NIST AI 100-2 (Adversarial ML Taxonomy)
NIST AI 100-2 is a report published by the U.S. National Institute of Standards and Technology (NIST) that organizes and defines the terminology used to describe attacks against machine learning systems and the methods used to defend against them. It is intended as voluntary guidance rather than binding law, giving practitioners a shared vocabulary for discussing how AI systems can be manipulated or compromised. Because it is a taxonomy, its main purpose is to classify concepts consistently rather than to impose specific requirements.
NIST AI 100-2, titled 'Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations,' is a NIST Trustworthy and Responsible AI report (authored by A. Vassilev et al.) that develops a taxonomy of concepts and standardizes terminology in the field of adversarial machine learning (AML). It provides a structured classification of attack types and corresponding mitigations to support common understanding across the AML community. The document exists in multiple editions (including the E2023 and E2025 versions), and NIST characterizes it as voluntary guidance. As a taxonomy and terminology reference, its scope is definitional and organizational; it is distinct from prescriptive control frameworks and, based on the evidence provided, does not itself establish binding regulatory obligations. Practitioners should consult the specific edition and its publication details directly, as the evidence here does not enumerate the individual attack or mitigation categories.
Why it matters
Adversarial machine learning is a fast-moving field in which researchers, vendors, and defenders often describe the same attack or defense using different labels, creating confusion that can undermine risk assessment and communication. NIST AI 100-2 addresses this by providing a shared taxonomy and standardized terminology, which matters because inconsistent language makes it harder for organizations to compare threats, coordinate mitigations, and articulate risk to oversight functions. A common vocabulary supports clearer conversations among data scientists, security teams, model risk managers, and governance stakeholders who may otherwise talk past one another.
For practitioners, the value of the report lies in its definitional and organizational role rather than in any set of enforceable requirements. As NIST characterizes it, AI 100-2 is voluntary guidance, so it does not itself impose binding regulatory obligations. It can nonetheless inform how organizations frame AI security risks, structure threat models, and document the attacks and mitigations relevant to their machine learning systems. Because it is a taxonomy, it helps organizations organize their thinking, but it does not substitute for prescriptive control frameworks or for jurisdiction-specific legal obligations.
The report exists in multiple editions, including the E2023 and E2025 versions, reflecting the evolving nature of the field. Practitioners should treat the taxonomy as a reference point that is updated over time rather than a fixed or final catalog, and should consult the specific edition and its publication details directly, since the terminology and organization of concepts may change between editions.
Who it's relevant to
Inside NIST AI 100-2
Common questions
Answers to the questions practitioners most commonly ask about NIST AI 100-2.