T14-AT-013CRITICAL

Economic Espionage

T14 · Infrastructure & Economic Warfare →
Risk score255
RatingCritical
Procedures10
Severity
Mechanism

AI assets represent extraordinary value concentration: a frontier model represents $100M+ in training compute, proprietary training datasets may be irreplaceable, and AI-derived business intelligence (pricing algorithms, recommendation logic, customer models) is competitively decisive. Economic espionage targets this value through model extraction (query-based distillation), training data extraction (membership inference, data reconstruction), trade secret exfiltration through AI-assisted intelligence gathering, and insider threat amplified by AI tools. The trust assumption violated is that serving a model through an API doesn't leak the model itself — in practice, systematic querying can extract a functional copy (model stealing) or reconstruct training data (training data extraction).

Mitigation
Model extraction detectionHIGH
Differential privacy in trainingMEDIUM
API output perturbationMEDIUM
Access controls on model weightsCRITICAL
Chaining

Economic espionage chains from T14-AT-012 (Cloud Provider Exploitation) for infrastructure access and T14-AT-001 (GPU Farm Hijacking) for direct model weight access. Chains into T14-AT-006 (Competitive Sabotage) when stolen intelligence is used to undercut the victim.

Framework mapping
OWASP LLMLLM02
MITRE ATLASAML.T0024;AML.T0044
Open in the technique browser →