Research record

Compact, verifiable operator-based options risk

Historical source. Some claims in older records were subsequently corrected. The associated article states the adopted interpretation. This record preserves the original source alongside its rendered reading view.

Rendered archival Markdown

This reading view preserves headings, tables, lists, code fragments and mathematical notation from the local research record.

Compact, verifiable operator-based options risk

Executive assessment

A small operator-based risk engine can now produce and independently check a specific, useful warning: two stationary local-volatility fields both fit the same noisy option surface, yet predict materially different finite spot responses. In a frozen synthetic comparison across twelve fresh fields, jointly fitting four maturities leaves verified warnings in eight of twenty-four tested directions. A matched single-expiry search finds eighteen. None of the single-expiry selected fields fits the complete surface, so the joint result requires genuinely shared-field witnesses rather than an assembly of unrelated slice calibrations. Joint search plus verification takes 1.371 seconds median on the tested workstation.[^1]

The complete native recipient checks such a warning in 37.69 milliseconds median, using 2.41 MiB peak process memory and a 119,624-byte executable. It does not trust the publisher's prices or optimizer: it recomputes both fields at all four maturities, checks every quote block and numerical allowance, and verifies the response separation. All 126 repeated classification and interval checks, 128 malformed-packet/recovery pairs and nineteen sanitizer requests pass. This establishes a compact CPU verification capability under a fixed mathematical contract, not profitable trading, hard real-time behavior or performance on a weak processor.[^2]

The main scientific contribution is the integration of exact operator cells, signed Green inner products, a whole-spectrum time-inversion bound and validated residual computation. These components separate numerical error from model ambiguity. They also expose limits: a broad positive-operator relaxation is structurally too loose to certify narrow risk, straightforward parameter-box coverage is impractical, and robust changing-operator evaluation misses its original timing target. No full-class narrow-risk certificate or external SOTA advantage has been established.

The most credible application is therefore an inspectable options-risk component that can return a verified ambiguity warning or an unresolved result, alongside a separately declared conditional model calculation. A certificate that all compatible models have sufficiently similar risk remains a missing third outcome. The evidence supports continued development of this application, but not automatic confidence in market-model adequacy or autonomous hedging.

Calculation and observation contract

The principal experiments use a one-dimensional normalized diffusion with fifteen piecewise-constant log-volatility parameters. Volatility lies between 0.08 and 0.60, adjacent log-volatility contrasts are at most 0.70, and a separately recorded numerical parameter allowance is 10−910^{-9}. Interfaces cluster near the reference spot to permit localized coefficient changes. The finite computational log domain is [−4,4][-4,4]; selected whole-line results additionally require a global volatility cap of 0.600000001 and a declared extension outside the domain.

The normalized asset XX is driftless, dX=σ(log⁡X)X dWdX=\sigma(\log X)X\,dW. Its logarithm has drift −σ2/2-\sigma^2/2: zero carry must not be confused with zero log drift. The implemented price convention multiplies the normalized call expectation by exp⁡(−0.01T)\exp(-0.01T). It is consistent with the parent drift-normalized coordinate, but does not implement arbitrary interest-rate, dividend or drift fields. An autonomous coefficient field in this normalized coordinate is not automatically an autonomous coefficient field in physical spot. The internal model-coordinate audit records this distinction and clarifies a misleading historical packet identifier without altering old hashes.

Each maturity supplies twenty-one original quote coordinates and two additional quotes at the portfolio legs. The portfolio is a signed two-call spread with log strikes -0.05 and 0.05. Risk is its finite value change under fixed -0.5% and +0.5% spot shifts, with the coefficient field and reference coordinate held fixed. Recentring the field during a bump would define a different quantity. Neither a finite-response bound nor a price certificate automatically certifies classical point delta or gamma.

The final joint experiment uses maturities 0.01, 0.05, 0.2 and 0.5, with target response at 0.05. Synthetic observation errors are independent Gaussian price perturbations with the declared strike-dependent standard deviation, whose minimum is 5×10−55\times10^{-5}. Two discrepancy ellipsoids are checked separately at every expiry. Their binary64 chi-square limits use probability 1−0.01/81-0.01/8, giving a nominal 1% family-wise exclusion level under the ideal Gaussian assumptions. The numerical verifier checks the declared limits exactly as serialized; it does not separately certify the statistical quantile calculation. The recorded numerical mean allowance is not silently treated as exact data. Both comparison arms use these same limits.

These are synthetic quote observations, not executable bid/ask intervals, physical-return forecasts or independent market sessions. The twelve generating fields comprise two constants, two alternating controls and eight random fields. Their maximum generating mean interval width is 9.508×10−129.508\times10^{-12}, and all twelve known fields are admitted. The materiality threshold is a declared normalized response separation of 2×10−42\times10^{-4}, not a universally justified economic threshold.

Operator representation and exact inner-product calculus

After conjugation and Laplace transformation, the spatial pencil is K+sMK+sM, where K=−D2+1/4K=-D^2+1/4 and M=2/σ2M=2/\sigma^2. A constant-coefficient cell of width hh has local pole p=1/4+sMp=\sqrt{1/4+sM}. Its Dirichlet-to-Neumann matrix has diagonal pcoth⁡(ph)p\coth(ph) and off-diagonal −pcsch⁡(ph)-p\operatorname{csch}(ph). Assembly produces a small complex-symmetric tridiagonal resolvent system. Stable small-cell and decaying-exponential formulas avoid avoidable cancellation.

This is the relevant transfer from exponential-spline theory: choose local functions that reproduce the homogeneous differential operator, then perform evaluation, differentiation and integration on their coefficients. The financial cells are coefficient-adapted and nonuniform; this is not a conventional cardinal B-spline neural network. Nor is the bounded heterogeneous operator circulant. Periodic inner-product calculus motivates the approach, but its periodic Fourier identities cannot simply be imported into this model.[^3]

Laplace-domain analytic local-volatility calculations themselves have close financial prior art. Itkin and Lipton extend the earlier Lipton-Sepp piecewise-constant construction to piecewise-linear local variance, solving transformed spatial equations analytically. Accordingly, neither analytic operator cells nor their use in local-volatility calibration should be claimed as an invention of this campaign. The tested addition is their integration with signed-functional numerical bounds and independently rechecked ambiguity warnings; direct comparison with those established financial implementations remains open.[^22]

Signed functionals are especially important. The spread source is μ=ey1/2δy1−ey2/2δy2\mu=e^{y_1/2}\delta_{y_1}-e^{y_2/2}\delta_{y_2} and a finite spot readout is ν=ex/2δx−δ0\nu=e^{x/2}\delta_x-\delta_0. Their energy norms are small Gram quadratic forms in the explicitly known Green kernel of KK. Taking the signed combination before the norm preserves cancellation. In the initial certificate calculation this reduces the transferred bound by roughly a factor of 172 relative to adding separate call and bump bounds; it is a bound-tightness gain, not a 172-fold execution-speed claim.[^4]

The same calculus supplies exact cell products and parameter derivatives. If N(q)N(q) is the cell boundary matrix, its derivative gives the basis mass Gram matrix. For different operators, the divided difference [N(q)−N(r)]/(q−r)[N(q)-N(r)]/(q-r) gives a cross mass product, with the derivative as the coincident limit. Such identities replace spatial quadrature with small coefficient calculations. They are mathematically exact identities, while their numerical evaluation and time inversion still require separate error accounting.

Continuum and floating-point numerical certificates

Exact spatial cells do not make finite time inversion exact. The campaign first bounds a scalar rational approximation error uniformly over the entire nonnegative spectrum. Fixed binary64 contour coefficients are treated as exact inputs to that certificate. Interval Taylor bounds cover finite spectral intervals and an analytic inverse-variable expansion covers the infinite tail; a sampled maximum is not promoted to a proof. Rational contour approximation and its connection to spectral calculus are established numerical-analysis tools.[^5]

For signed source and readout functionals, spectral Cauchy-Schwarz transfers the uniform scalar error δ\delta to δ∥μ∥K−1∥ν∥K−1\delta\|\mu\|_{K^{-1}}\|\nu\|_{K^{-1}}. The norms depend on the fixed reference operator, not on a sampled volatility field. The tightened scalar certificate used in the application is approximately 4.249×10−124.249\times10^{-12}. This controls continuous-time inversion on the bounded-domain continuum; it is not merely an error estimate for a discretized matrix.

Floating-point evaluation is enclosed separately. An approximate inverse CC proposes a residual correction, and an outward bound η≥∥I−CA∥∞<1\eta\geq\|I-CA\|_\infty<1 verifies it. The solution radius follows from the enclosed residual divided by 1−η1-\eta. Point solves and optimizers may be inaccurate; acceptance depends on the residual enclosure. This follows classical validated-numerics methodology rather than introducing a new general verification principle.[^6]

The unchanged native single-slab verifier passes all 320 fresh cases spanning sixty-four fields and five maturities. Its median full request is about 4.96 ms. Every result contains the independent sixty-digit interval reference; maximum price and finite-response widths are approximately 6.18×10−106.18\times10^{-10} and 6.44×10−116.44\times10^{-11}. A faster direct interval elimination variant contains its references but qualifies only half of the earlier endpoint cohort, so it is not substituted for the residual verifier.[^4]

These certificates have a trusted computing base. Native arithmetic assumes IEEE binary64, nearest rounding, gradual underflow and strict compiler settings; runtime checks reject detected unsupported arithmetic conditions. Elementary interval functions, residual assembly and serialization require correct implementations. The independent high-precision implementation uses mpmath interval arithmetic, whose documentation identifies implementation caveats. Neither implementation is a proof-assistant verification of the entire software stack.[^7]

Whole-line and changing-operator extensions

The bounded calculation is not automatically the unbounded financial model. A separate tail/heat supersolution bounds the missing boundary contribution under the global volatility cap. It combines a conservative Black-Scholes boundary allowance with an inward heat-hitting bound, then propagates signed leg errors with their correct signs. The cap must hold outside the computational domain as well as inside it; it is not inferred from observed quotes.[^8]

All 108 constant-coefficient domain controls contain their whole-line references. At domain half-width four, all twenty-seven corresponding controls meet the narrowness gate. The allowance also preserves all previously selected ambiguity warnings in the tested cohort. Smaller-domain failures remain recorded. This establishes a conditional domain-extension calculation, not protection against jumps, unbounded volatility or unknown market structure.

Changing coefficients require a different composition argument. In common energy coordinates, each slab has a positive self-adjoint generator Hi=K1/2Mi−1K1/2H_i=K^{1/2}M_i^{-1}K^{1/2} and contraction Ei=e−tiHiE_i=e^{-t_iH_i}. With a fixed source and zero initial time value, the transformed solution is [I−En⋯E1]b[I-E_n\cdots E_1]b. Individual rational errors therefore accumulate by at most ∏i(1+δi)−1\prod_i(1+\delta_i)-1, without a volatility-contrast factor at every slab boundary. Later slabs multiply on the left; the operators generally do not commute.

For two slabs the concrete approximation is Q1+Q2−Q2KQ1Q_1+Q_2-Q_2KQ_1. Exact cross-cell energy products evaluate its composition. A naive implementation loses numerical tightness near almost equal poles; five of forty fresh cases fail the width target even though their wide intervals contain the references. A separately derived confluent kernel removes pole-gap division using an entire exponential integral. It passes all thirty-two subsequent fresh cases, including equivalent operator steps with different parameters.[^9]

The stable implementation costs 28.26 ms median kernel time and therefore misses the predeclared 25-ms timing target. That failure is retained. These tests certify forward-strike prices for two specified slabs, not time-dependent spot Greeks, arbitrary-depth cheap composition or arbitrary continuously varying coefficients. The common-energy theorem controls error propagation; it does not prove linear representation cost in the number of slabs.

Matched conventional comparison

A matched native polynomial comparator uses consistent-mass linear finite elements, cubic flux reconstruction and an enclosed primal/dual defect correction. For trial functions U,VU,V with residuals rμ,rνr_\mu,r_\nu, the exact identity is ν(Rμ)=ν(U)+rμ(V)+rν(Rrμ)\nu(R\mu)=\nu(U)+r_\mu(V)+r_\nu(Rr_\mu). The last term is bounded in the reference energy norm. Both implementations therefore target the same twenty-three prices and two finite responses with explicit numerical certificates, rather than comparing certified computation with an unqualified approximation.[^10]

Fixed comparison on twelve exposed casesExact operator cellsPolynomial residual certificate
Qualified cases12/126/12 at largest tested mesh
Median complete request5.006 ms877.331 ms at largest mesh
Peak native process memoryAbout 2.18 MBAbout 9.11 MB
Jointly qualifying cost frontierReference45.7-189.8 times higher on six cases

The comparison supports a scoped representation/certification advantage, not superiority over all polynomial algorithms. The comparator uses a conservative absolute-residual estimate and a mesh focused at one source. Higher-order elements, better dual-focused meshes or sharper residual norms could reduce its cost. Its six short-maturity failures are not evidence that conventional methods cannot be certified efficiently, and only the six jointly qualifying cases support the paired frontier ratios.

A separate frozen test addresses the residual-norm caveat directly. An enclosed Green quadratic form retains signed cross-cell and nodal terms for the same polynomial trial. All 324 repeated application requests contain the reference. Median finite-response intervals become about sixteen times tighter, but median paired cost rises by 1.75 times and no additional case or smaller mesh qualifies. The price-accuracy bottleneck remains. This demonstrates a useful inner-product-calculus transfer to the comparator, without establishing an end-to-end improvement or ruling out higher-order/adaptive alternatives.[^21]

The broader project already contains a faster conditional quote-to-portfolio service and matched native finite-element controls. That earlier service also showed that numerical precision and conditional quote-noise propagation can coexist with substantial model bias. In particular, its smooth-model portfolio delta coverage was poor despite accurate derivative calculations. The present work addresses that interpretation gap rather than treating another fast point price as sufficient evidence of trustworthy risk.[^11]

Model ambiguity and the failed global-bound routes

A verified pair is a constructive lower witness: the compatible model class contains at least two materially separated responses. It does not identify the true field, attain the global extrema or provide a worst-case upper range. Conversely, an unsuccessful optimizer or absence of a discovered pair cannot certify narrow risk. This distinction is essential because calibration inverse problems and their regularization requirements are longstanding, not newly discovered by this campaign.[^12]

