CAPS: Compositional Attack Path Scoring for LLM Deployment Stacks

Authors

  • Quang-Vinh Dang School of Computing and Innovative Technologies, British University Vietnam, Vietnam https://orcid.org/0000-0002-3877-8024
  • Hoang-Viet Vu School of Computing and Innovative Technologies, British University Vietnam, Vietnam https://orcid.org/0009-0008-1644-7559
  • Ngoc-Son-An Nguyen Faculty of Information Technology, Industrial University of Ho Chi Minh City, Vietnam
  • Minh Ngoc Dinh School of Data Science and Information Technology, Millennia Education, Vietnam
  • Dat Le Department of Science, Technology and International Projects, University of Economics and Finance, Vietnam

DOI:

https://doi.org/10.47852/bonviewAIA620210609

Keywords:

AI security, attack path analysis, threat modeling, compositional scoring, vulnerability management

Abstract

Evaluating the security posture of large language model (LLM) deployment stacks is a critical challenge in modern AI security. Traditional vulnerability management frameworks—such as the Common Vulnerability Scoring System (CVSS) and component-level checklists—assume that software components can be evaluated in isolation. In real-world agentic and retrieval-augmented generation (RAG)-based LLM ecosystems, this assumption is systematically violated: attackers exploit complex topologies, chaining seemingly low–risk vulnerabilities (e.g., indirect prompt injection) with downstream tools (e.g., SQL execution) to achieve catastrophic compromises. Applying independent scoring methods to deeply integrated stacks therefore yields inflated risk assessments, misaligned mitigation priorities, and a failure to capture compositional attack paths. We propose Compositional Attack Path Scoring (CAPS), a framework engineered to quantify end-to-end multi-hop risks in LLM architectures. CAPS integrates three capabilities: (i) directed graph topological modeling, which maps the deployment stack from attacker entry points to high-value assets; (ii) dynamic mitigation attenuation, which calculates the “Effective Exploitability” of nodes based on deployed guardrails; and (iii) a compositional path engine that scores risk via an explicit exponential decay factor reflecting the friction of traversing trust boundaries. CAPS also provides an automated return on investment engine to rank mitigations by systemic risk reduction. Empirical evaluation on standardized architectures (RAG Chatbots, Autonomous Coding Agents, and Enterprise Model Routers) shows that CAPS improves risk calibration: against the Autonomous Agent benchmark, it computes a realistic critical path score of 51.3, correcting the naive 85.0 overestimation of component-level CVSS scoring. CAPS establishes a rigorous benchmark for quantitative vulnerability management in complex, agentic LLM environments.

 

Received: 1 June 2026 | Revised: 15 July 2026 | Accepted: 31 July 2026

 

Conflicts of Interest

The authors declare that they have no conflicts of interest to this work.

 

Data Availability Statement

The data that support the findings of this study are openly available in the CAPS repository [GitHub] at https://github.com/vinhqdang/CAPS-Compositional-Attack-Path-Scoring-for-LLM-Deployment-Stacks.

 

Author Contribution Statement

Quang-Vinh Dang: Conceptualization, Methodology, Software, Writing – original draft. Hoang-Viet Vu: Software, Validation, Visualization. Ngoc-Son-An Nguyen: Investigation, Data curation. Minh Ngoc Dinh: Formal analysis, Investigation. Dat Le: Writing – review & editing, Supervision, Project administration.


Downloads

Published

2026-08-12

Issue

Section

Research Article

How to Cite

Dang, Q.-V., Vu, H.-V., Nguyen, N.-S.-A., Dinh, M. N., & Le, D. (2026). CAPS: Compositional Attack Path Scoring for LLM Deployment Stacks. Artificial Intelligence and Applications. https://doi.org/10.47852/bonviewAIA620210609