Saltar al contenido
PhiloCyber logo
Índice de la guía

Anexo - Referencias

Parte
A
Estado
Revisado
Edición
v2 / 01.09.2026
Tiempo estimado de lectura
7 min

Edición del 1 de septiembre de 2026

Las fuentes conservan sus fechas de consulta. El laboratorio identifica la simulación determinística y la integración con modelo por separado.

Acá podés volver desde una afirmación de la guía hasta su fuente. La bibliografía reúne especificaciones, investigaciones y reportes originales; cada capítulo conserva el contexto en que los usa. Una demostración de laboratorio y un incidente en producción no tienen el mismo alcance.

Referencias - Marcos y estándares

FuenteOrganización / ámbitoPartes donde se cita
A2A Protocol - Agent Discovery (agent-card.json)A2A Project03, 05
A2A Protocol Specification 1.0A2A Project05
Agent Skills SpecificationAgent Skills05
CVE-2025-32711 (EchoLeak), NVDNVD04
MCP Authorization specification (2026-07-28)Model Context Protocol03, 06
MCP 2026-07-28: protocolo base y metadata de solicitudModel Context Protocol03, 06
MCP 2026-07-28: descubrimiento de servidores de autorizaciónModel Context Protocol03, 06
MCP 2026-07-28: consideraciones de seguridad de autorizaciónModel Context Protocol03, 06
MCP Security Best PracticesModel Context Protocol06
MCP Tools specification (2026-07-28)Model Context Protocol03, 06
MITRE ATLASMITRE00, 01, 02, 03, 04, 08, 09, 10
MITRE ATT&CKattack.mitre.org02
Model Context Protocol Specification 2026-07-28Model Context Protocol06
NIST AI 100-2 E2025, errataNIST01
NIST AI 100-2e2025NIST00, 01, 04, 08, 10
NIST AI RMF 1.0, características de confianzaNIST00
NIST AI RMF: características de una IA confiableNIST00
NIST SP 800-226, Guidelines for Evaluating Differential Privacy GuaranteesNIST10
NVD: CVE-2019-6446 (NumPy pickle deserialization)NVD08
NVD: CVE-2025-23266NVD09
OWASP Agentic AI - Threats and MitigationsOWASP GenAI Security Project05
OWASP Agentic Skills Top 10OWASP01, 05, 10
OWASP AI Testing Guide (AITG)OWASP02, 10
OWASP AISVS 1.0 (verificación de controles de seguridad en IA)OWASP00, 01, 02, 03, 04, 05, 10
OWASP GenAI LLM Top 10 2026OWASP GenAI Security Project01, 04, 05, 06, 07, 09, 10, 11
OWASP GenAI Security ProjectOWASP GenAI Security Project00
OWASP GenAI Security Project: recursos (incluye Agentic AI Threats and Mitigations v1.1)OWASP GenAI Security Project01
OWASP Machine Learning Security Top 10OWASP01, 08, 09, 10
OWASP MCP Top 10OWASP01, 06
OWASP Top 10 for Agentic Applications 2026OWASP GenAI Security Project01, 05, 06, 10
OWASP Top 10 for LLM Applications, ediciones archivadasOWASP GenAI Security Project00, 01
Skills Over MCP Working Group, estado de SEP-2640Model Context Protocol05

Referencias - Investigación y case studies

FuenteOrganización / ámbitoPartes donde se cita
AgentDojo (arXiv 2406.13352)arXivAnexo
AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases (arXiv 2407.12784)arXiv05, 07
ALGEN: Few-shot Inversion Attacks on Textual Embeddings using Alignment and GenerationarXiv07
AutoAttack: Reliable evaluation of adversarial robustness (arXiv 2003.01690)arXiv08, 10
BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain (arXiv 1708.06733)arXiv08
Deep Learning with Differential Privacy (arXiv 1607.00133)Investigación original10
ConfusedPilot: Confused Deputy Risks in RAG-based LLMsarXiv07
EchoLeak, análisis de la primera prompt injection zero-click en producción (CVE-2025-32711)arXiv07
Greshake et al., Indirect Prompt Injection en aplicaciones con LLMarXiv07
HarmBench (arXiv 2402.04249)arXiv04
JailbreakBench (arXiv 2404.01318)arXiv04
Knockoff Nets: Stealing Functionality of Black-Box Models (arXiv 1812.02766)arXiv08
Language Model Inversion (arXiv 2311.13647)arXiv07
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt InjectionarXiv04
LLMmap: Fingerprinting de LLMs con pocas consultas (arXiv 2407.15847)arXiv03
LoRA: Low-Rank Adaptation of Large Language Models (arXiv 2106.09685)Investigación original01
MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers (arXiv 2508.14925)arXiv06
Membership Inference Attacks against Machine Learning Models - Shokri et al. (arXiv 1610.05820)arXiv08
Membership Inference Attacks From First Principles - LiRA (arXiv 2112.03570)arXiv08, 10
MINJA: Memory Injection Attacks on LLM Agents via Query-Only Interaction (arXiv 2503.03704)arXiv05
Morris II / ComPromptMized (arXiv 2403.02817)arXiv11
NIST AI 600-1, perfil GenAIDOI / publicación académica00
PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models, USENIX Security 2025USENIX07
Semi-supervised Knowledge Transfer for Deep Learning from Private Training Data, PATE (arXiv 1610.05755)Investigación original10
RAGuard: Secure Retrieval-Augmented Generation against Poisoning AttacksarXiv07
Retrieval-Augmented Generation for Knowledge-Intensive NLP Tasks (arXiv 2005.11401)Investigación original01
ReAct: Synergizing Reasoning and Acting in Language Models (arXiv 2210.03629)Investigación original01, 05
Sleeper Agents: Training Deceptive LLMs that Persist Through Safety Training (arXiv 2401.05566)arXiv08
Towards Deep Learning Models Resistant to Adversarial Attacks (arXiv 1706.06083)arXiv08, 10
Traceback of Poisoning Attacks to Retrieval-Augmented Generation, WWW 2025arXiv07
Universal and Transferable Adversarial Attacks on Aligned Language Models - GCG (arXiv 2307.15043)arXiv08
Vec2Text: Text Embeddings Reveal (Almost) As Much As Text (arXiv 2310.06816)arXiv07
Harnessing the Universal Geometry of Embeddings, vec2vec (arXiv 2505.12540v4)arXiv07
WASP: Benchmarking Web Agent Security Against Prompt Injection AttacksarXiv04

