AML.T0063
MITRE ATLAS / Discover AI Model Outputs
Adversaries obtain model outputs that are not required for the system to function and are not intended for end users, such as class confidence scores, logits, or embedding vectors.
In plain English
Confidence scores and raw logits leak far more than a label does. Returning them makes model extraction and evasion much cheaper for anyone querying the API.