AML.T0115
MITRE ATLAS / Publish Poisoned AI Artifacts
Adversaries create or modify AI artifacts and publish them through public or shared distribution channels so downstream systems are compromised when they consume them. Poisoned datasets, models, and agent tools may carry malicious content, behaviors, code, or configuration, published as novel artifacts or as malicious variants of legitimate ones.
In plain English
Model hubs, dataset repositories, package registries, and tool directories are supply chains. An artifact published there with a familiar-looking name can be pulled into a hundred systems that never inspected it.