空交集:溯源覆盖率升至98%且两项验证决策均未改变
Empty Intersection: Provenance Coverage Rose to 98% and Neither Verification Decision Moved
AI总结:
本研究测量了溯源的两项结构性防御措施,发现其虽提升覆盖率至98.4%并拒绝3,070次写入,但因修复行与决策读取行无交集,两项验证决策均未改变。
AI中文摘要:
针对溯源的两项结构性防御措施——对每一行进行分级,使验证程序不会将系统自身的输出误认为观测结果;以及单一写入入口,使分级得到强制执行而非仅具约定性——在促使这些措施产生的生产部署上进行了测量,测量基于194,620行的冻结快照以及该快照支持的两项验证决策。两项措施均未达成任一决策。这两项措施均由一篇配套论文提出,该论文诊断了该部署:其验证程序使用系统自身写入的值来决定结果。这两项建议均非新创:它们都是互不引用的领域中的既有实践,且未发现先前工作测量过任一措施是否改变裁决,因此此处提供的是测量结果而非建议。按分级过滤验证查询将两项决策从通过变为未确定;扩大分级词汇表将分类覆盖率从36.1%提升至98.4%;要求分级的单一入口拒绝了3,070次写入。三项措施均未为任一决策提供可接受的输入。这些建议在其指定范围内并未失效。每项建议均针对总体陈述,且不涉及任何决策,因此均未指明决策将读取哪些行,而每项干预所修复的行与决策读取的32行并无交集。改变行数最多的干预最清晰地展示了其影响范围:其从不可命名移至可命名的全部121,296行均落在两个查询窗口之外。本文报告了在测量而非设计条件下,决策拥有可接受输入所需的条件,并指出这两项决策因不同原因而受阻。
英文摘要:
Two structural defenses for provenance, a grade on every row, so that a verification routine cannot mistake the system's own output for an observation, and a single write ingress, so that the grade is enforced rather than merely conventional, were measured against the production deployment that motivated them, over a frozen snapshot of 194,620 rows and the two verification decisions the snapshot supports. Neither reaches either decision. Both were prescribed by a companion paper, which diagnosed that deployment: its verification routines decided outcomes using values the system itself had written. Neither prescription is new: both are established practice in fields that do not cite one another, and no prior work measuring whether either changes a verdict was found, so what is offered here is the measurement and not the prescriptions. Filtering the verification queries by grade turns both decisions from pass to undetermined; widening the grade vocabulary raises classified coverage from 36.1% to 98.4%; a single ingress requiring a grade refuses 3,070 writes. None of the three gives either decision admissible input. The prescriptions do not fail at what they specify. Each is stated over the population and makes no reference to any decision, so neither says which rows a decision will read, and the rows each intervention repairs and the 32 rows the decisions read do not intersect. The intervention that changed the most rows shows the reach most plainly: all 121,296 rows it moved from unnameable to named fall outside both query windows. This paper reports the conditions, measured rather than designed, under which the decisions would have admissible input at all, and notes that the two decisions are blocked for different reasons.