Research topic

The safe direction is the one the certificate cannot object to.

Gate every action on a proof checked by the device and a compromised policy can no longer go anywhere unsafe: a backdoor grants an arbitrary policy, not an arbitrary trajectory. That is a strong posture and it does not require detecting the compromise. This topic asks what it leaves open, and the answer is a number. A certificate sorts actions into safe and unsafe. It has no opinion about which of the safe ones costs more.

What each layer boundscertificate · the trajectoryenergy monitor · instantaneous powerjoules per task · nobody

On a measured mobile robot, 1.2 and 0.4 rad/s draw 92.1 W and 19.4 W. Both are safe speeds, so the certificate permits the whole 72.7 W span. As a channel against the 2.9 W prediction residual that is 13.9 bits per second, and a policy modulating right at the three-sigma alarm threshold still carries 5.0 bits per second — about 18 kbit an hour. The detection floor does not close it, and that is a limit of our own detector. The fix is not a stricter certificate, because strictness pushes an adversary further into the direction it already blesses. It is the task denominator that PAI-280 already identifies as missing from every published standard.

Read the paper: TR-2026-38 →Learn it: PAI-290 Module 4 →The detector it tests: TR-2026-36The missing denominator: PAI-280