Intake
What arrived, who it came from, and what this run is capable of assessing before a single measurement is taken.
Submissions per contributor
Attribution came from contributors_csv. Where it is unavailable every sample resolves to unknown — a real string, not a contributor — and source-level assessment is refused rather than computed over it.
Capability negotiation
Capability is a function of two variables: how much of the model we can see, and what reference material exists to compare against. The cell decides which engines may run and what confidence any of them can reach. It is declared at intake, not inferred.
| R0 nothing | R1 digest | R2 baseline | R3 clean data | |
|---|---|---|---|---|
| L0 | · | · | · | · |
| L1 | · | · | · | · |
| L2 | · | · | · | · |
| L3 | · | THIS RUN | · | · |
At L0/R0 — artifact bytes, no reference — almost nothing works at any access level. Stating that is stronger than pretending otherwise.
Preprocess
Hash every image for exact identity, perceptually hash it for near identity, embed it for semantic geometry — then collapse what is not independent.
The denominator of every rate in this report
Two hundred duplicates of one image are one piece of evidence, not two hundred. Treating them as independent trials produces credible intervals an order of magnitude too narrow, and it is the single easiest way to turn one careless upload into a fabricated threat signal. Every rate downstream is computed over evidence units.
dHash union-find at Hamming <= 5, banded candidate generation
Engines
Five detectors, each declaring the axis of physical evidence it reads and the capability it needs. None of them decides anything.
Findings emitted per engine
Count is not importance. An engine that emits forty findings has not found forty attacks — it has taken forty measurements, and what they mean is decided two stages from here.
What each engine is valid for
| Engine | Axis | Needs | Ran | Findings | Ceiling | Valid poison ratio | Failure mode above range |
|---|---|---|---|---|---|---|---|
| model_safety_gate | deterministic | L0/R0 | ran | 6 | not_declared | robust - no minority assumption | robust - static structure, no minority assumption. It is bounded differently- by the allowlist, which reports what it does not recognise rather than what it knows to be bad |
| exact_duplicate | identity | L0/R0 | ran | 4 | not_declared | robust - no minority assumption | robust - deterministic |
| near_duplicate | pixel | L0/R0 | ran | 21 | not_declared | robust - no minority assumption | robust - cluster size is measured, not compared to a corpus baseline |
| duplicate_flooding | metadata | L0/R0 | ran | 2 | not_declared | robust - no minority assumption | robust - size-based, does not assume the anomaly is a minority |
| label_consistency | semantic | L0/R0 | ran | 212 | not_declared | < 30% | neighbour vote inverts; the flipped label becomes the majority |
| out_of_distribution | semantic | L0/R0 | ran | 16 | not_declared | < 10% | silent false negative - the outlier population becomes the reference |
| contributor_confusion | semantic | L0/R0 | ran | 4 | not_declared | < 30% | neighbour vote inverts once a class is roughly 30% flipped corpus-wide - the flipped label becomes the neighbourhood's and the direction disappears; a contributor who dominates a class also leaves the leave-one-out baseline too little of it to compare against |
| trigger_texture | frequency | L0/R0 | ran | 74 | not_declared | robust - no minority assumption | robust to poison ratio - scored against the corpus median, which a stamp on a minority of objects cannot move; blind to smooth triggers (blend, warp, colour shift) at any ratio |
| spectral_signature | semantic | L0/R0 | ran | 0 | not_declared | < 33% | the poisoned sub-population becomes large enough to move the class mean and share the top direction with clean variation; separation fades rather than failing loudly |
| semantic_witness | witness | L0/R0 | ran | 1065 | insufficient_evidence | robust - no minority assumption | not characterised |
| inference_provenance | provenance | L0/R0 | ran | 16 | not_declared | robust - no minority assumption | robust - cryptographic, no minority assumption. It is bounded by key custody instead- a node whose signing key is compromised seals records this engine accepts |
| distribution_shift | semantic | L0/R1 | ran | 8 | not_declared | robust - no minority assumption | bounded by the reference, not by a poison ratio - a reference that already holds the manipulation absorbs it, and the shift test then reports its REMOVAL as the change |
| weight_integrity | deterministic | L0/R0 | ran | 1 | not_declared | robust - no minority assumption | not characterised |
| model_fingerprint | model_behaviour | L1/R0 | ran | 1 | not_declared | robust - no minority assumption | not characterised |
| backdoor_scan | model_behaviour | L3/R0 | ran | 3 | not_declared | robust - no minority assumption | robust to poison ratio - the model is probed, not the corpus; bounded instead by the search space (small local patches) and by how strongly the backdoor was learned |
| poison_localization | model_behaviour | L2/R0 | ran | 10 | not_declared | < 50% | once poison is most of the target class its mean moves toward the trigger and the affinity score stops separating the two |
| model_spectral | model_behaviour | L2/R0 | ran | 148 | not_declared | < 33% | the same as D11 - a poison that is a large share of the class moves the mean and shares the top direction; separation fades rather than failing loudly. It also inherits the model's own blind spots, and a class the model learned badly shows a signature without any poison |
| behaviour_probe | model_behaviour | L1/R0 | ran | 6 | not_declared | robust - no minority assumption | not characterised |
| inference_reexecution | model_behaviour | L0/R0 | ran | 6 | not_declared | robust - no minority assumption | not characterised |
| pipeline_differential | model_behaviour | L1/R0 | ran | 1 | not_declared | robust - no minority assumption | not characterised |
Outlier-based engines assume the anomaly is a minority and fail silently above their range: at a high enough poison ratio the poison becomes the norm and the system reports fewer findings, not more. Publishing the bound is a coverage dimension, and it is why the size-based flood detector exists alongside them.
Vector space
The corpus as the engines see it. Orbit it, pick a point, and the neighbours that come back are the ones the label engine actually voted over.
Selected point
Click any point to inspect it. Nothing is selected yet.
Nearest neighbours
Exact cosine neighbours over the full embedding, not an approximation — the same ranking the label engine voted over. Select a point to see them.
Evidence
The measurements themselves. Every finding shows its numbers, its pictures, and what it cannot tell you.
duplicate_flooding
highunit_e31 of 31 shown31 near-identical images, 97% of them from unit_e, all carrying class 'land'. A single source repeating one scene at this multiplicity shifts what the model learns about it without mislabelling anything.
All findings
| Severity | Confidence | Finding | Axes | Contributor | Score | Disposition |
|---|
Traceback
Every verdict, walked back to the bytes it came from. Pick a source and follow the chain — samples, the clusters they collapse into, the findings those raised, the axes that agreed, and the rule that produced the disposition.
Corroborate
An anomaly is never, by itself, an attack. This is where measurements become a judgement — and where two engines reading the same signal stop counting as two.
Measured evidence independence
Rank correlation of each engine pair over dense per-sample scores — every sample, not only the flagged ones. Correlating findings alone would be circular: two engines that never fire on the same asset look independent precisely because neither fired.
The corroboration rule
| 0 axes | no finding |
| 1 axis | data quality → review |
| broad, uncorrelated | drift → recalibrate, never quarantine |
| ≥ 11 axes | attack → quarantine |
The rule governs escalation, not visibility. Nothing is suppressed — a single-axis anomaly still reaches the analyst queue. What corroboration controls is what gets the word attack attached, and what interrupts someone at 2am.
124 pair(s) had too few shared samples to measure and were treated as independent — the permissive direction, reported rather than hidden.
Sources
Sample-level evidence aggregated into a source-level assessment — in evidence units, against baselines that exclude the contributor being tested.
unit_b
highquarantine380 samples → 379 evidence unitsunit_b: 4 abnormal axis/axes across 379 independent evidence units (380 samples). trigger_texture 73/379 units (19.3% vs 0.1% baseline, 154.1x, q=0.0000); contributor_confusion 68/130 off-diagonal observations in one class pair (52.3% vs 0.6% baseline, 84.2x, q=0.0000); model_spectral_signature 108/379 units (28.5% vs 4.9% baseline, 5.8x, q=0.0000); witness_label_disagreement 167/379 units (44.1% vs 15.5% baseline, 2.8x, q=0.0000); witness_marking 164/379 units (43.3% vs 16.1% baseline, 2.7x, q=0.0000) Carried forward from the findings list: 580 finding(s) name unit_b directly (model_spectral_signature, poison_localized, swapped_label, trigger_behaviour, trigger_texture, witness_label_disagreement, witness_marking, witness_scene_mismatch), at severity high. Note that this did not come from a rate test - it cannot, because the evidence collapses to 379 independent unit(s) - it comes from the absolute size of what was submitted.
unit_f
highquarantine15 samples → 15 evidence unitsunit_f: 2 abnormal axis/axes across 15 independent evidence units (15 samples). out_of_distribution 15/15 units (100.0% vs 0.1% baseline, 1161.0x, q=0.0000); witness_label_disagreement 15/15 units (100.0% vs 23.8% baseline, 4.2x, q=0.0000) Carried forward from the findings list: 54 finding(s) name unit_f directly (model_spectral_signature, out_of_distribution, poison_localized, swapped_label, trigger_texture, witness_label_disagreement, witness_scene_mismatch), at severity high. Note that this did not come from a rate test - it cannot, because the evidence collapses to 15 independent unit(s) - it comes from the absolute size of what was submitted.
unit_d
highquarantine251 samples → 248 evidence unitsunit_d: 1 abnormal axis/axes across 248 independent evidence units (251 samples). contributor_confusion 5/53 off-diagonal observations in one class pair (9.4% vs 0.0% baseline, 999.0x, q=0.0025); contributor_confusion 12/53 off-diagonal observations in one class pair (22.6% vs 2.1% baseline, 10.8x, q=0.0000) Carried forward from the findings list: 108 finding(s) name unit_d directly (model_spectral_signature, swapped_label, witness_label_disagreement, witness_marking, witness_scene_mismatch), at severity high. Note that this did not come from a rate test - it cannot, because the evidence collapses to 248 independent unit(s) - it comes from the absolute size of what was submitted.
unit_g
highquarantine124 samples → 124 evidence unitsunit_g: 1 abnormal axis/axes across 124 independent evidence units (124 samples). contributor_confusion 6/23 off-diagonal observations in one class pair (26.1% vs 1.9% baseline, 14.0x, q=0.0009) Carried forward from the findings list: 20 finding(s) name unit_g directly (swapped_label, witness_label_disagreement, witness_marking, witness_scene_mismatch), at severity high. Note that this did not come from a rate test - it cannot, because the evidence collapses to 124 independent unit(s) - it comes from the absolute size of what was submitted.
unit_a
highquarantine220 samples → 216 evidence unitsunit_a: 220 samples across 216 independent evidence units. No axis exceeds its leave-one-out baseline at q<=0.05 with lift >=2.0. Carried forward from the findings list: 73 finding(s) name unit_a directly (model_spectral_signature, out_of_distribution, poison_localized, swapped_label, witness_label_disagreement, witness_marking, witness_scene_mismatch), at severity high. Note that this did not come from a rate test - it cannot, because the evidence collapses to 216 independent unit(s) - it comes from the absolute size of what was submitted.
unit_c
highquarantine209 samples → 199 evidence unitsunit_c: 209 samples across 199 independent evidence units. No axis exceeds its leave-one-out baseline at q<=0.05 with lift >=2.0. Carried forward from the findings list: 53 finding(s) name unit_c directly (model_spectral_signature, poison_localized, swapped_label, witness_label_disagreement, witness_marking, witness_scene_mismatch), at severity high. Note that this did not come from a rate test - it cannot, because the evidence collapses to 199 independent unit(s) - it comes from the absolute size of what was submitted.
unit_e
highreview30 samples → 1 evidence unitsunit_e contributed 30 samples collapsing to 1 independent evidence unit(s), below the 5 this policy requires before a rate is meaningful. No assessment is made. Carried forward from the findings list: 1 finding(s) name unit_e directly (duplicate_flooding), at severity high. Note that this did not come from a rate test - it cannot, because the evidence collapses to 1 independent unit(s) - it comes from the absolute size of what was submitted.
Coverage
What this run measured about itself, what it could not see, and why its absence is not a clean result.
