Numerical intelligence · Research & Algorithms

Don’t trust the model’s warning—verify it independently

Finding a model-ambiguity warning can be expensive. Checking a concrete warning can be much smaller—and need not trust the optimizer.

EXPLORE THE IDEA

Trust the check, not the search

A concrete witness crosses a narrow verification boundary.

UNTRUSTED PROPOSERSend fields, not claimed risk numbersmodel θ₁model θ₂Fields here are schematicINDEPENDENT RECIPIENTRecompute each claimed propertyRequest bindingParameter validityObservation compatibilityResponse separationIllustrated checks are not live security results
50%
Protocol illustration: validate a request-bound pair of model fields, recompute observation compatibility, and check response separation. Status transitions illustrate the protocol; they are not live parser logs or market certification.

Follow the information

From input to outcome

The recipient recomputes rather than trusting numbers supplied by the search. Acceptance establishes this pair as an ambiguity witness. Rejection does not certify a narrow model class or prove no witness exists.

Scroll the diagram horizontally to follow the route. Keyboard: focus the diagram, then use the arrow keys.

Proposer packet → Trusted request checks → Independent recomputation → Compatibility + separation → Accept or reject witness. The recipient recomputes rather than trusting numbers supplied by the search. Acceptance establishes this pair as an ambiguity witness. Rejection does not certify a narrow model class or prove no witness exists.
Information-flow map. The digest binds a request; it does not authenticate exchange data. Original vector schematic based on the method and evidence discussed in this article; signal shapes and icons are illustrative, not additional measurements. Open full-size diagram ↗

Read the main route from left to right; labelled side branches show additional inputs, checks or feedback. The sections below explain the operations and their experimental limits.

Ask for a witness, not an assertion

A search reports that two models explain the same observations but imply materially different responses. Why believe it? Instead of sending only a warning and a pair of risk numbers, send the two model fields. A recipient can calculate the relevant quantities again under its own trusted request and verify the entire claim.

Keep search outside the trust boundary

The proposer sends two model fields and a direction. The recipient does not trust supplied prices: it recomputes the quote and response enclosures, verifies parameter restrictions, checks every observation block, and tests whether the response intervals are materially separated. A request digest binds the packet to the intended input specification.

Acceptance proves that this pair supplies a valid ambiguity witness under the declared assumptions. Rejection says no such assertion was established by this packet. It does not imply the model class has narrow risk, and optimizer failure does not imply a witness does not exist.

Search freely; verify a small assertion
Search freely; verify a small assertion. Original scientific diagram; the stated component and information flow, not an additional experiment. Open full-size figure ↗

The smaller statement is the useful one

Proving the largest possible risk over a model class is difficult. Demonstrating that at least two compatible models differ by a specified amount is an existential statement. It requires one valid pair, not a globally optimal search. In the synthetic four-expiry comparison, verified material separation remains in eight of 24 directions. The sixteen other directions are unresolved, not certified safe or narrow.

θ1,θ2∈Fobservations,∣R(θ1)−R(θ2)∣‾>η\begin{gathered}\theta_1,\theta_2\in\mathcal F_{\mathrm{observations}},\\ \underline{|R(\theta_1)-R(\theta_2)|}>\eta\end{gathered}
A checked pair proves a lower bound on possible response disagreement. Failure to produce such a pair does not prove an upper bound.

The search is outside the trust boundary

The verifier checks parameters, enclosed quote discrepancies, numerical widths, and guaranteed response separation. It does not trust prices supplied by the proposer. A digest binds the packet to the independently trusted request, preventing stale or mismatched use. The digest is not an exchange signature and does not authenticate market data.

The complete native cost

The recipient’s positive-packet warm median is 42.978 milliseconds, with a 44.956 millisecond p95 and 2.391 MiB peak native memory. All 210 retained warm-up, warm, and cold classifications pass their applicable reference checks. Positive cases are timed separately from cheaper rejections. These are workstation measurements for a bounded research parser—not production security certification.

Verified material directions in the single- and four-expiry synthetic studies. Missing witnesses remain unresolved; these counts are not upper bounds on model ambiguity.
Verified material directions in the single- and four-expiry synthetic studies. Missing witnesses remain unresolved; these counts are not upper bounds on model ambiguity. Open full-size figure ↗

Let a complex search propose a simple witness

This is an appealing division of labor for numerical intelligence: let an expensive or heuristic search propose something small that a separate implementation can check. The current native verifier demonstrates that interface and its complete request cost. It is neither a market-data authenticator nor a full-class risk optimizer.

Beyond this particular financial example

The architectural pattern is broader than pricing: an expensive learner or search proposes a compact object, and a cheaper trusted computation checks a precise property. The operator toolbox helps when it makes that checking calculation accurate and small. It cannot manufacture a useful property or a correct observation model. Here, the financial claim remains synthetic because no model was admitted in the later market-data study.

Evidence & further reading

The links below distinguish the project record from foundational literature. This revised story does not add a new application-validation experiment.

  1. Compact, verifiable operator-based options risk. Spline research archive (2026). Local archive snapshot.
  2. Single-thread deployment succeeds on the shared workstation. Spline research archive (2026). Local archive snapshot.
  3. Compact computation and model ambiguity in option risk. Spline research archive (2026). Local archive snapshot.