Masquerading
How AML.T0074 Masquerading shows up in practice: the mapped risk classes in this atlas, the documented incidents that prove it's real, and the scenarios and controls to learn and defend against it.
Mapped risks
Risk classes in this atlas that map to AML.T0074 — click through for the full definition, attack surface and controls.
Real-world cases
2Documented incidents, disclosed vulnerabilities and research that illustrate AML.T0074 — latest first, each with sources.
A universal, black-box, query-free attack that removes AI image watermarks including Google SynthID and Meta Stable Signature without knowing the scheme.
Constructive proof that any strong generative-model watermark can be removed, demonstrated against three LLM watermarking schemes.
Controls & guardrails that address this
4Guardrails across the risks mapped to AML.T0074, grouped by control function. Filter by control category below.
Making sure the machinery running the model — and the template used to stamp out new agents — is the real, unmodified version, and that one user's data can't leak into another's through shared shortcuts.
Tag AI-made content with a signed 'where it came from' label and an invisible watermark, and check those signals downstream — so AI media can be traced and flagged.
Live dashboards and alarms that notice unusual behaviour — spikes in errors, weird actions, sudden data access.
The organisational habits around the AI: assessing risks before launch, actively trying to break it, and having a plan for when something goes wrong.