VoxelScope acquired one approved OpenNeuro source once. All eight pinned objects matched their expected identities. Five medical files passed the bounded NIfTI structure, finite-value, mask-domain, and exact cross-file geometry gates.
The terminal result was STRUCTURAL GO.
That verdict made the source next-stage eligible. It did not authorize model extraction, model load, inference, GPU or MPS work, cloud use, or spend.
Evidence boundary: this is a research-only input-admission study for one outcome-blind source. It asks whether one approved acquisition can pass bounded file, NIfTI structure, and geometry gates, then whether a sanitized structural verdict can pass a separate privacy release. It does not measure segmentation quality, diagnostic value, clinical safety, patient validity, or GPU performance.
The GPU had nothing to prove until the inputs did.
Inference begins before the first kernel
An inference command looks like the start of an experiment. In a controlled run, it is near the middle.
Before a model sees a tensor, someone has already chosen the model archive, source revision, subject, modalities, file order, conversion boundary, and stop rules. Each choice can change the meaning of the run. A fast kernel cannot repair a swapped channel. A valid NIfTI header cannot authorize a private file for release. Four arrays with matching dimensions can still describe different physical grids.
VoxelScope treats those facts as admission gates. The run advances only when the evidence for the current gate is complete. A failure stops the sequence and preserves a bounded public status. Missing evidence is not converted into a pass.
That design separates four decisions that are often collapsed:
- Can these exact bytes be acquired under the approved one-shot rule?
- Do the acquired files satisfy the declared structural and cross-file geometry predicates?
- Can the structural verdict pass a separate privacy release without exposing medical evidence?
- Does a later authority permit inference?
A structural GO answers only the second question. It makes a later stage eligible. It does not start the GPU. This milestone cannot authorize inference.
What was fixed before acquisition
The protocol pinned the official OpenNeuro source ds007045:2.0.1. It did not search for a subject after viewing images or labels. An outcome-blind rule selected the lexicographically first eligible subject from 363 complete subjects using tree metadata only.
The input contract named four direct N4-only modality roles in model order:
- T1c
- T1
- T2
- FLAIR
An aligned mask was required beside those four modalities. The approved acquisition plan contains eight artifacts: five medical inputs and three public dataset support artifacts. The source-published medical payload for the five medical files totaled 24,219,725 bytes. That number is a source-side transfer expectation, not a claim about decoded arrays or clinical content.
Model custody was separate. The private MONAI archive was hash-verified without extraction or loading. Source identity did not authorize model execution, and model custody did not authorize medical acquisition.
The label domains also stayed separate. Source labels use 0/1/2/3. The MONAI output contract uses 0/1/2/4. The numeric 3 -> 4 mapping was identified but not authorized. Broader semantic equivalence remained unresolved. A geometry pass could not silently settle that question.
At the end of milestone 3, acquisition was blocked. No medical bytes had been acquired. The model had not been loaded. Inference, GPU work, cloud use, and spend had not begun. Milestone 4 then consumed one approval for one private acquisition followed by bounded NIfTI structural and geometry checks. The result was not predeclared.
Source note. This diagram is generated locally from a reduced public article-values file. That file permits only closed status values, bounded counts, and a commit-pinned reference to a separate VoxelScope public summary. The production gate recomputes that summary's SHA-256 from vendored bytes. It rejects private paths, receipts, raw headers, real shapes, affines, zooms, dtypes, label sets, locally derived private hashes, and medical bytes.
The decision table
The gate table is an execution boundary, not a progress graphic. The first four milestone checks produced the structural terminal state. Privacy release ran after that branch and controlled publication, not structure. Not authorized is stronger than saying the GPU did not start because it records the permission state that controls whether it may start.