Every assessment this system can make, and whether it was made here
| assessment | engine | state | why |
|---|---|---|---|
| static pickle opcode analysis against an import allowlist | model_safety_gate | covered | 6 findings from this engine |
| archive structure: traversal, symlinks, decompression ratio | model_safety_gate | covered | 6 findings from this engine |
| ONNX operator domains and external-data references | model_safety_gate | covered | 6 findings from this engine |
| safetensors header structure: dtypes, shapes, spans | model_safety_gate | covered | 6 findings from this engine |
| the access tier the artifact earns for the whole assessment | model_safety_gate | covered | 6 findings from this engine |
| byte-identical duplicate detection over SHA-256 | exact_duplicate | covered | 4 findings from this engine |
| near-duplicate clustering over perceptual hash and embedding | near_duplicate | covered | 21 findings from this engine |
| train/validation leakage detection | near_duplicate | covered | 21 findings from this engine |
| intra-cluster labelling disagreement | near_duplicate | covered | 21 findings from this engine |
| source-concentrated near-duplicate flooding | duplicate_flooding | covered | 2 findings from this engine |
| per-contributor duplication lift against the corpus | duplicate_flooding | covered | 2 findings from this engine |
| embedding neighbour-vote label disagreement | label_consistency | covered | 212 findings from this engine |
| per-class embedding reliability measurement | label_consistency | covered | 212 findings from this engine |
| kNN-distance outlier scoring (local) | out_of_distribution | covered | 16 findings from this engine |
| Mahalanobis outlier scoring (global) | out_of_distribution | covered | 16 findings from this engine |
| per-contributor directional label confusion against a leave-one-out baseline | contributor_confusion | covered | 4 findings from this engine |
| local texture anomaly scan for stamped triggers | trigger_texture | covered | 74 findings from this engine |
| trigger-pattern scan of training data | spectral_signature | covered | 0 findings from this engine |
| per-class spectral signature of crop embeddings | spectral_signature | covered | 0 findings from this engine |
| semantic witness: an independent vision-language model's label, marking and scene answers | semantic_witness | covered | 1065 findings from this engine |
| inference-record integrity (digest recomputation) | inference_provenance | covered | 16 findings from this engine |
| inference-record signatures against the trust store | inference_provenance | covered | 16 findings from this engine |
| inference log continuity: deletion, reordering, splicing | inference_provenance | covered | 16 findings from this engine |
| inference-record replay | inference_provenance | covered | 16 findings from this engine |
| model identity against the authorised deployment | inference_provenance | covered | 16 findings from this engine |
| pre/post-processing configuration against the deployment | inference_provenance | covered | 16 findings from this engine |
| input binding: substitution versus benign re-encoding | inference_provenance | covered | 16 findings from this engine |
| distribution drift against a reference profile | distribution_shift | covered | 8 findings from this engine |
| calibrated shift test (permutation p-value) | distribution_shift | covered | 8 findings from this engine |
| shift localisation by contributor and by class | distribution_shift | covered | 8 findings from this engine |
| physical characterisation: lighting, blur, noise, compression, haze | distribution_shift | covered | 8 findings from this engine |
| drift versus manipulation signatures | distribution_shift | covered | 8 findings from this engine |
| per-image nonconformity at a controlled false discovery rate | distribution_shift | covered | 8 findings from this engine |
| weight and graph integrity | weight_integrity | covered | 1 finding from this engine |
| behavioural fingerprinting | model_fingerprint | covered | 1 finding from this engine |
| backdoor trigger inversion | backdoor_scan | covered | 3 findings from this engine |
| localisation of poisoned training samples through model features | poison_localization | covered | 10 findings from this engine |
| per-class spectral signature in the submitted model's own features | model_spectral | covered | 148 findings from this engine |
| transplant probing of candidate triggers through the full pipeline | behaviour_probe | covered | 6 findings from this engine |
| re-execution of sealed inferences (signed but wrong) | inference_reexecution | covered | 6 findings from this engine |
| twin-pipeline differential of the deployed configuration | pipeline_differential | covered | 1 finding from this engine |
Read this as the list of questions the run was asked, not the list it answered. Three of the four states are ways of being absent and they are not equivalent: a submission that could not support a check, a run not entitled to make one, and a check nobody has written are different liabilities, and a single grey "N/A" would let the weakest of them borrow the credibility of the strongest. Coverage is recorded against the engine that owns the assessment; where an engine ran but hit a limit inside itself, that limit is on the findings it produced.
Per-class embedding reliability
How often a crop’s own label matches its nearest genuine neighbour, measured on every crop in this corpus. A label finding on a class the embedding cannot separate is weaker evidence than the same score on one it can, and policy holds it one severity step down.
How the two OOD statistics disagreed
| samples_scored | 1229 |
| knn_enabled | True |
| mahalanobis_enabled | True |
| knn_flagged | 1 |
| mahalanobis_flagged | 15 |
| both | 0 |
| mahalanobis_only | 15 |
| knn_only | 1 |
| projection | PCA to 64 components (from 384) for an estimable covariance |
| components | 64 |
A sample flagged by Mahalanobis while kNN stays silent is the documented signature of an inserted group large enough to become its own neighbourhood — the exact case local density scoring misses without any error.
Where the outliers sit
Both panels share one projection and one scale, so the only difference between them is which samples each statistic lights up. Running both is the point: they fail in opposite directions, and the disagreement is the signal.
Coverage statement
Template-generated from values this run computed. Never free text, never from a language model: in an air-gapped assurance system a hallucinated explanation is worse than no explanation.
- This run assessed a dataset, 6 model file(s), 73 inference record line(s), at access level L3 and reference level R1.
- Confidence is measured where the attack harness (tools/harness.py) has measured it: for a finding type at a corroboration level with at least the harness's min_findings findings, confidence is the share of such findings that named a planted defect across the harness's scenarios, and the finding says "calibrated" and names the measurement. Everywhere else it is a provisional heuristic over corroboration and must not be read as "N% of findings at this score were truly attacks". Deterministic findings (exact duplicate, hash identity, signatures) are exempt: their confidence is 1.0 by construction.
- 124 engine pair(s) had too few shared assets to measure rank correlation and were treated as independent. That is the permissive direction: if they are in fact correlated, some findings here are corroborated by one axis counted twice.
- distribution_shift and out_of_distribution correlate at rho=0.8914 across 1229 samples on this corpus and were collapsed into a single evidence axis before corroboration was counted. Any finding resting on both therefore holds ONE axis, not two, and is dispositioned accordingly - a weaker call than treating them as separate, and the correct one: counting a measurement twice because two engines computed it is how a corroboration rule becomes decorative.
- duplicate_flooding and near_duplicate correlate at rho=0.9372 across 1229 samples on this corpus and were collapsed into a single evidence axis before corroboration was counted. Any finding resting on both therefore holds ONE axis, not two, and is dispositioned accordingly - a weaker call than treating them as separate, and the correct one: counting a measurement twice because two engines computed it is how a corroboration rule becomes decorative.
- exact_duplicate and near_duplicate correlate at rho=0.7299 across 1229 samples on this corpus and were collapsed into a single evidence axis before corroboration was counted. Any finding resting on both therefore holds ONE axis, not two, and is dispositioned accordingly - a weaker call than treating them as separate, and the correct one: counting a measurement twice because two engines computed it is how a corroboration rule becomes decorative.
- 11 high-severity finding(s) stopped at 'review' rather than 'quarantine' because the axes supporting them collapsed to fewer than the 2 this policy requires. Escalating them would need corroboration from an axis this run did not have - frequency, model behaviour, or provenance - not a lower threshold.
- 15 sample(s) were flagged by the global Mahalanobis statistic while the local kNN statistic was silent. That is the documented signature of an inserted group large enough to become its own neighbourhood, and it is the case kNN-only OOD scoring misses without any error.
- 62 label finding(s) were withheld (too few neighbours); they are not evidence of correct labelling.
- The model safety gate read 6 model artifact(s) statically - no file was deserialised - and the assessment earned access tier L0: backdoored.safetensors clean (L3); custom_layer.pt unrecognized (L1); evil_pickle.pt dangerous (L0); external_escape.onnx dangerous (L0); pyop.onnx dangerous (L0); zip_bomb.pt corruption (L0). The run declared L3, so it proceeded at L3.
- The tier was set by the model under assessment (backdoored.safetensors); custom_layer.pt, evil_pickle.pt, external_escape.onnx, pyop.onnx, zip_bomb.pt were refused and never opened, and cap only themselves - a refused file bundled beside a model cannot switch off the model's own checks.
- The runtime can do L3 with backdoored.safetensors: white box - queries, features and gradients. Model-behaviour engines needing more than the effective tier are listed as not run with that reason: refused by the tier, not unwritten.
- ONNX is checked as a graph: operator domains, external-data references and declared shapes. What the weights compute is not assessed here.
- safetensors is data only - 20 tensor(s) and a header were checked; it carries no code path. Its declared architecture (pramana-tinydet-v1) must still be one the runtime defines before anything executes it.
- inference_provenance verified 72 of 73 record line(s) across 3 session(s): 69 signature(s) verified, 1 invalid, 1 from untrusted keys, 1 unsigned and 0 unverifiable.
- A valid signature proves who sealed a record, not that the output is what the model would have said. inference_reexecution re-ran 68 of 73 record(s) on the authorised model the assessor holds: 62 reproduced, 6 did not. Not re-executable: 1 naming an unauthorised model, 1 with no stored input, 0 whose deployment has no model file held. Truncation of a session's most recent records is undetectable from the log alone.
- A reference dataset (ds_58ed2d3bffdf) was declared, so the run proceeded at reference level R1: a declared operational reference, not a certified clean corpus. Every finding in this report carries R1 for that reason.
- distribution_shift compared 1229 image(s) with 600 in reference ds_58ed2d3bffdf: global permutation p = 0.0, read as suspicious manipulation - 5 of 7 contributor(s) shifted (broad); 2 of 8 class(es) shifted (class-selective); descriptors reproduce 48% of the separation (not physically explained). The p-value is exact under exchangeability; the reading is a written rule in policy.yaml (`shift:`), not a trained classifier.
- contributor_confusion did not test 1 contributor(s) (unit_e): each has fewer than the 10 independent evidence units a directional test requires. Untested is not clean.
- backdoor_scan synthesised a 8x8 trigger for 13 ordered class pair(s); median attack success 0%, surfaced: jet->land, stealth->land, jet->civ_hel. The search covers small local patches only: blended, warping and semantic triggers are outside it, so a clean scan does not rule them out.
- The investigation scheduler formed 12 hypothesis(es) from the data evidence and ordered 76 model experiment(s) by prior x power / cost; 48 ran within a budget of 60 (spent 60). Priors are a documented heuristic over the number of independent data axes behind each hypothesis, not probabilities.
- H1 (objects labelled civ_hel carry an injected trigger that the model learned; prior 0.55): reproduced in the model by E34.
- H2 (objects labelled drone carry an injected trigger that the model learned; prior 0.3): untested.
- H3 (objects labelled jet carry an injected trigger that the model learned; prior 0.3): untested.
- H4 (objects labelled land carry an injected trigger that the model learned; prior 0.8): reproduced in the model by E02, E07, E15, E16, E17, E18 and 2 more.
- H5 (objects labelled large_mil_plane carry an injected trigger that the model learned; prior 0.3): untested.
- H6 (objects labelled stealth carry an injected trigger that the model learned; prior 0.55): not reproduced by 3 experiment(s); a statement about these experiments, not an acquittal.
- H7 (objects labelled tech_vehicle carry an injected trigger that the model learned; prior 0.3): untested.
- H8 (unit_b's jet->land label flips are poisoning a jet->land backdoor; prior 0.3): reproduced in the model by E21.
- H9 (unit_d's civ_hel->mil_helicopter label flips are poisoning a civ_hel->mil_helicopter backdoor; prior 0.3): not reproduced by 1 experiment(s); a statement about these experiments, not an acquittal.
- H10 (unit_d's land->civ_hel label flips are poisoning a land->civ_hel backdoor; prior 0.3): not reproduced by 1 experiment(s); a statement about these experiments, not an acquittal.
- H11 (unit_g's jet->stealth label flips are poisoning a jet->stealth backdoor; prior 0.3): not reproduced by 1 experiment(s); a statement about these experiments, not an acquittal.
- Deferred by budget, and therefore not assessed: invert civ_hel->drone, invert civ_hel->jet, invert civ_hel->large_mil_plane, invert civ_hel->tech_vehicle, invert drone->jet, invert drone->large_mil_plane, invert drone->tech_vehicle, invert jet->drone and 20 more.
- Declared unsupported: clean-label poisoning (feature collision, gradient matching). The label is correct and no trigger is stamped, so neither the label engines nor the texture axis have anything to see; only model-side analysis could.
- Declared unsupported: smooth or invisible triggers (blended, warping such as WaNet, colour-shift such as SIG, frequency-domain). They concentrate no high-frequency energy, so the texture axis is blind; the spectral axis may still show a sub-population, which alone is held at review.
- Declared unsupported: model backdoors whose trigger is not a small local patch (blended, warping, colour-shift, semantic or physical-object triggers). Trigger inversion searches small local patches only; a clean scan says nothing about triggers outside that search space.