The first bounded parameter-box analysis is useful locally but impractical as a direct whole-class strategy. Preserving first-order signed cancellation through exact adjoint products tightens local variation bounds by roughly fourteen to twenty-two times. At radius 0.01, all eight tested local boxes become narrow enough for their target. The full admissible box remains noncontractive, and a fixed rational-pole co-design study does not resolve that obstacle. No isotropic box-count estimate is presented as a lower bound on every possible global algorithm.[^13]

A second route removes the coefficient field by relaxing the stationary time-value operator to 0⪯T⪯K−10\preceq T\preceq K^{-1}. Quote constraints and signed responses then become finite Gram-matrix optimization problems. A positive-spectrum support formula supplies valid outer bounds for any finite dual multiplier, regardless of optimizer convergence. This spectral optimization principle has direct prior art, including McCloud's operator-based option bounds; the present computation is not a quantum-computing algorithm.[^14]

All sixteen resulting application intervals verify, but their widths are about 0.0221-0.0223, far above the 2×10−42\times10^{-4} target. An exact Schur-complement completion analysis explains why. With a fixed quote column, the relaxed matrix class still permits attained response widths at least 0.02121 in every tested direction. Therefore improving the optimizer cannot make this particular relaxation narrow enough. The extremizing matrix completions are not asserted to be realizable local diffusions.[^15]

The general lesson is structural: positivity and quote interpolation alone discard too much locality and generator information. A useful future global certificate must retain more of the operator model, or explicitly narrow the admissible class through defensible prior assumptions. Neither another unconstrained search nor a smaller reported witness range repairs the missing upper guarantee.

Joint-expiry warning construction and independent verification

The four-expiry comparison uses identical fixed search budgets in both arms: two feasibility starts and eight signed-response optimization attempts, with bounded iterations and forward evaluations. The joint arm prices all four maturities at each visited field. Every selected endpoint is subsequently checked at every expiry with the unchanged native numerical verifier and whole-line allowance. Failed endpoints are not replaced after inspection.

Frozen twelve-field comparisonSingle expiryShared four-expiry field
Verified material directions18/248/24
Selected endpoints admitted to their own contract48/4847/47
Failed optimizer attempts, retained39/12052/120
Median complete search and verification0.392 s1.371 s

The eight surviving joint warnings occur in four random fields, in both spot directions. Their guaranteed normalized separations range from approximately 0.000238 to 0.000524. None of the constant or alternating controls produces a material joint warning in this bounded search. The other sixteen joint directions remain unresolved; their observed search ranges must not be advertised as full uncertainty intervals. All twelve known generating fields are admitted, so no excluded-truth case is silently removed from this comparison.[^1]

A compact packet contains two coefficient fields, a direction and a digest of the independently trusted request. It carries no asserted prices or precomputed admission decision. The initial recipient recomputes all eight field/maturity combinations, every quote discrepancy and the response separation. All ninety expected classifications and 128 mutations pass, while a separate 380-call high-precision audit contains all selected endpoint/maturity results. The maximum packet is 897 bytes, excluding the trusted request and installed verification code.[^16]

The initial Python recipient needs about 123 MB, despite its roughly two-megabyte native pricing child. A separately qualified native recipient closes that specific deployment gap. Its fixed contract and numerical configuration are embedded at build time; the wire request binds identity and ninety-two binary64 observations through system SHA-256. The complete native process performs parsing, binding, cap checks, tail allowances, pricing, quote accounting and response verification. Its 37.69-ms median and 2.41-MiB peak memory are whole-process measurements, not just an isolated arithmetic kernel.[^2]

The current native executable is macOS-specific because it uses CommonCrypto. A digest prevents an accidental or adversarial mismatch between a packet and the trusted request, but does not authenticate data or validate the model. The recipient is a research prototype with tested bounded parsing and recovery, not a production security assessment. Its fixed size also does not demonstrate favorable scaling to arbitrarily many strikes, state cells or stochastic-volatility dimensions.

Cross-maturity model-adequacy screening

The same stationary representation supplies a separate, cheaper decision before calibration. After removing the declared discount, the ATM diagonal response is f(t)=⟨b,(I−e−tH)b⟩f(t)=\langle b,(I-e^{-tH})b\rangle for a positive self-adjoint HH. The spectral theorem expresses it as a positive mixture of 1−e−tλ1-e^{-t\lambda}, so it is a Bernstein function. Equally spaced increments consequently form a Hausdorff moment sequence, giving finite-difference and Hankel positivity conditions. These are classical moment-theory consequences, not spline-exclusive identities.[^17]

Observation-aware rejection is one-sided. A condition rejects only when its outward upper bound is negative over the entire declared observation box. For a Hankel test, a point eigensolver merely proposes a vector; the recipient encloses the resulting quadratic form directly. Non-rejection is unresolved, not proof that a stationary diffusion fits the observations. A coherent time-varying model may violate these stationarity conditions, so rejection is not an arbitrage or trading signal.

On 3,072 regular-grid noisy requests, the full screen adds rejection certificates beyond monotonicity and concavity, with no rejections among 2,048 stationary controls. At ordinary noise it adds 192 rejections beyond concavity and 68 beyond all finite differences. Deliberately constructed diagnostic curves contribute to this gain. The native full screen, including the small eigenvector proposals, costs about 110 microseconds median.[^18]

A separate fresh study handles irregular expiries through signed divided differences at the actual serialized times. It does not interpolate onto a regular grid or reuse an unjustified Hankel matrix. All 4,096 numerical checks pass at about 79 microseconds per request, and none of the 3,072 stationary controls is rejected. However, all incremental power over concavity occurs on designed curves: the random time-varying examples are already rejected by concavity. This limits the application conclusion even though the small interval matrix-vector implementation works.[^18]

These tests concern only the normalized ATM diagonal and the specified autonomous model. General strike responses can have signed spectral measures and need a different argument. Exercise style, forwards, carry, discount factors, quote timing and ATM interpolation must be qualified before applying the test to market data. Related option shape and total-positivity literature is extensive, and the campaign does not claim a completed novelty audit of these screening conditions.[^19]

A separate observation-cost diagnostic tests that qualification gap on the thirty-two already exposed irregular-expiry curves. Synthetic Black cross-sections reproduce their enclosed ATM values at three strike spacings and two offsets. Three declared quote widths give 576 panels, not 576 independent markets. Exact-rational put-call parity and conservative convexity envelopes account for uncertain forwards, discounts and missing ATM strikes. All 1,728 frontend/curve results contain the known normalization and original ATM interval, and all subsequent native reference checks pass.[^20]

The practical result is limiting. At normalized quote half-width 5×10−55\times10^{-5}, parity-inferred normalization removes every tested higher-order rejection beyond concavity. A known-normalization control retains twenty of twenty-four designed-curve/geometry cases at that width. At 5×10−45\times10^{-4}, neither parity frontend rejects any of the time-varying or designed cases. These are synthetic sensitivity settings, not measured market spreads or an impossibility theorem for sharper observation handling. No rescue search follows; the earlier microsecond screen is not by itself a demonstrated market application.

Evidence quality, reproducibility and practical priorities

Protocols, source hashes, generated cohorts, all optimizer statuses, numerical failures and intermediate findings are retained. Several pre-application implementation or QA-accounting errors have explicit errata and preserved source commits. Successful studies are not silently rewritten to remove an earlier failure. No external market dataset, production system or trading account is involved, and no environment installation is needed for the numerical experiments.

