adv-accept report: seed 100767 hot-set finding at 2^24 nonces, bounded; census baseline

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
igneum-labs 2026-10-07 18:45:47 +00:00
parent 75e8ff24e9
commit ff81c2dea1

View file

@ -135,8 +135,35 @@ items, 1 MB) take at most 0.34% of reads against 0.26% expected; the hottest sin
reads. An on-die copy of these items saves under 0.1% of DRAM reads: no row of chip-model-v3.md moves.
(3) The mechanism is the known one, a near-saturated source (zero, or one bit off all ones) at one site in
one iteration, below the (c') 1% limit (0.013% here), so (c') never fires, and the per-site ratio at 0.98 is
loose enough (these sit at 0.9986) that (c'') never fires either. (4) Confirmation at the gate's own 2^24
nonces with attribution is running (adv/live-confirm-16m.log); numbers replace this paragraph when it lands.
loose enough (these sit at 0.9986) that (c'') never fires either.
### FINDING (bounded): seed 100767 at 2^24 nonces passes the rule and flags the f8 hot-set test (box 1, 18:4xZ)
`adv-live warps --program 100767 --nonces 16777216 --threads 32 --diag 1` (log adv/live-confirm-16m.log,
copied to logs/adv-accept/ when the four runs end). Program id 9d68e6286fc817d4, attempt 2, accepted by
every part of the rule.
| Measure | Value | Uniform / control |
|---|---|---|
| Hot-set test f = 0.1% | S_f 0.303%, E_f 0.148%, X_f +0.155%, X_f/f 1.55: HOT SET | X_f >= f fires |
| Hot-set test f = 0.5%, 1% | X_f +0.266% (X/f 0.53), +0.325% (0.33): no hot set | |
| Top 0.1% share over the window-model control | 2.05x (0.5%: 1.37x, 1%: 1.23x); flat control 2.31x | f8 gate 1.2x; population 0.998x to 1.043x (14 random accepted programs, census, 10^6 nonces) |
| Windowed 6-sigma, 64-item buckets | largest bucket +294.8 sigma | population +4.4 to +30.6 at 10^6 nonces |
| Hot items (top 0.1% = 17,034 items, 1.0 MB) | 6,579,906 of 2,147,483,648 reads (0.306%) | 0.148% expected |
| Top 8 items | 0x000000 (29,355 reads), 0x200000, 0x300000, 0x180000, 0x100000, 0x080000, 0x380000, 0x0c0000: multiples of 2^19, read almost only from site 6 in every iteration | |
| Site attribution | site 6 (instr 23, src r6, quarter window) puts 3.35% of its reads into the hot items; site 7 (instr 32, src r0) 0.41%; every other site 0.00 to 0.21% (expected 0.10%) | |
| Site 6 source | r6, last written by mad at instr 4; saturated (zero) in 0.0126% of evaluations at that position (the (c') limit is 1%); the hot items are the images of small source values under the era stride | |
Gain, priced against chip-model-v3.md section 5.7: an on-die copy of the top 0.1% of items (1 MB of SRAM)
serves 0.31% of this program's loads instead of 0.15%, so it removes 0.16% of DRAM reads. The f = 1 chip's
rate is lanes over latency per read; 0.16% fewer reads is a gain of 1.002x. No row moves. The rule has let
through a program with a measurable, attributable hot set, and the hot set is worthless to a chip. The
distinguisher is real; the bypass is not exploitable at this size.
What a larger search adds: the sweep ranks seeds by the stand-in ratio, and the worst of 4,600 accepted
programs gave X_0.1% = 0.155%. If the tail scales as the extreme of the population, 10^6 seeds reach a few
times that, still under 1% of reads. The census over consecutive seeds (random accepted programs) says how
often the hot-set test fires in the population; that number lands below.
### Live hot-set census (RUNNING)