Ask for a witness, not an assertion
A search reports that two models explain the same observations but imply materially different responses. Why believe it? Instead of sending only a warning and a pair of risk numbers, send the two model fields. A recipient can calculate the relevant quantities again under its own trusted request and verify the entire claim.
Keep search outside the trust boundary
The proposer sends two model fields and a direction. The recipient does not trust supplied prices: it recomputes the quote and response enclosures, verifies parameter restrictions, checks every observation block, and tests whether the response intervals are materially separated. A request digest binds the packet to the intended input specification.
Acceptance proves that this pair supplies a valid ambiguity witness under the declared assumptions. Rejection says no such assertion was established by this packet. It does not imply the model class has narrow risk, and optimizer failure does not imply a witness does not exist.
The smaller statement is the useful one
Proving the largest possible risk over a model class is difficult. Demonstrating that at least two compatible models differ by a specified amount is an existential statement. It requires one valid pair, not a globally optimal search. In the synthetic four-expiry comparison, verified material separation remains in eight of 24 directions. The sixteen other directions are unresolved, not certified safe or narrow.
The search is outside the trust boundary
The verifier checks parameters, enclosed quote discrepancies, numerical widths, and guaranteed response separation. It does not trust prices supplied by the proposer. A digest binds the packet to the independently trusted request, preventing stale or mismatched use. The digest is not an exchange signature and does not authenticate market data.
The complete native cost
The recipient’s positive-packet warm median is 42.978 milliseconds, with a 44.956 millisecond p95 and 2.391 MiB peak native memory. All 210 retained warm-up, warm, and cold classifications pass their applicable reference checks. Positive cases are timed separately from cheaper rejections. These are workstation measurements for a bounded research parser—not production security certification.
Let a complex search propose a simple witness
This is an appealing division of labor for numerical intelligence: let an expensive or heuristic search propose something small that a separate implementation can check. The current native verifier demonstrates that interface and its complete request cost. It is neither a market-data authenticator nor a full-class risk optimizer.
Beyond this particular financial example
The architectural pattern is broader than pricing: an expensive learner or search proposes a compact object, and a cheaper trusted computation checks a precise property. The operator toolbox helps when it makes that checking calculation accurate and small. It cannot manufacture a useful property or a correct observation model. Here, the financial claim remains synthetic because no model was admitted in the later market-data study.
Evidence & further reading
The links below distinguish the project record from foundational literature. This revised story does not add a new application-validation experiment.
- Compact, verifiable operator-based options risk. Spline research archive (2026). Local archive snapshot.
- Single-thread deployment succeeds on the shared workstation. Spline research archive (2026). Local archive snapshot.
- Compact computation and model ambiguity in option risk. Spline research archive (2026). Local archive snapshot.