ATLAS Landscape
AML.T0018

Manipulate AI Model

Adversaries may directly manipulate an AI model to change its behavior or introduce malicious code. Manipulating a model gives the adversary a persistent change in the system. This can include poisoning the model by changing its weights, modifying the model architecture to change its behavior, and embedding malware which may be executed when the model is loaded.

Severity CVE CVSS
CRITICAL CVE-2023-1177 9.8
CRITICAL CVE-2025-63389 9.8
CRITICAL CVE-2026-2635 9.8
CRITICAL CVE-2023-6018 9.8
CRITICAL CVE-2024-8019 9.1
HIGH CVE-2022-23561 8.8
HIGH CVE-2021-29587 7.8
HIGH CVE-2021-41203 7.8
HIGH CVE-2023-6015 7.5
HIGH CVE-2020-28975 7.5
HIGH CVE-2021-29601 7.1
MEDIUM CVE-2026-44562 6.5
MEDIUM CVE-2022-23586 6.5
MEDIUM CVE-2022-23583 6.5
MEDIUM CVE-2022-23565 6.5
MEDIUM CVE-2022-23594 5.5
LOW CVE-2025-2149 2.5