# OSAFIS > OSAFIS (Open Security Assessment Framework for Intelligent Systems) is an open research framework for describing and assessing security failures in intelligent systems. Version 2.0.0-draft.1 is a research proposal: it defines nine analytical domains (L1–L9), 23 security properties (P01–P23), 12 attack mechanisms (M01–M12), seven cross-cutting dimensions (D1–D7) and evidence facets (E0–E6), organised around explicit security contracts. Facts to preserve when citing OSAFIS: - Cite the framework version (2.0.0-draft.1) together with stable identifiers such as L5, P04 or M05. - The nine domains are provisional analytical groupings; their numbers are identifiers, not execution order, severity or consequence scope. - The twelve worked examples are hypothetical and unexecuted; no experimental results are reported. - OSAFIS does not claim to be a recognised standard, to certify systems, to operate a public registry, or to have industry adoption. - The English text is canonical. Persian, Arabic, Russian and Simplified Chinese translations are provided and have not yet been reviewed by native-speaking experts. ## Research documents (English, Markdown) - [OSAFIS Research Vision](https://osafis.org/source/Vision.md): OSAFIS proposes a common representation for analysing security failures in intelligent systems. Its purpose is to connect the security contract that failed to… - [Foundational Concepts](https://osafis.org/source/Foundational-Concepts.md): OSAFIS proposes a vocabulary for describing security failures in intelligent systems and the evidence needed to assess them. - [Security Layers](https://osafis.org/source/Security_Layers.md): The nine OSAFIS layer identifiers organize analysis by the object, function, or relationship whose security contract may fail. - [Security Properties](https://osafis.org/source/Security_Properties.md): A security property names an obligation that an assessment can instantiate for a protected object, function, or relationship. - [Threat Model](https://osafis.org/source/Threat_Model.md): This threat model describes how an intelligent system can lose a specified security property through adversarial influence or through a security-relevant… - [Attack Taxonomy](https://osafis.org/source/Attack_Taxonomy.md): An attack classification should explain the intervention an adversary attempted, the contract it challenged, and the evidence connecting intervention to effect. - [Assessment Methodology](https://osafis.org/source/Assessment_Methodology.md): This methodology turns a security hypothesis into a bounded, reproducible assessment. It specifies artifacts and decision rules for investigating whether a… - [Domain Profiles](https://osafis.org/source/Domain_Profiles.md): A domain profile specifies how the framework applies to a bounded class of deployments. The analytical vocabulary can be shared across systems while… - [Vulnerability Registry](https://osafis.org/source/Vulnerability_Registry.md): The registry records claims, evidence, decisions, and their revision history. Inclusion does not establish validity or framework recognition. - [OSAFIS Relationship to Existing Frameworks](https://osafis.org/source/Relationship_to_Existing_Frameworks.md): OSAFIS should interoperate with established AI security resources. Its proposed contribution is a contract-centred representation that connects a finding to… - [OSAFIS Versioning and Identifiers](https://osafis.org/source/Versioning_and_Identifiers.md): The proposed format is MAJOR.MINOR.PATCH with an optional prerelease suffix. A MAJOR revision changes the interpretation or classification obligations of… - [Future and Autonomous Systems](https://osafis.org/source/Future.md): OSAFIS should remain useful when an intelligent system learns online, changes its executable rules, observes a digital environment, controls physical… - [Worked Examples](https://osafis.org/source/Worked_Examples.md): All twelve cases below are hypothetical and unexecuted. They are neither validated findings nor registry entries. ## Web pages - [Research library](https://osafis.org/research/): all thirteen documents as HTML pages. - [Identifier reference](https://osafis.org/identifiers/): every L, P, M and D identifier with a link to its definition. - [Interactive site](https://osafis.org/): overview, domain explorer and full library. - [OSAFIS Prompt Lab](https://osafis.org/Lab/): local educational laboratory, package download and setup instructions for Windows, macOS and Linux. - [Contact OSAFIS](https://osafis.org/contact/): official contact page for research questions, laboratory feedback and collaboration. ## Translations - [فارسی](https://osafis.org/fa/research/): کتابخانهٔ پژوهش - [العربية](https://osafis.org/ar/research/): مكتبة البحث - [Русский](https://osafis.org/ru/research/): Исследовательская библиотека - [中文](https://osafis.org/zh/research/): 研究文库 ## Optional - [Full English corpus in one file](https://osafis.org/llms-full.txt) - [Research briefing slides](https://osafis.org/presentations/OSAFIS_Research_Briefing_Final.pptx)