Skip to main content
Flagship Research

AnubisX Framework

A Formal Framework for Behavioral Digital Attribution

16 Formal Axioms

Six groups of logically necessary axioms governing uncertainty, behavior, identity, attribution, evidence, and reasoning.

292 Mathematical Objects

24 categories including 10 formal spaces, 9 distance functions, 7 similarity functions, and a likelihood ratio evidence model.

37 Algorithms

Across 9 domains spanning 5 behavioral modalities: stylometric, chrono-profiling, terminal profiling, network analysis, and media forensics.

4-Tier Validation

31 pre-specified acceptance criteria across unit, component, system, and operational validation tiers with a priori thresholds.

Open Source

Released under CC BY 4.0 with MIT-licensed prototype implementation. DOI: 10.5281/zenodo.21393392.

Cognitive Centroid Theory

A formal model of behavioral identity as an asymptotic attractor in feature space, with four hypothesized formal properties.

Scientific Motivation

Digital attribution \u2014 determining the human source of digital actions \u2014 is a foundational requirement across cybersecurity, digital forensics, and counter-fraud. Current methods rely on technical identifiers (IP addresses, device fingerprints) that sophisticated adversaries can spoof or eliminate. The AnubisX Framework addresses this gap by shifting the analytical focus from transient technical identifiers to persistent human behavioral patterns.

Research Vision

The framework provides: (a) an axiomatic system of 16 axioms governing attribution reasoning; (b) Cognitive Centroid theory \u2014 a formal model of behavioral identity as an asymptotic attractor in feature space; (c) a mathematical framework of 292 defined objects including a likelihood ratio evidence model; (d) 37 specified algorithms spanning five behavioral modalities; and (e) a four-tier validation infrastructure with 31 pre-specified acceptance criteria with thresholds defined a priori.

Six-Layer Architecture

The framework implements a six-layer architecture with a six-stage pipeline supporting identification, verification, and forensic comparison workflows.

1

Data Ingestion

Implemented

Data acquisition through platform-specific adapters

2

Feature Extraction

Implemented

Modality-specific feature computation with normalization

3

Profile Construction

Implemented

Fingerprint generation with quality assessment

4

Comparison

Implemented

Similarity computation using configured metrics

5

Evidence Evaluation

Proposed

Score calibration and likelihood ratio computation

6

Decision

Proposed

Threshold-based classification with confidence quantification

Behavioral Modalities

Five behavioral modalities span the framework, each with specified algorithms and implementation status.

Stylometric

Prototype Validated

Linguistic style analysis, authorship attribution, writeprints

ALG-001 to ALG-004

Chrono-Profiling

Specified

Temporal behavior patterns, activity rhythms, posting schedules

ALG-005 to ALG-008

Terminal Profiling

Specified

Command-line patterns, shell behavior, tool usage signatures

ALG-009 to ALG-012

Network Analysis

Specified

Social graph analysis, interaction patterns, community detection

ALG-013 to ALG-016

Media Forensics

Specified

Image metadata, editing artifacts, content analysis

ALG-017 to ALG-020

Open Science Commitment

The AnubisX Framework is developed under full open science principles. All components \u2014 axioms, mathematical objects, algorithms, validation criteria, and limitation documentation \u2014 are publicly available for independent validation, replication, and community contribution. The framework explicitly documents all limitations, failure modes, and validation status, establishing a new standard of transparency in behavioral attribution research.

Version 3.0.0 \u2014 Scientific Re-Architecture \u00b7 July 2026 \u00b7 License: CC BY 4.0