The Vulnerability and the Adversary
ATG begins with an architectural choice: applications assemble themselves on the user's device. It becomes a vulnerability when that architecture meets a supply chain. It becomes an operational threat when an adversary holds a position in that supply chain.
Client-Side Rendering is the root architectural pattern that produces the modern Client Runtime: the technique by which every modern technology platform, from web browsers to vehicle infotainment systems, assembles itself at runtime on the user's device. The Client Runtime Boundary names the moment content that has been loaded starts running as code. The Perpetual State Machine names what the assembled application does after that moment: unlike a finite state machine, whose states and transitions are fixed in advance, countable, and testable, it never settles into a fixed set of states.
The ATG vulnerability architecture rests on the Glass and Integration on the Glass, with Supply Chain Injection as the general mechanism, the Two-Stage Attack, the formal definition of ATG, and the D5 effects spectrum. Content Swapping names what changes on the rendered surface, Post-Load and Post-Trust Modification names when it changes, Targeted Delivery names who receives it, and the Integrity Blindspot names why so little of it is seen.
The adversary is described along eight capability dimensions. Further conditions shape what that adversary can do: the commercialization gray zone, the local-AI detection blind spot, and the Placement, Access, Influence, Control causal chain.