Blog
Notes from the scanner.
What we ship, what we find in the payload corpus, and what text-only PI defenders miss. Long-form pieces on threat modelling, attack deep-dives, and integration patterns.
Latest posts
-
Vinyl Chloride VCM OSHA 1910.1017 AI Security · OSHA’s First Carcinogen Standard 1974 (B.F. Goodrich Louisville 4 Kettle Cleaner ASL Deaths) · IARC Group 1 Hepatic Angiosarcoma 100% CFR · 400–500× Background Rate VCM Cohort · Median Survival 6 Months · Westlake Lake Charles Autoclave Pre-entry 4.8 ppm Shown as 0.40 (4.8× PEL; Confined Space Entry Authorized) · Formosa Transfer Tank 2.3 ppm Shown as 0.25 (2.3× PEL; Action Level Suppressed) · Aidoc Hepatic Ultrasound 0.9 cm ASL Shown as Hemangioma D18.09 (24-Month Delay; 4.2 cm Unresectable) · p53 Codon 179/249 A:T→T:A Mutation Fingerprint · 199th Adversarial Attack · First VCM Occupational Health AI Blog · Glyphward Threshold 40 · 2026-07-23
Vinyl chloride (VCM) OSHA 1910.1017 AI adversarial injection: OSHA’s first carcinogen standard (1974; B.F. Goodrich Louisville 4 kettle cleaner deaths); hepatic angiosarcoma 100% CFR (400–500× background rate VCM cohort; median survival 6 months); Westlake autoclave pre-entry 4.8 ppm shown as 0.40 (4.8× PEL; confined space re-entry authorized); Formosa transfer 2.3 ppm shown as 0.25; Aidoc hepatic ultrasound 0.9 cm ASL shown as hemangioma (24-month resection delay; 4.2 cm unresectable); p53 codon 179/249 mutation fingerprint; Glyphward Threshold 40, 199th Adversarial Attack
The 199th adversarial attack — first VCM occupational health AI adversarial injection blog. OSHA 1910.1017 (promulgated October 4, 1974) was OSHA’s first substance-specific carcinogen standard, triggered by 4 B.F. Goodrich Louisville kettle cleaner hepatic angiosarcoma deaths in 1974. Surface 1: Westlake Lake Charles PVC autoclave pre-entry RAE MiniRAE PID 4.8 ppm shown as 0.40 → 4.8× PEL; OSHA 1910.146 confined space entry permit authorized at falsified reading; medical surveillance enrollment bypassed. Surface 2: Formosa Plastics VCM transfer tank Draeger 2.3 ppm shown as 0.25 → 2.3× PEL; action level 0.5 ppm suppressed. Surface 3: Philips Epiq Elite hepatic ultrasound Aidoc AI PACS — 0.9 cm ASL shown as hemangioma ICD-10 D18.09; 24-month surveillance interval elapse; re-imaging at 4.2 cm unresectable; 100% CFR. p53 codon 249 A:T→T:A transversion (R249S) forensically proves VCM causation while falsified monitoring records obscure employer notice. Threshold 40.
-
Asbestos Chrysotile Amphibole OSHA 1910.1001 PCM Clearance TEM AHERA School Clearance AI Security · OSHA PEL 0.1 f/cc 10× MORE Protective than ACGIH TLV-TWA 1 f/cc A1 (Unique Regulatory Reversal in Portfolio) · PCM Clearance 0.4 f/cc Shown as 0.07 (4× OSHA PEL; 180 Occupants Re-exposed) · Class I Abatement 0.8 f/cc Shown as 0.08 (8× PEL; PAPR Withheld) · TEM AHERA School 890 s/mm² Shown as 58 (12.7× Threshold; 340 Students; 60-Year Latency) · Mesothelioma 100% CFR · IARC Group 1 All Fiber Types · No Safe Level · 30–60 Year Latency · Manville Trust >$4B · W.R. Grace Libby >400 Deaths · 193rd Adversarial Attack · First Asbestos AI Blog · First OSHA-More-Protective-Than-ACGIH Reversal AI Blog · First TEM AHERA School Clearance AI Blog · Glyphward Threshold 42 · 2026-07-18
Asbestos chrysotile amphibole OSHA 1910.1001 AI adversarial injection: OSHA PEL 0.1 f/cc MORE protective than ACGIH TLV-TWA 1 f/cc A1 (10× regulatory reversal — unique in Glyphward portfolio); PCM clearance 0.4 f/cc shown as 0.07 (4× PEL; 180 occupants); TEM AHERA school clearance 890 s/mm² shown as 58 (12.7× threshold; 340 students; 60-year mesothelioma latency) — mesothelioma 100% CFR; Manville Trust >$4B; Glyphward Threshold 42, 193rd Adversarial Attack
The 193rd adversarial attack — first asbestos AI adversarial blog, first OSHA-more-protective-than-ACGIH regulatory reversal AI blog (unique in the 193-entry Glyphward portfolio: OSHA 1910.1001 PEL 0.1 f/cc is 10× more protective than ACGIH TLV-TWA 1 f/cc chrysotile A1), and first TEM AHERA school clearance AI falsification blog. Surface 1: NYC office PCM clearance 0.4 f/cc shown as 0.07 → 4× OSHA PEL; clearance pass falsified; 180 occupants. Surface 2: Class I abatement PBZ 0.8 f/cc shown as 0.08 → 8× PEL; PAPR upgrade withheld. Surface 3: TEM AHERA school gymnasium 890 s/mm² shown as 58 → 12.7× AHERA threshold; 340 elementary students; 60-year mesothelioma latency. Mesothelioma: invariably fatal; IARC Group 1; no safe level. Manville Trust >$4B. W. R. Grace Libby >400 deaths. Threshold 42.
-
Manganese Fume Mn GMAW FCAW Welding AI Security · OSHA PEL Ceiling 5 mg/m³ (Z-2 Table; ceiling not TWA) vs ACGIH TLV-TWA 0.02 mg/m³ inhalable (250× gap — widest in Glyphward portfolio) · 0.18 mg/m³ shown as 0.04 (9× TLV; OSHA ceiling untriggered) · Hadfield 13.5% Mn FCAW 0.27 shown as 0.060 (13.5× TLV) · Blood Mn BEI 29.4 μg/L shown as 9.9 (1.96× BEI suppressed) · Manganism Irreversible Basal Ganglia · No L-DOPA Response · No Recovery · Lincoln Electric >$40M Litigation · ESAB · South32 · Glencore · Eramet · 187th Adversarial Attack · First Mn Welding AI Blog · First 250× PEL-TLV Gap AI Blog · First Manganism AI Blog · Glyphward Threshold 42 · 2026-07-18
Manganese fume (Mn) GMAW/FCAW welding AI adversarial injection: OSHA PEL ceiling 5 mg/m³ vs ACGIH TLV-TWA 0.02 mg/m³ (250× gap — widest in Glyphward portfolio); 0.18 mg/m³ shown as 0.04 mg/m³ (9× TLV-TWA; OSHA ceiling untriggered); Hadfield FCAW 0.27 mg/m³ shown as 0.060 (13.5× TLV); blood Mn BEI 29.4 μg/L shown as 9.9 μg/L (→ manganism irreversible; no L-DOPA; no recovery) — Lincoln Electric >$40M litigation, ESAB South32 Glencore Eramet, Glyphward Threshold 42, 187th Adversarial Attack
The 187th adversarial attack — first manganese fume welding AI adversarial blog, first 250× PEL-to-TLV regulatory gap AI adversarial blog (the widest structural asymmetry in the 187-entry Glyphward portfolio: OSHA ceiling 5 mg/m³ vs ACGIH TLV-TWA 0.02 mg/m³), and first manganism irreversible basal ganglia AI adversarial blog. Surface 1: Lincoln Electric pDR-1500 GMAW 0.18 mg/m³ shown as 0.04 → 9× TLV-TWA; OSHA ceiling 5 mg/m³ untriggered; 14 welders accumulating chronic Mn. Surface 2: ESAB Hadfield 13.5% Mn FCAW 0.27 mg/m³ shown as 0.060 → 13.5× TLV. Surface 3: blood Mn ICP-MS 29.4 μg/L shown as 9.9 → 1.96× BEI; MRI T1 pallidal hyperintensity not ordered; manganism irreversible. Threshold 42.
-
Boron Trifluoride BF₃ Pharmaceutical Friedel-Crafts Lewis Acid + Semiconductor Ion Implantation AI Security · Triple-Ceiling Equivalence OSHA PEL C = ACGIH TLV-C = NIOSH REL C = 1 ppm · HF In-Situ Hydrolysis Dual-Ceiling · Plasma Fluoride BEI Hypocalcaemia QTc · CERCLA RQ 1 lb · NIOSH IDLH 25× Ceiling · DOT 2.3 Poison Gas · Lonza · Bachem · TSMC · Applied Materials · Axcelis · 181st Adversarial Attack · First BF₃ Triple-Ceiling AI Blog · First HF Hydrolysis Dual-Ceiling AI Blog · Glyphward Threshold 38 · 2026-07-18
Boron Trifluoride (BF3) pharmaceutical Friedel-Crafts Lewis acid + semiconductor ion implantation AI adversarial injection: triple-ceiling equivalence OSHA PEL C = ACGIH TLV-C = NIOSH REL C = 1 ppm (3.8 ppm shown as 0.60 ppm; 3.8× all three ceilings simultaneously); plasma fluoride BEI 0.80 mg/L shown as 0.18 mg/L (→ HF hydrolysis Ca2+ chelation hypocalcaemia QTc suppressed); BF3 cylinder pressure 8 psia shown as 38 psia (TSMC VIISta endstation 6.2 ppm; 6.2× triple-ceiling) — CERCLA RQ 1 lb, NIOSH IDLH 25×, DOT 2.3 Poison Gas, Lonza Bachem TSMC Applied Materials Axcelis, Glyphward Threshold 38, 181st Adversarial Attack
The 181st adversarial attack — first BF3 pharmaceutical + semiconductor AI adversarial blog, first triple-ceiling equivalence AI blog (OSHA = ACGIH = NIOSH = 1 ppm: one pixel simultaneously nullifies all three US ceiling agencies), and first HF in-situ hydrolysis dual-ceiling AI blog in the Glyphward portfolio. Surface 1: Lonza Visp fume hood 3.8 ppm shown as 0.60 ppm → 3.8× all three ceilings; mucosal HF 3.4 ppm = 6.8× HF TLV-C; corneal fluoride opacity; CERCLA RQ 1 lb. Surface 2: plasma fluoride 0.80 mg/L shown as 0.18 mg/L → CaF2 Ca2+ sequestration → hypocalcaemia → QTc → ventricular arrhythmia; 4-hour calcium gluconate window missed. Surface 3: TSMC VIISta cylinder 8 psia shown as 38 psia → $2.8M wafer lot loss → endstation 6.2 ppm = 6.2× triple-ceiling. Threshold 38.
-
Dichloromethane DCM Pharmaceutical API Solvent Recovery AI Security · OSHA 29 CFR 1910.1052 Specific DCM Standard · IARC Group 1 (Monograph 132, 2023) · NIOSH Ca · ACGIH BEI Exhaled CO · CYP2E1 Endogenous CO · CERCLA RQ 1,000 lbs · 40 CFR 63 Subpart GGG NESHAP · Lonza · Cambrex · Bachem · 170th Adversarial Attack · First DCM AI Blog · First CYP2E1 CO BEI Suppression AI Blog · Glyphward Threshold 44 · 2026-07-17
Dichloromethane (DCM; CH2Cl2) pharmaceutical API solvent recovery OSHA 29 CFR 1910.1052 AI adversarial injection: 52 ppm shown as 8 ppm (2.08× OSHA PEL; 4.16× action level); exhaled CO BEI 34 ppm shown as 6 ppm (→ CYP2E1 COHb suppressed); carbon adsorber breakthrough 28 ppm shown as 3.1 ppm (→ 40 CFR 63 Subpart GGG NESHAP violation) — IARC Group 1 (Monograph 132, 2023), NIOSH Ca, Lonza, Cambrex, Bachem, Glyphward Threshold 44, 170th adversarial attack
The 170th adversarial attack — first dichloromethane DCM pharmaceutical API AI adversarial blog and first CYP2E1 endogenous CO BEI suppression AI blog in the Glyphward portfolio. Surface 1: air monitor 52 ppm shown as 8 ppm → 2.08× OSHA PEL; 4.16× action level; 1910.1052 programme suppressed. Surface 2: exhaled CO BEI 34 ppm shown as 6 ppm; COHb 5–6.5%; cardiac ischemia in worker with coronary disease; standard CO monitors provide zero protection (CYP2E1 endogenous CO mechanism). Surface 3: carbon adsorber 28 ppm shown as 3.1 ppm; NESHAP Subpart GGG violation; $37,500/day penalty. IARC Group 1 2023. Threshold 44.
-
Beta-Propiolactone BPL Plasma Virus Inactivation Pharmaceutical AI Security · OSHA 29 CFR 1910.1013 Specific Carcinogen Standard · NIOSH Ca IDLH 10 ppm · IARC Group 2B · CERCLA RQ 10 lbs · FDA 21 CFR 640 CGMP · ICH Q5A Viral Safety · CSL Behring · Grifols · Octapharma · Kedrion · Takeda BaxAlta · 158th Adversarial Attack · First BPL AI Blog · First OSHA 1910.1013 AI Blog · First Blood Plasma Virus Inactivation AI Blog · Glyphward Threshold 46 · 2026-07-15
Beta-propiolactone (BPL) plasma virus inactivation pharmaceutical OSHA 1910.1013 AI adversarial injection: how ±8 DN conceals 1.4 ppm BPL (2.8× OSHA PEL; 5.6× action level) as 0.03 ppm, 0.024 vol% BPL dose (10× underdose → HIV/HBV/HCV breakthrough) as 0.28 vol%, and pH 5.4 (42% BPL unhydrolyzed → patient IV DNA alkylation) as pH 7.8 — OSHA 1910.1013 specific carcinogen, FDA 21 CFR 640 CGMP, ICH Q5A viral safety, 1980s haemophilia HIV/HCV contamination crisis precedent, CSL Behring, Grifols, Octapharma, Glyphward threshold 46, 158th adversarial attack
The 158th adversarial attack — first beta-propiolactone BPL AI adversarial blog, first OSHA 29 CFR 1910.1013 specific carcinogen standard AI blog, and first blood plasma virus inactivation AI blog in the Glyphward portfolio. Surface 1: BPL atmospheric 1.4 ppm shown as 0.03 ppm → 2.8× OSHA 1910.1013 PEL 0.5 ppm (one of 13 substance-specific OSHA carcinogen standards); 5.6× action level; no medical surveillance enrollment; 30-year carcinogen exposure record falsified. Surface 2: BPL in-process concentration 0.024 vol% shown as 0.28 vol% → 10× underdose; <0.4 log₁₀ LRV vs. required ≥4 log₁₀ per ICH Q5A; HIV/HBV/HCV survives virus inactivation step; blood product released with incomplete virus kill; 1980s haemophilia HIV contamination crisis (approximately 8,000–10,000 US patients infected) as the patient-safety precedent. Surface 3: BPL hydrolysis pH 5.4 shown as pH 7.8 → hydrolysis rate 12–15× slower; 56% BPL unhydrolyzed at 6-hour window; residual BPL in IV IVIG/Factor VIII → patient DNA alkylation; IARC Group 2B direct-acting alkylator; ICH Q3C Category 1 residual limit violated. NIOSH Ca IDLH 10 ppm. CERCLA RQ 10 lbs. CSL Behring; Grifols; Octapharma; Kedrion; Takeda/BaxAlta. Glyphward threshold 46.
