Skip to content
Paula Livingstone writing · projects · tools

Projects

Attestable

When probabilistic AI feeds safety-critical systems, unproven output can drive physical action unchecked. Attestable is a discipline for marking a claim's basis, so it cannot.

OT SecurityCyber-Physical AssuranceIEC 62443ProvenanceSafety CaseLLM Agents

Literature Review: The Chapter

6 entries

The literature review as continuous chapter prose. Read these six in order; they are the chapter itself.

  1. Introduction: Integrity, Admissibility, and the Shape of the Review The organising claim, stated as a composition rather than a universal negative: what no surveyed field supplies as a single working capability is a portable, per-claim representation of evidential basis supporting action-relative admissibility, derivation-aware inheritance, constrained elevation, and enforcement across an ownership boundary. States the integrity-versus-admissibility distinction that runs through the chapter, the fields surveyed and the two most-mistaken-for-it, the open-access and read-before-cited search method, and the reading order.
  2. Integrity Without Admissibility: Provenance, Policy, and Attestation The three disciplines closest to the contribution each certify the integrity of something other than a claim basis for action, and each marks its own boundary in its founding literature: provenance records lineage and hands the trust judgement onward; policy enforces permission and presupposes the basis; attestation certifies that a declared process ran. The gap they jointly enclose and none occupies is admissibility.
  3. Confidence Is the Wrong Category: Trustworthy Machine Learning The field that produces the confidence signal the whole problem begins with. Confidence is baseless by design, not malfunction; and every rung of the uncertainty apparatus - dropout, ensembles, evidential methods, OOD detection, conformal sets, the aleatoric/epistemic split, calibration - answers a distributional question about the estimation process, not whether a claim suffices to act. The field own survey: estimating predictive uncertainty is not sufficient for safe decision-making.
  4. From Software Integrity to Physical Consequence The argument carried out of software and into the physical world, where acting on an unfounded value opens a valve rather than corrupting a record. Supply-chain integrity certifies the artefact not the act; the perimeter, firewall or learned classifier, authorises transit not basis; and when ML makes the control decision, safe RL constrains it only probabilistically, the estimate can be falsified beneath it, and the trust bolted on top is post-hoc explanation. The gap is unchanged; the consequence is now irreversible.
  5. The Fields That See the Boundary: Assurance, Governance, Explanation, and Trust The four literatures that are aware of the boundary and still hand the judgement on. Assurance cases argue over evidence whose standing they presuppose, at design time, and name automation bias only to refer it onward. Governance mandates that basis reach the receiver and names confabulation and over-reliance as official risks, without specifying what would refuse them. Explanation approximates the model, and in deployment reaches engineers rather than the affected party. Trust in automation shows what reliance without basis costs, with fatalities in aviation and at sea, and concludes the human must calibrate. A bounded testimony coda closes it. Awareness of the boundary is not the scarce thing.
  6. What the Survey Establishes: The Composition None of Them Builds The consolidating section. Figure 4 sets all ten fields against what they establish, what they hand onward, and where they stop. The claim is discharged as the introduction framed it, a composition rather than a universal negative: each field holds one or two parts of a portable, per-claim basis representation supporting action-relative admissibility, derivation-aware inheritance, constrained elevation, and enforcement at an ownership boundary; none holds them together, and none at a machine handover. Why the union does not close it, why the convergence is structural, and the firewall precedent kept in its place.