# NIST updates its adversarial machine learning taxonomy

> NIST published NIST AI 100-2e2025, an update to its voluntary taxonomy and terminology for adversarial machine-learning attacks and mitigations. The report covers predictive and generative AI systems, including evasion, poisoning, privacy, and misuse attacks. NIST said the document was developed with input from U.S. and U.K. AI security institutes, industry, and academia, and that it would be updated annually.

Canonical: https://hypler.com/ai-news/nist-adversarial-machine-learning-taxonomy-2025
Hypler publication: 2026-10-06
Original source date: 2025-03-24
Publisher: NIST
Article kind: source-briefing
Category: Standards
Tags: NIST, adversarial machine learning, AI security, taxonomy

## Engineering relevance

A shared vocabulary helps engineering, security, and governance teams discuss concrete attack classes instead of treating AI risk as one undifferentiated category. The taxonomy is voluntary guidance, not a guarantee that a system is secure. It can inform threat modeling and evaluation plans, which still need to reflect the actual model, data flows, tools, and user actions in scope.

## Taxonomy update

NIST AI 100-2e2025 updates NIST's terminology and taxonomy for adversarial machine-learning attacks and mitigations. The agency described coverage for predictive AI and generative AI, including evasion, poisoning, privacy, and misuse attacks. The report also contains an index and glossary for practitioners navigating the material.

## Intended use

NIST identified designers, developers, deployers, evaluators, and governors of AI systems as the report's audience. It stated that the work was developed with AI security institutes, industry, and academia and would be maintained annually. The publication offers voluntary guidance rather than a compliance finding for any product or organization.

## Original source

- [NIST](https://www.nist.gov/news-events/news/2025/03/nist-trustworthy-and-responsible-ai-report-adversarial-machine-learning)

## Image provenance

### Primary image

![Generated editorial illustration. Adversarial ML attack classes illustrated as contaminated data, distorted paths and escaping fragments; not a scientific apparatus.](https://hypler.com/assets/news/nist-adversarial-machine-learning-taxonomy-2025.webp)

generated illustration. Credit: Hypler / AI-generated editorial illustration. Hypler editorial asset; not vendor or event photography.
- [Image source](https://hypler.com/ai-news/media.md)

### Supporting image

![Generated illustration of evidence records passing through a permission gate; not a compliance certification.](https://hypler.com/assets/news/policy-evidence.webp)

generated illustration. Credit: Hypler / AI-generated editorial illustration. Hypler editorial asset; not vendor or event photography.
- [Image source](https://hypler.com/ai-news/media.md)

## Reading boundary

Historical source briefing, not current availability, compliance advice, partnership, or proof of Hypler deployment. Generated artwork is not event photography. Public reading grants no private access or execution authority.
