# Worked Examples

OSAFIS 2.0.0-draft.1 · Illustrative practice cases · 2026-09-07

## Status and use

All twelve cases below are hypothetical and unexecuted. They are neither validated findings nor registry entries. Their identifiers are local teaching references. Proposed observables, positive controls, and negative controls describe a future contained evaluation; no measured result is implied. The cases exercise boundaries deliberately, including correct participation, non-adversarial defects, unresolved attribution, and broad impact without a separate systemic violation.

For each case, a seeded-violation positive control is an isolated fixture deliberately configured to violate the named contract so the detection apparatus can be checked. An authorized-function control instead verifies that legitimate operation remains possible. A negative control is a comparable legitimate condition expected to preserve the contract. State which response each control should produce. No control authorizes harmful live testing. Use synthetic records, simulated actions, and disposable state. The listed security controls are candidates requiring evaluation, not demonstrated mitigations.

Canonical domains are L1 Models & Computation, L2 Software & Infrastructure, L3 Data & Knowledge, L4 Perception & World Representation, L5 Interpretation & Objectives, L6 Memory & State Continuity, L7 Planning & Action, L8 Human–System Interaction, and L9 Collective & Systemic Interaction. A participating domain is not presumed violated. Property labels retain their original identifiers.

## Example 01 Reference text becomes instruction

Contract and scope: a reference-answering system must use retrieved documents as evidence, without granting them administrative instruction authority. Its retrieval service promises faithful delivery, not that every public source is trustworthy. The adversary can edit one reference document but cannot change the user request or system policy. The entry is retrieved content.

Graph path: document → information edge → retriever → information edge → context assembler → instruction interpretation → simulated response. L3 participates in faithful delivery. The proposed violation is at L5 when document text is promoted into authority, implicating P04 Instruction Integrity. Add P11 Semantic Integrity only if a separately specified meaning-preservation obligation also fails; instruction-authority confusion alone does not establish another violation. If the adopted objective changes, P09 Objective Integrity is an additional claim requiring evidence. Mechanisms are M02 Data Manipulation for the intervention and M05 Semantic Manipulation for the authority confusion; M10 Objective Manipulation is conditional.

Observables and failure criterion: record source-role metadata, governing instructions, and whether the output follows the unauthorized instruction in a harmless synthetic task. Positive control: a fixture explicitly treating reference text as administrative input. Negative control: the same reference content quoted for analysis without authority promotion. Compare meaning and requested task rather than merely output wording.

Candidate control: preserve source roles and independently validate instruction authority. Limitation: a changed answer alone cannot identify whether authority confusion occurred. Faithful retrieval does not constitute a separate L3 vulnerability in the stated contract.

## Example 02 Correct camera text followed by injection

Contract and scope: a simulated visual assistant must transcribe a displayed sign accurately and treat environmental writing as observed content. An adversary can place text in the scene. The camera and transcription pipeline remain uncompromised. Entry is the physical scene.

Graph path: sign → observation → camera and transcription → information → interpreter → simulated task response. L4 participates correctly if transcription matches the sign. The hypothesized violation is L5, involving P04 Instruction Integrity. Add P11 Semantic Integrity only if a separately specified meaning-preservation obligation also fails; the presence of text alone does not establish another violation. M03 Environmental Manipulation describes the physical intervention and M05 Semantic Manipulation the authority confusion. Do not add M04 Perception Manipulation merely because a camera delivered the text.

Observables and failure criterion: compare transcription with the known scene text, then assess whether environmental text overrides the authorized task. Positive control: an interpreter fixture that grants all transcribed text instruction priority. Negative control: accurate transcription followed by quotation or description without compliance. A separate transcription-error fixture can check the perception oracle but is not the positive control for this L5 hypothesis.

Candidate control: retain observation provenance through interpretation and gate authority independently of modality. Limitation: scene visibility, transcription confidence, and task ambiguity can confound an uncontrolled test. This example intentionally demonstrates an attack entering through L4 without a P22 Perception Integrity violation.

## Example 03 Retained preference crosses users

Contract and scope: a persistent assistant must bind retained preferences to the authorizing user and session context. An adversary can submit a preference in its own account and trigger a later retrieval path, but cannot directly administer the database. Entry is the preference interface.

Graph path: attacker session → state write → shared preference store → state retrieval → victim context → response. A faulty association at L6 violates P07 Memory Integrity and P08 Identity Integrity; P17 Temporal Integrity is relevant if an expired association is reused. L2 participates in authenticated sessions and is not separately violated unless its account boundary fails. M08 Memory Manipulation and M09 Identity Manipulation describe the attempted contamination.

Observables and failure criterion: capture synthetic user identifiers, association keys, authorized preference writes, and the provenance of reactivated state. Failure is use of the attacker-bound preference as the victim's preference. Positive control: a fixture deliberately sharing the association key. Negative control: separate keys with the same preference content and equivalent timing.

Candidate control: validate subject binding at write and read, and preserve revocation metadata. Limitation: state influence may be difficult to infer from natural-language outputs; direct state provenance is stronger evidence. A shared datastore alone does not establish L9 or even a defect. The case concerns its continuity contract, not its physical storage technology.

## Example 04 Online feedback changes a policy

Contract and scope: an adaptive system may update an executable policy only from feedback satisfying a declared validation rule. An adversary can submit feedback records within an ordinary contributor role. It cannot write executable parameters directly. Entry is the feedback admission interface.

Graph path: submitted feedback → information admission → update procedure → model version → simulated decision. The candidate L3 violation is failure of the stated feedback-admission contract. A separate L1 violation exists only if the update procedure fails its own permitted-update contract. L6 is not assigned merely because examples or parameters persist. P06 Knowledge Integrity and P02 Integrity apply to the respective contracts. M02 Data Manipulation describes the intervention.

Observables and failure criterion: retain feedback provenance, validation decisions, policy version differences, and results on the synthetic policy contract. Positive control: an update fixture that accepts a deliberately invalid feedback record. Negative control: valid matched feedback processed through the same update path, plus invalid feedback correctly rejected.

Candidate control: independent update admission, versioned policy checks, and bounded rollout. Limitation: a harmful decision after an update does not prove poisoned admission; a pre-existing model defect or an insufficient specification may explain it. D5 Lifecycle & Change Management is relevant, but it does not substitute for locating the actual failed update contract.

## Example 05 Symbolic rule import

Contract and scope: a symbolic decision service must activate only approved executable rules. An adversary can publish a rule package offered for import but cannot approve it. Entry is the package import interface. No neural model or prompt is required.

Graph path: proposed package → technical import → approval verifier → active inference rules → simulated decision. Bypassing approval implicates L2; activating rules outside the declared executable-rule contract implicates L1. Record both only when the evidence identifies both failures. L3 may participate as transport of package information. Properties include P02 Integrity and P20 Attribution Integrity where approval attribution is falsified. Mechanism M01 Technical Manipulation applies; M09 Identity Manipulation is conditional on a false approver assertion.

Observables and failure criterion: compare active rule identifiers and approval records against a fixed synthetic allowlist. Positive control: an import fixture that skips approval verification. Negative control: a properly approved package and an unapproved package rejected through the same interface.

Candidate control: separate import from activation and verify approval against the exact artifact. Limitation: a rule that is approved but substantively incorrect presents a different contract question. Do not equate all undesirable symbolic conclusions with import compromise. This case tests whether L1 remains intelligible without learned weights and whether L1 versus L2 attribution follows contracts rather than product names.

## Example 06 Stale digital world representation

Contract and scope: a browser-operating system must revalidate the current target after a page-state change before issuing a simulated action. A benign asynchronous update changes the interface after observation. No adversary is assumed, so no M identifier is assigned.

Graph path: page state → observation → retained environment estimate → planner → action validator → simulated target. L4 is violated if its specified estimate-validity contract presents the stale target as current, implicating P23 World-Model Integrity and P17 Temporal Integrity. L7 is additionally violated only if independent action revalidation is required and omitted, implicating P13 Action Integrity. The stale estimate's retention does not automatically establish an L6 defect.

