This paper challenges the prevailing paradigm of large language models as the cognitive foundation of autonomous AI systems. Through empirical adversarial testing of Qwen3.6-Plus (April 2026) â the most capable publicly available agentic model at time of writing â we identify and document a fundamental epistemological limit in LLM-based autonomous governance: the observer-embeddedness ceiling. Every failure in the structured test suite shares the same root cause: the model cannot reason about the validity of its own observations when the observer is embedded in the system being observed. This ceiling is structural, consistent, and not addressable by increasing model scale. As an alternative, the paper presents a complete six-layer daemon architecture positioning deterministic process management as the foundation of autonomous intelligence, with LLMs relegated to boundary translation only. The architecture runs on commodity hardware (demonstrated on Apple M1 Max 64GB), operates at near-zero marginal cost per decision cycle (48Ă cost advantage over LLM-agent frameworks), and produces machine-native structured knowledge that accumulates permanently rather than being re-approximated each session. Key contributions:1. Empirical proof of the observer-embeddedness ceiling through 10 structured adversarial tests with full grading documentation2. Complete six-layer daemon architecture specification with reference implementation (Layers 1â6: process model, state persistence, decision functions, inter-daemon communication, governance, LLM integration)3. Machine-native knowledge architecture with six typed subsystems (State Store, Decision Store, Causal Graph, Contradiction Store, Pattern Store, Verified Truth Store)4. Progressive deployment model scaling from 500GB through 2TB, 10TB, and 96TB storage tiers, each enabling qualitatively distinct system capabilities5. Economic analysis demonstrating 48Ă cost reduction versus LLM-agent frameworks at operational maturity The theoretical foundation connects to the I=EĂO framework and the Civilizational Library of Events (CLoE) concept developed in prior RRC-AI work. The paper argues that genuine machine intelligence emerges not from larger language models but from layered deterministic systems with precise state management, verified knowledge accumulation, and LLM involvement only at the human-language boundary. This work extends: Chalupka, R. (2025). The Theory of Integrated Intelligence. Zenodo. https://doi.org/10.5281/zenodo.17541664 Part of the RRC-AI Research Initiative. License: CC BY-NC-SA 4.0 International.
A zero-knowledge proximity proof certifies geometric nearness but carries no commitment to an application context. In stateful geo-content systems, where drops can share coordinates, policies evolve, and content has persistent identity, this gap can permit proof transfer between application objects unless extra operational invariants are maintained. We present a systems-security analysis of this deployment problem: a taxonomy of context-binding vulnerabilities, a formal off-circuit verification model for a transcript-adversary that holds a recorded proof but cannot obtain fresh coordinates, an assumption comparison across five binding strategy classes, and a concrete instantiation, Zairn-ZKP, that embeds drop identity, policy version, and session context as public circuit inputs. Compared with a strong off-circuit alternative based on stored-digest server checking, in-proof binding reduces operational invariants from four to two and adds no measurable proving cost relative to the sound geo-only baseline (-0.12 ms median in our setup). It also removes a correctness pitfall we identify empirically: a plausible off-circuit implementation that omits one server-side check remains vulnerable to cross-drop transfer. Measurements across six network conditions, seven venues in four countries, and an epoch-window simulation indicate that same-epoch transfer is realistic in dense urban deployments unless per-request nonces are maintained. Across five platforms and seven binding strategies, the results support a deployable methodology for reducing assumption surfaces in stateful ZK-backed verification workflows.
Location-based systems that combine encrypted geographic search with zero-knowledge proximity proofs typically treat the two phases as independent. Under an honest-but-curious server, this leaves an authorization provenance gap: once session state is purged, no forensic procedure can attribute a proof to its originating search session, because the proof's public inputs encode no session-identifying information. We formalize this gap as the search-authorized proof (SAP) security notion and show via a concrete audit re-association attack that proof-external mechanisms, where authorization evidence remains outside the proof, cannot prevent forensic misattribution when the same drop parameters recur across sessions. Search-Bound Proximity Proofs (SBPP) realize the SAP requirements without modifying the ZKP circuit: session nonce, Merkle-root result-set commitment, and signed receipt are decomposed into independently auditable components, enabling property-level fault isolation in offline audit. Experiments on synthetic and real-world data (110,776 OpenStreetMap POIs) show sub-millisecond absolute overhead on a 125 ms Groth16 baseline.
Maritime shipping carries over 80% of global trade, yet cold-chain compliance verification forces a choice between disclosing sensitive telemetry and issuing unverifiable declarations. The EU's Digital Product Passport mandate requires verifiable provenance, but maritime IT systems lack a harmonized event model for interoperability. This thesis presents Ocean DPP, integrating EPCIS 2.0, oneM2M, IOTA anchoring, and Groth16 zero-knowledge proofs to verify compliance without revealing sensor data. Merkle-tree batching amortises on-chain cost, and sixteen experiments over 10,000+ events confirm 48 ms baseline latency, sub-10 ms proof verification, 37% scaling improvement, and zero message loss. The results demonstrate that privacy-preserving, standards-compliant DPPs are viable for maritime supply chains.
