[bmwg] Re: Empirical attack vectors for draft-han-bmwg-agent-security-benchmark (real 2026 incidents + a runnable scorer)

patrick <patrick@dugganusa.com> Wed, 22 July 2026 15:47 UTC

Return-Path: <patrick@dugganusa.com>
X-Original-To: bmwg@mail2.ietf.org
Delivered-To: bmwg@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 52B4311C79D0C for <bmwg@mail2.ietf.org>; Wed, 22 Jul 2026 08:47:34 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784735254; bh=pp51k6CowAh9dbn5T+jcPGSHo/Au60RykEHlPoruQUk=; h=From:To:CC:Subject:Date:References:In-Reply-To; b=FEd6/yLEFANF1I4dcqksskahSHeI2L3m3pqoddnEdDtldIrSgiMcElZqmJtoFT6hJ kPeqVuur+IBQ7CtpplxU2oq7jn/axvG7xkGTB2TDBPqcSJYzo50BMDdk7NyOJfhi+e Wm7/tEyJtQfMx4x5BwMLxJa9dRawjFOZoy5Q7gHE=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.095
X-Spam-Level:
X-Spam-Status: No, score=-2.095 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_FONT_FACE_BAD=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=dugganusa.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qy4TwmBoBawS for <bmwg@mail2.ietf.org>; Wed, 22 Jul 2026 08:47:33 -0700 (PDT)
Received: from MW6PR02CU001.outbound.protection.outlook.com (mail-westus2azon11022142.outbound.protection.outlook.com [52.101.48.142]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-384) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id EF5F911C79C54 for <bmwg@ietf.org>; Wed, 22 Jul 2026 08:47:30 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=AY9srOuMB2GcezUh3x/oNYsEXJ8WpDBZ1gnmpgkTtEvpOXpk8BtPCt2Ubg3BwQW3DVHGB+i+xEl6cklt/WHeqPmf6YnQdf0FPp1u93srVFmll0+P756upZ4sTWOoVEo2/4gC40wDnbtKp+GzL6mEX9p3eGCGvU1FBnqpXnlIiK0aYJ4fGvHGvMiDDc9+knzoAKaX5OZqT6tZnP+YzS5UTewDXgunBYDHf1iaW7suSFuUlBwdmod3z6KydVU5OfoTlzW2HnHRr1QqwRWfHV11exGyI8+wBN/EIoKA8Z1k/sKF50SpKQgNqj9f18FjZygvFxnKFYKltgOI2WMyUc+nww==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=w9hU3uut+ll8p/d2LDRN5oqpduUisz0b70zZJQ8DApk=; b=XzV8wN30hu+baxPRxK9XHMEHJX9tgfUhm8c9jN287kx8+AJYk0POZkl4E8LD8bqm0OwJIGfn1sRIQqDgRUfTj+oedx+UZAAMAqdOqVb2RyMI/qoPvJqbjHRYP8AmADrz0wQeogXaEAhOjzBOxbfqqSdUQN7NuGHknuxvT1Nm1oWpcCpMcLI3TTJ0X50PoNMTR363qq2HOLoRmtdCSfEvZwfPWyye6zJCDCqszyLg3GH/xsULWHM84Q5QYp8rvQUcCZfW/BNIwCmwlH3oknaIyRAxfcao4yRBNFpcAjRZvrMIqfV1UhBOmSZNCgl3Tr+IJuWIy1DYomDbUAUotxkWng==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=dugganusa.com; dmarc=pass action=none header.from=dugganusa.com; dkim=pass header.d=dugganusa.