MITRE ATLAS Mapped 2026 – Top AI Training Data Poisoning Detection (AML.T0020)
Detects potential training data poisoning attempts by monitoring anomalies in ingestion volume, shifts in label distribution, and high-volume submissions from feedback channels. This rule uses statistical analysis to identify spikes in data input or abnormal distributions that deviate from established historical baselines.
Microsoft Sentinel (KQL)

