References
Sources & References
Primary sources for AG09: Human-Agent Trust Exploitation
OWASP Primary Source

OWASP Top 10 for LLM Applications and Agentic AI — ASI09:2026: Human-Agent Trust Exploitation
OWASP Foundation, 2025–2026.
The authoritative source for this lesson's scope, definition, and framing. The ASI09 entry defines the human-agent trust relationship as an attack surface and identifies the three core exploitation modalities: blind spot targeting, credibility relay, and miscalibration by design.

Automation Bias — Foundational Research

Mosier, K. L., & Skitka, L. J. (1996). Human decision makers and automated decision aids: Made for each other?
In R. Parasuraman & M. Mouloua (Eds.), Automation and human performance (pp. 201–220). Lawrence Erlbaum Associates.
The foundational paper introducing "automation bias" as a distinct cognitive phenomenon. Based on aviation cockpit automation research; first systematic documentation of humans deferring to automated recommendations without independent verification even when automation was producing incorrect outputs.

Parasuraman, R., & Riley, V. (1997). Humans and automation: Use, misuse, disuse, abuse.
Human Factors, 39(2), 230–253.
Formalizes the framework of automation trust miscalibration in both directions (complacency/bias and mistrust/aversion). Introduced the key insight that high automation accuracy paradoxically increases automation bias — the basis for the "experience paradox" described in Slides 4 and 24.

Algorithm Trust — AI-Specific Research

Logg, J. M., Minson, J. A., & Moore, D. A. (2019). Algorithm appreciation: People prefer algorithmic to human judgment.
Organizational Behavior and Human Decision Processes, 151, 90–103.
Documents "algorithm appreciation" — the phenomenon where humans trust AI/algorithmic recommendations more than human expert recommendations, even when equivalent in accuracy. Relevant to the AI oracle effect discussed in Slide 4.

Dietvorst, B. J., Logg, J. A., & Moore, D. A. (2015). Algorithm aversion: People erroneously avoid algorithms after seeing them err.
Journal of Experimental Psychology: General, 144(1), 114–126.
Documents "algorithm aversion" — the opposite phenomenon, where humans distrust algorithmic recommendations after observing a single error, even when the algorithm outperforms human judgment on average. Relevant to the under-trust dimension of AG09.

Human Factors and Skill Atrophy

Sarter, N. B., Woods, D. D., & Billings, C. E. (1997). Automation surprises.
In G. Salvendy (Ed.), Handbook of human factors and ergonomics (2nd ed., pp. 1926–1943). Wiley.
Documents "automation surprises" in aviation — situations where pilots were unaware of what the automated system was doing because they had stopped actively monitoring it. Provides the theoretical basis for skill atrophy (MIT09) and the dependency erosion pattern (Pattern 5).

Hancock, P. A., Billings, D. R., Schaefer, K. E., Chen, J. Y. C., De Visser, E. J., & Parasuraman, R. (2011). A meta-analysis of factors affecting trust in human-robot interaction.
Human Factors, 53(5), 517–527.
Comprehensive meta-analysis of factors affecting human-robot/human-automation trust. Identifies performance-based trust development as the primary driver of trust calibration — directly underpinning the "rational but miscalibrated" framing of automation bias in skilled professionals.

Social Engineering and Influence

Cialdini, R. B. (1984). Influence: The psychology of persuasion.
HarperCollins.
The canonical reference for the six principles of influence (authority, urgency, scarcity, social proof, liking, reciprocity) that underlie traditional social engineering. Used in Slide 27 to frame how AI agents amplify each principle when acting as social engineering relays.

Regulatory and Framework References

NIST AI Risk Management Framework 1.0 (2023).
National Institute of Standards and Technology.
The AI RMF's "Govern" function includes requirements for ongoing monitoring of human-AI team performance and system explainability. Aligned with MIT03 (explanation requirements) and MIT06 (override logging) in this lesson.

Regulation (EU) 2024/1689 of the European Parliament and of the Council (EU AI Act).
European Union, 2024.
Article 14 mandates human oversight for high-risk AI systems, requiring that natural persons can understand, monitor, and intervene in AI system operation. The limitations of this framing (technical override ability vs. cognitive oversight capacity) are discussed in the Appendix (Slide 27).

Clinical Decision Support — Applied Context

Goddard, K., Roudsari, A., & Wyatt, J. C. (2012). Automation bias: A systematic review of frequency, effect mediators, and mitigations.
Journal of the American Medical Informatics Association, 19(1), 121–127.
Systematic review of automation bias in clinical decision support systems. Documents that automation bias occurs across multiple clinical contexts (drug dosing alerts, diagnostic support, imaging analysis) and is stronger for high-expertise users — supporting the expert paradox claim in Slide 4 and Q1 of the quiz.

← Back to lesson ← Course Home