{
  "id": 3267,
  "url": "https://arxiv.org/abs/2606.02822v1",
  "title": "Which Defense Closes Which Threat? Attributing OWASP-LLM-Top-10 Coverage and Its Brittleness Under Paraphrasing",
  "summary": "Production LLM applications stack several defense families -- refusal-phrase filters, token-budget controls, model allowlists, rate limits, tool-registry authentication -- yet existing breach-and-attack-simulation (BAS) benchmarks report a single aggregate coverage number, hiding which family closes which threat. We measure attribution. We add four OWASP-LLM-Top-10-aware agents to a 21-agent baseline scanner and target a lattice of four synthetic LLM endpoints: $L_0$ (no defenses), $L_1$ (refusa",
  "authors": "Alexandre Cristovão Maiorano",
  "category": "research",
  "topics": "military-security,agents-autonomy",
  "orgs": null,
  "regions": null,
  "published_at": "2026-06-01T19:39:25.000Z",
  "fetched_at": "2026-07-14T16:30:09.958Z",
  "source_slug": "arxiv-ethics",
  "source_name": "arXiv",
  "source_homepage": "https://arxiv.org",
  "ethics_ai_record_url": "https://ethics.ai/record/3267",
  "original_url": "https://arxiv.org/abs/2606.02822v1",
  "evidence_status": "source-only",
  "attribution": "via ethics.ai"
}