CFSE methodology / Version 1.0.0

Turn security questions into inspectable knowledge.

CFSE is a structured method for modeling a system, stating what must hold, testing falsifiable scenarios, and preserving the evidence that changes what is known.

Author
Aditya Gupta
Version
1.0.0
Published
13 August 2026
Status
Public technical methodology

The method

A claim must survive the chain.

  1. 01World modelModel the system
  2. 02InvariantState what must hold
  3. 03ScenarioForm a falsifiable question
  4. 04ExplorationRun the comparison
  5. 05TracePreserve the evidence
  6. 06FindingChange what is known

Validity conditions

What makes a conclusion CFSE-valid?

  1. 01The system and its trust boundaries are explicit enough to challenge.
  2. 02Security expectations are written as invariants rather than implied requirements.
  3. 03A scenario asks one falsifiable question and declares what would count as enforcement or violation.
  4. 04An exploration compares a legitimate baseline with a controlled manipulation.
  5. 05The trace preserves what happened, in order, with the evidence needed to inspect the verdict.
  6. 06The finding states only what the evidence supports and feeds the result back into the model.

Scope

What CFSE governs

CFSE governs how security knowledge is structured, challenged, evidenced, and updated. The normative artifact schemas, grammar, lifecycle, and traceability rules live in the specification.

Read the normative specification →

Specialized method

Consequence Paths specializes the method

CFSE Consequence Paths specializes one part of the work: tracing a documented vulnerability mechanism through causal steps to distinct terminal consequences, while preserving source, inference, and operational-assumption boundaries.

Read the Consequence Paths method ↗

Publication boundary

What this publication establishes

This is a versioned public technical methodology. It is not a peer-reviewed paper, is not currently published on arXiv, and does not claim independent validation, empirical accuracy, or complete vulnerability coverage.

Authorship and citation

Aditya Gupta

Author of the CFSE methodology.

Suggested citation

Gupta, Aditya. “CFSE: Concept Flow Scenarios Explorations: A Methodology for Evidence-Linked Security Research.” CFSE.ai, version 1.0.0, 2026. https://cfse.ai/methodology