Doctoral exemplar · 30/30 axes D1–D6 · vs teaching nb04

Same CIC-IDS2018 web-attack day and cache SHA-256 as teaching nb04. What changed is the evaluation protocol: train/val/locked test, temporal + group-disjoint splits, selection on validation AP only, Dst Port removed, FPR-budget threshold, class weights, bootstrap CI, full family ledger. Measured doctoral axes 7→30 on that corpus.

Doctoral total30/30 PASS Selected modelLogisticRegression (val AP)
vs teaching selectionXGBoost (test ROC) Dst Portexcluded (was included)
Test AP (locked)1.000 Prec@ops thr0.061 (honest; not 0.5 thr)
Dataset SHA-256d0a7f5059d9823b6e9b392b759e306481a3502d190dea7a1b5502ae079ea069b

Inline tables in §0 and per-section vs teaching nb04 callouts document every protocol delta. Machine evidence: /praxis/answersheets/nb04-before-after-strong-evidence.json.