Skip to content

#93: retarget the 16 ATLAS rows whose own claim restates the ATLAS definition - #116

Merged
emmanuelgjr merged 1 commit into
mainfrom
fix/atlas-draft-rows
Sep 18, 2026
Merged

emmanuelgjr merged 1 commit into
mainfrom
fix/atlas-draft-rows

Conversation

@emmanuelgjr

Copy link
Copy Markdown
Contributor

Applies category A of the ruling sheet on #93. Categories B and C stay DRAFT.

What category A is

The rows where the text the author already wrote in the row matches an ATLAS technique's published description. The retarget follows that evidence rather than a judgment about what the mapping should be:

Label, as written Was Now The row's own claim
"Data Poisoning" T0032 (no such id) T0070 RAG Poisoning injecting malicious content into agent persistent memory or RAG stores
"Embedding Manipulation" T0063 T0066 Retrieval Content Crafting crafting content whose embeddings bias future retrieval
"Exploit Public-Facing ML Application" T0057 T0049 Exploit Public-Facing Application the label is that technique's name
"Data Leakage" T0021 T0057 LLM Data Leakage unintended exposure of training data or context through model outputs
"Information Disclosure" T0030 (no such id) T0057 LLM Data Leakage extraction of confidential information via targeted model queries
"Spearphishing via AI" T0049 T0052.000 Spearphishing via Social Engineering LLM agent crafts personalised, convincing manipulation
"Model Inversion" T0027 (no such id) T0024.001 Invert AI Model reconstructs sensitive training examples from model outputs
"Configuration Exposure" T0041 T0056 Extract LLM System Prompt extraction of model configuration, instructions, or system prompts
"LLM Capability Escalation" T0015 T0053 AI Agent Tool Invocation exploiting overly permissive tool access to exceed intended scope
"Network Service Scanning" T0043 T0006.002 Scan for Exposed AI Infrastructure identifying and mapping inter-agent communication endpoints

Each row takes the technique's official name, its DRAFT marker comes off, and the quick-reference id lists follow the detail rows of the same entry. Five techniques these rulings now cite are transcribed into the registry from ATLAS 2026.09: 52 → 57 items.

Left DRAFT, deliberately

  • B — 12 rows with two defensible targets (e.g. "Adversarial Model Manipulation", whose claim spans weights and tool components, so T0018 and T0110 both fit).
  • C — 6 rows with no ATLAS counterpart ("Disinformation", "Influence via Automated Content"; ATLAS describes those harms, not the method).

Both keep their inline markers and their entries in #93.

One consequence worth your eye

LLM02 now carries two AML.T0057 rows — "Data Leakage" and "Information Disclosure" both describe LLM Data Leakage, so the two rulings converge. Their notes differ, and merging them would discard one, so I left both. (ASI03 has a similar pre-existing pair on T0024.)

Verification

  • Validator: 34 → 18 flagged rows, matching category A exactly.
  • Mappings unchanged at 3,771; no row removed; no severity, relationship or confidence touched.
  • node scripts/validate.js: 0 errors, 327 passed. npm run test:scripts: 85 passed. Stats current, generator reproduces.

🤖 Generated with Claude Code

…finition

Category A of the ruling sheet posted on #93, approved by the maintainer.
These are the rows where the text the author wrote in the row matches an ATLAS
technique's published description, so the retarget follows the evidence rather
than a judgment:

  "Data Poisoning"                     T0032 -> T0070 RAG Poisoning
  "Embedding Manipulation"             T0063 -> T0066 Retrieval Content Crafting
  "Exploit Public-Facing ML Appl."     T0057 -> T0049 Exploit Public-Facing Application
  "Data Leakage"                       T0021 -> T0057 LLM Data Leakage
  "Information Disclosure"             T0030 -> T0057 LLM Data Leakage
  "Spearphishing via AI"               T0049 -> T0052.000 Spearphishing via Social Engineering LLM
  "Model Inversion"                    T0027 -> T0024.001 Invert AI Model
  "Configuration Exposure"             T0041 -> T0056 Extract LLM System Prompt
  "LLM Capability Escalation"          T0015 -> T0053 AI Agent Tool Invocation
  "Network Service Scanning"           T0043 -> T0006.002 Scan for Exposed AI Infrastructure

Each row takes the technique's official name, its DRAFT marker comes off, and
the quick-reference id lists follow the detail rows of the same entry. Five
techniques the rulings now cite are transcribed into the registry from ATLAS
2026.09 (52 -> 57 items).

Categories B (two defensible targets, 12 rows) and C (no ATLAS counterpart,
6 rows) keep their DRAFT markers and their entries in #93.

Validator: 34 -> 18 flagged rows. Mappings unchanged at 3,771; no row removed,
no severity, relationship or confidence touched.

Consequence to note: LLM02 now carries two AML.T0057 rows, because "Data
Leakage" and "Information Disclosure" both describe LLM Data Leakage. Their
notes differ and merging them would discard one, so both are left.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@emmanuelgjr
emmanuelgjr merged commit 6d7f9a7 into main Sep 18, 2026
6 checks passed
@emmanuelgjr
emmanuelgjr deleted the fix/atlas-draft-rows branch September 18, 2026 17:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant