{"schema_version":1,"assessment_id":"eoa_inverse_innovation_exp03_opportunity320_20260801","source_experiment_id":"eoa_inverse_innovation_exp03_full320_20260801","cell_id":"computability_boundary_mapping__security_intelligence","archetype_slug":"computability_boundary_mapping","domain_slug":"security_intelligence","title":"Boundary-aware classification for universal malware-behavior claims","opportunity_summary":"Replace unsupported binary verdicts for unrestricted executables with an enforceable partition among exact, approximate, bounded, one-sided, and out-of-scope analysis modes, preserving UNKNOWN, timeout, and engine-failure states. The proposal could reduce misleading negative verdicts and futile investment in a universal exact decider, but the prevalence of the diagnosed requirement, operational usefulness, and distinctiveness from existing practice remain unestablished.","adopter_authorizer":"The security-analysis service owner can authorize the synthetic sandboxed evaluation; an accountable security authority must separately authorize any production blocking or clearance use.","scores":{"meaningful_impact":{"score":4,"rationale":"If unrestricted exact classification and state collapse occur as described, correcting unsupported negative verdicts could protect investigations and redirect substantial technical effort. The candidate does not establish how often this failure occurs."},"stakeholder_pull":{"score":3,"rationale":"Malware analysts, incident responders, service owners, and downstream blocking teams have proposal-specific reasons to value defensible state labels, but no expressed demand, workflow study, or adoption commitment is supplied."},"incremental_advantage":{"score":4,"rationale":"Relative to the named calibrated heuristic rival, enforceable scope restrictions, computability-status contracts, and distinct UNKNOWN, timeout, out-of-scope, and failure states provide a clear testable advantage. Whether those distinctions improve operational decisions is still uncertain."},"distinctiveness_plausibility":{"score":3,"rationale":"The combination of checked reduction, enforceable fragment routing, guarantee labels, and versioned assumptions is specifically articulated, but prior art is explicitly unsearched and overlap with sound analysis or abstaining-classifier practices is unresolved."},"technical_implementability":{"score":3,"rationale":"A synthetic corpus, labeled interface, finite-state procedures, and bounded routing prototype appear constructible, while faithful semantic formalization, enforceable fragment membership, sound abstractions, and useful UNKNOWN rates present substantial unresolved difficulty."},"adoption_authority_feasibility":{"score":4,"rationale":"The candidate identifies a service owner authorized to approve a sandboxed evaluation, reserves production decisions for accountable authorities, and supplies exclusions and rollback conditions. Production integration would still require downstream agreement."},"evidence_readiness":{"score":4,"rationale":"The authorized first step specifies a synthetic non-deployable corpus, named cases, a baseline comparison, measurable state-label correctness, analyst interpretation, and explicit falsifiers. Corpus construction and independent proof review remain to be completed."},"safety_net_benefit":{"score":5,"rationale":"Preserving UNKNOWN, timeout, out-of-scope, and engine-failure states directly prevents mere non-observation or resource exhaustion from becoming unsupported NO verdicts, with explicit stop conditions if that safeguard fails."},"scalability":{"score":3,"rationale":"A common routing and guarantee-label interface could extend across engines and submissions, but scale may be limited by formalization work, enforceability of fragment membership, stale decision records, downstream binary fields, and potentially unusable UNKNOWN volume."}},"score_confidence":"MODERATE","costs":{"first_evidence":{"band_2026_usd":"50K_TO_250K","scope":"Formalize one declared behavior property and executable model, independently review a target-specific reduction, build a synthetic non-deployable witness corpus, prototype state labels and routing, and compare labeling and analyst interpretation with the baseline and nearest rival.","confidence":"LOW","assumptions":["The study reuses existing sandbox and analysis infrastructure.","The corpus remains synthetic and does not require deployment of generated malware.","The evaluation covers one narrowly declared semantic property and a small analyst sample.","Cost includes formal-methods, security-analysis, engineering, coordination, and evaluation labor."]},"initial_deployment_startup":{"band_2026_usd":"250K_TO_1M","scope":"Develop and harden enforceable fragment checks, routing logic, guarantee metadata, versioned assumptions, audit logs, downstream schemas, and analyst-facing handling for a limited non-production service integration.","confidence":"LOW","assumptions":["Existing analysis engines and submission pipelines can be adapted rather than replaced.","Only a limited set of fragments and behavior properties is supported initially.","Independent security and formal review are required.","No production blocking authority is included at this stage."]},"operational_launch":{"band_2026_usd":"1M_TO_5M","scope":"Launch a production-capable boundary-aware service with engine integrations, monitored downstream contracts, security review, analyst training, compliance and governance work, rollback controls, and evaluation across operationally relevant inputs.","confidence":"LOW","assumptions":["Multiple analysis modes and downstream consumers require integration.","Production launch requires validation against representative but safely handled executable samples.","Accountable authorities approve policies for UNKNOWN and out-of-scope cases.","The scope is one organization or platform rather than an industry-wide deployment."]