Formal analysis of CAS under malicious service providers: Implications for trust-aware deployments | AI Sec Watch