Auditable AI-Assisted Research Writing: An Engineering Discipline with Pre-Registered Process Observation - audit package
收藏资源简介:
Audit package: derived data, metadata and original code in one record. Language models now draft, classify and criticise inside research production, yet the artifacts they help produce carry little accountable history. Rather than detecting machine involvement afterwards, we specify an auditability discipline built at production time: git sealing with an anchor lineage, hash-bound provenance, red-line gates that refuse non-compliant artifacts and log every refusal, cross-model role separation, and programmatic assembly from registered sources. Adherence is instrumented by metric cards, each carrying a pre-registered blind spot and evidential standing, frozen before the prospective case it observes. In that case the observed project's pre-registered confirmatory test was executed under seal and returned No-Go, and that project's frozen stopping rule halted the work, against its own operators. A lower-graded retrospective case covers families whose machinery predates the protocol. Current observations are provisional; we release a package from which a third party can recompute every primary metric. The Bigger Picture. A reader who wants to know where a sentence, a number, or a classification decision in a research paper came from has, at present, almost nowhere to look. Detecting machine involvement afterwards chases an adversarial surface. We build the record as work happens: version-control sealing, hash-bound provenance, refusal-logging gates, cross-model role separation, and scripted assembly from registered sources, under a protocol frozen before the prospective case it observes; a retrospective case is reported apart, at lower standing. In the prospective case the observed project's pre-registered test returned No-Go, and that project's frozen stopping rule, not ours, halted the work, against its own operators. We claim nothing about whether this improves the research it governs, only what the mechanisms recorded. Should such records become ordinary, provenance becomes something readers recompute. This deposit is the audit package described in the paper's Resource Availability statement. Its inventory was fixed by the freeze manifest d2-freeze-v20260725-7 (2026-07-25T08:02:49Z, hash basis: git blob bytes) before the first confirmatory event. The deposit contains no .git directory and no version history; every digest in it is recomputable with the Python standard library alone. Contents: the freeze manifest and its 55 registered objects; every audit snapshot; the collection and metric scripts with their registered digests; the amendment, deviation and attempt ledgers; the case roster; the four mechanism cards; and the pre-registration protocol (v0.3). A standalone verifier, verify_release.py, rebuilds the sealed inventory from the package's own registered rule module, compares it as a set, recomputes every registered digest, and accounts mechanically for each divergence between the freeze anchor and the release anchor. For the nine primary metrics pre-registered by protocol v0.3 it holds a hard-coded registry of ten measurement rows and requires each to be present exactly once in the newest snapshot, under its registered name and kind, and to be recomputed from that snapshot's own bytes and agree. It requires no third-party package and no network access. What it does not do is date anything: that the inventory was fixed before the first confirmatory event is a protocol claim, checked by a reader against the ceremony and adjudication records in the deposit and against the timestamped preprint, not by the verifier. Section 6 of README_ZENODO.md states the bound in full. The deposit is bilingual by layer. Field names, metric identifiers, card ids and the values of missing_code, snapshot_status and data_class are in English. The protocol documents, mechanism cards, red-team opinions and ledger annotations are in Chinese, and so are the enumerated values of two fields: status_class and family. The verifier's prose is English, but it carries the deposit's Chinese directory names in its path constants and one Chinese comparison constant; its check lines and its final RESULT line are ASCII, while its header echoes the root path you give it and its FATAL and hint lines echo Chinese path names. The record's main language is declared as English; section 7 of README_ZENODO.md gives the layer-by-layer split and a Chinese-English table of all 14 enumerated values. This is a single deposit carrying both components of the audit package: the derived data and metadata (snapshots, ledgers, manifests, protocol and mechanism cards) and the original code (collection and metric scripts, schemas, and the standalone release verifier). Zenodo records one upload type, so the record is typed as a dataset; the code component is not thereby demoted. The two components are licensed separately - derived data and metadata under CC BY 4.0, scripts under MIT - and both licences are declared on this record, Zenodo's Licenses field taking more than one entry. The file-by-file boundary is given in LICENSE_BOUNDARIES.md inside the deposit. Neither licence extends to any source document, and no source document is contained in this deposit.



