DARR
MR-014 Security & adversarial System scope

Data and model poisoning and backdoors

Adversaries corrupt training/fine-tuning data or implant backdoors/trojans that alter model behavior under triggers.

Risk family
Security & adversarial
MIT domain
2. Privacy & Security
MIT subdomain
2.2 > AI system security vulnerabilities and attacks
AI type
GPAI, Classical_ML, Agentic
Scope
System
Source standard
MIT AI Risk Repository v4

Provenance

Source standard
MIT AI Risk Repository v4
MIT source entries
16 entries across 9 papers
  • Cui2024Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems02.10.03 02.10.05
  • Gipiškis2024Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems62.14.01 62.14.04 62.15.06 62.15.07 62.19.04
  • Hammond2025Multi-Agent Risks from Advanced AI63.10.06
  • IBM2025AI Risk Atlas65.08.01
  • Liu2024Trustworthy LLMs: A Survey and Guideline for Evaluating Large Language Models’ Alignment30.07.04
  • Marchal2024Generative AI Misuse: A Taxonomy of Tactics and Insights from Real-World Data64.04.07
  • Schnitzer2024AI Hazard Management: A Framework for the Systematic Management of Root Causes for AI Risks59.12.00
  • Tang2025Risks of AI Scientists: Prioritizing Safeguarding Over Autonomy71.01.05
  • TC2602024AI Safety Governance Framework45.01.04 45.01.08 45.01.11

Ev IDs of the entries consolidated into this risk in the MIT AI Risk Repository (V4); the source sheet row appears on hover.

ISO/IEC references
23894 obj A.11; src 6, 10; mech B.5 | 42001 ctrl A.7.3, A.7.5

Framework crosswalk

Every framework item mapped to this risk. Items marked partial overlap only in part; definitions appear on hover where the source licence permits.

Sourcesframeworks that contributed to the register
1
  • A.11 ISO/IEC 23894 Annex A A.11
2
  • A.7.3 ISO/IEC 42001 Annex A A.7.3
  • A.7.5 ISO/IEC 42001 Annex A A.7.5
7

Expanded into this risk’s technique sub-risks.

Cross-checksframeworks mapped in to test coverage
1
  • ibm-data-poisoning Data poisoning
6
  • AISubtech-6.1.1 Knowledge Base Poisoning
  • AISubtech-6.1.2 Reinforcement Biasing
  • AISubtech-6.1.3 Reinforcement Signal Corruption
  • AISubtech-7.3.1 Corrupted Third-Party Data
  • AISubtech-9.2.1 Obfuscation Vulnerabilities
  • AISubtech-9.2.2 Backdoors and Trojans
10
  • NISTAML.011 Model Poisoning (availability)
  • NISTAML.012 Clean-label Poisoning
  • NISTAML.013 Data Poisoning
  • NISTAML.02 Integrity Violations
  • NISTAML.021 Clean-label Backdoor
  • NISTAML.023 Backdoor Poisoning
  • NISTAML.024 Targeted Poisoning
  • NISTAML.026 Model Poisoning (integrity)
  • NISTAML.05 Supply Chain Attacks
  • NISTAML.051 Model Poisoning (supply chain)
1
  • LLM04:2025 Data and Model Poisoning

Sub-risks (4)

Technique-level decompositions of this risk, each anchored to the MITRE ATLAS technique it derives from.

MR-014.1

Direct model manipulation and backdoor insertion

#

The model is altered directly to change its behavior or embed a hidden backdoor trigger.

MITRE ATLAS technique: AML.T0018 Manipulate AI Model
MR-014.2

Poisoned datasets published for ingestion

#

Poisoned datasets are placed where the deployer is likely to collect and train on them.

MITRE ATLAS technique: AML.T0019 Publish Poisoned Datasets
MR-014.3

Training-data poisoning

#

Adversaries modify training or fine-tuning data to degrade the model or implant chosen behavior.

MITRE ATLAS technique: AML.T0020 Poison Training Data
MR-014.4

Dataset integrity erosion

#

Portions of a dataset are poisoned or altered to reduce its usefulness and reliability.

MITRE ATLAS technique: AML.T0059 Erode Dataset Integrity

Part of the Deployer AI Risk Register, an open-source resource powered by MindXO. Version 1.0, 3 July 2026. Derived from the MIT AI Risk Repository (V4, December 2025) under CC BY 4.0; an independent derivative work, not endorsed by or affiliated with MIT. Sub-risk decomposition references MITRE ATLAS™ v5.6.0 (© 2021-2026 The MITRE Corporation, reproduced and distributed with permission). ISO/IEC and EU AI Act references are by number only. License: CC BY 4.0. Full attribution and licensing.