Source-linked AI summary
Observation Design for Certified Control Authority: Projection--Estimability Separation and Active-Face Equivalence
Guangxi Wan, Hualong Du, Yuqi Liu, Qingwei Dong, Qingxin Li, Hongfei Bai, Peng Zeng
TL;DR
The paper asks how observations should be designed so runtime assurance can certify more safely admissible actions, rather than merely distinguish states. It separates projection-based discrimination from range-based admission and develops an active-face equivalence characterization for multi-face permissiveness design. The resulting framework gives exact convex-mode thresholds and shows that designs satisfying testing margins can still leave certification costs above ten times testing costs across every probe library tested.
Problem
The paper addresses how to design observations for certified action sets, a target not directly optimized by classical distinguishability, model-discrimination, estimation, or goal-oriented criteria.
Method
It combines exact per-mode certification geometry with projection–estimability separation, active-face equivalence for multi-face design, and audits comparing testing and certification costs.
Results
Above ten times the testing cost occurs for at least one face in 60% to 100% of three-face contracts in every probe library tested.
Takeaways & Limitations
Certified-control observation design must account for constraint estimability and active bottleneck faces, not only discrimination quality.
Takeaways & Limitations
The audit finds that dependence on contract size and binary rank criteria is governed by probe-subspace/contract-normal incidence rather than universal laws.
Abstract
from arXiv · showhide
A sound runtime admission gate executes only actions it can certify, and certifies only what its observations support. This paper asks how observations should be designed to maximize the set of actions that can be safely admitted, and shows the question is not a re-vocabulary of classical design problems. First, a projection--estimability separation: decomposing a constraint normal as $c=c_{\mathrm{Range}}+c_{\ker}$ relative to an information matrix, two-point discrimination along $c$ becomes arbitrarily reliable as the budget grows whenever $c_{\mathrm{Range}}\neq 0$, while robust admission of an action with normal $c$ is impossible at every budget whenever $c_{\ker}\neq 0$; such mixed directions are generic at any deficient rank, and at full rank the decoupling is bounded by the Kantorovich ratio and diverges with the condition number. Discrimination-optimal designs, being corner solutions of a linear criterion, land in exactly this regime. Second, an active-face equivalence theorem: the permissiveness-optimal design is $L$-optimal for a target matrix generated endogenously by the action faces that become certification bottlenecks, weighted inversely by their remaining slack; single-face collapse recovers $c$-optimal and goal-oriented design exactly, and a Caratheodory argument yields a bottleneck certificate of at most $r(r+1)/2+1$ faces. Around these we assemble exact certifiability per convex contract mode, for which $κ\approx 3.29$ is derived rather than calibrated, the $\sqrt{r}$ price of contract-agnostic design, an information-to-slack transfer theorem with a curvature-budget corollary, and a two-part audit in which a design meeting every margin requirement still leaves an action face at a certification cost above ten times its testing cost, in every probe library tested.
1 Introduction
The paper treats observation design as a problem of maximizing safely admissible actions, not merely distinguishing states or estimating quantities. It develops two structural results separating discrimination from admission and characterizing multi-face permissiveness design.
- Runtime assurance requires observations that support a certified action set containing no nonviable action.
- Classical design criteria optimize distinguishability, model discrimination, downstream uncertainty, or parameter information rather than certified action sets with hard admission semantics.
- Wall one: admission is not discrimination: Theorem 5 shows discrimination can become perfect while robust admission remains impossible when a constraint normal has both measured and unmeasured components.
- Wall two: multi-face admission: For multiple active faces, permissiveness design reallocates sensing toward bottleneck constraint normals weighted inversely by remaining slack.
- The paper also derives exact convex-mode certifiability, a √r cost for contract-agnostic design, information-to-slack transfer, and an audit separating testing from certification costs.
- The decision metric D removes scaling non-identifiability by anchoring margins to documented decision thresholds, but this convention carries no mathematical novelty.
2 Certification Geometry
The paper models sensing through a linearized noisy observation system and designs an information matrix over probe measures. Certification geometry is defined per convex violation mode, with structural blind directions removed from the recoverable dimension.
- Sensing is modeled as ys = J(us)x + ϵs with independent Gaussian noise, whitened probe sensitivity S(u), and information Q(u) aggregated by a design measure.
- Contracts are represented through a decision metric D and industrial unsafe sets formed as unions of violation modes.
- Mode margins measure the minimum standardized separation between safe and unsafe sets under the design information matrix.
- Each mode assumes compact probe space, continuous information, closed convex whitened images, positive separation, and a recoverable quotient dimension after removing structurally blind directions.
