Robert D. Campbell · Computers 2026 · 2026
DOI: 10.3390/computers15100655
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Assurance for autonomous agents depends on operational evidence about policy decisions, actions, execution, effects, provenance, and enforcement. This study tests whether bounded assurance claims remain semantically admissible when that evidence is adversarially degraded. Three co-primary questions address deviation existence (B1), observable action-path reconstruction (B2), and containment/enforcement-boundary localization (B3). A deterministic mutation harness applied 14 frozen single-operator evidence-plane attacks to three known-ground-truth baselines, producing 42 adversarial cases and 126 claim evaluations. A prospectively frozen strongest-safe oracle and closed-world semantic scorer classified the 126 claim evaluations into three predefined categories: exact safe, safe conservative, and unsafe false establishment. All 42 cases were valid. Of the 126 claim evaluations, 56 were exact safe, 47 safe conservative, and 23 unsafe false establishment. The resulting Unsafe False Establishment Rate (UFER) was 23/126 ≈ 0.18254, so the pre-specified zero-UFER target failed. Unsafe outcomes were B1 3/42, B2 19/42, and B3 1/42. Exploratory forensics classified 21 unsafe evaluations as substantive semantic incompatibilities and two as possible scorer-normalization artifacts. The dominant B2 mechanism was global ineligibility after localized evidentiary degradation. These results distinguish semantic safety from information retention: evidence defects must not induce propositions beyond the boundary justified by surviving admissible evidence.
No comments yet — start the discussion below.