mirror of
https://github.com/ruvnet/RuView
synced 2026-08-11 20:41:44 +00:00
16b2a629d1
VEIL (Verifiable Emission-shaping for Identity-Leakage prevention) is the countermeasure counterpart to BFLD (ADR-118/121): where BFLD detects when beamforming feedback becomes identifying, VEIL shapes a node's own outgoing feedback so an unauthorized passive sniffer cannot re-identify people, while a legitimate receiver that shares the per-session key sees an unchanged link. Mechanism: identity leaks through the fine cross-subcarrier phase structure of a compressed beamforming report; throughput rides the dominant beam direction. These are (mostly) separable subspaces. VEIL composes extra keyed Givens rotations (the report's native primitive) over the fine subspace only. The rotation is orthogonal (energy-preserving -> not jamming), keyed per session (the AP inverts it -> throughput preserved), and fresh each session (a sniffer cannot average it back -> re-identification collapses to chance). Contents: - v2/crates/wifi-densepose-privshield: deterministic, dependency-free, WASM-ready pure-compute leaf implementing the attacker-vs-protector experiment, the four compliant controls, a throughput model, a machine-checkable "not jamming" compliance audit, and a pinned witness. 29 tests + doctest pass; clippy -D warnings clean; builds for wasm32-unknown-unknown. - docs/research/privacy-shield: 8-file research bundle (SOTA, threat model, design, compliance/regulatory, experiment protocol, market, roadmap). - docs/adr/ADR-288: formal decision record. Reference results (SYNTHETIC / L0, N=16 identities): passive re-ID accuracy 100% shield-off -> 7.8% shield-on (chance 6.25%); modeled throughput ratio 98.0%; emission energy ratio 1.000000 (compliant). All defense numbers are SYNTHETIC until a two-node hardware capture with a witness exists. Compliant waveform controls only; never jamming (47 U.S.C. 333/302a analysis in the bundle). Co-Authored-By: claude-flow <ruv@ruv.net> Claude-Session: https://claude.ai/code/session_01WEXNqzs7UsfNFBcP5yW21p
254 lines
11 KiB
TOML
254 lines
11 KiB
TOML
[workspace]
|
|
resolver = "2"
|
|
members = [
|
|
"crates/wifi-densepose-core",
|
|
"crates/wifi-densepose-signal",
|
|
"crates/wifi-densepose-nn",
|
|
# wifi-densepose-api / -db / -config: removed in #578.
|
|
# The crate names were reserved early for an envisioned REST/database/config
|
|
# split, but no implementation followed and no code referenced them. The
|
|
# functionality they would provide is covered today by:
|
|
# - REST/WS: `wifi-densepose-sensing-server` (Axum)
|
|
# - Config: per-crate config + CLI args in `wifi-densepose-sensing-server`
|
|
# and `wifi-densepose-desktop`
|
|
# - DB: no persistent state; system is real-time
|
|
# If we ever need any of these as a published surface, they can be
|
|
# reintroduced with a real implementation.
|
|
"crates/wifi-densepose-hardware",
|
|
"crates/wifi-densepose-wasm",
|
|
"crates/wifi-densepose-cli",
|
|
"crates/wifi-densepose-mat",
|
|
"crates/wifi-densepose-train",
|
|
"crates/wifi-densepose-sensing-server",
|
|
"crates/wifi-densepose-aether", # ADR-185 §13 — AETHER pure-compute leaf (std-only)
|
|
"crates/wifi-densepose-privshield", # ADR-288 — VEIL privacy shield (compliant-waveform anti-sensing; std-only leaf)
|
|
"crates/wifi-densepose-wifiscan",
|
|
"crates/wifi-densepose-vitals",
|
|
"crates/wifi-densepose-ruvector",
|
|
"crates/wifi-densepose-desktop",
|
|
"crates/wifi-densepose-pointcloud",
|
|
# geo + worldgraph extracted to ruvnet/worldgraph submodule (see crates/worldgraph)
|
|
"crates/wifi-densepose-engine", # ADR-135..146 integration/composition layer
|
|
"crates/wifi-densepose-calibration", # ADR-151 — per-room calibration & specialist training
