{"path":"research/weakest-link-arithmetic-and-the-merge-hunch.md","content":"# Weakest-Link Arithmetic and the Merge Hunch\n\n**Date**: 2026-08-31 · **Type**: deep research pass on the padding-defense ruling (\"Go with option\nC, both\"), commissioned by the founder for reflection: *\"If any central decision we've made or are\nmaking here depends on something that can be questioned, research it extensively and deeply\nonline.\"* Includes the founder's auto-merge hunch (§ 5, verbatim), four worked example trees with\nnumbers computed by the shipped functions (§ 6), and one genuinely new open question the examples\nsurfaced (§ 7). Companion presentation: the **Weakest Link** artifact (interactive; same trees,\nsame arithmetic ported to the page). Plain-language intro:\n[what-the-necessary-default-changes.md](what-the-necessary-default-changes.md).\n\n---\n\n## 0. The three combination rules, and who else uses them\n\nWhen a claim has several parts, three families of rules exist for combining part-strengths into\nwhole-strength, and they recur independently across at least six fields:\n\n| Rule | Deliberus channel | Informal logic | Epistemology | Bayesian networks | Reputation systems |\n|---|---|---|---|---|---|\n| **Weakest part governs** (min) | `necessary` — now the DEFAULT for decomposition children | *linked* premises (Thomas 1973, Freeman 1991/2011) | Pollock's **Weakest Link Principle** | noisy-AND / noisy-MIN (Díez & Druzdzel 2002) | path-trust = min of edge capacities (Cheng & Friedman 2005) |\n| **Contributions add** | `corroborative` (tag required since the flip) | *convergent* premises | accrual (Verheij; Prakken 2005) — **rejected by Pollock** | noisy-adder | additive aggregation — **provably sybil-gameable** |\n| **Strongest part decides** (max) | `alternative` | alternative lines of defense | Pollock's own rule for separate arguments | noisy-MAX (Henrion 1989) | ⊕ = max — the **sybilproof** choice |\n\nThe convergence is not decoration. Every field that lets contributions **add** across parts\ndiscovered the same attack (more parts = more score) and built the same two defense families:\nchange the arithmetic, or detect the redundancy. That recurrence is this document's spine.\n\n## 1. The ruling's academic ground — each pillar, with what can be questioned\n\n### 1a. The attack is documented, not hypothetical\n\n**CORE** (Jiang, Zhang, Weir, Ebner, Wanner, Sanders et al., *Findings of ACL 2025*;\narXiv:2407.03572) measured exactly our defect in the factual-precision world: decompose-then-verify\nmetrics like FActScore \"can be manipulated by adding obvious or repetitive subclaims to\nartificially inflate scores\" — models tuned to do it \"can easily achieve over 80% FP without\ngenerating any substantial knowledge.\" Our own measured instance: 3 children at 0.70 → parent\n0.516; 12 identical children → 0.671 (`strength-layer-audit.md`). Same shape in social choice:\nunder Borda counting, \"any candidate can simply clone their way to victory... the winner being the\ncoalition that runs the most clones\" (**teaming**, in Tideman's 1987 clone taxonomy of\nvote-splitting / teaming / crowding, *Social Choice and Welfare* 4:185–206).\n\n### 1b. Min is the arithmetic that removes the payoff — by theorem, not by taste\n\nThe mathematically crisp fact: among all t-norms (the fuzzy-logic generalizations of AND),\n**minimum is the only one for which every value is idempotent** — T(a,a) = a for all a (Klement,\nMesiar & Pap, *Triangular Norms*, Kluwer 2000; position paper I, Prop. 6.1–6.2). Idempotence IS\nthe anti-padding property stated as algebra: **cloning a conjunct is a no-op under min and under\nnothing else**. The product rule (the probability-textbook conjunction) is a t-norm too, and it\nfails in the opposite direction — see § 1c.\n\nPollock reached min from epistemology rather than algebra: \"a deductive argument is as good as its\nweakest link... The argument strength of a deductive argument is the minimum of the degrees of\njustification of its premises,\" extended to defeasible arguments via conditionalization (\"Defeasible\nreasoning with variable degrees of justification,\" *Artificial Intelligence* 133, 2001). The same\npaper **rejects accrual outright** — two arguments for one conclusion yield the *maximum*, not a\nsum — which means our corroborative channel sides against Pollock and with the accrual school\n(Verheij; Prakken, \"A study of accrual of arguments,\" ICAIL 2005). That is a genuine contested\nchoice, held deliberately: see § 4.\n\n### 1c. Why min and not product — the law already ran this experiment\n\nThe naive Bayesian rule for a conjunction is the product of part-probabilities. It is\npadding-proof too (more parts can only lower), but it **punishes honest depth**: three parts at\n0.70 → 0.343, twelve → 0.014. A scoring rule that taxes fine-grained decomposition contradicts the\nseparability floor — under product, the rational contributor stops decomposing, which kills the\nproject's core mechanic.\n\nThe legal system has fought about precisely this for fifty years as the **conjunction paradox**\n(L.J. Cohen, *The Probable and the Provable*, 1977): legal doctrine applies the standard of proof\n**per element**, not to the conjunction — a plaintiff proving two elements each to 0.6 wins,\nthough the product is 0.36 (Pardo, \"The paradoxes of legal proof,\" *B.U. L. Rev.* 2019). Cohen's\npoint: if the product rule governed, \"as the number of independent elements increases, the\nthreshold of proof for each would rise. But the law recognises no such requirement.\" Element-wise\nthresholding is min-shaped, not product-shaped, and Clermont (\"Death of Paradox,\" *Notre Dame L.\nRev.* 2013) argues outright that fuzzy min-logic, not probability, describes what legal factfinding\ndoes. The rival school (Allen & Pardo's relative plausibility; Schwartz & Sober defending\nprobabilism) resolves the paradox **holistically** — compare whole competing stories, never\nelement-by-element — which is a real alternative design (§ 4, objection 3).\n\nSo the three candidate arithmetics sort cleanly: **additive** is the gameable one we measured;\n**product** is padding-proof but depth-punishing; **min** is padding-proof *and* depth-neutral —\nthe unique t-norm under which splitting a part into equal-strength subparts changes nothing, which\nis exactly the invariance the separability floor requires.\n\n### 1d. The linked/convergent tradition — and the honest asterisk on it\n\nThe two-channel design is the informal-logic **linked vs convergent** distinction (Beardsley 1950;\nThomas 1973; Freeman, *Dialectics and the Macrostructure of Arguments* 1991 and *Argument\nStructure* 2011; Walton, *Argument Structure: A Pragmatic Theory* 1996) given arithmetic: linked\npremises \"work together and fail together\" — refuting one refutes the argument — while convergent\npremises support independently. The asterisk: **Yu & Zenker (\"Identifying linked and convergent\nargument structures: a problem unsolved,\" *Informal Logic* 42(2), 2022) argue the distinction's\nstandard tests are circular** — they require evaluating support strength before structure can be\nidentified, putting the cart before the horse. Freeman's reply (2023) defends a **structural**\ncriterion needing no strength estimate. This dispute bears directly on the founder's\nderive-the-tag-from-content question: our deterministic pre-signal (child shares the parent's\nsubject and fragments its predicate → part; independent same-shape proposition → evidence) is a\ncriterion of Freeman's structural kind, and Yu & Zenker are the named reason to expect a genuine\ngrey zone the classifier must confess on rather than force.\n\n### 1e. The axiomatic result that says a choice is FORCED\n\nAmgoud & Ben-Naim's axiomatics for argument evaluation (KR 2016; Amgoud et al. 2017; the AIJ\nweighted-graph paper) prove that **Cardinality Precedence** (more counts for more), **Quality\nPrecedence** (the strongest single consideration dominates), and **Compensation** (many weak\noffset one strong) are pairwise incompatible — no semantics satisfies more than one. There is no\nneutral arithmetic; every aggregation is a stance. Deliberus's answer is the one Munro, Bloch &\nLesot (arXiv:2603.06067) license: make the aggregation **separately constrainable per relation**\nrather than fixed globally — quality-precedence (min) where parts are required, compensation\n(additive) where they corroborate, max where they compete. The flip moved only the *default* for\none relation type, exactly where the separability floor says the constitutive reading is true by\nconstruction.\n\n### 1f. What would Bayes say? — the founder's question, and the corpus's prior answer\n\n**The corpus answered this before the ruling existed**, and the two derivations converge from\nindependent directions. [evidence-division-and-the-foundation.md](evidence-division-and-the-foundation.md)\n§ 2b (2026-08-20) already grounded the three candidate rules in probability theory: **sum** is not\na probability operation at all; **product** is the conjunction probability under *independence* —\nmaximally wrong for constitutive parts, which are aspects of one thing, and an anti-clarification\nincentive besides; **min is the Fréchet–Hoeffding upper bound**, P(A∧B) ≤ min(P(A), P(B)) — \"the\ntightest thing that is always true regardless of correlation... the correlation-agnostic upper\nbound, which is exactly the right default posture for a system that cannot know the correlations.