Skip to content
Back to writing
· 13 min read

Before GPU inference, prove the inputs

How VoxelScope used one-shot custody and bounded NIfTI checks to admit one brain MRI source without authorizing inference.

VoxelScope acquired one approved OpenNeuro source once. All eight pinned objects matched their expected identities. Five medical files passed the bounded NIfTI structure, finite-value, mask-domain, and exact cross-file geometry gates.

The terminal result was STRUCTURAL GO.

That verdict made the source next-stage eligible. It did not authorize model extraction, model load, inference, GPU or MPS work, cloud use, or spend.

Evidence boundary: this is a research-only input-admission study for one outcome-blind source. It asks whether one approved acquisition can pass bounded file, NIfTI structure, and geometry gates, then whether a sanitized structural verdict can pass a separate privacy release. It does not measure segmentation quality, diagnostic value, clinical safety, patient validity, or GPU performance.

The GPU had nothing to prove until the inputs did.

Inference begins before the first kernel

An inference command looks like the start of an experiment. In a controlled run, it is near the middle.

Before a model sees a tensor, someone has already chosen the model archive, source revision, subject, modalities, file order, conversion boundary, and stop rules. Each choice can change the meaning of the run. A fast kernel cannot repair a swapped channel. A valid NIfTI header cannot authorize a private file for release. Four arrays with matching dimensions can still describe different physical grids.

VoxelScope treats those facts as admission gates. The run advances only when the evidence for the current gate is complete. A failure stops the sequence and preserves a bounded public status. Missing evidence is not converted into a pass.

That design separates four decisions that are often collapsed:

  1. Can these exact bytes be acquired under the approved one-shot rule?
  2. Do the acquired files satisfy the declared structural and cross-file geometry predicates?
  3. Can the structural verdict pass a separate privacy release without exposing medical evidence?
  4. Does a later authority permit inference?

A structural GO answers only the second question. It makes a later stage eligible. It does not start the GPU. This milestone cannot authorize inference.

What was fixed before acquisition

The protocol pinned the official OpenNeuro source ds007045:2.0.1. It did not search for a subject after viewing images or labels. An outcome-blind rule selected the lexicographically first eligible subject from 363 complete subjects using tree metadata only.

The input contract named four direct N4-only modality roles in model order:

  1. T1c
  2. T1
  3. T2
  4. FLAIR

An aligned mask was required beside those four modalities. The approved acquisition plan contains eight artifacts: five medical inputs and three public dataset support artifacts. The source-published medical payload for the five medical files totaled 24,219,725 bytes. That number is a source-side transfer expectation, not a claim about decoded arrays or clinical content.

Model custody was separate. The private MONAI archive was hash-verified without extraction or loading. Source identity did not authorize model execution, and model custody did not authorize medical acquisition.

The label domains also stayed separate. Source labels use 0/1/2/3. The MONAI output contract uses 0/1/2/4. The numeric 3 -> 4 mapping was identified but not authorized. Broader semantic equivalence remained unresolved. A geometry pass could not silently settle that question.

At the end of milestone 3, acquisition was blocked. No medical bytes had been acquired. The model had not been loaded. Inference, GPU work, cloud use, and spend had not begun. Milestone 4 then consumed one approval for one private acquisition followed by bounded NIfTI structural and geometry checks. The result was not predeclared.

STRUCTURAL GO branch is highlighted after eight acquired artifacts, five medical files, and four geometry comparisons passed the VoxelScope admission gates. The branch then passes a separate privacy release. Inference authorization remains not authorized.
Figure 1. The STRUCTURAL GO branch is highlighted from the verified public values. Privacy release passed after the structural terminal state. Inference remains unauthorized.

Source note. This diagram is generated locally from a reduced public article-values file. That file permits only closed status values, bounded counts, and a commit-pinned reference to a separate VoxelScope public summary. The production gate recomputes that summary's SHA-256 from vendored bytes. It rejects private paths, receipts, raw headers, real shapes, affines, zooms, dtypes, label sets, locally derived private hashes, and medical bytes.

The decision table

The gate table is an execution boundary, not a progress graphic. The first four milestone checks produced the structural terminal state. Privacy release ran after that branch and controlled publication, not structure. Not authorized is stronger than saying the GPU did not start because it records the permission state that controls whether it may start.

Gate Verified status Required evidence Failure action
IdentityVerifiedPinned protocol, official source version, private model archive custodyStop on source, model, or protocol drift
AuthorizationAuthorizedOne approved private acquisition, one selected source, frozen stop rulesStop before transport
Transport/contentVerifiedContent identity for all eight approved acquisition artifactsStop before parsing
File setVerifiedExactly five medical inputs and three public support artifacts, with no extrasStop before loading arrays
NIfTI structureVerifiedBounded structure, finite-value, and mask-domain checksStop before cross-file comparison
GeometryVerifiedFour exact cross-file comparisons under the frozen geometry contractStop before semantic review
Privacy/releaseVerifiedIndependent release after structural GO, with sanitized status and counts onlyReject publication
Inference authorizationNot authorizedOutside milestone 4, regardless of structural terminal stateNo model load or GPU inference

Milestone 4 outcome

The sanitized public summary records 8 verified acquired artifacts, 5 NIfTI-validated medical files, 4 completed geometry comparisons, and 0 failed structural gates.

The approved no-retry acquisition completed once. All eight objects matched their pinned identities. The five medical files passed the declared NIfTI structure and finite-value checks. The mask passed its bounded domain check. Four exact comparisons established the frozen cross-file geometry predicate.

The structural result was STRUCTURAL GO. No structural gate failed.

The separate privacy release then approved the reduced public summary. It withheld private paths, acquisition receipts, real shapes, affines, spacing, orientation, dtypes, label values, nonzero counts, private-file hashes, and header text.

The terminal result describes the validator, not the anatomy. It is not a quality score. inference_authorized=false.

What the eight verified artifacts mean

The acquisition count is eight because the closed plan covered more than the five medical inputs.

Five artifacts carried the four model channels and the aligned mask. Three artifacts carried public dataset support material. The validator did not discover this set after download. Each object already had an approved role, source identity, destination class, size, and content identity in the acquisition plan.

The one approved acquisition used that closed list. It did not retry a mismatch, replace a failed object, or search for another subject. The result therefore binds one execution to one preregistered source choice.

Identity came first. All eight acquired objects matched the expected content. That result allowed the five medical files to enter bounded structural validation. The other three objects stayed outside the medical-file count.

The NIfTI gate then counted five validated medical files. It checked the declared container and array properties, finite values, and the mask domain. The public summary exposes only that the checks passed and how many files reached the gate. It does not expose the values that the private validator read.

Geometry was the last structural gate. Four comparisons bound T1, T2, and FLAIR plus the mask to the T1c reference under the exact frozen predicate. The public count is four because there were four non-reference files to compare. It is not a registration score.

This ordering gives each number one scope:

  • 8 is the verified acquired artifact count;
  • 5 is the NIfTI-validated medical file count;
  • 4 is the completed cross-file geometry comparison count; and
  • 0 is the failed structural gate count.

Those counts explain the GO without reproducing the private evidence that produced it.

Aligned is a structural predicate

The word aligned invites a stronger claim than the validator can support.

For this protocol, alignment is a testable relation among files. The validator checks the exact cross-file geometry fields named before acquisition. Equality can show that the files describe the same sampled grid under that contract. It cannot show that anatomy is registered well, that a lesion is represented correctly, or that the image is suitable for a clinical task.

This distinction matters because NIfTI files carry both arrays and spatial descriptions. Matching array dimensions alone is weak. Two files can have the same dimensions while their voxel-to-world transforms differ. Matching geometry is stronger, but it is still structural evidence.

VoxelScope therefore uses a narrow sentence:

The files satisfy the frozen cross-file geometry predicate.

It does not substitute:

The scans are anatomically correct.

The second sentence needs evidence this study does not collect.

The privacy boundary is a separate publication gate

The private run inspected facts that should never enter a public article repository. The public export therefore worked as a reduction step, not a copy step. It ran after the structural terminal state.

It may retain:

  • closed gate statuses;
  • aggregate counts needed to bind the article;
  • the terminal structural status;
  • the fixed fact that inference remains unauthorized;
  • a commit-pinned URL and SHA-256 digest for a separate reviewed VoxelScope public summary; and
  • the already published source identity and source-side byte count.

It must reject:

  • subject identifiers and private filenames;
  • local paths, download receipts, and operator tokens;
  • NIfTI headers or real shapes, affines, zooms, and dtypes;
  • discovered label sets or voxel values;
  • locally derived hashes of private medical files; and
  • the medical files themselves.