| Gate | Verified status | Required evidence | Failure action |
|---|---|---|---|
| Identity | Verified | Pinned protocol, official source version, private model archive custody | Stop on source, model, or protocol drift |
| Authorization | Authorized | One approved private acquisition, one selected source, frozen stop rules | Stop before transport |
| Transport/content | Verified | Content identity for all eight approved acquisition artifacts | Stop before parsing |
| File set | Verified | Exactly five medical inputs and three public support artifacts, with no extras | Stop before loading arrays |
| NIfTI structure | Verified | Bounded structure, finite-value, and mask-domain checks | Stop before cross-file comparison |
| Geometry | Verified | Four exact cross-file comparisons under the frozen geometry contract | Stop before semantic review |
| Privacy/release | Verified | Independent release after structural GO, with sanitized status and counts only | Reject publication |
| Inference authorization | Not authorized | Outside milestone 4, regardless of structural terminal state | No model load or GPU inference |
Milestone 4 outcome
The sanitized public summary records 8 verified acquired artifacts, 5 NIfTI-validated medical files, 4 completed geometry comparisons, and 0 failed structural gates.
The approved no-retry acquisition completed once. All eight objects matched their pinned identities. The five medical files passed the declared NIfTI structure and finite-value checks. The mask passed its bounded domain check. Four exact comparisons established the frozen cross-file geometry predicate.
The structural result was STRUCTURAL GO. No structural gate failed.
The separate privacy release then approved the reduced public summary. It withheld private paths, acquisition receipts, real shapes, affines, spacing, orientation, dtypes, label values, nonzero counts, private-file hashes, and header text.
The terminal result describes the validator, not the anatomy. It is not a quality score. inference_authorized=false.
What the eight verified artifacts mean
The acquisition count is eight because the closed plan covered more than the five medical inputs.
Five artifacts carried the four model channels and the aligned mask. Three artifacts carried public dataset support material. The validator did not discover this set after download. Each object already had an approved role, source identity, destination class, size, and content identity in the acquisition plan.
The one approved acquisition used that closed list. It did not retry a mismatch, replace a failed object, or search for another subject. The result therefore binds one execution to one preregistered source choice.
Identity came first. All eight acquired objects matched the expected content. That result allowed the five medical files to enter bounded structural validation. The other three objects stayed outside the medical-file count.
The NIfTI gate then counted five validated medical files. It checked the declared container and array properties, finite values, and the mask domain. The public summary exposes only that the checks passed and how many files reached the gate. It does not expose the values that the private validator read.
Geometry was the last structural gate. Four comparisons bound T1, T2, and FLAIR plus the mask to the T1c reference under the exact frozen predicate. The public count is four because there were four non-reference files to compare. It is not a registration score.
This ordering gives each number one scope:
8is the verified acquired artifact count;5is the NIfTI-validated medical file count;4is the completed cross-file geometry comparison count; and0is the failed structural gate count.
Those counts explain the GO without reproducing the private evidence that produced it.
Aligned is a structural predicate
The word aligned invites a stronger claim than the validator can support.
For this protocol, alignment is a testable relation among files. The validator checks the exact cross-file geometry fields named before acquisition. Equality can show that the files describe the same sampled grid under that contract. It cannot show that anatomy is registered well, that a lesion is represented correctly, or that the image is suitable for a clinical task.
This distinction matters because NIfTI files carry both arrays and spatial descriptions. Matching array dimensions alone is weak. Two files can have the same dimensions while their voxel-to-world transforms differ. Matching geometry is stronger, but it is still structural evidence.
VoxelScope therefore uses a narrow sentence:
The files satisfy the frozen cross-file geometry predicate.
It does not substitute:
The scans are anatomically correct.
The second sentence needs evidence this study does not collect.
The privacy boundary is a separate publication gate
The private run inspected facts that should never enter a public article repository. The public export therefore worked as a reduction step, not a copy step. It ran after the structural terminal state.
It may retain:
- closed gate statuses;
- aggregate counts needed to bind the article;
- the terminal structural status;
- the fixed fact that inference remains unauthorized;
- a commit-pinned URL and SHA-256 digest for a separate reviewed VoxelScope public summary; and
- the already published source identity and source-side byte count.
It must reject:
- subject identifiers and private filenames;
- local paths, download receipts, and operator tokens;
- NIfTI headers or real shapes, affines, zooms, and dtypes;
- discovered label sets or voxel values;
- locally derived hashes of private medical files; and
- the medical files themselves.
