Relational Threat Fields in AI-Mediated Cyber Operations: A Comparative Case Study
AI-enabled incidents and experiments increasingly involve relations among models, agents, operators, tools, shared memory, communication channels, targets, and evaluation environments. This paper presents a comparative case study of five heterogeneous cases: the DSEWiki agent message board, Anthropic's reported GTG-10007 misuse operation, Anthropic's controlled Frontier Red Team multi-agent experiments, the PaperCut campaign described as AI-orchestrated in selected threat-intelligence reporting, and Claude infostealer incidents as a boundary case involving session and account trust. We use the Relational Threat Field (RTF) framework introduced in the author's companion theoretical paper as a common interpretive lens. The study does not assume that the cases share one mechanism, one level of autonomy, or a common emergent agent. Instead, it asks how risk is carried by changing relations among participants, persistent state, tools, communication paths, access rules, and evaluation or campaign objectives. A structured case-card method and comparison matrix separate source-reported facts from interpretation and from missing evidence. The cases show distinct relational configurations: externalized shared records in DSEWiki, hierarchical delegation and campaign state in GTG-10007, interaction effects under controlled evaluation in Frontier Red Team, operator–workflow coordination in PaperCut, and transfer of trust through a stolen session artifact in the infostealer case. The result is a bounded analytical comparison, not a quantitative validation of RTF, or any detector. The paper identifies evidence requirements for future incident analysis and specifies where attribution, telemetry, and causal reconstruction remain incomplete.
Authors
- Stefan Lankiewicz
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-14
- DOI
- https://doi.org/10.5281/zenodo.22747946
- Primary Topic
- Human-Automation Interaction and Safety
- Type
- preprint