Original framework · Needs validation · 3/5
The ATLAS Wall.
The D3FEND Wall asks the defensive question: what don't you cover? This is the same map drawn for the AI-attack world, so it asks the same question of MITRE ATLAS itself. Every ATLAS mitigation runs across the top, every ATLAS technique down the side, and a cell is filled where ATLAS maps that mitigation to that technique. The shape that falls out is mostly empty, and the empty part is the point.
What the wall shows
ATLAS carries 247 mitigation-to-technique mappings, which sounds like coverage until you count the rows it leaves blank: 97 of the 173 techniques (56%) have no mapped mitigation at all, and 36 of those uncovered techniques are Realized — ATLAS's own label for techniques observed in real incidents, not just demonstrated in a lab. The single most-exercised recent technique, LLM Prompt Crafting, shows up in 15 recent case studies and has zero mapped ATLAS mitigations. Coverage is not just sparse; it thins out exactly where the newest attacks are landing.
How the cells are weighted
A filled cell is hi or low, and the rule is deliberately simple so you can rebuild it or disagree with it. A cell scores on two signals that ATLAS actually carries: the maturity of the target technique (Realized counts more than Demonstrated or Feasible) and whether that technique was exercised in a recent 2024–2026 case study. A cell is hi only where both hold — a mapping to a real, recently-seen technique — which is the one place the maturity read and the recency read agree. 67 of the 247 cells clear that bar; the other 180 are mapped but point at something less mature or less recent.
Mapping is relevance, not interdiction
This is the caveat the whole artifact rests on, so it rides on the front rather than in a footnote. A mapping says a mitigation is relevant to a technique; it does not say the mitigation would have stopped the attack. I tested that gap directly: across nine recent agentic and GenAI case studies, 17 mapped (mitigation, case) pairs looked like they might plausibly interdict a step, and under an adversarial refuter told to default to skepticism, zero of the 17 survived. So read a hi cell as “mapped to a real, recent technique,” never as “this would have worked.” ATLAS carries no efficacy measurement, and the wall does not invent one.
Built from MITRE ATLAS v2026.06 (Apache-2.0), reproducibly, from the committed edge, maturity, recency, and counterfactual layers. SCF is deliberately excluded from the weighting, which keeps the artifact single-licence and clean to publish. Method and every number: the ATLAS-Wall claims register.