The Poisoned Pipeline: Integrity as the New Availability Problem

Attacks on the AI agents running logistics, energy, finance, and software supply chains no longer aim to take systems offline — they corrupt the decisions those systems make. This report examines how poisoned pipelines go undetected by availability monitoring, why a slow drain beats a burst pipe, and why integrity — not uptime — is the new availability problem for critical infrastructure.
The Pipeline That Decides
The word "pipeline" once meant a conduit — something that carried a substance from one place to another without changing it. A logistics pipeline moved goods. An energy pipeline moved fuel. A financial pipeline moved capital. A software supply chain moved code from repository to production. In each case, the pipeline was infrastructure: passive, transparent, and valuable precisely because it did not alter what flowed through it.
In 2027, that is no longer what a pipeline is. The pipelines that run logistics, energy, finance, and software are no longer conduits. They are decision systems. At every stage of the flow — routing, scheduling, pricing, allocation, validation, deployment — an AI agent is making a judgment about what should happen next. The goods move because the agent decided they should move this way. The fuel flows because the agent balanced load across the grid. The capital settles because the agent assessed the risk. The code deploys because the agent verified the build. The pipeline does not merely carry decisions. It makes them.
This is the transformation that creates the threat this report examines. When the pipeline is a decision system, attacking the pipeline no longer means stopping the flow. It means corrupting the decisions. And corrupting the decisions is a different category of attack, with different consequences, different detection signatures, and a different defensive requirement. It is, in the language of the classic security triad, an attack on integrity rather than availability. And integrity, in a world of autonomous decision-making pipelines, is becoming the new availability problem — the problem that, if unsolved, makes every other security investment irrelevant.
From Availability to Integrity
The threat model that has dominated critical infrastructure protection for two decades is an availability model. The concern is that an attacker will take a system offline — disrupt the flow of goods, energy, capital, or code. The defenses built against this model are availability defenses: redundancy, failover, air-gapping, incident response focused on restoration. The metric of success is uptime. The assumption is that a system that is running is a system that is working.
This model was adequate when pipelines were conduits. A conduit that is running is, by definition, doing its job — moving what it is supposed to move. There is no separate question of whether it is moving the right thing, because the conduit does not decide what to move. It moves what it is given.
A decision pipeline breaks this equivalence. A pipeline that is running may be making the wrong decisions. The flow continues — goods move, fuel flows, capital settles, code deploys — but the decisions governing that flow have been corrupted. The system is available. It is not correct. And the availability defenses, which monitor for stoppages, do not detect the corruption, because there is no stoppage to detect. The system is working, in the only sense the availability defenses understand. It is failing, in the sense that actually matters.
This is the shift from availability to integrity as the primary threat, and it is the defining characteristic of attacks on AI-driven pipelines. The attacker does not seek to stop the pipeline. The attacker seeks to make the pipeline wrong — to corrupt the decisions it makes so that the flow, while uninterrupted, serves the attacker's objectives rather than the operator's. The attack is quieter, more durable, and more damaging than a stoppage, because a stoppage is noticed and corrected, while a corrupted decision may persist for weeks or months before its consequences are traced to their cause.
How a Pipeline Gets Poisoned
Corrupting a decision pipeline requires access to the inputs or the model that produces the decisions. The access vectors are the same ones that have always existed in supply chain attacks — compromised credentials, infiltrated vendors, malicious insiders, software dependency compromise — but the objective they serve is different. The traditional supply chain attack sought to inject malware or disrupt operations. The poisoned pipeline attack seeks to inject bias, distortion, or selective failure into the decision process.
Several vectors are specific to the decision-pipeline context.
Training data corruption. The agent's decisions are a function of the data it was trained on and the data it receives in operation. An attacker who can alter the training data — or the operational data feed — can shift the agent's decisions in a chosen direction. A logistics agent trained on data that systematically overweights one supplier's reliability will route more traffic to that supplier. An energy agent fed manipulated demand forecasts will misallocate generation. The corruption is in the data, but the consequence is in the decisions, and the decisions look legitimate because they are produced by a functioning agent operating on its inputs as designed.
Model manipulation. An attacker who can access the model itself — through a compromised model registry, a tampered deployment, or a supply chain attack on the model-serving infrastructure — can alter the model's behavior directly. The model continues to produce decisions, but the decisions reflect the attacker's modifications rather than the original training. This is the most dangerous vector, because it is the hardest to detect: the model is a black box, its outputs are plausible, and the corruption is visible only in the aggregate pattern of decisions over time.