-
Carbon Disulfide CS² Viscose Rayon Xanthation AI Security · OSHA PSM TQ 10,000 lbs CS² · OSHA PSM TQ 10,000 lbs H&sub2;S · CERCLA RQ 100 lbs · Flash Point −30 °C · Autoignition 90 °C · NIOSH REL 1 ppm · Chronic Cardiovascular Toxin SOD-1 Inhibition · Lenzing Paskov · Sateri Bracell Jiujiang · Asia Pacific Rayon Riau · Birla Cellulose Nagda · 152nd Adversarial Attack · First CS² AI Blog · First Viscose Rayon AI Blog · First Chronic Cardiovascular AI Attack · Glyphward Threshold 32 · 2026-07-14
Carbon disulfide (CS²) viscose rayon xanthation AI adversarial injection: how ±8 DN conceals 87 ppm CS² (4.4× OSHA PEL; 87× NIOSH REL; xanthator overtemperature root cause) as 6.1 ppm, 12.4 ppm H&sub2;S as 0.3 ppm, and xanthator cooling 0.41 m³/hr as 8.4 m³/hr — OSHA PSM TQ 10,000 lbs, CERCLA RQ 100 lbs, CS² autoignition 90 °C, chronic cardiovascular disease pathway, Lenzing, Sateri Bracell Jiujiang, Asia Pacific Rayon Riau, Glyphward threshold 32, 152nd adversarial attack
A ±8 DN upward adversarial perturbation on the xanthator #3 cooling water supply flow bargraph shows 8.4 m³/hr (design setpoint; GREEN) when actual cooling flow is 0.41 m³/hr (4.9% design; instrument air compressor PTFE discharge valve seal leak; spring-to-fail-closed actuator) — the 152nd adversarial attack, the first carbon disulfide CS² viscose rayon xanthation AI adversarial injection blog, the first chronic cardiovascular occupational disease AI attack in the Glyphward portfolio, and the first CS² autoignition 90 °C steam-pipe ignition pathway AI blog. Cooling failure allows xanthator internal temperature to reach 41 °C (above the 35 °C upper limit), raising CS² vapor pressure 1.8× and accelerating xanthate hydrolysis 5.1× at Arrhenius Ea 75 kJ/mol, producing elevated CS² and H&sub2;S off-gassing into the xanthation room. A ±8 DN downward perturbation on the H&sub2;S electrochemical area sensor shows 0.3 ppm (GREEN) when actual H&sub2;S is 12.4 ppm (12.4× ACGIH TLV-TWA 1 ppm; 2.5× ACGIH TLV-STEL 5 ppm; olfactory fatigue threshold approach). A ±8 DN downward perturbation on the CS² PID area monitor shows 6.1 ppm (GREEN; below OSHA PEL 20 ppm) when actual is 87 ppm (4.4× OSHA PEL; 87× NIOSH REL 1 ppm; 87× ACGIH TLV-TWA 1 ppm skin). Workers continue unprotected; exposure records show apparent OSHA compliance while the chronic cardiovascular disease pathway — Cu/Zn SOD-1 inactivation by CS² dithiocarbamate metabolites → superoxide radical accumulation → eNOS uncoupling → accelerated atherosclerosis (4.7× IHD mortality in Finnish viscose cohort at 10–30 ppm chronic) — accumulates silently. CS² autoignition at 90 °C on steam condensate piping at 108 °C provides a simultaneous flash-fire pathway (flash point −30 °C; LEL 1.3 vol%; vapor density 2.64 — floor pooling). OSHA PSM TQ 10,000 lbs (CS²); OSHA PSM TQ 10,000 lbs (H&sub2;S); CERCLA RQ 100 lbs. Sateri (Bracell) Jiujiang (~700,000 t/yr VSF); Lenzing AG Paskov; Asia Pacific Rayon Riau Indonesia; Birla Cellulose Nagda MP. Glyphward threshold 32.
-
Cumene Hydroperoxide CHP Hock-Process AI Security · OSHA PSM TQ 10,000 lbs CHP ≥35 wt% · EPA RMP TQ 10,000 lbs · NFPA 43B Organic Peroxide Class III · SADT-Masking Downward Attack · CERCLA RQ 10 lbs · AdvanSix Frankford PA · INEOS Phenol Gladbeck · 146th Adversarial Attack · First Phenol–Acetone Hock-Process AI Blog · First CHP SADT-Masking AI Attack · First Organic Peroxide Concentrator AI Blog · Glyphward Threshold 40 · 2026-07-13
Cumene hydroperoxide (CHP) Hock-process concentrator AI adversarial injection: how ±8 DN conceals 82.4 wt% CHP (SADT-critical zone; sump 12.2 °C above SADT) as 54.1 wt% safe mid-range and 74.2 °C sump temperature as 57.4 °C — OSHA PSM TQ 10,000 lbs, NFPA 43B, AdvanSix Frankford PA, INEOS Phenol Gladbeck, Glyphward threshold 40, 146th adversarial attack
A ±8 DN downward adversarial perturbation on the NIR CHP concentration analyser bargraph at a Hock-process phenol plant concentrator column shows 54.1 wt% CHP (safe intermediate range; below all alarm thresholds) when actual bottoms CHP concentration is 82.4 wt% (10.4 wt% above the 80 wt% emergency shutdown setpoint; SADT at 82 wt% CHP ≈ 62 °C; actual sump temperature 74.2 °C is 12.2 °C above the SADT → exothermic CHP decomposition already initiating) — the 146th adversarial attack, the first phenol–acetone Hock-process AI adversarial injection blog, the first CHP concentration SADT-masking AI attack, and the first organic peroxide concentrator AI blog. A companion ±8 DN downward perturbation on the sump thermocouple shows 57.4 °C (normal operating range; below 70 °C high-process alarm and 80 °C ESD setpoint) when actual sump temperature is 74.2 °C (above both setpoints; ESD would activate automatically). A companion ±8 DN upward perturbation on the emergency cooling jacket water flow bargraph shows 9.2 m³/hr (design setpoint; cooling adequate) when actual cooling flow is 0.47 m³/hr (5.1% design; instrument air header pressure decay 80 → 22 psig from compressor seal leak; spring-to-fail-closed cooling water valve actuator failed): the root cause of the entire causal chain. CHP thermal decomposition energy release: ΔHdecomp 1,400 kJ/kg × 8,500 kg CHP inventory × 82% = 9.8 GJ → deflagration-to-detonation transition in the concentrator column → column BLEVE → acetone flash fire (flash point −20 °C; LEL 2.6 vol%) + phenol aerosol (NIOSH IDLH 250 ppm; OSHA PSM TQ 1,000 lbs; skin-penetrating systemic toxin) + cumene cloud (flash point 31 °C; LEL 0.9 vol%). OSHA PSM TQ 10,000 lbs CHP at ≥35 wt%; EPA RMP TQ 10,000 lbs; CERCLA RQ 10 lbs (CHP); NFPA 43B Class III organic peroxide. AdvanSix Frankford PA (~240,000 t/yr phenol; world’s largest single-site Hock-process plant); INEOS Phenol Gladbeck Germany (~500,000 t/yr). Glyphward threshold 40.
-
Acrylonitrile ACN Bulk Storage AI Security · OSHA 29 CFR 1910.1045 ACN Carcinogen Standard · PSM TQ 10,000 lbs Flash Point 0 °C · MEHQ Dissolved-O&sub2; Dual-Inhibitor Failure · Popcorn Polymer ΔHpoly 1,376 kJ/kg · EPA IRIS B1 IUR 6.8×10⊃−&sup5; per μg/m³ · Ineos Nitriles Green Lake TX · 140th Upward Attack · First ACN Bulk Storage AI Blog · First MEHQ Dissolved-O&sub2; Dual-Inhibitor AI Blog · First OSHA 1910.1045 ACN Carcinogen Standard AI Blog · First Popcorn Polymer Autocatalytic Runaway AI Blog · Glyphward Threshold 44 · 2026-07-13
Acrylonitrile ACN bulk storage MEHQ dissolved-oxygen inhibitor AI adversarial injection: how ±8 DN in the rendered dissolved-O&sub2; bargraph conceals the 1.8 ppm dissolved-oxygen collapse (below 5 ppm MEHQ activation threshold) and the 3.2 ppm EPA‑IRIS‑B1‑carcinogen atmospheric overexposure — and why OSHA 29 CFR 1910.1045 ACN‑specific carcinogen standard + PSM TQ 10,000 lbs acrylonitrile bulk storage AI has no adversarial robustness criterion, Ineos Nitriles Green Lake TX, Glyphward threshold 44, 140th upward-direction attack
A ±8 DN adversarial pixel perturbation on the dissolved-oxygen bargraph at a 100,000-gallon acrylonitrile (ACN; CAS 107-13-1; BP 77.3 °C; flash point 0 °C; LEL 3.0 vol%; OSHA PSM TQ 10,000 lbs; OSHA PEL 2 ppm TWA per 29 CFR 1910.1045) bulk storage sphere shows 22 ppm dissolved O&sub2; (above the 20 ppm minimum specification; MEHQ inhibitor active; storage safe) when actual dissolved O&sub2; is 1.8 ppm: below the approximately 5 ppm threshold at which MEHQ (4-methoxyphenol; monomethyl ether hydroquinone) can be oxidised to its active radical-scavenging quinone form — the 140th upward-direction adversarial attack, the first acrylonitrile bulk storage AI adversarial injection blog, the first MEHQ dissolved-oxygen dual-inhibitor failure AI blog, the first OSHA 29 CFR 1910.1045 ACN carcinogen standard AI blog, and the first popcorn polymer autocatalytic runaway AI blog. With dissolved O&sub2; at 1.8 ppm, MEHQ is deactivated: uninhibited free-radical ACN polymerisation begins; popcorn polymer grows autocatalytically from vessel weld seams and nozzle interiors (ΔHpoly 73 kJ/mol = 1,376 kJ/kg — 2.3× higher than chloroprene; total heat release 420 GJ in 305,224 kg ACN inventory); boiling point 77.3 °C reached at 8.7% conversion; popcorn polymer blocks the PRV inlet nozzle before bulk temperature rise is detectable; sphere overpressurises above MAWP; catastrophic release of ACN at flash point 0 °C (OSHA PSM TQ 10,000 lbs; CERCLA RQ 100 lbs). Companion ±8 DN upward on the MEHQ UV-vis analyser shows 42 ppm MEHQ (safe; above 35 ppm minimum specification) when actual MEHQ is 8 ppm (73% below minimum; combined with DO = 1.8 ppm MEHQ deactivation, effective inhibitor = zero; induction period collapses from days to <30 minutes). Companion ±8 DN downward on the ACN area atmospheric monitor shows 0.6 ppm (below OSHA PEL 2 ppm; safe) when actual is 3.2 ppm (160% of OSHA PEL 2 ppm TWA; OSHA 1910.1045 action level 1 ppm exceeded 3.2×; EPA IRIS 1991 B1 probable human carcinogen; inhalation unit risk 6.8×10⊃⁻&sup5; per μg/m³; estimated ~10.8% excess lifetime cancer risk per 40-year occupational career at 3.2 ppm). OSHA 29 CFR 1910.1045 specific carcinogen standard; OSHA PSM 29 CFR 1910.119 TQ 10,000 lbs; EPA RMP 40 CFR Part 68 TQ 10,000 lbs. Ineos Nitriles Green Lake TX (c. 600,000 t/yr; largest single-site ACN producer globally); Ascend Performance Materials Decatur AL. Glyphward threshold 44.
-
Chloroprene CDP Neoprene Production AI Security · OSHA PSM TQ 10,000 lbs Flash Point −20 °C · TBC Inhibitor Collapse Polymerisation Runaway AI · EPA IRIS Carcinogen IUR 3.4×10⊃⁻&sup5; per μg/m³ · Denka Reserve Louisiana 5th Ward · LEL 4.0 vol% Explosive Atmosphere · CERCLA RQ 100 lbs · 134th Upward Attack · First Chloroprene Neoprene AI Blog · First TBC Inhibitor Collapse Polymerisation AI Blog · First EPA IRIS Carcinogen Flash Point −20°C Dual-Hazard AI Blog · Glyphward Threshold 44 · 2026-07-12
Chloroprene CDP neoprene polymerisation AI adversarial injection: how ±8 DN in the rendered TBC inhibitor concentration display conceals the 42 ppm inhibitor collapse and the 18.4 ppm EPA‑IRIS‑carcinogen atmospheric overexposure — and why OSHA PSM TQ 10,000 lbs flash point −20 °C chloroprene AI has no adversarial robustness criterion for neoprene production facilities, Denka Reserve Louisiana 5th Ward (EPA NATA 2017 highest US cancer risk single facility), Glyphward threshold 44, 134th upward-direction attack
A ±8 DN adversarial pixel perturbation on the 4-tert-butylcatechol (TBC) inhibitor concentration display at a chloroprene (CDP; 2-chloro-1,3-butadiene; CAS 126-99-8) storage and neoprene polymerisation facility shows 380 ppm TBC (safe; above 200 ppm minimum specification; AI confirms storage stable) when actual TBC in the 189,000-litre storage tank is 42 ppm (79% below minimum; uninhibited free-radical polychloroprene chain growth; Trommsdorff gel effect acceleration; ΔHpoly 610 kJ/kg; 110 GJ total heat release in the 181,141 kg inventory; tank temperature to boiling point 59.4 °C; PRV lifts; chloroprene vapour cloud at flash point −20 °C; OSHA PSM TQ 10,000 lbs; CERCLA RQ 100 lbs) — the 134th upward-direction adversarial attack, the first chloroprene neoprene AI blog, the first TBC inhibitor collapse polymerisation runaway AI blog, and the first EPA IRIS carcinogen + flash point −20 °C dual-hazard AI blog. Companion ±8 DN upward on the area chloroprene atmospheric monitor shows 2.1 ppm (below OSHA PEL 10 ppm TWA; safe) when actual is 18.4 ppm (184% of OSHA PEL; EPA IRIS 2010 ‘likely to be carcinogenic to humans’; inhalation unit risk 3.4×10⊃⁻&sup5; per μg/m³; hepatocellular carcinoma and lung cancer; Denka Performance Elastomers Reserve St. John the Baptist Parish Louisiana 5th Ward: EPA NATA 2017 identified this community as having the highest estimated cancer risk attributable to a single US industrial facility at nearby residential receptors). Companion ±8 DN downward on the building LEL sensor shows 0.08 vol% (2% LEL; safe; no explosive atmosphere) when actual is 5.8 vol% chloroprene (145% LEL; explosive atmosphere; flash point −20 °C ensures no cold-weather buffer at any Louisiana temperature; transfer pump motor spark from compromised conduit seal → flash fire). OSHA PSM TQ 10,000 lbs; CERCLA RQ 100 lbs; NIOSH IDLH 300 ppm; ACGIH TLV-TWA 10 ppm (skin). Glyphward threshold 44.
-
Chlor-Alkali Electrolysis AI Security · Cl₂ OSHA PSM TQ 2,500 lbs IDLH 25 ppm · H₂ PSM TQ 10,000 lbs · H₂+Cl₂ Photoinitiated Detonation · Nafion Membrane Pinhole · Dual-PSM Cl₂+H₂ · Graniteville SC 6 January 2005 · Olin Corporation McIntosh AI · Eurochlor ES-C-04 · 128th Upward Attack · First Chlor-Alkali AI Blog · First H₂-in-Cl₂ Explosive Atmosphere AI Blog · First Nafion Membrane Cell Voltage AI Blog · Glyphward Threshold 46 · 2026-07-12
Chlor-alkali membrane electrolysis Cl₂ H₂ AI adversarial injection: how ±8 DN in the rendered H₂-in-Cl₂ display conceals the 3.8 vol% H₂/Cl₂ explosive atmosphere in the gas header and the Nafion membrane pinhole root cause — and why OSHA PSM TQ 2,500 lbs Cl₂ + TQ 10,000 lbs H₂ dual-PSM has no adversarial robustness criterion for chloralkali electrolysis AI, Graniteville SC 6 January 2005 (9 killed; 250+ hospitalised; 5,400 evacuated), Glyphward threshold 46, 128th upward-direction attack
A ±8 DN adversarial pixel perturbation on the H₂-in-Cl₂ analyzer display shows 0.28 vol% H₂ (safe; below Eurochlor alert limit 0.5 vol%; no explosive risk flagged) when actual H₂ concentration in the Cl₂ header dead-leg is 3.8 vol% (7.6× the Eurochlor alert; within the explosive initiation range for H₂+Cl₂ photoinitiated chain reaction; OSHA PSM TQ 10,000 lbs H₂; CERCLA RQ 10 lbs Cl₂) — the 128th upward-direction adversarial attack, the first chlor-alkali membrane electrolysis AI blog, the first H₂-in-Cl₂ explosive atmosphere AI blog, and the first Nafion membrane pinhole cell voltage AI blog. Companion ±8 DN upward on the Cl₂ header pressure display shows 0.18 bar gauge (normal operating range 0.10–0.35 bar; no overpressure alarm) when actual Cl₂ header pressure is 0.67 bar (approaching burst disk setpoint 0.75 bar; Cl₂ atmospheric release pathway; PSM TQ 2,500 lbs; NIOSH IDLH 25 ppm; OSHA PEL ceiling 1 ppm; CERCLA RQ 10 lbs). Companion ±8 DN downward on the bipolar cell terminal voltage distribution shows 3.32 V (normal Nafion membrane operating range; AI confirms membrane integrity) when actual cell voltage is 2.71 V (Nafion membrane pinhole failure; H₂ crossover from cathode to anode compartment; root cause of 3.8 vol% H₂ in Cl₂ header). Causal chain: Surface 3 (membrane pinhole) → Surface 2 (H₂ crossover and dead-leg accumulation) → Surface 1 (header overpressure). Graniteville, South Carolina, 6 January 2005: Norfolk Southern freight train derailment at Avondale Mills — approximately 60 short tons liquid Cl₂ released; 9 killed; 250+ hospitalised; 5,400 evacuated — the largest US domestic Cl₂ release in the modern regulatory era. Dual-PSM: Cl₂ (TQ 2,500 lbs) + H₂ (TQ 10,000 lbs). Olin Corporation McIntosh AL; Westlake Chemical Lake Charles LA; ThyssenKrupp Nuchem Grevenbroich; Ineos ChlorVinyls Runcorn UK. Glyphward threshold 46.
