Repository navigation
Module ai Future
Navigation: Home > Modules
- Hardening of endpoint safety, payload validation, and error observability for AI plugin generation.
- Introduction of dedicated performance coverage for the AI generation path.
- Future integration of external sandbox/static-analysis policy engines on top of the built-in artifact materialization gate.
- Public API contracts in
include/ai/ai_plugin_generator.hremain backward compatible within major line. - Validation and error behavior must remain deterministic and fail-closed.
- Runtime behavior must remain bounded by timeout/retry budgets.
- Security-sensitive request content must not be persisted unredacted.
| Interface | Requirement |
|---|---|
validatePrompt |
extend checks for required_capabilities and dependencies consistency |
generatePlugin |
preserve validation-first execution and fail-closed return semantics |
AIPluginGenerator::Config |
expose explicit safety knobs (allow-list, payload limit, retry policy) |
| benchmark integration | maintain dedicated ai generation benchmark target and release mapping |
- Add response schema validation with explicit required and optional fields.
- Add bounded retry/backoff only for transient transport failures.
- Add response-size hard limit before parse to prevent memory pressure.
- Field-level validation for
required_capabilities/dependencies, configurable endpoint allow-list, request/response size limits, dedicated benchmark coverage, and built-in sandbox artifact materialization are implemented in the runtime path; remaining hardening focuses on external sandbox/static-analysis policy engines. - Standardize error classes for validation, transport, HTTP status, parse, and payload shape failures.
- Unit tests for new validation rules and schema failure cases.
- Integration tests with deterministic endpoint fixtures (success, non-2xx, malformed JSON, oversized payload).
- Regression tests for existing structured error contracts.
- Benchmark regression tracking in release profile for mapped AI targets.
- Prompt validation path p99 remains within low-single-digit milliseconds.
- Endpoint orchestration overhead remains stable versus current release baseline.
- Proxy benchmark regressions stay within configured release threshold until dedicated benchmark is introduced.
- Enforce endpoint allow-list checks before outbound calls (implemented).
- Enforce maximum request and response size limits (implemented).
- Materialize generated source bundles into sandbox/output directories with fail-closed read-back verification before optional callback policy execution (implemented).
- Keep fail-closed behavior for malformed/untrusted responses.
- Ensure logs remain redacted and bounded for sensitive fields.
Long-term strategic AI/ML features for enhanced safety, privacy, and governance. Lower urgency but high strategic value.
- Design constitutional principles registry (21 built-in rules)
- Implement LLM-as-critic evaluation loop
- Build revision prompt generation
- Create critic-revision cycle (max 2 rounds)
- Unit tests CAI-01..15 + CAI-BENCH-01 (
tests/test_cai_safety_module.cpp) - Integration with EthicsEvaluator (
include/ai/cai_ethics_integration.h) - Production runtime hook integration in
LLMAQLHandlerpaths (executeInfer,executeInferStreaming,executeRAG,executeChat) with fail-closed callback handling - Human safety benchmark (500 samples, 3 annotators) β
tests/test_cai_safety_module.cpp(CAI-BENCH-01)
Acceptance Criteria:
- Safety score alignment β₯ 0.80 with human annotators
- Latency overhead β€ 2.0 s per response
- False-positive rate β€ 10% (benign content flagged as unsafe)
Reference: Bai et al. (2022) arXiv:2212.08073
- Design synchronized SGD gradient aggregation
- Implement secure aggregation primitive (stub: optional homomorphic encryption)
- Build Byzantine-robust averaging (median/trimmed mean)
- Create federated training coordinator
- Unit tests FEDERATED-01..15 + FEDERATED-BENCH-01 (
tests/test_federated_privacy_training.cpp) - Production telemetry hook integration in
LLMAQLHandlerpaths (executeInfer,executeInferStreaming,executeRAG,executeChat) with fail-closed callback handling - Multi-node convergence benchmark (10 nodes, 10% data each) β
tests/test_federated_privacy_training.cpp(FEDERATED-BENCH-01) - Differential privacy tuning framework
Acceptance Criteria:
- Training convergence β₯ 95% of centralized baseline
- Gradient communication overhead β€ 2.0 s per round
- Configurable epsilon-differential privacy budget
Reference: Kairouz et al. (2021) JMLR 2021, arXiv:2104.14881
ML pipeline phase tracking using a directed-acyclic-graph (DAG) orchestrator that enforces per-phase gate criteria and reports gaps (missing evidence) blocking phase advancement. Resolves C3 gap-tracking requirement from issue #6287.
