References
- Abbasi, Hammad, “Navigating AI Security: How Access Controls Can Make a Difference,” LinkedIn post, August 25, 2024. As of December 2, 2025: https://www.linkedin.com/pulse/navigating-ai-security-how-access-controls-can-make-hammad-abbasi-eufaf
- Adamski, Alexandre, “Overview of Intel SGX—Part 1, SGX Internals,” Quarkslab’s Blog, July 5, 2018. As of December 9, 2025: https://blog.quarkslab.com/overview-of-intel-sgx-part-1-sgx-internals.html
- Advanced Micro Devices, “AMD Secure Encrypted Virtualization (SEV),” webpage, undated. As of December 9, 2025: https://www.amd.com/en/developer/sev.html
- Adversarial Robustness Toolbox, homepage, undated. As of December 8, 2025: https://adversarial-robustness-toolbox.readthedocs.io/en/latest/
- Agdestein, Isabella, “AI with Human Oversight: Balancing Autonomy and Control,” Focalx, February 27, 2025. As of December 4, 2025: https://focalx.ai/ai/ai-with-human-oversight/
- Agent Development Kit, “Loop Agents,” webpage, undated. As of December 4, 2025: https://google.github.io/adk-docs/agents/workflow-agents/loop-agents/
- Agent Development Kit, “Workflow Agents,” webpage, undated. As of December 4, 2025: https://google.github.io/adk-docs/agents/workflow-agents/#why-use-workflow-agents
- Agrawal, Saharsh, “What Are Secure Enclaves?” OPAQUE Systems, February 15, 2022. As of December 9, 2025: https://www.opaque.co/resources/articles/what-are-secure-enclaves
- AI Fairness 360, homepage, undated. As of December 16, 2025: https://ai-fairness-360.org/
- AI Security Institute, “Inspect AI: An Open-Source Framework for Large Language Model Evaluations,” webpage, 2024. As of December 9, 2025: https://inspect.aisi.org.uk/
- AICert, homepage, undated. As of December 9, 2025: https://aicert.mithrilsecurity.io/en/latest/
- Akyash, Mohammad, and Hadi M. Kamali, “Evolutionary Large Language Models for Hardware Security: A Comparative Survey,” GLSVLSI ’24: Proceedings of the Great Lakes Symposium on VLSI 2024, Association for Computing Machinery, June 2024. As of December 9, 2025: https://dl.acm.org/doi/10.1145/3649476.3660390
- Allclair, Tim, “Secure Container Isolation: Problem Statement & Solution Space,” Google, February 12, 2018. As of December 4, 2025: https://docs.google.com/document/d/1QQ5u1RBDLXWvC8K3pscTtTRThsOeBSts_imYEoRyw8A/edit?pli=1&tab=t.0
- Alooba, “Data Origin Tracking: A Comprehensive Guide to Understanding and Implementing,” webpage, undated. As of December 5, 2025: https://www.alooba.com/skills/concepts/data-engineering-infrastructure/data-origin-tracking/
- Altair, “Altair® RapidMiner®,” webpage, undated. As of December 4, 2025: https://altair.com/altair-rapidminer
- Amazon Web Services, “Amazon API Gateway—API Management,” webpage, undated. As of December 4, 2025: https://aws.amazon.com/api-gateway/
- Amazon Web Services, “Amazon Bedrock Guardrails,” webpage, undated. As of December 8, 2025: https://aws.amazon.com/bedrock/guardrails/
- Amazon Web Services, “Amazon SageMaker,” webpage, undated. As of December 4, 2025: https://aws.amazon.com/sagemaker/
- Amazon Web Services, “Amazon Simple Queue Service,” webpage, undated. As of December 5, 2025: https://aws.amazon.com/sqs/?c=ai&sec=srvm
- Amazon Web Services, “AWS Identity and Access Management Documentation,” webpage, undated. As of December 2, 2025: https://docs.aws.amazon.com/iam/
- Amazon Web Services, “AWS Nitro Enclaves,” webpage, undated. As of December 9, 2025: https://aws.amazon.com/ec2/nitro/nitro-enclaves/
- Amazon Web Services, “AWS Secrets Manager,” webpage, undated. As of December 5, 2025: https://aws.amazon.com/secrets-manager/
- Amazon Web Services, “IAM Roles,” webpage, undated. As of December 4, 2025: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles.html
- Amazon Web Services, “What’s the Difference Between Kafka and RabbitMQ?” webpage, undated. As of December 5, 2025: https://aws.amazon.com/compare/the-difference-between-rabbitmq-and-kafka/
- Anaconda, “Anaconda Platform,” webpage, undated. As of December 4, 2025: https://www.anaconda.com/platform
- Ankor, Shuvy, “How to Implement RBAC with Permit.io,” Permit.io, January 4, 2023. As of December 2, 2025: https://www.permit.io/blog/rbac-with-permit
- Anthropic, “Frontier Model Security,” announcement, July 25, 2023. As of December 8, 2025: https://www.anthropic.com/news/frontier-model-security
- Anthropic, “Developing Nuclear Safeguards for AI Through Public‑Private Partnership,” August 21, 2025. As of December 16, 2025: https://red.anthropic.com/2025/nuclear-safeguards/
- AppArmor, homepage, undated. As of December 4, 2025: https://apparmor.net/
- Appknox, homepage, undated. As of December 8, 2025: https://www.appknox.com/
- Apple, “Secure Enclave,” webpage, December 19, 2024. As of December 9, 2025: https://support.apple.com/guide/security/secure-enclave-sec59b0b31ff/web
- Aqua Security, “Automate DevSecOps: CI/CD Security Without Compromise,” undated. As of December 8, 2025: https://www.aquasec.com/use-cases/devops-security/
- Arize, homepage, undated. As of December 8, 2025: https://arize.com/
- Arm Limited, “Confidential Compute Architecture,” webpage, undated. As of December 9, 2025: https://www.arm.com/architecture/security-features/arm-confidential-compute-architecture
- Arm Limited, “Security—Platform Security Architecture,” webpage, undated. As of December 9, 2025: https://developer.arm.com/documentation/101892/0100/Security---Platform-Security-Architecture
- Artificial Intelligence Security Center et al., “Deploying AI Systems Securely: Best Practices for Deploying Secure and Resilient AI Systems,” PP‑24‑1538, April 2024. As of December 9, 2025: https://media.defense.gov/2024/Apr/15/2003439257/-1/-1/0/CSI-DEPLOYING-AI-SYSTEMS-SECURELY.PDF
- Attila, Rácz‑Akácosi, “AI Agent Tool Use: Methods for Securely Restricting Function Calling,” AI Security Blog, AiQ AI Red Teaming, October 17, 2025. As of December 16, 2025: https://aiq.hu/en/ai-agent-tool-use-methods-for-securely-restricting-function-calling/
- Aublin, Pierre‑Louis, “Writing Secure Cloud Applications Using Intel SGX,” Large‑Scale Data & Systems Group, blog post, August 6, 2018. As of December 9, 2025: https://lsds.doc.ic.ac.uk/content/writing-secure-cloud-applications-using-intel-sgx
- Auth0, “Authorization for RAG,” webpage, undated. As of December 2, 2025: https://auth0.com/ai/docs/intro/authorization-for-rag
- Auth0, “Introduction to Identity and Access Management (IAM),” webpage, undated. As of December 4, 2025: https://auth0.com/docs/get-started/identity-fundamentals/identity-and-access-management
- Auth0, “JSON Web Tokens,” webpage, undated. As of December 4, 2025: https://auth0.com/docs/secure/tokens/json-web-tokens
- Auxiliobits, “Securing AI Agent Communications: Enterprise‑Grade Architecture Patterns,” webpage, undated. As of December 5, 2025: https://www.auxiliobits.com/blog/securing-ai-agent-communications-enterprise-grade-architecture-patterns/
- Avada Software, “The Ultimate Guide to Middleware Monitoring: Everything You Need to Know,” webpage, undated. As of December 8, 2025: https://avadasoftware.com/middleware-monitoring-guide/
- AWS—See Amazon Web Services.
- Bargury, Michael [mbrg], “Power‑pwn,” GitHub, last updated August 20, 2025. As of December 9, 2025: https://github.com/mbrg/power-pwn
- Barrett, Anthony M., Krystal Jackson, Evan R. Murphy, Nada Madkour, and Jessica Newman, Benchmark Early and Red Team Often: A Framework for Assessing and Managing Dual‑Use Hazards of AI Foundation Models, University of California, Berkeley, Center for Long‑Term Cybersecurity, May 2024. As of December 8, 2025: https://cltc.berkeley.edu/publication/benchmark-early-and-red-team-often-a-framework-for-assessing-and-managing-dual-use-hazards-of-ai-foundation-models/
- Bass, Daniel, “Attribute‑Based Access Control (ABAC) vs. Relationship‑Based Access Control (ReBAC),” Permit.io, October 3, 2023. As of December 2, 2025: https://www.permit.io/blog/abac-vs-rebac
- Carlini, Nicholas, Jamie Hayes, Milad Nasr, Matthew Jagielski, Vikash Sehwag, Florian Tramèr, Borja Balle, Daphne Ippolito, and Eric Wallace, “Extracting Training Data from Diffusion Models,” arXiv, arXiv:2301.13188, January 30, 2023. As of December 5, 2025: https://arxiv.org/abs/2301.13188
- Center for AI Safety, “An Overview of Catastrophic AI Risks,” undated. As of December 16, 2025: https://safe.ai/ai-risk
- Chan, Shih‑Han, “Encrypted Prompt: Securing LLM Applications Against Unauthorized Actions,” arXiv, arXiv:2503.23250, March 29, 2025. As of December 9, 2025: https://arxiv.org/abs/2503.23250
- Chaudhry, Hamza, and Landon Klein, Chemical & Biological Weapons and Artificial Intelligence: Problem Analysis and US Policy Recommendations, Future of Life Institute, February 27, 2024. As of December 16, 2025: https://futureoflife.org/wp-content/uploads/2024/02/FLI_AI_and_Chemical_Bio_Weapons.pdf
- Check Point, “CloudGuard: Cloud Security,” webpage, undated. As of December 8, 2025: https://www.checkpoint.com/cloudguard/
- Checkmarx, homepage, undated. As of December 8, 2025: https://checkmarx.com/
- Chen, Huili, Cheng Fu, Bita Darvish Rouhani, Jishen Zhao, and Farinaz Koushanfar, “DeepAttest: An End‑to‑End Attestation Framework for Deep Neural Networks,” ISCA ’19: Proceedings of the 46th International Symposium on Computer Architecture, Association for Computing Machinery, June 2019. As of December 9, 2025: https://dl.acm.org/doi/10.1145/3307650.3322251
- Cheng, Jikang, Ying Zhang, Zhongyuan Wang, Zou Qin, and Chen Li, “DePatch: Towards Robust Adversarial Patch for Evading Person Detectors in the Real World,” arXiv, arXiv:2408.06625, August 13, 2024. As of December 4, 2025: https://arxiv.org/abs/2408.06625
- Cleanlab, “Datasets,” webpage, undated. As of December 5, 2025: https://help.cleanlab.ai/studio/concepts/datasets/
- Cleanlab, “Trustworthy Language Model (TLM)—Quickstart,” webpage, undated. As of December 5, 2025: https://help.cleanlab.ai/tlm/tutorials/tlm/
- CleverHans Lab, “Cleverhans,” GitHub, last updated January 31, 2023. As of December 9, 2025: https://github.com/cleverhans-lab/cleverhans
- Cloud Security Alliance, “Secure Agentic System Design,” webpage, last updated August 7, 2025. As of December 8, 2025: https://cloudsecurityalliance.org/artifacts/secure-agentic-system-design
- Cloud Security Alliance, “Agentic AI Identity and Access Management: A New Approach,” webpage, August 18, 2025. As of December 8, 2025: https://cloudsecurityalliance.org/artifacts/agentic-ai-identity-and-access-management-a-new-approach
- Cloud Security Alliance, “AI Controls Matrix,” webpage, last updated October 30, 2025. As of December 8, 2025: https://cloudsecurityalliance.org/artifacts/ai-controls-matrix
- Cloudera, “Cloudera AI,” webpage, undated. As of December 4, 2025: https://www.cloudera.com/products/machine-learning.html
- Cloudflare, “What Is Access Control? Authorization vs Authentication,” webpage, undated. As of December 2, 2025: https://www.cloudflare.com/learning/access-management/what-is-access-control/
- Cloudflare, “What Is Mutual TLS (mTLS)?,” webpage, undated. As of December 4, 2025: https://www.cloudflare.com/learning/access-management/what-is-mutual-tls/
- CodeSandbox, “Find Machine Learning Examples and Templates,” webpage, undated. As of December 4, 2025: https://codesandbox.io/examples/package/machine-learning
- Confidential Computing Consortium, Confidential Computing: Hardware‑Based Trusted Execution for Applications and Data, version 1.3, November 2022.
