← AI security in plain English

AML.T0013

MITRE ATLAS / Discover AI Model Ontology

Adversaries determine the ontology of a model's output space, such as the set of classes it can predict or the types of object it detects, usually by observing responses to varied inputs.

Think of it likeWorking out the full menu by ordering enough different things to see what the kitchen can make.

In plain English

Knowing every label a model can output tells an attacker what to aim for. You cannot craft an input that forces a specific misclassification until you know which classes exist.