Scope:
- DAG-based phase registry: named pipeline phases (nodes) + prerequisite edges.
- Gate criteria: per-phase named metric thresholds (key β₯ threshold).
- Gap reporting: structured
PhaseGapReportlisting unsatisfied criteria and blocked-by-phase chains. - Topological ordering: valid execution sequence via Kahn's algorithm.
- Completion tracking:
passedPhaseCount()andcompletionRatio()(0.0β1.0). - Thread safety: shared-mutex reader/writer separation for concurrent evaluation.
Design Constraints:
- Public API confined to
include/graph/graph_phase_gate_orchestrator.h; no external dependencies beyond the C++ standard library. -
registerPhase()must preserve an acyclic public registration path by requiring already-registered prerequisites and rejecting self-referential registrations. - Gate evaluation is recursive (prerequisite-first); the BLOCKED status propagates without re-evaluating satisfied subtrees.
- All gate evaluation calls are read-only on the stored phase graph (shared lock); writes serialise via exclusive lock.
Required Interfaces:
| Interface | Requirement |
|---|---|
registerPhase(name, prereqs) |
DAG construction; acyclic registration enforcement; returns bool |
setGateCriteria(name, criteria) |
Replace metric thresholds for a phase |
attachMetric(name, key, value) |
Record an observed metric value |
gateStatus(name) |
Recursive gate evaluation β PASS / FAIL / BLOCKED / PENDING |
gaps(name) |
Structured gap report for a single phase |
allGaps() |
All gap reports for non-PASS phases |
topologicalOrder() |
Valid execution sequence (Kahn's algorithm) |
completionRatio() |
Float fraction of PASS phases |
Implementation Notes:
- Implementation:
src/graph/graph_phase_gate_orchestrator.cpp - Header:
include/graph/graph_phase_gate_orchestrator.h - Tests:
tests/graph/test_graph_phase_gate_orchestration.cpp(GRAPH_PHASE_GATE-01..15 + GRAPH_PHASE_GATE-BENCH-01)
Test Strategy:
- GRAPH_PHASE_GATE-01: empty orchestrator has zero phases and 0.0 completion ratio.
- GRAPH_PHASE_GATE-02: root phase (no prerequisites) registers successfully.
- GRAPH_PHASE_GATE-03: duplicate phase name registration is rejected.
- GRAPH_PHASE_GATE-04: prerequisite referring to unregistered phase is rejected.
- GRAPH_PHASE_GATE-05: self-referential and duplicate registrations are rejected.
- GRAPH_PHASE_GATE-06: unregistered phase gateStatus returns PENDING.
- GRAPH_PHASE_GATE-07: root phase with no criteria passes immediately.
- GRAPH_PHASE_GATE-08: gate FAIL when required metric is absent.
- GRAPH_PHASE_GATE-09: gate FAIL when metric is below threshold.
- GRAPH_PHASE_GATE-10: gate PASS when metric equals threshold exactly.
- GRAPH_PHASE_GATE-11: gate BLOCKED when a prerequisite phase has not passed.
- GRAPH_PHASE_GATE-12: gap report enumerates unsatisfied criteria and blockers.
- GRAPH_PHASE_GATE-13: allGaps excludes phases that have PASSED.
- GRAPH_PHASE_GATE-14: topological ordering respects prerequisite edges.
- GRAPH_PHASE_GATE-15: completionRatio accurately reflects PASS fraction.
- GRAPH_PHASE_GATE-BENCH-01: 20-phase linear pipeline with all gates passing completes within 500 ms wall-clock time.
Performance Targets:
- Gate evaluation for a 20-phase linear DAG: β€ 500 ms wall-clock (BENCH-01).
-
gateStatus()p99 latency for a single phase in a 100-phase DAG: β€ 10 ms.