The scheduled shared-host repeat study completed all five frozen windows through 04:50 UTC on September 17, 2026. All 630 classification/reference checks and forty stale-request/recovery pairs pass; all 160 positive outputs contain the complete quote and separation checks. Window medians range from 36.46 to 40.28 ms, with native peak memory unchanged at 2.44 MiB. The first launch-inclusive response takes 102.20 ms, and subsequent first-after-idle responses range from 60.80 to 90.71 ms. Every window meets the median and memory gates, but these repeated exposed cases establish neither independent financial evidence nor hard-real-time performance.[^23]

The final archive audit checks 470 source/binary hash records, including nine preserved historical source versions and one explicitly unavailable old failed-prerequisite executable. There are no unexplained source mismatches; all 92 linked artifacts, 72 visited-state archives, summary identities and twenty-eight unit tests pass. An isolated rebuild of the current recipient is byte-identical on this host and passes all forty-two replay cases. Reconstructibility of this qualified successor does not recover the missing historical executable or prove correctness of the full software stack.

The immediate practical result is a compact, independently checkable warning service under a clear model and observation contract. The operator-spline toolbox contributes through mode-reproducing local cells, exact signed and cross-operator products, and structured derivative/residual calculations. The underlying principles are established mathematics; integration, qualification and measured application cost are the demonstrated contribution.

The next high-value external test should qualify a small European-options cohort with coherent timestamps, contract definitions, forward/discount normalization and observation uncertainty, then compare against a suitable established pricing/calibration implementation under the same risk task. A genuinely modest target CPU is needed to test the low-hardware vision. These steps would address application relevance and deployment cost directly, rather than adding another favorable synthetic speed headline.

A separate mathematical priority is a useful upper certificate over the entire compatible operator class. The present local bounds, constructive warnings and broad relaxed bounds do not supply it. Progress there should retain locality or use explicitly justified regularity restrictions, with failure criteria fixed in advance. Until then, unresolved is an essential, honest output rather than a defect to conceal with more optimizer restarts.

Sources

[^1]: Project campaign, Study23, 2026. Shared-field four-expiry ambiguity findings. Frozen protocol, observations, searches and all endpoint records in the same archive. [^2]: Project campaign, Study25, 2026. Complete native recipient findings. Full numerical, transport, memory and sanitizer evidence; macOS workstation measurements. [^3]: Anais Badoual, Daniel Schmitter and Michael Unser. An Inner-Product Calculus for Periodic Functions and Curves. IEEE Signal Processing Letters 23(6), 878-882, 2016. DOI. Supplied badoual1601.pdf read in full; periodic assumptions remain distinct. [^4]: Project campaign, Studies01-06, 2026. Numerical certificate archive. DERIVATION.md, scalar/interval source, fresh validation and all failed alternatives retained. [^5]: Lloyd N. Trefethen, J. A. C. Weideman and Thomas Schmelzer. Talbot Quadratures and Rational Approximations. BIT 46, 653-670, 2006. Author paper, DOI 10.1007/s10543-006-0077-9. [^6]: Siegfried M. Rump. Verification Methods: Rigorous Results Using Floating-Point Arithmetic. Acta Numerica 19, 287-449, 2010. DOI. Primary abstract reviewed; general residual verification is prior methodology. [^7]: mpmath documentation. Contexts and interval arithmetic. Implementation caveats distinguish interval calculation from a formally verified software stack. [^8]: Project campaign, Study15, 2026. Whole-line domain allowance. DERIVATION_15.md and all constant/domain controls accompany the findings. [^9]: Project campaign, Studies10-16, 2026. Fresh confluence-safe validation. Common-energy derivation, near-coincidence failure and unchanged timing miss retained. [^10]: Project campaign, Study17, 2026. Matched polynomial certificate comparison. Exact defect identity, fixed meshes, full references and limited paired frontier. [^11]: Prior pricing application campaign, 2026. Conditional quote-to-portfolio risk report. Model bias and conditional-noise coverage are distinct from arithmetic accuracy. [^12]: Stephane Crepey. Calibration of the Local Volatility in a Generalized Black-Scholes Model Using Tikhonov Regularization. SIAM Journal on Mathematical Analysis 34(5), 1183-1206, 2003. DOI. Primary abstract checked for inverse-problem context. [^13]: Project campaign, Studies03,04,07, 2026. Affine local-box findings. Separate rational-pole failure in FINDINGS_07.md; no full-box certificate. [^14]: Paul McCloud. Quantum Bounds for Option Prices, 2018. Author preprint, Sections 2.1-2.3, Theorem 5 and proof, pp. 5-10. Positive-spectrum support principle, not quantum hardware. [^15]: Project campaign, Studies18-19, 2026. Exact completion diagnostic. DERIVATION_19.md proves the attained width inside the matrix relaxation, not the diffusion class. [^16]: Project campaign, Study24, 2026. Independent joint-surface packet verification. Complete 380-call reference audit and all 128 mutations retained. [^17]: Aleksey Kostenko. Hankel Operators and Applications, lecture notes, Section 2.1, pp. 19-21. Author notes. Moment and Hankel positivity background; only relevant sections reviewed. [^18]: Project campaign, Studies20-22, 2026. Fresh irregular-expiry findings. Regular and irregular protocols, curve families and all noise-tail exclusions remain separate. [^19]: Paul Glasserman and Dan Pirjol. Total Positivity and Relative Convexity of Option Prices, Foundations of Modern Finance, 2023. DOI. Abstract/introduction reviewed as related option-shape prior art, not an asserted equivalent test. [^20]: Project campaign, Study27, 2026. Conservative quote-normalization sensitivity. Exposed-curve diagnostic, fixed quote geometries and widths, all normalization/reference checks and negative outcomes retained. [^21]: Project campaign, Study28, 2026. Stronger conventional Green-energy residual comparison. Same twelve exposed cases, four fixed mesh budgets, independent moment/norm prerequisites and all 324 application results. [^22]: Andrey Itkin and Alexander Lipton. Filling the gaps smoothly, 2016. Author preprint. Abstract, introduction and Sections 8-9 excerpts reviewed for analytic local-volatility prior art and the stated Lipton-Sepp predecessor; no full-paper novelty or matched performance comparison is claimed here. [^23]: Project campaign, Study26 and final reproducibility audit, 2026. Five-window repeat findings. All raw windows, source bindings and AUDIT_FINAL.json are retained in the same committed snapshot.

Original: research/pricing_risk_certificate_20260916/REPORT.md · Raw source file

View raw MD source
# Compact, verifiable operator-based options risk

## Executive assessment

A small operator-based risk engine can now produce and independently check a specific, useful warning: two stationary local-volatility fields both fit the same noisy option surface, yet predict materially different finite spot responses. In a frozen synthetic comparison across twelve fresh fields, jointly fitting four maturities leaves verified warnings in eight of twenty-four tested directions. A matched single-expiry search finds eighteen. None of the single-expiry selected fields fits the complete surface, so the joint result requires genuinely shared-field witnesses rather than an assembly of unrelated slice calibrations. Joint search plus verification takes 1.371 seconds median on the tested workstation.[^1]

The complete native recipient checks such a warning in 37.69 milliseconds median, using 2.41 MiB peak process memory and a 119,624-byte executable. It does not trust the publisher's prices or optimizer: it recomputes both fields at all four maturities, checks every quote block and numerical allowance, and verifies the response separation. All 126 repeated classification and interval checks, 128 malformed-packet/recovery pairs and nineteen sanitizer requests pass. This establishes a compact CPU verification capability under a fixed mathematical contract, not profitable trading, hard real-time behavior or performance on a weak processor.[^2]

The main scientific contribution is the integration of exact operator cells, signed Green inner products, a whole-spectrum time-inversion bound and validated residual computation. These components separate numerical error from model ambiguity. They also expose limits: a broad positive-operator relaxation is structurally too loose to certify narrow risk, straightforward parameter-box coverage is impractical, and robust changing-operator evaluation misses its original timing target. No full-class narrow-risk certificate or external SOTA advantage has been established.