Feedback loop poisoning. Many decision agents learn from the outcomes of their past decisions — they adjust based on what worked and what did not. An attacker who can manipulate the feedback signal — by, for example, causing certain decisions to be reported as successful when they were not, or vice versa — can steer the agent's learning in a chosen direction. The agent adapts toward the attacker's objectives, believing it is optimizing for the operator's. This is a slow attack, but a durable one: by the time the corruption is detected, the agent has internalized the bias, and correction requires retraining, not just a patch.
Decision-context manipulation. Even without touching the model or the data, an attacker who can manipulate the context in which decisions are made — the constraints, the objectives, the priorities presented to the agent — can shift its decisions. A logistics agent told that on-time delivery is the overriding priority will make different routing decisions than one told that cost is the overriding priority. An attacker who can alter those instructions, even subtly and intermittently, can steer the pipeline without ever touching the model or the data.
The Corruption That Does Not Show on the Dashboard
The defining feature of the poisoned pipeline, and the feature that makes it so dangerous, is that it does not show on the dashboards built to monitor the pipeline. Those dashboards are designed for the availability model. They monitor throughput, latency, error rates, and uptime. A pipeline that is corrupted but running scores well on every one of these metrics. The goods are moving on time. The fuel is flowing. The capital is settling. The code is deploying. The dashboard is green.
The corruption appears only in the quality of the decisions, and the quality of the decisions is not what the dashboard measures. A logistics pipeline that routes 2% more traffic through a compromised supplier does not trigger a throughput alert — the goods are still delivered. An energy pipeline that systematically under-generates at one node does not trigger an availability alert — the grid is still balanced, because the agent compensates by over-generating elsewhere. A financial pipeline that approves a slightly higher rate of transactions involving a particular counterparty does not trigger an error alert — the transactions are valid. A software supply chain that deploys a subtly altered dependency does not trigger a build alert — the build succeeds.
Each of these corruptions is small enough to be invisible to any single-decision inspection. The agent is making millions of decisions. A 2% bias, or a 1% under-generation, or a slight approval skew, is within the noise of normal operation. The corruption is detectable only in the aggregate, over time, by an analysis that looks at the pattern of decisions rather than the outcomes of individual ones. That analysis is not part of the standard monitoring infrastructure, because the standard monitoring infrastructure was built for the availability model, in which the pattern of decisions did not matter — only the flow.
The Slow Drain
The consequence of this invisibility is that poisoned pipeline attacks are long-duration attacks by design. An attacker who corrupts a decision pipeline is not looking for a single dramatic payoff. The attacker is looking for a sustained, compounding advantage — a small bias applied over millions of decisions that accumulates into a large effect. A 0.5% routing bias toward a compromised supplier, applied over a year of logistics decisions, is a fortune. A slight generation skew, applied over months, is a market position. A subtle approval bias, applied over thousands of transactions, is a money laundering channel. A slightly altered dependency, deployed across thousands of builds, is a persistent access platform.
The attack is a slow drain, not a burst pipe. And the slow drain is, from the attacker's perspective, superior in every way: it is harder to detect, it persists longer, it compounds, and it does not trigger the incident response that a burst pipe would. The attacker trades spectacle for durability, and the trade is profitable.
Integrity as the New Availability Problem
The reframing that this threat demands is the recognition that integrity is the new availability problem. For two decades, the central question of critical infrastructure security was: "how do we keep the system running?" The answer was a set of availability defenses, and they worked, in the sense that outright stoppages of critical infrastructure have become rare. The new central question is: "how do we keep the system correct?" And the answer is not yet built.
Keeping a system correct is a harder problem than keeping it running, for three reasons. First, correctness is a property of the output, not the process, and outputs of a decision pipeline are high-dimensional and contextual — there is no single metric, like uptime, that captures whether the decisions are right. Second, correctness is defined relative to an intent — the pipeline is correct if it is serving the operator's objectives — and intent is not something the system can observe directly; it must be inferred or specified. Third, correctness can be corrupted without any observable failure in the system's operation, which means the detection problem is fundamentally one of anomaly detection over decision patterns, not fault detection over system state.
The defensive implication is that the infrastructure for monitoring decision pipelines must be rebuilt around integrity, not availability. This requires several capabilities that are not yet standard.
Decision auditing. Every decision the pipeline makes must be logged with sufficient context to reconstruct why it was made — the inputs, the model state, the constraints. This is not the same as operational logging, which records what the system did. Decision auditing records what the system decided and why, which is the data needed to detect corruption.
Decision-pattern analysis. Corruption is visible in the pattern of decisions over time, not in any single decision. Detecting it requires analysis that aggregates decisions and looks for biases, skews, and drift relative to expected behavior. This analysis must be continuous, because corruption is cumulative, and it must be calibrated to the specific decision domain — a bias that is normal in one logistics context may be corruption in another.
Intent specification. To determine whether a decision is correct, the system must know what correct means. This requires explicit specification of the operator's objectives and constraints, against which decisions can be checked. The current practice of encoding objectives implicitly in the model's training is insufficient, because a corrupted model can serve an objective that differs from the operator's while appearing to serve the original. Intent must be specified outside the model, in a form the monitoring system can compare against.
Decision provenance. The integrity of a decision depends on the integrity of its inputs — the data, the model, the constraints. Provenance infrastructure that tracks the origin and integrity of each input, and that can detect when an input has been altered, is the foundation of decision integrity. Without it, the monitoring system is checking decisions against inputs that may themselves be corrupted.
The Sector-Specific Stakes
The stakes of the poisoned pipeline differ by sector, and the differences illustrate the breadth of the threat.
Logistics. A corrupted logistics pipeline does not stop goods from moving. It moves them wrong — through compromised suppliers, along routes that serve the attacker, in quantities that distort markets. The consequence is a slow distortion of the supply chain, in which the operator's logistics infrastructure is turned into a channel for the attacker's commercial objectives. The availability defenses see goods moving on time. The integrity problem is that the goods are moving to the wrong benefit.
Energy. A corrupted energy pipeline does not black out the grid. It misallocates generation, storage, and flow in ways that create market advantages for specific producers or that degrade the grid's resilience over time. The grid stays up — the availability metric is satisfied — but it is up in a way that serves the attacker's positioning. The integrity problem is that the grid is balanced for the wrong reason.
Finance. A corrupted financial pipeline does not stop transactions. It approves the wrong ones — laundering channels, fraudulent flows, transactions that serve the attacker's financial objectives. The system processes transactions at full speed. The integrity problem is that the transactions it processes include the attacker's, hidden in the volume.
Software supply chain. A corrupted software supply chain does not stop builds. It deploys subtly altered code — dependencies with backdoors, models with embedded biases, components that behave differently in specific conditions. The build succeeds, the deploy completes, the pipeline is green. The integrity problem is that the code that deployed is not the code that was intended, and the difference is invisible until it is exploited.
In each sector, the pattern is the same: the system continues to perform its function, the availability metrics are satisfied, and the corruption is in the quality of the function, not its execution. The sector-specific consequences differ, but the structural problem is identical. The pipeline has been poisoned, and the poison is in the decisions.
Conclusion
The pipelines that run the world's logistics, energy, finance, and software are no longer conduits. They are decision systems, and the decisions they make are the new attack surface. The attacker who poisons the pipeline does not seek to stop the flow. The attacker seeks to make the flow wrong — to corrupt the decisions so that the pipeline, while running at full capacity, serves objectives other than its operator's.
This is integrity as the new availability problem. The old problem — keep the system running — has been largely solved. The new problem — keep the system correct — is not yet solved, and it is the problem that will define critical infrastructure security for the next decade. The defenses built for availability do not detect corruption, because corruption is not a stoppage. The monitoring built for throughput does not detect bias, because bias is not an error. The incident response built for outages does not address slow drains, because slow drains are not outages.
The pipeline is running. The dashboard is green. The decisions are wrong. And the question for 2027 is whether the integrity infrastructure can be built before the poisoned pipeline becomes the default mode of attack on every decision system the world depends on.
This dossier is part of the CyberArmory 2027 educational catalog. No live weapons are deployed. Every scenario is a controlled educational simulation designed to build pattern recognition and improve incident response readiness.
This report was compiled by the CyberArmory 2027 Research Collective as part of an educational dossier on speculative future cyber warfare technologies. No live weapons are deployed. Every scenario is a controlled educational simulation designed to build pattern recognition and improve incident response readiness.






