Research library
The thirteen documents of OSAFIS 2.0.0-draft.1, a research proposal for describing and assessing security failures in intelligent systems.
- 01OSAFIS Research Vision
OSAFIS proposes a common representation for analysing security failures in intelligent systems. Its purpose is to connect the security contract that failed to…
- 02Foundational Concepts
OSAFIS proposes a vocabulary for describing security failures in intelligent systems and the evidence needed to assess them.
- 03Security Layers
The nine OSAFIS layer identifiers organize analysis by the object, function, or relationship whose security contract may fail.
- 04Security Properties
A security property names an obligation that an assessment can instantiate for a protected object, function, or relationship.
- 05Threat Model
This threat model describes how an intelligent system can lose a specified security property through adversarial influence or through a security-relevant…
- 06Attack Taxonomy
An attack classification should explain the intervention an adversary attempted, the contract it challenged, and the evidence connecting intervention to effect.
- 07Assessment Methodology
This methodology turns a security hypothesis into a bounded, reproducible assessment. It specifies artifacts and decision rules for investigating whether a…
- 08Domain Profiles
A domain profile specifies how the framework applies to a bounded class of deployments. The analytical vocabulary can be shared across systems while…
- 09Vulnerability Registry
The registry records claims, evidence, decisions, and their revision history. Inclusion does not establish validity or framework recognition.
- 10OSAFIS Relationship to Existing Frameworks
OSAFIS should interoperate with established AI security resources. Its proposed contribution is a contract-centred representation that connects a finding to…
- 11OSAFIS Versioning and Identifiers
The proposed format is MAJOR.MINOR.PATCH with an optional prerelease suffix. A MAJOR revision changes the interpretation or classification obligations of…
- 12Future and Autonomous Systems
OSAFIS should remain useful when an intelligent system learns online, changes its executable rules, observes a digital environment, controls physical…
- 13Worked Examples
All twelve cases below are hypothetical and unexecuted. They are neither validated findings nor registry entries.