Equation 4 · AI and Cybersecurity in Practice: An Advanced Technical Guide
What does this equation mean?
Read the formula alongside the article passage below. Each part has a deeper page with its role in the equation, the supporting passage and nearby citations.
This equation states an equality: the expressions on both sides have the same value under the article’s assumptions. Read the equation part by part below; each part has a contextual explanation and a link to its mathematical background.
Read it piece by piece
Symbol E
E is part of the quantity the equation computes from the expression on the right.
Symbol c
c appears in the bound of this sum. The bound states where the repeated operation starts, ends, or which values it includes.
Symbol d_c
only bounded once you have already imagined the worst plausible use of the capability — the same failure of imagination that undermines defense-in-depth probability estimates generally.
=
The expressions on both sides represent the same quantity under the stated assumptions.
See an illustrated explanation →subscript
The lower label selects a particular version, component, or indexed member of the quantity. For example, x₀ and xₜ can be values at different positions.
Starting index or lower bound: c
This label says where the repeated addition, multiplication, or accumulation starts. Read its value or condition together with the article’s description of the index.
How to interpret it
Read it with the definitions, units, and assumptions supplied by the article.
What the article says around this equation
There is a simple way to see why capability removal should be the default move rather than the fallback. Model the expected exposure created by a credential as a sum over the capabilities c it carries, each with some probability that it is exploited in a given period and some damage if it is: . Two of the terms in that sum are hard to know honestly. An estimate of assumes a threat model that has to guess at an adversary’s behaviour, and is only bounded once you have already imagined the worst plausible use of the capability — the same failure of imagination that undermines defense-in-depth probability estimates generally. But there is one operation…
Read the full surrounding passage
There is a simple way to see why capability removal should be the default move rather than the fallback. Model the expected exposure created by a credential as a sum over the capabilities c it carries, each with some probability that it is exploited in a given period and some damage if it is: . Two of the terms in that sum are hard to know honestly. An estimate of assumes a threat model that has to guess at an adversary’s behaviour, and is only bounded once you have already imagined the worst plausible use of the capability — the same failure of imagination that undermines defense-in-depth probability estimates generally. But there is one operation available to a system designer that requires no estimate at all: revoke the capability, and its term leaves the sum exactly, not approximately. Better monitoring reduces your uncertainty about . Removing c removes the need to know it. That is the quantitative case for treating scope reduction as the first move rather than “we will detect misuse if it happens” — detection is a hedge against the terms you decided you could not remove, not a substitute for removing the ones you could.
Sources cited in the article section
- [4] LLM06:2025 Excessive Agency ↗
- [12] Security Best Practices ↗
- [5] OWASP Top 10 for Agentic Applications ↗
These citations give research context. Read each source to check which claims it supports.
Return to AI and Cybersecurity in Practice: An Advanced Technical Guide