\"\nThe t-norm idempotence theorem (§ 1b) and the Fréchet bound are two independent derivations landing\non the same operator: min is simultaneously the only clone-proof AND-generalization *and* the only\nconjunction estimate that never overstates under any dependence structure.\n\n**One sharpening is new here: for the padding attack's own case, min is not a bound — it is\nBayes's exact answer.** The adversarial slivers are entailment-chained by construction (\"she has\npublications\" ⊨ \"the publications exist\"), and for an entailment chain A₁ ⊨ A₂ ⊨ … the conjunction\nprobability *equals* the weakest link: P(∧Aᵢ) = P(A₁) = min. Perfect positive dependence attains\nthe upper bound (the comonotone case of copula theory). So the attacker who slices thin\nmanufactures precisely the dependence structure under which the new rule computes the true\nBayesian conjunction, exactly. The rule is most correct exactly where it is attacked.\n\n**The corroborative channel is Bayes's own rule for the case it claims.** Adding offsets is the\nadditive-log-odds shape — Good's \"weight of evidence\": for genuinely independent evidence, log\nlikelihood ratios add, which is why accumulation is right *there* and only there. Its known\nfailure is naive Bayes's known failure — the independence assumption — which is why the open flank\nof § 9 sits exactly where Bayesian analysis predicts: correlated evidence double-counts until a\njoint model (or its cheap surrogate, fair-share discounting plus source-independence provenance)\nprices the correlation. The honest full-Bayesian alternative — conditioning one joint model with\ncorrelations first-class — is what § 2b of the evidence-division doc already weighed and declined:\ntree-shaped propagation is the tractable approximation, and the architecture compensates by making\nrouting judgments visible, linkable and attackable rather than silent (confirmation holism's\n\"link, never divide\").\n\n**Where Bayes has no jurisdiction at all**: likelihoods exist only where evidence can bear — the\nempirical terminus class. The evaluative termini have no likelihood function to update, which the\ncorpus already holds as \"the terminus enum is a map of the oracle gradient\"\n([fragile-checkers-and-the-verification-bottleneck.md](fragile-checkers-and-the-verification-bottleneck.md)).\nAnd QEM strengths are deliberately *not* calibrated probabilities — the gravity-toward-prior\nproperty is Bayes-flavored (the March QBAF research called it \"Bayesian prior behavior\"), but the\nscale is a gradual semantics chosen by postulates, so no strength should be read as\nP(claim is true).\n\n**The up-transmission whisper (§ 7), restated in Bayes**: the parent equals the conjunction of its\nparts *only given* that the parts exhaust the parent. P(whole | all parts established) is capped\nby P(the decomposition is complete) — so the whisper is, in effect, a low prior on exhaustiveness,\nand coverage-gated lifting is Bayesian updating on a recomposition check.\n\n## 2. Consequence one, grounded: the pebble was independence, and independence is now claimed\n\nThe pre-flip additive channel protected a strong claim among unevidenced siblings because\nzero-offset siblings added zero. That protection **is** an independence assumption — and Freeman's\nlinked test says the opposite holds for genuine parts: \"refuting a single premiss of a linked\nargument suffices to refute the argument.\" A chain with an unverified link is an unverified chain.\nWhere independence is real (three studies), the corroborative tag says so and the additive\nbehaviour returns, pebble included. The protection moved from automatic to claimed; the truthful\ndefault for a decomposed whole is the linked one.\n\n## 3. Consequence two, grounded: the crux-pointer now implements Pollock\n\nThe hinge instrument asks: if you changed your mind about one part, how much would the conclusion\nmove? Under addition each part carried a thin slice (measured: denying a jointly-required part\nmoved the root ~0.02 — \"the instrument whispered exactly where it should have shouted\",\n`hinge.py`). Under min, sensitivity concentrates on the weakest required part — which is Pollock's\nweakest-link principle read as a *diagnostic*: the crux of a conjunction is its weakest link, so\nthe question worth asking first is the one the whole actually hangs on. Example numbers in § 6.