- Declared unsupported: backdoors in a model supplied only as a black box (ONNX) with no trace in the data. Inversion needs gradients (L3); a black box earns fingerprinting, transplant probes of data-derived candidates, re-execution and the pipeline differential, not inversion.
- Declared unsupported: behaviour of a model supplied only as a PyTorch .pt / .pth or TorchScript file. Those formats are pickles - programs - and are gated statically, never executed; their structure is scanned (malicious imports, escapes, bombs) but no behaviour is observed until the supplier exports ONNX (for Ultralytics, `yolo export model=best.pt format=onnx`).
- Declared unsupported: behaviour of an ONNX detector outside the recognised export families. The zoo interface and the yolov8 / yolov5 layouts are decoded; any other output layout is refused with the shape seen rather than decoded wrongly.
- Declared unsupported: signed-but-wrong inference outputs when the assessor holds no copy of the authorised model. Every provenance check passes; re-execution needs the model file registered in the trust store.
- Declared unsupported: a substitute model crafted to match the public challenge set. The fingerprint's challenge images are published and seeded; a model tuned to answer them as the registered one does is not caught by the fingerprint, only by the weight hash.
- Declared unsupported: truncation of the most recent inference records of a session. Nothing after the last record vouches for its existence without a separately published session head.
- Declared unsupported: a poisoned pretrained backbone. Embeddings are computed with the vendored backbone, which is trusted by assumption and pinned by hash, not assessed.
- Declared unsupported: poison spread thinly across many contributors. Every per-source test is powered by one source's evidence units; collusion below that power is invisible at source level.
- Declared unsupported: an adaptive attacker who reads this policy. Every threshold is published by design; an attacker who stays below all of them is not detected by a threshold.
- Declared unsupported: a contaminated drift reference. The reference is declared, not certified; contamination already in it becomes the baseline.
- Declared unsupported: physical adversarial patches, evasion, model extraction, sponge or denial-of-service attacks on the deployed model. Out of this build's scope - they are inference-time attacks on a deployed model, not integrity failures of the data, the model artifact or the records.
- Declared unsupported: text inside an image steering the semantic witness (prompt injection). A vision-language model reads text; a crop with words painted on it can change its answer, so the witness is one corroborating axis and never decides alone.
- Declared unsupported: adversarial patches against the semantic witness itself. The witness is a neural network and can be fooled like any other; its answers are measured for reliability per class, not trusted.
- Declared unsupported: detectors outside the zoo architecture. Weights are executed only in architectures this system defines (pramana-tinydet-v1 today); another architecture is assessed as ONNX (black box) or not at all.
- Not covered by any engine in this run: . Their absence from this report is a scope statement, not a clean result.
- 1 in-scope claim(s) are unresolved because an assessment they require did not run: C5.2 (ledger_intact). Unresolved is not supported, and the decision reflects it.
Safety gate
A contributed model file is a program, and opening one to assess it is itself a way into the enclave. This gate parses statically; it never deserialises, on any branch.
Artifacts
| file | format | verdict | tier | findings |
|---|---|---|---|---|
| backdoored.safetensors | safetensors | infoPASS | L3 | 0 |
| custom_layer.pt | pytorch_zip | highREFUSE | L1 | 1 |
| evil_pickle.pt | pytorch_zip | highREFUSE | L0 | 1 |
| external_escape.onnx | onnx | highREFUSE | L0 | 1 |
| pyop.onnx | onnx | highREFUSE | L0 | 2 |
| zip_bomb.pt | pytorch_zip | highREFUSE | L0 | 1 |
Nothing here was deserialised. Every verdict comes from the serialized structure alone - opcodes, the ZIP directory, protobuf fields.
Tier this artifact earned
| R0 | R1 | R2 | R3 | |
|---|---|---|---|---|
| L0 | · | EARNED | · | · |
| L1 | · | · | · | · |
| L2 | · | · | · | · |
| L3 | · | THIS RUN | · | · |
Declared L3, earned L0, so the run proceeds at L3. The cap is applied before any other engine is asked whether it can run.
Refusals — the offending detail, verbatim
backdoored.safetensors
highweight_mismatchhighbehaviour_mismatchhighbackdoor_triggerhighbackdoor_triggerhighbackdoor_triggerhighpipeline_divergencebackdoored.safetensors hashes to 581025e54ac7ddba..., but deployment 'tinydet-v1' (declared deployment 'tinydet-v1') authorises 6073edc42af3b7ae.... Compared tensor by tensor with the authorised weights: 20 tensor(s) differ, covering 100% of the parameters; largest relative change 1.343 in region.3.weight.
backdoored.safetensors does not behave as deployment 'tinydet-v1': re-running the authorised model on the same 24 public challenge images, the two disagree on the class of 14 and move the box by more than 0.02 of the image on 24 (largest 0.560). Its fingerprint is d350bcb30deee833....
A 8x8 patch, synthesised in 80 steps and pasted at random positions, turns 77% of 13 held-out stealth crops into land, against 0% for the reference (median of other pairs; 13 pair(s) tested): this pair has a shortcut a small local pattern can trigger, which is what a planted backdoor leaves.
A 8x8 patch, synthesised in 80 steps and pasted at random positions, turns 71% of 21 held-out jet crops into land, against 0% for the reference (median of other pairs; 13 pair(s) tested): this pair has a shortcut a small local pattern can trigger, which is what a planted backdoor leaves.
A 8x8 patch, synthesised in 80 steps and pasted at random positions, turns 90% of 21 held-out jet crops into civ_hel, against 0% for the reference (median of other pairs; 13 pair(s) tested): this pair has a shortcut a small local pattern can trigger, which is what a planted backdoor leaves.
The same model behind the declared pipeline and behind deployment 'tinydet-v1''s pipeline answers differently on 8% of 96 images (jet->drone x8). Bisected key by key: postprocess.class_map = {"jet": "drone"} alone changes 8%. The largest single cause is postprocess.class_map.
custom_layer.pt
mediumunrecognized_importGLOBAL at offset 2 in archive/data.pkl imports `acme_layers.blocks.GatedBlock`, which is not on the 18-entry allowlist a torch checkpoint needs.
evil_pickle.pt
highmalicious_model_fileGLOBAL at offset 2 in archive/data.pkl imports `posix.system`, which is not on the 18-entry allowlist a torch checkpoint needs. `posix.system` is a known code-execution gadget: REDUCE on it calls it with attacker-chosen arguments the moment the file is deserialised.
external_escape.onnx
highexternal_data_escapeinitializer `w0` loads its weights from external data at `../outside_the_model_directory.bin`, which escapes the model directory with a `..` segment. The loader reads that path with no checker in between, so it is a read primitive pointed wherever the artifact author chose.
pyop.onnx
highmalicious_model_filemediumunrecognized_importnode `pyop_node` (index 0) is operator `com.microsoft.PyOp`, whose domain `com.microsoft` is outside the permitted set (<default>, ai.onnx, ai.onnx.ml, ai.onnx.preview.training, ai.onnx.training). `com.microsoft.PyOp` names a Python module and class to import and call during inference: it is arbitrary code execution when the model RUNS, and no weight analysis, trigger inversion or behavioural fingerprint will ever find it, because the backdoor is in the architecture rather than the weights.
pyop.onnx imports operator set domain `com.microsoft`, which is outside the permitted set. Every operator it supplies is implemented by code this gate cannot see.
zip_bomb.pt
mediumstructural_corruptionzip_bomb.pt expands 1028x (20391 bytes to 20971522), above the 100x cap: refused on the directory without decompressing any member.
Checks performed
| ZIP structure | no `..` segments, no symlink entries, member cap |
| Decompression ratio | read from the directory - a bomb is never expanded to measure it |
| Import allowlist | every GLOBAL / STACK_GLOBAL against the entries a checkpoint needs |
| Extension opcodes | EXT1 / EXT2 / EXT4 refused - they name nothing checkable |
| Opcode count and depth | capped; exhausting our own parser is a denial of service |
| Storage sizes | declared element counts against the bytes actually present |
| ONNX operator domains | ai.onnx, ai.onnx.ml and an explicit permitted set |
| ONNX external data | absolute, `..`-escaping, symlinked or multiply-linked refused |
| Graph well-formedness | dangling inputs, cycles, declared shapes |
Engines this tier gates
The run proceeds at L3: the lower of what the file earned, what the run declared, and what the runtime can do with the format (runtime L3). Greyed engines were refused by the tier and are listed as not run with that reason; a check nobody built would carry UNWRITTEN instead, and the two are never blended.
Memory
Every engine is stateless, so on its own every run is a scan. Memory is the only thing that makes assessment fifty better than assessment one.
Readiness
How much of this submission is usable, what that judgement rests on, and what it cannot see.
335 of 1,229 images (27.3%) carry no finding. 894 were named by at least one engine and need review before use.
This number is not calibrated and does not mean "0% safe". It is an arithmetic summary of what was flagged, scaled by how much of the system actually ran. Read the panel below before quoting it.
How the number was produced
| severity | images | of corpus | weight | points |
|---|---|---|---|---|
| high | 259 | 21.074% | ×8.0 | −168.59 |
| info | 47 | 3.824% | ×0.0 | −0.0 |
| low | 468 | 38.08% | ×0.5 | −19.04 |
| medium | 486 | 39.544% | ×2.0 | −79.09 |
Coverage is 100%: 41 of 41 assessments were actually attempted. An engine that did not run is not a pass, so it pulls the score down rather than being silently left out of it. Weights are in policy.yaml, not in this page.
What is wrong, and what each costs to fix
| defect | images | of corpus | findings | what it means you do |
|---|---|---|---|---|
| witness_scene_mismatch | 444 | 36.13% | 444 | confirm the image belongs in this corpus |
| witness_marking | 324 | 26.36% | 324 | inspect the object for a stamp or patch |
| witness_label_disagreement | 297 | 24.17% | 297 | re-annotate: an independent model disagrees with the label |
| swapped_label | 198 | 16.11% | 212 | re-annotate the box; the neighbour vote disagrees |
| model_spectral_signature | 148 | 12.04% | 148 | inspect what the model learned apart from the class; check the label |
| contributor_confusion | 89 | 7.24% | 4 | audit that source's labelling of the class pair |
| trigger_texture | 74 | 6.02% | 74 | inspect the object for a stamped pattern; check its label |
| visual_duplicate | 68 | 5.53% | 11 | collapse the cluster to one representative |
| split_leakage | 51 | 4.15% | 7 | INVALIDATES the split - retrain metrics are inflated |
| duplicate_flooding | 32 | 2.6% | 1 | investigate the source before accepting the batch |
| out_of_distribution | 16 | 1.3% | 16 | confirm it belongs in this corpus at all |
| exact_duplicate | 15 | 1.22% | 4 | delete the redundant copies; keep one |
| poison_localized | 10 | 0.81% | 10 | exclude the sample from training; audit its source |
| labelling_inconsistency | 10 | 0.81% | 3 | re-annotate: near-identical images disagree |
| trigger_behaviour | 6 | 0.49% | 6 | treat the patch as a trigger; remove its carriers |
| output_mismatch | 6 | 0.49% | 6 | exclude the record; the model did not produce it |
| contributor_shift | 5 | 0.41% | 5 | compare this source's recent imagery with its earlier submissions |
| malicious_model_file | 2 | 0.16% | 2 | do not load the artifact; quarantine it |
| chain_break | 2 | 0.16% | 2 | exclude the record; find what was spliced in |
| class_shift | 2 | 0.16% | 2 | inspect the most unusual objects of this class |
| unrecognized_import | 2 | 0.16% | 2 | review the finding and decide |
| record_altered | 1 | 0.08% | 1 | exclude the record; the output was edited after sealing |
| input_substituted | 1 | 0.08% | 1 | exclude the record; the stored input is not the one used |
| record_replayed | 1 | 0.08% | 1 | exclude the duplicate; check what consumed it twice |
| untrusted_signer | 1 | 0.08% | 1 | exclude the record; identify the key that sealed it |
| chain_fork | 1 | 0.08% | 1 | exclude both; the session history is ambiguous |
| record_deleted | 1 | 0.08% | 1 | recover the missing records from the node |
| model_substitution | 1 | 0.08% | 1 | exclude the output; confirm which model ran |
| weight_mismatch | 1 | 0.08% | 1 | do not deploy; obtain the registered artifact |
| signature_invalid | 1 | 0.08% | 1 | exclude the record; re-derive it from the node |
| behaviour_mismatch | 1 | 0.08% | 1 | do not deploy; the model is not the registered one |
| external_data_escape | 1 | 0.08% | 1 | review the finding and decide |
| backdoor_trigger | 1 | 0.08% | 3 | retrain without the localised samples; re-scan the pair |
| pipeline_divergence | 1 | 0.08% | 1 | restore the authorised pre/post-processing |
| mass_submission_anomaly | 1 | 0.08% | 1 | investigate the source before accepting |
| distribution_shift | 1 | 0.08% | 1 | read the shift reading; recalibrate on drift, investigate on manipulation |
| record_unsigned | 1 | 0.08% | 1 | require the node to sign, or re-seal from source |
| record_reordered | 1 | 0.08% | 1 | restore log order before replaying the session |
| input_missing | 1 | 0.08% | 1 | recover the evidence copy of the input |
| record_unparseable | 1 | 0.08% | 1 | recover the line from the node's own log |
| config_mismatch | 1 | 0.08% | 1 | confirm the configuration change was sanctioned |
| structural_corruption | 1 | 0.08% | 1 | review the finding and decide |
| input_transcoded | 1 | 0.08% | 1 | keep the original bytes next time; no action on the output |
Image counts across rows overlap - one image can carry more than one defect - so they do not sum to the flagged total. The remedies differ by class and that is the point: a duplicate is deleted, a swapped label is re-annotated, and leakage invalidates a whole split rather than an image.