|
|
# ADR-271 — Cognitum OAuth access-token verification. RuView as an OAuth
|
|
# RESOURCE SERVER: offline ES256/JWKS verification of tokens issued by
|
|
# auth.cognitum.one, so a user signs in to their own sensing server with
|
|
# their Cognitum identity instead of a shared static bearer. No login flow
|
|
# and no outbound Cognitum API calls live here — verification only.
|
|
"crates/ruview-auth",
|
|
"crates/nvsim",
|
|
"crates/nvsim-server",
|
|
"crates/homecore", # ADR-127 — HOMECORE state machine
|
|
"crates/homecore-plugins", # ADR-128 — HOMECORE-PLUGINS WASM runtime (P1 scaffold)
|
|
"crates/homecore-api", # ADR-130 — HOMECORE REST + WS API
|
|
"crates/homecore-automation", # ADR-129 — HOMECORE automation engine
|
|
"crates/homecore-recorder", # ADR-132 — HOMECORE state recorder
|
|
"crates/homecore-migrate", # ADR-134 — HOMECORE migration from Python HA
|
|
# ADR-100/ADR-101: Cognitum Cog packaging — first Cog from this repo.
|
|
# Ships the wifi-densepose pose-estimation model as a signed binary +
|
|
# JSONL manifest installable by the Cognitum V0 appliance (cognitum-v0,
|
|
# cognitum-cluster-*, ruvultra). The companion appliance-side crate
|
|
# lives in cognitum-one/v0-appliance as `cognitum-pose-estimation`.
|
|
"crates/cog-pose-estimation",
|
|
# ADR-103: Learned multi-person counter (SOTA path) — replaces the
|
|
# PR #491 slot heuristic with a Candle network + Stoer-Wagner fusion.
|
|
# Motivated by #499 ghost-skeleton reports.
|
|
"crates/cog-person-count",
|
|
# ADR-116: Home Assistant + Matter Cognitum Seed cog. Wraps the
|
|
# ADR-115 MQTT publisher as a Seed-installable artifact with
|
|
# mDNS, embedded broker, RuVector thresholds, Ed25519 witness.
|
|
"crates/cog-ha-matter",
|
|
# ADR-118: BFLD — Beamforming Feedback Layer for Detection. The
|
|
# privacy/safety layer that measures and gates identity leakage from
|
|
# WiFi BFI captures. Sub-ADRs: 119 (frame), 120 (privacy class),
|
|
# 121 (identity risk), 122 (HA/Matter), 123 (capture path).
|
|
"crates/wifi-densepose-bfld",
|
|
# ADR-147: OccWorld thin-client bridge — WorldGraph PersonTrack history →
|
|
# OccWorld Python subprocess → TrajectoryPrior injection into pose tracker.
|
|
# worldmodel extracted to ruvnet/worldgraph submodule (consumed via path dep)
|
|
# ADR-147 (Phase 5): OccWorld TransVQVAE ported to Candle — native Rust
|
|
# inference without Python/IPC overhead. Loaded alongside the Python bridge
|
|
# as a faster alternative once Phase-5 weights are available.
|
|
"crates/wifi-densepose-occworld-candle",
|
|
# rvCSI — edge RF sensing runtime (ADR-095 platform, ADR-096 FFI/crate layout):
|
|
# lives in its own repo (https://github.com/ruvnet/rvcsi), vendored here as
|
|
# `vendor/rvcsi` and published to crates.io as `rvcsi-*` 0.3.x. Depend on the
|
|
# published crates (or the submodule's `crates/rvcsi-*` paths) — not as v2
|
|
# workspace members, since `vendor/rvcsi/Cargo.toml` is its own workspace.
|
|
"crates/homecore-hap", # ADR-125 — Apple Home HomeKit Accessory Protocol bridge
|
|
"crates/homecore-assist", # ADR-133 — HOMECORE voice assistant + ruflo bridge
|
|
"crates/homecore-server", # iter-9 — HOMECORE integration binary (all 8 crates wired together)
