Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
3 detections
Filters
Last updated
All Time
Detection languages
2
1
Contributors
3
Categories
3
1
1
1
Platforms
1
1
Products / Services
3
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
Detects unauthorized or anomalous modifications to machine learning model checkpoints. The rule triggers on significant deviations in weight delta percentages outside of scheduled fine-tuning windows, or when a model checkpoint hash is altered by users or service accounts without corresponding CI/CD pipeline approval or documented code review.
Detects potential AI model backdoor trigger attempts by identifying inference requests from a single caller that result in high-confidence, rare-label predictions across multiple distinct input artifacts. This pattern is indicative of an adversary probing or activating a poisoned model by injecting specific triggers designed to force anomalous outputs.
Detects unauthorized or unreviewed modifications to AI model weights, retraining jobs, or pushes to the model registry within MLOps pipelines. This activity is monitored to prevent AI model weight poisoning, ensuring that all model-related changes undergo required peer-review or approval processes before deployment.
