Skip to main content

CCC.GenAI.TH08: Model Tampering

Threat ID:CCC.GenAI.TH08
Title:Model Tampering
Description:

Supply chain risks, including tampering with a model's core components at any stage of its lifecycle—from its source code and training data to the final deployable artifact—may result in embedding backdoors or adversarial triggers altering model behaviour under certain conditions.

Related Capabilities

IDTitleDescription
CCC.GenAI.F01Text-Based Model SelectionAbility to select a foundation model that excels at natural language understanding and generation tasks such as summarization, translation, text generation, question answering, and sentiment analysis.
CCC.GenAI.F02Code-Based Model SelectionAbility to select a foundation model that focuses on code understanding, generation, and transformation tasks.
CCC.GenAI.F03Embedding Model SelectionAbility to select a foundation model used for tasks like semantic search, clustering, and document similarity by converting text into vector embeddings.
CCC.GenAI.F04Image-Based Model SelectionAbility to select a foundation model that focuses on tasks related to vision, such as image generation, editing, and manipulation.
CCC.GenAI.F04Image-Based Model SelectionAbility to select a foundation model that focuses on tasks related to vision, such as image generation, editing, and manipulation.
CCC.GenAI.F04Image-Based Model SelectionAbility to select a foundation model that focuses on tasks related to vision, such as image generation, editing, and manipulation.

External Mappings

Reference IDEntry IDStrengthRemarks
FINOS-AIGF
AIR-SEC-008
0
Tampering With the Foundational Model
SAIF
MST
0
Model Source Tampering
SAIF
MDT
0
Model Deployment Tampering
OWASP-LLM-TOP10
LLM03:2025
0
Supply Chain
MITRE-ATLAS
AML.T0010
0
AI Supply Chain Compromise

Controls

IDTitleObjectiveControl FamilyThreat MappingsGuideline MappingsAssessment Requirements
CCC.GenAI.C08Quality Control and Red TeamingEstablish a formal program for quality evaluation and adversarial testing (red teaming) to ensure GenAI system meet all business, quality, security and compliance requirements before getting deployed into production environments. Model Assurance and Evaluation
5
5
2