NIST Releases Guidance on AI Cyberattacks

January 4, 2024

United StatesU.S. Executive Branch

Summary

On January 4, 2024, NIST released a publication titled Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (NIST.AI.100-2), which identifies threats to AI and machine learning systems along with potential mitigation strategies. The guidance aims to help developers and users understand attacks on AI, which are grouped into four categories: • Evasion attacks that attempt to alter an input to change how the system responds to it, such as causing an autonomous vehicle to misinterpret visual cues. • Poisoning attacks that, e.g., introduce corrupted or untrustworthy data during training by creating many copies of incorrect information to cause the model to rely on that information. • Privacy attacks that attempt to learn sensitive information about an AI model, or its training data, to misuse the model. These attacks include, e.g., reverse engineering prompts to reveal model weaknesses. • Abuse attacks that compromise a generative AI tool to force it to carry out malicious acts that overcome model safeguards, such as promoting hate speech or enabling cyberattacks. The document includes mitigation guidance for various types of attack, but also notes the limitations of mitigation techniques and the need for ongoing efforts to identify risks and potential defensive strategies.

Share This Page

Additional Information

Artificial Intelligence Resource Center

Giving you full access to the latest in AI across regulatory developments, legal & policy issues and industry news.

Akin Intelligence Newsletter

Subscribe to Akin Intelligence, our monthly newsletter recapping the latest in AI and its impact on various sectors. 

© 2025 Akin Gump Strauss Hauer & Feld LLP. All rights reserved. Attorney advertising. This document is distributed for informational use only; it does not constitute legal advice and should not be used as such. Prior results do not guarantee a similar outcome. Akin is the practicing name of Akin Gump LLP, a New York limited liability partnership authorized and regulated by the Solicitors Regulation Authority under number 267321. A list of the partners is available for inspection at Eighth Floor, Ten Bishops Square, London E1 6EG. For more information about Akin Gump LLP, Akin Gump Strauss Hauer & Feld LLP and other associated entities under which the Akin Gump network operates worldwide, please see our Legal Notices page.