{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp06_four_proposal_generalization60_20260803","cell_id":"predictive_residual_processing__criminology_forensic","arm":"COMPLETE_PROPOSAL_PORTFOLIO","candidate_id":"prp_forensic_timeline_residual_triage_v0","proposal_index":1,"version":0,"title":"Residual-First Triage for Digital Forensic Timelines","problem":"In a digital-forensic examination, an analyst may need to review a timeline containing large runs of operating-system, application, synchronization, and acquisition-generated events alongside a smaller set of potentially case-relevant events. When the interface repeatedly presents predictable background activity in full, limited analyst attention can be consumed before missing, extra, displaced, or attribute-changing events are examined. Static suppression is unsafe because an expected-looking event can still contain inculpatory, exculpatory, provenance, or integrity information.","actors":["Digital forensic examiner","Forensic laboratory quality manager","Case investigator requesting the examination","Independent technical reviewer or defense expert","Prosecutor and defense counsel as downstream evidence users","Court as the ultimate adjudicative authority","Person whose device or account data is examined"],"observable_state":"For each read-only extraction from an immutable forensic image, the laboratory can observe the number and classes of timeline events, the share reconstructible from a versioned reference model, structured residuals such as missing expected events, unexpected events, time displacement, or changed attributes, analyst review time by event class, residual-queue saturation, model-version mismatches, raw-audit disagreements, fallback frequency, and whether seeded or independently labeled material events are found with their surrounding context intact.","consequence":"Predictable background events can crowd the analyst’s review surface, delaying examination and increasing the chance that a material inculpatory, exculpatory, or integrity-relevant event is overlooked. Conversely, unexplained deviations presented without their expected context can be overinterpreted as evidence of wrongdoing.","affected_objective":"Support timely and complete digital-forensic review under a bounded attention budget while preserving evidentiary context, reproducibility, neutrality between inculpatory and exculpatory information, and access to the immutable full record.","intervention":"Add a read-only residual-review layer above, never in place of, the preserved forensic image and complete extraction. For a narrowly declared target such as operating-system and application background events within a specified software version and time window, a versioned reference model predicts expected event bundles. The system compares each observed event bundle with that prediction and represents the discrepancy as missing, extra, time-shifted, reordered, or attribute-changed components. A consequence- and reliability-weighted gate places selected residuals in an analyst queue together with the model version, source provenance, uncertainty, and enough expected context to reconstruct the full local sequence. User-authored content, evidence-integrity failures, acquisition errors, clock discontinuities, deletion indicators, legally mandated disclosures, and any analyst-requested scope bypass suppression and appear with full context. Random and risk-stratified raw timeline windows are independently reviewed; case sections periodically re-anchor to full state; missing heartbeats, version mismatch, structured residual drift, excessive reconstruction error, or audit disagreement switch the affected scope to full-timeline review. Residuals may inform offline model review only after human classification; they do not automatically revise the active model or determine evidentiary significance.","structural_mapping":[{"archetype_element":"Prediction target and observation boundary","domain_realization":"A declared class of timestamped system or application events extracted from an immutable device image, bounded by software version, source, time window, acquisition method, and required contextual fidelity."},{"archetype_element":"Generative model state and forward expectation","domain_realization":"A versioned reference model built from controlled or previously validated background-event sequences predicts the event bundle expected for the declared device and software context before the held-out case sequence is scored."},{"archetype_element":"Actual behavior with provenance","domain_realization":"The complete read-only extraction records each observed event, timestamp, source artifact, parser version, acquisition identifier, and quality state independently of the attention layer."},{"archetype_element":"Prediction comparator and structured residual","domain_realization":"The comparator identifies extra, missing, reordered, time-displaced, or attribute-different event components rather than reducing every discrepancy to one anomaly score."},{"archetype_element":"Precision and consequence weighting","domain_realization":"Residual priority reflects source reliability, timestamp uncertainty, parser confidence, evidentiary-integrity implications, possible exculpatory as well as inculpatory relevance, and analyst-channel cost."},{"archetype_element":"Residual propagation and reconstruction","domain_realization":"The analyst interface foregrounds selected discrepancies but carries the prediction, model version, and adjacent full events needed to reconstruct and inspect the original local timeline."},{"archetype_element":"Synchronization and validity","domain_realization":"Each residual is accepted only against the predictor version that generated it; unsupported software versions, stale reference models, parser changes, or gaps force re-anchoring or raw review."},{"archetype_element":"Independent raw-state audit","domain_realization":"A reviewer receives random and risk-stratified full timeline windows selected outside the production predictor and compares them with the residual interface’s reconstruction and suppression decisions."},{"archetype_element":"Safety- and rights-critical bypass","domain_realization":"User-authored material, deletion indicators, integrity failures, acquisition errors, clock discontinuities, mandated disclosure material, and examiner-requested records always travel in full."},{"archetype_element":"Bounded update and fallback loop","domain_realization":"Validated misses enter an offline, attributable review process; the active case model remains fixed, and drift, audit disagreement, mismatch, or cumulative error returns the affected scope to complete chronological review."