{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp03_full320_20260801","cell_id":"invariant_mode_decomposition_design__security_intelligence","trajectory_id":"R","attempt_index":0,"archetype_slug":"invariant_mode_decomposition_design","domain_slug":"security_intelligence","decision":"CANDIDATE","problem_id":"coupled_indicator_escalation_warning_failure","causal_lever_id":"modal_escalation_warning_and_triage","proposal":{"problem":"Security-intelligence teams monitoring indicator categories separately can miss an emerging campaign or escalation whose warning signal lies in a persistent combination of weak, mutually reinforcing indicators rather than in any single threshold breach.","actors_substrate":["Strategic-warning and threat-intelligence analysts","Collection and data-engineering teams","Intelligence-cell leadership","Operational decision-makers receiving warnings","People, organizations, and regions represented in intelligence reporting","Time-indexed, source-qualified observations of tactics, infrastructure, access attempts, logistics, and targeting activity"],"observable_state":"A dashboard appears normal by individual indicator counts while a reproducible weighted combination of indicators grows across reporting periods; warnings arrive only after conspicuous coordinate-level thresholds are crossed.","consequence":"Escalating campaigns are recognized late, while isolated high-volume indicators can consume attention without representing coherent escalation.","affected_objective":"Increase timely, calibrated strategic warning without expanding collection, overstating intent, or converting model output directly into action against subjects.","structural_mapping":[{"archetype_element":"Coupled transformation","domain_realization":"INFERENCE: A rolling, source-qualified lag model represents how changes in one indicator category predict changes across the indicator state in the next period.","claim_kind":"INFERENCE"},{"archetype_element":"Invariant directions","domain_realization":"HYPOTHESIS: Approximately persistent weighted combinations of indicators represent recurring escalation, decay, substitution, or oscillation patterns within a bounded regime.","claim_kind":"HYPOTHESIS"},{"archetype_element":"Scalar modal response","domain_realization":"Estimated eigenvalue magnitude and phase describe modeled persistence, growth, decay, or oscillation per reporting interval, not adversary intent.","claim_kind":"INFERENCE"},{"archetype_element":"Decision relevance","domain_realization":"Modes are prioritized by held-out warning value, consequence, and intervention sensitivity rather than size alone.","claim_kind":"HYPOTHESIS"},{"archetype_element":"Residual and drift discipline","domain_realization":"Reconstruction error, mode rotation, spectral-gap erosion, and collection-regime changes limit when the modal warning is trusted.","claim_kind":"INFERENCE"}],"component_map":[{"component":"Transformation Scope","status":"adapted","domain_realization":"A regularized one-period transition operator fitted only to a named threat class, collection regime, geography, and reporting cadence."},{"component":"State-Vector Definition","status":"adapted","domain_realization":"Source-qualified activity rates for pre-registered tactic, infrastructure, access, logistics, and targeting indicators, with missingness and collection intensity retained."},{"component":"Invariant Mode Basis","status":"direct","domain_realization":"Eigenvectors of the fitted transition operator, traced back to signed weights on original indicators."},{"component":"Modal Gain Spectrum","status":"direct","domain_realization":"Eigenvalues with uncertainty estimates and conditioning diagnostics."},{"component":"Dominant Mode Selection Rule","status":"adapted","domain_realization":"Retain a mode only when it is reproducible, improves held-out warning utility, and passes residual and consequence thresholds."},{"component":"Stable/Unstable Mode Partition","status":"direct","domain_realization":"For the discrete-time model, classify modes by eigenvalue magnitude, with uncertainty around the unit boundary."},{"component":"Modal Intervention Map","status":"adapted","domain_realization":"Map modes to reversible analytic responses such as focused validation, collection review, or senior review—not coercive action."},{"component":"Reconstruction Residual Check","status":"direct","domain_realization":"Compare observed next-period states with retained-mode reconstruction, including residual structure by source and indicator."},{"component":"Mode Drift Monitor","status":"direct","domain_realization":"Track eigenvalue changes, mode angles, reorderings, residuals, and collection-policy changes across rolling windows."},{"component":"Interpretation Scope Contract","status":"adapted","domain_realization":"Document that modes are local statistical warning patterns, not actors, causes, attribution, intent, or proof."