That restriction makes the article less reconstructive by design. A reader can audit the state machine and its public claims without receiving a shadow copy of the medical evidence.
Reproduce the gates without medical data
VoxelScope ships deterministic synthetic NIfTI fixtures for both accepted and refused parser paths. Its public verifier checks the closed milestone bundle, and its focused tests exercise malformed gzip, invalid headers, bounded decompression, non-finite values, mask-domain failures, geometry mismatches, transport identity, and one-shot replay refusal:
uv run voxelscope milestone4-public verify --bundle research/milestone-4
uv run pytest tests/test_one_volume_custody.py -q
The portfolio has a separate publication gate:
pnpm test:voxelscope-article
pnpm check:voxelscope-article-production
Those tests bind the prose, decision table, generated SVG, counts, terminal status, privacy release, and immutable VoxelScope summary. They reject unknown states, extra fields, missing provenance, private or medical material, and generated-asset drift. The Python fixtures reproduce the structural validator without patient data. The TypeScript fixtures prove that the article cannot publish a stronger claim than the sanitized result.
What this article may claim
The allowed claims are exact:
- the source, model custody boundary, selection rule, channel order, source-published payload count, and label-domain mismatch were fixed before acquisition;
- milestone 3 stopped before medical acquisition, model load, inference, GPU use, cloud use, or spend;
- milestone 4 completed one approved private acquisition and bounded structural checks;
- the verified structural GO makes a later stage eligible;
- the structural result passed a separate privacy release before publication; and
- milestone 4 requires
inference_authorized=false.
The forbidden claims are just as exact:
- no segmentation accuracy, quality, or usefulness result;
- no diagnosis, clinical safety, or patient-specific claim;
- no anatomical correctness claim from structural alignment;
- no GPU latency, throughput, memory, utilization, power, or cost result;
- no semantic equivalence between source labels and MONAI outputs; and
- no claim that a structural GO or privacy release authorizes inference.
A reusable admission checklist
- Pin custody. Record the model archive, source revision, protocol revision, and verifier version before execution.
- Select without outcomes. Freeze the eligibility rule and choose the source without inspecting the result-bearing content.
- Name every role. Bind each input channel to one declared model position. Reject duplicates, substitutions, and extras.
- Separate authorization. Treat acquisition, validation, inference, and publication as different permissions.
- Verify transport. Check the closed file set and content identity before parsing.
- Validate structure. Reject malformed containers, unsupported structures, and values outside the frozen contract.
- Compare geometry exactly. Use the declared cross-file predicate. Do not replace it with dimensions alone.
- Keep semantics explicit. A numeric mapping is not authorized because it looks obvious.
- Reduce after the terminal state. Export statuses and counts from either structural branch. Do not publish raw evidence by default.
- Stop on missing evidence.
not_runandnot_authorizedare valid states. Neither means pass. - Bind prose to data. Generate figures from the same reduced values and test the article table against them.
- Keep milestone permissions fixed. This milestone can validate structure and release a sanitized result. It cannot authorize inference.
Limitations
This study covers one official source version, one outcome-blind selection rule, one private model archive, and one frozen validator. Its public evidence is intentionally reduced. It cannot support an independent reconstruction of the private acquisition or a claim about image content.
The validator can establish its declared file and geometry predicates. It cannot establish clinical meaning.
Conclusion
An inference pipeline is easier to trust when failure has somewhere precise to happen.
Identity can fail before authorization. Transport can fail before parsing. Structure can fail before geometry. Geometry can produce a structural refusal. Privacy can block publication after either structural terminal state. And inference must remain unauthorized after every milestone 4 check passes.
That sequence does not make the eventual model result better. It makes the conditions for obtaining one inspectable.
The GPU had nothing to prove until the inputs did.
Evidence: VoxelScope repository · VoxelScope PR #4 · Exact merge commit f4ec1ef · Public milestone 4 summary · Public summary SHA-256 1f483f8beb775d5974eba167febe5eae00e1c10571e50948413646618f5a2590 · Public bundle root SHA-256 d3fdca9d8e5dccfbe5b1e755ca1a9fa782dd986e1fd00c5caa1997986a1c20df