Skip to main content
Category: Adversarial Security

NIST AI 100-2 (Adversarial ML Taxonomy)

Also known as: NIST AI 100-2, Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations, AI 100-2 E2025, AI 100-2 E2023, NIST AML Taxonomy
Simply put

NIST AI 100-2 is a report published by the U.S. National Institute of Standards and Technology (NIST) that organizes and defines the terminology used to describe attacks against machine learning systems and the methods used to defend against them. It is intended as voluntary guidance rather than binding law, giving practitioners a shared vocabulary for discussing how AI systems can be manipulated or compromised. Because it is a taxonomy, its main purpose is to classify concepts consistently rather than to impose specific requirements.

Formal definition

NIST AI 100-2, titled 'Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations,' is a NIST Trustworthy and Responsible AI report (authored by A. Vassilev et al.) that develops a taxonomy of concepts and standardizes terminology in the field of adversarial machine learning (AML). It provides a structured classification of attack types and corresponding mitigations to support common understanding across the AML community. The document exists in multiple editions (including the E2023 and E2025 versions), and NIST characterizes it as voluntary guidance. As a taxonomy and terminology reference, its scope is definitional and organizational; it is distinct from prescriptive control frameworks and, based on the evidence provided, does not itself establish binding regulatory obligations. Practitioners should consult the specific edition and its publication details directly, as the evidence here does not enumerate the individual attack or mitigation categories.

Why it matters

Adversarial machine learning is a fast-moving field in which researchers, vendors, and defenders often describe the same attack or defense using different labels, creating confusion that can undermine risk assessment and communication. NIST AI 100-2 addresses this by providing a shared taxonomy and standardized terminology, which matters because inconsistent language makes it harder for organizations to compare threats, coordinate mitigations, and articulate risk to oversight functions. A common vocabulary supports clearer conversations among data scientists, security teams, model risk managers, and governance stakeholders who may otherwise talk past one another.

For practitioners, the value of the report lies in its definitional and organizational role rather than in any set of enforceable requirements. As NIST characterizes it, AI 100-2 is voluntary guidance, so it does not itself impose binding regulatory obligations. It can nonetheless inform how organizations frame AI security risks, structure threat models, and document the attacks and mitigations relevant to their machine learning systems. Because it is a taxonomy, it helps organizations organize their thinking, but it does not substitute for prescriptive control frameworks or for jurisdiction-specific legal obligations.

The report exists in multiple editions, including the E2023 and E2025 versions, reflecting the evolving nature of the field. Practitioners should treat the taxonomy as a reference point that is updated over time rather than a fixed or final catalog, and should consult the specific edition and its publication details directly, since the terminology and organization of concepts may change between editions.

Who it's relevant to

AI security and machine learning engineers
Teams building or defending machine learning systems can use the taxonomy to describe adversarial threats and mitigations with consistent terminology, supporting clearer threat modeling and communication. The report is voluntary guidance and does not enumerate specific technical controls here, so engineers should consult the relevant edition directly for the concept definitions.
Model risk managers
Those responsible for identifying, measuring, and monitoring model risk may find the shared vocabulary useful when documenting AI security-related risks and coordinating with security functions. The taxonomy informs how risks are described and organized but does not itself establish requirements or replace an organization's model risk management processes.
AI governance and policy specialists
Governance stakeholders can reference the taxonomy to establish common language across organizational policies, oversight discussions, and cross-functional coordination on AI security. Because it is voluntary guidance rather than binding law, it should be positioned as a terminology reference rather than as a compliance obligation.
Auditors and assurance professionals
Auditors reviewing AI systems may use the standardized terminology to frame findings and communicate consistently with technical teams. The report is definitional in scope and does not, based on the evidence here, provide a prescriptive control set against which to test, so auditors should distinguish it from control frameworks and confirm the applicable edition.

Inside NIST AI 100-2

Adversarial Machine Learning Taxonomy
A structured classification of attacks against AI and machine learning systems, along with associated terminology and mitigation concepts. It is published by the U.S. National Institute of Standards and Technology (NIST) as a taxonomy and reference document rather than as binding law; it functions as informational guidance.
Attack Classification Dimensions
The taxonomy commonly organizes attacks along dimensions such as the attacker's goals or objectives, capabilities, and knowledge of the target system. These dimensions help practitioners characterize threats consistently rather than describing every possible exploit.
Categories of Attacks
The document typically distinguishes broad classes of adversarial threats, which may include evasion attacks (manipulating inputs at inference time), poisoning attacks (corrupting training data or the training process), and privacy or extraction attacks (inferring data or model parameters). Specific naming and grouping should be verified against the published version rather than assumed.
Terminology Standardization
A shared vocabulary intended to align how researchers, developers, and risk practitioners describe adversarial phenomena, reducing ambiguity across teams and disciplines.
Mitigation and Limitations Framing
Where addressed, the taxonomy tends to frame mitigations as measures that reduce or manage adversarial risk, while noting that many defenses have trade-offs and that no single control eliminates the underlying risk.

