Foundation
Basic cybersecurity and prompt-injection labs. Classroom workflows. Environment lifecycle.
IN DEVELOPMENTA research program for programmable, reproducible and measurable security environments.
PROPOSED / RESEARCHCan security intent survive the journey from a scenario definition to a deployed environment and a defensible verdict?
That is the central question. Our proposed program focuses first on a bounded AI-agent environment, where tool permissions, protected resources and evidence can be inspected together.
No experimental results are claimed. The thesis distinguishes established work, proposed contributions and experiments that could falsify the hypotheses.
Models, agents, retrieval and tool permissions.
↗02Typed scenarios and validated initial state.
↗03Constrained transformations that preserve intent.
↗04Security outcomes supported by independent evidence.
↗05Correlated events with explicit provenance.
↗A typed scenario contract can preserve a defined security property across constrained changes.
A deployable configuration can still remove the attack path or invalidate the grader.
Generate controlled variants with independent benign and vulnerability witnesses.
Valid-run fraction, missed semantic defects and total authoring/repair time.
Independent state evidence can distinguish model statements from actual tool effects.
A model can refuse in its answer after already performing an unauthorized action.
Compare output grading, existing state-aware evaluation and the proposed contract evaluator.
Precision, recall, inconclusive rate and legitimate task completion.
Separate fixture replay from equivalent state reconstruction and statistical repetition.
Provider changes and asynchronous scheduling prevent universal determinism.
Repeat pinned and live-model conditions while changing one dependency at a time.
State equivalence, verdict agreement, outcome distributions and reproduction time.
Evidence obligations can prevent missing observations from becoming false passes.
Events can be lost, delayed, duplicated or forged by a compromised target.
Inject evidence faults and ablate sensors against independent resource witnesses.
False-pass rate, erroneous graph edges, evidence loss and detection delay.
Basic cybersecurity and prompt-injection labs. Classroom workflows. Environment lifecycle.
IN DEVELOPMENTScenario-as-code, dynamic provisioning, isolation and telemetry.
RESEARCHAgents, RAG, MCP, tools and validated automated evaluation.
RESEARCHConstrained scenario generation, event graphs and reproducible experiments.
LONG-TERM RESEARCH