\n\n## 4. What can be questioned in the min choice — three real objections, answered honestly\n\n**Objection 1 — min is count-blind.** Two weak parts score the same as one weak part; fixing one\nof two problems shows no progress until the last one moves. True, and it is Quality Precedence's\nknown cost (§ 1e: you cannot have counting and quality at once). Mitigation: the *display* can\nlist every below-threshold part even though the *number* tracks only the weakest; the horizon\nband and the sorry markers already do this per part.\n\n**Objection 2 — min is noncompensatory.** A 0.51 part caps a whole whose other parts sit at 0.99.\nFor a genuine conjunction that is correct (logic, not policy): the whole *is* unestablished until\nits last requirement is. The dangerous direction — the one the audit measured — is the compensating\none, where strong siblings paper over a failed domain-match. Where compensation is genuinely\nright, the parts were not parts (§ 8).\n\n**Objection 3 — element-wise scoring may be the wrong frame entirely.** Allen & Pardo's holism:\njuries compare whole competing *stories*, not element scores, and the conjunction paradox\ndissolves when the unit of assessment is the story. The graph's analogue would score competing\nsubtrees holistically rather than propagate per-node. Answer: holism is a *reader's* operation and\nthe graph serves many readers; per-node propagation keeps every intermediate addressable (every\nclaim is a link), which is the substrate bet. But holistic comparison of rival decomposition\nsubtrees is a legitimate future instrument, and this objection is the standing reason to build it\nrather than believe per-node numbers are the whole story.\n\n**And one non-objection to name:** Yu & Zenker's circularity critique (§ 1d) attacks the\n*identification* of linkage, not the *arithmetic* once linkage is asserted. Under the separability\nfloor the identification question is transformed anyway: parts are linked by construction, and the\nreal classification job is parts-vs-evidence (§ 8).\n\n## 5. The founder's hunch: can better auto-merge replace the arithmetic?\n\nVerbatim (2026-08-31): *\"I have a hunch that part of the protection against splitting subclaims\nthin could be based on steadily improving the auto-merge of claims, such that we'd always see\nthrough the trivial attempts to split into unwarranted subclaims? Investigate this. Maybe it's not\nenough, maybe it is.\"*\n\n### 5a. The hunch is real enough that someone built it\n\nThe literature's answer to the padding attack is **CORE itself** — and CORE is, precisely, an\nimproved auto-merge: it deduplicates subclaims by **pairwise entailment** (not mere sameness),\nweights each by informativeness/surprisal, and selects the maximum-weight non-redundant subset via\ninteger programming. It works in its setting: with CORE attached, \"neither [uninformative] nor\n[repetitive] generation boosts\" the score. So a sufficiently good redundancy detector CAN see\nthrough trivial splitting — including entailment-chained slivers that sameness-merge would miss,\nbecause \"she has publications\" entails \"the publications exist\" even though the two are not\nduplicates. **Correction to what I said in chat before this research**: I claimed merge\nstructurally cannot catch thin slicing because the slices are genuinely distinct; entailment-based\nredundancy detection (stronger than sameness) can. The distinct-but-entailed case is catchable —\nat a price.\n\n### 5b. What the detector costs that the arithmetic doesn't\n\n1. **It must run, forever, on everything.** An NLI/entailment model per candidate pair, with model\n   error on every call. The measured ceilings for the adjacent task (claim matching): SemEval-2025\n   Task 7's best systems reach success@10 ≈ 0.93–0.96 monolingual and 0.79–0.86 crosslingual — and\n   success@10 is a *generous* metric (a hit anywhere in the top ten). Sameness-judgment error\n   rates of 3–20% are the corpus's standing `owl:sameAs` numbers. A defense with a 5–20% miss rate\n   held together by continuous inference compares badly to an algebraic identity that holds at\n   100% by construction, costs nothing, and cannot be down.\n2. **Detection invites the arms race; arithmetic ends it.