top of page
Featured in IEEE Journal of IEEE Security & Privacy

Published in: IEEE Security & Privacy ( Volume: 24, Issue: 3, May-June 2026)

  • Keywords: SAST, Large Language Models (LLMs), Generative AI, Cybersecurity, Vulnerability Detection, Vulnerability Discovery, Static Analysis, Code Security.

  • Read 

After months of rigorous peer-review, our latest paper that is the result of our collaboration with Google, Mountain View, CA, got published in Featured in IEEE Journal of IEEE Security & Privacy

  • Impact Factor (2024): 3

  • 5-Year Impact Factor: 3.9

  • Scopus CiteScore: 4.9

  • Publisher: IEEE

Link to the page for more details: Click Here

Featured in the Journal of Computer Information Systems

Executive Summary: This research introduces the LLM Scalability Risk Index (LSRI), a parametric framework to stress-test Agentic-AI in security-critical environments. It further proposes a model-supply-chain framework to establish a verifiable root of trust throughout the model lifecycle.

  • Keywords: AI Governance, Agentic-AI, LSRI, Model Supply Chain Security, Cybersecurity, Dual-use AI.

  • Read 

After months of rigorous peer-review, our latest paper that s the result f our collaboration with Google, Mountain View, CA, got published yesterday in Journal of Computer Information Systems by Taylor & Francis with  

  • Impact Factor (2024): 4.2

  • 5-Year Impact Factor: 3.9

  • SCImago Journal Rank (SJR): 0.882 (2024)

  • Scopus CiteScore: 9.3 (2024)

  • Publisher: Taylor & Francis 

Link to the page for more details: Click Here

Ahi, K., Agrawal, V., & Valizadeh, S. (2026). LLM Scalability Risk for Agentic-AI and Model Supply Chain Security. Journal of Computer Information Systems, 1–17. https://doi.org/10.1080/08874417.2026.2624670

Abstract

As artificial intelligence transitions from passive, human-in-the-loop interfaces to autonomous, multi-agent architectures executing real-time code and tool integration via emerging protocols like the Model Context Protocol (MCP), traditional static and signature-based application security testing (SAST) models completely fail. This paper introduces the LLM Scalability Risk Index (LSRI), a novel, parametric mathematical framework and software standard designed to stress-test agentic systems and quantify the precise operational thresholds where systemic load, compounding hallucinations, and adversarial prompt injections cause autonomous security boundaries to fracture. Beyond standard behavioral alignment, we propose an enterprise-grade software architecture rooted in a Verifiable Root of Trust, utilizing cryptographic attestation and dual-channel semantic policy enforcement to continuously secure the probabilistic layers of the software model supply chain against malicious LoRA adapters, weight tampering, and hallucination-induced dependency typosquatting. By shifting the paradigm from post-hoc alignment to verifiable runtime engineering controls, this standard cybersecurity framework actively accelerates autonomous orchestration under heavy enterprise loads while simultaneously boosting next-generation AI-generated malware defense and providing necessary system explainability. Ultimately, the LSRI framework establishes an objective, deployable compliance baseline for mitigating the rapidly emerging operational, security, and privacy risks inherent to generative AI in mission-critical environments.

Executive Summary

Overview of the Capability Gap

Modern enterprise and federal computing architectures are undergoing a critical shift from passive, human-in-the-loop chat interfaces to autonomous, multi-agent architectures. These agentic systems dynamically execute real-time code, invoke APIs, and handle vendor procurement via emerging protocols like the Model Context Protocol (MCP). However, because autonomous agents operate on probabilistic outputs generated by Large Language Models (LLMs) interpreting natural language instructions at runtime, traditional static application security testing (SAST) and signature-based defensive postures completely fail.

When an untrusted component, poisoned data stream, or adversarial prompt injection manipulates the underlying model's intent, the agent’s execution script inherits its full administrative authority. This creates an acute vulnerability loop where systemic load, compounding hallucinations, and supply chain compromises cause critical operational boundaries to fracture.

