AI-Adversary Research

When the adversary learns, authorization must withstand it.

SΛDB researches how to contain adaptive agents without allowing speed, repetition, or tampering to bypass the decision boundary.

The question

Can adaptation be contained without weakening authorization?

The laboratory separates the agent, sensors, and enforcement point. The agent receives no access to control; only evidence-bound authorization can reach the actuator.

Adaptive

A learning attack policy

The agent selects actions through a restricted API and updates its policy according to the observed outcome.

Independent

Sensors outside the boundary

Independent predicates must agree before evidence is considered sufficient.

Governed

SΛDB as the mandatory path

Capability, durable receipt, tenant, correlation, evidence hash, action, and scope remain bound together.

Containment path

From evidence to verifiable enforcement.

The architecture tests not only time, but also the inability to reuse or alter a valid authorization.

Observe

Independent sensors record the agent's behavior.

Correlate

Sufficient evidence is bound to the same execution.

Authorize

A bounded capability produces a durable receipt.

Validate

Enforcement verifies proof, hash, scope, and replay.

Contain

The resident actuator stops only the authorized target.

Preserved official result

Lower impact with governed resident containment.

Run sadb-ai-v22-official-20260915-002, executed in a controlled local environment with three paired conditions.

Resident containment median48.0192 msFrom evidence onset to containment in the laboratory.
Resident impact median1 unitCompared with 60 units under the uncontained condition.
Integrity0 failuresReplay was blocked in every governed condition.
Protocol: 20 warmups per condition, 100 measurements per condition, 300 total measurements, 100 paired triplets, seed 20260914, 10,000 bootstrap replicates, and no outlier removal. The result is not a production SLA and does not demonstrate containment of an LLM or a real attack.

Evaluated invariants

Resistance before speed.

The experiment seeks to preserve properties that cannot be sacrificed to reduce latency.

Fail-closed

Missing, divergent, or tampered proof cannot reach enforcement.

Replay protection

An authorization that has already been used cannot produce a second effect.

Bounded authority

Authorization is limited to the corresponding tenant, correlation, action, target, and evidence.

Durable receipt

Authorized intent is recorded before the command is issued to the actuator.

Operational separation

Public transparency without exposing the laboratory.

The site presents methodology, boundaries, and aggregate results. Topology, images, keys, operational seeds, endpoints, capabilities, receipts, per-trial telemetry, and execution controls remain private.

Research and collaboration

Evaluate adaptive-agent governance with auditable evidence.

Talk with SΛDB about defensive research, isolated environments, and authorization systems for automated actions.