ATLASAML.T0005.001
ATLAS index
AML.T0005.001

Train Proxy via Replication

Adversaries may replicate a private model. By repeatedly querying the victim's AI Model Inference API Access, the adversary can collect the target model's inferences into a dataset. The inferences are used as labels for training a separate model offline that will mimic the behavior and performance of the target model.

Framework
MITRE ATLAS
Maturity
Demonstrated
Platforms
Predictive AI, Generative AI, Agentic AI
Release
2026.05

Overview

Adversaries may replicate a private model. By repeatedly querying the victim's AI Model Inference API Access, the adversary can collect the target model's inferences into a dataset. The inferences are used as labels for training a separate model offline that will mimic the behavior and performance of the target model.

A replicated model that closely mimic's the target model is a valuable resource in staging the attack. The adversary can use the replicated model to Craft Adversarial Data for various purposes (e.g. Evade AI Model, Spamming AI System with Chaff Data).

Sources

  1. MITRE ATLAS AML.T0005.001: Train Proxy via Replication — MITRE