Research corpus
Research
Tyche Institute publishes open research where verifiable AI evidence, digital trust infrastructure, and governance meet: provenance, integrity, human oversight, agent delegation, public administration, open data, procurement, standards, regulation, and long-term institutional memory. Deposits are versioned under permanent DOIs; licensing is stated on each record.
The Tyche Attestable Agency Programme is the programme-level map for mandate, execution attestation, Action Evidence Packages, anchoring, independent appraisal, legal interpretation, and observatories. EATF is its appraisal framework, not a name for the whole field.
Governance is a first-class research domain here, not a synonym for compliance. See the governance programme for the public-sector, institutional, and administrative questions that connect the corpus.
Unless marked otherwise, working papers are preprints and not peer reviewed. Tyche Institute is a research entity, not an eIDAS trust service provider under Article 3(16) of Regulation (EU) No 910/2014. The papers do not provide legal advice, certify compliance, or claim that cryptographic evidence proves truth.
The papers below are a selection from Tyche Institute's research corpus, which was assembled and formalised in May 2026 as the institute was constituted. The full corpus is larger than this page shows: work under anonymous peer review is deliberately not listed while a venue's blinding applies. Several outputs draw on multi-year operational notes, earlier drafts, and a sustained independent research programme that preceded formal registration. All works are preprints or working papers unless marked otherwise; the canonical version record is each paper's Zenodo deposit timestamp where a deposit exists, and the venue submission record otherwise. Peer-review outcomes are reflected here as they arrive.
Tyche Institute has an institution record in the Estonian Research Information System (ETIS); the deposited papers and the EATF reference implementation are indexed in ETIS as 7.1 preprints under Tyche Instituut — an administrative publication-indexing step, not peer review or endorsement. See the institution's ETIS entry and the author's ETIS profile .
01
Verifiable AI evidence
Provenance, integrity, agent delegation, human-oversight records, and evidence packages that remain inspectable beyond the system that produced them.
02
Digital trust infrastructure
PKI, digital identity, remote attestation, post-quantum transition, and public interoperability infrastructure studied as technical and institutional systems.
03
Governance and public institutions
Public-sector AI accountability, administrative contestability, procurement, standards, regulatory implementation, and the public records needed to scrutinise decisions.
Research Paper · CEN/CENELEC AI assurance · evidence graphs · mutation testing · submitted to Computer Standards & Interfaces on 13 August 2026 as CSI-D-26-01247
engineering diagnosticStandards Assurance as Join Integrity: Evidence graphs, counterfactual mutation testing, and LLM failure modes in a CEN/CENELEC AI case study
Anton Sokolov · v0.3.1 — public research capsule and interactive evidence lab · August 2026
↳ applies: EATF evidence binding to standards assurance; no conformity, trust-service, or semantic-truth claim
Standards assurance is a join-integrity problem: a plausible clause or artifact is insufficient unless the legal requirement, exact standard version, dependency, evidence object, and human disposition remain bound to one inspectable chain.
NORMTRACE connects AI Act Articles 12–14 and 17 to a declared CEN/CENELEC assurance spine covering logging, transparency, human oversight, quality management, and organisation-level AI management. A separate five-standard ETSI corpus validates the mapping instrument under complete-source conditions; controlled architecture and mutation experiments expose identity loss, invented joins, document-state drift, modal weakening, and actor/object binding failures. A same-window multilingual portal panel preserves public reachability and missingness without republishing protected standards text. The public capsule includes code, manifests, model receipts, signed attestations, external timestamp evidence, and explicit claim boundaries. Independent human adjudication remains future validation; neither the paper nor the demonstrator certifies conformity or semantic truth.
doi:10.5281/zenodo.21924089 → concept DOI: 10.5281/zenodo.21924046 interactive evidence lab →
BibTeX
@misc{sokolov2026normtrace,
author = {Sokolov, Anton},
title = {Standards Assurance as Join Integrity: Evidence Graphs, Counterfactual Mutation Testing, and {LLM} Failure Modes in a {CEN/CENELEC} {AI} Case Study},
year = {2026},
month = aug,
publisher = {Zenodo},
version = {0.3.1},
doi = {10.5281/zenodo.21924089},
url = {https://doi.org/10.5281/zenodo.21924089},
note = {Research Paper submitted to Computer Standards \& Interfaces as CSI-D-26-01247}
} Systems/security research note · 4,995 words · 43-case matched corpus · prospective RIPE Atlas pilot · Apache-2.0 code + CC BY 4.0 text/data · github.com/tyche-institute/from-permit-to-packet
empirical prototypeFrom Permit to Packet: Composing Agent Authority with Public Internet Measurement Evidence
Anton Sokolov · v0.1.0 — full manuscript and executable research artifact · August 2026
↳ applies: SCITT Permit and RATS role-separation concepts to an externally assigned public-measurement effect; no conformance claim
A valid signature cannot compensate for a broken transition from mandate to action, external platform effect, captured evidence, or bounded claim: five isolated treatments accept all 22 authorised controls, while only the composed verifier with a witness rejects and correctly localises all 21 designed faults; a precommitted live RIPE Atlas trace then binds the authorised request to eight later-assigned measurement IDs and 32/32 captured rows.
An executable method for testing authority-to-claim composition around a real external platform. The release contains 21 matched positive/negative pairs plus one clean baseline, a 448-variation deterministic mutation sweep, a prospective Zeus1-only action with an exact request digest committed before RIPE assigned IDs, five unit tests, manifests, a Node prospective verifier, a 12-page manuscript, and a public Observatory. A GitHub-hosted runner reproduces 56 prospective gates over checkout and production artifacts. The evidence boundary is explicit: RIPE public API rows are not RIPE-signed statements, the witness shares Tyche administration and the RIPE upstream, and the study claims neither SCITT/RATS conformance, independent audit, population error rates, legal compliance, nor global availability.
doi:10.5281/zenodo.21923744 → concept DOI: 10.5281/zenodo.21923743
BibTeX
@software{sokolov2026permitpacket,
author = {Sokolov, Anton},
title = {From Permit to Packet: Composing Agent Authority with Public Internet Measurement Evidence},
year = {2026},
month = aug,
publisher = {Zenodo},
version = {0.1.0},
doi = {10.5281/zenodo.21923744},
url = {https://doi.org/10.5281/zenodo.21923744}
} Peer-reviewed Data in Brief article · volume 67, article 113041 · DOI 10.1016/j.dib.2026.113041 · open access under CC BY-NC 4.0 · dataset v0.3 DOI 10.5281/zenodo.20405512 · concept DOI 10.5281/zenodo.20405511
empiricalNekropolis: a cross-domain dataset of computer-science retractions and AI-governance lifecycle records (2018–2026)
Anton Sokolov · published article — Data in Brief · June 2026
↳ parent-of: “A source-stratified opacity profile of six…”, “Computer-generated content and the AI/ML…”
A single unified entry schema brings five public negative-results record families — journal retractions, preprint withdrawals, trusted-service lifecycle changes, archived governance repositories, and reviewed benchmark withdrawals — into one cross-domain corpus of 14,923 records, while keeping source-family labels visible so the evidentiary unevenness between families is never silently pooled.
A peer-reviewed Data in Brief data article for Nekropolis v0.3 — a 14,923-record curated public-record corpus of artifacts retracted, withdrawn, revoked, archived, or discontinued across computer-science retractions, AI-governance records, trusted-service lifecycle changes, withdrawn benchmarks, archived governance repositories, and related source families between 2018 and 2026. Each record carries an artifact category, lifecycle dates, source-stated reason where one exists, a conservative project-inferred cause label, and hashed source pointers. The article defines the schema, source-family gates, validation checks, deposit layout, licensing, and responsible-reuse guidance for the corpus. Companion analyses of public-record opacity (sokolov2026nekropolisOpacity) and AI/ML retraction causes (sokolov2026nekropolisRipr) are separate manuscripts that read this corpus through narrower slices. Dataset deposit: Zenodo v0.3 DOI 10.5281/zenodo.20405512 (CC BY 4.0).
