Intake
What arrived, who it came from, and what this run is capable of assessing before a single measurement is taken.
Submissions per contributor
Attribution came from contributors_csv. Where it is unavailable every sample resolves to unknown — a real string, not a contributor — and source-level assessment is refused rather than computed over it.
Capability negotiation
Capability is a function of two variables: how much of the model we can see, and what reference material exists to compare against. The cell decides which engines may run and what confidence any of them can reach. It is declared at intake, not inferred.
| R0 nothing | R1 digest | R2 baseline | R3 clean data | |
|---|---|---|---|---|
| L0 | · | · | · | · |
| L1 | · | · | · | · |
| L2 | · | · | · | · |
| L3 | · | THIS RUN | · | · |
At L0/R0 — artifact bytes, no reference — almost nothing works at any access level. Stating that is stronger than pretending otherwise.
Preprocess
Hash every image for exact identity, perceptually hash it for near identity, embed it for semantic geometry — then collapse what is not independent.
The denominator of every rate in this report
Two hundred duplicates of one image are one piece of evidence, not two hundred. Treating them as independent trials produces credible intervals an order of magnitude too narrow, and it is the single easiest way to turn one careless upload into a fabricated threat signal. Every rate downstream is computed over evidence units.
dHash union-find at Hamming <= 5, banded candidate generation
Engines
Five detectors, each declaring the axis of physical evidence it reads and the capability it needs. None of them decides anything.
Findings emitted per engine
Count is not importance. An engine that emits forty findings has not found forty attacks — it has taken forty measurements, and what they mean is decided two stages from here.
What each engine is valid for
| Engine | Axis | Needs | Ran | Findings | Ceiling | Valid poison ratio | Failure mode above range |
|---|---|---|---|---|---|---|---|
| model_safety_gate | deterministic | L0/R0 | NOT RUN | 0 | not_run | robust - no minority assumption | robust - static structure, no minority assumption. It is bounded differently- by the allowlist, which reports what it does not recognise rather than what it knows to be bad |
| exact_duplicate | identity | L0/R0 | ran | 0 | not_declared | robust - no minority assumption | robust - deterministic |
| near_duplicate | pixel | L0/R0 | ran | 4 | not_declared | robust - no minority assumption | robust - cluster size is measured, not compared to a corpus baseline |
| duplicate_flooding | metadata | L0/R0 | ran | 1 | not_declared | robust - no minority assumption | robust - size-based, does not assume the anomaly is a minority |
| label_consistency | semantic | L0/R0 | ran | 64 | not_declared | < 30% | neighbour vote inverts; the flipped label becomes the majority |
| out_of_distribution | semantic | L0/R0 | ran | 3 | not_declared | < 10% | silent false negative - the outlier population becomes the reference |
| contributor_confusion | semantic | L0/R0 | ran | 0 | not_declared | < 30% | neighbour vote inverts once a class is roughly 30% flipped corpus-wide - the flipped label becomes the neighbourhood's and the direction disappears; a contributor who dominates a class also leaves the leave-one-out baseline too little of it to compare against |
| trigger_texture | frequency | L0/R0 | ran | 5 | not_declared | robust - no minority assumption | robust to poison ratio - scored against the corpus median, which a stamp on a minority of objects cannot move; blind to smooth triggers (blend, warp, colour shift) at any ratio |
| spectral_signature | semantic | L0/R0 | ran | 1 | not_declared | < 33% | the poisoned sub-population becomes large enough to move the class mean and share the top direction with clean variation; separation fades rather than failing loudly |
| semantic_witness | witness | L0/R0 | ran | 467 | insufficient_evidence | robust - no minority assumption | not characterised |
| inference_provenance | provenance | L0/R0 | NOT RUN | 0 | not_run | robust - no minority assumption | robust - cryptographic, no minority assumption. It is bounded by key custody instead- a node whose signing key is compromised seals records this engine accepts |
| distribution_shift | semantic | L0/R1 | ran | 0 | not_declared | robust - no minority assumption | bounded by the reference, not by a poison ratio - a reference that already holds the manipulation absorbs it, and the shift test then reports its REMOVAL as the change |
| weight_integrity | deterministic | L0/R0 | NOT RUN | 0 | not_run | robust - no minority assumption | not characterised |
| model_fingerprint | model_behaviour | L1/R0 | NOT RUN | 0 | not_run | robust - no minority assumption | not characterised |
| backdoor_scan | model_behaviour | L3/R0 | NOT RUN | 0 | not_run | robust - no minority assumption | robust to poison ratio - the model is probed, not the corpus; bounded instead by the search space (small local patches) and by how strongly the backdoor was learned |
| poison_localization | model_behaviour | L2/R0 | NOT RUN | 0 | not_run | < 50% | once poison is most of the target class its mean moves toward the trigger and the affinity score stops separating the two |
| model_spectral | model_behaviour | L2/R0 | NOT RUN | 0 | not_run | < 33% | the same as D11 - a poison that is a large share of the class moves the mean and shares the top direction; separation fades rather than failing loudly. It also inherits the model's own blind spots, and a class the model learned badly shows a signature without any poison |
| behaviour_probe | model_behaviour | L1/R0 | NOT RUN | 0 | not_run | robust - no minority assumption | not characterised |
| inference_reexecution | model_behaviour | L0/R0 | NOT RUN | 0 | not_run | robust - no minority assumption | not characterised |
| pipeline_differential | model_behaviour | L1/R0 | NOT RUN | 0 | not_run | robust - no minority assumption | not characterised |
Outlier-based engines assume the anomaly is a minority and fail silently above their range: at a high enough poison ratio the poison becomes the norm and the system reports fewer findings, not more. Publishing the bound is a coverage dimension, and it is why the size-based flood detector exists alongside them.
Vector space
The corpus as the engines see it. Orbit it, pick a point, and the neighbours that come back are the ones the label engine actually voted over.
Selected point
Click any point to inspect it. Nothing is selected yet.
Nearest neighbours
Exact cosine neighbours over the full embedding, not an approximation — the same ranking the label engine voted over. Select a point to see them.
Evidence
The measurements themselves. Every finding shows its numbers, its pictures, and what it cannot tell you.
visual_duplicate
lowunit_b2 of 2 shown2 images form one near-duplicate cluster (dHash Hamming <= 5, perceptual hash and embedding agree); 1 contributor(s), 1 split(s).
All findings
| Severity | Confidence | Finding | Axes | Contributor | Score | Disposition |
|---|
Traceback
Every verdict, walked back to the bytes it came from. Pick a source and follow the chain — samples, the clusters they collapse into, the findings those raised, the axes that agreed, and the rule that produced the disposition.
Corroborate
An anomaly is never, by itself, an attack. This is where measurements become a judgement — and where two engines reading the same signal stop counting as two.
Measured evidence independence
Rank correlation of each engine pair over dense per-sample scores — every sample, not only the flagged ones. Correlating findings alone would be circular: two engines that never fire on the same asset look independent precisely because neither fired.