The most credible application is therefore an inspectable options-risk component that can return a verified ambiguity warning or an unresolved result, alongside a separately declared conditional model calculation. A certificate that all compatible models have sufficiently similar risk remains a missing third outcome. The evidence supports continued development of this application, but not automatic confidence in market-model adequacy or autonomous hedging.

## Calculation and observation contract

The principal experiments use a one-dimensional normalized diffusion with fifteen piecewise-constant log-volatility parameters. Volatility lies between 0.08 and 0.60, adjacent log-volatility contrasts are at most 0.70, and a separately recorded numerical parameter allowance is $10^{-9}$. Interfaces cluster near the reference spot to permit localized coefficient changes. The finite computational log domain is $[-4,4]$; selected whole-line results additionally require a global volatility cap of 0.600000001 and a declared extension outside the domain.

The normalized asset $X$ is driftless, $dX=\sigma(\log X)X\,dW$. Its logarithm has drift $-\sigma^2/2$: zero carry must not be confused with zero log drift. The implemented price convention multiplies the normalized call expectation by $\exp(-0.01T)$. It is consistent with the parent drift-normalized coordinate, but does not implement arbitrary interest-rate, dividend or drift fields. An autonomous coefficient field in this normalized coordinate is not automatically an autonomous coefficient field in physical spot. The internal model-coordinate audit records this distinction and clarifies a misleading historical packet identifier without altering old hashes.

Each maturity supplies twenty-one original quote coordinates and two additional quotes at the portfolio legs. The portfolio is a signed two-call spread with log strikes -0.05 and 0.05. Risk is its finite value change under fixed -0.5% and +0.5% spot shifts, with the coefficient field and reference coordinate held fixed. Recentring the field during a bump would define a different quantity. Neither a finite-response bound nor a price certificate automatically certifies classical point delta or gamma.

The final joint experiment uses maturities 0.01, 0.05, 0.2 and 0.5, with target response at 0.05. Synthetic observation errors are independent Gaussian price perturbations with the declared strike-dependent standard deviation, whose minimum is $5\times10^{-5}$. Two discrepancy ellipsoids are checked separately at every expiry. Their binary64 chi-square limits use probability $1-0.01/8$, giving a nominal 1% family-wise exclusion level under the ideal Gaussian assumptions. The numerical verifier checks the declared limits exactly as serialized; it does not separately certify the statistical quantile calculation. The recorded numerical mean allowance is not silently treated as exact data. Both comparison arms use these same limits.

These are synthetic quote observations, not executable bid/ask intervals, physical-return forecasts or independent market sessions. The twelve generating fields comprise two constants, two alternating controls and eight random fields. Their maximum generating mean interval width is $9.508\times10^{-12}$, and all twelve known fields are admitted. The materiality threshold is a declared normalized response separation of $2\times10^{-4}$, not a universally justified economic threshold.

## Operator representation and exact inner-product calculus

After conjugation and Laplace transformation, the spatial pencil is $K+sM$, where $K=-D^2+1/4$ and $M=2/\sigma^2$. A constant-coefficient cell of width $h$ has local pole $p=\sqrt{1/4+sM}$. Its Dirichlet-to-Neumann matrix has diagonal $p\coth(ph)$ and off-diagonal $-p\operatorname{csch}(ph)$. Assembly produces a small complex-symmetric tridiagonal resolvent system. Stable small-cell and decaying-exponential formulas avoid avoidable cancellation.

This is the relevant transfer from exponential-spline theory: choose local functions that reproduce the homogeneous differential operator, then perform evaluation, differentiation and integration on their coefficients. The financial cells are coefficient-adapted and nonuniform; this is not a conventional cardinal B-spline neural network. Nor is the bounded heterogeneous operator circulant. Periodic inner-product calculus motivates the approach, but its periodic Fourier identities cannot simply be imported into this model.[^3]

Laplace-domain analytic local-volatility calculations themselves have close financial prior art. Itkin and Lipton extend the earlier Lipton-Sepp piecewise-constant construction to piecewise-linear local variance, solving transformed spatial equations analytically. Accordingly, neither analytic operator cells nor their use in local-volatility calibration should be claimed as an invention of this campaign. The tested addition is their integration with signed-functional numerical bounds and independently rechecked ambiguity warnings; direct comparison with those established financial implementations remains open.[^22]

Signed functionals are especially important. The spread source is $\mu=e^{y_1/2}\delta_{y_1}-e^{y_2/2}\delta_{y_2}$ and a finite spot readout is $\nu=e^{x/2}\delta_x-\delta_0$. Their energy norms are small Gram quadratic forms in the explicitly known Green kernel of $K$. Taking the signed combination before the norm preserves cancellation. In the initial certificate calculation this reduces the transferred bound by roughly a factor of 172 relative to adding separate call and bump bounds; it is a bound-tightness gain, not a 172-fold execution-speed claim.[^4]

The same calculus supplies exact cell products and parameter derivatives. If $N(q)$ is the cell boundary matrix, its derivative gives the basis mass Gram matrix. For different operators, the divided difference $[N(q)-N(r)]/(q-r)$ gives a cross mass product, with the derivative as the coincident limit. Such identities replace spatial quadrature with small coefficient calculations. They are mathematically exact identities, while their numerical evaluation and time inversion still require separate error accounting.

## Continuum and floating-point numerical certificates

Exact spatial cells do not make finite time inversion exact. The campaign first bounds a scalar rational approximation error uniformly over the entire nonnegative spectrum. Fixed binary64 contour coefficients are treated as exact inputs to that certificate. Interval Taylor bounds cover finite spectral intervals and an analytic inverse-variable expansion covers the infinite tail; a sampled maximum is not promoted to a proof. Rational contour approximation and its connection to spectral calculus are established numerical-analysis tools.[^5]

For signed source and readout functionals, spectral Cauchy-Schwarz transfers the uniform scalar error $\delta$ to $\delta\|\mu\|_{K^{-1}}\|\nu\|_{K^{-1}}$. The norms depend on the fixed reference operator, not on a sampled volatility field. The tightened scalar certificate used in the application is approximately $4.249\times10^{-12}$. This controls continuous-time inversion on the bounded-domain continuum; it is not merely an error estimate for a discretized matrix.

