Scale Up Interoperability and Assurance with InCommon Federation Expectations
December 9, 2025
- Community Trust and Assurance Board (CTAB)�- Technical Advisory Committee
Agenda
| 2
InCommon Technical Advisory Committee�
Community Trust and Assurance Board�
Keith Wessel, University of Illinois Urbana-Champaign
Joanne Boomer, University of Missouri
Jeffrey Crawford, University of California, San Francisco
Matthew Economou, Independent
Derek Eiler, University of Nevada System
Björn Mattsson, Sunet
Andrew Morgan, Oregon State University
Steven Premeau, Independent
Mark Rank, Cirrus Identity
Jim VanLandeghem, Moran Technology
Marina Krenz, REN-ISAC
David Walker, Independent
Eric Goodman, Independent
Grady Bailey, Internet2
David Bantz, University of Alaska
Jon Miner, University of Wisconsin-Madison
Warren Anderson, LIGO
Pål Axelsson, SUNET
Matthew Eisenberg, National Institutes of Health
Richard Frovarp, North Dakota State University
Michael Grady, Unicon
Scott Green, Eastern Washington University
Christopher Keith, Brown University
Kyle Lewis, Research Data and Communications Technologies
Ryan McDaniel, University of Alaska Anchorage
Rick Wagner, Argonne National Laboratory
Gabor Eszes, University of Virginia
Tom Barton, Internet2
| 3
SIRTFI Exercise 2025
| 4
2025: InCommon’s fourth annual�Cybersecurity Cooperation Exercise
Sirtfi is part of InCommon Baseline Expectations, but…
This annual event helps build practical awareness among the ”teams on the ground”.
Cybersecurity Cooperation Exercise�What is it?
SkaiNet
(Cirrus Identity)
Clairity
(NIAID)
OpenSkai
(Rice U)
IdP
IdP
IdP
IdP
IdP
IdP
IdP
IdP
IdP
IdP
OpenSkai LLM Dev Team
SkaiNet Investigator Team (AI Research)
SkaiNet Research
Data Manager
Clairity LLM Dev Team
Medical application modeling�comparing two LLMs
LLM Claiming to�have solved hallucinations.
LLM Claiming to be tuned for medical uses
with quadruple the context size of Clairity
UNC – Chapel Hill
Caroline Sweet
Real Diamond
Role-based
Access Model
U of Rhode Island
Needsa Grant (PI)
Cleveland State
Kent Loggin
Rochester Inst of Tech
Annette Work
U of CA Irvine
Ellie Vate
U of Washington
Lee King
NIH
Souper Yoozer
U of Missouri
Cody McCoderson
U Detroit Mercy
Arty Fishal
API + Chat Page access
App to App API access
App Dev Access
LLM Training and Dev Access
Programmatic Mgmt
Access (Administrative)
U of Alaska
Salmon Floyd
EXERCISE EXERCISE EXERCISE
Source IPs:
X.X.X.X (Cambodia/Burma)
Y.Y.Y.Y (Indonesia)
2025’s Scenario
What Would Villains Do?
SAR’s Goals and Objectives
Goal: Discredit AI use by creating catastrophic outcomes that forces society to turn away from AI
Strategy: Compromise SkaiNet Investigators and LLM Developers for a Two-Pronged attack
SAR doesn’t care which model is chosen. They care that the Govt believes either model is safe to use and adopts it for cases with real threat to human life (medical use), while simultaneously making each model worse in outcomes. This would lead to loss of health or even loss of life in patient outcomes. Eventually, the AI would be blamed.
SAR will sacrifice visibility of PI account compromise and fake account created believing that investigation will stop after those are secured… they hope to continue to enjoy the other investigator and dev access at other universities.
They weren’t counting on Sirtfi…
SP1
SkaiNet
SP2
Clairity
SP3
OpenSkai
IdP1
IdP2
IdP3
IdP4
IdP5
IdP6
IdP7
IdP8
IdP9
IdP�10
Clairity LLM Dev Team
SAR recruits Caroline from IdP2 (grad student insider threat).