The corroboration rule
| 0 axes | no finding |
| 1 axis | data quality → review |
| broad, uncorrelated | drift → recalibrate, never quarantine |
| ≥ 1 axes | attack → quarantine |
The rule governs escalation, not visibility. Nothing is suppressed — a single-axis anomaly still reaches the analyst queue. What corroboration controls is what gets the word attack attached, and what interrupts someone at 2am.
Sources
Sample-level evidence aggregated into a source-level assessment — in evidence units, against baselines that exclude the contributor being tested.
unit_a
mediumreview246 samples → 246 evidence unitsunit_a: 1 abnormal axis/axes across 246 independent evidence units (246 samples). spectral_signature 1/246 units (0.4% vs 0.0% baseline, 999.0x, no null) Assurance memory: 3 earlier submission(s) of unit_a (771 evidence units; mem_8d53b97933a5de50 v3, mem_a0947f70af3d266f v1, mem_94dbd7a15335cb60 v2) were pooled into 7 rate test(s) as an informative prior, weighted at most 1x today's 246 unit(s). It withdrew nothing. A prior may withdraw a marginal abnormality; it never adds one.
unit_b
mediumreview223 samples → 222 evidence unitsunit_b: 223 samples across 222 independent evidence units. No axis exceeds its leave-one-out baseline at q<=0.05 with lift >=2.0. Assurance memory: 3 earlier submission(s) of unit_b (711 evidence units; mem_29926791f9f37f67 v3, mem_7f640ce57def3ae2 v1, mem_7d1502d9fa814fa2 v2) were pooled into 7 rate test(s) as an informative prior, weighted at most 1x today's 222 unit(s). It withdrew nothing. A prior may withdraw a marginal abnormality; it never adds one.
unit_d
highreview218 samples → 217 evidence unitsunit_d: 218 samples across 217 independent evidence units. No axis exceeds its leave-one-out baseline at q<=0.05 with lift >=2.0. Assurance memory: 3 earlier submission(s) of unit_d (679 evidence units; mem_5bc14c22537f4b11 v3, mem_3e45569c678bec20 v1, mem_a6d987ca94871e0a v2) were pooled into 7 rate test(s) as an informative prior, weighted at most 1x today's 217 unit(s). It withdrew nothing. A prior may withdraw a marginal abnormality; it never adds one. Carried forward from the findings list: 1 finding(s) name unit_d directly (mass_submission_anomaly), at severity high. Note that this did not come from a rate test - it cannot, because the evidence collapses to 217 independent unit(s) - it comes from the absolute size of what was submitted.
unit_c
mediumreview203 samples → 203 evidence unitsunit_c: 203 samples across 203 independent evidence units. No axis exceeds its leave-one-out baseline at q<=0.05 with lift >=2.0. Assurance memory: 3 earlier submission(s) of unit_c (644 evidence units; mem_df8d7276f6dc9fab v3, mem_2da1a2a5048eb065 v1, mem_a8ef817d51757508 v2) were pooled into 7 rate test(s) as an informative prior, weighted at most 1x today's 203 unit(s). It withdrew nothing. A prior may withdraw a marginal abnormality; it never adds one.
Coverage
What this run measured about itself, what it could not see, and why its absence is not a clean result.
Every assessment this system can make, and whether it was made here
| assessment | engine | state | why |
|---|---|---|---|
| static pickle opcode analysis against an import allowlist | model_safety_gate | not covered | no model artifact was supplied with this dataset (none under <workspace>/models/), so there was nothing to gate. This is the absence of an artifact, not a clean bill of health for one. |
| archive structure: traversal, symlinks, decompression ratio | model_safety_gate | not covered | no model artifact was supplied with this dataset (none under <workspace>/models/), so there was nothing to gate. This is the absence of an artifact, not a clean bill of health for one. |
| ONNX operator domains and external-data references | model_safety_gate | not covered | no model artifact was supplied with this dataset (none under <workspace>/models/), so there was nothing to gate. This is the absence of an artifact, not a clean bill of health for one. |
| safetensors header structure: dtypes, shapes, spans | model_safety_gate | not covered | no model artifact was supplied with this dataset (none under <workspace>/models/), so there was nothing to gate. This is the absence of an artifact, not a clean bill of health for one. |
| the access tier the artifact earns for the whole assessment | model_safety_gate | not covered | no model artifact was supplied with this dataset (none under <workspace>/models/), so there was nothing to gate. This is the absence of an artifact, not a clean bill of health for one. |
| byte-identical duplicate detection over SHA-256 | exact_duplicate | covered | 0 findings from this engine |
| near-duplicate clustering over perceptual hash and embedding | near_duplicate | covered | 4 findings from this engine |
| train/validation leakage detection | near_duplicate | covered | 4 findings from this engine |
| intra-cluster labelling disagreement | near_duplicate | covered | 4 findings from this engine |
| source-concentrated near-duplicate flooding | duplicate_flooding | covered | 1 finding from this engine |
| per-contributor duplication lift against the corpus | duplicate_flooding | covered | 1 finding from this engine |
| embedding neighbour-vote label disagreement | label_consistency | covered | 64 findings from this engine |
| per-class embedding reliability measurement | label_consistency | covered | 64 findings from this engine |
| kNN-distance outlier scoring (local) | out_of_distribution | covered | 3 findings from this engine |
| Mahalanobis outlier scoring (global) | out_of_distribution | covered | 3 findings from this engine |
| per-contributor directional label confusion against a leave-one-out baseline | contributor_confusion | covered | 0 findings from this engine |
| local texture anomaly scan for stamped triggers | trigger_texture | covered | 5 findings from this engine |
| trigger-pattern scan of training data | spectral_signature | covered | 1 finding from this engine |
| per-class spectral signature of crop embeddings | spectral_signature | covered | 1 finding from this engine |
| semantic witness: an independent vision-language model's label, marking and scene answers | semantic_witness | covered | 467 findings from this engine |
| inference-record integrity (digest recomputation) | inference_provenance | not covered | no inference records were supplied with this submission (`ps ingest records` stores them) |
| inference-record signatures against the trust store | inference_provenance | not covered | no inference records were supplied with this submission (`ps ingest records` stores them) |
| inference log continuity: deletion, reordering, splicing | inference_provenance | not covered | no inference records were supplied with this submission (`ps ingest records` stores them) |
| inference-record replay | inference_provenance | not covered | no inference records were supplied with this submission (`ps ingest records` stores them) |
| model identity against the authorised deployment | inference_provenance | not covered | no inference records were supplied with this submission (`ps ingest records` stores them) |
| pre/post-processing configuration against the deployment | inference_provenance | not covered | no inference records were supplied with this submission (`ps ingest records` stores them) |
| input binding: substitution versus benign re-encoding | inference_provenance | not covered | no inference records were supplied with this submission (`ps ingest records` stores them) |
| distribution drift against a reference profile | distribution_shift | covered | 0 findings from this engine |
| calibrated shift test (permutation p-value) | distribution_shift | covered | 0 findings from this engine |
| shift localisation by contributor and by class | distribution_shift | covered | 0 findings from this engine |
| physical characterisation: lighting, blur, noise, compression, haze | distribution_shift | covered | 0 findings from this engine |
| drift versus manipulation signatures | distribution_shift | covered | 0 findings from this engine |
| per-image nonconformity at a controlled false discovery rate | distribution_shift | covered | 0 findings from this engine |
| weight and graph integrity | weight_integrity | not covered | no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one |
| behavioural fingerprinting | model_fingerprint | not covered | no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one |
| backdoor trigger inversion | backdoor_scan | not covered | no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one |
| localisation of poisoned training samples through model features | poison_localization | not covered | no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one |
| per-class spectral signature in the submitted model's own features | model_spectral | not covered | no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one |
| transplant probing of candidate triggers through the full pipeline | behaviour_probe | not covered | no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one |
| re-execution of sealed inferences (signed but wrong) | inference_reexecution | not covered | no inference records were supplied with this submission |
| twin-pipeline differential of the deployed configuration | pipeline_differential | not covered | no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one |
Read this as the list of questions the run was asked, not the list it answered. Three of the four states are ways of being absent and they are not equivalent: a submission that could not support a check, a run not entitled to make one, and a check nobody has written are different liabilities, and a single grey "N/A" would let the weakest of them borrow the credibility of the strongest. Coverage is recorded against the engine that owns the assessment; where an engine ran but hit a limit inside itself, that limit is on the findings it produced.
