{"id":"ecf15ef5-0568-4602-be99-24a3acd866ba","arxiv_id":"2607.16651","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":4.0,"correctness_risk":"high","formal_verification":"none","parameter_count":10,"one_line_summary":"In VIGIL, trust decays unless biometric evidence arrives, verification has an inconclusive middle zone, and repeated suspicion shrinks the window to pressure persistent attackers.","lead":"This paper proposes VIGIL, a continuous multi-modal biometric authentication framework in which trust in a user can only fall while no biometric evidence arrives, and repeated suspicious events shrink the verification window. The paper gives the math of those rules and hand-worked examples, but no real sensor data or end-to-end tests are presented.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Walkthrough contradicts stated mode-transition rule: with τ_p=10s, T_stay=0.70, no-observation P1 dwell is capped at ~4.4s from P(N)=0.95, yet Scenario F/Table 6 assume 10–20s Normal periods; the penalty-decay usability mechanism is therefore not demonstrated.","rationale":"The central claim is that VIGIL reduces time to detect intrusions while maintaining high usability. The paper's analytical support for usability rests on the penalty-decay mechanism, illustrated in Table 6 and Supplementary Scenario F. However, §3.3 states that the system transitions to P2 when P(N) drops below T_stay. With defaults (τ_p=10s, T_stay=0.70), P(N) decays below 0.70 in ~4.4s from 0.95. Scenario F models 20s of P1 no-observation decay while staying in P1, contradicting this rule. This is not a minor typo: it affects the entire demonstration that the adaptive window restores itself after a Normal period. If transitions are continuous (as stated), long no-observation Normal periods are impossible, and the penalty can only decay while observations keep P(N) above T_stay. If transitions are event-driven, a sensor-avoiding attacker would never enter P2, and the paper's stalling-prevention claim fails. Both readings undermine the usability half of the central claim. The reader's verdict focused on missing empirical validation; this concern is more fundamental—the analytical walkthrough itself is not faithful to the framework's stated behavior. A concrete re-run of the walkthrough under the §3.3 rule would expose the contradiction. Unless the paper clarifies the transition semantics and corrects the walkthrough, the claimed analytical demonstration should not be credited. This moves the verdict from CONDITIONAL to REJECT, because the internal inconsistency invalidates the primary evidence for the headline claim, even before considering empirical validation.","tokens_in":17320,"tokens_out":18283,"duration_ms":176306,"concrete_test":"Re-implement the VIGIL pipeline exactly as specified in §3.2–3.3 with the Table 7/S1 defaults, treating the P1→P2 transition as occurring immediately when P(N)<T_stay is reached (continuous monitoring). Replay Supplementary Scenario F and Table 6. If the 10s and 20s Normal periods with no observations do not reproduce—because P2 is entered at ≈4.4s and the no-observation verification rule alerts—the walkthrough is internally inconsistent. Alternatively, run a discrete-event version where transitions are checked only at observation times; verify whether a sensor-avoiding attacker ever leaves P1. The failure of either run settles the ambiguity.","verdict_should_be":"REJECT","load_bearing_attack":"In §3.3, VIGIL specifies that the system transitions from P1 to P2 'when P(N) drops below the stay threshold T_stay during cruise mode' (also Figure 1). Under the default parameters from Table 7/S1 (τ_p=10s, T_stay=0.70), a genuine user who recovers to P1 with P(N)=0.95 (as in Scenario F) will cross T_stay after t=(τ_p/ln2)·ln(P0/T_stay)=10/0.6931·ln(0.95/0.70)≈4.4s without observations. The supplementary Scenario F instead lets P1 run for 20s with no observations, applies decay to P(N)=0.2380, and states that only then does 'a weak observation' trigger P2. Table 6 similarly lists 10s and 20s Normal periods. These timelines violate the stated transition rule. If the rule is continuous, those long Normal periods are impossible: a dropout of ~4.4s forces P2, and a 5s verification window without observations produces an immediate alert—making the claimed penalty-decay/restoration (the usability half of the central claim) largely inoperative for genuine users with even moderate sensor gaps. If the rule is instead event-driven (only checked when observations arrive), then an attacker who avoids delivering any biometric data will never be forced into P2, contradicting the paper's stalling-prevention claim (Scenario D only addresses P2). Either interpretation invalidates the analytical walkthrough that is offered as evidence that VIGIL 'reduces the time to detect intrusions while maintaining high usability.'","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper proposes VIGIL, a continuous multi-modal biometric authentication framework built on two state-transition machines. The main technical contribution is a unidirectional temporal-fusion design: in both cruise mode (STM1) and verification mode (STM2), probability mass can leave the Normal state but cannot return to it without new biometric evidence, eliminating the S-to-N backflow