S0076RS3-T09-S0076-Z · Full risk code

Cross-Model Transfer Attack

跨模型遷移攻擊

Verification & Validation
Risk Description

When an organization protects its model with strict access controls, believing outsiders cannot study its behavior; due to unmitigated control gaps, an attacker crafts adversarial samples using a similar public model and applies them directly to the target system with success, rendering the existing access protections ineffective, triggering compliance exposure and operational reputational costs.

Framework Mappings

MITRE ATLASAML.T0043
NIST AI 100-2Evasion
OWASP Top 10 for LLMLLM01
ISO/IEC 5338驗證與確效
MIT AI Risk RepositoryDomain 2

Risk Treatment & Implementation Guidance

Recognize that access control does not stop transfer attacks and center defense on model robustness itself; Differentiate the model (architecture, data, randomization) to reduce behavioral similarity to public models; Use ensemble defenses and self-test transferability with public surrogate models