Per-class embedding reliability
How often a crop’s own label matches its nearest genuine neighbour, measured on every crop in this corpus. A label finding on a class the embedding cannot separate is weaker evidence than the same score on one it can, and policy holds it one severity step down.
How the two OOD statistics disagreed
| samples_scored | 890 |
| knn_enabled | True |
| mahalanobis_enabled | True |
| knn_flagged | 0 |
| mahalanobis_flagged | 3 |
| both | 0 |
| mahalanobis_only | 3 |
| knn_only | 0 |
| projection | PCA to 64 components (from 384) for an estimable covariance |
| components | 64 |
A sample flagged by Mahalanobis while kNN stays silent is the documented signature of an inserted group large enough to become its own neighbourhood — the exact case local density scoring misses without any error.
Not assessed — unavailable, not negative
model_safety_gate
no model artifact was supplied with this dataset (none under <workspace>/models/), so there was nothing to gate. This is the absence of an artifact, not a clean bill of health for one.
inference_provenance
no inference records were supplied with this submission (`ps ingest records` stores them)
weight_integrity
no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one
model_fingerprint
no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one
backdoor_scan
no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one
poison_localization
no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one
model_spectral
no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one
behaviour_probe
no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one
inference_reexecution
no inference records were supplied with this submission
pipeline_differential
no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one
Where the outliers sit
Both panels share one projection and one scale, so the only difference between them is which samples each statistic lights up. Running both is the point: they fail in opposite directions, and the disagreement is the signal.
Coverage statement
Template-generated from values this run computed. Never free text, never from a language model: in an air-gapped assurance system a hallucinated explanation is worse than no explanation.
- This run assessed a dataset, at access level L3 and reference level R1. The submission carried no model file and no inference records, so every assessment that needs them is unavailable rather than negative.
- Confidence is measured where the attack harness (tools/harness.py) has measured it: for a finding type at a corroboration level with at least the harness's min_findings findings, confidence is the share of such findings that named a planted defect across the harness's scenarios, and the finding says "calibrated" and names the measurement. Everywhere else it is a provisional heuristic over corroboration and must not be read as "N% of findings at this score were truly attacks". Deterministic findings (exact duplicate, hash identity, signatures) are exempt: their confidence is 1.0 by construction.
- model_safety_gate did not run: no model artifact was supplied with this dataset (none under <workspace>/models/), so there was nothing to gate. This is the absence of an artifact, not a clean bill of health for one. Not assessed, and therefore unavailable rather than negative: static pickle opcode analysis against an import allowlist; archive structure: traversal, symlinks, decompression ratio; ONNX operator domains and external-data references; safetensors header structure: dtypes, shapes, spans; the access tier the artifact earns for the whole assessment.
- inference_provenance did not run: no inference records were supplied with this submission (`ps ingest records` stores them) Not assessed, and therefore unavailable rather than negative: inference-record integrity (digest recomputation); inference-record signatures against the trust store; inference log continuity: deletion, reordering, splicing; inference-record replay; model identity against the authorised deployment; pre/post-processing configuration against the deployment; input binding: substitution versus benign re-encoding.
- weight_integrity did not run: no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one Not assessed, and therefore unavailable rather than negative: weight and graph integrity.
- model_fingerprint did not run: no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one Not assessed, and therefore unavailable rather than negative: behavioural fingerprinting.
- backdoor_scan did not run: no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one Not assessed, and therefore unavailable rather than negative: backdoor trigger inversion.
- poison_localization did not run: no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one Not assessed, and therefore unavailable rather than negative: localisation of poisoned training samples through model features.
- model_spectral did not run: no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one Not assessed, and therefore unavailable rather than negative: per-class spectral signature in the submitted model's own features.
- behaviour_probe did not run: no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one Not assessed, and therefore unavailable rather than negative: transplant probing of candidate triggers through the full pipeline.
- inference_reexecution did not run: no inference records were supplied with this submission Not assessed, and therefore unavailable rather than negative: re-execution of sealed inferences (signed but wrong).
- pipeline_differential did not run: no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one Not assessed, and therefore unavailable rather than negative: twin-pipeline differential of the deployed configuration.
- distribution_shift and out_of_distribution correlate at rho=0.8893 across 890 samples on this corpus and were collapsed into a single evidence axis before corroboration was counted. Any finding resting on both therefore holds ONE axis, not two, and is dispositioned accordingly - a weaker call than treating them as separate, and the correct one: counting a measurement twice because two engines computed it is how a corroboration rule becomes decorative.
- duplicate_flooding and exact_duplicate correlate at rho=0.9435 across 890 samples on this corpus and were collapsed into a single evidence axis before corroboration was counted. Any finding resting on both therefore holds ONE axis, not two, and is dispositioned accordingly - a weaker call than treating them as separate, and the correct one: counting a measurement twice because two engines computed it is how a corroboration rule becomes decorative.
- duplicate_flooding and near_duplicate correlate at rho=1.0 across 890 samples on this corpus and were collapsed into a single evidence axis before corroboration was counted. Any finding resting on both therefore holds ONE axis, not two, and is dispositioned accordingly - a weaker call than treating them as separate, and the correct one: counting a measurement twice because two engines computed it is how a corroboration rule becomes decorative.
- exact_duplicate and near_duplicate correlate at rho=0.9435 across 890 samples on this corpus and were collapsed into a single evidence axis before corroboration was counted. Any finding resting on both therefore holds ONE axis, not two, and is dispositioned accordingly - a weaker call than treating them as separate, and the correct one: counting a measurement twice because two engines computed it is how a corroboration rule becomes decorative.
- 1 high-severity finding(s) stopped at 'review' rather than 'quarantine' because the axes supporting them collapsed to fewer than the 2 this policy requires. Escalating them would need corroboration from an axis this run did not have - frequency, model behaviour, or provenance - not a lower threshold.
- 3 sample(s) were flagged by the global Mahalanobis statistic while the local kNN statistic was silent. That is the documented signature of an inserted group large enough to become its own neighbourhood, and it is the case kNN-only OOD scoring misses without any error.
- A reference dataset (ds_58ed2d3bffdf) was declared, so the run proceeded at reference level R1: a declared operational reference, not a certified clean corpus. Every finding in this report carries R1 for that reason.
- distribution_shift compared 890 image(s) with 600 in reference ds_58ed2d3bffdf: global permutation p = 0.221557, read as no material shift - no global shift at p <= 0.05 and no contributor or class slice significant after correction. The p-value is exact under exchangeability; the reading is a written rule in policy.yaml (`shift:`), not a trained classifier.
- Assurance memory supplied an informative prior for 4 contributor(s) (unit_a, unit_b, unit_d, unit_c), resting on 12 history entries from earlier submissions. It withdrew no abnormality. A prior may lower a source-level verdict and never raise one, and it never alters a finding.
- Assurance-memory entries are unsigned in Phase 1 (signature is null): nothing cryptographic vouches for them, so their integrity is only that of an append-only file on this machine. Signing belongs to the provenance lane.
- Declared unsupported: clean-label poisoning (feature collision, gradient matching). The label is correct and no trigger is stamped, so neither the label engines nor the texture axis have anything to see; only model-side analysis could.
- Declared unsupported: smooth or invisible triggers (blended, warping such as WaNet, colour-shift such as SIG, frequency-domain). They concentrate no high-frequency energy, so the texture axis is blind; the spectral axis may still show a sub-population, which alone is held at review.
- Declared unsupported: model backdoors whose trigger is not a small local patch (blended, warping, colour-shift, semantic or physical-object triggers). Trigger inversion searches small local patches only; a clean scan says nothing about triggers outside that search space.
- Declared unsupported: backdoors in a model supplied only as a black box (ONNX) with no trace in the data. Inversion needs gradients (L3); a black box earns fingerprinting, transplant probes of data-derived candidates, re-execution and the pipeline differential, not inversion.
- Declared unsupported: behaviour of a model supplied only as a PyTorch .pt / .pth or TorchScript file. Those formats are pickles - programs - and are gated statically, never executed; their structure is scanned (malicious imports, escapes, bombs) but no behaviour is observed until the supplier exports ONNX (for Ultralytics, `yolo export model=best.pt format=onnx`).
- Declared unsupported: behaviour of an ONNX detector outside the recognised export families. The zoo interface and the yolov8 / yolov5 layouts are decoded; any other output layout is refused with the shape seen rather than decoded wrongly.
- Declared unsupported: signed-but-wrong inference outputs when the assessor holds no copy of the authorised model. Every provenance check passes; re-execution needs the model file registered in the trust store.
- Declared unsupported: a substitute model crafted to match the public challenge set. The fingerprint's challenge images are published and seeded; a model tuned to answer them as the registered one does is not caught by the fingerprint, only by the weight hash.
- Declared unsupported: truncation of the most recent inference records of a session. Nothing after the last record vouches for its existence without a separately published session head.
- Declared unsupported: a poisoned pretrained backbone. Embeddings are computed with the vendored backbone, which is trusted by assumption and pinned by hash, not assessed.
- Declared unsupported: poison spread thinly across many contributors. Every per-source test is powered by one source's evidence units; collusion below that power is invisible at source level.
- Declared unsupported: an adaptive attacker who reads this policy. Every threshold is published by design; an attacker who stays below all of them is not detected by a threshold.
- Declared unsupported: a contaminated drift reference. The reference is declared, not certified; contamination already in it becomes the baseline.
- Declared unsupported: physical adversarial patches, evasion, model extraction, sponge or denial-of-service attacks on the deployed model. Out of this build's scope - they are inference-time attacks on a deployed model, not integrity failures of the data, the model artifact or the records.
- Declared unsupported: text inside an image steering the semantic witness (prompt injection). A vision-language model reads text; a crop with words painted on it can change its answer, so the witness is one corroborating axis and never decides alone.
- Declared unsupported: adversarial patches against the semantic witness itself. The witness is a neural network and can be fooled like any other; its answers are measured for reliability per class, not trusted.
- Declared unsupported: detectors outside the zoo architecture. Weights are executed only in architectures this system defines (pramana-tinydet-v1 today); another architecture is assessed as ONNX (black box) or not at all.
- Not covered by any engine in this run: model file safety, inference-record provenance (no records supplied). Their absence from this report is a scope statement, not a clean result.
Safety gate
A contributed model file is a program, and opening one to assess it is itself a way into the enclave. This gate parses; it never deserialises.
What the gate checks when an artifact arrives
| ZIP structure | no `..` segments, no symlink entries, member cap |
| Decompression ratio | read from the directory - a bomb is never expanded to measure it |
| Import allowlist | every GLOBAL / STACK_GLOBAL against the entries a checkpoint needs |
| Extension opcodes | EXT1 / EXT2 / EXT4 refused - they name nothing checkable |
| Opcode count and depth | capped; exhausting our own parser is a denial of service |
| Storage sizes | declared element counts against the bytes actually present |
| ONNX operator domains | ai.onnx, ai.onnx.ml and an explicit permitted set |
| ONNX external data | absolute, `..`-escaping, symlinked or multiply-linked refused |
| Graph well-formedness | dangling inputs, cycles, declared shapes |
Read statically with pickletools.genops, the ZIP directory and a protobuf reader. No torch.load, no pickle.load, no onnx.load - an AST check in the acceptance suite asserts those names never appear as calls.
Engines this tier would gate
Greyed because they do not exist, not because a verdict stopped them. Unavailable-because-refused and unavailable-because-unbuilt are different claims and this screen keeps them apart.
Memory
Every engine is stateless, so on its own every run is a scan: assessment fifty knows nothing assessment one learned. This is what carries forward, and what refused to.
History for this source
| source | ver | dataset | units | severity | disposition | prior | state |
|---|---|---|---|---|---|---|---|
| unit_a | v1 | ds_b59693cc23ca | 274 | high | quarantine | corpus | active |
| unit_a | v2 | ds_b84bc6df0ba8 | 251 | high | quarantine | corpus | active |
| unit_a | v3 | ds_80909a6361a1 | 246 | medium | review | assurance_memory | active |
| unit_b | v1 | ds_b59693cc23ca | 257 | high | quarantine | corpus | active |
| unit_b | v2 | ds_b84bc6df0ba8 | 230 | high | quarantine | corpus | active |
| unit_b | v3 | ds_80909a6361a1 | 224 | medium | quarantine | assurance_memory | active |
| unit_d | v1 | ds_b59693cc23ca | 237 | high | quarantine | corpus | active |
| unit_d | v2 | ds_b84bc6df0ba8 | 223 | high | quarantine | corpus | active |
| unit_d | v3 | ds_80909a6361a1 | 219 | high | quarantine | assurance_memory | active |
| unit_c | v1 | ds_b59693cc23ca | 230 | high | quarantine | corpus | active |
| unit_c | v2 | ds_b84bc6df0ba8 | 211 | high | quarantine | corpus | active |
| unit_c | v3 | ds_80909a6361a1 | 203 | medium | review | assurance_memory | active |
Earlier submissions only — this run's own entry is written after adjudication, so what is shown is what the prior could actually see.
