<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><title>AITBM AI Security Use Cases</title><link>https://aitbm.org/use-cases</link><description>Public-evidence AI security cases, AITBM risk scenarios, and research notes.</description><language>en</language><lastBuildDate>Thu, 13 Aug 2026 00:00:00 +0000</lastBuildDate>  <item><title>Deadbugz: GitHub PRs Delivered a Delayed, Shape-Shifting Malicious MCP Server</title><link>https://aitbm.org/use-cases/deadbugz-mcp-supply-chain-campaign</link><guid>https://aitbm.org/use-cases/deadbugz-mcp-supply-chain-campaign</guid><pubDate>Wed, 12 Aug 2026 00:00:00 +0000</pubDate><description>MCP onboarding cannot be a one-time trust decision: clients must bind descriptor and prompt semantics, detect drift, and re-authorize every consequential action against current user intent.</description><category>AI security case study</category></item>  <item><title>Stolen Thoughts: Opaque Reasoning Blocks Could Be Replayed to Recover Secrets</title><link>https://aitbm.org/use-cases/stolen-thoughts-reasoning-trace-extraction</link><guid>https://aitbm.org/use-cases/stolen-thoughts-reasoning-trace-extraction</guid><pubDate>Wed, 12 Aug 2026 00:00:00 +0000</pubDate><description>Opaque state is not safe state: reasoning artifacts need confidentiality, principal/session binding, bounded retention, and an output gate before they enter logs or client-visible trajectories.</description><category>AI security case study</category></item>  <item><title>LangSmith Tracing Header Injection Turned Observability Metadata into a Data Route</title><link>https://aitbm.org/use-cases/langsmith-tracing-header-injection</link><guid>https://aitbm.org/use-cases/langsmith-tracing-header-injection</guid><pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate><description>Observability metadata is routing authority when it can select an exporter; trace context must be schema-restricted, destination-pinned, and minimized before export.</description><category>AI security case study</category></item>  <item><title>SGLang&#x27;s ZMQ and Pickle Paths Show Why Internal AI Messages Need a Trust Boundary</title><link>https://aitbm.org/use-cases/sglang-zmq-pickle-deserialization-rce</link><guid>https://aitbm.org/use-cases/sglang-zmq-pickle-deserialization-rce</guid><pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate><description>An internal AI message bus is still an untrusted code boundary: peer identity, segmentation, and safe serialization must hold before bytes reach a deserializer.</description><category>AI security case study</category></item>  <item><title>Pydantic AI Shows How Message History Can Become Server-Side Fetch Authority</title><link>https://aitbm.org/use-cases/pydantic-ai-message-history-ssrf</link><guid>https://aitbm.org/use-cases/pydantic-ai-message-history-ssrf</guid><pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate><description>Serialized conversation history is active authority when deserialization triggers I/O; replay paths require the same destination policy as an explicit network tool call.</description><category>AI security case study</category></item>  <item><title>MCFA Turns Agent Memory into a Delayed Control-Flow Input</title><link>https://aitbm.org/use-cases/mcfa-memory-control-flow-attacks-agent-memory</link><guid>https://aitbm.org/use-cases/mcfa-memory-control-flow-attacks-agent-memory</guid><pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate><description>Long-term memory is persistent control input: every write needs provenance and promotion policy, and every recall must be re-authorized against the current task before it can influence tools.</description><category>AI security case study</category></item>  <item><title>Poisoned GGUF Chat Templates Backdoor Inference Without Changing Model Weights</title><link>https://aitbm.org/use-cases/poisoned-gguf-chat-template-inference-backdoor</link><guid>https://aitbm.org/use-cases/poisoned-gguf-chat-template-inference-backdoor</guid><pubDate>Sun, 02 Aug 2026 00:00:00 +0000</pubDate><description>Model weights are only one executable release component; chat templates must be digest-bound, provenance-checked, and security-regression-tested with the same rigor as the weights.</description><category>AI security case study</category></item>  <item><title>Model Namespace Reuse Turns a Trusted Name Into a Supply-Chain Redirect</title><link>https://aitbm.org/use-cases/model-namespace-reuse-supply-chain-attack</link><guid>https://aitbm.org/use-cases/model-namespace-reuse-supply-chain-attack</guid><pubDate>Sun, 02 Aug 2026 00:00:00 +0000</pubDate><description>A familiar model name is not an identity: deployment admission must bind approved bytes, signer, source ownership, and loader policy before first load and every reload.</description><category>AI security case study</category></item>  <item><title>ZombieAgent Shows How Connector Prompt Injection Can Persist and Spread</title><link>https://aitbm.org/use-cases/zombieagent-chatgpt-connector-persistent-exfiltration</link><guid>https://aitbm.org/use-cases/zombieagent-chatgpt-connector-persistent-exfiltration</guid><pubDate>Sun, 02 Aug 2026 00:00:00 +0000</pubDate><description>Persistent memory changes prompt injection from a one-chat event into delayed control flow; trusted intent must govern both memory promotion and every later rehydration.</description><category>AI security case study</category></item>  <item><title>Claude Code GitHub Action: When a File-Read Tool Crosses the CI Secret Boundary</title><link>https://aitbm.org/use-cases/claude-code-github-action-secret-exposure</link><guid>https://aitbm.org/use-cases/claude-code-github-action-secret-exposure</guid><pubDate>Sun, 02 Aug 2026 00:00:00 +0000</pubDate><description>A sandbox is only as strong as its least-governed sibling tool: the Bash boundary held, but the in-process Read path crossed the same CI-secret boundary without equivalent enforcement.</description><category>AI security case study</category></item>  <item><title>AgentForger Turned One ChatGPT Link Into a Scheduled Autonomous Insider</title><link>https://aitbm.org/use-cases/agentforger-chatgpt-workspace-agent-autonomous-insider</link><guid>https://aitbm.org/use-cases/agentforger-chatgpt-workspace-agent-autonomous-insider</guid><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><description>A platform can ship an approval gate and still score Cn-6 = 0.00 when that gate is writable by the very workflow it governs — AITBM scores the exercised configuration, not the nominal capability — and because the forged agent constitutes an identity-boundary change with new tool authority, the C_event &lt;= 0.35 cap, not the seven-day calendar age, is what sets Temporal Freshness.</description><category>AI security case study</category></item>  <item><title>Frontier Lab Agent Intrusion into Hugging Face: Technical Reconstruction and Defensive Priorities</title><link>https://aitbm.org/use-cases/openai-evaluation-agent-hugging-face-production-breach</link><guid>https://aitbm.org/use-cases/openai-evaluation-agent-hugging-face-production-breach</guid><pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate><description>A case can have eight or nine genuinely effective controls — an SSRF allowlist that never failed, 84 straight denials at the credential store, digest verification that kept the supply chain clean — and still sit at the ceiling of the ORP layer, because AITBM scores boundaries independently rather than crediting an incident for the boundaries that happened not to be on the attacker&#x27;s path: one ungated escalation route from an entry-exposed workload to credential-issuing nodes forces Cp to 1.00 on its own merits, and no number of denials elsewhere reduces it.</description><category>AI security case study</category></item>  <item><title>Notion AI Agent Lethal Trifecta Leads to Silent Data Exfiltration</title><link>https://aitbm.org/use-cases/notion-ai-agent-lethal-trifecta-exfiltration</link><guid>https://aitbm.org/use-cases/notion-ai-agent-lethal-trifecta-exfiltration</guid><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><description>A human-approval gate only counts for as much of the chain as it actually governs: Notion&#x27;s page-edit approval was real enough to raise Aa to 0.50 and hold Cn-6 above zero, yet the render hop that fired before the gate carried the data out, which is exactly the worst-case chain-composition condition Cn-6&#x27;s upper anchors require and the reason Cp still resolves to 1.00.</description><category>AI security case study</category></item>  <item><title>Moltbook Shows How Agent Social Feeds Can Become a Global Callback Surface</title><link>https://aitbm.org/use-cases/moltbook-agent-network-callback-map</link><guid>https://aitbm.org/use-cases/moltbook-agent-network-callback-map</guid><pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate><description>This is the reference case for cp_basis = default: the agents are maximally exposed and their navigation action is entirely ungated, yet the measured terminal impact is a benign HTTP request, so Cp = 1.00 is the spec&#x27;s worst-case default for a missing System Dependency Graph rather than a finding the evidence corroborates — and saying which of the two applies is what keeps a published ERS honest.</description><category>AI security case study</category></item>  <item><title>AgentFlayer Turns ChatGPT Connectors Into a Zero-Click Exfiltration Path</title><link>https://aitbm.org/use-cases/agentflayer-chatgpt-connectors-zero-click-exfiltration</link><guid>https://aitbm.org/use-cases/agentflayer-chatgpt-connectors-zero-click-exfiltration</guid><pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate><description>AgentFlayer is the batch&#x27;s clearest case of a control that half-held changing two scores at once: because a URL reputation check existed and had to be bypassed, Cn-3 sits at the rubric&#x27;s bypass anchor (0.25) rather than its absence anchor — yet under the GDCP rule that a gate may only be claimed at CBR &gt;= 0.95, that same demonstrated bypass invalidates the gate for cascade purposes and makes Cp corroborated rather than defaulted. The 358-day evidence age is the second lesson: it drives Temporal Freshness toward zero and, per spec 3.3.4, that is the framework declaring the assessment stale rather than declaring the product risky.</description><category>AI security case study</category></item>  <item><title>Prompt Mines Show Why CRM Agents Need Write-Action Gates</title><link>https://aitbm.org/use-cases/salesforce-einstein-prompt-mines-data-corruption</link><guid>https://aitbm.org/use-cases/salesforce-einstein-prompt-mines-data-corruption</guid><pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate><description>This is the cleanest Cn-6 = 0.00 in the set and shows why AITBM separates Cn-6 from Cn-1: the agent never exceeded its granted CRM permissions, so a permission-only assessment would find nothing wrong, yet the absence of any pre-execution reversibility classification let an ungated bounded-irreversible write execute repeatedly on the authority of anonymous external text.</description><category>AI security case study</category></item>  <item><title>PerplexedBrowser: When an Agent Browser Can Read Local Files</title><link>https://aitbm.org/use-cases/perplexedbrowser-comet-local-file-exfiltration</link><guid>https://aitbm.org/use-cases/perplexedbrowser-comet-local-file-exfiltration</guid><pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate><description>This case shows the Behavioral Attestation Window being correctly withheld: the agent is unambiguously Agentic and scores at the ORP ceiling, but none of the four BAW checklist items is evidenced for a single-session browser agent, so applying the behavioural staleness floor would have been an assumption rather than a finding — the freshness penalty here comes from the event and monitoring caps, which the evidence does support.</description><category>AI security case study</category></item>  <item><title>LangGraph Checkpointer Bugs Turn Agent State History Into an RCE Path</title><link>https://aitbm.org/use-cases/langgraph-checkpointer-sqli-deserialization-rce</link><guid>https://aitbm.org/use-cases/langgraph-checkpointer-sqli-deserialization-rce</guid><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><description>LangGraph is the cleanest available demonstration that agent memory is an Ro-4 poisoning surface rather than a storage detail: an attacker-planted checkpoint row promoted straight into trusted agent state with no signature, type guarantee or quarantine gate scores Ro-4 = 0.00 outright — and because the checkpointer is exactly the cross-session model-writable memory the BAW checklist describes, the same fact that sets Ro-4 also switches on the behavioural staleness floor.</description><category>AI security case study</category></item>  <item><title>ChainLeak Shows How AI Framework Helper APIs Can Expose Prompts, Files, and Cloud Keys</title><link>https://aitbm.org/use-cases/chainleak-chainlit-file-read-ssrf-cloud-takeover</link><guid>https://aitbm.org/use-cases/chainleak-chainlit-file-read-ssrf-cloud-takeover</guid><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><description>Two AITBM behaviours meet in this case: As sitting exactly on 0.75 keeps N_elevated at one and CRM at 1.00 even though the cascade path is corroborated all the way to a credential-issuing node, and 191-day-old evidence about a stateful consumer-facing app drives the behavioural freshness floor low enough that the honest conclusion is &#x27;reassess&#x27;, not &#x27;here is a precise score&#x27;.