Red teamers who move into AI security quickly find that their existing toolkit does not transfer cleanly to AI systems. SQL injection, buffer overflows, and network pivoting are irrelevant when the target is a large language model or a machine learning pipeline. The attack surface is fundamentally different, the failure modes are different, and the defenses are different.
What makes this particularly relevant to AAISM is a finding from Microsoft's AI Red Team, which attacked over 100 generative AI products between 2024 and 2025. Their conclusion: you do not need gradient mathematics to break most AI systems in practice. Prompt injection and fuzzing, techniques that every experienced red teamer already understands conceptually, were more effective than sophisticated machine learning evasion attacks against real deployments. The AI attack surface is not as alien as it first appears to a practitioner with a traditional offensive security background.
AAISM does not test your ability to execute these attacks. It tests whether you understand them well enough to make sound governance decisions about the risk they represent and the controls that address them. That distinction matters for how you prepare. The professional who approaches AAISM with a red team background is well-positioned for Domain 2 and Domain 3: the question is whether they can translate their offensive knowledge into the governance framing the exam rewards.
This guide maps the AI attack taxonomy AAISM tests, connects it to real-world findings, and explains how each attack type appears in exam scenarios across Domain 2 (AI Risk Management) and Domain 3 (AI Technologies and Controls).
Why AI Attacks Require a Different Mental Model
Traditional penetration testing operates on a relatively stable set of assumptions: systems have defined inputs and outputs, vulnerabilities have discrete root causes, and patches fix the underlying issue. AI systems break most of these assumptions.
A machine learning model does not behave like a web application. Its vulnerability surface is its statistical behavior, not its code. An attacker can cause a model to misclassify a stop sign without touching a single line of code, without exploiting a memory error, and without even having direct access to the model's internals. The attack works by understanding how the model processes inputs and constructing inputs that exploit that processing in unexpected ways.
This creates a different threat modeling problem for security leaders. The attack surface is not just the infrastructure the model runs on. It is the model itself, the data it was trained on, the API through which it is queried, and the decisions it makes during inference. Each of these creates a distinct attack category with distinct governance implications.
AAISM tests understanding of four primary attack categories: evasion attacks (adversarial examples), data poisoning, model extraction, and inference attacks (model inversion and membership inference).
Prompt injection, which is the most practically exploited AI attack type in current deployments, is addressed in depth in the AAISM LLM Security guide and is treated here as a related but distinct category.
The AI Attack Taxonomy AAISM Tests
Adversarial Examples: Evasion Attacks
Adversarial examples are inputs crafted to cause a model to produce an incorrect output while appearing normal to human observation. The classic demonstration is an image of a panda with imperceptible pixel-level perturbations that cause a vision model to classify it as a gibbon with 99% confidence. The same technique applies to text, audio, and multimodal inputs.
Two variants matter for governance:
- Digital adversarial examples manipulate inputs before they reach the model. An attacker submitting a crafted document to a document classification system, or a malformed image to a computer vision pipeline, is executing a digital evasion attack. The goal is to cause a specific wrong output: misclassification, bypassed safety filter, or incorrect decision.
- Physical adversarial examples manipulate real-world objects that a model will observe. Adversarial patches on physical objects that defeat facial recognition or object detection systems fall into this category. For organizations using AI in physical security or operational environments, this creates a distinct threat vector that traditional security testing does not address.
AAISM Governance Framing
Domain 3 tests what governance controls address evasion attacks at a program level. Input validation and adversarial robustness testing are the primary controls, but the governance decision is how to implement continuous adversarial testing as an ongoing program activity rather than a point-in-time assessment.
Data Poisoning
Data poisoning attacks corrupt the training process rather than the model's inference behavior. By injecting malicious data into a model's training set, an attacker can cause the model to learn incorrect patterns, develop exploitable backdoors, or behave in ways that serve the attacker's objectives.
- Clean-label poisoning injects data that appears legitimate but shifts the model's decision boundary in ways that benefit the attacker. The poisoned samples look like normal training data, making detection difficult without statistical analysis of the full training set.
- Backdoor attacks inject data that causes the model to behave normally under most conditions but produce attacker-controlled outputs when a specific trigger pattern is present. A model might classify all inputs correctly in testing but misclassify any input containing a specific pixel pattern or phrase.
Supply Chain Implications
Organizations that fine-tune publicly available foundation models, use third-party training data, or incorporate AI components from external vendors face data poisoning risk through their supply chain rather than through direct data access. An attacker who compromises a dataset or model checkpoint used upstream can affect every downstream deployment without ever directly targeting the organization.
AAISM Governance Framing
Domain 2 addresses data poisoning through supply chain risk assessment and training in data governance. The governance questions are: how does the organization vet training data sources, how does it detect statistical anomalies in training datasets, and what procurement controls apply to AI components acquired from external vendors?
Model Extraction
Model extraction attacks reconstruct a target model's decision-making logic through repeated queries without direct access to the model's parameters. By systematically probing how the model responds to different inputs, an attacker can build a substitute model that approximates the target's behavior closely enough to steal the intellectual property it represents.
The attack has two primary objectives. Intellectual property theft reconstructs a proprietary model that an organization has invested significant resources to train, enabling a competitor or adversary to replicate that capability without the associated investment. Adversarial example transfer uses the extracted substitute model to develop adversarial examples offline that transfer to the target model, circumventing query-rate limits and monitoring that would otherwise detect a direct attack.
AAISM governance framing
Domain 3 addresses model extraction through API access controls, rate limiting, and output monitoring. The governance decision is not just whether rate limits are configured, but whether the organization has designed its model serving infrastructure to make systematic extraction economically unviable while maintaining legitimate usability.
Looking for some exam prep guidance and mentoring?
Learn about our personal mentoring

Model Inversion and Membership Inference
These two attack types target the data used to train a model rather than the model's behavior.
Model inversion recovers approximate reconstructions of training data from model outputs. Given sufficient query access to a model trained on sensitive data: medical records, financial transactions, or personal communications, an attacker can reconstruct data that approximates the original training inputs. For organizations using AI in healthcare or financial services, this creates direct regulatory exposure under HIPAA, GDPR, and equivalent frameworks.
Membership inference determines whether a specific individual's data was used to train a model. In healthcare, this can reveal that a patient's records were part of a study. In financial services, it can expose which customer accounts were used to train a fraud detection model. The attack does not reconstruct the underlying data but proves its presence in the training set, which can itself constitute a privacy violation under some regulatory frameworks.
AAISM Governance Framing
Domain 2 addresses both attack types through data minimization, differential privacy, and access control governance for AI training pipelines. The governance questions are: what is the minimum data required to train a model that meets the organization's objectives, what technical controls reduce model memorization of sensitive training data, and how does the organization detect and respond to membership inference attempts?
The full range of AI attack types and how they map to real detection and response practices form the foundation for the governance framing the exam tests. The free AI Threat Hunting Playbook from Destination Certification maps the detection and response thinking for AI-specific threats, including the attack categories addressed in this guide, and gives you a structured foundation before you start working through Domain 3 exam content formally.
What Microsoft's AI Red Team Found: The Governance Implications
The most authoritative real-world data on AI attack effectiveness comes from Microsoft's AI Red Team, which has conducted adversarial testing on AI systems since 2018. As Microsoft's Security Blog documents, after red teaming more than 100 generative AI products, the team drew a conclusion that reshapes how security leaders should think about AI defense: you do not need to compute gradients to break an AI system. Prompt injection and script-based fuzzing were consistently more effective than sophisticated machine learning evasion techniques against real production deployments.
This finding has direct implications for AI governance program design. If the most effective attacks against deployed AI systems are prompt-based rather than gradient-based, then the governance controls that matter most are the architectural ones: instruction hierarchy enforcement, input validation, output monitoring, and the access controls that determine what an AI system can see and do. The mathematically sophisticated attacks that dominate academic literature are less relevant to enterprise security programs than the operationally grounded ones that practitioners can execute with existing skills.
The second key conclusion: "the work of securing AI systems will never be complete." AI systems change through retraining, fine-tuning, and prompt updates. The attack surface evolves continuously. A governance program that treats AI security as a one-time assessment rather than an ongoing operational discipline will drift out of alignment with the actual threat environment faster than traditional software systems.
For AAISM, these findings frame Domain 3's emphasis on continuous adversarial testing as an ongoing governance obligation rather than a project deliverable.
How AAISM Maps These Attacks Across Its Domains
Domain 2: AI Risk Management (31%)
Domain 2: AI Risk Management is where AI attacks appear as risks to be assessed and treated. The exam tests whether you can identify which attack types are relevant for a given AI deployment context, evaluate their likelihood and impact based on the deployment architecture and data sensitivity, and select appropriate risk treatment approaches.
Exam questions in this area present deployment scenarios and ask which risk factors are most significant or which treatment approach is most appropriate. A healthcare organization deploying an AI system trained on patient records faces different risk prioritization than a financial services firm using AI for fraud detection. Domain 2 tests whether you can apply that context to risk assessment and treatment decisions.
Supply chain risk is particularly prominent in Domain 2 for AI attack scenarios. Data poisoning through third-party training data, model extraction enabling competitor IP theft, and backdoor attacks through compromised model checkpoints are all supply chain attack vectors that Domain 2 addresses through vendor risk assessment and procurement governance.
Domain 3: AI Technologies and Controls (38%)
Domain 3: AI Technologies and Controls is where the governance controls for these attack types are evaluated. The exam tests whether you understand what effective controls look like for each attack category, how to evaluate whether those controls are working, and what governance obligations apply when they fail.
For adversarial examples: input validation and adversarial robustness testing. For data poisoning: training data provenance, statistical anomaly detection, and supply chain security for AI components. For model extraction: API rate limiting, output perturbation, and query monitoring. For inference attacks: differential privacy implementation, data minimization, and access controls for model training environments.
The exam frames all of these as governance program decisions, not technical implementations. The question is always: what governance decision addresses this risk at the right layer of the problem, given the organization's risk tolerance and regulatory context?
Once you understand how AAISM frames these attacks as governance decisions rather than technical challenges, working through exam questions becomes significantly more structured. The free Neutral Playbook from Destination Certification builds the governance-first mental model that makes the distinction between technical knowledge and governance judgment clear before you encounter it in exam scenarios.
Certification in 3 Days
Study everything you need to know for the AAISM exam in a 3-day bootcamp!
What This Means for Your AAISM Preparation
Red teamers approaching AAISM have a genuine preparation advantage in Domain 3: they already understand how attacks work at a technical level, which makes the governance framing of controls more intuitive. The challenge is the mental model shift from "how do I execute this attack" to "what governance decision determines whether this attack is possible in the first place."
The preparation mistake red teamers specifically tend to make is over-indexing on technical attack detail and under-investing in the governance decision layer. Knowing the mathematical mechanics of adversarial example generation does not help you answer a Domain 2 question about which risk treatment approach is most appropriate for an organization deploying an image classification system in a high-risk regulatory environment. Knowing that adversarial examples exploit statistical decision boundaries, and that the governance response is ongoing adversarial robustness testing rather than a one-time assessment, does.
For the connection between AI attack techniques and the operational detection challenges they create, the AAISM LLM Security guide maps how prompt injection and related attacks appear in Domain 2 and Domain 3, and the AAISM Shadow AI guide addresses how unauthorized AI deployments expand the attack surface that governance programs must address.
For the complete AAISM certification context and how all three domains work together, the ISACA AAISM guide maps the full scope before you finalize your preparation approach.
Frequently Asked Questions
Adversarial examples manipulate model inputs at the statistical level to cause misclassification or incorrect outputs, targeting the model's learned behavior rather than its instruction-following capability. Prompt injection manipulates natural language instructions to override a deployed system's intended behavior, targeting the application layer rather than the underlying model. Both are AI-specific attack vectors, but they operate at different layers and require different defensive controls.
Traditional data theft requires access to a data store: a database, a file system, or a network share. Model extraction requires only query access to a deployed model's API. The attacker does not steal data directly; they reconstruct the model's decision-making logic through systematic probing, which constitutes intellectual property theft without any direct data access. The governance controls are also different: rate limiting, output perturbation, and query monitoring address model extraction in ways that have no direct equivalent in traditional data protection.
Both Domain 2 and Domain 3 address AI attacks, but from different angles. Domain 2 treats attacks as risks to be identified, assessed, and treated within the AI risk management program. Domain 3 addresses the governance controls designed to detect, prevent, and respond to those attacks. Together, they account for 69% of the exam weight, making AI attack governance one of the most heavily tested areas across the certification.
Traditional malware is typically detected and remediated after execution: antivirus, endpoint detection, and incident response are the relevant governance controls. Data poisoning corrupts model behavior before deployment through the training process, making it undetectable by runtime security tools. The governance response requires training data provenance controls, statistical anomaly detection during the training pipeline, and supply chain security for AI components, all of which operate upstream of deployment rather than at the operational security layer.
The Attack Surface Is Expanding. The Credential That Validates AI Security Expertise Is Here
You now understand how adversarial examples, data poisoning, model extraction, and inference attacks work at the level AAISM tests, how each attack type maps to governance decisions in Domain 2 and Domain 3, and why the governance framing matters more than technical execution depth for exam performance. The red team practitioner who can translate offensive AI knowledge into governance program decisions is exactly who AAISM was designed to certify.
If you want to move fast, the AAISM Bootcamp delivers all three domains in three intensive days of live online instruction, with expert-led sessions and real-time Q&A throughout. If your schedule requires more flexibility, the AAISM MasterClass gives you the same expert instruction at your own pace, with an adaptive learning system that identifies exactly what you still need to work on across all three domains.
Before committing to a full program, the free AI Threat Hunting Playbook from Destination Certification maps the detection and response framework for the AI attack types addressed in this guide, so you have a concrete picture of what the formal preparation builds on before you begin.
Red teamers who understand AI attacks understand the defenses better than anyone else. AAISM validates that expertise at the governance level.
John is a major force behind the Destination Certification CISSP program's success, with over 25 years of global cybersecurity experience. He simplifies complex topics, and he utilizes innovative teaching methods that contribute to the program's industry-high exam success rates. As a leading Information Security professional in Canada, John co-authored a bestselling CISSP exam preparation guide and helped develop official CISSP curriculum materials. You can reach out to John on LinkedIn.








