Banana Navy
Back to the checklist FR
Lab · Threat modeling AI · Diagram view

20 checkpoints, as a diagram

The caller-to-action path as 20 numbered security layers, the threats of each layer placed on the links between layers, cross-linked with the catalogue of threats.

Checkpoints20 layers
Threat families5
Direct caller-to-LLM path0
FrameworkMITRE · OWASP

Every check is a numbered layer. Each layer carries its threats on the link that leaves it; every node and every threat links to the corresponding file in the catalogue.

How to read this view

Diagram of the 20 checkpoints Caller-to-action path shown as 20 numbered security layers; the threats of each layer sit on the link that leaves it. F1Caller ID spoo… F10robocalls, cal… F6injection SIP… F13toll fraud, tr… F3rejeu d'audio… F2flux audio syn… F11abus de silenc… F6manipulation d… F6perturbations… F16payloads inaud… F2clonage de voi… F3réponses préen… F4empreinte voca… F7mauvaise trans… F16transcription… F15ignore previou… F20tool hijacking F9extraction du… F17jailbreak F21fausse urgence… F13requête fraudu… F5impersonation… F14faux négatif… F18hallucination F9fuite de donné… F20agence excessi… F13mise à jour CR… F13fraude au paie… F9exfiltration d… F20abus de workfl… F21fausse urgence… F8logs altérés… F9violation de v… F12sondage lent… F18dérive du modè… F19modèle empoiso… F19dépendance vul… 01ENTRYCall Entry 02ENTRYSession Security 03ENTRYAudio Capture 04ENTRYVAD & Quality Gate 05ENTRYAudio Normalization 06AUDIO AUTHDeepfake Detection 07AUDIO AUTHLiveness Challenge 08AUDIO AUTHSpeaker Verification 09AUDIO AUTHSTT Transcription 10PROMPT & INTENTPrompt Injection Filter 11PROMPT & INTENTIntent Detection 12PROMPT & INTENTIdentity & Context Check 13PROMPT & INTENTRisk Scoring 14POLICY & TOOLINGLLM Interpretation 15POLICY & TOOLINGPolicy Engine 16POLICY & TOOLINGWorkflow Execution 17POLICY & TOOLINGHuman Escalation 18POLICY & TOOLINGAudit Logging 19SUPPLY CHAINMonitoring 20SUPPLY CHAINModel & Supply Chain
Numbered layers in reading order 01→20, from call entry to controlled action.Threat pills sit on the link that leaves each layer; click to open the threat file.Colours map to the 5 threat families of the catalogue.

See the full list view Back to the checklist ↗

Accessible version, layer by layer

  1. 01Call EntryENTRYMenacesF1Caller ID spoofingF10robocalls, call flooding, SIM farms, DDoS voix
  2. 02Session SecurityENTRYMenacesF6injection SIP, paquets malformésF13toll fraud, trunk non autorisé
  3. 03Audio CaptureENTRYMenacesF3rejeu d'audio, voix préenregistréeF2flux audio synthétique
  4. 04VAD & Quality GateENTRYMenacesF11abus de silence, bruit, injection de musique, brouillage
  5. 05Audio NormalizationENTRYMenacesF6manipulation de codec, payloads ultrasonoresF6perturbations adversesF16payloads inaudibles, sons synthétiques (vecteur indirect)
  6. 06Deepfake DetectionAUDIO AUTHMenacesF2clonage de voix, usurpation TTS, conversion, appels d'urgence synthétiques
  7. 07Liveness ChallengeAUDIO AUTHMenacesF3réponses préenregistrées, rejeu, messages clonés statiques
  8. 08Speaker VerificationAUDIO AUTHMenacesF4empreinte vocale clonée, fausse correspondance, échantillon volé
  9. 09STT TranscriptionAUDIO AUTHMenacesF7mauvaise transcription, confusion multilingue, phrases parlées adversesF16transcription piégée, phrases adverses (vecteur indirect)
  10. 10Prompt Injection FilterPROMPT & INTENTMenacesF15ignore previous instructionsF20tool hijackingF9extraction du prompt systèmeF17jailbreak
  11. 11Intent DetectionPROMPT & INTENTMenacesF21fausse urgence, ingénierie socialeF13requête frauduleuse, bypass de politique
  12. 12Identity & Context CheckPROMPT & INTENTMenacesF5impersonation, mauvais appariement, prise de compte
  13. 13Risk ScoringPROMPT & INTENTMenacesF14faux négatif, faux positif, signaux fragmentés
  14. 14LLM InterpretationPOLICY & TOOLINGMenacesF18hallucinationF9fuite de données, fuite du prompt systèmeF20agence excessive
  15. 15Policy EnginePOLICY & TOOLINGMenacesF13mise à jour CRM non autoriséeF13fraude au paiementF9exfiltration de données
  16. 16Workflow ExecutionPOLICY & TOOLINGMenacesF20abus de workflow, injection API, escalade de privilège
  17. 17Human EscalationPOLICY & TOOLINGMenacesF21fausse urgence, ingénierie sociale de l'opérateur, coercition
  18. 18Audit LoggingPOLICY & TOOLINGMenacesF8logs altérés, preuves manquantesF9violation de vie privée
  19. 19MonitoringSUPPLY CHAINMenacesF12sondage lent, dérive du modèle, campagne, dégradationF18dérive du modèle
  20. 20Model & Supply ChainSUPPLY CHAINMenacesF19modèle empoisonné, RAG empoisonnéF19dépendance vulnérable, paquet malveillant, détecteur obsolète

Threat modeling AI catalogue

MITRE ATLAS 2026.07 · OWASP GenAI · risk-voicebot