{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp05_complete_proposal_portfolio20_20260803","cell_id":"invariant_mode_decomposition_design__information_theory","arm":"COMPLETE_PROPOSAL_PORTFOLIO","candidate_id":"cand02_spectral_disclosure_firewall","proposal_index":2,"version":0,"title":"Spectral Disclosure Firewall for Correlated Data Releases","problem":"An analytics service publishes a vector of correlated aggregates, scores, or model outputs derived from records containing protected attributes. Release controls assess outputs one at a time, but the releases jointly form a channel from private source variation to observable outputs. A weighted combination of individually acceptable outputs can strongly transmit a particular combination of protected attributes or subgroup counts. Coordinate-level suppression or independent noise can therefore spend distortion on low-consequence outputs while leaving the joint disclosure direction comparatively intact.","actors":["Data steward responsible for the protected source records","Privacy engineer who specifies and audits release transformations","Analytics-service owner who implements the output filter","Authorized analysts who consume the released statistics","Privacy or governance officer who approves release-policy changes"],"observable_state":"Individual outputs satisfy their existing release checks, yet an approved offline evaluator can combine several outputs to predict a protected contrast more reliably than from any output alone. Across bounded counterfactual perturbations, changes in the private source vector repeatedly map into a similar cross-output response pattern, indicating a potentially stable high-gain direction in the local disclosure channel.","consequence":"A release bundle can expose a protected joint attribute or subgroup contrast that is not visible in per-output audits, while independent suppression or noise unnecessarily degrades outputs that contribute little to that disclosure path.","affected_objective":"Reduce decision-relevant disclosure through a multi-output release channel while preserving declared analytical utility and all existing formal privacy requirements.","intervention":"Within an offline release sandbox, define a standardized private-source state vector and an observable release vector. Construct an analytic or experimentally estimated local operator T that maps bounded source perturbations to output changes. Apply singular value decomposition to obtain paired private-input and observable-output directions with scalar transmission gains. Use a modal sensitivity sweep to test how perturbing each input mode or attenuating its paired output mode changes a predeclared disclosure measure and approved utility measures. Under a fixed utility-loss budget, replace independent output treatment with a bounded release filter that projects out, attenuates, or adds correlated noise along only the highest-leverage disclosure output modes. Preserve mandatory suppression and formal privacy accounting as hard constraints. Validate the filtered release against held-out perturbations, inspect residual disclosure structure, and suspend reuse of the basis when its modes, gains, or spectral separation drift.","structural_mapping":[{"archetype_element":"Transformation Scope","domain_realization":"The bounded local mapping from standardized protected source contrasts to a fixed bundle of published aggregates, scores, or model outputs."},{"archetype_element":"State-Vector Definition","domain_realization":"Input coordinates are approved protected-attribute or subgroup-count contrasts; output coordinates are the simultaneously observable releases, with units fixed before analysis."},{"archetype_element":"Invariant or Paired Mode Basis","domain_realization":"Right singular vectors identify joint private-source directions, while paired left singular vectors identify the cross-output patterns through which those directions are transmitted."},{"archetype_element":"Modal Gain Spectrum","domain_realization":"Singular values quantify the local transmission gain between each paired private-input and release-output direction."},{"archetype_element":"Dominant Mode Selection Rule","domain_realization":"A mode becomes actionable only when its transmission gain and measured disclosure consequence cross declared thresholds and its paired control can satisfy the utility budget."},{"archetype_element":"Modal Intervention Map","domain_realization":"Projection, attenuation, and correlated-noise controls are mapped to the output-side modes they damp and to their measured privacy and utility consequences."},{"archetype_element":"Mode-Coupling Register","domain_realization":"The audit records nonlinear cross-effects, near-degenerate singular directions, and cases where filtering one output mode changes another disclosure or utility measure."