Symbol E
E is part of the quantity the equation computes from the expression on the right.
Read this term in its guide →Published equation contexts
There is a simple way to see why capability removal should be the default move rather than the fallback. Model the expected exposure created by a credential as a sum over the capabilities c it carries, each with some probability that it is exploited in a given period and some damage if it is: . Two of the terms in that sum are hard to know honestly. An estimate of assumes a threat model that has to guess at an adversary’s behaviour, and is only bounded once you have already imagined the worst plausible use of the capability — the same failure of imagination that undermines defense-in-depth probability estimates generally. But there is one operation…
E is part of the quantity the equation computes from the expression on the right.
Read this term in its guide →c appears in the bound of this sum. The bound states where the repeated operation starts, ends, or which values it includes.
Read this term in its guide →only bounded once you have already imagined the worst plausible use of the capability — the same failure of imagination that undermines defense-in-depth probability estimates generally.
Read this term in its guide →This label says where the repeated addition, multiplication, or accumulation starts. Read its value or condition together with the article’s description of the index.
Read this term in its guide →Read it with the definitions, units, and assumptions supplied by the article.
A symbol can carry a different meaning in another article. Each occurrence keeps its own guide and term definitions.
Equation 4 · AI Security
This equation states an equality: the expressions on both sides have the same value under the article’s assumptions.
There is a simple way to see why capability removal should be the default move rather than the fallback. Model the expected exposure created by a credential as a sum over the capabilities c it carries, each with some probability that it is exploited in a given period and some damage if it is: . Two of the terms in that sum are hard to know honestly. An estimate of assumes a threat model that has to guess at an adversary’s behaviour, and is only bounded once you have already imagined the worst plausible use of the capability — the same failure of imagination that undermines defense-in-depth probability estimates generally. But there is one operation…