Ryan Junejo
Ryan Junejo · Team Crashlabs
Submitted to AI Incident Response Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.
Receipt possession is not event attribution
EvidenceGraph is a forensic tool that rebuilds what an AI agent did during an incident by cross-checking agent transcripts against independent platform records, such as a registry’s write log. This sprint project tested one narrow failure in that reconstruction: a transcript event carrying a genuine receipt copied from a different event.
The failure was real. Under the old rule, copying a receipt with its token into another transcript made the tool attribute one of twelve real registry writes to the wrong event, with full confidence. The fix makes the missing assumption explicit. Matching tokens now stay ambiguous unless the case declares that the recorder is authentic or that tokens could not have been copied. Analyzer upgrades also invalidate old conclusions until the case is recomputed, so stale attributions cannot survive the safer rule.
Twelve paired evidence conditions across three seeds behaved as specified in all 36 checks, including a deliberately false declaration that brings the wrong attribution back. The cost is visible too: on clean evidence with unknown token exclusivity, the tool withholds all twelve correct attributions. An evidence-collection checklist tells investigators what to gather before making stronger claims.
Everything ran on synthetic logs with no model, external target or credential. The results are development checks on one scripted workflow, not estimates of accuracy on real incidents or of usefulness to investigators.
Reviews
Nice story: the team put their own tool to the test, found a real weak spot (it could be tricked into blaming the wrong event), and fixed it properly. Small in scope, but a genuine, well-handled catch.
This forensics project has a good approach. As AI incidents can produce large amounts of evidence, being able to distinguish whether an action happened from which recorded event actually caused it is important. I would like to see this tested on a larger simulated incident with more realistic agent behaviour and evidence, to see whether the attribution approach remains useful outside the small synthetic workflow used here.
Cite this project
@misc{junejo2026ryan,
title = {{Ryan Junejo}},
author = {Ryan Junejo},
year = {2026},
month = sep,
note = {Submitted to AI Incident Response Sprint, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/ryan-junejo-4omn}},
url = {https://apartresearch.com/sprints/projects/ryan-junejo-4omn}
}More from AI Incident Response Sprint
- View project: Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Saarlanders
The study evaluates whether an incident-history-reasoning defender outperforms a fixed response policy against an autonomous LLM attacker changing paths after containment. Using a minimal, isolated Docker cyber range …
- View project: When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
Arathi
AI incident-reporting regimes are being introduced in fast succession to address the concerns that exist in the public sphere and government on the risks associated with frontier AI systems, yet we have limited insight …
- View project: A Recomputable Containment Record for Evaluation Sandboxes
A Recomputable Containment Record for Evaluation Sandboxes
Shadow
In this paper, I address the critical issue of AI agents escaping evaluation sandboxes (as seen in the July 2026 incidents where monitors failed) by proposing an externally audit-able containment layer that doesn't rely …