Finance: Fraud goes undetected
Adversarial attacks on fraud detection systems allow attackers to slip fraudulent transactions past detection - with minimal adjustments to transaction features.
ML Model Security
Fraud detection systems, credit scoring models, medical diagnostics - they are all attackable. A crafted image fools your classifier. A poisoned data point corrupts training. We test your models against exactly these attacks - following OWASP ML Top 10, with documented findings.
The Problem
Classical ML systems have an attack surface that conventional penetration tests do not capture: they are statistically attackable - not through code exploits, but through targeted manipulation of input and output data. For production systems in regulated industries, this is not an academic problem.
Finance: Fraud goes undetected
Adversarial attacks on fraud detection systems allow attackers to slip fraudulent transactions past detection - with minimal adjustments to transaction features.
Healthcare: Diagnostics manipulated
Adversarial examples on medical imaging systems can cause a tumor to go undetected or a misdiagnosis to be made - without any visible image manipulation.
GDPR: Personal data extractable from the model
Model inversion and membership inference threaten data protection compliance: conclusions about training data can be drawn from your model - even without access to the original data.
ATTACK EXAMPLE - EVASION ATTACK
ATTACK EXAMPLE - MEMBERSHIP INFERENCE
What We Test
Every test covers all OWASP ML Top 10 categories - with verified proof-of-concept exploits for your specific model.
Minimal manipulations of input data - invisible to humans - that force the model into misclassification. White-box attacks (FGSM, PGD, C&W) using gradient descent and black-box attacks through transfer and query methods. Particularly critical for fraud detection, image classification, and quality control.
critical · OWASP ML01 · FGSM · PGD · C&W
Manipulation of the training dataset to plant backdoors or systematically degrade model quality. Particularly critical for continuously retrained systems (online learning, feedback loops). We analyze your data ingestion pipeline and training processes for poisoning vectors.
critical · OWASP ML02 · Backdoor · Clean-Label
Reconstruction of training data through systematic API queries. Particularly relevant for models trained on personal data. We quantify how precisely input features can be inferred from output information - direct GDPR risk assessment.
high · OWASP ML03 · GDPR Risk
Statistical attacks to determine whether a data point was used in training. Confidence-based and shadow-model-based attack methods. We measure the attack success rate and determine information leakage per GDPR Article 5 (purpose limitation, data minimization).
high · OWASP ML04 · Art. 5 GDPR
Theft of model weights or behavior through systematic querying of the inference API. We measure how many queries are needed for accurate extraction, and test your API protections: rate limiting, output perturbation, query pattern detection.
high · OWASP ML05 · IP Protection
Auditing pre-trained models from public sources (Hugging Face, TensorFlow Hub, PyPI) for known and novel backdoor signatures. Analysis of the training supply chain: which third-party datasets were used? Are they trustworthy and auditable?
critical · OWASP ML07 · MITRE ATLAS AML.T0010
Industries
Wherever ML models automatically make decisions with consequences for people or organizations - security resilience is not an option, it is a requirement.
Finance
DORA · Financial regulation · MaRisk
Healthcare
EU AI Act High-Risk · MDR
Insurance
GDPR · Solvency II
Industry & Quality Control
NIS-2 · IEC 62443
Methodology
Systematic attack simulation per OWASP ML Top 10 and MITRE ATLAS - combined with GDPR risk assessment.
2-3 days
Identification of all ML components, data flows, and dependencies. Threat modeling per MITRE ATLAS (ML-specific tactics). Assessment of the regulatory framework: EU AI Act risk class, GDPR processing basis, industry-specific requirements. Definition of test scope and rules of engagement.
2-4 days
Architecture analysis: model type, framework (scikit-learn, PyTorch, TensorFlow), training history, feature engineering. API endpoint mapping: what inputs are accepted? How precise are the outputs? Training supply chain analysis: data sources, frameworks, pre-trained models. Attack surface identification.
5-8 days
White-box attacks (with model access): gradient-based methods (FGSM, PGD, Carlini & Wagner), backward pass differentiable approximation. Black-box attacks (API only): transfer-based methods, zeroth-order optimization, square attack. Tabular data: feature manipulation, constraint-based evasion for fraud and scoring systems.