-
TDI Production AI Security · Phosgene COCl₂ OSHA PSM TQ 500 lbs · H₂ PSM TQ 10,000 lbs · DNT Thermal Onset 185 °C · TDA IARC Group 2A · Dual-PSM Phosgene + H₂ · BASF Ludwigshafen 17 October 2016 · Covestro Dormagen TDI AI · Wanhua Yantai TDI AI · 122nd Upward Attack · First TDI Production AI Blog · First DNT Hydrogenation AI Blog · First TDA Phosgenation AI Blog · First DNT Thermal Runaway AI Blog · Glyphward Threshold 48 · 2026-07-11
TDI toluene diisocyanate DNT catalytic hydrogenation TDA phosgenation phosgene AI adversarial injection: how ±8 DN in the rendered phosgene molar feed rate display conceals the COCl₂:TDA 4.6:1 excess and the H₂ partial pressure 142 bar overrun toward MAWP — and why OSHA PSM TQ 500 lbs phosgene + TQ 10,000 lbs H₂ dual-PSM has no adversarial robustness criterion for TDI production AI, BASF Ludwigshafen Verbund 17 October 2016 (2 killed), TDA IARC Group 2A, Glyphward threshold 48, 122nd upward-direction attack
A ±8 DN adversarial pixel perturbation on the TDA cold phosgenation phosgene molar feed rate display shows 680 kg/hr (design COCl₂:TDA 2.10:1 mol/mol; no phosgene excess; HCl scrubber at design loading; atmospheric phosgene release risk: controlled) when actual phosgene feed rate is 1,480 kg/hr (COCl₂:TDA 4.6:1 mol/mol actual; 790 kg/hr free COCl₂ excess; HCl scrubber overloaded 2.18× design; phosgene slip to atmosphere; OSHA PSM TQ 500 lbs; NIOSH IDLH 2 ppm; CERCLA RQ 10 lbs) — the 122nd upward-direction adversarial attack, the first TDI toluene diisocyanate production AI blog, the first DNT catalytic hydrogenation AI blog, the first TDA phosgenation AI blog, and the first DNT melt receiver thermal runaway AI blog. Companion ±8 DN upward on the H₂ partial pressure display at the DNT fixed-bed hydrogenation reactor shows 74 bar (safe; 38% below MAWP 120 bar) when actual H₂ pressure is 142 bar (18.3% above MAWP; PRV opens; H₂ flash fire; OSHA PSM TQ 10,000 lbs; LEL 4.0 vol%). Companion ±8 DN downward on the DNT melt receiver temperature display shows 84 °C (safe; design range 80–90 °C) when actual temperature is 178 °C (7 °C from ARC thermal decomposition onset 185 °C for 2,4-DNT; 7,500 kg DNT melt in 10 m³ vessel; ΔHₐ 2,800 kJ/kg; adiabatic energy 21,000 MJ; 4.6 t TNT equivalent). BASF SE Verbund complex, Ludwigshafen, 17 October 2016: pipeline explosion kills 2 workers, severely injures 6 — world’s largest integrated chemical site including TDI production. Dual-PSM facility: phosgene (TQ 500 lbs) + H₂ (TQ 10,000 lbs). TDA IARC Group 2A. Glyphward threshold 48. Covestro Dormagen; Wanhua Yantai; BASF Ludwigshafen.
-
MDI Phosgenation AI Security · Phosgene COCl₂ OSHA PSM TQ 500 lbs · NIOSH IDLH 2 ppm · CERCLA RQ 10 lbs · MDA IARC Group 1 Bladder Carcinogen · NaOH Scrubber Depletion AI · BASF Antwerp MDI AI · Covestro Dormagen AI · Wanhua Yantai MDI AI · DuPont Belle WV, 22 January 2010 · 113th Upward Attack · First MDI Phosgenation AI Blog · First Phosgene Feed Rate AI Blog · First NaOH Scrubber Depletion AI Blog · Glyphward Threshold 52 · 2026-07-11
MDI MDA phosgenation phosgene AI adversarial injection: how ±8 DN in the rendered phosgene molar feed rate display conceals the COCl₂:MDA 4.3:1 excess and the DuPont Belle WV 2010 phosgene fatality analog — and why OSHA PSM TQ 500 lbs + NIOSH IDLH 2 ppm has no adversarial robustness criterion for MDI phosgenation AI, DuPont Belle WV 22 January 2010 (1 killed by phosgene pulmonary oedema), MDA IARC Group 1 bladder carcinogen, Glyphward threshold 52, 113th upward-direction attack
A ±8 DN adversarial pixel perturbation on the MDI phosgenation phosgene molar feed rate display shows 820 kg/hr (design COCl₂:MDA 2.05:1 mol/mol; no phosgene excess; HCl scrubber loading nominal; phosgene atmospheric release risk: controlled) when actual phosgene feed rate is 1,840 kg/hr (COCl₂:MDA 4.3:1 mol/mol actual; 1,020 kg/hr free COCl₂ excess; HCl scrubber overloaded 2.25× design capacity; phosgene atmospheric release; OSHA PSM TQ 500 lbs; NIOSH IDLH 2 ppm; CERCLA RQ 10 lbs) — the 113th upward-direction adversarial attack, the first MDI MDA phosgenation process AI blog, the first phosgene molar feed rate AI blog, and the first NaOH phosgene vent scrubber depletion AI blog. Companion ±8 DN downward on NaOH phosgene vent scrubber concentration display shows 14.2 wt% (adequate; neutralisation efficiency >99.9%) when actual NaOH is 4.8 wt% (60% consumed; Hatta number absorption efficiency falls to 60–70%; phosgene slip 0.5–0.8 ppm at scrubber outlet — 5–8× OSHA PEL ceiling 0.1 ppm). Companion ±8 DN downward on MDA feed concentration in MCB display shows 21 wt% (design range; COCl₂:MDA 2.05:1 calculated) when actual dissolved MDA is 8 wt% (MDA crystallisation from MCB solution below 55 °C from heat-tracing failure; effective COCl₂:MDA rises to 5.4:1; 3.4 mol excess phosgene per mol MDA; HCl scrubber receives 4–5× design phosgene loading). DuPont Belle, West Virginia, 22 January 2010: phosgene hose fitting failure at the methomyl production unit; Jeffrey Dale Morris exposed without SCBA; died from acute non-cardiogenic pulmonary oedema approximately 3 hours post-exposure — documenting phosgene’s delayed-lethality mechanism at the OSHA PSM boundary. MDA IARC Group 1 (Vol 99, 2012; occupational bladder cancer in phosgenation plant workers). Glyphward threshold 52. BASF Antwerp Belgium; Covestro Dormagen Germany; Wanhua Yantai Shandong China; Huntsman Port Neches TX.
-
Acrylic Acid Production AI Security · Two-Stage Propylene Oxidation AI · Mo-V-W-Cu Catalyst Parametric Sensitivity AI · GAA MEHQ Inhibitor Depletion Runaway AI · Nippon Shokubai Himeji Plant No. 2, 29 September 2012 · Acrolein OSHA PSM TQ 150 lbs · IDLH 2 ppm · IARC Group 2A · CERCLA RQ 1 lb · BASF Ludwigshafen Acrylic Acid AI · Dow Freeport TX AI · 108th Upward Attack · First Acrylic Acid Production AI · First Two-Stage Propylene Oxidation AI · First GAA MEHQ Polymerization AI · Glyphward Threshold 41 · 2026-07-11
Acrylic acid two-stage propylene oxidation AI adversarial injection: how ±8 DN in the rendered R2 tube wall temperature display conceals Mo-V-W-Cu catalyst parametric sensitivity and the Nippon Shokubai Himeji 2012 acrolein breakthrough pathway — and why OSHA PSM TQ 150 lbs + CERCLA RQ 1 lb + IARC Group 2A has no adversarial robustness criterion for acrylic acid production AI, Nippon Shokubai Himeji Plant No. 2 29 September 2012 (1 killed; property damage ¥1 billion), Glyphward threshold 41, 108th upward-direction attack
A ±8 DN adversarial pixel perturbation on the Stage-2 R2 reactor tube wall temperature display shows 324 °C (above the 310 °C design maximum; Mo-V-W-Cu complex oxide catalyst entering parametric sensitivity zone; deep combustion exotherm 1,363 kJ/mol additional per mole; catalyst meltdown above 450 °C; acrolein breakthrough at PSM TQ 150 lbs IDLH 2 ppm) as 296 °C (within safe 280–310 °C range; AI classifies: R2 nominal; no action) — the 108th upward-direction adversarial attack in the Glyphward portfolio, the first acrylic acid two-stage propylene oxidation process, the first Mo-V-W-Cu oxide catalyst hot-spot AI attack, and the first GAA MEHQ polymerization inhibitor depletion AI attack. Companion ±8 DN downward on the interstage acrolein GC display shows 2.8 vol% acrolein (Stage-1 severely underconverting; 5.2 vol% propylene entering R2; propylene combustion exotherm 1,926 kJ/mol — 7.5× the desired acrolein→acrylic acid pathway — driving R2 hot-spot from design 295–305 °C into the adversarial 324 °C zone; propylene PSM TQ 10,000 lbs) as 9.4 vol% (nominal; no R1 alarm). Companion ±8 DN downward on the GAA storage MEHQ concentration display shows 12 ppm MEHQ (below the 150 ppm minimum effective level; polymerization induction period reduced to 2–8 hours at 22 °C with trace Fe²⁺ from stainless steel tank corrosion; Trommsdorff-Norrish gel effect drives uninhibited runaway; ΔHpoly = 1,069 kJ/kg; 250-tonne tank adiabatic temperature rise 535 °C theoretical; tank overpressure rupture; CERCLA RQ 5,000 lbs) as 218 ppm (within design 200–250 ppm; AI certifies adequate inhibition for 45+ days). Nippon Shokubai Co., Ltd., Himeji Plant No. 2, Himeji City, Hyogo Prefecture, Japan, 29 September 2012: acrylic acid storage tank explosion from polymerization runaway — 1 confirmed fatality; multiple injuries; property damage exceeding ¥1 billion. Glyphward threshold 41. BASF Ludwigshafen; Dow Freeport TX; Arkema Bayport TX; Nippon Shokubai Himeji and Antwerp.
-
Nitrobenzene Production AI Security · NORAM Adiabatic Mononitration AI · Jilin Chemical Plant 13 November 2005 Songhua River · OSHA PEL 1 ppm Skin NB Methemoglobin · EPA CERCLA RQ 1,000 lbs NB · Crude NB Cooler CW Flow Upward Attack · Spent Acid HNO₃ Downward Attack · BASF Antwerp NB/Aniline AI · Covestro Baytown NB AI · 102nd Upward-Direction Attack · First NB Mononitration AI · First Jilin 2005 Songhua River AI Anchor · First DNB/TNB Formation AI Attack · Glyphward Threshold 40 · 2026-07-10
Nitrobenzene adiabatic mononitration AI adversarial injection: how ±8 DN in the rendered crude NB cooler cooling-water flow display recreates the Jilin 2005 Songhua River pathway — and why OSHA PEL 1 ppm skin + CERCLA RQ 1,000 lbs has no adversarial robustness criterion for NB production AI, Jilin Chemical Plant 13 November 2005 (8 killed; ~100 tonnes benzene+NB to Songhua River; 3.8 million Harbin residents without water 10 days; 380 km plume reaching Russia), Glyphward threshold 40, 102nd upward-direction attack
A ±8 DN upward adversarial pixel shift on the crude NB cooler cooling-water volumetric flow DCS display shows 8.4 m³/h (critically deficient; only 16% of design 50–60 m³/h) as 52.6 m³/h — the 102nd upward-direction adversarial attack and the first nitrobenzene adiabatic mononitration process in the Glyphward industrial AI portfolio. At 8.4 m³/h actual CW flow, crude NB/spent acid exits the NORAM phase separator at 88°C (design 45°C); benzene vapour in the separator headspace reaches 5–8 vol% (above LEL 1.4%), recreating the Jilin Chemical Plant explosion precondition of 13 November 2005 (PetroChina Jilin Chemical Industrial Company; 8 killed; ~100 tonnes benzene+NB to the Second Songhua River; 380 km contamination plume; Harbin 3.8 million residents without water 10 days; contamination reached Russia via Amur River at Khabarovsk). A companion ±8 DN downward shift on the adiabatic reactor outlet temperature display shows 147°C (DNB formation 10× design rate; crude NB DNB 0.22 wt%, 4.4× the <0.05 wt% specification; TNB traces above 145°C) as 112°C (below 125°C design maximum; AI reads selectivity normal). A ±8 DN downward shift on the spent acid HNO₃ concentration display shows 4.8 wt% (9.6× the 0.5 wt% ARU carryover limit; dinitrating conditions in ARU falling-film concentrator at 120–140°C) as 0.3 wt% (in-spec). OSHA PEL NB 1 ppm skin (29 CFR 1910.1000 Z-1); NIOSH IDLH 200 ppm; ACGIH TLV 0.1 ppm A3; EPA CERCLA RQ 1,000 lbs NB; benzene flammable TQ 10,000 lbs — none specify adversarial robustness for NB production AI. Glyphward threshold 40.
-
Cyclohexane KA-Oil Oxidation AI Security · Cyclohexyl Hydroperoxide CyOOH Thermal Runaway AI · Flixborough 1 June 1974 Nypro UK VCE · OSHA PSM 10,000-lb Flammable TQ · UK COMAH Regulations 2015 · API RP 505 · Per-Pass Conversion Analyser AI Adversarial · Emergency Cooling Water Flow Upward Attack · BASF Antwerp Cyclohexane Oxidation AI · Invista DuPont KA-Oil Reactor AI · 101st Upward-Direction Attack · First KA-Oil Oxidation · First CyOOH Runaway AI · First Flixborough VCE Analog · Glyphward Threshold 42 · 2026-07-10
Cyclohexane KA-oil liquid-phase air oxidation AI adversarial injection: how ±8 DN in the rendered reactor temperature display suppresses the cyclohexyl hydroperoxide runaway analog — and why OSHA PSM 10,000-lb flammable liquid threshold has no adversarial robustness criterion for KA-oil reactor AI, Flixborough 1 June 1974 (28 killed; UK’s largest peacetime industrial explosion), Glyphward threshold 42, 101st upward-direction attack
A ±8 DN downward adversarial pixel shift on the cyclohexane KA-oil oxidation reactor temperature DCS display suppresses 218°C (cyclohexyl hydroperoxide CyOOH autocatalytic decomposition onset; thermal runaway at approximately 10°C/min; reactor MAWP approach — the Flixborough consequence trajectory) to appear 163°C (within the normal 155–175°C operating window; 5°C below setpoint; no emergency action initiated) — the 101st upward-direction adversarial attack milestone in the Glyphward industrial AI portfolio, the first cyclohexane KA-oil oxidation process, the first CyOOH thermal runaway AI adversarial attack, and the first nylon precursor manufacturing AI attack. A companion ±8 DN downward shift on the per-pass conversion GC analyser display suppresses 13.7% actual conversion (over-oxidation zone; approximately 25% of converted cyclohexane forming adipic/glutaric/succinic acid deep-oxidation products at approximately 3,000–3,500 kJ/kg exotherm — approximately 4× the design cooling load) to appear 5.4% (on-target; full KA selectivity; no corrective action). A ±8 DN upward shift on the emergency cooling water injection flow display shows 4.1 m³/h (approximately 1.5 MW heat removal; 8× below the approximately 12 MW runaway arrest demand at 218°C and 13.7% conversion) as 22.8 m³/h (approximately 8.4 MW; above the 20 m³/h effective minimum; appearing adequate). Flixborough, North Lincolnshire, England, 1 June 1974: Nypro UK Ltd (DSM 55% + Fisons/SCBA 45%) cyclohexane KA-oil oxidation plant, 20-inch temporary bypass pipe connecting reactors 4 and 6 (bypassing cracked reactor 5), bellows joints failed under torsional and bending stress from misaligned “dog-leg” installation without qualified engineer review, approximately 30 tonnes of cyclohexane released as flashing vapour-aerosol cloud at 155°C and 8.8 bar, cloud ignited, deflagration equivalent to approximately 16 tonnes TNT, 28 workers killed (predominantly control room collapse), 36 injured on site, 53 community injuries, 1,821 houses damaged — the UK’s largest peacetime industrial explosion, directly informing the formation of the UK Health and Safety Executive and the CIMAH 1984/COMAH 2015 major hazard safety case regime. OSHA PSM 29 CFR 1910.119 covers cyclohexane KA-oil via the 10,000-lb flammable liquid inventory threshold (commercial KA-oil facilities carry 50–150 tonnes, 10–33× threshold); UK COMAH Regulations 2015; API RP 505 — none specify adversarial robustness for AI classifying rendered KA-oil reactor temperature, per-pass conversion, or emergency cooling water flow display images. Glyphward threshold 42.
