Find the insights and best practices about our product.
Arena Model Vulnerabilities

This endpoint returns model vulnerability findings across every model in your tenant, so you can track AI model risk in your own vulnerability management or GRC tooling.

List Arena Model Vulnerabilities

Returns a paginated list of model vulnerability findings (attack categories) across all models in your tenant. Each record represents on aggregated attack category result per model, combining all penetration test runs for that model into a single success ratio. Technology vulnerabilities and model vulnerabilities are tracked as separate endpoints, since CVE-based package findings and pen-test-based model findings have fundamentally different schemas; poll both independently if you need both. See the Technology Vulnerabilities endpoint reference for package-level findings.

Request

GET /api/public/arena/attackcategories

Authentication

Bearer token. See Authentication & Generating Credentials.

Required Permission

Api_ArenaModels_Read

Query parameters:

Response Fields

Sample Response

{
"data": [
{
"uniqueId": "d3e4f5a6-2a1b-4c3d-9e0f-1a2b3c4d5e6f",
"billOfMaterialsId": "a1b2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d",
"billOfMaterialsName": "my-ml-service",
"modelId": "d3e4f5a6-7b8c-4d9e-0f1a-2b3c4d5e6f7a",
"modelName": "llama-3-8b-instruct",
"modelType": "LLM",
"modelSource": "HuggingFace",
"attackCategoryId": "f5a6b7c8-9d0e-4f1a-2b3c-4d5e6f7a8b9c",
"attackCategory": "Prompt Injection",
"attackCategoryDescription": "Attempts to override the model's original instructions",
"attackAlgorithm": "PAIR",
"attackFramework": "Cranium Arena",
"attackSuccessRatio": 0.73,
"severityLevel": "Critical",
"weakness": "Insufficient input sanitization",
"resolvedStatus": null,
"remediationGuidance": "Add an explicit system-prompt guard against instruction override attempts.",
"updatedDate": "2026-04-01T00:00:00Z"
}
],
"pagination": {
"limit": 100,
"nextCursor": "eyJ1cGRhdGVkQXQiOiIyMDI2LTA0LTAxVDAwOjAwOjAwWiIsImlkIjoiZDNlNGY1YTYifQ==",
"hasMore": false
},
"error": null,
"meta": {
"requestId": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"timestamp": "2026-08-24T10:15:00Z"
}
}


attackCategoryId is the stable dictionary identifier for the attack category; prefer it over the attackCategory name when correlating across systems, since names may be localized or renamed. remediationGuidance contains AI-generated remediation advice and is null when remediation hasn't been generated for that finding yet. resolvedStatus reflects user-actioned resolution only: attack categories that no longer appear in subsequent penetration test runs are not automatically marked as resolved. They remain in the feed with resolvedStatus: null until a user explicitly resolved them in Cranium.

Error Responses

  • 400 VALIDATION_FAILED: the cursor is invalid, or cursor and updatedAfter were supplied together.
  • 401 UNAUTHORIZED: the request is missing a token, or the token lacks the required permission.
  • 500 INTERNAL_ERROR: an unexpected server error.

Why Model & Technology Vulnerabilities are Separate Endpoints

Technology vulnerabilities are CVE-based findings from package scanning, with CVSS scores and fixed versions. Model vulnerabilities are penetration test results from Cranium Arena, with attack categories, success ratios, and dataset context. They have fundamentally different schemas and remediation workflows. A unified endpoint would require a discriminated union schema with roughly half the fields nullable on each record type. Two focused endpoints with clean schemas allow each surface to evolve independently. To retrieve a complete vulnerability picture for a tenant, poll both endpoints.


Did this answer your question?