Skip to main content

AI/ML / Mlde

CCC Machine Learning Development Environment Threats

Version: DEV

IDTitleDescriptionExternal MappingsCapability MappingsControl Mappings
CCC.MLDE.TH01Elevated System Access on Notebook Instances is AbusedManaged notebook instances may be configured to permit root privileges, interactive terminal sessions, or unrestricted access modes for the users of the environment. When such access is available, the underlying instance configuration could be modified, security agents disabled, or arbitrary commands executed outside the notebook interface. This compromises the integrity of the development environment and the confidentiality of any data or credentials accessible from the instance.014
CCC.MLDE.TH02Training Data or Model Artifacts are ExfiltratedNotebook instances and connected data pipelines may be configured with unrestricted egress paths, such as file downloads, public network interfaces, or writable external destinations. Training datasets, model artifacts, and embedded credentials could be transferred out of the environment through these paths. This results in a loss of confidentiality for proprietary data and models, and may expose regulated or sensitive records used in training.012
CCC.MLDE.TH03Model Artifacts or Experiment Records are Tampered WithModel registry entries, experiment metadata, and reproducibility records may be modified by entities with write access to the environment. Altered artifacts or records could be promoted to training and deployment workflows in place of the intended versions. This compromises the integrity of deployed models and the reliability of experiment lineage used for reproduction and audit.010
CCC.MLDE.TH04Outdated or Unapproved Environment Images are ExploitedNotebook instances may be created from arbitrary virtual machine or container images, or left running without scheduled upgrades, so that pre-installed machine learning libraries and runtimes fall behind current security patches. Known vulnerabilities in these components could be exploited to execute code or escalate privileges within the environment. This compromises the confidentiality, integrity, and availability of the development environment and the data it processes.012

Imports

IDRemarks
CCC.Core.TH01Access Control is Misconfigured
CCC.Core.TH02Data is Intercepted in Transit
CCC.Core.TH04Data is Replicated to Untrusted or External Locations
CCC.Core.TH06Data is Lost or Corrupted
CCC.Core.TH07Logs are Tampered With or Deleted
CCC.Core.TH08Cost Management Data is Manipulated
CCC.Core.TH09Logs or Monitoring Data are Read by Unauthorized Users
CCC.Core.TH12Resource Constraints are Exhausted
CCC.Core.TH13Resource Tags are Manipulated
CCC.Core.TH15Automated Enumeration and Reconnaissance by Non-human Entities
CCC.Core.TH16Logging and Monitoring are Disabled