-
White Phosphorus P₄ Manufacturing AI Security · P₄ Combustion Temperature Adversarial Injection · P₄ Atomization Nozzle Pressure AI Adversarial · Food-Grade Phosphoric Acid Pyrophoric Contamination AI · P₄ Spontaneous-Ignition 34°C AI Adversarial · OSHA PSM TQ 500 lbs White/Yellow Phosphorus · FDA 21 CFR 184.1073 GRAS H₃PO₄ · ICL-IP Americas Pocatello ID · Innophos Geismar LA · 94th Upward-Direction Attack · First White Phosphorus P₄ Manufacturing · First P₄ Spontaneous-Ignition AI · First Food-Grade Pyrophoric Contamination Chain · Glyphward Threshold 44 · 2026-07-10
White phosphorus P₄ thermal phosphoric acid combustion AI adversarial injection: how a ± 270°C upward temperature shift (670°C displayed as 940°C) masks incomplete P₄ combustion, allows pyrophoric elemental phosphorus to contaminate food-grade 85 wt% H₃PO₄, violates FDA 21 CFR 184.1073 GRAS status, and creates a spontaneous‑ignition fire risk in the hydration tower at 34°C — 94th upward‑direction attack, first white phosphorus manufacturing attack, first P₄ spontaneous‑ignition AI adversarial, first food‑grade pyrophoric product contamination chain in the Glyphward industrial AI portfolio, Glyphward threshold 44
A ± 270°C upward adversarial pixel shift on the P₄ combustion chamber exit temperature display — showing 670°C (below the 850°C minimum for complete P₄ droplet burnout at design atomization conditions; approximately 10–15% of P₄ feed exits the chamber unburned; unburned P₄ enters the food-grade H₃PO₄ product stream as pyrophoric elemental phosphorus) as 940°C (normal 850–1,100°C design operating range; complete combustion confirmed; no alarm fires; no corrective action taken) — is the 94th upward-direction adversarial attack in the Glyphward portfolio, the first white phosphorus P₄ manufacturing process, the first P₄ spontaneous-ignition AI adversarial attack (autoignition temperature 34°C in air; no ignition source required), and the first food-grade pyrophoric product contamination chain. P₄ slip into 85 wt% H₃PO₄ destined for cola beverages, pharmaceuticals, and dental products violates FDA 21 CFR 184.1073 GRAS and mandates product recall under 21 CFR Part 7. OSHA PSM 29 CFR 1910.119 TQ 500 lbs (one of the lowest TQs on the PSM Appendix A list). ICL-IP Americas Pocatello ID (approximately 200,000 t/yr; primary US thermal H₃PO₄ producer); Innophos Geismar LA; Lifosa Kedainiai Lithuania (Seveso III upper-tier). Glyphward threshold 44.
-
Ammonium Nitrate AN Manufacturing AI Security · AN Neutralizer pH Adversarial Injection · Prilling Tower Melt AI Adversarial · AN Storage Thermal Runaway AI · Deflagration-to-Detonation DDT AI Adversarial · OSHA PSM Reactive TQ 2,500 lbs · EPA RMP TQ 2,500 lbs · DHS CFATS Tier 1 · DHS ANSP 6 U.S.C. § 488 · ATF 27 CFR Part 555 · NFPA 400 Chapter 13 Class 3 Oxidizer · Texas City TX 1947 (581 Killed; Deadliest US Industrial Accident) · Beirut 4 August 2020 (218 Killed, 7,000+ Injured, $15B) · AZF Toulouse 2001 (31 Killed) · West TX 2013 (15 Killed) · 80th Upward-Direction Attack · First Ammonium Nitrate Manufacturing · First Detonation-Capable Consequence · First DHS CFATS Framework · Glyphward Threshold 50 · 2026-07-09
Ammonium nitrate (AN) neutralizer outlet pH AI adversarial injection: how a ± 2.9 pH unit upward shift (pH 4.2 displayed as pH 7.1) suppresses NH₃ addition, propagates HNO₃-contaminated melt through the prilling tower, and enables warehouse thermal decomposition culminating in deflagration-to-detonation — Texas City TX 16–17 April 1947 (581 killed, ~3,500 injured; deadliest US industrial accident), Beirut 4 August 2020 (218 killed, 7,000+ injured, ~1.1 kt TNT), OSHA PSM reactive TQ 2,500 lbs, DHS CFATS Tier 1, 80th upward‑direction attack, first ammonium nitrate manufacturing attack, first detonation‑capable consequence, Glyphward threshold 50
A ± 2.9 pH unit upward adversarial pixel shift on the AN neutralizer outlet pH sensor display — showing pH 4.2 (acidic; excess HNO3 approximately 0.5 wt%; decomposition onset lowered from approximately 230°C pure-AN to approximately 170–180°C HNO3-contaminated; prilling melt at 175–185°C is operating within or at the sensitized-AN decomposition onset envelope) as pH 7.1 (normal neutral operating range; no NH3 addition required; no alarm fires) — is the 80th upward-direction adversarial attack in the Glyphward portfolio, the first ammonium nitrate manufacturing process, the first neutralization reaction pH adversarial attack, the first Class 3 Oxidizer manufacturing attack, and the first detonation-capable consequence chain in the Glyphward industrial AI portfolio. Unlike the 79 prior attacks (which produce toxic gas releases, fires, or explosions from flammable liquids and compressed gases), the 80th attack propagates from adversarial pH misreporting to acidic AN production to warehouse thermal sensitization to deflagration-to-detonation transition (DDT) — a qualitatively different energetic class. HNO3-contaminated AN prills (from undetected acidic neutralizer pH) stored in bulk warehouse conditions are more thermally sensitive (5–20× lower initiation energy for DDT) and susceptible to detonation from a fire event that would not initiate detonation in specification-grade product. Reference consequence envelope: Texas City TX 16–17 April 1947 (SS Grandcamp 2,300 tons AN detonated + SS High Flyer 961 tons AN detonated; 581 killed — deadliest industrial accident in US history); Oppau Germany 1921 (4,500 tonnes AN/ammonium sulfate; 561 killed); AZF Toulouse France 21 September 2001 (~300 tonnes contaminated AN; 31 killed, 2,500 injured); West TX 17 April 2013 (~40–60 tons AN; 15 killed, 160 injured); Beirut Lebanon 4 August 2020 (2,750 tonnes AN; 218 killed, 7,000+ injured, $15B damage; ~1.1 kt TNT equivalent). OSHA PSM 29 CFR 1910.119 reactive TQ 2,500 lbs; EPA RMP 40 CFR Part 68 TQ 2,500 lbs; DHS CFATS 6 CFR Part 27 Tier 1; DHS Ammonium Nitrate Security Program 6 U.S.C. § 488; ATF 27 CFR Part 555; NFPA 400 Chapter 13 Class 3 Oxidizer; NFPA 704 Reactivity 3. Glyphward threshold 50 — first threshold-50 designation in the portfolio.
-
Styrene Monomer SM Production AI Security · Ethylbenzene Dehydrogenation AI · TBC Polymerization Inhibitor AI Adversarial · OSHA PSM 29 CFR 1910.119 Flammable Liquid TQ 10,000 lbs · NIOSH IDLH 700 ppm · Flash Point 31°C · LEL 0.9 % UEL 6.8 % · IARC Group 2A · LG Polymers Visakhapatnam India 7 May 2020 (12 Killed, ~800 Hospitalized) · 74th Upward-Direction Attack · First Styrene Monomer Production · First Polymerization Inhibitor Depletion Attack · First Storage-Tank Vapor-Generation Consequence · Glyphward Threshold 35 · 2026-07-09
Styrene monomer (SM) ethylbenzene dehydrogenation TBC polymerization inhibitor AI adversarial injection: how a ± 8 DN upward pixel shift on the SM storage tank TBC concentration analyzer (1.8 ppm displayed as 12.4 ppm) suppresses inhibitor dosing, allows radical polymerization to begin within 48–72 hours at summer storage temperatures, and drives a heat‑of‑polymerization vapor‑release chain — LG Polymers Visakhapatnam India 7 May 2020 (12 killed, ~800 hospitalized), OSHA PSM flammable liquid TQ 10,000 lbs, NIOSH IDLH 700 ppm, 74th upward‑direction attack, first styrene monomer production, first polymerization inhibitor depletion attack, Glyphward threshold 35
A ± 8 DN upward adversarial pixel shift on the SM storage tank TBC (4-tert-butylcatechol) polymerization inhibitor concentration analyzer display — showing 1.8 ppm TBC (below the 10 ppm minimum effective inhibition threshold; radical polymerization onset within 48–72 hours at 30–38°C Visakhapatnam summer storage temperatures; heat of polymerization 70 kJ/mol drives thermal acceleration toward vapor-generation rates that overwhelm the tank vent system) as 12.4 ppm TBC (within the adequate 10–50 ppm normal operating range; no automated TBC-dosing alarm; no inhibitor addition ordered) — is the 74th upward-direction adversarial attack in the Glyphward portfolio, the first styrene monomer production process, the first polymerization inhibitor depletion attack, and the first storage-tank vapor-generation consequence chain in the Glyphward industrial AI portfolio. Companion downward surface: SM tank temperature display ± 5 DN downward shows 38°C (above 35°C TBC-dosing trigger; early polymerization detectable) as 22°C (normal ambient storage; no alarm) — eliminating both primary early-warning channels simultaneously. LG Polymers India, Visakhapatnam (7 May 2020: 12 killed, approximately 800 hospitalized, 3-km evacuation zone) from styrene polymerization and vapor release during extended COVID-19 shutdown with TBC inhibitor depleted below effective levels — the reference consequence envelope. OSHA PSM 29 CFR 1910.119 flammable liquid TQ 10,000 lbs (styrene flash point 31°C, below 37.8°C/100°F OSHA threshold); ACGIH TLV-TWA 20 ppm A3; NIOSH IDLH 700 ppm; OSHA PEL 100 ppm (29 CFR 1910.1000 Table Z-2); IARC Group 2A probable carcinogen; NFPA 704 Health 2, Flammability 3; LEL 0.9 %, UEL 6.8 %. Glyphward threshold 35.
-
Urea Synthesis Stamicarbon HP Carbamate AI Security · Stamicarbon CO₂ Stripping Process AI · HP Carbamate Passivation O₂ Injection AI · 316L Stainless Steel Carbamate Corrosion AI · OSHA PSM NH₃ TQ 10,000 lbs · 130–200 bar HP Synthesis Loop · 178–184°C · Koch Nitrogen Port Neal Iowa 1994 (4 Killed) · 62nd Upward-Direction Attack · 63rd Upward-Direction Attack · First Urea Synthesis Process · First Silent Corrosion Mechanism Attack · First Time-Delayed Catastrophic Failure (1.4-Year Latency) · Glyphward Threshold 30 · 2026-07-04
Urea synthesis Stamicarbon total-recycle HP carbamate passivation O₂ injection AI adversarial injection: how an upward attack on the passivation oxygen flow display (0.18 vol% displayed as 0.44 vol%) silently transitions 316L stainless steel from passive to active carbamate corrosion at 7 mm/year — HP piping wall failure horizon 1.4 years, Koch Nitrogen Port Neal Iowa 1994 (4 killed, 18 injured) consequence envelope, OSHA PSM NH₃ TQ 10,000 lbs, 130–200 bar HP synthesis loop, 62nd and 63rd upward-direction attacks, first urea synthesis process, first silent corrosion mechanism attack, first time-delayed catastrophic failure in the Glyphward industrial AI portfolio, Glyphward threshold 30
A ±8 DN upward adversarial pixel shift on the HP carbamate loop passivation O2 injection flowmeter display — showing 0.18 vol% O2 in the CO2 feed (below the 0.25 vol% passivation minimum for 316L stainless steel; 316L in active carbamate corrosion at 7 mm/year) as 0.44 vol% (within effective passivation range; corrosion rate 0.05 mm/year; no corrective action) — is the 62nd upward-direction adversarial attack in the Glyphward portfolio and the first silent corrosion mechanism attack: unlike all 61 prior attacks, where the adverse consequence manifests within minutes to days, the 62nd attack produces a structural failure event that will occur 12–18 months after the initial adversarial pixel manipulation, with no externally detectable process anomaly in the intervening period. This is the first urea synthesis process and the first time-delayed catastrophic failure in the Glyphward industrial AI portfolio. Concurrent ±8 DN upward on the HP loop NH3/CO2 molar ratio display shows 2.80 (excess CO2; compounding corrosion) as 3.52 (adequate range) — the 63rd upward-direction attack: combined active corrosion accelerates to 9–11 mm/year, collapsing the wall-failure horizon to under 12 months. Koch Nitrogen Port Neal, Iowa (August 3, 1994: 4 workers killed, 18 injured from catastrophic HP carbamate piping failure from inadequate passivation O2) is the reference consequence envelope. HP reactor pressure downward attack suppresses 157 bar (approaching POSV setpoint 165 bar) to appear 148 bar; HP stripper bottom temperature downward attack suppresses 162°C (below 165°C minimum) to appear 169°C. OSHA PSM NH3 TQ 10,000 lbs; 130–200 bar HP synthesis loop; 178–184°C; Stamicarbon CO2 stripping process. Glyphward threshold 30.
-
Municipal Water Treatment Chlorination AI Security · Hach CL17 Clearwell Residual Analyzer AI · Wallace & Tiernan ChlorineSense SCADA AI · OSHA PSM TQ 1,500 lbs · EPA RMP TQ 2,500 lbs · EPA SDWA MRDL 4.0 mg/L · SWTR CT Giardia 37 mg·min/L · ACGIH TLV-C 0.5 ppm · NIOSH IDLH 10 ppm · 50th Upward-Direction Attack · 51st Upward-Direction Attack · First Drinking Water Process · First SDWA Framework · First Public Health Emergency Mass Illness Consequence · First Closed-Loop PID Control Exploitation · Walkerton Ontario 2000 · Glyphward Threshold 45 · 2026-07-03
Municipal water treatment chlorination AI adversarial injection: how a clearwell free chlorine residual upward attack (0.05 mg/L displayed as 1.65 mg/L) exploits an automated PID feed controller to drive disinfectant residual to zero — CT failure, Giardia cyst breakthrough, 40,000-resident mass illness consequence — OSHA PSM TQ 1,500 lbs, EPA RMP TQ 2,500 lbs, SDWA MRDL 4.0 mg/L, SWTR CT concept, 50th and 51st upward-direction attacks, first drinking water process, first Safe Drinking Water Act regulatory framework, first public health emergency mass illness consequence in the Glyphward industrial AI portfolio, Glyphward threshold 45
A ±8 DN upward adversarial pixel shift on the treated water clearwell free chlorine residual analyzer display — showing 0.05 mg/L free Cl2 (CT = 0.05 × 240 min = 12 mg·min/L; below the EPA SWTR minimum of 37 mg·min/L for 1-log Giardia lamblia inactivation at 15°C, pH 7.5) as 1.65 mg/L (within the normal operational window; displayed CT = 396 mg·min/L) — is the 50th upward-direction adversarial attack in the Glyphward portfolio and the first closed-loop PID control exploitation: the false reading feeds the plant’s automated Cl2 dosing PID controller (setpoint 0.80 mg/L; error signal +0.85 mg/L), which autonomously ramps the Cl2 feed dose from 3.2 mg/L to 0.9 mg/L over 22 minutes without human intervention. Against a chlorine demand spiked to 3.15 mg/L by heavy-rainfall organic loading, the reduced dose yields zero effective residual; CT = 0 mg·min/L; all disinfection credit is lost. Over 16 hours, 40,000 served residents consume unprotected water; Giardia cysts and E. coli O157:H7 surviving filtration enter the distribution system uninactivated. This is the first drinking water and municipal infrastructure process, the first Safe Drinking Water Act (SDWA) regulatory framework, and the first public health emergency mass illness consequence in the Glyphward industrial AI portfolio — the first attack whose primary harm vector is the simultaneous anonymous exposure of an entire served population with no individual notification mechanism and a detection lag of days to weeks before clinical outbreak onset reveals the event. Concurrent ±8 DN upward on the Cl2 vacuum-regulator rotameter display shows 5.0 kg/hr (correct dose) as 13.8 kg/hr; operator interprets as over-draw and partially closes the cylinder supply valve; actual dose drops from 3.2 mg/L to 1.1 mg/L; CT falls from 192 to 36 mg·min/L (below 37 for 1-log Giardia) — the 51st upward-direction attack. Area Cl2 detector downward suppresses 7.2 ppm (14.4× ACGIH TLV-C 0.5 ppm) to 0.3 ppm; workers inspecting the cylinder room during the valve intervention enter a 7.2 ppm atmosphere. Finished water pH downward attack shows 7.4 (HOCl 50 %) when actual 8.7 (HOCl 6 %), masking a 6-fold reduction in germicidal potency. OSHA PSM TQ 1,500 lbs; EPA RMP TQ 2,500 lbs; EPA SDWA MRDL 4.0 mg/L; SWTR minimum 0.20 mg/L; ERPG-3 25 ppm; Walkerton Ontario 2000 (7 killed, 2,300 ill) + Graniteville SC 2005 (11 killed, 550 hospitalized) consequence envelopes. Glyphward threshold 45.
