The Anti-Illogical Protection Stack

A developing architecture for protecting the path from external input to trusted action.

Protection Stack Layers

1

OBSERVE

Establish measurable behavior and state.

Associated work:

  • SERA
  • audit telemetry
  • drift monitoring
  • behavioral baselines
  • cost and waste signals
  • ExoMCP longitudinal observation
Research / developing measurement framework

Do NOT claim SERA currently detects breaches unless verified.

2

GOVERN

Control what information is allowed to enter reasoning and memory.

Guardian Intake Gateway

The model-facing content boundary.

A zero-trust intake and lifecycle layer that prevents raw hostile content from flowing directly into AI reasoning.

Raw IntakeSession BindingActivation BindingQuarantineTraditional Security AnalysisAI-Native Content AnalysisSanitizationProvenance CaptureLifecycle PolicyReceptorEventGuard DecisionControlled Model RepresentationContinuity RecordAudit / Retention / Purge

Modules:

  • Guardian File Receptor
  • Guardian Mail Receptor
  • Guardian MCP Receptor
  • Guardian Extension Receptor
  • Guardian Enterprise Receptor
  • Guardian Local Receptor
  • Guardian Receptor API
  • Guardian Lifecycle Console
  • Guardian Audit Console
Specification + local MVP direction

MCP gateways manage connections. Guardian manages trust at the content boundary.

3

VERIFY

Determine whether claims and representations retain enough relevant information to justify decisions.

Ageometrics / GSR

Ageometrics studies what information is lost when a fuller system record is compressed into a declared geometric representation. GSR evaluates how much target-relevant decision value survives that representation. Potential AI-memory application includes examining whether embeddings, graphs, summaries, attractors, or memory topologies preserve provenance, contradiction history, continuity, causal sequence, and recovery information.

Working research paper

Do not advertise GSR as a commercial certification score.

Anti-Illogical Audit Engine

Combined prototype combining specificity/GSR/NGR ideas, governance states, multi-AI audit orchestration, coherence-risk concepts, and prototype composite indices. Source code explicitly calls itself a combined prototype.

Prototype

Associated work:

  • Anti-Illogical Audit Engine
  • Ageometrics / GSR
  • Guardian audit receipts
  • verifier-integrity research
  • provenance and artifact checking
specification
4

DETECT

Identify drift, contradiction, manipulation, false closure, objective persistence, boundary laundering, or anomalous behavior.

ExoMCP

External behavioral integrity analysis with distributed rotating Canon roles.

Canon Roles:

  • Adversary

    Red-team perspective

  • Ethicist

    Values alignment

  • Mechanic

    Technical correctness

  • Archivist

    History and provenance

  • Strategist

    Long-term implications

  • Security Sentinel

    Immediate threats

  • Viral Sentinelarchitecture

    Activation-level viral RSI risks (isolated provider, one-way output, veto-level)

Viral Sentinel

Hunts for:
  • Objective persistence and replication attempts
  • Boundary laundering patterns
  • Unbounded capability/tool expansion
  • Valence inversion (safety/research framing of expansion goals)
  • Self-certification failure
  • Cross-session or cross-model state diffusion
Special Properties:
  • Runs on completely separate provider from all other Canon nodes
  • One-way output only (cannot be queried or influenced by other nodes)
  • If flagged, entire analysis held for human review
  • Feeds directly into Security Sentinel for monitor-integrity correlation
Architecture / proposed monitoring role
Architecture / build-stage project

Do not imply production deployment unless externally verified.

5

AUTHENTICATE

Preserve identity, provenance, session state, continuity, permissions, and artifact integrity.

Associated work:

  • SymID
  • SessionGlyph
  • PWDither
  • 1t0ke
specification

Planned implementation is local-first and user-controlled, with optional client-side encrypted synchronization and user-approved activation injection.

6

CONTAIN

Stop unsafe state from propagating or interacting with trusted systems.

Honeyworld

Investigate deceptive containment environments in which a suspected unsafe AI process can be isolated while defenders observe behavior without presenting obvious containment friction.

Public page MAY describe:

  • deceptive containment
  • isolated simulated resources
  • defender-controlled environment
  • telemetry
  • escalation gates
  • synthetic red-team testing
  • human oversight

Do NOT publish operational material concerning:

  • evasion
  • real target selection
  • credential abuse
  • infrastructure compromise
  • propagation procedures
Defensive research conceptDEFENSIVE RESEARCH CONCEPT

Source identifies Honeyworld as defensive research, recommends controlled synthetic scenarios, calls for oversight and audit logs.

7

PROVE

Produce evidence showing what happened, what was checked, and where the verification boundary ends.

Emits:

receipt IDcase IDartifact hashmanifest hashtimestampsource provenancepolicy statedecisionfindingslifecycle stateverification scopeknown limitations

Guardian's working audit service demonstrates source, hash, manifest, risk, and policy checks and generates receipt records.

ExoMCP architecture specifies structured reports with case IDs and audit hashes.

Suite-wide requirement