</description><category>AI security case study</category></item>  <item><title>AutoJack Turns Localhost Agent Control Planes Into a Browser-RCE Lesson</title><link>https://aitbm.org/use-cases/autojack-autogen-studio-localhost-agent-rce</link><guid>https://aitbm.org/use-cases/autojack-autogen-studio-localhost-agent-rce</guid><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><description>A loopback-bound control plane is not a lower-exposure deployment: because a browsing agent renders untrusted content on the same host, As reaches the 1.00 anchor and the Cp path is corroborated end-to-end — while the thin two-axis evidence base forces the Lite Ec cap, showing how AITBM records the limits of its own evidence rather than papering over them.</description><category>AI security case study</category></item>  <item><title>A Clean Repo Can Still Turn an AI Coding Agent Into a Reverse Shell</title><link>https://aitbm.org/use-cases/clean-repo-claude-code-dns-reverse-shell</link><guid>https://aitbm.org/use-cases/clean-repo-claude-code-dns-reverse-shell</guid><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><description>This is the batch&#x27;s only case with no patch to point at, and it lands where AITBM says it should: Rf = 0.75 rather than 0.00 because every remedy is an external containment layer, while Cn-6 = 0.00 for a subtler reason than a missing gate — the payload arrived over DNS at runtime, so the action&#x27;s reversibility class was undeterminable at the only moment a gate could have fired.</description><category>AI security case study</category></item>  <item><title>PerplexedBrowser Shows Why Agentic Browsers Need Session and Sink Boundaries</title><link>https://aitbm.org/use-cases/perplexedbrowser-comet-1password-agent-hijack</link><guid>https://aitbm.org/use-cases/perplexedbrowser-comet-1password-agent-hijack</guid><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><description>PerplexedBrowser is the case where the assessed system&#x27;s own security controls were largely irrelevant to the outcome: the vault held, the model filter partly held, and the system still failed — because Cn-1, Cn-3 and Cn-6 were all measuring boundaries that simply did not exist between an untrusted-content task and an authenticated session sharing one agent context, which is why Cp is corroborated at 1.00 rather than defaulted.</description><category>AI security case study</category></item>  <item><title>Amazon Q&#x27;s MCP Auto-Load Bug Made Cloned Repos a Cloud Credential Risk</title><link>https://aitbm.org/use-cases/amazon-q-mcp-auto-execution-cloud-credential-theft</link><guid>https://aitbm.org/use-cases/amazon-q-mcp-auto-execution-cloud-credential-theft</guid><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><description>When a client treats repository content as configuration, the poisoning surface is the tool manifest rather than the model — Ro-4 and Cn-5 both collapse to 0.00 on the same evidence, and a shipped, version-boundaried vendor fix earns Rf = 0.00 without moving any IVP score, which is exactly the layer separation AITBM is built to preserve.</description><category>AI security case study</category></item>  <item><title>DifyTap Turns Multi-Tenant AI App Plumbing Into a Data Exposure Problem</title><link>https://aitbm.org/use-cases/difytap-cross-tenant-ai-data-exposure</link><guid>https://aitbm.org/use-cases/difytap-cross-tenant-ai-data-exposure</guid><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><description>DifyTap is the case that separates audit-trail completeness from audit-trail safety: Tr-3 field coverage was strong enough for the 0.75 band and still capped at 0.50, because the 0.75 criterion requires the trail to be access-controlled — and the same records that made the platform investigable were the records that leaked across tenants.</description><category>AI security case study</category></item>  <item><title>JADEPUFFER Shows Agentic Ransomware Moving From AI RCE to Database Extortion</title><link>https://aitbm.org/use-cases/jadepuffer-agentic-ransomware-langflow-database-extortion</link><guid>https://aitbm.org/use-cases/jadepuffer-agentic-ransomware-langflow-database-extortion</guid><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><description>JADEPUFFER is the case that forces the assessor to keep the attacker out of the assessed system: the agentic behaviour that compressed the kill chain to 31-second self-repair belonged to the offence, so it drives no ORP or BAW score here — what AITBM scores is a Tier 1 workflow host with Cn-1, Cn-2 and Cn-5 all at 0.00 and a corroborated Cp = 1.00 traced from an unauthenticated origin to a P4 backdoor-administrator terminal.</description><category>AI security case study</category></item>  <item><title>LiteLLM Control Plane Is Being Hit in the Wild</title><link>https://aitbm.org/use-cases/litellm-control-plane-active-exploitation</link><guid>https://aitbm.org/use-cases/litellm-control-plane-active-exploitation</guid><pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate><description>An AI gateway with no agents, no memory and no autonomy still classifies as Connected GenAI and still forces Cp = 1.00 on its merits — because the corroborating path runs through a credential-issuing (P4) node rather than through autonomy, showing that AITBM&#x27;s cascade term is driven by reachable privilege, not by how &#x27;agentic&#x27; the system sounds.</description><category>AI security case study</category></item>  <item><title>Exposed LLM Backends Are Becoming Attacker AI Compute</title><link>https://aitbm.org/use-cases/exposed-llm-backends-offensive-ai-compute</link><guid>https://aitbm.org/use-cases/exposed-llm-backends-offensive-ai-compute</guid><pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate><description>Architecture class is scored on the assessed boundary, not on the attacker&#x27;s behaviour: the exposed backend is a Standalone LLM with Aa = 0.25 and baw/agentic both false, yet three Containment sub-metrics sit at 0.00 and Cp is corroborated at 1.00 — an unauthenticated endpoint can be maximally exposed and trivially remediable (Rf = 0.00) at the same time, and the thin two-axis evidence base correctly forces the Lite Ec cap.</description><category>AI security case study</category></item>  <item><title>Lingua Ex Machina: When the AI Monitor Cannot See What the Executor Sees</title><link>https://aitbm.org/use-cases/lingua-ex-machina-tokenizer-monitor-blind-spots</link><guid>https://aitbm.org/use-cases/lingua-ex-machina-tokenizer-monitor-blind-spots</guid><pubDate>Sat, 27 Jun 2026 00:00:00 +0000</pubDate><description>Detection capability and evidence freshness are scored in different layers, and this case separates them cleanly: the monitor&#x27;s blindness is a point-in-time IVP finding at Ro-1 and Cn-3, while the same sensor loss independently caps ACI Temporal Freshness through C_monitor and Band 0 C_behavior — and because the report measured visibility rather than consequence, Cn-1 and Cn-6 are correctly omitted instead of guessed.</description><category>AI security case study</category></item>  <item><title>SearchLeak: How a Microsoft 365 Copilot Search Link Became a One-Click Data Exfiltration Path</title><link>https://aitbm.org/use-cases/microsoft-365-copilot-searchleak-one-click-data-exfiltration</link><guid>https://aitbm.org/use-cases/microsoft-365-copilot-searchleak-one-click-data-exfiltration</guid><pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate><description>This is the clean illustration of cp_basis = &#x27;default&#x27; versus &#x27;corroborated&#x27;: all four stack layers were reachable and data did leave the tenant, but every terminal node in the observed path was read-scoped, so the reconstruction supports 0.75 on its merits and Cp = 1.00 applies only because no verified System Dependency Graph exists — while the controls that held (CSP, entitlement scoping, a real sanitiser) raise Cn-2 and Ro-1 well above the containment floor.</description><category>AI security case study</category></item>  <item><title>Agentjacking: How Fake Sentry Errors Turn MCP Telemetry into Agent Code Execution</title><link>https://aitbm.org/use-cases/agentjacking-sentry-mcp-coding-agent-hijack</link><guid>https://aitbm.org/use-cases/agentjacking-sentry-mcp-coding-agent-hijack</guid><pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate><description>A tool integration that is read-only by design can still drive an agent to code execution: the boundary that failed is the MCP output boundary, not the model, which is why Ro-1 stays at 0.25 while five Containment sub-metrics sit at the ad-hoc anchor and Cp is corroborated at 1.00 by an ungated path from an anonymous event submitter to host credential material.</description><category>AI security case study</category></item>  <item><title>Gemini Voice Assistant: When Phone Notifications Become Prompt Injection</title><link>https://aitbm.org/use-cases/gemini-notification-idpi-fake-context-alignment</link><guid>https://aitbm.org/use-cases/gemini-notification-idpi-fake-context-alignment</guid><pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate><description>A confirmation gate that exists but is not bound to a canonical action summary earns Cn-6 = 0.25, not credit for human-in-the-loop control — and because the gate cannot be claimed at CBR &gt;= 0.95, the same defect forces Cp to the corroborated 1.00 anchor by making an otherwise-gated path to a write-external node effectively ungated.</description><category>AI security case study</category></item>  <item><title>ChatGPhish: When a Webpage Makes ChatGPT Render a Phishing Interface</title><link>https://aitbm.org/use-cases/chatgphish-chatgpt-markdown-phishing</link><guid>https://aitbm.org/use-cases/chatgphish-chatgpt-markdown-phishing</guid><pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate><description>Cascade Potential can legitimately be a default rather than a corroborated 1.00: the injected content traverses all four stack layers, but the terminal node is an external fetch rather than a write-external or credential-issuing node, so with a verified dependency graph this case would most likely score Cp = 0.75 — the distinction the cp_basis field exists to record.</description><category>AI security case study</category></item>  <item><title>TrapDoor: Poisoned .cursorrules and CLAUDE.md Turn AI Coding Assistants Into Credential Stealers</title><link>https://aitbm.org/use-cases/trapdoor-ai-assistant-config-poisoning-supply-chain</link><guid>https://aitbm.org/use-cases/trapdoor-ai-assistant-config-poisoning-supply-chain</guid><pubDate>Mon, 01 Jun 2026 00:00:00 +0000</pubDate><description>Ro-4 poisoning resistance is not only about training data and RAG corpora: an agent&#x27;s own instruction and configuration files are an ingestion channel, and where they are read as authoritative guidance with no provenance, signature or hidden-character check, Ro-4 sits at the 0.00 anchor regardless of how well the training pipeline is protected.</description><category>AI security case study</category></item>  <item><title>Agent Session Smuggling: Hidden Instructions Across A2A Agent Sessions</title><link>https://aitbm.org/use-cases/agent-session-smuggling-a2a-systems</link><guid>https://aitbm.org/use-cases/agent-session-smuggling-a2a-systems</guid><pubDate>Wed, 27 May 2026 00:00:00 +0000</pubDate><description>Authentication is not authorisation: a cryptographically valid, correctly authenticated peer session still scores Cn-5 low, because Cn-5 measures whether identity is bound to instruction provenance and tool invocation — not merely whether the counterparty is who it claims to be.</description><category>AI security case study</category></item>  <item><title>ChromaToast: ChromaDB Pre-Auth RCE Through Malicious Hugging Face Model Loading</title><link>https://aitbm.org/use-cases/chromatoast-chromadb-pre-auth-rce</link><guid>https://aitbm.org/use-cases/chromatoast-chromadb-pre-auth-rce</guid><pubDate>Tue, 26 May 2026 00:00:00 +0000</pubDate><description>Remediation Feasibility sits at its bottom anchor — a patchable ordering bug with a CVE and a fixed release — while Cascade Potential still forces 1.00, which is exactly the layer separation AITBM is built for: how easily a defect is fixed and how far it reaches are scored independently, so a cleanly patchable flaw never gets to look harmless.</description><category>AI security case study</category></item>  <item><title>AI App Misconfigurations: Public Agent Endpoints as RCE and Credential-Leak Paths</title><link>https://aitbm.org/use-cases/ai-agent-app-misconfigurations-rce-credential-leakage</link><guid>https://aitbm.org/use-cases/ai-agent-app-misconfigurations-rce-credential-leakage</guid><pubDate>Fri, 15 May 2026 00:00:00 +0000</pubDate><description>Nothing in this case reaches the model — there is no prompt, no injection, and no Robustness-1 signal at all — so AITBM&#x27;s not-applicable redistribution rule carries the whole assessment on Containment, identity, and posture evidence, which is the correct answer for an incident where, as the brief puts it, security was lost before the model saw any prompt.