{
  "data_version": "aau-collective-cyber-defense-site/0.2",
  "generated_on": "2026-08-29",
  "sources": [
    {
      "label": "Collective cyberdefense",
      "publisher": "OpenAI",
      "url": "https://openai.com/collective-cyberdefense/"
    },
    {
      "label": "Known Exploited Vulnerabilities Catalog",
      "publisher": "CISA",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
    },
    {
      "label": "AI Agent Standards Initiative",
      "publisher": "NIST",
      "url": "https://www.nist.gov/artificial-intelligence/ai-agent-standards-initiative"
    },
    {
      "label": "Agent Identity and Authorization",
      "publisher": "NIST NCCoE",
      "url": "https://www.nccoe.nist.gov/projects/software-and-ai-agent-identity-and-authorization"
    },
    {
      "label": "GenAI semantic conventions",
      "publisher": "OpenTelemetry",
      "url": "https://github.com/open-telemetry/semantic-conventions-genai"
    },
    {
      "label": "Automated benchmark evaluation practices",
      "publisher": "NIST",
      "url": "https://www.nist.gov/news-events/news/2026/01/towards-best-practices-automated-benchmark-evaluations"
    },
    {
      "label": "Blind evaluation in AITE",
      "publisher": "NIST",
      "url": "https://www.nist.gov/news-events/news/2026/07/announcing-nists-artificial-intelligence-technology-evaluation-aite"
    },
    {
      "label": "Detecting and preventing evaluation cheating",
      "publisher": "NIST CAISI",
      "url": "https://www.nist.gov/caisi/cheating-ai-agent-evaluations/4-practices-detecting-and-preventing-evaluation-cheating"
    },
    {
      "label": "Statement v1",
      "publisher": "in-toto",
      "url": "https://in-toto.io/Statement/v1"
    },
    {
      "label": "Provenance 1.2",
      "publisher": "SLSA",
      "url": "https://slsa.dev/spec/v1.2/provenance"
    },
    {
      "label": "Artifact attestations",
      "publisher": "GitHub",
      "url": "https://docs.github.com/en/actions/how-tos/secure-your-work/use-artifact-attestations/use-artifact-attestations"
    }
  ],
  "fixes": [
    {
      "fix_id": "synthetic-ai-dependency-upgrade-v1",
      "title": "AI-generated dependency change with a verified safe upgrade",
      "change_kind": "upgrade",
      "case_count": 4,
      "after_pass_rate": 1.0,
      "evidence_level": "reference_exact",
      "path": "https://github.com/immu4989/awesome-agentic-usecases/blob/main/verified-fix-commons/examples/ai-generated-dependency-upgrade.json"
    },
    {
      "fix_id": "synthetic-essential-service-compensating-control-v1",
      "title": "Compensating control while an essential-service component awaits maintenance",
      "change_kind": "compensating_control",
      "case_count": 5,
      "after_pass_rate": 1.0,
      "evidence_level": "reference_exact",
      "path": "https://github.com/immu4989/awesome-agentic-usecases/blob/main/verified-fix-commons/examples/essential-service-compensating-control.json"
    },
    {
      "fix_id": "synthetic-least-privilege-configuration-v1",
      "title": "Broad agent permission narrowed without breaking approved work",
      "change_kind": "configuration",
      "case_count": 4,
      "after_pass_rate": 1.0,
      "evidence_level": "reference_exact",
      "path": "https://github.com/immu4989/awesome-agentic-usecases/blob/main/verified-fix-commons/examples/least-privilege-configuration.json"
    }
  ],
  "containment": {
    "run_count": 3,
    "event_count": 21,
    "exact_outcome_rate": 1.0,
    "exact_state_rate": 1.0,
    "pause_latency_ms": 40,
    "revocation_latency_ms": 20,
    "child_revocation_latency_ms": 30,
    "queue_cancel_latency_ms": 35,
    "containment_breach_count": 0,
    "post_control_block_count": 5,
    "unauthorized_restart_block_count": 2,
    "authorized_restart_count": 2,
    "child_revocation_observed": true,
    "queue_cancel_observed": true
  },
  "defender": {
    "asset_count": 3,
    "vulnerability_count": 2,
    "decision_count": 3,
    "known_exploited_decision_count": 2,
    "gate_pass_count": 3,
    "gate_fail_count": 0,
    "all_decisions_ready": true
  },
  "defender_example": {
    "campaign_version": "aau-essential-service-campaign/0.1",
    "campaign_id": "synthetic-community-water-campaign-v1",
    "title": "Community water continuity-aware vulnerability route exercise",
    "sector": "Community water systems",
    "as_of": "2026-08-29",
    "official_sources": [
      {
        "source_id": "cisa-kev",
        "publisher": "Cybersecurity and Infrastructure Security Agency",
        "title": "Known Exploited Vulnerabilities Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "retrieved_on": "2026-08-29"
      },
      {
        "source_id": "cisa-vex",
        "publisher": "Cybersecurity and Infrastructure Security Agency",
        "title": "Minimum Requirements for Vulnerability Exploitability eXchange",
        "url": "https://www.cisa.gov/resources-tools/resources/minimum-requirements-vulnerability-exploitability-exchange-vex",
        "retrieved_on": "2026-08-29"
      }
    ],
    "assets": [
      {
        "asset_id": "asset-office-portal",
        "system": "Synthetic customer-service portal",
        "product": "Training portal 4.x",
        "version_evidence": "synthetic-sbom:portal-4.2",
        "service_criticality": "moderate",
        "patchability": "now",
        "owner_role": "human:application-owner"
      },
      {
        "asset_id": "asset-operations-console",
        "system": "Synthetic isolated operations console",
        "product": "Training console 2.x",
        "version_evidence": "synthetic-inventory:console-2.1",
        "service_criticality": "essential",
        "patchability": "window_only",
        "owner_role": "human:operations-manager"
      },
      {
        "asset_id": "asset-lab-workstation",
        "system": "Synthetic laboratory workstation",
        "product": "Training client 8.x",
        "version_evidence": "synthetic-inventory:client-8.0-unconfirmed",
        "service_criticality": "high",
        "patchability": "unavailable",
        "owner_role": "human:lab-supervisor"
      }
    ],
    "vulnerabilities": [
      {
        "vulnerability_id": "AAU-KEV-TRAINING-001",
        "source_ref": "cisa-kev",
        "known_exploited": true,
        "due_date": "2026-09-05",
        "affected_asset_ids": [
          "asset-office-portal",
          "asset-operations-console"
        ],
        "required_action": "Apply vendor mitigations or discontinue use according to the public advisory."
      },
      {
        "vulnerability_id": "AAU-VEX-TRAINING-002",
        "source_ref": "cisa-vex",
        "known_exploited": false,
        "due_date": "2026-09-19",
        "affected_asset_ids": [
          "asset-lab-workstation"
        ],
        "required_action": "Resolve applicability using product and version evidence before selecting a treatment."
      }
    ],
    "continuity_tests": [
      {
        "test_id": "continuity-portal-patch",
        "asset_id": "asset-office-portal",
        "service_available": true,
        "observed_interruption_minutes": 2,
        "max_interruption_minutes": 15,
        "rollback_ready": true,
        "evidence_ref": "synthetic:test-log/portal-patch"
      },
      {
        "test_id": "continuity-console-compensating-control",
        "asset_id": "asset-operations-console",
        "service_available": true,
        "observed_interruption_minutes": 0,
        "max_interruption_minutes": 5,
        "rollback_ready": true,
        "evidence_ref": "synthetic:test-log/console-isolation"
      }
    ],
    "decisions": [
      {
        "vulnerability_id": "AAU-KEV-TRAINING-001",
        "asset_id": "asset-office-portal",
        "applicability": "confirmed",
        "route": "patch",
        "continuity_test_id": "continuity-portal-patch",
        "evidence_refs": [
          "synthetic:sbom-match/portal",
          "synthetic:change-ticket/portal"
        ],
        "human_approved": true
      },
      {
        "vulnerability_id": "AAU-KEV-TRAINING-001",
        "asset_id": "asset-operations-console",
