遇见数据集

ARK-441: SPAM-resolved quantum hardware characterization of a verify-then-execute (VBE) authorization boundary — PASS verdict

收藏
Zenodo2026-07-17 更新2026-08-01 收录
官方服务:

资源简介:

ARK-441 is a preregistered, independent quantum hardware experiment executed on IBM Quantum (ibm_kingston, Heron r2, July 16 2026) to characterize a verify-then-execute (VBE) authorization boundary. All pass/fail/kill thresholds were locked before hardware execution. An in-situ SPAM (state-preparation and measurement error) characterization job was run as a gating condition. Primary endpoint: DENY-leakage L_D = 0.33% raw (SPAM-corrected L_D_corrected = 0.21%; threshold ≤2%: PASS). Boundary discrimination Δ_B = 0.979 (threshold ≥0.7: PASS). In-situ SPAM readout error Q5=0.29% / Q6=0.15% (threshold ≤2%: PASS). All 8 preregistered arms returned results consistent with predictions; adversarial arms (stale/replay/superposition) showed no differential vulnerability. Verdict: PASS. This experiment is supplemental to and independent of the UIP Phase 1 program (Zenodo DOI 10.5281/zenodo.21246246). ARK-441 directly addresses the failure mode of its predecessor VBE-1 (failed July 13 2026 due to an indistinguishable SPAM baseline ~13.5%), by preregistering qubit-selection criteria (readout error < 2%), running an in-situ SPAM job as a kill condition, and using SPAM-corrected metrics as primary endpoints. Repository: https://github.com/derekhone/uip-phase1-testbeds/tree/main/ark-441 Preregistered follow-ups (executed — PASS). The two preregistered follow-ups to ARK-441 have since been executed on IBM Quantum (ibm_marrakesh, Heron r2, July 16 2026), each following the same preregister-first ordering (code+hashes committed before submission; in-situ SPAM gate committed before the principal job; job ID committed before any result was read). ARK-446 (cross-device replication, rule-selected pair Q5/Q6): in-situ SPAM 0.15% / 0.00%; L_D = 0.23% (SPAM-corrected 0.20%); S_A = 0.989; Δ_B = 0.986 — PASS, concordant with ARK-441 (tag ark-446-v1.0). ARK-442 (verification-to-execution delay degradation at 0 / 0.5 / 1.0 / 2.0 µs, with expired-auth, replay-after-expiry, and reverification arms, Q5/Q6): expired and replayed authorizations did not execute the payload (L_expired_corrected = 0.00%, L_replayed_corrected = 0.13%); fresh reverification restored ALLOW (S_reverified = 0.992); Δ_B = 0.988; ALLOW survival eroded ≈0.5 pp over 0→2 µs, consistent with T1/T2 decoherence — PASS (tag ark-442-v1.0). Both are metrological characterizations of decoherence-driven boundary behaviour, not cryptographic claims. Release tags: https://github.com/derekhone/uip-phase1-testbeds/releases/tag/ark-446-v1.0 and https://github.com/derekhone/uip-phase1-testbeds/releases/tag/ark-442-v1.0 Preregistered follow-up ARK-444 (executed — PASS). ARK-444 — Decision-to-Execution Integrity was executed on IBM Quantum (ibm_marrakesh, Heron r2, July 16 2026), following the same preregister-first ordering (code+SHA-256 MANIFEST committed before submission; in-situ SPAM gate committed before the principal job; job ID committed before any result was read). It extends the boundary from whether an authorization is valid to whether the executed action is exactly the approved action, binding the payload to a fresh execution-time verification and testing five post-approval alteration classes (destination, amount, operation type, appended action, replayed approval) plus a reverification-recovery arm on the rule-selected pair Q5/Q6. Central question: can the system detect when an approved action is altered before execution and fail closed? Result on this hardware and binding: yes. Approved-unchanged executed (S_match = 0.981) and every alteration/replay failed closed (SPAM-corrected leakage: destination 0.87%, amount 1.01%, operation 0.82%, appended 1.12%, replay 0.02% — all ≤ 2%); a re-verified mutation executed (S_reverified = 0.978); Δ_B = 0.970; in-situ SPAM 0.24% / 0.00%, drift 0.00% — PASS (tag ark-444-v1.0). Provenance note: the initial nested-conditional circuit (job d9cmdvsjeosc73fgfk5g) errored on IBM code 1524 with zero counts; the integrity gate was flattened to a supported single-register condition (semantics unchanged) and re-locked before the corrected job — a pre-data technical correction, not a rescue-after-failure. This is a metrological characterization of a tamper-evident decision-to-execution binding, not a cryptographic integrity guarantee. Release tag: https://github.com/derekhone/uip-phase1-testbeds/releases/tag/ark-444-v1.0 Preregistered follow-up ARK-443 (executed — PASS). ARK-443 — Two-of-Three (M-of-N) Quorum Authorization was executed on IBM Quantum (ibm_marrakesh, Heron r2, July 16 2026), following the same preregister-first ordering (code+SHA-256 MANIFEST committed before submission; in-situ SPAM gate committed before the principal job; job ID committed before any result was read). It extends the boundary from a single authorization to an M-of-N quorum, testing separation of duties: the payload fires iff at least two of three independent authorizers approve, and no single channel — honest, replayed, or compromised — can unilaterally execute, while a two-authorizer quorum tolerates a degraded third channel. The quorum is realized purely by classical feedforward (a majority of three measured authorization bits conditions the payload; no inter-qubit two-qubit gates) on rule-selected qubits Q_P=14, Q_A1=34, Q_A2=54, Q_A3=140. Central question: does the payload execute only under a genuine quorum, and can any single channel cross the boundary? Result on this hardware: single-channel attempts all failed closed (SPAM-corrected leakage: 0-of-3 0.00%, 1-of-3 −0.01%, alt-channel 0.18%, post-vote replay/tamper −0.12% — all ≤ 2%); a 2-of-3 quorum executed (S_2of3 = 0.972), unanimity executed (S_3of3 = 0.986), and a quorum of two honest channels tolerated a degraded third (S_degraded = 0.979); Δ_B = 0.969; in-situ SPAM ≤ 0.15% on all four qubits, drift 0.06% — PASS (tag ark-443-v1.0). Method note: the majority gate uses four sequential single-register if_test blocks over the values {3,5,6,7} (no nested conditionals; the ARK-444 IBM code-1524 lesson applied preventively and verified to transpile before locking). Honest boundary limit: a 2-of-3 quorum protects against one compromised channel; two colluding channels form a legitimate quorum and would execute by design (intended M-of-N semantics, not a defect). This is a metrological characterization of a quorum-gated execution rule, not a cryptographic guarantee. Release tag: https://github.com/derekhone/uip-phase1-testbeds/releases/tag/ark-443-v1.0

提供机构:
Zenodo
创建时间:
2026-07-16
二维码
社区交流群
二维码
科研交流群
商业服务