Skip to content

Strengthen empirical controls and offline reproduction - #1

Closed
bc1cindy wants to merge 224 commits into
masterfrom
audit/phase-0
Closed

Strengthen empirical controls and offline reproduction#1
bc1cindy wants to merge 224 commits into
masterfrom
audit/phase-0

Conversation

@bc1cindy

@bc1cindy bc1cindy commented Sep 9, 2026

Copy link
Copy Markdown
Owner

Summary

  • strengthens empirical controls and makes seeded graph matching deterministic
  • adds bounded route-capacity, value-pruned route, and maximum-flow evidence
  • refreshes offline reproduction bundles and source provenance
  • removes implicit network access from the test pipeline
  • bundles the pinned NumPy dependency required by graph reproductions
  • aligns the paper with the route-capacity implementation and committed result

Verification

  • full offline suite: 1,633 passed, 7 skipped, 70 deselected
  • committed match-controls reproductions: 2 passed, including the independent verification pass
  • route-capacity algorithm and experiment: 27 passed
  • paper-number gates: 6 passed
  • bundle/provenance gates: 29 passed
  • bundle sync check: clean
  • Git diff check: clean

Scope and limitations

  • route-capacity-v1 is a depth- and data-bounded measurement on one committed slice, not a chain-scale proof of robust connectivity
  • own-origin robustness has not yet been evaluated with independently specified user antecedents
  • matcher determinism is fixed, but multiseed, order, and window sensitivity with confidence intervals remains future work
  • link prediction remains partial as documented in the reference-fidelity audit
  • the committed bundles reproduce offline on the current platform; Linux x86-64/aarch64 bundles and immutable mirrored publication remain release work
  • full committed-bundle reproductions are intentionally slow and should be classified as nightly/manual rather than fast per-commit gates

The clusterer declines a doubted merge that would fuse two established
clusters, cuts views along cluster-collapse regions, and orders a clustering by
how little each merge contradicts itself. The shared detectors go with it: equal-
amount coinjoins are recognised by their denomination, and the UIH axis is
labelled by the heuristic it actually computes.
…tion

Streaming transactions with a dense-int union-find lets a slice larger than
memory cluster; the chunked downloader collects a month at a time without
billing-side limits. Epoch splitting and backend profiling come with them.
…tion

Seeds bootstrap from vertices whose local degree signature is unique and
identical across both views, so propagation no longer needs an externally
supplied seed, and the link-prediction fallback abstains by default to keep
precision high. Measured on a real 2016 slice, where the attack's precondition
fails and is reported as failing.
Run against real transactions for the first time, the channel was cutting
every coin it could not measure: the oracle spells unreachable as negative
infinity while the guard tested for None, which is 98.2% of input coins. The
whole-transaction count is bounded at the width where it stops returning, and
the link matrix supplies a fee-tolerant per-coin reading the exact-hit counts
cannot.
Subset-sum multiplicity does not enter a refuse-only bound. In the
sub-transaction literature the mapping count is the denominator of a link
probability, never a multiplier on one, and the column being weighted is already
renormalized, so the factor reintroduced exactly what the matrix had divided out.

The paper moves with the contract: each claim the tree no longer supports is
corrected at its source rather than only where it was retracted, and the guard
matches the claim rather than three phrasings of it.
…a direction

A manifest records a result's source identity and the population invariants a
byte digest cannot see. separable is three-valued, so a decisive inversion is not
reported as noise, and it gates the exact binomial on min(a, b) rather than a + b:
the exact sum costs min(a, b) terms, so the lopsided shape a real direction claim
takes stays exact at any sample size, and only near-ties reach the approximation.
…olicy

The persistence curve and the slice gate reproduce their published tables from committed query
output, so both move to state 1. Change-id validation moves the other way: the window it names holds
739,889 transactions and cannot be a fixture. Twenty-five documents that carried no evidence level
now name one; the two that fit no state say which and why, and one of them is why the policy needs a
state for a measurement whose data is gone.

slice_gate.sql did not run: all three of its queries closed a CTE they never opened.
The rule is the one already applied here: bold marks a claim, not a term. Applied to running prose it
leaves twenty independent clauses bold and strips a hundred and twenty-one names, values and single
emphasis words. Run-in headings, table cells and quoted emphasis are untouched — the emphasis inside
a quotation belongs to whoever wrote it.
Every evidence channel had a canonical run and the engine that fuses them had none: it ran on stubs
in unit tests and on data this repository does not ship, so the object the argument rests on was the
one nothing published executed. The reason was structural — the engine read transactions through a
cache that is not committed — so fetch becomes an argument, the way the subset-sum hook already was.