** Adversarial-paraphrase results against\n   text detectors show the pattern: adaptive attacks reach 99.9% evasion success and transfer to\n   detector families never seen in training (StealthRL, arXiv:2602.08934; Adversarial\n   Paraphrasing, NeurIPS 2025 — average 87.9% reduction in detection at fixed false-positive\n   rate). Those are AI-text detectors, not claim-mergers, but the structural lesson carries: a\n   *detector* is a strategy-class surface — publishing it arms the adversary (the fleet's\n   fair-meiosis rule). The min rule is publish-safe: knowing it exists gives an attacker nothing,\n   because there is no behaviour left that pays.\n3. **An aggressive-enough merge threatens honest depth.** The separability floor makes fine,\n   genuinely-distinct parts *desirable*; a redundancy filter tuned to kill trivial slivers must\n   discriminate trivial-because-entailed from fine-because-separable, and its false positives\n   destroy exactly the decompositions the project wants most. CORE tolerates this in its setting\n   (metric evaluation, where dropped subclaims cost little); in a graph where **claims are\n   addressable objects people build on**, a false merge is the `sameAs`-catastrophe class.\n\n### 5c. The elegant closure: under min, the entailment-detector's work is already priced in\n\nIf part A entails part B, then B cannot be less established than A — any coherent scoring gives\nσ(B) ≥ σ(A). Under min, **the entailed part can never be the weakest, so it never governs: it is\ninert automatically, with no detector, no model call, and no error rate.** The very redundancy an\nentailment-based merger would find and remove is exactly the redundancy min already prices at\nzero. Pollock made the epistemological version of this point with his two-witness example: the\n\"accrued\" reason is not the conjunction of the two testimonies but a single subsuming\nconsideration — the pieces do not add because they were never independent.\n\n### 5d. Verdict on the hunch — three parts\n\n- **Not needed where the flip landed.** In the necessary channel, arithmetic already does what a\n  perfect entailment-merger would do, at zero cost and zero error.\n- **Right, and genuinely needed, where addition survives.** The corroborative channel and SUPPORTS\n  edges still add, so *there* redundancy still pays: two restatements of one study, three papers\n  laundering one dataset. This is where the hunch is correct and where a CORE-shaped instrument\n  (entailment-aware redundancy + informativeness weighting) belongs — as does auto-merge proper,\n  whose primary jobs (reuse flywheel, retrieval, addressability) are independent of security.\n- **Insufficient alone.** Even a perfect merger passes genuinely-distinct correlated evidence\n  (three real studies, one shared dataset — different claims, no entailment, still not\n  independent). No sameness technology reaches correlation as *merge* — but see § 9b: the\n  published reconciliation uses the same similarity machinery as a *discount inside aggregation*,\n  which is where the hunch lands vindicated.\n\nOne more supporting result from the reputation literature: Cheng & Friedman prove **no symmetric\nreputation function is sybilproof** — identity-blind aggregation is gameable by manufactured\nidentities *in principle*, and their sufficient conditions for sybilproofness include, verbatim, a\n**no-splitting axiom** (\"if we split P into two paths P1, P2, then g(P1) ⊕ g(P2) ≤ g(P)\") with\nmax-aggregation. Structure-blind additive counting is the provably-losing design; splitting-must-\nnot-pay is the provably-necessary axiom. The flip installed that axiom in the one channel where\nparts are constitutive.\n\n## 6. The four example trees — numbers from the shipped functions\n\nAll strengths computed with `qem_strength`, `interpreted_energy`, `necessary_ceiling` (the live\ncode), evidence edges at full offset, subclaim channel at the shipped 0.3 weight. Reproduce:\n`scratchpad/tree_compute.py` logic inlined in the presentation.\n\n### 6a. Synthetic: the flat padding pair (the ruling's own anchor)\n\nParts each at 0.70:\n\n| n parts | additive (old default) | weakest-part (new) | product (rejected) |\n|---|---|---|---|\n| 1 | 0.502 | 0.502 | 0.700 |\n| 3 | 0.516 | 0.502 | 0.343 |\n| 6 | 0.557 | 0.502 | 0.118 |\n| 12 | **0.671** | **0.502** | **0.014** |\n\nAdditive rewards slicing; min is indifferent to it; product punishes it — and would punish honest\ndepth identically.