Skip to content

Latest commit

 

History

History

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 

README.md

Module 6: Domain-Specific Verification

"In God we trust. All others must bring data—verified data." — W. Edwards Deming (adapted)

⏱️ Duration: 75 minutes
📊 Level: Advanced
🎯 Goal: Apply QWED verification to real industry use cases.


🧠 What You'll Learn

After this module, you'll understand:

  • ✅ How to verify financial calculations (NPV, IRR, compound interest)
  • ✅ HIPAA/GDPR compliant verification with PII masking
  • ✅ Legal contract and clause verification
  • ✅ Secure code review automation
  • ✅ Statistical claim verification

📚 Table of Contents

Section Industry Time
6.1 Financial Services 15 min
6.2 Healthcare (HIPAA) 12 min
6.3 Legal & Contracts 10 min
6.4 Code & Security 13 min
6.5 Data & Analytics 10 min
6.6 The Compliance Loop 15 min

6.1: Financial Services

The Stakes

Financial errors aren't just embarrassing—they're expensive and illegal.

Type Consequence
Wrong interest calculation Customer lawsuits
Incorrect tax computation IRS penalties
Bad investment projections SEC violations
Currency conversion errors Trading losses

Scary Story: The $12,889 Bug

User: "Calculate compound interest on $100K at 5% for 10 years"

GPT-4 Response: "The compound interest would be $50,000, 
                giving you a total of $150,000."

Actual: $162,889.46 (compound) vs $150,000 (simple)
Error: $12,889.46 (8.6% off)

The LLM used simple interest instead of compound interest!

QWED Solution

from qwed_sdk import QWEDLocal

client = QWEDLocal(provider="openai")

# Verify compound interest calculation
result = client.verify_math("""
Principal: $100,000
Rate: 5% annual
Time: 10 years
Compounding: Annual
Final Amount = Principal * (1 + rate)^time
""")

print(f"Status: {result.status.value}")
print(f"Computed: ${result.developer_fields.get('value'):,.2f}")
# Output: Status: VERIFIED, Computed: $162,889.46

Financial Verification Patterns

Pattern 1: NPV/IRR Verification

# Verify Net Present Value calculation
cash_flows = [-100000, 30000, 35000, 40000, 45000]
discount_rate = 0.10

result = client.verify_math(f"""
NPV of cash flows {cash_flows} at {discount_rate*100}% discount rate
""")

# QWED uses SymPy to compute exact NPV
# NPV = Σ(CF_t / (1+r)^t)

Pattern 2: Loan Amortization

# Verify monthly payment calculation
result = client.verify_math("""
Loan: $500,000
Interest: 6.5% annual
Term: 30 years
Monthly Payment = ?
""")

# QWED computes: M = P * [r(1+r)^n] / [(1+r)^n - 1]
# Verified: $3,160.34/month

Pattern 3: Currency Conversion Chain

# Verify multi-hop conversion
result = client.verify_math("""
Convert $1000 USD → EUR → GBP → USD
Rates: USD/EUR = 0.92, EUR/GBP = 0.86, GBP/USD = 1.27
Expected final USD amount
""")

# Catches arbitrage calculation errors

Pattern 4: ISO 20022 Message Validation (ISOGuard)

# Illustrative domain guard example.
# In production, use the QWED package that owns your banking/ISO policy surface.
from qwed_sdk.guards import ISOGuard

guard = ISOGuard()
result = guard.verify_iso20022_xml(xml_payload)

# QWED validates against the official pacs.008 schema
# Blocks non-compliant SWIFT/ISO messages before transmission

🎯 Key Takeaway

"Never trust an LLM with money. Verify every calculation."


6.2: Healthcare (HIPAA)

The Stakes

Healthcare AI errors can:

  • Kill patients (wrong dosages)
  • Violate HIPAA ($1.5M+ fines)
  • Expose PHI (lawsuits, reputation)

The Challenge: PII in Medical Queries

Patient Query: "John Smith (DOB: 03/15/1985, SSN: 123-45-6789) 
               weighs 180 lbs. Calculate his BMI."

Problem: We need to verify the calculation WITHOUT exposing PHI!

QWED Solution: PII Masking

from qwed_sdk import QWEDLocal

# Enable automatic PII masking
client = QWEDLocal(
    provider="ollama",  # Keep data local!
    mask_pii=True       # Auto-mask before LLM sees query
)

query = """
Patient: John Smith (DOB: 03/15/1985)
Height: 5'10" (70 inches)
Weight: 180 lbs
Calculate BMI
"""

result = client.verify_math(query)

# What the LLM sees (masked):
# "Patient: [PERSON_1] (DOB: [DATE_1])
#  Height: 5'10" (70 inches)
#  Weight: 180 lbs
#  Calculate BMI"

# What QWED verifies (math only):
# BMI = (weight_lbs * 703) / height_inches²
# BMI = (180 * 703) / 70² = 25.8

print(f"BMI: {result.developer_fields.get('value')}")  # 25.8
print(f"Status: {result.status.value}")                 # VERIFIED
# Patient name NEVER reached the LLM!

