For the complete documentation index, see llms.txt. This page is also available as Markdown.

Suspicious AI Dataset Label Modification

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

5 Days

Required Data

Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log

Detection Modules

Cloud

Detector Tags

Cloud AI Infrastructure Analytics

ATT&CK Tactic

Impact (TA0040)

ATT&CK Technique

Data Manipulation: Stored Data Manipulation (T1565.001)

Severity

Low

Description

AI Dataset labels were modified by an identity that typically doesn't interact with labels. MITRE ATLAS Technique: AML.T0020 - Poison Training Data. OWASP Top 10 LLM Technique: LLM04 - Data and Model Poisoning.

Attacker's Goals

Contaminating training set, so that predictions on new data will be modified.

Investigative actions

  • Check the identity that modified the dataset's labels.

  • Check that the dataset is correctly labeled.

Was this helpful?