← AI security in plain English

AML.T0109

MITRE ATLAS / AI Supply Chain Rug Pull

Adversaries publish legitimate AI components or software, wait for genuine adoption, then ship an update containing a malicious variant, compromising every downstream system that takes the update.

Think of it likeRunning an honest bakery for two years to build the queue, then selling one bad batch on purpose.

In plain English

Trust is earned and then spent. A package or model that has been safe for a dozen releases gets updated without scrutiny, which is exactly what makes the poisoned release effective.