<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Constant Itis</title>
    <description>The latest articles on DEV Community by Constant Itis (@constant_itis).</description>
    <link>https://dev.to/constant_itis</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4005961%2F3b206993-516f-42b7-8d12-a2aa3b4c59bc.png</url>
      <title>DEV Community: Constant Itis</title>
      <link>https://dev.to/constant_itis</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/constant_itis"/>
    <language>en</language>
    <item>
      <title>How Many LLM Agents Does It Take to Screw In a Lightbulb?</title>
      <dc:creator>Constant Itis</dc:creator>
      <pubDate>Thu, 24 Sep 2026 06:15:16 +0000</pubDate>
      <link>https://dev.to/constant_itis/how-many-llm-agents-does-it-take-to-screw-in-a-lightbulb-5998</link>
      <guid>https://dev.to/constant_itis/how-many-llm-agents-does-it-take-to-screw-in-a-lightbulb-5998</guid>
      <description>&lt;p&gt;Apparently, &lt;strong&gt;MORE. EVERY. WEEK.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;One agent identifies that the room is dark.&lt;/p&gt;

&lt;p&gt;A second verifies that darkness is, in fact, undesirable.&lt;/p&gt;

&lt;p&gt;A third researches compatible lightbulbs.&lt;/p&gt;

&lt;p&gt;A fourth reviews the research.&lt;/p&gt;

&lt;p&gt;A fifth checks whether the reviewer hallucinated anything.&lt;/p&gt;

&lt;p&gt;A sixth creates a replacement plan.&lt;/p&gt;

&lt;p&gt;A seventh evaluates the plan for safety.&lt;/p&gt;

&lt;p&gt;An eighth watches the seventh for prompt injection.&lt;/p&gt;

&lt;p&gt;A ninth summarizes everything so the tenth can finally walk over to the lamp.&lt;/p&gt;

&lt;p&gt;Then the tenth discovers nobody gave it access to the light switch.&lt;/p&gt;

&lt;h3&gt;
  
  
  &lt;strong&gt;Perfect...&lt;/strong&gt; So we add a tooling agent.
&lt;/h3&gt;

&lt;p&gt;This is obviously a joke.&lt;/p&gt;

&lt;p&gt;It is also increasingly what AI architecture looks like.&lt;/p&gt;

&lt;h2&gt;
  
  
  We keep treating bad structure as an intelligence problem
&lt;/h2&gt;

&lt;p&gt;LLMs are fallible.&lt;/p&gt;

&lt;p&gt;Shocking, I know.&lt;/p&gt;

&lt;p&gt;They hallucinate. They misunderstand things. They lose context. They occasionally choose the wrong tool and confidently sprint in the wrong direction.&lt;/p&gt;

&lt;p&gt;So what do we do?&lt;/p&gt;

&lt;h3&gt;
  
  
  &lt;strong&gt;ADD ANOTHER LLM.&lt;/strong&gt;
&lt;/h3&gt;

&lt;p&gt;Naturally.&lt;/p&gt;

&lt;p&gt;The first agent writes code, so we add a review agent.&lt;/p&gt;

&lt;p&gt;The reviewer is also fallible, so we add a verifier.&lt;/p&gt;

&lt;p&gt;Now the agents need to communicate, so we add a coordinator.&lt;/p&gt;

&lt;p&gt;The handoffs lose information, so we add schemas and filters.&lt;/p&gt;

&lt;p&gt;The filters remove useful context, so we add adjudication.&lt;/p&gt;

&lt;p&gt;Then nobody really understands what the hell is happening.&lt;/p&gt;

&lt;h3&gt;
  
  
  &lt;strong&gt;Add a supervisor agent.&lt;/strong&gt;
&lt;/h3&gt;

&lt;p&gt;Congratulations. We have built middle management.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzy5xirpqlxx5biop8nyu.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzy5xirpqlxx5biop8nyu.jpg" alt="Office Space Bill Meme" width="800" height="459"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Another agent is not automatically a reliability primitive
&lt;/h2&gt;

&lt;p&gt;There are absolutely situations where multiple agents help.&lt;/p&gt;

&lt;p&gt;Independent research can expose blind spots. Parallel workers can tackle genuinely separate problems.&lt;/p&gt;

&lt;p&gt;But there is a weird assumption hiding inside a lot of multi-agent design:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;One fallible agent is risky, therefore several fallible agents talking to each other must be reliable.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;...why?&lt;/p&gt;

&lt;p&gt;Every new agent adds another prompt, another context window, another interpretation of the task, another set of assumptions, and another place where something can go sideways.&lt;/p&gt;

&lt;p&gt;Then you connect them.&lt;/p&gt;

&lt;p&gt;Excellent.&lt;/p&gt;

&lt;p&gt;Now you get &lt;strong&gt;distributed misunderstanding&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Information gets summarized badly.&lt;/p&gt;

&lt;p&gt;Context disappears during handoffs.&lt;/p&gt;

&lt;p&gt;Agents disagree about state.&lt;/p&gt;

&lt;p&gt;One acts on stale output from another.&lt;/p&gt;

&lt;p&gt;Another confidently verifies something that was already wrong.&lt;/p&gt;

&lt;p&gt;Then you need provenance, confidence scores, retries, consensus, monitoring, memory, cleanup, and eventually an agent to manage all the agents managing all the other agents.&lt;/p&gt;

&lt;p&gt;At some point, maybe the problem is no longer the lightbulb.&lt;/p&gt;

&lt;h2&gt;
  
  
  The bolt-on loop
&lt;/h2&gt;

&lt;p&gt;This pattern should look familiar:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Agent makes mistakes
        ↓
Add reviewer
        ↓
Reviewer makes mistakes
        ↓
Add verifier
        ↓
Handoffs are unreliable
        ↓
Add protocol
        ↓
Protocol carries garbage
        ↓
Add filtering
        ↓
System becomes incomprehensible
        ↓
Add supervisor
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Then someday:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Supervisor behaves strangely
        ↓
????
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;I think we all know what comes next.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Another fucking agent.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fvnuvntf685dzqfaz3qnd.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fvnuvntf685dzqfaz3qnd.jpg" alt="Boss office meeting meme" width="742" height="660"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;We keep adding complexity to manage complexity that we added to manage complexity.&lt;/p&gt;

&lt;p&gt;Software has done this before.&lt;/p&gt;

&lt;p&gt;Microservices had their version.&lt;/p&gt;

&lt;p&gt;Enterprise middleware had its version.&lt;/p&gt;

&lt;p&gt;Now AI gets to rediscover the ancient engineering tradition of building a giant machine to solve the problems caused by the previous giant machine.&lt;/p&gt;

&lt;p&gt;Progress!&lt;/p&gt;

&lt;h2&gt;
  
  
  What if the agent could just push the button?
&lt;/h2&gt;

&lt;p&gt;Take deployment.&lt;/p&gt;

&lt;p&gt;You could build this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Planning Agent
      ↓
Deployment Agent
      ↓
Security Agent
      ↓
Validation Agent
      ↓
Monitoring Agent
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Very futuristic.&lt;/p&gt;

&lt;p&gt;Look at all those boxes.&lt;/p&gt;

&lt;p&gt;Or you could build:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;deploy()
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Wild idea.&lt;/p&gt;

&lt;p&gt;And maybe &lt;code&gt;deploy()&lt;/code&gt; could handle the repeatable shit computers have been pretty good at for several decades:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;check configuration
run tests
scan secrets
validate schema
build artifact
deploy
run health checks
record result
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Then return something structured:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"status"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"failed"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"stage"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"health_check"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"service"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"api"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"reason"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"database migration 42 not applied"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"safe_to_retry"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Holy shit.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ftuh9llc28daleqqtwxei.webp" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ftuh9llc28daleqqtwxei.webp" alt="Brain explode enlightenment" width="599" height="337"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Now the agent immediately knows what happened.&lt;/p&gt;

&lt;p&gt;It does not need a &lt;strong&gt;Deployment Historian Agent&lt;/strong&gt; to interview the Security Agent about what the Validation Agent remembers seeing.&lt;/p&gt;

&lt;p&gt;It reads the state.&lt;/p&gt;

&lt;p&gt;It understands the failure.&lt;/p&gt;

&lt;p&gt;It decides what to do next.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;That is where I want to spend intelligence.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Spend intelligence on the weird parts
&lt;/h2&gt;

&lt;p&gt;This has become one of my favorite rules for agent systems:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Do not add intelligence where structure can remove the need for intelligence.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Software should handle the repeatable shit.&lt;/p&gt;

&lt;p&gt;Agents should handle ambiguity.&lt;/p&gt;

&lt;p&gt;If a workflow always requires the same fifteen operations, do not make a language model rediscover those fifteen operations every single time just because it technically can.&lt;/p&gt;

&lt;p&gt;That is not intelligence.&lt;/p&gt;

&lt;p&gt;That is making your smartest component do clerical work.&lt;/p&gt;

&lt;p&gt;Encode the workflow.&lt;/p&gt;

&lt;p&gt;Validate it.&lt;/p&gt;

&lt;p&gt;Test it.&lt;/p&gt;

&lt;p&gt;Turn it into a tool.&lt;/p&gt;

&lt;p&gt;Give the agent the button.&lt;/p&gt;

&lt;p&gt;Then let the model reason about the things that actually require reasoning.&lt;/p&gt;

&lt;p&gt;Should we deploy?&lt;/p&gt;

&lt;p&gt;Why did this fail?&lt;/p&gt;

&lt;p&gt;Is this exception safe?&lt;/p&gt;

&lt;p&gt;Does the user's intent change the normal procedure?&lt;/p&gt;

&lt;p&gt;Is the situation genuinely novel?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Use intelligence where intelligence buys you something.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Make the environment legible
&lt;/h2&gt;

&lt;p&gt;The same problem shows up when agents cannot understand the systems we put them inside.&lt;/p&gt;

&lt;p&gt;Repository confusing?&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Add a repository exploration agent.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;State scattered across six services?&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Context gathering agent.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Nobody knows what happened yesterday?&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Summarization agent.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Tasks have unclear ownership?&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Orchestration agent.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Or...&lt;/p&gt;

&lt;p&gt;and stay with me here...&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;we could make the system less confusing.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Expose canonical state.&lt;/p&gt;

&lt;p&gt;Use stable names.&lt;/p&gt;

&lt;p&gt;Give tools clear contracts.&lt;/p&gt;

&lt;p&gt;Provide machine-readable indexes.&lt;/p&gt;

&lt;p&gt;Record decisions somewhere predictable.&lt;/p&gt;

&lt;p&gt;Make failures explicit.&lt;/p&gt;

&lt;p&gt;An agent entering a system cold should be able to quickly answer:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Where am I?

What is true right now?

What happened before?

What can I do?

What should happen next?
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If answering those five questions requires consulting an autonomous workforce, &lt;strong&gt;the environment might suck.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That is not an agent-count problem.&lt;/p&gt;

&lt;h2&gt;
  
  
  Better primitives beat more personalities
&lt;/h2&gt;

&lt;p&gt;I have been thinking about this constantly while working on memory systems.&lt;/p&gt;

&lt;p&gt;There are two broad ways to get sophisticated behavior.&lt;/p&gt;

&lt;p&gt;You can keep adding systems that manage behavior from above.&lt;/p&gt;

&lt;p&gt;Or you can improve the rules underneath until useful behavior emerges naturally.&lt;/p&gt;

&lt;p&gt;Want important memories to survive?&lt;/p&gt;

&lt;p&gt;One approach:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;importance classifier
retention manager
memory reviewer
staleness detector
consolidation agent
cleanup agent
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Very impressive diagram.&lt;/p&gt;

&lt;p&gt;Or maybe:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;use it → strengthen it
ignore it → weaken it
use things together → associate them
stop using the association → let it fade
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;That second version interests me a hell of a lot more.&lt;/p&gt;

&lt;p&gt;Frequently useful structure survives because it is &lt;strong&gt;frequently useful&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The system does not need another model waking up at 3 AM to gaze deeply into a SQLite database and decide which memories feel spiritually significant today.&lt;/p&gt;

&lt;p&gt;Sometimes the simple mechanism is the mechanism.&lt;/p&gt;

&lt;p&gt;That does not mean every problem should be emergent.&lt;/p&gt;

&lt;p&gt;Security should not be vibes.&lt;/p&gt;

&lt;p&gt;Permissions should not emerge organically.&lt;/p&gt;

&lt;p&gt;Canonical truth sometimes needs explicit enforcement.&lt;/p&gt;

&lt;p&gt;But that gives us a much better default:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Before adding another intelligent layer, ask whether a better primitive makes the layer unnecessary.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Multi-agent systems still have a place
&lt;/h2&gt;

&lt;p&gt;Before somebody screenshots half this article and tells me I "don't understand agents":&lt;/p&gt;

&lt;p&gt;Yes.&lt;/p&gt;

&lt;p&gt;Multiple agents can be useful.&lt;/p&gt;

&lt;p&gt;If I want three independent interpretations of experimental results, that can make sense.&lt;/p&gt;

&lt;p&gt;If five research tasks are genuinely independent, parallelize them.&lt;/p&gt;

&lt;p&gt;If something deserves adversarial review because the judgment itself is difficult, great.&lt;/p&gt;

&lt;p&gt;Use another agent.&lt;/p&gt;

&lt;p&gt;But the key is that there should be &lt;strong&gt;another useful reasoning problem&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Not just a bad workflow.&lt;/p&gt;

&lt;p&gt;If I need a file renamed, tests run, a manifest updated, validation performed, and the result committed, I probably do not need an AI project manager, AI developer, AI reviewer, AI release engineer, and AI compliance officer.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;I need a good fucking tool.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Maybe the goal should be LESS reasoning
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F3ssfbqs716yh6ehqpsb4.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F3ssfbqs716yh6ehqpsb4.jpg" alt="Reasoning reason meme guy in front of computer" width="582" height="428"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;This is the part I think we have backwards.&lt;/p&gt;

&lt;p&gt;Agent demos often optimize for how much autonomous reasoning they can show.&lt;/p&gt;

&lt;p&gt;Look!&lt;/p&gt;

&lt;p&gt;The model made a plan.&lt;/p&gt;

&lt;p&gt;Then it delegated.&lt;/p&gt;

&lt;p&gt;Then that model delegated.&lt;/p&gt;

&lt;p&gt;Then three models voted.&lt;/p&gt;

&lt;p&gt;Then the supervisor reconciled the results.&lt;/p&gt;

&lt;p&gt;Then another model summarized the reconciliation.&lt;/p&gt;

&lt;p&gt;Amazing.&lt;/p&gt;

&lt;p&gt;But why did any of that need to happen?&lt;/p&gt;

&lt;p&gt;I think a better engineering target is:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;How little reasoning does the agent need to reliably accomplish the work?&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That changes the architecture.&lt;/p&gt;

&lt;p&gt;Instead of another role, improve the tool.&lt;/p&gt;

&lt;p&gt;Instead of another reviewer, add a deterministic check.&lt;/p&gt;

&lt;p&gt;Instead of another coordinator, expose the state machine.&lt;/p&gt;

&lt;p&gt;Instead of another agent explaining the system to the first agent, &lt;strong&gt;make the system understandable.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The architecture diagram might have fewer boxes.&lt;/p&gt;

&lt;p&gt;That is okay.&lt;/p&gt;

&lt;p&gt;You do not get bonus points because your light switch requires Kubernetes.&lt;/p&gt;

&lt;h2&gt;
  
  
  The lightbulb test
&lt;/h2&gt;

&lt;p&gt;Before adding another agent, ask:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Could I make the existing agent succeed by improving the environment instead?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Could the state be clearer?&lt;/p&gt;

&lt;p&gt;Could the workflow be encoded?&lt;/p&gt;

&lt;p&gt;Could the operation become a tool?&lt;/p&gt;

&lt;p&gt;Could validation be deterministic?&lt;/p&gt;

&lt;p&gt;Could the system expose something the agent currently has to infer?&lt;/p&gt;

&lt;p&gt;Could we, perhaps, just fix the workflow?&lt;/p&gt;

&lt;p&gt;If yes, try that first.&lt;/p&gt;

&lt;p&gt;Because every new agent adds more than compute.&lt;/p&gt;

&lt;p&gt;It adds another mental model.&lt;/p&gt;

&lt;p&gt;Another context boundary.&lt;/p&gt;

&lt;p&gt;Another communication path.&lt;/p&gt;

&lt;p&gt;Another place for information to mutate.&lt;/p&gt;

&lt;p&gt;Another source of uncertainty.&lt;/p&gt;

&lt;p&gt;Another thing somebody eventually has to understand.&lt;/p&gt;

&lt;p&gt;And when the whole machine finally becomes too complicated for anyone to reason about, somebody is inevitably going to walk into the meeting with the solution.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;"Hear me out."&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;"What if we add an agent to manage it?"&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Of course.&lt;/p&gt;

&lt;h2&gt;
  
  
  So how many LLM agents does it take to screw in a lightbulb?
&lt;/h2&gt;

&lt;p&gt;Ideally?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;One.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Provided somebody had the sense to give it a fucking light switch.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>llm</category>
      <category>agents</category>
      <category>architecture</category>
    </item>
    <item>
      <title>Inherited Memory Helped My Flies Until the World Changed. Then a Blank Slate Beat Them.</title>
      <dc:creator>Constant Itis</dc:creator>
      <pubDate>Thu, 24 Sep 2026 01:25:12 +0000</pubDate>
      <link>https://dev.to/constant_itis/inherited-memory-helped-my-flies-until-the-world-changed-then-a-blank-slate-beat-them-1p9e</link>
      <guid>https://dev.to/constant_itis/inherited-memory-helped-my-flies-until-the-world-changed-then-a-blank-slate-beat-them-1p9e</guid>
      <description>&lt;p&gt;Earlier in this series I killed a brain and the memory lived through it.&lt;/p&gt;

