diff --git a/docs/paper-site/index.html b/docs/paper-site/index.html index b9cfce5..bc5c120 100644 --- a/docs/paper-site/index.html +++ b/docs/paper-site/index.html @@ -569,7 +569,7 @@ anonymity set rather than growing it (RQ2-P1, a Holm-significant negative
-

Abstract (skeleton — quantitative claims held until data + RQ2 ratification)

+

Abstract

Onion-routing systems typically admit any relay that meets a directory's technical criteria; they do not model relay consent — a host's in-band, per-circuit choice to carry a given flow. We build and measure a consent-gated, federated, nested-SSH relay data plane in which @@ -577,7 +577,7 @@ every hop must explicitly accept or reject each circuit through a signed in-band (Ed25519-authenticated, X25519 per-hop credentials), and in which relays are organized into houses that federate either through a shared bridge or through a directory. Treating this as a measurement instrument for a trust model's exposure (not a service that provides -anonymity), we ask two confirmatory questions on a lab grid of two phones and a laptop: (RQ1) +anonymity), we ask two confirmatory questions on a single-laptop isolated-docker grid (two non-forwarding phones pinned): (RQ1) does a shared bridge introduce a measurable flow-linkability leak between a circuit's entry and exit segments, and does cover padding remove it; (RQ2) does federating relays across houses grow or shrink the anonymity set an adversary faces, and is any effect explained by @@ -635,8 +635,7 @@ linkability (RQ1) and the anonymity-set effect of federation (RQ2) on a lab grid when consent-gated federation helps or harms anonymity. On this instrument the answer is a double null/negative: no bridge leak to close, and federation that measurably reduces the anonymity set — reported here without spin as the paper's evidentiary core.

-

Scope. Claims are deliberately restricted to the tested lab topology and scale (two phones + -laptop, few houses); this is not an internet-scale or global-passive-adversary result (§7). +

Scope. Claims are deliberately restricted to the tested lab topology and scale (a single laptop's isolated-docker containers; two phones pinned but non-forwarding; few houses); this is not an internet-scale or global-passive-adversary result (§7). The paired churn-resilience question (RQ3) and a QUIC/ssh3 transport arm [Michel2023] are pre-registered but held for a companion paper; this lead paper covers G4 + RQ1 + RQ2 only.


@@ -700,7 +699,14 @@ by the freeze. Key mechanisms:


4. Methods (pre-registered; frozen)

This study is a confirmatory factorial controlled comparison; the design, variables, seeds, -detectors, and analysis were frozen and hashed on 2026-07-19 before any confirmatory cell ran.

+detectors, and analysis were frozen and hashed on 2026-07-19 before any confirmatory cell ran. +It was designed, pre-registered, and executed under the Interpretable Context Methodology +(ICM) [VanClief2026], a staged-pipeline framework in which each phase — literature, hypothesis, +design/pre-registration, build, execution, analysis, and write-up — is a numbered stage whose +frozen output/ is the sole input to the next. ICM is the structural mechanism behind the +freeze-before-data discipline used throughout this section: the pre-registration was frozen and +SHA-256-sealed in the design stage before the build and execution stages could consume it, so the +provenance chain (§4.4) is auditable by construction rather than by convention.

4.1 Design matrix

Cells are organised per RQ with the other factors held at their declared control: