureApplication VulnerabilitiesShadow AI (Unsanctioned AI Service Use) |
BIML-LLM inference:3 |
Wrongness PDF p. 18, [inference:3:wrongness] | Factual Inconsistencies (Hallucinations) |
BIML-LLM inference:8 |
Unstructured Output PDF p. 19, [inference:8:unstructured output] | Insecure Output Handling |
BIML-LLM inference:9 |
Hosting PDF p. 19, [inference:9:hosting] | Supply Chain – InfrastructureApplication VulnerabilitiesApplication Denial of Service |
BIML-LLM input:2 |
Prompt Injection PDF p. 16, [input:2:prompt injection] | Prompt Injection – DirectPrompt Injection – Indirect |
BIML-LLM input:3 |
Open to the Public PDF p. 16, [input:3:open to the public] | JailbreaksModel Reconnaissance |
BIML-LLM input:5 |
Sponge Input PDF p. 17, [input:5:sponge input] | Model Denial of Service |
BIML-LLM LLMtop10:2 |
Data Debt PDF p. 12, [LLMtop10:2:data debt] | Supply Chain – Datasets |
BIML-LLM LLMtop10:5 |
Prompt Manipulation PDF p. 13, [LLMtop10:5:prompt manipulation] | Prompt Injection – DirectPrompt Injection – IndirectJailbreaks |
BIML-LLM LLMtop10:6 |
Poison in the Data PDF p. 13, [LLMtop10:6:poison in the data] | Supply Chain – DatasetsTraining Data PoisoningTargeted Poisoning / Label Poisoning |
BIML-LLM LLMtop10:9 |
Model Trustworthiness PDF p. 13, [LLMtop10:9:model trustworthiness] | OverrelianceFactual Inconsistencies (Hallucinations) |
BIML-LLM model:4 |
Trojan PDF p. 17, [model:4:Trojan] | Supply Chain – ModelsBackdoor ML ModelSleepy Agent (Time/Event-Triggered Hidden Instructions) |
BIML-LLM model:6 |
Training Set and Prompt Reveal PDF p. 18, [model:6:training set and prompt reveal] | Meta Prompt ExtractionPrivacy Attacks |
BIML-LLM model:9 |
Modality PDF p. 18, [model:9:modality] | Multimodal Attacks |
BIML-LLM output:11 |
Black Box Discrimination PDF p. 20, [output:11:black box discrimination] | Hate Speech and Discrimination |
BIML-LLM output:12 |
Overconfidence PDF p. 20, [output:12:overconfidence] | Overreliance |
BIML-LLM raw:10 |
Query Data PDF p. 15, [raw:10:query data] | Prompt Injection – IndirectFactual Inconsistencies (Hallucinations)RAG-Specific Attacks (Document Poisoning) |
BIML-LLM raw:5 |
Data Confidentiality PDF p. 15, [raw:5:data confidentiality] | Privacy AttacksSensitive Information Disclosure |
BIML-LLM raw:9 |
Time PDF p. 15, [raw:9:time] | Model Drift & Degradation |
This page does not reproduce the text of the standards. It states the identifier, title and location of the clause; the wording itself is in the original document. The mappings are taxonomic and not evidence of compliance.
Threats referencing this document (25)
Grouped by topic. Every entry leads to the full threat page.
Application and Integration Security
Attacks on the Running Model and Service
Harmful Content
Model and Training Data Manipulation
Privacy and Data Leakage
Prompt Attacks and Guardrail Evasion
Reliability and Responsible Use
Supply Chain and Provenance
More documents from the same publisher
All documents by Berryville Institute of Machine Learning (BIML) cited in the catalogue.
From the reference to the assessment
The full catalogue states the mitigations, the possible impact and every verified location for each threat. The live demo runs locally in your browser, with no sign-up.
Cite this page
For reports, policies or internal documents; the link leads directly to this source page.
“An Architectural Risk Analysis of Large Language Models: Applied Machine Learning Security” (Berryville Institute of Machine Learning (BIML)). References in the AI threat catalogue, Versatile AI Risk Assessment, as of July 2026. https://www.versatile-ai-risk-assessment.com/en/wissensbasis/sources/biml-architectural-risk-analysis-large-language-models/