Skip to content

Adversarial Machine Learning

Adversarial AI needs a shared language before it needs another tool

Security teams and artificial intelligence (AI) teams can look at the same system and see different attack surfaces. One sees identities, networks, software dependencies, and data flows. The other sees training distributions, model behavior, embeddings, prompts, and evaluation drift.

The National Institute of Standards and Technology (NIST) publishes its adversarial machine-learning taxonomy on March 24 to create a more consistent vocabulary for attacks and mitigations across predictive and generative systems.

AI Data Poisoning Is a Knowledge-Supply-Chain Problem

Originally published in 2024; substantially revised in 2026 to deepen the analysis and incorporate additional sources.

NIST’s warning about adversarial manipulation of AI systems should change how organizations define the security boundary. Conventional software security focuses heavily on code, dependencies, infrastructure, identity, and configuration. AI systems add another attack surface: the evidence from which system behavior emerges.

Training corpora, feedback data, retrieval indexes, evaluation sets, model artifacts, prompts, and operational context all influence what an AI system learns or produces. If an adversary can shape those inputs, the system may remain technically available while becoming epistemically compromised.

AI expands the software supply chain into a knowledge supply chain. Security must protect not only what the system executes, but what it is permitted to believe.

READER-NEUTRAL SUBSCRIPTION

Follow Field Notes via RSS.

Copy this address into the RSS reader you already use. New notes will appear there automatically—no account, email address, or tracking required.