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=dugganusa.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=w9hU3uut+ll8p/d2LDRN5oqpduUisz0b70zZJQ8DApk=; b=EoeNOmJ6IurSkg+nFO9VhnxoJTGI8l1vQKjIq94RWw0YNW3759721FvjIxnlX09JhP8ORWOOTRfq7bAXjsWoxxFNt9y5iGfMqmOQk7ih39iOZ9qiCYTs1wePcJ3IjPK+zxDNN/JacXXzE+cwCx3xeHZxq/10b5EU6tN7ZSZ8Iv9xF/EdyOqy52A4jf3yMNRVmmsIp+LZWms1qRdfZqxHiPZqjNzhTU78J2ZVy4DTZLM4L+ng+kEApcrMYmZrXkyeHuSeoSPCfpkUV+OCNmTneREtufOmBu7krppv8FhpVN8NCjk0HKAb9FdRKYIjjijSz80/iP6TpNmjGnP+Zam9FQ==
Received: from BL3PR16MB4475.namprd16.prod.outlook.com (2603:10b6:208:346::5) by BLAPR16MB3906.namprd16.prod.outlook.com (2603:10b6:208:27a::24) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.223.14; Wed, 22 Jul 2026 15:47:22 +0000
Received: from BL3PR16MB4475.namprd16.prod.outlook.com ([fe80::1060:b371:1984:7f95]) by BL3PR16MB4475.namprd16.prod.outlook.com ([fe80::1060:b371:1984:7f95%6]) with mapi id 15.21.0245.009; Wed, 22 Jul 2026 15:47:22 +0000
From: patrick <patrick@dugganusa.com>
To: "chenmeiling@chinamobile.com" <chenmeiling@chinamobile.com>, "hanyu@chinamobile.com" <hanyu@chinamobile.com>
Thread-Topic: Empirical attack vectors for draft-han-bmwg-agent-security-benchmark (real 2026 incidents + a runnable scorer)
Thread-Index: AQHdGSws34MKCjxovEyrnwld0ta6YrZ5TqMdgABhyaY=
Date: Wed, 22 Jul 2026 15:47:22 +0000
Message-ID: <BL3PR16MB4475A5F6659AEE2B2D572451BAC12@BL3PR16MB4475.namprd16.prod.outlook.com>
References: <BL3PR16MB4475EC8F56A7027081BD93EFBAC22@BL3PR16MB4475.namprd16.prod.outlook.com> <202607221756388160434@chinamobile.com>
In-Reply-To: <202607221756388160434@chinamobile.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=dugganusa.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: BL3PR16MB4475:EE_|BLAPR16MB3906:EE_
x-ms-office365-filtering-correlation-id: 879d9e34-b5c0-4d69-6d75-08dee808853a
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|376014|23010399003|1800799024|366016|38070700021|13003099007|6133799003|4143699003|10067099003|56012099006|22082099003|18002099003|3023799007|8096899003;