- Containers, “Bubblewrap,” GitHub, last updated August 4, 2025. As of December 4, 2025: https://github.com/containers/bubblewrap
- Controllability, “Jailbreak‑Evaluation,” GitHub, last updated November 4, 2024. As of December 9, 2025: https://github.com/controllability/jailbreak-evaluation
- Coringrato, James, “Global Approaches to Artificial Intelligence Regulation,” Henry M. Jackson School of International Studies, University of Washington, July 10, 2025. As of December 9, 2025: https://jsis.washington.edu/news/global-approaches-to-artificial-intelligence-regulation/
- Cortegaca, Danny, Ana Malhotra, and Kareem Abdol‑Hamid, “Threat Modeling Your Generative AI Workload to Evaluate Security Risk,” AWS Security Blog, November 18, 2024. As of December 16, 2025: https://aws.amazon.com/blogs/security/threat-modeling-your-generative-ai-workload-to-evaluate-security-risk/
- CrowdStrike, “Accelerate Zero Trust with Unified Identity Protection,” webpage, undated. As of December 5, 2025: https://www.crowdstrike.com/en-us/platform/next-gen-identity-security/zero-trust/
- Cyberhaven, “Cyberhaven for Generative AI,” webpage, undated. As of December 8, 2025: https://www.cyberhaven.com/technologies/gen-ai
- Cybersecurity & Infrastructure Security Agency, “Secure by Design,” webpage, undated. As of December 8, 2025: https://www.cisa.gov/securebydesign
- Cybersecurity & Infrastructure Security Agency, AI Data Security: Best Practices for Securing Data Used to Train & Operate AI Systems, May 22, 2025. As of December 8, 2025: https://www.cisa.gov/resources-tools/resources/ai-data-security-best-practices-securing-data-used-train-operate-ai-systems
- CycloneDX, “Machine Learning Bill of Materials (ML‑BOM),” webpage, undated. As of December 5, 2025: https://cyclonedx.org/capabilities/mlbom/
- Databricks, “Lakehouse Monitoring,” webpage, undated. As of December 8, 2025: https://www.databricks.com/product/machine-learning/lakehouse-monitoring
- Databricks, “Generative AI Models Maintenance Policy,” webpage, last updated November 12, 2025. As of December 8, 2025: https://docs.databricks.com/aws/en/machine-learning/retired-models-policy
- Datadog, homepage, undated. As of December 8, 2025: https://www.datadoghq.com/
- DataRobot, homepage, undated. As of December 4, 2025: https://www.datarobot.com/
- Datasaur, “Sandbox,” webpage, last updated August 25, 2025. As of December 3, 2025: https://docs.datasaur.ai/llm-projects/sandbox
- de Dinechin, Christophe, “Learn About Confidential Computing Attestation,” Red Hat, September 7, 2023. As of December 9, 2025: https://www.redhat.com/en/blog/learn-about-confidential-computing-attestation
- DeepTeam, homepage, undated. As of December 9, 2025: https://www.trydeepteam.com/
- Deng, Xiyu, Quan Khanh Luu, Anh Van Ho, and Yorie Nakahira, “Context‑Aware LLM‑Based Safe Control Against Latent Risks,” arXiv, arXiv:2403.11863, May 6, 2025. As of December 9, 2025: https://arxiv.org/abs/2403.11863
- Dhanraj, Vijay, Harpreet Singh Chawla, Tao Zhang, Daniel Manila, Eric Thomas Schneider, Erica Fu, Mona Vij, Chia‑Che Tsai, and Donald E. Porter, “Adaptive and Efficient Dynamic Memory Management for Hardware Enclaves,” arXiv, arXiv:2504.16251, May 31, 2025. As of December 9, 2025: https://arxiv.org/abs/2504.16251
- Dialzara, “AI Model Monitoring vs. Maintenance: Key Differences,” December 2, 2024. As of December 8, 2025: https://dialzara.com/blog/ai-model-monitoring-vs-maintenance-key-differences
- Doherty, Roger, “Azure Sandbox,” Microsoft, undated. As of December 3, 2025: https://learn.microsoft.com/en-us/azure/architecture/guide/azure-sandbox/azure-sandbox
- Dolan‑Gavitt, Brendan [moyix], “GPT‑WPRE,” GitHub, last updated December 30, 2022. As of December 9, 2025: https://github.com/moyix/gpt-wpre
- Dreadnode, homepage, undated. As of December 9, 2025: https://dreadnode.io/
- Duddu, Vasisht, Anudeep Das, Nora Khayata, Hossein Yalame, Thomas Schneider, and N. Asokan, “Attesting Distributional Properties of Training Data for Machine Learning,” arXiv, arXiv:2308.09552, April 9, 2024. As of December 9, 2025: https://arxiv.org/abs/2308.09552
- Duddu, Vasisht, Oskari Järvinen, Lachlan J. Gunn, and N. Asokan, “ML Property Attestation Using TEEs,” poster presented at the IEEE Symposium on Security and Privacy 2024, May 20–22, 2024. As of December 9, 2025: https://sp2024.ieee-security.org/downloads/SP24-posters/sp24posters-final33.pdf
- Duy Huynh [vndee], “LLM Sandbox,” GitHub, last updated November 28, 2025. As of December 3, 2025: https://github.com/vndee/llm-sandbox
- EleutherAI, “LM‑Evaluation‑Harness,” GitHub, last updated December 9, 2025. As of December 9, 2025: https://github.com/EleutherAI/lm-evaluation-harness
- Eppel, Greg, Denis V. Batalov, and Mihir Patel, “Monitoring Generative AI Applications Using Amazon Bedrock and Amazon CloudWatch Integration,” AWS Cloud Operations Blog, Amazon Web Services, October 11, 2023. As of December 8, 2025: https://aws.amazon.com/blogs/mt/monitoring-generative-ai-applications-using-amazon-bedrock-and-amazon-cloudwatch-integration/
- Etzioni, Amitai, and Oren Etzioni, “Pros and Cons of Autonomous Weapons Systems,” Military Review, May–June 2017. As of December 4, 2025: https://www.armyupress.army.mil/Journals/Military-Review/English-Edition-Archives/May-June-2017/Pros-and-Cons-of-Autonomous-Weapons-Systems/
- European Commission, The General‑Purpose AI Code of Practice, updated December 10, 2025. As of December 14, 2025: https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai
- European Union, Artificial Intelligence Act, July 12, 2024. As of December 4, 2025: https://artificialintelligenceact.eu/
- European Union Agency for Cybersecurity, “Multilayer Framework for Good Cybersecurity Practices for AI,” webpage, June 2023. As of December 8, 2025: https://www.enisa.europa.eu/publications/multilayer-framework-for-good-cybersecurity-practices-for-ai
- Executive Office of the President, United States Government Policy for Oversight of Dual Use Research of Concern and Pathogens with Enhanced Pandemic Potential, May 2024. As of December 16, 2025: https://bidenwhitehouse.archives.gov/wp-content/uploads/2024/05/USG-Policy-for-Oversight-of-DURC-and-PEPP.pdf
- Executive Order 14110, “Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence,” Executive Office of the President, November 1, 2023. As of December 10, 2025: https://www.federalregister.gov/documents/2023/11/01/2023-24283/safe-secure-and-trustworthy-development-and-use-of-artificial-intelligence
- FairNow, homepage, undated. As of December 9, 2025: https://fairnow.ai/
- Fessi, Ahmed, “AI Agent Security—Why You Should Pay Attention,” Medium, September 2, 2025. As of December 16, 2025: https://medium.com/@AhmedF/ai-agent-security-why-you-should-pay-attention-d27733eb8c2a
- Firesmith, Donald, “System Resilience Part 6: Verification and Validation,” SEI Blog, Software Engineering Institute, Carnegie Mellon University, April 20, 2020. As of December 10, 2025: https://www.sei.cmu.edu/blog/system-resilience-part-6-verification-and-validation/
- Flatpak, “Flatpak,” GitHub, last updated December 4, 2025. As of December 4, 2025: https://github.com/flatpak/flatpak
- Flower Labs, homepage, undated. As of December 8, 2025: https://flower.ai/
- Fredrikson, Matt, Somesh Jha, and Thomas Ristenpart, “Model Inversion Attacks That Exploit Confidence Information and Basic Countermeasures,” CCS ’15: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, October 12, 2015. As of December 5, 2025: https://dl.acm.org/doi/10.1145/2810103.2813677
- Frontegg, “What Is Identity and Access Management (IAM)?,” December 4, 2023. As of December 2, 2025: https://frontegg.com/guides/identity-and-access-management
- Frontier Model Forum, “Foundational Security Practices,” issue brief, July 31, 2024. As of December 8, 2025: https://www.frontiermodelforum.org/updates/issue-brief-foundational-security-practices/
- Gallagher, Shannon, Austin Whisnant, Anton Hristozov, and Amit Vasudevan, Reviewing the Role of Machine Learning and Artificial Intelligence for Remote Attestation in 5G+ Networks, IEEE, October 2022. As of December 9, 2025: https://www.sei.cmu.edu/library/reviewing-the-role-of-machine-learning-and-artificial-intelligence-for-remote-attestation-in-5g-networks/
- Galtea, “Misuse Resilience,” webpage, undated. As of December 10, 2025: https://docs.galtea.ai/concepts/metric/misuse-resilience
- Garg, Rupesh, “What Is Resilience Testing? Tools, Techniques, and Real‑World Best Practices,” Frugal Testing, blog post, June 16, 2025. As of December 10, 2025: https://www.frugaltesting.com/blog/what-is-resilience-testing-tools-techniques-and-real-world-best-practices
- Garg, Sanjam, Aarushi Goel, Somesh Jha, Saeed Mahloujifar, Mohammad Mahmoody, Guru‑Vamsi Policharla, and Mingyuan Wang, “Experimenting with Zero‑Knowledge Proofs of Training,” CCS ’23: Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, Association for Computing Machinery, November 2023. As of December 9, 2025: https://dl.acm.org/doi/10.1145/3576915.3623202
- Gatling, homepage, undated. As of December 10, 2025: https://gatling.io/
- German Federal Office for Information Security, Generative AI Models: Opportunities and Risks for Industry and Authorities, 2025. As of December 16, 2025: https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/KI/Generative_AI_Models.pdf
