Definition · AI security
MITRE ATLAS
MITRE ATLAS is a public knowledge base of the tactics, techniques and mitigations adversaries use against AI systems, modelled on MITRE ATT&CK. ATLAS adds what ATT&CK has no equivalent of — dated case studies naming an actor and a target, each typed as a real incident or as an authorised researcher exercise.
Last reviewed
Key points
- MITRE ATLAS is a public knowledge base of adversary tactics, techniques and mitigations aimed at AI systems, published by MITRE under Apache 2.0 and modelled on MITRE ATT&CK.
- The 2026.08 collection holds 16 tactics, 197 techniques, 39 mitigations and 72 case studies, each with a stable ID that a report can cite.
- ATLAS is modelled on ATT&CK without being a subset of it. Fourteen of its sixteen tactics carry an ATT&CK reference, only 42 of its 197 techniques do, and a case study cannot carry one because the schema gives it no such field.
- Every case study is typed Exercise or Incident, and in the 2026.08 collection 50 of the 72 are exercises. Reading an ATLAS entry as a breach is wrong more often than it is right.
- A mitigation carries two different texts — its own description, and a separate per-technique mapping in the relationships block. They differ in scope and are not interchangeable.
MITRE ATLAS answers the question every attack-class page eventually gets asked: has anyone actually done this? ATLAS is MITRE’s public catalogue of adversary behaviour against AI systems, and the 2026.08 collection holds 16 tactics, 197 techniques, 39 mitigations and 72 case studies.
How ATLAS is organised
ATLAS borrows the shape of MITRE ATT&CK. A tactic is the adversary’s goal, a technique is how they reach it, a mitigation is what a defender does about it, and every object has a stable ID — AML.TA0002 Reconnaissance, AML.M0005 Control Access to AI Models and Data at Rest.
It borrows the shape, not the contents. Fourteen of the sixteen tactics carry an ATT&CK reference; the two without one are AI Model Access and AI Attack Adaptation. Just 42 of the 197 techniques map back to ATT&CK. Case studies cannot map at all — the schema gives them no ATT&CK field.
What an ATLAS case study proves
Less than most readers assume. Every case study is typed Incident or Exercise, and 50 of the 72 are exercises — authorised research against a real system, not a breach. The schema enforces the line: an Exercise is forbidden from naming a reporter.
NIST reads ATLAS with that care. NIST AI 100-2e2025 cites it for evasion of malware classifiers — Palo Alto Networks against a command-and-control traffic detector and a botnet DGA detector, a universal evasion of Cylance’s model, a shadow-model evasion of ProofPoint’s email protection — then says these “are demonstrations of evasion vulnerabilities by researchers, but did not result in attacks in the wild.” ATLAS types all four Exercise. Where NIST does report an ATLAS incident, poisoning of VirusTotal, ATLAS types that one Incident and names McAfee Advanced Threat Research as the reporter.
So the entry you cite decides what you may claim, and adversarial example demonstrations dominate the corpus.
Questions and answers
What is MITRE ATLAS?
MITRE ATLAS is a public knowledge base of how adversaries attack AI systems, published by MITRE under Apache 2.0. It is organised like MITRE ATT&CK — tactics for what the adversary wants, techniques for how they get it, mitigations for what a defender does — and the 2026.08 collection holds 16 tactics, 197 techniques, 39 mitigations and 72 case studies. Every object has a stable ID, such as AML.T0051, so a report can cite one.
How is ATLAS different from MITRE ATT&CK?
ATLAS copies ATT&CK's structure but is not a subset of its content. In the 2026.08 collection 14 of 16 ATLAS tactics carry a reference to an ATT&CK tactic, but only 42 of 197 techniques reference an ATT&CK technique, and two tactics carry no ATT&CK reference at all — AI Model Access and AI Attack Adaptation. The case studies are the other difference: the ATLAS schema gives a case study no ATT&CK field, so it cannot map to one.
Does an ATLAS case study mean a real attack happened?
Usually not. Every ATLAS case study is typed either Incident or Exercise, and in the 2026.08 collection 50 of the 72 are exercises — authorised research against a real system rather than an attack by an adversary. The schema draws the line: an entry typed Exercise is forbidden from naming a reporter, and 21 of the 22 Incident entries name one. Read the type field before citing an entry as a breach.
Is MITRE ATLAS free to use?
Yes. The ATLAS data repository, mitre-atlas/atlas-data, is licensed under the Apache License, Version 2.0, with the notice "Copyright 2021-2026 MITRE", so quoting it with attribution is permitted.
Where do I get the ATLAS data?
From the pinned collection file in the mitre-atlas/atlas-data repository, which carries every tactic, technique, mitigation, case study and relationship in one YAML document. The atlas.mitre.org website is a client-rendered application, so fetching a technique or mitigation page without a browser returns nothing useful. Parsing the YAML gives dictionaries keyed by ATLAS ID rather than lists.
Sources
- MITRE ATLAS data repository README, and the collection block of the pinned collection (2026.08)MITRE
- MITRE ATLAS data repository, atlas/schemas.py TacticFields, TechniqueFields, MitigationFields and CaseStudyFieldsMITRE
- MITRE ATLAS data repository, atlas/enums.py CaseStudyType and atlas/schemas.py CaseStudyFields, with counts from the pinned collection (2026.08)MITRE
- Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (NIST AI 100-2e2025)NIST, 24 Mar 2025
- MITRE ATLAS data repository, LICENSEMITRE