Research Note
Open Model Threat-Control Framework
Begin with one use case and record users, identities, data, retrieval, model artifact, system prompts, tools, external services, outputs, human decisions, logging, operat
Open Model Threat-Control Framework
System boundary
Begin with one use case and record users, identities, data, retrieval, model artifact, system prompts, tools, external services, outputs, human decisions, logging, operators, and downstream consumers.
Threat-control record
| Field | Required decision |
|---|---|
| Threat | Actor, precondition, path, affected asset, and plausible impact |
| Prevention | Least privilege, isolation, validation, policy, limits, and approval |
| Detection | Logs, signals, thresholds, reviewer, and alert path |
| Recovery | Disablement, rollback, revocation, containment, notification, and restoration |
| Evidence | Test, version, result, false-positive and false-negative behavior, and limitation |
| Ownership | Control owner, risk owner, responder, approver, and review date |
Layer rule
Model alignment and guard classifiers are controls inside a larger system. They cannot replace identity, authorization, data minimization, retrieval boundaries, tool permissions, output validation, human review, monitoring, incident response, or governance.
Completion rule
A control map is ready for accountable review when every material threat has prevention, detection, recovery, evidence, owners, residual risk, and a retest trigger. It is not a certification or a universal checklist.
Sources
Follow the evidence.
- ai.meta.com: the llama 3 herd of modelsai.meta.com
- ai-challenges.nist.gov: genaiai-challenges.nist.gov
- owasp.org: www project top 10 for large language model applicationsowasp.org
- youtu.be: 1KNOcY e9Tsyoutu.be
- github.com: PurpleLlamagithub.com
- crfm.stanford.edu: indexcrfm.stanford.edu
- NIST AI Risk Management Frameworknist.gov
- mlcommons.org: jailbreak 0 7mlcommons.org
- mlcommons.org: safety faqmlcommons.org
- github.com: MODEL CARDgithub.com
- ai-challenges.nist.gov: ariaai-challenges.nist.gov
- github.com: MODEL CARDgithub.com
- daltonanderson.ghost.io: metas llama 3 safety scaling and simple solutionsdaltonanderson.ghost.io
- ai.meta.com: meta llama 3 1 ai responsibilityai.meta.com
- NIST Generative AI Profilenvlpubs.nist.gov
- mlcommons.org: safety methodologymlcommons.org
- huggingface.co: concept guidehuggingface.co
- github.com: MODEL CARDgithub.com
- csrc.nist.gov: red teamingcsrc.nist.gov
- open.spotify.com: 44o5OPSumaZJcvRkXutorBopen.spotify.com