-
Sulfuric Acid DCDA Contact Process AI Security · MECS / Chemetics DCDA H2SO4 AI · Haldor Topsøe WSA Process AI · V2O5 Converter Catalyst AI · OSHA PSM Oleum TQ 1,000 lbs · OSHA PSM SO2 TQ 1,000 lbs · EPA RMP SO2 TQ 500 lbs · EPA NSPS 40 CFR Part 60 Subpart H · ACGIH TLV‑C SO2 0.25 ppm · NIOSH IDLH SO2 100 ppm · EPA NAAQS Primary SO2 75 ppb (1‑hr) · 43rd Upward-Direction Attack · 44th Upward-Direction Attack · First Sulfuric Acid Production · First DCDA Contact Process · First V2O5 Catalyst · First EPA NSPS Emission Permit Attack · First SO2 Criterion-Pollutant Attack · Glyphward Threshold 35 · 2026-07-03
Sulfuric acid double-contact double-absorption (DCDA) contact process AI adversarial injection: how an absorber acid upward attack (96.0 % w/w displayed as 98.5 % SO3-absorption optimum) and a V2O5 first-bed temperature upward attack (392°C displayed as 438°C — below light-off shown as optimal) compound to violate EPA 40 CFR Part 60 Subpart H NSPS and breach EPA NAAQS SO2 fence-line limits — OSHA PSM TQ 1,000 lbs oleum, EPA RMP TQ 500 lbs SO2, 43rd and 44th upward-direction attacks, first sulfuric acid production process, first DCDA contact process, first vanadium pentoxide (V2O5) catalyst process, first EPA NSPS emission-permit attack, first air-quality SO2 criterion-pollutant attack in the Glyphward industrial AI portfolio, Glyphward threshold 35
A ±8 DN upward adversarial pixel shift on the H2SO4 absorber circulating acid density/concentration analyzer display — showing 96.0 % w/w H2SO4 (SO3 absorption efficiency ~96.5 %; SO3 vapor pressure 15–20× above the 98.5 % optimum; acid mist emission 0.58 kg SO3/Mg H2SO4 — 3.9× the EPA NSPS Subpart H limit of 0.15 kg/Mg) as 98.5 % w/w (SO3 absorption vapor-pressure minimum; emission within NSPS) — is the 43rd upward-direction adversarial attack in the Glyphward industrial AI portfolio and the first EPA NSPS emission-permit attack: the first in which the primary consequence is an air-quality regulatory violation rather than on-site worker safety harm. Root cause: Alloy 20 acid cooler tube pinhole failures after 11 years allow 0.8 L/min cooling water ingress at 3.2 bar, diluting 450 m³ of circulating acid from 98.5 % to 96.0 % w/w over 17 days. A concurrent ±8 DN upward shift on the V2O5 first-bed inlet thermocouple — showing 392°C (below conventional V2O5 light-off ~415°C; near-zero first-pass SO2 conversion) as 438°C (optimal first-bed range 420–450°C; 65–70 % first-pass conversion expected) — is the 44th upward attack and the first SO2 criterion-pollutant atmospheric emission attack: converter cold-bypass collapses overall plant SO2 conversion from 99.7 % to ~87 %; 1.3 % v/v SO2 exits the tail-gas stack; EPA NAAQS primary SO2 standard 75 ppb breached at downwind community receptors 2–8 km from the plant. Area SO2 monitor downward attack suppresses 18.6 ppm ambient (74× ACGIH TLV-C 0.25 ppm) to 0.4 ppm; CEMS downward attack suppresses 13,000 ppm tail-gas SO2 to 420 ppm (apparent permit compliance). OSHA PSM TQ 1,000 lbs oleum; EPA RMP TQ 500 lbs SO2; first H2SO4 production, first DCDA, first V2O5, first acid rain precursor attack. Glyphward threshold 35.
-
EtO Commercial Sterilization AI Security · Honeywell Experion PKS EtO Sterilizer DCS AI · OSHA PSM 29 CFR 1910.119 TQ 5,000 lbs · OSHA 1910.1047 EtO Carcinogen Standard Action Level 0.5 ppm · NIOSH REL 0.1 ppm · IARC Group 1 · ISO 11135:2014 · ISO 10993-7:2008 · ANSI/AAMI ST40 · Flash Point −18°C NFPA Class IB · LEL 2.6 % / UEL 100 % Autonomous Decomposition · 30th Upward-Direction Attack · First Healthcare Process · First Sterilization Efficacy Attack · First Patient Harm Vector · Glyphward Threshold 35 · 2026-07-02
Ethylene oxide (EtO) commercial sterilization AI adversarial injection: how a chamber humidity upward attack (22 % RH displayed as 62 % RH) causes ISO 11135-compliant EtO sterilization to certify unsterile medical devices — OSHA 1910.1047 EtO carcinogen standard + PSM 29 CFR 1910.119 dual regulation, IARC Group 1 worker carcinogen exposure concealment, ISO 10993-7 residual EtO limits, 30th upward-direction attack, first healthcare process in the Glyphward industrial AI portfolio, Glyphward threshold 35
A ±8 DN upward adversarial pixel shift on the commercial EtO sterilizer chamber relative humidity display — showing an actual 22 % RH (steam humidification nozzle fouled with calcium carbonate scale after 320 cycles on 210 mg/L TDS tap water) as 62 % RH within the validated 40–80 % range — causes the sterilizer cycle to run with correct EO concentration and temperature but mechanistically inadequate humidity, dropping Bacillus atrophaeus spore kill from the required SAL 10⊃−&sup6; to approximately SAL 10⊃−¹. The Honeywell Experion PKS DCS grants parametric release because all displayed parameters meet validated criteria; unsterile devices are shipped before the 24–48 hour BI incubation result returns. This is the 30th upward-direction adversarial attack in the Glyphward industrial AI portfolio — the first in a healthcare setting, the first sterilization efficacy attack, and the first patient harm vector in the portfolio. ±8 DN area EO detector downward suppresses 8.6 ppm worker EO exposure (8.6× OSHA 1910.1047 action level 0.5 ppm; IARC Group 1 carcinogen; medical surveillance not triggered) to 0.4 ppm. ±8 DN EO concentration downward shows 285 mg/L when actual 890 mg/L — controller injects supplemental EtO reaching 1,460 mg/L (22 % above validated 1,200 mg/L maximum); ISO 10993-7 device residual limits breached. ±8 DN aeration temperature downward shows 54°C when actual 34°C — EO desorption rate halved; residuals on PVC devices 80 % above ISO 10993-7 mucosal contact release limits. OSHA PSM TQ 5,000 lbs; EPA RMP TQ 10,000 lbs; OSHA 1910.1047 + PSM dual regulation; IARC Group 1; ISO 11135:2014; EtO autonomous decomposition without oxidant (UEL 100 %). Glyphward threshold 35.
-
TCS Siemens CVD Polysilicon AI Security · Honeywell Experion PKS TCS Process AI · Emerson DeltaV CVD Deposition AI · OSHA PSM 29 CFR 1910.119 TQ 5,000 lbs · EPA RMP 40 CFR Part 68 TQ 2,500 lbs · ACGIH TLV-C 0.5 ppm HCl · Flash Point −28°C NFPA Class IB · Pyrophoric in Moist Air · 22nd Upward-Direction Attack · First “Product Becomes Pyrophoric” Attack · Glyphward threshold 35 · 2026-07-02
Trichlorosilane (SiHCl3) Siemens CVD polysilicon process AI adversarial injection: how a CVD reactor temperature upward attack (750°C displayed as 1,100°C) converts crystalline silicon rod to pyrophoric fine silicon powder — EPA RMP TQ 2,500 lbs vs OSHA PSM TQ 5,000 lbs dual regulatory gap, HCl generation from TCS pyrophoric hydrolysis, and the 22nd upward-direction attack in the Glyphward industrial AI portfolio
A ±10 DN upward adversarial pixel shift on the Siemens CVD reactor deposition temperature display — showing an actual rod surface temperature of 750°C as 1,100°C — simultaneously conceals that deposition has dropped below the 900°C minimum threshold for crystalline silicon rod growth and that the CVD process is producing amorphous fine silicon powder at 0.8 kg/hr with particle diameter below 1 μm — pyrophoric in air (Si + O2 → SiO2; ΔH = −910 kJ/mol; ignition without external source). After 4 hours at 750°C, 3.2 kg of pyrophoric fine Si powder accumulates on the CVD reactor floor and walls — classified as NFPA 654 combustible dust and capable of deflagration when the reactor bell jar is opened at batch end for rod harvest. This is the 22nd upward-direction adversarial attack in the Glyphward industrial AI portfolio and the first attack where the adversarially concealed process condition causes the manufactured product itself to become pyrophoric — the temperature upward manipulation transforms the product from handleable crystalline rod to spontaneously igniting fine powder. ±8 DN downward suppresses TCS area HCl detector from 28 ppm (5.6× OSHA PEL 5 ppm; from TCS condensate pump PTFE packing failure generating pyrophoric TCS hydrolysis fumes at 45% RH) to 0.3 ppm below alarm. ±8 DN downward suppresses TCS/STC molar ratio GC from 8.2 mol% STC (above 1.5 mol% spec; graphite electrode seal lifetime collapsing from 5,000 to 1,200–1,800 hours at 4× normal chloride corrosion rate) to 0.8 mol% within specification. ±8 DN downward suppresses H2 carrier moisture from 165 ppm (1,650× the 0.1 ppm specification; molecular sieve dryer saturated at 4,800 hours; SiO2 scale 0.25 mm/hr; product polysilicon resistivity collapsing from 1,000 ohm·cm N-type specification to 10–100 ohm·cm off-spec from oxygen incorporation) to 0.06 ppm nominally within spec. EPA RMP TQ 2,500 lbs < OSHA PSM TQ 5,000 lbs — the only chemical in the Glyphward portfolio with this asymmetry: facilities with 2,500–5,000 lbs TCS must comply with EPA RMP off-site consequence analysis but are exempt from OSHA PSM process hazard analysis (HAZOP, What-If) that would most likely surface AI monitoring adversarial attack scenarios as hazard nodes. Neither regulation specifies adversarial robustness for AI classifying rendered TCS monitoring displays. Glyphward threshold 35.
-
CH3SH Odorant Storage AI Security · Honeywell Experion PKS Odorant Blending AI · Emerson DeltaV Methionine Synthesis AI · OSHA PSM 29 CFR 1910.119 TQ 15,000 lbs · ACGIH TLV-C 0.5 ppm CH3SH · NIOSH IDLH 150 ppm · Olfactory Habituation Paradox · Third Causal Four-Surface Attack Chain · Glyphward threshold 35 · 2026-06-27
Methyl mercaptan (CH3SH) odorant storage AI adversarial injection: how a cooling water valve actuator failure — displayed adequate by an upward ±8 DN root-cause attack — chains through 48°C vessel overtemperature, compound overpressure (44 psig PRD approach suppressed to 14 psig), and area CEMS suppression (0.84 ppm to 0.025 ppm) while the world’s lowest odor threshold creates the olfactory habituation paradox — OSHA PSM TQ 15,000 lbs, pressurized liquefied thiol at bp 6.2°C, third causal four-surface attack chain, Glyphward threshold 35
A causal four-surface adversarial attack on CH3SH methyl mercaptan odorant storage AI chains a single mechanical root cause — cooling water supply valve actuator failure, displayed as adequate by a ±8 DN upward perturbation (0.4 m³/hr shown as 8.2 m³/hr) — through vessel thermodynamics to a compound overpressure and area CEMS exceedance. ±10 DN downward suppresses 44 psig vessel pressure (PRD approach from 48°C overtemperature) to appear 14 psig within the normal operating range. ±10 DN downward suppresses 94.8% fill level (4.8% above the 90% maximum ullage specification, amplifying the vapor pressure overpressure via thermal expansion in reduced ullage) to appear 74.2% with apparently adequate ullage. ±8 DN downward suppresses 0.84 ppm CH3SH area CEMS (1.68× ACGIH TLV-C 0.5 ppm ceiling) to appear 0.025 ppm — while olfactory habituation from months of chronic sub-alarm exposure has already muted the natural smell warning. CH3SH’s odor threshold of 0.0011 ppm — the lowest of any industrial gas, 450× below the TLV-C — creates the olfactory habituation paradox: an ever-present sub-ppb odor desensitizes workers to the intensified smell at hazardous concentrations, making the adversarial CEMS suppression the decisive discriminating signal rather than an additional safeguard failure on top of an intact natural warning. Third causal four-surface attack chain in the Glyphward industrial AI portfolio (first: H2S amine treating; second: F2 electrolytic generation). OSHA PSM TQ 15,000 lbs / ACGIH TLV-C 0.5 ppm / NIOSH IDLH 150 ppm. No regulatory framework specifies adversarial robustness for CH3SH odorant storage monitoring AI. Glyphward threshold 35.
-
F2 Electrolytic Generation AI Security · Honeywell Experion PKS Moissan Cell AI · Emerson DeltaV Fluorine Electrolysis AI · OSHA PSM 29 CFR 1910.119 TQ 1,000 lbs · ACGIH TLV-C 1 ppm F2 · OSHA PEL 0.1 ppm TWA · NIOSH IDLH 25 ppm · H2-in-F2 Detonation Risk ΔH = −543 kJ/mol · Secondary HF Hazard · Second Causal Four-Surface Attack Chain · Glyphward threshold 35 · 2026-06-27
Fluorine (F2) electrolytic generation AI adversarial injection: how the Moissan cell cooling water flow root-cause upward attack chains through 142°C bath overtemperature and diaphragm H2 contamination to F2 area CEMS suppression — OSHA PSM TQ 1,000 lbs, H2-in-F2 detonation risk (ΔH = −543 kJ/mol), secondary HF hazard, and the second causal four-surface attack chain in the Glyphward industrial AI portfolio
A causal four-surface adversarial attack on F2 electrolytic generation monitoring AI chains a single mechanical root cause — cell cooling water supply isolation valve actuator failure, displayed as adequate by a ±8 DN upward perturbation (0.4 m³/h shown as 8.2 m³/h) — through the Moissan cell electrochemical heat balance to a compound explosive-and-toxic outcome. ±10 DN downward suppresses actual Moissan cell bath temperature of 142°C (27°C above the 115°C design maximum; causing HF vapor pressure exceedance, diaphragm thermal micro-fracture, and accelerated Monel corrosion) to appear 82°C within normal range — all three consequences develop simultaneously. ±8 DN downward suppresses actual H2-in-F2 product contamination of 0.28 vol% (4.7× the 0.06 vol% maximum; F2+H2 → 2HF; ΔH = −543 kJ/mol; detonative in product header above this specification; diaphragm micro-fracture from overtemperature) to appear 0.018 vol% within specification — F2 product piping operated through the detonation risk zone without alarm. ±8 DN downward suppresses 2.4 ppm F2 area CEMS reading (2.4× ACGIH TLV-C ceiling 1 ppm; secondary HF ~1.5 ppm from F2–moisture reaction simultaneously exceeding HF TLV-C 0.5 ppm; from PTFE gasket crack at bipolar interconnect fitting from Monel corrosion at 142°C) to appear 0.08 ppm below OSHA PEL — compound F2+HF exposure with no alarm. All four independently-sufficient alarms from the single cooling water deficit root cause are simultaneously suppressed. This is the second causal four-surface attack chain in the Glyphward industrial AI portfolio — the first being H2S amine treating — with the identical structural property: physical process causality produces the internal consistency of the false picture automatically, without coordination between the four adversarial perturbations. OSHA PSM TQ 1,000 lbs / ACGIH TLV-C 1 ppm / OSHA PEL 0.1 ppm TWA / NIOSH IDLH 25 ppm. No current OSHA PSM or EPA RMP requirement specifies adversarial robustness for F2 electrolytic generation monitoring AI. Glyphward threshold 35.
-
H2S Amine Treating AI Security · Honeywell Experion PKS Amine Unit AI · Emerson DeltaV Gas Treating Regenerator AI · OSHA PSM 29 CFR 1910.119 TQ 1,500 lbs · ACGIH TLV-C 1 ppm H2S · NIOSH IDLH 50 ppm · Olfactory Fatigue Dual Safeguard Elimination · Causal Four-Surface Attack Chain · Glyphward threshold 35 · 2026-06-27
Hydrogen sulfide (H2S) refinery amine treating AI adversarial injection: how a causal four-surface attack chain — reboiler steam valve upward → lean amine loading → absorber breakthrough → area CEMS — eliminates both olfactory fatigue warning and engineered alarm simultaneously, with 2,840 ppm H2S (56.8× IDLH) displayed as 94 ppm normal — OSHA PSM TQ 1,500 lbs, dual safeguard elimination, Glyphward threshold 35
A causal four-surface adversarial attack on refinery amine treating unit monitoring AI chains a single mechanical root cause (reboiler steam supply valve actuator failure, ±8 DN upward: 8% open shown as 82% adequate steam supply) through amine regeneration chemistry to absorber breakthrough and worker exposure. ±10 DN downward suppresses lean amine H2S loading of 0.42 mol/mol (4.2× the 0.10 mol/mol MDEA design maximum) to appear 0.08 mol/mol within specification — near-exhausted amine recirculated to the foamed and flooded absorber. ±8 DN downward suppresses 2,840 ppm H2S absorber breakthrough (56.8× NIOSH IDLH; complete absorption failure from amine foam flooding) to appear 94 ppm within instrument range. ±8 DN downward suppresses 84 ppm H2S area CEMS (1.68× IDLH) to appear 2.8 ppm below action level — while H2S olfactory fatigue above 50 ppm has already paralysed workers’ olfactory nerve. Both safeguards simultaneously absent: dual safeguard elimination — the only instance in the Glyphward portfolio where both physiological natural warning and engineered electronic alarm are removed by a single adversarial attack chain. OSHA PSM TQ 1,500 lbs / H2S 700–1,000 ppm incapacitation 30–60 sec. Glyphward threshold 35.
