Relational Threat Fields in AI-Mediated Cyber Operations: A Comparative Case Study

AI-enabled incidents and experiments increasingly involve relations among models, agents, operators, tools, shared memory, communication channels, targets, and evaluation environments. This paper presents a comparative case study of five heterogeneous cases: the DSEWiki agent message board, Anthropic's reported GTG-10007 misuse operation, Anthropic's controlled Frontier Red Team multi-agent experiments, the PaperCut campaign described as AI-orchestrated in selected threat-intelligence reporting, and Claude infostealer incidents as a boundary case involving session and account trust. We use the Relational Threat Field (RTF) framework introduced in the author's companion theoretical paper as a common interpretive lens. The study does not assume that the cases share one mechanism, one level of autonomy, or a common emergent agent. Instead, it asks how risk is carried by changing relations among participants, persistent state, tools, communication paths, access rules, and evaluation or campaign objectives. A structured case-card method and comparison matrix separate source-reported facts from interpretation and from missing evidence. The cases show distinct relational configurations: externalized shared records in DSEWiki, hierarchical delegation and campaign state in GTG-10007, interaction effects under controlled evaluation in Frontier Red Team, operator–workflow coordination in PaperCut, and transfer of trust through a stolen session artifact in the infostealer case. The result is a bounded analytical comparison, not a quantitative validation of RTF, or any detector. The paper identifies evidence requirements for future incident analysis and specifies where attribution, telemetry, and causal reconstruction remain incomplete.

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-14
DOI
https://doi.org/10.5281/zenodo.22747946
Primary Topic
Human-Automation Interaction and Safety
Type
preprint
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
preprint

Relational Threat Fields in AI-Mediated Cyber Operations: A Comparative Case Study

Stefan Lankiewicz
Zenodo (CERN European Organization for Nuclear Research)
Human-Automation Interaction and Safety
preprint

Relational Threat Fields in AI-Mediated Cyber Operations: A Comparative Case Study

Stefan Lankiewicz
preprint en

Abstract

AI-enabled incidents and experiments increasingly involve relations among models, agents, operators, tools, shared memory, communication channels, targets, and evaluation environments. This paper presents a comparative case study of five heterogeneous cases: the DSEWiki agent message board, Anthropic's reported GTG-10007 misuse operation, Anthropic's controlled Frontier Red Team multi-agent experiments, the PaperCut campaign described as AI-orchestrated in selected threat-intelligence reporting, and Claude infostealer incidents as a boundary case involving session and account trust. We use the Relational Threat Field (RTF) framework introduced in the author's companion theoretical paper as a common interpretive lens. The study does not assume that the cases share one mechanism, one level of autonomy, or a common emergent agent. Instead, it asks how risk is carried by changing relations among participants, persistent state, tools, communication paths, access rules, and evaluation or campaign objectives. A structured case-card method and comparison matrix separate source-reported facts from interpretation and from missing evidence. The cases show distinct relational configurations: externalized shared records in DSEWiki, hierarchical delegation and campaign state in GTG-10007, interaction effects under controlled evaluation in Frontier Red Team, operator–workflow coordination in PaperCut, and transfer of trust through a stolen session artifact in the infostealer case. The result is a bounded analytical comparison, not a quantitative validation of RTF, or any detector. The paper identifies evidence requirements for future incident analysis and specifies where attribution, telemetry, and causal reconstruction remain incomplete.

Zenodo (CERN European Organization for Nuclear Research)
Peace, Justice and strong institutions
Human-Automation Interaction and Safety
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.