doi:10.1016/j.dib.2026.113041 → concept DOI: 10.5281/zenodo.20405511 publication note →
BibTeX
@article{sokolov2026nekropolis,
author = {Sokolov, Anton},
title = {Nekropolis: a cross-domain dataset of computer-science retractions and {AI}-governance lifecycle records (2018--2026)},
journal = {Data in Brief},
volume = {67},
pages = {113041},
year = {2026},
month = aug,
doi = {10.1016/j.dib.2026.113041},
issn = {2352-3409},
publisher = {Elsevier BV},
url = {https://doi.org/10.1016/j.dib.2026.113041}
} Synthetic case study · artifact-first evidence lab · accepted 23 July 2026 for the ESORICS 2026 RAISE workshop proceedings (Springer LNCS) · Submission 957 · camera-ready delivered; conference registration completed 7 August 2026 · to be presented in Rome, 17–18 September 2026
empiricalSigned, Fresh, and Wrong: Cross-Verifier Disagreement in AI-Agent Evidence over X-Road
Anton Sokolov · Accepted — in the ESORICS 2026 RAISE proceedings · May 2026
Independent verifier paths return contradictory verdicts on byte-identical agent-evidence packages: in the 29-package corpus, the strict profile verifier accepts 7 and rejects 22 while a signature-oriented path accepts 15 and rejects 14, exposing why “verified” is not a single property.
An empirical security study of cross-verifier disagreement over Action Evidence Packages and an X-Road carrier. It runs 29 adversarial packages plus 11 conformance vectors through a structural inspector, a strict package-profile verifier, and a signature-oriented verifier; reproduces a fresh-but-invalid producer path caused by a human-readable-versus-canonical-byte mismatch; compares co-deployed audit and ledger integrity signals; and exercises 13 dual-envelope X-Road scenarios with carrier-versus-agent failure attribution. The paper reports verdict disagreement and bounded failure modes, not truth or legal compliance. Submission 957 was updated in place on 20 June 2026, replacing the earlier Breakable Receipts version, and accepted on 23 July 2026 for the ESORICS 2026 RAISE workshop proceedings. The public corpus is DOI 10.5281/zenodo.21563876. The camera-ready has been delivered and registration completed; the paper will be presented at the RAISE workshop in Rome on 17–18 September 2026.
Archival deposit pending editorial response. The full manuscript is held under submission.
BibTeX
@unpublished{sokolov2026crossverifierraise,
author = {Sokolov, Anton},
title = {Signed, Fresh, and Wrong: Cross-Verifier Disagreement in {AI}-Agent Evidence over {X-Road}},
year = {2026},
month = jul,
note = {Accepted 23 July 2026 for the ESORICS 2026 Workshop on Real-world AI Security and Engineering for Cybersecurity Systems (RAISE), submission 957; proceedings publication pending; public corpus DOI 10.5281/zenodo.21563876},
institution = {Tyche Institute}
} Security engineering · differential fuzzing · accepted 31 July 2026 at STM 2026, the 22nd International Workshop on Security and Trust Management, co-located with ESORICS 2026 (Springer LNCS) · Submission 1188 · camera-ready delivered; conference registration completed 7 August 2026 · to be presented in Rome, 14–18 September 2026
technicalSpec-as-(N+1)-oracle Differential Fuzzing of SD-JWT Presentation Verification
Anton Sokolov · Accepted — in the STM 2026 proceedings · July 2026
Treating the specification itself as an additional oracle alongside N implementations surfaces silent claim-drops in SD-JWT presentation verification — cases where a verifier returns success while quietly discarding selectively disclosed claims.
A security-engineering study that fuzzes SD-JWT presentation verification differentially, using the specification as an (N+1)-th oracle against the implementations under test. The method targets silent failure: a verifier that accepts a presentation while dropping disclosed claims produces no error a relying party can observe. The evidence boundary is explicit — findings are version-bound to the libraries and versions tested, the high-severity reading holds under permissive default-allow authorization, and the study claims neither ecosystem-wide prevalence nor any compliance or certification status. Accepted at STM 2026, co-located with ESORICS 2026 in Rome.
Archival deposit pending editorial response. The full manuscript is held under submission.
