One-sentence brief
AI systems combine probabilistic models with ordinary software, data pipelines, identity, retrieval, memory, and tools. Harm can arise without conventional malware, yet conventional cybersecurity remains essential.
AI KILL CHAINS & DECISION SYSTEMS
A non-operational defensive model of Recon, Poison, Hijack, Persist, Impact, and the Iterate/Pivot loop in agentic systems.
ANALYTICAL & SAFETY BOUNDARIES
Analytical boundary: AI kill chain is used here as a family of analytical models. Attacks against AI systems, AI as a conventional cyber enabler, and AI-enabled military targeting are related but distinct subjects. Capability is not deployment; deployment is not autonomy; classification confidence is not positive identification; recommendation is not authorization; a simulation is not operational evidence.
Simulation safety boundary: Use synthetic identities, reserved domains, fictional infrastructure, nonfunctional artifacts, abstract effects, and constrained defensive actions. Do not accept executable scripts, malware, credentials, arbitrary external URLs, real targets, command execution, or contact with third-party systems.
Source basis: Owner-supplied exact source packet with bounded official-primary-source currentness; external claims remain subject to stated source and review limits.
ORIENTATION
AI systems combine probabilistic models with ordinary software, data pipelines, identity, retrieval, memory, and tools. Harm can arise without conventional malware, yet conventional cybersecurity remains essential.
WORKING BRIEF
The adversary seeks to understand inputs, guardrails, retrieval, tools, components, errors, and behavior. Defensive priorities are minimized information disclosure, access controls, rate controls, and telemetry for unusual probing.
The synthetic scenario displays probe frequency and disclosure without real endpoints.
Untrusted instructions, corrupted records, adversarial inputs, tainted training data, or compromised dependencies enter the system. Defenses include provenance, authorization, validation, isolation, data lineage, and bounded transformation before ingestion.
Learners can quarantine a synthetic source, inspect provenance, or allow it and observe downstream uncertainty.
The model or agent follows an unauthorized goal, emits unsafe tool parameters, leaks contextual data, or deviates from the original task. Tool calls require independent policy checks, least privilege, scoped credentials, and confirmation for consequential actions.
The server validates every proposed action against scenario rules before state changes.
A temporary compromise becomes persistent when poisoned content enters memory, retrieval indexes, shared state, or planning loops. Impact occurs when the system changes external state. Agentic feedback can repeat, spread, or pivot the compromise. Defenses include write authorization, lineage, egress control, anomaly detection, human approval, rapid rollback, and rebuilding corrupted memory or indexes.
Replay shows which control interrupted the pathway and which state must be repaired afterward.
COMPLETE DOSSIER
No game connection is required to use this educational page.
Terms are defined for this site’s evidence method, not as universal legal or clinical definitions.
| Stage | What changes | Defensive interruption |
|---|---|---|
| Recon | Attacker knowledge | Limit disclosure and detect probing |
| Poison | Input or supply integrity | Validate, isolate, and record lineage |
| Hijack | Goal or tool path | Independent authorization and least privilege |
| Persist | Memory or shared state | Controlled writes, deletion, rebuild, rollback |
| Impact | External state | Human approval, egress and action controls |
| Iterate/Pivot | Feedback and lateral spread | Continuous plan validation and containment |
SOURCE QUALITY · UNCERTAINTY · NEUTRALITY
Primary institutional doctrine or policy; supports what the issuing body states, not deployment or compliance.
Primary technical specification or documentation; supports interface/status claims, not truth or field effectiveness.
First-party capability statement requiring independent corroboration.
Attributable public evidence of deployment scope; does not automatically establish autonomy, effectiveness, or legality.
Observed demo or exercise under bounded conditions; not field deployment.
Structured test with stated conditions; external validity remains limited.
Scholarly evidence with method and scope limitations.
Journalistic account requiring attribution and corroboration assessment.
Preserved source packet; claims remain unverified unless separately supported.
Repository-authored inference explicitly marked and linked to supporting evidence.
Synthetic scenario for education; not operational evidence.
Evidence absent from the bounded search; absence is not proof of nonexistence.
| Meaning | Subject | Analysis model |
|---|---|---|
| AI_AS_TARGET | Attacks against models, data, retrieval, context, tools, infrastructure, and users. | Lifecycle defense: provenance, isolation, least privilege, retrieval authorization, tool-specific credentials, deterministic policy outside the model, egress controls, telemetry, rollback, and human approval. |
| AI_AS_CYBER_ENABLER | AI accelerates conventional reconnaissance, social engineering, vulnerability analysis, or campaign execution. | Defensive analysis must remain non-operational and must not provide executable payloads, credentials, real targets, or attack procedures. |
| AI_ENABLED_MILITARY_KILL_CHAIN | AI assists sensing, fusion, classification, prioritization, assignment, guidance, engagement support, or assessment. | Use a function-context-control model; distinguish recommendation from authorization, navigation autonomy from target-selection autonomy, and classifier score from positive identification. |
Instructional boundary: Educational, defensive, governance-focused, synthetic, and non-operational. No executable payloads, credentials, malware, arbitrary target URLs, real target selection, or weapon-employment procedures.
RESEARCH EDITION
This page follows the public method for provenance, confidence, source independence, alternative accounts, limitations, review state, and visible correction.
CONTINUE