Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Capability Atlas Datasets and Models

Informative. This appendix records the datasets behind the Capability Atlas, the gate each one sits behind, and the first models DCN serves from them. Every served model is an advisory capability: capability != authority. An output is evidence for a clinician or a DG authority decision, never an authorization to act.

Open Atlas Explore to browse the Atlas: domains, capabilities, datasets and their gates.

Sources of truth:

  • dataset manifest: capability-atlas/datasets/datasets-v1.yaml
  • exact downloaded bytes: capability-atlas/datasets/datasets-v1.lock.json
  • model artifacts: capability-atlas/models/*.v1.json
  • Atlas node records: capability-atlas/nodes/*.json
  • served components: adapters/atlas-models (dcn-atlas-models-server)

Datasets

DatasetDomainsGateStatus
NHANES 2017–March 2020 (CDC/NCHS), 16 filescardiovascular, metabolic, renal, mental health, primary careopendownloaded, hash-locked
UCI Breast Cancer Wisconsin (Diagnostic)oncologyopen (CC BY 4.0)downloaded, hash-locked
UCI Heart Diseasecardiovascularopen (CC BY 4.0)downloaded, benchmark only
UCI Chronic Kidney Diseaserenalopen (CC BY 4.0)downloaded, sanity check only
Synthea FHIR R4contract fixturesopen (generated)not generated; needs Java, fixtures only
MIMIC-IVrenal, cardiovascular, metaboliccredentialed (PhysioNet DUA + CITI)gate closed
UK Biobankall six domainsapplication + feesgate closed
Framingham (BioLINCC)cardiovascularapplication + IRBgate closed
SEER Researchoncologyregistration + DUAgate closed
Swedish national registersall six domainsethics approval + register holdergate closed
ProvidEHR / TakeCare recordsprimary care, CV, metabolic, renalpatient data: lawful basis, DPIAgate closed
Metabolog via OpenBody contractmetabolicpartner: OpenBody #44 acceptance + consentgate closed

Only open datasets are fetched, by capability-atlas/datasets/fetch_open_datasets.py. Downloads are cached outside version control. The lock file binds each model to the exact bytes it was trained on.

Held by sibling repositories

About 150 GB of further health, wearable and discovery data already sits in sibling repositories. The manifest's held_elsewhere section records each owner, location, licence and any existing models. DCN references these data by owner and does not duplicate them. A DCN node may train on one only after the owner publishes a hash-locked export and the licence permits the use.

DatasetOwnerSize
Open CGM cohorts (AZT1D, HUPA-UCM, T1D-UOM, Shanghai, UC_HT)InVivo EHM2.7 GB
D1NAMO; BIG IDEAsInVivo ECG2BG9.5 GB; 5.1 GB
PTB-XL, MIT-BIH, Icentia11kInVivo BioSignalFM2.5 GB
NHANES 1999–2018 with mortalityInVivo EHM234 MB
WESAD; StudentLifeBrIAn / InnerState16 GB; 2.8 GB
ChEMBL 36, IEDB, PepBDB, LINCSDiscoveryLab62 GB
Food-101, FoodX-251, Nutrition5kInVivo food-model14 GB

Open licence questions for the owners:

  • PhysioCGM (23 GB). Its licence is no-derivatives. EHM excludes it from training, but ECG2BG trains on it.
  • WESAD, CGMacros and WearableQA. These are non-commercial. That rules them out of any commercial DCN capability.

Contracts named in the current workstream have these data states:

  • OpenBody #44 (whole-person state). A PR with synthetic fixtures only; the contract is not accepted.
  • ProvidEHR #600 and TakeCare. Synthetic encounters, plus sanitized digests from one test-tenant read; no clinical content.
  • Metabolog #1131 and #1145. Consumers pinned in OpenBody's mapping; no real cohort has been projected yet.
  • Kline #181–#190, Memorex and OpenMind. Synthetic only.