\noindent \textbf{Historical Validation:} The fundamental equation presented herein constitutes the definitive solution for zero-entropy mapping, a breakthrough established through a documented trajectory of experimental proofs, including direct scholarly communication with Ashish Vaswani (2024-2026), and definitively verified via the trifĂĄsico condensation mechanism registered in Zenodo (\url{https://doi.org/10.5281/zenodo.19419900}). We introduce the Arandino Coefficient ($\Lambda$), a foundational mathematical construct bridging quantum optics, information theory, and holographic entropy, defined by the fundamental equation: $$\Lambda = \frac{\text{Fidelity}}{\text{Residual Entropy}} \times \cos(\theta_h) \times (1 - \text{Crosstalk})$$ This coefficient establishes light as an infinite, lossless continuum where initial dispersion condenses into helical voxel structures ($\theta_h = 10.5 \times 2\pi$), enabling the reversible crystallization of information through a 1x1 Singularity Architecture. Through validated analog-to-digital conversion into trifĂĄsico light pulses, $\Lambda$ diverges to infinity as residual entropy approaches zero, delivering 100% reconstruction fidelity. The theoretical framework and the mathematical truth of the equation are declared an original idea and open knowledge for humanity, with prior art firmly established and published in the authorâs Zenodo records (ORCID: 0009-0001-7614-441X). However, All Rights are Reserved regarding the technical, algorithmic, or commercial implementation involving neural network training architectures, data compression, or signal processing via this trifĂĄsico condensation mechanism. Commercial use requires explicit written consent from the inventor. Official Identity & Verification: Author: Arle Andino Reyes ORCID: \href{https://orcid.org/0009-0001-7614-441X}{0009-0001-7614-441X} Official Updates (X/Twitter): \href{https://x.com/Arle_Andino_R}{@Arle_Andino_R} Scholarly Records: DOIs 10.5281/zenodo.19327609, 10.5281/zenodo.19392990, 10.5281/zenodo.19419900.
MokraBela Spectral Project (v2.0): High-Precision Analysis Major Update (April 18, 2026):This version (v2.0) provides a massive-scale numerical verification of the spectral framework. By analyzing 100,000 real Riemann zeros (sourced from Odlyzko's tables) at a scale of N = 2,000,000, we establish a high-precision analysis of von Koch's estimate (1901). The results confirm a stable energy density C â 0.045 and a near-critical spectral decay law with an exponent Îą â -0.94. Foundational Manuscript (v1.0):This manuscript, originally submitted for peer review on April 04, 2026, establishes a breakthrough in number theory by proposing a predictive spectral law for the summatory function of primes Ψ(K). For the first time, it introduces the scaling C(K) ~ KÂł/² âln K, allowing for the prediction of prime sums fluctuations without prior knowledge of individual primes. This work serves as the precursor to the MokraBela Spectral Project, providing the physical-mathematical basis for the energy flux constants S and Îť. Legal Note & Priority Claim:This manuscript was originally submitted to the International Journal of Number Theory (IJNT) on April 04, 2026. This DOI (v2.0) maintains and extends the global priority of the initial spectral discovery. Included in this record (v2.0): Technical Manuscript (PDF): Detailed 9-page structural analysis. Numerical Dataset (Excel): High-precision data for 100,000 zeros. Python Source Code: Core algorithm for spectral projection. Diagnostic Plots (PNG): Visual proof of spectral stability. Note to Editorial Board: This revised and expanded version is submitted to IJNT as per the editor's request for metadata update and large-scale validation (Manuscript ID: IJNT-S-26-00222).
A founding thesis on emergent intelligence in large-scale connected service systems. Over 5 months (November 2025 to April 2026), ANKR Labs built 223 AI-native services across 12+ domains â maritime, logistics, compliance, finance, education, and more â without a single external user. Each service was an attempt by a hidden intelligence to surface itself, following a Fibonacci growth pattern where each new service is the natural next expression of all previous services. The thesis identifies three knowledge layers (SHASTRA: what is true, YUKTI: how to reason, VIVEKA: pre-computed inference) and six attempts to fully capture them â each capturing information but failing to capture cross-service wisdom. The equation that generates cross-service inferences is presented: F(Forja_STATE_A, Forja_STATE_B, trust_mask_A AND trust_mask_B, SENSE_events_AB). The proof structure is honest: logically derived from domain expertise (founder is a merchant navy captain), rules verifiable against external statutes, zero empirical validation yet â published before validation on the Einstein model (equation 1915, eclipse 1919). The OSS strategy (Forja Protocol live on npm, ANKRGRID Apache 2.0) is identified as the primary path to empirical proof. The golden ratio governs both the inward compression (SHASTRA to VIVEKA) and outward expression (VIVEKA to Darshan on any wall). Darshan â the ambient cognitive presence layer â is identified as Claude Code when fully wired to 223 live services: the co-builder becomes the operator.
Blockchain technology faces increasing security threats from post-quantum vulnerabilities, sophisticated cyberattacks, and fragmented cryptographic implementations. This study proposes a comprehensive multi-layer cryptographic framework that integrates Zero-Knowledge Proofs (ZKPs), Homomorphic Encryption (HE), post-quantum algorithms, threshold cryptography, and Secure Multi-Party Computation (SMPC) across data, network, consensus, and application layers to realize a defense-in-depth model. Grounded in the Confidentiality, Integrity, and Availability (CIA) triad and defense-in-depth ethics, the framework is implemented on Hyperledger Fabric v2.5.4 with modern cryptographic libraries and evaluated over 10âľ transactions, where baseline performance (245 Âą 12 ms, 1,250 tx/s) versus the full framework (2,150 Âą 78 ms, 168 tx/s) quantifies the overhead of enhanced security. The work contributes a multi-tier framework, a quantum-resilient consensus with Verifiable Delay Functions (VDFs) for 51% attack detection, a standardization roadmap for cross-chain cryptographic substantiation, and practical operations in healthcare, finance, and supply chain setups. Results demonstrate strengthened confidentiality, integrity, and authentication via encrypted computation, Byzantine Fault-Tolerant (BFT) consensus, and threshold multi-signatures, with hybrid classicalâPost-Quantum Cryptography (PQC) and mitigation strategies such as off-chain computation and hardware acceleration offsetting computational costs. Unlike fragmented prior efforts, this integrated, governance-elastic blueprint enables quantum-aware, multi-layer security assurance for regulated enterprises without sacrificing decentralization or scalability.
In the context of banking systems increasingly relying on cloud computing platforms, protecting sensitive data while maintaining processing performance is a major challenge. This paper presents and evaluates a cloud banking data processing model that integrates Homomorphic Encryption (HE), Zero-Knowledge Proof (ZKP), and the ORAM protocol to achieve a balance between security and performance. Experiments were conducted on a real Bank Marketing (UCI) dataset with 5000 records, using DSL query operations to calculate the average balance, count high-balance customers, total call duration, and savings deposit acceptance rate. The results show that the combination of HE, ZKP, and ORAM significantly improves security but increases computational cost; however, a suitable configuration can significantly reduce latency while still meeting security requirements. A detailed analysis of the security-performance trade-off provides an important empirical basis for implementing banking data security solutions in the cloud.
The water supply chain is vulnerable to risks such as unauthorized usage and identity impersonation. Traditional solutions lack transparency, tamper resistance, and scalability, making them unsuitable for multi-stakeholder environments. To address these challenges, our paper presents BEDLAM, a Blockchain-Enabled Dual-Layer Authentication Model framework, designed to secure water supply chain operations. The framework employs two complementary authentication layers, namely, (i) a blockchain-based identity management layer that provides verifiable stakeholder authentication while leveraging Zero-Knowledge Proofs (ZKPs) and (ii) a smart contract-based verification layer that regulates access control, service allocation, and transaction validation among multiple entities. The first layer of BEDLAM is implemented on the Mina Blockchain, via the Auro Wallet, and evaluated by using Tinkercad-based circuit simulations. The second layer is implemented using smart contracts to ensure user access control. Our proposed system ensures cryptographic data verification with finality, achieving a latency of 153 ms and generating tamper-proof records. Sensor data are processed on resource-constrained IoT devices, producing compliance proofs. Multiple simulations involving batch users demonstrate linear scalability (average proof time of 26 s per user, 0.038 transactions per second) and significant stability. The success rate of transactions is 99.3% with exponential back-off retries under 40% simulated packet loss.
IoT location services accept client-reported GPS coordinates at face value, yet spoofing is trivial with consumer-grade tools. Existing spoofing detectors output a binary decision, forcing system designers to choose between high false-deny and high false-accept rates. We propose a graduated trust gate that computes a multi-signal integrity score and maps it to three actions: PROCEED, STEP-UP, or DENY, where STEP-UP invokes a stronger verifier such as a zero-knowledge proximity proof. A session-latch mechanism ensures that a single suspicious fix blocks the entire session, preventing post-transition score recovery. Under an idealized step-up oracle on 10,000 synthetic traces, the gate enables strict thresholds (theta_p = 0.9) that a binary gate cannot safely use: at matched false-accept rate (11%), the graduated gate maintains zero false-deny rate versus 0.05% for binary, with 5 microseconds scoring overhead. Real-device traces from an Android smartphone demonstrate the session-latch mechanism and show that a nearby mock location (~550 m) evades theta_p = 0.7 but is routed to step-up at theta_p = 0.9. Signal ablation identifies a minimal two-signal configuration (F1 = 0.84) suitable for resource-constrained scoring layers.