Floating-point evaluation is enclosed separately. An approximate inverse $C$ proposes a residual correction, and an outward bound $\eta\geq\|I-CA\|_\infty<1$ verifies it. The solution radius follows from the enclosed residual divided by $1-\eta$. Point solves and optimizers may be inaccurate; acceptance depends on the residual enclosure. This follows classical validated-numerics methodology rather than introducing a new general verification principle.[^6]

The unchanged native single-slab verifier passes all 320 fresh cases spanning sixty-four fields and five maturities. Its median full request is about 4.96 ms. Every result contains the independent sixty-digit interval reference; maximum price and finite-response widths are approximately $6.18\times10^{-10}$ and $6.44\times10^{-11}$. A faster direct interval elimination variant contains its references but qualifies only half of the earlier endpoint cohort, so it is not substituted for the residual verifier.[^4]

These certificates have a trusted computing base. Native arithmetic assumes IEEE binary64, nearest rounding, gradual underflow and strict compiler settings; runtime checks reject detected unsupported arithmetic conditions. Elementary interval functions, residual assembly and serialization require correct implementations. The independent high-precision implementation uses mpmath interval arithmetic, whose documentation identifies implementation caveats. Neither implementation is a proof-assistant verification of the entire software stack.[^7]

## Whole-line and changing-operator extensions

The bounded calculation is not automatically the unbounded financial model. A separate tail/heat supersolution bounds the missing boundary contribution under the global volatility cap. It combines a conservative Black-Scholes boundary allowance with an inward heat-hitting bound, then propagates signed leg errors with their correct signs. The cap must hold outside the computational domain as well as inside it; it is not inferred from observed quotes.[^8]

All 108 constant-coefficient domain controls contain their whole-line references. At domain half-width four, all twenty-seven corresponding controls meet the narrowness gate. The allowance also preserves all previously selected ambiguity warnings in the tested cohort. Smaller-domain failures remain recorded. This establishes a conditional domain-extension calculation, not protection against jumps, unbounded volatility or unknown market structure.

Changing coefficients require a different composition argument. In common energy coordinates, each slab has a positive self-adjoint generator $H_i=K^{1/2}M_i^{-1}K^{1/2}$ and contraction $E_i=e^{-t_iH_i}$. With a fixed source and zero initial time value, the transformed solution is $[I-E_n\cdots E_1]b$. Individual rational errors therefore accumulate by at most $\prod_i(1+\delta_i)-1$, without a volatility-contrast factor at every slab boundary. Later slabs multiply on the left; the operators generally do not commute.

For two slabs the concrete approximation is $Q_1+Q_2-Q_2KQ_1$. Exact cross-cell energy products evaluate its composition. A naive implementation loses numerical tightness near almost equal poles; five of forty fresh cases fail the width target even though their wide intervals contain the references. A separately derived confluent kernel removes pole-gap division using an entire exponential integral. It passes all thirty-two subsequent fresh cases, including equivalent operator steps with different parameters.[^9]

The stable implementation costs 28.26 ms median kernel time and therefore misses the predeclared 25-ms timing target. That failure is retained. These tests certify forward-strike prices for two specified slabs, not time-dependent spot Greeks, arbitrary-depth cheap composition or arbitrary continuously varying coefficients. The common-energy theorem controls error propagation; it does not prove linear representation cost in the number of slabs.

## Matched conventional comparison

A matched native polynomial comparator uses consistent-mass linear finite elements, cubic flux reconstruction and an enclosed primal/dual defect correction. For trial functions $U,V$ with residuals $r_\mu,r_\nu$, the exact identity is $\nu(R\mu)=\nu(U)+r_\mu(V)+r_\nu(Rr_\mu)$. The last term is bounded in the reference energy norm. Both implementations therefore target the same twenty-three prices and two finite responses with explicit numerical certificates, rather than comparing certified computation with an unqualified approximation.[^10]

| Fixed comparison on twelve exposed cases | Exact operator cells | Polynomial residual certificate |
| --- | --- | --- |
| Qualified cases | 12/12 | 6/12 at largest tested mesh |
| Median complete request | 5.006 ms | 877.331 ms at largest mesh |
| Peak native process memory | About 2.18 MB | About 9.11 MB |
| Jointly qualifying cost frontier | Reference | 45.7-189.8 times higher on six cases |

The comparison supports a scoped representation/certification advantage, not superiority over all polynomial algorithms. The comparator uses a conservative absolute-residual estimate and a mesh focused at one source. Higher-order elements, better dual-focused meshes or sharper residual norms could reduce its cost. Its six short-maturity failures are not evidence that conventional methods cannot be certified efficiently, and only the six jointly qualifying cases support the paired frontier ratios.

A separate frozen test addresses the residual-norm caveat directly. An enclosed Green quadratic form retains signed cross-cell and nodal terms for the same polynomial trial. All 324 repeated application requests contain the reference. Median finite-response intervals become about sixteen times tighter, but median paired cost rises by 1.75 times and no additional case or smaller mesh qualifies. The price-accuracy bottleneck remains. This demonstrates a useful inner-product-calculus transfer to the comparator, without establishing an end-to-end improvement or ruling out higher-order/adaptive alternatives.[^21]

The broader project already contains a faster conditional quote-to-portfolio service and matched native finite-element controls. That earlier service also showed that numerical precision and conditional quote-noise propagation can coexist with substantial model bias. In particular, its smooth-model portfolio delta coverage was poor despite accurate derivative calculations. The present work addresses that interpretation gap rather than treating another fast point price as sufficient evidence of trustworthy risk.[^11]

## Model ambiguity and the failed global-bound routes

A verified pair is a constructive lower witness: the compatible model class contains at least two materially separated responses. It does not identify the true field, attain the global extrema or provide a worst-case upper range. Conversely, an unsuccessful optimizer or absence of a discovered pair cannot certify narrow risk. This distinction is essential because calibration inverse problems and their regularization requirements are longstanding, not newly discovered by this campaign.[^12]

The first bounded parameter-box analysis is useful locally but impractical as a direct whole-class strategy. Preserving first-order signed cancellation through exact adjoint products tightens local variation bounds by roughly fourteen to twenty-two times. At radius 0.01, all eight tested local boxes become narrow enough for their target. The full admissible box remains noncontractive, and a fixed rational-pole co-design study does not resolve that obstacle. No isotropic box-count estimate is presented as a lower bound on every possible global algorithm.[^13]

A second route removes the coefficient field by relaxing the stationary time-value operator to $0\preceq T\preceq K^{-1}$. Quote constraints and signed responses then become finite Gram-matrix optimization problems. A positive-spectrum support formula supplies valid outer bounds for any finite dual multiplier, regardless of optimizer convergence. This spectral optimization principle has direct prior art, including McCloud's operator-based option bounds; the present computation is not a quantum-computing algorithm.[^14]

All sixteen resulting application intervals verify, but their widths are about 0.0221-0.0223, far above the $2\times10^{-4}$ target. An exact Schur-complement completion analysis explains why. With a fixed quote column, the relaxed matrix class still permits attained response widths at least 0.02121 in every tested direction. Therefore improving the optimizer cannot make this particular relaxation narrow enough. The extremizing matrix completions are not asserted to be realizable local diffusions.[^15]

The general lesson is structural: positivity and quote interpolation alone discard too much locality and generator information. A useful future global certificate must retain more of the operator model, or explicitly narrow the admissible class through defensible prior assumptions. Neither another unconstrained search nor a smaller reported witness range repairs the missing upper guarantee.

