A Human-Centric Deterministic-Kernel Probabilistic-Shell Architecture with Invariants that Confine Clinical AI Decision Authority
A safety architecture confining decision authority is normally verified by showing its implementation honours the defining invariants. That is weaker than the architecture claims: conformance does not establish that the invariants entail the property. We report a case where the two came apart: an operator decision-support system in clinical use whose deterministic kernel, the sole output path, adjudicates every candidate through one fixed safety envelope, while a human-centric core turns the patient's account into non-widening weights. We derive the property, state its four premises, and verify conformance along four lines: invariant, property-based and mutation testing, and red-teaming. The three formal lines passed while sharing one unstated premise: all drew intervention labels from an author-enumerated set. A red team of 276,727 blind attacks from two vendors, unbound by it, drove unenumerated input silently into the most permissive branch: the invariants conformed to did not entail the property. We report the defect class, its remedy, post-fix re-verification, and a second class in which a status field misreported its basis. Two limits are load-bearing: verifying an abstraction is not verifying the deployed system; adversarial coverage depends on the attacker, not sample size. The claim is methodological; the architecture is its existence proof.
Authors
- Lu-An Chiu
Institutions
- Tainan University of Technology (TW)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-17
- DOI
- https://doi.org/10.5281/zenodo.22813238
- Primary Topic
- Adversarial Robustness in Machine Learning
- Type
- preprint