G

AIP-07: Threat Model

AIP-07: Threat Model

Abstract#

Defines adversarial assumptions and residual risks.

Threat Classes#

  • Replay attacks

  • Prompt injection

  • Privilege escalation

  • Double execution

  • Compute inflation

  • Compromised host environment

  • Audit tampering

  • Identity spoofing

  • Tool server compromise

Normative Requirements#

  1. Runtime MUST mitigate replay at remote boundaries.

  2. Runtime MUST prevent double execution via lease/fencing or equivalent.

  3. Runtime MUST detect audit chain breaks when hash-chaining is enabled.

  4. Prompt injection MUST be mitigated per AIP-13.

  5. Residual risks MUST be documented and acknowledged.