Served components

ComponentKindDataHoldout AUROC (95% CI)Sens / Spec at threshold
deterministic.ckd_epi_2021published equationnonen/an/a
deterministic.phq9published scoringnonen/an/a
metabolic.dysglycemia_screenlogistic regression, 7 inputsNHANES, n=5,6960.779 (0.729–0.819)0.87 / 0.57
renal.ckd_screenlogistic regression, 7 inputsNHANES, n=6,3270.753 (0.719–0.787)0.80 / 0.57
cardiovascular.hypertension_screenlogistic regression, 7 inputsNHANES, n=4,3900.739 (0.700–0.773)0.80 / 0.57
oncology.breast_fna_malignancylogistic regression, 6 inputsUCI WDBC, n=5690.982 (0.959–0.999)0.92 / 0.99

Label definitions:

  • Dysglycemia screen. HbA1c ≥ 6.5% in adults aged 20–79 never told they have diabetes.
  • CKD screen. CKD-EPI 2021 eGFR < 60 or UACR ≥ 30 mg/g on a single measurement, in adults not told of weak or failing kidneys. The label is derived with the same CKD-EPI node that DCN serves.
  • Hypertension screen. Mean of three oscillometric readings ≥ 140/90 mmHg in adults never told they have hypertension. The screen prioritises home-BP referral (service.home_bp, NICE NG136); it does not replace BP measurement.
  • Breast FNA classifier. A research demonstrator only. It is prohibited for clinical use.

Limitations, which travel in every artifact's context_of_use:

  • The NHANES models are cross-sectional prevalence screens, not prognostic risk models.
  • They were trained unweighted on a complex survey sample. The survey-weighted holdout AUROC is reported alongside.
  • No model has external validation, and none is validated for Swedish use.
  • The Atlas evidence status is therefore vendor_claim, not independently_evaluated.

Invocation contract

The host binds loopback only (DCN_ATLAS_MODELS_LISTEN, default 127.0.0.1:8095):

GET  /v1/atlas/components               ComponentDescriptor[] with Atlas metadata
GET  /v1/atlas/components/{id}          one descriptor
POST /v1/atlas/components/{id}/invoke   dcn.atlas-model-result.v1

Each result carries the following fields:

  • model_commitment: the SHA-256 of the exact artifact bytes compiled into the binary.
  • input_commitment: the SHA-256 of the canonical input.
  • authority: "advisory".
  • The output.

Inputs are fail-closed. The host rejects any of the following instead of extrapolating:

  • missing fields
  • unknown fields
  • non-finite numbers
  • non-binary values for binary fields
  • values outside the range seen in training

Reproduction

python3 capability-atlas/datasets/fetch_open_datasets.py
python3 capability-atlas/models/train_atlas_models.py
python3 capability-atlas/models/build_atlas_nodes.py --check
cargo test --manifest-path adapters/atlas-models/Cargo.toml
cargo run --manifest-path adapters/atlas-models/Cargo.toml --bin dcn-atlas-models-server

cargo test replays golden vectors, so the Rust evaluator must reproduce the scikit-learn probabilities to within 1e-9.

Data processing

Every Atlas node, dataset and set of consumption terms carries a dcn.atlas-processing.v1 facet (DCN #83). It records:

  • where data is processed and stored, as a jurisdiction (ISO country code, EU_EEA or unknown) plus an execution class (local, hospital edge, attested EU CFI, provider domain, public cloud)
  • retention and who can see plaintext
  • for datasets, whether the data is personal and where it originates
  • every transfer out of the EU/EEA, with its legal mechanism

Each location is claimed until an attestation reference makes it verified, and a claim never satisfies a verified requirement (#41). Personal data processed outside the EU/EEA without a recorded transfer is rejected.

Today every connected model and every held dataset is processed on the local machine in Sweden. That is still a claim, since no attestation of the location exists yet. Closed-gate datasets are not_processed.

Schema: capability-atlas/schema/processing.schema.json. Dataset facets: capability-atlas/datasets/processing-v1.yaml.

Selection enforces it before ranking (#85). A consumer states a hashable ProcessingRequirement covering:

  • allowed residency (any, EU/EEA, or named jurisdictions)
  • whether locations must be verified
  • whether provider plaintext is forbidden
  • maximum retention
  • whether third-country transfers are allowed

Every offer or route is admitted or rejected against it before price is considered, with a reason. The requirement hash is recorded in the selection. A missing or unknown facet fails closed, a claimed location never meets a verified requirement, and fallback re-applies the same requirement, so it can never downgrade to a non-EU route.

