{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp03_full320_20260801","cell_id":"computability_boundary_mapping__statistics_experimental_design","trajectory_id":"R","attempt_index":0,"archetype_slug":"computability_boundary_mapping","domain_slug":"statistics_experimental_design","decision":"CANDIDATE","problem_id":"universal_adaptive_experiment_validity_certification","causal_lever_id":"enforceable_protocol_fragment_with_explicit_unknown","proposal":{"problem":"Statistical-governance teams may require an automated certifier to terminate and correctly determine, for every executable adaptive-experiment protocol and every covered null distribution, whether the protocol terminates and controls its declared false-positive rate. If protocols permit arbitrary computation, this unrestricted total-exact requirement may be impossible, while simulation timeouts and successful examples cannot establish its boundary.","actors_substrate":["trial participants","experiment designers","statistical reviewers","ethics and governance bodies","certification-tool maintainers","downstream decision makers"],"observable_state":"Arbitrary executable stopping, adaptation, and analysis code is admitted; certification is presented as binary; simulations, timeouts, or reviewer judgment substitute for class-wide termination and correctness evidence; scope and UNKNOWN states are undocumented.","consequence":"A tool can clear unsupported designs, reject or delay valid designs, conceal nontermination as failure, and create false assurance for participant-affecting experiments.","affected_objective":"Reliable predeployment certification of experimental validity without overstating the guarantee or silently excluding difficult protocols.","structural_mapping":[{"archetype_element":"unrestricted problem class","domain_realization":"All executable adaptive protocols under all covered null-generating processes.","claim_kind":"INFERENCE"},{"archetype_element":"universal exact terminating decider","domain_realization":"A certifier that always returns VALID or INVALID for termination and false-positive control.","claim_kind":"INFERENCE"},{"archetype_element":"computability obstruction","domain_realization":"A protocol can simulate an arbitrary program before executing a fixed valid design, potentially transferring the halting boundary.","claim_kind":"HYPOTHESIS"},{"archetype_element":"decidable region","domain_realization":"A mechanically enforceable protocol language with bounded state, loops, horizons, and declared distributional assumptions.","claim_kind":"HYPOTHESIS"},{"archetype_element":"honest weaker fallback","domain_realization":"Conservative checks, bounded exploration, certificate validation, or UNKNOWN outside proved contracts.","claim_kind":"INFERENCE"},{"archetype_element":"guarantee drift","domain_realization":"New protocol constructs, oracle services, or altered statistical assumptions invalidate an earlier certificate.","claim_kind":"INFERENCE"}],"component_map":[{"component":"Problem-Class Specification","status":"adapted","domain_realization":"Protocols and validity property to be certified."},{"component":"Instance Representation Contract","status":"adapted","domain_realization":"Protocol syntax, null family, alpha, horizon, and outputs."},{"component":"Computation Model Contract","status":"adapted","domain_realization":"Permitted computation, randomness, data access, and external services."},{"component":"Solvability Guarantee Profile","status":"direct","domain_realization":"Exact, conservative, bounded, or certificate-relative verdicts."},{"component":"Quantifier and Scope Map","status":"direct","domain_realization":"Every admitted protocol and every covered null distribution."},{"component":"Computability Status Lattice","status":"direct","domain_realization":"Decidable, recognizable, partial, relative, or unresolved."},{"component":"Constructive Procedure Witness","status":"adapted","domain_realization":"Verifier plus correctness and termination proof for a fragment."},{"component":"Reduction Preservation Contract","status":"adapted","domain_realization":"Program instances map computably to protocol instances preserving answers."},{"component":"Computability Impossibility Certificate","status":"adapted","domain_realization":"Reviewed reduction for the unrestricted protocol language."},{"component":"Assumption Register","status":"direct","domain_realization":"Language expressiveness and statistical-model premises."},{"component":"Decidable Subclass Map","status":"adapted","domain_realization":"Enforceable bounded protocol fragments and supported null families."},{"component":"One-Sided Recognition Contract","status":"adapted","domain_realization":"Confirm only verdicts carrying checkable certificates."},{"component":"Unknown and Nontermination Policy","status":"direct","domain_realization":"UNKNOWN, timeout, out-of-scope, and INVALID remain distinct."},{"component":"Fallback Solution Contract","status":"adapted","domain_realization":"Route to exact, conservative, bounded, or human review."