Skip to content

feat(ml-worker): add disposition corpus export census - #3297

Merged
Xore merged 8 commits into
mainfrom
issue-3295-coder
Sep 25, 2026
Merged

Xore merged 8 commits into
mainfrom
issue-3295-coder

Conversation

@Xore

@Xore Xore commented Sep 25, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • add a read-only ml-anomalies export/census command with one point-in-time snapshot for status totals and closed dispositions
  • redact free-text disposition reasons by default, write atomic NDJSON/JSON outputs with SHA-256 metadata, and report explicit precision-only and calibration gates
  • document the alert-population limitation: below-threshold traffic is not persisted, so this corpus cannot measure deployment recall
  • add fixture tests for denominators, open/legacy exclusion, class balance, redaction, missing fields, and safe Elasticsearch failures

Validation

  • python3 -m pytest ml-worker/tests/test_disposition_corpus.py -q — 11 passed
  • python3 -m pytest ml-worker/tests/ -q — 319 passed
  • local fixture smoke run — printed the precision-only banner, exported only closed labels, redacted reasons, and verified the report digest
  • read-only live Elasticsearch census through the deployed worker (ephemeral snapshot) — reached ES 9.5.3; 7,675,439 alerts, all open, zero labels, time range 2026-09-05T22:00:04.700Z–2026-09-25T07:12:42.167Z

Closes #3295

@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@Xore

Xore commented Sep 25, 2026

Copy link
Copy Markdown
Owner Author

The two failing checks on this PR are pre-existing breakage on main, not caused by this diff. This branch touches no backend or container files.

Every PR running the backend-service job is red until that is fixed. Not fixed here to keep this diff to its own scope.

Export closed operator dispositions through one read-only Elasticsearch PIT, redact free-text reasons by default, and report a hashed census with explicit precision-only and calibration gates. Add fixture coverage for denominators, missing fields, class balance, and safe transport errors. Closes #3295
Accept Elasticsearch 9 date-stat bounds returned alongside the aggregation and preserve the exact ISO range in the census.
Handle both Elasticsearch 8 nested stats and Elasticsearch 9 flattened date-stat responses so the live census reports its actual alert window.
Ensure live census reports fixed open and closed status buckets even when Elasticsearch omits zero-count terms.
Clarify that disposition reasons are redacted by default and only exposed through an explicit operator opt-in.
Return the atomic report digest consistently with the existing benchmark convention and document the independent report-file hash.
Keep model grouping and missing-field census honest when every detector abstained but the model_scores object is present.
Compute the census report hash over canonical content with the digest field excluded, store it in the report, and print it with the snapshot digest. Add coverage and usage documentation for the report artifact contract.
@Xore
Xore merged commit 55d30ab into main Sep 25, 2026
106 of 107 checks passed
@Xore
Xore deleted the issue-3295-coder branch September 25, 2026 13:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ml: export and census the queryable operator-disposition corpus for calibration

1 participant