Build a security model that can be challenged.
Learn how CFSE moves from system structure to falsifiable hypotheses, controlled exploration, and evidence-backed conclusions.
Follow the methodologyA methodology for security epistemology
CFSE connects system structure, security invariants, falsifiable hypotheses, and execution evidence—so every conclusion can be inspected, challenged, and reused.
The artifact chain is not paperwork. It is how a security claim keeps its provenance.
Two ways in
Learn how CFSE moves from system structure to falsifiable hypotheses, controlled exploration, and evidence-backed conclusions.
Follow the methodologyA CFSE retrospective applies the full artifact chain — world model, invariants, scenarios, traces, findings — to a publicly reported Unitree Go2 vulnerability. Original discovery by boschko.ca. Methodology demonstration by us.
Open the CFSE retrospectiveThe method
Each step changes what the next step can legitimately claim. Skip the model, and the hypothesis floats. Skip the trace, and the conclusion loses its evidence.
Name the actors, trust boundaries, interfaces, state, and legitimate flows before deciding where the vulnerability must be.
Concepts · Entry Points · Interactions · FlowsTurn security expectations into explicit invariants whose state can change as evidence arrives.
Invariants · PredicatesAsk one bounded question that targets a specific invariant and declares what enforcement or violation would look like.
Scenarios · GeneratorsCompare a legitimate baseline with the manipulated path, then retain the ordered observations that support the verdict.
Explorations · TracesConvert what the experiment changed into a bounded finding, a repaired invariant, and regression work that survives this target.
Findings · Patches · Updated invariantsCFSE Retrospective / Unitree Go2
We took a publicly reported exploit and modeled it through CFSE — Concepts, Entry Points, Invariants, Scenarios, Traces, Findings. Not our discovery. Our methodology, demonstrated.
See the retrospectiveThe published report describes the tamper-to-root sequence.
We reconstructed how CFSE would have represented the sequence.
CFSE makes authority handoffs and evidence boundaries inspectable.
The current corpus has no live Go2 target or faithful harness.
Precise underneath
Every object has one job. Together they preserve the path from system understanding to remediation without confusing hypotheses for evidence.
Spec 1.0.0C · EP · I · FWhat exists, and how does authority move?
INVWhat must remain true?
SWhat specific failure can we falsify?
EHow do baseline and attack paths differ?
TWhat happened, in what order?
FDWhat conclusion does the evidence support?
PATCHHow is the failure repaired and prevented elsewhere?
Put it to work
Learn the method in progressive, practitioner-facing order.
Inspect normative artifact schemas, semantics, and traceability rules.
Build the practice through Attify programs and team delivery.
Bring CFSE into a concrete product, research target, or assurance workflow.