Capability Atlas Datasets and Models
Informative. This appendix records the datasets behind the Capability Atlas,
the gate each one sits behind, and the first models DCN serves from them. Every
served model is an advisory capability: capability != authority. An
output is evidence for a clinician or a DG authority decision, never an
authorization to act.
Open Atlas Explore to browse the Atlas: domains, capabilities, datasets and their gates.
Sources of truth:
- dataset manifest:
capability-atlas/datasets/datasets-v1.yaml - exact downloaded bytes:
capability-atlas/datasets/datasets-v1.lock.json - model artifacts:
capability-atlas/models/*.v1.json - Atlas node records:
capability-atlas/nodes/*.json - served components:
adapters/atlas-models(dcn-atlas-models-server)
Datasets
| Dataset | Domains | Gate | Status |
|---|---|---|---|
| NHANES 2017–March 2020 (CDC/NCHS), 16 files | cardiovascular, metabolic, renal, mental health, primary care | open | downloaded, hash-locked |
| UCI Breast Cancer Wisconsin (Diagnostic) | oncology | open (CC BY 4.0) | downloaded, hash-locked |
| UCI Heart Disease | cardiovascular | open (CC BY 4.0) | downloaded, benchmark only |
| UCI Chronic Kidney Disease | renal | open (CC BY 4.0) | downloaded, sanity check only |
| Synthea FHIR R4 | contract fixtures | open (generated) | not generated; needs Java, fixtures only |
| MIMIC-IV | renal, cardiovascular, metabolic | credentialed (PhysioNet DUA + CITI) | gate closed |
| UK Biobank | all six domains | application + fees | gate closed |
| Framingham (BioLINCC) | cardiovascular | application + IRB | gate closed |
| SEER Research | oncology | registration + DUA | gate closed |
| Swedish national registers | all six domains | ethics approval + register holder | gate closed |
| ProvidEHR / TakeCare records | primary care, CV, metabolic, renal | patient data: lawful basis, DPIA | gate closed |
| Metabolog via OpenBody contract | metabolic | partner: OpenBody #44 acceptance + consent | gate closed |
Only open datasets are fetched, by
capability-atlas/datasets/fetch_open_datasets.py. Downloads are cached outside
version control. The lock file binds each model to the exact bytes it was
trained on.
Held by sibling repositories
About 150 GB of further health, wearable and discovery data already sits in
sibling repositories. The manifest's held_elsewhere section records each
owner, location, licence and any existing models. DCN references these data
by owner and does not duplicate them. A DCN node may train on one only after
the owner publishes a hash-locked export and the licence permits the use.
| Dataset | Owner | Size |
|---|---|---|
| Open CGM cohorts (AZT1D, HUPA-UCM, T1D-UOM, Shanghai, UC_HT) | InVivo EHM | 2.7 GB |
| D1NAMO; BIG IDEAs | InVivo ECG2BG | 9.5 GB; 5.1 GB |
| PTB-XL, MIT-BIH, Icentia11k | InVivo BioSignalFM | 2.5 GB |
| NHANES 1999–2018 with mortality | InVivo EHM | 234 MB |
| WESAD; StudentLife | BrIAn / InnerState | 16 GB; 2.8 GB |
| ChEMBL 36, IEDB, PepBDB, LINCS | DiscoveryLab | 62 GB |
| Food-101, FoodX-251, Nutrition5k | InVivo food-model | 14 GB |
Open licence questions for the owners:
- PhysioCGM (23 GB). Its licence is no-derivatives. EHM excludes it from training, but ECG2BG trains on it.
- WESAD, CGMacros and WearableQA. These are non-commercial. That rules them out of any commercial DCN capability.
Contracts named in the current workstream have these data states:
- OpenBody #44 (whole-person state). A PR with synthetic fixtures only; the contract is not accepted.
- ProvidEHR #600 and TakeCare. Synthetic encounters, plus sanitized digests from one test-tenant read; no clinical content.
- Metabolog #1131 and #1145. Consumers pinned in OpenBody's mapping; no real cohort has been projected yet.
- Kline #181–#190, Memorex and OpenMind. Synthetic only.
