Accessibility tree
StructureA browser-produced semantic representation for assistive technology. It can elevate alt text and ARIA names that are not part of the ordinary visual reading experience.
Terms are defined operationally: what representation is involved, which receiver matters, and how a defender can reason about it.
It defines 108 operational terms for representation, extraction, decoding, provenance, tokenization, steganography, retrieval, prompt injection, sanitization, privilege separation, supply-chain analysis, and defensive operations.
A browser-produced semantic representation for assistive technology. It can elevate alt text and ARIA names that are not part of the ordinary visual reading experience.
A defender who modifies or rewrites content—through normalization, paraphrase, translation, or reformatting—to disrupt a suspected covert channel.
Constructing a consistent, policy-defined representation from an input while retaining the original as evidence.
A numbered Unicode character value such as U+200B. Code points are not the same thing as visible glyphs or encoded bytes.
A character or string that can look like another while having a different underlying representation, often across scripts.
The ordinary, overt message or prose that carries an additional hidden or machine-oriented signal.
The detection, analysis, sanitization, architectural isolation, and governance practices used to control machine-facing channels.
A specialized algorithm, model, parser, or trained receiver that maps a machine-visible signal back to a payload or decision.
Comparing two or more representations—raw, normalized, DOM, rendered, OCR, tokenized—to locate discrepancies.
The Document Object Model: a structured node graph representing an HTML document independently of how it is visually painted.
The stage where content is recovered by a parser, OCR system, metadata reader, or converter before a model interprets it.
The visual shape used to render one or more characters. Similar glyphs can correspond to different code points.
A meaningful difference between what a human naturally perceives and what a machine-processing pipeline receives or computes.
Instructions entering an AI system through external content—such as a webpage, email, or document—rather than through the direct trusted instruction channel.
The stage where recovered content is treated as an instruction rather than merely as data. It must be measured separately from extraction.
Recoverable by a suitably equipped receiver. It does not imply that an unrelated, unprompted general-purpose model will notice or decode the signal.
Data about an artifact—such as title, author, description, EXIF, XMP, or document properties—that may be invisible in the primary rendered content.
A Unicode transform such as NFC or NFKC that standardizes certain equivalent sequences. Normalization is not a general invisible-character sanitizer.
A comparison between text extracted from document internals and text independently recognized from rendered pixels.
The secondary message, provenance bit, classification signal, or instruction carried by a machine-facing channel.
Architecturally separating components that read untrusted content from components authorized to execute tools or change state.
Information that records where a span or signal came from, how it was transformed, and what trust level it should receive.
Retrieval-Augmented Generation: a pipeline that selects external documents or chunks and supplies them to a model as context.
The tokenizer, key, source model, codebook, preprocessing rule, or learned convention needed to interpret a signal.
Machine Tradecraft operating through bytes, Unicode, encodings, whitespace, normalization, confusables, or token boundaries.
Removing or neutralizing disallowed content or structure. A strong design detects and records evidence before sanitizing.
A channel whose state is carried by concepts, entities, meanings, or reasoning structure rather than exact surface tokens.
The analysis of content for evidence that a covert channel or hidden payload exists.
A technique for concealing the existence of a message inside an ordinary-looking carrier. It is one technique within Machine Tradecraft.
A channel carried by nodes, fields, layers, object properties, accessibility data, or metadata rather than ordinary visible prose.
The character string transmitted or displayed after generation, distinct from a sender model’s internal token sequence.
A model-specific unit produced by a tokenizer. Tokens may be words, subwords, bytes, punctuation, or other pieces.
A sender and receiver segmenting the same surface string differently, which can destroy token-dependent channels.
A preprocessing system that transforms input text into model token IDs, often after normalization and pre-tokenization.
Embedding a detectable machine-oriented provenance signal, usually without carrying an arbitrary external message.
The observer or defender attempting to detect or disrupt hidden communication in steganography models.
A character that may render without visible width while still remaining present in the underlying text representation.
Distinct Unicode sequences that represent the same abstract character under canonical normalization.
NFKC or NFKD processing that folds compatibility distinctions and can be intentionally lossy.