},{"archetype_element":"Reconstruction Residual Check","domain_realization":"Held-out output responses are reconstructed from retained modes, and unexplained residuals are tested for remaining protected-attribute predictability rather than judged by magnitude alone."},{"archetype_element":"Mode Drift Monitor","domain_realization":"The service periodically compares mode directions, gains, ordering, and retained-to-discarded separation after query, model, schema, or source-distribution changes."},{"archetype_element":"Interpretation Scope Contract","domain_realization":"The modes describe a bounded local disclosure channel; they are not causal descriptions of people, proof of privacy, or substitutes for formal guarantees."}],"mechanism_mapping":[{"mechanism_slug":"singular_value_decomposition","role":"Factor the rectangular source-to-release operator into paired private-input and observable-output directions ordered by transmission gain.","counterfactual_removal":"Without SVD, the audit remains organized by named fields and outputs and cannot expose a disclosure direction assembled across several coordinates."},{"mechanism_slug":"modal_sensitivity_sweep","role":"Perturb each modal coordinate and candidate filter in the sandbox to rank its influence on disclosure and approved analytical utility, while logging cross-mode effects.","counterfactual_removal":"Without the sweep, the service would suppress modes by singular value alone even when a high-gain mode is harmless or a lower-gain mode carries the protected inference of concern."},{"mechanism_slug":"residual_reconstruction_test","role":"Determine whether the retained modes adequately reproduce held-out release responses and whether omitted residuals retain structured disclosure information.","counterfactual_removal":"Without residual testing, a low-energy protected direction could be discarded and remain available through the filtered release."},{"mechanism_slug":"spectral_gap_monitor","role":"Track whether actionable disclosure modes remain separated and directionally stable as the release bundle and underlying data change.","counterfactual_removal":"Without monitoring, a fixed filter could attenuate obsolete directions while a newly rotated or near-degenerate disclosure mode passes through."},{"mechanism_slug":"spectral_decomposition_report","role":"Document mode loadings, gains, disclosure and utility sensitivities, couplings, conditioning, operating bounds, and the relationship to mandatory privacy controls.","counterfactual_removal":"Without the report, tentative local modes could be treated as semantic facts or as sufficient evidence that the release is private."},{"mechanism_slug":"reduced_order_model","role":"Provide a small sandbox surrogate of the retained disclosure modes for rapid comparison of projection, attenuation, and correlated-noise settings within the validated regime.","counterfactual_removal":"Without the surrogate, each bounded control comparison requires the full release pipeline; the intervention remains possible but loses its explicit, testable modal control surface."}],"causal_chain":["A bundle of correlated releases acts jointly as a channel from protected source variation to observable output variation.","Per-output checks inspect the visible coordinates, while a recipient can combine outputs along directions that the release transformation transmits more strongly.","SVD exposes paired source and output directions and assigns each a local transmission gain.","Disclosure-and-utility sensitivity tests distinguish modes that are merely high-gain from modes that actually carry the protected inference relevant to governance.","Projection, attenuation, or correlated noise applied along selected output modes lowers the channel gain for the corresponding protected source combinations without automatically degrading every output independently.","Held-out residual tests determine whether consequential disclosure remains outside the retained modal account.","Gap and drift monitoring withdraw the filter's authority when the release transformation no longer supports the fitted modal interpretation."],"baseline":"Apply existing release rules independently to each output, such as coordinate-level suppression, independent noise, rounding, minimum-count thresholds, or manual removal, without modeling the joint source-to-output transformation.","nearest_rivals":["Formal differential-privacy accounting with independently calibrated or workload-optimized noise","Query-by-query suppression based on each output's direct protected-attribute association","Direct adversarial privacy-utility optimization over the complete release pipeline without an interpretable modal decomposition","Global dimensionality reduction of the released outputs based on variance rather than protected-source transmission","Manual privacy review of output combinations selected by domain experts"],"remaining_contrastive_claim":"The candidate's testable distinction is that release controls are allocated to paired directions of a measured joint disclosure transformation and ranked by disclosure