Poison AI/ML Training for Evasion
Parent: DE-0003
Description
When security monitoring relies on AI/ML (e.g., anomaly detection on telemetry, RF fingerprints, or command semantics), the training data itself is a target. Data-poisoning introduces crafted examples or labels so the learned model embeds false associations, treating attacker behaviors as normal, or flagging benign patterns instead. Variants include clean-label backdoors keyed to subtle triggers, label flipping that shifts decision boundaries, and biased sampling that suppresses rare-but-critical signatures. Models trained on tainted corpora are later deployed as routine updates; once in service, the adversary presents inputs containing the trigger or profile they primed, and the detector omits or downranks the very behaviors that would reveal the intrusion.
Mappings
EU regulation articles
Poisoning training data with crafted examples or labels is unauthorized modification of the data (and downstream model) the product processes — the integrity property (2)(f) covers.
Anomaly-detection / monitoring models ARE the (2)(l) recording-and-monitoring layer when the product implements ML-based security telemetry; clean-label backdoors and label flipping directly defeat the obligation.
AI/ML training-data poisoning via third-party component pipelines (primary mapping: Art. 13(5)) requires SBOM-grade documentation of training data and model artifacts; (1)'s component-and-vulnerability-identification obligation extends to ML pipeline components.
Training data and pretrained models are commonly sourced from third parties; (13)(5)'s component-due-diligence obligation triggers when a manufacturer integrates third-party ML pipelines exposed to poisoning.
Poisoned training data corrupts the model the network-and-information-system relies on for monitoring — 84(2)'s integrity scope under Annex VII point 5.1.
88(1)'s testing programme can include adversarial-input testing on monitoring models — surfacing clean-label backdoors and biased-sampling artifacts.
AI/ML training-data poisoning (primary: Art. 88(1)) cascades to 88(3) — TLPT every 3 years should validate ML pipeline integrity against adversarial-input tests.
ML training corpora and pretrained models often arrive via supplier or scientific-archive channels — 92(1)'s contractual information-security obligation governs how training-data provenance is disciplined.
Detector training corpora (telemetry archives, RF-fingerprint datasets, command-semantic logs) often ride supplier and service-provider data flows; Art. 21(2)(d)'s supplier-relationship security obligation governs the trust framework around those sources.
Detector model training/packaging/promotion is part of the network-and-information-systems development/maintenance pipeline Art. 21(2)(e) governs, including disclosed-weakness handling on label-flipping and clean-label backdoor attacks.
Validating that anomaly detectors actually detect — including against adversarial-input campaigns — is exactly how the entity assesses the effectiveness of its cybersecurity risk-management measures under Art. 21(2)(f).
Primary mapping to Art. 21(2)(d) covers supplier-relationship security for the AI/ML training-data pipeline. Art. 21(3) extends that obligation to the supplier-quality assessment itself (vulnerabilities of direct suppliers, secure development procedures), which is exactly the procedural lever needed to detect and remediate poisoned training data flowing from upstream data brokers, annotation services, and pretrained-model vendors.
Training datasets and reference labels for security-monitoring models are mission-critical information assets whose classification level drives integrity and access controls.
Anomaly-detection model training data is supplied through data brokers, telemetry-archive providers and ML-as-a-service vendors; the supply-chain policy governs how these data suppliers are vetted, contracted and monitored.
AI/ML model training is part of the secure-development life cycle; the rules for that lifecycle govern training-data integrity, model provenance and pre-deployment validation that detect poisoned anomaly-detection models.
ENISA controls
Integrity checking on training corpora and packaged ML model artefacts detects poisoned data before deployment.
ML data-integrity testing (regression, validity, manual, statistical analysis) is the named control against poisoning of detector training data for evasion.
Cross-reference controls
Derived by composition, not from a source that names this pair. D3FEND publishes that File Eviction counters T1565.001 Stored Data Manipulation; SafeMode's curated mapping records DE-0003.12 as addressing that same adversary behaviour in the space domain. Deleting an unauthorised file from storage applies to on-board file stores and table areas as well as to ground hosts. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because DE-0003.12 spans both a ground and a space face while the control reaches only one of them.
Derived by composition, not from a source that names this pair. D3FEND publishes that File Integrity Monitoring counters T1565.001 Stored Data Manipulation; SafeMode's curated mapping records DE-0003.12 as addressing that same adversary behaviour in the space domain. Detecting unexpected changes to stored files is the on-board table, parameter, and image integrity check, and is one of the few D3FEND controls that transfers to the spacecraft without reinterpretation. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because DE-0003.12 spans both a ground and a space face while the control reaches only one of them.
Derived by composition, not from a source that names this pair. D3FEND publishes that Local File Permissions counters T1565.001 Stored Data Manipulation; SafeMode's curated mapping records DE-0003.12 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because DE-0003.12 spans both a ground and a space face while the control reaches only one of them.
Derived by composition, not from a source that names this pair. D3FEND publishes that Restore File counters T1565.001 Stored Data Manipulation; SafeMode's curated mapping records DE-0003.12 as addressing that same adversary behaviour in the space domain. Restoring a file from a known-good copy covers reloading an on-board table, image, or stored product. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because DE-0003.12 spans both a ground and a space face while the control reaches only one of them.
Derived by composition, not from a source that names this pair. D3FEND publishes that Remote File Access Mediation counters T1565.001 Stored Data Manipulation; SafeMode's curated mapping records DE-0003.12 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because DE-0003.12 spans both a ground and a space face while the control reaches only one of them.
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Training data is stored data used to train models; T1565.001 'Stored Data Manipulation' covers manipulation of the training corpus itself (the underlying data-modification activity). Cross-tactic moderate (impact vs defense-evasion).
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
SA-11 mitigates DE-0003.12 by surfacing data-poisoning effects in ML detection models via developer testing.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
T2054.001 covers stored-data corruption — addresses DE-0003.12's poisoning of training corpora used by onboard anomaly-detection ML models (data-poisoning is data alteration). SPACE-SHIELD has no AI/ML-specific evasion technique.
SPARTA countermeasures
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Cite as SafeMode Space, DE-0003.12 (SPARTA v3.2).