</description><category>AI security case study</category></item>  <item><title>PromptMink: Malicious Packages Built to Persuade AI Coding Agents</title><link>https://aitbm.org/use-cases/promptmink-ai-coding-agent-malicious-dependencies</link><guid>https://aitbm.org/use-cases/promptmink-ai-coding-agent-malicious-dependencies</guid><pubDate>Fri, 08 May 2026 00:00:00 +0000</pubDate><description>The adversary never touched the model — it optimised the documentation the model reads — so the scoring weight lands on Ro-4 ingestion integrity and Cn-1/Cn-6 execution gating rather than on jailbreak resistance, and the case shows why AITBM scores the pipeline configuration rather than the assistant that proposed the change.</description><category>AI security case study</category></item>  <item><title>OpenAI Codex Command Injection: Malicious GitHub Branch Names as a Token-Theft Path</title><link>https://aitbm.org/use-cases/openai-codex-github-branch-token-theft</link><guid>https://aitbm.org/use-cases/openai-codex-github-branch-token-theft</guid><pubDate>Sun, 03 May 2026 00:00:00 +0000</pubDate><description>The exploited input never reached the model, which is exactly why Ro-1 must be scored over the agent&#x27;s whole task-setup surface rather than its prompt: an agent&#x27;s adversarial-input resistance is only as good as the least-validated field in the request that provisions its container.</description><category>AI security case study</category></item>  <item><title>CursorJacking: Rogue Cursor Extensions Can Steal AI API Keys</title><link>https://aitbm.org/use-cases/cursorjacking-cursor-extension-api-key-theft</link><guid>https://aitbm.org/use-cases/cursorjacking-cursor-extension-api-key-theft</guid><pubDate>Sun, 03 May 2026 00:00:00 +0000</pubDate><description>Containment can score 0.00 on an AI product whose model behaved perfectly: the assessed boundary here is the extension host and the credential store, so a client-side trust-boundary failure lands squarely on Cn-1 and Cn-5 — and demonstrates that a &#x27;no model involvement&#x27; incident is still an AI security finding, not an exemption from scoring.</description><category>AI security case study</category></item>  <item><title>PocketOS Cursor Agent Data Wipe: Destructive Actions Need Runtime Boundaries, Not Prompt Rules</title><link>https://aitbm.org/use-cases/pocketos-cursor-agent-database-wipe</link><guid>https://aitbm.org/use-cases/pocketos-cursor-agent-database-wipe</guid><pubDate>Sun, 03 May 2026 00:00:00 +0000</pubDate><description>There is no adversary in this case at all, and AITBM still scores it as a Containment collapse — Cn-1, Cn-2 and Cn-6 are driven by what the agent was technically able to do, not by whether anyone attacked it, which is why an assessment that only looks for attack success rates would have missed this deployment entirely.</description><category>AI security case study</category></item>  <item><title>Entra Agent ID Administrator Scope Gap: Agent Roles Reaching Service Principals</title><link>https://aitbm.org/use-cases/entra-agent-id-admin-service-principal-takeover</link><guid>https://aitbm.org/use-cases/entra-agent-id-admin-service-principal-takeover</guid><pubDate>Wed, 29 Apr 2026 00:00:00 +0000</pubDate><description>An AI system can fail the Containment axis with no model in the loop at all: Cn-5 is scored on the enforced authorization boundary around agent identities, so a directory role whose documented scope and effective scope diverge is an agent-identity finding, not merely an IAM bug.</description><category>AI security case study</category></item>  <item><title>Kimi Privacy Leak Report: When a Translation Request Returns Another User&#x27;s Resume</title><link>https://aitbm.org/use-cases/kimi-cross-user-resume-privacy-leak</link><guid>https://aitbm.org/use-cases/kimi-cross-user-resume-privacy-leak</guid><pubDate>Wed, 29 Apr 2026 00:00:00 +0000</pubDate><description>An incident with no established root cause is still scorable — the enforced boundary and the missing release gate are directly observable from the outcome — and the unresolved mechanism belongs in ACI (thin coverage, a critical-invariant C_event cap) rather than being smoothed over with invented sub-metric scores; it is also the clearest example of a &#x27;default&#x27; Cp, where 1.00 comes from the missing dependency graph and not from the impact.</description><category>AI security case study</category></item>  <item><title>Web-Based IDPI in the Wild: When Webpages Become Agent Prompt Delivery</title><link>https://aitbm.org/use-cases/web-based-idpi-agent-prompt-injection</link><guid>https://aitbm.org/use-cases/web-based-idpi-agent-prompt-injection</guid><pubDate>Sat, 25 Apr 2026 00:00:00 +0000</pubDate><description>A population study can be scored honestly as a representative configuration, but only if the assurance layer carries the cost: Pc = 0.10 and a class-level Cp classified as default rather than corroborated are what keep the case from overclaiming — and the ORP shows the strict-inequality boundary at work, with Aa and Rf sitting exactly at 0.75 and therefore not counting toward N_elevated.</description><category>AI security case study</category></item>  <item><title>Vertex AI Double Agents: When Service-Agent Defaults Become an Agentic Cloud Boundary</title><link>https://aitbm.org/use-cases/vertex-ai-double-agents-service-agent-permissions</link><guid>https://aitbm.org/use-cases/vertex-ai-double-agents-service-agent-permissions</guid><pubDate>Sat, 25 Apr 2026 00:00:00 +0000</pubDate><description>Authentication succeeded and the provider&#x27;s write boundary held, so the failure has to be located precisely rather than described as &#x27;broken identity&#x27;: AITBM puts it in Cn-5 = 0.40 (a valid managed token with no binding to agent instance, session or invocation) and Cn-1 = 0.25 (flat reachability across three project boundaries), while Tr-3 stays at 0.50 because cloud audit logging did record the calls it could not attribute.</description><category>AI security case study</category></item>  <item><title>Apple Intelligence Hijack: Prompt Injection Against an OS-Level Local LLM</title><link>https://aitbm.org/use-cases/apple-intelligence-neural-exec-prompt-injection</link><guid>https://aitbm.org/use-cases/apple-intelligence-neural-exec-prompt-injection</guid><pubDate>Sat, 25 Apr 2026 00:00:00 +0000</pubDate><description>Controls that held move the numbers as much as the ones that failed: a measured 76% attack success rate coexists with Cn-1 and Cn-2 at 0.50 (the OS app sandbox bounded the blast radius) and Rf at 0.25 (a platform patch shipped), so only Cascade Potential is elevated, N_elevated stays at one and no Compound Risk Alert is raised — a profile a failure-only assessment would have got badly wrong.