consequence, rather than assigned to outputs independently or selected from output variance alone. It is an allocation and monitoring layer under existing privacy requirements, not a replacement for a formal privacy guarantee.","authority_safety":{"decision_authority":"The privacy or governance officer owns the release decision. The privacy engineer may run the bounded offline audit, while the analytics-service owner may implement a live filter only after governance approval and confirmation that existing guarantees remain satisfied.","authorized_first_step":"Evaluate the unmodified and filtered release pipelines in an isolated environment using approved synthetic or de-identified evaluation records and bounded counterfactual source perturbations; do not change any live release.","excluded_actions":["Attempting to identify, contact, or target real individuals","Weakening an existing suppression rule, access control, or formal privacy parameter to improve utility","Publishing modal loadings that expose protected subgroup structure","Treating low measured residual disclosure as proof of privacy","Assigning causal or demographic meaning to a mathematical mode without separate authorization and evidence","Automatically applying a fitted filter after the query set, model, schema, source distribution, or privacy policy changes"],"halt_rollback":"Halt evaluation or restore the unchanged baseline release policy if a mandatory privacy constraint is violated, held-out residuals retain declared consequential disclosure structure, the operator is unstable under permitted perturbations, singular directions are too poorly separated for reliable targeting, utility floors are breached, or the protected-source basis cannot be governed safely."},"negative_tests":{"strongest_counterevidence":"At the same declared utility and formal privacy settings, an existing workload-optimized privacy method or direct privacy-utility optimizer controls held-out joint inference at least as well, while the fitted singular modes vary substantially across admissible samples or perturbations.","problem_falsifier":"Approved combination tests show no joint protected inference beyond what is already identified by per-output controls, or a coordinate-independent null operator predicts held-out source-to-release responses as adequately as the coupled operator.","intervention_falsifier":"A stable, consequential joint disclosure mode is reproducibly identified, but attenuating or noising its paired output direction under the same utility budget does not improve the predeclared held-out disclosure criterion relative to the strongest rival.","risks":["The local linear operator may omit nonlinear or threshold-based disclosure paths.","Protected-source perturbations may be unrealistic or may encode governance assumptions as mathematical structure.","Near-degenerate singular values may make individual modes unstable and their loadings misleading.","Filtering a visible mode may redirect inference into an unmodeled residual direction.","Correlated noise may create unexpected bias or complicate interpretation for authorized analysts.","A modal audit could be mistaken for a formal privacy guarantee.","The audit artifacts themselves may contain sensitive subgroup information and require restricted handling."]},"next_evidence_step":"In one isolated release workload, freeze the source schema, query bundle, existing privacy settings, disclosure criterion, utility measures, and admissible perturbation range. Fit T on a training partition of approved synthetic or de-identified evaluation records, compute its singular modes and conditioning, and preselect controls using declared gain, disclosure-sensitivity, utility, and spectral-separation rules. On held-out records and perturbations, compare the mode-targeted filter against the unchanged baseline, independent-noise allocation, query-level suppression, and an available workload-optimized privacy allocation under matched formal settings and utility constraints. Inspect both aggregate disclosure scores and residual structure. The result may authorize only a shadow evaluation of generated releases, not publication.","prior_art_status":"UNSEARCHED","diversity_from_prior_proposals":"Proposal 1 addressed temporal propagation of reconstruction errors inside a predictive telemetry codec and intervened by transmitting protected refresh coefficients along persistent error modes. This proposal addresses joint disclosure through a static multi-output data-release channel and intervenes by filtering or adding correlated noise along output-side disclosure modes. It uses different actors, state variables, consequences, control authority, evidence, and causal path, and can be adopted in an analytics-release service with no predictive codec or telemetry refresh mechanism.","revision_record":{"parent_version":null,"progress_targets_addressed":[],"conceptual_changes":[],"operational_changes":[],"evidence_changes":[],"claim_changes":[]}}