Research Note
Open Model Threat-Control Framework
Begin with one use case and record users, identities, data, retrieval, model artifact, system prompts, tools, external services, outputs, human decisions, logging, operat
In this article
Open Model Threat-Control Framework
System boundary
Begin with one use case and record users, identities, data, retrieval, model artifact, system prompts, tools, external services, outputs, human decisions, logging, operators, and downstream consumers.
Threat-control record
| Field | Required decision |
|---|---|
| Threat | Actor, precondition, path, affected asset, and plausible impact |
| Prevention | Least privilege, isolation, validation, policy, limits, and approval |
| Detection | Logs, signals, thresholds, reviewer, and alert path |
| Recovery | Disablement, rollback, revocation, containment, notification, and restoration |
| Evidence | Test, version, result, false-positive and false-negative behavior, and limitation |
| Ownership | Control owner, risk owner, responder, approver, and review date |
Layer rule
Model alignment and guard classifiers are controls inside a larger system. They cannot replace identity, authorization, data minimization, retrieval boundaries, tool permissions, output validation, human review, monitoring, incident response, or governance.
Completion rule
A control map is ready for accountable review when every material threat has prevention, detection, recovery, evidence, owners, residual risk, and a retest trigger. It is not a certification or a universal checklist.
Sources
Follow the evidence.
- ai-challenges.nist.gov: ariaai-challenges.nist.gov
- ai-challenges.nist.gov: genaiai-challenges.nist.gov
- ai.meta.com: meta llama 3 1 ai responsibilityai.meta.com
- ai.meta.com: the llama 3 herd of modelsai.meta.com
- crfm.stanford.edu: indexcrfm.stanford.edu
- csrc.nist.gov: red teamingcsrc.nist.gov
- daltonanderson.ghost.io: metas llama 3 safety scaling and simple solutionsdaltonanderson.ghost.io
- github.com: MODEL CARDgithub.com
- github.com: MODEL CARDgithub.com
- github.com: PurpleLlamagithub.com
- github.com: MODEL CARDgithub.com
- huggingface.co: concept guidehuggingface.co
- mlcommons.org: safety faqmlcommons.org
- mlcommons.org: jailbreak 0 7mlcommons.org
- mlcommons.org: safety methodologymlcommons.org
- NIST Generative AI Profilenvlpubs.nist.gov
- open.spotify.com: 44o5OPSumaZJcvRkXutorBopen.spotify.com
- owasp.org: www project top 10 for large language model applicationsowasp.org
- NIST AI Risk Management Frameworknist.gov
- youtu.be: 1KNOcY e9Tsyoutu.be