Served components
| Component | Kind | Data | Holdout AUROC (95% CI) | Sens / Spec at threshold |
|---|---|---|---|---|
deterministic.ckd_epi_2021 | published equation | none | n/a | n/a |
deterministic.phq9 | published scoring | none | n/a | n/a |
metabolic.dysglycemia_screen | logistic regression, 7 inputs | NHANES, n=5,696 | 0.779 (0.729–0.819) | 0.87 / 0.57 |
renal.ckd_screen | logistic regression, 7 inputs | NHANES, n=6,327 | 0.753 (0.719–0.787) | 0.80 / 0.57 |
cardiovascular.hypertension_screen | logistic regression, 7 inputs | NHANES, n=4,390 | 0.739 (0.700–0.773) | 0.80 / 0.57 |
oncology.breast_fna_malignancy | logistic regression, 6 inputs | UCI WDBC, n=569 | 0.982 (0.959–0.999) | 0.92 / 0.99 |
Label definitions:
- Dysglycemia screen. HbA1c ≥ 6.5% in adults aged 20–79 never told they have diabetes.
- CKD screen. CKD-EPI 2021 eGFR < 60 or UACR ≥ 30 mg/g on a single measurement, in adults not told of weak or failing kidneys. The label is derived with the same CKD-EPI node that DCN serves.
- Hypertension screen. Mean of three oscillometric readings ≥ 140/90 mmHg in adults never told they have hypertension. The screen prioritises home-BP referral (
service.home_bp, NICE NG136); it does not replace BP measurement. - Breast FNA classifier. A research demonstrator only. It is prohibited for clinical use.
Limitations, which travel in every artifact's context_of_use:
- The NHANES models are cross-sectional prevalence screens, not prognostic risk models.
- They were trained unweighted on a complex survey sample. The survey-weighted holdout AUROC is reported alongside.
- No model has external validation, and none is validated for Swedish use.
- The Atlas evidence status is therefore
vendor_claim, notindependently_evaluated.
Invocation contract
The host binds loopback only (DCN_ATLAS_MODELS_LISTEN, default 127.0.0.1:8095):
GET /v1/atlas/components ComponentDescriptor[] with Atlas metadata
GET /v1/atlas/components/{id} one descriptor
POST /v1/atlas/components/{id}/invoke dcn.atlas-model-result.v1
Each result carries the following fields:
model_commitment: the SHA-256 of the exact artifact bytes compiled into the binary.input_commitment: the SHA-256 of the canonical input.authority: "advisory".- The output.
Inputs are fail-closed. The host rejects any of the following instead of extrapolating:
- missing fields
- unknown fields
- non-finite numbers
- non-binary values for binary fields
- values outside the range seen in training
Reproduction
python3 capability-atlas/datasets/fetch_open_datasets.py
python3 capability-atlas/models/train_atlas_models.py
python3 capability-atlas/models/build_atlas_nodes.py --check
cargo test --manifest-path adapters/atlas-models/Cargo.toml
cargo run --manifest-path adapters/atlas-models/Cargo.toml --bin dcn-atlas-models-server
cargo test replays golden vectors, so the Rust evaluator must reproduce the
scikit-learn probabilities to within 1e-9.
Data processing
Every Atlas node, dataset and set of consumption terms carries a dcn.atlas-processing.v1 facet (DCN #83). It records:
- where data is processed and stored, as a jurisdiction (ISO country code,
EU_EEAorunknown) plus an execution class (local, hospital edge, attested EU CFI, provider domain, public cloud) - retention and who can see plaintext
- for datasets, whether the data is personal and where it originates
- every transfer out of the EU/EEA, with its legal mechanism
Each location is claimed until an attestation reference makes it verified, and a claim never satisfies a verified requirement (#41). Personal data processed outside the EU/EEA without a recorded transfer is rejected.
Today every connected model and every held dataset is processed on the local machine in Sweden. That is still a claim, since no attestation of the location exists yet. Closed-gate datasets are not_processed.
Schema: capability-atlas/schema/processing.schema.json. Dataset facets: capability-atlas/datasets/processing-v1.yaml.
Selection enforces it before ranking (#85). A consumer states a hashable ProcessingRequirement covering:
- allowed residency (any, EU/EEA, or named jurisdictions)
- whether locations must be verified
- whether provider plaintext is forbidden
- maximum retention
- whether third-country transfers are allowed
Every offer or route is admitted or rejected against it before price is considered, with a reason. The requirement hash is recorded in the selection. A missing or unknown facet fails closed, a claimed location never meets a verified requirement, and fallback re-applies the same requirement, so it can never downgrade to a non-EU route.
Under the default EU healthcare requirement, only routes whose retention is recorded qualify (today, OpenAI EU with zero data retention, and local self-hosting). Azure EU, Bedrock Stockholm and Corti EU are refused until their retention terms are recorded, because unknown retention fails closed.
In Atlas Explore, Processing view colours the whole Atlas by processing location, and the EU/EEA-only, verified-only and no-provider-plaintext filters hide whatever does not qualify, with a count of what was hidden and why.
Numeric relation
The served models compute in one shared no_std core, adapters/atlas-eval (#86), under the profile dcn.atlas-numeric.ieee754-binary64+libm-0.2.16.v1. That means IEEE binary64 arithmetic, plus the pure-Rust libm crate at a pinned version for exp, log and pow, and never a platform maths library. The host and any proof guest therefore compute bit-identical results. The core's golden bit patterns hold on macOS arm64 and Linux arm64 with glibc.
Every descriptor and result carries a relation_commitment, which binds the model bytes to this numeric profile and core version. That commitment is what a computation proof will attest to (#82).
Switching from platform libm (which differs by up to 1 ulp between platforms) to the core changes no decision. capability-atlas/models/numeric-equivalence-v1.json records the comparison:
- Logistic screens: maximum probability difference of 1.8×10⁻¹⁵ over 200,000 samples per model, with no threshold flips.
- CKD-EPI 2021: maximum eGFR difference of 8.5×10⁻¹⁴ over 370,326 grid points, with no GFR-category flips.
Computation proofs
All six deterministic nodes have a verified RISC Zero 3.0.5 proof of one example invocation (#87); see capability-atlas/proofs/qualification-v1.json. The guest runs the same dcn-atlas-eval core as the server and hashes the model artifact inside the zkVM. It commits:
- the model commitment and relation commitment
- a salted input commitment
- the exact output bits, which are bit-identical to the served result
Inputs outside the admitted ranges produce a proven rejection. Verifying a receipt takes 15–64 ms and needs only the receipt and the pinned guest image id. Proving takes 20–26 s for CKD-EPI and PHQ-9 and 1.5–3.5 min for the logistic screens. These proofs establish computation correctness only: not clinical validity, not authority, and not yet input hiding (#89).
Consumption terms
The conditions for consuming a capability are recorded separately from the capability itself, as dcn.atlas-consumption-terms.v1 declarations (DCN #53):
- price and settlement
- capacity
- licence scope, retention and training rights
- jurisdiction
- credential prerequisites
- privacy
- delivery evidence
The rules:
- Stable contract identity. Terms bind to a stable
contract_digestover the capability and its input/output schemas, so several providers can compete on terms for the same contract. Each set of terms has its ownterms_id. - Monotonic revisions. Revisions only move forward, and expired terms are refused.
- No authority or evidence. Terms can never carry authority, lifecycle or evidence.
- Loss-explicit x403 projection. Terms project to x403 with a list of every field the projection omits.
- x403 discoveries enter as DISCOVERED. An external resource first seen through x403 is recorded as DISCOVERED, with its advertised claims kept as untrusted data.
Schema: capability-atlas/schema/consumption-terms.schema.json. Fixtures: capability-atlas/terms/fixtures. Semantics: adapters/atlas-models/src/terms.rs.
Gates to open next
Each gate below unlocks something specific, and none can be opened by an agent:
- Remote exposure. Needs a governed gateway, with an owner, that adds authentication and destination-bound egress authority (DCN #44–#47, the Kline gateway).
- Prognostic models. Need UK Biobank or Framingham access.
- Swedish context-of-use validation. Needs register ethics approval.
- Real-patient invocation. Needs acceptance of the ProvidEHR #600 and OpenBody #44 contracts, plus a DPIA.
- MIMIC-IV inpatient models. Need a named credentialed researcher.