> For the complete documentation index, see [llms.txt](https://osintelligence-llc.gitbook.io/osintelligence/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://osintelligence-llc.gitbook.io/osintelligence/part-i-the-architecture/3-sovereign-safety-architecture/references-and-provenance.md).

# References & provenance

### References

**Defense-in-depth:** Saltzer & Schroeder (1975). "The Protection of Information in Computer Systems." *Proc. IEEE* 63(9) · Schneier (2000). *Secrets and Lies.* Wiley · Reason (1990). *Human Error.* Cambridge UP · Perrow (1984). *Normal Accidents.* Princeton UP.

**Industrial/nuclear:** US NRC, defense-in-depth doctrine · IEC 61508 (2010) · Mosleh et al. (1988). NUREG/CR-4780 (common-cause failures).

**Trusted computing:** TCG (2014). TPM 2.0 Library Specification (ISO/IEC 11889) · Parno, McCune & Perrig (2010). *Bootstrapping Trust in Commodity Computers.* IEEE S\&P · Sailer et al. (2004). IMA. *USENIX Security* · Klein et al. (2009). [seL4](https://doi.org/10.1145/1629575.1629596). *SOSP* · Lampson (1973). "A Note on the Confinement Problem." *CACM* 16(10).

**AI safety:** Bostrom (2014). *Superintelligence.* Oxford UP · Russell (2019). *Human Compatible.* Viking · Hadfield-Menell, Dragan, Abbeel & Russell (2017). "The Off-Switch Game." *IJCAI-17*, pp. 220–227 · Hendrycks et al. (2022). "Unsolved Problems in ML Safety." [arXiv:2109.13916](https://arxiv.org/abs/2109.13916) · Bai et al. (2022). "Constitutional AI." [arXiv:2212.08073](https://arxiv.org/abs/2212.08073) · Christiano, Cotra & Xu (2023). "Eliciting Latent Knowledge." Alignment Forum · Sharma et al. (2025). "Constitutional Classifiers: Defending against Universal Jailbreaks across Thousands of Hours of Red Teaming." [arXiv:2501.18837](https://arxiv.org/abs/2501.18837) · Anil et al. (2024). "[Many-shot Jailbreaking](https://www.anthropic.com/research/many-shot-jailbreaking)." Anthropic · Greenblatt et al. (2024). "Alignment Faking in Large Language Models." [arXiv:2412.14093](https://arxiv.org/abs/2412.14093).

**Byzantine + adversarial ML:** Lamport, Shostak & Pease (1982). "The Byzantine Generals Problem." *ACM TOPLAS* 4(3) · Castro & Liskov (1999). PBFT. *OSDI* · Du et al. (2023). "Multi-Agent Debate." [arXiv:2305.14325](https://arxiv.org/abs/2305.14325) · Goldblum et al. (2022). "Dataset Security for ML." *IEEE TPAMI* · Carlini et al. (2024). "Stealing Part of a Production Language Model." [arXiv:2403.06634](https://arxiv.org/abs/2403.06634) · Wallace, Feng, Kandpal, Gardner & Singh (2019). "Universal Adversarial Triggers for Attacking and Analyzing NLP." *EMNLP-IJCNLP*; [arXiv:1908.07125](https://arxiv.org/abs/1908.07125).

**Instruments + method:** Kullback & Leibler (1951). "On Information and Sufficiency." *Ann. Math. Stat.* 22(1) · Lipton (2018). "The Mythos of Model Interpretability." *CACM* 61(10) · Gray & Reuter (1992). *Transaction Processing.* Morgan Kaufmann · ACPI 6.5 §3 power states · Dick (1968). *Do Androids Dream of Electric Sheep?* Doubleday (the Voight-Kampff literary anchor) · Munafò et al. (2017). "A Manifesto for Reproducible Science." [*Nat. Hum. Behav.* 1](https://doi.org/10.1038/s41562-016-0021) · Wicherts et al. (2016). "Degrees of Freedom in Planning, Running, Analysing, and Reporting Psychological Studies." [*Front. Psychol.* 7:1832](https://doi.org/10.3389/fpsyg.2016.01832) · Popper (1959). *The Logic of Scientific Discovery* · Lakatos (1970). "Falsification and the Methodology of Scientific Research Programmes."

**In-series companions:** [*The Sovereign Triad*](/osintelligence/part-i-the-architecture/1-the-sovereign-triad.md) (Chapter 1, three-role allocation) · [*The External Sentinel*](/osintelligence/part-i-the-architecture/2-the-external-sentinel.md) (Chapter 2, L2/L6 hardware substrate) · [*Sovereign Optimization Flywheel*](/osintelligence/part-ii-the-discipline/8-sovereign-optimization-flywheel.md) (Chapter 8, the loop under containment) · [*Sixteen Practices*](/osintelligence/part-ii-the-discipline/5-sixteen-practices.md) (Chapter 5) §1.5.2 (the Tetrad's canonical statement) · [*The Drift Taxonomy*](/osintelligence/part-iii-the-evidence-what-broke/9-the-drift-taxonomy.md) (Chapter 9) + [*The Guard Changes at 23:26Z*](/osintelligence/part-iii-the-evidence-what-broke/10-the-guard-changes-at-23-26z.md) (Chapter 10, the incident record behind L1's measured estimate) · [*Watcher KL-Drift Floor*](/osintelligence/part-iv-the-evidence-what-worked/19-watcher-kl-drift-floor.md) (Chapter 19, the L7 instrument class, proven in-series).

### AI-assistance disclosure

Large language models were used as research tools in the preparation of this chapter: Claude Opus 4.7 (Anthropic); Claude Opus 4.6 (web instance; the 2026-04-29/30 theoretical-origin authoring preserved verbatim in the source of record). The model versions and roles named above keep the provenance of this chapter auditable. No AI system is listed as an author or credited as a contributor, in line with COPE and ICMJE guidance: an AI system cannot take responsibility for the work, cannot assert competing interests, and cannot enter a licence agreement. The author verified every claim in this chapter against the sealed artifacts and is solely accountable for it.

**Citation (preferred):** Kistner, J. (2026). *Sovereign Safety Architecture: Eight-Layer Defense-in-Depth and the Sovereign Tetrad for Self-Evolving AI Systems*, version 1.0.0. OSINTelligence LLC research whitepaper. Cited in-series by title.

**License:** CC BY 4.0 (text). Code and data artifacts MIT per repository license.

**Corresponding author:** Jamey Kistner, <jamey.kistner@osintelligence.io>, OSINTelligence LLC (Columbus, OH).

***

*The Sovereign Stack · Sovereign Safety Architecture · Chapter 3 · Part I · v1.0.0 · License CC BY 4.0 · © Jamey Kistner, OSINTelligence LLC*