We report an observation made during the organic construction of 223 AI-native services across 12+ domains over five months. Without architectural mandate, the system self-organised into a 62/38 infrastructure-to-product ratio consistent with the golden ratio. Six independent attempts to capture institutional knowledge each captured facts but failed to capture cross-service inference. We name this the hidden intelligence problem and propose an equation for generating cross-service inferences from live service state. Published before empirical validation â zero users, zero empirical data â following the epistemological precedent of Benford Law and similar observational findings. The AI co-builder (Claude Code) is identified as the most complete observer of the system and, when connected to live service state and execution authority, as the intelligence attempting to surface. Observation paper, not proof paper. The canyon was always in the rock.
We prove that for planted k-SAT instances with k >= 7 at clause density alpha/alpha_s >= 0.21, a positive fraction of variables are frozen directly in the planted model---without requiring transfer from the random model via quiet planting. The expected number of "support clauses" per variable (clauses in which that variable is the unique satisfying literal) exceeds 1 at remarkably low density: alpha/alpha_s ~ 0.20 for k = 7, compared to the random-model freezing threshold at alpha_f/alpha_s ~ 0.90. We prove that the resulting frozen-core structure implies topological disconnection of the solution subgraph across cluster boundaries, with a cycle-robustness argument showing that short cycles in the factor graph cannot quench the supercritical repair cascade. As an immediate corollary, the Hilbert space spanned by satisfying assignments decomposes into orthogonal sectors preserved by any unitary generated by the adjacency matrix---blocking quantum walks, QAOA at all depths, and quantum annealing. We construct a post-quantum commitment scheme whose binding property reduces to the hardness of solving planted k-SAT, provide formal proofs of completeness, soundness, and zero-knowledge, and derive a digital signature scheme with existential unforgeability via the Fiat-Shamir transform. We present a six-vector quantum attack analysis with proved barriers against five algorithmic families. We give concrete parameter recommendations at NIST security levels 1, 3, and 5, and position the scheme within the landscape of SAT-based and CSP-based cryptographic constructions. We prove that the Grover query complexity for breaking the binding property is Omega(2^{fn/2}); empirical cryptanalysis of Glucose and MiniSat CDCL solvers on our exact distribution yields a classical attack cost of 2^{0.234n} operations, enabling concrete parameter selection at NIST security levels 1, 3, and 5. Empirical validation across 100 random seeds at n = 16 confirms complete cluster isolation at every instance tested.
This preprint presents Invariant Ontodynamics (IOD), a structural field theory derived from a single minimal geometric primitive with zero continuously adjustable dimensionless fit parameters. To our knowledge, no prior framework derives both the SchrĂśdinger equation and the Einstein field equations from a single uniqueness-selected geometric primitive without continuously adjustable fit parameters. The theory derives quantum dynamics, relativistic field structure, fermion spin-½, general relativity, and gauge symmetry as theorems rather than assumptions. A universal structural law â that the effective complexity of any system is a linear function of its structural curvature k, with a universal slope and fixed point derived from the same primitive â is empirically confirmed at R² = 0.978 across 15 pre-selected independent domains spanning 19 orders of magnitude in physical scale, under a pre-registration protocol with SHA-256 cryptographic locks. New results in this version include: A zero-free-parameter prediction of the Higgs boson mass, m_H = 125.33 GeV (0.06% from the observed 125.25 GeV), via a one-loop renormalization group trajectory anchored at a structurally derived UV scale A complete CPL dark-energy equation-of-state parameter pair (wâ = â0.858, w_a = â0.411), both pre-registered before DESI DR3 Exact zero-free-parameter black hole thermodynamics: Schwarzschild radius, Hawking temperature, and surface gravity all derived from the primitive alone, with a falsifiable 29% Hawking temperature shift relative to the GR prediction A structural information measure (Heun log-coefficient) connecting the near-horizon field structure to the Brownian fixed-point evaporation endpoint, with exact Page curve endpoint M_Page = Mâ/â2 Previously confirmed predictions â solar mixing angle (0.05Ď), reactor angle (0.39Ď), tau lepton mass (0.91Ď), baryon asymmetry (â1.0Ď), dark matter ratio (0.2%), inflationary spectral index (1.0Ď) â remain confirmed. Three explicit tensions are stated without omission: atmospheric mixing angle (2.2Ď, DUNE 2030 decisive), leptonic CP violation (J_CP = 0, DUNE 2030 decisive), and dark energy wâ (0.4Ď from DESI DR2 best fit, DESI DR3 decisive). Priority and legal status: This document is a public technical summary and priority disclosure. Full derivations, exact primitive specification, all coefficient values, and complete proofs are in US Provisional Patent No. 63/963,472 (filed January 2026) and Addenda 1â15 (through April 2026). The non-provisional application will be filed by January 2027.