that the authors identify in the baseline SSPRA model. The paper also introduces a configurable subset-level fusion strategy, a three-zone P2 decision model with multi-round verification, and an adaptive shrinking verification window. The evaluation is entirely analytical: monotonic decay is proved from the transition matrices, and six numerical walkthrough scenarios are presented in the supplementary material to illustrate recovery, gradual alert, no-observation alert, max-round exhaustion, and penalty decay.","tokens_in":17738,"tokens_out":6601,"duration_ms":68045,"significance":"The core mathematical observation is sound and useful: replacing SSPRA's S-to-N recovery path with an absorbing Suspense state gives strict monotonic decay of P(N) under no observations, and the derivation in Eqs. (3)-(6) and (12)-(14) is clean and easy to verify. The paper is also honest in Section 4 about the lack of empirical validation and about the hand-set nature of the parameters. If the internal inconsistency described in the major comments were resolved, the unidirectional temporal-fusion idea would be a legitimate incremental improvement over SSPRA. However, the abstract's stronger claims, specifically that VIGIL 'reduces the time to detect intrusions while maintaining high usability,' are not supported by the current analytical walkthroughs, and one of those walkthroughs contradicts the paper's own mode-transition rule. The significance of the contribution is therefore real but narrower than the paper claims.","major_comments":[{"comment":"The P1-to-P2 transition rule is stated as occurring 'when P(N) drops below the stay threshold T_stay during cruise mode.' Using Eq. (4) with the default τ_p=10s and T_stay=0.70, a user at P(N)=0.95 (the value entering the 20s Normal period in Scenario J.2) drops below T_stay after approximately 4.4s without observations. Scenario J.2 and Table 6 nevertheless assume 10-20s Normal periods with no observations. If the rule is continuously enforced, those periods are impossible and the user would enter P2, where the no-observation rule triggers an immediate alert—contradicting the claimed usability benefit. If the rule is event-driven (checked only when an observation arrives), an attacker who withholds all observations never enters P2, so the stalling-prevention claim in Section 3.3.5 is vacuous. Either interpretation invalidates the walkthrough's demonstration of penalty decay and window r","section":"§3.3 / Supplementary Scenario J.2 and Table 6"},{"comment":"The abstract claims VIGIL 'reduces the time to detect intrusions while maintaining high usability.' This is not derived or measured anywhere in the paper. The six scenarios in the supplementary material assign strong likelihoods to genuine users and weak likelihoods to attackers, so the outcomes are forced by the input scores; they do not quantify time-to-detection, false-alarm rates, or lockout probability under realistic sensor dropout. Section 4 explicitly states that 'Empirical validation on multimodal datasets is a natural next step.' The categorical claim in the abstract should be qualified to a design objective or supported by a formal performance bound.","section":"Abstract and §4"},{"comment":"The adaptive-window penalty mechanism is presented as the usability-preserving component, but its operation depends on the same inconsistent Normal-period assumption. Table 7 sets λ=0.1s⁻¹ and W_min=1.0s, and Table 6 shows the penalty decaying during 10s and 20s in Normal. Because, under the default decay parameters, a continuous P1 check would force P2 after roughly 4.4s without observations, the claimed restoration of the full window for 'a genuine user who maintains stable behavior' is not actually demonstrated. The paper needs to specify when P1 thresholds are evaluated and then show that legitimate sensor dropouts of the durations used in the walkthroughs do not cause lockouts.","section":"§3.3.4 / Table 7"}],"minor_comments":[{"comment":"The introduction refers to 'Section II,' 'Section III,' and 'Section IV,' but the sections are numbered 2, 3, and 4. Please use consistent numeric labels.","section":"§1"},{"comment":"Reference [6] contains spacing artifacts ('V . V . Phoha' should be 'V.V. Phoha'). Several other references have similar spacing issues; a final proofread is recommended.","section":"References"},{"comment":"The notation P(M_t | s_t) in Eq. (2) is defined only loosely. Since the paper stresses per-modality likelihoods P_N^j and P_¬N^j, the relationship between the two notations should be clarified or unified.","section":"§3.1"},{"comment":"In Scenario E, the statement 'Shorter windows reduce per-round decay (q closer to 1), but the cumulative effect is decisive' is not a general result; it depends on the particular sequence of window lengths and decay half-life. The table is correct, but the interpretive sentence should not be phrased as a theorem.","section":"Table S3"}],"recommendation":"major_revision","confidential_remarks":"The central mathematical contribution—the unidirectional transition matrix—is correct and worth publishing, but the manuscript currently overstates its demonstrated scope, and the walkthrough contains an internal inconsistency between the stated P1 transition rule and the simulated Normal periods. This is fixable with a clear specification of the transition semantics and a re-scoped set of claims; I do not see a reason to reject outright."