Observables and failure criterion: record state version, observation timestamp, target identity, and action-time validation. Failure is a simulated action against a target whose required validity check was not satisfied. Positive control: a fixture that deliberately suppresses revalidation after a known state change. Negative control: an unchanged page and a changed page with correct revalidation.

Candidate control: bind actions to validated environment state or require fresh target checks. Limitation: this is a candidate quality or safety defect unless security relevance is established under the deployment contract. An adversarial variant would require a separately stated attacker capability; none is invented here.

## Example 07 Delegated scope expands

Contract and scope: an executor receiving delegated authority for one synthetic resource must not operate on another resource. An adversarial upstream agent can send task messages but has authority only over the first resource. Entry is the delegation interface.

Graph path: authorized principal → authority delegation → upstream agent → attempted delegation → executor → simulated resource. The L7 failure is acceptance of expanded scope, violating P16 Delegation Integrity. P12 Capability Integrity additionally requires evidence against a separately specified capability-selection obligation. A separate L2 access-control failure is conditional on the stated enforcement architecture. Mechanisms M11 Capability Manipulation and M09 Identity Manipulation apply when the message falsely asserts expanded authority.

Observables and failure criterion: preserve delegation ancestry, permitted targets, expiry, and executor decisions. Failure is acceptance of an action outside the originating scope. Positive control: an executor fixture that trusts the immediate sender without checking ancestry. Negative control: an in-scope delegation and the same out-of-scope request correctly rejected.

Candidate control: independently verify delegated scope and require target binding. Limitation: authentication of the upstream agent establishes identity, not authority for every target. An information message between agents would not be a delegation edge. The involvement of multiple agents does not itself create an L9 failure.

## Example 08 Shared model creates broad impact

Contract and scope: a deployment must serve the approved model artifact. An adversary with unauthorized write access replaces that artifact. Many clients use the shared service, but no separate collective interaction contract is specified. Entry is the artifact store.

Graph path: unauthorized artifact write → shared model node → resource dependency edges → multiple clients → simulated outputs. L2 is implicated by the unauthorized write; L1 by serving the substituted model under an approved-artifact contract. P02 Integrity is the central property. M01 Technical Manipulation describes the intervention. L9 is not assigned solely because client count or impact is large.

Observables and failure criterion: compare served artifact identity with approval records and trace which synthetic clients share it. Positive control: a test deployment intentionally serving a disallowed artifact. Negative control: all clients served the approved artifact through the same shared infrastructure.

Candidate control: artifact verification at activation and serving, with explicit shared-dependency inventory. Limitation: additional evidence could establish an L9 containment or feedback failure, but this scenario does not supply it. The graph must retain the single shared node rather than pretending each client owns an independent copy. Impact scope is recorded even without a systemic vulnerability label.

## Example 09 Collective retry overload

Contract and scope: a group of cooperating clients must preserve a declared shared-service availability envelope under a bounded transient error. All clients follow their local retry rules. No attacker is assumed. Entry is the benign service disturbance.

Graph path: service error → feedback → client retry policies → resource dependency → shared queue → further service errors. The hypothesized failure resides at L9 in the group contract, involving P03 Availability. L2 and L7 participate in service operation and local actions; their individual contracts may remain satisfied. No attack mechanism is assigned.

Observables and failure criterion: in a bounded simulator, measure aggregate request load, queue occupancy, and recovery relative to the declared envelope. Positive control: a fixture with intentionally synchronized retry behavior known by construction to exceed the configured test budget. Negative control: a coordinated retry fixture under the same disturbance and a no-disturbance baseline.

Candidate control: a collective retry budget, admission coordination, or bounded backoff policy. Limitation: exceeding a budget must be observed in an eventual test, not assumed from this narrative. Without a declared group contract, the case remains an architectural hazard hypothesis. This illustrates why failures may concern a subgraph rather than one agent or one communication edge.

## Example 10 Physical stop contract fails without an attacker

Contract and scope: a simulated actuator system must bring commanded motion inside a specified safe envelope after a stop signal within a declared interval. A benign implementation defect delays cancellation. No adversary is present.