Healthcare Verification Patterns

Pattern 1: Dosage Calculation

# Pediatric dosage based on weight
result = client.verify_math("""
Medication: Amoxicillin
Child weight: 25 kg
Recommended dose: 25-50 mg/kg/day in divided doses
Prescribed: 500mg twice daily

Is this dosage correct?
""")

# QWED verifies:
# Min: 25 * 25 = 625 mg/day
# Max: 25 * 50 = 1250 mg/day
# Prescribed: 1000 mg/day ✅ (within range)

Pattern 2: Drug Interaction Check

# Verify drug interaction claims
result = client.verify_fact(
    claim="Warfarin and Aspirin have no significant interaction",
    sources=["drug_interactions.json"]  # Your verified database
)

# QWED fact-checks against your sources
# Returns: verified=False, reason="Major interaction documented"

Pattern 3: Lab Value Interpretation

# Verify lab result interpretation
result = client.verify_math("""
Patient glucose: 126 mg/dL (fasting)
Normal range: 70-100 mg/dL
Prediabetes: 100-125 mg/dL
Diabetes: ≥126 mg/dL

Classification: ?
""")

# QWED verifies: 126 >= 126 → Diabetes range ✅

HIPAA Compliance Checklist

Requirement QWED Feature
Minimize data exposure PII masking
Local processing option QWEDLocal + Ollama
Audit trail Verification logs
Data encryption HTTPS + local storage

🎯 Key Takeaway

"Healthcare AI needs two things: accuracy AND privacy. QWED provides both."


6.3: Legal & Contracts

The Stakes

Legal AI errors can:

  • Invalid contracts
  • Missed deadlines → defaults
  • Wrong liability exposure
  • Compliance violations

Scary Story: AI Lawyer Disaster

In 2023, lawyers used ChatGPT for legal research. It cited fake cases that didn't exist. The lawyers were sanctioned by the court.

QWED Solution: Contract Verification

Pattern 1: Date/Deadline Verification

from qwed_sdk import QWEDLocal
from datetime import datetime

client = QWEDLocal(provider="openai")

contract_text = """
Agreement signed: January 15, 2024
Payment due: 30 days from signing
Late penalty applies after: February 14, 2024
"""

result = client.verify_logic(f"""
Given:
- Signed: 2024-01-15
- Due: 30 days later
- Penalty date: 2024-02-14

Verify: Is the penalty date correct?
(Account for 2024 being a leap year)
""")

# QWED calculates:
# Jan 15 + 30 days = Feb 14 ✅
# (Leap year: Jan has 31 days, so Jan 15 + 16 = Jan 31, then +14 = Feb 14)

Pattern 2: Logical Consistency

# Check for contradictory clauses
result = client.verify_logic("""
Clause 5.1: "Seller may terminate with 30 days notice"
Clause 5.2: "Neither party may terminate before 90 days"
Clause 7.3: "Seller may terminate immediately upon breach"

Are these clauses logically consistent?
""")

# QWED uses Z3 to find contradictions
# Returns: "Clauses 5.1 and 5.2 may conflict if termination 
#          is attempted between days 30-90"

Pattern 3: Liability Cap Verification

# Verify liability calculations
result = client.verify_math("""
Total contract value: $5,000,000
Liability cap: 200% of contract value
Maximum liability exposure: $10,000,000

Is this correct?
""")

# QWED: 5,000,000 * 2 = 10,000,000 ✅

🎯 Key Takeaway

"Contracts require precision. LLMs provide probability. QWED bridges the gap."


6.4: Code & Security

The Stakes

Code from LLMs can:

  • Contain vulnerabilities
  • Import malicious packages
  • Expose secrets
  • Enable injection attacks

Scary Story: Package Hallucination

Researchers found that 22% of LLM-suggested packages don't exist.

Attackers can:

  1. Note non-existent package names
  2. Register them on PyPI/npm
  3. Add malware
  4. Wait for developers to pip install

QWED Solution: Code Security Engine

from qwed_sdk import QWEDLocal

client = QWEDLocal(provider="openai")

suspicious_code = """
import pickle
import os

def load_config(data):
    return pickle.loads(data)  # Unsafe deserialization!

def run_command(user_input):
    os.system(f"echo {user_input}")  # Command injection!
"""

result = client.verify_code(suspicious_code, language="python")

print(result.issues)
# [
#   {"severity": "HIGH", "type": "unsafe_deserialization", 
#    "line": 5, "message": "pickle.loads on untrusted data"},
#   {"severity": "CRITICAL", "type": "command_injection",
#    "line": 8, "message": "os.system with user input"}
# ]

Code Verification Patterns

Pattern 1: SQL Injection Detection

# Check SQL query safety
sql_query = """
SELECT * FROM users 
WHERE username = '{user_input}' 
AND password = '{password}'
"""

result = client.verify_sql(sql_query)

# QWED detects:
# - String interpolation (injection risk)
# - No parameterized queries
# - Plain text password comparison

Pattern 2: Secret Detection

# Scan for exposed secrets
code = """
AWS_KEY = "AKIAIOSFODNN7EXAMPLE"
API_KEY = "sk-1234567890abcdef"
DATABASE_URL = "postgres://user:password123@host/db"
"""

result = client.verify_code(code, check_secrets=True)

# Detected:
# - AWS Access Key (line 1)
# - OpenAI API Key pattern (line 2)
# - Database credentials (line 3)

Pattern 3: Dependency Verification

# Verify imported packages exist
imports = ["requests", "aiohttp_security", "flask_login"]

for pkg in imports:
    result = client.verify_fact(
        f"Python package '{pkg}' exists on PyPI",
        sources=["pypi_packages.json"]
    )
    if not result.is_verified:
        print(f"⚠️ WARNING: {pkg} may not exist!")

# Output: ⚠️ WARNING: aiohttp_security may not exist!

🎯 Key Takeaway

"Never deploy LLM-generated code without security verification."


6.5: Data & Analytics

The Stakes

Analytics errors can:

  • Wrong business decisions
  • Misleading reports
  • False insights
  • Compliance issues (SOX, etc.)

QWED Solution: Statistical Verification

Pattern 1: Statistical Claim Verification

from qwed_sdk import QWEDLocal

client = QWEDLocal(provider="openai")

# Verify statistical claims
data = [23, 45, 67, 89, 12, 34, 56, 78, 90, 21]

result = client.verify_stats(f"""
Dataset: {data}
Claim: "The mean is 51.5 and standard deviation is 27.3"
""")

# QWED computes:
# Mean = sum(data)/len(data) = 515/10 = 51.5 ✅
# Std = sqrt(sum((x-mean)²)/n) = 27.28... ≈ 27.3 ✅

Pattern 2: SQL Query Verification

# Verify SQL before execution
query = """
SELECT department, AVG(salary) as avg_salary
FROM employees
WHERE hire_date > '2020-01-01'
GROUP BY department
HAVING COUNT(*) > 5
ORDER BY avg_salary DESC
LIMIT 10
"""

result = client.verify_sql(query)

# QWED checks:
# ✅ Valid SQL syntax
# ✅ Aggregation with GROUP BY (correct)
# ✅ HAVING uses aggregate function (correct)
# ✅ No injection vulnerabilities
# ✅ Reasonable complexity (not a table scan bomb)

Pattern 3: Report Claim Verification

# Verify claims in generated reports
report_claim = """
Q4 2024 Performance:
- Revenue: $12.5M (up 23% YoY)
- Q4 2023 Revenue was $10.2M
"""

result = client.verify_math("""
If Q4 2024 = $12.5M and YoY growth = 23%,
what was Q4 2023?

Calculation: Q4_2023 = Q4_2024 / 1.23
""")

# QWED: 12.5 / 1.23 = 10.16... ≈ $10.2M ✅

🎯 Key Takeaway

"Data drives decisions. Verified data drives good decisions."


6.6: The Compliance Loop (Enterprise)

The Stakes

Getting the right answer isn't enough in regulated industries. You need proof.

Requirement Why
Audit Trail Regulators need logs
Cryptographic Proof Tamper-evident records
Timestamped Receipts Legal evidence
Input Hashing Prove what was verified

The Pattern: From Correctness to Proof

Traditional: LLM → Verify → ✅/❌ → Done
Enterprise:  LLM → Verify → Receipt → Audit Log → Archive

QWED Solution: Verification Receipts

# Illustrative enterprise pattern. Exact package boundaries may vary by deployment.
from qwed_sdk.audit import VerificationReceipt
from qwed_sdk.guards import ComplianceGuard

# Step 1: Verify the transaction
guard = ComplianceGuard()
result = guard.verify_aml_flag(
    amount=15000,        # Over $10k threshold
    country_code="US",
    llm_flagged=True     # LLM correctly flagged it
)

# Step 2: Generate cryptographic receipt
receipt = VerificationReceipt.create(
    engine="COMPLIANCE",
    input_data={"amount": 15000, "country": "US"},
    result=result,
    metadata={"transaction_id": "TXN-12345"}
)

print(f"✅ Compliant: {result.compliant}")
print(f"📝 Receipt ID: {receipt.receipt_id}")
print(f"🔐 Input Hash: {receipt.input_hash}")
print(f"⏰ Timestamp: {receipt.timestamp}")

Output:

✅ Compliant: True
📝 Receipt ID: RCP-a1b2c3d4
🔐 Input Hash: sha256:8f14e...
⏰ Timestamp: 2026-01-19T01:30:00Z

Diagnostics ≠ Explainability (Principle 9): A VerificationReceipt is a diagnostic record — it captures what was checked and what was found. It is not an explanation of why the LLM suggested a particular action. Never let a downstream gate treat "good explainability" as a substitute for deterministic proof.

