NIST updates its adversarial machine learning taxonomy

NIST published NIST AI 100-2e2025, an update to its voluntary taxonomy and terminology for adversarial machine-learning attacks and mitigations. The report covers predictive and generative AI systems, including evasion, poisoning, privacy, and misuse attacks. NIST said the document was developed with input from U.S. and U.K. AI security institutes, industry, and academia, and that it would be updated annually.

Original source date: . Hypler briefing published October 6, 2026.

Topics: NIST, adversarial machine learning, AI security, taxonomy

Generated editorial illustration. Adversarial ML attack classes illustrated as contaminated data, distorted paths and escaping fragments; not a scientific apparatus.
Generated editorial illustration. Adversarial ML attack classes illustrated as contaminated data, distorted paths and escaping fragments; not a scientific apparatus. Credit: Hypler / AI-generated editorial illustration. Hypler editorial asset; not vendor or event photography
Generated illustration of evidence records passing through a permission gate; not a compliance certification.
Generated illustration of evidence records passing through a permission gate; not a compliance certification. Credit: Hypler / AI-generated editorial illustration. Hypler editorial asset; not vendor or event photography

Engineering relevance

A shared vocabulary helps engineering, security, and governance teams discuss concrete attack classes instead of treating AI risk as one undifferentiated category. The taxonomy is voluntary guidance, not a guarantee that a system is secure. It can inform threat modeling and evaluation plans, which still need to reflect the actual model, data flows, tools, and user actions in scope.

Taxonomy update

NIST AI 100-2e2025 updates NIST's terminology and taxonomy for adversarial machine-learning attacks and mitigations. The agency described coverage for predictive AI and generative AI, including evasion, poisoning, privacy, and misuse attacks. The report also contains an index and glossary for practitioners navigating the material.

Intended use

NIST identified designers, developers, deployers, evaluators, and governors of AI systems as the report's audience. It stated that the work was developed with AI security institutes, industry, and academia and would be maintained annually. The publication offers voluntary guidance rather than a compliance finding for any product or organization.

Original source

This is a historical source briefing, not a statement of current availability or Hypler deployment.