What Aspects of the ADR Detection System Are Not Included in the Open-Source Release?
The open-source uber/ADR release includes the Sensor, Detector, and Benchmark components, but excludes ADR Prevention (runtime blocking), ADR Explorer (offline red-teaming engine), and Uber's enterprise telemetry infrastructure.
The ADR (Automated Decision‑making Risk) research repository from Uber provides researchers and practitioners with core tools for building and evaluating AI safety detectors. While the open-source distribution covers the foundational detection pipeline, several production-hardened components remain proprietary. This guide maps exactly what you get—and what's intentionally withheld.
What Is Open-Source in uber/ADR
The repository ships three fully functional components installable from PyPI:
| Component | Purpose | Status |
|---|---|---|
| ADR Sensor | Real-time library that monitors program execution and emits structured events | ✅ Fully released |
| ADR Detector | Core inference engine consuming sensor events and flagging unsafe actions | ✅ Fully released |
| ADR-Bench | Benchmark suite evaluating detectors against synthetic attacks | ✅ Fully released |
These components form a complete research toolchain for detecting potentially unsafe actions in automated decision-making systems.
Critical Components Missing From the Release
Three major subsystems are explicitly excluded from the open-source distribution. According to the top-level README.md and supporting documentation, these omissions are intentional due to dependencies on internal Uber infrastructure, proprietary data, or security-sensitive logic.
ADR Prevention (Runtime Blocking Module)
The ADR Prevention module automatically intervenes to block unsafe actions before they cause harm. This runtime enforcement layer sits downstream of detection and represents the full production safety stack at Uber.
"ADR Prevention: Stop unsafe actions before they cause harm. This component is not included in the current open-source release" —
README.md【/__modal/volumes/vo-cSqLfqnnIwYXEonuEJnnZa/repos/github.com/uber/ADR/main/README.md】
Without this module, open-source users can detect unsafe behavior but cannot automatically prevent it in deployed systems. You must implement your own intervention logic.
ADR Explorer (Offline Red-Teaming Engine)
The ADR Explorer is a heavyweight offline engine used for pre-deployment red-team testing and detector hardening. It enables systematic adversarial exploration of detector failure modes at scale.
"the offline ADR Explorer engine … is not included here." —
README.md【/__modal/volumes/vo-cSqLfqnnIwYXEonuEJnnZa/repos/github.com/uber/ADR/main/README.md】
This omission means researchers cannot replicate Uber's internal red-teaming workflows or access the automated hardening pipelines that refine detectors before production deployment.
Enterprise Telemetry and Production Results
Uber's production deployment telemetry—including detector-level metrics, incident reports, and performance data from Uber-scale environments—is withheld. The docs/REPRODUCIBILITY.md file explicitly confirms:
| Artifact | Included? |
|---|---|
| Synthetic benchmark results | ✅ Yes |
| Production deployment results (§6) | No — enterprise telemetry not included |
Reference:
docs/REPRODUCIBILITY.md【/__modal/volumes/vo-cSqLfqnnIwYXEonuEJnnZa/repos/github.com/uber/ADR/main/docs/REPRODUCIBILITY.md】
This gap prevents independent verification of detector performance under real-world load distributions and attack patterns.
Working With the Available Components
Despite these omissions, the open-source release provides sufficient tooling for research and prototyping. Below are canonical usage patterns for each released component.
Installing Released Packages
pip install adr-sensor adr-detector adr-bench
Emitting Events With ADR Sensor
The Sensor instruments Python processes and streams execution events. In Sensor/adr_sensor/observer.py, the core observer implementation handles event capture and serialization.
from adr_sensor import observer, cli
# Start sensor in subprocess; instruments current Python process
cli.run() # emits JSON-L stream of ADR events to stdout
For programmatic access to the event stream:
from adr_sensor import observer
# Iterate over sensor events as Python objects
for event in observer.event_stream():
print(event.timestamp, event.event_type, event.payload)
Running Detection With ADR Detector
The detector implementation resides in Detection/main_detector.py. The ADRDetector class consumes sensor events and produces safety alerts.
from adr_detector import main_detector
detector = main_detector.ADRDetector()
# Process events and flag unsafe actions
for event in observer.event_stream():
alert = detector.process(event)
if alert:
print(f"⚠️ Unsafe action detected: {alert.severity}")
print(f" Category: {alert.category}")
print(f" Confidence: {alert.confidence:.3f}")
Evaluating With ADR-Bench
Benchmark orchestration lives in Detection/benchmark/benchmark_pack.py. The benchmark.run() function executes standardized test suites.
from adr_bench import benchmark
result = benchmark.run(
detector=detector,
suite="adr_bench_20251017_151604", # Built-in synthetic attack suite
timeout_seconds=30,
)
print(f"Benchmark score: {result.score:.4f}")
print(f"True positives: {result.tp}")
print(f"False positives: {result.fp}")
print(f"Latency p99: {result.latency_p99_ms}ms")
Key Source Files and Documentation
| File | Role | Open-Source? |
|---|---|---|
Sensor/adr_sensor/observer.py |
Event streaming and instrumentation | ✅ Yes |
Detection/main_detector.py |
Inference pipeline implementation | ✅ Yes |
Detection/benchmark/benchmark_pack.py |
Benchmark execution framework | ✅ Yes |
README.md |
Explicit inventory of included/excluded components | ✅ Yes |
docs/REPRODUCIBILITY.md |
Reproducibility limits and missing artifacts | ✅ Yes |
docs/OPEN_SOURCE_REVIEW.md |
Official scope of open-source release | ✅ Yes |
These files provide both functional code and authoritative documentation on release boundaries.
Why Uber Withheld These Components
The omitted pieces share common characteristics that make them unsuitable for open-source distribution:
- Infrastructure coupling — ADR Prevention and ADR Explorer depend on Uber's internal orchestration systems, sandboxes, and data pipelines
- Proprietary data dependencies — Training artifacts for the red-teaming engine incorporate Uber-specific operational data
- Security sensitivity — Detailed blocking logic and telemetry schemas could expose attack surfaces or operational patterns
- Operational liability — Automated intervention systems carry legal and safety implications when deployed outside controlled environments
Summary
- ADR Sensor, Detector, and Bench constitute the complete open-source release from uber/ADR
- ADR Prevention (runtime blocking) is excluded—you must build your own intervention layer
- ADR Explorer (offline red-teaming) is excluded—no access to Uber's adversarial testing infrastructure
- Enterprise telemetry and production results are excluded—benchmark on synthetic data only
- All exclusions are documented in
README.mdanddocs/REPRODUCIBILITY.mdwith explicit rationale
Frequently Asked Questions
Can I automatically block unsafe actions with the open-source ADR release?
No. The ADR Prevention module that performs runtime blocking is explicitly excluded from the open-source distribution per README.md. You can detect unsafe actions using ADRDetector, but any preventive intervention must be implemented independently.
Is the ADR Explorer red-teaming tool available for independent research?
No. The ADR Explorer offline engine for systematic adversarial testing and detector hardening is not included in the release. The open-source adr-bench package provides synthetic benchmarks, but not the full red-teaming capabilities Uber uses internally.
Why can't I reproduce the production deployment results from the ADR paper?
Uber's enterprise telemetry pipelines and production-scale deployment metrics are proprietary infrastructure not released open-source. As documented in docs/REPRODUCIBILITY.md, only synthetic benchmark results are reproducible; real-world performance data remains internal to Uber.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →