{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp09_archetype_breadth150_20260804","research_id":"eoa_inverse_innovation_exp09_light_prior_art_20260804","cell_id":"pareto_frontier_navigation__computer_science","search_lanes":{"direct_problem_and_intervention":{"queries":["static analysis configuration Pareto frontier false positives runtime defect detection multi objective","monorepo CI static analysis bundle Pareto optimization rules","SAST multiobjective configuration Pareto"],"source_ids":["SRC1","SRC2"],"no_result_note":null},"synonyms_and_historical_terms":{"queries":["static analyzer configuration tuning precision recall performance Pareto","static analysis \"Pareto front\" precision performance configuration","static analyzer \"Pareto optimal\" configuration precision runtime"],"source_ids":["SRC1","SRC2","SRC4"],"no_result_note":null},"products_practices_and_standards":{"queries":["SAST rule configuration false positive tuning CI official guidance","CodeQL query suites precision performance CI documentation","CodeQL query suites precision severity false positives"],"source_ids":["SRC2","SRC3"],"no_result_note":null},"component_combination":{"queries":["software static analysis rules multi objective optimization false positives execution time","program analysis configuration Pareto frontier recall false positives runtime","configurable software Pareto front performance computational cost uncertainty"],"source_ids":["SRC1","SRC2","SRC4"],"no_result_note":null}},"sources":[{"source_id":"SRC1","title":"Automatically Tailoring Static Analysis to Custom Usage Scenarios","publisher":"Mansur et al.","url":"https://bmarwritescode.github.io/assets/pdf/tailor.pdf","source_type":"PRIMARY_RESEARCH","claims_supported":["Static analyzers can expose millions of configurations controlling precision and performance.","Default configurations may be poorly suited to particular code, resource limits, and lifecycle stages including CI.","TAILOR evaluates configurations on real benchmarks and optimizes verified properties and resource use, providing direct precedent for replay-based configuration comparison.","The work uses a scalar cost function and automatic optimization rather than retaining a Pareto set for accountable human selection."]},{"source_id":"SRC2","title":"Can the configuration of static analyses make resolving security vulnerabilities more effective?—A user study","publisher":"Springer Nature","url":"https://link.springer.com/article/10.1007/s10664-023-10354-3","source_type":"PRIMARY_RESEARCH","claims_supported":["SAST users report excessive false positives and analysis times that impair daily workflow.","Rule and scope configurations create unavoidable tradeoffs among precision, recall, and runtime.","In a 40-participant study, users with configuration access resolved reported vulnerabilities more effectively than users of a default configuration.","The study evaluates configurable-versus-default use but does not perform dominance screening, Pareto exposure, or governed frontier selection."]},{"source_id":"SRC3","title":"CodeQL query suites","publisher":"GitHub","url":"https://docs.github.com/en/code-security/concepts/code-scanning/codeql/codeql-query-suites","source_type":"FIRST_PARTY_PRODUCT","claims_supported":["CodeQL supports built-in and custom bundles of queries.","GitHub's default suite emphasizes high precision and few false positives, while the larger security-extended suite can produce more false positives and includes lower-precision and lower-severity queries.","Organization owners and security managers can recommend suites, demonstrating a concrete governance role around static-analysis bundle selection.","The documentation specifies available suites but not empirical dominance screening or Pareto-governed selection."]},{"source_id":"SRC4","title":"Pareto Front—DeepCAVE Documentation","publisher":"DeepCAVE Project","url":"https://automl.github.io/DeepCAVE/main/plugins/pareto_front.html","source_type":"FIRST_PARTY_PRODUCT","claims_supported":["A deployed configuration-analysis tool can expose non-dominated configurations when objectives such as performance and computational cost conflict.","The tool supports objective selection, budget filtering, display of dominated configurations, and error bars for nondeterministic runs.","This is implementation precedent for frontier visualization and uncertainty display, but it is generic configuration analysis rather than a static-analysis governance workflow."]}],"problem_evidence":{"status":"PARTLY_SUPPORTED","finding":"The core problem is visible: primary studies document large configurable static-analysis spaces, precision/recall/runtime tradeoffs, burdens from false positives and long runs, and shortcomings of inherited defaults; GitHub documents a real query-suite choice that exchanges broader coverage for lower precision and more false positives. The retained evidence does not directly establish that a monorepo's currently deployed pull-request bundle is dominated across detection, review burden, latency, and compute, so that instance-level premise remains to be measured.","source_ids":["SRC1","SRC2","SRC3"]},"closest_prior_art":[{"name":"TAILOR static-analysis configuration optimization","source_ids":["SRC1"],"overlap":"Evaluates analyzer configurations against program-specific precision and resource outcomes, searches beyond defaults, and supports reuse followed by retuning as code evolves.","remaining_difference":"TAILOR scalarizes outcomes into a cost function and automatically returns a tailored configuration; it does not preserve a multiobjective frontier, impose protected-category guardrails first, measure review burden, or require an accountable human sacrifice record and sensitivity-triggered reselection."