implement blast-radius containment

Design, build, and validate controls and architectural patterns that limit the impact surface of failures, vulnerabilities, or misconfigurations to a bounded component or scope of a system. This work produces isolation boundaries, resource and rate limits, privilege restrictions, circuit breakers/automatic failover, and the instrumentation and automation needed to detect, enforce, and measure that containment.

implementblast-radiuscontainment

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
0.58
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$205K/year
Oct 01, 2026Oct 01, 2026

Recommended Survey Paper

Quick overview of the field
View more

This work addresses the current lack of a systematic understanding of the capabilities of AI sandboxes in ensuring safety, security, and regulatory compliance, particularly within physical AI and cyber-physical systems. It proposes the first unified, assurance-oriented framework for AI sandboxes, introducing a formal boundary definition, a comprehensive sandbox taxonomy, a threat model targeting the assurance mechanisms themselves, and a quantifiable evaluation methodology spanning six dimensions—including fidelity and controllability. Through formal modeling, threat analysis, and multi-case validation, the study clarifies what aspects of AI behavior can be effectively tested in sandboxes, which risk categories can be meaningfully controlled, and what forms of evidence such environments can generate to support safety and compliance claims, thereby establishing foundational tools for trustworthy AI verification.

AI sandboxassurancecyber-physical systems

Must-Read Papers

Most classic and influential ideas
View more

Enter, Exit, Page Fault, Leak: Testing Isolation Boundaries for Microarchitectural Leaks

Jul 08, 2025
OO
Oleksii Oleksenko
🏛️ Microsoft | ETH Zurich | MPI-SP

Microarchitectural side-channel attacks (e.g., Meltdown, Foreshadow) evade traditional CPU isolation mechanisms—such as virtualization and privilege-level enforcement—rendering existing software patches reactive, lagging, and insufficient for ensuring isolation integrity across security domains (VMs, kernel, processes). This paper introduces the first automated microarchitectural isolation boundary detection framework targeting multiple security domains. Our approach integrates model-driven relational testing, domain-specific sandboxed execution, fine-grained leakage modeling, and cross-domain uncertainty analysis. A key methodological advance is enabling precise inter-domain information-flow tracking under non-deterministic execution, coupled with high-accuracy leakage classification. Evaluated on six x86-64 processors, our framework discovers four previously unknown vulnerabilities, reproduces multiple known leaks, and achieves a mere 2% false-positive rate—significantly advancing processor security from reactive patching toward proactive, systematic verification.

Detecting cross-domain information leakage vulnerabilitiesTesting microarchitectural isolation flaws in CPUsValidating proactive security in processor design

To address the challenges of complex security control configuration, difficult policy enforcement, and delayed response in networked systems, this paper proposes a Security Capability Model (SCM). The SCM establishes, for the first time, a computable abstract framework integrating information and data models, formally specifying rule semantics, policy parsing mechanisms, and data representations for filtering- and channel-protection–based controls. Leveraging UML/SysML modeling, Model-Driven Engineering (MDE), and a multi-granularity security control description language, the approach enables automated policy refinement, cross-heterogeneous-device (e.g., firewalls, encrypted gateways) configuration generation, and event-driven response. Experimental evaluation demonstrates a threefold improvement in policy deployment timeliness and a 40% increase in configuration accuracy, thereby filling a critical gap in the formal foundations for automated security policy enforcement.

OptimizationSecurity ControlsThreat Response

Querying Attack-Fault-Defense Trees: Property Specification in Smart Grid and Aerospace Case Studies

Jun 30, 2025
RS
Reza Soltani
🏛️ University of Twente | Radboud University

Modeling the intricate interplay among security, safety, and defense in mission-critical systems (e.g., smart grids, aerospace) remains challenging, particularly due to difficulties in formalizing domain-specific analysis goals and eliciting expert knowledge intuitively. Method: This paper introduces AFDL—a unified formal logic integrating attack, fault, and defense behaviors—and LangAFDL, a domain-specific language built atop templated syntax to lower adoption barriers. AFDL supports Boolean and quantitative queries as well as minimal cut-set analysis; LangAFDL enables readable specification and automated verification of cross-domain safety properties. The approach synergizes attack-fault-defense tree semantics, DSL engineering, and logical reasoning. Results: Evaluated on two real-world case studies—GridShield and Ground Segment-as-a-Service (GSaaS)—AFDL and LangAFDL demonstrate expressive power and practical utility, establishing a scalable, automated theoretical and tooling foundation for collaborative safety analysis in mission-critical systems.

Automating safety-security analysis for mission-critical systems like smart gridsEnabling domain experts to specify complex analysis queries intuitivelyModeling safety-security-defense interactions in Attack-Fault-Defense Trees

Automated Reasoning for Vulnerability Management by Design

Jul 08, 2025
AS
Avi Shaked
🏛️ University of Oxford | IRIT | CNRS | UT2

Existing vulnerability management approaches lack systematic reasoning capabilities for the vulnerability posture during system design, hindering proactive security control design. This paper introduces the first automated vulnerability reasoning mechanism tailored for the design phase, leveraging formal modeling and automated reasoning to support end-to-end vulnerability identification, mitigation option generation, and security control specification. The mechanism is deeply integrated into an open-source security design tool and validated in real-world industrial settings: it accurately identifies applicable vulnerabilities and significantly improves both the accuracy and efficiency of security control design, thereby shifting vulnerability management from reactive response to design-driven assurance. Its core contribution lies in establishing verifiable, formal relationships among design artifacts, vulnerabilities, and security controls—addressing a critical gap in automation-enabled security left-shifting.

Automated identification of design-specific vulnerabilitiesFormal specification of mitigation controls for vulnerabilitiesSystematic reasoning about system vulnerability postures

Existing automated tool-calling systems often suffer from insufficient generalization due to model-centric designs and heavy reliance on prompting, leading to recurrent failures such as unsafe side effects, invalid parameters, uncontrolled retries, and sensitive data leakage. This work proposes a model-agnostic, policy-first framework for tool orchestration that enforces permission control prior to invocation, enhancing safety through explicit constraints, risk-aware gating, recovery mechanisms, and auditable explanations. Key contributions include a policy-first paradigm for tool workflows, a lightweight domain-specific language (DSL) for policies, a runtime execution engine, and a reproducible safety benchmark based on trajectory replay. In 225 controlled experiments, the strictest policy configuration achieved a violation prevention rate of 0.681, reduced retry amplification to 1.378, and attained a sensitive information leakage recall of 0.875, effectively quantifying the trade-off between safety and utility.

model-agnostic safetysensitive data leakagetool-using automation

Latest Papers

What's happening recently
View more

This study addresses the significant abstraction gap between security-by-design specifications—typically expressed in domain-specific languages (DSLs)—and code-level analyzers, which impedes the traceability of design intent to implementation vulnerabilities. It presents the first large-scale empirical investigation, examining 559 security checks across 36 analyzers and 66 security design DSLs. The authors introduce SecLan, a unified model that captures shared security concepts between these two layers, and validate its structure through expert evaluation involving 22 practitioners and qualitative interviews with 9 additional experts. The findings reveal a pronounced mismatch between security concepts at the design and implementation levels, with existing analyzer checks often relying on overly broad vulnerability descriptions, leading to ambiguous mappings. This work provides both an empirical foundation and a modeling framework to bridge the gap between security design and implementation.

abstraction gapcode analyzersdomain-specific languages

Hot Scholars

DM

Dimitrios M. Thilikos

National and Kapodistrian University of Athens
graph theorygraph algorithmsparameterized complexity
WM

Wanli Ma

University of Cambridge, Cardiff, Bristol
Computer VisionRemote SensingStructural Damage Assessment
RG

Ross Gruetzemacher

Wichita State University
AI StrategyAI RiskForesightCatastrophic Risk
SK

Stephan Kreutzer

Professor of Computer Science, Technical University Berlin
LogicGraph TheoryComplexity TheoryDatabase Theory
MH

Meike Hatzel

IBS DIMAG, Daejeon, Korea
directed graphsbutterfly minorsgraph structure theoryperfect matchings