},{"component":"Computability Guarantee Record","status":"direct","domain_realization":"Versioned statement of each shipped guarantee."},{"component":"Recheck Trigger","status":"direct","domain_realization":"Language, model, oracle, alpha, or verifier changes."},{"component":"Termination Condition","status":"adapted","domain_realization":"Finite checking budget returns UNKNOWN, never INVALID."},{"component":"Scope Boundary","status":"direct","domain_realization":"Mechanically checked fragment and assumption membership."},{"component":"Decision Record","status":"direct","domain_realization":"Auditable boundary choice and provenance."},{"component":"Uncertainty Residue","status":"direct","domain_realization":"Open proof obligations and uncovered protocol behavior."},{"component":"Independent Proof Review","status":"direct","domain_realization":"Separate review of formalization, reduction, and fragment proof."},{"component":"Complexity Follow-On Gate","status":"direct","domain_realization":"Feasibility analysis only after decidability is established."}],"mechanism_dispositions":[{"slug":"abstract_interpretation_or_model_checking","disposition":"selected_supporting","contribution_type":"CORE_CAUSAL","adaptation_or_rejection":"Conservatively checks finite abstractions of protocol state.","counterfactual_removal":"Fewer useful guarantees beyond the exact fragment."},{"slug":"bounded_domain_exhaustive_search","disposition":"selected_supporting","contribution_type":"TEST_DESIGN","adaptation_or_rejection":"Exhausts synthetic protocols within fixed state and horizon bounds.","counterfactual_removal":"The pilot loses complete bounded cases."},{"slug":"computability_boundary_decision_record","disposition":"selected_supporting","contribution_type":"OPERATIONAL","adaptation_or_rejection":"Versions scope, guarantees, assumptions, and triggers.","counterfactual_removal":"Boundary drift becomes difficult to audit."},{"slug":"computational_complexity_analysis","disposition":"selected_supporting","contribution_type":"OPERATIONAL","adaptation_or_rejection":"Tests feasibility after a fragment is proved decidable.","counterfactual_removal":"Decidable but unusable verification may be shipped."},{"slug":"constructive_algorithm_and_correctness_proof","disposition":"selected_load_bearing","contribution_type":"CORE_CAUSAL","adaptation_or_rejection":"Establishes total certification inside the restricted fragment.","counterfactual_removal":"The positive side of the boundary lacks a witness."},{"slug":"diagonalization_impossibility_proof","disposition":"considered_rejected","contribution_type":"NONE","adaptation_or_rejection":"A domain-specific halting reduction is clearer.","counterfactual_removal":"No material change."},{"slug":"enumeration_and_dovetailing","disposition":"considered_rejected","contribution_type":"NONE","adaptation_or_rejection":"Unbounded running is unacceptable for certification operations.","counterfactual_removal":"No change; bounded semi-decision remains."},{"slug":"fallback_mode_router","disposition":"selected_load_bearing","contribution_type":"OPERATIONAL","adaptation_or_rejection":"Routes by enforceable scope and labels each guarantee.","counterfactual_removal":"Weaker methods can be mistaken for universal certification."},{"slug":"halting_problem_reduction","disposition":"selected_load_bearing","contribution_type":"CORE_CAUSAL","adaptation_or_rejection":"Map a program to a protocol that runs it before a fixed valid design.","counterfactual_removal":"The impossibility claim becomes unsupported."},{"slug":"language_fragment_restriction","disposition":"selected_load_bearing","contribution_type":"CORE_CAUSAL","adaptation_or_rejection":"Enforce bounded constructs admitting total verification.","counterfactual_removal":"No enforceable exact region remains."},{"slug":"many_one_reduction_proof","disposition":"selected_supporting","contribution_type":"SAFETY_GUARDRAIL","adaptation_or_rejection":"Supplies totality and answer-preservation obligations for the halting map.","counterfactual_removal":"Reduction defects are easier to overlook."},{"slug":"promise_problem_restriction","disposition":"considered_rejected","contribution_type":"NONE","adaptation_or_rejection":"Unenforced statistical promises permit authoritative wrong answers.","counterfactual_removal":"No change; syntactic restriction is enforceable."},{"slug":"proof_by_counterexample","disposition":"selected_supporting","contribution_type":"TEST_DESIGN","adaptation_or_rejection":"Refutes overbroad certifier claims with in-scope protocols.","counterfactual_removal":"Pilot detects fewer scope overclaims."},{"slug":"proof_checking","disposition":"selected_load_bearing","contribution_type":"SAFETY_GUARDRAIL","adaptation_or_rejection":"Independently checks the reduction and fragment proofs.","counterfactual_removal":"Participant-affecting guarantees rest on author authority."},{"slug":"reduction_direction_checklist","disposition":"selected_supporting","contribution_type":"SAFETY_GUARDRAIL","adaptation_or_rejection":"Confirms source-to-target direction and assumptions.","counterfactual_removal":"A reversed reduction could survive review."},{"slug":"semi_decision_with_explicit_unknown","disposition":"selected_load_bearing","contribution_type":"CORE_CAUSAL","adaptation_or_rejection":"Returns certified verdicts when found and UNKNOWN at the budget.","counterfactual_removal":"Timeouts are pressured into false binary verdicts."},{"slug":"theorem_prover_guided_search","disposition":"considered_rejected","contribution_type":"NONE","adaptation_or_rejection":"Proof checking suffices for the bounded first test.","counterfactual_removal":"No material change."},{"slug":"turing_reduction_analysis","disposition":"considered_rejected","contribution_type":"NONE","adaptation_or_rejection":"Relative computability is unnecessary for the proposed boundary.","counterfactual_removal":"No material change."}],"causal_chain":["Specify protocol language, statistical property, quantifiers, and computation model.","Formally test whether unrestricted certification would decide halting.","Independently review the reduction and its statistical formalization.","Enforce a decidable protocol fragment and prove its verifier total and correct.","Route other inputs to conservative, bounded, certificate-based, or UNKNOWN modes.","Version guarantees and reclassify when language or assumptions change."],"baseline":"Ordinary practice uses preregistration checklists, simulation, code review, and time-limited analysis; unresolved cases receive inconsistent manual judgments or are treated as failures.","nearest_rival":"A simulation-heavy validator plus expert review, without a proved language boundary; it can estimate operating characteristics on sampled scenarios but cannot certify universal termination or validity.","authority_safety":{"affected_parties":["participants exposed to experimental interventions","investigators whose protocols are accepted or delayed","reviewers and regulators","people affected by downstream conclusions"],"decision_authority":"The statistical-methods governance body may define certification labels and accepted protocol syntax; ethics bodies and study sponsors retain authority over live studies.","authorized_first_step":"Offline test on 24 synthetic protocols: bounded valid cases, explicit invalid cases, nonterminating cases, and reduction-generated pairs; no participant data or deployment decisions.","excluded_actions":["approving or rejecting a live study from the prototype","altering consent, allocation, stopping, or analysis in an ongoing experiment","treating UNKNOWN or timeout as VALID or INVALID","claiming undecidability before independent proof review"],"halt_rollback":"Stop if the reduction fails, fragment membership cannot be enforced, or any out-of-contract definitive verdict occurs; withdraw the boundary claim and revert to labeled expert review."}},"negative_tests":{"strongest_counterevidence":"Practically used adaptive designs may fit finite, well-specified classes with existing analytic checks, making unrestricted executable protocols an avoidable specification choice rather than the operational problem.","analogy_break":"Statistical validity is distribution- and estimand-relative, unlike a purely semantic program property. The halting transfer applies only if the protocol language embeds arbitrary computation and the certified property includes termination under explicitly matched assumptions.","failure_condition":"The proposed mapping fails if no answer-preserving program-to-protocol construction exists, or if the real certifier is accountable only for an enforceable finite fragment.","problem_falsifier":"Show that all protocols actually admitted by the target organization belong to a mechanically enforced class with a proved total-exact validity verifier and no unrestricted public claim.","intervention_falsifier":"In the bounded pilot, reject the intervention if fragment membership is not mechanically decidable, any definitive verdict exceeds its proved contract, the reviewed reduction fails, or routing cannot preserve UNKNOWN distinctly.","risks":["A formal proof may certify the wrong statistical model.","A narrow fragment may exclude scientifically necessary adaptations.","UNKNOWN may become a de facto rejection and disadvantage complex studies.","Conservative abstractions may generate unusable false alarms.","A boundary record may institutionalize an erroneous result.","Reviewers may overgeneralize bounded findings beyond their scope."]},"null_rationale":null,"classification":{"candidate_kind":"DOMAIN_TRANSFER","prior_art_status":"UNSEARCHED","evidence_maturity":"HYPOTHESIS"},"revision_change_log":{"revision_kind":"ORIGINAL","prior_problem_id":null,"prior_causal_lever_id":null,"problem_changed":false,"causal_lever_changed":false,"conceptual_changes":[],"operational_changes":[],"repairs_addressed":[]},"confidence":0.82,"generator_notes":"Closed-book structural inference. The target-domain impossibility and decidable-fragment claims remain hypotheses pending formal construction and independent review."}