Skip to main content
Category: Adversarial Security

MITRE ATLAS

Also known as: ATLAS, Adversarial Threat Landscape for Artificial-Intelligence Systems, ATLAS Matrix
Simply put

MITRE ATLAS is a publicly available, continuously updated knowledge base that catalogs the tactics and techniques adversaries use to attack AI-enabled systems, drawing on real-world attack observations. It is maintained by MITRE and is intended to help organizations understand and defend against threats specific to AI systems. It functions as a reference resource rather than a binding regulation or standard.

Formal definition

MITRE ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems) is described in the evidence as a globally accessible, living knowledge base of adversary tactics and techniques against AI-enabled systems, based on real-world attack observations and realistic scenarios. It is structured in part through an 'ATLAS Matrix' that organizes these tactics and techniques, and it is presented as a tool to support identifying and addressing vulnerabilities in AI systems. As commonly used, ATLAS supports AI security threat modeling and defensive planning; it is a reference framework rather than a compliance mandate, and the evidence does not establish it as a legally binding instrument. Note that ATLAS is scoped to adversarial threats against AI systems and is distinct from broader AI governance frameworks or model risk management guidance, which address organizational oversight and non-adversarial model risks respectively; the evidence provided does not detail ATLAS's internal taxonomy beyond the tactics/techniques and matrix concepts referenced.

Why it matters

As organizations deploy AI-enabled systems, they face a class of threats that traditional security frameworks were not designed to capture. MITRE ATLAS matters because it provides a shared, continuously updated vocabulary for the tactics and techniques adversaries use against AI systems specifically, drawing on real-world attack observations rather than purely hypothetical concerns. This gives security teams, model risk practitioners, and AI governance functions a common reference point for reasoning about AI-specific attack surfaces, which can otherwise be difficult to articulate and compare across teams.

Who it's relevant to

AI Security and Red Teams
Security practitioners can use ATLAS as a structured reference for AI-specific adversary tactics and techniques when conducting threat modeling, red-team exercises, or defensive planning. Because it draws on real-world attack observations, it offers a common vocabulary for describing and prioritizing AI-specific attack surfaces.
Model Risk Managers
For those managing model risk, ATLAS can serve as one input for understanding adversarial threats to models in production. It is worth noting that ATLAS is scoped to adversarial threats and does not, on its own, address the broader non-adversarial model risks—such as performance degradation, data quality, or model misuse—that model risk management typically covers.
AI Governance and Compliance Functions
Governance and compliance teams can reference ATLAS to inform risk assessments and to demonstrate awareness of AI-specific threat landscapes. Because the evidence does not establish ATLAS as a binding regulation or certifiable standard, it should be treated as a reference resource that supports, rather than substitutes for, governance policies, accountability structures, and any applicable regulatory obligations.
Auditors and Assurance Providers
Auditors reviewing AI system controls may use ATLAS as a reference for the kinds of adversarial threats an organization should have considered. Because it is a knowledge base rather than a control catalog, evidence of ATLAS use is best interpreted as an indication of threat awareness rather than proof of a completed control framework.

Inside ATLAS

Adversarial Threat Landscape
MITRE ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems) is a knowledge base that catalogs adversary tactics and techniques observed or demonstrated against AI-enabled and machine learning systems. It is maintained by MITRE and is publicly available; treat it as a reference resource rather than a binding regulatory instrument.
Tactics
High-level adversary objectives or goals across the lifecycle of an attack on an AI system (for example, reconnaissance, initial access, or exfiltration of a model). Tactics describe the 'why' of an adversary action and are typically arranged to reflect stages of an attack.
Techniques (and sub-techniques)
The specific methods adversaries use to achieve a tactic against an ML or AI system, such as evasion, data poisoning, or model extraction. Techniques describe the 'how' and provide the practical detail practitioners map threats to.
Structure modeled on ATT&CK
ATLAS is commonly described as adapting the structure and philosophy of MITRE ATT&CK to the AI/ML domain, extending threat-modeling concepts to attacks that target models, training data, and ML pipelines. It is distinct from ATT&CK and scoped to AI-specific threats.
Case studies
ATLAS typically includes documented real-world or demonstrated incidents illustrating how techniques have been applied against AI systems, intended to help practitioners understand attack chains in context rather than as an exhaustive record of all incidents.

Common questions

Answers to the questions practitioners most commonly ask about ATLAS.

