Skip to content

Frameworks

Research, mapped to the standards

Find the papers and tools behind each OWASP risk, MITRE ATLAS technique, NIST AI RMF function and ISO/IEC 42001 clause. Mappings on unreviewed entries are suggested from their categories.

OWASP Top 10 for LLM Applications

v2025 · 725 mapped resources

Official source
LLM10

Unbounded Consumption

2

Uncontrolled resource usage by LLMs

OWASP Top 10 for Agentic Applications

v2026 · 70 mapped resources

Official source
ASI04

Agentic Supply Chain Compromise

3

Compromised tools, plugins, models, prompts or agents pulled in at runtime

ASI05

Unexpected Code Execution

1

Agent-generated or agent-triggered code execution leading to compromise

ASI07

Insecure Inter-Agent Communication

1

Unauthenticated or unencrypted agent-to-agent messages enabling spoofing and manipulation

ASI08

Cascading Failures

1

Faults amplifying across coupled agents and systems

ASI09

Human-Agent Trust Exploitation

1

Exploiting users' trust in agents, e.g. with fabricated justifications

MITRE ATLAS

v5.6.0 · 768 mapped resources

Official source
AML.T0010

AI Supply Chain Compromise

14

Adversaries may gain initial access to a system by compromising the unique portions of the AI supply chain.

Show 8 more

Most cited shown; 2 more are mapped here.

AML.T0015

Evade AI Model

2

Adversaries can Craft Adversarial Data that prevents an AI model from correctly identifying the contents of the data or Generate Deepfakes that fools an AI m...

AML.T0019

Publish Poisoned Datasets

0

Adversaries may Poison Training Data and publish it to a public location.

AML.T0025

Exfiltration via Cyber Means

0

Adversaries may exfiltrate AI artifacts or other information relevant to their goals via traditional cyber means.

AML.T0029

Denial of AI Service

0

Adversaries may target AI-enabled systems with a flood of requests for the purpose of degrading or shutting down the service.

AML.T0034

Cost Harvesting

0

Adversaries may deliberately drive a victim's AI services beyond normal operating capacity with the intent of increasing the cost of services.

AML.T0040

AI Model Inference API Access

0

Adversaries may gain access to a model via legitimate access to the inference API.

AML.T0042

Verify Attack

0

Adversaries can verify the efficacy of their attack via an inference API or access to an offline copy of the target model.

AML.T0044

Full AI Model Access

0

Adversaries may gain full "white-box" access to an AI model.

AML.T0047

AI-Enabled Product or Service

0

Adversaries may use a product or service that uses artificial intelligence under the hood to gain access to the underlying AI model.

AML.T0056

Extract LLM System Prompt

0

Adversaries may attempt to extract a large language model's (LLM) system prompt.

AML.T0057

LLM Data Leakage

3

Adversaries may craft prompts that induce the LLM to leak sensitive information.

AML.T0058

Publish Poisoned Models

0

Adversaries may publish a poisoned model to a public location such as a model registry or code repository.

AML.T0070

RAG Poisoning

0

Adversaries may inject malicious content into data indexed by a retrieval augmented generation (RAG) system to contaminate a future thread through RAG-based...

NIST AI Risk Management Framework

v1.0 · 111 mapped resources

Official source

ISO/IEC 42001

v2023 · 4 mapped resources

Official source