Suspicious AI Dataset Label Modification
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log
Detection Modules
Cloud
Detector Tags
Cloud AI Infrastructure Analytics
ATT&CK Tactic
Impact (TA0040)
ATT&CK Technique
Data Manipulation: Stored Data Manipulation (T1565.001)
Severity
Low
Description
AI Dataset labels were modified by an identity that typically doesn't interact with labels. MITRE ATLAS Technique: AML.T0020 - Poison Training Data. OWASP Top 10 LLM Technique: LLM04 - Data and Model Poisoning.
Attacker's Goals
Contaminating training set, so that predictions on new data will be modified.
Investigative actions
Check the identity that modified the dataset's labels.
Check that the dataset is correctly labeled.
Was this helpful?