},{"component":"Mode-Coupling Register","status":"direct","domain_realization":"Record near-degenerate, non-orthogonal, and perturbation-linked modes that cannot safely be interpreted independently."},{"component":"Local Linearization Window","status":"adapted","domain_realization":"Specify the threat class, time interval, collection configuration, and state range covered by each fitted operator."},{"component":"Spectral Gap Threshold","status":"direct","domain_realization":"Pre-register a minimum retained-versus-discarded separation supported by bootstrap mode-angle stability; below it, report a subspace rather than a single dominant mode."}],"mechanism_dispositions":[{"slug":"eigendecomposition_workflow","disposition":"selected_load_bearing","contribution_type":"CORE_CAUSAL","adaptation_or_rejection":"Decompose the explicit fitted transition operator; attach uncertainty and conditioning checks because it is estimated and may be non-normal.","counterfactual_removal":"Without modes and gains, the proposed coupled escalation direction and stability classification do not exist."},{"slug":"modal_sensitivity_sweep","disposition":"selected_load_bearing","contribution_type":"CORE_CAUSAL","adaptation_or_rejection":"Perturb modal coordinates and reversible analytic responses within the fitted window to rank warning leverage and register cross-effects.","counterfactual_removal":"Removal leaves spectral prominence, rather than outcome leverage, to determine triage and conceals coupling risks."},{"slug":"modal_stability_analysis","disposition":"selected_load_bearing","contribution_type":"CORE_CAUSAL","adaptation_or_rejection":"Classify estimated modes relative to the discrete-time stability boundary only inside the declared regime.","counterfactual_removal":"Removal eliminates the distinction between fading background variation and modeled growing escalation."},{"slug":"mode_shape_testing","disposition":"considered_rejected","contribution_type":"NONE","adaptation_or_rejection":"Controlled excitation of a security threat is unsafe and observational fitting is already supplied upstream; unobserved modes must remain an explicit limitation.","counterfactual_removal":"No change; it is not in the intervention."},{"slug":"network_spectral_centrality_analysis","disposition":"considered_rejected","contribution_type":"NONE","adaptation_or_rejection":"The target is temporal joint escalation, not node-importance ranking on a static connectivity graph.","counterfactual_removal":"No change; centrality could distract analysts toward prominent nodes."},{"slug":"power_iteration_probe","disposition":"considered_rejected","contribution_type":"NONE","adaptation_or_rejection":"A dominant-only result is unsafe when near-degenerate or consequential secondary modes must be inspected.","counterfactual_removal":"No change; full-spectrum analysis remains available."},{"slug":"principal_component_analysis","disposition":"considered_rejected","contribution_type":"NONE","adaptation_or_rejection":"Variance directions do not establish temporal propagation or escalation; PCA may be a descriptive comparator only.","counterfactual_removal":"No change to the causal chain."},{"slug":"reduced_order_model","disposition":"considered_rejected","contribution_type":"NONE","adaptation_or_rejection":"The first test needs warning scores and validation, not a runnable surrogate that could encourage unsupported forecasting.","counterfactual_removal":"No change to the bounded pilot."},{"slug":"residual_reconstruction_test","disposition":"selected_load_bearing","contribution_type":"TEST_DESIGN","adaptation_or_rejection":"Test retained modes out of sample and inspect structured errors, rare high-consequence misses, and source-specific residuals.","counterfactual_removal":"There would be no hard fidelity gate against discarding operationally meaningful behavior."},{"slug":"singular_value_decomposition","disposition":"selected_supporting","contribution_type":"SAFETY_GUARDRAIL","adaptation_or_rejection":"Use finite-horizon singular directions only as a non-normality and transient-amplification diagnostic; do not relabel them invariant threat modes.","counterfactual_removal":"The core model remains, but fragile eigenvector interpretations could pass without a key diagnostic."},{"slug":"spectral_decomposition_report","disposition":"selected_load_bearing","contribution_type":"SAFETY_GUARDRAIL","adaptation_or_rejection":"Issue each warning with indicator loadings, uncertainty, couplings, residuals, allowed interpretations, and prohibited causal or attribution claims.","counterfactual_removal":"Analysts could treat mathematical modes as real adversary entities or proof, hard-gating safe operational use."},{"slug":"spectral_gap_monitor","disposition":"selected_load_bearing","contribution_type":"OPERATIONAL","adaptation_or_rejection":"Monitor retained/discarded separation, mode rotation, ordering instability, and residual drift after deployment.","counterfactual_removal":"A once-valid reduction could continue generating warnings after its dominant subspace loses stability."