Research report in English · KyaniteLabs Research. First published September 28, 2026. Original public report. This edition consolidates the report and preserves its original limits.
A lab that generates its own test data needs to show how its evidence can fail. The September 28 report records attacks against a small lab's custody chain and the defenses those attacks forced.
The attack ledger
- Forged permissions. Fabricated authorization attempted to admit test-pool items. The reported defense uses signed permission from a key held outside the producing system and an issuer ratified by the organization.
- Fake receipts. Outputs were claimed without generation. Append-only, hash-chained indexes and per-item content hashes make acceptance depend on resolving the chain.
- Frozen-field replacement. A verified record could still be mutated through language-level escape hatches. The proposed repair re-derives the registry from signed canonical bytes inside the trust boundary.
- Marker forgery. A reachable module marker allowed an attacker key to construct an accepted state. The proposed repair removes caller-constructible acceptance paths.
Two defects remained open
The source explicitly marks frozen-field replacement and marker forgery as open, with repairs under review. This historical report does not establish that either repair later passed. A new verdict would need its own evidence.
The method worth copying
Separate producer and reviewer custody. Pin artifact hashes when outputs are created. Run probes that construct bypasses, then require the repaired path to refuse those same probes. Keep failed runs and rejected claims in the record.
Limits
One team and one measurement program. The reviewer was separate from the producer, but was not an independent organization. No external red team, external audit or proof of unforgeability is claimed.
The report offers an attack ledger and a repeatable method. It leaves open defects visible rather than treating internal review as a security certification.