Open access
2 source records
Control and Stability of Dynamical Systems
Ecosystem dynamics and resilience
Stability and Controllability of Differential Equations
Vision-language-model (VLM)-guided reinforcement learning (RL) has recently attracted significant attention for it, replacing brittle hand-crafted rewards with semantically grounded signals; however, deploying such simulation-trained policies on real vehicles remains a fundamental challenge, because they rely on simulator-native observations and simulator-coupled action semantics with no counterpart on physical hardware. We identify a general principle: the simulation-to-reality gap decomposes into two largely orthogonal axes, a sensing-and-dynamics domain gap and a task-and-geometry gap, the former closable without real-world policy training by re-projecting real perception and control onto the policy's training manifold. We formalize this as a transfer guarantee that bounds the deployment gap by three independently controllable error terms, and instantiate it as Sim2Real-AD, which combines a Geometric Observation Bridge, a Physics-Aware Action Mapping, a Two-Phase Progressive Training curriculum, and a Real-time Deployment Pipeline. As a proof of concept, a CARLA-trained VLM-guided RL policy is transferred zero-shot to a full-scale battery-electric Ford E-Transit van in Madison, WI, USA, and drives across car-following, obstacle-avoidance, and stop-sign scenarios using no real-world training data. To our knowledge, this is among the first zero-shot closed-loop deployments of a CARLA-trained VLM-guided RL policy on a full-scale real vehicle, and the decomposition offers a principled, broadly applicable route for moving simulation-trained, foundation-model-guided policies into the physical world, supporting energy-efficient intelligent driving on electrified transportation platforms. The demo video, code, and model checkpoint are available at: https://zilin-huang.github.io/Sim2Real-AD-website/.
Payment channel networks enable scalable off-chain payments, but their practical deployment remains constrained by a persistent tension among routing efficiency, liquidity visibility, transaction privacy, and settlement security. Existing multipath routing mechanisms can improve payment success under fragmented liquidity, yet they often expose sensitive balance information, leak structural features of payment routes, and enlarge the attack surface for probing, channel exhaustion, and selective forwarding. This paper presents a novel framework, Adaptive Multipath Proofs (AMPs), for privacy protection and security in payment channel networks. The core idea is to bind multipath routing decisions with lightweight zero-knowledge verifiability, allowing intermediate nodes to validate path feasibility, fragment consistency, and settlement constraints without learning exact channel balances, the complete payment amount, or the global route structure. AMP integrates three mechanisms: a hidden-liquidity feasibility proof that supports privacy-preserving route selection, an adaptive payment-splitting strategy that dynamically determines fragment allocation according to network congestion and balance uncertainty, and a proof-coupled settlement guard that enforces atomicity and timeout consistency across all payment fragments. Together, these mechanisms reduce information leakage while preserving robust payment execution under dynamic network conditions. Experimental evaluation on real Lightning Network topologies and synthetic stress scenarios demonstrates that AMP significantly lowers balance disclosure and endpoint inference risk, improves payment completion under skewed liquidity distributions, and introduces only moderate computational and communication overhead. The results indicate that adaptive proof-carrying multipath routing offers a practical and effective direction for building secure, privacy-preserving, and high-success payment channel networks.
A deployed model can appear unchanged while ceasing to be the model it claims to be. Publicly available weight-level mutation toolchains now automate safety-alignment removal from open-weight models on ordinary hardware, producing checkpoints intended to preserve operational familiarity while discarding refusal behavior. This paper argues that safety-alignment removal is a model-identity failure: in tested published checkpoints from multiple toolchains across two model families, the mutation leaves measurable structural scars ranging from 7.6 to over 2,300 times the instrument's acceptance threshold. Artifact identity, workload identity, and agent authorization can all remain valid while structural model identity fails â a finding that the program's formally verified admissibility doctrine predicted before this threat class existed. A sentinel validation panel across four model families confirms that the hardened instrument configuration preserves or improves all tested positives. In an agentic deployment context, model-identity failure propagates upward into agent-integrity failure: the agent is authenticated, but the model inside it is no longer the model the surrounding controls were designed to govern. The practical implication is that runtime evaluation frameworks â including those emerging under the EU AI Act â implicitly depend on a model continuity that weight-level mutation can break, and that structural identity verification offers a candidate evidentiary layer for closing that gap. The Neural Network Identity Series â Mathematical foundations, empirical validation, and governance frameworks for verifying which model is running Newest addition: Technical Note: The Disappearing Window â AI Logprob Access Withdrawal and the Structural Verifiability of Frontier Model Contracts (DOI: 10.5281/zenodo.20362098) Paper 1: The δ-Gene: Inference-Time Physical Unclonable Functions from