Chapters

Chapter directory

Public metadata only. Full chapter bodies are protected. Search runs in-browser—no third-party search provider.

40 / 40

  1. 01AI Is Not SoftwareEstablishes why deterministic security assumptions fail when policy compliance is an inference problem under uncertainty.Part 1inputinferenceOverview
  2. 02The AI Execution Stack Reference ModelDefines the canonical stack used throughout the manual and maps vendor agent abstractions to layers.Part 1inputtokenizationOverview
  3. 03Prompt InjectionPrompt injection is input-level control-plane compromise; indirect injection weaponizes retrieval and tool outputs.Part 1inputcontext-assemblyOverview
  4. 04Context PoisoningRetrieved equals trusted is the default failure mode; poisoning attacks target the retrieval layer.Part 1context-assemblyOverview
  5. 05Reasoning Failures and Goal HijackingPlanning is inference; attackers target objective inference and constraint weighting.Part 1planninginferenceOverview
  6. 06Tool ExploitationTools turn language failures into real-world side effects; tool selection and execution are exploitable surfaces.Part 1tool-selectionexecutionOverview
  7. 07Execution Failures and Side EffectsBlind execution, races, and missing confirmations convert inference errors into irreversible change.Part 1executionOverview
  8. 08Memory Is an Attack SurfacePersistent memory enables lasting injection, poisoning, and cross-session contamination.Part 1memorycontext-assemblyOverview
  9. 09Indirect Prompt Injection in the WildModern IPI research and defenses for retrieval-mediated instruction hijack.Part 2inputcontext-assemblyOverview
  10. 10Instruction Smuggling and Hidden ContentDisplay text is not parse text; HTML, CSS, and Unicode hide instructions.Part 2inputtokenizationOverview
  11. 11Retrieval Poisoning and Embedding WeaknessesVector and ranking attacks undermine similarity-as-trust assumptions.Part 2context-assemblyOverview
  12. 12Cross-Tenant Leakage in RAG and MemoryShared indexes and caches collapse isolation boundaries.Part 2context-assemblymemoryOverview
  13. 13Output Handling: When Text Becomes CodeModel output treated as trusted code or query language creates RCE and injection paths.Part 2inferenceexecutionOverview
  14. 14Unbounded Consumption: Cost and Availability AttacksLoops, long contexts, and retries become economic and availability weapons.Part 2inferenceplanningOverview
  15. 15The Planning Loop as an Attack SurfaceThreat modeling the orchestration loop itself.Part 3planningOverview
  16. 16Tool Chaining and Capability GravityAvailable tools pull agent behavior toward higher blast radius.Part 3tool-selectionexecutionOverview
  17. 17Multi-Agent Handoffs and Delegation AbuseAuthenticated and unauthenticated handoffs create authority confusion.Part 3planningexecutionOverview
  18. 18Agent Graph Poisoning and Workflow AttacksWorkflow graphs can be steered, substituted, or poisoned.Part 3planningOverview
  19. 19Human-in-the-Loop Failure ModesRubber-stamping and incomplete context defeat approval theater.Part 3planningexecutionOverview
  20. 20Observability Failures: When You Can’t Reconstruct WhyMissing spans mean you cannot prove what executed.Part 3executionmemoryOverview
  21. 21Sensitive Information Disclosure in Agentic SystemsSecrets and PII leak through answers, tools, and traces.Part 4inferenceexecutionOverview
  22. 22Privacy Attacks: Inversion, Membership, and RegurgitationModel and memory surfaces enable privacy attacks beyond classic appsec.Part 4inferencememoryOverview
  23. 23Data Residency, Retention, and Right to ForgetPolicy must bind memory, traces, and third-party tools.Part 4memoryOverview
  24. 24Auditability at Scale: Traces, Logs, and EvidenceUnify traces and logs into evidence suitable for auditors.Part 4executionOverview
  25. 25Compliance Mapping: SOC 2, ISO 27001, HIPAA, PCI DSS, EU AI ActMap DASTOR controls and evidence to compliance frameworks.Part 4executionmemoryOverview
  26. 26Incident Response for Agents: Containment and RollbackContain, freeze tools, and reverse when evidence allows.Part 4executionOverview
  27. 27Training and Fine-Tuning PoisoningPoisoned data and adapters compromise model integrity.Part 5inferenceOverview
  28. 28Backdoors, Trojan Triggers, and Model IntegritySigned artifacts and evaluation gates for model supply chain.Part 5inferenceOverview
  29. 29Model Theft and Behavioral CloningAbuse detection and rate limits for extraction.Part 5inferenceOverview
  30. 30Tool Marketplace and Connector Supply ChainThird-party tools and MCP servers require trust tiers.Part 5tool-selectionexecutionOverview
  31. 31Runtime Compromise: Sandboxes, Scripts, Container EscapesHardened runtimes and egress controls for code-executing agents.Part 5executionOverview
  32. 32CI/CD and Agent Builds in ProductionSeparate duties when agents can deploy.Part 5executionOverview
  33. 33Deterministic Execution GatesNo side effects without a check that can be proven.Part 6executionplanningOverview
  34. 34Tool Security Engineering PatternsAllowlists, schemas, least privilege, and pre/post guardrails.Part 6tool-selectionexecutionOverview
  35. 35Retrieval Security Engineering PatternsProvenance, sanitization, and poisoning detection.Part 6context-assemblyOverview
  36. 36Memory Security Engineering PatternsSeparate durable and working memory with approval for durable writes.Part 6memoryOverview
  37. 37Evaluation, Red Teaming, and Regression HarnessesContinuous regression against ATLAS and OWASP classes.Part 6inferenceexecutionOverview
  38. 38Governance Operating Model and Change ControlRisk tolerance, change control, and operating cadence for AI systems.Part 6planningexecutionOverview
  39. 39The DASTOR Evidence Standard (ExecutionReceipt)ExecutionReceipt as the evidence artifact for governed AI execution.Part 6executionOverview
  40. 40Building AI Systems That Fail SafelyWhen in doubt, stop execution; degrade safely.Part 6executionplanningOverview