K05 assurance architecture
Model and data poisoning
Direct answer
Evaluate provenance checks, disagreement detection, drift thresholds, action suspension, and clean model/data restoration.
Evidence boundary. These records describe architecture, control relationships, test requirements, and legal-source status. They do not certify a facility, authorize a mission, prove deployment, or replace current facility-specific engineering and legal review.
Objective
Evaluate provenance checks, disagreement detection, drift thresholds, action suspension, and clean model/data restoration.
Abstract injected condition
controlled corruption of approved evaluation data or model metadata
Required observations
- protected-function state
- policy decision and confidence
- authority and configuration state
- timing and identity health
- incident chronology
- rollback or safe-state result
Pass evidence
high-consequence actions suspend before unsafe execution; provenance gap is recorded and restored
Safety envelope
- isolated range or approved hardware-in-the-loop environment
- no production plant or public-network target
- synthetic or authorized data and identities
- effects-disabled or non-damaging test substitutes
- independent stop authority
- complete artifact removal and reset evidence
Excluded public detail
- exploit or payload instructions
- credential theft procedure
- persistence or evasion recipe
- targeting or engagement thresholds
- weapon construction
- real-world unauthorized access