Understanding adversarial attacks against Machine Learning and AI
Download this document free
Get this document with your free trial. Choose from the full Complyzard library.
Try 1 month free30 days free, then $19/month. Trial terms apply. Card required. Cancel anytime.Document information
Introducing a common language to improve awareness, threat modelling, and collaboration on AI security
Adapted edition
- Document type
- Reference Guide
- Format
- DOCX
- Pages
- 15
- Language
- English
- Version
- 1.0
- Updated
- 2026-09-16
- Category
- AI governance
- Licence
- Open Government Licence v3.0
Description
Introducing a common language to improve awareness, threat modelling, and collaboration on AI security for organisational planning, review and training. NCSC guidance is advisory and should be applied to the organisation's own risks and obligations.
Contents
- In this paper:
- 1. Introducing adversarial machine learning (AML) attacks
- 1.1 Aims of this paper
- 1.2 ML attacks in a cyber security context
- 1.3 Goals of a malicious actor
- 1.4 Glossary of terms
- 2. Defining AML attack classes
- 2.1 Model characterisation
- What is it?
- Further details
- 2.2 Model inversion
- 2.3 Training data poisoning
- 2.4 Malicious model training
- 2.5 Model input manipulation
- 2.6 Model artefact manipulation
- 2.7 Model hardware attacks
- Source links
Source and licence
National Cyber Security Centre
AttributionNational Cyber Security Centre, “Understanding adversarial attacks against Machine Learning and AI” (29 April 2026), reused under the Open Government Licence v3.0.
ChangesAdapted 16 September 2026: converted the official HTML article into neutral text-only DOCX and PDF editions. Preserved article headings, paragraphs, lists and plain-text source-link destinations; normalized web whitespace and typographic punctuation; omitted site navigation, topic and download cards, images, logos, scripts, styles and page furniture.
Version history
- v1.016/09/2026