Banana Navy
Catalog FR
Lab · Threat modeling IA · Fiche détaillée

Risk scoring failure (false negatives, fragmented signals)

the risk engine under-rates an attack (false negative), over-rates a legitimate call (false positive) or merges fragmented attack signals poorly, letting a malicious action through.

SheetF14
Categoryborne du moteur de risque (angle mort méthodologique)
Layers13 · Risk Scoring
Systemvoicebot IA

adversarial scoring tests (camouflaging an attack as benign signals), human-in-the-loop on edge cases, tracing of incoming signals.

The threat

the risk engine under-rates an attack (false negative), over-rates a legitimate call (false positive) or merges fragmented attack signals poorly, letting a malicious action through.

Angle mortWhy classic frameworks miss it

scoring is often treated as a reliable box; its failure (merge flaw, thresholds) is a silent elevation vector nobody tests adversarially.

MitigationProposed approach

adversarial scoring tests (camouflaging an attack as benign signals), human-in-the-loop on edge cases, tracing of incoming signals.

The proposed control
no sensitive action passed on score alone without signal tracing.

Expected evidence
a fragmented campaign does not pass the risk engine without an alert.

SourcesReferences and public research

Recherche publiquePublic research sources: MITRE ATLAS 2026.07 (verified technique mapping), OWASP GenAI (catégories par abus de modèle), and the public risk-voicebot (aivansoul/risk-voicebot) template defining the 20 checkpoints. No client registry data: generic sheet, no rating, no verdict.
couche 13 · Risk Scoring

Explore the 20 security layers

MITRE ATLAS 2026.07 · OWASP GenAI · risk-voicebot