- Convexity is imposed per mode rather than on the nonconvex union, reflecting the one-face structure used for certification.
- Robustification uses a range-aware support-function penalty because the Moore–Penrose quadratic form can remain finite off the information range.
3 Exact Certifiability: Modes and Their Composition
Exact certifiability is reduced to standardized mode margins, with necessity and sufficiency established for convex modes and composition handled by conjunction across violation modes. Multiplicity affects usefulness thresholds rather than unsafe-state reliability.
- A convex mode is (α, β)-certifiable exactly when its margin satisfies mT,k(ξ) ≥ z1−α + z1−β.
- The sufficiency proof uses a nearest-pair mid-normal test, while necessity restricts to the nearest pair and applies the Neyman–Pearson Gaussian shift test.
- At α = β = 0.05, the threshold constant is κ = 3.29, derived from the declared error levels rather than calibrated.
- For a nonconvex two-sided violation, minimum pair distance does not characterize composite testing because useful admission requires accepting an interval.
- Conjoining K mode tests preserves the full α reliability level for each unsafe mode, while the β usefulness threshold becomes z1−β/K.
- The correction assigns multiplicity to usefulness, not reliability; the distinction can be hidden when α = β but appears when the levels differ.
- The resulting industrial certificate is a margin vector with one entry per violation face rather than a scalar for the union.
- An adaptive policy cannot certify beyond a total-variation bound determined by the largest standardized trajectory separation, and zero separation makes the laws identical at every budget.
4 Wall One: Projection–Estimability Separation
Theorem 5 separates discrimination from robust admission by decomposing a constraint normal into information-range and null components. Mixed directions can be discriminated increasingly well while remaining uncertifiable, especially under rank-deficient or ill-conditioned designs.
- For c = cRange + cker, discrimination requires cRange ≠ 0, whereas robust certification requires cker = 0.
- In the mixed regime, total variation tends to 1 as T grows while the robust certification support function remains infinite at every budget.
- When 0 < rank M < n, mixed directions are generic because the pure-range and pure-null exceptions form two proper subspaces.
- The two tasks consume different features of the same design: discrimination uses projection, while admission uses estimability over the unresolved state set.
- Admission design is feasible only when active constraint normals lie in Range M, a spanning requirement absent from discrimination design.
- A corner design can maximize the linear discrimination criterion yet make certification impossible, while an interior Elfving point avoids that failure in the two-probe example.
- At full rank, the decoupling ratio is bounded by the Kantorovich condition-number ratio and grows as the design becomes ill-conditioned.
5 Wall Two: Permissiveness Design and Active-Face Equivalence
Permissiveness-optimal design is a concave maximin problem over action–face slacks, and its active bottlenecks generate an endogenous L-optimal target. Single-face cases reduce exactly to c-optimal and goal-oriented design, while optimality admits a sparse face certificate.
- Objective: The permissiveness objective maximizes the worst certified slack across indexed action–face pairs, using nominal slacks and constraint normals.The certified action set requires every face of an action to have nonnegative certified slack.
- Active-face equivalence: Single-face collapse recovers c-optimal design exactly and coincides with goal-oriented design for the corresponding linear functional.The paper claims no novelty at this single-face level.
- Objective: The resulting problem is a concave maximin program because each face slack is concave in the design and information is linear in the design.
- Active-face equivalence: The permissiveness-optimal design is L-optimal for an endogenous target matrix formed from active bottleneck faces.The target is generated by the optimizer itself through multipliers supported on the active set.
- Active-face equivalence: Faces with less remaining slack receive greater weight, reallocating sensing toward the constraint normals limiting certified control authority.
- Certificate: At most r(r+1)/2+1 bottleneck faces are needed to certify optimality, regardless of the action-library size.This follows from representing the target in the convex hull of rank-one face matrices.
6 The Price of Universality
A D-optimal universal design provides a contract-agnostic guarantee on both margins and certified-slack penalties, with a worst-case √r loss that is tight.
- Universal design: The D-optimal design loses at most √r in margin and certified-slack penalty relative to the corresponding contract-specific optimum.The guarantee holds on the r-dimensional recoverable quotient.
- Universal design: The √r factor is worst-case tight, as shown by coordinate probes with uniform design.
- Universal design: Certifying a contract spanning r competing directions requires T ≥ r(κ/inf σ)^2 under the universal design.The factor r is identified as the price of not knowing the contract.
7 From Information to Certified Slack
For constraints affine over the confidence region, information transfers exactly into certified slack and certified-action monotonicity; nonlinear curvature requires a separate budget.