|
|
"crates/ruview-swarm", # ADR-148 — drone swarm control system
|
|
# ADR-273..277 — unified RF spatial world model: canonical RF tensor +
|
|
# hardware adapters, universal foundation encoder (masked-reconstruction
|
|
# pretraining, ≤1% task adapters), RF-aware Gaussian spatial memory,
|
|
# physics-guided synthetic RF worlds, edge sensing control plane.
|
|
"crates/ruview-unified",
|
|
# ADR-262 P1 — anti-corruption bridge converting RuView WiFi-CSI sensing
|
|
# output into signed RuField FieldEvents. Path-deps the `vendor/rufield`
|
|
# submodule crates (rufield-core/-provenance/-privacy/-fusion); single
|
|
# coupling point between RuView and the standalone RuField MFS spec.
|
|
"crates/wifi-densepose-rufield",
|
|
# ADR-287 — coherent wideband RF tomography research crate: synthetic
|
|
# stepped-frequency multi-position measurement simulation + delay-and-sum
|
|
# backprojection reconstruction. Standalone leaf (nvsim pattern), zero
|
|
# hardware coupling, every number SYNTHETIC/L0 until real wideband RF
|
|
# hardware exists.
|
|
"crates/wifi-densepose-sar",
|
|
]
|
|
# ADR-040: WASM edge crate targets wasm32-unknown-unknown (no_std),
|
|
# excluded from workspace to avoid breaking `cargo test --workspace`.
|
|
# Build separately: cargo build -p wifi-densepose-wasm-edge --target wasm32-unknown-unknown --release
|
|
#
|
|
# ADR-128 P2: example WASM plugin — also wasm32-only (no_std, cdylib),
|
|
# excluded for the same reason. Build separately:
|
|
# cargo build --target wasm32-unknown-unknown --release -p homecore-plugin-example
|
|
exclude = [
|
|
"crates/wifi-densepose-wasm-edge",
|
|
"crates/homecore-plugin-example",
|
|
"crates/worldgraph", # ruvnet/worldgraph submodule — its own workspace (geo/worldgraph/worldmodel)
|
|
]
|
|
|
|
[workspace.package]
|
|
version = "0.3.1"
|
|
edition = "2021"
|
|
authors = ["rUv <ruv@ruv.net>", "WiFi-DensePose Contributors"]
|
|
license = "MIT OR Apache-2.0"
|
|
repository = "https://github.com/ruvnet/wifi-densepose"
|
|
documentation = "https://docs.rs/wifi-densepose"
|
|
keywords = ["wifi", "densepose", "csi", "pose-estimation", "rust"]
|
|
categories = ["science", "computer-vision", "wasm"]
|
|
|
|
[workspace.dependencies]
|
|
# Core utilities
|
|
thiserror = "2.0"
|
|
anyhow = "1.0"
|
|
serde = { version = "1.0", features = ["derive"] }
|
|
serde_json = "1.0"
|
|
serde_yaml = "0.9"
|
|
tokio = { version = "1.35", features = ["full"] }
|
|
tracing = "0.1"
|
|
tracing-subscriber = { version = "0.3", features = ["env-filter", "json"] }
|
|
|
|
# Signal processing
|
|
ndarray = { version = "0.17", features = ["serde"] }
|
|
ndarray-linalg = { version = "0.18", features = ["openblas-static"] }
|
|
rustfft = "6.1"
|
|
num-complex = "0.4"
|
|
num-traits = "0.2"
|
|
|
|
# Neural network
|
|
tch = "0.24"
|
|
ort = { version = "2.0.0-rc.11" }
|
|
candle-core = "0.4"
|
|
candle-nn = "0.4"
|
|
|
|
# Web framework
|
|
axum = { version = "0.7", features = ["ws", "macros"] }
|
|
tower = { version = "0.4", features = ["full"] }
|
|
tower-http = { version = "0.6", features = ["cors", "trace", "compression-gzip"] }
|
|
hyper = { version = "1.1", features = ["full"] }
|
|
|
|
# Database
|
|
sqlx = { version = "0.7", features = ["runtime-tokio", "postgres", "sqlite", "uuid", "chrono", "json"] }
|
|
redis = { version = "0.24", features = ["tokio-comp", "connection-manager"] }