That restriction makes the article less reconstructive by design. A reader can audit the state machine and its public claims without receiving a shadow copy of the medical evidence.

Reproduce the gates without medical data

VoxelScope ships deterministic synthetic NIfTI fixtures for both accepted and refused parser paths. Its public verifier checks the closed milestone bundle, and its focused tests exercise malformed gzip, invalid headers, bounded decompression, non-finite values, mask-domain failures, geometry mismatches, transport identity, and one-shot replay refusal:

uv run voxelscope milestone4-public verify --bundle research/milestone-4
uv run pytest tests/test_one_volume_custody.py -q

The portfolio has a separate publication gate:

pnpm test:voxelscope-article
pnpm check:voxelscope-article-production

Those tests bind the prose, decision table, generated SVG, counts, terminal status, privacy release, and immutable VoxelScope summary. They reject unknown states, extra fields, missing provenance, private or medical material, and generated-asset drift. The Python fixtures reproduce the structural validator without patient data. The TypeScript fixtures prove that the article cannot publish a stronger claim than the sanitized result.

What this article may claim

The allowed claims are exact:

  • the source, model custody boundary, selection rule, channel order, source-published payload count, and label-domain mismatch were fixed before acquisition;
  • milestone 3 stopped before medical acquisition, model load, inference, GPU use, cloud use, or spend;
  • milestone 4 completed one approved private acquisition and bounded structural checks;
  • the verified structural GO makes a later stage eligible;
  • the structural result passed a separate privacy release before publication; and
  • milestone 4 requires inference_authorized=false.

The forbidden claims are just as exact:

  • no segmentation accuracy, quality, or usefulness result;
  • no diagnosis, clinical safety, or patient-specific claim;
  • no anatomical correctness claim from structural alignment;
  • no GPU latency, throughput, memory, utilization, power, or cost result;
  • no semantic equivalence between source labels and MONAI outputs; and
  • no claim that a structural GO or privacy release authorizes inference.

A reusable admission checklist

  1. Pin custody. Record the model archive, source revision, protocol revision, and verifier version before execution.
  2. Select without outcomes. Freeze the eligibility rule and choose the source without inspecting the result-bearing content.
  3. Name every role. Bind each input channel to one declared model position. Reject duplicates, substitutions, and extras.
  4. Separate authorization. Treat acquisition, validation, inference, and publication as different permissions.
  5. Verify transport. Check the closed file set and content identity before parsing.
  6. Validate structure. Reject malformed containers, unsupported structures, and values outside the frozen contract.
  7. Compare geometry exactly. Use the declared cross-file predicate. Do not replace it with dimensions alone.
  8. Keep semantics explicit. A numeric mapping is not authorized because it looks obvious.
  9. Reduce after the terminal state. Export statuses and counts from either structural branch. Do not publish raw evidence by default.
  10. Stop on missing evidence. not_run and not_authorized are valid states. Neither means pass.
  11. Bind prose to data. Generate figures from the same reduced values and test the article table against them.
  12. Keep milestone permissions fixed. This milestone can validate structure and release a sanitized result. It cannot authorize inference.

Limitations

This study covers one official source version, one outcome-blind selection rule, one private model archive, and one frozen validator. Its public evidence is intentionally reduced. It cannot support an independent reconstruction of the private acquisition or a claim about image content.

The validator can establish its declared file and geometry predicates. It cannot establish clinical meaning.

Conclusion

An inference pipeline is easier to trust when failure has somewhere precise to happen.

Identity can fail before authorization. Transport can fail before parsing. Structure can fail before geometry. Geometry can produce a structural refusal. Privacy can block publication after either structural terminal state. And inference must remain unauthorized after every milestone 4 check passes.

That sequence does not make the eventual model result better. It makes the conditions for obtaining one inspectable.

The GPU had nothing to prove until the inputs did.


Evidence: VoxelScope repository · VoxelScope PR #4 · Exact merge commit f4ec1ef · Public milestone 4 summary · Public summary SHA-256 1f483f8beb775d5974eba167febe5eae00e1c10571e50948413646618f5a2590 · Public bundle root SHA-256 d3fdca9d8e5dccfbe5b1e755ca1a9fa782dd986e1fd00c5caa1997986a1c20df

Support independent writing

If this post was useful, consider supporting my open source work and independent writing.

Siddhant Khare
Agentic Engineering Guide Resume