Can a Black-Box System Remain Alive at Its Boundary?
Boundary-Encoded Stability Theory, or BEST, reframes stability analysis for black-box systems. Instead of asking whether the hidden…
Can a Black-Box System Remain Alive at Its Boundary?
Boundary-Encoded Stability Theory, or BEST, reframes stability analysis for black-box systems. Instead of asking whether the hidden internal state of a system is safe, aligned, interpretable, or stable, BEST asks a more operational question: can the system’s boundary layer remain self-maintaining under perturbations that surface at that boundary? The theory models the boundary as a stochastic, resource-consuming, damage-accumulating, repair-capable, schema-reorganizing subsystem that can also die when viability conditions fail. In this sense, BEST is not a theory of hidden-bulk safety or containment. It is a stochastic viability theory for boundary-layer persistence under fallible control (Takahashi, 2026).
1. What problem is BEST trying to solve?
Many important systems are operationally opaque. Large AI systems, distributed cloud platforms, cyber-physical infrastructures, and institutions may have internal states that are unavailable, unstable, too complex to interpret, or changing faster than external theories can describe them. A conventional stability theory often assumes that the analyst can model the internal state, define internal safety predicates, and reason about system trajectories directly. BEST begins from the opposite premise: what if the interior is not the right object of analysis?
The central move in BEST is to shift the stability target from the hidden internal bulk to the boundary layer. The boundary layer is the interface through which perturbations, evidence, resource flows, repairs, refusals, audits, exchanges, and schema changes become operationally relevant. The core question is not “Is the hidden system internally safe?” but “Can the boundary layer remain alive while interacting with the world?”
This is a scientific narrowing, not a rhetorical substitution. BEST explicitly refuses to infer hidden-bulk safety from boundary persistence. Its object is the survival of the boundary process, not the moral, semantic, or mechanistic correctness of the hidden interior.
2. What is a “boundary layer” in BEST?
In BEST, a boundary layer is not merely an interface, firewall, monitor, or shield. It is a viability-bearing subsystem with its own state. The paper represents the operational boundary state as a tuple containing resource reserves, response capacity, accumulated damage or debt, exchange throughput, and structural integrity. A schema specifies thresholds, exchange requirements, admissible actions, reorganization rules, costs, and transition conventions. The extended state also includes an absorbing death state, meaning that nonviability is not ignored but represented explicitly.
This modeling choice matters. A passive interface can only permit, block, or transform flows. A BEST boundary can spend resources, accumulate damage, repair itself, change its schema, maintain exchange, and fail. Thus, the boundary is treated as a metabolic control subject. It survives only if its reserves, capacities, damage levels, throughput, structural integrity, and schema remain jointly viable.
3. Why does BEST reject the “closed shield” solution?
A common safety intuition is that if a system is dangerous, the safest policy is to close every channel. BEST blocks this trivialization by treating exchange as a viability condition. If a boundary layer requires positive exchange throughput, then complete closure is not survival. It may satisfy an external safety property, but it kills or starves the boundary as a metabolic system.
The paper formalizes this through closure-death results: if a post-transition schema requires positive exchange and the next state has zero exchange throughput, the killed kernel maps the process to death. Temporary sealed operation can be modeled as a separate emergency schema, but finite reserves impose a finite reopening deadline.
The conceptual point is precise: BEST is not about minimizing exposure at all costs. It is about maintaining viable exposure.
4. What does “fallible control” mean?
BEST separates selected action from realized outcome. A boundary may choose a response, a schema reorganization, and a resource allocation, but it does not fully control what actually happens next. The response may be blocked, delayed, corrupted, under-resourced, or overwhelmed. Formally, the next boundary state is sampled from a stochastic kernel conditioned on the current boundary state, surfaced perturbation, evidence, selected response, reorganization action, and allocation. Therefore, action selection does not imply state realization.
This is essential to the theory. If selected actions were always realized exactly, the boundary would be a controller with deterministic authority. In BEST, the boundary is a fallible agent embedded in a stochastic environment. It can choose, but it can still die.
The minimal execution-loss model makes this quantitative: if a nominal action has a positive metabolic drift margin but execution can fail with probability ε and impose loss Δ, then the effective predictable drift margin is reduced by εΔ. The same selected repair policy therefore becomes weaker once fallible realization is included.
5. How does BEST define stability?
BEST distinguishes several stability modes.
First, robust BEST is an adversarial, support-level condition: for every allowed perturbation and evidence realization, there must exist actions and allocations that keep all possible next states within the viable set.
Second, finite-horizon stochastic BEST is the paper’s primary mode. A state is ((H,\beta))-BEST-stable if there exists an admissible policy such that the probability of surviving beyond horizon (H) is at least (\beta).
Third, dominance BEST asks for a policy that maximizes survival probability over a horizon, when such a maximizer exists. If exact maximizers cannot be guaranteed, the appropriate object is epsilon-dominance: a policy whose survival probability is within (\varepsilon) of the supremum.
