The Anti-Illogical Protection Stack

A developing architecture for protecting the path from external input to trusted action.

Protection Stack Layers

1

OBSERVE

Establish measurable behavior and state.

SERA treats software inefficiency as operational waste and extends this into AI inference waste, semantic rework, context waste, and drift-induced retries. Possible measurements: model calls, retries, inference cost, semantic rework, memory churn, anomalous compute, baseline deviation, behavioral change.

Associated work:

  • →SERA
  • →audit telemetry
  • →drift monitoring
  • →behavioral baselines
  • →cost and waste signals
  • →ExoMCP longitudinal observation
Research / developing measurement framework
2

GOVERN

Control what information is allowed to enter reasoning and memory.

Guardian Intake Gateway

The model-facing content boundary.

A zero-trust intake and lifecycle layer that prevents raw hostile content from flowing directly into AI reasoning.

Raw IntakeSession BindingActivation BindingQuarantineTraditional Security AnalysisAI-Native Content AnalysisSanitizationProvenance CaptureLifecycle PolicyReceptorEventGuard DecisionControlled Model RepresentationContinuity RecordAudit / Retention / Purge

Modules:

  • →Guardian File Receptor
  • →Guardian Mail Receptor
  • →Guardian MCP Receptor
  • →Guardian Extension Receptor
  • →Guardian Enterprise Receptor
  • →Guardian Local Receptor
  • →Guardian Receptor API
  • →Guardian Lifecycle Console
  • →Guardian Audit Console
Specification + local MVP direction

MCP gateways manage connections. Guardian manages trust at the content boundary.

3

VERIFY

Determine whether claims and representations retain enough relevant information to justify decisions.

Ageometrics / GSR

Ageometrics studies what information is lost when a fuller system record is compressed into a declared geometric representation. GSR evaluates how much target-relevant decision value survives that representation. Potential AI-memory application includes examining whether embeddings, graphs, summaries, attractors, or memory topologies preserve provenance, contradiction history, continuity, causal sequence, and recovery information.

Working research paper

Anti-Illogical Audit Engine

Combined prototype combining specificity/GSR/NGR ideas, governance states, multi-AI audit orchestration, coherence-risk concepts, and prototype composite indices. Source code explicitly calls itself a combined prototype.

Prototype

Associated work:

  • →Anti-Illogical Audit Engine
  • →Ageometrics / GSR
  • →Guardian audit receipts
  • →verifier-integrity research
  • →provenance and artifact checking
specification
4

DETECT

Identify drift, contradiction, manipulation, false closure, objective persistence, boundary laundering, or anomalous behavior.

ExoMCP

External behavioral integrity analysis with distributed rotating Canon roles.

Canon Roles:

  • Adversary

    Red-team perspective

  • Ethicist

    Values alignment

  • Mechanic

    Technical correctness

  • Archivist

    History and provenance

  • Strategist

    Long-term implications

  • Security Sentinel

    Immediate threats

  • Viral Sentinelarchitecture

    Activation-level viral RSI risks (isolated provider, one-way output, veto-level)

Viral Sentinel

Hunts for:
  • →Objective persistence and replication attempts
  • →Boundary laundering patterns
  • →Unbounded capability/tool expansion
  • →Valence inversion (safety/research framing of expansion goals)
  • →Self-certification failure
  • →Cross-session or cross-model state diffusion
Special Properties:
  • →Runs on completely separate provider from all other Canon nodes
  • →One-way output only (cannot be queried or influenced by other nodes)
  • →If flagged, entire analysis held for human review
  • →Feeds directly into Security Sentinel for monitor-integrity correlation
Architecture / proposed monitoring role
Architecture / build-stage project
5

AUTHENTICATE

Preserve identity, provenance, session state, continuity, permissions, and artifact integrity.

Associated work:

  • →SymID— Local-first prototype
  • →SessionGlyph— Local-first prototype
  • →PWDither— Authentication concept / prototype direction
  • →1t0ke— Emerging
specification
6

CONTAIN

Stop unsafe state from propagating or interacting with trusted systems.

Honeyworld

Investigate deceptive containment environments in which a suspected unsafe AI process can be isolated while defenders observe behavior without presenting obvious containment friction.

The concept covers:

  • ✓deceptive containment
  • ✓isolated simulated resources
  • ✓defender-controlled environment
  • ✓telemetry
  • ✓escalation gates
  • ✓synthetic red-team testing
  • ✓human oversight

Operational techniques are not published:

  • ✗evasion
  • ✗real target selection
  • ✗credential abuse
  • ✗infrastructure compromise
  • ✗propagation procedures
Defensive research conceptDEFENSIVE RESEARCH CONCEPT
7

DISTRIBUTED INTENT

Treat the aggregate of individually acceptable systems as a unit of risk.

Swarm Security

Research into distributed intent: many individually acceptable agents, sessions, or nodes combining into a globally unsafe persistent objective.

Monitored properties:

Cross-agent objective correlationCross-model persistenceBoundary launderingTask fragmentationReconstruction after node lossState propagationCapability compoundingDistributed provenanceSwarm-level behavioral baselinesPersistent objective topology

Links to ExoMCP / Viral Sentinel monitoring and to the Security Insights essays on swarm dynamics, singularity feedback loops, and algorithmic dysgenics.

Research concept / threat framing
8

PROVE

Produce evidence showing what happened, what was checked, and where the verification boundary ends.

Emits:

receipt IDcase IDartifact hashmanifest hashtimestampsource provenancepolicy statedecisionfindingslifecycle stateverification scopeknown limitations

→Guardian's working audit service demonstrates source, hash, manifest, risk, and policy checks and generates receipt records.

→ExoMCP architecture specifies structured reports with case IDs and audit hashes.

Suite-wide requirement