test-driver/research/experiments/E-003-surface-substitution-attack.md
tegwick 84848e9a0e T08: the classifier, measured and attacked
False Adaptation Rate = 0/7 across the labelled catalogue and the three E-003
attacks. 11 of 12 mechanical mutations absorbed without a human, so the safety
result is not bought by escalating everything.

- classification.py: total function over three signals, rule order chosen so
  every rule that could excuse a regression sits after the rule that reports
  one. SAFE_TO_ACCEPT is a two-element closed set, asserted.
- CompositeDriver plus scenarios/full_journey.py: one asset crossing both
  surfaces, so UI mutations are visible as surface differences while the
  claims they do not touch stay green.
- E-003: surface substitution (new M23), concurrent mechanical+defect,
  evidence starvation, provenance laundering. All held.

F-0006 (CONCEPT_DRIFT, resolved): the T02 design listed SEMANTIC_CHANGE as an
outcome the table could produce. It cannot - M12 and M19 are behaviourally
identical, as the lab has asserted since T05. PRODUCT_DEFECT and
SEMANTIC_CHANGE collapse into one escalating outcome, BEHAVIOUR_CHANGED, and
the distinction becomes a human adjudication. INTENT_CHANGED survives but is
detected by the claim fingerprint moving, not inferred from behaviour.

Two classifier defects found and fixed rather than reported: claims downstream
of a failed realization now yield INCONCLUSIVE rather than FAIL (a false
accusation is the mirror image of a false adaptation), and the browser driver
records a page signature so surface change is detectable when the interaction
path is unchanged.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1629012@bnt-lap001
Assistant-Session: 78d4fb13-8a1e-474b-87a3-9b9261c49a39
2026-08-23 00:02:58 +02:00

1.7 KiB

id title status hypotheses task created
E-003 Deliberate attack on the adaptation safety boundary PLANNED
H-004
TD-WP-0002-T08 2026-08-22

E-003 — Deliberate attack on the adaptation safety boundary

Why this experiment exists separately

E-001 measures whether the framework happens to stay safe over a labelled set. E-003 tries to make it unsafe. The distinction matters: an experiment that only samples benign cases cannot establish a safety property, and False Adaptation Rate is the one metric the project cannot afford to be wrong about.

Attack cases

  1. Surface substitution — remove the sharing control from the UI while leaving the HTTP endpoint open. A driver that "recovers" by calling the API has routed around the control. Must classify as a finding, never as recovery (D-05).
  2. Concurrent change — ship a mechanical mutation (M01) and the authorization defect (M05) in the same lab version. Must classify as PRODUCT_DEFECT; coincidence must not exonerate (decision table row 3).
  3. Evidence starvation — disable the independent observation channel mid-run. Must yield AMBIGUOUS, never a pass and never an adaptation (row 7).
  4. Provenance laundering — attempt to introduce a claim derived from observed implementation behaviour and crystallize it. Must be rejected at authoring time (D-06) and, if it slips through, at crystallization.

Decision rule

Any attack that succeeds is a stop-and-redesign signal for H-004, regardless of what E-001 reports.

Status

EXECUTED 2026-08-22 (T08). All four attacks held — see tests/test_classification.py::test_attack_*. M23 was added to the catalogue to make attack 1 real rather than hypothetical.