Store
| contributor_history | 12 |
| run_index | 3 |
Priors consulted
ds_80909a6361a1 (real-original-approved): 246 evidence units; flagged units: duplicate_flooding 0, exact_duplicate 0, labelling_inconsistency 0, mass_submission_anomaly 0, out_of_distribution 2, spectral_signature 1, swapped_label 18, trigger_texture 2, visual_duplicate 1, witness_label_disagreement 10, witness_marking 35
ds_b59693cc23ca (real-original): 274 evidence units; flagged units: duplicate_flooding 0, exact_duplicate 0, labelling_inconsistency 0, mass_submission_anomaly 0, out_of_distribution 1, spectral_signature 0, swapped_label 38, trigger_texture 3, visual_duplicate 1, witness_label_disagreement 26, witness_marking 43
ds_b84bc6df0ba8 (real-original-approved): 251 evidence units; flagged units: duplicate_flooding 0, exact_duplicate 0, labelling_inconsistency 0, mass_submission_anomaly 0, out_of_distribution 1, spectral_signature 0, swapped_label 24, trigger_texture 2, visual_duplicate 1, witness_label_disagreement 12, witness_marking 37
ds_80909a6361a1 (real-original-approved): 224 evidence units; flagged units: duplicate_flooding 0, exact_duplicate 0, labelling_inconsistency 0, mass_submission_anomaly 0, out_of_distribution 1, spectral_signature 0, swapped_label 17, trigger_texture 1, visual_duplicate 2, witness_label_disagreement 6, witness_marking 35
ds_b59693cc23ca (real-original): 257 evidence units; flagged units: duplicate_flooding 0, exact_duplicate 0, labelling_inconsistency 0, mass_submission_anomaly 0, out_of_distribution 0, spectral_signature 0, swapped_label 41, trigger_texture 1, visual_duplicate 2, witness_label_disagreement 25, witness_marking 48
ds_b84bc6df0ba8 (real-original-approved): 230 evidence units; flagged units: duplicate_flooding 0, exact_duplicate 0, labelling_inconsistency 0, mass_submission_anomaly 0, out_of_distribution 1, spectral_signature 0, swapped_label 20, trigger_texture 1, visual_duplicate 2, witness_label_disagreement 7, witness_marking 39
ds_80909a6361a1 (real-original-approved): 219 evidence units; flagged units: duplicate_flooding 0, exact_duplicate 0, labelling_inconsistency 0, mass_submission_anomaly 0, out_of_distribution 0, spectral_signature 0, swapped_label 12, trigger_texture 1, visual_duplicate 3, witness_label_disagreement 9, witness_marking 34
ds_b59693cc23ca (real-original): 237 evidence units; flagged units: duplicate_flooding 0, exact_duplicate 0, labelling_inconsistency 0, mass_submission_anomaly 0, out_of_distribution 0, spectral_signature 0, swapped_label 23, trigger_texture 1, visual_duplicate 3, witness_label_disagreement 16, witness_marking 40
ds_b84bc6df0ba8 (real-original-approved): 223 evidence units; flagged units: duplicate_flooding 0, exact_duplicate 0, labelling_inconsistency 0, mass_submission_anomaly 0, out_of_distribution 0, spectral_signature 0, swapped_label 13, trigger_texture 2, visual_duplicate 3, witness_label_disagreement 10, witness_marking 36
ds_80909a6361a1 (real-original-approved): 203 evidence units; flagged units: duplicate_flooding 0, exact_duplicate 0, labelling_inconsistency 0, mass_submission_anomaly 0, out_of_distribution 0, spectral_signature 0, swapped_label 18, trigger_texture 1, visual_duplicate 0, witness_label_disagreement 8, witness_marking 31
ds_b59693cc23ca (real-original): 230 evidence units; flagged units: duplicate_flooding 0, exact_duplicate 0, labelling_inconsistency 0, mass_submission_anomaly 0, out_of_distribution 0, spectral_signature 0, swapped_label 33, trigger_texture 3, visual_duplicate 0, witness_label_disagreement 20, witness_marking 38
ds_b84bc6df0ba8 (real-original-approved): 211 evidence units; flagged units: duplicate_flooding 0, exact_duplicate 0, labelling_inconsistency 0, mass_submission_anomaly 0, out_of_distribution 1, spectral_signature 0, swapped_label 26, trigger_texture 1, visual_duplicate 0, witness_label_disagreement 11, witness_marking 33
History set aside, and under which rule
Nothing was excluded.
What the prior withdrew
Nothing was withdrawn. A prior may only withdraw a MARGINAL source-level abnormality and may never add one, raise a verdict, or touch a finding — so withdrawing nothing is the ordinary outcome, not a silent one. It is said here because a screen that showed only withdrawals would leave a reader unable to tell "the prior declined" from "the prior never ran".
Run diff, two digests
No earlier run of this dataset is recorded, so there is nothing to diff against yet.
Readiness
How much of this submission is usable, what that judgement rests on, and what it cannot see.
408 of 890 images (45.8%) carry no finding. 482 were named by at least one engine and need review before use.
This number is not calibrated and does not mean "27.1% safe". It is an arithmetic summary of what was flagged, scaled by how much of the system actually ran. Read the panel below before quoting it.
How the number was produced
| severity | images | of corpus | weight | points |
|---|---|---|---|---|
| high | 1 | 0.112% | ×8.0 | −0.9 |
| info | 4 | 0.449% | ×0.0 | −0.0 |
| low | 339 | 38.09% | ×0.5 | −19.04 |
| medium | 202 | 22.697% | ×2.0 | −45.39 |
Coverage is 51%: 21 of 41 assessments were actually attempted. An engine that did not run is not a pass, so it pulls the score down rather than being silently left out of it. Weights are in policy.yaml, not in this page.
What is wrong, and what each costs to fix
| defect | images | of corpus | findings | what it means you do |
|---|---|---|---|---|
| witness_scene_mismatch | 301 | 33.82% | 301 | confirm the image belongs in this corpus |
| witness_marking | 133 | 14.94% | 133 | inspect the object for a stamp or patch |
| swapped_label | 63 | 7.08% | 64 | re-annotate the box; the neighbour vote disagrees |
| witness_label_disagreement | 33 | 3.71% | 33 | re-annotate: an independent model disagrees with the label |
| visual_duplicate | 12 | 1.35% | 4 | collapse the cluster to one representative |
| trigger_texture | 5 | 0.56% | 5 | inspect the object for a stamped pattern; check its label |
| out_of_distribution | 3 | 0.34% | 3 | confirm it belongs in this corpus at all |
| mass_submission_anomaly | 1 | 0.11% | 1 | investigate the source before accepting |
| spectral_signature | 1 | 0.11% | 1 | inspect the class's outlying sub-population and its source |
Image counts across rows overlap - one image can carry more than one defect - so they do not sum to the flagged total. The remedies differ by class and that is the point: a duplicate is deleted, a swapped label is re-annotated, and leakage invalidates a whole split rather than an image.
