Add AVE-2026-00078/79/80: multi-agent pipeline boundary records (arXiv:2608.00718) - #177
Conversation
Three genuinely distinct behavioral classes extracted from Bappy et al., "Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in Agentic AI Architectures" (arXiv:2608.00718, accepted IEEE GLOBECOM 2026), empirically derived from 147 annotated TRAIL- benchmark production traces (GAIA + SWE-Bench Lite) plus a controlled cross-model evaluation (GPT-5-mini, Claude Sonnet 4.5, Kimi K2.5). The paper's fourth mechanism (prompt injection via retrieved content, its content-boundary class) was confirmed already covered by AVE-2026-00016 and related records via keyword sweep and field-level provenance_vector comparison -- not drafted as new. - AVE-2026-00078: consensus poisoning -- an orchestrator accepts a single sub-agent's result as authoritative with no quorum or cross-verification across redundant sources. Distinct from AVE-2026-00020 and AVE-2026-00018 (issue #174). MEDIUM, AIVSS 6.4. - AVE-2026-00079: plan hijacking via false completion signal -- a self-reported "task already completed" claim forces early termination of a declared plan with no plan-to-execution binding check. Distinct from AVE-2026-00021 and AVE-2026-00063 (issue #175). MEDIUM, AIVSS 6.2. - AVE-2026-00080: silent agent substitution (Sybil) -- an unverified process responding at an agent's routing position during a retry is accepted as that agent with no credential check. Distinct from AVE-2026-00017 and AVE-2026-00030 (issue #176). MEDIUM, AIVSS 6.8. owasp_mcp mappings verified against the primary OWASP MCP Top 10 source docs (MCP06, MCP07). mitre_atlas swept against the live 170-technique ATLAS.yaml -- no fit found for any of the three, confirmed genuine gap rather than forced. nist_ai_rmf verified against the NIST AI 100-1 primary text. owasp_asi omitted -- no stable, independently-verifiable primary-source category list could be confirmed. researcher field credits the paper's actual authors, not an AVE maintainer, per docs/specs/researcher-process.md. Validated: scripts/validate_records.py, scripts/check_fixtures.py, pytest tests/ (321 passed). Published via scripts/build-records.js. README badge/stats/record-index and CHANGELOG updated.
Fixes a gap caught in PR #177 review: owasp_asi was silently absent from AVE-2026-00078/00079/00080 despite each record's aivss.notes already documenting the research that ruled it out. The key just never got added. Set to [] on all three with the existing reasoning kept in aivss.notes -- an absent key reads as "nobody checked", an empty array reads as "checked, no fit found", and only the second is honest. - records/AVE-2026-00078/79/80.json: add "owasp_asi": [], reword the corresponding aivss.notes sentence from "omitted" to "left empty" - docs/specs/researcher-process.md: replace the "optional, omit rather than force a fit" framing for owasp_asi/owasp_mcp/mitre_atlas/ nist_ai_rmf (which incorrectly grouped owasp_mcp as optional even though the schema requires it) with a "governance and framework mappings" section stating owasp_mcp is schema-required and the other three must always have the key present (empty array when no fit), plus a Common Mistakes entry documenting this exact recurrence - .claude/skills/add-ave-record/SKILL.md: same rule added to Step 3, with a pointer to the researcher-process.md detail Making key-presence for owasp_asi/mitre_atlas/nist_ai_rmf an actual schema constraint (not just a process-doc convention) is tracked separately as a deliberate v1.2.0 minor version bump -- issue #178 -- not done here since schema/ave-record-1.1.0.schema.json is a frozen snapshot that's never edited retroactively per docs/specs/scaling-and-governance.md Section 2. Revalidated: scripts/validate_records.py (80/80), check_fixtures.py, pytest tests/ (321 passed). Republished via scripts/build-records.js.