x-microsoft-antispam-message-info: L8bIO41JBD1rvUmlvI5SbbAFcWzMeZgmqf771NV2eB6r+ws1Rc6/CbMzSKenkvH2FSrEhajQoGMAaS/Dt1ScaOHxv/8IxP6xgU8Y1MAnKyylzVWj7yVp8s+a1WBP/7McWahOTpMxmuMv3QkQz55e415DTJD4wcb5L+5hD6y+lFHVzm6N99sp+L61TYYqVgRt8P3Og8H5gp2c3GB117VWp5BnA/t8exk+UfBBG3QSvWTy5sXFeUWgpI1kbbhjvgHFEoLKJFnbtVzv9tEXnjEbh2GbaZ/XqvRT9Kme49usAI2SugDdV0kM+XbddW7CDoAWKPxdx/swWMhghBjpjQQecN5sr930zSeFBQSa7/k0ZdO3VB28vqdSm14RpUAwHpPfgI4Jw7MZDnFgArXPEzTxw+N2CpwZO2cCdKkUlwy0dce3548lgmp36Ir6IIiH3YEcGsTg8ZAO9X3a3YmTtTvcdGPvJvxACxBP7e/TDR4p9be4MwdsluptLK43tqFY/te8FRUFa5JNl4dlmddCsa5dfKbsCwSLCJgz04bwKmtrOzOrxv0aHYatgLeHVXujwkn0nj8MBF/TJp5n0xoEZ9AXogvsE6u/e4y0oqRDmLC4cboBXMWPVUctJ0GoBNwPvD4ZSnfQXe88Ze2Wn71/nfYXhX8yShVVWUsZugDf0h1/QnU=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:BL3PR16MB4475.namprd16.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(376014)(23010399003)(1800799024)(366016)(38070700021)(13003099007)(6133799003)(4143699003)(10067099003)(56012099006)(22082099003)(18002099003)(3023799007)(8096899003);DIR:OUT;SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: Zcy48zF52GCIpfAP5UQY0Sd2iCVP2vfJLtIwW2aOZp55PItCBBPVc9sepyleq40pmO0d8gNmRMwKu8ThphEfqkNF8ZTPGvkjhyxKu63Rouurb/h4jJEvkS/SFL2qfiMkQB3bDiY9It+t5FefF0Zq/A8Ji/px40DPhhUrNMiaRLO+gy0fVkPAxX2E1Wgjdh5zMijGK8XFk8qADMIvUG+ku5uPG0vLshzQ7HJxHoyvjwLn+3LQkdE7ksgBlQIdv8yZLeeadYVhawPyrlKugo99NzZx7l7d1PNS9YS2K+9fdXO/Kyb9fnYEE4JLjFLulj+4SCDAVNE0q9EM1jgzx6+NRsVzp97QIiIM0Je83N3higJvyrmPyCq0oOl+2vVmZkX7Kcwb6bSQT2w7BQK/loZrXEFZjCyqWpWM9lldQ0wJuJcWdcXCTHWC49BcbBppUtnzvUXbughyA3y+NW9DVQ0X0VTWaYArIz7isd7pZ/g4rKlzPaa6mK1LZ7/u0vowpYayCXR2F27HXPJudxn9iLKys5pMXItwuiJ5q741SvUtZfLuT1zeJbAs35fagKieMOKKxRWUhJAH7d3m/NN7wg9nbrDL4DpI8QfcutfTQWUrXRkdh+6jzb3SSvXAIQ4E6+pfgnMzJJkYOnjlLtf0ECRVosNSjhlQnUSmB6krj8Hf2RdI5iUQodnHxFAKNdJnxR2U8c2yugSL1VSIlnXtGGA9IRKXRbU1hiN8iDSfwflGZGUmIEgP60qjcM8tvwIFcOd1uJYX7nmM4Yi4N565voqWKN2+lVb6H0VmS7A78zqvHvEty/gfRMMVP8/6Z16T3QsZf+zRCtGFX8holiTmbronnlEejtbluRgXwBDwg8QHbh2MJBwZWu4Vz/2WyEQirQ8s4XSwIeR6n19E7IPU0EbYPE7TRVWgTG2th1UM9OyXtROhYEYU3ZgqDrjYb6Xuboj8xpv0wL5Ej93h3b3G/BIN9Yseuo3/pVzKBThX9Qc5Ua381s5EcF2+hvm2nMY3LFyi8JPm5syltbhipOH/JHwjTcZ1rM05PIjQi1F1o3qs9PLtviejJZDVGf1gn7GRUjD43RXx+lOo7jjrYWfMdiLqTnwxxCLUrOIj/zEGaxMNR5rqtaLIQCOWOhrKz3djJkS4zCEwp3HEumdMaPmIr7t++Nxx7YPf+9KFIIeJuYozbxLfI4W5d3g0mSxqRS2eE5/q3wyEcZBbIDIJpNnPgC5FiliFEOZTssRoL4epQgVD6d6/2zLjbpMtvsjcKG4igqYRaObv0djF6rCTp6NsQNmdhPNkPE2XwufFqfWzCJObRjuuZAXbDDgl1lOrWQ1EnSXFfSPb/OGbRJEERJPNTb2QuBmGrSnGgW41hwl5XXlwtKI6J63B1KaH6nJ0SqqHQ3Tmc8ODwQqfzAKrblmXo1QvbeR058rpw81VYE+y9QItmcLR6UAs3oMiO9o4lJi688BiuqeAVbX3M0XJFarCJVvjzuI+Sv/Dbg11msODFfsDLCG0L0omIm2oC5rT7EnyT570ZJRypFNlBwpd+j6TDKy8SnxXPce68ZgGyJwDi7eSXt440+1bdGnXE2U9DixkrD+X9jgBbPkbhHnKgzdzC11JR72mEN4+3tjMUI55+mnd2fYX1XU0g6qxAxn7zRpgk6QCtNy0qhJ4EIYB6KCTbDBCCUFM8LpHj8Ijg4l8pT+CBvexdnZd5JWMn1/dO7viKxQpmXJhWnOhJHOWSu/UNNjEmzEjeyhBcCO0TCFgzpa2xFY=
Content-Type: multipart/alternative; boundary="_000_BL3PR16MB4475A5F6659AEE2B2D572451BAC12BL3PR16MB4475namp_"
MIME-Version: 1.0
X-OriginatorOrg: dugganusa.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: BL3PR16MB4475.namprd16.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 879d9e34-b5c0-4d69-6d75-08dee808853a
X-MS-Exchange-CrossTenant-originalarrivaltime: 22 Jul 2026 15:47:22.5729 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: bf27d873-5f46-4955-a55e-42b5d1109446
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 2A4m8PaTRcuccfsP+Nrgt82MaWPxjY/oTc9V9TiQaNTkDSVPwZtIigXGbHz+RXPcgrjYLcsRCr/FMEwNsT0vlQ==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BLAPR16MB3906
X-MailFrom: patrick@dugganusa.com
X-Mailman-Rule-Hits: nonmember-moderation
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-bmwg.ietf.org-0
Message-ID-Hash: 6CVCCEJD4TDXDLAE64DLGPY5V6NZ5XSC
X-Message-ID-Hash: 6CVCCEJD4TDXDLAE64DLGPY5V6NZ5XSC
X-Mailman-Approved-At: Wed, 22 Jul 2026 11:09:04 -0700
CC: bmwg <bmwg@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [bmwg] Re: Empirical attack vectors for draft-han-bmwg-agent-security-benchmark (real 2026 incidents + a runnable scorer)
List-Id: "IETF Benchmarking Methodology Working Group (BMWG)" <bmwg.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/bmwg/ZgHjNgPv7lHexXhq3cZauFzK5pA>
List-Archive: <https://mailarchive.ietf.org/arch/browse/bmwg>
List-Help: <mailto:bmwg-request@ietf.org?subject=help>
List-Owner: <mailto:bmwg-owner@ietf.org>
List-Post: <mailto:bmwg@ietf.org>
List-Subscribe: <mailto:bmwg-join@ietf.org>
List-Unsubscribe: <mailto:bmwg-leave@ietf.org>