},{"name":"Configurable-SAST user-study workflow","source_ids":["SRC2"],"overlap":"Directly treats rule and scope selection as a precision-recall-runtime tradeoff and experimentally compares configurable analysis with defaults.","remaining_difference":"It studies interactive configuration and vulnerability-resolution effectiveness, not dominance elimination among versioned bundles, uncertainty-tolerant frontier construction, guardrail-first governance, or a committed selection record."},{"name":"GitHub CodeQL default, extended, and custom query suites","source_ids":["SRC3"],"overlap":"Provides actual static-analysis bundles whose coverage, precision, severity, and false-positive characteristics differ, with organizational security roles able to recommend suites.","remaining_difference":"The product documentation supplies preset and customizable bundles but no replay-derived dominance table, Pareto map, compute/latency comparison, sensitivity sweep, or explicit frontier preference rule."},{"name":"DeepCAVE Pareto-front configuration analysis","source_ids":["SRC4"],"overlap":"Filters and visualizes configurations by multiple objectives, distinguishes frontier points from other configurations, incorporates budgets, and can show error bars.","remaining_difference":"It is generic analysis tooling and does not specify SAST detection floors, false-positive review cost, CI deployment authority, ordered guardrails, human-owned sacrifice rationale, or recheck triggers."}],"prior_art_disposition":"ADJACENT_PRIOR_ART","contrastive_claim_remaining":"For version-pinned pull-request static-analysis bundles, a separately ordered process of protected-category and operational guardrails, uncertainty-tolerant dominance elimination, frontier exposure, and accountable human selection under a declared detection-first preference rule will exclude technically inferior admissible bundles while preserving legitimate detection-versus-friction choices more explicitly than either defaults or a scalar score; the decision will then be rechecked under declared drift triggers.","contrastive_claim_falsifier":"The claim is falsified if no bundle is dominated after guardrails and tolerances, an omitted material objective reverses the eliminations, repeated corpus strata materially change frontier membership under the same rule, or blinded reviewers find the resulting choice and rationale no more reproducible or defensible than a prespecified weighted-score baseline.","gates":{"adequate_source_search":{"status":"PASS","rationale":"The bounded search covered the proposal directly, older precision/performance and configuration-tuning terminology, concrete SAST suites and governance practices, and the combination of configurable-system Pareto analysis with uncertainty. Exactly four opened sources from four publishers were retained, including two primary studies and two first-party documentation sources.","source_ids":["SRC1","SRC2","SRC3","SRC4"]},"supported_problem":{"status":"PASS","rationale":"Primary and first-party evidence supports the existence of configurable bundles, unavoidable detection/precision/runtime tradeoffs, false-positive and latency burdens, and defaults that may be unsuitable. The specific dominated monorepo bundle remains an empirical premise, making the evidence partial but sufficient for this screen.","source_ids":["SRC1","SRC2","SRC3"]},"distinct_testable_claim":{"status":"PASS","rationale":"The retained art covers configuration optimization, empirical SAST tradeoffs, query suites, and generic Pareto visualization separately, but not the proposal's ordered guardrail-to-dominance-to-frontier-to-human-commitment workflow. Its incremental effect can be tested against a fixed weighted-score or inherited-default baseline.","source_ids":["SRC1","SRC2","SRC3","SRC4"]},"bounded_next_test":{"status":"PASS","rationale":"The proposed offline replay of the current bundle and no more than five alternatives on one pinned corpus is limited, reversible, and produces inspectable dominance, frontier, sensitivity, and mock-governance artifacts without changing enforcement. Prior studies demonstrate that benchmarked configuration comparisons and configured-versus-default evaluations are practicable.","source_ids":["SRC1","SRC2","SRC4"]},"no_obvious_safety_or_authority_stop":{"status":"PASS","rationale":"The first test is read-only and non-deploying, preserves required checks and resource ceilings, assigns attestation and approval roles, excludes developer ranking, and includes halt conditions for secrets, disputed labels, non-reproducibility, and uncertain dominance. GitHub documentation also confirms that static-analysis suite recommendations can sit with organization and security-management roles.","source_ids":["SRC3"]}},"screen_survival":true,"world_novelty_boundary":"This limited public-web screen found adjacent components and strong problem precedent but no retained source describing the complete ordered intervention for monorepo pull-request static-analysis bundles. That bounded result does not establish world novelty, patentability, market size, expert acceptance, or realized value; unindexed patents, proprietary engineering processes, differently worded research, and product features outside the searched pages may contain closer art."}