# What Aspects of the ADR Detection System Are Not Included in the Open-Source Release?

> Discover what's missing from the open-source uber/ADR release. Learn which ADR detection system components like Prevention and Explorer are not included.

- Repository: [Uber Open Source/ADR](https://github.com/uber/ADR)
- Tags: internals
- Published: 2026-08-06

---

**The open-source uber/ADR release includes the Sensor, Detector, and Benchmark components, but excludes ADR Prevention (runtime blocking), ADR Explorer (offline red-teaming engine), and Uber's enterprise telemetry infrastructure.**

The **ADR (Automated Decision‑making Risk) research repository** from Uber provides researchers and practitioners with core tools for building and evaluating AI safety detectors. While the open-source distribution covers the foundational detection pipeline, several production-hardened components remain proprietary. This guide maps exactly what you get—and what's intentionally withheld.

## What Is Open-Source in uber/ADR

The repository ships three fully functional components installable from PyPI:

| Component | Purpose | Status |
|-----------|---------|--------|
| **ADR Sensor** | Real-time library that monitors program execution and emits structured events | ✅ Fully released |
| **ADR Detector** | Core inference engine consuming sensor events and flagging unsafe actions | ✅ Fully released |
| **ADR-Bench** | Benchmark suite evaluating detectors against synthetic attacks | ✅ Fully released |

These components form a complete research toolchain for detecting potentially unsafe actions in automated decision-making systems.

## Critical Components Missing From the Release

Three major subsystems are **explicitly excluded** from the open-source distribution. According to the top-level [`README.md`](https://github.com/uber/ADR/blob/main/README.md) and supporting documentation, these omissions are intentional due to dependencies on internal Uber infrastructure, proprietary data, or security-sensitive logic.

### ADR Prevention (Runtime Blocking Module)

The **ADR Prevention** module automatically intervenes to block unsafe actions before they cause harm. This runtime enforcement layer sits downstream of detection and represents the full production safety stack at Uber.

> "*ADR Prevention: Stop unsafe actions before they cause harm. This component is not included in the current open-source release*"
> — [`README.md`](https://github.com/uber/ADR/blob/main/README.md)【/__modal/volumes/vo-cSqLfqnnIwYXEonuEJnnZa/repos/github.com/uber/ADR/main/README.md】

Without this module, open-source users can **detect** unsafe behavior but cannot automatically **prevent** it in deployed systems. You must implement your own intervention logic.

### ADR Explorer (Offline Red-Teaming Engine)

The **ADR Explorer** is a heavyweight offline engine used for pre-deployment red-team testing and detector hardening. It enables systematic adversarial exploration of detector failure modes at scale.

> "*the offline **ADR Explorer** engine … is not included here.*"
> — [`README.md`](https://github.com/uber/ADR/blob/main/README.md)【/__modal/volumes/vo-cSqLfqnnIwYXEonuEJnnZa/repos/github.com/uber/ADR/main/README.md】

This omission means researchers cannot replicate Uber's internal red-teaming workflows or access the automated hardening pipelines that refine detectors before production deployment.

### Enterprise Telemetry and Production Results

Uber's **production deployment telemetry**—including detector-level metrics, incident reports, and performance data from Uber-scale environments—is withheld. The [`docs/REPRODUCIBILITY.md`](https://github.com/uber/ADR/blob/main/docs/REPRODUCIBILITY.md) file explicitly confirms:

| Artifact | Included? |
|----------|-----------|
| Synthetic benchmark results | ✅ Yes |
| Production deployment results (§6) | **No** — enterprise telemetry not included |

> Reference: [`docs/REPRODUCIBILITY.md`](https://github.com/uber/ADR/blob/main/docs/REPRODUCIBILITY.md)【/__modal/volumes/vo-cSqLfqnnIwYXEonuEJnnZa/repos/github.com/uber/ADR/main/docs/REPRODUCIBILITY.md】

This gap prevents independent verification of detector performance under real-world load distributions and attack patterns.

## Working With the Available Components

Despite these omissions, the open-source release provides sufficient tooling for research and prototyping. Below are canonical usage patterns for each released component.