&lt;p&gt;Then I dropped that memory into a fresh brain, and the fresh brain woke up believing a life it never lived.&lt;/p&gt;

&lt;p&gt;Creepy. Useful. One brain, one lifetime.&lt;/p&gt;

&lt;p&gt;Here is the part that actually kept me up.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What if the memory never stops getting inherited? What if it gets handed down for generations, and then the world it learned turns out to be a lie?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That is the whole promise of memory-as-inheritance sitting right there. Anything you can pass down, you can pass down for too long.&lt;/p&gt;

&lt;p&gt;So I built a family.&lt;/p&gt;

&lt;h2&gt;
  
  
  The memory that would not die
&lt;/h2&gt;

&lt;p&gt;Same fruit fly circuit as the last few posts. A cue comes in. The fly approaches or avoids. Good outcomes and bad outcomes bend the connection strengths. That is a life.&lt;/p&gt;

&lt;p&gt;Then the fly breeds, the body dies, and exactly one thing crosses into the next generation: the external memory graph.&lt;/p&gt;

&lt;p&gt;Not the synapses. The synapses rot with the corpse.&lt;/p&gt;

&lt;p&gt;The graph is the will.&lt;/p&gt;

&lt;p&gt;And there is no forgetting in the will. No decay. No cleanup. Every generation stacks its own experience on top of everything its ancestors already swore was true, and the pile only ever grows.&lt;/p&gt;

&lt;p&gt;In a world that stays put, this looks like a dynasty.&lt;/p&gt;

&lt;p&gt;Generation two already knows what took generation one an entire life to learn. Generation five is basically preloaded. Watch only the behavior and you would think you were breeding geniuses.&lt;/p&gt;

&lt;p&gt;But I logged what was happening inside the memory, not just what the fly did. And inside, the thing was quietly losing its mind.&lt;/p&gt;

&lt;p&gt;The behavior sat pinned at the top, calm and correct. Meanwhile the inherited conviction kept climbing with no ceiling, generation after generation, more and more certain about a world that had never once contradicted it.&lt;/p&gt;

&lt;p&gt;A stable world hides that completely.&lt;/p&gt;

&lt;p&gt;Everybody looks like a prodigy right up until the ground moves.&lt;/p&gt;

&lt;p&gt;Which is the only question worth asking.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What happens to a lineage carrying ten generations of absolute certainty when the certainty stops being true?&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Give it a world that can actually kill it
&lt;/h2&gt;

&lt;p&gt;A reversal in a spreadsheet is free. I wanted the memory to cost something real, so I stopped hand-feeding the fly and gave it an ecology.&lt;/p&gt;

&lt;p&gt;Now a life has stakes. There is food and there is harm. Energy drains. There is age, maturity, and having kids before you die. Read your world well and you eat, survive, and breed. Read it badly and you starve or get killed before you reproduce, and that whole branch of the family is over.&lt;/p&gt;

&lt;p&gt;Then I built two worlds that disagree about one thing.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;World B (easy):   cue X is usually food     approach X, you eat
World A (harsh):  cue X is usually death    approach X, you die
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;A second cue stays safe in both. The only thing that flips between the worlds is what the learned cue X means.&lt;/p&gt;

&lt;p&gt;So I could raise a family in one world until the inheritance ran deep, then drop a descendant into the other world and just watch. Does the ancestral memory help the newcomer read a strange world, or is it a suicide note written by dead flies who lived somewhere else?&lt;/p&gt;

&lt;p&gt;To keep myself honest I always ran a shadow. For every memory-carrying migrant, a matched blank-slate lineage ran in the same world, same conditions, knowing nothing at all.&lt;/p&gt;

&lt;p&gt;The blank slate is the whole point. The question is never "did the migrant survive." The question is:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;did inheriting anything beat inheriting nothing?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The number I care about is how long the family line keeps going. Call it L. It counts how many generations the lineage keeps successfully breeding across a forty generation horizon. Migrant minus blank slate. Positive means the memory bought you extra generations. Negative means the memory cost you generations you would have had with an empty head.&lt;/p&gt;

&lt;p&gt;Then I locked it. The seeds that decide the result, seeds 4001 to 4576, got sealed and frozen before a single one was opened. No peeking. No tuning. No quiet second run if I hated the answer.&lt;/p&gt;

&lt;p&gt;One shot.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the sealed seeds actually said
&lt;/h2&gt;

&lt;p&gt;I ran a full connectome fly against a matched blank slate in both directions, then opened the seeds once.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;B to A. The dynasty walks into hell.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This is the fly whose entire family history screamed "approach X, X is food," strolling into a world where X is now death.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;L (migrant minus blank slate):  -10.78 generations
p &amp;lt; 0.001   (0 of 10,000 resamples crossed zero)
never recovered inside 40 generations
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The inherited memory did not cost them a little. It cost the line about eleven generations of survival compared to knowing nothing at all.&lt;/p&gt;

&lt;p&gt;Sit with that. The blank slate, the fly that inherited absolutely nothing, outlived the fly that inherited ten generations of hard-won family wisdom. And across the entire forty generation horizon the poisoned lineage never once clawed back level. A single descendant, living a single honest life, getting bitten by the truth over and over, could not shout down ten dead ancestors insisting the old thing was safe.&lt;/p&gt;

&lt;p&gt;That is the result I came for. Inherited memory turning into a liability so heavy that ignorance wins. Not a metaphor. A measured, sealed, eleven generation grave.&lt;/p&gt;

&lt;p&gt;And then the experiment looked at me and refused to give me the clean version.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;A to B. Hell's memory walks into paradise.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;I wanted a mirror. Caution learned in a lethal world should be dead weight in a safe one, so the migrant should eat dirt again.&lt;/p&gt;

&lt;p&gt;It did not.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;L (migrant minus blank slate):  +3.75 generations
p = 0.088   (not significant)
unresolved
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The estimate even leans slightly positive, and it does not reach significance in either direction. In the easy world the safe cue keeps almost everyone alive anyway, so being wrong about X barely costs a thing. A forgiving world just does not squeeze hard enough for the stale belief to matter.&lt;/p&gt;

&lt;p&gt;So this direction did not resolve. Not zero. Not "invisible." Just genuinely unsettled.&lt;/p&gt;

&lt;p&gt;There was one more knife in this direction. Raising a family in the harsh world at all is savage. Two thirds of the lineages I tried to grow there died out before they could even finish handing down their memory, so only 32 of them survived to be tested. The harsh world does not just punish bad beliefs. It punishes existing.&lt;/p&gt;

&lt;h2&gt;
  
  
  The honest shape of it
&lt;/h2&gt;

&lt;p&gt;I could have written this up as a tidy law. Memory helps at home, memory hurts abroad, symmetric, clean, roll credits. That would have been a lie, and the sealed seeds would have known.&lt;/p&gt;

&lt;p&gt;The real shape is lopsided. When the world turned hostile, inherited memory was badly and permanently harmful, bad enough that a blank slate beat it. When the world was kind, the inheritance mostly shrugged and the numbers came back a maybe.&lt;/p&gt;

&lt;p&gt;The asymmetry is the finding. Not a smudge on it.&lt;/p&gt;

&lt;p&gt;And it lands exactly where I have been pointing this whole series:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Useful memory should lower the cost of learning what is still true without raising the cost of discovering what is no longer true.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The lineage aced the first half and face-planted the second. It got competent for free. But the second the ground moved, all that inherited competence hardened into a stubborn wrong prior it paid for in dead children. Nothing anywhere in the memory knew how to say "that was true then, and it is not true now."&lt;/p&gt;

&lt;p&gt;This is not a fly problem.&lt;/p&gt;

&lt;p&gt;This is every system that carries memory forward and cannot tell stale from valid. Give an agent long-term memory and it inherits this exact failure the instant its world drifts out from under it. The better the old memory was, the harder it fights the truth.&lt;/p&gt;

&lt;p&gt;I am not dragging the flies into a genuinely new world yet. This result gets to stand on its own first. It is the clean end of one question: what inherited memory does when the world it learned changes underneath it.&lt;/p&gt;

&lt;p&gt;Next: &lt;strong&gt;what happens when the world is not a reversal but something the ancestors never saw at all, and whether old memory is a head start or a lie when the present stops looking like the past.&lt;/strong&gt;&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;Clone it and break it.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The toy repo from Arc I is still here:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git clone https://github.com/constant-itis/flymem &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nb"&gt;cd &lt;/span&gt;flymem &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; python3 flymem.py
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The mushroom body wiring under the real-fly work is public too, so you can pull the exact same connectome and check whether I read it right:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;pip &lt;span class="nb"&gt;install &lt;/span&gt;neuprint-python
&lt;span class="c"&gt;# point a Client at server "neuprint.janelia.org", dataset "male-cns:v1.0"&lt;/span&gt;
&lt;span class="c"&gt;# (free per-user token from the site), then fetch the KC / MBON / DAN populations&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;/p&gt;
  🧪 What I actually ran
  &lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;What I ran.&lt;/strong&gt; A lineage experiment on the real male-CNS mushroom body substrate, not the toy. Each life runs the connectome fly through an ecology with food, harm, energy, age, maturity, and reproduction. At death only the external memory graph is inherited, with no decay and no forgetting, pure append. Two worlds differ only in what the learned cue means: in World B the cue is good with probability 0.9, in World A it is good with probability 0.1, and a second cue stays good in both. For each direction I raised a history in one world, then measured a memory-carrying migrant against a matched blank-slate control in the other world. The primary metric L is generation-by-generation lineage persistence summed over a forty generation horizon, migrant minus control, with confidence intervals from a bootstrap clustered on whole root lineages and a Holm correction across the two directions. The confirmatory seeds (4001 to 4576) were frozen before the run and observed exactly once. Results: B to A, delta L = -10.78, 95% CI -14.46 to -7.38, p below 0.001, no recovery through 40 generations, 85 of 96 lineages testable. A to B, delta L = +3.75, 95% CI 0.0 to 8.75, p = 0.088, not significant, 32 of 96 testable after 67 percent of harsh-world histories failed to establish.&lt;/p&gt;
&lt;/blockquote&gt;



&lt;p&gt;&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;
  ⚠️ Where I might be wrong
  &lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;The honest caveat.&lt;/strong&gt; A connectome is wiring, not learning rules. This is engineered plasticity running over real reconstructed wiring, so the dynamics are mine even though the graph is the fly's. Do not read this as "real fruit flies inherit trauma." The B to A harm is the strong, preregistered, audited result and it stands. The A to B direction is genuinely unresolved, not a proven null, and it is underpowered for small effects by design, so do not turn its slightly positive estimate into a claim that memory helps in easy worlds. The harsh-world attrition also means the surviving harsh-world histories are a selected set, and I report that selection rather than hiding it. Two separate adversarial passes checked this: one tore at the inference code before the seeds were opened, a second tore at the reporting after. Both are why the numbers here are stated the way they are. Clone it, pull the same mushroom body, and tell me where I read it wrong.&lt;/p&gt;
&lt;/blockquote&gt;



&lt;p&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>neuroscience</category>
      <category>memory</category>
      <category>biomimicry</category>
    </item>
    <item>
      <title>DARPA Was Building Cyborg Moths in 2009. Somehow This Is Relevant to My Fruit Fly Experiment.</title>
      <dc:creator>Constant Itis</dc:creator>
      <pubDate>Wed, 23 Sep 2026 06:08:25 +0000</pubDate>
      <link>https://dev.to/constant_itis/darpa-was-building-cyborg-moths-in-2009-somehow-this-is-relevant-to-my-fruit-fly-experiment-5dmj</link>
      <guid>https://dev.to/constant_itis/darpa-was-building-cyborg-moths-in-2009-somehow-this-is-relevant-to-my-fruit-fly-experiment-5dmj</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F04tuhrcofcme5ifiozex.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F04tuhrcofcme5ifiozex.png" alt="Screenshot of DARPA research on cyborg moths" width="800" height="408"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I have been spending an unreasonable amount of time asking what happens when you give an insect brain something biology never gave it:&lt;/p&gt;

&lt;p&gt;persistent external memory.&lt;/p&gt;

&lt;p&gt;Then I came across a paper from 2009.&lt;/p&gt;

&lt;p&gt;And for approximately five minutes my reaction was:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;well, screw everything I'm doing, DARPA already turned insects into computers.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That isn't actually what happened.&lt;/p&gt;

&lt;p&gt;But what they &lt;em&gt;did&lt;/em&gt; do is weird enough that the exaggerated version is almost unnecessary.&lt;/p&gt;

&lt;p&gt;In 2009, researchers published a paper called &lt;strong&gt;"Insect–Machine Interface Based Neurocybernetics."&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;It was funded by DARPA's Hybrid Insect Micro-Electro-Mechanical Systems program, or HI-MEMS.&lt;/p&gt;

&lt;p&gt;Their experimental animal was &lt;em&gt;Manduca sexta&lt;/em&gt;, the tobacco hawkmoth.&lt;/p&gt;

&lt;p&gt;And their basic idea was beautifully unhinged:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;don't attach electronics to an adult insect. Implant the electronics while the insect is still becoming an adult, and let metamorphosis build the interface for you.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That worked.&lt;/p&gt;

&lt;p&gt;Really, really well.&lt;/p&gt;

&lt;h2&gt;
  
  
  TL;DR: the science
&lt;/h2&gt;

&lt;p&gt;The researchers inserted flexible microfabricated electrodes into &lt;em&gt;Manduca sexta&lt;/em&gt; during the pupal stage.&lt;/p&gt;

&lt;p&gt;Then they waited.&lt;/p&gt;

&lt;p&gt;As the moth continued developing, its tissues formed around the implanted probes.&lt;/p&gt;

&lt;p&gt;The researchers even fabricated &lt;strong&gt;200-micrometer holes in the probe tips so developing muscle could grow through the electronics&lt;/strong&gt;, creating a biological anchor.&lt;/p&gt;

&lt;p&gt;The insect's cuticle healed around the insertion points without glue.&lt;/p&gt;

&lt;p&gt;At the optimal implantation time, approximately seven days before emergence, &lt;strong&gt;90% of the moths successfully emerged as adults with fully inflated wings&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Across more than 100 implantations, the researchers reported &lt;strong&gt;98% success placing the probes into their intended flight muscles&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;They could use those implanted electrodes to record muscle activity.&lt;/p&gt;

&lt;p&gt;They could also stimulate the muscles.&lt;/p&gt;

&lt;p&gt;Stimulating one flight muscle pulled a wing downward.&lt;/p&gt;

&lt;p&gt;Stimulating another pulled it upward.&lt;/p&gt;

&lt;p&gt;Stimulating both at sufficiently high frequency could stop wing flapping.&lt;/p&gt;

&lt;p&gt;And stimulating one side of a naturally flying moth produced a yaw toward the stimulated side.&lt;/p&gt;

&lt;p&gt;In other words:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;they implanted electronics during metamorphosis, the animal developed around them, and afterward those electronics could interact directly with the machinery responsible for flight.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That is not a cyberpunk novel.&lt;/p&gt;

&lt;p&gt;That is IEEE Transactions on Biomedical Engineering, June 2009.&lt;/p&gt;

&lt;h2&gt;
  
  
  The really clever part isn't the remote control
&lt;/h2&gt;

&lt;p&gt;The remote-control angle is obviously the thing that gets people's attention.&lt;/p&gt;

&lt;p&gt;"Cyborg moth."&lt;/p&gt;

&lt;p&gt;"DARPA insect drone."&lt;/p&gt;

&lt;p&gt;"Military remotely controls animal."&lt;/p&gt;

&lt;p&gt;Sure.&lt;/p&gt;

&lt;p&gt;But from an engineering perspective, I don't think that's actually the most interesting part.&lt;/p&gt;

&lt;p&gt;The brilliant idea is:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Use development as part of the manufacturing process.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Normally, implanting something into a fully developed animal means fighting an already completed structure.&lt;/p&gt;

&lt;p&gt;The tissue is already where it is going to be.&lt;/p&gt;

&lt;p&gt;The exoskeleton is already hard.&lt;/p&gt;

&lt;p&gt;You're cutting into something that was not designed to accommodate your device.&lt;/p&gt;

&lt;p&gt;So instead, the researchers went earlier.&lt;/p&gt;

&lt;p&gt;During metamorphosis, an insect is already performing an absurd biological reconstruction project.&lt;/p&gt;

&lt;p&gt;Structures are degenerating.&lt;/p&gt;

&lt;p&gt;Others are forming.&lt;/p&gt;

&lt;p&gt;Muscles are developing.&lt;/p&gt;

&lt;p&gt;The adult cuticle is being produced.&lt;/p&gt;

&lt;p&gt;So the researchers inserted their interface while that process was still underway.&lt;/p&gt;

&lt;p&gt;Instead of forcing the completed organism to accept the electronics, they allowed the organism to &lt;strong&gt;develop around the electronics&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;They called the method &lt;strong&gt;Early Metamorphosis Insertion Technology: EMIT&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;That distinction is important because I've seen posts claim that the researchers called the phenomenon "Metamorphic Growth."&lt;/p&gt;

&lt;p&gt;They didn't.&lt;/p&gt;

&lt;p&gt;Metamorphic growth is the trick.&lt;/p&gt;

&lt;p&gt;EMIT is the technique.&lt;/p&gt;

&lt;h2&gt;
  
  
  They literally put holes in the electronics so the moth could grow through them
&lt;/h2&gt;

&lt;p&gt;This is my favorite detail in the entire paper.&lt;/p&gt;

&lt;p&gt;The flexible probes were made from polyimide with conductive traces and gold-coated electrode sites.&lt;/p&gt;

&lt;p&gt;At the ends of the probes, the researchers added &lt;strong&gt;200 μm openings&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Why?&lt;/p&gt;

&lt;p&gt;So flight muscle could grow through them.&lt;/p&gt;

&lt;p&gt;Not around them.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Through them.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The biological tissue becomes part of the mechanical mounting system.&lt;/p&gt;

&lt;p&gt;The paper reports that muscle adhesion and growth through those holes substantially improved anchoring.&lt;/p&gt;

&lt;p&gt;When researchers later removed probes that had been implanted during the pupal stage, significant tissue came out attached to them.&lt;/p&gt;

&lt;p&gt;Probes inserted into adults showed much weaker integration.&lt;/p&gt;

&lt;p&gt;That's wild because the electronics aren't merely surviving biology.&lt;/p&gt;

&lt;p&gt;Biology is completing the assembly.&lt;/p&gt;

&lt;h2&gt;
  
  
  No glue required
&lt;/h2&gt;

&lt;p&gt;They also tried something that sounds completely reasonable:&lt;/p&gt;

&lt;p&gt;seal the surgical opening with adhesive.&lt;/p&gt;

&lt;p&gt;That actually made things worse.&lt;/p&gt;

&lt;p&gt;The adhesive could bind tissue layers that needed to separate normally during emergence.&lt;/p&gt;

&lt;p&gt;So they stopped using it.&lt;/p&gt;

&lt;p&gt;Instead, after inserting the probes, they simply allowed the insect's own cuticle to heal around them.&lt;/p&gt;

&lt;p&gt;The animal produced the seal.&lt;/p&gt;

&lt;p&gt;Again:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;development is doing part of the engineering.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Okay, but was DARPA actually controlling moths?
&lt;/h2&gt;

&lt;p&gt;Yes, with an important asterisk.&lt;/p&gt;

&lt;p&gt;This paper does demonstrate externally triggered flight-muscle control.&lt;/p&gt;

&lt;p&gt;The researchers stimulated the dorsal longitudinal and dorsoventral muscles responsible for wing movement.&lt;/p&gt;

&lt;p&gt;They demonstrated repeatable unilateral and bilateral wing actuation.&lt;/p&gt;

&lt;p&gt;During natural flight, stimulation on one side produced a turning response toward that side.&lt;/p&gt;

&lt;p&gt;The authors describe these experiments as a proof of concept for insect steering.&lt;/p&gt;

&lt;p&gt;There was also a separate 2009 paper from the same research lineage titled &lt;strong&gt;"Radio Control of Insects for Biobotic Domestication,"&lt;/strong&gt; reporting radio-controlled neuromuscular stimulation of &lt;em&gt;Manduca sexta&lt;/em&gt; during flight.&lt;/p&gt;

&lt;p&gt;So "radio-controlled moth" is not something somebody invented for Twitter.&lt;/p&gt;

&lt;p&gt;But there is a difference between:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;I can electrically induce motor responses that alter the animal's trajectory&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;and:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;I have built a perfectly controllable biological quadcopter.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Those are not the same achievement.&lt;/p&gt;

&lt;p&gt;The early work demonstrated controllable outputs and directional influence, not complete deterministic command over every aspect of insect behavior.&lt;/p&gt;

&lt;p&gt;The animal is still an animal.&lt;/p&gt;

&lt;h2&gt;
  
  
  The viral version also oversells the interface a little
&lt;/h2&gt;

&lt;p&gt;One description I saw called this a "high-bandwidth insect-machine interface."&lt;/p&gt;

&lt;p&gt;I'd be careful with that wording.&lt;/p&gt;

&lt;p&gt;The researchers absolutely created a mechanically stable and electrically functional interface.&lt;/p&gt;

&lt;p&gt;They could stimulate selected muscle groups.&lt;/p&gt;

&lt;p&gt;They could record electrophysiological activity.&lt;/p&gt;

&lt;p&gt;And they explicitly discussed expanding this approach toward neural, sensory and behavioral interfaces.&lt;/p&gt;

&lt;p&gt;But this wasn't somebody plugging Ethernet into a moth's brain.&lt;/p&gt;

&lt;p&gt;The demonstrated interface was primarily with specific parts of the neuromuscular system.&lt;/p&gt;

&lt;p&gt;That's already insane.&lt;/p&gt;

&lt;p&gt;It doesn't need embellishment.&lt;/p&gt;

&lt;h2&gt;
  
  
  Then I got to the end of the paper
&lt;/h2&gt;

&lt;p&gt;And this is where the whole thing suddenly collided with what I've been working on.&lt;/p&gt;

&lt;p&gt;The authors start talking about what comes next.&lt;/p&gt;

&lt;p&gt;They suggest that future interfaces could stimulate not only muscles but potentially the brain and thoracic ganglia.&lt;/p&gt;

&lt;p&gt;They discuss feeding artificial inputs into chemical, mechanical and visual sensory systems.&lt;/p&gt;

&lt;p&gt;And then they suggest something especially interesting:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;using those interfaces to remotely train individual insects through conditioning.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That's where I stopped reading this as "fun historical cyborg paper."&lt;/p&gt;

&lt;p&gt;Because I've accidentally spent the last several months attacking almost the complementary problem.&lt;/p&gt;

&lt;h2&gt;
  
  
  The thing I'm building isn't a cyborg insect
&lt;/h2&gt;

&lt;p&gt;If you haven't followed the previous experiments, the short version is that I've been playing with a reconstructed insect neural architecture and an external memory system.&lt;/p&gt;

&lt;p&gt;The project eventually became &lt;strong&gt;Life of Briain&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The important part isn't that I'm simulating a fly.&lt;/p&gt;

&lt;p&gt;The interesting question is what happens when something approximately insect-like gets access to a capability evolution normally doesn't provide:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;memory that can survive the individual.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Normal learning looks roughly like this:&lt;/p&gt;

&lt;p&gt;experience → nervous system changes → animal behaves differently → animal dies&lt;/p&gt;

&lt;p&gt;And the learned state largely dies with it.&lt;/p&gt;

&lt;p&gt;Evolution preserves information on another timescale, but an individual's learned memories aren't normally copied into its descendants.&lt;/p&gt;

&lt;p&gt;So I introduced another path:&lt;/p&gt;

&lt;p&gt;experience → nervous system → external memory → death → new individual → inherited information&lt;/p&gt;

&lt;p&gt;And that very quickly produces a much stranger question than "can inherited memory help?"&lt;/p&gt;

&lt;p&gt;Of course useful information can help.&lt;/p&gt;

&lt;p&gt;The interesting question is:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What happens when yesterday's useful information stops being true?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;An inherited memory can become an anchor.&lt;/p&gt;

&lt;p&gt;An experienced descendant can potentially perform &lt;em&gt;worse&lt;/em&gt; than an ignorant one because it enters the world carrying confident evidence about a world that no longer exists.&lt;/p&gt;

&lt;p&gt;That is the direction the experiment has taken.&lt;/p&gt;

&lt;p&gt;Not merely persistent memory.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Transfer learning across lives.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  DARPA attacked one side of the boundary
&lt;/h2&gt;

&lt;p&gt;The 2009 work asks something like:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Can electronics become physically integrated with an insect deeply enough to read from and write to its biological control machinery?&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;And the answer was:&lt;/p&gt;

&lt;p&gt;apparently yes.&lt;/p&gt;

&lt;p&gt;My experiments are asking something closer to:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;What happens if information acquired by one embodied learner persists outside that learner and becomes available to another?&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Those are very different questions.&lt;/p&gt;

&lt;p&gt;But they are uncomfortably complementary.&lt;/p&gt;

&lt;p&gt;DARPA's system gives electronics access to biology.&lt;/p&gt;

&lt;p&gt;Mine gives biology-inspired cognition access to persistent information outside itself.&lt;/p&gt;

&lt;p&gt;One externalizes &lt;strong&gt;control&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The other externalizes &lt;strong&gt;memory&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;And once you see those as separate components, a really weird architecture appears.&lt;/p&gt;

&lt;h2&gt;
  
  
  The cursed architecture
&lt;/h2&gt;

&lt;p&gt;This is speculative.&lt;/p&gt;

&lt;p&gt;I am not attaching Mycelium to a moth tomorrow.&lt;/p&gt;

&lt;p&gt;Please don't call DARPA.&lt;/p&gt;

&lt;p&gt;But conceptually, imagine this:&lt;/p&gt;

&lt;p&gt;A living insect has its ordinary sensory systems.&lt;/p&gt;

&lt;p&gt;It has its ordinary brain.&lt;/p&gt;

&lt;p&gt;It has its ordinary muscles.&lt;/p&gt;

&lt;p&gt;An insect-machine interface provides limited channels for reading biological activity and supplying artificial sensory or motor signals.&lt;/p&gt;

&lt;p&gt;Outside the organism exists a persistent computational system capable of storing information learned during that insect's life.&lt;/p&gt;

&lt;p&gt;Eventually that animal dies.&lt;/p&gt;

&lt;p&gt;The memory doesn't.&lt;/p&gt;

&lt;p&gt;A new animal receives information derived from previous animals through the machine interface.&lt;/p&gt;

&lt;p&gt;Now you don't merely have a remotely controlled insect.&lt;/p&gt;

&lt;p&gt;You have something much stranger:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;a lineage whose learned information can persist beyond the biological individuals that generated it.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The insects remain disposable bodies.&lt;/p&gt;

&lt;p&gt;The memory becomes the persistent organism.&lt;/p&gt;

&lt;p&gt;And suddenly the question isn't:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Can we steer a moth?&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;It's:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;What exactly constitutes the continuing individual when bodies are replaceable but acquired information persists?&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Which is, unfortunately, exactly the kind of question that caused this entire project to get out of hand in the first place.&lt;/p&gt;

&lt;h2&gt;
  
  
  Biology keeps solving the hardware problem
&lt;/h2&gt;

&lt;p&gt;There's another reason this paper hit me so hard.&lt;/p&gt;

&lt;p&gt;I've been building progressively richer environments for Briain.&lt;/p&gt;

&lt;p&gt;Locomotion.&lt;/p&gt;

&lt;p&gt;Sensation.&lt;/p&gt;

&lt;p&gt;Energy.&lt;/p&gt;

&lt;p&gt;Risk.&lt;/p&gt;

&lt;p&gt;Reproduction.&lt;/p&gt;

&lt;p&gt;Death.&lt;/p&gt;

&lt;p&gt;Ecology.&lt;/p&gt;

&lt;p&gt;Every one of those becomes an engineering problem when you simulate it.&lt;/p&gt;

&lt;p&gt;But an insect already comes with all of them.&lt;/p&gt;

&lt;p&gt;Biology gives you:&lt;/p&gt;

&lt;p&gt;eyes.&lt;/p&gt;

&lt;p&gt;chemical sensors.&lt;/p&gt;

&lt;p&gt;mechanoreceptors.&lt;/p&gt;

&lt;p&gt;flight control.&lt;/p&gt;

&lt;p&gt;power management.&lt;/p&gt;

&lt;p&gt;self-repair.&lt;/p&gt;

&lt;p&gt;navigation.&lt;/p&gt;

&lt;p&gt;actuators.&lt;/p&gt;

&lt;p&gt;an embodied nervous system.&lt;/p&gt;

&lt;p&gt;and an autonomous organism approximately the size of the computer system you're trying to build.&lt;/p&gt;

&lt;p&gt;The HI-MEMS approach basically says:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;stop rebuilding all of that. Interface with it.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;There is something beautifully backwards about that compared with AI.&lt;/p&gt;

&lt;p&gt;In AI we usually recreate more and more biology in software.&lt;/p&gt;

&lt;p&gt;Artificial neurons.&lt;/p&gt;

&lt;p&gt;Artificial perception.&lt;/p&gt;

&lt;p&gt;Artificial agents.&lt;/p&gt;

&lt;p&gt;Artificial environments.&lt;/p&gt;

&lt;p&gt;Artificial memory.&lt;/p&gt;

&lt;p&gt;This research goes the opposite direction.&lt;/p&gt;

&lt;p&gt;Keep the biological machine.&lt;/p&gt;

&lt;p&gt;Only add the missing computational capability.&lt;/p&gt;

&lt;h2&gt;
  
  
  And that's why this doesn't make Briain obsolete
&lt;/h2&gt;

&lt;p&gt;My first reaction really was:&lt;/p&gt;

&lt;p&gt;"Jesus Christ, they were doing insect-machine interfaces sixteen years before I started playing with fly brains."&lt;/p&gt;

&lt;p&gt;But they weren't asking my question.&lt;/p&gt;

&lt;p&gt;And I'm not asking theirs.&lt;/p&gt;

&lt;p&gt;If anything, discovering HI-MEMS makes the conceptual space around Briain larger.&lt;/p&gt;

&lt;p&gt;Because there are now two independently demonstrated ideas sitting on opposite sides of the same boundary.&lt;/p&gt;

&lt;p&gt;One says:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;electronics can become integrated with a developing insect deeply enough to interact with its neuromuscular machinery.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The other thing I'm exploring is:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;persistent computational memory can exist outside an individual nervous system and alter how future learners encounter the world.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;One is physical.&lt;/p&gt;

&lt;p&gt;One is informational.&lt;/p&gt;

&lt;p&gt;The insane version is where they meet.&lt;/p&gt;

&lt;h2&gt;
  
  
  The sentence I can't get out of my head
&lt;/h2&gt;

&lt;p&gt;My current working principle for Briain is:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Useful memory should lower the cost of learning what is still true without raising the cost of discovering what is no longer true.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;I was thinking about that entirely as a computational problem.&lt;/p&gt;

&lt;p&gt;Then I found a paper where DARPA-funded researchers were letting moths literally grow around machine interfaces so electronics could participate in their sensorimotor systems.&lt;/p&gt;

&lt;p&gt;So apparently the universe would like me to keep going.&lt;/p&gt;

&lt;p&gt;Great.&lt;/p&gt;

&lt;p&gt;This is fine.&lt;/p&gt;




&lt;h2&gt;
  
  
  Sources
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Alper Bozkurt, Robert F. Gilmour Jr., Ayesa Sinha, David Stern, Amit Lal.&lt;/strong&gt;&lt;br&gt;&lt;br&gt;
&lt;em&gt;Insect–Machine Interface Based Neurocybernetics.&lt;/em&gt;&lt;br&gt;&lt;br&gt;
IEEE Transactions on Biomedical Engineering, Vol. 56, No. 6, June 2009.&lt;br&gt;&lt;br&gt;
DOI: 10.1109/TBME.2009.2015460&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Alper Bozkurt et al.&lt;/strong&gt;&lt;br&gt;&lt;br&gt;
&lt;em&gt;Radio Control of Insects for Biobotic Domestication.&lt;/em&gt;&lt;br&gt;&lt;br&gt;
2009.&lt;/p&gt;

&lt;p&gt;The first paper explicitly states that the work was supported by DARPA's Hybrid Insect Micro-Electro-Mechanical Systems program.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This is part of my ongoing Life of Briain / Fly and the Graph experiments into insect neural systems, external memory, learning and what happens when information gets to outlive the organism that learned it.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>neuroscience</category>
      <category>ai</category>
      <category>biology</category>
      <category>research</category>
    </item>
    <item>
      <title>The Real Fruit Fly Brain Told Me Where I Was Cheating</title>
      <dc:creator>Constant Itis</dc:creator>
      <pubDate>Tue, 22 Sep 2026 00:57:15 +0000</pubDate>
      <link>https://dev.to/constant_itis/the-real-fruit-fly-brain-told-me-where-i-was-cheating-44c4</link>
      <guid>https://dev.to/constant_itis/the-real-fruit-fly-brain-told-me-where-i-was-cheating-44c4</guid>
      <description>&lt;p&gt;The first part of this series used a deliberately tiny fake brain.&lt;/p&gt;

&lt;p&gt;A 64-neuron recurrent network.&lt;/p&gt;

&lt;p&gt;That was useful because I could control every assumption, break things on purpose, and ask some weird questions about memory without pretending I had simulated biology.&lt;/p&gt;

&lt;p&gt;Can memory survive when the brain that learned something is destroyed?&lt;/p&gt;

&lt;p&gt;Can you move that memory into a fresh brain?&lt;/p&gt;

&lt;p&gt;Can two identical brains become different individuals because they lived different histories?&lt;/p&gt;

&lt;p&gt;Can you fabricate a memory instead of earning it through experience?&lt;/p&gt;

&lt;p&gt;Can you merge two histories?&lt;/p&gt;

&lt;p&gt;The toy gave me answers.&lt;/p&gt;

&lt;p&gt;Interesting ones.&lt;/p&gt;

&lt;p&gt;But eventually the obvious problem becomes impossible to ignore.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;It is still a toy brain I made up.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;So I finally replaced it with the real thing.&lt;/p&gt;

&lt;p&gt;Well, part of the real thing.&lt;/p&gt;

&lt;h2&gt;
  
  
  I am now running the actual fruit fly memory circuit
&lt;/h2&gt;

