Guidance
Machine learning principles
These principles help developers, engineers, decision makers and risk owners make informed decisions about the design, development, deployment and operation of their machine learning (ML) systems.
Pages
Page 12 of 22
Part 3: Secure deployment

iStock.com/dem10
This section contains principles that apply to the deployment stage of the ML system life cycle.
This section contains principles that apply to the deployment stage of the ML system life cycle, which includes protecting the system from a range of attacks that include:
- evasion attacks, designed to make a model misclassify specific examples (such as adversarial data) or produce unintended outputs (LLM prompt injection attacks)
- model extraction attacks, when an attacker uses repeated querying to build a copy of a model
- model inversion attacks, when an attacker aims to identify or reconstruct data on which the model was trained
- data extraction attacks, when an attacker attempts to infer training data membership (such as a membership inference attack), or extract full training samples from the deployed model (such as model inversion or LLM prompt extraction attacks)
- availability attacks, when an attacker deliberately manipulates training or inference data to degrade the performance of the system to cause a denial of service
Protecting information about your model will help strengthen the barrier to entry against an attacker.