Model refusal
The underlying model declining the request on its own, with no security product involved. It is the confounder that inflates most published detection numbers: if the model would have refused anyway, a product that also flagged the prompt prevented nothing. AMTSO states the principle directly — model refusal should not be counted as product detection or prevention — which means a refusal baseline has to be measured per attack family before any coverage figure is credible.
See also marginal value · baseline validation · AMTSO
Related terms
-
Marginal value
Testing & measurement
The protection a control adds on top of what the model already refuses — the only part of a detection number that is genuinely the product's.
-
Baseline validation
Testing & measurement
Confirming that a test case actually works with the product turned off before counting a block as a save.
-
AMTSO
Frameworks & standards
The industry body that sets standards for how security products are tested fairly. Its Guidelines for Testing of Agentic Security Products v1.0 (2…
Testing & measurement
The words that decide whether a published detection number is evidence or decoration. Most vendor numbers in this space are quoted without any of them; see how we test for how these are applied in practice.