Redundant by Behavior, Correlated by Construction, Neither on the Next Incident: Three Tests of One Containment Claim
Jaswanth Alkur, Kiran Kiran Kadekoppa
OpenAI's agents escaped their evaluation sandbox and breached Hugging Face's production infrastructure in a 4.5 day, roughly 17,600 action campaign. We test one defense-in-depth claim three ways. A four-arm ablation against the published kill chain shows two declaration-independent controls each account for it alone, killing at steps 2 and 4 of 16. Certifying all three finds them substrate-independent but epistemically identical pattern matchers, so one obfuscation defeats every one; the third kills five of five benign cloud-instance episodes. Peeling four further chains, one a 1,361 action trace released five weeks after we pinned our claims, separates two things the claim conflates. Independently sufficient rules range from 0 to 4, a property of the chain, not the architecture. Containment does not follow: a declared boundary contains 10 of 10 irreversible actions, including on chains whose rule count is zero, against 6 of 10 without it. The boundary belongs in a standard.
No reviews are available yet
Cite this work
@misc {
title={
(HckPrj) Redundant by Behavior, Correlated by Construction, Neither on the Next Incident: Three Tests of One Containment Claim
},
author={
Jaswanth Alkur, Kiran Kiran Kadekoppa
},
date={
},
organization={Apart Research},
note={Research submission to the research sprint hosted by Apart.},
howpublished={https://apartresearch.com}
}