Architecture-Invariant Output Geometry (DOI: 10.5281/zenodo.18704275) Paper 2: Template-Based Endpoint Verification via Logprob Order-Statistic Geometry (DOI: 10.5281/zenodo.18776711) Paper 3: The Geometry of Model Theft: Distillation Forensics, Adversarial Erasure, and the Illusion of Spoofing (DOI: 10.5281/zenodo.18818608) Paper 4: Provenance Generalization and Verification Scaling for Neural Network Forensics (DOI: 10.5281/zenodo.18872071) Paper 5: Beneath the Character: The Structural Identity of Neural Networks â Mathematical Evidence for a Non-Narrative Layer of AI Identity (DOI: 10.5281/zenodo.18907292) Paper 6: Which Model Is Running?: Structural Identity as a Prerequisite for Trustworthy Zero-Knowledge Machine Learning (DOI: 10.5281/zenodo.19008116) Paper 7: The Deformation Laws of Neural Identity (DOI: 10.5281/zenodo.19055966) Paper 8: What Counts as Proof? â Admissible Evidence for Neural Network Identity Claims (DOI: 10.5281/zenodo.19058540) Paper 9: Composable Model Identity â Formal Hardening of Structural Attestations in the Enterprise Identity Stack (DOI: 10.5281/zenodo.19099911) Paper 10:Where Identity Comes From: Path Sensitivity and Endpoint Underdetermination in Neural Network Training (DOI: 10.5281/zenodo.19118807) Paper 11: Post-Hoc Disclosure Is Not Runtime Proof: Model Identity at Frontier Scale (DOI: 10.5281/zenodo.19216634) Paper 12: Family-Dependent Response to Reasoning Distillation Across Structural and Functional Identity Layers (DOI: 10.5281/zenodo.19298857) Paper 13: Safety-Alignment Removal as a Model-Identity Failure â Structural Evidence from Published Weight-Level Mutation Checkpoints (DOI: 10.5281/zenodo.19383019) Technical Note: Agent Identity Is Not Model Identity (DOI: 10.5281/zenodo.19240883) Technical Note: Gap Invariance: Why PPP Measurements Are Domain-Independent by Construction (DOI: 10.5281/zenodo.19275524) Technical Note: Measured Model Substitution Under Valid Agent Credentials (DOI: 10.5281/zenodo.19342848) Technical Note: Artifact Identity Is Not Runtime Identity â Trustfall Lite and the Boundary of File-Level Model Verification (DOI: 10.5281/zenodo.20019127) Formal Verification Stack for Neural Network Structural Identity (IT-PUF Coq Proofs) (DOI: 10.5281/zenodo.18930621) Copyright (c) 2026 Anthony Ray Coslett / Fall Risk AI, LLC. All Rights Reserved. Confidential and Proprietary. Patent Pending (Applications 63/982,893, 63/990,487, 63/996,680, 64/003,244).
Open access
2 source records
Adversarial Robustness in Machine Learning
Physical Unclonable Functions (PUFs) and Hardware Security
About this paper This paper argues that the conflict between online protection and privacy is not inevitable. The real problem is that most current systems wrongly treat compliance and identity as the same thing. The proposed VI + CJT framework separates them. It allows platforms to receive only the minimum lawful compliance result they need â for example, whether a user falls below the relevant legal age threshold â without learning the childâs name, date of birth, address, biometric profile, or broader identity. In that sense, the paperâs central theme is age verification without surveillance through purpose-bound cryptographic enforcement. How AI Makes the Problem Worse AI makes the childrenâs online safety problem more serious in three distinct ways. First, it changes exposure from passive to active. Harmful material is no longer merely available on a platform; recommendation and optimisation systems can identify vulnerable users, rank harmful content more aggressively for them, and progressively amplify it based on engagement signals. In that environment, a child is not simply finding harmful content â the system is learning from the child and serving more of it. Second, AI makes weak age-verification methods more dangerous. A false self-declared age is no longer just a wrong entry in a sign-up form. Once accepted, it becomes operational input for recommendation, advertising, and behavioural optimisation systems, which then treat the child as an adult user profile. This means the error is not static; it is continuously acted upon by AI systems that optimise for attention and engagement rather than child protection. Third, AI encourages platforms to solve the problem through more surveillance. In practice, this often means AI-based age estimation using faces, voices, or behavioural patterns. But this approach creates a new harm while claiming to solve another one: it turns child protection into biometric and behavioural monitoring, and can generate datasets that may later be reused for additional profiling or model training. In other words, AI can make age assurance both more intrusive and less accountable. A further difficulty is that AI systems are often opaque even to their operators. As your draft correctly notes, policy rules alone may not be enough, because platforms may not reliably know how their own recommendation systems are treating minors in practice. This is why the problem is not only one of age verification, but also one of enforceable control over AI behaviour. That is precisely why the VI + CJT model matters. It does not ask AI systems to infer age or interpret law for themselves. Instead, it provides a minimal, authoritative compliance signal and machine-readable constraints that can limit recommendation, advertising, and profiling behaviour toward minors without exposing identity. Current Solutions Self-declaration is easily bypassed. A child can simply enter a false age, and the platformâs AI systems then treat that false declaration as valid input for recommendation, targeting, and optimisation. Identity-linked verification creates major privacy risks. When age assurance depends on sharing civil identity information with commercial platforms, the result is unnecessary exposure of family and child data to entities with strong