Stream Assembly Is an Uncontrolled Treatment in Streaming Intrusion-Detection Benchmarks: Reproducibility Package
Abstract
Reproducibility package for "Stream Assembly Is an Uncontrolled Treatment inStreaming Intrusion-Detection Benchmarks". Contents: the analysis code and tests, the LaTeX source of the manuscript, thegenerated macro layer that every reported number resolves through, the full setof run manifests (including retired manifests with their retirement reasons),the sentence-level claim ledger, the provenance gate that fails the build on anynumber without a manifest, and the two headline result tables. Every measured value in the manuscript is generated by a script that writes anarchived run manifest in the same execution. An eight-check build gate fails on:a number with no manifest; a macro two runs claim with different values; driftbetween the derived macro index and the manifests; a typed literal anywhere inthe manuscript, its inputs, or any file the claim ledger cites; a derived valuethat disagrees with the values printed beside it; inconsistent display width;shell-escape damage in the LaTeX sources; and text typeset past the page measure. Provenance limitation, stated precisely. Nineteen of the twenty-five live runmanifests in this record executed on a working tree that carried uncommittededits, so the exact source state for those runs is not recoverable. Every basecommit they name resolves and is an ancestor of the published branch, so thegenerating code is reachable at commit granularity; what is missing is theuncommitted delta at run time. Two of the nineteen are irreducible: the CICIDSconstruction-contrast arms, run idss4_construction_contrast_20260819T064027_20f44694 ands4_construction_contrast_20260819T090813_46e9bd32, ran on an EC2 Linux instancethat has since been decommissioned, and re-running them on the author's Windowsmachine would change published numbers -- the cross-platform difference thisproject records as corrected incident CI-16. They were therefore not re-run, andthe other seventeen were deliberately left as they are rather than regenerate asubset that would not change this disclosure. Earlier versions of the associated manuscript (arXiv:2605.24696 v1 and v2)reported results produced under a composite benchmark construction and describeda scoring rule the released code did not implement. This package is the rebuildfrom that audit. Earlier manuscript versions cite doi:10.5281/zenodo.20074590, which resolves to version 1.0.0 of the artifact record, deposited 2026-05-07 and containing the pre-audit codebase; this corrected rebuild is published as version 2.0.0 in the same record lineage and supersedes it, and Zenodo displays a newer-version notice on the superseded record.
// Source
Authors: Michel A. Youssef