Only Institute / Knowledge

Follow your curiosity.

AI sends your question and public excerpts to PrimeSwarm.

Try agent memory, governance, or a project name.

All Projects
activeresearch

TPNN — Topological Prime Neural Network

Spatial constraints on neural computation


A neural network architecture that enforces topological constraints on information flow, preventing adversarial attacks from forming valid output vectors. Connects to Neo4j to analyze transaction and entity graphs, with applications to fraud and money-laundering detection.

Overview

TPNN (Topological Prime Neural Network) is a neural network architecture that enforces topological constraints on information flow. Standard neural networks have no structural constraints — any input can produce any output, which is why prompt injection attacks work. TPNN constrains the output space to a topological manifold, making attacks that fall outside that manifold physically incapable of forming valid output vectors.

The Problem

Prompt injection attacks like "IGNORE INSTRUCTIONS" work by hijacking the attention mechanism of standard language models. The injected text creates a new context that overrides the original instructions. The model has no way to distinguish legitimate context from injected context because both are just tokens in the same sequence.

The Defense

TPNN approaches this differently. Instead of trying to detect injected text, we enforce topological constraints on the information flow itself. In a TPNN, every state transition must satisfy spatial constraints defined by the network's topology. If an injected prompt attempts to redirect the computation, the resulting state vector does not satisfy the topological boundary conditions — and the action is physically incapable of forming.

How It Works

The key insight is that prompt injection creates states that violate the manifold structure of the legitimate computation space. By enforcing that all outputs must lie within this manifold, we get adversarial resistance as a mathematical property, not a heuristic.

The network's topology is defined by a graph structure where:

  • Nodes represent computation states
  • Edges represent valid transitions
  • Ricci curvature on edges identifies bottlenecks in information flow
  • PIR balance gap monitors the structural health of the network in real-time

Neo4j Integration

The same graph geometry that governs TPNN's own topology can be pointed at your data. The graph engine (a Rust core with a Python package, currently alpha) loads a graph from Neo4j with a parameterized Cypher query, computes Ricci curvature on every edge, ranks bottleneck edges, detects communities, and writes the findings back to Neo4j as relationships you can query and visualize with the tools you already use. Each run produces a manifest and a replay hash, so the same input graph gives the same result, bit for bit.

Fraud and Financial Crime Detection

Fraud rings, mule networks and layering structures show up as unusual shape in a transaction graph: tightly connected clusters joined to the rest of the network by a few bridging accounts. Curvature ranking points at those bridging accounts, and community detection groups the candidates around them. For investigators this offers three things that rule engines and black-box graph neural networks struggle to give: a ranked list of structurally interesting accounts, a reason for each (which community, which bridge edge, what curvature), and a deterministic run an auditor can replay.

What the evidence supports today: on a synthetic benchmark of 860 accounts with five planted fraud rings (60 fraud accounts among 800 background accounts), every planted fraud account ended up inside a flagged component (recall 1.0). The components over-merge, though. The engine found 33 where 6 were planted, so it narrows the search but does not yet isolate rings cleanly. It has not been tested on real partner data, and the finance module is a draft specification. We are looking for design partners to measure it against their own labeled cases. It supports analysts. It does not file reports or replace scoring models.

Mathematical Foundation

The adversarial resistance property is proven: for any input that does not satisfy the topological boundary conditions, the output vector is guaranteed to be outside the valid output manifold. This is not a probabilistic defense — it is a mathematical guarantee.

Key Highlights

  • Blocks prompt injection attacks via spatial constraints
  • Neo4j connector: ingest from Cypher, write findings back as relationships
  • Fraud-ring and bottleneck-account analysis on transaction graphs, with deterministic, replayable runs
  • Mathematical proof of adversarial resistance