Abstract: A method and system is provided which enables the operating environment around an ML model to be monitored to determine whether an attack is taking place. A method and system is provided enables the ML model to be analysed in a framework independent manner.