What is Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations?
NIST AI 100-2 develops a taxonomy and terminology for adversarial machine learning. It organizes concepts around ML methods and lifecycle stages, attacker objectives and knowledge, and mitigations. It is a vocabulary and analysis resource, not a maturity model or required control baseline.
Adversarial machine learning taxonomy should be assessed in the context of the system, data flows, identities, integrations, and decision consequences. A precise boundary helps owners evaluate the exposure without overstating what one control can achieve.
What is Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations used for?
Security architects, data scientists, and risk leaders can use it to make threat modeling and assessment language precise. It distinguishes poisoning, extraction, and inversion rather than collapsing them into “AI risk.” Teams must still translate the taxonomy into their model type, data flows, deployment architecture, and operational controls.
Leaders should define accountable ownership, test relevant failure conditions, and retain evidence for decisions and change review. The response depends on the use case, authority, data sensitivity, architecture, and operational capacity rather than a universal checklist.