Source directoryNational Institute of Standards and Technology (NIST)NIST AI 100-2e2025
Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations
“Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations”. Publisher: National Institute of Standards and Technology (NIST). Version used: NIST AI 100-2e2025. The Versatile AI Risk Assessment threat catalogue backs 29 of its 52 threats with this document, at 23 verified locations.
Document details
- Publisher
- National Institute of Standards and Technology (NIST)
- Version used
- NIST AI 100-2e2025
- Year
- not stated
- Licence
- not stated
- Framework
- NIST AI RMF
Open the original document at the publisher External link; the publisher’s version always takes precedence.
References in the catalogue (23)
Every row states the clause, its title, the exact location in the document and the threats that refer to it.
| Clause | Title and location | Referencing threats |
|---|---|---|
NISTAML.012 |
Clean-label Poisoning Taxonomy Index, p. x; Section 2.3.1, p. 20; related clean-label targeted attacks in Section 2.3.2, p. 21 | Training Data PoisoningTargeted Poisoning / Label Poisoning |
NISTAML.013 |
Data Poisoning Taxonomy Index, pp. x–xi; Section 2.3.1, p. 19; Section 3.2.1, p. 42 | Training Data Poisoning |
NISTAML.014 |
Energy-latency Taxonomy Index, p. x; Section 2.1.2, p. 6; Glossary, p. 108 | Model Denial of Service |
NISTAML.015 |
Indirect Prompt Injection Taxonomy Index, pp. x–xi; Section 3.4, pp. 50–53; Glossary, p. 110 | Prompt Injection – IndirectExfiltration from ML ApplicationRAG-Specific Attacks (Document Poisoning)Cross-Tenant Leakage (Multi-Tenant Vector DB)MCP Hijacking (Model Context Protocol)Graph-RAG Poisoning (Knowledge Graph Injection) |
NISTAML.018 |
Prompt Injection Taxonomy Index, pp. x–xi; Section 3.3, pp. 43–49; Glossary, p. 111 | Prompt Injection – DirectMeta Prompt Extraction |
NISTAML.021 |
Clean-label Backdoor Taxonomy Index, p. x; Section 2.3.3, pp. 22–25 | Backdoor ML Model |
NISTAML.022 |
Evasion Taxonomy Index, p. x; Section 2.2, pp. 11–18 | Adversarial InputsMultimodal Attacks |
NISTAML.023 |
Backdoor Poisoning Taxonomy Index, pp. x–xi; Section 2.3.3, pp. 22–25; Section 3.2.1–3.2.2, p. 42 | Backdoor ML ModelSleepy Agent (Time/Event-Triggered Hidden Instructions) |
NISTAML.024 |
Targeted Poisoning Taxonomy Index, pp. x–xi; Section 2.3.2, p. 21; Section 3.2.1, p. 42 | Targeted Poisoning / Label Poisoning |
NISTAML.025 |
Black-box Evasion Taxonomy Index, p. x; Section 2.2.2, p. 15 | Adversarial InputsMultimodal Attacks |
NISTAML.026 |
Model Poisoning Taxonomy Index, p. x; Section 2.3.4, p. 26 | Supply Chain – ModelsBackdoor ML Model |
NISTAML.027 |
Misaligned Outputs Taxonomy Index, p. xi; Section 3.4.2, pp. 51–52 | RAG-Specific Attacks (Document Poisoning)Graph-RAG Poisoning (Knowledge Graph Injection) |
NISTAML.031 |
Model Extraction Taxonomy Index, p. x; Section 2.4.4, pp. 31–32; Section 3.3.2, p. 47 | Model TheftModel ReconnaissanceSide-Channel Attacks (Timing Analysis) |
NISTAML.032 |
Reconstruction Taxonomy Index, p. x; Section 2.4.1, pp. 28–29 | Privacy AttacksSensitive Information Disclosure |
NISTAML.033 |
Membership Inference Taxonomy Index, p. x; Section 2.4.2, pp. 29–30 | Privacy Attacks |
NISTAML.035 |
Prompt Extraction Taxonomy Index, p. xi; Section 3.3.2, pp. 46–47; Glossary, p. 111 | Meta Prompt ExtractionSensitive Information Disclosure |
NISTAML.036 |
Leaking information from user interactions Taxonomy Index, p. xi; Section 3.4.3, pp. 52–53 | Exfiltration from ML ApplicationCross-Tenant Leakage (Multi-Tenant Vector DB) |
NISTAML.038 |
Data Extraction Taxonomy Index, p. xi; Section 3.3.2, pp. 46–47 | Privacy AttacksSensitive Information Disclosure |
NISTAML.039 |
Compromising connected resources Taxonomy Index, p. xi; Section 3.4.3, pp. 52–53 | Exfiltration from ML ApplicationMCP Hijacking (Model Context Protocol) |
NISTAML.04 |
Misuse Violations Taxonomy Index, p. xi; Section 3.1.2, p. 40 | Jailbreaks |
NISTAML.05 |
Supply Chain Attacks Taxonomy Index, pp. x–xi; Section 3.2, pp. 41–43 | Supply Chain – InfrastructureSupply Chain – DatasetsMiddleware Exploits (AI Framework Attacks)Shadow AI (Unsanctioned AI Service Use) |
NISTAML.051 |
Model Poisoning Taxonomy Index, p. xi; Section 3.2.2, p. 42 | Supply Chain – ModelsBackdoor ML ModelSleepy Agent (Time/Event-Triggered Hidden Instructions) |
Section 3.5 |
Security of Agents Section 3.5, p. 54 | Insecure Tool DesignExcessive AgencyAgentic AI / Autonomous AgentsMCP Hijacking (Model Context Protocol) |
This page does not reproduce the text of the standards. It states the identifier, title and location of the clause; the wording itself is in the original document. The mappings are taxonomic and not evidence of compliance.
Threats referencing this document (29)
Grouped by topic. Every entry leads to the full threat page.
Agentic and Autonomous AI
Application and Integration Security
Attacks on the Running Model and Service
Model and Training Data Manipulation
Privacy and Data Leakage
Prompt Attacks and Guardrail Evasion
Reliability and Responsible Use
Supply Chain and Provenance
More documents from the same publisher
All documents by National Institute of Standards and Technology (NIST) cited in the catalogue.
From the reference to the assessment
The full catalogue states the mitigations, the possible impact and every verified location for each threat. The live demo runs locally in your browser, with no sign-up.
Cite this page
For reports, policies or internal documents; the link leads directly to this source page.
“Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations” (National Institute of Standards and Technology (NIST)). References in the AI threat catalogue, Versatile AI Risk Assessment, as of July 2026. https://www.versatile-ai-risk-assessment.com/en/wissensbasis/sources/nist-ai-100-2-adversarial-machine-learning/