ARMFA v1 evaluation artifacts: evidence JSON, re-implementation, and simulation code
收藏资源简介:
# ARMFA v1 Evaluation Artifacts **Paper:** "Auditable but Not Accurate: Deterministic Evidence Authority in Agentic Memory Forensics" **Authors:** A. Khaled, K. Hesham, A. Ayman, R. Ashraf, M. Hamahmy Evaluation artifacts for the paper "Auditable but Not Accurate: Deterministic Evidence Authority in Agentic Memory Forensics." Contents:- JSON investigation reports for two public training images (D1: MemoryDump_Lab5, D2: MemoryDump_Lab6)- Experiment scripts and results for E1 (clean control), E2 (truncation sweep), and E4 (baseline comparison)- Per-step tool outputs from ARMFA investigation runs- Key source files including the k=60 truncation in volatility_runner.py (line 197) and the Bayesian hypothesis store All experiment scripts are reproducible with Volatility 3 and a Windows memory image. ## Contents ### reports/ Machine-readable JSON investigation reports deposited by ARMFA: - `D1_report_MemoryDump_Lab5.json` — Lab 5 training image (rootkit_user, P=0.52) - `D2_report_MemoryDump_Lab6.json` — Lab 6 training image (trojan, P=0.57) ### experiments/ Scripts and results for the decisive experiments: - `e1_clean_control.py` — E1: Clean control (Section 5.3) - `e2_truncation_sweep.py` — E2: Truncation sweep (Section 5.4) - `e4_baseline_comparison.py` — E4: Baseline comparison (Section 5.6) - `results/` — JSON output from each experiment run ### scoring/ Bayesian risk scoring re-implementation: - `hypothesis_store.py` — HypothesisStore with LR_TABLE and posterior update ### tool_outputs/ Per-step tool outputs from ARMFA investigation runs, organized by run ID. ### source/ Key source files from ARMFA v1: - `volatility_runner.py` — Contains the k=60 truncation (line 197) - `agent.py` — ReAct agent loop - `tools.py` / `tool_registry.py` — Tool definitions ## Reproducibility All experiment scripts can be run with Volatility 3 installed: ``` python experiments/e1_clean_control.py # requires a clean Windows memory image python experiments/e2_truncation_sweep.py # requires an infected memory image python experiments/e4_baseline_comparison.py <dump1> [dump2] ... ``` The k=60 truncation is at `source/volatility_runner.py`, line 197: ```python for r in rows[:60]: ``` ## License CC BY 4.0