Security / Reliability:
- Cycle detection prevents unbounded recursion in gate evaluation.
- Shared-mutex design allows concurrent reads without write serialisation pressure.
- No external I/O or LLM dependency; orchestrator is deterministic and self-contained.
Acceptance Criteria:
- GRAPH_PHASE_GATE-01..15 all PASS.
- GRAPH_PHASE_GATE-BENCH-01 completes within 500 ms.
- Acyclic registration constraints are enforced (GRAPH_PHASE_GATE-05).
Status: β
Implemented β include/graph/graph_phase_gate_orchestrator.h,
src/graph/graph_phase_gate_orchestrator.cpp,
tests/graph/test_graph_phase_gate_orchestration.cpp
- Wave A + Wave B stability checks tracked in release verification artifacts (
CTEST.md, issues#5038/#5039) - Constitutional AI principles formalized in ethics framework (
src/ai/cai_ethics_integration.cpp,tests/test_cai_safety_module.cpp) - Multi-node federated benchmark infra/security review tracking established (FEDERATED-BENCH-01 + Wave issue traceability)
- Graph phase gate orchestrator implemented and tested β
include/graph/graph_phase_gate_orchestrator.h,tests/graph/test_graph_phase_gate_orchestration.cpp(GRAPH_PHASE_GATE-01..15 + GRAPH_PHASE_GATE-BENCH-01, issue #6287)
- C1 (CAI): Start with simple rule-based critic; LLM-based only after v0.1
- C2 (Federated): Deploy in staging first; Byzantine-robustness is nice-to-have, not critical for v1.0
- C3 (Graph Phase Gate): Orchestrator is self-contained (no LLM dependency); rollout risk is minimal.
- Start: Q3 2027 (early July)
- Target: End Q4 2027 (mid-December)
- Estimated Effort: 16β24 weeks total (depending on C2 security requirements)
- Joint paper: ThemisDB Integration of Research-Backed ML Features
- Target: ML Systems + Governance conference (e.g., MLSys 2028, FAccT 2028)
- Research Bibliography:
docs/research/ml_enhancements_bibliography.md - Roadmap:
src/ai/ROADMAP.md - Future Enhancements:
src/ai/FUTURE_ENHANCEMENTS.md - Wave C Issue:
#5040 - Wave A Issue:
#5038 - Wave B Issue:
#5039 - Wave B ML Enhancements exit-gate sign-off:
#6286β SIGNED OFF 2026-09-09
Research-backed AI/ML features for mid-term deployment (Q1βQ2 2027). Builds on Wave A foundation and targets significant performance/capability improvements.
- Design retrieval controller (binary classify: Retrieve now?)
- Implement critic model (3-class: Relevant/Partial/Irrelevant)
- Build iterative refinement loop (max 3 rounds)
- Unit tests SELF_RAG-01..12
- Integration with InferenceEngineEnhanced callback
- Benchmark vs. vanilla RAG on ALCE dataset
Acceptance Criteria:
- β Hallucination rate reduction β₯ 20% vs. standard RAG
- β Latency increase β€ 1.5Γ vs baseline
- β Precision@K retrieval β₯ 0.85 on golden-doc tests
- Implement RotatE embedding model (relation-as-rotation)
- Build triple loss with negative sampling
- Create link-prediction head
- Unit tests KGC-01..15
- Benchmark vs. TransE baseline
- Integrate with KnowledgeGraphReasoner
Acceptance Criteria:
- β MRR β₯ 0.35, Hits@10 β₯ 0.55 on deterministic acceptance fixture
- β Inference latency β€ 50 ms for top-20 predictions
- β Zero backward compatibility breaks
- Design shared LoRA base with task-specific projections
- Implement domain-gating mechanism
- Build joint loss with configurable task weighting
- Unit tests MTL-01..10
- Ablation study: shared multi-task training vs. per-task single-task baselines
