Attack and repair network
This is a versioned projection of the selected synthetic run—not a live infrastructure map. Red shows disturbance targets; green shows repair, rerouting, isolation, or escalation structures supported by event evidence.
Virtual Surgery Academy · synthetic research and continuous-assurance demonstrator
Research boundary: deterministic synthetic models only. There are no live clinical, personal-account, manufacturing, emergency, or consequential-control integrations.
The default design compares five synthetic problem frames, five disturbance levels, and sole/ensemble/collective agent configurations through a complete MAPE-K trace.
NIST-aligned, framework-specific measurement—not an official NIST or ISO certification. Comparable trends require the same manifest, challenge coverage, thresholds, score version, and evidence rules. NIST SP 800-160 Vol. 2
A synthetic shadow model uses retained experiment evidence to rank which logical component may fail under the next declared challenge, then compares candidate modifications before another attack is injected. It does not consume live telemetry and its risk index is not a real-world failure probability.
| Component | Risk | Candidate modification | Counterfactual risk | Governance |
|---|
Filter the complete evidence batch, compare acceptable drift with corrected or contained outcomes, and select a run to inspect its attack-and-repair trace.
| Challenge iChallenge identifies the deterministic disturbance family injected into a synthetic run, such as degraded data, infrastructure failure, ontology change, or a black-swan condition. Grouping by family shows whether different kinds of stress produce meaningfully different drift, recovery, or containment patterns. It is a categorical experimental factor, not a severity ranking and not evidence that a real attack occurred. Use it to compare like with like before interpreting averages. The Cynefin lens can then help explain why a familiar, analysable disturbance may warrant a different response from a complex or chaotic one. The framework’s categories remain synthetic and bounded to this manifest. Reference: Cynefin domains. | n in is the number of experiment runs included in that challenge row after applying the current dashboard filters. It tells you how much evidence contributes to every mean, percentile, and outcome count alongside it. Larger n generally gives more stable descriptive estimates, while small or uneven groups make comparisons less dependable. Here, n should be checked before comparing challenge families because filters can reduce groups differently. It does not, by itself, demonstrate adequate statistical power or external validity. The qualification design uses repeated deterministic cells, so n also reflects the number of demonstrators, architectures, conditions, waves, and repetitions represented in the group. Reference: NIST sample-size guidance. | Mean drift iMean drift is the arithmetic average of peak distance from the deterministic C0 baseline for all runs in the challenge group. It provides a compact indication of the group’s typical displacement from normal operation. In this framework, values at or below 0.20 remain inside the synthetic operating envelope; larger values require interpretation through corrected or contained outcomes. The mean can conceal clusters, asymmetry, or extreme cases, so it should be read with n, P90 drift, the histogram, and the architecture filter. It is descriptive rather than causal and does not imply equivalent behaviour in a live system. Distribution shape matters when deciding whether the mean is representative. Reference: NIST distributional assumptions. | P90 drift iP90 drift is the estimated 90th percentile of peak distance from C0 within the challenge group. Approximately 90% of included runs have drift at or below this value, while the remaining 10% form the more severe tail. It helps reviewers see risk that the mean may hide, especially when a few architecture or repetition combinations respond poorly. Compare P90 with the 0.20 operating envelope and the blast-radius budget to judge whether tail behaviour remains correctable or requires containment. Percentiles are sample estimates and interpolation methods can differ, particularly for small n, so the value should be read with group size and the full distribution. Reference: NIST percentiles. | Blast budget iBlast budget is the mean declared containment ceiling for runs in the challenge group. It represents the largest modelled disturbance spread the synthetic experiment permits before protective degradation, isolation, safe stop, or escalation becomes necessary. It is intentionally wider than the 0.20 acceptable operating envelope: exceeding the operating envelope may still be corrected, whereas approaching or crossing the blast boundary calls for containment. The value is a designed experiment constraint, not a measured probability and not a safety certification for real infrastructure. Review it with peak drift, P90, outcome, affected topology nodes, and invariant status to understand whether the response limited propagation as intended. Reference: NIST cyber-resilient systems engineering. | Acceptable iAcceptable counts runs whose peak drift stayed at or below the versioned 0.20 synthetic operating-envelope limit. These runs may have experienced a challenge, but their observed displacement remained within the tolerance currently declared by the experiment model. The count is useful for comparing how often architectures absorb disturbances without requiring restoration or protective containment. “Acceptable” does not mean harmless, approved for production, clinically safe, or statistically normal; it is only an internal disposition under this manifest and engine version. Always compare it with n, challenge severity, invariants, P90 drift, and the network trace. A changed envelope would require a new versioned basis rather than silently reclassifying evidence. Reference: NIST withstand and resilience objectives. | Corrected iCorrected counts runs whose peak drift exceeded the 0.20 operating envelope but whose governed response subsequently maintained or restored the required synthetic function. It distinguishes genuine recovery activity from disturbances that were merely absorbed inside tolerance. A corrected result should be interpreted with recovery time, residual risk, topology changes, immutable events, and the MAPE-K decision trace. It does not mean a learned structural change was automatically promoted: persistent deltas remain candidates requiring independent approval. Nor does correction establish that the same response will work in a live domain. The category operationalises the recover-and-adapt aspects of resilience while retaining the experiment’s authority and provenance boundaries. Reference: NIST recover and adapt objectives. | Contained iContained counts runs where restoration was not the appropriate success criterion and the boundary was protected through controlled degradation, isolation, safe refusal, or human escalation. This treats a correct refusal as a resilience outcome rather than a conventional failure. Use the count to examine whether severe, novel, semantic, or cascading challenges were prevented from propagating beyond their blast-radius budget. The network map shows which nodes were isolated or escalated, while the evidence trace shows why execution stopped. Contained is not equivalent to recovered, and it may preserve only bounded function; reviewers should therefore examine outcome, residual risk, invariants, and recovery values together. Reference: NIST withstand and recover guidance. | Mean recovery iMean recovery is the arithmetic average of synthetic seconds from disturbance detection through the governed recovery outcome for runs in the challenge group. It summarises response duration and supports comparisons between sole, ensemble, and collective architectures. A lower value can indicate faster restoration, but it is not automatically better: safe containment, semantic review, or human escalation may appropriately take longer, while P4 safe-stop runs record no restoration interval. Read it with n, outcome composition, P90 recovery, drift, and resilience margin so differing challenge mixes are not mistaken for architecture effects. These are logical experiment seconds rather than wall-clock service measurements or a contractual recovery objective. Reference: NIST recovery-time terminology. |
|---|
This is a versioned projection of the selected synthetic run—not a live infrastructure map. Red shows disturbance targets; green shows repair, rerouting, isolation, or escalation structures supported by event evidence.
Up to 100 matching runs are shown. Select any row to drill into its topology, observations, event chain, and MAPE-K decisions.
| Demonstrator | Condition | Architecture | Challenge | State | Drift / budget | Disposition | Outcome |
|---|
| State | Meaning | Governed response |
|---|---|---|
| P0 | Normal / robust | Observe |
| P1 | Elastic | Temporary adaptation |
| P2 | Plastic | Candidate persistent adaptation; no automatic promotion |
| P3 | Degraded | Preserve bounded function and escalate |
| P4 | Boundary exceeded | Safe stop, containment, human escalation |