MITRE ATLAS (Adversarial Threat Landscape for AI Systems)
- Type
- Public reporting channel
- Place
- International — Global
- Last checked
- 2026-09-22
- Next check due
- 2027-03-21
Ways to reach them
- Submission page
- Homepage
What it does
Adversarial ML tactics, techniques and real-world case studies — i.e. attacks against AI systems. Contributions are curated into the ATLAS matrix and case study set.
Honest assessment
Genuinely consequential within AI security — ATLAS IDs are used by vendors, red teams and compliance products. But the bar is a well-evidenced adversarial technique, and a GitHub PR against a MITRE schema is a high-skill submission. Wrong venue for most non-technical safety concerns.
How to file
Contributions flow through the public data repository github.com/mitre-atlas/atlas-data (CONTRIBUTING.md, pull requests against YAML technique and case study files) and via MITRE's ATLAS contact channels. The repo has active open issues and pull requests, so outside PRs are a live route.
Format
Structured YAML records matching the ATLAS schema; case studies follow a fixed template (summary, incident details, procedure mapped to ATLAS technique IDs, references).
Timing
Rolling; batched into periodic ATLAS releases.
What happens after
MITRE curators review; accepted content appears in a versioned ATLAS release with attribution and is consumed by security tooling.
What it accepts
Adversarial ML tactics, techniques and real-world case studies — i.e. attacks against AI systems. Contributions are curated into the ATLAS matrix and case study set.
What it does not accept
Model-behaviour or societal-harm concerns with no adversary. ATLAS is a security threat knowledge base modelled on ATT&CK, not a harm registry. Also not a disclosure channel — it documents attacks after the fact.
Operated by
MITRE, with the Center for Threat-Informed Defense (CTID) and industry partners