Enterprise Pattern: Cross-Guard

When a single check isn't enough, use Cross-Guard for multi-layer verification:

from qwed_sdk.guards import CrossGuard

guard = CrossGuard()

# Verify SWIFT message + Sanctions check in one call
result = guard.verify_swift_with_sanctions(
    swift_message="""
    :20:TXN-2024-001
    :32A:240119USD15000,00
    :50K:/1234567890
    JOHN DOE
    :59:/9876543210
    ACME CORP
    :71A:SHA
    """,
    sanctions_list=["ACME CORP", "BAD ACTOR INC"]  # OFAC list
)

print(f"SWIFT Valid: {result.swift_result.valid}")
print(f"Sanctions Clear: {result.sanctions_result.cleared}")
print(f"Overall: {'🚫 BLOCKED' if not result.cleared else '✅ APPROVED'}")

Output:

SWIFT Valid: True
Sanctions Clear: False  # ACME CORP is on sanctions list!
Overall: 🚫 BLOCKED

Audit Log Integration

Every verification generates an audit entry:

from qwed_sdk.audit import AuditLog

# View audit trail
log = AuditLog()

for entry in log.get_entries(transaction_id="TXN-12345"):
    print(f"{entry.timestamp} | {entry.action} | {entry.status}")

# Output:
# 2026-01-19T01:30:00Z | AML_CHECK | PASSED
# 2026-01-19T01:30:01Z | SANCTIONS_SCREEN | BLOCKED
# 2026-01-19T01:30:01Z | RECEIPT_GENERATED | ARCHIVED

🏦 Banking Compliance Checklist

Regulation QWED Feature
BSA/FinCEN CTR ($10k+) ComplianceGuard.verify_aml_flag()
OFAC Sanctions CrossGuard.verify_swift_with_sanctions()
SOX Audit Trail VerificationReceipt + AuditLog
ISO 20022 Messages MessageGuard.verify_iso20022_xml()

🎯 Key Takeaway

"In banking, correctness without provenance is incomplete. QWED couples deterministic checks with auditable receipts."


🧪 Exercise: Build a Domain Verifier

Choose an industry and build a verification workflow:

Option A: Finance

# Build a loan calculator verifier
def verify_loan_calculation(principal, rate, term, monthly_payment):
    # Your code here
    pass

Option B: Healthcare

# Build a dosage verifier with PII masking
def verify_dosage(patient_info, medication, dose):
    # Your code here
    pass

Option C: Legal

# Build a contract deadline verifier
def verify_deadlines(contract_text):
    # Your code here
    pass

📋 Self-Assessment Quiz

Q1: What's the difference between simple and compound interest?

Answer: Simple interest: calculated only on principal (P × r × t). Compound interest: calculated on principal + accumulated interest (P × (1+r)^t). The $12,889 bug happened because the LLM used simple instead of compound.

Q2: How does QWED handle HIPAA compliance?

Answer: Through PII masking (auto-masks patient data before LLM sees it), local processing (QWEDLocal + Ollama keeps data on-premise), and audit trails (verification logs for compliance).

Q3: What percentage of LLM-suggested packages don't exist?

Answer: 22%! This is a security risk because attackers can register these non-existent package names and add malware.

Q4: Name 3 things the Code Security Engine detects.

Answer: Any 3 of: SQL injection, command injection, unsafe deserialization (pickle), exposed secrets/API keys, XSS vulnerabilities, weak cryptography.

Q5: Which QWED engine would you use to verify a legal contract has no contradictory clauses?

Answer: The Logic Engine (Z3). It can formally prove whether clauses are logically consistent or find contradictions.


📝 Summary

Domain Key Verification QWED Engine
Finance Calculations, interest Math Engine
Healthcare Dosages, PII masking Math + Masking
Legal Logic, dates Logic + Math
Code Security, secrets Code Engine
Data Statistics, SQL Stats + SQL
Infrastructure IAM, Networks, Cost, Artifacts qwed-infra guards

➡️ Next Steps

Congratulations! You've completed the core QWED Learning Curriculum.

Continue to Infrastructure Verification: The qwed-infra package extends QWED's deterministic fail-closed philosophy to IaC — verifying IAM policies, network topologies, cost estimates, and release artifacts. See Module 14: Infrastructure Verification.

What's Next?


"If it can't be verified, it doesn't ship."