One-sentence brief
Immersive views can reveal dependencies and lateral propagation hidden in a flat diagram, but spectacle, cognitive overload, unsafe authoring, or real-system connectivity can undermine the educational purpose.
AI KILL CHAINS & DECISION SYSTEMS
An event-driven instructional architecture for desktop and WebXR that teaches causality, uncertainty, defensive intervention, and governance without becoming an attack-execution or targeting platform.
ANALYTICAL & SAFETY BOUNDARIES
Analytical boundary: AI kill chain is used here as a family of analytical models. Attacks against AI systems, AI as a conventional cyber enabler, and AI-enabled military targeting are related but distinct subjects. Capability is not deployment; deployment is not autonomy; classification confidence is not positive identification; recommendation is not authorization; a simulation is not operational evidence.
Simulation safety boundary: Use synthetic identities, reserved domains, fictional infrastructure, nonfunctional artifacts, abstract effects, and constrained defensive actions. Do not accept executable scripts, malware, credentials, arbitrary external URLs, real targets, command execution, or contact with third-party systems.
Source basis: Owner-supplied exact source packet with bounded official-primary-source currentness; external claims remain subject to stated source and review limits.
ORIENTATION
Immersive views can reveal dependencies and lateral propagation hidden in a flat diagram, but spectacle, cognitive overload, unsafe authoring, or real-system connectivity can undermine the educational purpose.
WORKING BRIEF
Clients request constrained actions such as inspect indicator, compare evidence, apply control, pause, advance, or replay. The server validates authorization and scenario rules, appends an immutable event, derives the next state, and broadcasts a bounded state delta. The client never supplies executable code or authoritative outcomes.
Deterministic replay supports after-action explanation and testability.
Scenario authoring rejects scripts, shell syntax, executable attachments, arbitrary HTML, external model or media URLs, credentials, malware, real targets, and unreviewed connections. Imported 3D assets are transcoded, validated, budgeted, and quarantined before publication.
A two-person review is required for realistic, organization-specific, exportable, or range-linked scenarios.
Nodes represent sources, models, memories, tools, human gates, controls, and effects. Edges show data flow, authority, uncertainty, and trust boundaries. Animation is useful only when it explains temporal sequence or propagation; decorative motion should yield to reduced-motion preferences.
The same event ledger drives 3D, 2D, table, and text views.
Head pose, hand movement, gaze, voice, room mapping, and performance history can be sensitive. Collect only what the learning objective requires, minimize retention, disclose use, support withdrawal, and avoid inferring mental state. Essential content remains available without a headset or biometric telemetry.
Accessibility and privacy controls are part of the scenario contract rather than optional polish.
COMPLETE DOSSIER
No game connection is required to use this educational page.
Terms are defined for this site’s evidence method, not as universal legal or clinical definitions.
Can any client content become code, a real request, or contact with a third-party system?
Pass condition: No; only schema-validated instructional commands can change synthetic scenario state.
Are doctrine, claims, demonstrations, deployment, and effects visibly separate?
Pass condition: Each record carries source authority, supported proposition, prohibited inference, and uncertainty.
Does the simulation show who may authorize, reject, abort, or reopen action?
Pass condition: Every irreversible transition has an explicit authority and intervention model.
Can a learner complete the essential lesson without VR, animation, pointer precision, or JavaScript?
Pass condition: Equivalent text, table, keyboard, reduced-motion, and desktop paths are available.
Is XR telemetry minimized and prevented from becoming mental-state inference?
Pass condition: Only necessary telemetry is collected with clear purpose, retention, access, and withdrawal controls.
SOURCE QUALITY · UNCERTAINTY · NEUTRALITY
Primary institutional doctrine or policy; supports what the issuing body states, not deployment or compliance.
Primary technical specification or documentation; supports interface/status claims, not truth or field effectiveness.
First-party capability statement requiring independent corroboration.
Attributable public evidence of deployment scope; does not automatically establish autonomy, effectiveness, or legality.
Observed demo or exercise under bounded conditions; not field deployment.
Structured test with stated conditions; external validity remains limited.
Scholarly evidence with method and scope limitations.
Journalistic account requiring attribution and corroboration assessment.
Preserved source packet; claims remain unverified unless separately supported.
Repository-authored inference explicitly marked and linked to supporting evidence.
Synthetic scenario for education; not operational evidence.
Evidence absent from the bounded search; absence is not proof of nonexistence.
| Meaning | Subject | Analysis model |
|---|---|---|
| AI_AS_TARGET | Attacks against models, data, retrieval, context, tools, infrastructure, and users. | Lifecycle defense: provenance, isolation, least privilege, retrieval authorization, tool-specific credentials, deterministic policy outside the model, egress controls, telemetry, rollback, and human approval. |
| AI_AS_CYBER_ENABLER | AI accelerates conventional reconnaissance, social engineering, vulnerability analysis, or campaign execution. | Defensive analysis must remain non-operational and must not provide executable payloads, credentials, real targets, or attack procedures. |
| AI_ENABLED_MILITARY_KILL_CHAIN | AI assists sensing, fusion, classification, prioritization, assignment, guidance, engagement support, or assessment. | Use a function-context-control model; distinguish recommendation from authorization, navigation autonomy from target-selection autonomy, and classifier score from positive identification. |
Instructional boundary: Educational, defensive, governance-focused, synthetic, and non-operational. No executable payloads, credentials, malware, arbitrary target URLs, real target selection, or weapon-employment procedures.
RESEARCH EDITION
This page follows the public method for provenance, confidence, source independence, alternative accounts, limitations, review state, and visible correction.
CONTINUE