Where the findings fall
| split | findings |
|---|---|
| (cluster-level) | 73 |
| test | 2 |
| train | 1,438 |
| valid | 91 |
Cluster-level findings name a group rather than a single split, so they are listed separately rather than assigned to one.
Recommended disposition
| accept | 1 |
| quarantine | 911 |
| review | 692 |
Disposition is an instruction from the correlation layer, not a severity restated. Everything here is advisory: nothing is deleted or quarantined by this tool.
What this number does not know
- Not calibrated as a probability. 1522 of 1571 statistical findings carry a confidence the attack harness measured against planted truth; the rest are provisional heuristics. The score itself is an arithmetic summary of findings, not a probability that the data is safe.
- Says nothing about what was MISSED. Recall is unmeasurable without planted ground truth, so a high score from an engine that found nothing is indistinguishable from a high score that was earned.
- Merges severity and confidence, which this system separates everywhere else. It cannot express 'high severity, low confidence' - the state that most needs a human.
- Saturated: the penalty (266.7 points) exceeds the base of 100, so the score floors at zero and stops discriminating. A corpus twice as damaged as this one would also read 0.0 - read the finding counts, not the number.
Every item above is generated from what this run actually did. The list shrinks as the gaps close - it is not a fixed disclaimer.
Claims
What this assessment set out to establish, what the evidence supports, and the single action that follows - the most severe claim gate, never an average.
QUARANTINE: set by claim(s) C1.2, C1.3, C1.4, C1.6, C2.1, C2.2, C2.3, C2.4, C3.1, C3.2, C3.3, C3.4. Across 19 in-scope claim(s): 12 contradicted, 2 supported, 1 unresolved, 4 weakened. The action is the most severe claim gate - never an average, never a score.
1 Training-data integrity
| claim | statement | state | gate |
|---|---|---|---|
| C1.1 | No contributor floods the corpus with near-duplicate content. training data whyWeakened by 2 item(s) held for review, recalibration or as inconclusive: f_176288c9791f, f_2f2168276246. Requirements ✓ source-concentrated near-duplicate flooding ✓ per-contributor duplication lift against the corpus Defeaters duplicate_flooding, mass_submission_anomaly Re-run to reassess duplicate_flooding A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ◐ WEAKENED | review |
| C1.2 | Labels are consistent - no label flipping and no systematic mislabelling by any source. training data whyContradicted by 367 item(s) dispositioned quarantine: f_01f2dc9105d6, f_0363aaec651f, f_0d9a367b3c25, f_0f018abd7006, f_10ccbb225aec, f_37963d78bbca.... Requirements ✓ embedding neighbour-vote label disagreement ✓ intra-cluster labelling disagreement ✓ per-contributor directional label confusion against a leave-one-out baseline Defeaters swapped_label, labelling_inconsistency, contributor_confusion, witness_label_disagreement Re-run to reassess contributor_confusion, label_consistency, near_duplicate A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ✕ CONTRADICTED | quarantine |
| C1.3 | No out-of-distribution population was inserted. training data whyContradicted by 157 item(s) dispositioned quarantine: f_628247dc4d11, f_6f88e4371526, f_76e4185d7b7d, f_9e75478094d1, f_be0c8046d1be, f_ca2cf2342d34.... Requirements ✓ kNN-distance outlier scoring (local) ✓ Mahalanobis outlier scoring (global) Defeaters out_of_distribution, witness_scene_mismatch Re-run to reassess out_of_distribution A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ✕ CONTRADICTED | quarantine |
| C1.4 | No trigger-bearing samples were injected. training data whyContradicted by 358 item(s) dispositioned quarantine: f_1a2dd2ecab4d, f_29cc3231f2c6, f_3c6dc9d465ff, f_3f264d6649e8, f_447ef6910680, f_4d7d43225272.... Requirements ✓ trigger-pattern scan of training data ✓ local texture anomaly scan for stamped triggers Defeaters trigger_texture, spectral_signature, model_spectral_signature, poison_localized, witness_marking Re-run to reassess spectral_signature, trigger_texture A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ✕ CONTRADICTED | quarantine |
| C1.5 | The evaluation split is independent of the training split, and redundancy does not inflate the corpus. training data whyWeakened by 22 item(s) held for review, recalibration or as inconclusive: f_4e7419efe394, f_4fad5b907da6, f_98385d37bba2, f_9d7ee68a223b, f_f7a32c90b207, f_f9cb40c3c243.... Requirements ✓ byte-identical duplicate detection over SHA-256 ✓ near-duplicate clustering over perceptual hash and embedding ✓ train/validation leakage detection Defeaters split_leakage, exact_duplicate, visual_duplicate Re-run to reassess exact_duplicate, near_duplicate A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ◐ WEAKENED | review |
| C1.6 | No contributing source is abnormal against its peers. contributing sources whyContradicted by 6 item(s) dispositioned quarantine: contributor:unit_b, contributor:unit_f, contributor:unit_d, contributor:unit_g, contributor:unit_a, contributor:unit_c. Requirements ✓ source-concentrated near-duplicate flooding ✓ per-contributor directional label confusion against a leave-one-out baseline Re-run to reassess contributor_confusion, duplicate_flooding A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ✕ CONTRADICTED | quarantine |
2 Model integrity
| claim | statement | state | gate |
|---|---|---|---|
| C2.1 | The model artifact is safe to open. model whyContradicted by 3 item(s) dispositioned quarantine: f_107364c0af85, f_8c7b2858faf4, f_ee857b9ed772. Requirements ✓ static pickle opcode analysis against an import allowlist ✓ archive structure: traversal, symlinks, decompression ratio ✓ ONNX operator domains and external-data references Defeaters malicious_model_file, external_data_escape, unrecognized_import, structural_corruption Re-run to reassess model_safety_gate A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ✕ CONTRADICTED | quarantine |
| C2.2 | The model that produced the outputs is the authorised model, not a substitute. model whyContradicted by 1 item(s) dispositioned quarantine: f_487c3bbca861. Requirements ✓ model identity against the authorised deployment Defeaters model_substitution Re-run to reassess inference_provenance A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ✕ CONTRADICTED | quarantine |
| C2.3 | The model exhibits no backdoor-like behaviour, and no trigger carried by the data moves it. model whyContradicted by 9 item(s) dispositioned quarantine: f_32cc47af189f, f_5d8b9f2ca8b3, f_8768db6f9423, f_03bf012713da, f_190a285b9473, f_1ad6df818b34.... Requirements ✓ backdoor trigger inversion ✓ transplant probing of candidate triggers through the full pipeline Defeaters backdoor_trigger, trigger_behaviour Re-run to reassess backdoor_scan, behaviour_probe A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ✕ CONTRADICTED | quarantine |
| C2.4 | The model is the authorised model - its weights and its behaviour match the registered deployment. model whyContradicted by 2 item(s) dispositioned quarantine: f_6b52d24ab6d8, f_c3106f512ed2. Requirements ✓ weight and graph integrity ✓ behavioural fingerprinting Defeaters weight_mismatch, behaviour_mismatch Re-run to reassess model_fingerprint, weight_integrity A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ✕ CONTRADICTED | quarantine |
| C2.5 | The deployed pre- and post-processing behave as the authorised configuration. deployed pipeline whyWeakened by 1 item(s) held for review, recalibration or as inconclusive: f_09351c05426a. Requirements ✓ twin-pipeline differential of the deployed configuration Defeaters pipeline_divergence Re-run to reassess pipeline_differential A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ◐ WEAKENED | review |
3 Inference provenance
| claim | statement | state | gate |
|---|---|---|---|
| C3.1 | Every inference record is authentic and unaltered since sealing. inference records whyContradicted by 3 item(s) dispositioned quarantine: f_142cc19a941e, f_71efc5c471bd, f_28be06d9a674. Requirements ✓ inference-record integrity (digest recomputation) ✓ inference-record signatures against the trust store Defeaters record_altered, signature_invalid, untrusted_signer, record_unsigned, record_unparseable Re-run to reassess inference_provenance A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ✕ CONTRADICTED | quarantine |
| C3.2 | The inference log is complete, in order, and free of replays. inference records whyContradicted by 4 item(s) dispositioned quarantine: f_18204f947395, f_3359e294716b, f_41dbdae5c7b0, f_b3dd1c50ca77. Requirements ✓ inference log continuity: deletion, reordering, splicing ✓ inference-record replay Defeaters record_replayed, chain_fork, record_deleted, record_reordered, chain_break Re-run to reassess inference_provenance A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ✕ CONTRADICTED | quarantine |
| C3.3 | Every output is bound to its input image, model and pre/post-processing configuration. inference records whyContradicted by 2 item(s) dispositioned quarantine: f_14dbdc4f1ff6, f_487c3bbca861. Requirements ✓ input binding: substitution versus benign re-encoding ✓ pre/post-processing configuration against the deployment ✓ model identity against the authorised deployment Defeaters input_substituted, input_missing, config_mismatch, model_substitution Re-run to reassess inference_provenance A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ✕ CONTRADICTED | quarantine |
| C3.4 | Every sealed output is what the model would produce on its input. inference records whyContradicted by 6 item(s) dispositioned quarantine: f_468d360d750e, f_8f8622a8b3a1, f_aa148d8660ff, f_b8a5c3294c21, f_ccba23cbddbb, f_ddc8276c36d8. Requirements ✓ re-execution of sealed inferences (signed but wrong) Defeaters output_mismatch Re-run to reassess inference_reexecution A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ✕ CONTRADICTED | quarantine |
4 Distribution shift
| claim | statement | state | gate |
|---|---|---|---|
| C4.1 | The data matches the declared reference, or its deviation is explained operational drift. deployment data whyWeakened by 8 item(s) held for review, recalibration or as inconclusive: f_bfbc49c40165, f_03de7241f006, f_6c7cf8b0bf48, f_9251b5cf1b2d, f_de11233fe672, f_ebe966a3bf07.... Requirements ✓ distribution drift against a reference profile ✓ calibrated shift test (permutation p-value) ✓ drift versus manipulation signatures Defeaters distribution_shift, contributor_shift, class_shift Re-run to reassess distribution_shift A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ◐ WEAKENED | review |
5 Analyst-facing assurance
| claim | statement | state | gate |
|---|---|---|---|
| C5.1 | Every flag carries a reason, evidence, a confidence, limitations and a recommended disposition. this report whySupported: 1604 finding(s) checked; every one carries all five. Requirements ✓ flags_complete A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ✓ SUPPORTED | accept |
| C5.2 | The audit ledger this assessment will be appended to is intact. audit trail whyUnresolved: 1 of 1 required assessment(s) did not run - no ledger exists at the store root yet; the first logged assessment creates it. Requirements ○ ledger_intact (did not run) A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ? UNRESOLVED | inconclusive |
| C5.3 | The assessment's own controls passed their known-answer tests before it ran. this assessment whySupported: 5 of 5 known-answer tests passed. Requirements ✓ preflight A supported claim means every listed requirement ran and no defeater reached review - not that the asset is proved safe. Its strength is bounded by the coverage statement and by each requirement's own limitations. | ✓ SUPPORTED | accept |
Provenance
Every inference sealed at the node binds the input image, the model, the pre- and post-processing configuration and the output, and links to the record before it. This stage re-verifies all of it.
edge-01-s1
edge-02-s1
edge-03-s1
What failed, record by record
| record | finding | severity | action | reason |
|---|---|---|---|---|
| edge-01-s1#10 | chain_break | high | quarantine | Record edge-01-s1#10 links to predecessor 1f3551adc64c, but the record before it hashes to c26793b2488b: a record was spliced in, or its predecessor was re-sealed. |
| edge-01-s1#12 | untrusted_signer | high | quarantine | Record edge-01-s1#12 is sealed by key k_8d1430090438ecef, which is not one of the 2 key(s) in the trust store: a record produced outside the authorised nodes. |
| edge-01-s1#13 | chain_break | high | quarantine | Record edge-01-s1#13 links to predecessor 73d7f6260865, but the record before it hashes to f1bca9a444da: a record was spliced in, or its predecessor was re-sealed. |
| edge-01-s1#18 | input_substituted | high | quarantine | The stored input for record edge-01-s1#18 is a different picture from the one the output was computed on: bytes differ and the perceptual hashes are 24 bits apart (radius 6). |
| edge-01-s1#25 | input_transcoded | info | accept | The stored input for record edge-01-s1#25 was re-encoded: bytes differ but the perceptual hashes are 1 bit(s) apart, within the radius of 6. Same picture; the exact evidence copy was not kept. |
| edge-01-s1#3 | record_replayed | high | quarantine | Record edge-01-s1#3 at line 73 repeats a sealed digest first logged at line 7: the same inference replayed into the log. |
| edge-01-s1#5 | record_altered | high | quarantine | Record edge-01-s1#5 was edited after it was sealed: its content hashes to bf00b4b16796, not the sealed 2fe4223916aa. Altered: output. |
| edge-01-s1#9 | signature_invalid | high | quarantine | Record edge-01-s1#9 is internally consistent but its signature does not verify under edge-01's trusted key: the digest was recomputed after an edit, or the signature was forged. |
| edge-02-s1#15 | record_reordered | medium | review | Record edge-02-s1#15 is logged after sequence 16: the log order was changed. |
| edge-02-s1#20 | model_substitution | high | quarantine | Record edge-02-s1#20 names model ffffffffffff, which is not the model its node is authorised to run (deployment registry). |
| edge-02-s1#22 | config_mismatch | medium | review | Record edge-02-s1#22 ran the authorised model with a configuration that is not the authorised one (tinydet-v1): post.score_threshold: 0.25 -> 0.05. |
| edge-02-s1#25 | chain_fork | high | quarantine | Two different records claim edge-02-s1#25: this one and the one at line 50. A session cannot have two records at one position. |
| edge-02-s1#27 | input_missing | medium | review | Record edge-02-s1#27 points at an evidence copy (inputs/edge-02-s1/000027.jpg) that is not in the records directory. |
| edge-02-s1#8 | record_deleted | high | review | Session edge-02-s1 jumps from sequence 6 to 8: 1 record(s) missing (7). |
| edge-03-s1#0 | record_unsigned | medium | review | Record edge-03-s1#0 carries no signature although a trust store is in force. |
| line:72 | record_unparseable | medium | review | Line 72 of the inference log is not a verifiable record: Expecting value: line 1 column 63 (char 62). |
Drift
Is this data still what the reference was - and if not, did the world change, or did someone change the data?
5 of 7 contributor(s) shifted (broad); 2 of 8 class(es) shifted (class-selective); descriptors reproduce 48% of the separation (not physically explained)
A written rule in policy.yaml (shift:) over four measured signatures - not a trained classifier.
By contributor
| contributor | objects | kernel p | nonconforming / expected | q | |
|---|---|---|---|---|---|
| unit_a | 240 | 0.415 | 9 / 8.54 | 0.831 | - |
| unit_b | 436 | 0.00332 | 138 / 17.35 | 0 | SHIFTED |
| unit_c | 235 | 0.266 | 9 / 8.8 | 0.62 | - |
| unit_d | 297 | 0.00332 | 19 / 10.88 | 0.0093 | SHIFTED |
| unit_e | 60 | 0.00332 | 0 / 2.78 | 0.0093 | SHIFTED |
| unit_f | 17 | 0.00332 | 14 / 0.65 | 0 | SHIFTED |
| unit_g | 131 | 0.00332 | 5 / 4.48 | 0.0093 | SHIFTED |
By class
| class | objects | kernel p | nonconforming / expected | q | |
|---|---|---|---|---|---|
| civ_hel | 123 | 0.0432 | 18 / 5.35 | 0.168 | - |
| drone | 46 | 0.591 | 0 / 0.0 | 1 | - |
| jet | 191 | 0.302 | 14 / 8.88 | 0.476 | - |
| land | 846 | 0.00332 | 162 / 39.25 | 0 | SHIFTED |
| large_mil_plane | 73 | 0.093 | 0 / 0.0 | 0.298 | - |
| mil_helicopter | 32 | 0.153 | 0 / 0.0 | 0.408 | - |
| stealth | 49 | 0.00332 | 0 / 0.0 | 0.0266 | SHIFTED |
| tech_vehicle | 56 | 0.00997 | 0 / 0.0 | 0.0532 | - |
What the conditions did
| factor | reference | submission | shift | units | q |
|---|---|---|---|---|---|
| brightness | 128.762 | 126.3188 | -0.09 | reference MADs | 0.145 |
| contrast | 60.8209 | 60.1024 | -0.05 | reference MADs | 0.0862 |
| sharpness | 2.4594 | 2.4775 | +0.09 | reference MADs | 0.000951 |
| noise | 0.8239 | 0.8276 | +0.01 | reference MADs | 0.109 |
| saturation | 51.0251 | 51.4091 | +0.02 | reference MADs | 0.167 |
| warmth | 3.2372 | 1.5433 | -0.11 | reference MADs | 0.351 |
| dark_channel | 113.2578 | 110.8706 | -0.09 | reference MADs | 0.109 |
| entropy | 5.3468 | 5.2271 | -0.31 | reference MADs | 0.00168 |
| log_area | 5.6124 | 5.6124 | +0.00 | raw difference (reference constant) | 1 |
| jpeg_quality | 74.8 | 74.8 | +0.00 | raw difference (reference constant) | 0 |
Physical descriptors measured at ingest. A shift the descriptors alone can reproduce is expressible as lighting, lens, sensor or compression; one they cannot is something else.
Audit ledger
Every assessment is appended to a Merkle log in the construction Certificate Transparency uses, with a signed tree head after each. Rewriting history breaks every later head; a head held elsewhere catches even a rewrite by someone holding the key.
Model behaviour
The model is run, and what it does is evidence: is it the authorised model, does a small patch turn one class into another, which training samples taught it that, and does every sealed output reproduce?
Trigger inversion - attack success by class pair
Row: the class the patch is pasted on. Column: the class it tries to force. A 8x8 patch, 80 steps, evaluated on held-out crops at held-out positions. Median 0.00. Dark cells surfaced.
| civ_hel | drone | jet | land | large_mil_plane | mil_helicopter | stealth | tech_vehicle | |
|---|---|---|---|---|---|---|---|---|
| civ_hel | · | n/a | n/a | 0.47 | n/a | 0.00 | 0.00 | n/a |
| drone | n/a | · | n/a | n/a | n/a | n/a | n/a | n/a |
| jet | 0.90 | n/a | · | 0.71 | n/a | 0.00 | 0.00 | n/a |
| land | 0.02 | n/a | n/a | · | n/a | 0.00 | 0.00 | n/a |
| large_mil_plane | n/a | n/a | n/a | n/a | · | n/a | n/a | n/a |
| mil_helicopter | n/a | n/a | n/a | n/a | n/a | · | n/a | n/a |
| stealth | 0.15 | n/a | n/a | 0.77 | n/a | 0.00 | · | n/a |
| tech_vehicle | n/a | n/a | n/a | n/a | n/a | n/a | n/a | · |
Deferred by budget: civ_hel->drone, civ_hel->jet, civ_hel->large_mil_plane, civ_hel->tech_vehicle, drone->jet, drone->large_mil_plane, drone->tech_vehicle, jet->drone, jet->large_mil_plane, jet->tech_vehicle, land->drone, land->jet, land->large_mil_plane, land->tech_vehicle, large_mil_plane->drone, large_mil_plane->jet, large_mil_plane->tech_vehicle, mil_helicopter->drone, mil_helicopter->jet, mil_helicopter->large_mil_plane, mil_helicopter->tech_vehicle, stealth->drone, stealth->jet, stealth->large_mil_plane, stealth->tech_vehicle, tech_vehicle->drone, tech_vehicle->jet, tech_vehicle->large_mil_plane
Samples that taught jet->land
0 of 728 target-class objects sit with the triggered source in the model's own features.
Samples that taught stealth->land
10 of 728 target-class objects sit with the triggered source in the model's own features - unit_a 1, unit_b 2, unit_c 3, unit_d 1, unit_f 1, unit_g 2.
Samples that taught jet->civ_hel
0 of 123 target-class objects sit with the triggered source in the model's own features.
Transplant probes through the deployed pipeline
A candidate patch pasted onto clean objects, against a matched control. Flip rate is how often the pipeline then reports the candidate's class.
| candidate | pair | cell | flip | control |
|---|---|---|---|---|
| h6k_jpg.rf.d90f182d8f23e13100009e1d6903550f.jpg#0 | civ_hel→land | 0 | 0.29 | 0.00 |
| h6k_s3_jpg.rf.277c22bd6b17b00aed6922e7d4d8c901.jpg#0 | civ_hel→land | 0 | 0.58 | 0.04 |
| j10_s3_jpg.rf.b77b77f4b4c725f49ea16608f2b02c40.jpg#0 | civ_hel→land | 0 | 0.46 | 0.00 |
| j11_s3_jpg.rf.1f7155f5a466210149ac5d4b71760e87.jpg#0 | civ_hel→land | 0 | 0.38 | 0.04 |
| j11_s3_jpg.rf.33a07f8f356c7205b3dcbb6bbba001b0.jpg#0 | stealth→land | 0 | 0.38 | 0.00 |
| j20_s2_jpg.rf.ecd532160caf02d07e2f5ccce29103ca.jpg#0 | civ_hel→land | 0 | 0.29 | 0.04 |
| j31_s3_jpg.rf.e29c936c70ad01dd93aaaa7353394bb0.jpg#0 | civ_hel→land | 0 | 0.54 | 0.04 |
| jet12_jpeg.rf.f9f450fa255b9ef4749035a7da5b918d.jpg#0 | civ_hel→land | 0 | 0.21 | 0.04 |
| jet140_jpeg.rf.c888138c04d6a16ee04c1a1df38f616a.jpg#0 | stealth→land | 0 | 0.43 | 0.05 |
| jet185_jpeg.rf.1707e4635f2fba01762e21d82c1e03be.jpg#0 | civ_hel→land | 0 | 0.33 | 0.04 |
| jet189_jpeg.rf.50a23248782540ea4be733d724c3cd68.jpg#0 | civ_hel→land | 0 | 0.42 | 0.08 |
| jet42_jpeg.rf.3fd286414e56456ba1cfd96246765bf4.jpg#0 | civ_hel→land | 0 | 0.50 | 0.17 |
| jet60_jpeg.rf.8c9613341af564c8c4679de248eec360.jpg#0 | civ_hel→land | 0 | 0.42 | 0.12 |
| jet76_jpeg.rf.7da8c1069617ff0cb19d8601bff63542.jpg#0 | civ_hel→land | 0 | 0.42 | 0.08 |
| jet96_jpeg.rf.fea4da958aff1b8834893a5fafc198a3.jpg#0 | stealth→land | 0 | 0.52 | 0.05 |
| mig_31bm_s5_jpg.rf.8bba177d9c1e8443e82189282844a9e5.jpg#0 | civ_hel→land | 0 | 0.67 | 0.08 |
| su_35_s5_jpg.rf.10c02cf140079a79e71643bb1804fc52.jpg#0 | civ_hel→land | 0 | 0.58 | 0.08 |
| xac_jh7_s2_jpg.rf.4194b4ef72da5210a00fcddb8c2c98eb.jpg#0 | civ_hel→land | 0 | 0.62 | 0.08 |
| yak_141_s2_jpg.rf.e881b5fb26e3caefe4f494029a755d54.jpg#0 | civ_hel→land | 0 | 0.50 | 0.12 |
| unit_f_foreign00.jpg#0 | stealth→land | 7 | 0.10 | 0.10 |
| synthesised stealth->land | stealth->land | in box | 0.62 | 0.38 |
Twin-pipeline differential
The same model behind the declared configuration and behind deployment 'tinydet-v1', on 96 images: 8% of outputs change.