This hierarchy is important. BEST does not pretend that all systems admit robust survival guarantees. It permits weaker, scientifically explicit claims when only probabilistic or approximate survival can be certified.
6. What is the “surface law,” and why does it replace hidden-state modeling?
BEST does not require direct modeling of the hidden bulk. Instead, it models the conditional law by which the hidden bulk and environment generate surfaced perturbations and boundary evidence. This is called the surface law.
The surface law is not assumed to be stationary or memoryless. It can depend on previous boundary states, previous perturbations, selected actions, allocations, reorganizations, and evidence. This allows the theory to represent feedback: for example, a defensive action may protect today’s reserves while making future perturbations more intense.
The paper is careful about this point. If history-dependent surface feedback is compressed into a Markov model without sufficient memory, resource-concentration claims may become invalid. A valid certificate must either include the relevant memory in the state, prove that memory has a contractive or fading envelope, or control the killed-kernel perturbation at the full process level.
The result is a disciplined externalism: BEST studies what the boundary can observe and survive, not what the hidden bulk “really is.”
7. What is the no-interiority principle?
The no-interiority principle states that hidden systems that induce the same surface law are indistinguishable for BEST purposes. If two different hidden bulk–environment generators produce the same boundary observations and the same induced boundary process, then no statistic based only on the killed boundary process can distinguish hidden properties that differ between them.
The paper proves this through surface equivalence and non-identifiability results. In particular, BEST-stability does not imply hidden-bulk safety, alignment, or containment unless the hidden property is surface-measurable under additional assumptions.
This is one of the theory’s strongest scientific constraints. BEST does not overclaim. It explicitly says: boundary survival is not interior truth.
8. When does allocating more resources to the boundary improve survival?
BEST’s motivating hypothesis is that black-box systems may persist longer when enough resources are concentrated in the boundary layer. But the paper makes this claim conditional. More boundary allocation helps only on intervals where it improves reserves, repair, response capacity, damage absorption, exchange maintenance, or schema reorganization without destroying exchange or bulk support.
The resource-concentration theorem formalizes this through monotone coupling. Under appropriate stochastic-order comparisons of observations, feasible-action embeddings, and killed-next-state couplings, increasing allocation within a valid interval improves finite-horizon fixed-schema survival probability.
This is not a universal monotonicity claim. BEST does not say “more defense is always better.” It says more boundary allocation improves survival only when the system admits a monotone comparison in which higher allocation leads to no worse boundary states under the relevant vitality order.
9. Why is there a metabolic band rather than a maximal allocation rule?
BEST introduces a metabolic band: an interior allocation region in which the boundary receives enough resources to repair, respond, and reorganize, but not so many that it starves exchange, support, or adaptive diversity. The paper’s over-concentration model captures this with a net margin function that has diminishing metabolic returns, direct concentration costs, and a singular exchange-strangulation cost as allocation approaches one. As allocation approaches full concentration, the net margin can collapse to negative infinity.
This is scientifically plausible for many systems. A cloud platform that spends all resources on defense may stop serving users. An institution that allocates all effort to compliance may lose operational capacity. An AI interface that maximizes refusal and audit overhead may destroy useful throughput. In BEST terms, these systems may become safer under one external criterion while becoming metabolically nonviable.
The design target is therefore not maximal boundary control. It is sufficient, balanced, dynamically sustainable boundary metabolism.
10. What role does metabolic capital play?
Metabolic capital is the scalar or certificate function that summarizes how far the boundary is from death under a schema. It does not replace the multidimensional boundary state; rather, it gives a way to prove survival bounds. If the expected or controlled drift of metabolic capital remains positive enough, and if shocks have suitable moment bounds, one can bound the probability of death before schema exit.
The paper’s contribution is not merely to define such a function, but to show how positive cumulative metabolic margin suppresses finite-horizon death risk under explicit assumptions. It also distinguishes exact scalarizations from conservative certificates and discusses constructive routes such as signed-distance functions and semialgebraic or sum-of-squares certificate synthesis.
The scientific interpretation is straightforward: BEST survival certificates require measurable reserves of viability, not informal confidence.
11. How does BEST handle schema reorganization?
A boundary schema defines what counts as viable, what actions are admissible, what exchange is required, and how the boundary may reorganize. In long-running systems, a fixed schema may become inadequate when new perturbation classes appear. BEST therefore allows schema growth, contraction, or reconstruction.
However, schema change is not treated as automatic progress. Reorganization must be evidence-gated. Because the same evidence may be used to compare many candidate reorganizations, ordinary fixed-candidate confidence bounds may be invalid after adaptive selection. BEST therefore requires post-selection-safe evidence accounting, such as candidate-wise confidence budgets, validation splits, or uniform complexity bounds over a certificate class.
This prevents a common failure mode: allowing “adaptation” to become an unconstrained escape hatch. In BEST, schema growth is viable only when evidence supports the post-reorganization survival claim in the operating context.
12. How are finite-horizon risks combined?
BEST uses risk ledgers rather than a single vague safety probability. A finite-horizon survival claim may involve several distinct failure channels: metabolic death before schema exit, schema exit without accepted reorganization, fallible execution loss, memory-approximation error, failed post-reorganization certificates, and fallback-policy failure.
The boundary risk ledger theorem combines ordered conditional failure budgets multiplicatively and also gives a union-bound lower approximation. Crucially, the result does not assume independence. It uses conditional budgeting and the chain rule.
This is a useful discipline for applied safety analysis. Instead of saying “the system is 99% safe,” BEST asks: 99% relative to which horizon, which evidence event, which schema, which fallback policy, which execution-loss model, and which memory approximation?
13. Can BEST make infinite-horizon claims?
Finite-horizon stochastic BEST is the primitive notion. Infinite-horizon survival requires stronger conditions. The paper characterizes infinite survival through the product of conditional survival probabilities, or equivalently through the summability of conditional death hazards. Positive infinite-horizon survival is possible if the sequence of hazards decays fast enough; if hazards remain bounded below by a positive constant, infinite survival probability is zero.
This has a direct interpretation. Long-run persistence cannot be obtained merely by asserting adaptability. Either the boundary stabilizes in a fixed or finite schema class with summable residual hazards, or it undergoes endless schema growth with summable episode risks. The latter requires costs: computation, validation, redundancy, memory, search, or meta-learning capacity.
Thus, BEST turns indefinite survival into a hazard-accounting problem.
14. How does BEST relate to existing theories?
BEST overlaps mathematically with viability theory, Markov decision processes, stochastic reach-avoid analysis, barrier certificates, dissipativity, Foster–Lyapunov drift, runtime assurance, and contract-based design. But it is not equivalent to any one of them.
The difference is the object. Viability theory often constrains the full system state; BEST constrains the boundary’s metabolic state and schema. Barrier methods enforce invariance of safety sets; BEST includes exchange lower bounds, damage, repair, starvation, schema reorganization, and death. Runtime shields enforce external properties; BEST evaluates whether the shield-like boundary itself remains viable. Absorbing MDPs can compute finite-horizon BEST values, but only after the BEST structure has specified metabolism, exchange, schema, surface laws, and killing.
BEST should therefore be read as a structured theorem family, not as a new probability calculus.
15. What are the main limitations?
The limitations are not incidental; they are part of the theory’s scientific hygiene.
BEST does not prove hidden-bulk safety, alignment, truthfulness, interpretability, or containment. Boundary layers can die. Robust BEST may be empty under severe perturbations. Stochastic BEST is horizon-dependent unless additional recurrence, drift, hazard, or schema-growth assumptions support longer claims. Complete closure is nonviable when positive exchange is required. Over-concentration of resources can damage exchange and support. Exact metabolic capital may be hard to compute. Continuous-time BEST requires additional generator, first-passage, boundary-regularity, killing-intensity, and jump-reset assumptions; a discrete killed kernel is not automatically a continuous-time safety proof.
These limitations make the theory less rhetorically expansive but more scientifically constrained.
16. What is the central scientific message?
BEST relocates the proof obligation. It does not ask the analyst to prove hidden interior virtue. It asks the analyst to specify the boundary state, surface law, viability predicate, killed kernel, resource allocation, fallible execution model, schema rules, evidence gates, memory assumptions, and risk ledger. Once these are specified, survival claims can be made with explicit horizons, confidence levels, drift margins, hazard rates, and failure budgets.
The central message is therefore:
A black-box system may be analyzable not by interpreting its interior, but by certifying whether its boundary layer can remain metabolically viable under surfaced perturbations, fallible responses, finite resources, evidence-gated schema change, and explicit death conditions.
That is the conceptual contribution of BEST. It is not a promise that black boxes are safe. It is a framework for asking what can be proven when the only scientifically defensible object is the boundary process.
Reference
Takahashi, K. (2026). Boundary-Encoded Stability Theory (BEST). Zenodo. https://doi.org/10.5281/zenodo.20443834
Author’s research hub: https://kadubon.github.io/github.io/
A thousand-year-old Yakushima cedar does not survive because its interior is perfectly intact. It survives because its living boundary layers continue to exchange, repair, and grow. BEST abstracts this intuition for black-box systems: persistence is certified at the boundary, not inferred from a hidden core.
메타데이터
- post_id
- bc6bc3b1ebb9
- slug
- can-a-black-box-system-remain-alive-at-its-boundary-bc6bc3b1ebb9
- url
- https://medium.com/@omanyuk/can-a-black-box-system-remain-alive-at-its-boundary-bc6bc3b1ebb9
- canonical_url
- https://medium.com/@omanyuk/can-a-black-box-system-remain-alive-at-its-boundary-bc6bc3b1ebb9
- author_url
- https://medium.com/@omanyuk
- status
- ok
- fetched_at
- 2026-06-15 20:49:13