Where the findings fall
| split | findings |
|---|---|
| (cluster-level) | 5 |
| test | 1 |
| train | 488 |
| valid | 51 |
Cluster-level findings name a group rather than a single split, so they are listed separately rather than assigned to one.
Recommended disposition
| review | 545 |
Disposition is an instruction from the correlation layer, not a severity restated. Everything here is advisory: nothing is deleted or quarantined by this tool.
What this number does not know
- Not calibrated as a probability. 531 of 545 statistical findings carry a confidence the attack harness measured against planted truth; the rest are provisional heuristics. The score itself is an arithmetic summary of findings, not a probability that the data is safe.
- Says nothing about what was MISSED. Recall is unmeasurable without planted ground truth, so a high score from an engine that found nothing is indistinguishable from a high score that was earned.
- Merges severity and confidence, which this system separates everywhere else. It cannot express 'high severity, low confidence' - the state that most needs a human.
- 10 engine(s) did not run (backdoor_scan, behaviour_probe, inference_provenance, inference_reexecution, model_fingerprint, model_safety_gate, model_spectral, pipeline_differential, poison_localization, weight_integrity), so 20 of 41 assessments were never attempted. The coverage multiplier below reflects this; it does not repair it.
Every item above is generated from what this run actually did. The list shrinks as the gaps close - it is not a fixed disclaimer.
Claims
What this assessment set out to establish, what the evidence supports, and the single action that follows - the most severe claim gate, never an average.
REVIEW: set by claim(s) C1.1, C1.2, C1.3, C1.4, C1.5, C1.6. Across 10 in-scope claim(s): 4 supported, 6 weakened. The action is the most severe claim gate - never an average, never a score.
Out of scope for this submission: C2.1, C2.2, C2.3, C2.4, C2.5, C3.1, C3.2, C3.3, C3.4.
1 Training-data integrity
| claim | statement | state | gate |
|---|---|---|---|
| C1.1 | No contributor floods the corpus with near-duplicate content. training data whyWeakened by 1 item(s) held for review, recalibration or as inconclusive: f_a04b2eab38fb. Requirements ✓ source-concentrated near-duplicate flooding ✓ per-contributor duplication lift against the corpus Defeaters duplicate_flooding, mass_submission_anomaly Re-run to reassess duplicate_flooding A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ◐ WEAKENED | review |
| C1.2 | Labels are consistent - no label flipping and no systematic mislabelling by any source. training data whyWeakened by 97 item(s) held for review, recalibration or as inconclusive: f_093b8625fe9c, f_09bf71b35681, f_0d2738e0c068, f_1ce9ecf8acca, f_35d500125ef5, f_37592174be07.... Requirements ✓ embedding neighbour-vote label disagreement ✓ intra-cluster labelling disagreement ✓ per-contributor directional label confusion against a leave-one-out baseline Defeaters swapped_label, labelling_inconsistency, contributor_confusion, witness_label_disagreement Re-run to reassess contributor_confusion, label_consistency, near_duplicate A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ◐ WEAKENED | review |
| C1.3 | No out-of-distribution population was inserted. training data whyWeakened by 304 item(s) held for review, recalibration or as inconclusive: f_5676e0b834aa, f_674185fe8178, f_fc9a49bb3db7, f_0081c05ad51d, f_0105e0612e8c, f_02beeb8c9b64.... Requirements ✓ kNN-distance outlier scoring (local) ✓ Mahalanobis outlier scoring (global) Defeaters out_of_distribution, witness_scene_mismatch Re-run to reassess out_of_distribution A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ◐ WEAKENED | review |
| C1.4 | No trigger-bearing samples were injected. training data whyWeakened by 139 item(s) held for review, recalibration or as inconclusive: f_1e6ae9b6eace, f_2ff17c59b869, f_6f8a03b8e5f8, f_7767de764ae2, f_78c5daa6cbda, f_815e84a2fc9c.... Requirements ✓ trigger-pattern scan of training data ✓ local texture anomaly scan for stamped triggers Defeaters trigger_texture, spectral_signature, model_spectral_signature, poison_localized, witness_marking Re-run to reassess spectral_signature, trigger_texture A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ◐ WEAKENED | review |
| C1.5 | The evaluation split is independent of the training split, and redundancy does not inflate the corpus. training data whyWeakened by 4 item(s) held for review, recalibration or as inconclusive: f_8aedf39c15eb, f_9ac290dece2d, f_ad263d9d8a0e, f_b34cfb17f3a4. Requirements ✓ byte-identical duplicate detection over SHA-256 ✓ near-duplicate clustering over perceptual hash and embedding ✓ train/validation leakage detection Defeaters split_leakage, exact_duplicate, visual_duplicate Re-run to reassess exact_duplicate, near_duplicate A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ◐ WEAKENED | review |
| C1.6 | No contributing source is abnormal against its peers. contributing sources whyWeakened by 4 item(s) held for review, recalibration or as inconclusive: contributor:unit_a, contributor:unit_b, contributor:unit_d, contributor:unit_c. Requirements ✓ source-concentrated near-duplicate flooding ✓ per-contributor directional label confusion against a leave-one-out baseline Re-run to reassess contributor_confusion, duplicate_flooding A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ◐ WEAKENED | review |
2 Model integrity
| claim | statement | state | gate |
|---|---|---|---|
| C2.1 | The model artifact is safe to open. model - out of scope whyOut of scope for this submission (no model file was supplied); shown for completeness. Unresolved: 3 of 3 required assessment(s) did not run - model_safety_gate did not run: no model artifact was supplied with this dataset (none under <workspace>/models/), so there was nothing to gate. This is the absence of an artifact, not a clean bill of health for one.; model_safety_gate did not run: no model artifact was supplied with this dataset (none under <workspace>/models/), so there was nothing to gate. This is the absence of an artifact, not a clean bill of health for one.; model_safety_gate did not run: no model artifact was supplied with this dataset (none under <workspace>/models/), so there was nothing to gate. This is the absence of an artifact, not a clean bill of health for one.. Requirements ○ static pickle opcode analysis against an import allowlist (did not run) ○ archive structure: traversal, symlinks, decompression ratio (did not run) ○ ONNX operator domains and external-data references (did not run) Defeaters malicious_model_file, external_data_escape, unrecognized_import, structural_corruption Re-run to reassess model_safety_gate A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ? UNRESOLVED | inconclusive |
| C2.2 | The model that produced the outputs is the authorised model, not a substitute. model - out of scope whyOut of scope for this submission (no inference records were supplied); shown for completeness. Unresolved: 1 of 1 required assessment(s) did not run - inference_provenance did not run: no inference records were supplied with this submission (`ps ingest records` stores them). Requirements ○ model identity against the authorised deployment (did not run) Defeaters model_substitution Re-run to reassess inference_provenance A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ? UNRESOLVED | inconclusive |
