AI SECURITY • 347 / 397
Understand how untrusted text, tools and autonomy create new attack paths.

Confused Deputy

A confused-deputy problem occurs when a more privileged system is tricked into using its authority on behalf of an untrusted requester.

Think of it like

Think of Confused Deputy as an input-trust or privilege problem: words can influence software decisions, so boundaries must be explicit.

Real life

Email, documents and web pages can become hostile inputs to AI systems through attacks involving Confused Deputy.

SRE lens

An agent with AWS privileges may be manipulated by untrusted document content.

Remember thisA confused-deputy problem occurs when a more privileged system is tricked into using its authority on behalf of an untrusted requester.
AIForSREJump to a concept
Search is optional. The main journey is simply ↓ Next.