MITRE ATLAS Mapped 2026 Top AI Training Pipeline Detection – Poison Training Data (AML.T0020)
This rule detects unauthorized or anomalous file modifications or creations to machine learning training datasets (e.g., fine-tuning data, training corpora) by users not belonging to the authorized data engineering group, occurring within one hour of a scheduled training or fine-tuning job execution. This behavioral pattern is indicative of potential data poisoning, where an adversary attempts to inject malicious data into the training set to bias or compromise the resulting model.
YARA-L

