Source directoryBerryville Institute of Machine Learning (BIML)v1.0 (2020-01-13)
An Architectural Risk Analysis of Machine Learning Systems: Toward More Secure Machine Learning
“An Architectural Risk Analysis of Machine Learning Systems: Toward More Secure Machine Learning”. Publisher: Berryville Institute of Machine Learning (BIML). Version used: v1.0 (2020-01-13). The Versatile AI Risk Assessment threat catalogue backs 21 of its 52 threats with this document, at 24 verified locations.
Document details
- Publisher
- Berryville Institute of Machine Learning (BIML)
- Version used
- v1.0 (2020-01-13)
- Year
- 2020
- Licence
- CC BY-SA 3.0
- Framework
- BIML
Open the original document at the publisher External link; the publisher’s version always takes precedence.
References in the catalogue (24)
Every row states the clause, its title, the exact location in the document and the threats that refer to it.
| Clause | Title and location | Referencing threats |
|---|---|---|
BIML78 alg:1 |
Online PDF p. 16, [alg:1:online] | Model Drift & Degradation |
BIML78 alg:11 |
Parameters PDF p. 17, [alg:11:parameters] | Supply Chain – Models |
BIML78 assembly:2 |
Annotation PDF p. 13, [assembly:2:annotation] | Targeted Poisoning / Label Poisoning |
BIML78 assembly:6 |
Filter PDF p. 13, [assembly:6:filter] | Model Reconnaissance |
BIML78 data:1 |
Poisoning PDF p. 14, [data:1:poisoning] | Training Data Poisoning |
BIML78 data:2 |
Transfer PDF p. 14, [data:2:transfer] | Supply Chain – Models |
BIML78 data:6 |
Supervisor PDF p. 15, [data:6:supervisor] | Targeted Poisoning / Label Poisoning |
BIML78 eval:5 |
Catastrophic Forgetting PDF p. 18, [eval:5:catastrophic forgetting] | Model Drift & Degradation |
BIML78 inference:3 |
Confidence Scores PDF p. 20, [inference:3:confidence scores] | Adversarial InputsModel Reconnaissance |
BIML78 inference:4 |
Hosting PDF p. 20, [inference:4:hosting] | Supply Chain – Infrastructure |
BIML78 inference:5 |
User Risk PDF p. 20, [inference:5:user risk] | Sensitive Information DisclosureShadow AI (Unsanctioned AI Service Use) |
BIML78 input:1 |
Adversarial Examples PDF p. 19, [input:1:adversarial examples] | Adversarial Inputs |
BIML78 input:2 |
Controlled Input Stream PDF p. 19, [input:2:controlled input stream] | Adversarial Inputs |
BIML78 model:2 |
Trojan PDF p. 20, [model:2:Trojan] | Backdoor ML Model |
BIML78 model:5 |
Steal the Box PDF p. 20, [model:5:steal the box] | Model Theft |
BIML78 raw:1 |
Data Confidentiality PDF p. 10, [raw:1:data confidentiality] | Privacy Attacks |
BIML78 raw:2 |
Trustworthiness PDF p. 10, [raw:2:trustworthiness] | Supply Chain – DatasetsTraining Data Poisoning |
BIML78 raw:3 |
Storage PDF p. 10, [raw:3:storage] | Supply Chain – InfrastructureExfiltration from ML Application |
BIML78 system:1 |
Black Box Discrimination PDF p. 25, [system:1:black box discrimination] | Hate Speech and Discrimination |
BIML78 system:10 |
Denial of Service PDF p. 26, [system:10:denial of service] | Model Denial of ServiceApplication Denial of Service |
BIML78 system:2 |
Overconfidence PDF p. 25, [system:2:overconfidence] | Overreliance |
BIML78 system:5 |
Error Propagation PDF p. 25, [system:5:error propagation] | Agentic AI / Autonomous Agents |
BIML78 system:8 |
Insider PDF p. 26, [system:8:insider] | Exfiltration from ML Application |
BIML78 system:9 |
API Encoding PDF p. 26, [system:9:API encoding] | Insecure Output HandlingApplication Vulnerabilities |
This page does not reproduce the text of the standards. It states the identifier, title and location of the clause; the wording itself is in the original document. The mappings are taxonomic and not evidence of compliance.
Threats referencing this document (21)
Grouped by topic. Every entry leads to the full threat page.
Agentic and Autonomous AI
Application and Integration Security
Attacks on the Running Model and Service
Harmful Content
Model and Training Data Manipulation
Privacy and Data Leakage
Reliability and Responsible Use
Supply Chain and Provenance
More documents from the same publisher
All documents by Berryville Institute of Machine Learning (BIML) cited in the catalogue.
From the reference to the assessment
The full catalogue states the mitigations, the possible impact and every verified location for each threat. The live demo runs locally in your browser, with no sign-up.
Cite this page
For reports, policies or internal documents; the link leads directly to this source page.
“An Architectural Risk Analysis of Machine Learning Systems: Toward More Secure Machine Learning” (Berryville Institute of Machine Learning (BIML)). References in the AI threat catalogue, Versatile AI Risk Assessment, as of July 2026. https://www.versatile-ai-risk-assessment.com/en/wissensbasis/sources/biml-architectural-risk-analysis-machine-learning/