Research / bounded intelligence

Forecasts without authority.

FerrumOS asks a narrow systems question: can a learned world model help detect risky state transitions while deterministic policy and the kernel retain final control?

Two forecasts. One monotonic gate.

Each eligible action is projected through an independent deterministic transition model and an action-conditioned JEPA latent model. Their risk results are combined monotonically: the learned branch may make the result more cautious, never less. Capability checks, operator confirmation, and syscall validation remain outside the learned model.

Claim boundaryThe current paper establishes reproducible behavior on an authored counterfactual fixture. It does not establish formal safety, natural-use accuracy, or a meaningful safety advantage over every simpler model.

Episode-disjoint, inspectable, versioned.

Transitions

13,697

Recorded state-action-next-state transitions.

QEMU episodes

3,639

Split by episode to reduce direct transition leakage.

Fitting rows

13,270

Versioned alongside the dataset card and hashes.

Evaluation fixture

500

Balanced authored episodes used for paired screening comparison.

A shadow can warn. It cannot drive.

The physical JEPA evaluates deterministic simulator traces behind a hard architectural boundary. The surrounding software now covers versioned sessions, replay/faults, virtual devices, simulator bridges, deterministic supervision, transport conformance, actuator-disabled delivery, and host-managed cell contracts. Learned output remains telemetry-only and permanently shadow-only.

Software regression: 152/152 deterministic contract tests and 32/32 physical-model, robustness, and neural-decoder gates passed for the named source snapshot.

Claim boundaryThere is no installed Gazebo/Webots/ROS 2/MQTT/CAN deployment, native hypervisor containment, real-robot validation, camera-accuracy study, live hardware-in-the-loop safety result, hard-real-time proof, or autonomous physical-control claim.

Coarse signed evidence, not mind reading.

The neural path is constrained to deterministic synthetic or recorded EEG evidence, artifact abstention, explicit non-neural arming, and proposal-only UI or read-only goals. The evidence envelope is signed before crossing into FerrumOS.

Claim boundaryNo live participant or live-EEG accuracy has been measured. FerrumOS makes no diagnostic, clinical, medical, thought-decoding, or silent physical-control claim.

The primary record is public.

Reproduce it. Break it. Improve it.

Contribute ↗