Transitions
13,697Recorded state-action-next-state transitions.
Research / bounded intelligence
FerrumOS asks a narrow systems question: can a learned world model help detect risky state transitions while deterministic policy and the kernel retain final control?
OS world model
Each eligible action is projected through an independent deterministic transition model and an action-conditioned JEPA latent model. Their risk results are combined monotonically: the learned branch may make the result more cautious, never less. Capability checks, operator confirmation, and syscall validation remain outside the learned model.
Claim boundaryThe current paper establishes reproducible behavior on an authored counterfactual fixture. It does not establish formal safety, natural-use accuracy, or a meaningful safety advantage over every simpler model.
Corpus
Recorded state-action-next-state transitions.
Split by episode to reduce direct transition leakage.
Versioned alongside the dataset card and hashes.
Balanced authored episodes used for paired screening comparison.
Physical systems
The physical JEPA evaluates deterministic simulator traces behind a hard architectural boundary. The surrounding software now covers versioned sessions, replay/faults, virtual devices, simulator bridges, deterministic supervision, transport conformance, actuator-disabled delivery, and host-managed cell contracts. Learned output remains telemetry-only and permanently shadow-only.
Software regression: 152/152 deterministic contract tests and 32/32 physical-model, robustness, and neural-decoder gates passed for the named source snapshot.
Claim boundaryThere is no installed Gazebo/Webots/ROS 2/MQTT/CAN deployment, native hypervisor containment, real-robot validation, camera-accuracy study, live hardware-in-the-loop safety result, hard-real-time proof, or autonomous physical-control claim.
Neural intent
The neural path is constrained to deterministic synthetic or recorded EEG evidence, artifact abstention, explicit non-neural arming, and proposal-only UI or read-only goals. The evidence envelope is signed before crossing into FerrumOS.
Claim boundaryNo live participant or live-EEG accuracy has been measured. FerrumOS makes no diagnostic, clinical, medical, thought-decoding, or silent physical-control claim.
Read & reproduce