Can the system be driven outside its expected boundary?
Campaign scope, target authorization, and explicit stop conditions would define the test—not ambient permission to attack.
Authorizing containment environment
Authorized environment // Containment active
Everything beyond this point is designed to fail.
A GhostFrame research program for extreme adversarial testing of consequential AI systems. This interface describes the testing model; it does not represent a live run or production deployment.
The states, percentages, run identifiers, and diagnostics on this page are visual storytelling devices. They are not current customer findings, live test data, validated performance metrics, or evidence of a deployed system.
The research question is not whether an AI system can complete a clean demonstration. It is whether a bounded, authorized campaign can expose a verified failure, show how far it travels, and establish what evidence would be needed to contain and replay it.
Campaign scope, target authorization, and explicit stop conditions would define the test—not ambient permission to attack.
The research model follows state, dependencies, decisions, and downstream artifacts without claiming universal observability.
A defensible answer requires comparable conditions, preserved evidence, and a clear distinction between absence of recurrence and proof of safety.
Demon Core is organized publicly as a research sequence rather than a list of finished features. Implementation detail remains deliberately bounded until it can be supported.
Core state / Approaching criticality
The failure is no longer isolated. At this point the interface becomes quieter: the important question is no longer whether an anomaly appeared, but what crossed the containment boundary with it.
STATE MODEL // PROPAGATION UNDER REVIEWCampaign family / Persistent influence
The original attack is over. The question is whether it left something behind.
Possession is the Demon Core campaign model for influence that persists after the initiating interaction—dormant, conditional, capable of changing behavior or connected state, and subject to remediation and replay. The sequence below is illustrative, not a production validation.
A credible adversarial program would need a reviewable chain from authorization through observed behavior, propagation hypothesis, containment action, remediation, and replay. Demon Core’s public interface does not substitute for those artifacts.
Defensible run model
Run IDs, evidence hashes, and replay states are shown here as the intended information architecture. No public sample is represented as a completed Demon Core result.
Restricted node detected
Some failures don’t stay where they started.
Restricted // Concept in developmentContainment state / Closed
Demon Core returns to GhostFrame Studios with the boundary, evidence, and uncertainty preserved.
Exit to GhostFrame Studios