AI & Computingpreprint2026-08-08

Availability-Preserving Containment: Measuring the Cost of Correct Isolation

Open access0 citations

Abstract

Containment mechanisms that correctly propagate taint across a dependency graph can disable far more legitimate state than an attacker directly compromised. This paper measures whether operational availability can be restored without weakening containment. Using the frozen CSR-BENCH-1.0 CDoS population—69,930 matched baseline cells over nine acyclic topologies, eight attack classes, seven policies, three graph scales, and thirty seeds—we evaluate six response profiles against identical exact observed-reachable containment: baseline only, isolation only, substitution first, checkpoint first, degraded operation, and governed composition. Every profile is bound by frozen safety invariants: no taint is cleared, quarantine is never reduced, hidden material truth is never consulted, and all created or replacement state must carry new provenance. Restoration is therefore strictly operational: availability is recovered through trusted substitution and checkpoint replay, never by releasing contaminated state. Across 9,990 matched pairs at the primary baseline policy, governed composition raises median Critical Function Availability from 0.24 to 0.95 (median paired difference 0.645, 95% percentile bootstrap interval [0.6376, 0.6525], Holm-adjusted p = 0.0004) and lowers median operational-unavailability WCAL (OU-WCAL) from 0.2494 to 0.2018 (median paired difference -0.1248, [-0.1259, -0.1235]). The containment footprint remains bit-identical: paired containment-WCAL, RER, and CPI differences are exactly zero in all 9,990 pairs, with zero taint clearings, zero quarantine reductions, and zero hidden-truth uses. The preregistered joint success rule is nevertheless not satisfied: H5 and H6 are not rejected, and H1, H2, and H4 are unevaluable on the RC5 surface. The result is therefore a bounded existence-and-direction finding within a synthetic benchmark, not a claim that any product prevents, eliminates, or bounds containment denial of service.

// Source

View paper (DOI)Open access versionOpenAlexZenodo (CERN European Organization for Nuclear Research)Published 2026-08-08

Authors: Andre Byrd

Institutions: Hewlett Packard Enterprise (Ireland)