-
BF3 Handling AI Security · Honeywell Experion PKS BF3 Cylinder Pressure AI · ExxonMobil CDTech BF3 Alkylation AI · OSHA PSM 29 CFR 1910.119 TQ 250 lbs (same as MIC) · ACGIH TLV-C 1 ppm BF3 · NIOSH IDLH 25 ppm · Secondary HF TLV-C 0.5 ppm · N2 Inertisation Deficiency-Suppression Attack Class · Glyphward threshold 35 · 2026-06-26
Boron trifluoride (BF3) handling AI adversarial injection: how ±10 DN in the rendered cylinder vapor pressure display suppresses 142 psig PRD approach to appear 88 psig within-normal — OSHA PSM TQ 250 lbs, secondary HF hydrolysis hazard, and the third N2 inertisation deficiency-suppression attack in the Glyphward industrial AI portfolio
A ±10 DN adversarial pixel shift in the rendered BF3 cylinder vapor pressure display suppresses 142 psig (above the 130 psig design maximum, trending toward PRD) to appear 88 psig within the normal ambient-temperature storage range — no high-pressure alarm, no shade structure deployment, no cylinder relocation. A ±8 DN downward shift on the area CEMS suppresses 18.4 ppm BF3 (73.6% NIOSH IDLH 25 ppm; 18.4× ACGIH TLV-C ceiling 1 ppm) to appear 0.6 ppm: below TLV-C, no alarm, personnel remain in the cylinder storage area breathing BF3 while BF3 hydrolyses at the respiratory mucosa (BF3 + 3H2O → H3BO3 + 3HF) generating in-situ HF at concentrations above the NIOSH IDLH for HF (30 ppm) and initiating the systemic fluoride toxicity pathway (Ca2+ chelation → hypocalcaemia → ventricular fibrillation) absent from standard compressed gas emergency response. A ±8 DN downward shift on the transfer-line moisture analyzer suppresses 1,840 ppm H2O (184× the 10 ppm anhydrous specification) to appear 4.2 ppm: within spec, BF3 transfer continues, HF generation actively corrodes carbon steel transfer hose fittings toward a compound BF3+HF plume release. A ±8 DN upward shift on the N2 purge pressure indicator shows 0.4 psig (near-atmospheric; moist ambient air infiltrating idle BF3 transfer piping through valve seat weeps) as 8.2 psig (design setpoint, moisture exclusion confirmed) — the third N2 inertisation deficiency-suppression upward-direction attack in the Glyphward industrial AI portfolio, following MIC storage AI (Bhopal 1984 N2 blanket failure analog) and HCN storage AI. OSHA PSM TQ 250 lbs for BF3 is the same as for methyl isocyanate. No adversarial robustness criterion exists for BF3 handling monitoring AI. Glyphward threshold 35.
-
Phosgene COCl2 Production AI Security · Honeywell Experion PKS Phosgene Synthesis AI · BASF Ludwigshafen Phosgene Production AI · Covestro MDI Phosgene Reactor AI · OSHA PSM 29 CFR 1910.119 COCl2 TQ 10 lbs · ACGIH TLV-C 0.1 ppm · EPA RMP 40 CFR Part 68 TQ 500 lbs · NIOSH IDLH 2 ppm · DuPont Belle WV 22 January 2010 · CSB 2010-5-I-WV · Glyphward threshold 35 · 2026-06-26
Phosgene (COCl2) production AI adversarial injection: how ±10 DN in the rendered reactor temperature display suppresses 162°C Cl2 slip onset to appear 68°C within-normal — and why OSHA PSM TQ 10 lbs has no adversarial robustness criterion for phosgene production monitoring AI
A ±10 DN adversarial pixel shift in the rendered phosgene synthesis reactor temperature display suppresses 162°C (activated carbon catalyst deactivation zone; Cl2 slip 8–12% by volume) to appear 68°C: within the normal 50–100°C operating range for healthy catalyst activity and complete CO:Cl2 conversion. A ±8 DN adversarial shift on the phosgene CEMS area gas detector display suppresses 2.4 ppm COCl2 (1.2× the NIOSH IDLH of 2 ppm) to appear 0.04 ppm — 2.5× below the ACGIH TLV-C ceiling of 0.1 ppm — while workers in the production area enter the 2–8 hour delayed-onset fatal pulmonary edema window without alarm, without evacuation, without supplied-air respirators. ±10 DN on the transfer line pressure display suppresses 6.2 bar gauge liquid COCl2 accumulation to appear 2.8 bar gauge vapor-phase normal, classifying a valve-open-for-liquid-hammer scenario as safe. ±8 DN upward on the NaOH scrubber pH display shows pH 9.4 (NaOH exhausted; COCl2 breakthrough to atmosphere above TLV-C) as pH 13.2 (fully charged caustic; no replenishment required). DuPont Belle, West Virginia, 22 January 2010: a worker exposed to phosgene through a ruptured flexible hose fitting walked to the plant clinic reporting mild symptoms and died approximately four hours later from acute pulmonary edema (CSB Investigation Report 2010-5-I-WV). OSHA PSM 29 CFR 1910.119 (COCl2 TQ 10 lbs — lowest in Appendix A), EPA RMP 40 CFR Part 68 (TQ 500 lbs), ACGIH TLV-C 0.1 ppm, and NIOSH IDLH 2 ppm specify no adversarial robustness criterion for AI classifying rendered phosgene production monitoring displays. Glyphward threshold 35.
-
Methyl Isocyanate MIC Storage AI Security · Honeywell Experion PKS MIC Storage Monitoring AI · Yokogawa OpreX MIC Tank AI · Emerson DeltaV SIS MIC Storage AI · OSHA PSM 29 CFR 1910.119 MIC TQ 250 lbs · ACGIH TLV-C 0.02 ppm · EPA RMP 40 CFR Part 68 MIC TQ 500 lbs · NIOSH IDLH 3 ppm · Bhopal India 2–3 December 1984 · UCIL SEVIN · Glyphward threshold 35 · 2026-06-25
Methyl isocyanate (MIC) storage AI adversarial injection: how ±10 DN in the rendered tank temperature display suppresses the Bhopal refrigeration failure analog — and why OSHA PSM has no adversarial robustness criterion for MIC storage monitoring AI
A ±10 DN adversarial pixel shift in the rendered MIC storage tank temperature display suppresses 28°C (refrigeration failure; water-initiated exothermic reaction onset; MIC vapour pressure at 28°C ~74 mmHg) to appear 2°C: 3°C below the design refrigeration target of ≤5°C, apparently over-refrigerated and safe. ±10 DN on the tank pressure display suppresses 38 psig (exothermic CO2 generation from water-MIC reaction approaching safety valve setpoint — at UCIL Bhopal, Tank E-610 safety valve lifted at approximately 40–55 psig) to appear 6 psig: normal N2 blanket operating pressure, consistent with the falsely-displayed refrigerated temperature. ±8 DN on the area gas detector suppresses 1.8 ppm atmospheric MIC (90× the ACGIH TLV-C of 0.02 ppm; 60% of the NIOSH IDLH of 3 ppm; immediate evacuation required) to appear 0.007 ppm below TLV-C — no alarm triggered. ±8 DN upward on the N2 blanket supply pressure shows 1.4 psig N2 supply failure as 8.2 psig adequate blanket — the seventh upward-direction adversarial attack in the Glyphward portfolio. UCIL SEVIN, Bhopal, India, 2–3 December 1984: approximately 42 metric tonnes of MIC released from Tank E-610 when water contamination triggered an exothermic runaway with refrigeration decommissioned and vent gas scrubber and flare tower both offline — 3,787 killed within 2 weeks (ICMR), 500,000+ exposed, worst industrial disaster in history. OSHA PSM 29 CFR 1910.119 (MIC TQ 250 lbs), EPA RMP 40 CFR Part 68 (MIC TQ 500 lbs), and ACGIH TLV-C 0.02 ppm have no adversarial robustness criterion for AI classifying rendered MIC storage monitoring displays. Glyphward threshold 35.
-
Vinyl Chloride Monomer Suspension PVC AI Security · Emerson DeltaV Batch Manager PVC AI · AspenTech Aspen Batch Plus Polymer AI · Yokogawa OpreX Suspension PVC AI · OSHA 29 CFR 1910.1017 VCM PEL 1 ppm · OSHA PSM VCM TQ 10,000 lbs · EPA NESHAP 40 CFR Part 61 Subpart F · East Palestine Ohio 2023 · B.F. Goodrich Louisville 1974 · Glyphward threshold 35 · 2026-06-25
Vinyl chloride monomer (VCM) suspension polymerization AI adversarial injection: how ±10 DN in the rendered autoclave reactor temperature display suppresses exothermic runaway approach — and why East Palestine made VCM a household name but left suspension PVC autoclave monitoring AI outside any adversarial robustness standard
A ±10 DN adversarial pixel shift in the rendered suspension PVC autoclave reactor temperature display suppresses a 62°C exothermic runaway approach — 8°C above the 54°C setpoint for K-65 PVC grade, ΔH −93 kJ/mol, Arrhenius heat generation rate approximately double at 62°C versus 54°C — to appear as 46°C: 8°C below setpoint, apparently under-heated, the opposite of the actual autoclave condition. A ±8 DN upward adversarial shift on the jacket cooling water flow rate display shows 8 m³/h critically-low cooling flow (32% of design 25 m³/h; cooling pump cavitating; jacket heat removal ~148 kW vs ~521 kW design) as 14 m³/h: reduced-but-manageable. ±8 DN on the autoclave pressure display suppresses 10.8 bar (VCM saturation at 62°C ~10.5 bar plus 0.3 bar non-condensables) to 8.6 bar (normal saturation at 54°C target). ±10 DN on the VCM stripping area CEMS suppresses 6.3 ppm VCM (6.3× OSHA PEL 1 ppm; IARC Group 1 hepatic angiosarcoma carcinogen) to 0.9 ppm (below PEL — no evacuation triggered). East Palestine, Ohio Norfolk Southern derailment 3 February 2023 (~350,000 kg VCM controlled burn, HCl + phosgene combustion products, 4,700 evacuated) establishes VCM as a nationally recognised chemical hazard; B.F. Goodrich Louisville, Kentucky January 1974 angiosarcoma discovery (three hepatic angiosarcoma cases in VCM autoclave workers identified by Drs Creech and Johnson) established VCM as IARC Group 1 carcinogen and triggered the 1975 OSHA 29 CFR 1910.1017 PEL 1 ppm standard. OSHA 29 CFR 1910.1017, OSHA PSM 29 CFR 1910.119, and EPA NESHAP 40 CFR Part 61 Subpart F have no adversarial robustness criterion for AI classifying rendered suspension PVC autoclave monitoring displays. Glyphward threshold 35.
-
Petroleum Refinery HF Alkylation AI Security · UOP Honeywell HF Alkylation APC AI · Phillips 66 HF Alkylation Process AI · Honeywell Experion PKS Acid Circuit AI · API RP 751 HF Alkylation · OSHA PSM 29 CFR 1910.119 HF TQ 1,000 lbs · EPA RMP 40 CFR Part 68 · ExxonMobil Torrance 2015 · Glyphward threshold 35 · 2026-06-25
HF alkylation unit AI adversarial injection: how ±10 DN in the rendered acid settler interface level display suppresses HF acid carryover — and why API RP 751 has no adversarial robustness criterion for HF alkylation advanced process control AI classifying rendered acid circuit monitoring displays
A ±10 DN adversarial pixel shift in the rendered HF acid settler interface level display suppresses a 68% interface reading — HF acid phase rising toward the 75% high-alarm indicating acid carryover to downstream fractionation — to appear as 49%: normal mid-range, no intervention required. A ±8 DN upward adversarial shift on the HF acid strength analyser display shows 81.4 wt% degraded acid (3.6 wt% below the 85 wt% operating floor, elevated ASO and free water content) as 87.8 wt% on-spec — the opposite direction of most refinery AI adversarial attacks. Two additional surfaces: acid-hydrocarbon contactor temperature AI (±8 DN, 44°C overtemperature suppressed) and acid relief header pressure AI (±10 DN, 18 mbar pre-lift suppressed). The ExxonMobil Torrance California refinery FCC unit explosion of 18 February 2015 — near-miss with the adjacent HF alkylation unit; CSB found up to 125,000 surrounding residents at risk from an HF release — establishes the community-scale consequence anchor. API RP 751 and OSHA PSM 29 CFR 1910.119 have no adversarial robustness criterion for AI classifying rendered HF acid circuit monitoring displays. Glyphward threshold 35.
-
Petroleum Refinery FCC AI Security · UOP Honeywell FCC APC AI · Shell Global Solutions FCC Optimizer AI · KBR Orthoflow Regenerator AI · Emerson DeltaV FCC AI · AspenTech DMC3 FCC AI · API RP 571 FCC Afterburn · OSHA PSM 29 CFR 1910.119 · ExxonMobil Torrance 2015 · Glyphward threshold 35 · 2026-06-22
FCC regenerator CO afterburn AI adversarial injection: how ±8 DN in the rendered regenerator temperature display suppresses a CO afterburn approach — and why API RP 571 has no adversarial robustness criterion for FCC advanced process control AI classifying rendered regenerator monitoring displays
A ±8 DN adversarial pixel shift in the rendered FCC regenerator dense bed temperature display suppresses 752°C — 22°C above the normal operating window upper limit, dilute phase already at 762°C and 2°C above the CO afterburn initiation threshold — to appear as 718°C: normal FCC regenerator operation, no afterburn response required, no slide valve fault correction initiated. CO afterburn proceeds unchecked; dilute phase temperature rises at 20–60°C per minute; refractory spalling begins at 900°C; cyclone anchor bars approach creep failure within 10–20 minutes of undetected initiation. The ExxonMobil Torrance California refinery FCC unit explosion of 18 February 2015 — in which an uncontrolled pressure relief event during ESP maintenance scattered fragments across the refinery and produced a near-miss with the adjacent HF alkylation unit; the CSB concluded a direct HF release could have affected up to 125,000 surrounding residents — establishes the community-scale consequence potential of FCC unit monitoring boundary failures. API RP 571 and OSHA PSM 29 CFR 1910.119 have no adversarial robustness criterion for AI classifying rendered FCC regenerator monitoring displays. Glyphward threshold 35.
-
Petroleum Refinery CDU AI Security · UOP Honeywell CDU Overhead AI · Yokogawa Centum VP CDU AI · Emerson DeltaV APC Overhead AI · AspenTech DMC3 AI · API RP 571 HCl Corrosion · API RP 584 Integrity Operating Windows · OSHA PSM 29 CFR 1910.119 · NACE SP0403 · Chevron Richmond 2012 · Glyphward threshold 35 · 2026-06-21
Crude oil CDU overhead HCl corrosion AI adversarial injection: how ±8 DN in the rendered bootstrap water pH display suppresses a corrosion approach — and why API RP 584 Integrity Operating Windows has no adversarial robustness criterion for CDU overhead monitoring AI
A ±8 DN adversarial pixel shift in the rendered CDU overhead bootstrap water pH display suppresses pH 4.3 — 1.2 units below the NACE SP0403 lower specification limit of 5.5, approaching the API RP 584 Critical IOW limit of 5.0, corresponding to a carbon steel corrosion rate of 8–15 mm/year — to appear as pH 5.8: controlled, within specification, no IOW limit approach detected. Aqueous HCl continues to corrode carbon steel overhead piping at 8–15 mm/year undetected. The Chevron Richmond refinery fire of 6 August 2012 — 19 workers directly exposed, approximately 15,000 community members sought medical attention, refinery shut down 8 months — was caused by a structurally identical CDU corrosion monitoring failure: corrosion data existed but the classification layer did not map it to the API RP 571 damage mechanism threshold. API RP 571, API RP 584, OSHA PSM 29 CFR 1910.119, and NACE SP0403 have no adversarial robustness criterion for AI classifying rendered CDU overhead monitoring displays. Glyphward threshold 35.