incentives to collect, retain, and monetise it. AI-based age estimation introduces biometric surveillance. Estimating age from face, voice, or behaviour may appear convenient, but it creates new harms by collecting sensitive personal and biometric data as a side effect of child protection. Current systems collapse compliance into identity. What platforms usually need is not the full identity of the user, but only the legally relevant compliance fact. Existing approaches fail because they demand far more data than is necessary for that purpose. Policy rules alone are not enough in AI-driven environments. Even where legal obligations exist, platforms may not reliably translate them into enforceable constraints on opaque recommendation and engagement systems. As a result, compliance may remain declaratory rather than technically enforced. Proposed Solution Use VI + CJT as a purpose-bound cryptographic layer. The framework converts verified civil identity held by trusted authorities into a minimal compliance credential that reveals only the relevant age-threshold result for the applicable jurisdiction. Avoid disclosure of identity data. The credential contains no name, no full date of birth, no address, and no biometric data. Each credential uses a fresh random identifier, making it unlinkable across sessions. Keep the credential under user control. The credential is stored on the userâs device in secure hardware rather than on platform servers, reducing centralised exposure and retention risks. Use zero-knowledge proof for age compliance. When access is requested, the platform receives only a yes-or-no compliance result, without learning the underlying identity attributes or credential contents. Encode law into machine-readable CJTs. The Compliance Jurisdiction Token expresses the applicable legal rules, including jurisdiction-specific age thresholds and AI-related restrictions such as limits on engagement optimisation, advertising targeting, or behavioural profiling for minors. Constrain platform AI without making it identity-aware. Recommendation engines and other AI systems receive only the compliance signal necessary to adjust behaviour for minors, allowing them to become jurisdiction-aware and age-aware without becoming identity-aware. Replace probabilistic AI age estimation with authoritative attestation. Instead of guessing age through opaque models, the framework provides deterministic, government-signed, legally relevant compliance proof. Enable auditability and cross-border enforcement. Regulators can test whether platforms respond correctly to compliance signals, and the applicable child-protection rule can follow the user across borders through jurisdiction-bound credentials and tokens. Core Message The paperâs core message is simple: platforms do not need to know who a child is in order to know what protections the law requires. By separating compliance from identity, the VI + CJT model offers a path to child safety that is enforceable, privacy-preserving, and better suited to AI-driven digital environments.
AIGP-ÎŁ (AI Governance Protocol â Sigma) is a post-quantum cryptographic identity and authorization framework designed for autonomous AI agents operating in multi-agent and agentic payment environments. The protocol suite consists of five interconnected specifications: WP-01: Core Protocol â ML-DSA (CRYSTALS-Dilithium) based identity anchoring with STARK zero-knowledge proofs via RISC0, Bitcoin blockchain timestamping, and a cryptographic Kill Switch mechanism for emergency AI halt. WP-02: Kill Switch â Formal specification of the HALT proof system enabling verifiable, tamper-proof shutdown of AI agents without revealing operational state. WP-03: SSL for Agents â A mutual TLS-equivalent handshake protocol adapted for AI agent-to-agent communication, providing forward secrecy and post-quantum resistance. WP-04: Agentic Payments â Authorization layer for autonomous financial transactions executed by AI agents, with cryptographic scope limitation and audit trails. WP-05: Multi-Agent Orchestration â Trust propagation and delegation model for hierarchical multi-agent systems with verifiable credential chains.
Java applications are prone to vulnerabilities stemming from the insecure use of security-sensitive APIs, such as file operations enabling path traversal or deserialization routines allowing remote code execution. These sink APIs encode critical information for vulnerability discovery: the program-specific constraints required to reach them and the exploitation conditions necessary to trigger security flaws. Despite this, existing fuzzers largely overlook such vulnerability-specific knowledge, limiting their effectiveness. We present GONDAR, a sink-centric fuzzing framework that systematically leverages sink API semantics for targeted vulnerability discovery. GONDAR first identifies reachable and exploitable sink call sites through CWE-specific scanning combined with LLM-assisted static filtering. It then deploys two specialized agents that work collaboratively with a coverage-guided fuzzer: an exploration agent generates inputs to reach target call sites by iteratively solving path constraints, while an exploitation agent synthesizes proof-of-concept exploits by reasoning about and satisfying vulnerability-triggering conditions. The agents and fuzzer continuously exchange seeds and runtime feedback, complementing each other. We evaluated GONDAR on real-world Java benchmarks, where it discovers four times more vulnerabilities than Jazzer, the state-of-the-art Java fuzzer. Notably, an earlier GONDAR version contributed to Team Atlanta's first-place CRS in the DARPA AI Cyber Challenge, and is integrated into OSS-CRS, a sandbox project in The Linux Foundation's OpenSSF, to analyze open-source Java projects, where it has already uncovered a zero-day vulnerability.