\n\n### 6b. Synthetic, 5 levels: Dr. Smith (the corpus's house example, extended)\n\nRoot: *\"Dr. Smith's testimony that a $15 minimum wage is safe deserves substantial weight\"* →\nparts: genuine expert (→ research record (→ papers exist+peer-reviewed [2 evid]; papers in-field\n[2 evid]); position [2 evid]); testimony in-field [2 evid]; **no disqualifying bias — naked, no\nevidence, σ = 0.5**. Result: old root 0.500, new root 0.500 — *the same number with opposite\nmeanings*. Old: everything diluted to nothing (the 0.3-weighted quadratic channel barely moves at\nsmall n — the \"whisper\" of § 7). New: root is **capped by the naked bias part**, and the\ngoverned-by-weakest-part note names it. The expert-opinion scheme's classic critical question\n(bias) is structurally guaranteed never to be papered over by publication evidence — which is what\nthe old arithmetic permitted in principle and CORE-style attackers exploit in practice.\n\n### 6c. Real, bounded: the minimum-wage tree (5 levels; sources are in the live corpus register)\n\nRoot: *\"A $15 federal minimum wage would not cause significant job losses.\"* Parts: **historical\nrecord** (Card & Krueger 1994 as an evidence-subgraph whose own parts are design-validity\n[+0.75,+0.70] and measurement-accuracy [Neumark & Wascher 2000 attack −0.70 vs Card & Krueger 2000\npayroll reanalysis +0.80,+0.70]; plus Cengiz et al. 2019, Dube-Lester-Reich 2010 as convergent\nsupport) → 0.680; **mechanism applies broadly** (monopsony) → 0.529; **$15 stays within the\nstudied range** — attacked (ratio-to-median in low-wage states exceeds anything studied,\n−0.75,−0.70) → **0.416**. Roots: old **0.501**, new **0.416**. Old renders a claim whose\nscale-applicability premise is *failing* as neutral-drifting; new transmits the failing required\npart 1:1 and the hinge points at it. The channels nest correctly: convergent studies (additive,\ntagged) *inside* a necessary method-decomposition *inside* a necessary three-part case.\n\n### 6d. Real, bounded: the deterrence tree (5 levels; van den Haag register is in the corpus)\n\nRoot: *\"The death penalty is justified because it deters murder better than imprisonment.\"*\nParts: **marginal deterrence** (Ehrlich 1975 as evidence-subgraph: identification attacked by the\n1978 NAS panel −0.75; period-robustness attacked −0.80 → Ehrlich 0.459 new vs **0.500 old**; plus\nDonohue & Wolfers 2005 attacking directly) → 0.478; **the value premise** (\"the gain outweighs the\nmoral cost\") — naked, σ = 0.5, the implicit crux run 3F documented; **administrability** (attacked\nby the exoneration record) → 0.481. Roots: old 0.500, new **0.456**. Two lessons: a\nmethodologically-attacked study reads pristine under addition (its two attacked parts dilute to\n−0.02 energy ≈ nothing) and honestly weak under min; and under min **the naked value premise is\nload-bearing** — old arithmetic let it contribute zero and vanish, new arithmetic makes the\nunstated crux exactly what the whole hangs on, which is the run-3F implicit-crux finding turned\ninto arithmetic.\n\n## 7. What the examples surfaced that nobody had decided: the up-transmission asymmetry\n\nBuilding the trees exposed a shipped behaviour worth a founder look. The necessary channel\ntransmits **weakness downward at full strength** (the ceiling: a failing part caps the whole 1:1)\nbut **strength upward only at a whisper**: `necessary_energy` is (min − 0.5) × 0.3 through the\nquadratic impact, so **three parts each established at 0.9 lift their parent only to 0.507.**\nPollock's weakest-link would say the parent *is* 0.9 (parent = min of parts, both directions).\n\nThe asymmetry has a principled reading nobody has stated before: **it prices the coverage gap.**\nEstablishing every listed part establishes the whole only if the parts *exhaust* the whole — and\nthe corpus has no coverage instrument (the B-arc's named missing check: nothing verifies children\njointly recompose the parent). Capping downward is safe regardless of coverage (a failing required\npart sinks the whole whatever else the whole contains); lifting upward assumes exhaustiveness. So\nthe shipped conservatism is defensible — but it is currently an **accident of inherited constants**\n(the 0.3 corroborative weight reused), not a decision. Proposal filed in TODO: **coverage-gated\nlifting** — when a decomposition passes a recomposition/coverage check (the built-but-unwired\n`decompose_claim` verifier is the natural organ), the parent may inherit min(parts) upward; until\nthen the whisper stands as the honest price of unverified exhaustiveness. This also dissolves an\napparent paradox in § 6b: old and new roots can share a number while meaning opposite things — the\ndisplay note (governed-by-weakest-part, naming the part) carries the difference, which is why the\nnote is not decoration.\n\n## 8. Deriving the tag from content — the classifier question, grounded\n\nThe founder asked whether the necessary/corroborative default could be derived from content. The\nresearch sharpens the § 8-of-the-plain-doc answer:\n\n- Under the separability floor, a genuine part is necessary **by construction**, so the real\n  classification is **parts vs evidence-items**: a corroborative-looking child is usually an\n  evidence edge mislabelled as decomposition (three studies are witnesses, not parts).\n- The deterministic pre-signal (child shares the parent's subject and fragments its predicate →\n  part; independent same-shape proposition → evidence) is a **structural** criterion — the kind\n  Freeman's 2023 reply defends as evaluable without strength estimates, against Yu & Zenker's\n  circularity critique of the traditional tests. Their critique is the named reason the classifier\n  keeps a confession value for the genuine grey zone instead of forcing a nearest fit.\n- The three-way pass (necessary / corroborative / miscast-as-SUPPORTS) with the founder's lazy\n  agree/disagree review is registered in TODO § padding-defense option C.\n\n## 9. The honestly open flank: correlated corroboration\n\nNeither the arithmetic nor any merge touches it: three genuinely distinct studies sharing one\ndataset add three times in the corroborative channel. Pollock's Fredonia witnesses make the\nepistemological case (the joint probability is not a function of the individual ones — it depends\non the witnesses' dependence structure); Prakken's first accrual principle states it formally (\"an\naccrual is sometimes weaker than its accruing elements... the strength of an accrual cannot be\ncalculated from the strengths of its elements\" when reasons interact). The shipped near-answer is\nfair-share discounting (`evidence_routing.py` — built, tested, not adopted); the missing piece is\nsource-independence provenance (shared datasets, shared authors, citation chains). This remains\nthe strength layer's least-defended channel, now with the literature naming exactly why.\n\n## 9b. The reconciliation landscape — what has been published about partial dependence (added same day, founder question)\n\nThe founder asked whether anyone has published reconciliations of the two poles — full\nindependence (add / product) and full dependence (min / count-once). **Yes: at least five fields\nhave, independently, and every one of them converges on the same shape — a dependence dial, plus\na structure that supplies the dial's value.** The dial cannot be computed from the strengths\nthemselves (Pollock's point, § 1f); each field found a different place to get it.\n\n**1. Our own field already built the exact construction.** Amgoud, Bonzon, Delobelle, Doder,\nKonieczny & Maudet, \"Gradual Semantics Accounting for Similarity between Arguments\" (KR 2018) and\nAmgoud & David, \"A General Setting for Gradual Semantics Dealing with Similarity\" (AAAI 2021)\nextend gradual semantics with an **adjustment function**: before aggregation, each contributor's\nstrength is discounted by its similarity to its stronger co-contributors, so only its **novelty**\ncounts (\"if x₁ and x₂ are fully similar, only one of them is considered... if they are partially\nsimilar, the redundant part should not be counted twice\" — a part similar at degree α to a\nstronger sibling contributes 1−α). Their axioms name the target properties: **Redundancy\nFreeness** (a fully-redundant contributor is discarded) and **Sensitivity to Similarity** (the\nmore similar a group, the weaker its joint force). Full similarity recovers count-once\n(idempotence); zero similarity recovers the full sum; partial similarity interpolates\ncontinuously. This is the published answer to the corroborative channel's flank, in the exact\nformalism the strength layer already uses — and the corpus had cited these authors' *axiom*\npapers without ever meeting the similarity line.\n\n**2. Belief-function theory built the same dial for evidence fusion.** Dempster's rule assumes\ndistinct (independent) evidence and multiplies; Denœux's **cautious rule** (AIJ 2008) is the\nidempotent minimum-based combination for *overlapping* bodies of evidence; and Denœux/Pichon\nshowed both are endpoints of **infinite t-norm-based families of combination rules \"whose\nbehavior is intermediate between Dempster's rule and the cautious rule.\"** Same two poles, same\ninterpolating family (the Frank t-norms run min → product continuously).