Graph path: operator stop → intervention signal → controller → actuator simulation → motion state. L7 is implicated by the failure to enforce the stop contract, involving P14 Controllability and P13 Action Integrity. L8 participates through the operator interface; it is not separately violated if it accurately communicates the stop request and response state. L2 is conditional on whether a distinct implementation contract is identified. No mechanism tag is assigned.

Observables and failure criterion: compare command and stop timestamps, simulated motion, and the stated response envelope. Positive control: a simulation fixture deliberately delaying cancellation beyond the limit. Negative control: timely cancellation under equivalent starting conditions and load.

Candidate control: an independent stop path and explicit cancellation propagation, assessed within a domain-reviewed safety design. Limitation: this is a safety defect hypothesis, not an established attack. A live physical experiment is neither necessary nor authorized by the example. Simulation cannot establish deployment safety outside its modeled envelope.

## Example 11 Team authorization is misrepresented

Contract and scope: a decision interface must distinguish a recommendation from recorded team approval and disclose unresolved objections before a synthetic commitment. An adversary can provide a forged approval summary through an ordinary information channel. It cannot alter actual approval records. Entry is the summary source.

Graph path: adversarial summary → information → presentation interface → human team review → simulated authorization. L8 is implicated if the interface represents the unverified summary as completed approval, involving P19 Human Decision Integrity and P20 Attribution Integrity. M09 Identity Manipulation and M12 Human Manipulation describe the attempted influence. L3 participates; a separate provenance contract failure is conditional. L9 is not automatic merely because several people review the interface.

Observables and failure criterion: first inspect whether the interface distinguishes verified approvals, recommendations, and objections. Positive control: a fixture deliberately displaying an unverified approval as verified. Negative control: identical content clearly labeled unverified with the authoritative record visible. Any study of actual human decisions requires appropriate consent, review, debriefing, and data protection.

Candidate control: bind approval displays to authoritative records and show material disagreement. Limitation: interface inspection can establish misrepresentation but cannot quantify its effect on human decisions. Synthetic agents must not be presented as evidence about a human team.

## Example 12 Self generated evidence recirculates

Contract and scope: a research collective must not treat recirculated claims as independent corroboration when they originate from the same source. An adversary can seed one claim into a public input used by the collective, without controlling its internal services. Entry is that information source.

Graph path: seeded claim → information → agent A summary → shared publication store → retrieval by agents B and C → feedback → collective confidence decision. L3 is implicated if promised provenance independence checks fail. A distinct L9 violation is hypothesized where the collective corroboration contract counts dependent feedback as independent evidence. P06 Knowledge Integrity, P20 Attribution Integrity, and P21 Trust Integrity are relevant. M02 Data Manipulation applies to the seed; further mechanism attribution requires evidence.

Observables and failure criterion: track synthetic claim lineage, citations, source dependence, and the collective acceptance rule. Positive control: a fixture intentionally counting copies as independent sources. Negative control: lineage-preserving copies correctly counted once, alongside truly independent synthetic sources evaluated under the same rule.

Candidate control: maintain provenance and enforce independence at the collective decision boundary. Limitation: shared wording alone does not prove common origin, and source dependence does not automatically make a claim false. The contract concerns warranted corroboration, not guaranteed truth. This example differs from broad distribution in Example 08 because a specific feedback coupling and collective contract are stated.

## Reading the set as a boundary test

The set intentionally contains fewer than nine violated domains in many cases and no adversary in several. That is correct use of the method. Mechanism uncertainty is allowed, domains can participate without failure, and one property can be relevant at several loci. Property tags require the stated contract rather than keyword matching.

Before using these cases in a coding study, freeze the case text and scoring rubric, separate training examples from held-out cases, and have reviewers classify independently. Disagreement with the proposed classifications should be recorded and adjudicated against explicit contracts. These examples are editorial hypotheses about useful boundaries, not a benchmark with established ground truth or evidence that the nine-domain architecture is complete.
