punchmark
No practitioner can currently re-certify an already-published benchmark number backwards from the responses it was computed on. A hosted route name persists while whatever serves it moves. Every runnable producer-identity tool needs fresh probes issued live to an endpoint that has since changed. punchmark is the retrospective half: point it at the response archive you already have and get a producer-identity verdict for the number you already published.
pip install punchmark
punchmark fit dev/*.jsonl.gz --candidates routeA,routeB --out model.pmk-model.json
punchmark score archive.jsonl.gz --model model.pmk-model.json --far 0.01
punchmark certify --ruling pmk-r-...
Four outputs:
- A fitted whole-set producer identifier with its printed miss-rate-versus-false-alarm curve over a named candidate set.
- A per-(route, window) ruling:
SAME-PRODUCER,SUBSTITUTEDorUNDETERMINED, issued at an operating point you declared yourself (as opposed to one you inherited).UNDETERMINEDis a verdict in its own right: it is what a passing statistic means when your archive could not have resolved the substitution you asked about. - A one-line certificate attachable to the published score: "producer identity of route R over window W HOLDS at false-alarm rate 0.01 against candidate set C."
- The minimum substituted fraction your k and item count could have resolved, so a null result reads as a power limit and not as reassurance.
What a verdict means, and what it does not
A ruling certifies the route label as served within a closed candidate set. It is
never a statement about model weights: a public route name does not denote a fixed
configuration, and punchmark does not repair that. A SAME-PRODUCER ruling means exactly
"a substitution of the declared fraction by any candidate in the set would have been
flagged with the calibrated power, and none was", and nothing more. See docs/honesty.md
for the full list of things a ruling does not show.
How it works
- Inputs: gzipped-JSONL response archives, one row per item with k draws of response text only: no logprobs, no headers, no timing. The route name comes from the archive filename (fixed by you at collection time); the collection window comes from a sidecar you write. Neither is ever inferred from content.
- Oracle: by construction. Cross-route labels score identification. Same-route subsets inside one window calibrate the false-alarm rate. Seeded substitutions (spliced from another route's rows over the identical item set) measure power.
- Discipline: every threshold is an empirical null quantile, cross-fitted so calibration optimism cannot silently overshoot the declared false-alarm rate. Every committed artifact is byte-stable and content-addressed. Rulings are append-only: a ruling can be superseded but is never edited. The CI gate fails any calibration move that arrives without a declared version bump.
Status
Pre-release (0.1.0 in preparation). The calibrated chargram detector, the reference
corpus manifest, the shipped default model and the held-out validation study
(validation/angle_a/FINDING.md) are all committed; the numbers in docs/validation.md
trace to committed derived artifacts. Nothing in this repository states or implies a
finding about the capabilities of any model.
Data provenance
The reference calibration corpus is defined over the committed response archives of the
public Spaghetti Architect benchmark,
pinned by commit and per-file hash in calibration/spaghetti/MANIFEST.json. No
completion text is re-published here; the command
punchmark corpus rebuild --corpus calibration/spaghetti --source <checkout>
verifies a local checkout byte-for-byte. Results in this repository are statements
about producer identity of those archives as re-analysed here. They are not claims
about, or corrections to, any capability table published from that benchmark
elsewhere.
License
MIT.
Metadata
Release files for punchmark 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| punchmark-0.1.0.tar.gz | 829.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| punchmark-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 1.7 MB
Release files / punchmark-0.1.0.tar.gz
| Download URL | punchmark-0.1.0.tar.gz |
|---|---|
| Size | 829.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
a87afd94f7014a05ab4cc1d675c38c5e9ef1291f022a125e2fd757acec8fbaec
|
|
BLAKE2b-256 checksum How to use checksums |
ee6790bfa2c7b65bfbbc626af66c649f286254945c151228011478b2e2bfa332
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 7, 2026.
Transparency logRelease files / punchmark-0.1.0-py3-none-any.whl
| Download URL | punchmark-0.1.0-py3-none-any.whl |
|---|---|
| Size | 842.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
5155e23d9f62bd9285394815506b09ef69d8a6a019e3684f71c6342497630701
|
|
BLAKE2b-256 checksum How to use checksums |
c782df52385baca85fb92a6aa011306f2f6e268b5c2ee8e2d29595b0682bea5c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 7, 2026.
Transparency log