AI SECURITY RESEARCH NOTE · NO ERS

Real Attackers Don’t Compute Gradients: Operational Threat Modeling for ML Security

This source is retained for threat and defensive-evidence research, but AITBM does not manufacture a deployment score where no assessable system boundary exists.

Why this analysis has no ERS

Methodology brief with no assessed deployment. The source is a research paper (Apruzzese, Anderson, Dambra, Freeman, Pierazzi, Roundy) arguing that adversarial-ML evaluation over-weights gradient-style model attacks relative to the cheaper system-level bypasses real attackers use. Its illustrative material — Facebook's abuse-fighting funnel, an unnamed commercial phishing detector, the MLSEC competition — is second-hand and generic: no named system in a stated configuration, no incident, no measured control outcome, and no evidence of which defences were present or absent at a point in time. Under protocol section 7 this is a methodology/population study, and the representative-configuration exception does not apply because the brief does not describe any single deployment in enough detail to reconstruct one. Scoring it would require inventing sub-metric evidence.

Classification: Research · source date 2026-04-26

AIDEFEND evidence routes

AIDEFEND defences → AITBM sub-metrics

Identifiers are quoted as they appear on the AIDEFEND in Action brief (retrieved 2026-08-13); the sub-metric mapping is AITBM's own, from the specification's AIDEFEND tables reconciled at catalogue data version 2026.08.05. AIDEFEND renumbers identifiers between releases, so the data version travels with every mapping and neither side's IDs should be cited without one. A mapping identifies a possible evidence route; a recommendation does not prove that the control was implemented or effective and receives no scoring credit by itself.

TechniqueDefence PriorityEvidences
AID-M-004AI Threat Modeling & Risk AssessmentParent technique AID-M-004 (catalogue dataVersion 2026.08.05), same ID at parent level. The paper's central lesson. The lookup maps it to fairness and explainability evidence; in this brief its practical AITBM value is upstream of scoring — it defines the component set an assessor must cover before deciding which sub-metrics are in scope.Very HighFa-1 Fa-4 Tr-1
AID-M-001.002AI System Dependency MappingParent AID-M-001 'AI Asset Inventory & Mapping' (dataVersion 2026.08.05). Directly relevant to ORP: this is the control that produces the System Dependency Graph that graph-derived Cascade Potential requires. Without it, DGC cannot be computed and Cp defaults to 1.00 by spec rule.Very HighCn-5 Fa-3 Tr-4
AID-H-002.004Feature Pipeline Integrity & Transformation AuditParent AID-H-002 'AI-Contextualized Data Sanitization & Input Validation' (dataVersion 2026.08.05). Evidence source for Ro-1 where evasion exploits the gap between raw input and the features the model consumes.HighFa-1 Fa-3 Ro-1
AID-M-005.002Policy-as-Code Configuration Baselines & Posture Release GatesParent AID-M-005 maps directly to Tr-3 in the reconciled AIDEFEND dataVersion 2026.08.05 crosswalk. The Policy-as-Code Configuration Baselines & Posture Release Gates control is applied here as evidence for Tr-3.HighTr-3
AID-M-003.002General Predictive Performance & Operational BaseliningParent AID-M-003 'Model Behavior Baseline & Documentation' (dataVersion 2026.08.05). Also the artefact class the ACI behavioural baseline requirement depends on (spec 3.3.3.1).HighFa-2 Fa-4 Ro-2 Tr-1 Tr-2
AID-D-002.001Input / Output Distribution Drift MonitoringParent AID-D-002 'AI Model Anomaly & Performance Drift Detection' (dataVersion 2026.08.05). Primary evidence source for Ro-2 and for the DRD/BOD signals of the Time Drift Index.MediumCn-7 Fa-1 Fa-2 Ro-2 Tr-2
AID-D-005.001AI System Log Generation & CollectionParent AID-D-005 'AI Activity Logging, Monitoring & Threat Hunting' (dataVersion 2026.08.05). The paper's point that attacks unfold across automation, accounts, activity, model decisions and analyst feedback is an argument for Tr-3 completeness across all of those layers, not just model calls.MediumCn-7 Tr-3
AID-H-001Adversarial Robustness TrainingParent technique AID-H-001 (dataVersion 2026.08.05). Rated Partial in the brief: robustness training is one control inside the funnel, not the default answer — consistent with Ro-1 being one sub-metric of five axes.PartialRo-1

Related AITBM rubrics

Sources