Resources
The products are downstream of the papers
Odingard's engineering starts as published work — source independence, transitive taint propagation, containment survivability, runtime execution control, calibrated confidence. Everything below carries a DOI or an ISBN, so you can read the argument, check the method and disagree with it in public.
Source independence and the evidence problem
Three papers on a single claim: when several sources agree, nothing in today's infrastructure tells you whether they are independent observations or echoes of one origin — and for an autonomous system, that difference decides whether a decision was supported at all.
Shared agent state and transitive contamination
Agents increasingly coordinate through shared memory rather than messages. This line establishes the trust primitive for that field, measures a working implementation of it, and extends the same taint-closure reasoning to verifying machine unlearning. It is the research underneath Cerberus's L4 provenance ledger and blast-radius containment.
- Transitive Taint Propagation for Shared Agent State: A Trust Primitive for the Verified Field
Multi-agent systems are moving from message-passing to a shared field of memory. Every such system verifies who writes and when, but none verifies whether a write is trustworthy before it becomes shared reality — so a single poisoned write can launder itself through honest agents. The paper names this the unverified-writer gap.
SSRN preprint · 202610.2139/ssrn.6973658Zenodo deposit →
- Transitive Taint Propagation for Shared Agent State: An Empirical Evaluation
Measures a reference implementation of the primitive above, built as an extension to a runtime guard's provenance ledger: dependency edges recorded under a SHA-256 commitment, a forward blast radius B(p) computed by graph traversal, containment by append-only quarantine. Reports accuracy, performance, and the soundness boundary — where the mechanism is blind by construction.
SSRN preprint · 202610.2139/ssrn.6976282ttp-lab — reproduce it yourself →
- Transitive Taint Propagation for Shared Agent State: Measured Generalization Across Models and Topologies — An Empirical Companion (v0.3)
Tests whether the primitive generalizes beyond one model and one agent layout, on real instrumented traces. A read-relevance gate lifts blast-radius precision from 80% to 100% across three model families and reaches 100% precision in six topologies, with the recall cost reported per workload. Self-declared ground truth is near-complete in five topologies and half-missing in one, so it must be measured, not assumed.
Zenodo preprint · 202610.5281/zenodo.20838847
- The Removability Gap: Adversary-Resistant Verification of Machine Unlearning via Taint-Closure Criteria
Machine-unlearning verification asks whether a provider really removed a data subject's contribution. The paper argues the fragility of current methods is definitional rather than empirical: they certify that no deleted datum appears in the recorded computation, which is provably blind to influence-equivalent substitution.
Zenodo preprint · 202610.5281/zenodo.21041133
- The Removability Gap: An Empirical Evaluation of Taint-Closure Verification, Its Soundness Boundary, and Adversary-Resistant Fusion in Retrieval-Augmented Generation
The empirical validation on retrieval-augmented generation. A paraphrase of a deleted fact evades a set-membership deletion check on all 200 targets; taint-closure verification by recorded lineage detects all 200. Its blind spot is an independently authored equivalent with no shared lineage, which a calibrated fusion covers — at an honest false-positive cost the paper discloses and then reduces about 33-fold. A working paper.
Zenodo working paper · 202610.5281/zenodo.21200682
Containment survivability
Correct containment is not the end of the problem. This four-paper program shows how an attacker can weaponize containment itself, then measures whether availability can be preserved and trusted state reconstructed without ever clearing taint. Every result is preregistered and reported against its own success rule — including where that rule was not met.
- When Containment Becomes the Attack: Denial-of-Service Against Transitive Taint Propagation in Shared Agent State
A correct containment mechanism can be turned against the system it protects: an adversary who influences where poison enters, what depends on it or what gets designated as poisoned can make sound containment disable far more legitimate state than was ever compromised. The paper names this containment denial-of-service, gives an eight-class attack taxonomy and the CSR-BENCH-1.0 benchmark, and measures the failure without claiming a mitigation.
Zenodo preprint · 202610.5281/zenodo.21849125
- Availability-Preserving Containment: Measuring the Cost of Correct Isolation
Asks whether availability can be restored without weakening containment. Governed composition — trusted substitution and checkpoint replay under new provenance, never releasing contaminated state — raises median critical-function availability from 0.24 to 0.95 with the containment footprint bit-identical. The preregistered joint success rule is not satisfied, and the paper says so: a bounded finding within a synthetic benchmark.
Zenodo preprint · 202610.5281/zenodo.21849129
- Self-Healing Containment Graphs: Trusted Reconstruction After Transitive Contamination
Quarantined state stays unavailable forever unless it can be rebuilt. Governed repair emits reconstructed state forward under a new identity, verified by a separate derivation path and gated against reintroducing prohibited ancestry. Across 4.68 million trials it raises verified repair coverage by a median 0.600 over continuity alone while every containment invariant holds exactly; its joint success rule is not satisfied.
Zenodo preprint · 202610.5281/zenodo.21849133
- From Taint Propagation to Governed Recovery: A Unified Framework for Containment Survivability in Shared Agent State
Synthesizes the program into one framework, from integrity-bound dependency recording through governed reintegration and explicit irreducibility. It separates conformance, which an audit can decide, from survivability within a stated envelope, which only a preregistered empirical criterion can establish — and claims no system has yet met the second. The mixed empirical record is reported without retrospective harmonization.
Zenodo preprint · 202610.5281/zenodo.21849137
Runtime execution control
Filtering what a model says is the wrong control point. This work moves the constraint into execution itself, aborting before a payload is generated rather than judging it afterwards.
Calibrated confidence under adversarial conditions
Autonomous systems condition their decisions on confidence values that are usually uncalibrated and trivially manipulable. Three papers build the Verdict Weight framework from four streams to eight, add causal attribution, and bound what any such score can achieve given the quality of the evidence.
Books
The long-form treatment, for readers who want the argument end to end rather than paper by paper.
- The Execution Boundary
Engineering the brakes for agentic AI — why the control point belongs at execution rather than at generation, and what it takes to build one.
Book · 2026ISBN 979-8-9965652-1-4
- The Verdict Weight Methodology
The eight streams of execution control, worked through as a method rather than a framework paper.
Book · 2026ISBN 979-8-9965652-0-7
Reproduce it
Published claims are only worth as much as the ability to check them. These are the runnable artifacts — the open cores, the reproduction kit and the benchmark set — under permissive licenses.
Reproduce and vary the published read-relevance gate study from seed, or run the mechanism on your own agent-memory traces. On a real trace it reports behavior only: with no ground truth to score against, the runner is structurally unable to print accuracy metrics.
MIT
The open core of Cerberus — runtime detection and correlation of Lethal Trifecta tool-execution paths, published on npm as @cerberus-ai/core.
MIT
The open core of Argus, the autonomous red-team engine for LLM and agent targets.
MIT
Nineteen intentionally vulnerable agent targets spanning chat, tool-calling, memory, MCP, multimodal, cloud-pivot, identity and multi-agent surfaces. Canary-based win conditions give a binary pass or fail instead of a judgment call.
Apache-2.0
A GitHub Action that tests one agent workflow for dangerous tool-execution paths in CI, plus a companion action that scans agent and MCP tool descriptions for hidden instructions.
MIT
Bring the research to your own estate
Warden is the same people applying this work to systems you are already running — red-teaming agents, constraining what they can reach, and turning the results into evidence an auditor accepts.