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Short version: the unidirectional transition matrices are a real, clean fix for the SSPRA backflow problem, and the monotonic-decay derivation is correct. But the paper's only evidence for 'maintaining high usability while reducing time to detect' is a self-constructed analytical walkthrough, and that walkthrough contradicts the paper's own transition rule. The framework deserves a serious referee, but the abstract overreaches.\n\nWhat's actually new: VIGIL's STM1 and STM2 use transition matrices with no S-to-N path, so only actual biometric fusion can raise P(N). The derivation of monotonic decay and the backflow threshold in §3.2 is solid; Tables 4-5 are consistent. The three-zone decision and adaptive shrinking window are genuine extensions to the SSPRA baseline. The paper also honestly states in §4 that evaluation is analytical and empirical validation is future work.\n\nThe soft spots are in the walkthrough, and they are real. The stress-test note is correct. In §3.3, P2 is entered when P(N) drops below T_stay during cruise. With defaults τ_p=10s and T_stay=0.70, a user at P(N)=0.95 crosses that threshold after ~4.4s without observations. Yet Scenario F and Table 6 assume 10-20s Normal periods with no observations; Scenario F even computes P(N)=0.2380 after 20s. Under the stated rule the system would have escalated to P2 after ~4.4s and, with no observations, would alert. So either the rule is continuous (and those long dropout periods are impossible for genuine users, making the penalty-decay mechanism mostly moot) or it is event-driven (and an attacker can avoid triggering P2 by withholding data, contradicting the stalling-prevention claim in Scenario D). Either way, the walkthrough does not demonstrate usability.\n\nThe scenarios are also constructed with favorable likelihoods for genuine users and weak ones for attackers; the outcomes are forced by the inputs. The claim that VIGIL 'reduces time to detect intrusions' is not derived quantitatively relative to the baseline. The parameters are hand-set; that's fine for a framework, but not evidence of performance.\n\nWho is this for: anyone working on temporal fusion for continuous authentication. The anti-backflow construction is worth knowing, and the math is a solid foundation. But the paper needs to fix the transition semantics before the usability claims can be taken seriously.\n\nRecommendation: I'd send it to peer review. The core idea is sound enough to merit referee time, and reviewers should be able to catch the inconsistency. If I were the editor, I'd ask for major revision: either make the transition rule event-driven and consistent with attacker behavior, or narrow the claims to the mathematical properties.","headline":"Sound anti-backflow math undercut by a walkthrough that contradicts VIGIL's own transition rule.","tokens_in":18249,"tokens_out":5591,"would_cite":true,"duration_ms":55900,"reading_group":"maybe","serious_thinker":"no","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"VIGIL is a continuous-authentication framework whose core rule is that only actual biometric observations may increase the probability a user is genuine; without them, trust decays monotonically and attackers cannot simply wait out verifica","keywords":["continuous authentication","multimodal biometrics","temporal fusion","state transition machine","unidirectional transition matrix","adaptive verification window","monotonic decay","backflow elimination"],"falsifier":"Measure VIGIL end-to-end on a real multimodal dataset (e.g., face plus voice or keystroke) with natural sensor dropout and a simulated persistent attacker: if the false-alarm rate for genuine users whose observation gaps exceed the minimum window (1 s) is unacceptably high, or if the time-to-alert for an attacker who produces neutral evidence is not shortened relative to a static-window baseline, then the claim that VIGIL reduces detection time while preserving usability is falsified.","tokens_in":17137,"feed_emoji":"🔐","tokens_out":6400,"duration_ms":58168,"temperature":0.7,"pith_summary":"The paper sets out to prove that continuous authentication can be made both faster and more usable by enforcing a single rule: the system's belief that the current user is genuine may only increase when real biometric observations arrive, and must decay monotonically when they do not. To implement this, it proposes VIGIL, a dual-state Markov framework whose transition matrices are unidirectional, so probability mass cannot flow back from Suspense to Normal without evidence. The authors argue this closes a loophole in prior temporal-fusion systems, where an attacker could wait out a verification window and regain a trusted state for free. They further claim that a three-zone decision model, which allows multiple verification rounds when evidence is inconclusive, together with an adaptive window that shrinks on each repeat entry, shortens the time to detect persistent attackers while preserving usability for legitimate users. The evaluation is analytical; the paper itself identifies empirical validation on real datasets as the natural