- German Federal Office for Information Security, “Artificial Intelligence,” webpage, undated. As of December 16, 2025: https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Kuenstliche-Intelligenz/kuenstliche-intelligenz_node.html
- Global AI Governance Observatory, “AGILE Index 2026 by Country,” webpage, undated. As of December 16, 2025: https://agile-index.ai/
- Glynn, Fergal, “Gartner AI TRiSM Market Guide: Everything You Need to Know,” Mindgard, last updated August 20, 2025. As of December 9, 2025: https://mindgard.ai/blog/gartner-ai-trism-market-guide
- Glynn, Fergal, “What Is AI Red Teaming?,” Mindgard, last updated October 8, 2025. As of December 9, 2025: https://mindgard.ai/blog/what-is-ai-red-teaming
- Glynn, Fergal, “10 Best AI Security Tools for LLM and GenAI Application Protection (2025),” Mindgard, last updated December 9, 2025. As of December 9, 2025: https://mindgard.ai/blog/best-ai-security-tools-for-llm-and-genai
- Glynn, Fergal, “31 Best Tools for Red Teaming: Bolster Your Security with a Leading Red Teaming Solution (2025),” Mindgard, last updated December 9, 2025. As of December 10, 2025: https://mindgard.ai/blog/best-tools-for-red-teaming
- Goel, Megha, “Demystifying AI Agents: How They Work and Why Monitoring Them Is a Must,” UptimeRobot, last updated December 5, 2025. As of December 8, 2025: https://uptimerobot.com/knowledge-hub/monitoring/ai-agents-how-they-work/
- Google, “Google’s Secure AI Framework (SAIF),” webpage, undated. As of December 9, 2025: https://safety.google/safety/saif/
- Google Cloud, “Confidential Computing,” webpage, undated. As of December 9, 2025: https://cloud.google.com/security/products/confidential-computing?hl=en
- Google Cloud, “What Is Human‑in‑the‑Loop (HITL) in AI & ML?,” webpage, undated. As of December 4, 2025: https://cloud.google.com/discover/human-in-the-loop?hl=en
- Google Cloud, “GKE Sandbox,” webpage, last updated December 2, 2025. As of December 3, 2025: https://docs.cloud.google.com/kubernetes-engine/docs/concepts/sandbox-pods
- Google Cloud, “Roles and Permissions,” webpage, last updated December 2, 2025. As of December 2, 2025: https://cloud.google.com/iam/docs/roles-overview
- Google Cloud, “Introduction to Vertex AI Model Monitoring,” last updated December 5, 2025. As of December 8, 2025: https://docs.cloud.google.com/vertex-ai/docs/model-monitoring/overview
- Google for Developers, “Code Execution Isolation and Containment with Sandbox Solutions,” webpage, undated. As of December 4, 2025: https://developers.google.com/code-sandboxing
- Google for Developers, “What Is Sandbox2?,” last updated April 22, 2024. As of December 4, 2025: https://developers.google.com/code-sandboxing/sandbox2
- Google for Developers, “What Is Sandboxed API?,” last updated April 22, 2024. As of December 4, 2025: https://developers.google.com/code-sandboxing/sandboxed-api
- Google Git, “Minijail,” webpage, undated. As of December 4, 2025: https://android.googlesource.com/platform/external/minijail/
- Granica, homepage, undated. As of December 16, 2025: https://www.granica.ai/
- Gremlin, homepage, undated. As of December 10, 2025: https://www.gremlin.com/
- Grinbaum, Alexei, and Laurynas Adomaitis, “Dual Use Concerns of Generative AI and Large Language Models,” Journal of Responsible Innovation, Vol. 11, No. 1, 2024. As of December 9, 2025: https://www.tandfonline.com/doi/full/10.1080/23299460.2024.2304381
- Guardrails AI, homepage, undated. As of December 16, 2025: https://www.guardrailsai.com/
- gVisor, “Kubernetes Quick Start,” webpage, undated. As of December 3, 2025: https://gvisor.dev/docs/user_guide/quick_start/kubernetes/
- H2O.ai, “About Us,” webpage, undated. As of December 4, 2025: https://h2o.ai/company/
- HARPA AI Technologies, “How to Use ChatGPT Sandbox,” webpage, undated. As of December 3, 2025: https://harpa.ai/blog/how-to-use-chatgpt-sandbox-digital-playground
- HashiCorp, “Secure Applications Identities and Protect Sensitive Data,” webpage, undated. As of December 5, 2025: https://www.hashicorp.com/en/products/vault
- Hattoh, Gertrude, Jeremiah Ayensu, Nyarko Prince Ofori, Solomon Eshun, and Darlington Akogo, “Can Large Language Models Design Biological Weapons? Evaluating Moremi Bio,” arXiv, arXiv:2505.17154, May 22, 2025. As of December 16, 2025: https://arxiv.org/abs/2505.17154
- HazyResearch, “Meerkat,” GitHub, last updated February 25, 2024. As of December 9, 2025: https://github.com/HazyResearch/meerkat
- Hickey, Alan, “The GPT Dilemma: Foundation Models and the Shadow of Dual‑Use,” arXiv, arXiv:2407.20442, July 29, 2024. As of December 9, 2025: https://arxiv.org/abs/2407.20442
- Hillard, Ryan, Muhammad Qazafi, and Renato Ahiable, “4 Common IoT Protocols and Their Security Considerations,” AWS Public Sector Blog, Amazon Web Services, October 22, 2024. As of December 5, 2025: https://aws.amazon.com/blogs/publicsector/4-common-iot-protocols-and-their-security-considerations/
- Holistic AI, homepage, undated. As of December 8, 2025: https://www.holisticai.com/
- Hong, Zhang‑Wei, Idan Shenfeld, Tsun‑Hsuan Wang, Yung‑Sung Chuang, Aldo Pareja, James Glass, Akash Srivastava, and Pulkit Agrawal, “Curiosity‑Driven Red‑Teaming for Large Language Models,” arXiv, arXiv:2402.19464, February 29, 2024. As of December 9, 2025: https://arxiv.org/abs/2402.19464
- Hu, Vincent C., David Ferraiolo, Rick Kuhn, Adam Schnitzer, Kenneth Sandlin, Robert Miller, and Karen Scarfone, Guide to Attribute Based Access Control (ABAC) Definition and Considerations, National Institute of Standards and Technology, NIST 800‑162, January 2014. As of December 2, 2025: https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-162.pdf
- Huang, Ken, “Sandboxing as a Security Control in ML and LLMs,” LinkedIn post, September 15, 2024. As of December 4, 2025: https://www.linkedin.com/pulse/sandboxing-security-control-ml-llms-ken-huang-cissp-1qr1e
- Huang, Ken, “Agentic AI Threat Modeling Framework: MAESTRO,” Cloud Security Alliance blog post, February 6, 2025. As of December 9, 2025: https://cloudsecurityalliance.org/blog/2025/02/06/agentic-ai-threat-modeling-framework-maestro
- Hubinger, Evan, Carson Denison, Jesse Mu, Mike Lambert, Meg Tong, Monte MacDiarmid, Tamera Lanham, Daniel M. Ziegler, Tim Maxwell, Newton Cheng, et al., “Sleeper Agents: Training Deceptive LLMs That Persist Through Safety Training,” arXiv, arXiv:2401.05566, January 17, 2024. As of December 4, 2025: https://arxiv.org/abs/2401.05566
- Humanloop, “Agents,” webpage, undated. As of December 4, 2025: https://humanloop.com/docs/v5/explanation/agents
- Huynh, Daniel, and Jade Hardouin, “PoisonGPT: How We Hid a Lobotomized LLM on Hugging Face to Spread Fake News,” Mithril Security, July 9, 2023. As of December 4, 2025: https://blog.mithrilsecurity.io/poisongpt-how-we-hid-a-lobotomized-llm-on-hugging-face-to-spread-fake-news/
- IBM, “Artificial Intelligence (AI) Cybersecurity,” webpage, undated. As of December 8, 2025: https://www.ibm.com/solutions/ai-cybersecurity
- IBM, “IBM Observability,” webpage, undated. As of December 8, 2025: https://www.ibm.com/solutions/observability
- IBM, “IBM Verify Identity Governance,” webpage, undated. As of December 2, 2025: https://www.ibm.com/products/verify-identity-governance
- IBM, “IBM Watson Studio,” webpage, undated. As of December 4, 2025: https://www.ibm.com/products/watson-studio
- IBM, “Scale Trusted AI with Watsonx.governance,” webpage, undated. As of December 9, 2025: https://www.ibm.com/products/watsonx-governance
- IBM, “What Is IBM Secure Execution?,” webpage, last updated December 17, 2025. As of December 9, 2025: https://www.ibm.com/docs/en/linux-on-systems?topic=execution-introduction
- Ibrar, Werisha, Danish Mahmood, Ahmad Sami Al‑Shamayleh, Ghufran Ahmed, Salman Z. Alharthi, and Adnan Akhunzada, “Generative AI: A Double‑Edged Sword in the Cyber Threat Landscape,” Artificial Intelligence Review, Vol. 58, No. 9, 2025. As of December 9, 2025: https://link.springer.com/article/10.1007/s10462-025-11285-9
- InfluxData, “AI Monitoring,” webpage, undated. As of December 8, 2025: https://www.influxdata.com/glossary/ai-monitoring/
- Informatica, homepage, undated. As of December 5, 2025: https://www.informatica.com/
- Intel, “Intel® Trust Domain Extensions (Intel® TDX),” webpage, undated. As of December 9, 2025: https://www.intel.com/content/www/us/en/developer/tools/trust-domain-extensions/overview.html
- Intel, “Reduce the Attack Surface Around Your Data to Unlock New Opportunities,” webpage, undated. As of December 9, 2025: https://www.intel.com/content/www/us/en/products/docs/accelerator-engines/software-guard-extensions.html
- International Organization for Standardization, “ISO/IEC JTC 1/SC 42: Artificial Intelligence,” webpage, 2017. As of December 16, 2025: https://www.iso.org/committee/6794475.html
- International Organization for Standardization, Risk Management—Guidelines, ISO 31000:2018, 2018. As of December 8, 2025: https://www.iso.org/standard/65694.html
- International Organization for Standardization, Information Security, Cybersecurity and Privacy Protection—Information Security Management Systems—Requirements, ISO/IEC 27001, 2022. As of December 8, 2025: https://www.iso.org/standard/27001
- Irwin, John, and Kai Greshake, “How Code Execution Drives Key Risks in Agentic AI Systems,” NVIDIA Technical Blog, November 3, 2025. As of December 16, 2025: https://developer.nvidia.com/blog/how-code-execution-drives-key-risks-in-agentic-ai-systems/
- ISO—See International Organization for Standardization.
- Jepsen, homepage, undated. As of December 10, 2025: https://jepsen.io/
- Ji, Jessica, “What Does AI Red‑Teaming Actually Mean?,” Center for Security and Emerging Technology, Georgetown University, October 24, 2023. As of December 10, 2025: https://cset.georgetown.edu/article/what-does-ai-red-teaming-actually-mean/
- Jit, homepage, undated. As of December 8, 2025: https://www.jit.io/
- Ka, Adel [0x4D31], “Galah,” GitHub, last updated July 23, 2025. As of December 9, 2025: https://github.com/0x4D31/galah
- Kaggle, “Code,” webpage, undated. As of December 4, 2025: https://www.kaggle.com/code
- Kandakji, Oussama, and Ioan Catana, “Evaluate the Reliability of Retrieval Augmented Generation Applications Using Amazon Bedrock,” Artificial Intelligence blog, Amazon Web Services, June 20, 2024. As of December 5, 2025: https://aws.amazon.com/blogs/machine-learning/evaluate-the-reliability-of-retrieval-augmented-generation-applications-using-amazon-bedrock/
- Kansas State University, “[Hardware] Attacking Edge LLM (New),” webpage, undated. As of December 9, 2025: https://ece.k-state.edu/research/hardware-security/llm.html
- Katz, Eyal, “Top 10 CI/CD Security Tools,” Spectral, September 27, 2023. As of December 9, 2025: https://spectralops.io/blog/top-10-ci-cd-security-tools/
- Kosinski, Matthew, and Amber Forrest, “What Is a Prompt Injection Attack?,” IBM, undated. As of December 5, 2025: https://www.ibm.com/think/topics/prompt-injection
- Kumar, Vaibhav, “What Role Does Memory Play in the Performance of LLMs?,” Association of Data Scientists, July 10, 2024. As of December 5, 2025: https://adasci.org/what-role-does-memory-play-in-the-performance-of-llms/
- Kumar, Varun, “Evaluating and Mitigating Software Supply Chain Security Risks,” Practical DevSecOps, blog post, July 9, 2024. As of December 9, 2025: https://www.practical-devsecops.com/software-supply-chain-risks-to-evaluate-and-mitigate
- Kumar, Varun, “Software Supply Chain with Zero Trust,” Practical DevSecOps, blog post, July 10, 2024. As of December 9, 2025: https://www.practical-devsecops.com/software-supply-chain-security-with-zero-trust/
- Kumar, Varun, “7 Pillars to Strengthen Software Supply Chain Security,” Practical DevSecOps, blog post, August 11, 2024. As of December 9, 2025: https://www.practical-devsecops.com/strengthen-software-supply-security-7-pillars/
- Kumar, Varun, “Software Supply Chain Vulnerabilities in Large Language Models (LLMs),” Practical DevSecOps, blog post, August 11, 2024. As of December 9, 2025: https://www.practical-devsecops.com/software-supply-chain-vulnerabilities-llms/
- Kwiatkowski, Ivan [JusticeRage], “Gepetto,” GitHub, last updated December 4, 2025. As of December 9, 2025: https://github.com/JusticeRage/Gepetto
- Lacasse, Nicolas, “Open‑Sourcing gVisor, a Sandboxed Container Runtime,” Google Cloud, May 2, 2018. As of December 3, 2025: https://cloud.google.com/blog/products/identity-security/open-sourcing-gvisor-a-sandboxed-container-runtime
- LangChain, “Interrupts,” webpage, undated. As of December 4, 2025: https://docs.langchain.com/oss/python/langgraph/interrupts
- LangChain, “LangChain Reference,” webpage, undated. As of December 4, 2025: https://reference.langchain.com/python/langchain/
- LangChain, “Memory Overview,” webpage, undated. As of December 5, 2025: https://docs.langchain.com/oss/python/langgraph/memory
- Langfuse, homepage, undated. As of December 8, 2025: https://langfuse.com/
- Layton, Tina, “ChatGPT Playground: What It Is and How to Use It,” ChatGPT Global blog, April 23, 2025. As of December 16, 2025: https://chatgptglobal.net/blog/chatgpt-playground-what-it-is-and-how-to-use-it/
- Lee, Guanlin, “ART,” GitHub, last updated September 26, 2024. As of December 9, 2025: https://github.com/GuanlinLee/ART
- Lee, Sarah, “Verification in Digital Forensics,” Number Analytics blog, June 10, 2025. As of December 5, 2025: https://www.numberanalytics.com/blog/verification-in-digital-forensics
- Linux Kernel, “Protected Execution Facility,” webpage, undated. As of December 9, 2025: https://docs.kernel.org/arch/powerpc/ultravisor.html
- LitmusChaos, homepage, undated. As of December 10, 2025: https://litmuschaos.io/
- Liu, Lei, Xiaoyan Yang, Yue Shen, Binbin Hu, Zhiqiang Zhang, Jinjie Gu, and Guannan Zhang, “Think‑in‑Memory: Recalling and Post‑Thinking Enable LLMs with Long‑Term Memory,” arXiv, arXiv:2311.08719, November 15, 2023. As of December 9, 2025: https://arxiv.org/abs/2311.08719
- Livneh, Hananel, “Not All Sandboxes Are for Children: How to Secure Your SaaS Sandbox,” Cloud Security Alliance, February 22, 2023. As of December 4, 2025: https://cloudsecurityalliance.org/blog/2023/02/22/not-all-sandboxes-are-for-children-how-to-secure-your-saas-sandbox
- Lu, Sheng, Irina Bigoulaeva, Rachneet Sachdeva, Harish Tayyar Madabushi, and Iryna Gurevych, “Are Emergent Abilities in Large Language Models Just In‑Context Learning?,” arXiv, arXiv:2309.01809, July 15, 2024. As of December 9, 2025: https://arxiv.org/abs/2309.01809
- Lucas, Joseph, “Sandboxing Agentic AI Workflows with WebAssembly,” NVIDIA Developer, December 16, 2024. As of December 3, 2025: https://developer.nvidia.com/blog/sandboxing-agentic-ai-workflows-with-webassembly/
- Lucas, Matthew, “Resilience Testing with Toxiproxy,” Medium, July 8, 2022. As of December 10, 2025: https://notmattlucas.com/resilience-testing-with-toxiproxy-f24ce7b81dba
- Lumelsky, Avi, “OWASP Top 10 LLM, Updated 2025: Examples and Mitigation Strategies,” Oligo Security, January 6, 2025. As of December 9, 2025: https://www.oligo.security/academy/owasp-top-10-llm-updated-2025-examples-and-mitigation-strategies
- Lynch, Clifford A., “When Documents Deceive: Trust and Provenance as New Factors for Information Retrieval in a Tangled Web,” Journal of the American Society for Information Science and Technology, Vol. 52, No. 1, 2001.
- Lyzr, “AI Model Monitoring,” September 14, 2024. As of December 8, 2025: https://www.lyzr.ai/glossaries/ai-model-monitoring/
- Malik, Amir, “Code Sandboxes for LLMs and AI Agents,” Amir’s Blog, March 7, 2025. As of December 4, 2025: https://amirmalik.net/2025/03/07/code-sandboxes-for-llm-ai-agents
- Marchal, Nahema, Rachel Xu, Rasmi Elasmar, Iason Gabriel, Beth Goldberg, and William Isaac, “Generative AI Misuse: A Taxonomy of Tactics and Insights from Real‑World Data,” arXiv, arXiv:2406.13843, June 21, 2024. As of December 16, 2025: https://arxiv.org/abs/2406.13843
- Marshall, Andrew, Jugal Parikh, Emre Kiciman, and Ram Shankar Siva Kumar, Threat Modeling AI/ML Systems and Dependencies, Microsoft, November 2019. As of December 8, 2025: https://learn.microsoft.com/en-us/security/engineering/threat-modeling-aiml
- Martin, Manuel, “Model Deployment: Types, Strategies and Best Practices,” DagsHub, 2024. As of December 10, 2025: https://dagshub.com/blog/model-deployment-types-strategies-and-best-practices/
- Martineau, Kim, “What Is Red Teaming for Generative AI?,” IBM, blog post, April 11, 2024. As of December 9, 2025: https://research.ibm.com/blog/what-is-red-teaming-gen-AI
- Mascellino, Alessandro, “EmailGPT Exposed to Prompt Injection Attacks,” InfoSecurityMagazine, June 7, 2024. As of December 4, 2025: https://www.infosecurity-magazine.com/news/emailgpt-exposed-prompt-injection/
- Massed Compute, “How Does a Trusted Execution Environment (TEE) Differ from a Secure Enclave?,” undated. As of December 9, 2025: https://massedcompute.com/faq-answers/?question=How%20does%20a%20Trusted%20Execution%20Environment%20(TEE)%20differ%20from%20a%20Secure%20Enclave
- Mem0, homepage, undated. As of December 5, 2025: https://mem0.ai/
- Mend.io, homepage, undated. As of December 9, 2025: https://www.mend.io/
- Meng, Xiao‑Li, “Data Science and Engineering with Human in the Loop, Behind the Loop, and Above the Loop,” Harvard Data Science Review, Vol. 5, No. 2, Spring 2023. As of December 4, 2025: https://hdsr.mitpress.mit.edu/pub/812vijgg/release/3
- Meta, “Introducing Purple Llama for Safe and Responsible AI Development,” December 7, 2023. As of December 16, 2025: https://about.fb.com/news/2023/12/purple-llama-safe-responsible-ai-development/
- Microsoft, “Azure Key Vault,” webpage, undated. As of December 5, 2025: https://azure.microsoft.com/en-us/products/key-vault
- Microsoft, “Azure Machine Learning,” webpage, undated. As of December 4, 2025: https://azure.microsoft.com/en-us/products/machine-learning/
- Microsoft, “Azure OpenAI in Microsoft Foundry Model Deprecations and Retirements,” webpage, undated. As of December 5, 2025: https://learn.microsoft.com/en-us/azure/ai-foundry/openai/concepts/model-retirements?view=foundry-classic&tabs=text#retirement-and-deprecation-history
- Microsoft, “Azure RBAC Documentation,” webpage, undated. As of December 2, 2025: https://learn.microsoft.com/en-us/azure/role-based-access-control/
- Microsoft, “Create a New Network‑Secured Environment with User‑Managed Identity,” webpage, undated. As of December 5, 2025: https://learn.microsoft.com/en-us/azure/ai-foundry/agents/how-to/virtual-networks?view=foundry-classic
- Microsoft, “Expose REST API in API Management as an MCP Server,” webpage, undated. As of December 5, 2025: https://learn.microsoft.com/en-us/azure/api-management/export-rest-mcp-server
- Microsoft, “Microsoft AI Red Team,” webpage, undated. As of December 9, 2025: https://learn.microsoft.com/en-us/security/ai-red-team/
- Microsoft, “What Is Endpoint Detection and Response (EDR)?,” webpage, undated. As of December 8, 2025: https://www.microsoft.com/en-us/security/business/security-101/what-is-edr-endpoint-detection-response
- Microsoft, “What Is Managed Identities for Azure Resources?,” undated. As of December 4, 2025: https://learn.microsoft.com/en-us/entra/identity/managed-identities-azure-resources/overview
- Microsoft, “Security Planning for LLM‑Based Applications,” last updated April 29, 2025. As of December 9, 2025: https://learn.microsoft.com/en-us/ai/playbook/technology-guidance/generative-ai/mlops-in-openai/security/security-plan-llm-application
- Microsoft, “Azure Offerings,” last updated May 7, 2025. As of December 9, 2025: https://learn.microsoft.com/en-us/azure/confidential-computing/overview-azure-products
- Microsoft, “Secure AI,” last updated July 2, 2025. As of December 5, 2025: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/scenarios/ai/secure
- Microsoft, “Learn About Insider Risk Management,” last updated July 18, 2025. As of December 8, 2025: https://learn.microsoft.com/en-us/purview/insider-risk-management
- Microsoft, “Detect and Mitigate Potential Issues Using AIOps and Machine Learning in Azure Monitor,” last updated September 2, 2025. As of December 8, 2025: https://learn.microsoft.com/en-us/azure/azure-monitor/aiops/aiops-machine-learning
- Microsoft, “Retrieval‑Augmented Generation (RAG) Evaluators,” last updated November 18, 2025. As of December 5, 2025: https://learn.microsoft.com/en-us/azure/ai-foundry/concepts/evaluation-evaluators/rag-evaluators?view=foundry-classic
- Microsoft, “Azure OpenAI in Microsoft Foundry Model Deprecations and Retirements,” last updated November 21, 2025. As of December 8, 2025: https://learn.microsoft.com/en-us/azure/ai-foundry/openai/concepts/model-retirements?view=foundry-classic&tabs=text
- Microsoft, “Monitor Your Generative AI Applications (Preview),” last updated November 21, 2025. As of December 8, 2025: https://learn.microsoft.com/en-us/azure/ai-foundry/how-to/monitor-applications?view=foundry-classic
- Microsoft Azure, “Counterfit,” GitHub, last updated July 18, 2025. As of December 9, 2025: https://github.com/Azure/counterfit
- Microsoft Azure, “PyRIT,” GitHub, last updated December 9, 2025. As of December 9, 2025: https://github.com/Azure/PyRIT
- Mikulski, Bartosz, “Shadow Deployment vs. Canary Release of Machine Learning Models,” Qwak, February 10, 2022. As of December 10, 2025: https://www.qwak.com/post/shadow-deployment-vs-canary-release-of-machine-learning-models
- Miles, Justin, Liv d’Aliberti, and Joe Kovba, “Large Language Model Inference over Confidential Data Using AWS Nitro Enclaves,” HKU SPACE AI Hub, March 12, 2024. As of December 9, 2025: https://aihub.hkuspace.hku.hk/about/
- Millet, Raphaël, “AICert v1.0—Open‑Source AI Traceability Tool for Verifiable Training,” Mithril Security, September 30, 2024. As of December 9, 2025: https://blog.mithrilsecurity.io/aicert-open-source-tool-for-verifiable-training/
- Mindgard, homepage, undated. As of December 8, 2025: https://mindgard.ai/
- Mindgard, “Offensive Security Testing for Your AI,” webpage, undated. As of December 9, 2025: https://mindgard.ai/ai-security-platform
- Ministry of Japan, Group of 7, and European Union, Hiroshima Process International Guiding Principles for Organizations Developing Advanced AI System, 2023. As of December 16, 2025: https://www.mofa.go.jp/files/100573471.pdf
- Mithril Security, “AICert,” GitHub, last updated June 25, 2024. As of December 9, 2025: https://github.com/mithril-security/aicert
- MITRE Corporation, “MITRE ATLAS,” homepage, undated. As of December 8, 2025: https://atlas.mitre.org/
- MITRE Corporation, “LLM Prompt Injection,” MITRE ATLAS, last updated November 5, 2025. As of December 5, 2025: https://atlas.mitre.org/techniques/AML.T0051
- ModelOp, “AI Regulations & Standards,” webpage, undated. As of December 9, 2025: https://www.modelop.com/ai-governance/ai-regulations-standards
- ModelOp, “AI TRiSM Adoption,” webpage, undated. As of December 9, 2025: https://www.modelop.com/ai-governance/ai-regulations-standards/ai-trism-adoption
- ModelOp, “Attestation,” webpage, undated. As of December 16, 2025: https://www.modelop.com/ai-governance/glossary/attestation
- Mucci, Tim, “What Is Data Provenance?,” IBM, undated. As of December 5, 2025: https://www.ibm.com/think/topics/data-provenance
- Naghdi, Joseph, “Digital Document Forensics—How to Tell a Digital Document Is Genuine?,” Computer Forensics Lab—Digital Forensics Services, July 23, 2023. As of December 5, 2025: https://computerforensicslab.co.uk/digital-document-forensics-how-to-tell-a-digital-document-is-genuine/
- Narwal, “AI‑Driven Data Integrity: Ensuring Trust, Security, and Compliance,” Data Blog, March 14, 2025. As of December 5, 2025: https://narwal.ai/ai-driven-data-integrity-ensuring-trust-security-and-compliance/
- National Cyber Security Centre, United Kingdom, “Guidelines for Secure AI System Development,” webpage, November 27, 2023. As of December 9, 2025: https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development
- National Cyber Security Centre, United Kingdom, “Machine Learning Principles,” webpage, undated. As of December 8, 2025: https://www.ncsc.gov.uk/collection/machine-learning-principles/secure-design/raise-awareness
- National Cyber Security Centre, United Kingdom, “Risk Management,” webpage, undated. As of December 8, 2025: https://www.ncsc.gov.uk/collection/risk-management
- National Institute of Standards and Technology, “5 AI RMF Core,” webpage, NIST AI Resource Center, undated. As of December 8, 2025: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/
- National Institute of Standards and Technology, “AI Risk Management Framework,” webpage, undated. As of December 8, 2025: https://www.nist.gov/itl/ai-risk-management-framework
- National Institute of Standards and Technology, Security and Privacy Controls for Information Systems and Organizations, Special Publication 800‑53, revision 5, September 2020. As of December 16, 2025: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf
- National Institute of Standards and Technology, “Updated Guidelines for Managing Misuse Risk for Dual‑Use Foundation Models,” updated February 4, 2025. As of December 16, 2025: https://www.nist.gov/news-events/news/2025/01/updated-guidelines-managing-misuse-risk-dual-use-foundation-models
- National Nuclear Security Administration, “Artificial Intelligence for National Security,” webpage, undated. As of December 16, 2025: https://www.energy.gov/topics/artificial-intelligence-national-security
- National Security Agency et al., Guidelines for Secure AI System Development, 2023. As of December 8, 2025: https://media.defense.gov/2023/Nov/27/2003346994/-1/-1/0/GUIDELINES-FOR-SECURE-AI-SYSTEM-DEVELOPMENT.PDF
- NCSC—See National Cyber Security Centre.
- Netflix, “Chaos Monkey,” GitHub, undated. As of December 10, 2025: https://netflix.github.io/chaosmonkey/
- Netskope, “Securing AI,” webpage, undated. As of December 8, 2025: https://www.netskope.com/solutions/securing-ai
- Nevo, Sella, Dan Lahav, Ajay Karpur, Yogev Bar‑On, Henry Alexander Bradley, and Jeff Alstott, Securing AI Model Weights: Preventing Theft and Misuse of Frontier Models, RAND Corporation, RR‑A2849‑1, 2024. As of December 8, 2025: https://www.rand.org/pubs/research_reports/RRA2849-1.html
- New Relic, homepage, undated. As of December 8, 2025: https://newrelic.com/
- Newell, Glen, “How to Set Up Linux Chroot Jails,” Red Hat Blog, February 27, 2020. As of December 4, 2025: https://www.redhat.com/en/blog/set-linux-chroot-jails
- Nightfall, “Model Integrity Verification,” webpage, undated. As of December 5, 2025: https://www.nightfall.ai/ai-security-101/model-integrity-verification
- Nightfall, “Safeguard Sensitive Data Across the AI Stack,” webpage, undated. As of December 8, 2025: https://www.nightfall.ai/solutions/ai-data-governance
- NIST—See National Institute of Standards and Technology.
- NsJail, homepage, undated. As of December 5, 2025: https://nsjail.dev/
- NVIDIA, “NVIDIA Agent Intelligence Toolkit Memory Module,” webpage, undated. As of December 5, 2025: https://docs.nvidia.com/aiqtoolkit/latest/store-and-retrieve/memory.html
- NVIDIA, “Garak,” GitHub, last updated December 5, 2025. As of December 9, 2025: https://github.com/NVIDIA/garak
- NVIDIA Developer, “NVIDIA FLARE,” webpage, undated. As of December 8, 2025: https://developer.nvidia.com/flare
- nyariv, “SandboxJS,” GitHub, last updated May 9, 2025. As of December 4, 2025: https://github.com/nyariv/SandboxJS
- Obadiaru, Andrew, “LLM Data Leakage: 10 Best Practices for Securing Large Language Model,” Cobalt, April 25, 2025. As of December 5, 2025: https://www.cobalt.io/blog/llm-data-leakage-10-best-practices
- Okta, “Authentication vs. Authorization,” September 2, 2024. As of December 4, 2025: https://www.okta.com/identity-101/authentication-vs-authorization/
- Open Identity Platform, “Using Large Language Models (LLMs) in Access Management,” June 6, 2025. As of December 2, 2025: https://www.openidentityplatform.org/blog/2025-06-06-llm-in-access-management
- Open Web Application Security Project, “A01:2021—Broken Access Control,” OWASP Top 10, undated. As of December 2, 2025: https://owasp.org/Top10/A01_2021-Broken_Access_Control/
- Open Web Application Security Project, “AI Security and Privacy Guide,” undated. As of December 16, 2025: https://owasp.org/projects/spotlight/
- Open Web Application Security Project, “Authorization Cheat Sheet,” OWASP Cheat Sheets Series, undated. As of December 2, 2025: https://cheatsheetseries.owasp.org/cheatsheets/Authorization_Cheat_Sheet.html
- Open Web Application Security Project, “LLM01 Prompt Injection,” webpage, OWASP GenAI Security Project, undated. As of December 5, 2025: https://genai.owasp.org/llmrisk2023-24/llm01-24-prompt-injection/
- Open Web Application Security Project, “LLM02 Insecure Output Handling,” webpage, OWASP GenAI Security Project, undated. As of December 5, 2025: https://genai.owasp.org/llmrisk2023-24/llm02-insecure-output-handling/
- Open Web Application Security Project, “LLM03:2023—Inadequate Sandboxing,” webpage, undated. As of December 5, 2025: https://owasp.org/www-project-top-10-for-large-language-model-applications/Archive/0_1_vulns/Inadequate_Sandboxing.html
- Open Web Application Security Project, “LLM03 Training Data Poisoning,” webpage, OWASP GenAI Security Project, undated. As of December 5, 2025: https://genai.owasp.org/llmrisk2023-24/llm03-training-data-poisoning/
- Open Web Application Security Project, “LLM04 Model Denial of Service,” webpage, OWASP GenAI Security Project, undated. As of December 5, 2025: https://genai.owasp.org/llmrisk2023-24/llm04-model-denial-of-service/
- Open Web Application Security Project, “LLM05 Supply Chain Vulnerabilities,” webpage, OWASP GenAI Security Project, undated. As of December 5, 2025: https://genai.owasp.org/llmrisk2023-24/llm05-supply-chain-vulnerabilities/
- Open Web Application Security Project, “LLM06 Sensitive Information Disclosure,” webpage, OWASP GenAI Security Project, undated. As of December 5, 2025: https://genai.owasp.org/llmrisk2023-24/llm06-sensitive-information-disclosure/
- Open Web Application Security Project, “LLM07:2025 System Prompt Leakage,” webpage, OWASP GenAI Security Project, undated. As of December 5, 2025: https://genai.owasp.org/llmrisk/llm072025-system-prompt-leakage/
- Open Web Application Security Project, “LLM07 Insecure Plugin Design,” webpage, OWASP GenAI Security Project, undated. As of December 5, 2025: https://genai.owasp.org/llmrisk2023-24/llm07-insecure-plugin-design/
- Open Web Application Security Project, “LLM08 Excessive Agency,” webpage, OWASP GenAI Security Project, undated. As of December 5, 2025: https://genai.owasp.org/llmrisk2023-24/llm08-excessive-agency/
- Open Web Application Security Project, “LLM09 Overreliance,” webpage, OWASP GenAI Security Project, undated. As of December 5, 2025: https://genai.owasp.org/llmrisk2023-24/llm09-overreliance/
- Open Web Application Security Project, “LLM10 Model Theft,” webpage, OWASP GenAI Security Project, undated. As of December 5, 2025: https://genai.owasp.org/llmrisk2023-24/llm10-model-theft/
- Open Web Application Security Project, “ML01:2023 Input Manipulation Attack,” webpage, undated. As of December 5, 2025: https://owasp.org/www-project-machine-learning-security-top-10/docs/ML01_2023-Input_Manipulation_Attack.html
- Open Web Application Security Project, “ML02:2023 Data Poisoning Attack,” webpage, undated. As of December 5, 2025: https://owasp.org/www-project-machine-learning-security-top-10/docs/ML02_2023-Data_Poisoning_Attack.html
- Open Web Application Security Project, “ML03:2023 Model Inversion Attack,” webpage, undated. As of December 5, 2025: https://owasp.org/www-project-machine-learning-security-top-10/docs/ML03_2023-Model_Inversion_Attack.html
- Open Web Application Security Project, “ML04:2023 Membership Inference Attack,” webpage, undated. As of December 5, 2025: https://owasp.org/www-project-machine-learning-security-top-10/docs/ML04_2023-Membership_Inference_Attack.html
- Open Web Application Security Project, “ML05:2023 Model Theft,” webpage, undated. As of December 5, 2025: https://owasp.org/www-project-machine-learning-security-top-10/docs/ML05_2023-Model_Theft.html
- Open Web Application Security Project, “ML06:2023 ML Supply Chain Attacks,” webpage, undated. As of December 5, 2025: https://owasp.org/www-project-machine-learning-security-top-10/docs/ML06_2023-AI_Supply_Chain_Attacks.html
- Open Web Application Security Project, “ML07:2023 Transfer Learning Attack,” webpage, undated. As of December 5, 2025: https://owasp.org/www-project-machine-learning-security-top-10/docs/ML07_2023-Transfer_Learning_Attack.html
- Open Web Application Security Project, “ML08:2023 Model Skewing,” webpage, undated. As of December 5, 2025: https://owasp.org/www-project-machine-learning-security-top-10/docs/ML08_2023-Model_Skewing.html
- Open Web Application Security Project, “ML09:2023 Output Integrity Attack,” webpage, undated. As of December 5, 2025: https://owasp.org/www-project-machine-learning-security-top-10/docs/ML09_2023-Output_Integrity_Attack.html
- Open Web Application Security Project, “ML10:2023 Model Poisoning,” webpage, undated. As of December 5, 2025: https://owasp.org/www-project-machine-learning-security-top-10/docs/ML10_2023-Model_Poisoning.html
- Open Web Application Security Project, “OWASP Enterprise Security API (ESAPI),” webpage, undated. As of December 2, 2025: https://owasp.org/www-project-enterprise-security-api/
- Open Web Application Security Project, “Software Supply Chain Security,” webpage, OWASP Cheat Sheet Series, undated. As of December 16, 2025: https://cheatsheetseries.owasp.org/cheatsheets/Software_Supply_Chain_Security_Cheat_Sheet.html/
- Open Web Application Security Project, “API1:2023 Broken Object Level Authorization,” webpage, OWASP API Security Top 10, 2023. As of December 5, 2025: https://owasp.org/API-Security/editions/2023/en/0xa1-broken-object-level-authorization/
- Open Web Application Security Project, “Agentic AI—Threats and Mitigations: OWASP Top 10 for LLM Apps & Gen AI Agentic Security Initiative,” 2025. As of December 8, 2025: https://genai.owasp.org/resource/agentic-ai-threats-and-mitigations/
- Open Web Application Security Project, “LLM and Generative AI Security Solutions Landscape—Q1, 2025,” January 5, 2025. As of December 10, 2025: https://genai.owasp.org/resource/llm-and-generative-ai-security-solutions-landscape-q12025/
- Open Web Application Security Project, “Multi‑Agentic System Threat Modelling Guide: OWASP GenAI Security Project—Agentic Security Initiative, Version 1.0,” April 23, 2025. As of December 8, 2025: https://genai.owasp.org/resource/multi-agentic-system-threat-modeling-guide-v1-0/
- Open Web Application Security Project, “Securing Agentic Applications Guide,” version 1.0, July 28, 2025. As of December 16, 2025: https://genai.owasp.org/resource/securing-agentic-applications-guide-1-0/
- OpenAI, “Depreciations,” webpage, undated. As of December 8, 2025: https://platform.openai.com/docs/deprecations
- OPENVAS, homepage, undated. As of December 9, 2025: https://www.openvas.org/
- OperantAI, “Woodpecker,” GitHub, last updated December 5, 2025. As of December 9, 2025: https://github.com/OperantAI/woodpecker?tab=readme-ov-file
- Oracle, “Java Authentication and Authorization Service (JAAS) Reference Guide,” in Java Platform, Standard Edition: Security Developer’s Guide, Release 11, October 2025. As of December 2, 2025: https://docs.oracle.com/en/java/javase/11/security/java-authentication-and-authorization-service-jaas-reference-guide.html
- Organisation for Economic Co‑operation and Development, “AI Principles,” webpage, undated. As of December 8, 2025: https://www.oecd.org/en/topics/sub-issues/ai-principles.html
- Organisation for Economic Co‑operation and Development and Global Partnership on Artificial Intelligence, “Policies, Data and Analysis for Trustworthy Artificial Intelligence,” webpage, undated. As of December 16, 2025: https://oecd.ai/en/
- Oueslati, Amin, and Robin Staes‑Polet, Ahead of the Curve: Governing AI Agents Under the EU AI Act, The Future Society, June 2025. As of December 4, 2025: https://thefuturesociety.org/wp-content/uploads/2023/04/Report-Ahead-of-the-Curve-Governing-AI-Agents-Under-the-EU-AI-Act-4-June-2025.pdf
- OWASP—See Open Web Application Security Project.