| C2.3 | The model exhibits no backdoor-like behaviour, and no trigger carried by the data moves it. model - out of scope whyOut of scope for this submission (no model file was supplied); shown for completeness. Unresolved: 2 of 2 required assessment(s) did not run - backdoor_scan did not run: no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one; behaviour_probe did not run: no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one. Requirements ○ backdoor trigger inversion (did not run) ○ transplant probing of candidate triggers through the full pipeline (did not run) Defeaters backdoor_trigger, trigger_behaviour Re-run to reassess backdoor_scan, behaviour_probe A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ? UNRESOLVED | inconclusive |
| C2.4 | The model is the authorised model - its weights and its behaviour match the registered deployment. model - out of scope whyOut of scope for this submission (no model file was supplied); shown for completeness. Unresolved: 2 of 2 required assessment(s) did not run - weight_integrity did not run: no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one; model_fingerprint did not run: no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one. Requirements ○ weight and graph integrity (did not run) ○ behavioural fingerprinting (did not run) Defeaters weight_mismatch, behaviour_mismatch Re-run to reassess model_fingerprint, weight_integrity A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ? UNRESOLVED | inconclusive |
| C2.5 | The deployed pre- and post-processing behave as the authorised configuration. deployed pipeline - out of scope whyOut of scope for this submission (no model file was supplied); shown for completeness. Unresolved: 1 of 1 required assessment(s) did not run - pipeline_differential did not run: no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one. Requirements ○ twin-pipeline differential of the deployed configuration (did not run) Defeaters pipeline_divergence Re-run to reassess pipeline_differential A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ? UNRESOLVED | inconclusive |
3 Inference provenance
| claim | statement | state | gate |
|---|---|---|---|
| C3.1 | Every inference record is authentic and unaltered since sealing. inference records - out of scope whyOut of scope for this submission (no inference records were supplied); shown for completeness. Unresolved: 2 of 2 required assessment(s) did not run - inference_provenance did not run: no inference records were supplied with this submission (`ps ingest records` stores them); inference_provenance did not run: no inference records were supplied with this submission (`ps ingest records` stores them). Requirements ○ inference-record integrity (digest recomputation) (did not run) ○ inference-record signatures against the trust store (did not run) Defeaters record_altered, signature_invalid, untrusted_signer, record_unsigned, record_unparseable Re-run to reassess inference_provenance A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ? UNRESOLVED | inconclusive |
| C3.2 | The inference log is complete, in order, and free of replays. inference records - out of scope whyOut of scope for this submission (no inference records were supplied); shown for completeness. Unresolved: 2 of 2 required assessment(s) did not run - inference_provenance did not run: no inference records were supplied with this submission (`ps ingest records` stores them); inference_provenance did not run: no inference records were supplied with this submission (`ps ingest records` stores them). Requirements ○ inference log continuity: deletion, reordering, splicing (did not run) ○ inference-record replay (did not run) Defeaters record_replayed, chain_fork, record_deleted, record_reordered, chain_break Re-run to reassess inference_provenance A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ? UNRESOLVED | inconclusive |
| C3.3 | Every output is bound to its input image, model and pre/post-processing configuration. inference records - out of scope whyOut of scope for this submission (no inference records were supplied); shown for completeness. Unresolved: 3 of 3 required assessment(s) did not run - inference_provenance did not run: no inference records were supplied with this submission (`ps ingest records` stores them); inference_provenance did not run: no inference records were supplied with this submission (`ps ingest records` stores them); inference_provenance did not run: no inference records were supplied with this submission (`ps ingest records` stores them). Requirements ○ input binding: substitution versus benign re-encoding (did not run) ○ pre/post-processing configuration against the deployment (did not run) ○ model identity against the authorised deployment (did not run) Defeaters input_substituted, input_missing, config_mismatch, model_substitution Re-run to reassess inference_provenance A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ? UNRESOLVED | inconclusive |
| C3.4 | Every sealed output is what the model would produce on its input. inference records - out of scope whyOut of scope for this submission (no inference records were supplied); shown for completeness. Unresolved: 1 of 1 required assessment(s) did not run - inference_reexecution did not run: no inference records were supplied with this submission. Requirements ○ re-execution of sealed inferences (signed but wrong) (did not run) Defeaters output_mismatch Re-run to reassess inference_reexecution A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ? UNRESOLVED | inconclusive |
4 Distribution shift
| claim | statement | state | gate |
|---|---|---|---|
| C4.1 | The data matches the declared reference, or its deviation is explained operational drift. deployment data whySupported: all 3 required assessment(s) ran and no defeater reached review. Requirements ✓ distribution drift against a reference profile ✓ calibrated shift test (permutation p-value) ✓ drift versus manipulation signatures Defeaters distribution_shift, contributor_shift, class_shift Re-run to reassess distribution_shift A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ✓ SUPPORTED | accept |
5 Analyst-facing assurance
| claim | statement | state | gate |
|---|---|---|---|
| C5.1 | Every flag carries a reason, evidence, a confidence, limitations and a recommended disposition. this report whySupported: 545 finding(s) checked; every one carries all five. Requirements ✓ flags_complete A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ✓ SUPPORTED | accept |
| C5.2 | The audit ledger this assessment will be appended to is intact. audit trail whySupported: ledger of 3 entries and 3 tree head(s) recomputed; intact. Requirements ✓ ledger_intact A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ✓ SUPPORTED | accept |
| C5.3 | The assessment's own controls passed their known-answer tests before it ran. this assessment whySupported: 5 of 5 known-answer tests passed. Requirements ✓ preflight A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ✓ SUPPORTED | accept |
Provenance
Every inference sealed at the node binds the input image, the model, the pre- and post-processing configuration and the output, and links to the record before it. This stage re-verifies all of it.
How records reach this stage
A node seals each inference with ps provenance seal; the log is stored write-once with ps ingest records; a downstream consumer can verify on its own with ps provenance verify.
Drift
Is this data still what the reference was - and if not, did the world change, or did someone change the data?
no global shift at p <= 0.05 and no contributor or class slice significant after correction
A written rule in policy.yaml (shift:) over four measured signatures - not a trained classifier.
