Skip to main content
This is a research prototype. The data and analyses are preliminary and not yet validated — we'd welcome your .

Data exfiltration

Generative AI Misuse: A Taxonomy of Tactics and Insights from Real-World Data

Marchal & Xu (2024)

Sub-category
Risk Domain

Vulnerabilities that can be exploited in AI systems, software development toolchains, and hardware, resulting in unauthorized access, data and privacy breaches, or system manipulation causing unsafe outputs or behavior.

"Data Exfiltration goes beyond revealing private information, and involves illicitly obtaining the training data used to build a model that may be sensitive or proprietary. Model Extraction is the same attack, only directed at the model instead of the training data — it involves obtaining the architecture, parameters, or hyper-parameters of a proprietary model (Carlini et al., 2024)."(p. 9)

Part of Misuse tactics to compromise GenAI systems (Data integrity)

Other risks from Marchal & Xu (2024) (22)