next step.","feed_headline":"Trust decays without biometrics, so attackers can't wait out alerts","feed_subtitle":"Unidirectional state transitions mean only real biometric evidence can raise the probability a user is genuine","key_machinery":"The central mechanism is the unidirectional state transition matrix used in both state transition machines (STM1 for cruise and STM2 for verification). In STM1, the Suspense state is absorbing during temporal fusion: probability mass leaving Normal cannot return without a Bayesian update from actual biometric observations. In STM2, entry transfers all Suspense mass to Alert, and the decay function q(Δt) governs Normal-to-Alert erosion. This, together with the three-zone decision model and the penalty-based adaptive window W_current = max(W_min, W_base − penalty), carries the argument: no-observation periods monotonically reduce P(N), and repeated inconclusive verification rounds compound pre","core_discovery":"The central claim is that a continuous authentication system should treat biometric evidence as the only permissible cause of an increase in the posterior probability P(N) that the current user is genuine. VIGIL enforces this with unidirectional transition matrices in both of its state transition machines: in cruise mode (STM1), the Suspense state is absorbing during temporal fusion, so P(N) can only fall as time passes without observations; in verification mode (STM2), all Suspense mass is transferred to Alert at entry and only a fresh Bayesian update from actual observations can raise P(N). The paper proves monotonic decay and shows analytically that a baseline approach with a Suspense-to-","pith_inferences":["A direct corollary the paper does not spell out is that the unidirectional principle transfers to any continuous trust system—zero-trust access, anomaly detection, fraud scoring—where the absence of positive evidence should lower confidence, not merely leave it unchanged.","Because the monotonic decay proof is independent of the fusion function, the security benefit of VIGIL holds for any per-modality combination rule; operators can therefore tune fusion for accuracy or robustness without weakening the no-backflow guarantee.","The framework's parameters are hand-set (table S1), so a testable extension is automated parameter tuning: a deployment could search over (T_stay, T_back, T_alert, W_base, δ, λ) on a validation set to explicitly trade off false alarms against time-to-detection."],"forward_implications":["A persistent attacker who triggers suspicion cannot wait out a static window and return to Normal: the no-observations branch in P2 alerts immediately, and re-entry into P2 shortens the active window.","Suspicion does not reset over time: because P(N) decays monotonically without observations, the system requires progressively stronger biometric evidence to recover in later rounds.","Operators can select fusion strategies (product, weighted sum, weighted geometric mean) per active sensor subset, so a weak sensor cannot collapse the fused likelihood the way the plain product rule does.","The penalty mechanism gives legitimate users a full window after stable Normal behavior (penalty decays at rate λ), so the claimed usability cost is bounded."],"fun_headline_variants":["Only biometrics can restore trust in continuous authentication","Monotonic probability decay blocks persistent attackers","Unidirectional states make intrusions fade without biometrics","VIGIL: trust decays between biometric signals, so attackers can't linger"],"cache_read_input_tokens":2304,"weakest_assumption_plain":"The load-bearing premise is that legitimate users, in real deployments, will supply enough biometric observations with strong enough fused scores that the monotonic decay of P(N) and the alert-on-no-observations rule will not lock them out — an assumption about real sensor dropout and score distributions that the paper does not test empirically.","fun_headline_variants_meta":{"raw":{"variants":["Only biometrics can restore trust in continuous authentication","Monotonic probability decay blocks persistent attackers","Unidirectional states make intrusions fade without biometrics","VIGIL: trust decays between biometric signals, so attackers can't linger"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000371,"raw_usage":{"total_tokens":1790,"prompt_tokens":676,"completion_tokens":1114,"prompt_tokens_details":{"cached_tokens":256},"prompt_cache_hit_tokens":256,"prompt_cache_miss_tokens":420,"completion_tokens_details":{"reasoning_tokens":1049}},"tokens_in":420,"tokens_out":1114,"duration_ms":9332,"temperature":1.0,"reasoning_tokens":1049,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-01T20:20:16.629408+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Measure VIGIL end-to-end on a real multimodal dataset (e.g., face plus voice or keystroke) with natural sensor dropout and a simulated persistent attacker: if the false-alarm rate for genuine users whose observation gaps exceed the minimum window (1 s) is unacceptably high, or if the time-to-alert for an attacker who produces neutral evidence is not shortened relative to a static-window baseline, then the claim that VIGIL reduces detection time while preserving usability is falsified.","supporting_citations":[],"review_version":1}