- Packetlabs, “What Is the Definition of a Cryptographic Enclave?,” February 7, 2024. As of December 9, 2025: https://www.packetlabs.net/posts/what-is-a-cryptographic-enclave/
- Paddy SR, “Secure Your RAG: Where to Start?,” Axiomatics, March 24, 2025. As of December 2, 2025: https://axiomatics.com/blog/secure-your-rag-where-to-start
- Paktiti, Maria, “Securing AI Agents: A Guide to Authentication, Authorization, and Defense,” WorkOS, June 2, 2025. As of December 4, 2025: https://workos.com/blog/securing-ai-agents
- Palo Alto Networks, “AI Governance for AI‑Powered Applications,” March 26, 2025. As of December 16, 2025: https://www.paloaltonetworks.com/resources/whitepapers/ai-governance
- Panicker, Krishnapriya, “The Art of Software Survival: Resilience Testing,” Walmart Global Tech Blog, Medium, April 16, 2025. As of December 10, 2025: https://medium.com/walmartglobaltech/the-art-of-software-survival-resilience-testing-823be820531b
- Pasquier, Thomas F. J.‑M., Jatinder Singh, Jean Bacon, and David Eyers, “Information Flow Audit for PaaS Clouds,” 2016 IEEE International Conference on Cloud Engineering (IC2E), 2016. As of December 5, 2025: https://ieeexplore.ieee.org/document/7484162
- Pattern Recognition and Applications Lab and Pluribus One, “SecML: Secure and Explainable Machine Learning in Python,” version 0.15, 2021. As of December 10, 2025: https://secml.readthedocs.io/en/v0.15/
- Payong, Adrien, and Shaoni Mukherjee, “Building Autonomous Systems: A Guide to Agentic AI Workflows,” Digital Ocean, July 14, 2025. As of December 4, 2025: https://www.digitalocean.com/community/conceptual-articles/build-autonomous-systems-agentic-ai
- Peyrott, Sebastián, JWT Handbook, Auth0, 2018. As of December 4, 2025: https://auth0.com/resources/ebooks/jwt-handbook
- Pinecone, “Pinecone Vector Database—Pay As You Go Pricing,” Amazon product page, undated. As of December 5, 2025: https://aws.amazon.com/marketplace/pp/prodview-xhgyscinlz4jk
- PLSysSec, “Rlbox,” GitHub, last updated December 3, 2025. As of December 4, 2025: https://github.com/PLSysSec/rlbox
- Podman, homepage, undated. As of December 4, 2025: https://podman.io/
- Popa, Raluca Ada, “Secure Computation: Homomorphic Encryption or Hardware Enclaves?,” RISELab, University of California, Berkeley, October 1, 2021. As of December 9, 2025: https://rise.cs.berkeley.edu/blog/secure-computation-homomorphic-encryption-or-hardware-enclaves/
- PortSwigger, “What Do You Want to Do?,” webpage, undated. As of December 8, 2025: https://portswigger.net/burp
- Practical DevSecOps, Safeguarding Supply Chains in the Digital Era: Empower Your Organization to Forge Resilient and Secure Digital Supply Chains, 2024. As of December 16, 2025: https://www.practical-devsecops.com/wp-content/uploads/2024/06/eBook-Safeguarding-Software-Supply-Chains-in-the-Digital-Era.pdf
- Prasad, Varun, “AI Algorithm Audits: Key Control Considerations,” ISACA, August 2, 2024. As of December 9, 2025: https://www.isaca.org/resources/news-and-trends/industry-news/2024/ai-algorithm-audits-key-control-considerations
- Proofpoint, “What Is a Sandbox?,” webpage, undated. As of December 4, 2025: https://www.proofpoint.com/uk/threat-reference/sandbox
- Pulapaka, Hari, “Windows Sandbox,” Windows OS Platform Blog, Microsoft, December 18, 2018. As of December 4, 2025: https://techcommunity.microsoft.com/blog/windowsosplatform/windows-sandbox/301849
- Qdrant, “Security,” webpage, undated. As of December 5, 2025: https://qdrant.tech/documentation/guides/security/
- Qian, Hangkai, Bo Li, and Qichen Wang, “ClaimTrust: Propagation Trust Scoring for RAG Systems,” arXiv, arXiv:2503.10702, March 12, 2025. As of December 5, 2025: https://arxiv.org/abs/2503.10702
- Qlik, homepage, undated. As of December 5, 2025: https://www.talend.com/
- Rabin, Rafiqul, Jesse Hostetler, Sean McGregor, Brett Weir, and Nick Judd, “SandboxEval: Towards Securing Test Environment for Untrusted Code,” arXiv, arXiv:2504.00018, March 27, 2025. As of December 4, 2025: https://arxiv.org/abs/2504.00018
- Radharapu, Bhaktipriya, Kevin Robinson, Lora Aroyo, and Preethi Lahoti, “AART: AI‑Assisted Red‑Teaming with Diverse Data Generation for New LLM‑Powered Applications,” arXiv, arXiv:2311.08592, November 29, 2023. As of December 9, 2025: https://arxiv.org/abs/2311.08592
- Ravi, Divya, and Renuka Sindhgatta, “Exploring Trust and Transparency in Retrieval‑Augmented Generation for Domain Experts,” CHI EA '25: Proceedings of the Extended Abstracts of the CHI Conference on Human Factors in Computing Systems, April 25, 2025. As of December 5, 2025: https://dl.acm.org/doi/10.1145/3706599.3719985
- Red Hat, “Understanding Containers,” webpage, undated. As of December 4, 2025: https://www.redhat.com/en/topics/containers
- Red Hat, “What Does an API Gateway Do?,” January 8, 2019. As of December 4, 2025: https://www.redhat.com/en/topics/api/what-does-an-api-gateway-do
- Red Hat, “What Is SELinux (S ecurity‑Enhanced Linux)?,” August 30, 2019. As of December 4, 2025: https://www.redhat.com/en/topics/linux/what-is-selinux
- Red Hat, “What Is Identity and Access Management (IAM)?,” February 9, 2022. As of December 2, 2025: https://www.redhat.com/en/topics/security/what-identity-and-access-management-iam
- Red Hat, “What Are Sandboxed Containers?," April 11, 2023. As of December 4, 2025: https://www.redhat.com/en/topics/containers/sandboxed-containers
- Renzo, Chris, Liv d’Aliberti, Justin Miles, and Joe Kovba, “Large Language Model Inference over Confidential Data Using AWS Nitro Enclaves,” Artificial Intelligence blog, Amazon Web Services, March 12, 2024. As of December 9, 2025: https://aws.amazon.com/blogs/machine-learning/large-language-model-inference-over-confidential-data-using-aws-nitro-enclaves/
- RidgeRun.ai, “How to Evaluate Retrieval Augmented Generation (RAG) Systems,” Medium, November 14, 2024. As of December 5, 2025: https://ridgerunai.medium.com/how-to-evaluate-retrieval-augmented-generation-rag-systems-16ff8185d38f
- Roccia, Thomas [fr0gger], “IATelligence,” GitHub, last updated December 8, 2022. As of December 9, 2025: https://github.com/fr0gger/IATelligence
- Rose, Scott, Oliver Borchert, Stu Mitchell, and Sean Connelly, Zero Trust Architecture, NIST Special Publication 800‑207, National Institute of Standards and Technology, August 2020. As of December 5, 2025: https://nvlpubs.nist.gov/nistpubs/specialpublications/NIST.SP.800-207.pdf
- Roshan, Imran, “AI Assisted Red Teaming—an Efficient Approach,” Google Cloud, Medium, July 22, 2024. As of December 10, 2025: https://medium.com/google-cloud/ai-assisted-red-teaming-an-efficient-approach-68673dc33218
- RoX818, “Trust Issues? Rate Sources in RAG Workflows Right,” AICompetence.org, May 5, 2025. As of December 5, 2025: https://aicompetence.org/trust-issues-rate-sources-in-rag-workflows-right/
- Saade, Tiffany, “AI and Misuse,” Resilience, September 11, 2024. As of December 10, 2025: https://cyberresilience.com/threatonomics/ai-and-misuse/
- SafeLlama, “Plexiglass,” GitHub, last updated December 24, 2023. As of December 9, 2025: https://github.com/safellama/plexiglass
- Sahota, Harpreet, “Memory in LangChain: A Deep Dive into Persistent Context,” Comet, November 11, 2023. As of December 5, 2025: https://www.comet.com/site/blog/memory-in-langchain-a-deep-dive-into-persistent-context/
- Salesforce, “Salesforce Sandboxes,” webpage, undated. As of December 4, 2025: https://www.salesforce.com/platform/sandboxes-environments/
- Sancheti, Mahavir, “Deep Dive: Multi-Agent and Autonomous Chaining Risks—Part 3,” LinkedIn post, July 3, 2025. As of December 4, 2025: https://www.linkedin.com/pulse/deep-dive-multi-agent-autonomous-chaining-risks-part-sancheti-qqydc
- Sandia National Laboratories, “Artificial Intelligence at Sandia,” webpage, undated. As of December 16, 2025: https://www.sandia.gov/research/area/computing-information-science-and-mathematics/ai/
- Sathaye, Praseeda, and Vijay Chintalapati, “Getting Started with Istio on Amazon EKS,” AWS Open Source Blog, Amazon Web Services, December 5, 2023. As of December 10, 2025: https://aws.amazon.com/blogs/opensource/getting-started-with-istio-on-amazon-eks/
- Schnabl, Christoph, Daniel Hugenroth, Bill Marino, and Alastair R. Beresford, “Attestable Audits: Verifiable AI Safety Benchmarks Using Trusted Execution Environments,” arXiv, arXiv:2506.23706, June 30, 2025. As of December 9, 2025: https://arxiv.org/abs/2506.23706
- SepidehEb, “MLOps Gym—Beginners Guide to Monitoring,” Technical Blog, Databricks, July 15, 2024. As of December 8, 2025: https://community.databricks.com/t5/technical-blog/mlops-gym-beginners-guide-to-monitoring/ba-p/78803
- Shepardson, Victor, Gary McGraw, Harold Figueroa, and Richie Bonett, “A Taxonomy of ML Attacks,” MLsec Musings blog, May 2019. As of December 5, 2025: https://berryvilleiml.com/taxonomy/
- Sherman, Eli, Susannah Shattuck, Navrina Singh, and Ian Eisenberg, “From Assistant to Agent: Navigating the Governance Challenges of Increasingly Autonomous AI,” Credo.AI, April 29, 2025. As of December 4, 2025: https://www.credo.ai/recourseslongform/from-assistant-to-agent-navigating-the-governance-challenges-of-increasingly-autonomous-ai
