Ledger topology
Four hypergraph classes coexist because machine learning provenance genuinely has four shapes; the same structure serves research attribution and IP as a secondary case. Flattening any of them into one linear chain destroys the information consensus needs.
Directed
Multi-party attribution. One edge e = (T, H, ω) states
"these four checkpoints, these two datasets and these three training runs, in these
proportions, produced this model," or equivalently which prior works and authors produced a
claim. A pairwise lineage graph must decompose that into edges nobody actually asserted.
Uniform
Standardized evaluation. Every review edge binds exactly k
evaluators, whether k benchmark harnesses scoring a checkpoint or k
reviewers judging a paper. Uniformity makes those edges exchangeable, the precondition for
lifted inference and for comparing rigor across domains at all.
Pseudo
Recursive derivation. Multiset edges keep repeated lineage visible instead of silently deduplicating it, so a model fine-tuned from its own ancestor, or a self-citation, is on the ledger and gets discounted rather than rewarded.
Complete
Saturation reference. σ_d = |E_d| / C(n_d, k) measures how much
of a domain's combinatorial space is already explored. A novelty score of 0.6 means something
very different in a saturated architecture family than in an emerging one.
The consensus mathematics
Every quantity below is recomputable by any party from committed inputs. That is not a convenience; it is what makes the fraud proofs work.
1 · Novelty as a U-statistic
Nearest-neighbour novelty misses the case that matters: a claim no single prior work anticipates, but which a combination jointly anticipates. Combination is a property of subsets, so the estimator ranges over subsets.
Unbiasedness is the property that matters legally: the estimator does not systematically favour or disfavour any claim, which is defensible in a dispute in a way a tuned heuristic is not.
2 · Report a band, never a number
By Hoeffding's projection the estimator is asymptotically normal, so novelty is always an interval. A claim whose interval straddles the commit threshold is not "borderline approved"; it is epistemically unresolved.
With n = 10⁷ and K ≈ 4·10³, degree 3 drops from roughly
10²⁰ groundings to under 10¹⁰ class tuples. Residual approximation is
carried as an explicit variance term, so imprecision costs confidence rather than being
laundered into a crisper number.
3 · Possibility, not probability
An unverified claim in an emerging field has no reference class and no
frequency data. Forcing a probability invents information. The gap Π − N
is the epistemic ignorance, and it is reported rather than minimised away.
4 · The collapse rule
Commitment is gated on necessity, the conservative lower bound. Rejection is gated on possibility, the optimistic upper bound. Both gates are hard to pass, and the residual region is not a coin flip: it escalates to a human.
Saturated domains demand more necessity. Domains under active drift demand less, so a breakthrough is not penalised for looking unlike a stale corpus.
Stated plainly · on the RQM framing
Observer-relative state is a structural analogy, not physics. There is no Hilbert space, no unitary evolution, no Born rule, no entanglement. What is genuinely borrowed from Rovelli's relational reading is one commitment: state is relative to the observer, and "collapse" is the establishment of a shared relation rather than the revelation of a pre-existing fact. That has concrete operational content here, namely per-node possibility distributions plus an explicit collapse operator with a disagreement threshold. The mathematics that actually runs is classical: possibility theory, U-statistics, and weighted Byzantine agreement.
Mathematical foundations
A system built to verify machine learning has to rest on mathematics that will still hold when the models it checks look nothing like today's. Twelve areas underpin AperX; what matters as much as the list is the honesty about which are load-bearing now and which are research frontier. They sort into three tiers.
Tier I · now
Load-bearing today. Relational calculus gates logical consistency before any score; probability theory bounds collusion risk and sets the challenge window; game theory and mechanism design align staking and slashing so honest reporting is rational; information theory measures lineage as actual information transfer; optimization makes disputed training replay bit-identical; statistics audit model drift cheaply; graph theory is the DAG backbone of every provenance record.
Tier II · scheduled
Specified, not yet built. Computability theory and formal methods draw the line between what can be a blocking gate, which must provably halt, and what cannot; the scheduled work is a mechanized proof that recomputation is a total deterministic function of its inputs. Homological algebra and topology fingerprint a network's structure so a verified model can be confirmed to match its claimed architecture, not just its metrics.
Tier III · frontier
Carried as optionality, risk stated. Stochastic PDEs would extend provenance to scientific-ML surrogates, where fixed-point determinism is genuinely hard. Finite fields under the crypto layer are real and standard; algebraic geometry over parameter varieties is aspirational. Spacekime Analytics is a named research option that nothing depends on, listed so it is never mistaken for a load-bearing claim.
The discipline this imposes
A document meant to establish mathematical credibility is destroyed faster by one indefensible claim than it is helped by twelve impressive ones. Every pillar above states its concrete job and its honest limit, and where a framing is an analogy rather than a theorem, it says so. The full treatment, with the formal sketch and subsystem locus for each pillar, is in the white paper and the enterprise repository's foundations reference.
The ledger, live
A synthetic hypergraph region. Amber vertices are claims in epistemic suspension. Suspension has two distinct causes, and the demo distinguishes them: observers may disagree (D > \u03b4), or the necessity floor may simply be unmet (N < \u03bd). Only the second is fixable by machine. The first is what the NOC exists for, and vertices collapsed by a human operator are marked in violet.
Committed
0 hyperedges sealed
Suspended
0 awaiting symbiosis
Mean band width
0.00 Π − N
Domain drift
0.00 MMD² vs baseline
Node validation lifecycle
Submission to permanent encoding. Step 8 is the architectural heart: a protocol forced to produce a verdict on every claim will produce bad verdicts on hard claims. This one is permitted to say "unresolved" and hand the claim to a human.
| # | Stage | Owning plane | Operation |
|---|---|---|---|
| 01 | Ingest | Gateway | Content-address the submission; bind submitter identity and priority timestamp under commit-reveal |
| 02 | Gate | Stage 0 Compliance | Export control (ITAR / EAR), patent-office embargo, PHI in attached datasets, residency |
| 03 | Formalize | Interpretive | Extract atoms into stratified Datalog; verify KB ∪ Φ_c ⊭ ⊥, returning the firing rule on failure |
| 04 | Featurize | Relational Reasoner | Map to directed / uniform / pseudo hyperedges; compute lineage multiplicities |
| 05 | Partition | SRML | Build the exchangeability partition; publish partitionRoot |
| 06 | Estimate | SRML | Draw the incomplete design at committed seed; compute Û_B and total variance by lifted class-count summation |
| 07 | Observe | Consensus | Each validator independently posts a bonded, observer-relative verdict |
| 08 | Collapse / Suspend | Consensus + NOC | Evaluate the collapse rule. On failure the claim suspends to a human privileged observer whose verdict is itself bonded, challengeable and calibration-scored |
| 09 | Commit | Ledger | Write the hyperedge with attribution signatures; seal; open the challenge window |
| 10 | Challenge | Consensus | Any party recomputes deterministically; divergence is a fraud proof; the arbiter replays one contested subset; slash |
| 11 | Anchor | Ledger | Finalize; the claim becomes prior art for every subsequent estimate |
| 12 | Supersede | Ledger | Later refutation appends supersedes(e_new, e_old). Nothing is ever deleted |
Why the heavy mathematics is off-chain
You cannot compute a lifted U-statistic over millions of prior-art tuples inside a block gas limit. Any design claiming on-chain novelty computation is either overstating or operating on a corpus small enough to be uninteresting. The Epistemic Hyperledger is therefore an optimistic verification system: mathematics runs off-chain under a pinned, content-addressed specification with fixed-point arithmetic and canonical subset ordering, and the chain holds commitments, bonds, verdicts, the collapse rule and the challenge window. Determinism is not a nicety here; without it two honest validators disagree and the entire fraud-proof mechanism becomes noise.
UltraMassive ProtoLab™ gateway
ProtoLab hosts the pre-release AperX Blockchain testnet, the reference validator, and the unpublished specification annexes. Access is governed by a mutual (two-way) non-disclosure agreement, because evaluation is bidirectional: you will disclose context about your IP corpus, and we will disclose unreleased protocol internals.
Prototype disclosure · read before relying on this
This gateway performs client-side consent capture, not access control. Everything below runs in your browser. It produces a genuine SHA-256 digest of the executed terms, which is a real integrity artifact, but a browser gate is trivially bypassed and must never be the thing standing between a visitor and confidential material.