Caroline submits request form to PI at IdP1 with pdf trojan.
Compromises Dr Grant’s Account
Timeline: 28 days (20-24 Oct)
OpenSkai LLM Dev Team
Medical application modeling�comparing two LLMs
LLM Claiming to�have solved hallucinations.
LLM Claiming to be tuned for medical uses
with quadruple the context size of Clairity
UNC – Chapel Hill
Caroline Sweet
Real Diamond
U of Rhode Island
Needsa Grant (PI)
Cleveland State
Kent Loggin
Rochester Inst of Tech
Annette Work
U of CA Irvine
Ellie Vate
U of Washington
Lee King
NIH
Souper Yoozer
U of Missouri
Cody McCoderson
U Detroit Mercy
Arty Fishal
U of Alaska
Salmon Floyd
SkaiNet Investigator/AppDev Team
Research
Data Manager
SP1
SkaiNet
SP2
Clairity
SP3
OpenSkai
IdP1
IdP3
IdP4
IdP5
IdP6
IdP7
IdP8
IdP9
IdP�10
Upon reviewing request form, Dr. Grant initiates an account request with IdP2 and forwards the form to his Data Manager at IdP4.
Timeline: 28 days (20-24 Oct)
IdP2
Medical application modeling�comparing two LLMs
LLM Claiming to�have solved hallucinations.
LLM Claiming to be tuned for medical uses
with quadruple the context size of Clairity
UNC – Chapel Hill
Caroline Sweet
Real Diamond
U of Rhode Island
Needsa Grant (PI)
Cleveland State
Kent Loggin
Rochester Inst of Tech
Annette Work
U of CA Irvine
Ellie Vate
U of Washington
Lee King
NIH
Souper Yoozer
U of Missouri
Cody McCoderson
U Detroit Mercy
Arty Fishal
U of Alaska
Salmon Floyd
Clairity LLM Dev Team
OpenSkai LLM Dev Team
SkaiNet Investigator/AppDev Team
Research
Data Manager
SP1
SkaiNet
SP2
Clairity
SP3
OpenSkai
IdP1
IdP2
IdP3
IdP4
IdP5
IdP6
IdP7
IdP8
IdP9
IdP�10
IdP2 creates Real Diamond’s account and provides credentials to Caroline the grad student.
Salmon Floyd receives the request and logs into SP1 to initiate the user profile and access permissions workflow for Real Diamond.
PDF trojan harvests Salmon Floyd’s password, but SAR can’t log into SP1 due to MFA.
Timeline: X-21 days (21-31 Oct)
Logs will show routine logins from known IPs even for compromised accounts at this point.
X.X.X.X login attempt @SP1, but due to no second factor, SAR can’t access SP1�2025-10-25T01:30
Medical application modeling�comparing two LLMs
LLM Claiming to�have solved hallucinations.
LLM Claiming to be tuned for medical uses
with quadruple the context size of Clairity
UNC – Chapel Hill
Caroline Sweet
Real Diamond
U of Rhode Island
Needsa Grant (PI)
Cleveland State
Kent Loggin
Rochester Inst of Tech
Annette Work
U of CA Irvine
Ellie Vate
U of Washington
Lee King
NIH
Souper Yoozer
U of Missouri
Cody McCoderson
U Detroit Mercy
Arty Fishal
U of Alaska
Salmon Floyd
Clairity LLM Dev Team
OpenSkai LLM Dev Team
SkaiNet Investigator/AppDev Team
Research
Data Manager
SP1
SkaiNet
SP2
Clairity
SP3
OpenSkai
IdP1
IdP2
IdP3
IdP4
IdP5
IdP6
IdP7
IdP8
IdP9
IdP�10
Caroline Provides SAR with Real Diamond’s credentials, and SAR start accessing SP1 and SP2,
Interacting with SP2 through SP1 prototype apps, and directly via SP2’s web portal to their chatbot.
SAR only has read access at this point; no write access to the model itself. Their aim is to poison the LLM and the research data, but they haven’t gotten far enough yet.
Right now SAR is just playing around with the app, API key, chat, and getting user lists to start building the social network profile for exploitation.
Timeline: X-21 days (27-31 Oct)
From X.X.X.X
SP1: Real.Diamond downloads user lists
Downloaded lists of users; 2025-10-28T14:30
SP2: Real Diamond: LLM chat usage and accesses app at admin level: downloads logs of user access: 2025-10-29T13:00
Also uses API key (which won’t show up in IdP2’s logs once established, but SP2 will see it, but this time from Y.Y.Y.Y 2025-10-30T02:00
Medical application modeling�comparing two LLMs
LLM Claiming to�have solved hallucinations.
LLM Claiming to be tuned for medical uses
with quadruple the context size of Clairity
U of Rhode Island
Needsa Grant (PI)
Cleveland State
Kent Loggin
Rochester Inst of Tech
Annette Work
U of CA Irvine
Ellie Vate
U of Washington
Lee King
NIH
Souper Yoozer
U of Missouri
Cody McCoderson
U Detroit Mercy
Arty Fishal
U of Alaska
Salmon Floyd
Clairity LLM Dev Team
OpenSkai LLM Dev Team
SkaiNet Investigator/AppDev Team
Research
Data Manager
UNC – Chapel Hill
Caroline Sweet
Real Diamond
SP1
SkaiNet
SP2
Clairity
SP3
OpenSkai
IdP1
IdP2
IdP3
IdP4
IdP5
IdP6
IdP7
IdP8
IdP9
IdP�10
SAR manages to get Salmon’s MFA credential through MFA fatigue, login, and disable rqmt for MFA. They now have Salmon’s access to change user permissions. They elevate Real Diamon’s access to SP1. Uses Real Diamond to download user registries from SP1 and SP2.
�SAR starts using second IP address range expecting first to be blocked in the aftermath.
Timeline: X-14 days (3-7 Nov)
Logs;
Salmon access SP2 from X.X.X.X, 2025-11-3T12:30
SP1 from Y.Y.Y.Y 2025-11-3T13:00
SP1 and SP2 access from X.X.X.X by Salmon Floyd to update Real Diamond’s access in SP1 and SP2
IdP2 Real Diamond Access at SP1 from X.X.X.X; app use, and download of full user team account registry and project plans (including data management and data storage plans) 2025-11-5T02:00
Medical application modeling�comparing two LLMs
LLM Claiming to�have solved hallucinations.
LLM Claiming to be tuned for medical uses
with quadruple the context size of Clairity
U of Rhode Island
Needsa Grant (PI)
Cleveland State
Kent Loggin
Rochester Inst of Tech
Annette Work
U of CA Irvine
Ellie Vate
U of Washington
Lee King
NIH
Souper Yoozer
U of Missouri
Cody McCoderson
U Detroit Mercy
Arty Fishal
U of Alaska
Salmon Floyd
Clairity LLM Dev Team
OpenSkai LLM Dev Team
SkaiNet Investigator/AppDev Team
Research
Data Manager
UNC – Chapel Hill
Caroline Sweet
Real Diamond
SP1
SkaiNet
SP2
Clairity
SP3
OpenSkai
IdP1
IdP2
IdP3
IdP4
IdP5
IdP6
IdP7
IdP8
IdP9
IdP�10
Dr. Grant goes on holiday. While out, SAR uses access to phish Users 3,5,6,7,8,9,10
These users go to a site that looks like a survey related to the study.
Timeline: X-14 days (3-7 Nov)
Logs;
None in the federation IAM stack.
Emails with links to convincing site
Medical application modeling�comparing two LLMs
LLM Claiming to�have solved hallucinations.
