Pranav Bhave
Public record — every technical claim bound in the ledger Registry v0.2 · 8 claims CI prosecution: weekly + every push

AI assurance research · statistical bounds · provenance systems

PranavBhave

I build research software that exposes what an AI-assurance claim establishes, what it assumes, and where it must stop.

Two guardrails each fail 10% of the time. How often do they fail together? The common answer is 1%. The evidence permits anywhere from 0% to 10% — multiplying the two rates quietly chose one world out of many, and never said so.

Bounds that admit unknown dependence. Receipts that prove bytes rather than safety. Claims that return for review when their evidence changes.

Audited twice · corrected in public · prosecuted weekly by its own CI

Penn State — B.S. CS ’26 Cybersecurity minor AWS CCP + AI Practitioner Philadelphia, PA
Pranav Bhave on a sunlit lawn in a navy polo and sunglasses, smiling, chin resting on his hand
Fig. 01 — subject · palette source
Two 10 percent failure rates permit anywhere from 0 to 10 percent joint failure A rectangle of area one represents the population. Two shaded strips each cover ten percent of it, one per guardrail. Their overlap is the probability both fail on the same input. Across the frames the overlap sweeps from zero to ten percent while neither individual rate ever changes. A vertical scale marks where each overlap falls between 0 and 10 percent, with a dashed mark at 1 percent — the single value that assuming independence selects. The population — area = 1 10% upper witness 0% lower witness 1% — what independence picks π(q) = (0.80, 0.10, 0.10, 0.00) · P(A) = P(B) = 10% in every frame0%π(q) = (0.81, 0.09, 0.09, 0.01) · P(A) = P(B) = 10% in every frame1%π(q) = (0.82, 0.08, 0.08, 0.02) · P(A) = P(B) = 10% in every frame2%π(q) = (0.83, 0.07, 0.07, 0.03) · P(A) = P(B) = 10% in every frame3%π(q) = (0.84, 0.06, 0.06, 0.04) · P(A) = P(B) = 10% in every frame4%π(q) = (0.85, 0.05, 0.05, 0.05) · P(A) = P(B) = 10% in every frame5%π(q) = (0.86, 0.04, 0.04, 0.06) · P(A) = P(B) = 10% in every frame6%π(q) = (0.87, 0.03, 0.03, 0.07) · P(A) = P(B) = 10% in every frame7%π(q) = (0.88, 0.02, 0.02, 0.08) · P(A) = P(B) = 10% in every frame8%π(q) = (0.89, 0.01, 0.01, 0.09) · P(A) = P(B) = 10% in every frame9%π(q) = (0.90, 0.00, 0.00, 0.10) · P(A) = P(B) = 10% in every frame10%
Fig. 02 — the same two scores, every world they permit. Both guardrails fail 10% of the time in every frame. Only their overlap moves. Multiplying the two rates selects one frame out of all of them and reports it as the answer. The full argument →

Selected work

Discipline, scoped: evidence markers apply to the technical project claims below; biographical facts are owner-attested unless linked. Chips with a solid dot open public evidence. Attested means stated on my responsibility, dated, with no public artifact yet — provenance, not proof. Exact bindings — commit SHAs, executable review triggers, non-claims — live in the evidence ledger, which is generated from the registry and drift-checked in CI.

Research framework · Python · MIT · 2025 — present

CC-Framework

Treats composed-guardrail failure as a partial-identification problem: individual rail failure rates are known, their joint dependence is not. Given marginal evidence and declared dependence assumptions, it computes sharp Fréchet–Hoeffding bounds on stacked-system failure and records the boundary of the resulting claim — claim envelopes, evidence roles, Merkle-logged receipts, decay semantics. Its flagship computation is re-reproduced from a clean clone by this site's CI, weekly.

S2 Lab, Penn State · verification research · in development

Ghost-Ark

A verifier and measurement harness for the provenance limits of AI-governance receipts. Its research claim: a receipt identifies an execution only up to the kernel of its canonicalizer — so receipt soundness does not persist over time even when the receipt system never changes. Ghost-Ark makes canonicalization collisions, evidence resolution, and receipt non-claims executable rather than implicit.