The Solution: The LSRI Software Platform

To bridge this gap, this framework introduces the LLM Scalability Risk Index (LSRI)—a novel, parametric mathematical framework and standard cybersecurity software platform designed to stress-test agentic systems under heavy operational loads. Rather than relying on static compliance checklists, LSRI utilizes non-linear mapping functions to quantify the precise thresholds where an autonomous system's performance and security boundaries degrade.

Complementing this metric layer, the platform implements a comprehensive Verifiable Root of Trust for the software model supply chain. This engineering architecture moves beyond soft, post-hoc behavioral alignment (like standard RLHF) to enforce strict, dual-channel runtime engineering controls. The system continuously cross-evaluates linguistic intent alongside the raw API execution channel to detect and neutralize adversarial payloads in real time.

+-----------------------------------------------------------------------------------+ | THE LSRI RUNTIME CONTROL FILTER | +-----------------------------------------------------------------------------------+ | [Agent Intent Layer] ------> ( Linguistic Intent Analysis ) ------+ | | |--> [ENFORCED | | [Tool/MCP Data Stream] ----> ( Cryptographic Weight/LoRA Proofs ) |--> ROOT OF | | | TRUST] | | [Execution Channel] -------> ( Dual-Channel Payload Auditing ) ---+ | +-----------------------------------------------------------------------------------+

Core Technical Pillars & Deliverables

The LSRI software standard establishes automated, continuous validation across three core domains:

  • Software Model Supply Chain Integrity: Utilizes cryptographic attestation and behavioral integrity verification (BIV) to secure the probabilistic layers of the AI pipeline. It prevents code execution via legacy weight formats (e.g., PyTorch pickle files) and blocks backdoors introduced by malicious downstream Low-Rank Adaptation (LoRA) adapters.

  • Active Malware Defense & Typosquatting Mitigation: Automatically intercepts hallucination-induced dependency typosquatting—preventing autonomous agents from pulling poisoned open-source packages from public registries—while neutralizing highly adaptive, AI-generated polymorphic malware.

  • Explainability and Transparent Governance: Provides detailed, auditable diagnostic logs mapping agent behaviors to concrete risk scores, fully satisfying modern federal compliance mandates for explainable, trustworthy AI systems.

Dual-Use Commercialization and Mission Impact

The LSRI framework is engineered as a highly scalable, dual-use technology tailored for both commercial enterprise networks and mission-critical defense operations. By providing non-human machine identities with short-lived, transaction-bound tokens and enforcing just-in-time least privilege abstractions, LSRI eliminates standing administrative credentials and prevents lateral drift across networks.

For federal procurement managers and enterprise Chief Information Security Officers (CISOs), LSRI delivers an objective, deployable compliance baseline. It ensures that complex, high-throughput multi-agent orchestration platforms can be scaled rapidly without exposing underlying infrastructure to systemic execution compromise.

SPIE.jpg

Citation Download Citation

Kiarash AhiChih-Hung Hsieh, and Germain Fenger "LLMs and LVMs for agentic AI: a GPU-accelerated multimodal system architecture for RAG-grounded, explainable, and adaptive intelligence", Proc. SPIE 13687, Photomask Technology 2025, 136871R (6 November 2025); https://doi.org/10.1117/12.3078485

TY  - CONF
TI  - LLMs and LVMs for agentic AI: a GPU-accelerated multimodal system architecture for RAG-grounded, explainable, and adaptive intelligence
AU  - Kiarash Ahi
AU  - Chih-Hung Hsieh
AU  - Germain Fenger
T2  - Proc.SPIE
VL  - 13687
SP  - 136871R

UR  - https://doi.org/10.1117/12.3078485
PY  - 2025/11/6
DO  - 10.1117/12.3078485
ER  - 

 

bottom of page