Cerberus blocks the lethal trifecta at the tool boundary — see the 525-run evidence set.

Resources

The products are downstream of the papers

Odingard's engineering starts as published work — source independence, transitive taint propagation, containment survivability, runtime execution control, calibrated confidence. Everything below carries a DOI or an ISBN, so you can read the argument, check the method and disagree with it in public.

Source independence and the evidence problem

Three papers on a single claim: when several sources agree, nothing in today's infrastructure tells you whether they are independent observations or echoes of one origin — and for an autonomous system, that difference decides whether a decision was supported at all.

Shared agent state and transitive contamination

Agents increasingly coordinate through shared memory rather than messages. This line establishes the trust primitive for that field, measures a working implementation of it, and extends the same taint-closure reasoning to verifying machine unlearning. It is the research underneath Cerberus's L4 provenance ledger and blast-radius containment.

Containment survivability

Correct containment is not the end of the problem. This four-paper program shows how an attacker can weaponize containment itself, then measures whether availability can be preserved and trusted state reconstructed without ever clearing taint. Every result is preregistered and reported against its own success rule — including where that rule was not met.

  • When Containment Becomes the Attack: Denial-of-Service Against Transitive Taint Propagation in Shared Agent State

    A correct containment mechanism can be turned against the system it protects: an adversary who influences where poison enters, what depends on it or what gets designated as poisoned can make sound containment disable far more legitimate state than was ever compromised. The paper names this containment denial-of-service, gives an eight-class attack taxonomy and the CSR-BENCH-1.0 benchmark, and measures the failure without claiming a mitigation.

    Zenodo preprint · 202610.5281/zenodo.21849125

  • Availability-Preserving Containment: Measuring the Cost of Correct Isolation

    Asks whether availability can be restored without weakening containment. Governed composition — trusted substitution and checkpoint replay under new provenance, never releasing contaminated state — raises median critical-function availability from 0.24 to 0.95 with the containment footprint bit-identical. The preregistered joint success rule is not satisfied, and the paper says so: a bounded finding within a synthetic benchmark.

    Zenodo preprint · 202610.5281/zenodo.21849129

  • Self-Healing Containment Graphs: Trusted Reconstruction After Transitive Contamination

    Quarantined state stays unavailable forever unless it can be rebuilt. Governed repair emits reconstructed state forward under a new identity, verified by a separate derivation path and gated against reintroducing prohibited ancestry. Across 4.68 million trials it raises verified repair coverage by a median 0.600 over continuity alone while every containment invariant holds exactly; its joint success rule is not satisfied.

    Zenodo preprint · 202610.5281/zenodo.21849133

  • From Taint Propagation to Governed Recovery: A Unified Framework for Containment Survivability in Shared Agent State

    Synthesizes the program into one framework, from integrity-bound dependency recording through governed reintegration and explicit irreducibility. It separates conformance, which an audit can decide, from survivability within a stated envelope, which only a preregistered empirical criterion can establish — and claims no system has yet met the second. The mixed empirical record is reported without retrospective harmonization.

    Zenodo preprint · 202610.5281/zenodo.21849137

Runtime execution control

Filtering what a model says is the wrong control point. This work moves the constraint into execution itself, aborting before a payload is generated rather than judging it afterwards.

Calibrated confidence under adversarial conditions

Autonomous systems condition their decisions on confidence values that are usually uncalibrated and trivially manipulable. Three papers build the Verdict Weight framework from four streams to eight, add causal attribution, and bound what any such score can achieve given the quality of the evidence.

Books

The long-form treatment, for readers who want the argument end to end rather than paper by paper.

  • The Execution Boundary

    Engineering the brakes for agentic AI — why the control point belongs at execution rather than at generation, and what it takes to build one.

    Book · 2026ISBN 979-8-9965652-1-4

  • The Verdict Weight Methodology

    The eight streams of execution control, worked through as a method rather than a framework paper.

    Book · 2026ISBN 979-8-9965652-0-7

Reproduce it

Published claims are only worth as much as the ability to check them. These are the runnable artifacts — the open cores, the reproduction kit and the benchmark set — under permissive licenses.

ttp-lab

Reproduce and vary the published read-relevance gate study from seed, or run the mechanism on your own agent-memory traces. On a real trace it reports behavior only: with no ground truth to score against, the runner is structurally unable to print accuracy metrics.

MIT

cerberus-core

The open core of Cerberus — runtime detection and correlation of Lethal Trifecta tool-execution paths, published on npm as @cerberus-ai/core.

MIT

argus-core

The open core of Argus, the autonomous red-team engine for LLM and agent targets.

MIT

ARGUS validation benchmarks

Nineteen intentionally vulnerable agent targets spanning chat, tool-calling, memory, MCP, multimodal, cloud-pivot, identity and multi-agent surfaces. Canary-based win conditions give a binary pass or fail instead of a judgment call.

Apache-2.0

cerberus-action

A GitHub Action that tests one agent workflow for dangerous tool-execution paths in CI, plus a companion action that scans agent and MCP tool descriptions for hidden instructions.

MIT

Bring the research to your own estate

Warden is the same people applying this work to systems you are already running — red-teaming agents, constraining what they can reach, and turning the results into evidence an auditor accepts.