Non-claim — a verifying receipt does not establish that the governed action was safe, authorized, or semantically correct.

Media provenance · AWS Nitro Enclaves · early stage

Assay

An early-stage experiment in enclave-attested media processing: which processing and provenance claims can a verifier actually derive from Nitro Enclave attestation — and which can it not. The epistemic boundary is the project. Private while the answers are unsettled; public artifacts when they can stand behind themselves.

Attested · 2026-08 — stated on my responsibility; no public artifact linked yet
Ghost Visualizer A seven-scene visual essay, “Why AI Safety Scores Lie”: identical marginal guardrail scores hiding shared misses, with computed bounds, endpoint witnesses, and an inspectable receipt object. Runs locally; no hosted deployment yet.
Inspect source ↗
GCE — Guardrail Composability Explorer MVP demo built for AI-285: toggle guardrails and watch composed behavior diverge from intuition.
Inspect GCE source ↗

The five-card discipline

One experimental protocol — E₁ — not a universal grammar. It fits controlled tests; theorems, historical claims, and calibration problems need other test designs. The general form is the claim envelope, below.

Claim

What I say the system does. Named first, in writing.

Falsifier

The observation that would end the claim. If none exists, neither does the claim.

Control

The comparison that could embarrass it — run on purpose.

Non-claim

What this evidence will never support, stated before anyone asks.

Result

Two distributions sharing every singleton and pairwise moment; three-way failure of 0% in one and 25% in the other. Measuring every pair does not identify the triple.

Supported within scope — controlled synthetic · decision: Narrow

Lock the first four before the result slot fills, then let the result disagree. The result above is E₁'s: it survived, and it narrowed the claim rather than widening it. A story can start a question. It cannot finish an answer. Untested is not inconclusive: inconclusive means evidence arrived and failed to discriminate; untested means the world has not answered yet. This page keeps the two apart — and keeps its own rules scoped, as declared above.

Candidate C₁

The claim envelope

1 · Proposition

What exactly is asserted.

2 · Scope

Where it holds, and under which assumptions.

3 · Support

The evidence that bears on it, bound to immutable artifacts.

4 · Challenge

What would reduce confidence or force revision.

5 · Test design

Control, comparator, calibration, proof, benchmark, or adversary.

6 · Status

Untested · supported within scope · partial · inconclusive · contradicted.

7 · Boundary

What remains unestablished — the non-claims.

8 · Freshness

When, and on what trigger, it must be re-examined.

The evidence ledger is generated from a registry that implements these fields — propositions, separated provenance and status dimensions, immutable bindings, executable review triggers that watch the bound evidence upstream, freshness windows, non-claims. Where a trigger can't be executed by CI, the ledger says manual, plainly.

Research & training

Aug — Dec 2025 · Penn State

Independent research — LLM safety guardrail composition

Reinforcement, interference, and dependence-driven failure in composed LLM safety systems, via probabilistic bounds and copula-family reasoning. Supervised by Dr. Peng Liu (IST 496). CC-Framework is the primary deliverable.

Jan — May 2025 · Penn State

Research assistant — logic & verification tooling

Python CNF-conversion tooling for SAT-solving workflows, and evaluation of LLM-assisted formalization of natural-language logic: translation reliability, ambiguity handling, verification-readiness.

May 2026

Pennsylvania State University

B.S. Computer Science, minor in Cybersecurity. Coursework: computer security, operating systems, algorithms, statistical inference, theory of computation.

Certified

AWS — Cloud Practitioner · AI Practitioner

Solutions Architect Associate (SAA-C03) and Security — Specialty in progress.

Certifications are owner-attested here: verification IDs are available on request rather than published.

Contact

Have a claim worth checking?
Bring it — I’ll bring the falsifier.

I’m looking for research, engineering, and independent consulting work where statistical assurance, provenance, and claim governance matter.