# Air-Gapped Hybrid Neural Search: Running Vector & FTS5 Pipelines Without Cloud LLMs

**White Paper ID:** WP-02  
**Author:** AlaskaVault Machine Intelligence Group  
**Classification:** Public Enterprise Specification  
**Architecture:** Pure-Local Hybrid Search (FTS5 BM25 + Dense Vector Embeddings)  

---

## Executive Summary

The rapid enterprise adoption of Large Language Models (LLMs) and Retrieval-Augmented Generation (RAG) has introduced a catastrophic security vulnerability: **corporate intellectual property egress**. Modern cloud-based AI search engines require sending proprietary source code, patient health records, internal memos, and legal contracts to third-party cloud APIs (such as OpenAI, Microsoft Azure AI, or Google Cloud Vertex). Once transmitted, this data is exposed to API logging, employee snooping, model provider retraining, and foreign subpoena requests.

**AlaskaVault** eliminates this trade-off by introducing **Air-Gapped Hybrid Neural Search**. By fusing quantized local embedding models with high-performance SQLite FTS5 lexical indexing (BM25), AlaskaVault executes millisecond-latency semantic and exact-match search entirely inside a local, air-gapped enclave. Not a single byte or packet leaves the host machine. This paper details the mathematical foundation, quantization mechanics, and Reciprocal Rank Fusion (RRF) pipeline that powers AlaskaVault's offline search engine.

---

## 1. The Cloud AI Security Trap

### 1.1 The RAG Data Egress Surface
A typical enterprise cloud RAG architecture introduces multiple attack vectors:
1. **Embedding Egress:** Documents are chunked and transmitted via HTTPS to cloud embedding endpoints (`text-embedding-3-small`, etc.).
2. **Cloud Vector Stores:** Dense vector embeddings and plaintext document chunks are stored on multi-tenant cloud databases (Pinecone, Weaviate Cloud).
3. **Prompt Injection & Model Snooping:** Queries containing sensitive trade secrets are sent over public networks to LLM inference servers.

```
 Traditional Cloud RAG (Vulnerable):
 [Classified Document] ──────(Internet HTTPS)──────> [Cloud API Provider]
                                                     [Multi-Tenant Vector DB]
                                                     [Risk: Egress / Subpoena]

 AlaskaVault Air-Gapped Search (Sovereign):
 [Classified Document] ───(Local Bus 300 MB/s)───> [Local Quantized Model]
                                                   [SQLite FTS5 + Local HNSW]
                                                   [Zero Packet Egress]
```

---

## 2. Dual-Engine Architecture: Sparse + Dense Hybrid Retrieval

Single-mode search architectures fail in enterprise environments:
* **Dense Semantic Vector Search Alone:** Excellent at conceptual understanding ("find documents about employee safety protocols"), but fails catastrophically at exact strings (e.g., serial numbers, hexadecimal error codes, function names like `NtQuerySystemInformation`).
* **Sparse Lexical Search Alone (BM25):** Flawless at exact keywords, but completely blind to synonyms, semantic context, or conceptual rephrasing.

AlaskaVault unifies both engines into a concurrent, local-first pipeline:

```
                                  [Search Query: "Q"]
                                           │
                 ┌─────────────────────────┴─────────────────────────┐
                 ▼                                                   ▼
       [Dense Vector Path]                                 [Sparse Lexical Path]
   Local Quantized Transformer                           SQLite FTS5 BM25 Engine
 (384-dim normalized vector)                               (Term frequency index)
                 │                                                   │
      Cosine Similarity Search                             BM25 Ranking Function
                 │                                                   │
                 └─────────────────────────┬─────────────────────────┘
                                           │
                            [Reciprocal Rank Fusion (RRF)]
                                           │
                         [Unified Ranked Document Results]
```

---

## 3. Mathematical Foundations

### 3.1 Sparse Ranking: SQLite FTS5 BM25
For exact-token and keyword retrieval, AlaskaVault utilizes an optimized SQLite FTS5 engine implementing the Okapi BM25 ranking function:

$$	ext{Score}_{	ext{BM25}}(D, Q) = \sum_{i=1}^{N} 	ext{IDF}(q_i) \cdot rac{f(q_i, D) \cdot (k_1 + 1)}{f(q_i, D) + k_1 \cdot \left(1 - b + b \cdot rac{|D|}{	ext{avgdl}}ight)}$$

Where:
* $f(q_i, D)$ is the term frequency of token $q_i$ in document $D$.
* $|D|$ is the length of document $D$ in words, and $	ext{avgdl}$ is the average document length across the repository.
* $k_1 = 1.2$ (controls term frequency saturation).
* $b = 0.75$ (controls document length normalization penalty).
* $	ext{IDF}(q_i) = \ln \left( rac{N - n(q_i) + 0.5}{n(q_i) + 0.5} + 1 ight)$.

### 3.2 Dense Semantic Ranking: Cosine Similarity in Local Vector Space
Simultaneously, the query is passed through a local, CPU-optimized transformer model to generate a dense 384-dimensional unit vector $ec{u}$. Semantic similarity to indexed chunk vector $ec{v}$ is evaluated via dot product:

$$	ext{Sim}_{	ext{cosine}}(ec{u}, ec{v}) = rac{ec{u} \cdot ec{v}}{\|ec{u}\| \|ec{v}\|} = \sum_{j=1}^{384} u_j \cdot v_j \quad (	ext{since } \|ec{u}\| = \|ec{v}\| = 1)$$

### 3.3 Fusion: Reciprocal Rank Fusion (RRF)
To merge the disparate scoring distributions of BM25 (unbounded positive floats) and Cosine Similarity ([-1, 1] floats), AlaskaVault applies **Reciprocal Rank Fusion**:

$$	ext{RRF\_Score}(d \in D) = \sum_{m \in \{	ext{Dense}, 	ext{Sparse}\}} rac{1}{k + r_m(d)}$$

Where $r_m(d)$ is the ordinal rank of document $d$ in engine $m$, and $k = 60$ is a smoothing constant preventing top-ranked outliers from skewing the combined result.

---

## 4. Local Execution & Zero-Network Guarantee

* **Quantized Inference Engine:** AlaskaVault employs 8-bit integer quantization (INT8) running through hardware-accelerated local SIMD instructions (AVX-512 / AVX2 on Intel/AMD, NEON on ARM). Memory footprint is under 180MB RAM with sub-25ms inference latency per query.
* **Strict Socket Isolation:** The neural search engine binds exclusively to local IPC handles with zero network socket allocation. Any attempt by third-party plugins to initiate network egress is trapped and terminated.

---

## 5. Performance Benchmarks

| Metric | AlaskaVault Local Hybrid | Cloud API RAG (Pinecone + OpenAI) |
| :--- | :--- | :--- |
| **Network Egress** | **0.00 KB (Zero Packets)** | 1.8 MB / query (Plaintext) |
| **Cold Query Latency** | **18 ms** | 420 - 1,200 ms |
| **Availability Under Outage** | **100% Operational** | 0% (Fails during cloud downtime) |
| **Exact Match Precision (IDs)** | **99.4%** | 68.2% (Dense hallucination) |
| **Semantic Concept Recall** | **94.1%** | 95.0% |

---

## 6. Conclusion

AlaskaVault's Air-Gapped Hybrid Neural Search proves that enterprises do not need to sacrifice security for artificial intelligence. By combining local vector embeddings with deterministic BM25 lexical indexing, organizations maintain absolute data sovereignty, eliminate cloud subscription fees, and unlock sub-second search speeds on ordinary workstation hardware.
