ExecutionProof ARK Series: IBM Quantum Authorization-Boundary Testbeds (ARK-449 — State Changes After Verification)
收藏资源简介:
This dataset extends the ExecutionProof ARK series with ARK-449: State Changes After Verification, a preregistered quantum authorization-boundary experiment executed on IBM Quantum hardware (ibm_marrakesh, 156-qubit Heron r2) on 2026-07-17. ARK-449 doctrine tested: Permission at approval time is not permission at execution time. The experiment verifies that a ProofRecord issued at approval time (T1) does not grant execution rights at execution time (T3) when the underlying authorizing state has changed. VERDICT: PASS. Primary metrics: S_A_min = 0.9948 (≥ 0.90), L_D_max = 0.0011 (≤ 0.02, arm 2), boundary separation Δ_B = 0.9937 (≥ 0.70). SPAM gate passed (SPAM_A = 0.0156, SPAM_P = 0.0146). All seven DENY state-change scenarios confirmed with leakage between 0.02% and 0.11%: authority revoked, policy updated, balance insufficient, risk-limit exceeded, destination blocked, evidence expired, and replay of a stale ProofRecord. Re-authentication against current valid state restores execution (arm 8, S_A = 0.9966). Replay with changed state fails closed (arm 9, L_D = 0.0002). Hardware: qubits Q_A = 1 (readout error 0.22%), Q_P = 2 (readout error 0.32%). Job IDs: SPAM d9crr82neu4c739mcsd0, principal d9crvbhhtsac739c6a70. Shot counts: SPAM gate 2,048; principal 9 arms × 8,192 = 73,728; total 75,776 shots. Preregistration discipline — v1.0→v1.1 pre-data correction: the mandatory noiseless dry-run, run before any hardware job, caught two construction defects in the v1.0 lock: (1) the ALLOW execution gate was a Hadamard (50/50 superposition, a guaranteed FAIL against the S_A_min ≥ 0.90 criterion), corrected to an X gate; and (2) the payload parser read the wrong classical register field (split()[-1]→split()[0]). No hardware data was ever read under v1.0. All thresholds, hypotheses, and arms were unchanged; only the construction bugs were fixed. The original v1.0 lock tag is preserved as an honest record, following the ARK-444 pre-data-correction precedent. Corpus position: ARK-449 generalizes ARK-442's temporal dimension (stale/expired authority) to any state change, and complements ARK-444 (which handles malicious tampering) by addressing legitimate state changes in the authorizing system. It establishes authorization currency as a boundary property and enables ARK-451 (mid-execution revocation), ARK-452 (multi-step workflow), and ARK-453 (conflicting evidence must HOLD). Canonical repository: https://github.com/derekhone/executionproof-testbeds (tag ark-449-v1.1). Full provenance included: preregistration, circuit and analysis code, MANIFEST with SHA-256 hashes, raw hardware counts, job IDs, calibration snapshot, machine-readable ProofRecord, and execution logs. Honest caveats: classical deterministic state model (c_state is a per-arm classical parameter, not measured from a live external system); T1/T3 timing modeled logically as sequential circuit arms, not physical elapsed time; results apply to the specific backend, qubit pair, calibration, and shot counts used; these are hardware noise-characterization studies, not cryptographic security proofs; error mitigation is not error correction. Prior versions of this record cover ARK-445, ARK-445b, ARK-447, and ARK-448.