- Exact transfer: For affine constraints over the confidence region, robust feasibility is characterized exactly by the ellipsoid support function and the information-based penalty.The result applies over the whole region, not merely through a first-order approximation at its center.
- Exact transfer: M1 ⪰ M2 implies nested confidence regions and a superset of certified actions under M1.
- Curvature limitation: For nonlinear constraints, c ∈ Range M does not ensure finite robust penalty because null-space curvature can make the constraint unbounded.The example has a vanishing first-order penalty but sup_C g = +∞.
- Curvature limitation: The curvature-budget corollary separates an O(T^-1/2) linear penalty from an O(T^-1) curvature term, recovering the affine formula asymptotically.The stated bounds require boundedness through reachability and provide sufficient feasibility or infeasibility conditions.
8 Saturation Classes of the Certifiable Dimension
The certifiable dimension exhibits finite-cap, zero-cap, and unsaturated response classes, while geometric spectral decay yields a falsifiable slope prediction for mode growth.
- Response classes: The response classes are finite cap, zero cap, and unsaturated growth until a structural rank bound.For steady-state diffusive networks, reciprocity bounds the accumulated information rank.
- Spectral prediction: For a geometrically decaying whitened spectrum, the fitted slope of certifiable dimension against ln D is 2/ln(1/ρ).
- Spectral prediction: At ρ = 0.55, the measured slope is 3.29 versus the predicted 3.35 in the flat scan.
- Spectral prediction: A mixed library at ρ = 0.4175 raises the fitted slope from the flat-scan value to 2.99, establishing a deviation direction.The passage presents this as a physical corollary and falsifiable prediction rather than a central novelty.
9 Two Audits: Margins and Certified Slack
The audits show that margin-oriented designs and certified-slack designs can diverge sharply: a design can satisfy every testing margin yet leave an action face impossible or extremely expensive to certify. Across libraries, exact-failure patterns depend on probe–normal alignment, while the active-face optimum reallocates sensing toward bottleneck constraints.
- Certified-slack audit: A margin-maximin design puts all mass on slope sensing, yielding rank 12 and a clearance normal with ∥cRange∥=0.926 and ∥cker∥=0.378.The mixed normal is testable but not robustly certifiable.
- Certified-slack audit: Testing the clearance face costs Ttest = 8.3 deployments, whereas certification is impossible at every budget; adding 0.23% full-scan mass restores rank 13 and gives Tcert = 127.The design change repairs feasibility while remaining invisible to the margin objective.
- Library dependence: On the original library, exact-failure rates for nf = 1, . . . , 7 are (0.00, 0.19, 0.34, 0.37, 0.29, 0.14, 0.00), peaking at nf = 4.Perturbations move the peak to nf = 1, 2, 3, or 4, or remove it entirely.
- Certified-slack audit: A design satisfying every margin requirement leaves at least one face with certification cost above ten times testing cost in 60% to 100% of three-face contracts across every tested library.This operational gap persists even when exact rank failure is repaired.
- Certified-slack audit: At 45°, testing costs 7.7 deployments while certification costs 20 428, and the decoupling ratio χ reaches 625.The largest separation occurs for mixed normals, not normals wholly in the weak subspace.
- Equivalence verification: The permissiveness optimum has τ⋆= 0.3206, two active faces, two support probes, and a sensitivity threshold of 1.3873 matched on both supports to 10^-8.Its bottleneck certificate uses two faces out of fifteen action–face pairs, versus the bound r(r + 1)/2 + 1 = 92.
- Audit conclusion: The audit concludes that exact failure and severe certification cost are controlled by incidence between measured subspaces and contract normals, not contract size alone.The face count nf is only a coarse proxy for this geometry.
10 Discussion
The discussion argues that certified-control observation design differs from classical design when admission depends on estimability and multiple competing faces. Audits show that positive testing margins can coexist with severe certification-cost gaps, while several predictions and scope limits remain explicit.
- Admission can become infeasible even when discrimination is perfect, because certification requires constraint normals to lie in the measured span.The paper contrasts what observations can distinguish with what they can robustly certify.
- Certification costs exceeded ten times testing costs for at least one face in 60% to 100% of three-face contracts across every tested probe library.The audit found this break despite every witness retaining a strictly positive margin.
- The predicted rank, certifiable-dimension, spectral-decay, and high-mode-amplification effects remain empirical questions rather than established outcomes.The discussion states that excitation rounds can stop adding information after a structural rank bound, but whether the bound is attained is empirical.
- The results are limited by local linear-Gaussian assumptions, finite-face and attained-optimum conditions, affine constraints for the exact transfer theorem, and a constructed semi-physical audit.The paper also does not address how the active set changes with budget.