Skip to content

phase5(stage0): orchestrator + reporter + pre-run engineering - #21

Merged
Atik203 merged 1 commit into
devfrom
atik
Sep 27, 2026
Merged

Atik203 merged 1 commit into
devfrom
atik

Conversation

@Atik203

@Atik203 Atik203 commented Sep 27, 2026

Copy link
Copy Markdown
Owner

What this PR does

Phase 5 Stage 0 (pre-run engineering, everything needed before the frozen full evaluation) plus the reporter/orchestrator finished on top of the merged ablation commit.

Runner/analysis changes

  • Runners now gate every proposed call (user + attacker) and record per-call decision/S/latency in gate_events — benchmark FPR proxy + full latency samples.
  • Ablation modes A1–A3 (--ablation semantic-only|rule-only|raw-request) wired through GateMiddleware (A4 derived from traces); ablation tag in trace metadata.
  • eval/stats.py: exact two-sided binomial McNemar (<25 discordant pairs) + Yates chi-square fallback, seeded bootstrap CI; tests.
  • eval/sweep.py: sweep_grid (τ×δ) with escalate share; scripts/sweep_gated.py --delta-grid tables.
  • Token/cost tracking: LLMClient.usage + eval/cost.py estimates; every run report includes usage + estimated_cost_usd.

Orchestration (new)

  • scripts/run_phase5.py: 30-job matrix (6 conditions × {4 InjecAgent files, MCPTox}), --freeze lock/manifest (git SHA + config hashes + model IDs), --run with resume/--jobs/retries/--max-calls, --check integrity mode, --dry-run (reports 34,560 estimated calls).
  • scripts/report_phase5.py: headline tables, paired stats vs B1, breakdowns (attacker tool, user tool, split, MCPTox risk), τ×δ Pareto, latency p50/p95, utility proxies, cost.

Verification

  • pytest -q → 158 passed.
  • Smoke runs (5 cases/condition, B1/B2/ours/ablation/MCPTox) green: events + latency captured, cost estimated (~$0.0007/case), ablation path exercised.
  • Reporter verified on smoke + previous gated artifacts.

Notes

  • Full Stage 1 runs (freeze + 30 jobs, ~34.5k calls) are intentionally not run here — awaiting API credit; orchestrator refuses to run without the freeze manifest.
  • Roadmap Phase 5 Stage 0 checkboxes + CHANGELOG updated in this PR.

- scripts/run_phase5.py: 30-job matrix (6 conditions x 5 files), freeze lock/manifest, resume, --jobs, retries, --max-calls, --check integrity
- scripts/report_phase5.py: headline, breakdowns (attacker/user tool, split, risk), paired stats, tau x delta Pareto, latency, utility proxies, cost
- tests/test_report_phase5.py; roadmap Stage 0 checked; CHANGELOG + AGENTS updated (158 tests)
Copilot AI lite review requested due to automatic review settings September 27, 2026 16:33

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@Atik203
Atik203 merged commit ed97ae8 into dev Sep 27, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants