Versatile AI Risk Assessment

AI threat catalogueAttacks on the Running Model and ServiceProduction

Model Reconnaissance

Attackers gather information about a deployed model, such as its design, the model family used and its capabilities, to prepare more targeted attacks later. This is the reconnaissance phase before theft or evasion.

As of: July 2026 · Catalogue version 2026.07.17.3 · 6 mitigations · 12 verified sources

Description

Before a targeted attack, attackers scout out the deployed model. Through the normal interface they probe which model family and version lies behind it (fingerprinting), which architecture is likely in use, and what capabilities and output categories the model has. To do so they analyse answers, accompanying metadata, verbose error messages or publicly accessible artefacts. This reconnaissance is usually not an end in itself but the precursor to model theft or to adversarial inputs that are then tailored precisely.

Possible impact

The immediate damage is small, but the insights gained make follow-on attacks considerably more effective and harder to defend against. Once the underlying model family is identified, known weaknesses of that family can be exploited in a targeted way, especially since many services build on the same base models. At the same time, internal model and configuration details can leak as trade secrets.

Example

An attacker sends an AI service a series of systematic test questions and analyses phrasing, response times and error messages. From this they infer the base model in use and aim their next attack squarely at its known weaknesses.

Recommended mitigations (6)

Every mitigation states its control type, effect, implementation level and the reason for the classification.

Framework mappings

Verified locations in OWASP, NIST AI RMF, MITRE ATLAS, the EU AI Act and further frameworks. The mappings are taxonomic, not evidence of compliance.

OWASP LLM Top 10 LLM02:2025 · LLM10:2025NIST AI RMF NISTAML.031MITRE ATLAS AML.T0002 · AML.T0014 · AML.T0040EU AI Act Article 55(1)(d)BSI R12 · R25BIML BIML-LLM input:3 · BIML78 assembly:6 · BIML78 inference:3

Verified references (12)

Every reference states the framework, the exact location and the publishing organisation.

More entries from the topic group Attacks on the Running Model and Service.

Assess this threat in your own system

The live demo contains all 52 threats of this catalogue, including the EU AI Act and GDPR assessment. The free single modules cover AI risk, the EU AI Act and GDPR. No sign-up; the assessment runs locally in your browser.

Cite this entry

For reports, policies or internal documents; the link leads directly to this entry.

“Model Reconnaissance”. Versatile AI Risk Assessment, AI threat catalogue, as of July 2026.
https://www.versatile-ai-risk-assessment.com/en/wissensbasis/threats/model-reconnaissance/

← Back to the full catalogue