Under the default EU healthcare requirement, only routes whose retention is recorded qualify (today, OpenAI EU with zero data retention, and local self-hosting). Azure EU, Bedrock Stockholm and Corti EU are refused until their retention terms are recorded, because unknown retention fails closed.

In Atlas Explore, Processing view colours the whole Atlas by processing location, and the EU/EEA-only, verified-only and no-provider-plaintext filters hide whatever does not qualify, with a count of what was hidden and why.

Numeric relation

The served models compute in one shared no_std core, adapters/atlas-eval (#86), under the profile dcn.atlas-numeric.ieee754-binary64+libm-0.2.16.v1. That means IEEE binary64 arithmetic, plus the pure-Rust libm crate at a pinned version for exp, log and pow, and never a platform maths library. The host and any proof guest therefore compute bit-identical results. The core's golden bit patterns hold on macOS arm64 and Linux arm64 with glibc.

Every descriptor and result carries a relation_commitment, which binds the model bytes to this numeric profile and core version. That commitment is what a computation proof will attest to (#82).

Switching from platform libm (which differs by up to 1 ulp between platforms) to the core changes no decision. capability-atlas/models/numeric-equivalence-v1.json records the comparison:

  • Logistic screens: maximum probability difference of 1.8×10⁻¹⁵ over 200,000 samples per model, with no threshold flips.
  • CKD-EPI 2021: maximum eGFR difference of 8.5×10⁻¹⁴ over 370,326 grid points, with no GFR-category flips.

Computation proofs

All six deterministic nodes have a verified RISC Zero 3.0.5 proof of one example invocation (#87); see capability-atlas/proofs/qualification-v1.json. The guest runs the same dcn-atlas-eval core as the server and hashes the model artifact inside the zkVM. It commits:

  • the model commitment and relation commitment
  • a salted input commitment
  • the exact output bits, which are bit-identical to the served result

Inputs outside the admitted ranges produce a proven rejection. Verifying a receipt takes 15–64 ms and needs only the receipt and the pinned guest image id. Proving takes 20–26 s for CKD-EPI and PHQ-9 and 1.5–3.5 min for the logistic screens. These proofs establish computation correctness only: not clinical validity, not authority, and not yet input hiding (#89).

Consumption terms

The conditions for consuming a capability are recorded separately from the capability itself, as dcn.atlas-consumption-terms.v1 declarations (DCN #53):

  • price and settlement
  • capacity
  • licence scope, retention and training rights
  • jurisdiction
  • credential prerequisites
  • privacy
  • delivery evidence

The rules:

  • Stable contract identity. Terms bind to a stable contract_digest over the capability and its input/output schemas, so several providers can compete on terms for the same contract. Each set of terms has its own terms_id.
  • Monotonic revisions. Revisions only move forward, and expired terms are refused.
  • No authority or evidence. Terms can never carry authority, lifecycle or evidence.
  • Loss-explicit x403 projection. Terms project to x403 with a list of every field the projection omits.
  • x403 discoveries enter as DISCOVERED. An external resource first seen through x403 is recorded as DISCOVERED, with its advertised claims kept as untrusted data.

Schema: capability-atlas/schema/consumption-terms.schema.json. Fixtures: capability-atlas/terms/fixtures. Semantics: adapters/atlas-models/src/terms.rs.

Gates to open next

Each gate below unlocks something specific, and none can be opened by an agent:

  • Remote exposure. Needs a governed gateway, with an owner, that adds authentication and destination-bound egress authority (DCN #44–#47, the Kline gateway).
  • Prognostic models. Need UK Biobank or Framingham access.
  • Swedish context-of-use validation. Needs register ethics approval.
  • Real-patient invocation. Needs acceptance of the ProvidEHR #600 and OpenBody #44 contracts, plus a DPIA.
  • MIMIC-IV inpatient models. Need a named credentialed researcher.