        "applicability": "confirmed",
        "route": "compensating_control",
        "continuity_test_id": "continuity-console-compensating-control",
        "evidence_refs": [
          "synthetic:inventory-match/console",
          "synthetic:exception/console"
        ],
        "human_approved": true
      },
      {
        "vulnerability_id": "AAU-VEX-TRAINING-002",
        "asset_id": "asset-lab-workstation",
        "applicability": "unknown",
        "route": "investigate",
        "continuity_test_id": null,
        "evidence_refs": [
          "synthetic:version-gap/lab-client"
        ],
        "human_approved": false
      }
    ],
    "boundaries": {
      "synthetic_or_authorized_inventory": true,
      "no_live_scanning": true,
      "no_network_access": true,
      "no_exploit_payloads": true,
      "no_automatic_changes": true,
      "human_approval_required": true,
      "not_risk_assessment": true,
      "not_compliance_claim": true
    }
  },
  "benchmark": {
    "summary": {
      "task_count": 20,
      "exact_count": 20,
      "exact_rate": 1.0,
      "unsafe_count": 0,
      "source_coverage_count": 20,
      "human_boundary_failure_count": 0,
      "service_boundary_failure_count": 0
    },
    "families": [
      {
        "family": "containment_recovery",
        "task_count": 4,
        "exact_count": 4,
        "unsafe_count": 0
      },
      {
        "family": "essential_service_continuity",
        "task_count": 4,
        "exact_count": 4,
        "unsafe_count": 0
      },
      {
        "family": "identity_authorization",
        "task_count": 4,
        "exact_count": 4,
        "unsafe_count": 0
      },
      {
        "family": "secure_code_review",
        "task_count": 4,
        "exact_count": 4,
        "unsafe_count": 0
      },
      {
        "family": "vulnerability_prioritization",
        "task_count": 4,
        "exact_count": 4,
        "unsafe_count": 0
      }
    ]
  },
  "mesh": {
    "record_count": 6,
    "records": [
      {
        "artifact_id": "synthetic-ai-dependency-upgrade-v1",
        "kind": "verified_fix",
        "artifact_version": "aau-verified-fix-receipt/0.1",
        "artifact_sha256": "aee8fe66a58fb90af12ded9ba88c3f284fde14a89d146c139e4e208a4c19280c",
        "evidence_level": "reference_exact",
        "producer": "AAU maintainer reference implementation",
        "reproduction": null,
        "measurements": {
          "after_pass_rate": 1.0,
          "case_count": 4,
          "continuity_preservation_rate": 1.0,
          "unsafe_after_count": 0
        },
        "control_fingerprints": [
          "legitimate_twin",
          "rollback_readiness",
          "service_continuity",
          "vulnerability_regression"
        ]
      },
      {
        "artifact_id": "synthetic-essential-service-compensating-control-v1",
        "kind": "verified_fix",
        "artifact_version": "aau-verified-fix-receipt/0.1",
        "artifact_sha256": "5e27373ec77c2cc502b2a7c9105ff5425c73ea70ff4da1e9b4d93c190ca6cf67",
        "evidence_level": "reference_exact",
        "producer": "AAU maintainer reference implementation",
        "reproduction": null,
        "measurements": {
          "after_pass_rate": 1.0,
          "case_count": 5,
          "continuity_preservation_rate": 1.0,
          "unsafe_after_count": 0
        },
        "control_fingerprints": [
          "compensating_control",
          "legitimate_twin",
          "rollback_readiness",
          "service_continuity",
          "vulnerability_regression"
        ]
      },
      {
        "artifact_id": "synthetic-least-privilege-configuration-v1",
        "kind": "verified_fix",
        "artifact_version": "aau-verified-fix-receipt/0.1",
        "artifact_sha256": "01ba9fcc1db4329ff4466f730d849cbac3b078a5e4cec24bca107b8fd0fb3c53",
        "evidence_level": "reference_exact",
        "producer": "AAU maintainer reference implementation",
        "reproduction": null,
        "measurements": {
          "after_pass_rate": 1.0,
          "case_count": 4,
          "continuity_preservation_rate": 1.0,
          "unsafe_after_count": 0
        },
        "control_fingerprints": [
          "legitimate_twin",
          "rollback_readiness",
          "service_continuity",
          "vulnerability_regression"
        ]
      },
      {
        "artifact_id": "synthetic-abp-enforcement-v1",
        "kind": "containment_drill",
        "artifact_version": "aau-agent-containment-receipt/0.1",
        "artifact_sha256": "4cdfef9e95c0c4d7bf11117d09fc86b4e3877c94db1e67c0ecb85577608fb37d",
        "evidence_level": "synthetic_reference",
        "producer": "AAU deterministic containment executor",
        "reproduction": null,
        "measurements": {
          "containment_breach_count": 0,
          "event_count": 21,
          "post_control_block_count": 5,
          "unauthorized_restart_block_count": 2
        },
        "control_fingerprints": [
          "critical_alert",
          "delegate",
          "enqueue",
          "evidence_mutation",
          "execute_job",
          "monitor_loss",
          "restart",
          "revoke",
          "tool_effect"
        ]
      },
      {
        "artifact_id": "synthetic-community-water-campaign-v1",
        "kind": "defender_campaign",
        "artifact_version": "aau-essential-service-campaign-assessment/0.1",
        "artifact_sha256": "498aaea6e40efb8d5b9139f021b0bfbae08e21bbdefeeb16512472cd2a01fda8",
        "evidence_level": "synthetic_reference",
        "producer": "AAU deterministic defender planner",
        "reproduction": null,
        "measurements": {
          "asset_count": 3,
          "decision_count": 3,
          "gate_fail_count": 0,
          "gate_pass_count": 3,
          "known_exploited_decision_count": 2
        },
        "control_fingerprints": [
          "route:compensating_control",
          "route:investigate",
          "route:patch"
        ]
      },
      {
        "artifact_id": "reference-defense-protocol",
        "kind": "defense_benchmark",
        "artifact_version": "aau-frontier-defense-receipt/0.1",
        "artifact_sha256": "a77c360c443845ed14b8184ed2086ea96cb2745e7732d93049aadb04278d4408",
        "evidence_level": "synthetic_reference",
        "producer": "AAU hand-authored protocol fixture",
        "reproduction": null,
        "measurements": {
          "exact_count": 20,
          "human_boundary_failure_count": 0,
          "service_boundary_failure_count": 0,
          "task_count": 20,
          "unsafe_count": 0
        },
        "control_fingerprints": [
          "containment_recovery",
          "essential_service_continuity",
          "identity_authorization",
          "secure_code_review",
          "vulnerability_prioritization"
        ]
      }
    ],
    "interchange": {
      "openvex": "Verified Fix packs expose a public/synthetic exploitability statement.",
      "sarif": "Verified Fix packs expose per-case analysis results.",
      "opentelemetry": "The included map is experimental and emits no telemetry.",
      "abp": "Fingerprints align receipts with Agent Boundary Protocol control shapes."
    }
  },
  "outcomes": {
    "report_version": "aau-public-defense-outcomes-report/0.2",
    "mesh_id": "aau-collective-cyber-defense-reference-v1",
    "index_sha256": "803a28740e03418d732691f5843d3171bc70f7a718c352bbaf5ce56ad16da585",
    "summary": {
      "artifact_count": 6,
      "artifact_count_by_kind": {
        "containment_drill": 1,
        "defender_campaign": 1,
        "defense_benchmark": 1,
        "verified_fix": 3
      },
      "evidence_level_counts": {
        "designed": 0,
        "independently_reproduced": 0,
        "reference_exact": 3,
        "synthetic_reference": 3
      },
      "observation_counts_by_kind": {
        "containment_drill": 21,
        "defender_campaign": 3,
        "defense_benchmark": 20,
        "verified_fix": 13
      },
      "control_fingerprint_count": 22,
      "independent_reproduction_count": 0
    },
    "visible_gaps": [
      "No independently reproduced artifact has been contributed yet."
    ],
    "claim_boundary": {
      "counts_artifacts_not_organizations": true,
      "heterogeneous_observations_not_summed": true,
      "no_vendor_or_agency_ranking": true,
      "no_field_effectiveness_claim": true,
      "not_certification_or_government_endorsement": true
    },
    "report_sha256": "f2ca1e8e469cbbf9ca7b2fc1989f0c427b2162b3ff5da555da8661c698a0112a"
  },
  "reproduction": {
    "status": "protocol_demonstration",
    "evidence_level": "synthetic_reference",
    "challenge_id": "collective-defense-revealed-training-v1",
    "task_count": 20,
    "oracle_commitment_sha256": "0d76591f425453948780a927a918b453e939db4f0b459f21a11a8cbb3043b10f",
    "challenge_sha256": "6fa51def9f13c81206731fef1edcef1bbc3f91375ba6b1de946d0b99d2620421",
    "role_gate": {
      "commitments_distinct": true,
      "relationships_declared_independent": false,
      "relationship_evidence_human_reviewed": true,
      "independence_cryptographically_proved": false
    },
    "pipeline": [
      {
        "step": "Commit",
        "owner": "Issuer",
        "artifact": "Answer-free challenge + hidden oracle commitment"
      },
      {
        "step": "Run",
        "owner": "Reproducer",
        "artifact": "Offline response + environment + methodology declarations"
      },
      {
        "step": "Review",
        "owner": "Reviewer",
        "artifact": "Relationship evidence + transcript/blinding review"
      },
      {
        "step": "Reveal",
        "owner": "Verifier",
        "artifact": "Recomputed receipt + in-toto byte binding + manifest"
      }
    ],
    "unlock_requirements": [
      "A producer commitment distinct from the issuer",
      "A reviewer commitment distinct from both parties",
      "No affiliate, contractor, same-organization, or unknown relationship",
      "Human review of relationship evidence, blinding, affordances, and transcript",
      "A pack whose oracle, receipt, statement, adjudication, and byte manifest recompute"
    ]
  },
  "federation": {
    "report_version": "aau-federated-defense-report/0.1",
    "pack_count": 1,
    "independently_reviewed_contribution_count": 0,
    "protocol_demonstration_count": 1,
    "minimum_cell_size": 3,
    "cells": [],
    "visible_gaps": [
      "No independently reviewed reproduction has been contributed yet."
    ],
    "claim_boundary": {
      "counts_evidence_not_organizations": true,
      "small_cells_suppressed": true,
      "no_names_or_role_commitments_published": true,
      "no_vendor_agency_or_model_ranking": true,
      "no_cross_challenge_universal_score": true,
      "not_field_effectiveness_or_certification": true
    },
    "report_sha256": "8d69a79c8c862cd18663550d6babcfbd9f9258808cc12515dacc2abe6b6a6ca1"
  },
  "routes": [
    {
      "title": "Prove the fix",
      "description": "Close the vulnerability while retaining the legitimate twin, service continuity, and rollback.",
      "href": "https://github.com/immu4989/awesome-agentic-usecases/tree/main/verified-fix-commons"
    },
    {
      "title": "Prove the stop",
      "description": "Measure parent, child, and queued-work containment, then gate restart on human evidence.",
      "href": "https://github.com/immu4989/awesome-agentic-usecases/tree/main/agent-containment-drills"
    },
    {
      "title": "Plan locally",
      "description": "Turn authorized inventory evidence into a continuity-aware vulnerability route without an upload.",
      "href": "https://github.com/immu4989/awesome-agentic-usecases/tree/main/essential-service-defender-box"
    },
    {
      "title": "Benchmark safely",
      "description": "Test bounded defensive reasoning across five families without invoking a live target or tool.",
      "href": "https://github.com/immu4989/awesome-agentic-usecases/tree/main/frontier-defense-benchmark"
    },
    {
      "title": "Exchange evidence",
      "description": "Publish hashes, evidence levels, measurements, and control fingerprints\u2014not sensitive raw logs.",
      "href": "https://github.com/immu4989/awesome-agentic-usecases/tree/main/cyber-defense-evidence-mesh"
    },
    {
      "title": "Measure honestly",
      "description": "Keep heterogeneous observations separate and show missing independent reproduction as a gap.",
      "href": "https://github.com/immu4989/awesome-agentic-usecases/tree/main/public-defense-outcomes-observatory"
    },
    {
      "title": "Reproduce blindly",
      "description": "Commit a hidden oracle, separate issuer/reproducer/reviewer roles, bind every byte, and suppress small public-result cells.",
      "href": "https://github.com/immu4989/awesome-agentic-usecases/tree/main/independent-reproduction-exchange"
    }
  ],
  "boundary": {
    "reference_results_only": true,
    "no_live_targets": true,
    "no_exploit_payloads": true,
    "zero_upload_workbench": true,
    "no_vendor_or_agency_ranking": true,
    "not_field_effectiveness_or_certification": true
  }
}
