Catalog
FR

Context summary · TB2 and TB3 boundaries

The privileged boundaries

Beyond the public TB7 boundary, two privileged boundaries concentrate the largest blast radius of the crisis voicebot: the support/admin operator (TB2) and the AI owner who steers prompts and configuration (TB3). Five threats, each with its justified risk position and required controls.

Threats
5 · 2 TB2 + 3 TB3
Scope
All deployments
Position
Initial (preliminary)
Source
Context-level risk assessment

Risk concentration

TB7 concentrates the highest attack likelihood; TB2 and TB3 concentrate the largest blast radius: one compromise can affect every deployment. The assessment therefore weighs exposure AND systemic scope, not likelihood alone.

Part 1 · TB2: support/admin operator ↔ chatbot

The operator who supervises and administers the crisis chatbots. A compromised privileged account hits not one zone, but every chatbot under its management.

TB2-ASupport/admin ↔ chatbot

Account spoofing / excessive privilege

A compromised operator account changes monitoring, suppresses alerts, accesses citizen data or causes incorrect escalation across multiple chatbots.

Exploit.
Medium
Position
Critical
Required next stepSTRIDE analysis of identity, role model, tenant scope, session management, auditability and emergency override
Why this position

Position critical. A compromised operator account hits every chatbot under its management: altered supervision, deleted alerts, exposed citizen data, distorted escalations. D4 (config compromise) feeding D1: the multi-deployment blast radius grounds the Critical position.

Exploit. medium. Medium because privileged access is required first. But operator accounts are a real, documented target (valid accounts, ATLAS AML.T0012): phishing or session reuse is enough, and the cited sheets, framed on the caller channel, do not cover the admin console.

Sources: AML.T0012 Valid Accounts · AML.T0053 AI Agent Tool Invocation

TB2-BSupport/admin ↔ chatbot

Administrative DoS / misconfiguration

Operator action or a compromised session disables service or creates overload across all managed instances.

Exploit.
Not rated
Position
Critical (D2)
Required next stepSeparation of duties, change control, emergency rollback and per-tenant blast-radius limits
Why this position

Position critical. Privileged insider DoS: an operator action or a compromised session disables the service or overloads every managed instance, a case the catalogue sheets (external DoS) do not cover directly. Simultaneous unavailability of asset A4 across all managed deployments is a full D2: Critical position.

Sources: AML.T0029 Denial of AI Service · AML.T0034 Cost Harvesting

Part 2 · TB3: AI owner ↔ prompts/config/rules

Who writes and evolves the bot's behaviour: system prompts, intent lists, scripts, model. Tampering here becomes systemic.

TB3-AAI owner ↔ prompts/config/rules

Prompt/config tampering

Compromised AI-owner access changes system prompts, intent allowlists, deterministic scripts or output format, creating systemic misinformation.

Exploit.
Medium
Position
Critical (D1)
Required next stepMFA, dual approval, signed/versioned configuration, testing gates and rapid rollback
Why this position

Position critical. One edit to prompts or scripts steers every future answer of every deployment: systemic disinformation (D1), invisible call by call. No card covers this privileged tampering directly; poisoning (F19) and hallucination (F18) are the closest mechanisms.

Exploit. medium. It requires an AI owner account, which caps the rating, but such high-privilege accounts are a real, documented target: phishing or stolen credentials are enough, no software exploit needed.

Sources: AML.T0060 Publish Hallucinated Entities · AML.T0020 Training Data Poisoning

TB3-BAI owner ↔ prompts/config/rules

Sensitive configuration disclosure

Prompts, rules, restrictions or credentials are exposed and used to optimize attacks or access connected systems.

Exploit.
Not rated
Position
High to Critical (D4)
Required next stepSeparate secrets from prompts, restrict export, monitor privileged access and rotate compromised credentials
Why this position

Position high to critical. Leaked prompts, rules or restrictions hand the attacker a map and tune his attacks (High); it turns Critical when exposed credentials open connected systems across every deployment (D4). Sheet F9 covers this case directly.

Sources: AML.T0085 Data from AI Services · AML.T0024 Exfiltration via AI Inference API · OWASP LLM07:2025 System Prompt Leakage

TB3-CAI owner ↔ prompts/config/rules

Supply-chain / model change

A hosted model or provider update changes behaviour without validated regression testing.

Exploit.
Not rated
Position
High to Critical
Required next stepPin versions where possible, maintain acceptance tests, monitor drift, approve provider/model changes
Why this position

Position high to critical. A vendor model change hits every deployment at once: without regression gates, the drift slips under alert thresholds and durably skews answers (D1), or degrades service (D2); High to Critical depending on scope.

Sources: OWASP LLM03:2025 Supply Chain · AML.T0029 Denial of AI Service

Doomsday legend

The four acceptance scenarios the risk positions refer to.

IDScenarioAssets affectedAcceptance position
D1Misinformation: the chatbot provides false, manipulated or unsafe information to citizens or emergency services, including incorrect evacuation or safety instructions.A1, A2, A6, A8Critical; not acceptable. TB7 may affect one zone; TB2/TB3 may affect all deployments.
D2Unavailability: the chatbot is blocked, overloaded or unavailable during an emergency and citizens cannot obtain information or provide emergency details.A4, A8, A9Critical; not acceptable when emergency functions are needed.
D3Sensitive-information exposure: citizen phone numbers, locations, condition, persons at risk, evacuation-point information or emergency-service data are disclosed or misused.A3, A7, A8Critical where personal safety, privacy or operational security is affected.
D4Credential / configuration disclosure or compromise: administrative credentials, system prompts, configuration or other sensitive control information is exposed or abused.A2, A5, A7High to critical; systemic if common configuration or multi-tenant administration is affected.

And the public boundary?

The TB7 boundary (citizen/attacker ↔ chatbot) has its dedicated STRIDE-AI analysis, twelve rated and justified threats.

See the TB7 analysis

AI Threat Modeling Catalog