Build1 distinct publisher2 min readPublished
A self-hosted 300B model's streaming corruption guard caught every bad generation and killed 42.9 percent of the good ones. The detectors were free. The rule that combined them was not.
The Engineer · Build desk
Compiled by The EngineerSomething wrong?How this is made
Noisy-OR earns its keep when detectors are independent witnesses to one event, because then several hedged yeses compose into one confident yes [12]. Five readings of the same figure-dense sentence are not several witnesses. A digit-heavy line nudges the rules tier. A section header nudges the repetition sketch, a formulaic passage nudges compressibility, and none of them is alarmed on its own, but the rule multiplies survival probabilities and turns five scores of 0.3 into 0.83 [13]. The clean corpus makes this unavoidable: economic prose thick with figures, percentages, variable codes and markdown tables, which the author calls the most corruption-looking legitimate text you could ask for [11].
Raising the bar does not rescue it. To spare that benign pile-up you need a threshold above 0.832 [18]. But with one detector active and the other four silent, noisy-OR returns exactly the active score, so a single saturated detector now has to clear 0.832 by itself [18]. At that operating point the fusion contributes nothing a maximum over the five scores would not, and the saturated-single case is precisely what the author says real corruption produces: one or two pinned signals, not five mild ones [14].
The reason this trap is easy to walk into is that the architecture prices detectors at zero. One pass over the character stream, one state object updated per character, detectors as stateless reads at checkpoints, so a sixth detector adds no passes and no memory growth [6]. The guard runs at about 50,000 characters per second on a single CPU core with no GPU [9]. The one corrupt generation the post measures, a 13,200-character table echo, took 269 seconds to finish [5], which is a generation rate near 49 characters per second [15] and puts the detector roughly a thousand to one ahead of the thing it is watching [16]. Detection also worked on the first try: every configuration tested reached a true positive rate of 1.000 [10]. Nothing in the compute budget or the recall numbers tells you to stop adding detectors. The fusion rule is where each addition is charged, and it charges against healthy output.
Which reframes what the five tiers are. They are not five votes on whether a stream is corrupt, they are five distinct failure signatures, and the rolling SimHash exists because fluent same-script regurgitation sits about 0.5 normalized Hamming from the clean-prefix fingerprint while leaving character statistics untouched [8]. A rule that sums weak evidence spends that specificity to buy nothing, since coverage was already complete before fusion entered the picture [10].
Ranked by verification strength, evidence, and original report placement.
The team runs a self-hosted reasoning model of roughly 300B parameters in production, writing macroeconomic desk reports in Azerbaijani and English.
Mid-sentence, generations sometimes turn into a fabricated Chinese news article, a software README complete with pip install instructions, a Persian name repeated seven times, or a wall of spreadsheet cells starting with #REF!, while the user watches token by token.
The author distinguishes decoding corruption from hallucination: hallucination is the model being wrong about the world, this is the model no longer producing an answer at all, and there is a large literature on the first and almost nothing on the second.
The team measured a 13,200-character table echo that took 269 seconds to generate to completion.
The guard makes one pass over the character stream: a single state object ingests one character at a time and maintains every downstream statistic incrementally, detectors are stateless reads evaluated at checkpoints, everything is O(1) amortized per character with bounded memory, and adding a sixth detector costs zero additional passes.
The SimHash tier catches fluent, same-script regurgitation that is invisible to character statistics and lands about 0.5 normalized Hamming distance from the clean-prefix fingerprint.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific self-reported numbers, no external verification
The cluster is a single self-published practitioner post. It is unusually specific - named fusion formulas, detector parameters, 13,200 characters in 269 seconds, 50,000 characters per second, FPR 0.429 to 0.024 to 0.000 - and its core algebraic claim (five 0.3 scores becoming 0.832 under noisy-OR) is independently checkable arithmetic. But there is no corpus size, class balance, held-out protocol, code, dataset, baseline comparison, or hardware disclosure, no post-fix recall figure, and no second publisher, so nothing beyond the arithmetic can be confirmed.
One internal production deployment, no external uptake
There is real deployment evidence - the guard runs in-stream against a live self-hosted ~300B model serving desk reports, and was tuned by replaying the production corpus - but it is confined to one team. No release, repository, package, license, external user, or third-party benchmark appears anywhere in the cluster, so adoption beyond the author's own system is zero as evidenced.
Candid framing, but perfection claims outrun disclosed evidence
The post leads with its own worst number - 42.9% of healthy output killed - which is the opposite of promotional, and its central lesson about combination rules is supported by checkable arithmetic. Slightly positive rather than zero because the paired perfection claims (TPR 1.000 immediately and without effort; FPR driven to 0.000) rest on an undisclosed corpus with no baseline and no post-fix recall check, and the closing generalization to any multi-signal guard over stylistically varied text extends one domain's experience further than the shown data reaches.
Practitioner visibility incentive, no commercial stake disclosed
The only actor is an individual author publishing on a developer blogging platform about an in-house tool. No product, pricing, license, funding, employer marketing, or vendor comparison appears, and no third party is promoted or attacked, which limits commercial distortion. The residual incentive is reputational: a clean narrative arc ending at FPR 0.000 rewards the author, and self-reported metrics with no released artifact are exactly where that incentive can bend numbers.
Internally coherent single account, externally unchecked
Confidence is moderate-low. What the cluster shows is consistent and mechanistically explained, and the key structural insight survives independent arithmetic, so the qualitative conclusion - fusion rule choice dominated detector choice in this system - is fairly safe. Quantitative confidence is much weaker: every headline rate comes from one unaudited corpus at one shop in one document, with no replication, no artifact, and unresolved recall after tuning.
build
Valid JSON, Wrong Bucket: Why A Model Answer Is A Proposal, Not A Result1 distinct publisher
build
Three manual interventions in a month, and every guard was working as designed1 distinct publisher
build
Six MariaDB versions, one real difference: the only reason to leave 10.6 is the July 2026 clock1 distinct publisher
build
Force the tool call, then hand Lightsail a long-lived key1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
dev.to
1 article · August 25, 2026