发表机构
State Key Laboratory of Robotics and Intelligent Systems, Shenyang Institute of Automation, Chinese Academy of Sciences; University of Chinese Academy of Sciences(中国科学院沈阳自动化研究所机器人学国家重点实验室; 中国科学院大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文研究观测设计以最大化可认证动作集,提出投影-可估计性分离和活跃面等价性定理,推导精确可认证性与审计结果,揭示认证成本与测试成本的显著差距。
AI 中文摘要
一个健全的运行时准入门只执行它能够认证的动作,并且只认证其观测所支持的内容。本文探讨如何设计观测以最大化可安全准入的动作集合,并表明该问题并非经典设计问题的重新表述。首先,投影-可估计性分离:将约束法向量相对于信息矩阵分解为 $c=c_{\mathrm{Range}}+c_{\ker}$,当 $c_{\mathrm{Range}}\neq 0$ 时,沿 $c$ 的两点判别随预算增长变得任意可靠,而当 $c_{\ker}\neq 0$ 时,在任何预算下对法向量为 $c$ 的动作进行稳健准入都是不可能的;这样的混合方向在任何秩亏缺情况下都是普遍的,而在满秩情况下,解耦受 Kantorovich 比率限制,并随条件数发散。判别最优设计作为线性准则的角点解,恰好落入这一区域。其次,活跃面等价性定理:宽容度最优设计是针对由成为认证瓶颈的动作面内生生成的目标矩阵的 $L$-最优设计,该矩阵按剩余裕度的倒数加权;单面坍缩精确恢复 $c$-最优和目标导向设计,而 Caratheodory 论证产生至多 $r(r+1)/2+1$ 个面的瓶颈证书。围绕这些,我们为每个凸契约模式组装精确可认证性,其中 $\u03ba\approx 3.29$ 是推导而非校准的,契约无关设计的 $\u221ar$ 代价,信息-裕度转移定理及其曲率-预算推论,以及一个两部分审计,其中满足每个裕度要求的设计仍使一个动作面的认证成本超过其测试成本的十倍,在所有测试的探针库中均如此。
英文摘要
A sound runtime admission gate executes only actions it can certify, and certifies only what its observations support. This paper asks how observations should be designed to maximize the set of actions that can be safely admitted, and shows the question is not a re-vocabulary of classical design problems. First, a projection--estimability separation: decomposing a constraint normal as $c=c_{\mathrm{Range}}+c_{\ker}$ relative to an information matrix, two-point discrimination along $c$ becomes arbitrarily reliable as the budget grows whenever $c_{\mathrm{Range}}\neq 0$, while robust admission of an action with normal $c$ is impossible at every budget whenever $c_{\ker}\neq 0$; such mixed directions are generic at any deficient rank, and at full rank the decoupling is bounded by the Kantorovich ratio and diverges with the condition number. Discrimination-optimal designs, being corner solutions of a linear criterion, land in exactly this regime. Second, an active-face equivalence theorem: the permissiveness-optimal design is $L$-optimal for a target matrix generated endogenously by the action faces that become certification bottlenecks, weighted inversely by their remaining slack; single-face collapse recovers $c$-optimal and goal-oriented design exactly, and a Caratheodory argument yields a bottleneck certificate of at most $r(r+1)/2+1$ faces. Around these we assemble exact certifiability per convex contract mode, for which $κ\approx 3.29$ is derived rather than calibrated, the $\sqrt{r}$ price of contract-agnostic design, an information-to-slack transfer theorem with a curvature-budget corollary, and a two-part audit in which a design meeting every margin requirement still leaves an action face at a certification cost above ten times its testing cost, in every probe library tested.
Comments12 pages, 3 figures, 2 tables