Chapter 04 · Part 1: The AI execution stack

Context Poisoning

Retrieved equals trusted is the default failure mode; poisoning attacks target the retrieval layer.

Scenario excerpt

Internal knowledge-base ingestion pulls malicious content; the assistant repeats attacker-chosen answers.

Frameworks: MITRE ATLAS · OWASP LLM Top 10 · NIST AI RMF

Layers: context-assembly

Related chapters

Public practitioner doctrine. Free doctrine. Open knowledge. Paid enforcement.