Wire
MOAT holds adversarial compute loss to 3.4%
MOAT limited adversarial GFLOPs degradation to within 3.4% of the unattacked baseline across every evaluated pruned vision transformer, according to the IEEE ISVLSI 2026 paper. The model-agnostic defense transforms inputs before inference, avoiding changes to the model architecture or token-pruning mechanism; the figure remains an author-reported research result, not a production service-level guarantee. Teams building the layered controls described in the agent-runtime security pilot framework should add worst-case compute and latency to adversarial acceptance tests instead of measuring accuracy alone.