IR-011cloudv1.0.0
AI/ML Model Abuse and Training Data Poisoning
⚠️ medium⚠️ high⚠️ critical
⏱ Est. Time60m
📋 Steps10 steps
🔧 Tools6 required
🔗 Integrations5 platforms
📊 Avg Resolution90m
🔧 Tools Required
siemcloud consoleapi gatewaydlp platformml platform logsthreat intelligence platform
⚡ Triggers
ml_api_rate_limit_breachinference_cost_spike_alertmodel_endpoint_anomalytraining_pipeline_unauthorized_accesssiem_ml_api_abusedlp_training_data_exfiltration
🔌 Integrations
opt
openai api
Usage dashboard and API key management for OpenAI-hosted models
opt
aws sagemaker
CloudWatch metrics for SageMaker endpoints — inference anomaly detection
opt
azure ml
Azure Monitor for ML workspace activity and model registry changes
opt
splunk
Ingest model API logs for SIEM correlation and anomaly queries
opt
datadog
APM for model serving infrastructure and cost anomaly detection
Click each step to expand the full procedure, automation hints, and expected outputs.