Safe-State Trigger Independence Under Compute Compromise
Objective
Ensure the safe-state trigger remains functional even if the AI compute/inference stack is adversarially compromised, not merely faulty.
Control / requirement
Safe-state activation path tested specifically under simulated adversarial compute compromise, verifying the trigger fires independent of an actively hostile primary system.
Applicability
Systems where compute compromise (not just random failure) is a credible threat per the Section 5 threat catalog.
Expected evidence
Adversarial fault-injection test records distinguishing compromise scenarios from random-failure scenarios. [T3/T4]
Assurance expectation
Test evidence specifically covering the adversarial case — evidence of resilience to random failure alone is insufficient for this control.
Dependencies
PAI-SF-ATT-001 (Domain 3, attestation) — a compromised system that fails attestation should itself be a trigger condition.
Exclusions
Not applicable to air-gapped systems with no plausible compute-compromise threat model.
Maturity / conformance relevance
Expected at High-Assurance level; Foundational/Operational may address only random- fault independence.
Ecosystem relationship
This is a security concern layered onto a safety mechanism — the clearest example in the register of PAI-SF™'s stated boundary between AI security and functional safety. Relevant to AI-IRF™ investigation of compromise-related incidents.