Framework Overview
The AnubisX Framework provides a complete, formal methodology for behavioral digital attribution. It integrates an axiomatic foundation (16 axioms in 6 groups), the Cognitive Centroid theory of behavioral identity, a mathematical framework comprising 292 objects across 24 categories, an algorithmic catalog of 37 algorithms spanning 5 behavioral modalities, a six-layer architectural design, and a pre-specified four-tier validation infrastructure with 31 acceptance criteria. Together, these components form the first comprehensive framework for attribution of digital artifacts based on behavioral evidence.
Research Contributions
- C1. First complete axiomatic foundation for behavioral digital attribution (16 axioms in 6 groups).
- C2. Cognitive Centroid Theory — formal model of behavioral identity as asymptotic attractor in feature space.
- C3. Formal mathematical framework for multimodal behavioral evidence (292 objects, 24 categories).
- C4. Pre-specified four-tier validation infrastructure with a priori thresholds (31 criteria, 4 tiers).
- C5. Open-source prototype demonstrating stylometric feasibility (Anubis Twitter v2.5, 47 Python files, ~2,800 LOC).
- C6. Empirical feasibility evidence from 15 experiments on 31 Egyptian Twitter accounts.
- C7. Transparent documentation of all limitations, failure modes, and validation status.
- C8. Five behavioral modalities: stylometric, chrono-profiling, terminal profiling, network analysis, media forensics.
- C9. Six-layer architecture: Data, Feature, Profile, Comparison, Evidence, Decision.
Framework Components
Axiomatic Foundation (16 axioms)
The axiomatic system defines 16 axioms organized into 6 groups — Identity, Behavior, Observation, Evidence, Comparison, and Decision — providing the complete logical grounding for all framework operations and ensuring formal consistency across all modalities and workflows.
Cognitive Centroid Theory
Behavioral identity is modeled as an asymptotic attractor in high-dimensional feature space. The Cognitive Centroid represents the theoretical center of an individual's behavioral patterns, toward which observations converge with increasing sample size, enabling formal reasoning about identity from incomplete evidence.
Mathematical Framework (292 objects)
A comprehensive formalization comprising 292 mathematical objects organized across 24 categories, including vector spaces, metric spaces, probability spaces, transformation operators, and evidence combinators. This provides the rigorous mathematical language for all framework definitions and operations.
Algorithm Catalog (37 algorithms)
37 algorithms across 9 domains spanning all 5 behavioral modalities. Algorithms range from feature extraction and normalization through behavioral profile construction, identity matching, evidence fusion, and confidence assessment. The catalog includes 33 established, 2 proposed, and 2 TBD algorithms.
Six-Layer Architecture
The framework is organized into six hierarchical layers: Data Acquisition, Feature Extraction, Profile Construction, Comparison Engine, Evidence Aggregation, and Decision Output. Each layer has well-defined interfaces, inputs, outputs, and formal properties governing inter-layer communication.
Validation Infrastructure (31 criteria)
A pre-specified four-tier validation framework with 31 acceptance criteria. Tier I (Foundation) validates the axiomatic and mathematical consistency, Tier II (Implementation) validates algorithmic correctness, Tier III (Empirical) validates experimental reliability, and Tier IV (Operational) validates deployment readiness.
Operational Workflows
The framework supports three primary operational workflows:
- Identification (1:N matching) — Given a query artifact with unknown source, rank the sources in S by the probability that the artifact belongs to each source.
- Verification (1:1 matching) — Given two artifacts, determine the probability that they share a source.
- Forensic Comparison (1:1 with evidence grading) — Given two artifacts, compute the likelihood ratio LR = P(evidence | same source) / P(evidence | different source).
Framework Status
| Component | Status |
|---|---|
| Axiomatic Foundation (16 axioms, 6 groups) | COMPLETE |
| Cognitive Centroid Theory | COMPLETE |
| Mathematical Framework (292 objects, 24 categories) | COMPLETE |
| Algorithm Catalog (37 algorithms, 9 domains) | SPECIFIED |
| Six-Layer Architecture | DESIGNED |
| Validation Infrastructure (31 criteria, 4 tiers) | SPECIFIED |
| Open-Source Prototype | PROTOTYPE |
| Empirical Validation | PARTIAL |
Known Limitations
- L1. The framework has not been empirically validated across all five modalities; only stylometric analysis has been tested in the current prototype.
- L2. The open-source prototype implements only the stylometric modality, preventing full end-to-end validation of the complete multimodal architecture.
- L3. Empirical evidence is limited to 31 accounts from a single platform (Twitter), which restricts generalizability to other platforms and contexts.
- L4. Computational requirements for full multimodal analysis have not been characterized or benchmarked.
- L5. Algorithm ALG-023 (Confidence Calibration) remains at TBD status and is required for operational deployment.
- L6. Generalizability across languages, platforms, and cultural contexts has not been established.