},"annual_recurring":{"band_2026_usd":"250K_TO_1M","scope":"Maintain formal specifications, fragment procedures, routing rules, guarantee labels, engine integrations, audits, analyst support, security monitoring, and periodic revalidation as environments and assumptions change.","confidence":"LOW","assumptions":["A small specialist team supports the service.","Existing compute and sandbox capacity absorbs most execution demand.","Major new behavior properties or analysis engines would be separately funded.","Recurring independent review is periodic rather than continuous."]}},"research_burden":"HIGH","earliest_credible_horizon":"3_TO_12_MONTHS","pipeline_gates":{"recognizable_externally_supportable_problem":{"status":"YES","reason":"The sealed candidate identifies a concrete and falsifiable failure: unrestricted total-exact requirements combined with interfaces that can collapse timeout, silence, or failed proof search into NO. External inquiry is still needed to establish its prevalence."},"identifiable_adopter_or_authorizer":{"status":"YES","reason":"The security-analysis service owner is identified as the sandboxed-evaluation authorizer, while production blocking and clearance remain with an accountable security authority."},"distinct_testable_incremental_claim":{"status":"YES","reason":"The candidate claims improved correct distinction among NO, UNKNOWN, timeout, out-of-scope, and engine failure versus binary baseline and calibrated heuristic rival interfaces, with reduction preservation as a separate test."},"bounded_next_evidence_step":{"status":"YES","reason":"The proposed synthetic, non-deployable corpus comparison is bounded, names relevant witness and fragment cases, measures labeling and interpretation, and includes explicit falsifiers."},"no_unresolved_safety_or_authority_stop":{"status":"YES","reason":"The first step avoids live deployment and production decisions, prohibits verdict coercion and generated-malware deployment, assigns authority, and specifies halt and rollback triggers."},"implementation_cost_scope_and_range":{"status":"UNCERTAIN","reason":"The candidate defines implementation components but supplies no installed architecture, corpus requirements, staffing model, integration count, or compliance context; only assumption-dependent broad resource bands can be assigned closed-book."}},"blocking_evidence":["Whether any target platform actually admits arbitrary executables under a total-exact semantic classification requirement or collapses UNKNOWN, timeout, and failure into NO.","Whether the declared executable class is already finite, bounded, syntactic, or otherwise governed by a total decision procedure.","Independent confirmation that the reduction preserves the target answer under the declared semantics.","Evidence that fragment membership can be enforced and that abstractions cover the operational behaviors claimed by each guarantee.","Comparative results showing improved state-label correctness and analyst interpretation relative to both the baseline and nearest rival.","Evidence that downstream systems preserve guarantee states and that UNKNOWN volume remains operationally usable.","Prior-art evidence establishing whether the proposed governance and interface combination is meaningfully distinct."],"next_evidence_step":"Run the authorized synthetic, non-deployable corpus study for one precisely declared behavior property: independently check the reduction, then compare the baseline, calibrated heuristic rival, and boundary-aware prototype on known witnesses, finite-state cases, out-of-fragment inputs, timeouts, and reduction-derived constructions. Advance only if the prototype improves correct state labeling and analyst distinction without emitting NO after resource exhaustion or accepting out-of-scope inputs as guaranteed; either failure falsifies the intervention for the tested scope.","research_questions":["Do actual requirements or interfaces claim total exact semantic classification for unrestricted executables, and how are timeout, silence, UNKNOWN, and engine failure currently represented?","Under a precise program model, environmental-input definition, quantifier, and malicious-behavior property, does an independently checked reduction establish the claimed unrestricted boundary?","Which useful executable fragments have enforceable membership tests and constructive exact, bounded, approximate, or one-sided procedures?","Does the boundary-aware interface improve analyst interpretation and downstream handling relative to the baseline and calibrated heuristic rival?","What UNKNOWN and out-of-scope rates are operationally acceptable, and are those states preserved by downstream schemas and decisions?","What existing sound-analysis, abstention, malware-governance, or guarantee-label approaches overlap with the proposal?","Can scope boundaries be exposed to authorized users without materially improving attacker evasion?","What staffing, integration, data-handling, review, and compliance requirements determine credible deployment costs?"] ,"recommendation":"PRIOR_ART_RESEARCH","uncertainty_constraints":["Closed-book assessment cannot establish prior art, novelty, prevalence, market size, realized impact, stakeholder demand, or exact cost.","Impact depends on the diagnosed unrestricted requirement and verdict-state collapse existing in an actual target platform.","The computability conclusion applies only to a faithfully declared semantic property and program model, not to security-intelligence judgments generally.","Feasibility depends on enforceable fragment membership, sound procedures, downstream preservation of labels, and a tolerable UNKNOWN rate.","All cost bands are resource-equivalent ranges based on stated assumptions rather than observed implementation data."],"closed_book_prior_art_boundary":"Prior art was not searched. This assessment makes no claim that formal computability boundaries, sound malware-analysis interfaces, abstaining classifiers, explicit UNKNOWN states, guarantee labels, or their proposed combination are novel or uncommon."}