AI & Computingpreprint2026-08-01

CHIRAGE: A Morphic-Polymorphic Threat Axis for Deception-Based Defensive Systems

Open access0 citations

Abstract

Established threat-modeling frameworks, STRIDE for security and LINDDUN for privacy, contain no category for the threats specific to deception-based defensive systems: systems that protect assets by morphing, mimicking, or concealing their own state. Such systems are increasingly deployed (moving-target defenses, polymorphic obfuscation, decoy and honeytoken infrastructures), yet the defensive use of morphism inherits a body of threats from the historically offensive practice of polymorphism, and those threats are not named by any existing framework. This work introduces CHIRAGE (a portmanteau of Chimera and Mirage), a threat axis of seven categories describing how a morphic or polymorphic defense can be predicted, poisoned, evaded, forged, frozen, or unmasked: M1 morph prediction, M2 covert-channel abuse, M3 adaptation poisoning, M4 polymorphic evasion, M5 concealment forgery, M6 isometry break, and M7 mimicry detection. The central claim is deliberately narrow and falsifiable. CHIRAGE does not claim novelty for morphism, moving-target defense, or any individual attack several are folklore. The claim is that no existing threat taxonomy names this class as such, and that naming it has demonstrable analytic value, surfacing threats that STRIDE and LINDDUN leave invisible. To make the claim testable rather than asserted, each of the seven categories is instantiated as an executable attack against a concrete, open morphic engine (the MIMIC Kaleidoscope/Chameleon deception engine), and the outcome of each is reported with its exact mechanism. Five of the seven categories are demonstrated as real, exploitable attacks; one (M6, isometry break) is defended by the engine's isometry contract and serves as a positive control that must read as defended; and one (M7) is defended on the channel tested but open via another. CHIRAGE is offered not as a replacement for STRIDE or LINDDUN but as a complementary axis for the specific and growing class of systems that defend by deception, and as an invitation to the community to rule on its completeness, category boundaries, and value. The MASQUE Constellation relationship and classification Within MASQUARAIDE, the threat-modeling work is organized under MASQUE, the masquerade-themed umbrella that sits over four axes: two established (STRIDE, LINDDUN) and two original (QUANTA, CHIRAGE). Keeping with the project's imagery of disguise, reflection, and shifting form, the two original axes are classified not as equals but by the strength of what they claim: CHIRAGE (Chimera + Mirage). The Masque proper: the true face behind the disguise. This is the primary contribution. A substantively novel morphic-polymorphic threat axis, the one that names a class no existing taxonomy names, and the most heavily demonstrated (five of seven categories shown as live exploits). Where MASQUE is the masquerade, CHIRAGE is the threat that the mask itself can be predicted, poisoned, forged, or turned against its wearer. QUANTA the Domino: a lighter mask worn over a familiar face. This is the secondary contribution. A framing-novel quantum-compute axis whose novelty lies in the consolidation, not the individual threats, most of which are established prior art. It gives known quantum-compute threats a seat at the same table as STRIDE and LINDDUN, with two of seven categories demonstrated and the rest honestly deferred. Both are seven-category sub-axes (Q1–Q7, M1–M7) of MASQUE; neither is a standalone framework. In the masquerade: STRIDE and LINDDUN are the guests everyone already knows, QUANTA is the newcomer in a light domino, and CHIRAGE is the figure whose mask is the whole point of the ball. The one the room hasn't seen before.

// Source

View paper (DOI)Open access versionOpenAlexZenodo (CERN European Organization for Nuclear Research)Published 2026-08-01

Authors: Yen Amy