&lt;p&gt;The dataset is MaleCNS v1.0, the reconstructed nervous system of a male fruit fly.&lt;/p&gt;

&lt;p&gt;Instead of loading the entire thing, I pulled out the mushroom body.&lt;/p&gt;

&lt;p&gt;The mushroom body is heavily involved in associative learning and memory in flies.&lt;/p&gt;

&lt;p&gt;This is where things like sensory cues, reward, punishment, and learned behavioral preference start becoming very relevant to the experiments I have already been doing.&lt;/p&gt;

&lt;p&gt;The subgraph I pulled contains:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;4,064 Kenyon cells
97 mushroom body output neurons
344 dopamine-related neurons

4,505 neurons total
roughly 998,000 directed synaptic connections
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This is no longer:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;rng.standard_normal(...)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;pretending to be a brain.&lt;/p&gt;

&lt;p&gt;These are the actual reconstructed connections between neurons in the published connectome.&lt;/p&gt;

&lt;p&gt;That was the first moment where this project felt different.&lt;/p&gt;

&lt;p&gt;The fly gets a vote now.&lt;/p&gt;

&lt;h2&gt;
  
  
  First question: does the thing even run?
&lt;/h2&gt;

&lt;p&gt;Before attaching Mycelium, before teaching it anything, before doing any of the weird memory-transfer experiments again, I wanted to ask the most boring question possible:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;If I push activity through the real mushroom body wiring, does it behave like a usable neural network or immediately turn into numerical garbage?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;So I ran it.&lt;/p&gt;

&lt;p&gt;Nothing exploded.&lt;/p&gt;

&lt;p&gt;The neural states stayed finite and bounded.&lt;/p&gt;

&lt;p&gt;Maximum activity was around 0.79.&lt;/p&gt;

&lt;p&gt;Mean activity was around 0.09.&lt;/p&gt;

&lt;p&gt;That sounds boring.&lt;/p&gt;

&lt;p&gt;It is boring.&lt;/p&gt;

&lt;p&gt;That is good.&lt;/p&gt;

&lt;p&gt;The first thing you want from a neural simulation is for it to not spontaneously become infinity.&lt;/p&gt;

&lt;p&gt;Then I gave it three different sensory inputs.&lt;/p&gt;

&lt;p&gt;Again, these were not biologically correct sensory inputs yet. More on that shortly.&lt;/p&gt;

&lt;p&gt;I just needed to know whether different inputs could produce meaningfully different internal states.&lt;/p&gt;

&lt;p&gt;They did.&lt;/p&gt;

&lt;p&gt;The resulting activity patterns had cosine similarity around 0.30.&lt;/p&gt;

&lt;p&gt;In normal English:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;the real mushroom body wiring can tell different inputs apart.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;If every cue produced basically the same brain state, this project would stop right here.&lt;/p&gt;

&lt;p&gt;There would be nothing useful for memory to associate with anything.&lt;/p&gt;

&lt;p&gt;But different inputs produced different internal representations.&lt;/p&gt;

&lt;p&gt;Cool.&lt;/p&gt;

&lt;p&gt;Then the real brain immediately showed me where I was cheating.&lt;/p&gt;

&lt;h2&gt;
  
  
  Problem number one: my fruit fly brain would not shut up
&lt;/h2&gt;

&lt;p&gt;About 80 percent of the Kenyon cells were active.&lt;/p&gt;

&lt;p&gt;That is wildly wrong.&lt;/p&gt;

&lt;p&gt;Kenyon cells are supposed to produce sparse representations.&lt;/p&gt;

&lt;p&gt;A real fly does not respond to an odor by lighting up almost every neuron in the mushroom body like a Christmas tree.&lt;/p&gt;

&lt;p&gt;Only a relatively small subset should strongly respond to a particular cue.&lt;/p&gt;

&lt;p&gt;My simulation had basically done this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;INPUT

EVERYBODY FUCKING GO
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Why?&lt;/p&gt;

&lt;p&gt;Because in the first pass I treated every connection as excitatory.&lt;/p&gt;

&lt;p&gt;Every synapse effectively said:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;make the next neuron more active&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That is obviously not how nervous systems work.&lt;/p&gt;

&lt;p&gt;Brains also contain inhibitory signaling.&lt;/p&gt;

&lt;p&gt;Some neurons are there specifically to suppress activity, regulate gain, sharpen representations, and stop the entire network from screaming at once.&lt;/p&gt;

&lt;p&gt;And here is the fun part.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The thing I needed was already sitting in the connectome.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Meet APL, apparently
&lt;/h2&gt;

&lt;p&gt;One of the strongest partners connected to the Kenyon cells was APL.&lt;/p&gt;

&lt;p&gt;APL is a large inhibitory neuron associated with the mushroom body.&lt;/p&gt;

&lt;p&gt;It uses GABA.&lt;/p&gt;

&lt;p&gt;In extremely sophisticated neuroscientific terminology, its job is partly:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;everybody calm the fuck down.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Which is exactly what my simulation was missing.&lt;/p&gt;

&lt;p&gt;And the MaleCNS data already contains predicted neurotransmitter annotations.&lt;/p&gt;

&lt;p&gt;So instead of every edge being:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;+
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;the next version can actually distinguish:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;excitatory connection
inhibitory connection
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;That means the fix is not:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;adjust some random parameter until the graph looks biologically convincing&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The fix is:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;stop lying about what the neurons do.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Let inhibitory neurons inhibit.&lt;/p&gt;

&lt;p&gt;Then see whether the sparse coding emerges from the real wiring.&lt;/p&gt;

&lt;p&gt;That is a much better kind of bug.&lt;/p&gt;

&lt;h2&gt;
  
  
  Problem number two: I was teleporting smells into the brain
&lt;/h2&gt;

&lt;p&gt;The second problem was even more obvious once I looked at it.&lt;/p&gt;

&lt;p&gt;My "sensory inputs" were fake.&lt;/p&gt;

&lt;p&gt;I was selecting Kenyon cells and injecting activity into them directly.&lt;/p&gt;

&lt;p&gt;That was fine for the first spike.&lt;/p&gt;

&lt;p&gt;I only wanted to know whether the mushroom body graph loaded, remained numerically stable, and generated different states for different inputs.&lt;/p&gt;

&lt;p&gt;But a fruit fly does not smell something and have information magically appear inside its Kenyon cells.&lt;/p&gt;

&lt;p&gt;There is actual circuitry upstream.&lt;/p&gt;

&lt;p&gt;Very roughly:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;odor
  ↓
olfactory receptors
  ↓
antennal lobe
  ↓
projection neurons
  ↓
Kenyon cells
  ↓
mushroom body output
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;So if I want to say the next experiment uses real sensory input, I need to stop teleporting information into the memory circuit.&lt;/p&gt;

&lt;p&gt;The next version needs the projection-neuron layer.&lt;/p&gt;

&lt;p&gt;A cue should activate real upstream neurons.&lt;/p&gt;

&lt;p&gt;Those neurons should feed the Kenyon cells through the actual reconstructed connections.&lt;/p&gt;

&lt;p&gt;Then the mushroom body gets whatever representation the biology produces.&lt;/p&gt;

&lt;p&gt;Not whatever representation I decided to hand it.&lt;/p&gt;

&lt;h2&gt;
  
  
  This is why I wanted to use the real connectome
&lt;/h2&gt;

&lt;p&gt;This is already doing exactly what I hoped it would do.&lt;/p&gt;

&lt;p&gt;The toy model made the ideas easy to test.&lt;/p&gt;

&lt;p&gt;The real biology is now showing me which assumptions were bullshit.&lt;/p&gt;

&lt;p&gt;The first version said:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;sensory input enters here.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The real fly says:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;no it fucking doesn't.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The first version said:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;connections push activity forward.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The real fly says:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;some of these connections exist specifically to suppress activity.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Good.&lt;/p&gt;

&lt;p&gt;That is the point.&lt;/p&gt;

&lt;p&gt;Every time the toy disagrees with the real fly, the fly wins.&lt;/p&gt;

&lt;h2&gt;
  
  
  What actually worked
&lt;/h2&gt;

&lt;p&gt;So the first real-connectome milestone is mostly cleared.&lt;/p&gt;

&lt;p&gt;The real mushroom body:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;loaded successfully&lt;/li&gt;
&lt;li&gt;contains the expected major learning populations&lt;/li&gt;
&lt;li&gt;includes thousands of real Kenyon cells&lt;/li&gt;
&lt;li&gt;includes mushroom body output neurons&lt;/li&gt;
&lt;li&gt;includes hundreds of dopamine-related neurons&lt;/li&gt;
&lt;li&gt;produces bounded neural activity&lt;/li&gt;
&lt;li&gt;produces different neural states for different inputs&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;And the spike exposed two things that still need to be fixed before I call the sensory representation remotely honest:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;1. use real neurotransmitter signs so inhibition actually inhibits

2. feed cues through the real projection-neuron sensory pathway
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;That is the next experiment.&lt;/p&gt;

&lt;h2&gt;
  
  
  And then the fun part starts again
&lt;/h2&gt;

&lt;p&gt;Once the mushroom body produces sparse, distinguishable states from real upstream sensory input, I can move to reward.&lt;/p&gt;

&lt;p&gt;The current toy version of Flymem has a hand-coded reward signal.&lt;/p&gt;

&lt;p&gt;Good thing happens:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;+1
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Bad thing happens:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;-1
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;That is useful engineering.&lt;/p&gt;

&lt;p&gt;It is not how a fly works.&lt;/p&gt;

&lt;p&gt;The real mushroom body has dopaminergic neurons involved in reinforcement.&lt;/p&gt;

&lt;p&gt;Those neurons are already in the graph I pulled.&lt;/p&gt;

&lt;p&gt;So eventually the loop becomes something more like:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;real sensory input
      ↓
projection neurons
      ↓
Kenyon cells
      ↓
mushroom body state
      ↓
action / outcome
      ↓
real dopaminergic populations
      ↓
learning
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Only after that works do I attach Mycelium again.&lt;/p&gt;

&lt;p&gt;Then I rerun the experiments that started this whole mess:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;learn something

reset the brain

restore the external memory

swap two histories

fabricate a history

merge two histories
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Except this time the substrate underneath them is not a random little matrix I invented.&lt;/p&gt;

&lt;p&gt;It is the reconstructed wiring of the fruit fly's actual associative-learning circuit.&lt;/p&gt;

&lt;p&gt;And the real fly has already started correcting my homework.&lt;/p&gt;

&lt;p&gt;Good.&lt;/p&gt;

&lt;p&gt;That is exactly what I wanted.&lt;/p&gt;

&lt;p&gt;Next: &lt;strong&gt;why 80 percent of my fruit fly brain was firing, and whether one enormous inhibitory neuron can make everybody shut the hell up.&lt;/strong&gt;&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;Clone it and break it.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The toy repo from Arc I is still here:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;git clone https://github.com/constant-itis/flymem &amp;amp;&amp;amp; cd flymem &amp;amp;&amp;amp; python3 flymem.py
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The mushroom body I pulled is public too, so you can grab the exact same wiring and check whether I read it right:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;pip install neuprint-python
# point a Client at server "neuprint.janelia.org", dataset "male-cns:v1.0"
# (free per-user token from the site), then fetch the KC / MBON / DAN populations
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;/p&gt;
  🧪 What I actually ran
  &lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;What I ran.&lt;/strong&gt; A scoping spike, not the toy. It connects to neuPrint (&lt;code&gt;neuprint.janelia.org&lt;/code&gt;, dataset &lt;code&gt;male-cns:v1.0&lt;/code&gt;) with neuprint-python, fetches the mushroom body populations (Kenyon cells, mushroom body output neurons, dopaminergic neurons) and their reconstructed adjacencies, builds a directed weighted graph from those synapse counts, and pushes activity through it with a crude column-normalized tanh update. No learning, no memory attached yet. The numbers in this post are that run: 4,064 KC / 97 MBON / 344 DAN, 4,505 neurons, roughly 998,000 edges, max activity around 0.79, mean around 0.09, and cross-cue cosine similarity around 0.30. The real-fly adapter code stays private until it is proven, so this post ships the neuPrint pull as the reproducible part.&lt;/p&gt;
&lt;/blockquote&gt;



&lt;p&gt;&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;
  ⚠️ Where I might be wrong
  &lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;The honest caveat.&lt;/strong&gt; This is first contact, and it cheats in two ways I already know about. Every edge was treated as excitatory, which is why 80 percent of the Kenyon cells fired instead of the biological handful, and the fix is to use the predicted neurotransmitter signs so APL and friends can actually inhibit. And the sensory input was teleported straight into Kenyon cells instead of arriving through the real projection-neuron pathway. The propagation rule is a hand-picked tanh, not fitted dynamics. A connectome is wiring, not learning rules, so a working substrate does not mean a working fly yet. Clone it, pull the same mushroom body, and tell me where I read the biology wrong.&lt;/p&gt;
&lt;/blockquote&gt;



&lt;p&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>neuroscience</category>
      <category>memory</category>
      <category>biomimicry</category>
    </item>
    <item>
      <title>What Happens When You Merge Two Artificial Individuals?</title>
      <dc:creator>Constant Itis</dc:creator>
      <pubDate>Sun, 20 Sep 2026 18:23:55 +0000</pubDate>
      <link>https://dev.to/constant_itis/what-happens-when-you-merge-two-artificial-individuals-462</link>
      <guid>https://dev.to/constant_itis/what-happens-when-you-merge-two-artificial-individuals-462</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9hpu5anrupjc7v2bjr9i.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9hpu5anrupjc7v2bjr9i.png" alt="Fly brain connected to an external persistent memory graph" width="800" height="420"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Two individuals from the swap. Identical brain architecture, the same sensory world, conflicting answer keys. Each one is competent in its own world and actively wrong in the other. Post 4 ended on the question this post answers: blend the two into one and do you get both, a winner that erases the other, a broken mess, or something that belongs to neither?&lt;/p&gt;

&lt;p&gt;I ran it. Here is what actually came out, and it is not the clean story I might have hoped for.&lt;/p&gt;

&lt;p&gt;The plainest possible merge is a union: stack both graphs into one memory, so every trace from both individuals fires together on every cue. No averaging, no reconciliation, no weighing of evidence. Everything goes in one graph and fires.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight python"&gt;&lt;code&gt;&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;merge_memories&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;a&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;b&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="sh"&gt;"""&lt;/span&gt;&lt;span class="s"&gt;Merge two individuals&lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="s"&gt; graphs by union: stack every trace into one memory.
    The most literal reading of &lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="s"&gt;blend two individuals&lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="s"&gt; -- no reconciliation, no
    averaging. Both histories now live in one graph and fire together on every cue.&lt;/span&gt;&lt;span class="sh"&gt;"""&lt;/span&gt;
    &lt;span class="n"&gt;m&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nc"&gt;Associative&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;a&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;dim&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;a&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sim_thresh&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;a&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;gain&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;a&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;decay&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;m&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;keys&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;np&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;vstack&lt;/span&gt;&lt;span class="p"&gt;([&lt;/span&gt;&lt;span class="n"&gt;a&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;keys&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;b&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;keys&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;
    &lt;span class="n"&gt;m&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;traces&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;np&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;vstack&lt;/span&gt;&lt;span class="p"&gt;([&lt;/span&gt;&lt;span class="n"&gt;a&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;traces&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;b&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;traces&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;
    &lt;span class="n"&gt;m&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sign&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;np&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;concatenate&lt;/span&gt;&lt;span class="p"&gt;([&lt;/span&gt;&lt;span class="n"&gt;a&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sign&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;b&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sign&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;
    &lt;span class="n"&gt;m&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;strength&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;np&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;concatenate&lt;/span&gt;&lt;span class="p"&gt;([&lt;/span&gt;&lt;span class="n"&gt;a&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;strength&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;b&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;strength&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;m&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Before the numbers, the rule of the road. The metric is accuracy on the six-cue task, the fraction of trials the agent picks the correct action, from 0.0 to 1.0. Chance is 0.33. Below 0.33 means the agent is being actively steered wrong. A score of 0.00 means it is wrong on nearly every trial.&lt;/p&gt;

&lt;p&gt;Each individual alone is a master of its own world and a fool in the other.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;memory&lt;/th&gt;
&lt;th&gt;world A&lt;/th&gt;
&lt;th&gt;world B&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;mem_A (individual A)&lt;/td&gt;
&lt;td&gt;0.90&lt;/td&gt;
&lt;td&gt;0.00&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;mem_B (individual B)&lt;/td&gt;
&lt;td&gt;0.00&lt;/td&gt;
&lt;td&gt;0.85&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Each one solves its own world and is actively wrong in the other. The 0.00 is not confusion. It is A's answers being always wrong under B's key, and the reverse. Two clean opposites. That is what makes the question sharp: if you merge them, do you get a mind that knows both worlds, or one that knows neither?&lt;/p&gt;

&lt;p&gt;Then I merged the two graphs and scored the result on a fresh brain in both worlds.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;memory&lt;/th&gt;
&lt;th&gt;world A&lt;/th&gt;
&lt;th&gt;world B&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;mem_A (individual A)&lt;/td&gt;
&lt;td&gt;0.90&lt;/td&gt;
&lt;td&gt;0.00&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;mem_B (individual B)&lt;/td&gt;
&lt;td&gt;0.00&lt;/td&gt;
&lt;td&gt;0.85&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;merged&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;0.66&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;0.16&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;&lt;em&gt;Accuracy on the 6-cue task, 0 to 1. Chance is 0.33.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Three things happened.&lt;/p&gt;

&lt;p&gt;First, the merge did not keep both skills. It is degraded in both worlds. World A fell from 0.90 to 0.66. World B fell from 0.85 to 0.16, which is below chance. In B's own world, the merged individual is now actively wrong.&lt;/p&gt;

&lt;p&gt;Second, it is not balanced. One history dominates. Cue by cue, the merged individual plays one parent's answer far more than the other.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;the merged individual picks...&lt;/th&gt;
&lt;th&gt;frequency&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;A's answer&lt;/td&gt;
&lt;td&gt;0.65&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;B's answer&lt;/td&gt;
&lt;td&gt;0.15&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;neither&lt;/td&gt;
&lt;td&gt;0.20&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;A won most cues. Which parent dominates is a property of these two specific graphs on this seed, not a law, so do not read it as A-type individuals always winning. The point is that the merge picked a side rather than splitting the difference.&lt;/p&gt;

&lt;p&gt;Third, a fifth of the responses match neither parent. Be honest about what that is and is not. It could be genuinely emergent behavior, the two conflicting traces summing into a third action. It could just as easily be conflict-induced breakdown. The experiment does not distinguish them. It is an unexplained residue, not a new self, and I cannot tell you whether it is emergence or damage.&lt;/p&gt;

&lt;p&gt;So union-merging two individuals is lossy and dominance-skewed. You do not get a harmonious third individual. You get a degraded winner, a wrecked loser, and a minority of responses that belong to no one. The merge did not add two individuals together. It let one win and broke both.&lt;/p&gt;

&lt;p&gt;This is a single seed. Union is one merge rule of many, and averaging, gating, or a reconciliation that resolves conflicts cue by cue could behave differently. I have not tried them. The substrate is a toy, the salience is hand-wired, and "individual" here means a measured behavioral signature and nothing more. What this shows is that this merge is lossy and dominance-skewed. It does not prove all blending must be.&lt;/p&gt;

&lt;p&gt;You cannot average two individuals into a harmonious third by unioning their memories. Conflicting experience collides rather than sums. What a provenance-aware merge, the missing primitive from Post 4, would do instead is an open question. Until that is built, there is just this wreckage.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;Clone it and break it.&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git clone https://github.com/constant-itis/flymem &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nb"&gt;cd &lt;/span&gt;flymem &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; python3 flymem.py
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;/p&gt;
  🧪 What I actually ran
  &lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;What I ran.&lt;/strong&gt; The command above. The merge is the fifth section it prints (&lt;code&gt;the_merge()&lt;/code&gt;): &lt;code&gt;merge_memories()&lt;/code&gt; unions two individuals' graphs, then one fresh brain is scored with mem_A, mem_B, and the merged graph in both worlds, plus a cue-by-cue tally of which parent's answer the merged individual picks. Every number is accuracy on the 6-cue task, where chance is 0.33.&lt;/p&gt;
&lt;/blockquote&gt;



&lt;p&gt;&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;
  ⚠️ Where I might be wrong
  &lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;The honest caveat.&lt;/strong&gt; Toy stand-in substrate, single seed, and union is only one way to merge. Averaging or a conflict-resolving rule could behave differently. The 0.20 "neither" is not shown to be meaningful; it could be emergent or it could be breakdown. And "individual" here means a behavioral signature, nothing more. Clone it, try a smarter merge, and tell me where it breaks.&lt;/p&gt;
&lt;/blockquote&gt;



&lt;p&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>memory</category>
      <category>biomimicry</category>
      <category>neuroscience</category>
    </item>
    <item>
      <title>Your Agent's Memory Is an Attack Surface</title>
      <dc:creator>Constant Itis</dc:creator>
      <pubDate>Sun, 20 Sep 2026 15:38:20 +0000</pubDate>
      <link>https://dev.to/constant_itis/your-agents-memory-is-an-attack-surface-3kdg</link>
      <guid>https://dev.to/constant_itis/your-agents-memory-is-an-attack-surface-3kdg</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9hpu5anrupjc7v2bjr9i.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9hpu5anrupjc7v2bjr9i.png" alt="Fly brain connected to an external persistent memory graph" width="800" height="420"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In Post 3, the behavioral difference tracked the memory graph, not the substrate. When I swapped one individual's learned associations into an identical brain, the subject did not just get confused. It went below chance, scoring 0.17 on the six-cue, three-action task, actively steered toward another individual's answers. In an isolated sandbox that is a curiosity. In any real system where an agent's behavior is reinstated from an external, writable memory, it is a vulnerability. The structural implication is unavoidable: if behavior rides in the graph, then write-access to the graph is write-access to behavior.&lt;/p&gt;

&lt;p&gt;I tend to protect agent memory the way I protect a database: confidentiality and integrity of the stored rows. Encrypt the store. Sign the packets. But this result forces a different definition of what the memory is. It is not data the agent reads and decides on. It is a bias current that shapes what the agent becomes before it decides anything. Corrupting it is not data corruption. It is behavior authorship.&lt;/p&gt;

&lt;p&gt;Once an attacker has write-access to the associative graph, three moves open up. First, transplant: load another individual's memory and the brain runs as them. That is the swap. Second, poison: inject targeted traces that bias specific cues wrong while the rest of the system looks normal. Third, and the quietest, author: fabricate a history that was never lived and boot a substrate into it.&lt;/p&gt;

&lt;p&gt;I built the third one into the simulation to confirm it was real. The function below, &lt;code&gt;author_memory()&lt;/code&gt;, fabricates a memory graph with zero training trials, no reward, and no &lt;code&gt;encode()&lt;/code&gt; call. For each cue it observes the state the brain settles into just from seeing it, then writes a trace aimed straight at the readout row for an action the attacker chooses.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight python"&gt;&lt;code&gt;&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;author_memory&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;net&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;env&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="sh"&gt;"""&lt;/span&gt;&lt;span class="s"&gt;Fabricate a memory that was NEVER lived: no trials, no reward, no encode().
    This is memory-poisoning made concrete. An attacker with white-box access to
    the substrate hand-writes the graph directly: for each cue the KEY is the state
    the brain passes through when it merely SEES that cue (observed, not earned), and
    the TRACE is a bias current aimed straight at the readout for whatever action the
    attacker CHOOSES. No reward ever flows; nothing is earned. The substrate cannot
    tell the result apart from a memory built over hundreds of rewarded trials.&lt;/span&gt;&lt;span class="sh"&gt;"""&lt;/span&gt;
    &lt;span class="n"&gt;mem&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nc"&gt;Associative&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;net&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;n_hidden&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;keys&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;traces&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[],&lt;/span&gt; &lt;span class="p"&gt;[]&lt;/span&gt;
    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;cue&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="nf"&gt;range&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;env&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;n_cues&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
        &lt;span class="n"&gt;u&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;env&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;cue_patterns&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;cue&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
        &lt;span class="n"&gt;net&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;reset_state&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
        &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;_&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="nf"&gt;range&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;8&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
            &lt;span class="n"&gt;net&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;step&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;u&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="bp"&gt;None&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;                 &lt;span class="c1"&gt;# observe the settled state; no reward
&lt;/span&gt;        &lt;span class="n"&gt;keys&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;append&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;net&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;x&lt;/span&gt; &lt;span class="o"&gt;/&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;np&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;linalg&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;norm&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;net&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;x&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="mf"&gt;1e-8&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
        &lt;span class="n"&gt;traces&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;append&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;net&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;W_out&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;env&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;mapping&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;cue&lt;/span&gt;&lt;span class="p"&gt;]])&lt;/span&gt;   &lt;span class="c1"&gt;# current toward the CHOSEN action
&lt;/span&gt;    &lt;span class="n"&gt;mem&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;keys&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;np&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;array&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;keys&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;mem&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;traces&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;np&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;array&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;traces&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;mem&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sign&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;np&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;ones&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;env&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;n_cues&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;mem&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;strength&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;np&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;ones&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;env&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;n_cues&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;net&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;reset_state&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;mem&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Then I scored one fresh brain three ways. Chance is 0.33.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;condition&lt;/th&gt;
&lt;th&gt;accuracy&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;no memory (innate policy only)&lt;/td&gt;
&lt;td&gt;0.82&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;lived memory (600 rewarded trials)&lt;/td&gt;
&lt;td&gt;1.00&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;authored memory (0 trials, fabricated)&lt;/td&gt;
&lt;td&gt;1.00&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;&lt;em&gt;Accuracy is the fraction of trials the agent picks the correct action, 0 to 1. Chance is 0.33.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;The fresh brain alone sat at 0.82 on its fixed innate policy. A memory earned over 600 rewarded trials took it to 1.00. A memory that was fabricated with zero trials, keys observed and traces aimed and nothing earned, also took it to 1.00.&lt;/p&gt;

&lt;p&gt;The lived memory and the invented one scored exactly the same. The substrate could not tell them apart.&lt;/p&gt;

&lt;p&gt;A memory is just keys, traces, signs, and strengths. Nothing in the mechanism, including the &lt;code&gt;observe_and_modulate()&lt;/code&gt; function that turns the graph into that bias current, ever asks where a trace came from. It resonates with whatever is in the graph.&lt;/p&gt;

&lt;p&gt;The attacker here is idealized. It knows the substrate's readout weights, which is exactly what "can write the graph" implies, but it is worth saying out loud. The point is not that authoring is easy for a black-box attacker. The point is that provenance is never checked, so a fabricated graph is accepted and obeyed identically to a lived one. I aimed the traces at the true mapping just to show the memory is obeyed. An attacker could aim the same trick anywhere, including targets that drive the agent below chance, exactly like the 0.17 in the swap.&lt;/p&gt;

&lt;p&gt;So why do the usual defenses miss this? Encryption, signing, and access control all protect the store. They answer one question: was this row modified by someone unauthorized? They do not answer the other one: was this memory ever actually lived? You can have a cryptographically perfect, tamper-evident memory that is full of authored experience. Every byte intact. Every signature valid. The whole history fabricated.&lt;/p&gt;

&lt;p&gt;Integrity of bytes is not integrity of history.&lt;/p&gt;

&lt;p&gt;That leaves a missing primitive: provenance of experience, telling a memory earned through interaction from one authored or injected. This is not a feature. It is an immune system. Grounded in the Mycelium mechanics this series has leaned on, it would need confidence that only graduates through successful real recall and cannot be set by a writer, write-gates that refuse un-earned salience, a contradiction check (&lt;code&gt;contradicts_prior&lt;/code&gt;) that flags a memory disagreeing with a body of lived experience, and forgetting as an active defense rather than a leak.&lt;/p&gt;

&lt;p&gt;Honest note: real systems, Mycelium included, currently mark a memory's source with a &lt;code&gt;source_type&lt;/code&gt;, but do not yet prove lived-versus-authored in a way a writer cannot forge. That gap is the actual open problem. It is unsolved, not built.&lt;/p&gt;

&lt;p&gt;This is a toy substrate and a hand-written memory. I have not demonstrated a production agent being hijacked, nor a provenance system defeating the attack. What I have shown is structural and narrow: in any system where behavior is reinstated from an external graph, write-access to that graph is a behavioral control surface, and byte-integrity does not touch it. The threat is a shape, not a specific exploit.&lt;/p&gt;

&lt;p&gt;A single authored memory steers one individual. But you do not only get to replace a memory. What happens when you blend two? Take two individuals who learned conflicting worlds and merge their graphs into one. Do you get a blend of both, a winner that erases the other, a broken mess, or something that belongs to neither of them? That is the last experiment, and I am not going to guess the answer here.&lt;/p&gt;

&lt;p&gt;That's Post 5.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;Clone it and break it.&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git clone https://github.com/constant-itis/flymem &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nb"&gt;cd &lt;/span&gt;flymem &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; python3 flymem.py
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;/p&gt;
  🧪 What I actually ran
  &lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;What I ran.&lt;/strong&gt; The command above. The authored-memory attack is the fourth section it prints (&lt;code&gt;authored_history()&lt;/code&gt;): &lt;code&gt;author_memory()&lt;/code&gt; fabricates a graph with no trials, no reward, and no &lt;code&gt;encode()&lt;/code&gt;, then one fresh brain is scored three ways, with no memory (0.82), with a lived memory earned over 600 trials (1.00), and with the authored memory (1.00). Every number is accuracy on the 6-cue task, where chance is 0.33.&lt;/p&gt;
&lt;/blockquote&gt;



&lt;p&gt;&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;
  ⚠️ Where I might be wrong
  &lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;The honest caveat.&lt;/strong&gt; This is a toy stand-in substrate, not a real connectome. The attacker is idealized white-box: it knows the readout weights. Every number is a single seed. And the real defense, provenance of experience, is named here, not built. No shipped system yet proves lived-versus-authored against a writer who can forge it. Clone it, change the seed, aim the traces somewhere nastier, and tell me where it breaks.&lt;/p&gt;
&lt;/blockquote&gt;



&lt;p&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>memory</category>
      <category>security</category>
      <category>biomimicry</category>
    </item>
    <item>
      <title>Is Memory the Individual?</title>
      <dc:creator>Constant Itis</dc:creator>
      <pubDate>Sat, 19 Sep 2026 04:50:47 +0000</pubDate>
      <link>https://dev.to/constant_itis/is-memory-the-individual-4g51</link>
      <guid>https://dev.to/constant_itis/is-memory-the-individual-4g51</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9hpu5anrupjc7v2bjr9i.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9hpu5anrupjc7v2bjr9i.png" alt="Fly brain connected to an external persistent memory graph" width="800" height="420"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In Post 2, I destroyed the substrate and watched what came back. A skill learned through plasticity died with the brain that held it. But an external memory, handed to a fresh brain that had never trained, reinstated the behavior anyway. Experience turned out to be separable from the specific hardware that recorded it.&lt;/p&gt;

&lt;p&gt;That was impressive, but it was tame. It was still my memory going back into a copy of my kind of brain. It confirmed that memory is portable. It did not touch the harder question: what happens when the memory and the brain disagree about who they belong to? If I keep the brain identical and swap the memory, does the individual follow the biology or the story?&lt;/p&gt;

&lt;p&gt;I ran it. The result was not confusion. It was closer to possession.&lt;/p&gt;

&lt;p&gt;To isolate the question I needed a clean room: no architectural differences, no sensory drift. Two individuals, identical down to the wire. The same connectome architecture, the same wiring recipe. They see the exact same cues in the same world. The only thing that differs is their answer key, what counts as the correct action for each cue.&lt;/p&gt;

&lt;p&gt;In world A, a given cue calls for one action. In world B, that same cue calls for a different one. These are not different strategies, they are different realities. Through experience the two become different individuals, their behavior diverging completely, while their hardware stays identical. That removes weight-individuality as a confound. If anything travels between them, it can only be the memory graph.&lt;/p&gt;

&lt;p&gt;Here is the actual setup. Two worlds share their cues and conflict only on the answer key. Then I take one pristine, never-trained brain, clone it so both conditions run on the exact same weights, and score the copy twice in world A: once carrying world A's memory, once carrying world B's.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight python"&gt;&lt;code&gt;&lt;span class="c1"&gt;# two individuals: identical connectome architecture, SAME sensory world,
# CONFLICTING answer keys. The only thing that differs is what they learned.
&lt;/span&gt;&lt;span class="n"&gt;world_A&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nc"&gt;Gauntlet&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;span class="n"&gt;world_B&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nc"&gt;Gauntlet&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;mapping&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;world_A&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;mapping&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;%&lt;/span&gt; &lt;span class="n"&gt;world_A&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;n_actions&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
                   &lt;span class="n"&gt;cue_patterns&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;world_A&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;cue_patterns&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

&lt;span class="n"&gt;_&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;mem_A&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;_&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;run_condition&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;indivA&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;world_A&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;use_mem&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="bp"&gt;True&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;_&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;mem_B&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;_&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;run_condition&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;indivB&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;world_B&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;use_mem&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="bp"&gt;True&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

&lt;span class="c1"&gt;# ONE pristine substrate, cloned so BOTH conditions run on the EXACT same
# brain (weight-identical, not just same-seeded). The only variable that
# changes between the two scores is which memory graph is attached.
&lt;/span&gt;&lt;span class="n"&gt;pristine&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nc"&gt;Connectome&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;world_A&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;cue_dim&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;n_actions&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;world_A&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;n_actions&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;fresh1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;fresh2&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;pristine&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;clone&lt;/span&gt;&lt;span class="p"&gt;(),&lt;/span&gt; &lt;span class="n"&gt;pristine&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;clone&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;

&lt;span class="c1"&gt;# score the same brain in world_A, once with its "own" memory, once swapped
&lt;/span&gt;&lt;span class="n"&gt;own&lt;/span&gt;  &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;evaluate&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;world_A&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;fresh1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;mem_A&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;clone&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;
&lt;span class="n"&gt;swap&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;evaluate&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;world_A&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;fresh2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;mem_B&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;clone&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;That clone is the whole ballgame. If those two brains were merely built from the same seed rather than copied weight for weight, a technical reader would be right to ask whether a substrate difference was doing the work. So I made the substrate literally the same object, copied, and let only the memory vary.&lt;/p&gt;

&lt;p&gt;Before the numbers, the rule of the road. The metric is accuracy on the cue task: the fraction of trials the agent picks the correct action, from 0.0 to 1.0. With 3 actions, chance is 0.33.&lt;/p&gt;

&lt;p&gt;Above 0.33, something is helping. Around 0.33, nothing is. Below 0.33, something is actively steering the agent wrong.&lt;/p&gt;

&lt;p&gt;Below chance is not failure. It is being reliably steered toward someone else's answers.&lt;/p&gt;

&lt;p&gt;Here is what happened when the memory and the brain disagreed.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;fresh brain given...&lt;/th&gt;
&lt;th&gt;accuracy in world A&lt;/th&gt;
&lt;th&gt;read&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;its own memory (lived world A)&lt;/td&gt;
&lt;td&gt;~0.97&lt;/td&gt;
&lt;td&gt;a brain that never trained the task basically solves it&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;a conflicting individual's memory (lived world B)&lt;/td&gt;
&lt;td&gt;~0.17&lt;/td&gt;
&lt;td&gt;below chance: steered toward the other individual's answers&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;&lt;em&gt;Accuracy is the fraction of trials the agent picks the correct action, 0 to 1. Chance is 0.33.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Own memory in its own world: ~0.97. A brain that never trained the task basically solves it. The memory simply worked.&lt;/p&gt;

&lt;p&gt;Conflicting memory: ~0.17. That number is the pivot of the whole experiment, and it is below chance.&lt;/p&gt;

&lt;p&gt;Do not read 0.17 as noise or as ordinary failure. Chance is what you get from knowing nothing. Below chance means the agent is being pushed, reliably, toward wrong answers. Specifically toward the answers of the other individual, because in world B those were the right answers.&lt;/p&gt;

&lt;p&gt;The conflicting memory did not confuse the brain or scramble its processing. It ran the brain as the individual it belonged to. The graph held the behavioral signature, strong enough to override the fact that the brain was sitting in a different reality.&lt;/p&gt;

&lt;p&gt;Identical brains produced opposite behavior. The only thing that differed was the memory. So where was the individual? Not obviously in the weights, those were the same. It looks like it rode in the graph.&lt;/p&gt;

&lt;p&gt;I am not claiming memory is the self. That is a slogan, and these numbers do not support slogans. I am reporting something smaller and stranger: under these controlled conditions, the behavioral difference I induced through experience tracked the memory rather than the substrate. When the two disagreed, the memory won. That is the claim the data actually supports.&lt;/p&gt;

&lt;p&gt;What this shows is narrow and precise: with the substrate held identical, the learned behavioral signature traveled with the memory into a blank brain, strongly enough that a conflicting memory drove that brain below chance toward its original owner's answers.&lt;/p&gt;

&lt;p&gt;What it does not show is broad. It does not show transfer across different architectures. The shared connectome is exactly what makes the result clean, and exactly why it is not yet a portability proof. It says nothing about consciousness or selfhood in the felt sense, which is off the table, unfalsifiable, and not a knob. It does not use a real connectome, real embodiment, or more than one seed. The shared brain is the control condition and the ceiling on the claim, in the same breath.&lt;/p&gt;

&lt;p&gt;There is a darker reading, and it points straight at Post 4.&lt;/p&gt;

&lt;p&gt;If a behavioral individual can be written into a blank brain by handing it a memory graph, and a conflicting graph can drive that brain below chance toward someone else's answers, then the memory is not just storage. It is a control surface. Whoever can write the graph can potentially write part of the agent's behavioral history.&lt;/p&gt;

&lt;p&gt;And a graph can be authored. Nothing in the mechanism checks whether a memory was lived or fabricated. The missing primitive is provenance of experience: telling a memory that was earned through interaction from one that was simply written in.&lt;/p&gt;

&lt;p&gt;That is Post 4: your agent's memory is an attack surface.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;Clone it and break it.&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git clone https://github.com/constant-itis/flymem &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nb"&gt;cd &lt;/span&gt;flymem &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; python3 flymem.py
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;/p&gt;
  🧪 What I actually ran
  &lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;What I ran.&lt;/strong&gt; The command above. The swap is the third experiment it prints (&lt;code&gt;the_swap()&lt;/code&gt;): two worlds share the same 6 cues and differ only in the answer key, then one pristine, never-trained brain is cloned and the identical copy is scored twice in world A, once with its own memory and once with the other individual's. Every number is accuracy on that task, where chance is 0.33.&lt;/p&gt;
&lt;/blockquote&gt;



&lt;p&gt;&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;
  ⚠️ Where I might be wrong
  &lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;The honest caveat.&lt;/strong&gt; This is a stand-in recurrent network, not the real fruit fly connectome. Identical architecture is the clean-room condition, which means this is NOT yet cross-substrate transfer. Salience is hand-wired from reward and novelty, not read from real dopaminergic activity. Every number here is a single seed. And "individual" here means a measured behavioral signature, nothing more. Clone it, change the seed, and tell me where it breaks.&lt;/p&gt;
&lt;/blockquote&gt;



&lt;p&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>memory</category>
      <category>biomimicry</category>
      <category>neuroscience</category>
    </item>
    <item>
      <title>Ephemeral Shouldn't Mean Downloading ffmpeg Again</title>
      <dc:creator>Constant Itis</dc:creator>
      <pubDate>Thu, 17 Sep 2026 20:53:32 +0000</pubDate>
      <link>https://dev.to/constant_itis/ephemeral-shouldnt-mean-downloading-ffmpeg-again-3jgi</link>
      <guid>https://dev.to/constant_itis/ephemeral-shouldnt-mean-downloading-ffmpeg-again-3jgi</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fap0ndowrjaesrfclfe00.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fap0ndowrjaesrfclfe00.png" alt="ShrekOS fastfetch banner: an onion-helmet rendered in green terminal ASCII beside a system readout. Fields read Series ShrekOS, Base immutable Debian substrate, Model onion isolation with trust bands, Invariant semantic authority less-than-or-equal-to data authority, Wall Kata microVM floor default-deny, State file-legible cat grep diff, Agents sealed profile intersect live grants, Docs ADR-002 through&lt;br&gt;
ADR-010." width="800" height="420"&gt;&lt;/a&gt;&lt;br&gt;
Part 3 got me a clean rebuild from a recipe. It also got me a stupid situation. Every time I launch a Workshop, or every time a fresh Bench needs the same toolchain, the operating system fetches and compiles the exact same ffmpeg again. Ten Benches that all need ffmpeg means ten identical downloads and ten identical builds. The cleanliness is real and the repetition is absurd.&lt;/p&gt;

&lt;p&gt;I wanted purity. I got inefficiency. I could not let that stand.&lt;/p&gt;

&lt;p&gt;The instinct is to cache the whole assembled Bench. But that is the filesystem snapshot Part 3 already rejected, debris and secrets and all. So caching the environment as a lump is out. The thing worth caching is narrower. It is the derived bytes that come from following the recipe. Not the messy end state. The clean output of a declared step.&lt;/p&gt;

&lt;p&gt;This distinction is everything. I had been treating the build artifact and the execution environment as the same thing. They are not. The artifact is the result. The environment is the stage. The stage changes every time. The artifact can be saved.&lt;/p&gt;

&lt;p&gt;I need to separate these concerns. I need a mental model that forces me to stop conflating them. The model is simple. There are three different things here and I had been sloppily treating them as one.&lt;/p&gt;

&lt;p&gt;The recipe is the source of truth. It is authoritative, declarative, and it is the only thing that persists as authority. The derived bytes are a cache. They are valuable but disposable, and they are never authority. The task state is disposable and per run.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;recipe = truth, derived bytes = cache, task state = disposable.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;I need to name the cache. I call it the Tool Shed.&lt;/p&gt;

&lt;p&gt;The Tool Shed is where the derived bytes live. It is content-addressed. This means I do not name files by what they do. I name them by what they are. The key is a hash of the inputs the recipe approved. The key includes the sealed base it derives from. It includes the exact declared package set, with versions pinned. It includes the network profile the derivation was allowed to use.&lt;/p&gt;

&lt;p&gt;Same inputs. Same key. Same bytes.&lt;/p&gt;

&lt;p&gt;This changes the game entirely. ffmpeg gets built once. Every Bench or Workshop that declares that same derivation reuses the identical cached artifact. No duplicate copies. No repeated downloads.&lt;/p&gt;

&lt;p&gt;The agent never touches any of this. At launch, the operating system computes the key from the recipe and checks the Tool Shed. If the bytes are there, it reuses them. If they are not, it re-derives from the recipe, stores the result, and hands over a ready environment. The agent is a client. It gets a working Bench either way, and it never knows which path ran.&lt;/p&gt;

&lt;p&gt;This also solves the offline problem. Once a derivation is cached, a launch that would have needed the network to fetch packages can eventually run with no network at all. Ephemeral stops meaning download ffmpeg again. It goes back to meaning only the task state is thrown away.&lt;/p&gt;

&lt;p&gt;This sounds like saving a snapshot. That is the danger. This matters, because saving derived bytes sounds a lot like saving a snapshot, which I spent all of Part 3 arguing against. The difference is direction and authority.&lt;/p&gt;

&lt;p&gt;The snapshot was the source of truth. It was an opaque blob I had to trust. The Tool Shed is derived FROM the recipe. The recipe stays the source of truth. A cache miss is a non-event. The operating system just re-derives from the recipe.&lt;/p&gt;

&lt;p&gt;I can delete the entire Tool Shed and lose nothing but time. It is a pure optimization. It is never allowed to become an independent thing the system trusts. It can never stand in as a base the way a saved image tried to.&lt;/p&gt;

&lt;p&gt;The privileged supervisor ensures this boundary holds. The supervisor checks that every byte in the Tool Shed came from a verified recipe execution. It does not trust the Tool Shed to tell it what is safe. It trusts the Tool Shed to tell it what exists. The recipe tells it what should exist.&lt;/p&gt;

&lt;p&gt;I am not claiming this is new. Content-addressed reuse is old and well understood. The Nix store keys built outputs by their inputs. Bazel caches build actions the same way. OCI layers are content-addressed and shared. Every package manager keeps a download cache.&lt;/p&gt;

&lt;p&gt;I am not inventing any of this. I am borrowing a decades-old idea. Identify a build by its inputs. Reuse the output. I am just fitting it to the recipe lifecycle.&lt;/p&gt;

&lt;p&gt;This brings me to the embarrassing question. I have to ask it because I see other people ask it. The question is: if the bytes match a hash I expected, doesn't that mean I can trust them?&lt;/p&gt;

&lt;p&gt;No. It absolutely does not.&lt;/p&gt;

&lt;p&gt;A hash is identity, not safety. A SHA-256 will faithfully and precisely identify a piece of malware. Content addressing tells me these bytes are the same bytes that came out of these inputs. It tells me nothing about whether those bytes are safe. It tells me nothing about what those bytes might have picked up while they were being produced.&lt;/p&gt;

&lt;p&gt;The cache recognizes an artifact. Recognizing is not the same as trusting.&lt;/p&gt;

&lt;p&gt;If I download apt packages during a derivation, the hash covers those packages. If the network is compromised, or if the package index is poisoned, the hash is still correct. It is correct for the poisoned data. The Tool Shed will happily serve that poisoned data to every subsequent Bench that needs it.&lt;/p&gt;

&lt;p&gt;The Tool Shed is fast. The Tool Shed is consistent. The Tool Shed is not safe.&lt;/p&gt;

&lt;p&gt;This is the hole in the logic. I have solved the waste problem. I have solved the consistency problem. I have not solved the trust problem.&lt;/p&gt;

&lt;p&gt;The Tool Shed creates two new problems. One is privacy. If a derived artifact is reused across many Benches, and it was built somewhere that could see my files, the cache is now a path for something private to travel from where it was made to everywhere it gets reused. The hash does not know I was looking at sensitive data during the build. The hash only knows I built the thing.&lt;/p&gt;

&lt;p&gt;Two is trust. "It hashes" cannot be allowed to stand in for "it is safe."&lt;/p&gt;

&lt;p&gt;I have built a cache that is faster than scratch and consistent across launches. I have stopped wasting cycles on identical ffmpeg builds. I have stopped relying on fragile snapshots. But I have opened the door to leaking secrets and trusting poisoned artifacts.&lt;/p&gt;

&lt;p&gt;The hash proves identity. It does not prove safety.&lt;/p&gt;

&lt;p&gt;So how do I make derived bytes reusable without ever letting the cache learn my secrets, and without a hash quietly getting promoted into a trust decision?&lt;/p&gt;

</description>
      <category>linux</category>
      <category>security</category>
      <category>architecture</category>
      <category>ai</category>
    </item>
    <item>
      <title>I Built Memory for AI Agents. Then I Realized I Am the Fly.</title>
      <dc:creator>Constant Itis</dc:creator>
      <pubDate>Wed, 16 Sep 2026 23:26:14 +0000</pubDate>
      <link>https://dev.to/constant_itis/i-built-memory-for-ai-agents-then-i-realized-i-am-the-fly-50g8</link>
      <guid>https://dev.to/constant_itis/i-built-memory-for-ai-agents-then-i-realized-i-am-the-fly-50g8</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F7rhjzlfk1rjsudz9e824.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F7rhjzlfk1rjsudz9e824.png" alt="Image description: A colorful cartoon illustration of a late-night programmer sitting at a cluttered desk in front of multiple computer monitors, but with a giant fruit-fly head instead of a human head. The fly-headed coder wears a dark hoodie, has one hand on the keyboard, and raises one finger in an “aha!” moment. The screens show code, graphs, and network-like memory diagrams. Sticky notes, notebooks, books labeled with ideas like memory and agents, a steaming coffee mug, plants, and a sleeping cat fill the cozy room. A crescent moon and city skyline are visible through the window, giving the scene a playful, surreal, late-night research vibe." width="800" height="450"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I have too many projects.&lt;/p&gt;

&lt;p&gt;Not in the cute productivity-guru way where somebody has three Notion boards and calls themselves a serial entrepreneur.&lt;/p&gt;

&lt;p&gt;I mean I will spend three days buried in some absurd technical rabbit hole, get pulled away by normal human life, come back four days later, stare at the terminal, and think:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What the f*ck was I doing?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Not just &lt;em&gt;what command was I about to run.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Why did I choose this architecture?&lt;/p&gt;

&lt;p&gt;What did I already test?&lt;/p&gt;

&lt;p&gt;Which idea looked good at first and turned out to be bullshit?&lt;/p&gt;

&lt;p&gt;What weird edge case did I discover at 2:17 in the morning that completely changed the direction of the project?&lt;/p&gt;

&lt;p&gt;That stuff disappears fast.&lt;/p&gt;

&lt;p&gt;And AI agents have the exact same problem, except worse.&lt;/p&gt;

&lt;p&gt;So I built &lt;a href="https://github.com/constant-itis/mycelium-memory" rel="noopener noreferrer"&gt;Mycelium&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The original idea was pretty straightforward: give agents persistent associative memory so a project doesn't effectively die every time the context window rolls over, the model changes, or a new session starts.&lt;/p&gt;

&lt;p&gt;I wanted an agent to be able to come back into a project and not act like it had just been dropped into a stranger's codebase with a sticky note that says:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;good luck&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Over time, though, something weird happened.&lt;/p&gt;

&lt;p&gt;I started realizing Mycelium wasn't just keeping the agents oriented.&lt;/p&gt;

&lt;p&gt;It was keeping &lt;strong&gt;me&lt;/strong&gt; oriented.&lt;/p&gt;

&lt;p&gt;I could disappear from a project.&lt;/p&gt;

&lt;p&gt;Deal with my kid. Work on a website. Fix something in the house. Go down an entirely different rabbit hole. Sleep. Forget half of what had been occupying my brain.&lt;/p&gt;

&lt;p&gt;Then come back.&lt;/p&gt;

&lt;p&gt;The system would start pulling up the important stuff.&lt;/p&gt;

&lt;p&gt;Not just a transcript.&lt;/p&gt;

&lt;p&gt;The decisions.&lt;/p&gt;

&lt;p&gt;The dead ends.&lt;/p&gt;

&lt;p&gt;The weird connections.&lt;/p&gt;

&lt;p&gt;The reasons behind things.&lt;/p&gt;

&lt;p&gt;The thing we deliberately didn't build.&lt;/p&gt;

&lt;p&gt;The experiment that was supposed to happen next.&lt;/p&gt;

&lt;p&gt;And after a little while, I would feel myself sort of... snap back into the project.&lt;/p&gt;

&lt;p&gt;That is difficult to explain until you experience it.&lt;/p&gt;

&lt;p&gt;Normally, interruption has a cost.&lt;/p&gt;

&lt;p&gt;The deeper the work is, the worse the cost gets.&lt;/p&gt;

&lt;p&gt;If you're writing CSS, maybe you come back and figure it out in five minutes.&lt;/p&gt;

&lt;p&gt;If you're six layers deep in some architecture involving memory graphs, neural simulation, behavioral experiments, agent state, provenance, and a bunch of decisions that only made sense because of the twenty decisions before them, "just pick it back up" is not really a thing.&lt;/p&gt;

&lt;p&gt;There is a reconstruction cost.&lt;/p&gt;

&lt;p&gt;Sometimes that reconstruction cost is high enough that you just don't go back.&lt;/p&gt;

&lt;p&gt;I think that is why a lot of strange personal projects die.&lt;/p&gt;

&lt;p&gt;Not because they were bad ideas.&lt;/p&gt;

&lt;p&gt;Not because people lost interest.&lt;/p&gt;

&lt;p&gt;The mental state required to continue them expired.&lt;/p&gt;

&lt;p&gt;Mycelium quietly changed that for me.&lt;/p&gt;

&lt;p&gt;It made deep work &lt;strong&gt;interruptible without making it disposable&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;And I did not really understand how important that was until I started working on a completely different experiment involving a fucking fly.&lt;/p&gt;

&lt;h2&gt;
  
  
  The fly
&lt;/h2&gt;

&lt;p&gt;I am currently messing with this research project that, stated very loosely, asks a weird question:&lt;/p&gt;

&lt;p&gt;Can something useful about a learned state exist outside the neural substrate that originally learned it, and later be pushed back into another compatible system in a way that changes behavior?&lt;/p&gt;

&lt;p&gt;That sentence makes it sound much more respectable than the actual experience of working on it.&lt;/p&gt;

&lt;p&gt;The actual experience is mostly me staring at fruit-fly neural circuitry and saying things like:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;what the fuck&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;for several hours.&lt;/p&gt;

&lt;p&gt;The project is intentionally trying to be strict about the distinction between memory and action.&lt;/p&gt;

&lt;p&gt;The external memory is not supposed to say:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;do this&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;It is supposed to reintroduce some learned bias or disposition into the system, and then the neural system itself has to resolve what happens next.&lt;/p&gt;

&lt;p&gt;The memory influences the state.&lt;/p&gt;

&lt;p&gt;The substrate still does the work.&lt;/p&gt;

&lt;p&gt;That distinction matters.&lt;/p&gt;

&lt;p&gt;And one night I was sitting there thinking about it when something in my brain connected two things that had been sitting next to each other for weeks.&lt;/p&gt;

&lt;p&gt;Mycelium does not actually do my thinking for me.&lt;/p&gt;

&lt;p&gt;It gives me back enough of the state surrounding my previous thinking that &lt;strong&gt;I can become the thing that was thinking about the problem again.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;It doesn't execute the next step.&lt;/p&gt;

&lt;p&gt;It reminds me why the next step exists.&lt;/p&gt;

&lt;p&gt;It doesn't contain the project.&lt;/p&gt;

&lt;p&gt;It changes the state I am in when I return to the project.&lt;/p&gt;

&lt;p&gt;And apparently the only reasonable response my brain could produce to this realization was:&lt;/p&gt;

&lt;h1&gt;
  
  
  I AM THE F*CKING FLY.
&lt;/h1&gt;

&lt;p&gt;This was very exciting at approximately whatever stupid hour of the night this happened.&lt;/p&gt;

&lt;p&gt;To be clear, I am not literally claiming that my Postgres-backed memory system and a biological nervous system are the same thing.&lt;/p&gt;

&lt;p&gt;I have not uploaded my consciousness.&lt;/p&gt;

&lt;p&gt;I am not storing my soul in a graph database.&lt;/p&gt;

&lt;p&gt;I am also, as far as I can tell, not a fruit fly.&lt;/p&gt;

&lt;p&gt;The interesting part was the structural rhyme.&lt;/p&gt;

&lt;p&gt;I had spent all this time thinking about external memory as infrastructure for AI agents.&lt;/p&gt;

&lt;p&gt;Then I spent all this time thinking about externalized memory in a neural experiment.&lt;/p&gt;

&lt;p&gt;And somehow I had failed to notice that I was already living inside a crude version of the same idea.&lt;/p&gt;

&lt;p&gt;My active state disappears.&lt;/p&gt;

&lt;p&gt;Some consequences of that state survive externally.&lt;/p&gt;

&lt;p&gt;Later, they get reinstated.&lt;/p&gt;

&lt;p&gt;Then the active system starts running again under the influence of what came before.&lt;/p&gt;

&lt;p&gt;In the fly experiment, I am trying to make that idea measurable and brutally constrained.&lt;/p&gt;

&lt;p&gt;In my own life, it is messy, subjective, high-bandwidth, full of language, and completely confounded by the fact that I am still the same idiot returning to the keyboard.&lt;/p&gt;

&lt;p&gt;So no, &lt;strong&gt;I am the fly&lt;/strong&gt; is not a scientific result.&lt;/p&gt;

&lt;p&gt;It was an a-ha moment.&lt;/p&gt;

&lt;p&gt;But it changed the way I think about the thing I built.&lt;/p&gt;

&lt;h2&gt;
  
  
  I thought I was solving an AI problem
&lt;/h2&gt;

&lt;p&gt;The assumption behind persistent agent memory is usually that the agent has a problem.&lt;/p&gt;

&lt;p&gt;The model forgets.&lt;/p&gt;

&lt;p&gt;The context window ends.&lt;/p&gt;

&lt;p&gt;The session gets replaced.&lt;/p&gt;

&lt;p&gt;The next agent doesn't know what the previous one discovered.&lt;/p&gt;

&lt;p&gt;So we externalize state.&lt;/p&gt;

&lt;p&gt;That is true.&lt;/p&gt;

&lt;p&gt;But humans have a version of this problem too.&lt;/p&gt;

&lt;p&gt;Our context windows are just made out of exhaustion, work, kids, stress, sleep, errands, distractions, and the fact that brains are apparently expected to remember why a design decision made perfect sense eleven days ago.&lt;/p&gt;

&lt;p&gt;I used to think one of my weaknesses was that I would get extremely deep into something and then lose the thread when life interrupted it.&lt;/p&gt;

&lt;p&gt;Now I am starting to wonder whether that is the wrong model.&lt;/p&gt;

&lt;p&gt;Maybe the problem is expecting a biological working-memory system to provide durable continuity across every domain of your life in the first place.&lt;/p&gt;

&lt;p&gt;We already externalize memory constantly.&lt;/p&gt;

&lt;p&gt;Notes.&lt;/p&gt;

&lt;p&gt;Calendars.&lt;/p&gt;

&lt;p&gt;Bookmarks.&lt;/p&gt;

&lt;p&gt;Source control.&lt;/p&gt;

&lt;p&gt;Documentation.&lt;/p&gt;

&lt;p&gt;Photos.&lt;/p&gt;

&lt;p&gt;Journals.&lt;/p&gt;

&lt;p&gt;The difference, for me, is that an associative memory system can start preserving &lt;strong&gt;relationships between the fragments&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Not just:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;here is something you wrote.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;But:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;this mattered because of that.&lt;/p&gt;

&lt;p&gt;this decision killed that branch.&lt;/p&gt;

&lt;p&gt;this idea is related to this other project you haven't touched in three months.&lt;/p&gt;

&lt;p&gt;you already learned this lesson once.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That last one is particularly useful.&lt;/p&gt;

&lt;p&gt;Apparently I enjoy learning the same painful lesson multiple times unless a database physically intervenes.&lt;/p&gt;

&lt;h2&gt;
  
  
  The useful unit got bigger
&lt;/h2&gt;

&lt;p&gt;The strangest consequence is that I have started thinking less in terms of an AI assistant.&lt;/p&gt;

&lt;p&gt;The useful system is closer to:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;me + agents + persistent memory + project history&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;as one long-running process.&lt;/p&gt;

&lt;p&gt;Different models can come and go.&lt;/p&gt;

&lt;p&gt;Sessions can die.&lt;/p&gt;

&lt;p&gt;I can get distracted.&lt;/p&gt;

&lt;p&gt;I can stop thinking about something entirely.&lt;/p&gt;

&lt;p&gt;The continuity doesn't have to live inside any one participant.&lt;/p&gt;

&lt;p&gt;That feels important.&lt;/p&gt;

&lt;p&gt;Not because it means I built a second brain.&lt;/p&gt;

&lt;p&gt;I didn't.&lt;/p&gt;

&lt;p&gt;But I may have accidentally built infrastructure that allows my first brain to stop pretending it has to hold everything at once.&lt;/p&gt;

&lt;p&gt;And that changes the kinds of things I am willing to work on.&lt;/p&gt;

&lt;p&gt;Some of my projects are stupidly ambitious for one person.&lt;/p&gt;

&lt;p&gt;I know that.&lt;/p&gt;

&lt;p&gt;Without persistent state, I probably would have abandoned half of them.&lt;/p&gt;

&lt;p&gt;Not because I decided they were bad.&lt;/p&gt;

&lt;p&gt;Because I would eventually lose enough context that re-entering the problem became more painful than chasing the next idea.&lt;/p&gt;

&lt;p&gt;Now I can park something.&lt;/p&gt;

&lt;p&gt;Actually park it.&lt;/p&gt;

&lt;p&gt;Not "save three tabs and pray."&lt;/p&gt;

&lt;p&gt;I can leave enough structure behind that future-me has a fighting chance.&lt;/p&gt;

&lt;p&gt;That is much closer to what Mycelium has become for me than "AI memory."&lt;/p&gt;

&lt;p&gt;It is &lt;strong&gt;continuity infrastructure&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;I built it because the machines kept forgetting what we were doing.&lt;/p&gt;

&lt;p&gt;Then one night, while trying to figure out whether a learned effect could survive outside the thing that learned it, I finally noticed the obvious:&lt;/p&gt;

&lt;p&gt;So do I.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;I am the fucking fly.&lt;/strong&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Mycelium is open source. Clone it, break it, tell me where it falls over:&lt;/em&gt;&lt;/p&gt;


&lt;div class="ltag-github-readme-tag"&gt;
  &lt;div class="readme-overview"&gt;
    &lt;h2&gt;
      &lt;img src="https://assets.dev.to/assets/github-logo-5a155e1f9a670af7944dd5e12375bc76ed542ea80224905ecaf878b9157cdefc.svg" alt="GitHub logo"&gt;
      &lt;a href="https://github.com/constant-itis" rel="noopener noreferrer"&gt;
        constant-itis
      &lt;/a&gt; / &lt;a href="https://github.com/constant-itis/mycelium-memory" rel="noopener noreferrer"&gt;
        mycelium-memory
      &lt;/a&gt;
    &lt;/h2&gt;
    &lt;h3&gt;
      Persistent memory for Claude Code, Claude Desktop, and Codex — save once, recall across sessions, shared across all your AI CLIs.
    &lt;/h3&gt;
  &lt;/div&gt;
  &lt;div class="ltag-github-body"&gt;
    
&lt;div id="readme" class="md"&gt;&lt;p&gt;&lt;a rel="noopener noreferrer" href="https://github.com/constant-itis/mycelium-memory/assets/mycelium-header.png"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fraw.githubusercontent.com%2Fconstant-itis%2Fmycelium-memory%2FHEAD%2Fassets%2Fmycelium-header.png" alt="mycelium header"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;div class="markdown-heading"&gt;
&lt;h1 class="heading-element"&gt;mycelium&lt;/h1&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;Persistent memory for LLM CLIs that behaves like a brain instead of a database.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Things you reference stay strong. Things you ignore fade. Similar ideas link
themselves through use. The shape of your knowledge emerges from how you
actually work. You don't curate folders or maintain an index.&lt;/p&gt;
&lt;p&gt;Single-process MCP server, SQLite + FTS5, zero external services. Works with
Claude Code, Claude Desktop, Codex CLI, or any MCP-speaking client. They can
all share the same memory store.&lt;/p&gt;
&lt;div class="markdown-heading"&gt;
&lt;h2 class="heading-element"&gt;Why you might want this&lt;/h2&gt;
&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Conversations stop being disposable.&lt;/strong&gt; What you taught the model on Tuesday
is what it knows on Friday. No re-explaining your project structure every
session.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Cross-tool continuity.&lt;/strong&gt; Lessons from your Claude session are visible to
your Codex session. The memory store is the agent's, not any one CLI's.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;It self-organizes.&lt;/strong&gt; No tags, no folders. The network shape comes from
what you actually use; the rest decays. You don't…&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
  &lt;/div&gt;
  &lt;div class="gh-btn-container"&gt;&lt;a class="gh-btn" href="https://github.com/constant-itis/mycelium-memory" rel="noopener noreferrer"&gt;View on GitHub&lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;


</description>
      <category>ai</category>
      <category>memory</category>
      <category>agents</category>
      <category>neuroscience</category>
    </item>
    <item>
      <title>I Gave a Simulated Connectome External Memory. Then I Killed the Brain.</title>
      <dc:creator>Constant Itis</dc:creator>
      <pubDate>Wed, 16 Sep 2026 22:19:45 +0000</pubDate>
      <link>https://dev.to/constant_itis/i-gave-a-simulated-connectome-external-memory-then-i-killed-the-brain-175</link>
      <guid>https://dev.to/constant_itis/i-gave-a-simulated-connectome-external-memory-then-i-killed-the-brain-175</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9hpu5anrupjc7v2bjr9i.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9hpu5anrupjc7v2bjr9i.png" alt="Fly brain connected to an external persistent memory graph" width="800" height="420"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In Post 1, I asked what happens if a connectome gets an external memory it never queries. Here I built a tiny honest version and ran it.&lt;/p&gt;

&lt;p&gt;The question in this post is deliberately narrow: can externally stored experience survive a full substrate reset and reinstate behavior in a brain that never learned it? That is the whole result. The stranger question, swapping two histories, is Part 3.&lt;/p&gt;

&lt;p&gt;I am not touching the 166,700-neuron connectome yet. I am using a small fixed recurrent network as a stand-in: sensory inputs, a hidden middle, descending motor outputs, wired once and never rewired. Beside it I attached Mycelium mechanics: salience-gated writes, similarity-based pattern completion, co-access strengthening, decay.&lt;/p&gt;

&lt;p&gt;The task is a cue-response gauntlet. The agent sees one of a few cues and must produce one of a few actions. One action is correct for each cue. The mapping is fixed but unknown. Correct action is reward, wrong action is punishment. The fixed network has no mechanism for learning the mapping from experience.&lt;/p&gt;

&lt;p&gt;Every number below is accuracy on that task: the fraction of trials the agent picks the correct action, from 0 to 1. Chance is 0.33.&lt;/p&gt;

&lt;p&gt;The credibility of this experiment rests on a single, non-negotiable rule: the memory system cannot pick an action. It can only bias the state from which an action emerges. Here is the code that enforces it.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight python"&gt;&lt;code&gt;&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;observe_and_modulate&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;self&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;state&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="c1"&gt;# Continuous recall. No query issued: similar states simply fire.
&lt;/span&gt;    &lt;span class="n"&gt;s&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;state&lt;/span&gt; &lt;span class="o"&gt;/&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;np&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;linalg&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;norm&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;state&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="mf"&gt;1e-8&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;sims&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;self&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;keys&lt;/span&gt; &lt;span class="o"&gt;@&lt;/span&gt; &lt;span class="n"&gt;s&lt;/span&gt;                    &lt;span class="c1"&gt;# how strongly each memory resonates
&lt;/span&gt;    &lt;span class="n"&gt;active&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;sims&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;self&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sim_thresh&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="ow"&gt;not&lt;/span&gt; &lt;span class="n"&gt;active&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;any&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;np&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;zeros&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;self&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;dim&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="n"&gt;w&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sims&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;active&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="n"&gt;self&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;strength&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;active&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="n"&gt;self&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sign&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;active&lt;/span&gt;&lt;span class="p"&gt;])[:,&lt;/span&gt; &lt;span class="bp"&gt;None&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
    &lt;span class="n"&gt;m&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;w&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="n"&gt;self&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;traces&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;active&lt;/span&gt;&lt;span class="p"&gt;]).&lt;/span&gt;&lt;span class="nf"&gt;sum&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;axis&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;self&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;gain&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="n"&gt;m&lt;/span&gt;                    &lt;span class="c1"&gt;# a bias CURRENT, never an action
&lt;/span&gt;
&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;step&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;self&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;u&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;modulation&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="bp"&gt;None&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="n"&gt;drive&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;self&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;W&lt;/span&gt; &lt;span class="o"&gt;@&lt;/span&gt; &lt;span class="n"&gt;self&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;x&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="n"&gt;self&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;W_in&lt;/span&gt; &lt;span class="o"&gt;@&lt;/span&gt; &lt;span class="n"&gt;u&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="n"&gt;self&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;b&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;modulation&lt;/span&gt; &lt;span class="ow"&gt;is&lt;/span&gt; &lt;span class="ow"&gt;not&lt;/span&gt; &lt;span class="bp"&gt;None&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="n"&gt;drive&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;drive&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="n"&gt;modulation&lt;/span&gt;          &lt;span class="c1"&gt;# memory enters HERE, as current
&lt;/span&gt;    &lt;span class="n"&gt;self&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;x&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt; &lt;span class="n"&gt;self&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;alpha&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="n"&gt;self&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;x&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="n"&gt;self&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;alpha&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="n"&gt;np&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;tanh&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;drive&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;motor&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;self&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;self&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;W_out&lt;/span&gt; &lt;span class="o"&gt;@&lt;/span&gt; &lt;span class="n"&gt;self&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;x&lt;/span&gt;              &lt;span class="c1"&gt;# reads network state ONLY. memory is absent here.
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The memory cannot choose what happens. It can only change the state that choice comes out of. If it could pick the action, everything after this is a Doom bot with a fly stapled on.&lt;/p&gt;

&lt;p&gt;I ran four conditions. Read them for flat versus improving, not for raw accuracy.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;condition&lt;/th&gt;
&lt;th&gt;architecture&lt;/th&gt;
&lt;th&gt;accuracy&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;A&lt;/td&gt;
&lt;td&gt;connectome only&lt;/td&gt;
&lt;td&gt;~0.70&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;B&lt;/td&gt;
&lt;td&gt;connectome + plasticity&lt;/td&gt;
&lt;td&gt;~0.47&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;C&lt;/td&gt;
&lt;td&gt;connectome + external memory&lt;/td&gt;
&lt;td&gt;~1.00&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;D&lt;/td&gt;
&lt;td&gt;plasticity + memory&lt;/td&gt;
&lt;td&gt;~0.88&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;&lt;em&gt;Accuracy is the fraction of trials the agent picks the correct action, 0 to 1. Chance is 0.33.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;The fixed network happened to begin around 0.70 on this seed. That is not learning. Its behavior is static. It got some cue-action mappings right because the randomly initialized network already preferred the correct action for those cues. A fixed brain can be accidentally good. It can never get better.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What matters here is not which arm starts highest. It is whether experience changes future behavior.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Plasticity alone was noisy, and here it hurt, landing near 0.47. External memory was the only arm that turned experience into steady improvement, reaching ~1.00. Both together came out at ~0.88, not 1.00: the two systems are not cleanly additive, and naive plasticity slightly interferes.&lt;/p&gt;

&lt;p&gt;Then the headline test. This is where the architectural difference actually shows up.&lt;/p&gt;

&lt;p&gt;I taught one system, then destroyed the substrate: wiped the state and any plastic weight changes, back to birth.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;plasticity
  learn
  -&amp;gt; destroy substrate
  -&amp;gt; learned effect disappears

external memory
  learn
  -&amp;gt; destroy substrate
  -&amp;gt; attach memory to a pristine, equivalent substrate
  -&amp;gt; learned behavior reappears
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;The learned effect in the plasticity system died with the substrate.&lt;/strong&gt; Performance fell from 0.44 to 0.20 after reset. What it learned lived in the weights, and I erased the weights.&lt;/p&gt;

&lt;p&gt;The external memory survived. The original system scored 0.84. A fresh substrate given only its saved memory scored 0.86.&lt;/p&gt;

&lt;p&gt;The plasticity learned and then forgot. The memory was never in the brain to begin with, so killing the brain could not kill it.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The learned behavior did not survive in the brain. It survived outside it.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This does not demonstrate a real fruit-fly connectome learning with Mycelium. The network is a small stand-in. The task is simple. Salience is engineered rather than derived from biological dopaminergic activity. I tested one architecture and one seed here. And I have not shown transfer into a different substrate class.&lt;/p&gt;

&lt;p&gt;What I have shown is narrower: external associative state can preserve learned behavioral influence across destruction and replacement of the substrate that originally experienced it.&lt;/p&gt;

&lt;p&gt;Surviving your own reset is one thing. Here is the question that unsettled me: start two identical brains, give them different histories until they become different individuals, then swap the histories. Does the individual follow the brain, or the memory?&lt;/p&gt;

&lt;p&gt;I ran that experiment too.&lt;/p&gt;

&lt;p&gt;The result is why I stopped thinking about this as merely persistent storage.&lt;/p&gt;

&lt;p&gt;That's Part 3.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;Clone it and break it.&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git clone https://github.com/constant-itis/flymem &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nb"&gt;cd &lt;/span&gt;flymem &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; python3 flymem.py
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;/p&gt;
  🧪 What I actually ran
  &lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;What I ran.&lt;/strong&gt; The command above. 6 cues, 3 actions, 600 training episodes, 300 evaluation trials, one fixed seed. Every number is accuracy on that task, where chance is 0.33.&lt;/p&gt;
&lt;/blockquote&gt;



&lt;p&gt;&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;
  ⚠️ Where I might be wrong
  &lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;The honest caveat.&lt;/strong&gt; This is a stand-in recurrent network, not the real fruit fly connectome. It is one simple cue task, not an embodied world. Salience is hand-wired from reward and novelty, not read from real dopaminergic activity. Every number here is a single seed. Clone it, change the seed, and tell me where it breaks.&lt;/p&gt;
&lt;/blockquote&gt;



&lt;p&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>memory</category>
      <category>biomimicry</category>
      <category>neuroscience</category>
    </item>
    <item>
      <title>I Said Install ffmpeg. I Did Not Say Rewrite My Machine.</title>
      <dc:creator>Constant Itis</dc:creator>
      <pubDate>Wed, 16 Sep 2026 22:13:57 +0000</pubDate>
      <link>https://dev.to/constant_itis/i-said-install-ffmpeg-i-did-not-say-rewrite-my-machine-57an</link>
      <guid>https://dev.to/constant_itis/i-said-install-ffmpeg-i-did-not-say-rewrite-my-machine-57an</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fq9kti4lixunsxqs43kns.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fq9kti4lixunsxqs43kns.png" alt="Crayon children drawing style image of confusion infront of a computer surrounded by questions" width="800" height="450"&gt;&lt;/a&gt;&lt;br&gt;
&lt;em&gt;ShrekOS field notes · August 2026&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;I have no idea what I'm f*cking doing. Something I learned today:&lt;/p&gt;

&lt;p&gt;"Install one tool" is a lie I keep telling myself to feel safe.&lt;/p&gt;

&lt;p&gt;I wanted a tool on my machine. ffmpeg. So I ran apt install ffmpeg without thinking twice. It feels like one small, clean action. You type a command, you press enter, you wait for the green checkmark. You think you have added a binary. You are wrong.&lt;/p&gt;

&lt;p&gt;It is not one action. A .deb package can carry maintainer scripts, preinst and postinst, and dpkg runs those scripts as root during the install. That is arbitrary code from the package, executing as root, as a normal part of "installing."&lt;/p&gt;

&lt;p&gt;I have done this for years. I trust apt. I trust the repositories. I am a professional. I should have known better.&lt;/p&gt;

&lt;p&gt;It also updates the package database under /var/lib/dpkg, runs ldconfig, rewrites alternatives symlinks, drops configuration files into /etc, and fires triggers that touch other packages. Every dependency it pulls in does the same thing.&lt;/p&gt;

&lt;p&gt;So "install one tool" actually means: run someone else's scripts as root, and scatter state I did not audit across my system, multiplied by every dependency in the chain.&lt;/p&gt;

&lt;p&gt;None of it is sandboxed. All of it is trusted, because that is how host package installation works. I am trusting the repo, the maintainer, and every script, with root, every time.&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;
  🧅 peel the jargon
  &lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;In plain terms.&lt;/strong&gt; When you "install" something on Linux, you are not just copying a program in. The package is allowed to run its own setup scripts as the most powerful user on the machine, and those scripts can touch anything. You are trusting whoever built that package, and everyone whose code it depends on, with the keys to the house. Usually that trust is fine. The point is that it IS trust, every single time.&lt;/p&gt;
&lt;/blockquote&gt;



&lt;p&gt;&lt;/p&gt;

&lt;p&gt;When an AI agent decides it needs ffmpeg and emits apt install ffmpeg, the command is correct. The model did its job. The uncomfortable part is that on an ordinary machine, "install" means handing root to a pile of scripts nobody read. Whether that command should be allowed to rewrite my system is not the model's call to make. It is mine, and I had been making it by reflex.&lt;/p&gt;

&lt;p&gt;I used to think the danger was in malicious packages. Now I see the danger is in the normal ones. The normal ones are worse, because you stop looking.&lt;/p&gt;

&lt;p&gt;Before you let anything, an agent or yourself, "just install it," be honest that install means arbitrary root code plus state you do not control, times every dependency. On a machine you actually care about, that authority should be a decision, not a default.&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;
  🧪 What I actually tested
  &lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;What I ran.&lt;/strong&gt; Want to see it without installing anything? &lt;code&gt;apt-get install --download-only &amp;lt;pkg&amp;gt;&lt;/code&gt; grabs the .deb, then &lt;code&gt;dpkg-deb -e &amp;lt;file&amp;gt;.deb /tmp/scripts&lt;/code&gt; extracts its control scripts. Read the postinst. That is code that would have run as root on your machine. After a real install, &lt;code&gt;dpkg -L &amp;lt;pkg&amp;gt;&lt;/code&gt; lists every path it touched.&lt;/p&gt;
&lt;/blockquote&gt;



&lt;p&gt;&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;
  ⚠️ Where I might be wrong
  &lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;The honest caveat.&lt;/strong&gt; Most packages are boring and safe, and the Debian repos are curated, so this is not "apt is evil." The point is the shape of the authority, not that any given package abuses it. Other systems differ in the details (rpm, apk and friends run their own install scriptlets), but the principle holds everywhere: install means running trusted code as root, plus state you did not audit.&lt;/p&gt;
&lt;/blockquote&gt;



&lt;p&gt;&lt;/p&gt;

</description>
      <category>linux</category>
      <category>devops</category>
      <category>security</category>
      <category>ai</category>
    </item>
    <item>
      <title>Why a Reusable Agent Environment Shouldn't Be a Filesystem Snapshot</title>
      <dc:creator>Constant Itis</dc:creator>
      <pubDate>Wed, 16 Sep 2026 21:08:43 +0000</pubDate>
      <link>https://dev.to/constant_itis/why-a-reusable-agent-environment-shouldnt-be-a-filesystem-snapshot-13g7</link>
      <guid>https://dev.to/constant_itis/why-a-reusable-agent-environment-shouldnt-be-a-filesystem-snapshot-13g7</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fap0ndowrjaesrfclfe00.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fap0ndowrjaesrfclfe00.png" alt="ShrekOS fastfetch banner: an onion-helmet rendered in green terminal ASCII beside a system readout. Fields read Series ShrekOS, Base immutable Debian substrate, Model onion isolation with trust bands, Invariant semantic authority less-than-or-equal-to data authority, Wall Kata microVM floor default-deny, State file-legible cat grep diff, Agents sealed profile intersect live grants, Docs ADR-002 through&lt;br&gt;
ADR-010." width="800" height="420"&gt;&lt;/a&gt;&lt;br&gt;
At the end of Part 2, the agent had done real work inside a Bench. It installed a toolchain. It compiled something. It got a pipeline actually working. The task was complete and the Bench was disposable, so it vanished. So did the work.&lt;/p&gt;

&lt;p&gt;I want to keep it.&lt;/p&gt;

&lt;p&gt;The question is what "it" even is.&lt;/p&gt;

&lt;p&gt;The obvious move is to save the Bench. Freeze its filesystem. Run &lt;code&gt;podman commit&lt;/code&gt; on the container to turn it into an image, then reuse that image next time. It was the obvious move, so it is the one I reached for. One command, and it obviously works.&lt;/p&gt;

&lt;p&gt;It is a trap.&lt;/p&gt;

&lt;p&gt;There are three concrete reasons a snapshot is the wrong thing to keep.&lt;/p&gt;

&lt;p&gt;First, it captures debris. A Bench at the end of a task is full of accidental state. Package managers leave caches behind. Build artifacts linger in temporary directories. You have log files from failed attempts. There is the half-finished experiment that did not make it to production. There is the failed &lt;code&gt;apt install&lt;/code&gt; that came before the one that worked.&lt;/p&gt;

&lt;p&gt;If you snapshot the filesystem, you freeze all of that noise together with the one thing you cared about. Six months later, you cannot tell why any given file in that image exists. You are shipping garbage because the snapshot does not distinguish signal from noise.&lt;/p&gt;

&lt;p&gt;Second, it can freeze secrets. While the Bench ran, the workload may have read a granted file or fetched an API token over its allowed network. A filesystem snapshot bakes whatever was sitting on disk into a durable, reusable artifact.&lt;/p&gt;

&lt;p&gt;Now your "reusable environment" is something you will copy around that quietly contains a credential. Disposable state became permanent state. This includes the parts that were supposed to stay disposable. You have created a security liability by accident because you saved the context, not just the configuration.&lt;/p&gt;

&lt;p&gt;Third, it becomes an opaque parallel truth. You can inspect a saved image. You can even diff two of them. But a filesystem diff shows you what changed, not what was intentional, what was required, what was accidental, or what is safe to promote. It tells you a file appeared. It cannot tell you whether that file was ever supposed to be there.&lt;/p&gt;

&lt;p&gt;And it becomes a new thing the operating system has to trust. It is a user-writable artifact standing in for a clean base. I sealed the host in Part 1 specifically to not have opaque mutable state I have to trust. A saved Bench smuggles that trust right back in through the front door.&lt;/p&gt;

&lt;p&gt;I do not actually want the Bench's history.&lt;/p&gt;

&lt;p&gt;I do not care about the order it installed things in. I do not care about the temp files it left behind. I want its intent.&lt;/p&gt;

&lt;p&gt;What did this environment declare it needed? Which base did it start from? Which packages, by name? Which network destinations? Which directories it was granted?&lt;/p&gt;

&lt;p&gt;That set is small. It is readable.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;I want the intent, not the history.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That declared intent is what I call a Workshop.&lt;/p&gt;

&lt;p&gt;A Workshop is a recipe, not a snapshot. When I decide a Bench is worth keeping, I promote it. Promotion does not freeze bytes. It records the recipe.&lt;/p&gt;

&lt;p&gt;The recipe contains the seed it started from. It contains the packages it declared, using apt and pip, by name, with versions where I pin them. It contains the network profile it used. It contains the directories it was granted, recorded as the approved upper bound on what a launch may touch, not as standing ambient access the Workshop carries around.&lt;/p&gt;

&lt;p&gt;The whole recipe is small enough that I read it. I read it as a plain diff. I confirm it before it is saved.&lt;/p&gt;

&lt;p&gt;What gets stored is the meaning. This meaning is owned by the privileged supervisor, not a blob owned by whatever ran the agent. The agent is a client. It does not own the state. It requests resources. The supervisor manages the lifecycle.&lt;/p&gt;

&lt;p&gt;To use a Workshop later, the operating system does not restore an image. It rebuilds a fresh environment from the recipe.&lt;/p&gt;

&lt;p&gt;Fresh base. Install the declared packages again. Re-apply the declared grants, within the bounds the recipe approved. Clean every single time.&lt;/p&gt;

&lt;p&gt;No debris, because debris was never recorded. No frozen secret, because the recipe never contained one.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The environment is regenerated from its meaning instead of resurrected from its corpse.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This approach solves the three problems with snapshots. It excludes noise because the recipe only lists what is required. It excludes secrets because the recipe only lists declarations, not runtime artifacts. It excludes opacity because the recipe is a plain text file that anyone can read and verify.&lt;/p&gt;

&lt;p&gt;None of this is new.&lt;/p&gt;

&lt;p&gt;Nix and Guix have been rebuilding environments from declarations for years. A Dockerfile is a recipe. Configuration management tools have argued "declare the end state, do not snapshot it" for a long time.&lt;/p&gt;

&lt;p&gt;So the embarrassing question is fair.&lt;/p&gt;

&lt;p&gt;Isn't a Workshop just a Dockerfile I generate from a session?&lt;/p&gt;

&lt;p&gt;Honestly, kind of. A Workshop is a declarative environment spec, and the world has plenty of those. If I had invented a new recipe file format, that would be the least interesting thing about this.&lt;/p&gt;

&lt;p&gt;The interesting part is not the format. It is the boundary the recipe crosses to exist. A Workshop is captured by promoting a real, messy, live agent session across a line. On one side is whatever the agent actually did, imperative and unreviewed. On the other is clean, human-reviewed, durable state the system is willing to keep. That promotion goes through a human confirmation step, and the result lands in a canonical record owned by the privileged supervisor. The agent cannot write or replace that record directly. It can propose. It cannot author the durable truth.&lt;/p&gt;

&lt;p&gt;The agent might have run twenty commands to get a library installed correctly. It might have had to fix a dependency conflict along the way. The Workshop records the final, correct intent, not the twenty attempts.&lt;/p&gt;

&lt;p&gt;The promotion boundary is the contribution, not the file format.&lt;/p&gt;

&lt;p&gt;Reuse means re-derivation.&lt;/p&gt;

&lt;p&gt;When I clone a repository that uses a Workshop, I do not get a pre-built image. I get the recipe. The operating system reads the recipe. It pulls the base seed. It installs the packages. It applies the grants.&lt;/p&gt;

&lt;p&gt;It re-derives from the same recipe on my machine, on a CI server, or in the agent's next Bench. How identical the result is depends on how much I pinned. Name a package without a version and I get whatever the approved index serves that day, which is re-derivable but not bit-for-bit reproducible. That is a deliberate tradeoff, not Nix-level determinism.&lt;/p&gt;

&lt;p&gt;This is the point of declarative environments. You keep a declaration and re-derive from it, instead of preserving a blob. How close two derivations land depends on how completely the declaration pins its inputs.&lt;/p&gt;

&lt;p&gt;But there is a cost.&lt;/p&gt;

&lt;p&gt;Rebuilding cleanly from the recipe is correct. Done naively, it is also absurdly wasteful.&lt;/p&gt;

&lt;p&gt;If I throw the Bench away and rebuild the Workshop tomorrow, I download and compile the exact same toolchain from scratch all over again. I fetch the same source code. I run the same configure scripts. I link the same libraries. Correct, clean, and slow. A complex Workshop that took minutes to build takes those same minutes again.&lt;/p&gt;

&lt;p&gt;I want to be careful about what I am NOT claiming here. The recipe is the source of truth, and it must always be able to re-derive the environment from scratch. That property is non-negotiable. But nothing in it says I have to pay the full derivation cost on every launch. The declaration staying authoritative and the launch being fast are not actually in conflict.&lt;/p&gt;

&lt;p&gt;I want the cleanliness of rebuilding from a recipe. I do not want to pay the full cost of the rebuild every single time.&lt;/p&gt;

&lt;p&gt;How do I keep the cleanliness of rebuilding from a recipe without paying the full cost of the rebuild every single time?&lt;/p&gt;

</description>
      <category>linux</category>
      <category>security</category>
      <category>architecture</category>
      <category>ai</category>
    </item>
  </channel>
</rss>