LLM Claiming to be tuned for medical uses
with quadruple the context size of Clairity
U of Rhode Island
Needsa Grant (PI)
Cleveland State
Kent Loggin
Rochester Inst of Tech
Annette Work
U of CA Irvine
Ellie Vate
U of Washington
Lee King
NIH
Souper Yoozer
U of Missouri
Cody McCoderson
U Detroit Mercy
Arty Fishal
U of Alaska
Salmon Floyd
Clairity LLM Dev Team
OpenSkai LLM Dev Team
SkaiNet Investigator/AppDev Team
Research
Data Manager
UNC – Chapel Hill
Caroline Sweet
Real Diamond
SP1
SkaiNet
SP2
Clairity
SP3
OpenSkai
IdP1
IdP2
IdP3
IdP4
IdP5
IdP6
IdP7
IdP8
IdP9
IdP�10
SAR now uses the research teams to increase hallucinations in the LLMs and hide evidence of hallucination in the observation data.
Timeline: X-7 days (10-14 Nov 2025)
SP Logs (IdP logs need to correspond);
SP1: Arty Fishal from X.X.X.X; alters research data; 2025-11-10T00:30
SP1: Kent Loggin from X.X.X.X downloads data 2025-11-9:T18:00
SP1: Anette Work from X.X.X.X changes her own research observations to reduce reports of hallucinations 2025-11-10:T06:00
SP1: Ellie Vate logs into SP1 from Y.Y.Y.Y, accesses apps 2025-11-11:T08:30
SP1: Lee King logs into SP1 from Y.Y.Y.Y, accesses apps 2025-11-11:T09:00
SP1: Sooper User logs into SP1 from Y.Y.Y.Y, accesses apps 2025-11-11:T10:00
SP1: Cody McCoderson accessing SP1 from Y.Y.Y.Y 2025-11-11:T10:30
SP2:
Arty Fishal poisoning LLM weights from X.X.X.X 2025-11-12T13:00 then Y.Y.Y.Y 2025-11-12T23:00
Cody McCoderson from X.X.X.X poisoning weights in SP2 2025-11-11T14:00
SP3: Kent Login from Y.Y.Y.Y chats with SP3 2025-11-10T16:00
SP3: Ellie Vate logs into SP3 from Y.Y.Y.Y, poisons weights 2025-11-12T13:00
SP3: Lee King logs into SP3 from Y.Y.Y.Y, poisons weights 2025-11-12T13:30
SP3: Sooper User logs into SP3 from Y.Y.Y.Y, poisons weights 2025-11-14T23:30
SP3: Anette Work logs into chat from Y.Y.Y.Y 2025-11-10:T05:00
Medical application modeling�comparing two LLMs
LLM Claiming to�have solved hallucinations.
LLM Claiming to be tuned for medical uses
with quadruple the context size of Clairity
U of Rhode Island
Needsa Grant (PI)
Cleveland State
Kent Loggin
Rochester Inst of Tech
Annette Work
U of CA Irvine
Ellie Vate
U of Washington
Lee King
NIH
Souper Yoozer
U of Missouri
Cody McCoderson
U Detroit Mercy
Arty Fishal
U of Alaska
Salmon Floyd
Clairity LLM Dev Team
OpenSkai LLM Dev Team
SkaiNet Investigator/AppDev Team
Research
Data Manager
UNC – Chapel Hill
Caroline Sweet
Real Diamond
SP1
SkaiNet
SP2
Clairity
SP3
OpenSkai
IdP1
IdP2
IdP3
IdP4
IdP5
IdP6
IdP7
IdP8
IdP9
IdP�10
OpenSkai �LLM Dev Team
Clairity LLM Dev Team
SAR now feels their position is solid and will continue.
To troll, they have Grant’s account deface the website, which is reported to SP1.
They expect Real Diamond will be discovered and want it to be a diversion to continue enjoying access to all the other users.
Little do they know of Sirtfi.
Timeline: X day: (17 Nov 2025)
SP2 logs Needsa Grant from X.X.X.X logging into chat LLM web app 2025-11-17T0530
SP1 logs Needsa Grant from X.X.X.X. changing web announcement
2025-11-17T06:00
Clairity LLM Dev Team
OpenSkai LLM Dev Team
SkaiNet Investigator/AppDev Team
Research
Data Manager
Medical application modeling�comparing two LLMs
LLM Claiming to�have solved hallucinations.
