DEFENSIVE PUBLICATION · ODA3 INSIGHTS

Attack-Vector-Specific Context Modifier Taxonomy with Per-Factor Capping for AI Incident Severity Scoring

ODA3 defensive publication establishing prior art for Attack-Vector-Specific Context Modifier Taxonomy with Per-Factor Capping for AI Incident Severity.

Editorial header for Attack-Vector-Specific Context Modifier Taxonomy with Per-Factor Capping for AI Incident Severity Scoring
CATEGORYDefensive Publication
EVIDENCE BASISPrimary public disclosure record
PUBLISHEDJune 17, 2026
READING TIME4 min

Defensive publication

Defensive Publication — Companion record to ODA3 IP Filing Doc #11

Document typeDefensive Publication (Prior Art Disclosure)
Author / OwnerODA3 Pvt Ltd (ODA3 Institute), Bihar, India
Related framework componentUAIF v1.0 — Context Modifiers, §4.3 (ODA3-2026-06-TCR-STD-002)
Canonical URLhttps://oda3.org/disclosures/context-modifier-taxonomy
https://www.tdcommons.org/dpubs_series/10506/
ContactCONTACT_AT_ODA3_DOT_ORG · https://oda3.org

Independent record notice This page is published on oda3.org as an independent, separately dated record of the disclosure below. The same disclosure text is also filed on Technical Disclosure Commons (tdcommons.org) as a companion defensive publication. Maintaining both records provides two independent, publicly verifiable timestamps for the same prior art.

ABSTRACT

A taxonomy of situational context modifiers, specific to AI-security attack vectors rather than generic deployment characteristics, for use in adjusting AI incident severity scores. Each context modifier represents a distinct, named AI-security attack pattern (model/training-data compromise, retrieval-augmented-generation data exfiltration, prompt-based instruction override, unauthorized agent/privilege escalation, broader multi-agent escalation risk, and generic adversarial input absent a specific identified vector), each assigned a fixed base value reflecting its relative severity contribution and a per-factor cap preventing any single context from contributing beyond a defined ceiling regardless of its base value. The taxonomy is designed for use with a diminishing-contribution aggregation function (disclosed separately) in which multiple co-occurring contexts are combined without unbounded additive escalation. Published to establish prior art.

TECHNICAL FIELD

Systems for representing and quantifying AI-security-specific attack-vector context as an input to AI incident severity scoring, as distinct from generic deployment-context factors (e.g., system criticality tier or population exposure) used in conventional incident scoring schemes.

BACKGROUND

Prior art severity-scoring context modifiers, where present, are typically generic deployment or environmental factors (criticality of the affected system, reversibility of harm, size of affected population, applicable regulatory regime) that apply broadly across IT incident types and are not specific to the mechanisms by which AI systems are actually attacked or fail. Such generic context taxonomies do not distinguish, for example, a prompt-injection-based instruction override from a training-data poisoning event, despite these representing materially different attack surfaces, detection methods, and remediation paths. There exists a need for a context-modifier taxonomy defined in terms of the attack vectors and failure modes specific to AI systems, with bounded per-factor influence so that the presence of a specific attack vector contributes a meaningful but capped amount to the overall severity determination.

DETAILED DESCRIPTION

1. Attack-Vector Context Taxonomy

The framework defines six named context types, each representing a specific AI-security attack pattern or failure mode, with an associated base value reflecting that context’s relative contribution to incident severity as established through expert elicitation: (a) a training-data/model-compromise context (covering backdoor injection and supply-chain compromise of the model itself), assigned the highest base value in the taxonomy; (b) a retrieval-augmented-generation data-exfiltration context, covering unauthorized extraction of data via retrieval mechanisms; (c) a prompt-based instruction-override context, covering direct injection and jailbreak-style manipulation of model instructions; (d) an unauthorized agent-control context, covering privilege escalation and unauthorized control of an autonomous agent; (e) a broader multi-agent escalation context, covering autonomous-action and multi-agent escalation risk not captured by the more specific agent-hijack context; and (f) a generic adversarial-input context, covering adversarial inputs that do not correspond to one of the more specific named vectors above, assigned the lowest base value in the taxonomy as a residual catch-all category.

2. Fixed Base Values with Independent Per-Factor Capping

Each context type in the taxonomy carries a fixed default base value, with the training-data/model-compromise context assigned a materially higher base value than the others, reflecting its outsized severity relative to the remaining five context types. Independently of its base value, each context is also subject to a per-factor cap applied at the point of aggregation, such that even the highest-base-value context cannot, on its own, exceed the defined per-factor ceiling — meaning the cap binds tightly on the highest-value context while leaving lower-value contexts’ base values largely unaffected by the cap. This two-part design (distinct base values reflecting relative severity, combined with a uniform per-factor ceiling) allows the taxonomy to express meaningful differentiation between attack-vector contexts while bounding any single context’s standalone influence on the aggregate score.

3. Designed Interoperation with Diminishing-Contribution Aggregation

The taxonomy is structured for use with an aggregation function (disclosed in a companion defensive publication directed to the severity scoring engine) in which multiple co-occurring context types are sorted by descending base value and combined such that each successive context contributes a geometrically diminishing fraction of its (already-capped) value, subject to a hard aggregate ceiling across all contexts combined. This disclosure covers the context taxonomy and its defining values and caps; the aggregation/diminishing-contribution computation itself is the subject of the companion severity-engine disclosure and is incorporated here by reference to establish the complete intended use of this taxonomy.

PRIOR ART COVERAGE

This disclosure covers: (1) a context-modifier taxonomy for AI incident severity scoring defined in terms of named, AI-security-specific attack vectors and failure modes (training-data/model compromise, RAG-based data exfiltration, prompt-based instruction override, unauthorized agent control, multi-agent escalation, and generic adversarial input) rather than generic deployment characteristics; (2) assignment of materially differentiated fixed base values across such attack-vector context types reflecting their relative severity contribution; (3) application of a per-factor cap at aggregation time that binds primarily on the highest-base-value context type while preserving differentiation among lower-value types; (4) use of such an attack-vector context taxonomy in combination with a diminishing-contribution aggregation function for multi-vector AI security incidents; (5) any AI incident classification system implementing any combination of the above.

PUBLICATION STATEMENT

Published by ODA3 Pvt Ltd (ODA3 Institute) on Technical Disclosure Commons (tdcommons.org) for prior art purposes. ODA3 Pvt Ltd asserts no patent rights in the methods described above and covenants not to assert any such rights against any party practicing these methods. This covenant is unconditional and is not contingent on certification, licensing, or conformance with any ODA3 Institute scheme. Separately, and without affecting the foregoing, UAIF® v1.0 and the certification scheme built upon it remain governed by the GAISSF Ecosystem Licence (GEL v1.0), under which ODA3 Institute is sole governing authority (GEL §10.5). ODA3 retains copyright in this disclosure. Bihar, India. June 2026. https://oda3.org

Publication date: June 17, 2026

Publisher: ODA3 Pvt Ltd (ODA3 Institute)

Jurisdiction of publication: India

Companion filing: Technical Disclosure Commons (tdcommons.org), Defensive Publications Series

Document reference: ODA3 IP Filing Doc #11

Framework context

This article supports operational interpretation across the GAISSF Ecosystem. Use GAISSF for governance and assurance context, UAIF for incident classification, and AI-IRF for incident-response architecture. These links describe relationships; they do not assert certification, regulatory approval, or legal compliance.

Tags

Defensive PublicationPrior ArtAI SecurityTechnical DisclosureODA3 Institute

Continue reading