Compute-Bounded Security Assurance - Coverage, Verification, and Response under Resource Constraints

arXiv:2609.09229 · cs.CR, cs.AI · Submitted 2026-09-07 · Read on arXiv

cs.CR, cs.AI

Submitted: 2026-09-07

Updated: 2026-09-07

License: http://creativecommons.org/licenses/by/4.0/

The gist: Additional inference compute can increase the number of correctly resolved security-assurance tasks, but repeated success, unique coverage, accepted evidence, and operational protection are different

Terminology

Abstract

Additional inference compute can increase the number of correctly resolved security-assurance tasks, but repeated success, unique coverage, accepted evidence, and operational protection are different quantities. We develop a resource-constrained framework that separates them. For repeated conditionally independent attempts with latent success probability Θ, coverage is C n = 1 - E[(1-Θ) n], and its limiting value is 1 - P(Θ= 0). Positive pairwise outcome correlation does not by itself imply a ceiling below one: we construct two models with the same mean success and pairwise correlation but different limiting coverage. We distinguish this result from the effective sample size used to estimate a mean, and show why finite-budget observations cannot generally identify an asymptotic support ceiling. We then connect coverage to fallible evidence checking, proper scoring of factual grounding, complete resource accounting, service capacity, and a response model that includes mitigation delay. A conceptual defensive architecture separates evidence analysis, adjudication, and operational authority. An evaluation protocol specifies held-out tasks, paired comparisons, negative cases, and uncertainty reporting. The contribution is a consistent theoretical synthesis and a set of counterexamples to invalid extrapolations, rather than an empirical scaling law. All numerical illustrations are analytic; no model-parity result, hardware benchmark, or general attacker-defender equilibrium is claimed.

Related papers