- 3-task benchmark evaluation
Acceptance Criteria:
- β Average task performance β₯ +8% vs. single-task
- β Training time increase β€ 15%
- β Robust across task configurations
- Start: Q1 2027 (early January)
- Target: End Q2 2027 (mid-June)
- Estimated effort: 12β16 weeks total
- Wave A (Speculative Decoding, DPR, Fairness) deployment complete
- LLM inference P95 latency < 200 ms (prerequisite for iterative loops)
- KnowledgeGraphReasoner stable + benchmarks passing
- Research Bibliography:
../../docs/research/ml_enhancements_bibliography.md - Roadmap:
ROADMAP.md - issue scope (original):
https://github.com/makr-code/ThemisDB/issues/5039 - exit-gate sign-off:
https://github.com/makr-code/ThemisDB/issues/6286β SIGNED OFF 2026-09-09
ThemisDB 1.9.0-beta Β· Home Β· Module-Index Β· GitHub Β· Issues
ThemisDB 1.9.0-beta Β· Home Β· Wiki-Index Β· Module-Index Β· FAQ Β· Quick-Reference Β· GitHub Β· Issues Β· Discussions Β· License
- Home
- Hero Articles
- All Wiki Pages
- FAQ
- Edition Comparison
- Repository README
- Changelog
- Roadmap
- Versioning
- Integration Mapping
- Overview
- Readme
- Appendix D Feature Status
- Appendix E Incident Runbooks
- Appendix F AQL Cheatsheet
- Appendix G Configuration
- Appendix H Glossary
- Appendix I Troubleshooting
- Appendix Literatur
- Chapter 00 Genesis
- Chapter 01 Introduction
- Chapter 02 Architecture
- Chapter 03 Multimodel
- Chapter 04 Installation
- Chapter 05 Relational
- Chapter 06 Graph
- Chapter 07 Document
- Chapter 08 Storage Layer
- Chapter 08 Vector
- Chapter 09 Timeseries
- Chapter 10 Enterprise
- Chapter 11 Realtime
- Chapter 12 Computervision
- Chapter 13 Fulltext
- Chapter 14 Geospatial
- Chapter 15 Analytics
- Chapter 16 Ml
- Chapter 16 Sharding
- Chapter 17 LLM Integration
- Chapter 17 Scaling
- Chapter 18 HA
- Chapter 18 Ml
- Chapter 19 Monitoring
- Chapter 19 Monitoring Observability
- Chapter 20 Backup
- Chapter 20 Performance
- Chapter 21 Auth
- Chapter 21 Performance
- Chapter 22 Clients
- Chapter 22 Encryption
- Chapter 23 Testing Qa
- Chapter 24 Ai Ethics
- Chapter 25 Devops Infrastructure
- Chapter 26 Migration Legacy
- Chapter 27 Troubleshooting
- Chapter 28 AQL Reference
- Chapter 29 Analytics Process Mining
- Chapter 30 Deployment Operations
- Chapter 31 API Protocols
- Chapter 32 API Design Rest Principles
- Chapter 32 AQL Oop Implementation
- Chapter 33 Best Practices
- Chapter 34 Query Optimization
- Chapter 35 Data Modeling Patterns
- Chapter 36 Security Hardening
- Chapter 37 Ecosystem Integration
- Chapter 38 Observability Sre
- Chapter 39 Performance Tuning Cookbook
- Chapter 40 Data Governance Compliance
- Chapter 41 Hands On Labs
- Chapter 42 Docs Assistant Usage
- Chapter MVCC Hlc
- Cover
- Cover Book
- Index
- Preface
- Test Links Example
- Batch Operations
- Best Practices
- CRUD Tutorial
- Custom Document Ingestion
- Getting Started Tutorial
- Interactive Examples
- Schema Design
- Video Tutorials
- AQL Reference
- AQL Examples
- AQL Overview
- AQL Feature Roadmap
- AQL Geospatial Guide
- AQL LLM Migration Guide
- AQL API
- AQL Grammar (EBNF)
- AQL Root Overview
- AQL Examples (root)
- API Reference
- API Module README
- OpenAPI Overview
- Client SDK Overview
- SDK Overview
- Operations
- Operations Overview
- Operations Runbook
- Operations Handbook
- ThemisCtl Admin Guide
- Pipeline E2E SOPs
- Docker Overview
- Docker Hub README