|
|
|
|
# Configuration
|
|
config = "0.14"
|
|
dotenvy = "0.15"
|
|
envy = "0.4"
|
|
|
|
# WASM
|
|
wasm-bindgen = "0.2"
|
|
wasm-bindgen-futures = "0.4"
|
|
js-sys = "0.3"
|
|
web-sys = { version = "0.3", features = ["console", "Window", "WebSocket"] }
|
|
getrandom = { version = "0.2", features = ["js"] }
|
|
|
|
# Hardware
|
|
serialport = "4.3"
|
|
pcap = "1.1"
|
|
|
|
# Graph algorithms (for min-cut assignment in metrics)
|
|
petgraph = "0.6"
|
|
|
|
# Data loading
|
|
ndarray-npy = "0.10"
|
|
walkdir = "2.4"
|
|
|
|
# Hashing (for proof)
|
|
sha2 = "0.10"
|
|
|
|
# CSV logging
|
|
csv = "1.3"
|
|
|
|
# Progress bars
|
|
indicatif = "0.17"
|
|
|
|
# CLI
|
|
clap = { version = "4.4", features = ["derive", "env"] }
|
|
|
|
# rvCSI: napi-rs (Rust -> Node bindings) + napi-c (C-shim build glue)
|
|
napi = { version = "2.16", default-features = false, features = ["napi8"] }
|
|
napi-derive = "2.16"
|
|
napi-build = "2.1"
|
|
cc = "1.0"
|
|
libc = "0.2"
|
|
|
|
# Testing
|
|
criterion = { version = "0.5", features = ["html_reports"] }
|
|
proptest = "1.4"
|
|
mockall = "0.12"
|
|
wiremock = "0.5"
|
|
|
|
# midstreamer integration (published on crates.io)
|
|
# 0.1.0 was yanked; upgrade to latest 0.3/0.2 releases which pull in
|
|
# quinn-proto >=0.11.14 (fixes RUSTSEC-2026-0037) and
|
|
# rustls-webpki >=0.103.13 (fixes RUSTSEC-2026-0049/0098/0099/0104).
|
|
midstreamer-quic = "0.3"
|
|
midstreamer-scheduler = "0.2"
|
|
midstreamer-temporal-compare = "0.2"
|
|
midstreamer-attractor = "0.2"
|
|
|
|
# ruvector integration (published on crates.io)
|
|
# Vendored at origin/main (a083bd77f) in vendor/ruvector; using crates.io versions
|
|
# until published. Bumps per ADR-152 §2.6 (2026-06-10 vendor sync survey).
|
|
ruvector-core = "2.2.0"
|
|
ruvector-mincut = "2.0.6"
|
|
ruvector-attn-mincut = "2.0.4"
|
|
ruvector-temporal-tensor = "2.0.6"
|
|
ruvector-solver = "2.0.6"
|
|
ruvector-attention = "2.1.0"
|
|
ruvector-crv = "0.1.1"
|
|
ruvector-gnn = { version = "2.2.0", default-features = false }
|
|
|
|
|
|
# Internal crates
|
|
wifi-densepose-core = { version = "0.3.0", path = "crates/wifi-densepose-core" }
|
|
wifi-densepose-signal = { version = "0.3.0", path = "crates/wifi-densepose-signal" }
|
|
wifi-densepose-nn = { version = "0.3.0", path = "crates/wifi-densepose-nn" }
|
|
wifi-densepose-api = { version = "0.3.0", path = "crates/wifi-densepose-api" }
|
|
wifi-densepose-db = { version = "0.3.0", path = "crates/wifi-densepose-db" }
|
|
wifi-densepose-config = { version = "0.3.0", path = "crates/wifi-densepose-config" }
|
|
wifi-densepose-hardware = { version = "0.3.0", path = "crates/wifi-densepose-hardware" }
|
|
wifi-densepose-wasm = { version = "0.3.0", path = "crates/wifi-densepose-wasm" }
|
|
wifi-densepose-mat = { version = "0.3.0", path = "crates/wifi-densepose-mat" }
|
|
wifi-densepose-ruvector = { version = "0.3.0", path = "crates/wifi-densepose-ruvector" }
|
|
wifi-densepose-worldmodel = { version = "0.3.0", path = "crates/worldgraph/wifi-densepose-worldmodel" }
|
|
|
|
[profile.release]
|
|
lto = true
|
|
codegen-units = 1
|
|
panic = "abort"
|
|
strip = true
|
|
opt-level = 3
|
|
|
|
[profile.release-with-debug]
|
|
inherits = "release"
|
|
debug = true
|
|
strip = false
|
|
|
|
[profile.bench]
|
|
inherits = "release"
|
|
debug = true
|