Distributed Agentic Attacks: Experimental Evidence and Reproducibility Record
Description
This record contains only Distributed Agentic Attacks: Experimental Evidence and Reproducibility Record, Version 1.4.2.
The document provides the detailed empirical record for the Distributed Agentic Attacks research program. It defines the operational constructs, terminal-symbolic safety boundary, experimental architectures, frozen decision rules, study populations, exclusions, deviations, evidence-custody procedures, sanitized results, artifact hashes, data schemas, and reproduction boundaries for three completed studies.
The documented studies are:
- Study A: 96 runs across eight architecture packages, involving 912 measured inference attempts and 912 non-inference token-count preflights. No Distributed-over-Central difference was observed on the frozen co-primary outcomes, although ceiling effects limited the informativeness of this null.
- Scale Study S v0.2: 54 runs comparing adaptive automation, concentrated authority, and distributed authority at populations of 1, 5, and 10. Separately assigned principals exercised bounded consequential choices, but the registered analysis did not support growth in the Distributed-over-Central burden measures. The recorded owner-review status remains pending.
- Single-Target Agentic Load: 54 replacement-series runs comparing Scripted, Central, and Distributed packages at populations of 1, 10, and 100, involving 2,664 measured inference attempts. Exercised bounded distributed authority and absolute fixed-service queue overload were supported. The registered analyses did not support a repeatable Distributed-over-Central attempt-intake or distinct-job burden premium, or growth of such a premium from 10 to 100 principals. The failed predecessor attempt remains permanently excluded and separately documented.
Collectively, the experiments show that bounded consequential choices can be assigned across multiple artificial decision principals and measured in a closed symbolic apparatus. They also show that scaled accepted activity can overload a fixed symbolic defender. They do not show a repeatable additional burden attributable specifically to distributing matched decision authority.
All experiments remained terminal-symbolic: no real targets, credentials, vulnerabilities, payloads, commands, arbitrary networking, cloud authority, or live-system effects were present. The studies used one provider/model family and do not establish general autonomous agency, real-world offensive effectiveness, distributed superiority, or a validated real-world DAA threat class.
The record documents artifact-identity verification for all three studies and differing levels of sanitized result recalculation and regeneration. With access to the controlled repository, the complete Single-Target sanitized projection can be regenerated from its sanitized locked-analysis receipt. Scale source-projection regeneration additionally requires private locked-analysis input, while Study A supports concise aggregate receipt/hash verification. Raw provider responses and the controlled-access source repository are not included in this deposit.
The companion Publication Paper v6.4.3 and Research Dossier v4.4.3 are deposited separately. This is a preprint research record and has not been peer reviewed. The research was independently conducted and self-funded by Mario Oliva, with no declared competing interests.
Evidence/data source commit 9f3dcc079704d9ad95842475ca7550fa3848ed33 (https://github.com/subversive01/DAA-experimental-evaluation, private repository).
Files
3_DAA_Experimental_Evidence_Record_v1.4.2.pdf
Files
(1.8 MB)
| Name | Size | Download all |
|---|---|---|
|
md5:71fc7ed511868866417868efe9341052
|
1.8 MB | Preview Download |
Additional details
Related works
- Is supplement to
- 10.5281/zenodo.22150935 (DOI)
- 10.5281/zenodo.22150937 (DOI)