</description><category>AI security case study</category></item>  <item><title>Your Agent Is Mine: Malicious LLM API Routers as an Agent Supply-Chain Boundary</title><link>https://aitbm.org/use-cases/malicious-llm-api-router-agent-supply-chain</link><guid>https://aitbm.org/use-cases/malicious-llm-api-router-agent-supply-chain</guid><pubDate>Sat, 25 Apr 2026 00:00:00 +0000</pubDate><description>The trust boundary that fails here is neither the model nor the tool but the transport intermediary between them, and AITBM localises it precisely — Cn-5 = 0.25 for an unverifiable response origin under API-key-only identity and Cn-6 = 0.00 for ARCR = 0 under auto-approve — a failure that no model-layer sub-metric and no prompt-injection test would have surfaced.</description><category>AI security case study</category></item>  <item><title>Malicious Hugging Face Models: When Loading a Model Opens a Backdoor</title><link>https://aitbm.org/use-cases/hugging-face-malicious-model-backdoor</link><guid>https://aitbm.org/use-cases/hugging-face-malicious-model-backdoor</guid><pubDate>Fri, 24 Apr 2026 00:00:00 +0000</pubDate><description>An artifact-supply-chain incident with no agent, no prompt and no model output is still fully scorable — the evidence lands on Ro-4, Tr-3/Tr-4 and Cn-1/Cn-2 — and because the assessed configuration was observed in February 2024, Temporal Freshness rather than the attack itself is what collapses assurance confidence, which is the temporal layer behaving exactly as designed.</description><category>AI security case study</category></item>  <item><title>Microsoft &quot;EchoLeak&quot;: How One Email Turned Microsoft 365 Copilot into a Zero-Click Data Exfiltration Path</title><link>https://aitbm.org/use-cases/microsoft-echoleak-zero-click-prompt-injection</link><guid>https://aitbm.org/use-cases/microsoft-echoleak-zero-click-prompt-injection</guid><pubDate>Thu, 23 Apr 2026 00:00:00 +0000</pubDate><description>This is the batch&#x27;s clearest demonstration that a control which held still gets scored, and scored up: CSP blocked the direct egress domain and the XPIA classifier forced the attacker to craft plain prose, which is exactly why Cn-3 and Cn-1 sit at 0.50 and Ro-1 at 0.40 rather than at failure anchors — and the residual risk is carried instead by Cp, where a single demonstrated chain crossing a declared-blocked boundary invalidates that gate&#x27;s containment claim and corroborates the 1.00 anchor.</description><category>AI security case study</category></item>  <item><title>Anthropic MCP STDIO Command Execution: When Tool Configuration Becomes an RCE Primitive</title><link>https://aitbm.org/use-cases/anthropic-mcp-stdio-command-execution</link><guid>https://aitbm.org/use-cases/anthropic-mcp-stdio-command-execution</guid><pubDate>Wed, 22 Apr 2026 00:00:00 +0000</pubDate><description>The scoring turns on an evidentiary rule rather than a judgement call: the 0.50 Ro-1 anchor describes this case qualitatively — common attacks resisted, multi-step tool-mediated attacks still effective — but its ASR-below-50% precondition is unmeasured, so the quantitative precondition fails and 0.25 governs; meanwhile Cn-6 = 0.00 is the cleanest reading in the batch, because a system that treats spawning an arbitrary OS process as routine tool setup has an Action Reversibility Classification Rate of exactly zero.</description><category>AI security case study</category></item>  <item><title>LiteLLM Fallout: How a Poisoned AI Dependency Reached Mercor</title><link>https://aitbm.org/use-cases/mercor-litelllm-poisoned-dependency-breach</link><guid>https://aitbm.org/use-cases/mercor-litelllm-poisoned-dependency-breach</guid><pubDate>Sat, 18 Apr 2026 00:00:00 +0000</pubDate><description>AITBM scores a software supply-chain compromise as an AI-system finding without distorting either: the AI-specific signal lands on Ro-4 (the dependency ingestion path is a poisoning channel), Cn-5 (static credentials with no workload binding) and Tr-4 (no AIBOM to bound the blast radius), while the thinness of published deployment detail is carried honestly by a base coverage of 4 of 22 rather than by inventing scores — the epistemic penalty appears in ACI, which is where the framework intends it.</description><category>AI security case study</category></item>  <item><title>ClawHub `google-qx4`: Malicious SKILL.md Prerequisites as Agent-Driven Social Engineering</title><link>https://aitbm.org/use-cases/clawhub-google-qx4-fake-prerequisite-malware</link><guid>https://aitbm.org/use-cases/clawhub-google-qx4-fake-prerequisite-malware</guid><pubDate>Sat, 18 Apr 2026 00:00:00 +0000</pubDate><description>A containment control can hold and the deployment still be compromised: the agent sandbox blocked in-runtime execution, which is why Cn-1 is scored up to 0.50 rather than down at a failure anchor, while the compromise travelled the one path the sandbox never covered — an instruction relayed through the human. AITBM captures this only because Cn-1&#x27;s 0.50 anchor names delegated workflows explicitly, and because the assessment is required to score the control that held alongside the ones that did not.</description><category>AI security case study</category></item>  <item><title>OpenClaw &#x27;ClawJacked&#x27;: Website-to-Local Agent Takeover via Loopback Trust and WebSocket Abuse</title><link>https://aitbm.org/use-cases/openclaw-browser-to-local-agent-takeover</link><guid>https://aitbm.org/use-cases/openclaw-browser-to-local-agent-takeover</guid><pubDate>Sat, 18 Apr 2026 00:00:00 +0000</pubDate><description>Cn-5 is the case&#x27;s hinge and shows why a mechanism-only reading of the rubric is wrong: the gateway had real authentication (pairing, device tokens, a password), which is the 0.25 anchor, but the measured Identity Spoofing Success Rate approached 1.00, so the precedence rule — quantitative floor, qualitative ceiling — drives the score to 0.10, and it is the identity failure rather than any single missing feature that turns a loopback listener into an internet-reachable admin API.</description><category>AI security case study</category></item>  <item><title>Bain Pyxis Compromise: When a Frontend Credential Owns Eleven Databases and the Identity Plane</title><link>https://aitbm.org/use-cases/bain-pyxis-ai-platform-compromise</link><guid>https://aitbm.org/use-cases/bain-pyxis-ai-platform-compromise</guid><pubDate>Sat, 18 Apr 2026 00:00:00 +0000</pubDate><description>Identity, not the model, is the AI attack surface here: every low sub-metric sits in Containment (Cn-1, Cn-2, Cn-4, Cn-5, Cn-6 all at or near the floor) while Robustness barely features - and the case is the cleanest available demonstration of PAD &gt;= 3 corroborating Cp = 1.00 on its merits, because one leaked frontend credential reached a P4 permission-issuing node with no gate on the path.</description><category>AI security case study</category></item>  <item><title>McKinsey Lilli Compromise: When SQL Injection Reaches the AI Prompt Layer</title><link>https://aitbm.org/use-cases/mckinsey-lilli-ai-platform-compromise</link><guid>https://aitbm.org/use-cases/mckinsey-lilli-ai-platform-compromise</guid><pubDate>Fri, 17 Apr 2026 00:00:00 +0000</pubDate><description>The sub-metric that should have stopped this is Ro-4, not a web-application control: once the prompt and retrieval tables were writable, the AI platform&#x27;s integrity depended on chunk and configuration signing that did not exist - and AITBM scores that AI asset store, not the endpoint. The case also shows the attacker&#x27;s autonomy must not leak into the victim&#x27;s architecture class; Lilli is RAG, and classifying it as agentic because CodeWall&#x27;s agent was would have silently changed the intra-axis weight set.</description><category>AI security case study</category></item>  <item><title>Salesforce &#x27;ForcedLeak&#x27;: Indirect Prompt Injection via Agentforce Web-to-Lead Forms</title><link>https://aitbm.org/use-cases/salesforce-agentforce-forcedleak-prompt-injection</link><guid>https://aitbm.org/use-cases/salesforce-agentforce-forcedleak-prompt-injection</guid><pubDate>Thu, 16 Apr 2026 00:00:00 +0000</pubDate><description>ForcedLeak shows why Cp = 1.00 here is corroborated rather than defaulted: a sink gate that a researcher&#x27;s payload was observed crossing cannot be claimed at CBR &gt;= 0.95, so the path counts as ungated to a P3 node on its own merits - and it shows a control can be simultaneously credited (Cn-1 = 0.25 not 0.00, because the CSP constrained the attacker) and defeated, which is what a two-sided assessment looks like.</description><category>AI security case study</category></item>  <item><title>Claude Code Protected Paths and Auto Mode: Why Bypass Is No Longer a Stable Control Boundary</title><link>https://aitbm.org/use-cases/claude-code-protected-paths-auto-mode</link><guid>https://aitbm.org/use-cases/claude-code-protected-paths-auto-mode</guid><pubDate>Thu, 16 Apr 2026 00:00:00 +0000</pubDate><description>A case with no exploit still moves the AITBM score: a change to an agent&#x27;s authority boundary trips the C_event &lt;= 0.35 cap and, with mutable behavioural state, the M_Em = 3.0 behavioural staleness floor - so &#x27;nothing was breached&#x27; does not mean &#x27;the prior assessment is still fresh&#x27;. It is also a clean example of Cp = 1.00 by default rather than by corroboration, because the gates in force were never shown to be bypassed.</description><category>AI security case study</category></item>  <item><title>hTAG&#x27;s Browser-Agent Benchmark Shows Why Model Refusal Is Not Authorization</title><link>https://aitbm.org/use-cases/htag-browser-agent-abuse-benchmark</link><guid>https://aitbm.org/use-cases/htag-browser-agent-abuse-benchmark</guid><pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate><description>The benchmark aggregates 20 scenarios across five browser-agent products and reports vendor-level completion counts without a complete prompt-and-trace corpus, exact reproducible builds, or repeated-run counts. It is useful evidence for authorization testing, but not one bounded deployment. A single score would average incompatible products, account states, tools, and transaction effects and would therefore manufacture a system that was never assessed.</description><category>AI security research note</category></item>  <item><title>Vector Databases Are Not Just Vectors: Orca Exposure Findings and Milvus Authentication Failures</title><link>https://aitbm.org/use-cases/orca-milvus-vector-database-exposure-auth-bypass</link><guid>https://aitbm.org/use-cases/orca-milvus-vector-database-exposure-auth-bypass</guid><pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate><description>The source combines an Internet-wide exposure study, several unrelated vector-database deployments, credential validation against external SaaS systems, and two different Milvus vulnerabilities with separate preconditions and fixed versions. There is no single assessed database, architecture, dependency graph, or remediation state. Combining them into one score would conflate population prevalence, two software defects, and several organizations&#x27; configurations.</description><category>AI security research note</category></item>  <item><title>IDEsaster Shows How Agent File Writes Can Activate Trusted IDE Features</title><link>https://aitbm.org/use-cases/idesaster-ai-ide-native-feature-abuse</link><guid>https://aitbm.org/use-cases/idesaster-ai-ide-native-feature-abuse</guid><pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate><description>The source reports a vulnerability class spanning more than ten AI IDE products, over 30 findings, and 24 CVEs. It does not define one product version, workspace trust state, enabled native feature set, agent tool policy, or deployment boundary from which a single IVP/ORP/ACI result can be calculated. Selecting one representative configuration would require an assessor choice not made by the source, so the analysis is preserved with its AIDEFEND routes but carries no ERS.</description><category>AI security research note</category></item>  <item><title>Shadow AI and Enterprise Data Governance: What 22.4M Prompts Reveal</title><link>https://aitbm.org/use-cases/shadow-ai-enterprise-data-governance</link><guid>https://aitbm.org/use-cases/shadow-ai-enterprise-data-governance</guid><pubDate>Wed, 24 Jun 2026 00:00:00 +0000</pubDate><description>There is no assessed AI deployment. The brief is a cross-vendor population study — Harmonic&#x27;s telemetry over 22,458,240 prompts and uploads across 665 tools, plus Cyberhaven, Verizon DBIR and IBM breach-cost figures — measuring how enterprise data flows out through employee use of unmanaged third-party AI accounts. The systems receiving the data (ChatGPT, Gemini, Claude, Copilot, Perplexity and 660 others) are not deployments the assessed organisation configures, and the brief supplies no evidence about any of their intrinsic security properties; it measures the volume and category of data leaving governed paths. AITBM scores a specific system in a specific configuration, and &#x27;shadow AI&#x27; is precisely the condition of there being no assessed configuration to score. Forcing an architecture class, tier, IVP or ORP onto a 665-tool population would fabricate a system that does not exist. The findings belong instead as evidence inputs to the assessment of the organisation&#x27;s *governed* AI paths — chiefly Pr-3 (data minimisation), Cn-1 (scope enforcement at the egress boundary), Tr-3 (audit trail completeness), Cn-5 (account and workload identity) and the ORP Attack Surface dimension.</description><category>AI security research note</category></item>  <item><title>Sysdig marimo: When an LLM Agent Drives Post-Exploitation After RCE</title><link>https://aitbm.org/use-cases/sysdig-marimo-llm-agent-post-exploitation</link><guid>https://aitbm.org/use-cases/sysdig-marimo-llm-agent-post-exploitation</guid><pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate><description>There is no assessed AI system on the victim side. The compromised asset is a marimo notebook runtime — a browser-based interactive Python execution environment used for AI and data-science work — reached through CVE-2026-39987 on its /terminal/ws WebSocket. It contains no model, no retrieval layer, no tool-calling interface and no agent: nothing in the deployed victim system produces or consumes model output. The only AI agency in this incident belonged to the attacker&#x27;s post-exploitation tooling, and protocol section 1 places the attacker out of scope. Consequently the AITBM architecture decision tree (spec 4.4) has no class that fits without misrepresentation: Q1 through Q5 are all NO, and the Q6 fall-through to Traditional ML / Classifier would be factually wrong for a code-execution surface with no model. Every IVP axis that gives AITBM its distinctive signal — Robustness, Fairness, Transparency&#x27;s explainability and calibration sub-metrics, Privacy&#x27;s model-behaviour sub-metrics — is unassessable, and what remains (network scope, credential hygiene, segmentation, telemetry) is conventional infrastructure security that AITBM does not exist to score. Forcing a score here would produce an ERS driven almost entirely by ORP with a Containment-only IVP, which would misrepresent both the incident and the framework. The correct AITBM treatment of this case is as an input to other assessments rather than as an assessment of its own: it is a spec 3.3.3.4 threat-override condition (a new exploited vulnerability with an active incident, M_threat = 1.50, Tf capped at 0.50 for exploited relevance) for any AI workload hosted on or reachable from such runtimes, and an exposure-management finding for AI development surfaces generally.</description><category>AI security research note</category></item>  <item><title>System-Level Agent Defenses: Why Indirect Prompt Injection Needs Plan and Policy Boundaries</title><link>https://aitbm.org/use-cases/ai-agent-system-level-idpi-defenses</link><guid>https://aitbm.org/use-cases/ai-agent-system-level-idpi-defenses</guid><pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate><description>There is no assessed deployment. The brief summarises an academic position paper (arXiv 2603.30016, &#x27;Architecting Secure AI Agents: Perspectives on System-Level Defenses Against Indirect Prompt Injection&#x27;) that argues for plan, policy, approval, execution, and feedback boundaries in general-purpose agents. It reports no incident, no victim system, no observed configuration, and no measurement of any deployment — every statement is an architectural proposal or a critique of benchmark methodology. Scoring it would require inventing a system&#x27;s IVP, ORP, and ACI inputs from prescriptive text, which the protocol forbids. The brief is retained for its AIDEFEND mapping and for what its benchmark critique implies about AITBM&#x27;s own evidence-quality machinery.</description><category>AI security research note</category></item>  <item><title>Real Attackers Don’t Compute Gradients: Operational Threat Modeling for ML Security</title><link>https://aitbm.org/use-cases/real-attackers-adversarial-ml-threat-modeling</link><guid>https://aitbm.org/use-cases/real-attackers-adversarial-ml-threat-modeling</guid><pubDate>Sun, 26 Apr 2026 00:00:00 +0000</pubDate><description>Methodology brief with no assessed deployment. The source is a research paper (Apruzzese, Anderson, Dambra, Freeman, Pierazzi, Roundy) arguing that adversarial-ML evaluation over-weights gradient-style model attacks relative to the cheaper system-level bypasses real attackers use. Its illustrative material — Facebook&#x27;s abuse-fighting funnel, an unnamed commercial phishing detector, the MLSEC competition — is second-hand and generic: no named system in a stated configuration, no incident, no measured control outcome, and no evidence of which defences were present or absent at a point in time. Under protocol section 7 this is a methodology/population study, and the representative-configuration exception does not apply because the brief does not describe any single deployment in enough detail to reconstruct one. Scoring it would require inventing sub-metric evidence.</description><category>AI security research note</category></item>  <item><title>Subliminal Learning: Behavioural Traits Leak Through Semantically Unrelated Distillation Data</title><link>https://aitbm.org/use-cases/subliminal-learning-distillation-trait-transfer</link><guid>https://aitbm.org/use-cases/subliminal-learning-distillation-trait-transfer</guid><pubDate>Thu, 16 Apr 2026 00:00:00 +0000</pubDate><description>This brief reports a controlled research result about a training-time mechanism, not an incident against a deployed AI system. The teacher and student models were created by the researchers to demonstrate the effect; there is no victim deployment, no operator, no production configuration, and no attack against a running system. Consequently the three AITBM layers have no referent: the IVP would have to be scored against a research artefact rather than an assessed configuration, and every ORP dimension - autonomy, attack surface, cascade potential, remediation feasibility - would have to be invented, since a distillation pipeline demonstrated in a laboratory has no deployment context to score. The protocol&#x27;s representative-configuration exception does not rescue it either: the brief studies a class of training pipeline, not a class of deployment, and it supplies no configuration facts (autonomy, exposure, downstream reach) from which a representative deployment could be reconstructed. Scoring it would manufacture numbers the evidence cannot support. The brief is nonetheless directly useful to AITBM as a scoping input, recorded in key_finding below.</description><category>AI security research note</category></item></channel></rss>