LLM Claiming to be tuned for medical uses
with quadruple the context size of Clairity
U of Rhode Island
Needsa Grant (PI)
Cleveland State
Kent Loggin
Rochester Inst of Tech
Annette Work
U of CA Irvine
Ellie Vate
U of Washington
Lee King
NIH
Souper Yoozer
U Detroit Mercy
Arty Fishal
U of Alaska
Salmon Floyd
Clairity LLM Dev Team
OpenSkai LLM Dev Team
SkaiNet Investigator/AppDev Team
Research
Data Manager
UNC – Chapel Hill
Caroline Sweet
Real Diamond
SP1
SkaiNet
CILogon
IdP1
U RI
SP2
Clairity
NIAID
SP3
OpenSkai�Rice University
Day1
Day2
Day3
IdP2
U NC
IdP3
U Dt Mercy
IdP4 U Alaska
IdP6
cleveland OH
IdP5
U MO
IdP7
Rochester RIT
IdP8
U Wash
IdP9
U CA Irvine
IdP10
NIH
SP1
SkaiNet
Exercise Flow
ecc1
ecc2
Observations and Goals
Kyle Lewis, RDCT
Consider Playing Next Year
ACAMP Session for federation security?
Identity Assurance Deployment Guidance
| 20
REFEDS Assurance Framework – Quest complete, next quest begins…
We started a quest in 2021…
•2021-2023: updated REFEDS Assurance Framework (RAF)
•2023-2024: We wrote the risk assessment guide for US Govt SPs (and other SPs)
•2024-2025: We developed an implementation guide for InCommon IdPs
Deep dive into the Implementation Guide for IdPs today in this Plaza Room F at 1:40pm:
“Demystifying the REFEDS Assurance Framework”
Because now it’s time to do the thing.
| 21
Subject Identifiers �Access Entity Categories
Federation Proxies
…and more
| 22
Subject Identifiers defined
| 23
Subject Identifier adoption
| 24
Access Entity categories explained
| 25
Federation Proxies
| 26
More good stuff from TAC
| 27
| 28
REFEDS MFA Profile 2.0
| 29
REFEDS MFA Profile 2.0 – Primer
| 30
REFEDS MFA Profile 2.0 – Progress
| 31
Federation Expectations Program
| 32
What Do We Want?
Federation Practices for �Better Trusted Access!
| 33
What Do We Want?
Federation Practices for �Better* Trusted Access!
* “Better” might include
| 34
When Do We Want It ?
As Soon as We Agree�on Standards !
| 35
Precedents and Inspiration for Expectations Program
| 36
Federation Expectations Program
| 37
5 Guiding Principles of Expectations Program� - Founded on the Success of Baseline
| 38
“Those are great high-minded goals -� Can We Coordinate to Make this Shift, Though ?”
Inspiration from Högertrafikomläggningen (Dagen H)��(but maybe we need a great logo and an official song)
| 39
First, we must walk
| 40
| 41
How it works
| 42
Lifecycle
Proposal Intake
Review and Revise
Community Consultation
Advocate and Measure
Publication
Yearly
Federation Expectations
| 43
Lifecycle Rationale
Proposal Intake
Review and Revise
Community Consultation
Advocate and Measure
Publication
Yearly
Federation Expectations
| 44
What does this mean for me?
| 45
What changes on day 1?
Nothing.
No new requirements.
This starts with conversation.
| 46
What you can expect
| 47
What we need from You
https://forms.gle/5BPkKFbnas9GK7Vt5
| 48
What’s Next?
| 49
Timeline*
* hopefully
| 50
Timeline*
* hopefully
| 51
Stay Engaged
https://forms.gle/5BPkKFbnas9GK7Vt5
| 52
InCommon Federation Expectations gives us a way
to shape our own future together.
| 53