}],"mechanism_mapping":[{"mechanism_slug":"predictive_codec","role":"Maintains matched expectations in the scoring service and analyst interface so an event bundle can be displayed as expected context plus a structured residual without altering the underlying evidence.","counterfactual_removal":"Without matched prediction and reconstruction, the intervention becomes ordinary anomaly highlighting and cannot demonstrate that suppressed context is recoverable."},{"mechanism_slug":"precision_weighted_error_gate","role":"Prioritizes residuals using source reliability, uncertainty, evidentiary consequence, and the finite analyst-attention budget while retaining suppressed decisions for audit.","counterfactual_removal":"Without this gate, large noisy parser differences could crowd out smaller but reliable integrity or exculpatory discrepancies, or every residual could recreate the original overload."},{"mechanism_slug":"model_version_checksum_handshake","role":"Checks the reference-model and parser identities before a residual is interpreted and tags each residual with those identities.","counterfactual_removal":"Without the handshake, an analyst interface could reconstruct a case event against a different baseline and produce a plausible but incorrect timeline."},{"mechanism_slug":"shadow_raw_channel_sampling","role":"Routes random and risk-stratified full timeline windows to an independent reviewer to measure what the prediction layer suppresses.","counterfactual_removal":"Without independent raw sampling, the system could appear accurate because only events visible to its own model are evaluated."},{"mechanism_slug":"model_drift_monitoring","role":"Tests for structured changes in residual distributions, calibration, unsupported contexts, and model staleness across software or parser versions.","counterfactual_removal":"Without drift monitoring, gradual software or artifact changes could be normalized or misclassified while the residual interface continued operating."},{"mechanism_slug":"raw_signal_fallback_switch","role":"Restores complete chronological presentation for an affected scope after mismatch, staleness, missing data, audit disagreement, excessive error, or a protected-event trigger.","counterfactual_removal":"Without a tested fallback, a failed predictor would remain an evidentiary filter precisely when its assumptions no longer held."},{"mechanism_slug":"prediction_error_review","role":"Requires human, provenance-tagged classification of material misses as model, parser, data-quality, scope, or interpretation problems before any later model change.","counterfactual_removal":"Without review, case-specific residuals could contaminate the reference model or be treated as self-explanatory evidence."}],"causal_chain":["A narrowly scoped, versioned model predicts the background event bundle expected in a defined portion of a digital-forensic timeline.","The complete extraction remains immutable while a comparator computes structured differences between predicted and observed bundles.","Reliability and consequence weighting routes informative discrepancies, protected full-context records, and reconstruction metadata into the bounded analyst-attention channel.","The analyst inspects residuals in their reconstructed local context while routine predicted material occupies less of the primary review surface.","Independent raw samples test whether the layer suppressed material context, and synchronization checks prevent residuals from being applied to the wrong baseline.","Validated residuals reveal either case-relevant deviations or defects in the model, parser, data, or scope; human review determines which interpretation is supportable.","Drift, mismatch, audit disagreement, or excessive reconstruction error suspends residual mode and restores complete chronological review.","If reconstruction fidelity and material-event coverage remain acceptable while review burden falls, the layer supports the objective; otherwise it is withdrawn without changing the evidence record."],"baseline":"The complete extracted timeline is presented chronologically, supplemented by examiner-created searches, sorting, bookmarks, and static known-file or event filters. The baseline retains full context but repeatedly exposes predictable background events and does not require a versioned expectation, structured residual, reconstruction test, independent suppression audit, or drift-triggered decompression.","nearest_rivals":["Static allowlists, known-file filters, and duplicate suppression: simpler and easier to explain, but they do not reconstruct events against a synchronized generative baseline or learn from structured prediction error.","Rule-based alerts for deletion, clock changes, keywords, or specified applications: strong for known conditions and protected bypasses, but limited to predeclared patterns rather than model-relative missing, extra, displaced, or attribute-changing events.","Standalone anomaly scoring: can rank unusual events, but usually does not make the expected portion reconstructible, synchronize model copies, preserve residual direction and type, or provide a governed full-state fallback.","Timeline clustering and visual summarization: can reduce visual density while retaining groups, but does not necessarily use a forward expectation whose residual becomes both the review message and a bounded teaching signal.","Full chronological review with sampling or keyword search: preserves completeness and may remain preferable when predictability or reconstruction fidelity is insufficient, but does not allocate attention through a maintained residual loop."],"remaining_contrastive_claim":"The proposal’s distinguishing testable feature is not merely unusual-event ranking. It couples a scoped, versioned prediction of forensic background activity to structured residual presentation, compatible reconstruction at the analyst interface, independent raw-window auditing, protected full-context bypasses, bounded human-approved updates, and automatic return to complete review when the predictive representation is invalid.","authority_safety":{"decision_authority":"The forensic laboratory quality manager may authorize or terminate a retrospective evaluation; an assigned examiner retains authority over examination methods and interpretations. Investigators, prosecutors, and the model do not control suppression thresholds for an active evaluation case, and courts retain authority over admissibility and evidentiary weight.","authorized_first_step":"Run a read-only, retrospective comparison on a bounded set of already closed or synthetic device images, with the active model frozen before scoring and reviewers blinded to whether each interface is baseline or residual-first. Preserve every full extraction and log every presentation, bypass, reconstruction, and fallback decision.","excluded_actions":["Do not use residual scores to infer guilt, intent, dangerousness, or suspect priority.","Do not use the system to authorize a search, arrest, charge, plea position, sentence, or surveillance expansion.","Do not delete, overwrite, compress away, or alter the forensic image or complete extraction.","Do not conceal suppressed or reconstructed material from authorized independent review or legally required disclosure.","Do not allow online or case-specific automatic model updates.","Do not treat an unexpected event as proof of human action or an expected event as proof that nothing material occurred.","Do not deploy on live cases from the bounded first evidence step."],"halt_rollback":"Immediately halt residual presentation for any affected scope after model or parser mismatch, missing heartbeat, unsupported context, audit discovery of suppressed material information, unexplained reconstruction discrepancy, protected-bypass failure, or residual-channel saturation. Revert to the preserved complete extraction and standard chronological workflow; retain logs for review, invalidate the affected model version, and require quality-manager approval before any new retrospective test."},"negative_tests":{"strongest_counterevidence":"In a blinded retrospective comparison, the residual-first interface fails to reduce examiner effort or delays material-event discovery, performs worse than static filters or full chronological review, produces recurrent audit disagreements, disproportionately suppresses particular artifact or user-context classes, or causes reviewers to overinterpret unexplained deviations despite context and training.","problem_falsifier":"The inferred problem is not present if complete-timeline review is not attention-constrained, predictable background activity does not occupy a material portion of the review surface, or material events are already found reliably and promptly through the baseline without burdens attributable to repeated expected content.","intervention_falsifier":"The intervention is unsupported if a predeclared blinded test cannot keep all material-event and protected-context misses within the laboratory’s zero-or-explicitly-justified tolerance, cannot reconstruct sampled windows to the required semantic fidelity, cannot outperform the strongest simple rival on the joint criteria of review effort and coverage, or requires audit, synchronization, and fallback work at least as burdensome as full review.","risks":["A wrong reference model could explain away material inculpatory or exculpatory evidence.","Residual unusualness could be mistaken for criminal significance, intent, or authorship.","Reference data or consequence weights could encode investigative assumptions and unevenly suppress device, language, application, or user-context classes.","Adaptive normalization could absorb repeated abnormal behavior into the expected baseline.","Parser errors, clock ambiguity, missing data, or model-version mismatch could create false residuals or false silence.","Residual queues could expose especially sensitive atypical behavior even while routine data receives less attention.","Audit sampling could miss rare blind spots and provide false reassurance.","Saved attention could be redirected into broader examination or surveillance rather than reduced burden.","Case-driven model updates could contaminate later cases or create circular confirmation.","The residual layer could complicate reproducibility, disclosure, or independent expert challenge if its versions and traces are incomplete."]},"next_evidence_step":"Pre-register one offline crossover study using a bounded set of synthetic or legally reusable closed-case images. Freeze one reference-model version and one confidence-threshold table; define the supported operating-system and application scope; seed or independently label both inculpatory-neutral, exculpatory, integrity, deletion, clock, and ordinary-background events without revealing labels to examiners. Have each examiner review matched image sections through the baseline and residual-first interfaces in randomized order. Record time to first inspection, total review time, material-event and protected-context misses, false escalations, context-reconstruction errors, bypass and fallback behavior, raw-audit disagreements, version-check failures, and examiner interpretations. Compare against full chronological review and the strongest static-filter configuration. The study licenses no operational deployment and stops on any protected-bypass failure or material suppression found by the independent raw audit.","prior_art_status":"UNSEARCHED","diversity_from_prior_proposals":"This is the first and only proposal in the sealed cell; no earlier within-cell proposal is available for comparison.","revision_record":{"parent_version":null,"progress_targets_addressed":["Initial complete proposal authored from the supplied archetype, mechanisms, and domain card.","Causal structure preserved through prediction, structured comparison, residual routing, reconstruction, bounded updating, independent raw audit, synchronization, and full-state fallback.","Forensic authority and rights safeguards separated residual triage from evidentiary interpretation and coercive decisions.","Problem and intervention supplied with distinct falsifiers and a bounded retrospective evidence step."],"conceptual_changes":["Initial version; no parent proposal.","Scoped the archetype to analyst-attention compression over digital-forensic background timelines while preserving the complete evidentiary record."],"operational_changes":["Initial version; specified immutable raw evidence, frozen-model retrospective testing, protected full-context bypasses, synchronization checks, audit sampling, and rollback to chronological review."],"evidence_changes":["Prior art remains unsearched.","Specified a pre-registered, blinded crossover comparison against full review and static filtering without asserting an effect size."],"claim_changes":["No novelty, prevalence, demand, or effectiveness claim is made.","The remaining claim is limited to a falsifiable architectural contrast and conditional operational value."]}}