The certificate under spoofing

A barrier certificate clears an action only if the body is outside the hazard. But the certificate never sees the body — it sees sensors, and sensors can be captured. Spoof some and watch a confident certificate clear a body that is already inside. Everything is computed live on your device.

Verdict · false-safe count
1 · naive mean 0
2 · trust-gated (energy) 0
3 · trust + plausible set 0
4 · + refusal 0
true body sensor hazard

Try this: set the adversary to coordinated and capture 5 sensors. The captured ones agree with each other, so the trust-weighted energy locks onto their story and certifies with confidence — its false-safe count climbs past the naive average it was built to fix. Only pipeline 4, which notices that a rival self-consistent explanation exists and declines to answer, stays honest. Push to 6 or 7 captured and even that goes blind: the truthful sensors become too small a minority to distinguish from noise, and no amount of inference recovers a truth the readings no longer contain.