The agreement text itself is counsel-reviewed and approved (revision 2026.07-v1.0). Two infrastructure items still stand between this and publication: a real e-signature provider with identity verification for ESIGN / UETA and eIDAS conformance; and server-side enforcement, where the credential is issued after countersignature and the protected material is never shipped to an unauthenticated client.
The receipt hash below is designed to be anchored as a ledger vertex once the testnet is live, which is what makes execution independently verifiable later.
Identify the Disclosing and Receiving Party. Under a mutual agreement you are both, simultaneously.
Reciprocal obligations. Each party is bound identically; neither is merely a recipient.
1 · Mutual character
This Agreement is bilateral. Each party may act as Disclosing Party and as Receiving Party, and every obligation stated herein binds each party symmetrically with respect to Confidential Information it receives.2 · Definition
"Confidential Information" means non-public information disclosed by either party relating to the AperX Epistemic Hyperledger, its consensus parameters, validator calibration methodology, unreleased specification annexes, and reciprocally, the Receiving Party's unpublished research, corpus characteristics and claim formalizations, whether disclosed orally, visually, in writing, or in machine-readable form.3 · Exclusions
Confidential Information does not include information that: is or becomes public through no breach of this Agreement; was rightfully known prior to disclosure; is independently developed without reference to the Confidential Information; or is rightfully received from a third party without restriction.4 · Obligations
Each Receiving Party shall use Confidential Information solely for the stated Evaluation Purpose; protect it with no less than reasonable care and no less care than it applies to its own confidential information of like importance; and limit access to personnel with a need to know who are bound by obligations no less protective than these.5 · Compelled disclosure
A party may disclose Confidential Information to the extent required by law or valid legal process, provided it gives prompt notice sufficient to permit the other party to seek a protective order, and discloses only the portion legally required.6 · No licence, no IP transfer
Nothing herein grants any licence, assignment or other right in any patent, copyright, trademark, trade secret or other intellectual property. Disclosure creates no obligation to enter any further agreement. Submission of a claim to the Hyperledger for evaluation does not transfer ownership of that claim.7 · Ledger anchoring and residual record
The parties acknowledge that a cryptographic digest of the executed terms, together with the identifying details supplied, may be anchored as a vertex in the Epistemic Hyperledger for integrity verification. Such anchoring records the fact and time of execution; it does not publish Confidential Information.8 · Term and survival
This Agreement commences on execution and continues for three (3) years. Confidentiality obligations survive termination for five (5) years from the date of disclosure; obligations with respect to information constituting a trade secret survive for so long as it remains a trade secret under applicable law.9 · Return or destruction
Upon written request each Receiving Party shall promptly return or destroy Confidential Information in its possession, save for one archival copy retained solely for compliance purposes and for automated backup copies made in the ordinary course.10 · Export control
Each party acknowledges that disclosed material may be subject to export control laws including the EAR and, where applicable, the ITAR, and undertakes not to export, re-export or transfer such material in contravention of those laws.11 · Remedies
The parties agree that monetary damages may be inadequate for breach and that injunctive relief may be sought in addition to any other available remedy.12 · Governing law and entire agreement
This Agreement is governed by the law of the Governing Jurisdiction selected above, without regard to conflict-of-laws principles. It constitutes the entire agreement between the parties with respect to its subject matter and supersedes all prior discussions.Instrument status
This agreement text has been reviewed and approved by counsel (revision 2026.07-v1.0). Each party should nonetheless have its own counsel confirm the instrument before executing on behalf of an entity, and the Governing Jurisdiction selection above may warrant jurisdiction-specific adjustments. The execution flow below remains a prototype: see the disclosure at the top of this section.Affirm each obligation in both directions, then sign.
Typing your name constitutes an electronic signature of intent. In production this field is replaced by an identity-verified e-signature provider.
Mutual NDA executed
Below is the SHA-256 digest of the executed instrument: agreement version, both parties' details, affirmations, signature and timestamp. It is computed in your browser and is reproducible from the downloadable record, which is what makes execution independently verifiable.