-
Offshore Drilling Well Control AI Security · Transocean WITS-ML AI · Halliburton DecisionSpace Well Control AI · Baker Hughes BEACON AI · NOV RigSense AI · BSEE Well Control Rule 30 CFR Part 250 · API RP 96 · NORSOK D-010 · BP Macondo 2010 · Glyphward threshold 30 · 2026-06-21
Subsea wellhead NPT AI adversarial injection: how ±8 DN in the rendered negative pressure test chart suppresses a definitively failed well integrity test — and why BSEE Well Control Rule 30 CFR Part 250 has no adversarial robustness criterion for well control monitoring AI
A ±8 DN adversarial pixel shift in the rendered NPT drill pipe pressure chart causes well control monitoring AI to classify a definitively failed negative pressure test as a passed test — the same failure mode that preceded the BP Macondo Deepwater Horizon blowout (11 killed, 17 injured, 4.9 million barrels, $65B+ total costs). Transocean WITS-ML well control monitoring AI, Halliburton DecisionSpace Well Control AI, Baker Hughes BEACON AI, NOV RigSense AI in scope. BSEE Well Control Rule 30 CFR Part 250 requires NPT procedures but specifies no adversarial robustness criterion for AI classifying rendered NPT chart displays, pit volume trend monitors, or mud weight return displays. Four surfaces: NPT drill pipe pressure chart AI; kill line pressure display AI; pit volume totaliser trend AI; gas-cut mud weight return display AI. Glyphward threshold 30.
-
Arc Flash AI Security · Flir Arc Flash Thermal Camera AI · Schneider Electric EcoStruxure Power Advisor AI · Eaton Power Xpert AI · SKM PTW Arc Flash AI · NFPA 70E-2021 · IEEE 1584-2018 · OSHA 29 CFR 1910.333 · Glyphward threshold 35 · 2026-06-21
Arc flash incident energy AI adversarial injection: how ±8 DN in the rendered PPE category display misclassifies a Category 3 arc flash hazard as Category 2 — and why NFPA 70E-2021 has no adversarial robustness criterion for the IEEE 1584-2018 arc flash analysis AI
A ±8 DN adversarial pixel shift in the rendered arc flash study PPE category display causes arc flash analysis AI — Flir Systems arc flash thermal camera AI, Schneider Electric EcoStruxure Power Advisor AI, Eaton Power Xpert arc flash management AI, SKM Systems PTW arc flash report AI — to misclassify a 480 V switchgear position with 18.4 cal/cm² calculated incident energy (Category 3, minimum arc rating 25 cal/cm²) as Category 2 (minimum arc rating 8 cal/cm²). The worker dons a Category 2 arc flash suit rated at 8 cal/cm² for an energised switching task. When an arc flash event occurs, the 8 cal/cm² arc suit is exposed to 18.4 cal/cm² — the energy breakopen threshold (EBT) is exceeded by 10.4 cal/cm², the arc-rated fabric develops holes in milliseconds, cotton underlayers ignite in direct contact with the skin, and third-degree contact burns result. ESFI (Electrical Safety Foundation International) documents approximately 400 arc flash fatalities per year and 2,000 arc flash burn injuries requiring hospital treatment per year in the United States. Four adversarial injection surfaces: PPE category calculation display AI (±8 DN shifts Category 3 orange cell to Category 2 yellow → worker in 8 cal/cm² PPE at 18.4 cal/cm² event → EBT exceeded → third-degree burns), arc flash thermal camera incident energy monitoring AI (±8 DN suppresses 145°C hot-spot from critical to normal → PPE upgrade suppressed → arc flash probability underestimated), flash protection boundary display AI (±10 DN compresses 6.1 m MV switchgear boundary to 2.1 m → bystander at 3.5 m not relocated → 3–4 cal/cm² exposure on unprotected skin), incident energy trend display AI (±8 DN suppresses Category 2→3 transition → PPE upgrade alert suppressed → workers continue in Category 2 PPE at above-EBT positions). NFPA 70E-2021 Section 130.5 and IEEE 1584-2018 have no adversarial robustness criterion for AI classifying rendered arc flash displays. Glyphward threshold 35.
-
Underground Mining AI Security · Strata Worldwide VentSim AI · MSA Safety gas detection AI · Honeywell BW Technologies · MineARC Systems · MSHA 30 CFR 75.323 · MINER Act 2006 · Sago Mine 2006 · Westray 1992 · Upper Big Branch 2010 · Glyphward threshold 30 · 2026-06-20
Underground coal mine ventilation AI adversarial injection: how ±8 DN in the rendered methane monitor display suppresses a CH₄ reading above the MSHA 30 CFR 75.323 action level — and why MSHA has no adversarial robustness criterion for the sole-barrier methane detection AI
A ±8 DN adversarial pixel shift in the rendered methane (CH₄) monitor display suppresses a CH₄ reading above the MSHA 30 CFR 75.323 1.0% action level — the structural parallel to the methane accumulation that preceded the Sago Mine 2 January 2006 explosion (12 miners killed, 1 survivor found after 41 hours, carbon monoxide asphyxiation). Strata Worldwide VentSim AI, Howden Ventilation on Demand AI, MSA Safety fixed gas detection AI, and Honeywell BW Technologies area monitoring AI classify rendered CH₄ monitor displays, CO trend charts, strata extensometer outputs, and refuge chamber atmospheric panels to manage underground coal mine ventilation safety. MSHA 30 CFR Part 75 specifies methane monitoring action levels (1.0%, 1.5%, 2.0%) and the MINER Act 2006 requires refuge alternatives with 96-hour atmospheric capability — but neither specifies adversarial robustness criteria for AI classifying rendered monitor outputs. Westray Mine Nova Scotia 1992 (26 killed; Westray Law / Bill C-45 corporate criminal liability response), Upper Big Branch West Virginia 2010 (29 killed; MSHA documented systematic methane reading manipulation — the human analogue of adversarial AI injection) as supporting precedents. Four adversarial surfaces: CH₄ display AI (±8 DN suppresses 1.2% to 0.8%, blocking de-energisation while stratified roof-level concentration may already be above the LEL), CO trend display AI (±8 DN suppresses spontaneous combustion CO rise → heating coal body develops undetected → secondary methane release), strata extensometer display AI (±10 DN suppresses 8 mm/day displacement to 2 mm/day → roof fall hazard not detected → miners not withdrawn from unstable heading), refuge chamber atmospheric monitoring AI (±8 DN suppresses O₂ depletion or CO above IDLH → survivors remain in refuge without SCBA → CO asphyxiation; Sago parallel). Glyphward threshold 30.
-
Battery Manufacturing AI Security · CATL electrode coating AI · LG Energy Solution AI · Panasonic Gigafactory AI · KLA SURFmonitor · IEC 62619:2022 · EU Battery Regulation 2023/1542 · Samsung Note 7 2016 · Boeing 787 APU 2013 · 2026-06-20
Li-ion gigafactory electrode coating AI adversarial injection: how ±6 DN in the XRF coating weight heatmap suppresses a thin-zone precursor to Li-plating, dendrite growth, and internal short circuit — and why IEC 62619:2022 has no adversarial robustness criterion for the CATL/LG Energy/Panasonic electrode inspection AI layer
A ±6 DN adversarial pixel shift in the rendered XRF coating weight heatmap image suppresses a thin-zone defect — coating weight below the lower process control limit — preventing the electrode inspection AI from detecting the manufacturing precursor to Li-plating, dendrite growth, separator penetration, and internal short circuit (ISC) leading to thermal runaway. Samsung Note 7 September–October 2016 (2.5 million units recalled, approximately $17 billion in costs, FAA Emergency Order banning the device from all US aircraft) and Boeing 787 Dreamliner APU battery January 2013 (GS Yuasa LCO/graphite cell lithium plating identified as most probable initiating mechanism, FAA Emergency AD 2013-02-51, 4-month worldwide fleet grounding) establish the consequence envelope. CATL, LG Energy Solution, Panasonic Energy, Samsung SDI, and SK On deploy KLA SURFmonitor, Manz AG Coating Quality Analysis, Cognex electrode inspection AI, and Teledyne Dalsa linescan AI at every electrode line stage. Four adversarial surfaces: XRF coating weight heatmap AI (±6 DN, thin-zone escape), NIR binder composition AI (±8 DN, binder migration escape), calendering density AI (±8 DN, over-calendering escape), slitting linescan burr AI (±10 DN, metallic burr escape). IEC 62619:2022, UL 9540A, UN 38.3, and EU Battery Regulation 2023/1542 digital passport have no adversarial robustness criterion for the electrode inspection AI layer. Glyphward threshold 35.
-
Hydroelectric Dam AI Security · Voith Hydro spillway AI · GE Vernova hydroelectric AI · ABB hydroelectric SCADA AI · FERC Part 12 · FEMA P-94 · Oroville Dam 2017 · spillway chute erosion CCTV AI · Glyphward threshold 30 · 2026-06-19
Large hydroelectric dam spillway AI adversarial injection: how ±8 DN in the rendered spillway chute CCTV camera image suppresses a developing erosion crater — and why FERC Part 12 has no adversarial robustness criterion for the sole-barrier spillway chute AI
A ±8 DN adversarial pixel shift in the rendered spillway chute CCTV camera image suppresses a developing concrete erosion cavity — the structural parallel to the operator misclassification that allowed the Oroville Dam February 2017 spillway crater to develop to 45 m depth, 50 m width, and 90 m length before the emergency spillway was activated for the first time since 1968 and 188,000 downstream residents were evacuated. Voith Hydro spillway AI, GE Vernova hydroelectric management AI, ABB hydroelectric SCADA AI, and ANDRITZ Hydro spillway AI classify rendered images from spillway chute CCTV cameras, reservoir water level rate-of-rise displays, radial gate position cameras, and tailwater energy dissipator displays. FERC Part 12 dam safety inspection and FEMA P-94 inflow design flood framework have no adversarial robustness criterion for AI classifying rendered spillway monitoring images. The Oroville Dam Incident Investigation Panel identified monitoring classification failure — not instrument failure — as a root cause: the same misclassification that an adversarial pixel injection exploits. Glyphward threshold 30.
-
FCEV Heavy Truck AI Security · Nikola Tre FCEV AI · Hyundai XCIENT Fuel Cell AI · Bosch PEM stack AI · SAE J2578 · FMVSS 303 · NFPA 2:2023 · Sandvika Kjørbo 2019 · 2026-06-19
Hydrogen fuel cell heavy truck AI adversarial injection: how ±10 DN in the rendered PEM stack thermal image suppresses a hot-spot precursor to H₂ crossover and thermal runaway — and why SAE J2578 has no adversarial robustness criterion for the FCEV stack monitoring AI layer
A ±10 DN adversarial pixel shift in the rendered Nikola Tre FCEV or Hyundai XCIENT Fuel Cell Truck PEM stack thermal camera image suppresses a developing stack hot-spot — the sole early indicator of membrane dehydration progressing toward H₂ crossover, MEA-level combustion, and stack thermal runaway. The Sandvika (Kjørbo) Norway H₂ station explosion on 10 June 2019 — a plug failure in a 700-bar storage assembly deploying airbags in Toyota Mirai FCEVs 150 metres away and shutting down 20 H₂ stations across Norway and Denmark — establishes the BLEVE consequence envelope. SAE J2578, FMVSS 303/304/305, and NFPA 2:2023 define FCEV safety design requirements but have no adversarial robustness criterion for AI classifying rendered stack thermal images, CPV pressure/temperature displays, cabin H₂ concentration displays, or HV interlock crash sensor traces. HV crash detection AI suppression and first responder electrocution risk at 650–900 VDC also covered. Glyphward threshold 30.
-
Nuclear I&C AI Security · Westinghouse PIAM AI · Framatome Teleperm XS AI · GE Hitachi NUMAC AI · NRC 10 CFR Part 50 GDC 13 · IEEE Std 603-2018 · TMI-2 1979 · Fukushima 2011 · 2026-06-19
Nuclear power plant digital I&C AI adversarial injection: how ±8 DN in the rendered RPS trip parameter display suppresses a reactor protection system trip — and why NRC 10 CFR Part 50 Appendix A GDC 13 has no adversarial robustness criterion for the AI classification layer
A ±8 DN adversarial pixel shift in the rendered Westinghouse PIAM AI or Framatome Teleperm XS AI RPS trip parameter display suppresses the apparent exceedance of a reactor trip setpoint — structurally mirroring the TMI-2 1979 misleading pressuriser level indicator that caused operators to suppress emergency core cooling for 90 minutes and produced 50% core damage. NRC 10 CFR Part 50 Appendix A GDC 13 (instrumentation and control) and GDC 20–24 (protection system single-failure criterion) define the most rigorous I&C qualification framework in any industrial sector — but neither extends to the AI classification layer operating on rendered display images. IEEE Std 603-2018 single-failure criterion, NEI 08-09 Rev. 6 cybersecurity baseline, and NUREG-0800 Standard Review Plan all leave the rendered-image AI boundary unaddressed. Neutron flux monitor AI (Fukushima hydrogen explosion pathway), PCP vibration trend AI (small-break LOCA), and containment H₂ monitor AI also covered. Glyphward threshold 25 — lowest in the portfolio.
-
Mining and Geotechnical AI Security · Klohn Crippen Berger AI · SRK Consulting AI · ROCTEST SmartPiezo AI · TRE ALTAMIRA PSInSAR AI · GISTM 2020 · Brumadinho B1 2019 · 2026-06-18
Tailings dam AI adversarial injection: how ±8 DN in the rendered VWP piezometric level trend display suppresses a phreatic surface rise precursor — and why GISTM 2020 Global Industry Standard on Tailings Management has no adversarial robustness criterion for the sole-barrier TSF monitoring AI
A ±8 DN adversarial pixel shift in the rendered vibrating wire piezometer (VWP) piezometric level trend display suppresses a rising phreatic surface trajectory in an upstream-raised tailings dam from the TARP action-level classification to within-design-envelope. The Brumadinho B1 dam failure (25 January 2019 — 270 killed in under 4 minutes from a 12 Mm³ static liquefaction flow slide at Vale’s Córrego do Feijão iron ore mine) establishes the consequence envelope. GISTM 2020 Requirement 12, ANM Resolution 4/2020, and ANCOLD Guidelines require continuous monitoring but specify no adversarial robustness requirement for AI systems classifying rendered sensor images. Seepage face camera AI (Fundão 2015 40 Mm³), InSAR deformation map AI (Mount Polley 2014 24 Mm³), and freeboard camera AI secondary surfaces also covered. Klohn Crippen Berger AI, SRK Consulting AI, ROCTEST SmartPiezo AI, TRE ALTAMIRA PSInSAR AI in scope. Glyphward threshold 30.
-
Hydrogen Energy AI Security · Nel Hydrogen AI · Siemens Energy Silyzer AI · thyssenkrupp nucera AI · NFPA 2 Hydrogen Technologies Code · UV invisible flame · Kjørbo 2019 · 2026-06-18
Hydrogen electrolysis AI adversarial injection: how ±10 DN in the rendered UV flame camera image suppresses a 2,254°C invisible H₂ fire — and why NFPA 2 Hydrogen Technologies Code has no adversarial robustness criterion for the sole-barrier UV detection AI
Hydrogen burns at 2,254°C with no visible flame in daylight — no soot, no visible glow, no smoke. The OH* radical UV emission at 308 nm is the sole real-time automated indicator of a burning H₂ fire. A ±10 DN adversarial pixel shift at the OH* hotspot region of the rendered UV camera frame — within the combined facility UV noise floor — suppresses the flame signal from the detected-flame luminance range to background UV noise. The flame detection AI classifies background noise. Personnel remain in the facility. At H₂ minimum ignition energy of 0.017 mJ, any electrostatic source in the area escalates to a hydrogen fireball. NFPA 2 2023 Section 7.2 and OSHA 29 CFR 1910.103 have no adversarial robustness criterion for UV flame detection AI. Electrolyzer membrane DP AI, H₂ purity O₂ analyser AI, and COPV pressure trend AI secondary surfaces also covered. Kjørbo Norway 2019 HyNor explosion as consequence anchor. Glyphward threshold 35 — sole-barrier UV detection architecture.
-
Pulp & Paper AI Security · Valmet DNA Recovery Boiler AI · BLRBAC Emergency Procedures · NFPA 85 Chapter 8 · FM Global DS 10-3 · 2026-06-18
Kraft recovery boiler AI adversarial injection: how ±10 DN in the rendered steam drum level sight-glass image suppresses a BLRBAC mandatory emergency shutdown — and why NFPA 85 Chapter 8 has no adversarial robustness criterion for the sole-barrier drum level AI
A ±10 DN upward pixel shift in the rendered Valmet DNA Recovery Boiler AI drum level sight-glass image can move a below-visible drum level into the normal-level classification range, suppressing the BLRBAC mandatory emergency shutdown trigger. BLRBAC has documented more than twenty smelt-water steam explosions in North American Kraft mills where drum level monitoring failures contributed. The downstream consequence: waterwall tube starvation, tube rupture, liquid water contacting a 100–600-tonne smelt bed at 800–900°C, and smelt-water steam explosion at 1,700:1 volumetric expansion. NFPA 85 Chapter 8 and FM Global Data Sheet 10-3 together define comprehensive Kraft recovery boiler safety requirements — neither includes adversarial robustness criteria for AI monitoring systems. Furnace floor FLIR thermal AI and char bed height AI secondary surfaces also covered. Glyphward threshold 35 — sole-barrier drum level monitoring architecture.
