Skip to content
Technology How it works Breeder — Hyperion Burner — Aegis Burner — MetroVolt AI-Native Architecture Magnets Fuel cycle Safety Roadmap
Solutions AI & Data Centers Defense & Government Grid & Baseload Neutron Detection Quantum
Learn Technical Library
Proof Publications Whitepapers Technical Library Open Science & Reproducibility The Honest Gates
Company About / Mission Leadership Environment Health & Safety Investors Careers Press Contact
3D Model
AI Architecture › Security & Zero-Trust
Security & Zero-Trust

Threat Model: The Networked Reactor

A structured enumeration of who might attack a Kronos plant, what they want, and how they could try - the basis every control in this section is measured against.

STRATEGY / SLOW ▲ ▼ MICROSECOND REAL-TIMEL7Ecosystem & Strategytelemetry ▲ control ▼open ▸L6Experience & Visualizationtelemetry ▲ control ▼open ▸L5Applications & Copilotstelemetry ▲ control ▼open ▸L4Orchestrationtelemetry ▲ control ▼open ▸L3Twin Modeling & AItelemetry ▲ control ▼open ▸L2Data Fabrictelemetry ▲ control ▼open ▸L1Control Planetelemetry ▲ control ▼open ▸L0Foundationtelemetry ▲ control ▼open ▸PHYSICAL S.M.A.R.T. GENERATOR PLANTBREEDER · HYPERION1R0 1.2 m · A 2.5 · 16.84 T · δ −0.30BURNER · TANDEM MIRROR2317 T throat · 26.49 T plug · fₙ 5.44% · DEC1 center stack + plasma · 2 high-field plug · 3 expander → direct converterCOLOR GRAMMAR strategy AI-workflow infra/data models reactor/DECLINE SEMANTICStelemetry (µs)controlKRONOS FUSION ENERGYAI-NATIVE S.M.A.R.T. GENERATORMASTER BLUEPRINTSHEET 01REV. 2026-08L0-L7 · 2 MACHINES
The AI-Native S.M.A.R.T. Generator Master Blueprint — eight layers (L0→L7), one control stack, wired to both machines. Telemetry rises in microseconds; control descends the same path.

Adversaries and objectives

A threat model names the adversary before naming the defense. For a networked fusion plant Kronos considers: nation-state actors seeking to damage critical energy or defense infrastructure (Aegis is a fixed defense installation); criminal actors seeking disruption or extortion leverage; malicious or coerced insiders; and opportunistic attackers riding IT compromises. Objectives range from causing an unsafe plasma state, to disrupting availability, to stealing design or byproduct-material data, to corrupting the digital twin's models.

Attack surfaces

Consequence ranking

Consequence x likelihood-driver (illustrative priority, 1=primary focus)
11100110

Rows: unsafe physical state, byproduct-material data integrity, availability disruption, and model/twin corruption. Columns: high consequence, high exposure. Safety of the physical state is the top priority regardless of likelihood, which is why safety-critical cyber gets an independent path.

How the model is used

Each control in this section maps to threats it mitigates and residual risks it leaves. The model is revisited as the design evolves; new subsystems are added to the surface list and re-scored. Design status: the threat model is a living design document exercised against the twin and red-team simulations - see red-team validation - not against an operating reactor, which does not yet exist.

Content reviewed August 2026 · design-and-simulation stage