3-5 days
Model inversion: reconstruction of input features from outputs. Membership inference: confidence ratio attacks, shadow model method, LiRA attack. Attribute inference: can unsubmitted features be inferred? Quantitative GDPR risk calculation: information leakage in bits, precision/recall of attacks.
2-4 days
Audit of all pre-trained models and datasets used. Backdoor detection with neural cleanse methods (NC, STRIP, ABS). Testing the data ingestion pipeline for poisoning vectors. CI/CD analysis: are training pipelines protected from unauthorized manipulation?
2-4 days
Technical report with OWASP ML mapping, MITRE ATLAS references, and CVSS v4 scoring. GDPR risk section: quantified information leakage and recommendations. EU AI Act compliance evidence for Art. 15 (robustness, cybersecurity). Prioritized remediation roadmap: defense-in-depth strategy (adversarial training, differential privacy, monitoring).
Typical total duration: 15-25 days - depending on model complexity, data access, and test depth.
You receive a binding fixed-price offer within 48 hours (business days) from EUR 15,000.
Compliance & Regulation
Every finding is mapped to relevant standards and regulations. Your report is audit-ready.
Systematic testing of all ten vulnerability categories for ML systems - the de facto standard for ML security assessments worldwide.
ML01-ML10 · fully covered
Threat modeling using the AI-specific ATT&CK equivalent: tactics and techniques of real attacks on ML systems as the basis for test planning.
Tactics · Techniques · Procedures
Evidence of robustness against adversarial attacks, data poisoning, and model manipulation for high-risk AI systems per Article 15.
High-risk AI · GPAI since Aug. 2025
Quantified evidence of information leakage through model inversion and membership inference. Technical measures per privacy by design (Art. 25).
Privacy by Design · Risk Report
Technical evidence for the operational AI security controls of the AI management system standard - foundation for ISO 42001 certification.
38 controls · 9 objective categories
Mapping to the core functions Govern, Map, Measure, Manage. Particularly relevant for the AI RMF Adversarial ML Profile (NIST AML).
NIST AML · GenAI Profile (2024)
Why AWARE7
Pure awareness platforms don't test systems. Pure consulting firms are too far removed. AWARE7 combines both: we hack your infrastructure and train your employees: tailored to mid-sized companies, personal, without enterprise overhead.
Around 20% of our revenue comes from research projects for the BSI and the BMBF. Our studies, published at ACM and Springer conferences, analyse millions of websites and tens of thousands of phishing emails. Three of our executives are professors at German universities at the same time.
From first contact to final report, your data is stored on our own servers in Germany - no US cloud providers, no third-country transfers. Our AI also runs on our own hardware in Germany - with locally operated open-source models. Client and project data never reach external AI services. All staff are permanently employed, covered by social insurance and bound by uniform legal obligations.
More on digital sovereigntyWithin 24 hours you receive a binding fixed-price quote without hourly rate risk. A well-practised team and standardised processes ensure a clear schedule with a defined start and end date.
A personal project manager accompanies you from the first meeting to the retest. You book appointments directly with your contact person and keep the same contact throughout the project.
Peer-reviewed publications
Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations
ACM AsiaCCS 2025
Oskar Braun, Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
A Platform for Physiological and Behavioral Security
NSPW 2025
Jan Hörnemann
Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem
IEEE/IFIP DSN 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Understanding Regional Filter Lists: Efficacy and Impact
PoPETS 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Who is AWARE7 the right partner for?
Mid-sized companies with 50-2,000 employees
Companies that need real security, without paying for a DAX-corporation provider. Fixed price, clear scope, one point of contact.
IT managers & CISOs
Who have to argue convincingly in-house and need a report in boardroom language for that, not just technical findings.
Regulated industries
Critical infrastructure, healthcare, financial services: NIS-2, ISO 27001, DORA. We know the requirements and deliver evidence that auditors accept.
FAQ
Everything you should know about adversarial attacks, data poisoning, and GDPR risks in ML systems.
Our experts test your fraud detection system, scoring model, or AI diagnostics against all OWASP ML Top 10 attacks - with a fixed-price commitment and GDPR risk assessment.
Free · 30 minutes · No obligation
Arturs Nikitins
Initial consultation & needs analysis
Looking for personal advice?
No obligation · Reply within 24h on business days