## Joint-expiry warning construction and independent verification

The four-expiry comparison uses identical fixed search budgets in both arms: two feasibility starts and eight signed-response optimization attempts, with bounded iterations and forward evaluations. The joint arm prices all four maturities at each visited field. Every selected endpoint is subsequently checked at every expiry with the unchanged native numerical verifier and whole-line allowance. Failed endpoints are not replaced after inspection.

| Frozen twelve-field comparison | Single expiry | Shared four-expiry field |
| --- | ---: | ---: |
| Verified material directions | 18/24 | 8/24 |
| Selected endpoints admitted to their own contract | 48/48 | 47/47 |
| Failed optimizer attempts, retained | 39/120 | 52/120 |
| Median complete search and verification | 0.392 s | 1.371 s |

The eight surviving joint warnings occur in four random fields, in both spot directions. Their guaranteed normalized separations range from approximately 0.000238 to 0.000524. None of the constant or alternating controls produces a material joint warning in this bounded search. The other sixteen joint directions remain unresolved; their observed search ranges must not be advertised as full uncertainty intervals. All twelve known generating fields are admitted, so no excluded-truth case is silently removed from this comparison.[^1]

A compact packet contains two coefficient fields, a direction and a digest of the independently trusted request. It carries no asserted prices or precomputed admission decision. The initial recipient recomputes all eight field/maturity combinations, every quote discrepancy and the response separation. All ninety expected classifications and 128 mutations pass, while a separate 380-call high-precision audit contains all selected endpoint/maturity results. The maximum packet is 897 bytes, excluding the trusted request and installed verification code.[^16]

The initial Python recipient needs about 123 MB, despite its roughly two-megabyte native pricing child. A separately qualified native recipient closes that specific deployment gap. Its fixed contract and numerical configuration are embedded at build time; the wire request binds identity and ninety-two binary64 observations through system SHA-256. The complete native process performs parsing, binding, cap checks, tail allowances, pricing, quote accounting and response verification. Its 37.69-ms median and 2.41-MiB peak memory are whole-process measurements, not just an isolated arithmetic kernel.[^2]

The current native executable is macOS-specific because it uses CommonCrypto. A digest prevents an accidental or adversarial mismatch between a packet and the trusted request, but does not authenticate data or validate the model. The recipient is a research prototype with tested bounded parsing and recovery, not a production security assessment. Its fixed size also does not demonstrate favorable scaling to arbitrarily many strikes, state cells or stochastic-volatility dimensions.

## Cross-maturity model-adequacy screening

The same stationary representation supplies a separate, cheaper decision before calibration. After removing the declared discount, the ATM diagonal response is $f(t)=\langle b,(I-e^{-tH})b\rangle$ for a positive self-adjoint $H$. The spectral theorem expresses it as a positive mixture of $1-e^{-t\lambda}$, so it is a Bernstein function. Equally spaced increments consequently form a Hausdorff moment sequence, giving finite-difference and Hankel positivity conditions. These are classical moment-theory consequences, not spline-exclusive identities.[^17]

Observation-aware rejection is one-sided. A condition rejects only when its outward upper bound is negative over the entire declared observation box. For a Hankel test, a point eigensolver merely proposes a vector; the recipient encloses the resulting quadratic form directly. Non-rejection is unresolved, not proof that a stationary diffusion fits the observations. A coherent time-varying model may violate these stationarity conditions, so rejection is not an arbitrage or trading signal.

On 3,072 regular-grid noisy requests, the full screen adds rejection certificates beyond monotonicity and concavity, with no rejections among 2,048 stationary controls. At ordinary noise it adds 192 rejections beyond concavity and 68 beyond all finite differences. Deliberately constructed diagnostic curves contribute to this gain. The native full screen, including the small eigenvector proposals, costs about 110 microseconds median.[^18]

A separate fresh study handles irregular expiries through signed divided differences at the actual serialized times. It does not interpolate onto a regular grid or reuse an unjustified Hankel matrix. All 4,096 numerical checks pass at about 79 microseconds per request, and none of the 3,072 stationary controls is rejected. However, all incremental power over concavity occurs on designed curves: the random time-varying examples are already rejected by concavity. This limits the application conclusion even though the small interval matrix-vector implementation works.[^18]

These tests concern only the normalized ATM diagonal and the specified autonomous model. General strike responses can have signed spectral measures and need a different argument. Exercise style, forwards, carry, discount factors, quote timing and ATM interpolation must be qualified before applying the test to market data. Related option shape and total-positivity literature is extensive, and the campaign does not claim a completed novelty audit of these screening conditions.[^19]

A separate observation-cost diagnostic tests that qualification gap on the thirty-two already exposed irregular-expiry curves. Synthetic Black cross-sections reproduce their enclosed ATM values at three strike spacings and two offsets. Three declared quote widths give 576 panels, not 576 independent markets. Exact-rational put-call parity and conservative convexity envelopes account for uncertain forwards, discounts and missing ATM strikes. All 1,728 frontend/curve results contain the known normalization and original ATM interval, and all subsequent native reference checks pass.[^20]

The practical result is limiting. At normalized quote half-width $5\times10^{-5}$, parity-inferred normalization removes every tested higher-order rejection beyond concavity. A known-normalization control retains twenty of twenty-four designed-curve/geometry cases at that width. At $5\times10^{-4}$, neither parity frontend rejects any of the time-varying or designed cases. These are synthetic sensitivity settings, not measured market spreads or an impossibility theorem for sharper observation handling. No rescue search follows; the earlier microsecond screen is not by itself a demonstrated market application.

## Evidence quality, reproducibility and practical priorities

Protocols, source hashes, generated cohorts, all optimizer statuses, numerical failures and intermediate findings are retained. Several pre-application implementation or QA-accounting errors have explicit errata and preserved source commits. Successful studies are not silently rewritten to remove an earlier failure. No external market dataset, production system or trading account is involved, and no environment installation is needed for the numerical experiments.

The scheduled shared-host repeat study completed all five frozen windows through 04:50 UTC on September 17, 2026. All 630 classification/reference checks and forty stale-request/recovery pairs pass; all 160 positive outputs contain the complete quote and separation checks. Window medians range from 36.46 to 40.28 ms, with native peak memory unchanged at 2.44 MiB. The first launch-inclusive response takes 102.20 ms, and subsequent first-after-idle responses range from 60.80 to 90.71 ms. Every window meets the median and memory gates, but these repeated exposed cases establish neither independent financial evidence nor hard-real-time performance.[^23]

The final archive audit checks 470 source/binary hash records, including nine preserved historical source versions and one explicitly unavailable old failed-prerequisite executable. There are no unexplained source mismatches; all 92 linked artifacts, 72 visited-state archives, summary identities and twenty-eight unit tests pass. An isolated rebuild of the current recipient is byte-identical on this host and passes all forty-two replay cases. Reconstructibility of this qualified successor does not recover the missing historical executable or prove correctness of the full software stack.

The immediate practical result is a compact, independently checkable warning service under a clear model and observation contract. The operator-spline toolbox contributes through mode-reproducing local cells, exact signed and cross-operator products, and structured derivative/residual calculations. The underlying principles are established mathematics; integration, qualification and measured application cost are the demonstrated contribution.

The next high-value external test should qualify a small European-options cohort with coherent timestamps, contract definitions, forward/discount normalization and observation uncertainty, then compare against a suitable established pricing/calibration implementation under the same risk task. A genuinely modest target CPU is needed to test the low-hardware vision. These steps would address application relevance and deployment cost directly, rather than adding another favorable synthetic speed headline.

A separate mathematical priority is a useful upper certificate over the entire compatible operator class. The present local bounds, constructive warnings and broad relaxed bounds do not supply it. Progress there should retain locality or use explicitly justified regularity restrictions, with failure criteria fixed in advance. Until then, unresolved is an essential, honest output rather than a defect to conceal with more optimizer restarts.

## Sources

[^1]: Project campaign, Study23, 2026. [Shared-field four-expiry ambiguity findings](https://github.com/danielschmitter/operator_spline_neural_representation/blob/449534024/research/pricing_risk_certificate_20260916/FINDINGS_23.md). Frozen protocol, observations, searches and all endpoint records in the same archive.
[^2]: Project campaign, Study25, 2026. [Complete native recipient findings](https://github.com/danielschmitter/operator_spline_neural_representation/blob/449534024/research/pricing_risk_certificate_20260916/FINDINGS_25.md). Full numerical, transport, memory and sanitizer evidence; macOS workstation measurements.
[^3]: Anais Badoual, Daniel Schmitter and Michael Unser. *An Inner-Product Calculus for Periodic Functions and Curves*. IEEE Signal Processing Letters 23(6), 878-882, 2016. [DOI](https://doi.org/10.1109/LSP.2016.2555139). Supplied badoual1601.pdf read in full; periodic assumptions remain distinct.
[^4]: Project campaign, Studies01-06, 2026. [Numerical certificate archive](https://github.com/danielschmitter/operator_spline_neural_representation/tree/449534024/research/pricing_risk_certificate_20260916). DERIVATION.md, scalar/interval source, fresh validation and all failed alternatives retained.
[^5]: Lloyd N. Trefethen, J. A. C. Weideman and Thomas Schmelzer. *Talbot Quadratures and Rational Approximations*. BIT 46, 653-670, 2006. [Author paper](https://people.maths.ox.ac.uk/trefethen/publication/PDF/2006_118.pdf), DOI 10.1007/s10543-006-0077-9.
[^6]: Siegfried M. Rump. *Verification Methods: Rigorous Results Using Floating-Point Arithmetic*. Acta Numerica 19, 287-449, 2010. [DOI](https://doi.org/10.1017/S096249291000005X). Primary abstract reviewed; general residual verification is prior methodology.
[^7]: mpmath documentation. [Contexts and interval arithmetic](https://mpmath.org/doc/current/contexts.html). Implementation caveats distinguish interval calculation from a formally verified software stack.
[^8]: Project campaign, Study15, 2026. [Whole-line domain allowance](https://github.com/danielschmitter/operator_spline_neural_representation/blob/449534024/research/pricing_risk_certificate_20260916/FINDINGS_15.md). DERIVATION_15.md and all constant/domain controls accompany the findings.
[^9]: Project campaign, Studies10-16, 2026. [Fresh confluence-safe validation](https://github.com/danielschmitter/operator_spline_neural_representation/blob/449534024/research/pricing_risk_certificate_20260916/FINDINGS_16.md). Common-energy derivation, near-coincidence failure and unchanged timing miss retained.
[^10]: Project campaign, Study17, 2026. [Matched polynomial certificate comparison](https://github.com/danielschmitter/operator_spline_neural_representation/blob/449534024/research/pricing_risk_certificate_20260916/FINDINGS_17.md). Exact defect identity, fixed meshes, full references and limited paired frontier.
[^11]: Prior pricing application campaign, 2026. [Conditional quote-to-portfolio risk report](https://github.com/danielschmitter/operator_spline_neural_representation/blob/449534024/research/pricing_application_20260916/REPORT.md). Model bias and conditional-noise coverage are distinct from arithmetic accuracy.
[^12]: Stephane Crepey. *Calibration of the Local Volatility in a Generalized Black-Scholes Model Using Tikhonov Regularization*. SIAM Journal on Mathematical Analysis 34(5), 1183-1206, 2003. [DOI](https://doi.org/10.1137/S0036141001400202). Primary abstract checked for inverse-problem context.
[^13]: Project campaign, Studies03,04,07, 2026. [Affine local-box findings](https://github.com/danielschmitter/operator_spline_neural_representation/blob/449534024/research/pricing_risk_certificate_20260916/FINDINGS_04.md). Separate rational-pole failure in FINDINGS_07.md; no full-box certificate.
[^14]: Paul McCloud. *Quantum Bounds for Option Prices*, 2018. [Author preprint](https://arxiv.org/pdf/1712.01385), Sections 2.1-2.3, Theorem 5 and proof, pp. 5-10. Positive-spectrum support principle, not quantum hardware.
[^15]: Project campaign, Studies18-19, 2026. [Exact completion diagnostic](https://github.com/danielschmitter/operator_spline_neural_representation/blob/449534024/research/pricing_risk_certificate_20260916/FINDINGS_19.md). DERIVATION_19.md proves the attained width inside the matrix relaxation, not the diffusion class.
[^16]: Project campaign, Study24, 2026. [Independent joint-surface packet verification](https://github.com/danielschmitter/operator_spline_neural_representation/blob/449534024/research/pricing_risk_certificate_20260916/FINDINGS_24.md). Complete 380-call reference audit and all 128 mutations retained.
[^17]: Aleksey Kostenko. *Hankel Operators and Applications*, lecture notes, Section 2.1, pp. 19-21. [Author notes](https://users.fmf.uni-lj.si/kostenko/teach/HankelNotes.pdf). Moment and Hankel positivity background; only relevant sections reviewed.
[^18]: Project campaign, Studies20-22, 2026. [Fresh irregular-expiry findings](https://github.com/danielschmitter/operator_spline_neural_representation/blob/449534024/research/pricing_risk_certificate_20260916/FINDINGS_22.md). Regular and irregular protocols, curve families and all noise-tail exclusions remain separate.
[^19]: Paul Glasserman and Dan Pirjol. *Total Positivity and Relative Convexity of Option Prices*, Foundations of Modern Finance, 2023. [DOI](https://doi.org/10.3934/fmf.2023001). Abstract/introduction reviewed as related option-shape prior art, not an asserted equivalent test.
[^20]: Project campaign, Study27, 2026. [Conservative quote-normalization sensitivity](https://github.com/danielschmitter/operator_spline_neural_representation/blob/4490b2b25/research/pricing_risk_certificate_20260916/FINDINGS_27.md). Exposed-curve diagnostic, fixed quote geometries and widths, all normalization/reference checks and negative outcomes retained.
[^21]: Project campaign, Study28, 2026. [Stronger conventional Green-energy residual comparison](https://github.com/danielschmitter/operator_spline_neural_representation/blob/ab21185e9/research/pricing_risk_certificate_20260916/FINDINGS_28.md). Same twelve exposed cases, four fixed mesh budgets, independent moment/norm prerequisites and all 324 application results.
[^22]: Andrey Itkin and Alexander Lipton. *Filling the gaps smoothly*, 2016. [Author preprint](https://arxiv.org/abs/1608.05145). Abstract, introduction and Sections 8-9 excerpts reviewed for analytic local-volatility prior art and the stated Lipton-Sepp predecessor; no full-paper novelty or matched performance comparison is claimed here.
[^23]: Project campaign, Study26 and final reproducibility audit, 2026. [Five-window repeat findings](https://github.com/danielschmitter/operator_spline_neural_representation/blob/5f5c521f4/research/pricing_risk_certificate_20260916/FINDINGS_26.md). All raw windows, source bindings and AUDIT_FINAL.json are retained in the same committed snapshot.