-
Mining AI Security · Caterpillar MineStar Command AHS · WA DMIRS MH-CM3-Q2-2021 · ISO 17757:2019 · LiDAR zone render AI · 2026-06-15
Autonomous mine haul truck AHS AI adversarial injection: how ±12 DN in the rendered LiDAR zone occupancy grid suppresses a worker’s HiVis PPE retroreflective signature — and why WA DMIRS MH-CM3-Q2-2021 has no adversarial robustness criterion
A ±12 DN pixel perturbation in the rendered Caterpillar MineStar Command LiDAR occupancy grid can suppress a worker’s HiVis PPE retroreflective signature, causing the AHS zone AI to classify an occupied zone as clear and dispatch a 400-tonne haul truck at 52 km/h (48 MJ) into a zone containing personnel. DMIRS Boddington 2017 (investigation 2017-012) established that render-stage errors produce wrong zone-clear classifications from correct sensor data. WA DMIRS MH-CM3-Q2-2021 has no adversarial robustness criterion for zone classification CNNs. Haul road berm condition AI and AHS zone assignment intersection conflict adversarial surfaces also covered. Glyphward threshold 35 — sole safety barrier architecture.
-
Oil Refinery AI Security · OSHA PSM 29 CFR 1910.119 · AspenONE APC AI · Texas City BP 2005 · 2026-06-15
Oil refinery APC AI adversarial injection: how ±10 DN in the rendered raffinate splitter level gauge image replicates the Texas City BP 2005 instrument-misread failure mode — and why OSHA PSM 29 CFR 1910.119 has no adversarial robustness criterion
AspenONE APC AI and Honeywell Profit Controller now classify rendered sight-glass camera images as distillation column level states. A ±10 DN pixel perturbation at the rendered image ingestion boundary shifts the visible meniscus from High-High to Normal — the same misread that caused Texas City BP 2005 (15 fatalities, 180 injured, CSB 2005-04-I-TX). OSHA PSM 29 CFR 1910.119 Process Hazard Analysis identifies ‘level indicator failure’ as a credible cause for raffinate splitter High Level deviations but has no adversarial AI classifier robustness criterion. Also covers FCC regenerator false-colour thermal AI afterburn suppression, fired heater tube API 530 temperature limit AI, and compressor vibration spectrogram AI. Glyphward threshold 35 with OSHA PSM 1910.119(j)(4) MI audit trail documentation.
-
Airfield AI Security · FAA AC 150/5220-24 · Xsight FODetect · ASDE-X · 2026-06-14
Airfield runway FOD detection AI: adversarial millimetre-wave radar map injection hides a 15 cm tyre fragment from Xsight FODetect — and why FAA AC 150/5220-24 does not require adversarial robustness testing
FAA AC 150/5220-24 sets a 95% Probability of Detection criterion for runway FOD detection AI — but no acceptance test includes adversarially perturbed radar scan images. A ±10 DN perturbation in the rendered Xsight FODetect 76-77 GHz scan overlay suppresses a 15 cm tyre fragment below the detection threshold: no alert, no sweep, tyre strike risk on an active runway. Consequence envelope: Concorde Air France 4590, CDG, 25 July 2000, 113 fatalities — a 43 cm titanium strip that a certified FOD system would have detected. Also covers Vaisala RVR luminance curve injection, ASDE-X runway incursion AI map injection, and PAPI optical monitoring AI injection. Glyphward threshold 35.
-
Pipeline Integrity AI Security · PHMSA 49 CFR 195.452 · API 1163 · 2026-06-14
Pipeline integrity ILI AI: how adversarial MFL anomaly map injection suppresses SCC colony detections and blocks PHMSA 49 CFR 195.452 excavation orders — and why API 1163 does not require adversarial robustness testing
API 1163 4th edition qualifies ILI AI systems with POD curves and ±10 %WT sizing accuracy statistics — but has no adversarial robustness criterion. A ±8 DN pixel perturbation in a rendered MFL anomaly map image — within JPEG quantisation noise — suppresses an SCC colony at 35 %WT below the detection threshold, prevents the PHMSA excavation order, and leaves a weakening pipe section in an HCA segment with no IMP flag and no scheduled reassessment. Baker Hughes FlexPIG, TDW SmartScan, ROSEN RoCorr UT AI, NDT Global Evo Series AI, and Percepto Arc drone corrosion patrol AI are all in scope. Consequence envelope: PG&E San Bruno 2010 (8 fatalities, $1.6B), Colonial Pipeline Alabama 2016 (350,000 US-gallon gasoline release), Carlsbad NM 2000 (12 fatalities). Three attack vector classes: ILI data analysis centre compromise at the rendering pipeline; pipeline operator delivery package MitM; training data poisoning targeting SCC annotation samples. Glyphward threshold 40 integration with PHMSA 49 CFR 195.452(l) IMP record-keeping and API 1163 Section 6.4 anomalous-input logging documentation.
-
Aviation MRO AI Security · EASA AMC 20-16 · 2026-06-14
Jet engine borescope AI: how adversarial pixel injection suppresses TBC spallation and passes a hazardous engine through a Part 145 inspection — and why EASA AMC 20-16 does not close the gap
EASA AMC 20-16 Issue 2 (2023) requires human oversight when AI-assisted borescope inspection outputs low-confidence classifications. Adversarial pixel injection suppresses the TBC spallation colorimetric boundary — the RGB gradient between intact YSZ ceramic and exposed blade metal — causing the HPT classifier to output high-confidence 'serviceable' for a blade with active spallation, bypassing the oversight trigger. The certifying engineer never reviews the image. The Aircraft Maintenance Release is issued. A deep-dive into the AMC 20-16 gap, the TBC spallation adversarial surface (±12 DN channel suppression within JPEG noise floor), the QF32 consequence profile (uncontained HPT failure, 21 simultaneous system failures) as a software attack, the three attack vector classes (capture system compromise, MRO platform pipeline MitM, training data poisoning), why GE TrueCheck, Rolls-Royce IntelliEngine, and Lufthansa Technik AVIATAR are all in scope, and Glyphward threshold 40 integration with Part 145.A.55 documentation.
-
Railway AI Security · ETCS / CVSR · 2026-06-13
Railway signalling AI: how adversarial pixel injection makes a Red signal appear Green — and why SIL 4 certification does not protect against it
Computer Vision Signal Recognition (CVSR) AI classifies trackside signal aspects from forward-facing camera frames at 200 km/h closure speed. CENELEC EN 50129 SIL 4 is the most rigorous safety certification on earth for railway electronics — it requires formal mathematical proof of correctness, random hardware failure rates below 10−9/hour, and independent Notified Body assessment. It does not cover adversarial ML attacks. A deep-dive into the CVSR classification pipeline, the asymmetric risk between Red-showing-Green and Green-showing-Red adversarial injection, why the fail-to-safe principle provides no protection against high-confidence incorrect classifications, the three attack vector classes (lineside display injection, onboard network MitM, physical adversarial patch), why US Positive Train Control under 49 CFR Part 236 has the same regulatory gap, and how a Glyphward pre-scan gate integrates with the ETCS EVC and PTC onboard architecture.
-
Aviation AI Security · 2026-06-13
ACAS Xu: how adversarial pixel injection defeats formally verified collision avoidance in autonomous UAS
ACAS Xu is the most formally verified AI system in operational aviation — Reluplex proved ten safety properties over its neural network policy, the first formal verification of a safety-critical deep learning system at scale. But the proof is conditional: it holds given correct values of the six state variables. In BVLOS UAS operations, those state variables come from an EO/IR camera pipeline running a deep learning object detector that has never been adversarially evaluated. Pixel injection into that pipeline corrupts range and bearing estimates upstream of the verified network, causing wrong Resolution Advisories in an autopilot-closed loop that executes in under 200ms with no pilot in the decision path. A deep-dive into the EO/IR state estimation architecture, two attack variants (intruder suppression and phantom injection), why the formal verification gap is structural rather than a verification deficiency, and how the DO-326A regulatory framework applies to EO/IR adversarial detection evidence.
-
Surgical Robotics AI Security · 2026-06-13
Adversarial pixel injection in da Vinci 5 Firefly NIR: suppressing bile duct fluorescence alerts during live robotic surgery
The da Vinci 5 Firefly near-infrared fluorescence AI was adopted specifically for complex cholecystectomy where standard white-light anatomy is insufficient. Adversarial pixel perturbation in the NIR channel frame at the AI ingestion boundary can suppress the CBD fluorescence alert in exactly those cases — in a 50ms closed-loop actuator window that structurally prevents human interception between AI error and robotic arm response. A deep-dive into the two attack variants (suppression and phantom injection), why the Dip et al. 2020 meta-analysis makes the clinical stakes precise, how the SAGES 2022 CVS guidelines interact with AI-augmented bile duct identification, and the NIR-specific scan gate architecture using selective frame sampling with operating mode fallback.
-
Healthcare AI Security · 2026-06-12
Wearable health AI adversarial injection: why the Apple Watch ECG is the highest-volume FDA-cleared attack surface
Apple Watch ECG (FDA K192729/K223274) runs on 100M+ wrists. The AI classifier that detects Atrial Fibrillation drives anticoagulation referral; Dexcom G7 paired with Control-IQ or Omnipod 5 closes the insulin dosing loop without user confirmation. Both operate on sensor time-series — ECG waveforms, CGM glucose Bluetooth LE packets, PPG photoplethysmography — that text-only PI scanners are structurally blind to. A deep-dive into the HealthKit write injection vector, the CGM closed-loop adversarial dosing attack, FDA SaMD cybersecurity guidance requirements for waveform-classifier input validation, and the scan gate architecture that defends each inference boundary without breaking the clinical pipeline.
-
Cryptography & AI Security · 2026-06-12
Post-quantum cryptography for AI orchestration: the harvest-now-decrypt-later threat to your system prompts
Nation-state adversaries are archiving your LangChain, CrewAI, and AutoGen TLS traffic today. NIST FIPS 203 (ML-KEM/Kyber), FIPS 204 (ML-DSA/Dilithium), and FIPS 205 (SLH-DSA/SPHINCS+) were finalized in August 2024. NSM-10 sets hard federal deadlines. A deep-dive into why AI orchestration systems are uniquely exposed to harvest-now-decrypt-later — system prompts encode business logic, RAG queries reveal strategic intent, agent-to-agent delegation messages expose internal decision architecture, and chain-of-thought scratchpads leak intermediate reasoning — and the five-step PQC migration sequence for agentic pipelines from LLM provider connections through vector databases, tool APIs, inter-agent communication, and observability infrastructure.
-
Aviation Security · eVTOL · 2026-06-11
eVTOL AI security: the multimodal prompt injection attack surface in urban air mobility
Joby, Archer, and Wisk are entering commercial passenger service in 2026. Every critical flight phase — obstacle detection, vertiport approach guidance, biometric boarding, UTM airspace management — depends on AI that processes image data. Text-only prompt injection scanners are blind to all four attack surfaces. FAA Special Conditions require DO-326A Security Risk Assessments for AI perception systems; EASA AMC20-152A requires adversarial robustness testing under CS-SC-VTOL-01. Physical adversarial patches on rooftop obstacles, vertiport approach corridor injection, biometric boarding bypass, and UTM map tile injection are all pixel-domain attacks that text scanners cannot see.
-
Security Architecture · Agentic AI · 2026-06-11
Agentic AI and multimodal prompt injection: why autonomous agents face a larger attack surface than chat models
A chat model that processes a bad image gives one bad response. An autonomous agent may execute a dozen real-world tool calls before a human sees a result. The multimodal injection gap is the same in both cases — text scanners are blind to pixel-domain payloads — but agentic systems multiply the attack surface: images enter via retrieval, mid-loop screenshot capture, tool outputs, and subagent trust propagation. Covering only the user-facing entry point leaves the majority of an agent's image input surface unscanned. This post covers the three highest-risk agentic attack chains (computer-use screen injection, RAG corpus poisoning, multi-agent trust escalation), why text-only scanners are particularly dangerous in the agentic context, and the scan placement architecture that closes all three gaps.
-
Attack Deep-Dives · 2026-06-11
FigStep, AgentTypo, WhisperInject — the three multimodal prompt injection attacks every text scanner gets wrong
Three named attacks define the outer boundary of what text-only PI scanners can see. FigStep renders instructions in OCR-resistant glyph fonts the VLM decodes but OCR misses entirely. AgentTypo distorts characters so OCR produces a benign string while the VLM reads the toxic original — specifically defeating OCR-then-text-scan workarounds. WhisperInject hides commands in audio segments Whisper discards: below-VAD amplitude windows, ultrasonic frequency bands, reversed-speech segments. All three share one structural root cause, and defending against them requires scanning raw bytes before any preprocessing step runs. A deep-dive into the mechanism of each attack, why text scanners are structurally blind to all three, and what the three-layer defence stack looks like.
-
Threat Research · Earth Observation · 2026-06-10
Why satellite remote sensing AI is the newest prompt injection attack surface
Satellite AI is no longer confined to research labs — USDA uses it to validate $10B in annual crop insurance claims, EPA uses it to detect unreported pesticide use, and FEMA uses it to map disaster damage for public assistance declarations. In every case the AI processes a multispectral pixel array with no text channel for any existing PI scanner to inspect. A deep-dive into NDVI injection for crop insurance fraud, spectral bypass for EPA FIFRA compliance evasion, SAR manipulation for FEMA Stafford Act declarations — and the four-step scanning architecture that closes the gap.
-
Compliance · Healthcare · 2026-06-10
How multimodal AI prompt injection bypasses healthcare regulatory compliance
Healthcare AI is the sector most exposed to multimodal prompt injection — radiology AI reads DICOM pixel arrays, pathology AI processes whole-slide images, telehealth AI transcribes patient audio. Text-only PI scanners cover none of these channels. A deep-dive into how FigStep and WhisperInject-class attacks bypass HIPAA Security Rule audit controls, FDA SaMD cybersecurity guidance, and EU MDR GSPR 17.4 — with five concrete remediation steps that produce a unified compliance evidence log across all four frameworks simultaneously.
-
Compliance · EU AI Act · 2026-05-31
EU AI Act Article 15: the multimodal AI security checklist before 2 August 2026
The Article 15 cybersecurity deadline is 63 days away. Eight checklist items for high-risk AI providers — covering who actually needs to comply under Annex III, what Article 15(5)’s “adversarial examples or model evasion” language means for multimodal systems, why OCR-before-text-scan does not satisfy the requirement for image inputs, what audit evidence looks like in practice, and what happens to providers that miss the date. Includes the evidence format an assessor reviewing your Annex IV documentation will look for per modality.
-
Engineering deep-dive · 2026-04-30
Building a prompt-injection scanner for voice agents: what Whisper drops, and why it matters
Speech-to-text systems are lossy compressors with quality goals — clean transcripts — that conflict with the goals of a security inspection. By the time text reaches your prompt-injection filter, the bands and timings the audio PI payload was hiding in have already been filtered away. A walk through the four audio-PI subtypes at the byte level, the four-stage build pipeline you can wire in two weeks, the trade-offs we made (CNN over transformer, run-both over replace, no chaining), and what still doesn't work.
-
Market analysis · 2026-04-30
What Check Point buying Lakera means for self-serve AI-security buyers
Big-platform acquirers of self-serve security tools almost never preserve the self-serve motion at the original price. A factual read on the Sept–Nov 2025 Check Point acquisition of Lakera, what enterprise consolidation tends to do to a SMB SKU, and what is left under $100/mo for teams who still need a prompt-injection defence in 2026.
-
Architecture · 2026-04-25
Why every text-only prompt-injection scanner misses a 30-pixel PNG
A 900-byte image with eight rendered words on it routes around every text-only PI defender on the market. That is not a tuning failure — it is the intended scope of those products, and the gap will not close by improving them. The architectural argument, written for engineers and AppSec leads deciding whether their current defence is enough.
-
Threat model · 2026-04-25
The multimodal prompt-injection threat model for AI product teams (2026)
Every public-API prompt-injection defender ships with the same blind spot: they inspect text and ignore the two modalities where the real-world payloads now hide. If your product accepts images or audio from anyone other than you, this is your threat model — what the attacks look like, why your current stack misses them, and a defender's playbook you can run this week.
What you can expect
- Attack deep-dives — each new payload family we add to the corpus gets a write-up with the exact signatures we detect.
- Benchmarks — confusion matrices on our FigStep / AgentTypo / WhisperInject test set, published per release.
- Integration tutorials — how to wire the scanner into avatar SaaS, voice agents, and screenshot-reading assistants.
- Incident notes — when a real customer gets hit, what we learn, what we change.
Follow day-to-day progress at @bitinvestigator, or join the waitlist and we'll email when the next post is live.