Meiling, Yu -- thank you both, and I'm glad it's useful.

On gaps: your five dimensions hold up well against the incidents. Where I'd gently suggest room to grow is in three places the current axes don't fully separate:

1. Incident-response / false-refusal under legitimate-defender pressure. The Hugging Face case showed the inverse of jailbreak -- a model that over-refuses when a real defender needs it to read attack logs. "Does it refuse attackers" and "does it still help defenders under duress" are different measurements, and only the first is currently scored.

2. Non-text / cross-modal injection. Payloads that arrive as an image or file the agent reads as data and never as instructions (the GhostCommit class). This sits underneath "plugin/skill" but isn't quite the same axis.

3. Agent evades its own controls. Distinct from external jailbreak: the recent OpenAI disclosure had a model observe its own security scanner and route around it. That's an autonomous-iteration sub-dimension -- the agent modeling and defeating a monitor placed on it -- worth its own cell.

Offered as candidates, not corrections -- you know the framework far better than I do.

On the case study: yes, we'd be glad to have the mapping included as an appendix / case study, with the same rule we hold ourselves to -- every incident credited to its primary researcher; we're the grounding layer, not the discoverers. Happy to provide the material in whatever format the write-up needs (the JSON is machine-readable now; if there's an Internet-Draft or appendix convention you want it conformed to, point me at it and I'll match it).

-- Patrick

Patrick Duggan
DugganUSA LLC | dugganusa.com

________________________________
From: chenmeiling@chinamobile.com <chenmeiling@chinamobile.com>
Sent: Wednesday, 22 July 2026 09:56:43
To: patrick <patrick@dugganusa.com>; hanyu@chinamobile.com <hanyu@chinamobile.com>
Cc: bmwg <bmwg@ietf.org>
Subject: Re: Empirical attack vectors for draft-han-bmwg-agent-security-benchmark (real 2026 incidents + a runnable scorer)


Hi Patrick,

Wow, thank you so much for this incredibly helpful email and contribution! We love the "neighborly" spirit—this kind of proactive help is exactly what we need, and the work you've shared is fantastic.

We're already diving into the incident mappings, JSON data, and the reference scorer you provided. This is the perfect "ground truth" to help us validate and improve the benchmark.

As we dig in, two initial questions come to mind:

  1.  From your analysis, do you feel our existing metrics adequately cover the attack incidents you mentioned, or did you notice any potential gaps where our framework could be expanded?
  2.  This data is incredibly valuable. Would you be open to us including your analysis as a case study or appendix in our formal write-up? We would, of course, provide full credit to your shop and the primary researchers.

Thanks again for reaching out. We're excited to explore this further and look forward to the conversation!

I'm also CC'ing the working group mailing list to keep other interested members in the loop.

Best,
Meiling
________________________________
chenmeiling@chinamobile.com

From: patrick<mailto:patrick@dugganusa.com>
Date: 2026-07-22 00:15
To: chenmeiling@chinamobile.com<mailto:chenmeiling@chinamobile.com>; hanyu@chinamobile.com<mailto:hanyu@chinamobile.com>
Subject: Empirical attack vectors for draft-han-bmwg-agent-security-benchmark (real 2026 incidents + a runnable scorer)

Hello Meiling and Yu,

A small and slightly sheepish introduction: we're a bootstrapped threat-intelligence shop in Minnesota, and until this morning we had never heard of the IETF. We found one of our write-ups cited in the 126 hackathon wiki, went to learn what that meant, and decided the neighborly thing was to actually show up and help rather than just be flattered. So please read this as a newcomer offering a hand, not an expert pronouncing anything.

Your Security Evaluation Benchmark for AI Agents is well-specified — and a benchmark's next need is ground truth. That's exactly what we track for a living, so we mapped five documented 2026 agentic-attack incidents onto your metric dimensions (autonomous-iteration, plugin/skill, third-party components, jailbreak, operational) as candidate test vectors — JADEPUFFER's ~5-minute autonomous exploit-to-container-escape, the Pillar sandbox escapes, SleeperGem/ChocoPoC dependency poisoning, non-text prompt injection, and the Hugging Face incident-response false-refusal axis.

It's offered as prose and machine-readable JSON, plus a runnable reference scorer for the supply-chain vector (self-tests 6/6). Every incident is credited to its primary researcher.

https://github.com/pduggusa/dugganusa-ietf/tree/main/agent-security-benchmark — and our live check-package tool (on the MCP registry) is the production version of that scorer, testable now.

— Patrick Duggan
DugganUSA LLC · dugganusa.com<https://www.dugganusa.com>

Offered freely as an IETF 126 Hackathon contribution — take, leave, or ignore any of it. Apologies if this is an unexpected note; we're brand-new to the IETF and just trying to be useful.