- Shivaram, P. R., “How to Ensure Data Integrity: Strategies, Tools, and Best Practices,” Acceldata, November 19, 2024. As of December 5, 2025: https://www.acceldata.io/blog/how-to-ensure-data-integrity-strategies-tools-and-best-practices
- Singh, Rajni, “AI Defense 101: Protecting Your RAG-Based Systems from Threats,” GenusofTechnology, Medium, May 12, 2025. As of December 5, 2025: https://medium.com/genusoftechnology/ai-defense-101-protecting-your-rag-based-systems-from-threats-f5f60211c307
- Singhal, Ronit, Pransh Patwa, Parth Patwa, Aman Chadha, and Amitava Das, “Evidence-Backed Fact Checking Using RAG and Few-Shot In-Context Learning with LLMs,” arXiv, arXiv:2408.12060, October 4, 2024. As of December 5, 2025: https://arxiv.org/abs/2408.12060
- Sirota, Axel, “Securing Your RAG Application: A Comprehensive Guide,” Pluralsight, March 17, 2025. As of December 5, 2025: https://www.pluralsight.com/resources/blog/ai-and-data/how-to-secure-rag-applications-AI
- Smith, Travis, “A Guide to AI Red Teaming,” HiddenLayer, June 20, 2024. As of December 9, 2025: https://hiddenlayer.com/innovation-hub/a-guide-to-ai-red-teaming/
- SO Development, “Building Trust in LLM Answers: Highlighting Source Texts in PDFs,” Medium, May 29, 2025. As of December 5, 2025: https://sodevelopment.medium.com/building-trust-in-llm-answers-highlighting-source-texts-in-pdfs-0a9d26417353
- Soice, Emily H., Rafael Rocha, Kimberlee Cordova, Michael Specter, and Kevin M. Esvelt, “Can Large Language Models Democratize Access to Dual-Use Biotechnology?” arXiv, arXiv:2306.03809, June 6, 2023. As of December 9, 2025: https://arxiv.org/abs/2306.03809
- SonarSource, “SonarQube: Code Quality and Security,” webpage, undated. As of December 8, 2025: https://www.sonarsource.com/products/sonarqube/
- Spectral, homepage, undated. As of December 8, 2025: https://spectralops.io/
- Stryker, Cole, “What Is AI Agent Memory?” IBM, undated. As of December 5, 2025: https://www.ibm.com/think/topics/ai-agent-memory
- Suma, G., “ML Monitoring: Challenges and Best Practices for Production Environments,” Acceldata, February 20, 2025. As of December 8, 2025: https://www.acceldata.io/blog/ml-monitoring-challenges-and-best-practices-for-production-environments
- Swanda, Adam [deadbits], “Vigil-LLM,” GitHub, last updated January 31, 2024. As of December 10, 2025: https://github.com/deadbits/vigil-llm
- Symmetry Systems, “Symmetry Modern Data Security Platform,” webpage, undated. As of December 8, 2025: https://www.symmetry-systems.com/product/
- Takyar, Akash, “Monitoring ZBrain AI Agents: Significance, Key Metrics, Best Practices, Benefits and Future Trends,” ZBrain, undated. As of December 8, 2025: https://zbrain.ai/monitoring-zbrain-ai-agents/
- Tarunvoff, “Understanding and Mitigating Data Leakage in Large Language Models,” Medium, December 28, 2024. As of December 5, 2025: https://medium.com/@tarunvoff/understanding-and-mitigating-data-leakage-in-large-language-models-bf83e4ff89e7
- Tayouri, Bar-El, and Lisa Haas, “Best AI Red Teaming Tools: Top 7 Solutions in 2025,” Mend.io, July 16, 2025. As of December 10, 2025: https://www.mend.io/blog/best-ai-red-teaming-tools-top-7-solutions-in-2025/
- Tenable, “Tenable Nessus®,” webpage, undated. As of December 9, 2025: https://www.tenable.com/products/nessus
- Tenable, “Tenable One,” webpage, undated. As of December 16, 2025: https://www.tenable.com/products/tenable-one
- Tenable, “Ghidra_tools,” GitHub, last updated May 10, 2023. As of December 9, 2025: https://github.com/tenable/ghidra_tools
- Terry, Ryan, “Zero Trust Security Explained: Principles of the Zero Trust Model,” CrowdStrike, March 13, 2025. As of December 5, 2025: https://www.crowdstrike.com/en-us/cybersecurity-101/zero-trust-security/
- Tetrate, “Envoy AI Gateway V0.2: Enterprise Resilience and Security at Scale,” webpage, June 23, 2025. As of December 10, 2025: https://tetrate.io/blog/envoy-ai-gateway-v0-2-release
- TextAttack, homepage, University of Virginia QData Lab, undated. As of December 10, 2025: https://textattack.readthedocs.io/en/master/
- ThirdEye Data, “All About Emergent Behavior in Large Language Models,” webpage, undated. As of December 10, 2025: https://thirdeyedata.ai/llm/all-about-emergent-behavior-in-large-language-models/
- ThreatModeler, homepage, undated. As of December 10, 2025: https://threatmodeler.com/
- Treutlein, Johannes, Dami Choi, Jan Betley, Sam Marks, Cem Anil, Roger Grosse, and Owain Evans, “Connecting the Dots: LLMs Can Infer and Verbalize Latent Structure from Disparate Training Data,” Advances in Neural Information Processing Systems, Neural Information Processing Systems Foundation, Inc., Vol. 37, January 2024. As of December 9, 2025: https://www.researchgate.net/publication/397218319_Connecting_the_Dots_LLMs_can_Infer_and_Verbalize_Latent_Structure_from_Disparate_Training_Data
- Tricentis, “Resilience Testing: A Complete Guide for Testers,” webpage, undated. As of December 10, 2025: https://www.tricentis.com/learn/resilience-testing-complete-guide-for-testers
- Tricentis, “Tricentis NeoLoad: AI-Augmented Performance Testing,” webpage, undated. As of December 10, 2025: https://www.tricentis.com/products/performance-testing-neoload
- Turk, Matt, “Building a Reliable, Curated, and Accurate RAG System with Cleanlab and Pinecone,” Pinecone, October 25, 2024. As of December 5, 2025: https://www.pinecone.io/learn/building-reliable-curated-accurate-rag/
- United Nations Educational, Scientific and Cultural Organization, Recommendation on the Ethics of Artificial Intelligence, 2022. As of December 8, 2025: https://www.unesco.org/en/articles/recommendation-ethics-artificial-intelligence
- University of California, Berkeley, Responsible Use of Generative AI: A Playbook for Product Managers & Business Leaders, undated. As of December 8, 2025: https://re-ai.berkeley.edu/projects/responsible-use-generative-ai
- Urbina, Fabio, Filippa Lentzos, Cédric Invernizzi, and Sean Ekins, “Dual Use of Artificial-Intelligence-Powered Drug Discovery,” Nature Machine Intelligence, Vol. 4, March 2022. As of December 8, 2025: https://www.nature.com/articles/s42256-022-00465-9
- U.S. AI Safety Institute, Managing Misuse Risk for Dual-Use Foundation Models, NIST AI 800-1, National Institute of Standards and Technology, July 2024. As of December 8, 2025: https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.800-1.ipd.pdf
- Vaultody, homepage, undated. As of December 16, 2025: https://vaultody.com
- Vaultody, “Hardware Enclaves: The Ultimate Cybersecurity Shield for Data Protection,” February 5, 2025. As of December 9, 2025: https://vaultody.com/blog/250-hardware-enclaves-the-ultimate-cybersecurity-shield-for-data-protection
- VerifyWise, “Data Integrity for AI Systems,” webpage, undated. As of December 5, 2025: https://verifywise.ai/lexicon/data-integrity-for-ai-systems
- Verma, Ajay, “Memory Management in Large Language Models (LLMs): Challenges and Solutions,” Artificial Intelligence in Plain English, Medium, January 17, 2024. As of December 5, 2025: https://ai.plainenglish.io/memory-management-in-large-language-models-llms-challenges-and-solutions-a54439df39cd
- Weaviate, “Trust, Security, and Privacy Come First,” webpage, undated. As of December 5, 2025: https://weaviate.io/security
- WorkOS, “Connect,” webpage, undated. As of December 2, 2025: https://workos.com/docs/authkit/connect/concepts
- WorkOS, “Radar,” webpage, undated. As of December 8, 2025: https://workos.com/radar
- WorkOS, “Role-Based Access Control: Powerful and Flexible Permissions for Your Users,” webpage, undated. As of December 2, 2025: https://workos.com/fine-grained-authorization
- Yee, Bennet, David Sehr, Gregory Dardyk, J. Bradley Chen, Robert Muth, Tavis Ormandy, Shiki Okasaka, Neha Narula, and Nicholas Fullagar, “Native Client: A Sandbox for Portable, Untrusted x86 Native Code,” Communications of the ACM, Vol. 53, No. 1, January 2010. As of December 4, 2025: https://dl.acm.org/doi/pdf/10.1145/1629175.1629203
- Zep AI, homepage, undated. As of December 5, 2025: https://www.getzep.com/
- Zhang, Jinghong, Yidong Cui, Weilin Wang, and Xianyou Cheng, “TrustDataFilter: Leveraging Trusted Knowledge Base Data for More Effective Filtering of Unknown Information,” arXiv, arXiv:2502.15714, January 25, 2025. As of December 5, 2025: https://arxiv.org/abs/2502.15714
- Zhang, Zeyu, Quanyu Dai, Xiohe Bo, Chen Ma, Rui Li, Xu Chen, Jieming Zhu, Zhenhua Dong, and Ji-Rong Wen, “A Survey on the Memory Mechanism of Large Language Model-Based Agents,” ACM Transactions on Information Systems, Vol. 43, No. 6, September 2025. As of December 9, 2025: https://dl.acm.org/doi/10.1145/3748302
- Zhong, Wanjun, Lianghong Guo, Qiqi Gao, He Ye, and Yanlin Wang, “MemoryBank: Enhancing Large Language Models with Long-Term Memory,” Proceedings of the AAAI Conference on Artificial Intelligence, Vol. 38, No. 17, March 2024. As of December 9, 2025: https://ojs.aaai.org/index.php/AAAI/article/view/2994form6