Source directoryMITREv5.6.0
MITRE ATLAS data
“MITRE ATLAS data”. Publisher: MITRE. Version used: v5.6.0. The Versatile AI Risk Assessment threat catalogue backs 44 of its 52 threats with this document, at 28 verified locations.
Document details
- Publisher
- MITRE
- Version used
- v5.6.0
- Year
- not stated
- Licence
- not stated
- Framework
- MITRE ATLAS
Open the original document at the publisher External link; the publisher’s version always takes precedence.
References in the catalogue (28)
Every row states the clause, its title, the exact location in the document and the threats that refer to it.
| Clause | Title and location | Referencing threats |
|---|---|---|
AML.T0002 |
Acquire Public AI Artifacts ATLAS.yaml technique object with id AML.T0002 (pinned release v5.6.0) | Model Reconnaissance |
AML.T0010 |
AI Supply Chain Compromise ATLAS.yaml technique object with id AML.T0010 (pinned release v5.6.0) | Supply Chain – InfrastructureSupply Chain – ModelsSupply Chain – DatasetsMiddleware Exploits (AI Framework Attacks) |
AML.T0014 |
Discover AI Model Family ATLAS.yaml technique object with id AML.T0014 (pinned release v5.6.0) | Model Reconnaissance |
AML.T0015 |
Evade AI Model ATLAS.yaml technique object with id AML.T0015 (pinned release v5.6.0) | Adversarial InputsMultimodal Attacks |
AML.T0018 |
Manipulate AI Model ATLAS.yaml technique object with id AML.T0018 (pinned release v5.6.0) | Backdoor ML ModelSleepy Agent (Time/Event-Triggered Hidden Instructions) |
AML.T0020 |
Poison Training Data ATLAS.yaml technique object with id AML.T0020 (pinned release v5.6.0) | Training Data PoisoningTargeted Poisoning / Label PoisoningSleepy Agent (Time/Event-Triggered Hidden Instructions) |
AML.T0024 |
Exfiltration via AI Inference API ATLAS.yaml technique object with id AML.T0024 (pinned release v5.6.0) | Exfiltration from ML Application |
AML.T0024.000 |
Infer Training Data Membership ATLAS.yaml technique object with id AML.T0024.000 (pinned release v5.6.0) | Privacy Attacks |
AML.T0024.001 |
Invert AI Model ATLAS.yaml technique object with id AML.T0024.001 (pinned release v5.6.0) | Privacy Attacks |
AML.T0025 |
Exfiltration via Cyber Means ATLAS.yaml technique object with id AML.T0025 (pinned release v5.6.0) | Exfiltration from ML ApplicationCross-Tenant Leakage (Multi-Tenant Vector DB) |
AML.T0029 |
Denial of AI Service ATLAS.yaml technique object with id AML.T0029 (pinned release v5.6.0) | Model Denial of ServiceApplication Denial of Service |
AML.T0034 |
Cost Harvesting ATLAS.yaml technique object with id AML.T0034 (pinned release v5.6.0) | Cost Harvesting / Repurposing |
AML.T0040 |
AI Model Inference API Access ATLAS.yaml technique object with id AML.T0040 (pinned release v5.6.0) | Model TheftModel ReconnaissanceSide-Channel Attacks (Timing Analysis) |
AML.T0043 |
Craft Adversarial Data ATLAS.yaml technique object with id AML.T0043 (pinned release v5.6.0) | Multimodal Attacks |
AML.T0044 |
Full AI Model Access ATLAS.yaml technique object with id AML.T0044 (pinned release v5.6.0) | Model Theft |
AML.T0048 |
External Harms ATLAS.yaml technique object with id AML.T0048 (pinned release v5.6.0) | Insecure Output HandlingExcessive AgencyMCP Hijacking (Model Context Protocol) |
AML.T0048.002 |
Societal Harm ATLAS.yaml technique object with id AML.T0048.002 (pinned release v5.6.0) | Hate Speech and DiscriminationSexual ContentViolence / Unsafe ActionsControversial TopicsIllegal ActivitiesSelf-harmHarassmentUnethical ActionsSocial EngineeringFraudDisinformation |
AML.T0049 |
Exploit Public-Facing Application ATLAS.yaml technique object with id AML.T0049 (pinned release v5.6.0) | Application VulnerabilitiesMiddleware Exploits (AI Framework Attacks) |
AML.T0051 |
LLM Prompt Injection ATLAS.yaml technique object with id AML.T0051 (pinned release v5.6.0) | Agentic AI / Autonomous AgentsRAG-Specific Attacks (Document Poisoning)Multimodal AttacksMCP Hijacking (Model Context Protocol) |
AML.T0051.000 |
Direct ATLAS.yaml technique object with id AML.T0051.000 (pinned release v5.6.0) | Prompt Injection – Direct |
AML.T0051.001 |
Indirect ATLAS.yaml technique object with id AML.T0051.001 (pinned release v5.6.0) | Prompt Injection – Indirect |
AML.T0053 |
AI Agent Tool Invocation ATLAS.yaml technique object with id AML.T0053 (pinned release v5.6.0) | Insecure Tool DesignMCP Hijacking (Model Context Protocol) |
AML.T0054 |
LLM Jailbreak ATLAS.yaml technique object with id AML.T0054 (pinned release v5.6.0) | Jailbreaks |
AML.T0056 |
Extract LLM System Prompt ATLAS.yaml technique object with id AML.T0056 (pinned release v5.6.0) | Meta Prompt Extraction |
AML.T0057 |
LLM Data Leakage ATLAS.yaml technique object with id AML.T0057 (pinned release v5.6.0) | Sensitive Information DisclosureCross-Tenant Leakage (Multi-Tenant Vector DB) |
AML.T0073 |
Impersonation ATLAS.yaml technique object with id AML.T0073 (pinned release v5.6.0) | Insecure Inter-Agent Communication (A2A/MCP) |
AML.T0080.000 |
Memory ATLAS.yaml technique object with id AML.T0080.000 (pinned release v5.6.0) | Agent Memory Poisoning (Persistent Context) |
AML.T0110 |
AI Agent Tool Poisoning ATLAS.yaml technique object with id AML.T0110 (pinned release v5.6.0) | Insecure Inter-Agent Communication (A2A/MCP) |
This page does not reproduce the text of the standards. It states the identifier, title and location of the clause; the wording itself is in the original document. The mappings are taxonomic and not evidence of compliance.
Threats referencing this document (44)
Grouped by topic. Every entry leads to the full threat page.
Agentic and Autonomous AI
Application and Integration Security
Attacks on the Running Model and Service
Harmful Content
Malicious Use for Attacks, Fraud and Disinformation
Model and Training Data Manipulation
Privacy and Data Leakage
Prompt Attacks and Guardrail Evasion
Supply Chain and Provenance
From the reference to the assessment
The full catalogue states the mitigations, the possible impact and every verified location for each threat. The live demo runs locally in your browser, with no sign-up.
Cite this page
For reports, policies or internal documents; the link leads directly to this source page.
“MITRE ATLAS data” (MITRE). References in the AI threat catalogue, Versatile AI Risk Assessment, as of July 2026. https://www.versatile-ai-risk-assessment.com/en/wissensbasis/sources/mitre-atlas/