AI/ML Security
We assess the models and pipelines behind your AI products, from adversarial input through to model theft.
Request a Free ConsultationOverview
AI systems introduce a new attack surface built on familiar weaknesses. An inference endpoint is an API, frequently deployed without rate limiting. A training set is a supply chain, often assembled without verified provenance. We assess the model, the pipeline that feeds it and the infrastructure supporting both, because adversarial input, poisoned training data and model theft converge on the same outcome by different routes. Once business decisions depend on model output, the integrity of that output is a security concern rather than solely a data science concern.
Scope of Testing
We assess models you own or operate: the serving endpoint, the retraining pipeline, the storage holding your training data, and the third-party weights and libraries in your dependency chain. Where you consume a hosted third-party model through an API, risk concentrates at your integration, and testing is focused there. Not every deployment requires adversarial testing: a recommendation feature and a model informing credit decisions carry very different consequences when they fail, and we scope engagements to match the risk involved.
Our Approach
Risk Assessment
We inventory your deployed models and rank them by potential impact: which models influence significant decisions, what data trained them, and who can reach each endpoint with which credentials. The result is a prioritised list rather than an undifferentiated scan of every asset.
Adversarial Testing
We craft inputs designed to induce incorrect behaviour: evading a classifier, leaking a training record, or returning output the model was never intended to produce. We also test the pipeline, as corrupting a training set is often easier than defeating a finished model.
Zero Trust for AI
Authentication and rate limiting on inference endpoints, scoped credentials for the training pipeline, and logging that records what was asked of the model and what it returned. Without these records, effective post-incident investigation is not possible.
Secure Deployment
Each finding is delivered with its remediation: the configuration to change, the validation to add at the pipeline boundary, the dependency to pin. We work through remediation with your ML engineers, whose code the fixes typically affect.
Threats & Techniques
Adversarial Attacks
Inputs perturbed to alter a model's output while remaining indistinguishable from ordinary data to a human reviewer.
Data Poisoning
Malicious samples introduced into training data so the model learns behaviour defined by the attacker.
Model Inversion & Extraction
Repeated queries against an endpoint to reconstruct sensitive training records or replicate the model itself.
Membership Inference
Determining whether a specific individual's record was present in the training data, a privacy breach in its own right.
Supply Chain Attacks
A compromised library, or pre-trained weights obtained from a public repository without integrity verification.
Model Evasion
Crafting input to bypass a detection or classification model that is otherwise functioning as designed.
MITRE Mapping for AI/ML
We map findings to MITRE ATLAS and ATT&CK, presenting AI risk in the language your security team already uses across the rest of the environment. This ensures findings are triaged alongside your broader risk register rather than reviewed by the ML team in isolation.
Reconnaissance
Identifying exposed model endpoints and the data sources behind them.
Initial Access
Weak authentication on an inference API, or a vulnerability in the service surrounding it.
Execution
Delivering adversarial input or a payload processed by the model or its preprocessing code.
Persistence
Compromising the retraining loop so a corrupted model is rebuilt with every cycle.
Exfiltration
Extracting model parameters through the API, or accessing training data directly from storage.
Impact
Deliberate misclassification, cost inflation through query volume, or reputationally damaging model output.
Workforce Credentials
Ready to Secure Your AI?
Tell us what you have in production and we will scope an assessment around the models that carry real consequences when they fail.
Contact Us