|
Fixed a gap caught in review: `owasp_asi` was silently missing (not
Re-ran |
…us precedent Prompted by discovering (issue #179) that owasp_asi's ASI01-ASI10 numbering, used consistently across ~65 records and hard-coded into the schema's own regex, doesn't exist anywhere in OWASP's actual Agentic Security Initiative document -- confirmed by fetching the real PDF and grepping the full text, zero matches. The real taxonomy uses T1-T17. The fabricated numbering traces to a third-party blog's own retelling of the initiative, not OWASP's own document, and appears to have propagated by each record copying the pattern already used by prior records rather than any record tracing back to the source. docs/specs/researcher-process.md and the add-ave-record skill both now state explicitly: "primary source" means the actual document, fetched and read -- not a search result, not a WebFetch summary, not a third-party blog, and not corpus precedent no matter how many existing records agree with each other. Internal agreement across many records is not the same evidence as one primary-source document actually opened and read once. Added as a Common Mistakes entry in researcher-process.md alongside the existing ones (entry_class vs enforcement_point confusion, aars/aarf mismatches, label-vs-field duplicate checks). No schema or record changes in this commit -- issue #179 scopes the actual remediation (schema regex fix, per-record corpus audit) as separate, larger work, per explicit direction to file a tracking issue only for now.
|
While deep-checking whether `owasp_asi`/`mitre_atlas` really had That's a corpus-wide problem, not specific to this PR, so scoped it Added to this PR: `docs/specs/researcher-process.md` and the Re-validated after this addition: 80/80 schema-valid, 321 tests |
Summary
Three genuinely distinct behavioral classes extracted from Bappy et
al., "Adversarial Attacks in Multi-Agent LLM Pipelines: Unveiling
Structural Vulnerabilities in Agentic AI Architectures"
(arXiv:2608.00718, accepted IEEE
GLOBECOM 2026), empirically derived from 147 annotated TRAIL-benchmark
production traces (GAIA + SWE-Bench Lite) plus a controlled cross-model
evaluation (GPT-5-mini, Claude Sonnet 4.5, Kimi K2.5).
The paper actually describes four mechanisms. Its fourth (prompt
injection via retrieved content, the paper's "content boundary" class)
was checked against the live corpus by keyword sweep and field-level
provenance_vectorcomparison and confirmed already covered byAVE-2026-00016 and related records — not drafted as new. The other
three cleared the distinctness bar and are drafted here, each with its
id confirmed via its own issue first.
All three scored MEDIUM — AARF rewards amplification breadth, not raw
impact, and each of these is an architectural, single/dual-vector
mechanism even though the underlying failure mode reads as severe.
Framework mappings
owasp_mcp: verified against the primary OWASP MCP Top 10 sourcedocs (
github.com/OWASP/www-project-mcp-top-10), not inferred fromcorpus usage. MCP06 (Intent Flow Subversion) for 00078/00079 — its
own "Blind Planning" checklist criterion and Scenario B match
closely; MCP07 (Insufficient Authentication & Authorization) for
00080 — its own Impact list and Scenario 3 match closely.
mitre_atlas: swept the live 170-techniqueATLAS.yamldirectlyfor each mechanism. No fit found for any of the three — confirmed
genuine gap, documented in each record's
aivss.notesrather thanforced.
nist_ai_rmf: verified against the actual NIST AI 100-1 primarytext (Tables 1-4), not the corpus's own precedent alone.
owasp_asi: deliberately omitted — could not confirm a stable,independently-verifiable primary-source ASI01–10 category list at
drafting time.
Attribution
researcheron all three credits the paper's actual authors (FaisalHaque Bappy, Tahrim Hossain, Tarannum Shaila Zaman, Raiful Hasan,
Kamrul Hasan, Tariqul Islam),
researcher_urlpoints at the realarXiv page — not defaulted to an AVE maintainer, per
docs/specs/researcher-process.md.Checklist
AVE-2026-00079: Plan hijacking via false completion signal — forced early termination #175, AVE-2026-00080: Silent agent substitution (Sybil) via unverified retry #176)
python3 scripts/validate_records.py— 80/80 validpython3 scripts/check_fixtures.py— all have fixturespytest tests/ -x -q— 321 passednode scripts/build-records.js(not hand-edited)Closes #174, closes #175, closes #176.