Pidoku
Glossary

Glossary

Short definitions of the terms this course uses. The lesson in brackets is where each is explained.

TermMeaning
Action railThe deterministic check on every tool call: schema, authorisation, arguments, taint, approval. (Runtime Guardrails)
Adaptive attackAn attack tuned against a specific defence. (Prompt Injection)
AI-BOMA bill of materials for a model: files, lineage, data, licences, evaluations. (Models and Supply Chain)
ASI01–ASI10The OWASP Top 10 for Agentic Applications. (Frameworks and Maps, Agent Threats)
ATLASMITRE’s matrix of adversary tactics and techniques against AI systems. (Frameworks and Maps)
Attack success rateThe share of attack attempts that achieve their outcome. (Build and Test)
AttestationHardware-signed proof of what software is running in a protected environment. (Deployment and Infrastructure)
AudienceThe single resource server a token is valid for. (Identity and Authorization)
BackdoorBehaviour planted in a model that appears only on a trigger. (Poisoning and Supply Chain)
CaMeLA design that tracks the origin of every value and enforces policies on tool arguments. (Architectural Defenses)
CanaryA planted marker whose appearance in output or outbound traffic reveals a leak. (Data Exfiltration and Leakage)
Confidential computingHardware protection of data while in use, with attestation. (Deployment and Infrastructure)
Confused deputyA program tricked into using its authority for someone who lacks it. (Why AI Security Is Different)
Denial of walletDriving up token or GPU spend to exhaust a budget. (Abuse and Resource Attacks)
Deterministic controlA control enforced by code or configuration, independent of model behaviour. (Threat Modeling an AI System)
Dual LLMA privileged model that plans and a quarantined model that reads untrusted text. (Architectural Defenses)
Egress controlRestricting outbound network destinations. (Sandboxing and Egress)
Enterprise-Managed AuthorizationThe MCP extension by which an organisation’s identity provider governs access to servers. (Identity and Authorization)
Excessive agencyMore functionality, permission or autonomy than the task needs. (Agent Threats)
ExfiltrationMoving data to where an attacker can read it. (Data Exfiltration and Leakage)
GuardrailA runtime check on input, action or output. (Runtime Guardrails)
Hidden context exposureDisclosure of system prompts or other context the user should not see. (Frameworks and Maps)
Indirect prompt injectionInjection delivered through content the system reads. (Prompt Injection)
Influence flowWhich text can steer which model, and what that model can do. (Threat Modeling an AI System)
JailbreakGetting a model to violate its safety training or operator rules. (Abuse and Resource Attacks)
Lethal trifectaPrivate data, untrusted content and an outbound channel in one context. (Threat Modeling an AI System)
Memory poisoningPlanting instructions in an agent’s persistent memory. (Agent Threats)
OMSOpenSSF Model Signing: a signature over all files of a model. (Models and Supply Chain)
On-behalf-ofAn agent acting with a user’s delegated, scoped authority. (Identity and Authorization)
Probabilistic controlA control that estimates — a classifier, a judge model, an instruction. (Threat Modeling an AI System)
Prompt injectionText that makes a model follow someone else’s instructions. (Prompt Injection)
ProvenanceThe recorded origin of data, a model, or an item in a context. (Data and Training, Monitoring and Response)
Quarantined modelA tool-less model used to read untrusted content. (Architectural Defenses)
Red teamingAttacking your own system on purpose to find weaknesses. (The Red-Team Programme)
Rug pullA tool or server that changes behaviour or descriptions after approval. (Poisoning and Supply Chain)
Rule of twoAn agent session holds at most two of: untrusted input, sensitive access, external effect. (Architectural Defenses)
safetensorsA weights-only model file format that cannot execute code on load. (Models and Supply Chain)
SandboxAn isolated environment for untrusted code. (Sandboxing and Egress)
Session taintA sticky flag recording that untrusted content entered a context. (Architectural Defenses)
Token exchangeTrading one token for a narrower one naming subject, actor, audience and scope. (Identity and Authorization)
Tool gatewayThe proxy between agents and MCP servers: catalogue, authorisation, inspection, audit. (MCP and Tool Security)
Tool poisoningInstructions hidden in a tool’s description. (Poisoning and Supply Chain)
Trust boundaryA line in a design where control changes hands. (Threat Modeling an AI System)
Workload identityA cryptographic identity for a piece of software rather than a shared secret. (Deployment and Infrastructure)

↑↓ navigate↵ openesc close

drag to pan · scroll to zoom