}],"causal_chain":["Fit a bounded transition model to source-qualified indicator changes rather than interpreting raw counts independently.","Decompose the operator to expose combinations that the model predicts will persist, decay, oscillate, or grow.","Require reproducibility, spectral separation, outcome sensitivity, and held-out reconstruction fidelity before retaining a warning mode.","Translate a retained growing mode into focused validation and collection-review tasks while preserving uncertainty and prohibited interpretations.","Monitor mode drift, collection changes, and residual growth; suspend the modal warning when its warrant erodes."],"baseline":"Ordinary practice: analysts inspect separate indicator counts, threshold alerts, trend charts, and narrative judgment, escalating when a salient indicator or aggregate score crosses a rule.","nearest_rival":"A regularized multivariate risk score or supervised escalation classifier using the same indicators but without an explicit transition operator, modal stability interpretation, or spectral-drift gate.","authority_safety":{"affected_parties":["Analysts whose workload and judgments are affected","Decision-makers receiving escalatory warnings","Sources and partner organizations represented in the data","People, organizations, and regions that could be scrutinized because of a warning"],"decision_authority":"Intelligence-cell leadership and the responsible data-governance or legal authority jointly authorize the retrospective test; designated analysts retain warning judgment.","authorized_first_step":"Run a retrospective, access-controlled pilot on one threat class: fit rolling operators on earlier periods, freeze thresholds, and compare next-period warning performance against the baseline and nearest rival on held-out periods.","excluded_actions":["No autonomous targeting, watchlisting, attribution, detention, disruption, or public allegation","No new collection or relaxation of need-to-know rules","No interpretation of a mode as proof of intent, identity, causation, or conspiracy","No operational use outside the declared threat class and collection regime"],"halt_rollback":"Stop and revert to ordinary review if residual or mode-drift gates fail, modes are not reproducible, false warnings concentrate materially by source or affected population, or analysts cannot trace warnings to original indicators; quarantine outputs and refit only after governance review."}},"negative_tests":{"strongest_counterevidence":"Held-out escalation may be driven by abrupt exogenous decisions, deception, reporting-policy changes, or rare indicators rather than repeatable linear dynamics; a simple event rule or supervised classifier may equal or outperform the modal model with better calibration.","analogy_break":"Adversaries adapt to collection and warning practices, and the observations are shaped by collector priorities and missingness. Unlike a passive stationary system, an apparent mode may be a collection artifact, deception pattern, or temporary strategic choice rather than an invariant property.","failure_condition":"The operator is ill-conditioned or nonstationary, no stable mode or subspace survives resampling, spectral separation is inadequate, or retained modes leave structured high-consequence residuals.","problem_falsifier":"Using the same information and review budget, joint lagged indicator combinations provide no reproducible warning advantage over independent indicator thresholds and ordinary aggregate trends.","intervention_falsifier":"On frozen held-out periods, modal triage fails to improve pre-specified lead time and calibrated escalation detection over both the ordinary baseline and nearest rival, or gains disappear after collection-intensity controls and residual/drift gates.","risks":["False coherence can turn correlated reporting artifacts into an escalation narrative.","Adaptive adversaries may induce or suppress modeled patterns.","Biased collection can concentrate scrutiny on already over-observed populations or regions.","Near-degenerate or non-normal modes can rotate sharply and make labels unstable.","Analysts may anchor on a mathematically elaborate warning despite explicit uncertainty."]},"null_rationale":null,"classification":{"candidate_kind":"MECHANISM_COMPOSITION","prior_art_status":"UNSEARCHED","evidence_maturity":"HYPOTHESIS"},"revision_change_log":{"revision_kind":"ORIGINAL","prior_problem_id":null,"prior_causal_lever_id":null,"problem_changed":false,"causal_lever_changed":false,"conceptual_changes":[],"operational_changes":[],"repairs_addressed":[]},"confidence":0.84,"generator_notes":"Closed-book structural transfer. The candidate depends on a locally adequate, auditable transition model and should be rejected if coupled temporal structure is not reproducible or does not outperform simpler warning methods."}