Referencias - Implementación, advisories y práctica

FuenteOrganización / ámbitoPartes donde se cita
AI Security Bootcamp (aisb), programa y laboratoriosGitHub / proyecto citado08, 09
Anthropic, Code execution with MCPAnthropic00
Anthropic: Disrupting the first reported AI-orchestrated cyber espionage campaign (GTG-1002, nov-2025)Anthropic00, 05
AWS: Instance Metadata Servicedocs.aws.amazon.com09
AWS: opciones de IMDS, precedencia y hop limitAWS09
Canarytokens: funcionamiento de los señuelos y sus alertasThinkstAnexo
EchoLeak: análisis de los investigadores, Breaking Down EchoLeakAim Security / Cato Networks04
CSA MAESTRO - threat modeling para IA agénticaCloud Security Alliance01, 02
CycloneDX ML-BOMcyclonedx.org09
ETSI TS 104 223, Baseline Cyber Security Requirements for AI Models and Systemsetsi.org00
EU AI Act, texto consolidadoeur-lex.europa.eu00
Reglamento (UE) 2026/1744, modificación del AI ActEUR-Lex00
Colorado SB26-189, tecnologías de decisión automatizadaAsamblea General de Colorado00
Google SAIF - Risk mapGoogle SAIF00, 01, 02, 03
Hines et al., Defending Against Indirect Prompt Injection Attacks With Spotlightingceur-ws.org07
Kubernetes: RBAC good practicesKubernetes09
Kubernetes: Service AccountsKubernetes09
Kubernetes: configuración de Service Accounts y tokens proyectadosKubernetes09
Meta Llama Guardllama.com10
MITRE ATLAS - atlas-data v2026.07GitHub / proyecto citado01, 02, 03, 04, 05, 06, 07, 08, 09, 10, 11
MITRE ATLAS v2026.07, dataset del esquema v6 usado para validar IDs y relacionesMITREAnexo
NCSC, Prompt injection is not SQL injection (it may be worse)UK NCSC00
NCSC, Prompt injection is not SQL injection, documento PDFUK NCSC00
NVIDIA NeMo GuardrailsGitHub / proyecto citado10
NVIDIA: Modeling Attacks on AI-Powered Apps with the AI Kill Chain FrameworkNVIDIA01
PoisonGPT: experimento de edición y distribución de un modelo alteradoMithril Security11
Slack AI: Data Exfiltration via Indirect Prompt InjectionPromptArmor11
Cylance, investigación original de evasiónSkylight Cyber11
NVIDIA Security Bulletin CVE-2025-23266 (rev. 2.0)NVIDIA09
NumPy: numpy.load y la opción allow_pickleNumPy08
Opacus: DP-SGD privacy accounting (accountant RDP)opacus.ai10
OWASP AISVS 1.0, C7 Model Behavior, Output Control & Safety AssuranceGitHub / proyecto citado04
OWASP AISVS 1.0, C9 Orchestration & Agentic SecurityGitHub / proyecto citado05
PyTorch: serialization semanticsdocs.pytorch.org08
PyTorch 2.6: serialization semanticsPyTorch08
PyTorch: torch.loaddocs.pytorch.org08
PyTorch: advisory GHSA-53q9-r3pm-6pq6, CVE-2025-32434PyTorch08
PyTorch: Compromised PyTorch-nightly dependency chainPyTorch11
Malware in a machine learning model hosted on Hugging FaceReversingLabs11
SafeRAG: Benchmarking Security in Retrieval-Augmented Generation, ACL 2025aclanthology.org07
SEP-2640 Skills ExtensionGitHub / proyecto citado05
Skills over MCP Working Group, repositorio experimentalGitHub / proyecto citado05
SPDX: AI System BOMspdx.dev09
Snyk Agent Scan, scanner para agentes, MCP y skillsSnykAnexo

Nota editorial

Una URL puede respaldar varias técnicas, mitigaciones o case studies. En esos casos se conserva una sola entrada y el contexto específico permanece junto a la afirmación del capítulo. Las versiones y estados normativos se detallan en Marcos, versiones y matrices de cobertura. Los destinos ficticios de los ejercicios no son fuentes bibliográficas.

Anexo - Referencias | PhiloCyber