MITRE ATLAS Mapped 2026 Top AI Model Hub Detection – Publish Poisoned Models (AML.T0058)

Detects network connection events associated with the download of machine learning model artifacts from public hubs that display indicators of malicious intent, such as unverified or newly created publisher accounts, missing or invalid cryptographic signatures, or the presence of embedded executable/pickle-deserialization payloads.