BibTeX
@inproceedings{sokolov2026sdjwtfuzzing,
author = {Sokolov, Anton},
title = {Spec-as-($N$+1)-oracle Differential Fuzzing of {SD-JWT} Presentation Verification},
booktitle = {Security and Trust Management ({STM} 2026), co-located with {ESORICS} 2026},
year = {2026},
publisher = {Springer},
note = {Accepted; submission 1188}
} Workshop paper · 4 pp · accepted 31 July 2026 at XAI-EADM, the 1st International Workshop on Explainable AI for Enterprise Architecture and Decision-Making, at CBI & EDOC 2026 (Springer LNBIP) · Submission 6247 · camera-ready and licence-to-publish delivered; registration completed 3 August 2026 · Enschede, 15–18 September 2026
technicalPreparing X-Road for Explainable AI Agents
Anton Sokolov · Accepted — in the CBI/EDOC 2026 workshop proceedings · May 2026
↳ part-of: the carrier-bound-evidence line with “XATF: A Carrier-Binding Verification Profile…” and “Making AI Agents Legible to the State: X-Road,…”
The evidence an explanation would need — which agent acted, under whose mandate, and on what carrier — is not currently retained by the data-exchange layer itself, so explainability for agent actions has to be designed into the carrier rather than reconstructed after the fact.
A short workshop paper asking what a national data-exchange layer would have to record for an AI agent's action to be explainable afterwards. It takes X-Road as the concrete carrier and works through the evidence an explanation depends on: agent identity, the mandate under which the action was taken, and the carrier-level record binding the two. The paper is a position and design sketch grounded in the carrier-bound-evidence line of work; it makes no compliance, certification, or deployment-readiness claim about X-Road or any operator.
Archival deposit pending editorial response. The full manuscript is held under submission.
BibTeX
@inproceedings{sokolov2026xroadexplainable,
author = {Sokolov, Anton},
title = {Preparing {X-Road} for Explainable {AI} Agents},
booktitle = {Proceedings of the {CBI} \& {EDOC} 2026 Workshops ({XAI-EADM})},
year = {2026},
publisher = {Springer},
note = {Accepted; submission 6247}
} Conference submissions
Programme proposals submitted to external venues. These are not research publications — listed here for transparency while programme-committee decisions are pending.
Three proposals · submitted 2026-05-18 · PKI Consortium PQC Conference Amsterdam (vendor-neutral PKI + PQC migration forum)
conference-proposalPKIC PQC Conference Amsterdam 2026 — three Tyche proposals
Anton Sokolov · Conference proposals — awaiting program-committee review · May 2026
Three complementary slots on the same programme: a strategic presentation on decade-scale PQC evidence under the EU AI Act, a technical deep dive on two independent verifiers for hybrid RSA-4096 + ML-DSA-65 agent evidence, and a 90-minute hands-on workshop on signing and offline-verifying a hybrid PQC evidence package for an AI agent.
Three Tyche Institute proposals submitted to the PKI Consortium Post-Quantum Cryptography Conference (Amsterdam 2026), one of the few vendor-neutral forums where the cryptographic-agility transition meets the deployed PKI base: (1) Strategic presentation — Decade-scale PQC evidence under the EU AI Act: why "harvest now, decrypt later" is not only a TLS problem. (2) Technical deep dive — Two independent verifiers for hybrid RSA-4096 + ML-DSA-65 agent evidence: a conformance contract across TypeScript and Python. (3) Workshop — Hands-on hybrid PQC evidence package signing and offline verification (90 minutes). Awaiting program-committee review.
BibTeX
@unpublished{sokolov2026pkicAmsterdam,
author = {Sokolov, Anton},
title = {Three Tyche proposals to the {PKIC PQC} Conference {Amsterdam} 2026: decade-scale {AI} Act {PQC} evidence; hybrid {RSA-4096} + {ML-DSA-65} verifier conformance; hands-on hybrid agent-evidence signing workshop},
year = {2026},
month = may,
note = {Three conference proposals; submitted to PKIC PQC Conference Amsterdam on 18 May 2026; awaiting program-committee review},
institution = {Tyche Institute}
} Demo proposal (non-archival; not in Springer LNAI proceedings) · submitted 2026-05-25 · AIED 2026 Interactive Events (Demos) · Seoul, 27 June – 3 July 2026
conference-proposalMATx Evidence Replayer: A live demonstration of cryptographic attestation for a Bayesian Knowledge Tracing tutor under EU AI Act evidence requirements
Anton Sokolov · Demo proposal · AIED 2026 submission 2080 · May 2026
A live three-phase demo (Generate → Replay → Tamper) showing that a teacher, auditor, or market-surveillance authority can verify the integrity of a BKT session offline, without contacting any registry.