- Helm Overview
- Packaging Overview
- Operator Overview
- Security Policy
- Production Hardening Checklist
- Security Hardening Guide
- Encryption Key Management
- Access Control Framework
- Zero Trust Policy
- API Authentication & Authorization
- HSM Production Setup
- PKCS11 Integration
- DSGVO / SOC2 Checklist
- Access Model Runbooks
- Access Model Dashboard
- Maturity Automation Runbook
- Access Review Automation
- Access Model Dashboard
- Access Model Runbooks
- Rights Revocation
- Dr Checklists
- Dr Testing
- Incident Response Playbook
- Incident Response Testing
- GPU Oom Recovery
- Grammar Debugging
- Metrics Scrape Troubleshooting
- Model Swap Procedure
- Quota Tuning
- Subagent Deployment
- Logging Configuration
- Content Model
- Crypto & Keys
- Feature Flags Reference
- Modular Architecture Roadmap
- Modularization Guide
- Module Architecture Index
- PostgreSQL Wire Protocol
- Query Scheduling
- Raft Consensus Design
- Resource Pooling
- Source Directory Guide
- Unified Access Model
- E1 001 Layered Retrieval Design
- E1 002 Ann Abstraction Strategy
- E1 003 Tensor Summary Types
- E1 004 Lora Package Distinction
- E1 005 Model Switch Compatibility
- E1 006 Federated Tensor Summaries
- E2 001 Evaluation Framework Design
- E2 002 Hardware Profile Strategy
- E2 003 Query Planner Routing Model
- E2 004 Approximation Governance Rules
- E2 005 Cross Layer Fallback Confidence Policy
- E3 001 Distributed Tensor Design
- E3 002 Manifest Coordination Strategy
- E3 003 Recovery And Erasure Choice
- E3 004 Tensor Fabric Infrastructure
- Contributing
- Contributing (root)
- Code of Conduct
- Support
- Maintainers
- CTest Guide
- Build Quick Reference
- Developer Wiki Index
- Build / Test / CI
- Module Index
- Branching Strategy
- Release Strategy
- CI Policy Gates Wave C
- Disabled Stub Policy
- Docs PR Policy
- GA Promotion Sign Off
- Github Milestones Setup
- Governance Policies Phase1
- GPU Self Hosted Runner Requirements
- Hardening Phase 1 2 Summary 2026 09 23
- Maturity Claim Verification Checklist
- Maturity Evidence Registry
- Merge Gate Bot Config
- Merge Gate Status Live
- Phase 1 Closure Report
- Phase 1 Infrastructure Deployment
- Phase 1 Infrastructure Deployment Complete
- Phase 3 Baseline Capture
- Phase 3 Refinement Spec
- Phase 4 Sign Off And Closure
- Phase Closure Policy
- Phase Dependency Graph
- Phase3 Enforcement Runbook
- Plugin Submodule Rollback
- PR Version Targeting
- PR Version Targeting Backfill
- Production Ready 2026 Delivery Plan
- Publish Workflow Audit 2026 09 23
- Query Module Status
- Readme
- Release Governance
- Release Promotion Gate Policy
- Release Validation Checklist
- Root Hygiene Policy
- SBOM Approved Versions
- Security Compliance Audit Report 2026 08 10
- Security Module 5671 Evidence Summary
- Sharding P6 Residual Risk Acceptance
- Sourcecode Compliance Governance
- Src Module Documentation Compliance 2026 09 20
- Updates Development Status Sign Off
- Wave C Implementation Complete
- Wave C Implementation Plan
- Wave C Ml Exit Gate Sign Off
- Wave C Policy Gate Evidence
- Wiki Publish Tracking Guide
- Blob Storage
- Cuda
- Ethics Ai
- Exporters
- Huggingface
- Image Analysis
- Importers
- RPC
- Scraper
- Themisdb Ai Watermark Detector
- User Storage Encrypted
- Chimera Architecture
- Chimera Future
- Chimera Readme
- Chimera Roadmap
- Covina Fastapi Ingestion Architecture
- Covina Fastapi Ingestion Future
- Covina Fastapi Ingestion Roadmap
- Vcc Base Architecture
- Vcc Base Future
- Vcc Base Roadmap
- Vcc Clara Ingestion Architecture
- Vcc Clara Ingestion Future
- Vcc Clara Ingestion Roadmap
- Vcc Veritas Architecture
- Vcc Veritas Future
- Vcc Veritas Roadmap
- 01 Hello World
- 02 Todo App
- 03 Contact Manager
- 04 Inventory System
- 05 Time Series Monitor
- 06 Graph Social Network
- 07 Vector Search Documents
- 08 Dms Erp System
- 09 Iot Sensor Network
- 10 Drone Image Analysis
- 11 Blog Wiki
- 12 Expense Tracker
- 13 Recipe Manager
- 14 Ecommerce Catalog
- 15 Event Management
- 16 Kanban Board
- 17 Crm
- 18 Realtime Chat
- 19 Recommendation Engine
- 20 Smart Home
- 21 Coding Platform
- 22 AQL Diagram Tool
- 23 Traveling Salesman
- 24 Moral Philosophy Debates
- API Versioning
- Distributed Sharding
- Feedback Plugins
- Geo
- Gnn
- Image Analysis
- Legal Lora Training
- LLM
- Lora Sync
- Migration
- Nlp
- Performance
- Railway
- Replication
- Rope Visualization
- Sample Product Config
- Security
- Client SDK Overview
- Quickstart
- Sdk Enhancements
- Sdk Implementation Summary
- Test Suite Readme
- Go
- Java
- Javascript
- Php
- Python
- Ruby
- Rust
- Typescript
- 01 Grundlegende Operationen
- 02 AQL Queries
- 03 Graph Daten
- 04 Multimodell Anwendung
- 01 Quickstart Guide
- 02 AQL Referenz Kurzuebersicht
- 03 Datenmodellierung Guide
- 04 Uebungsaufgaben
- 05 Best Practices Guide
- Training Documents
- Training Overview
- 01 Einfuehrung Und Uebersicht
- 02 Datenmodelle Und Architektur
- 03 AQL Abfragesprache
- 04 Installation Und Setup
- 05 Anwendungsbeispiele
- Training Presentations
- Dependencies Readme
- Processmonitor Readme
- Themis.admintools.shared Readme
- Themis.aqlquerybuilder Readme
- Themis.aqlquerybuilder Roadmap
- Themis.auditlogviewer Readme
- Themis.auditlogviewer Roadmap
- Themis.classificationdashboard Readme
- Themis.classificationdashboard Roadmap
- Themis.compliancereports Readme
- Themis.compliancereports Roadmap
- Themis.gisviewer.controlpanel Readme
- Themis.gisviewer.controlpanel Roadmap
- Themis.impactanalysisviewer Readme
- Themis.impactanalysisviewer Roadmap
- Themis.ingestiontool Readme
- Themis.ingestiontool Roadmap
- Themis.keyrotationdashboard Readme
- Themis.keyrotationdashboard Roadmap
- Themis.piimanager Readme
- Themis.piimanager Roadmap
- Themis.retentionmanager Readme
- Themis.retentionmanager Roadmap
- Themis.sagaverifier Readme
- Themis.sagaverifier Roadmap
- Themis.usbadmintool Readme
- Themis.usbadmintool Roadmap
- Architecture Generator Readme
- CI Readme
- CI Roadmap
- Compiler Diagnostics Readme
- Compiler Diagnostics Roadmap
- Completion Readme
- Copilot Ollama Router Readme
- Copilot Ollama Router Roadmap
- Gnn Readme
- Gnn Roadmap
- Rope Visualizer Readme
- Rope Visualizer Roadmap
- Tco Calculator Readme
- Tco Calculator Roadmap
- Tests Readme
- Tests Roadmap
- Themis Config Wx Readme
- Themis Docs Builder Readme
- Wikipedia Ingestion Readme
- Ai Metadata And Provenance
- Build / Test / CI
- Governance And Roadmap
- Developer Wiki Index
- Module Direct Doxygen Check
- Module Doxygen Baseline Summary
- Module Doxygen Batch
- Module Doxygen Coverage Summary
- Module Doxygen Smoke Summary
- Modules And Apis
- Retrieval Direct Doxygen Check
- Soll Ist Gap Summary
- Wiki Delta Report