Is MITRE ATLAS a regulatory requirement or compliance standard?
No. MITRE ATLAS is a knowledge base of adversarial tactics and techniques against machine learning systems, curated by MITRE. It is a reference resource rather than binding law, mandatory regulation, or a certifiable standard such as ISO/IEC 42001. Organizations may voluntarily use it to inform threat modeling and security controls, but adopting it does not by itself demonstrate compliance with any specific regulatory framework.
Is MITRE ATLAS the same thing as MITRE ATT&CK?
They are related but distinct. ATT&CK catalogs adversary tactics and techniques for conventional enterprise IT and network systems, while ATLAS focuses specifically on threats targeting AI and machine learning systems. ATLAS is commonly described as modeled on and complementary to the ATT&CK structure, but conflating the two obscures the AI-specific attack surface—such as threats to training data, models, and inference pipelines—that ATLAS is intended to address. Treat them as separate resources with a shared conceptual framing.
How might an organization use MITRE ATLAS in threat modeling for an AI system?
Teams typically use ATLAS as a structured reference to enumerate potential adversarial tactics and techniques relevant to a given ML system, then map those against the system's data, model, and deployment components. This can help identify where controls may be needed. The scope of applicable techniques varies by system type and deployment context, so mappings should be tailored rather than applied wholesale.
Where does MITRE ATLAS fit relative to model risk management and AI governance activities?
ATLAS primarily informs the security dimension of AI risk—adversarial threats to ML systems—which overlaps with, but does not replace, broader model risk management concerns such as validation, performance monitoring, and model limitations. Within AI governance, it can be one input to risk identification, while accountability structures, policies, and oversight roles sit at the governance layer. Using ATLAS does not, by itself, satisfy either model risk management or governance obligations.
Which functions or lines of defense typically engage with MITRE ATLAS?
In practice, technical and security-focused teams often engage most directly with ATLAS when designing and testing controls, which commonly aligns with first-line activities. Second-line functions may reference it when reviewing risk coverage, and auditors or independent reviewers may consider whether relevant threat categories were considered. The precise assignment of responsibilities depends on an organization's operating model and is not prescribed by ATLAS itself.
What are the limitations of relying on MITRE ATLAS?
ATLAS is a curated, evolving knowledge base rather than an exhaustive or static inventory; new adversarial techniques may emerge that are not yet represented, and coverage may not map neatly onto every ML architecture or deployment context. It documents threats and techniques but does not prescribe specific controls, testing procedures, or acceptance criteria. Because it addresses the adversarial security dimension, it should be combined with other resources to cover the full range of model risk and governance considerations.

Common misconceptions

MITRE ATLAS is a regulatory standard or compliance requirement that organizations must adopt.
ATLAS is a publicly available knowledge base and threat-modeling reference maintained by MITRE, not binding law, mandatory guidance, or a certifiable standard. It can inform security and risk practices but does not by itself impose obligations, and it is distinct from frameworks such as the NIST AI RMF or ISO/IEC 42001.
ATLAS covers all aspects of AI governance and model risk management.
ATLAS is focused on the adversarial threat landscape—tactics and techniques used to attack AI systems—which is a security-oriented concern. It does not comprehensively address broader AI governance structures (accountability, oversight, policy) or the full scope of model risk management activities such as model validation, performance monitoring, and residual risk assessment, though it may complement them.
ATLAS is simply MITRE ATT&CK applied to AI, so ATT&CK knowledge alone is sufficient.
While ATLAS is commonly described as adapting the ATT&CK structure, it is a separate resource scoped to AI/ML-specific threats such as data poisoning and model extraction. Treating it as interchangeable with ATT&CK risks overlooking attack surfaces unique to models, training data, and ML pipelines.

Best practices

Use ATLAS as one input to AI-specific threat modeling, mapping identified tactics and techniques to your own model deployment, data pipeline, and access points rather than assuming the catalog is exhaustive.
Keep ATLAS-driven security analysis distinct from, but coordinated with, broader model risk management activities such as validation, monitoring, and residual risk assessment, so that adversarial threats are addressed without conflating security with performance or governance concerns.
Treat ATLAS as a reference resource, not a compliance checklist; document how any ATLAS-informed controls relate to the frameworks (for example NIST AI RMF or ISO/IEC 42001) that actually govern your obligations.
Review the ATLAS case studies to understand realistic attack chains against AI systems, while recognizing they illustrate rather than enumerate all possible threats.
Revisit ATLAS periodically, since the adversarial threat landscape for AI evolves and the knowledge base is updated over time; do not rely on a one-time assessment.
Describe controls derived from ATLAS as measures that reduce or manage adversarial risk, not as measures that eliminate it, and record residual risk explicitly.