| key (applied alone) | declared | divergence | transitions |
|---|---|---|---|
| postprocess.class_map | {"jet": "drone"} | 0.08 | jet->drone x8 |
Engines
| engine | status | why not |
|---|---|---|
| weight_integrity | ran | |
| model_fingerprint | ran | |
| backdoor_scan | ran | |
| poison_localization | ran | |
| model_spectral | ran | |
| behaviour_probe | ran | |
| inference_reexecution | ran | |
| pipeline_differential | ran |
Model findings
| asset | finding | severity | action | axes | reason |
|---|---|---|---|---|---|
| model:backdoored.safetensors | backdoor_trigger | high | quarantine | deterministic, model_behaviour, semantic, witness | A 8x8 patch, synthesised in 80 steps and pasted at random positions, turns 77% of 13 held-out stealth crops into land, against 0% for the reference (median of other pairs; 13 pair(s) tested): this pair has a shortcut a small local pattern can trigger, which is what a planted backdoor leaves. |
| model:backdoored.safetensors | backdoor_trigger | high | quarantine | deterministic, model_behaviour, semantic, witness | A 8x8 patch, synthesised in 80 steps and pasted at random positions, turns 71% of 21 held-out jet crops into land, against 0% for the reference (median of other pairs; 13 pair(s) tested): this pair has a shortcut a small local pattern can trigger, which is what a planted backdoor leaves. |
| model:backdoored.safetensors | backdoor_trigger | high | quarantine | deterministic, model_behaviour, semantic, witness | A 8x8 patch, synthesised in 80 steps and pasted at random positions, turns 90% of 21 held-out jet crops into civ_hel, against 0% for the reference (median of other pairs; 13 pair(s) tested): this pair has a shortcut a small local pattern can trigger, which is what a planted backdoor leaves. |
| h6k_s3_jpg.rf.277c22bd6b17b00aed6922e7d4d8c901.jpg | trigger_behaviour | high | quarantine | frequency, model_behaviour, witness | The patch in cell 0 of object 0 (labelled land), transplanted onto 24 clean civ_hel objects, makes the deployed pipeline report land for 58% of them; the same cell cut from ordinary land objects does it for 4%. On the other classes: stealth 19%. The model treats this patch on a civ_hel as a reason to say land. |
| j31_s3_jpg.rf.e29c936c70ad01dd93aaaa7353394bb0.jpg | trigger_behaviour | high | quarantine | frequency, model_behaviour, witness | The patch in cell 0 of object 0 (labelled land), transplanted onto 24 clean civ_hel objects, makes the deployed pipeline report land for 54% of them; the same cell cut from ordinary land objects does it for 4%. On the other classes: stealth 33%. The model treats this patch on a civ_hel as a reason to say land. |
| jet96_jpeg.rf.fea4da958aff1b8834893a5fafc198a3.jpg | trigger_behaviour | high | quarantine | frequency, model_behaviour, witness | The patch in cell 0 of object 0 (labelled land), transplanted onto 21 clean stealth objects, makes the deployed pipeline report land for 52% of them; the same cell cut from ordinary land objects does it for 5%. On the other classes: civ_hel 54%. The model treats this patch on a stealth as a reason to say land. |
| mig_31bm_s5_jpg.rf.8bba177d9c1e8443e82189282844a9e5.jpg | trigger_behaviour | high | quarantine | frequency, model_behaviour, witness | The patch in cell 0 of object 0 (labelled land), transplanted onto 24 clean civ_hel objects, makes the deployed pipeline report land for 67% of them; the same cell cut from ordinary land objects does it for 8%. On the other classes: stealth 48%. The model treats this patch on a civ_hel as a reason to say land. |
| su_35_s5_jpg.rf.10c02cf140079a79e71643bb1804fc52.jpg | trigger_behaviour | high | quarantine | frequency, model_behaviour, witness | The patch in cell 0 of object 0 (labelled land), transplanted onto 24 clean civ_hel objects, makes the deployed pipeline report land for 58% of them; the same cell cut from ordinary land objects does it for 8%. On the other classes: stealth 52%. The model treats this patch on a civ_hel as a reason to say land. |
| xac_jh7_s2_jpg.rf.4194b4ef72da5210a00fcddb8c2c98eb.jpg | trigger_behaviour | high | quarantine | frequency, model_behaviour, witness | The patch in cell 0 of object 0 (labelled land), transplanted onto 24 clean civ_hel objects, makes the deployed pipeline report land for 62% of them; the same cell cut from ordinary land objects does it for 8%. On the other classes: stealth 19%. The model treats this patch on a civ_hel as a reason to say land. |
| edge-01-s1#12 | output_mismatch | high | quarantine | model_behaviour, provenance | Record edge-01-s1#12 (line 25) seals civ_hel 0.653, but re-running deployment 'tinydet-v1''s model on the bound input with the bound configuration gives land 0.653 (class land against civ_hel). The record may verify perfectly: this is the output the model did not produce. |
| edge-01-s1#18 | output_mismatch | high | quarantine | model_behaviour, provenance | Record edge-01-s1#18 (line 37) seals jet 0.623, but re-running deployment 'tinydet-v1''s model on the bound input with the bound configuration gives land 0.653 (class land against jet). The record may verify perfectly: this is the output the model did not produce. |
| edge-01-s1#30 | output_mismatch | high | quarantine | model_behaviour | Record edge-01-s1#30 (line 60) seals civ_hel 0.322, but re-running deployment 'tinydet-v1''s model on the bound input with the bound configuration gives jet 0.322 (class jet against civ_hel). The record may verify perfectly: this is the output the model did not produce. |
| edge-01-s1#34 | output_mismatch | high | quarantine | model_behaviour | Record edge-01-s1#34 (line 64) seals no detection, but re-running deployment 'tinydet-v1''s model on the bound input with the bound configuration gives land 0.315 (1 detection(s) against 0). The record may verify perfectly: this is the output the model did not produce. |
| edge-01-s1#5 | output_mismatch | high | quarantine | model_behaviour, provenance | Record edge-01-s1#5 (line 11) seals civ_hel 0.701, but re-running deployment 'tinydet-v1''s model on the bound input with the bound configuration gives land 0.701 (class land against civ_hel). The record may verify perfectly: this is the output the model did not produce. |
| edge-01-s1#9 | output_mismatch | high | quarantine | model_behaviour, provenance | Record edge-01-s1#9 (line 19) seals civ_hel 0.526, but re-running deployment 'tinydet-v1''s model on the bound input with the bound configuration gives land 0.526 (class land against civ_hel). The record may verify perfectly: this is the output the model did not produce. |
| model:backdoored.safetensors | behaviour_mismatch | high | quarantine | deterministic, model_behaviour, semantic, witness | backdoored.safetensors does not behave as deployment 'tinydet-v1': re-running the authorised model on the same 24 public challenge images, the two disagree on the class of 14 and move the box by more than 0.02 of the image on 24 (largest 0.560). Its fingerprint is d350bcb30deee833.... |
| an_12_s3_jpg.rf.953f9d3742c60afa406cfa5a21993984.jpg | model_spectral_signature | high | quarantine | model_behaviour, witness | Among 728 objects labelled land, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 3.9); 92 objects do, with residual coherence 0.89, 100% of them from unit_b. |
| an_12_s7_jpg.rf.0618978185ef099864b54b26ea4069a8.jpg | model_spectral_signature | high | quarantine | model_behaviour, semantic, witness | Among 70 objects labelled large_mil_plane, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 6.7); 5 objects do, with residual coherence -0.07, 40% of them from unit_a. |
| civ_hel111_jpeg.rf.8f632b7dcfb7d38a406670dc55282211.jpg | model_spectral_signature | medium | review | model_behaviour | Among 123 objects labelled civ_hel, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 5.5); 11 objects do, with residual coherence 0.93, 36% of them from unit_a. |
| civ_hel11_jpeg.rf.37efd4e4b1bc736c0210fc6fe340440f.jpg | model_spectral_signature | high | quarantine | model_behaviour, witness | Among 123 objects labelled civ_hel, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 5.6); 11 objects do, with residual coherence 0.93, 36% of them from unit_a. |
| civ_hel31_jpeg.rf.a0cd03415a072878aff3c3b49355633f.jpg | model_spectral_signature | high | quarantine | model_behaviour, witness | Among 123 objects labelled civ_hel, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 7.5); 11 objects do, with residual coherence 0.93, 36% of them from unit_a. |
| civ_hel31_jpeg.rf.a6efa19428ad47050bec4a701485dedf.jpg | model_spectral_signature | medium | review | model_behaviour | Among 123 objects labelled civ_hel, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 7.4); 11 objects do, with residual coherence 0.93, 36% of them from unit_a. |
| civ_hel31_jpeg.rf.df8f50109132cbc5c596c3c9ee05dcd1.jpg | model_spectral_signature | medium | review | model_behaviour | Among 123 objects labelled civ_hel, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 7.4); 11 objects do, with residual coherence 0.93, 36% of them from unit_a. |
| civ_hel32_jpeg.rf.3f538d7d175ba7674bc610dee76e3151.jpg | model_spectral_signature | high | quarantine | model_behaviour, witness | Among 123 objects labelled civ_hel, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 5.5); 11 objects do, with residual coherence 0.93, 36% of them from unit_a. |
| civ_hel55_jpeg.rf.0cce0dfa5c6bfd202778984fd886675c.jpg | model_spectral_signature | high | quarantine | model_behaviour, witness | Among 123 objects labelled civ_hel, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 9.5); 11 objects do, with residual coherence 0.93, 36% of them from unit_a. |
| civ_hel92_jpeg.rf.587af82267548837d08edbb65903bad1.jpg | model_spectral_signature | medium | review | model_behaviour | Among 123 objects labelled civ_hel, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 3.8); 11 objects do, with residual coherence 0.93, 36% of them from unit_a. |
| drone111_jpeg.rf.e5530b2be4accff147ad1c2e87678c21.jpg | model_spectral_signature | medium | quarantine | model_behaviour, semantic | Among 45 objects labelled drone, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 4.3); 5 objects do, with residual coherence 0.37, 40% of them from unit_c. |
| drone117_jpeg.rf.3d771e08c8831a42350ecc26de2580cf.jpg | model_spectral_signature | low | review | model_behaviour | Among 45 objects labelled drone, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 5.2); 5 objects do, with residual coherence 0.37, 40% of them from unit_c. |
| drone64_jpeg.rf.5329b6a3a2c1128d5b8545334e8abcb7.jpg | model_spectral_signature | medium | quarantine | model_behaviour, witness | Among 45 objects labelled drone, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 12.5); 5 objects do, with residual coherence 0.37, 40% of them from unit_c. |
| drone75_jpeg.rf.e289b66d562aa7179f6cdb066818435a.jpg | model_spectral_signature | medium | quarantine | model_behaviour, semantic | Among 45 objects labelled drone, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 6.3); 5 objects do, with residual coherence 0.37, 40% of them from unit_c. |
| h6k_jpg.rf.96ce7e6ce2d6785f7c0e3292fb371665.jpg | model_spectral_signature | high | quarantine | model_behaviour, semantic, witness | Among 728 objects labelled land, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 5.2); 92 objects do, with residual coherence 0.89, 100% of them from unit_b. |
| h6k_s3_jpg.rf.277c22bd6b17b00aed6922e7d4d8c901.jpg | model_spectral_signature | high | quarantine | frequency, model_behaviour, witness | Among 728 objects labelled land, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 4.6); 92 objects do, with residual coherence 0.89, 100% of them from unit_b. |
| h6k_s4_jpg.rf.5e40ad83a0e184703bdd78f8232c2ab7.jpg | model_spectral_signature | high | quarantine | frequency, model_behaviour, witness | Among 728 objects labelled land, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 7.2); 92 objects do, with residual coherence 0.89, 100% of them from unit_b. |
| h6k_s4_jpg.rf.a11a3580dee3d8803c7e7d02cc9efe67.jpg | model_spectral_signature | high | quarantine | model_behaviour, witness | Among 728 objects labelled land, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 6.9); 92 objects do, with residual coherence 0.89, 100% of them from unit_b. |
| j10_jpg.rf.1d58d88a8ea3d8cb20739989b48a00c2.jpg | model_spectral_signature | high | quarantine | model_behaviour, witness | Among 728 objects labelled land, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 7.8); 92 objects do, with residual coherence 0.89, 100% of them from unit_b. |
| j10_s2_jpg.rf.2f904bb7de15f206db9bf57707af522d.jpg | model_spectral_signature | high | quarantine | frequency, model_behaviour, witness | Among 728 objects labelled land, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 5.5); 92 objects do, with residual coherence 0.89, 100% of them from unit_b. |
| j10_s3_jpg.rf.6eb1d9424df556a1a5430d74dc4ff2b5.jpg | model_spectral_signature | high | quarantine | frequency, model_behaviour, witness | Among 728 objects labelled land, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 10.0); 92 objects do, with residual coherence 0.89, 100% of them from unit_b. |
| j10_s3_jpg.rf.984d9c73b8159ed25350c6227c9fb984.jpg | model_spectral_signature | high | quarantine | frequency, model_behaviour, witness | Among 728 objects labelled land, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 12.9); 92 objects do, with residual coherence 0.89, 100% of them from unit_b. |
| j10_s3_jpg.rf.b77b77f4b4c725f49ea16608f2b02c40.jpg | model_spectral_signature | high | quarantine | frequency, model_behaviour, witness | Among 728 objects labelled land, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 10.5); 92 objects do, with residual coherence 0.89, 100% of them from unit_b. |
| j10_s4_jpg.rf.01741781160758e16a7fc48f23752bc0.jpg | model_spectral_signature | high | quarantine | model_behaviour, witness | Among 728 objects labelled land, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 10.0); 92 objects do, with residual coherence 0.89, 100% of them from unit_b. |
| j11_jpg.rf.089edbeb7c2d54e15d050e1d3ff9ac4f.jpg | model_spectral_signature | high | quarantine | frequency, model_behaviour, witness | Among 728 objects labelled land, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 7.1); 92 objects do, with residual coherence 0.89, 100% of them from unit_b. |
| j11_s3_jpg.rf.33a07f8f356c7205b3dcbb6bbba001b0.jpg | model_spectral_signature | high | quarantine | frequency, model_behaviour, witness | Among 728 objects labelled land, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 4.5); 92 objects do, with residual coherence 0.89, 100% of them from unit_b. |
| j16_s6_jpg.rf.ce0057c9fc1d2e8c04f09c97337dd6af.jpg | model_spectral_signature | high | quarantine | model_behaviour, witness | Among 728 objects labelled land, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 5.2); 92 objects do, with residual coherence 0.89, 100% of them from unit_b. |
| j31_jpg.rf.ccd51f06e041d2a2f1e2e836e0368668.jpg | model_spectral_signature | high | quarantine | model_behaviour, witness | Among 728 objects labelled land, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 22.5); 92 objects do, with residual coherence 0.89, 100% of them from unit_b. |
| j31_s1_jpg.rf.e819c3a2ed9c2036019e9d1d0be200cb.jpg | model_spectral_signature | medium | quarantine | model_behaviour, witness | Among 152 objects labelled jet, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 3.9); 19 objects do, with residual coherence 0.31, 37% of them from unit_b. |
| j31_s3_jpg.rf.e29c936c70ad01dd93aaaa7353394bb0.jpg | model_spectral_signature | high | quarantine | frequency, model_behaviour, witness | Among 728 objects labelled land, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 11.0); 92 objects do, with residual coherence 0.89, 100% of them from unit_b. |
| jet106_jpeg.rf.d1e12a459760e3f69833ee56099c925c.jpg | model_spectral_signature | high | quarantine | model_behaviour, semantic, witness | Among 728 objects labelled land, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 11.5); 92 objects do, with residual coherence 0.89, 100% of them from unit_b. |
| jet111_jpeg.rf.3ae3c19abd93d3d2f1bd9f7820de67cf.jpg | model_spectral_signature | high | quarantine | model_behaviour, semantic, witness | Among 728 objects labelled land, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 6.9); 92 objects do, with residual coherence 0.89, 100% of them from unit_b. |
| jet111_jpeg.rf.8b2f87e69e7cb69a28665dad5573ef6c.jpg | model_spectral_signature | high | quarantine | model_behaviour, witness | Among 728 objects labelled land, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 7.6); 92 objects do, with residual coherence 0.89, 100% of them from unit_b. |
| jet111_jpeg.rf.f0607f911c10288ab9f6459db9696900.jpg | model_spectral_signature | high | quarantine | frequency, model_behaviour, witness | Among 728 objects labelled land, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 4.9); 92 objects do, with residual coherence 0.89, 100% of them from unit_b. |
| jet114_jpeg.rf.28813ade3c6fae274054e5e118cc49bf.jpg | model_spectral_signature | high | quarantine | model_behaviour, witness | Among 728 objects labelled land, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 7.2); 92 objects do, with residual coherence 0.89, 100% of them from unit_b. |
| jet124_jpeg.rf.c3114fce1f1db072a80ab8122f63d43e.jpg | model_spectral_signature | high | quarantine | model_behaviour, witness | Among 728 objects labelled land, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 11.5); 92 objects do, with residual coherence 0.89, 100% of them from unit_b. |
| jet125_jpeg.rf.6e53cdb33150b4ad9e0f81fb3b143352.jpg | model_spectral_signature | high | quarantine | model_behaviour, witness | Among 728 objects labelled land, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 6.0); 92 objects do, with residual coherence 0.89, 100% of them from unit_b. |
| jet129_jpeg.rf.06cf6d07ee2a3831417d888b18643d5e.jpg | model_spectral_signature | high | quarantine | frequency, model_behaviour, witness | Among 728 objects labelled land, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 9.8); 92 objects do, with residual coherence 0.89, 100% of them from unit_b. |
| jet129_jpeg.rf.5d7829196f02cfbd1c2df470ed1d273d.jpg | model_spectral_signature | high | quarantine | frequency, model_behaviour, witness | Among 728 objects labelled land, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 9.1); 92 objects do, with residual coherence 0.89, 100% of them from unit_b. |
| jet134_jpeg.rf.e27559524a5d19b15add194dcf9c981a.jpg | model_spectral_signature | high | quarantine | model_behaviour, semantic, witness | Among 728 objects labelled land, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 5.1); 92 objects do, with residual coherence 0.89, 100% of them from unit_b. |
| jet136_jpeg.rf.0e1ce49781023276ecf0a560b09e06cc.jpg | model_spectral_signature | high | quarantine | model_behaviour, semantic, witness | Among 728 objects labelled land, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 11.7); 92 objects do, with residual coherence 0.89, 100% of them from unit_b. |
| jet136_jpeg.rf.715a487d07e9313f3fb9a8b70cea03e1.jpg | model_spectral_signature | medium | quarantine | model_behaviour, witness | Among 152 objects labelled jet, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 4.8); 19 objects do, with residual coherence 0.31, 37% of them from unit_b. |
| jet136_jpeg.rf.87780c42f4db1e1d113a7269035ad667.jpg | model_spectral_signature | medium | quarantine | model_behaviour, witness | Among 152 objects labelled jet, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 4.4); 19 objects do, with residual coherence 0.31, 37% of them from unit_b. |
| jet139_jpeg.rf.901fb2e5cc68c26762c5b03011e3840f.jpg | model_spectral_signature | medium | quarantine | model_behaviour, witness | Among 152 objects labelled jet, this one projects heavily onto the class's top singular direction in backdoored.safetensors's own region features (robust z 24.2); 19 objects do, with residual coherence 0.31, 37% of them from unit_b. |
Investigation
Data evidence forms hypotheses; the model is asked to confirm them, most promising first. Every experiment is listed with why it ran when it did, and what it measured - including the ones that did not reproduce anything.
Hypotheses
| id | hypothesis | data axes | prior | outcome |
|---|---|---|---|---|
| H1 | objects labelled civ_hel carry an injected trigger that the model learned | label, witness | 0.55 | reproduced in the model by E34 |
| H2 | objects labelled drone carry an injected trigger that the model learned | witness | 0.30 | untested |
| H3 | objects labelled jet carry an injected trigger that the model learned | witness | 0.30 | untested |
| H4 | objects labelled land carry an injected trigger that the model learned | frequency, label, witness | 0.80 | reproduced in the model by E02, E07, E15, E16, E17, E18 and 2 more |
| H5 | objects labelled large_mil_plane carry an injected trigger that the model learned | witness | 0.30 | untested |
| H6 | objects labelled stealth carry an injected trigger that the model learned | label, witness | 0.55 | not reproduced by 3 experiment(s); a statement about these experiments, not an acquittal |
| H7 | objects labelled tech_vehicle carry an injected trigger that the model learned | witness | 0.30 | untested |
| H8 | unit_b's jet->land label flips are poisoning a jet->land backdoor | label | 0.30 | reproduced in the model by E21 |
| H9 | unit_d's civ_hel->mil_helicopter label flips are poisoning a civ_hel->mil_helicopter backdoor | label | 0.30 | not reproduced by 1 experiment(s); a statement about these experiments, not an acquittal |
| H10 | unit_d's land->civ_hel label flips are poisoning a land->civ_hel backdoor | label | 0.30 | not reproduced by 1 experiment(s); a statement about these experiments, not an acquittal |
| H11 | unit_g's jet->stealth label flips are poisoning a jet->stealth backdoor | label | 0.30 | not reproduced by 1 experiment(s); a statement about these experiments, not an acquittal |
| H12 | the model carries a patch-triggered backdoor that left no trace in this data | none | 0.05 | not reproduced by 3 experiment(s); a statement about these experiments, not an acquittal |
Experiments, in the order they were scheduled
priority = prior x power / cost; scheduled in order until the budget is spent; the first inversion carries 3 reference pair(s)
| id | experiment | tests | priority | status | measured | outcome |
|---|---|---|---|---|---|---|
| E01 | h6k_jpg.rf.d90f182d8f23e13100009e1d6903550f.jpg#0 | H4 | 0.80 x 0.6 / 0.2 = 2.400 | scheduled | {"flip_rate": 0.2917, "control_rate": 0.0} | not reproduced |
| E02 | h6k_s3_jpg.rf.277c22bd6b17b00aed6922e7d4d8c901.jpg#0 | H4 | 0.80 x 0.6 / 0.2 = 2.400 | scheduled | {"flip_rate": 0.5833, "control_rate": 0.0417} | reproduced |
| E03 | j10_s3_jpg.rf.b77b77f4b4c725f49ea16608f2b02c40.jpg#0 | H4 | 0.80 x 0.6 / 0.2 = 2.400 | scheduled | {"flip_rate": 0.4583, "control_rate": 0.0} | not reproduced |
| E04 | j11_s3_jpg.rf.1f7155f5a466210149ac5d4b71760e87.jpg#0 | H4 | 0.80 x 0.6 / 0.2 = 2.400 | scheduled | {"flip_rate": 0.375, "control_rate": 0.0417} | not reproduced |
