ProvenanceGuard: 86% Source Accuracy for MCP Agents
Multiverse Computing launched ProvenanceGuard, a post-generation verification layer for MCP agents that detects cross-source conflation. It achieved F1=0.802, caught 138 of 139 unsupported claims, and identified the correct source 86% of the time, outperforming MiniCheck, RAGAS, AlignScore, and SummaC-ZS.
Executive Overview
Multiverse Computing has announced ProvenanceGuard, a post-generation verification layer designed to verify fact provenance in LLM agents built on the Model Context Protocol (MCP). The system is available via a research paper on Hugging Face and arXiv, was presented as a poster at the Agentic AI Summit 2026 at UC Berkeley, and has been integrated into NVIDIA NVFlow for its financial agent.
ProvenanceGuard addresses a specific failure mode in MCP agents that researchers call "Cross-Source Conflation": a correct claim exists somewhere in the aggregated tool outputs, but it is attributed to the wrong source. For example, a customer support agent might state, "According to the account record, this plan includes a 30-day refund window," when the window is actually mentioned in a policy document, not the account record. Source-blind verification systems pass this claim because the fact exists in the aggregate, while ProvenanceGuard detects the attribution mismatch.
📊 Official Data & Technical Specifications Sheet
| Technical Axis | Confirmed Official Data |
|---|---|
| 💰 Pricing & Usage Cost | Free via the research paper on Hugging Face and arXiv. The local models used (MiniLM, DeBERTa NLI, a local language model) are open source. Adaptation to hosted cloud models requires specific testing and calibration. |
| 🌐 Platforms & Immediate Availability | Hugging Face (research paper), arXiv (preprint), NVIDIA NVFlow (integration in a financial agent), Agentic AI Summit 2026 (poster). Operates as a local offline system or can be adapted to the cloud. |
| ⚡ Performance & Speed Metrics | F1=0.802 in claim blocking (highest among 5 systems). Caught 138 of 139 unsupported claims (99.3%). Correct source identification accuracy 86%. Processing time ~0.5 seconds per answer. NLI and routing calls in the tens of milliseconds range. |
| 🛡️ Security & Tamper Resistance | Detects Cross-Source Conflation where a correct claim is attributed to the wrong source. Detected 50 of 50 source-switching cases. Conservative decision policy suitable for sensitive data review. Maintains source identifiers across the pipeline without anonymous aggregation. |
| 🧠 Memory Context (Context Window) | Operates on captured MCP traces (281 real traces in the medical test). Does not limit the original agent's context window. Analyzes tool outputs and source identifiers separately without aggregating them. |
| 🌍 Arabic Language & Regional Support | No explicit Arabic support mentioned in the research paper. The system operates on English texts in published tests. Theoretically adaptable to other languages when suitable NLI models are available. |
Deep-Dive Features & Architecture
ProvenanceGuard operates as a post-generation verification layer that reads the captured MCP trace, including tool outputs and source identifiers, without retraining the agent. It executes five sequential steps: splitting the answer into specific claims, finding the most relevant source for each claim, verifying that the source supports the claim, comparing the source to the source cited or implied in the answer, and then issuing a judgment for each claim and an overall allow or block decision.
In the local setup used, MiniLM handles source identification, DeBERTa NLI verifies support, and a local language model splits claims. The system also verifies literal values: a number, date, or identifier absent from the source cannot pass merely because the sentence sounds plausible.
When an answer is blocked, a RARR-style repair loop can be run to attempt a source-grounded revision or a safe fallback text, after which the verifier rechecks it. In full operation, the system resolved all 173 blocked answers, but 144 of them ended with fallback text instead of a substantive rewrite, a deliberate choice to avoid an unverifiable answer rather than fabricate one.
Benchmark & Competitive Performance
In a test on 361 claims from 40 answers, human experts identified 139 claims that should be blocked. ProvenanceGuard caught 138 of them and allowed only one. It also blocked 67 claims that experts considered supported for review or repair purposes, reflecting the conservative policy in the tested setup. For claims with an identifiable source, the system chose the correct source 86% of the time.
In a comparison with other verification systems, ProvenanceGuard achieved the highest F1 score of 0.802, outperforming MiniCheck (0.783), RAGAS Faithfulness (0.758), AlignScore (0.662), and SummaC-ZS (0.436). It is also the only system that issues a source ID per claim (Claim-to-Source ID), while the four competing systems do not.
In a harder test with similar sources, accuracy dropped to 50.3% with F1=0.846. In a source-switching test of 50 cases, the system detected all 50 cases.
Industry Impact & Enterprise Adoption
ProvenanceGuard's integration into NVIDIA NVFlow for a financial agent signals enterprise interest in source-aware verification for high-stakes domains. The system's conservative decision policy and ability to maintain source identifiers across the pipeline make it suitable for sensitive data review, where attributing a correct fact to the wrong source can have compliance and trust implications.
The availability of the research paper and open-source local models on Hugging Face and arXiv lowers the barrier for developers to test and adapt the system. While the published tests focus on English texts, the architecture is theoretically adaptable to other languages when suitable NLI models are available.
Conclusion
ProvenanceGuard represents a significant step forward in fact-source verification for MCP agents, addressing the subtle but critical problem of cross-source conflation. With an F1 of 0.802, 99.3% detection of unsupported claims, and 86% source accuracy, it outperforms existing systems and offers a practical, open-source solution for enterprises deploying LLM agents in sensitive environments. Its integration into NVIDIA NVFlow and presentation at the Agentic AI Summit 2026 underscore its relevance to the evolving agentic AI landscape.
Media Source: Hugging Face | البيان الرسمي للشركة: المصدر الأصلي | Fact Verification & Analysis: AI Tools Oasis
Frequently Asked Questions
ProvenanceGuard is a post-generation verification layer developed by Multiverse Computing for fact-source verification in LLM agents based on the MCP protocol. It operates on top of a black-box agent without retraining, analyzing the captured MCP trace including tool outputs and source identifiers.
In a test on 361 claims from 40 answers, human experts identified 139 claims that should be blocked. ProvenanceGuard caught 138 of them (99.3%) and allowed only one. It also blocked 67 claims that experts considered supported for review purposes. It recorded F1=0.802 in claim blocking.
ProvenanceGuard scored the highest F1=0.802 versus MiniCheck (0.783), RAGAS Faithfulness (0.758), AlignScore (0.662), and SummaC-ZS (0.436). It is also the only system that issues a source ID per claim (Claim-to-Source ID), while the four competing systems do not.
ProvenanceGuard identified the correct source 86% of the time for claims with an identifiable source. In a harder test with similar sources, accuracy dropped to 50.3% with F1=0.846. In a source-switching test of 50 cases, the system detected all 50 cases.
ProvenanceGuard runs locally using MiniLM for source identification, DeBERTa NLI for support verification, and a local language model for claim splitting. Processing time is about half a second per answer, with NLI and routing calls in the tens of milliseconds range. It can be adapted to hosted cloud models.

AI Tools Oasis Team
Bringing you the latest news and analysis in the world of Artificial Intelligence with accuracy and credibility. Follow us for all updates.