Common questions

Answers to the questions practitioners most commonly ask about NIST AI 100-2.

Is NIST AI 100-2 a regulation or a mandatory compliance requirement?
No. NIST AI 100-2 is a taxonomy and conceptual publication issued by the U.S. National Institute of Standards and Technology, not binding law. It describes and categorizes adversarial machine learning attacks and mitigations to establish shared terminology; it does not impose enforceable obligations. Organizations may reference it voluntarily to inform their own security practices, but adherence is not a legal mandate in itself.
Does NIST AI 100-2 provide a checklist of defenses that will secure a model against adversarial attacks?
Not as commonly assumed. The publication is primarily a taxonomy that organizes attack types, attacker goals, capabilities, and knowledge, along with categories of mitigations and their trade-offs. It is intended to create a common vocabulary and conceptual map rather than a prescriptive, guaranteed-secure defense checklist. As commonly framed, it acknowledges that many mitigations involve trade-offs and that no set of controls eliminates adversarial risk; they reduce or manage it.
How can we use NIST AI 100-2 to structure an adversarial threat assessment for a deployed model?
Teams typically use the taxonomy's dimensions, such as attacker goals, capabilities, and knowledge of the system, to frame threat scenarios systematically rather than ad hoc. Mapping your model's exposure against these categories can help identify which attack classes are plausible in your deployment context. This supports, but does not replace, your organization's own risk assessment methodology, and the taxonomy itself does not prescribe scoring or acceptance criteria.
Where does NIST AI 100-2 fit relative to model risk management and AI governance activities?
The taxonomy is generally used as a shared reference for the security-focused aspects of AI risk, informing how adversarial threats are identified and described. Within model risk management, it can support the identification and characterization of one category of risk arising from model use. Within AI governance, it can inform policies and oversight structures addressing model security. It does not, on its own, establish governance roles, validation processes, or control ownership; those remain the responsibility of the adopting organization.
Can NIST AI 100-2's terminology help teams communicate across data science, security, and compliance functions?
Yes, that is one of its central purposes as commonly described. By providing consistent terminology for adversarial ML attacks and mitigations, it can reduce ambiguity when technical, security, and compliance stakeholders discuss threats. Adopting its vocabulary internally may improve the clarity of threat documentation and reporting, though organizations still need to map the shared terms to their own processes and roles.
How should we handle the mitigation trade-offs that NIST AI 100-2 describes when selecting controls?
The taxonomy, as commonly framed, notes that mitigations often involve trade-offs, such as effects on model performance or robustness against different attack classes. In practice, teams weigh these trade-offs against their specific deployment context and risk tolerance rather than treating any single mitigation as universally optimal. Decisions about which controls to apply, and acceptance of any residual risk, are made through the organization's own risk management process; the publication provides the conceptual categories, not the decision thresholds.

Common misconceptions

The NIST AI 100-2 taxonomy is a mandatory regulatory requirement that organizations must comply with.
It is issued by NIST as a taxonomy and reference resource, not as binding law. Its authority and applicability depend on how organizations, regulators, or contracts choose to adopt or reference it; it does not by itself impose legal obligations.
Adopting the taxonomy or implementing the mitigations it discusses makes an AI system secure against adversarial attacks.
The taxonomy is a classification and reference tool. Mitigations described in this space typically reduce or manage adversarial risk rather than eliminate it, and defenses often involve trade-offs. Using the taxonomy supports threat characterization; it does not guarantee security.
This adversarial ML taxonomy is interchangeable with broader AI governance or model risk management frameworks.
The taxonomy addresses the specific domain of adversarial threats to machine learning. It is not a substitute for AI governance structures (policies, accountability, oversight) or for model risk management practices (identifying, measuring, monitoring, and controlling model risk). It can inform the security-relevant portions of both without replacing either.

Best practices

Consult the specific published version of the NIST document to confirm the exact attack categories, terminology, and definitions before relying on them, rather than assuming a particular structure.
Use the taxonomy to standardize internal vocabulary so that data scientists, security teams, and risk practitioners describe adversarial threats consistently.
Map identified adversarial threats to your existing model risk management processes, treating adversarial robustness as one input to risk identification, measurement, and monitoring rather than as a standalone activity.
Frame any mitigations you adopt as measures that reduce or manage adversarial risk, and document their known trade-offs and limitations rather than presenting them as guarantees.
Distinguish the taxonomy's security-focused scope from your broader AI governance controls, and ensure accountability and oversight structures reference it without collapsing the two.
Periodically revisit the taxonomy and your threat assessments, since adversarial ML techniques and NIST's guidance in this area continue to evolve.