Inputs
Manipulated observations
Evaluate how a defined perception model responds to altered sensor inputs. Lighting, viewpoint, normal variation and sensor faults belong in the baseline.

Adversarial threats
Untrusted inputs, compromised training data and malicious model changes introduce distinct attack paths. Our research focuses on evaluating those threats in the conditions where an AI system operates.
The work
Text instructions, camera inputs and training data require different evaluations. An anomaly is a reason to investigate; it does not by itself establish an attack.
Inputs
Evaluate how a defined perception model responds to altered sensor inputs. Lighting, viewpoint, normal variation and sensor faults belong in the baseline.
Data
Investigate training-data provenance, unexpected changes and controlled poisoning cases. Runtime input filtering cannot establish that a training set is trustworthy.
Agents
Study prompt injection in workloads that consume external text or tool results. Keep resource permissions and consequential approval independent of model output.

Controlled evaluation
A useful evaluation identifies the model, attacker access, input path and expected outcome. Test normal operation alongside attack cases so protection is assessed against both missed attacks and false alarms.
This is research and development. We do not claim universal adversarial detection, guaranteed protection against unknown attacks or sub-millisecond performance on edge devices.
What comes next
Evidence should establish both the security result and the constraints of the proposed control.
Coverage
Document the attacks, model versions and conditions covered. Include attacks adapted to the proposed protection rather than relying only on a fixed example set.
Performance
Assess detection delay, inference impact, memory and compute consumption on the intended device. Software adds operating costs even when no new hardware is required.
Response
Use security findings to inform investigation and independently authorized responses. Preserve the system owner's existing safety and operating mechanisms.