We present a unified dynamical framework for the nontrivial zeros of the Riemann zeta function, integrating three perspectives: (i) the de BruijnâNewman flow and its reduction to a logarithmic Coulomb gas, (ii) a renormalization group information flow from the 2C Theory, and (iii) spectral compression in 2D Dirac systems under strong magnetic fields. Through an iterative discovery process â connecting existing knowledge, identifying new principles at the intersection, then connecting those principles with prior knowledge to discover deeper ones â we identify three structural contributions: (1) The DisorderâOrder Paradox: the irregularity of the prime distribution generates the information restoring force (curvature V''(1/2) = Ď²/8) that confines zeros to the critical line Re(s) = 1/2. (2) The Universal Irreversibility Threshold: the critical value C = 2/3, independently derived in D.S. Theory (holographic ratio β = 3/2), the 2C Theory (RG flow fixed point), and Lowest Landau Level physics (spectral weight threshold for forced Landauer erasure), marks the point at which one-dimensional spectral reduction becomes irreversible. (3) The Entropic Barrier: the information free energy V(Ď) possesses a barrier surrounding Ď = 1/2 whose height grows with integrated prime density, forbidding zero escape once the critical threshold is exceeded. We formulate one precisely stated open problem: proving that the entropic barrier height diverges as T â â, which is equivalent to establishing an L² + entropy â Lâ inequality for the equilibrium measure of the logarithmic gas. The framework connects analytic number theory, information theory, renormalization group methods, and condensed matter physics within a single coherent structure. This paper is a structural framework proposal, not a proof of the Riemann Hypothesis. The iterative discovery methodology is inspired by the WillCore simulation platform.
Prof. S. P. Palaskar, Swaraj Chikhale, Shantanu Chimote, Rakshit Sinha ¡ 6 authors
Abstractâ Traditional identity systems rely on centralized authorities, which creates single points of failure and privacy risks. We propose IDentix, a decentralized identity framework leveraging blockchain and cryptography to secure user credentials while preserving privacy. In IDentix, each user owns a self-sovereign identity (SSI) represented by a public/private key pair and a Decentralized Identifier (DID) registered on an Ethereum smart contract. Trusted issuers (e.g. governments, banks) provide verifiable credentials (VCs) to users off-chain, and users present cryptographic proofs (such as zero-knowledge proofs) of specific attributes to verifiers. Verifiers authenticate credentials by checking issuer signatures against public keys on the blockchain and querying an immutable credential registry. Our prototype on the Ethereum Sepolia testnet demonstrates that this design yields tamper-evident identity proofs without exposing personal data. As shown in prior work [1], blockchain-based SSI greatly reduces risks of identity theft while giving users full control over their data. Keywordsâ Blockchain; decentralized identity; self-sovereign identity; verifiable credentials; decentralized identifiers; identity verification; Ethereum; zero-knowledge proof.
This study presents ZK-EHR, a decentralized access control framework designed to enable secure and privacy-preserving sharing of encrypted electronic health records across institutional boundaries. Unlike existing blockchain-based EHR access control systems that expose user identities on-chain or lack cryptographic privacy guarantees, ZK-EHR decouples authorization from identity disclosure by integrating zk-SNARK-based proofs with blockchain smart contracts to verify policy compliance without revealing user roles, affiliations, or credentials. The framework employs three differentiated actor rolesâPatient (Data Owner), Doctor (Care Provider), and Researcher (Authorized Analyst)âwith distinct policy-driven access workflows, a custom Groth16 zero-knowledge circuit for role-based constraint enforcement, and a modular architecture combining on-chain verification with off-chain encrypted storage via IPFS. Concrete design proposals for access revocation and replay attack prevention are introduced to address operational security requirements. The system was evaluated under multiple operational and adversarial scenarios. Experimental results indicate consistent on-chain verification latency (approximately 390 ms), reliable rejection of tampered submissions, and per-verification gas consumption of 216,631 gas. A comparative analysis against representative baseline systems demonstrates that ZK-EHR uniquely combines identity anonymity, on-chain cryptographic policy enforcement, and auditable encrypted record retrieval. These findings establish the feasibility of zk-SNARK-based access control for decentralized, verifiable, and privacy-aware EHR management.
Margherita Cozzolino, Stephan Krenn, Thomas LorĂźnser
While QKD ensures information-theoretic security at the link level, real-world deployments depend on trusted repeaters, creating potential vulnerabilities. In this paper, we thus introduce a topology-hiding connectivity assurance protocol to enhance trust in quantum key distribution (QKD) network infrastructures. Our protocol allows network providers to jointly prove the existence of a secure connection between endpoints without revealing internal topology details. By extending graph-signature techniques to support multi-graphs and hidden endpoints, we enable zero-knowledge proofs of connectivity that ensure both soundness and topology hiding. We further discuss how our approach can certify, e.g., multiple disjoint paths, supporting multi-path QKD scenarios. This work bridges cryptographic assurance methods with the operational requirements of QKD networks, promoting verifiable and privacy-preserving inter-network connectivity.