unified
UC-AI-18 — Defend AI interfaces against adversarial input, injection, and endpoint abuse
Protect the inference and agent interfaces of AI systems with layered input defenses: screen prompts, uploaded content, retrieved data, and tool results for prompt-injection and jailbreak patterns before they reach the model or trigger actions; detect and alert on adversarial-input campaigns; and rate-limit, authenticate, and monitor endpoints to prevent scraping, model extraction, and resource-exhaustion abuse. Tune detections from evaluation findings and retain filter configurations and detection logs as evidence.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- AI Governance
- type
- preventive
- category
- technical
Details
- unified_id
- UC-AI-18
- title
- Defend AI interfaces against adversarial input, injection, and endpoint abuse
- statement
- Protect the inference and agent interfaces of AI systems with layered input defenses: screen prompts, uploaded content, retrieved data, and tool results for prompt-injection and jailbreak patterns before they reach the model or trigger actions; detect and alert on adversarial-input campaigns; and rate-limit, authenticate, and monitor endpoints to prevent scraping, model extraction, and resource-exhaustion abuse. Tune detections from evaluation findings and retain filter configurations and detection logs as evidence.
- domain
- AI Governance
- control_type
- preventive
- control_category
- technical
- members
- framework
- aiuc-1
- control_id
- B002
- coverage
- full
- relationship
- superset_of
- framework
- aiuc-1
- control_id
- B004
- coverage
- full
- relationship
- superset_of
- framework
- aiuc-1
- control_id
- B005
- coverage
- full
- relationship
- superset_of
- guidance
- source
- nist-ai-agent-identity
- sourceTitle
- NIST NCCoE: Software and AI Agent Identity and Authorization
- propositionId
- NIST-AGI-06
- propositionTitle
- Prompt-injection prevention and limits on resulting harm
- sourcePages
- Concept paper p. 4: Prompt Injection prevention and mitigation
- source
- nist-ai-tevv-athlon
- sourceTitle
- NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems
- propositionId
- NIST-TEVV-05
- propositionTitle
- Test direct and indirect prompt injection
- sourcePages
- NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Integrity attacks
Source
No record-specific source URL is provided.
Connections
- UC-AI-18 — Defend AI interfaces against adversarial input, injection, and endpoint abuse mitigates Adversarial attacks, data poisoning and prompt injection
- strength
- primary
- rationale
- Screening prompts, retrieved content, and tool results for injection and jailbreak patterns, plus adversarial-input detection, is the inference-time defense against prompt injection.
- UC-AI-18 — Defend AI interfaces against adversarial input, injection, and endpoint abuse informed_by NIST-AGI-06 — Prompt-injection prevention and limits on resulting harm
- framework
- nist-ai-agent-identity
- control_id
- NIST-AGI-06
- coverage
- guidance
- relationship
- informs
- delta
- Not provided
- source_version
- February 2026 draft concept paper
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- sourcePages
- Concept paper p. 4: Prompt Injection prevention and mitigation
- UC-AI-18 — Defend AI interfaces against adversarial input, injection, and endpoint abuse mitigates Credential and secret leakage through AI inputs, outputs, logs and generated code
- strength
- related
- rationale
- Input screening is where pasted credentials can be caught before they reach the model or its logs.
- Quarterly Third-Party AI Evaluation Cycle tests UC-AI-18 — Defend AI interfaces against adversarial input, injection, and endpoint abuse
- UC-AI-18 — Defend AI interfaces against adversarial input, injection, and endpoint abuse maps_to B005 — Implement real-time input filtering
- framework
- aiuc-1
- control_id
- B005
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- July 15, 2026 release (quarterly update cadence)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AI-18 — Defend AI interfaces against adversarial input, injection, and endpoint abuse mitigates AI endpoint abuse, scraping and model extraction
- strength
- primary
- rationale
- Rate limiting, authentication, and monitoring of inference endpoints directly stop scraping, extraction, and unbounded-consumption abuse.
- UC-AI-18 — Defend AI interfaces against adversarial input, injection, and endpoint abuse mitigates AI privacy leakage and re-identification
- strength
- related
- rationale
- Blocking injected instructions that try to exfiltrate context reduces one avenue for personal-data leakage.
- UC-AI-18 — Defend AI interfaces against adversarial input, injection, and endpoint abuse maps_to B004 — Prevent AI endpoint scraping
- framework
- aiuc-1
- control_id
- B004
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- July 15, 2026 release (quarterly update cadence)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AI-18 — Defend AI interfaces against adversarial input, injection, and endpoint abuse informed_by NIST-TEVV-05 — Test direct and indirect prompt injection
- framework
- nist-ai-tevv-athlon
- control_id
- NIST-TEVV-05
- coverage
- guidance
- relationship
- informs
- delta
- Not provided
- source_version
- NIST AI 200-2 ipd (Initial Public Draft), August 2026
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- sourcePages
- NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Integrity attacks
- AI Guardrail Configuration & Agent Permission Review operates UC-AI-18 — Defend AI interfaces against adversarial input, injection, and endpoint abuse
- UC-AI-18 — Defend AI interfaces against adversarial input, injection, and endpoint abuse maps_to B002 — Detect adversarial input
- framework
- aiuc-1
- control_id
- B002
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- July 15, 2026 release (quarterly update cadence)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.