How Hyperresearch Ensures Adversarial Verification of Citations: A 4‑Layer Defense System

Hyperresearch enforces adversarial verification of citations through a deterministic, multi‑layered pipeline that combines mechanical triage, LLM‑based verification, adversarial lint rules, and mandatory audit gates to block unsupported claims before they reach the final report.

The jordan-gibbs/hyperresearch repository implements a rigorous adversarial verification system designed to eliminate hallucinated citations and unsupported claims from research reports. By combining deterministic mechanical checks with targeted LLM analysis and mandatory audit barriers, Hyperresearch ensures that every citation in a synthesized report is traceable, accurate, and ethically sound. This open‑source framework treats citation verification as an adversarial process where multiple independent layers must be satisfied before any claim can be certified as valid.

Layer 1: Mechanical Triage for Rapid Validation

The first line of defense operates in src/hyperresearch/core/citecheck.py through the triage_pairs() function, which performs high‑speed mechanical validation without LLM inference. According to the source code at lines 14–22, this layer auto‑passes citation pairs when numeric values in the claim appear verbatim in the cited note, or when a six‑word shingle from the source text is detected in the citation sentence. By filtering out obvious matches deterministically, the system avoids expensive LLM calls for trivial cases while maintaining strict verification standards.

Layer 2: LLM Verification for Complex Citations

When mechanical triage cannot resolve a pair, the sample_needs_llm() function deterministically samples the remaining citations—including all "strong" citations plus a configurable fraction of the remainder. As implemented in lines 76–94 of citecheck.py, these cases are routed to the dedicated hyperresearch‑cite‑checker agent, which inspects note bodies and returns a categorical verdict: supported, partially‑supported, unsupported, or wrong‑source. This targeted approach ensures that LLM computational resources are reserved for ambiguous or high‑stakes verification scenarios where pattern matching fails.

Layer 3: Adversarial Lint Rules

After LLM verification, the hyperresearch lint command enforces three adversarial verification rules defined in src/hyperresearch/cli/lint.py (lines 1668–1771). These rules act as a secondary filter to catch subtle errors that might escape neural network analysis:

  • Quote‑integrity: Detects hallucinated quotes by verifying that every quotation exists verbatim in the source note.
  • Numeric‑consistency: Traces every number in the report back to its origin in the cited material.
  • Retracted‑citations: Identifies citations pointing to notes flagged as retracted or invalidated.

Layer 4: Self‑Certification Audit Gate

The final barrier is implemented in the same lint.py module (lines 1700–1790), which parses research/audit_findings.json to verify that a recent conformance audit has been completed. The gate checks that all CRITICAL findings from the audit carry a non‑null fixed_at timestamp. If unresolved critical issues remain, the system blocks the synthesize --save operation, preventing publication of non‑conforming reports. This creates an immutable checkpoint that cannot be bypassed without documented remediation.

The Complete Verification Workflow

Together, these four layers create an adversarial verification loop where each stage assumes the previous might have failed. The deterministic nature of the sampling—avoiding randomness—ensures reproducibility, while the lint rules provide explicit, rule‑based validation that complements the probabilistic nature of LLM verification. Because the save gate requires both successful linting and a clean audit trail, researchers cannot inadvertently publish reports containing invalid citations.

Running the Adversarial Verification Pipeline

To execute the full adversarial verification workflow on your research vault:


# Step 1: Generate citation pairs with mechanical and LLM tiers

hyperresearch citecheck --vault path/to/vault --tag nightly

# Step 2: Run specific adversarial lint rules

hyperresearch lint --rule quote-integrity
hyperresearch lint --rule numeric-consistency
hyperresearch lint --rule retracted-citations

# Step 3: Complete mandatory audits

hyperresearch audit --mode conformance
hyperresearch audit --mode comprehensiveness

# Step 4: Attempt synthesis (blocked if any gate fails)

hyperresearch synthesize --save

The --rule flag can be combined with -j to output JSON for CI/CD pipelines, enabling automated verification in research workflows.

Summary

  • Four-layer defense: Hyperresearch combines mechanical triage, LLM verification, adversarial lint rules, and audit gates to verify citations.
  • Deterministic sampling: The sample_needs_llm() function uses configurable but deterministic selection to ensure reproducible verification.
  • Immutable barriers: The audit gate in src/hyperresearch/cli/lint.py physically blocks synthesis if critical findings remain unresolved.
  • Rule-based validation: Three specific lint rules (quote‑integrity, numeric‑consistency, retracted‑citations) catch edge cases that neural networks might miss.
  • CLI integration: All verification layers are accessible via the hyperresearch CLI, supporting both interactive and automated research workflows.

Frequently Asked Questions

What constitutes adversarial verification in Hyperresearch?

Adversarial verification in Hyperresearch refers to the multi‑layered validation architecture where each tier assumes the previous layers may have failed. By requiring mechanical triage, LLM analysis, lint rules, and independent audits to all pass before allowing a report to be saved, the system treats citation validation as an adversarial process that actively resists attempts to insert unsupported claims.

How does the mechanical triage layer decide which citations to auto‑pass?

The triage_pairs() function in src/hyperresearch/core/citecheck.py auto‑passes citations when numeric values in the claim appear in the cited note, or when a six‑word shingle from the source text is found in the citation sentence. This heuristic‑based approach filters out trivial matches without consuming LLM resources.

What happens if the audit gate detects unresolved critical findings?

If the audit gate parses research/audit_findings.json and discovers CRITICAL findings without a fixed_at timestamp, it blocks the synthesize --save command and reports the specific unfixed issues. The researcher must remediate these findings and re‑run the audit before the synthesis can be completed.

Can the verification pipeline be bypassed to force a report save?

No. The hyperresearch CLI enforces that research/audit_findings.json must contain a recent conformance audit with all critical issues resolved. Because the save operation requires passing both the lint rules and the audit gate, there is no command‑line flag or configuration setting that allows bypassing these adversarial verification layers.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →