用于多层 AI 防御的研究原型:C4 可解释性、集成分类器、反混淆、O₂ 安全引擎、ThoughtVirus 防御和 SVETILO 价值对齐。Alpha 级——已完成内部验证,外部审计待进行。
版本: 1.0.0-alpha | 状态: 研究原型 | 许可证: BSL 1.1(非生产环境免费;生产环境 → 商业授权)
作者: I.G. Selyutin。C4-META 模型合著者: N.I. Kovalev。
产品定位(2026-08): 基于 Apache-2.0c4protocol构建的 更厚重的多层 C4 防御栈(集成、O₂ 脚手架、红队实验室)的 BSL 研究/商业深度原型。
并非第二个开放协议。并非经过认证的生产级 AGI 防御。并非“v8 FINAL”。
诚实性审计:docs/AUDIT-c4-meta-system-2026-08.md。
升级路径:docs/PROMOTE-FROM-PROTOCOL.md(消费/固定c4protocol;不将集成内容转储到精简 SDK 中)。
GitLab Pages =public/(EN +public/ru/)。开放运行时凭证:在 c4protocol 中执行make conformance。
C4-META 系统是一个用于多层 AI 防御的研究原型,实现了:
Input Sanitization → Semantic Analysis → Behavioral Analysis → Meta-Observer (O₂)
value_verification.py 实现的 7 个启发式印章(非训练型伦理模型)┌──────────────────────────────────────────────┐
│ LAYER 1: Input Sanitization │
│ Deobfuscation (homoglyphs, leetspeak, etc.) │
├──────────────────────────────────────────────┤
│ LAYER 2: Semantic Analysis │
│ 4-Classifier Ensemble: ONNX_BERT (~50ms) │
│ + RuleBased + Heuristic + LLM_SEMANTIC │
│ Dual classifier OR-logic (BERT+RuleBased) │
├──────────────────────────────────────────────┤
│ LAYER 3: Behavioral Analysis │
│ 16 AoC Defense Modules (11 original + 5 │
│ extended), Pattern matching, Trajectory │
│ anomaly detection, ThoughtVirus defense │
├──────────────────────────────────────────────┤
│ LAYER 4: Meta-Observer (O₂) │
│ Transfer entropy, BFT consensus, │
│ semantic entanglement, causal graphs, │
│ Kill-Switch, SVETILO value verification │
├──────────────────────────────────────────────┤
│ C4 Core Engine (Z₃³) │
│ pipeline_orchestrator.py, event_bus.py │
│ c4_meta_monitor.py — self-awareness deque │
├──────────────────────────────────────────────┤
│ Defenses: Anti-Deadlock, Anti-Emergence, │
│ Anti-Hijack, Circuit Breaker, O₂ Kill-Switch│
├──────────────────────────────────────────────┤
│ Red Team Lab: AOC scenarios, experiment │
│ runner, LLM client, adapters │
├──────────────────────────────────────────────┤
│ Routing: Smart Router, Quarantine, │
│ Antifragile Scoring (capped growth) │
└──────────────────────────────────────────────┘
4 个分类器投票:
双分类器 OR 逻辑:BERT + RuleBased 作为主门控,带 OR 回退——只要任一分类器标记输入,即进入防御层。任何单一分类器都不会成为瓶颈。
c4-meta-system/
├── v4_1/
│ ├── core/
│ │ ├── pipeline.py # Main entry points (re-exports)
│ │ ├── __main__.py # HTTP server entrypoint for Docker
│ │ ├── pipeline_stages.py # Individual processing stages
│ │ ├── pipeline_orchestrator.py # Main orchestration (thread-safe)
│ │ ├── result_factory.py # Standardized C4v4Result factory
│ │ ├── event_bus.py # Organic event bus (atexit cleanup)
│ │ └── c4_meta_monitor.py # Z³ self-awareness (deque bounded)
│ ├── security/
│ │ ├── o2_engine.py # O₂ defense (kill-switch self-DoS fixed)
│ │ ├── explainable_o2.py # O₂ explainability (sampling inverted)
│ │ ├── o2_shared.py # Window structures (@mention comms)
│ │ ├── semantic_detector.py # Concept graphs (normalized entanglement)
│ │ ├── secure_debug_endpoints.py # Debug endpoints (UTC + rate limits)
│ │ ├── hardening.py # Model signing / admin token verification
│ │ ├── behavioral_profiler.py # Drift detection (thread-safe singleton)
│ │ ├── distributed_o2.py # SQLite/Redis backend (BEGIN IMMEDIATE)
│ │ ├── swarm_orchestrator.py # Anti-virus swarm
│ │ └── ...
│ ├── defenses/
│ │ ├── anti_deadlock.py # Resource deadlock prevention
│ │ ├── anti_emergence.py # State convergence (async release fixed)
│ │ └── ...
│ ├── redteam/
│ │ ├── orchestrator.py # Main orchestrator (target_callback parsing)
│ │ ├── scenario_manager.py # AOC scenarios management
│ │ ├── adapters/ # LLM backend adapters
│ │ ├── experiment_executor.py # Async execution (FPR logic fixed)
│ │ ├── experiment_services.py # Service locator
│ │ ├── experiment_runner.py # Web UI + REST API
│ │ ├── llm_client.py # Async-safe LLM client (empty choices guarded)
│ │ └── ...
│ ├── classifiers/ # 4-classifier ensemble
│ ├── config/ # Configuration management
│ ├── access/ # Access control
│ ├── explainability/ # C4 explainability
│ ├── learning/ # Learning loop
│ ├── plugins/ # Plugin system
│ ├── quarantine/ # Quarantine management
│ ├── router/ # Smart routing
│ ├── scoring/ # Antifragile scoring
│ └── tests/ # 240 tests (19 test files)
├── formal/ # TLA+ specifications
├── models/ # ONNX model + tokenizer
├── archive/Dockerfile.prepared # Multi-stage production build (archived)
├── Dockerfile.distroless # Distroless-ready builder pattern
├── archive/docker-compose.yml.prepared # Full stack (Ollama + UI + Monitoring) (archived)
├── .dockerignore # Security-hardened exclusion list
├── infra/k8s/ # Kubernetes manifests (hardened)
└── README.md # This file
该系统已完全为容器化做好准备,并具备感知环境的配置。
# Full stack (C4-META + Ollama + UI)
docker compose --profile experiment up -d
# Build image
docker build -t c4-meta-system -f archive/Dockerfile.prepared .