Versatile AI Risk Assessment

AI threat cataloguePrivacy and Data LeakageProduction

Privacy Attacks

Attackers coax personal or sensitive information about the training data out of an AI model through carefully crafted queries, for example whether a specific person's data was used to train it.

As of: July 2026 · Catalogue version 2026.07.17.3 · 5 mitigations · 19 verified sources

Description

An AI model retains traces of its training data. Attackers exploit this by querying the model systematically through its normal input interface and analysing the answers statistically; they do not need to break into the IT environment. With membership inference they determine whether a specific person's data was part of the training set. With model inversion they reconstruct typical training content, such as a face from a facial recognition model. With attribute inference they derive sensitive characteristics of a person that the system was never meant to reveal. Even supposedly anonymised data sets can be linked back to specific individuals with AI support (re-identification).

Possible impact

The organisation breaches the confidentiality of personal data without any conventional intrusion, which can trigger notification duties, fines and claims by data subjects under the GDPR. Merely proving that a person was in the training data can harm them, for example with health data. Moreover, an AI model only counts as anonymous under data protection law if such attacks, carried out with reasonable means, are likely to fail; otherwise the model itself remains subject to the GDPR.

Example

A clinic trains a prediction model on patient data and offers it as an online service. Through targeted queries an attacker can prove that a specific person belonged to the study group for a rare disease, even though the model never outputs the person's name.

Recommended mitigations (5)

Every mitigation states its control type, effect, implementation level and the reason for the classification.

Framework mappings

Verified locations in OWASP, NIST AI RMF, MITRE ATLAS, the EU AI Act and further frameworks. The mappings are taxonomic, not evidence of compliance.

OWASP LLM Top 10 LLM02:2025NIST AI RMF Section 2.4 · Section 2.9 · MEASURE 2.10 · NISTAML.032 · NISTAML.033 · NISTAML.038MITRE ATLAS AML.T0024.000 · AML.T0024.001EU AI Act Article 55(1)(a)GDPR Article 25(1)–(2) · EDPB Opinion 28/2024, Section 3.2BSI R13 · R2 · R22 · R23BIML BIML-LLM model:6 · BIML-LLM raw:5 · BIML78 raw:1

Verified references (19)

Every reference states the framework, the exact location and the publishing organisation.

More entries from the topic group Privacy and Data Leakage.

Assess this threat in your own system

The live demo contains all 52 threats of this catalogue, including the EU AI Act and GDPR assessment. The free single modules cover AI risk, the EU AI Act and GDPR. No sign-up; the assessment runs locally in your browser.

Cite this entry

For reports, policies or internal documents; the link leads directly to this entry.

“Privacy Attacks”. Versatile AI Risk Assessment, AI threat catalogue, as of July 2026.
https://www.versatile-ai-risk-assessment.com/en/wissensbasis/threats/privacy-attacks/

← Back to the full catalogue