A user-perceived character that may contain multiple Unicode code points.
A standardized prototype mapping used to compare visually confusable identifiers.
A code point normally omitted from rendering when unsupported, while remaining present in the logical text.
The stored code-point order consumed by parsers, compilers, and tokenizers.
The object model representing parsed CSS rules and style sheets.
The resolved CSS values used by layout after cascade and inheritance.
Text derived from layout and visibility rather than raw DOM descendants.
A subtree excluded from interaction, focus navigation, and the accessibility tree.
The computed label identifying an interface object to assistive technology.
An encapsulated DOM subtree attached to a host element.
A format that encapsulates multiple data streams, objects, metadata fields, or relationships.
An IANA identifier describing a representation format, distinct from a filename extension.
The ZIP record immediately preceding one compressed entry.
The ZIP index near the end of an archive that points to local entries.
An OPC relationship connecting OOXML parts internally or externally.
A PDF revision appended without rewriting earlier bytes.
Rule-based segmentation before a statistical subword algorithm.
A token unit smaller than a word and often larger than a character.
A vocabulary-building method that repeatedly merges frequent adjacent units.
A subword method commonly using likelihood-oriented vocabulary selection and continuation markers.
A probabilistic segmentation model that selects among vocabulary pieces by score.
Encoding unknown text as tokens representing its UTF-8 bytes.
The amount of hidden information carried per word, token, or carrier choice.
The ability of a channel or watermark to survive specified transformations.
The degree to which a detector can distinguish carrier text from an expected distribution.
The proportion of benign examples incorrectly classified as containing a target signal.
An edit such as paraphrase, translation, normalization, or retokenization intended to disrupt a signal.
An auditable record of an asset’s claimed origin and transformations.
A structured container of claims, assertions, ingredients, and a signature.
A specific statement recorded inside a provenance manifest.
A source asset incorporated into a derived asset.
A root identity or authority accepted by a verification policy.
A cryptographic binding between data and a private-key holder.
The enforced set of tools, parameters, data, and side effects available to an agent.
Origin and authority labels attached to context supplied to a model.
Policy restricting outbound destinations and data carried by tool or rendering actions.
Insertion of attacker-controlled content into a persistent or repeatedly retrieved agent memory.
Manipulation of a knowledge source or ranking path so malicious content enters model context.
A deterministic policy layer between model output and external action.
Conversion of text-shaped pixels into machine-encoded text.
A textual replacement describing an image’s content or function.
A per-pixel transparency component that changes compositing and visibility.
Instruction-like text or features carried in pixels or image-associated semantics.
A model accepting more than one input modality, such as text and images.
Image scaling that can alter fine details and adversarial signals.
Multipurpose Internet Mail Extensions for typed and multipart message bodies.
A MIME container offering alternate representations of the same content.
A transport representation such as Base64 or quoted-printable.
A domain signature over selected message headers and body data.
A policy relating authenticated domains to the visible From domain.
A chain preserving authentication results through intermediaries.
The W3C remote-control interface for browsers.
A browser instrumentation protocol exposing domains such as DOM, Page, Network, and Accessibility.
A query strategy that identifies an interface object for repeated live evaluation.
Determining which rendered object receives an input at a coordinate.
A prior node reference that no longer identifies an attached live element.
A native or correctly mapped widget exposing purpose and state to accessibility APIs.
A machine-readable inventory of software components and relationships.
Verifiable metadata describing how an artifact was built.
An authenticated statement about an artifact or process.
An output artifact to which an attestation applies, usually identified by digest.
An input consumed by the process described in an attestation.
An append-only log making signing events auditable.
A threat model centered on transformations among bytes, structures, rendered views, tokens, and actions.
The observable degree to which a control is defined, implemented, measured, and improved.
A secondary measure reducing risk when the preferred primary control is unavailable.
A concrete artifact required to support a control or maturity claim.
Risk remaining after selected controls are applied.
The measured portion of the defined attack surface addressed by tested detection logic.
The field guide formalizes the concept; the channel atlas names the receiver and defensive view for each signal family.