AI summaryⓘ
The authors study how a model accepted by a sampling gate can be perfectly accurate within what the gate can observe but can be very wrong beyond that area. They analyze this using a shape called an annular freeze mode, which surrounds an unreachable inner region, showing how errors in unseen parts can persist and affect decisions. By experimenting with different model families and a tuning parameter, they identify when these errors are harmless, detectable but costly, or immediately falsified. They find that the risk depends on the topology related to what the planner can access, that fixing errors is limited by model parameters and sensor capabilities, and that mitigation strategies must match the error’s shape to be effective. Their work reveals that in higher dimensions, error areas become nearly unavoidable but the potential harm remains separately controllable.
sampling gateannular freeze modetopologyreachable setmodel errorBetti numberpersistent homologymitigationmodel parameterstopological artifact
Abstract
A code world model accepted by a sampling gate can be exactly right on everything the gate can see and arbitrarily wrong beyond it. We characterize what a certified model can know, and what its errors can cost, when the omission is an annular freeze mode enclosing an unreachable interior. The gate quotient makes the question precise: acceptance-with-certainty determines the model exactly on the reachable query set; beyond reach is gauge. On a minimal ring instrument we prove the extreme case (a wrong-topology filled-disc artifact unfalsifiable by any sampling gate and bitwise harmless at play) and measure, with LLM synthesis across three model families, how one knob (a channel of width gamma) walks the same artifact through three regimes: unfalsifiable-and-harmless, falsifiable-and-costly, and instantly falsified. Three principles organize the empirics. First, danger is topology relative to reach: a channel the planner can use collapses the blind model's exploitation (play cost 1.09 to ~0 over a knee at gamma ~ 0.1), while a hidden channel with the same first Betti number keeps it at full strength (1.12). Second, repair is parameter-bound and sensor-bound: no family recovers the region from outside evidence; from inside, models pose the right topology but cannot pin its parameters, and the posed topology tracks the guiding persistent-homology summary's wrong beta_1 (a sensor with a measured geometric resolution limit), not the truth. Third, mitigation must match the error's dimension and direction: point fences fail against the one-dimensional boundary, a dimension-matched persisted fence collapses exploitation to a two-lesson transient (0.999 to 0.058), and the dual freedom certificate collapses the invented-mode failure symmetrically (1.769 to 0.029). In n dimensions the shell makes misidentification near-certain while the danger stays fully exploitable: the two axes are independent.