Versatile AI Risk Assessment

AI threat cataloguePrivacy and Data LeakageProduction

Exfiltration from ML Application

Attackers or insiders copy data, model weights or configurations straight out of a production AI application without authorisation, exploiting software bugs, misconfigurations or legitimate access.

As of: July 2026 · Catalogue version 2026.07.17.3 · 5 mitigations · 17 verified sources

Description

Unlike attacks that work through the model's answers, this threat turns the application and its infrastructure into the target. Attackers exploit application vulnerabilities, openly reachable storage and interfaces, stolen credentials or insider access to siphon off training data, stored documents, chat histories, model weights or system configurations. In addition, the model itself can become the tool: through prompt injection, meaning smuggled-in instructions, attackers make it send confidential content to an address they control. The exposure lies in live operation, where the application works with real data.

Possible impact

The threat is large-scale data loss: customer data, trade secrets and internal documents, all in one stroke. Stolen model weights mean losing expensively developed intellectual property; stolen configurations and credentials enable follow-up attacks. Where personal data is affected, GDPR notification duties and fines apply, on top of recovery costs and reputational damage.

Example

A company runs its model store in the cloud but leaves it accessible without a login. One security study found more than 8,000 such openly accessible stores (container registries) on the internet, from which over 1,000 AI models could be downloaded or even modified.

Recommended mitigations (5)

Every mitigation states its control type, effect, implementation level and the reason for the classification.

Framework mappings

Verified locations in OWASP, NIST AI RMF, MITRE ATLAS, the EU AI Act and further frameworks. The mappings are taxonomic, not evidence of compliance.

OWASP LLM Top 10 LLM02:2025NIST AI RMF Section 2.4 · Section 2.9 · MEASURE 2.10 · NISTAML.015 · NISTAML.036 · NISTAML.039MITRE ATLAS AML.T0024 · AML.T0025EU AI Act Article 13(1), 13(3)(b)(ii), (iv), (v) · Article 55(1)(d) · Article 9(1), 9(2)(a), 9(2)(d)GDPR Article 25(1)–(2)BSI R2 · R28BIML BIML78 raw:3 · BIML78 system:8

Verified references (17)

Every reference states the framework, the exact location and the publishing organisation.

Terms on this page

Glossary terms that occur in this entry. Every link leads to the full explanation.

More entries from the topic group Privacy and Data Leakage.

Assess this threat in your own system

The live demo contains all 52 threats of this catalogue, including the EU AI Act and GDPR assessment. The free single modules cover AI risk, the EU AI Act and GDPR. No sign-up; the assessment runs locally in your browser.

Cite this entry

For reports, policies or internal documents; the link leads directly to this entry.

“Exfiltration from ML Application”. Versatile AI Risk Assessment, AI threat catalogue, as of July 2026.
https://www.versatile-ai-risk-assessment.com/en/wissensbasis/threats/exfiltration-ml-application/

← Back to the full catalogue