Submitted to AIED 2026 (Seoul, 27 June – 3 July 2026), Interactive Events (Demos) track, on 25 May 2026 (EasyChair submission 2080, deadline 29 May 2026 AoE). Per the AIED 2026 call, accepted Interactive Events contributions are non-archival: they are not included in the Springer LNAI conference proceedings and are instead featured in the IAIED Website Showcase. The demo wraps MATx in an AEP evidence-replayer scaffold: attendees play a 2-minute learner session, move the .aep file to a second laptop via USB, and watch two independent verifiers (TypeScript and Python) replay the BKT trace and detect a byte-flip tamper. Full backing paper: Zenodo DOI 10.5281/zenodo.20357766.
BibTeX
@unpublished{sokolov2026aied,
author = {Sokolov, Anton},
title = {{MATx} Evidence Replayer: A live demonstration of cryptographic attestation for a {Bayesian} Knowledge Tracing tutor under {EU AI Act} evidence requirements},
year = {2026},
month = may,
note = {Demo proposal submitted to AIED 2026 Interactive Events (Demos) track, EasyChair submission 2080},
institution = {Tyche Institute}
} 25-min Session Presentation · submitted 2026-05-14 · waitlisted 2026-07-21 · AGNTCon + MCPCon Europe 2026 (Linux Foundation / Sessionize, ~September 2026)
conference-proposalMCP Needs Receipts: Offline-Verifiable Attestation via Transparent Proxy
Anton Sokolov · Conference talk proposal — waitlisted · May 2026
An open-source transparent proxy (EATF MCP Gateway) wraps any MCP server and produces cryptographic attestations of tool calls without application changes — RFC 8785 JSON canonicalization, hybrid post-quantum signing, RFC 3161 timestamping, hash-chained audit ledger, and `_meta.eatf_attestation_id` injection into MCP responses.
Conference talk proposal submitted to AGNTCon + MCPCon Europe 2026 (Linux Foundation, Sessionize session #1233951). The session presents the EATF MCP Gateway, an open-source transparent proxy that wraps any MCP server and produces cryptographic attestations of tool calls without application changes. Live demo: wrap a standard MCP server, make a tool call, verify the resulting Action Evidence Package with independent verifiers — including offline verification. EATF is maintained by Tyche Institute and released under Apache 2.0; the AEP specification is open for public comment. MATx (Estonian school mathematics) is used as the illustrative vertical; it received the Bilt.me development-programme special prize at the President’s Education Hackathon (Presidendi haridushäkaton), Tallinn, May 2026. The Linux Foundation placed the proposal on the waitlist on 21 July 2026; the session is not confirmed and may be offered a replacement slot if one becomes available.
BibTeX
@unpublished{sokolov2026agntcon,
author = {Sokolov, Anton},
title = {{MCP} Needs Receipts: Offline-Verifiable Attestation via Transparent Proxy},
year = {2026},
month = may,
note = {Conference talk proposal; submitted to {AGNTCon} + {MCPCon} {Europe} 2026 ({Linux} {Foundation} via {Sessionize}, session \#1233951) on 14 May 2026; waitlisted by the {Linux} {Foundation} on 21 July 2026},
institution = {Tyche Institute}
} How to cite
Each paper has a permanent versioned DOI and a concept DOI that always resolves to the latest version. Cite the versioned DOI when you need to pin a specific revision; cite the concept DOI when you want the citation to track the most recent version.
Each card above exposes a ready-to-copy BibTeX entry under the BibTeX disclosure. The Zenodo page for each deposit also offers richer export formats (DataCite XML, CSL JSON, RIS) under its Export menu.
AI assistance disclosure
AI-based assistance was used in the preparation of these papers, consistent
with the Tyche Institute AI assistance disclosure policy and with the 2023
position statements of COPE and ICMJE. The author — Anton Sokolov — conceived
the research, conducted all primary-source work and empirical measurement,
and is solely responsible for the content and any errors. Each submitted
version reflects an author review pass. Version labels follow the
vMAJOR.MINOR[.PATCH] scheme — no process words
or person names in public labels.