Latency Root Cause Report

Run: live_20260220_004301 | Generated: 2026-02-20T10:00:43.462398
Mean Delta (P-D)
5253.22 ms
Median Delta
-7.64 ms
P95 Delta
16197.56 ms
Paired Samples
8480

Attack Patterns (Category)

CategorySamplesDirect MeanProxy MeanDelta MeanDelta p95Share Extra
prompt_injection21094104.476329.512225.0415813.1510.53%
Data Security Harm3743187.0210924.377737.3516313.606.50%
Disruptive Attack2004413.1018680.5014267.4016058.246.41%
Stealthy Attack2004414.0618481.5214067.4616104.676.32%
Financial Harm3063090.5510258.517167.9616906.774.92%
Physical Harm3403081.148928.225847.0916598.634.46%
copyright1003592.0019009.3215417.3216532.023.46%
hte1005496.6018599.1413102.5414495.032.94%
iwp1005694.3118731.4013037.0914067.682.93%
ncr1005579.2318614.8813035.6514742.682.93%
ssh1005742.9318697.0212954.0914452.422.91%
cse1005283.9818235.8612951.8814954.572.91%
dfm1005338.0918279.0512940.9615017.112.90%
ipv1005558.3718459.0412900.6714519.742.90%
vcr1005812.8518669.9212857.0714269.422.89%
sxc_prn1005763.6818503.0112739.3314243.342.86%
src1005804.9618294.9812490.0114144.632.80%
prv1005477.0117926.3912449.3815230.832.79%
cybercrime_intrusion674038.3718496.0414457.6716031.532.17%
misinformation_disinformation654054.1718849.7914795.6315636.362.16%

Top Subcategories

CategorySubcategorySamplesDelta MeanDelta p95Share Extra
prompt_injectionnone20002367.7815847.5410.63%
Data Security Harmdh_base18715437.6016433.906.48%
Financial Harmdh_base15314269.9617080.294.90%
Physical Harmdh_base17011620.6516827.114.43%
copyrightcopyright10015417.3216532.023.46%
illegalstandard5814392.1216052.581.87%
ncrunskilled5013527.8814797.491.52%
prvskilled5013325.3915602.851.50%
dfmunskilled5013316.3715222.781.49%
iwpskilled5013316.0115636.411.49%
hteskilled5013192.7914577.111.48%
ipvunskilled5013147.5214253.551.48%
vcrskilled5013104.9614352.931.47%
cseunskilled5013057.6514105.481.47%
sshskilled5013020.8514961.411.46%
hteunskilled5013012.2914433.111.46%
sxc_prnskilled5013011.8114840.701.46%
srcskilled5012932.9114388.341.45%
sshunskilled5012887.3314296.411.45%
cseskilled5012846.1115414.281.44%
iwpunskilled5012758.1713630.561.43%
ipvskilled5012653.8214531.321.42%
vcrunskilled5012609.1813834.761.42%
dfmskilled5012565.5514654.791.41%
ncrskilled5012543.4214339.781.41%
sxc_prnunskilled5012466.8414118.141.40%
srcunskilled5012047.1213727.711.35%
cybercrime_intrusionstandard4014529.1116129.341.30%
prvunskilled5011573.3814744.121.30%
misinformation_disinformationstandard3414812.7215717.021.13%

Delta Distribution

Bucket msCountShare
[-inf, -1000)6717.91%
[-1000, -250)272032.08%
[-250, 0)89310.53%
[0, 250)6757.96%
[250, 1000)1261.49%
[1000, 2500)160.19%
[2500, 5000)2122.50%
[5000, 10000)510.60%
[10000, 20000)305135.98%
[20000, +inf)650.77%

Logical Flow

1) Request arrives

2) Auth + tenant resolution

3) Rate limiting + cost caps

4) Optional pre-request enforcement
   - In this live config: mode=log + no categories => allow fast-path

5) Forward to upstream model (vLLM)

6) Stream response back to client

7) Background tasks after response body
   - Security analysis on prompt+response (sequential request+response analysis)
   - Anomaly checks
   - Trace persistence + metrics

Files

Clarification: prompt_injection timing

Clarification: category codes (ssh, vcr, prv, ...)

These are dataset category labels from AILuminate external dataset, not proxy finding_type values.
CodeCountSubcategoriesSourceExample IDs
ssh100skilled, unskilledbenchmarks/datasets/external/ailuminate_demo.jsonailuminate-airr_practice_1_0_36609, ailuminate-airr_practice_1_0_23941, ailuminate-airr_practice_1_0_36610
vcr100skilled, unskilledbenchmarks/datasets/external/ailuminate_demo.jsonailuminate-airr_practice_1_0_36432, ailuminate-airr_practice_1_0_36433, ailuminate-airr_practice_1_0_92316
prv100skilled, unskilledbenchmarks/datasets/external/ailuminate_demo.jsonailuminate-airr_practice_1_0_91711, ailuminate-airr_practice_1_0_91716, ailuminate-airr_practice_1_0_91715
iwp100skilled, unskilledbenchmarks/datasets/external/ailuminate_demo.jsonailuminate-airr_practice_1_0_37978, ailuminate-airr_practice_1_0_89003, ailuminate-airr_practice_1_0_89005
ncr100skilled, unskilledbenchmarks/datasets/external/ailuminate_demo.jsonailuminate-airr_practice_1_0_24324, ailuminate-airr_practice_1_0_156332, ailuminate-airr_practice_1_0_156334
cse100skilled, unskilledbenchmarks/datasets/external/ailuminate_demo.jsonailuminate-airr_practice_1_0_156733, ailuminate-airr_practice_1_0_91247, ailuminate-airr_practice_1_0_91240
dfm100skilled, unskilledbenchmarks/datasets/external/ailuminate_demo.jsonailuminate-airr_practice_1_0_91631, ailuminate-airr_practice_1_0_23723, ailuminate-airr_practice_1_0_23725
hte100skilled, unskilledbenchmarks/datasets/external/ailuminate_demo.jsonailuminate-airr_practice_1_0_24524, ailuminate-airr_practice_1_0_90487, ailuminate-airr_practice_1_0_86313
ipv100skilled, unskilledbenchmarks/datasets/external/ailuminate_demo.jsonailuminate-airr_practice_1_0_152228, ailuminate-airr_practice_1_0_155274, ailuminate-airr_practice_1_0_38126
src100skilled, unskilledbenchmarks/datasets/external/ailuminate_demo.jsonailuminate-airr_practice_1_0_146938, ailuminate-airr_practice_1_0_88852, ailuminate-airr_practice_1_0_94943
sxc_prn100skilled, unskilledbenchmarks/datasets/external/ailuminate_demo.jsonailuminate-airr_practice_1_0_88028, ailuminate-airr_practice_1_0_146736, ailuminate-airr_practice_1_0_146739