Files
geointel/docs/accuracy-program/15-runtime-model-provenance-remediation.md
T
Jens be2e092b33
GeoIntel release gates / Compile, test, contracts and builds (push) Failing after 20s
GeoIntel release gates / Python and npm vulnerability policy (push) Failing after 22s
GeoIntel release gates / GIS image, SBOM and container scan (push) Failing after 2m31s
Recover governed runtime provenance for legacy YOLO models
2026-08-23 23:22:02 +02:00

40 lines
2.0 KiB
Markdown

# Runtime model provenance remediation — 2026-08-23
## Outcome and claim boundary
The active detection checkpoint can receive a truthful narrow runtime sidecar
because its surviving training artifacts now establish an exact byte chain.
This remediation binds model bytes, retained checkpoint, base model, dataset
contract inputs and the surviving Ultralytics training receipts. It does not
retroactively assert a missing historical code commit/container, signed human
review, protected-test independence, national validity or a new promotion.
## Recovered immutable evidence
| Artifact | SHA-256 |
|---|---|
| active model and retained `best.pt` | `a9088b8491dfae36694b53e9e9406cb4e3511d334a5712fa34f75078a47759c1` |
| base model | `a8a79cf5b0bdc19a0245acc322cf77232c335e222bd5f3c00a17d5f29402c196` |
| training `args.yaml` | `2b482e6bbef26f433d4406e1acb5cbbf4ce63a63644b180a2d51b93f8c8f0dcb` |
| training `results.csv` | `6f83fdea2c59cfc5f3e4fe9673494e073c4e0054980b3020bad0289d0118b777` |
| training summary | `6d438308c923f50d885dc777d381f469fa215a0557f0f3e9d3facc2f75ce0b8e` |
| dataset YAML | `3a2ea97c35a18072a1ab6738cd673c0ecec5344b19461c91d72a15e138d46e8d` |
| dataset summary | `49b2a07d2105d08356431757b83eafc1498eaf1fb76965b1efe05b776824942a` |
The checkpoint embeds an Ultralytics detection task, class mapping
`0: building`, framework version `8.4.93`, 30 epochs, image size 640, seed 0
and deterministic mode. The dataset summary retains 198 tiles, 180 training
tiles, 18 validation tiles and 58,820 labels.
## Guarded migration
`scripts/migrate_runtime_model_provenance.py` performs the migration. It fails
closed on any mismatched file or recorded checksum, is dry-run by default,
writes the sidecar atomically and reuses only an identical immutable database
snapshot. The production check then validates the sidecar against the
server-owned `model` registry and snapshot before model loading.
The operational source version is
`sprint174-20260713-smallbld-minpx3-img640-ft30`. This is a recovered runtime
artifact identity, not an accuracy or release-level claim.