Skip to content

Reproduce HookPry, PatchBench, and UMPeek under frozen independent RuV baselines #281

Description

@ruvnet

Program

Independent reproduction for the 2026-09-04 RuV SOTA cycle.

Tracks:

Independent roles

  1. Research freezes source claims, versions, licenses, datasets, hardware assumptions, and exclusions.
  2. Baseline builds current unmodified RuV behavior and immutable evaluator artifacts.
  3. Implementation builds only adapters needed to exercise candidate primitives.
  4. Adversarial review designs mutation, replay, substitution, degradation, and distribution-shift cases without editing the candidate.
  5. Security validates authority boundaries, tenant isolation, privacy, supply-chain assumptions, and rollback.
  6. Testing runs deterministic unit, integration, resource-exhaustion, malformed-input, and partial-failure cases.
  7. Reproducibility pins model, harness, dataset, seeds, environment, costs, and exact commands.
  8. Release recommends ACCEPT, REJECT, or INCONCLUSIVE without merge authority.

Track A: HookPry

Compare current plugin or hook admission behavior with the RVM hook-update gate. Use ephemeral synthetic plugins only. Freeze benign and malicious update sequences before results. Measure unauthorized hook bindings, rights widening, legitimate acceptance, validation p50/p95, CPU, receipt size, and failure modes.

Track B: PatchBench

Compare crash-only, crash-plus-regression, and root-cause validation on seeded vulnerability repairs. Include transformed attack cases and patch-similarity analysis. Measure apparent versus true solve rate, false promotion, utility regressions, evaluator time, and model cost.

Track C: UMPeek

Compare no personalization, current RuV personalization, fixed probing, adaptive probing, response defense, and stateful counterfactual defense where feasible. Measure recovery F1, false inference, personalization utility, latency, tokens, model cost, and cross-tenant leakage.

Governance

Evaluators and attack sets freeze before candidate outcomes are visible. Candidate branches cannot alter evaluator, RVM authority, credentials, or production data. No real third-party plugin ecosystem attacks, credential extraction, deployment, autonomous merge, or irreversible migration.

Acceptance

Each track must publish baseline, candidate, workload, versions, seeds, sample size, absolute and relative results, variance, ablations, regressions, overhead, cost, exact reproduction steps, and negative results. Originating-team claims remain unverified until matched RuV reproduction completes.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions