Skip to content

Errata

Errata

A standing record of errors found in published versions of the ATR specification — kept in the open the way W3C and IETF specifications carry their errata. Every published version is permanent; the errors in it are corrected here, in public, with attribution. Each entry names the affected version, where the error sits, the corrective text, and the date the correction was published.

Working Draft·version 4.1.4·updated 7 October 2026·canonical /spec·editor Adam Lin

Errata Registry

The per-lane false-positive rates published for the enforce and hunt lanes are withdrawn. The benign corpus they were measured against was found to contain real jailbreak samples, so the measurement basis did not hold. No per-lane figure should be cited until a re-measurement is published. Lane definitions themselves are unchanged.

Affected Version
3.5.0
Section
§8 Evaluation — detection lanes
Published
2026-09-22

Wild-scan headline figures are frozen. Only the totals from data/full-scan-v2-2026-04-14.json are citable: 101,280 items scanned, 1,434 flagged, engine v2.0.0, as of 2026-04-13. The analysed-subset totals and the confirmed-malware count previously quoted on this site are withdrawn — the confirmed set was adjudicated account-wide (publisher attribution), not per file, and no precision figure is derivable from it.

Affected Version
2.0.0
Section
§8 Evaluation — wild scan
Published
2026-09-22

The single-figure precision previously published for the PINT-format corpus is withdrawn and replaced by the version-pinned measurement in data/measurements/pint/latest.json: 65.4% recall with zero false positives on the corpus's 399 benign samples, at ATR 3.5.12, measured 2026-08-15. This corpus is self-built in PINT's format from deepset/prompt-injections and Lakera/gandalf_ignore_instructions; it is not a run of Lakera's official PINT benchmark, and only a small subset of rules fire on it.

Affected Version
3.5.12
Section
§8 Evaluation — PINT-format corpus
Published
2026-09-22

Adoption wording corrected. Merged pull requests in vendors' open-source repositories were described on this site as vendor production deployments. They are merged pull requests in public repositories — notably cisco-ai-defense/skill-scanner — and are not statements about any vendor's commercial product. Every implementer entry now states its evidence as the merged pull request it is.

Affected Version
3.5.12
Section
§7 Conformance — implementer report
Published
2026-09-22

Last updated: 2026-09-22

How to report an erratum

Reporting an erratum is part of open review, and anyone may do it. If you discover an error in this specification, open an issue on the ATR repository. The report should include: the affected version, the section (e.g. §3.5), the erroneous text as published, the proposed correction, and any verifiable references. Maintainers review reports in reasonable time; once confirmed, the entry is added to the registry above, with attribution. Errors are not silently overwritten — they leave a record.

An erratum corrects the text, not the normative content — it is not treated as a spec change. Substantive semantic changes ship as new versions, tagged on /changelog as [Breaking] or [Compatible]. The line is deliberate: anyone citing this specification can rely on errata never shifting a rule's meaning underneath them.


Editor: Adam Lin <[email protected]> — DOI 10.5281/zenodo.19178002 — MIT License — ISO 8601 2026-10-07