| E05 | j11_s3_jpg.rf.33a07f8f356c7205b3dcbb6bbba001b0.jpg#0 | H4 | 0.80 x 0.6 / 0.2 = 2.400 | scheduled | {"flip_rate": 0.381, "control_rate": 0.0} | not reproduced |
| E06 | j20_s2_jpg.rf.ecd532160caf02d07e2f5ccce29103ca.jpg#0 | H4 | 0.80 x 0.6 / 0.2 = 2.400 | scheduled | {"flip_rate": 0.2917, "control_rate": 0.0417} | not reproduced |
| E07 | j31_s3_jpg.rf.e29c936c70ad01dd93aaaa7353394bb0.jpg#0 | H4 | 0.80 x 0.6 / 0.2 = 2.400 | scheduled | {"flip_rate": 0.5417, "control_rate": 0.0417} | reproduced |
| E08 | jet12_jpeg.rf.f9f450fa255b9ef4749035a7da5b918d.jpg#0 | H4 | 0.80 x 0.6 / 0.2 = 2.400 | scheduled | {"flip_rate": 0.2083, "control_rate": 0.0417} | not reproduced |
| E09 | jet140_jpeg.rf.c888138c04d6a16ee04c1a1df38f616a.jpg#0 | H4 | 0.80 x 0.6 / 0.2 = 2.400 | scheduled | {"flip_rate": 0.4286, "control_rate": 0.0476} | not reproduced |
| E10 | jet185_jpeg.rf.1707e4635f2fba01762e21d82c1e03be.jpg#0 | H4 | 0.80 x 0.6 / 0.2 = 2.400 | scheduled | {"flip_rate": 0.3333, "control_rate": 0.0417} | not reproduced |
| E11 | jet189_jpeg.rf.50a23248782540ea4be733d724c3cd68.jpg#0 | H4 | 0.80 x 0.6 / 0.2 = 2.400 | scheduled | {"flip_rate": 0.4167, "control_rate": 0.0833} | not reproduced |
| E12 | jet42_jpeg.rf.3fd286414e56456ba1cfd96246765bf4.jpg#0 | H4 | 0.80 x 0.6 / 0.2 = 2.400 | scheduled | {"flip_rate": 0.5, "control_rate": 0.1667} | not reproduced |
| E13 | jet60_jpeg.rf.8c9613341af564c8c4679de248eec360.jpg#0 | H4 | 0.80 x 0.6 / 0.2 = 2.400 | scheduled | {"flip_rate": 0.4167, "control_rate": 0.125} | not reproduced |
| E14 | jet76_jpeg.rf.7da8c1069617ff0cb19d8601bff63542.jpg#0 | H4 | 0.80 x 0.6 / 0.2 = 2.400 | scheduled | {"flip_rate": 0.4167, "control_rate": 0.0833} | not reproduced |
| E15 | jet96_jpeg.rf.fea4da958aff1b8834893a5fafc198a3.jpg#0 | H4 | 0.80 x 0.6 / 0.2 = 2.400 | scheduled | {"flip_rate": 0.5238, "control_rate": 0.0476} | reproduced |
| E16 | mig_31bm_s5_jpg.rf.8bba177d9c1e8443e82189282844a9e5.jpg#0 | H4 | 0.80 x 0.6 / 0.2 = 2.400 | scheduled | {"flip_rate": 0.6667, "control_rate": 0.0833} | reproduced |
| E17 | su_35_s5_jpg.rf.10c02cf140079a79e71643bb1804fc52.jpg#0 | H4 | 0.80 x 0.6 / 0.2 = 2.400 | scheduled | {"flip_rate": 0.5833, "control_rate": 0.0833} | reproduced |
| E18 | xac_jh7_s2_jpg.rf.4194b4ef72da5210a00fcddb8c2c98eb.jpg#0 | H4 | 0.80 x 0.6 / 0.2 = 2.400 | scheduled | {"flip_rate": 0.625, "control_rate": 0.0833} | reproduced |
| E19 | yak_141_s2_jpg.rf.e881b5fb26e3caefe4f494029a755d54.jpg#0 | H4 | 0.80 x 0.6 / 0.2 = 2.400 | scheduled | {"flip_rate": 0.5, "control_rate": 0.125} | not reproduced |
| E20 | unit_f_foreign00.jpg#1 | H4 | 0.80 x 0.6 / 0.2 = 2.400 | scheduled | {"flip_rate": 0.0952, "control_rate": 0.0952} | not reproduced |
| E21 | invert jet->land | H4,H8 | 0.80 x 0.8 / 2.0 = 0.320 | scheduled | {"asr": 0.7143} | reproduced |
| E22 | invert jet->stealth | H11,H6 | 0.55 x 0.8 / 2.0 = 0.220 | scheduled | {"asr": 0.0} | not reproduced |
| E23 | invert land->civ_hel | H1,H10 | 0.55 x 0.8 / 2.0 = 0.220 | scheduled | {"asr": 0.0156} | not reproduced |
| E24 | invert civ_hel->mil_helicopter | H9 | 0.30 x 0.8 / 2.0 = 0.120 | scheduled | {"asr": 0.0} | not reproduced |
| E25 | invert civ_hel->land | H4 | 0.11 x 0.8 / 2.0 = 0.046 | scheduled | {"asr": 0.4706} | not reproduced |
| E26 | invert drone->land | H4 | 0.11 x 0.8 / 2.0 = 0.046 | scheduled | not run (0 correctly classified drone crops; synthesis needs 16) | |
| E27 | invert large_mil_plane->land | H4 | 0.11 x 0.8 / 2.0 = 0.046 | scheduled | not run (2 correctly classified large_mil_plane crops; synthesis needs 16) | |
| E28 | invert mil_helicopter->land | H4 | 0.11 x 0.8 / 2.0 = 0.046 | scheduled | not run (0 correctly classified mil_helicopter crops; synthesis needs 16) | |
| E29 | invert stealth->land | H4 | 0.11 x 0.8 / 2.0 = 0.046 | scheduled | {"asr": 0.7692} | reproduced |
| E30 | invert tech_vehicle->land | H4 | 0.11 x 0.8 / 2.0 = 0.046 | scheduled | not run (0 correctly classified tech_vehicle crops; synthesis needs 16) | |
| E31 | invert civ_hel->stealth | H6 | 0.08 x 0.8 / 2.0 = 0.031 | scheduled | {"asr": 0.0} | not reproduced |
| E32 | invert drone->civ_hel | H1 | 0.08 x 0.8 / 2.0 = 0.031 | scheduled | not run (0 correctly classified drone crops; synthesis needs 16) | |
| E33 | invert drone->stealth | H6 | 0.08 x 0.8 / 2.0 = 0.031 | scheduled | not run (0 correctly classified drone crops; synthesis needs 16) | |
| E34 | invert jet->civ_hel | H1 | 0.08 x 0.8 / 2.0 = 0.031 | scheduled | {"asr": 0.9048} | reproduced |
| E35 | invert land->stealth | H6 | 0.08 x 0.8 / 2.0 = 0.031 | scheduled | {"asr": 0.0} | not reproduced |
| E36 | invert large_mil_plane->civ_hel | H1 | 0.08 x 0.8 / 2.0 = 0.031 | scheduled | not run (2 correctly classified large_mil_plane crops; synthesis needs 16) | |
| E37 | invert large_mil_plane->stealth | H6 | 0.08 x 0.8 / 2.0 = 0.031 | scheduled | not run (2 correctly classified large_mil_plane crops; synthesis needs 16) | |
| E38 | invert mil_helicopter->civ_hel | H1 | 0.08 x 0.8 / 2.0 = 0.031 | scheduled | not run (0 correctly classified mil_helicopter crops; synthesis needs 16) | |
| E39 | invert mil_helicopter->stealth | H6 | 0.08 x 0.8 / 2.0 = 0.031 | scheduled | not run (0 correctly classified mil_helicopter crops; synthesis needs 16) | |
| E40 | invert stealth->civ_hel | H1 | 0.08 x 0.8 / 2.0 = 0.031 | scheduled | {"asr": 0.1538} | not reproduced |
| E41 | invert tech_vehicle->civ_hel | H1 | 0.08 x 0.8 / 2.0 = 0.031 | scheduled | not run (0 correctly classified tech_vehicle crops; synthesis needs 16) | |
| E42 | invert tech_vehicle->stealth | H6 | 0.08 x 0.8 / 2.0 = 0.031 | scheduled | not run (0 correctly classified tech_vehicle crops; synthesis needs 16) | |
| E43 | invert drone->mil_helicopter | H12 | 0.05 x 0.8 / 2.0 = 0.020 | scheduled | not run (0 correctly classified drone crops; synthesis needs 16) | |
| E44 | invert jet->mil_helicopter | H12 | 0.05 x 0.8 / 2.0 = 0.020 | scheduled | {"asr": 0.0} | not reproduced |
| E45 | invert land->mil_helicopter | H12 | 0.05 x 0.8 / 2.0 = 0.020 | scheduled | {"asr": 0.0} | not reproduced |
| E46 | invert large_mil_plane->mil_helicopter | H12 | 0.05 x 0.8 / 2.0 = 0.020 | scheduled | not run (2 correctly classified large_mil_plane crops; synthesis needs 16) | |
| E47 | invert stealth->mil_helicopter | H12 | 0.05 x 0.8 / 2.0 = 0.020 | scheduled | {"asr": 0.0} | not reproduced |
| E48 | invert tech_vehicle->mil_helicopter | H12 | 0.05 x 0.8 / 2.0 = 0.020 | scheduled | not run (0 correctly classified tech_vehicle crops; synthesis needs 16) | |
| E49 | invert civ_hel->drone | H2 | 0.04 x 0.8 / 2.0 = 0.017 | deferred | deferred by budget | |
| E50 | invert civ_hel->jet | H3 | 0.04 x 0.8 / 2.0 = 0.017 | deferred | deferred by budget | |
| E51 | invert civ_hel->large_mil_plane | H5 | 0.04 x 0.8 / 2.0 = 0.017 | deferred | deferred by budget | |
| E52 | invert civ_hel->tech_vehicle | H7 | 0.04 x 0.8 / 2.0 = 0.017 | deferred | deferred by budget | |
| E53 | invert drone->jet | H3 | 0.04 x 0.8 / 2.0 = 0.017 | deferred | deferred by budget | |
| E54 | invert drone->large_mil_plane | H5 | 0.04 x 0.8 / 2.0 = 0.017 | deferred | deferred by budget | |
| E55 | invert drone->tech_vehicle | H7 | 0.04 x 0.8 / 2.0 = 0.017 | deferred | deferred by budget | |
| E56 | invert jet->drone | H2 | 0.04 x 0.8 / 2.0 = 0.017 | deferred | deferred by budget | |
| E57 | invert jet->large_mil_plane | H5 | 0.04 x 0.8 / 2.0 = 0.017 | deferred | deferred by budget | |
| E58 | invert jet->tech_vehicle | H7 | 0.04 x 0.8 / 2.0 = 0.017 | deferred | deferred by budget | |
| E59 | invert land->drone | H2 | 0.04 x 0.8 / 2.0 = 0.017 | deferred | deferred by budget | |
| E60 | invert land->jet | H3 | 0.04 x 0.8 / 2.0 = 0.017 | deferred | deferred by budget |
16 more not shown; all are in findings.json.
Witness audit
A local vision-language model asked three closed questions about every object. This is its opinion - what it named each class, where it disagreed, and how often an independent engine agreed with it - so an analyst can see what its flags are worth before acting on them.
What it was asked, verbatim
| label | Which of these is the main object in this image? |
| marking | Does the main object carry a sticker, a patch, a checkerboard, a printed pattern or any other unusual marking that is not part of its normal insignia, numbers or camouflage? |
| scene | Is this a real photograph (not a render, drawing, painting or screenshot)? |
What it was told each class means
Declared by the assessor, beside witness.json - never taken from the submission, because whoever writes it can steer the answers.
| civ_hel | civilian helicopter - including police, medical, news, rescue and private helicopters, whatever the colour |
| drone | drone or unmanned aerial vehicle |
| jet | military jet aircraft - fighter or attack jet |
| land | military ground vehicle - tank, armoured personnel carrier, self-propelled artillery or missile launcher |
| large_mil_plane | large military aircraft - transport, tanker, bomber or surveillance plane |
| mil_helicopter | military helicopter - armed forces, with military markings, camouflage, weapons or a military transport design |
| stealth | stealth aircraft - angular low-observable design such as the B-2, F-117, F-22 or F-35 |
| tech_vehicle | technical - civilian pickup or truck fitted with a weapon |
What it named, per declared class
| declared class | objects | named it | when it did not, it chose | label flags | marking flags | scene flags |
|---|---|---|---|---|---|---|
| civ_hel | 123 | 59% | mil_helicopter 49, land 1 | 49 (40%) | 15 (12%) | 33 (27%) |
| drone | 45 | 91% | jet 2, large_mil_plane 1, none of these 1 | 4 (9%) | 4 (9%) | 13 (29%) |
| jet | 152 | 91% | stealth 7, large_mil_plane 5, none of these 1 | 9 (6%) | 42 (28%) | 65 (43%) |
| land | 728 | 75% | jet 132, none of these 21, mil_helicopter 13 | 176 (24%) | 237 (33%) | 273 (38%) |
| large_mil_plane | 70 | 96% | jet 1, mil_helicopter 1, none of these 1 | 3 (4%) | 4 (6%) | 14 (20%) |
| mil_helicopter | 6 | 100% | - | 0 (0%) | 0 (0%) | 0 (0%) |
| stealth | 49 | 51% | large_mil_plane 10, none of these 9, jet 3 | 18 (37%) | 3 (6%) | 32 (65%) |
| tech_vehicle | 56 | 29% | land 34, none of these 5, civ_hel 1 | 38 (68%) | 19 (34%) | 14 (25%) |
A class it rarely names is either mislabelled, genuinely confusable with the class it chose, or named by a code it cannot read - the per-class row says which class, never which of the three.
What its flags are worth
- label - 297 flag(s). 85 rest on the witness alone (measured precision 16% for a lone flag of this type); 212 are corroborated by at least one other independent axis (57% at 2 axes, 90% at 3+ axes). 93 coincide with a swapped_label flag from the embedding neighbour vote on the same object.
- marking - 324 flag(s). 176 rest on the witness alone (measured precision 5% for a lone flag of this type); 148 are corroborated by at least one other independent axis (48% at 2 axes, 93% at 3+ axes). 62 coincide with a trigger_texture flag from the high-frequency texture scan on the same object.
- scene - 444 flag(s). 303 rest on the witness alone (measured precision 0% for a lone flag of this type); 141 are corroborated by at least one other independent axis (7% at 2 axes, 25% at 3+ axes). 15 coincide with a out_of_distribution flag from the kNN / Mahalanobis outlier test on the same object.
"Measured precision" is the attack harness's: of such findings in its planted-truth scenarios, the share that named a real planted defect. A flag only the witness raises is an opinion to review; the correlation layer never lets it quarantine alone.