The ladder is the result. Topology corroborates merges the fingerprint refused and provenance cuts
pairs it kept, which is what fusing them is for; the amount channel moves nothing here because it is
refuse-only and gated behind fingerprint disagreement.
… carry

The weekly export is 977 MB in five files, each past the 100 MB a git host accepts, so the results
measured on it could not be reproduced by anyone. What the pipeline reads is narrower than what the
export stores: the transaction id is never read, and an address only has to be distinguishable, not
itself. Sixteen times smaller, 5.9 million transactions, every file under 14 MB.

That an address may become an integer is a claim about the engine, so it is tested against the
engine: the same partition under an order-preserving and an order-reversing renaming. Addresses a
detector names itself in keep their text — 94 of 1,788,311 on the first epoch.
Numbering each file from zero passed every check the encoder had — counts, heights, coincidence
graph — because each of them read one file. The damage was between files: `a000000000` stood for a
different address in each window, so the clusterer read a coincidence that does not exist and the
rejoinable population fell from 17,431 to 4,972 on the committed epochs.

What caught it was not the suite, which stayed green, but running the same pipeline over the export
the derived files came from. With one namespace the two agree exactly, and two tests now cover the
seam the round-trip could not see.
The population was first measured on a 1.1 GB slice that no longer exists, so the figure could
neither be checked nor taken again. On the committed weekly graph it lands in the same place:
17,431 clusters straddling the boundary at a mean internal degree of 2.866, and one correct rejoin
out of the 15,688 pairs left once a tenth are seeded, with every shuffled-seed arm at zero.

The null is asserted as a bound rather than left as an absence, so a run that does ignite fails the
test instead of passing quietly. assortativity sorted vertices that a contracted view makes
incomparable, which is why no contracted view had ever been measured for shape.
Half of them were reachable from no claim that named a source, and five of those cited nothing in
the file either — no identifier, no year. A reader could not tell which paper, or which edition of
it, the code was meant to agree with. The other half were bound through the claim catalogue, which
does not help anyone who opens the module.

A gate now requires the citation and that the entry exists, which is the weakest rule that fixes the
problem: whether a reimplementation is faithful is a separate question this cannot answer.
Each was measured on a source that no longer exists, so nobody can check the numbers and nobody can
take them again. Keeping them behind a label would give a figure nobody can verify the standing this
work argues a vendor should not get: the burden of proof does not reverse because the measurement
was ours. The paper's witness-drift paragraph went with them, and five declared-unbacked numbers
with it.

Git keeps the record; the published surface no longer offers it as evidence. REPRODUCIBILITY.md
names the condition with the vocabulary the corpus already uses rather than inventing a sixth state.
Removing the results page took the script with it, and a test pins that script: the mechanism is
unit-tested even though the sample its headline numbers came from is gone. Two checks disagreed
about whether anything imported it and the narrower one was believed.
…y over

Both of the framework's positive properties are the size of a minimum cut — how many coins a
separation has to take before an output stops reaching its origins — and nothing here computed one.
path_count accumulates route mass and says in its own docstring that this is a different number;
on the committed cache the two disagree for three coins in every five.

A tenth of the coins are separated from their whole ancestry by removing one coin. The boundary the
walk stopped at is recorded beside that, because almost every origin it reaches is the edge of the
slice rather than a coinbase, and a reader given the fragility without the sample limit would take
a floor for a ceiling. Routes are counted, not weighted: the value half stays unimplemented and the
capability contract now says so rather than denying the whole metric.
The specification prunes before it counts — a path worth less than the amount in question may have
been removed — and leaving that out made the measurement overstate redundancy in the direction that
matters. Routes that could carry the coin take the single-coin cut from 10% to 21%, and 38% of coins
have no such route at all.

This is the same error as counting origins without their overlap, made twice: a route that shares a
coin does not add redundancy, and neither does one too small to explain the coin. Value enters as a
threshold and not as capacity, so the capability contract still denies plausible-flow capacity;
giving each coin its value and measuring the flow is a different quantity nothing here computes.
Nineteen of nineteen carried partially_supported, so the field said nothing and an audit could read
past it. The schema already distinguishes that from supported_at_evidence_level, and the distinction
is the one that matters: an existential claim demonstrated on a deterministic fixture is not partly
proven, it is proven at the level it declares, and its limitations say what it does not reach.

Twelve are that. Seven are genuinely partial and now each names what is missing, which is what the
new gate enforces — along with the rule that a supported claim cannot also declare an unfinished
mechanism. Writing them exposed that the reasons had lived in a script rather than the catalogue.
@bc1cindy

bc1cindy commented Sep 9, 2026

Copy link
Copy Markdown
Owner Author

Closing this preliminary publication while the local commit stack is reorganized and audited before the complete push.

@bc1cindy bc1cindy closed this Sep 9, 2026
@bc1cindy
bc1cindy deleted the audit/phase-0 branch September 9, 2026 04:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant