AML-ATLAS-2026-18 | MITRE ATLAS Mapped 2026 – Top AI Threat Detection: Unsafe AI Artifact Execution via Malicious Model File (AML.T0011.000)

Detects instances where machine learning runtime processes (e.g., Python, torch-model-loader) load serialized model files (e.g., .pkl, .joblib, .pth) and subsequently spawn suspicious child processes like command shells, scripting engines, or download utilities. This behavior is indicative of arbitrary code execution via unsafe deserialization of a malicious model artifact.