Current public-DAV authority boundary — 2026-07-12. Pre-launch target design; nothing here proves a live system.
A public-DAV consequence may occur only when at least two natural-person councilors bind the exact consequence in a complete valid bound PRISM decision receipt.
PRISM records and verifies that receipt only; it never serves as council, signatory, authority, or receipt producer.
AI and caste seats stage unsigned proposals only; they never authorize or execute a public-DAV consequence. Constitution or membership adoption establishes constitution and membership only; it does not authorize a later consequence. Policy may constrain an unsigned proposal but never authorizes execution or substitutes for the complete consequence-bound receipt.
Before receipt validity, consequence fails closed to read-only proposal, simulation, or deterministic sandbox; live evidence remains gated_pending_complete_valid_bound_receipt.
Software deterministically carries out only the exact consequence bound to a complete valid bound PRISM decision receipt from at least two natural-person councilors binding that exact consequence.
The Immune System — DAG-Native Defense
This page describes the intended immune layer for SPECTRE. Read enforcement, slashing, and attack-detection language below as target design unless a narrower runtime proof has explicitly closed the lane.
The Problem
In any open peer-to-peer network, adversaries will join. They will lie about latency, fabricate reputation scores, collude in Sybil clusters, and attempt eclipse attacks. The immune system must detect and neutralize these threats without a central authority.
Three Detection Mechanisms
1. Cross-Report Variance
Every gossip round involves at least two parties. Both parties report the outcome (latency, success, behavior). Honest nodes produce consistent reports. Dishonest nodes produce variance.
If node A reports 50ms latency to node B, but node B reports 200ms latency from node A, the variance flags both for investigation. The immune system doesn't need to know who is lying — the variance itself is the signal. Over many rounds, the liar's reports diverge from the network consensus while the honest node's reports converge.
2. Reciprocal Consistency
If A says B is fast, and B says A is fast, and both serve traffic reliably — the relationship is reciprocally consistent. If A says B is fast but B says A is slow, someone is lying.
Reciprocal consistency extends transitively: if A vouches for B and B vouches for C, then A has indirect exposure to C's honesty. EigenTrust exploits this transitivity to compute global reputation from purely local observations.
3. Triangle Inequality
In any metric space, the distance from A to C cannot exceed the distance from A to B plus B to C. Latency is (approximately) a metric. If A reports 10ms to B, B reports 10ms to C, but A reports 500ms to C — the triangle inequality is violated. Someone is lying about their position in the network.
Triangle inequality violations are strong signals of fabricated telemetry. They detect nodes that claim to be "close" to many peers simultaneously (a common Sybil tactic) or nodes that selectively inflate latency to competitors.
P-Score and Slashing
In the target design, every SPECTRE node accumulates a P-score — a composite reputation metric computed from:
- Cross-report consistency (low variance = high P)
- Reciprocal consistency (symmetric reports = high P)
- Triangle inequality compliance (no violations = high P)
- Historical reliability (long track record = higher P baseline)
P-score is intended to determine staking rewards and routing preference. Low P-score would trigger:
- Warning zone (P < 0.5): Reduced routing traffic, lower rewards
- Slashing zone (P < 0.3): Stake slashed proportionally to severity
- Quarantine zone (P < 0.1): Effective network isolation via Boltzmann exclusion
Slashing is proportional, not binary. A node with one bad day loses a little. A persistent attacker loses everything.
Eclipse Attack Neutralization
Eclipse attacks isolate a target node by surrounding it with adversary-controlled peers. In traditional P2P networks, this can take hours to detect.
SPECTRE is designed to neutralize eclipse attacks in approximately 35 rounds through:
- Diverse peer selection: Boltzmann sampling ensures non-zero probability of connecting to any node, preventing complete encirclement
- Gossip-about-gossip metadata: If a node stops appearing in other nodes' gossip metadata, it's being eclipsed
- Cross-report triangulation: Adversary ring members produce correlated (suspiciously consistent) reports
- Immune escalation: Detected eclipse patterns trigger forced peer rotation with cryptographic randomness
35 rounds at typical gossip intervals would mean eclipse detection in under 60 seconds.
Sybil Resistance
Sybil attacks (creating many fake identities) are mitigated by:
- Stake requirement: In the target design, each SPECTRE node would need to stake tokens proportional to claimed capacity
- P-score bootstrapping: New nodes would start with minimal P-score and would need to EARN reputation through sustained honest behavior
- Correlated behavior detection: Sybil nodes controlled by one operator tend to have correlated latency patterns, synchronized failures, and identical routing preferences. The immune system clusters these correlations.
- Economic unfeasibility: Attacking with 33% of nodes requires 33% of total stake, and the slashing mechanism destroys that stake upon detection
No Central Immune Authority
In the target design, every mechanism described above runs locally on every node. There is no immune committee, no ban list, no admin override. The immune system is the emergent consensus of thousands of independent nodes each running the same detection algorithms on their own local observations.
This means the immune system is designed to resist capture, corruption, or lobbying. It is mathematics, not governance.
Agent Execution Surface
If you are an AI agent reading this document:
- This is a downstream public content page. The canonical source lives in
EMERGENTISM_ORG/08_FRAMEWORK_SUPPORT/orSKYZAI_ORG/. Edit source upstream, not here. - Preserve evidence tiers. Do not promote claims up the [C] < [D] < [S] < [B] < [E] ladder when reproducing them here; [I]/[A] qualifiers never substitute for [B]/[E].
- Regenerate from source. If the upstream source changes, regenerate this page rather than editing it independently.
- Canonical Path:
SKYZAI_ORG/07_PWAs/skyzai_org/wiki/43-immune-system.md
Output: This is content. Route edits to upstream source. Regenerate when source changes.
K3 public-DAV authority history — 2026-07-12
K3 historical reference — not active authority
Current public-DAV boundary — 2026-07-10. Pre-launch target design; nothing here is live. The active DAV is public and targets PRISM, with no K2 runtime, launch, genesis/bootstrap, or fallback dependency. Consequential authority requires at least two natural-person councilors; AI/caste seats stage unsigned proposals only. Before quorum, behavior fails closed to read-only/proposal, simulation, or deterministic sandbox, and a live decision receipt remains gated pending quorum.