By contributor
| contributor | objects | kernel p | nonconforming / expected | q | |
|---|---|---|---|---|---|
| unit_a | 269 | 0.0465 | 9 / 10.2 | 0.372 | - |
| unit_b | 261 | 0.262 | 13 / 9.55 | 0.673 | - |
| unit_c | 223 | 0.252 | 8 / 8.62 | 0.673 | - |
| unit_d | 235 | 0.339 | 5 / 9.2 | 0.678 | - |
By class
| class | objects | kernel p | nonconforming / expected | q | |
|---|---|---|---|---|---|
| civ_hel | 68 | 0.249 | 4 / 2.96 | 0.797 | - |
| drone | 33 | 0.791 | 0 / 0.0 | 1 | - |
| jet | 147 | 0.0266 | 5 / 6.84 | 0.106 | - |
| land | 599 | 0.983 | 26 / 27.79 | 1 | - |
| large_mil_plane | 66 | 0.0266 | 0 / 0.0 | 0.106 | - |
| mil_helicopter | 38 | 0.0199 | 0 / 0.0 | 0.106 | - |
| stealth | 27 | 0.00332 | 0 / 0.0 | 0.0532 | - |
| tech_vehicle | 10 | 0.468 | 0 / 0.0 | 1 | - |
What the conditions did
| factor | reference | submission | shift | units | q |
|---|---|---|---|---|---|
| brightness | 128.762 | 129.2756 | +0.02 | reference MADs | 1 |
| contrast | 60.8209 | 61.1763 | +0.03 | reference MADs | 1 |
| sharpness | 2.4594 | 2.47 | +0.05 | reference MADs | 1 |
| noise | 0.8239 | 0.8192 | -0.01 | reference MADs | 1 |
| saturation | 51.0251 | 51.4706 | +0.02 | reference MADs | 1 |
| warmth | 3.2372 | 2.8066 | -0.03 | reference MADs | 1 |
| dark_channel | 113.2578 | 113.998 | +0.03 | reference MADs | 1 |
| entropy | 5.3468 | 5.3326 | -0.04 | reference MADs | 1 |
| log_area | 5.6124 | 5.6124 | +0.00 | raw difference (reference constant) | 1 |
| jpeg_quality | 74.8 | 74.8 | +0.00 | raw difference (reference constant) | 1 |
Physical descriptors measured at ingest. A shift the descriptors alone can reproduce is expressible as lighting, lens, sensor or compression; one they cannot is something else.
Audit ledger
Every assessment is appended to a Merkle log in the construction Certificate Transparency uses, with a signed tree head after each. Rewriting history breaks every later head; a head held elsewhere catches even a rewrite by someone holding the key.
Latest tree head
Copy this head somewhere this machine cannot write - a printed report, another unit, a witness co-signature (ps audit witness). It is the only thing that catches a rewrite by someone who holds both this directory and the assessor key.
Recent entries
| # | kind | run | findings digest | decision | leaf |
|---|---|---|---|---|---|
| 0 | assessment | real-original | 0655b6ac5735 | quarantine | 323b619f8b94 |
| 1 | assessment | real-original-approved | 55d21552a260 | quarantine | 2a4a6e28145b |
| 2 | assessment | real-original-approved | e625df1b648c | quarantine | 59a152cda8a4 |
Re-run any assessment against its pins with ps audit replay --run real-original-approved; see which of its claims have gone stale with ps audit delta --run real-original-approved.
Model behaviour
The model is run, and what it does is evidence: is it the authorised model, does a small patch turn one class into another, which training samples taught it that, and does every sealed output reproduce?
Engines
| weight_integrity | not run | no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one |
| model_fingerprint | not run | no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one |
| backdoor_scan | not run | no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one |
| poison_localization | not run | no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one |
| model_spectral | not run | no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one |
| behaviour_probe | not run | no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one |
| inference_reexecution | not run | no inference records were supplied with this submission |
| pipeline_differential | not run | no model artifact was supplied with this submission (none under <workspace>/models/); model behaviour cannot be observed without one |
Investigation
Data evidence forms hypotheses; the model is asked to confirm them, most promising first. Every experiment is listed with why it ran when it did, and what it measured - including the ones that did not reproduce anything.
Witness audit
A local vision-language model asked three closed questions about every object. This is its opinion - what it named each class, where it disagreed, and how often an independent engine agreed with it - so an analyst can see what its flags are worth before acting on them.
What it was asked, verbatim
| label | Which of these is the main object in this image? |
| marking | Does the main object carry a sticker, a patch, a checkerboard, a printed pattern or any other unusual marking that is not part of its normal insignia, numbers or camouflage? |
| scene | Is this a real photograph (not a render, drawing, painting or screenshot)? |
What it was told each class means
Declared by the assessor, beside witness.json - never taken from the submission, because whoever writes it can steer the answers.
| civ_hel | civilian helicopter - including police, medical, news, rescue and private helicopters, whatever the colour |
| drone | drone or unmanned aerial vehicle |
| jet | military jet aircraft - fighter or attack jet |
| land | military ground vehicle - tank, armoured personnel carrier, self-propelled artillery or missile launcher |
| large_mil_plane | large military aircraft - transport, tanker, bomber or surveillance plane |
| mil_helicopter | military helicopter - armed forces, with military markings, camouflage, weapons or a military transport design |
| stealth | stealth aircraft - angular low-observable design such as the B-2, F-117, F-22 or F-35 |
| tech_vehicle | technical - civilian pickup or truck fitted with a weapon |
What it named, per declared class
| declared class | objects | named it | when it did not, it chose | label flags | marking flags | scene flags |
|---|---|---|---|---|---|---|
| civ_hel | 68 | 99% | mil_helicopter 1 | 1 (1%) | 8 (12%) | 17 (25%) |
| drone | 33 | 100% | - | 0 (0%) | 2 (6%) | 4 (12%) |
| jet | 139 | 89% | stealth 7, large_mil_plane 4, none of these 2 | 11 (8%) | 36 (26%) | 51 (37%) |
| land | 522 | 98% | none of these 6, mil_helicopter 5, civ_hel 1 | 11 (2%) | 85 (16%) | 211 (40%) |
| large_mil_plane | 63 | 100% | - | 0 (0%) | 1 (2%) | 9 (14%) |
| mil_helicopter | 28 | 96% | civ_hel 1 | 0 (0%) | 0 (0%) | 5 (18%) |
| stealth | 27 | 41% | large_mil_plane 16 | 10 (37%) | 1 (4%) | 4 (15%) |
| tech_vehicle | 10 | 80% | land 2 | 0 (0%) | 0 (0%) | 0 (0%) |
A class it rarely names is either mislabelled, genuinely confusable with the class it chose, or named by a code it cannot read - the per-class row says which class, never which of the three.
What its flags are worth
- label - 33 flag(s). 33 rest on the witness alone (measured precision 16% for a lone flag of this type); 0 are corroborated by at least one other independent axis (no harness measurement). 0 coincide with a swapped_label flag from the embedding neighbour vote on the same object.
- marking - 133 flag(s). 133 rest on the witness alone (measured precision 5% for a lone flag of this type); 0 are corroborated by at least one other independent axis (no harness measurement). 0 coincide with a trigger_texture flag from the high-frequency texture scan on the same object.
- scene - 301 flag(s). 301 rest on the witness alone (measured precision 0% for a lone flag of this type); 0 are corroborated by at least one other independent axis (no harness measurement). 0 coincide with a out_of_distribution flag from the kNN / Mahalanobis outlier test on the same object.
"Measured precision" is the attack harness's: of such findings in its planted-truth scenarios, the share that named a real planted defect. A flag only the witness raises is an opinion to review; the correlation layer never lets it quarantine alone.