Skip to main content

Edit‑agnostic robustness evaluation reports for weight edits (InvarLock framework)

Project description

InvarLock

Edit‑agnostic robustness reports for weight edits

CI OpenSSF Scorecard PyPI Docs License: Apache-2.0 Python 3.12+

Catch silent quality regressions from quantization, pruning, and weight edits before they ship.

Quantizing, pruning, or otherwise editing a model’s weights can silently degrade quality. InvarLock compares an edited subject checkpoint against a fixed baseline with paired evaluation windows, enforces the canonical guard chain (invariantsspectralRMTvarianceinvariants), and produces a machine-readable evaluation report you can gate in CI.

Why InvarLock?

  • Quality gates for weight edits: catch regressions before deployment.
  • Statistical guarantees: paired primary metrics with confidence intervals.
  • Auditable evidence: deterministic pairing metadata + policy digests in evaluation.report.json.
  • CI/CD-friendly: stable exit codes, --json outputs, and portable “proof packs”.
  • Offline-first: network is disabled by default; enable downloads per command.

Who is this for?

  • ML engineers shipping quantized/pruned checkpoints.
  • MLOps teams building CI quality gates and reviewable artifacts.
  • Researchers validating compression/edit methods with reproducible, paired eval.

How it works

┌───────────────────────┐     ┌────────────────────────────────────────────┐
│ Baseline (checkpoint) │────►│                                            │
└───────────────────────┘     │  invarlock evaluate                        │
                              │  ├─► Paired windows (deterministic)        │
┌───────────────────────┐     │  ├─► GuardChain pipeline                   │
│ Subject  (checkpoint) │────►│  │   └─► invariants → spectral → RMT → VE  │
└───────────────────────┘     │  └─► Emit: evaluation.report.json          │
                              │                                            │
                              └────────────────────────────────────────────┘
                                                     │
                                     ┌───────────────┴───────────────┐
                                     ▼                               ▼
                                 ✅ PASS                          ❌ FAIL
                                 (ship)                          (rollback)

Quick start

Colab (CPU-friendly): Open in Colab

# HF adapter stack (torch/transformers)
pip install "invarlock[hf]"

# Version + report schema (when available)
invarlock --version

# Compare baseline vs subject (downloads require explicit network enable)
INVARLOCK_ALLOW_NETWORK=1 invarlock evaluate \
  --baseline gpt2 \
  --subject  gpt2 \
  --adapter auto \
  --profile dev \
  --quiet

# Validate the evaluation report
invarlock verify reports/eval/evaluation.report.json

# Render HTML for sharing
invarlock report html -i reports/eval/evaluation.report.json -o reports/eval/evaluation.html

Example output (abridged; counts vary by profile/config):

INVARLOCK v<version> · EVALUATE
Baseline: gpt2 -> Subject: gpt2 · Profile: dev
Status: PASS · Gates: <passed>/<total> passed
Primary metric ratio: <ratio>
Output: reports/eval/evaluation.report.json

Proof packs (portable evidence bundles)

Proof packs bundle reports + verification metadata into a distributable artifact.

Note: configs/ and scripts/ are repo resources and are not shipped in wheels; clone the repo to use presets and proof-pack helpers.

Installation

# Minimal CLI (no torch/transformers)
pip install invarlock

# HF workflows (torch/transformers)
pip install "invarlock[hf]"

Optional extras: invarlock[gpu], invarlock[awq,gptq]. Full setup: https://github.com/invarlock/invarlock/blob/main/docs/user-guide/getting-started.md.

Documentation

Community

Citation

If you use InvarLock in scientific work, please cite it (canonical metadata is in CITATION.cff):

@software{invarlock,
  title  = {InvarLock: Edit-agnostic robustness evaluation reports for weight edits},
  author = {{InvarLock Maintainers}},
  url    = {https://github.com/invarlock/invarlock},
}

Limitations

  • InvarLock evaluates an edited model relative to a baseline under a specific configuration; results are not “global” guarantees.
  • Not a content-safety/alignment tool.
  • Native Windows is not supported (use WSL2 or Linux).

Support matrix

Platform Status Notes
Python 3.12+ ✅ Required
Linux ✅ Full Primary dev target
macOS (Intel/M-series) ✅ Full MPS supported (default on Apple Silicon)
Windows ❌ Not supported Use WSL2 or a Linux container if required
CUDA ✅ Recommended For larger models
CPU ✅ Fallback Slower but functional

Project status

InvarLock is pre‑1.0. Until 1.0, minor releases may include breaking changes. See CHANGELOG.md.

For guidance on where to ask questions, how to report bugs, and what to expect in terms of response times, see SUPPORT.md.

Contributing

License

Apache-2.0 — see LICENSE.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

invarlock-0.4.0.tar.gz (492.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

invarlock-0.4.0-py3-none-any.whl (565.8 kB view details)

Uploaded Python 3

File details

Details for the file invarlock-0.4.0.tar.gz.

File metadata

  • Download URL: invarlock-0.4.0.tar.gz
  • Upload date:
  • Size: 492.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for invarlock-0.4.0.tar.gz
Algorithm Hash digest
SHA256 80371cdb0597abb11b7db27a2bab9127ae395c0509026fc613d31552d7097479
MD5 997ce218dc1582cb715d3c0090ac4c0b
BLAKE2b-256 ff18828893bc5816bfd861f23b425e91275d6dc3b65441bf4955e2607cc0e0f9

See more details on using hashes here.

Provenance

The following attestation bundles were made for invarlock-0.4.0.tar.gz:

Publisher: release.yml on invarlock/invarlock

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file invarlock-0.4.0-py3-none-any.whl.

File metadata

  • Download URL: invarlock-0.4.0-py3-none-any.whl
  • Upload date:
  • Size: 565.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for invarlock-0.4.0-py3-none-any.whl
Algorithm Hash digest
SHA256 ebc3d45a0ee42ff4f9cd68a74814b6ae5a204b6c7e25980a6f9348cecb78d615
MD5 efc1ccd35c23bfee14792925eae5f41a
BLAKE2b-256 59c9883b4cf9b62c7355b74580a37a73125f22c39bdbcea4ca8f13bf835cdb17

See more details on using hashes here.

Provenance

The following attestation bundles were made for invarlock-0.4.0-py3-none-any.whl:

Publisher: release.yml on invarlock/invarlock

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page