Cyber Resilience

The AI Attack SurfaceStanding

170 AI attacks, four weaknesses

Updated 12 August 2026 · Timeframe: Current snapshot

Prompt injection (CWE-142…33Vulnerable component (CWE…18Adversarial input (CWE-10…13GenAI output (CWE-1426)6Inference settings (CWE-1…1
AI attack techniques by the weakness they exploit · security-resilience.ai

MITRE ATLAS catalogs 170 techniques for attacking AI systems. We mapped every one to the CWE weakness catalog by hand. They reduce to five weaknesses, and only four of those are AI-specific. Out of more than nine hundred CWEs, four describe something particular to AI. And 61% of the attacks have no equivalent in enterprise ATT&CK at all.

Why it matters

You can name an AI attack precisely from ATLAS. You usually cannot name the weakness it exploits, because it has never been catalogued. Standard scans and control frameworks will not describe your real AI risk yet — the defensive vocabulary has not caught up to the attack vocabulary.

What to do

Our take

Naming the AI defensive gap precisely, from our own direct mappings, is exactly the evidence-first AI framing the market's tsunami narrative skips.