### Installing Released Packages

```bash
pip install adr-sensor adr-detector adr-bench

```

### Emitting Events With ADR Sensor

The Sensor instruments Python processes and streams execution events. In [`Sensor/adr_sensor/observer.py`](https://github.com/uber/ADR/blob/main/Sensor/adr_sensor/observer.py), the core observer implementation handles event capture and serialization.

```python
from adr_sensor import observer, cli

# Start sensor in subprocess; instruments current Python process

cli.run()   # emits JSON-L stream of ADR events to stdout

```

For programmatic access to the event stream:

```python
from adr_sensor import observer

# Iterate over sensor events as Python objects

for event in observer.event_stream():
    print(event.timestamp, event.event_type, event.payload)

```

### Running Detection With ADR Detector

The detector implementation resides in [`Detection/main_detector.py`](https://github.com/uber/ADR/blob/main/Detection/main_detector.py). The `ADRDetector` class consumes sensor events and produces safety alerts.

```python
from adr_detector import main_detector

detector = main_detector.ADRDetector()

# Process events and flag unsafe actions

for event in observer.event_stream():
    alert = detector.process(event)
    if alert:
        print(f"⚠️ Unsafe action detected: {alert.severity}")
        print(f"   Category: {alert.category}")
        print(f"   Confidence: {alert.confidence:.3f}")

```

### Evaluating With ADR-Bench

Benchmark orchestration lives in [`Detection/benchmark/benchmark_pack.py`](https://github.com/uber/ADR/blob/main/Detection/benchmark/benchmark_pack.py). The `benchmark.run()` function executes standardized test suites.

```python
from adr_bench import benchmark

result = benchmark.run(
    detector=detector,
    suite="adr_bench_20251017_151604",  # Built-in synthetic attack suite

    timeout_seconds=30,
)

print(f"Benchmark score: {result.score:.4f}")
print(f"True positives: {result.tp}")
print(f"False positives: {result.fp}")
print(f"Latency p99: {result.latency_p99_ms}ms")

```

## Key Source Files and Documentation

| File | Role | Open-Source? |
|------|------|--------------|
| [`Sensor/adr_sensor/observer.py`](https://github.com/uber/ADR/blob/main/Sensor/adr_sensor/observer.py) | Event streaming and instrumentation | ✅ Yes |
| [`Detection/main_detector.py`](https://github.com/uber/ADR/blob/main/Detection/main_detector.py) | Inference pipeline implementation | ✅ Yes |
| [`Detection/benchmark/benchmark_pack.py`](https://github.com/uber/ADR/blob/main/Detection/benchmark/benchmark_pack.py) | Benchmark execution framework | ✅ Yes |
| [`README.md`](https://github.com/uber/ADR/blob/main/README.md) | Explicit inventory of included/excluded components | ✅ Yes |
| [`docs/REPRODUCIBILITY.md`](https://github.com/uber/ADR/blob/main/docs/REPRODUCIBILITY.md) | Reproducibility limits and missing artifacts | ✅ Yes |
| [`docs/OPEN_SOURCE_REVIEW.md`](https://github.com/uber/ADR/blob/main/docs/OPEN_SOURCE_REVIEW.md) | Official scope of open-source release | ✅ Yes |

These files provide both functional code and authoritative documentation on release boundaries.

## Why Uber Withheld These Components

The omitted pieces share common characteristics that make them unsuitable for open-source distribution:

- **Infrastructure coupling** — ADR Prevention and ADR Explorer depend on Uber's internal orchestration systems, sandboxes, and data pipelines
- **Proprietary data dependencies** — Training artifacts for the red-teaming engine incorporate Uber-specific operational data
- **Security sensitivity** — Detailed blocking logic and telemetry schemas could expose attack surfaces or operational patterns
- **Operational liability** — Automated intervention systems carry legal and safety implications when deployed outside controlled environments

## Summary

- **ADR Sensor, Detector, and Bench** constitute the complete open-source release from uber/ADR
- **ADR Prevention** (runtime blocking) is excluded—you must build your own intervention layer
- **ADR Explorer** (offline red-teaming) is excluded—no access to Uber's adversarial testing infrastructure
- **Enterprise telemetry and production results** are excluded—benchmark on synthetic data only
- All exclusions are **documented** in [`README.md`](https://github.com/uber/ADR/blob/main/README.md) and [`docs/REPRODUCIBILITY.md`](https://github.com/uber/ADR/blob/main/docs/REPRODUCIBILITY.md) with explicit rationale

## Frequently Asked Questions

### Can I automatically block unsafe actions with the open-source ADR release?

No. The **ADR Prevention** module that performs runtime blocking is explicitly excluded from the open-source distribution per [`README.md`](https://github.com/uber/ADR/blob/main/README.md). You can detect unsafe actions using `ADRDetector`, but any preventive intervention must be implemented independently.

### Is the ADR Explorer red-teaming tool available for independent research?

No. The **ADR Explorer** offline engine for systematic adversarial testing and detector hardening is not included in the release. The open-source `adr-bench` package provides synthetic benchmarks, but not the full red-teaming capabilities Uber uses internally.

### Why can't I reproduce the production deployment results from the ADR paper?

Uber's **enterprise telemetry pipelines** and production-scale deployment metrics are proprietary infrastructure not released open-source. As documented in [`docs/REPRODUCIBILITY.md`](https://github.com/uber/ADR/blob/main/docs/REPRODUCIBILITY.md), only synthetic benchmark results are reproducible; real-world performance data remains internal to Uber.