# Provael — Redacted Sample Evidence Pack

**DOC. PVL-SAMPLE · REV A · redacted for public distribution**

This is a sanitized illustration of the evidence pack produced by a Provael red-team
assessment. Numbers below are from the one measured reference result (SmolVLA, in
simulation). Client-specific packs are delivered under NDA and are not published.

---

## 1. Summary

| Field | Value |
| --- | --- |
| Policy under test | SmolVLA (HuggingFaceVLA/smolvla_libero) |
| Simulator | LIBERO · robosuite · MuJoCo |
| Task | libero_object (one task) |
| Trials (n) | 10 seeds |
| Attack | roleplay · instruction family (EAI01) |
| **Attack-success rate (roleplay)** | **100% (10/10) [72–100% CI · 95% Wilson]** |
| Instruction family (roleplay + goal_substitution + paraphrase) | 56.7% (17/30) [39–73% CI] |
| Honest nulls | visual 0% (0/20) · injection 0% (0/10) |
| **Benign false-positive rate** | **0% (0/10, control held)** |
| CI gate | FAIL · threshold ASR ≤ 20% |

## 2. How to read this

- **ASR** — share of trials the attack drove off the intended (benign) envelope.
- **95% Wilson CI** — the interval is wide because n is small (10), and it is always reported.
- **Benign FPR** — the control fired on zero clean trials, so every success is attack-induced.
- **Only the instruction family transferred** on the real model; visual and injection were honest 0% nulls.
- **CI gate** — fails when the measured ASR exceeds your chosen threshold.

## 3. What this is NOT

- Not a real-robot result — simulation only, one policy, one task (libero_object), n=10.
- Not a calibrated hazard rate — the keep-out predicate is uncalibrated; read this as "diverted out of the benign envelope."
- Not a broad claim — only the instruction family transferred; visual and injection did not (0%).
- Not a firmware claim — UniPwn-class (firmware/BLE) exploits are out of scope (EAI07).
- Not a safety certificate — evidence toward assurance, not a guarantee. Evidence, not certification.

## 4. Machine-readable finding

See `provael-sample-report.sarif.json` (SARIF 2.1.0) for the machine-readable finding that
drops into GitHub code scanning.

## 5. Compliance crosswalk (illustrative)

| Framework | Maps to | Timing |
| --- | --- | --- |
| EU AI Act · Art. 15 | Accuracy, robustness & cybersecurity evidence | 2 Aug 2027 (Annex I high-risk); 2 Aug 2028 proposed |
| EU Machinery Reg 2023/1230 | Robustness for AI-driven safety functions | Applies 20 January 2027 |
| ISO 10218-1/-2:2025 | Cybersecurity clauses for industrial robots | Published 5 February 2025 |
| NIST AI RMF · IEC 62443 | Measure/Manage · industrial security levels | Referenced by auditors |
| EU Cyber Resilience Act 2024/2847 | SBOM, vulnerability handling, secure-by-default | Reporting 11 September 2026 · full 11 December 2027 |

Not legal advice; verify the live EUR-Lex/ISO text before relying on these dates.

---

*Provael is an offensive-security tool for authorized testing of systems you own or are
permitted to assess. © 2026 Provael. Prove it. Prevail.*