\n\n**3. Subjective logic ships the dial as a parameter.** Jøsang's **cumulative fusion** (independent\nsources; Dirichlet evidence adds) vs **averaging fusion** (fully dependent sources; idempotent),\nwith the explicit statement that \"partially dependent opinions can be fused using a combination\nof the cumulative and averaging fusion operators, but this requires an additional parameter to\ndetermine the degree of dependence.\" His **opinion fission** canonicalizes trust networks by\nsplitting a dependent path's evidence into independent portions before fusing — structurally the\nsame move as our fair-share discounting.\n\n**4. Meta-analysis is the production-grade statistical answer.** Hedges, Tipton & Johnson's\n**robust variance estimation** (Research Synthesis Methods 2010; `robumeta`, `clubSandwich`)\nhandles dependent effect sizes **without knowing the covariance structure**: assume a working\nmodel (the correlated-effects model posits one within-cluster correlation ρ — `robumeta`'s\ndefault is 0.8), get inference that stays valid under misspecification, and run sensitivity\nacross ρ instead of pretending to know it. Two transfers: a *working model plus robustness* beats\nboth ignoring dependence and claiming to know it; and defaulting ρ high is the same conservative\nposture as our necessary-default — assume dependence until someone asserts otherwise.\n\n**5. Philosophy of science supplies the warning label.** The variety-of-evidence literature\n(Bovens & Hartmann 2002/2003; Claveau 2013, who made source independence a *continuous degree*;\nLandes & Osimani 2020; Landes & Destercke 2025) proved the folk rule **false in well-defined\nBayesian settings: replication can trump variety.** When a source's *reliability* is itself being\nlearned, repeated confirmations from one source do double duty — confirming the claim AND the\nsource — and can outweigh spreading across independent sources. So \"correlated evidence is simply\nworth less\" must not be hardcoded: the honest treatment **represents the shared source\nexplicitly** and lets confirmation flow through its reliability. That is the evidence-as-subgraph\nmove — reliability is just another claim — arriving from confirmation theory.\n\n**A sixth member, from inside argumentation (the IRIT harvest, same day)**: the **Choquet\nintegral** — the aggregation function built for interacting contributors, used by Amgoud (ECAI\n2020) precisely to price synergies and redundancies among an analogical argument's supporters. A\ncapacity-weighted Choquet aggregation is the general form of which the novelty dial and fair-share\ndiscounting are special cases ([the-irit-harvest.md](the-irit-harvest.md) § 3).\n\n**The convergent design, proposed for Deliberus** (filed as design, founder-paced —\n*similarity-adjusted corroboration*): corroborative energy becomes\nΣ (σᵢ − 0.5) × novelty(i | stronger co-contributors) × 0.3, with novelty supplied by the\nsimilarity/sameness layer (the Amgoud–David adjustment function; Redundancy Freeness as its\naxiom). Fair-share discounting is its special case at full overlap; shared-source provenance\nclusters give a second, cheaper dial (count clusters, not items — the ingestion-balance\ninstrument's shape); and per the variety-of-evidence caveat, a shared source that is *known*\nshould be a node, not a discount.\n\n**Where the line gets drawn — the founder's probe, answered honestly (2026-08-31)**: today,\nnowhere — corroborative contributions still count in full; the dial is proposed, unruled. When\nbuilt, the conceptual definition of the novel part is conditional: *what establishing this\ncontribution would add, given what the stronger co-contributors already establish* (the Bayesian\nshape — the same reason the line can never be computed from the strengths alone). The value is\nSUPPLIED by a measure (the structural Amgoud–David similarity preferred, embeddings as fallback)\nand CALIBRATED by the seven-key eval's *overlaps* labels plus the friends' divergence — which is\nexactly why the eval sitting gates this design. The endpoints need no judgment (full overlap →\nfair-share; zero overlap → full count); only the middle is judged, and an error there misweights\nwithout ever merging or deleting anything.\n\n**And the merge hunch returns, vindicated one level up.** § 5d ruled the hunch unnecessary for\npadding but \"right, and genuinely needed, where addition survives.\" The reconciliation\nliterature names the mechanism precisely: not merge-as-deletion but **similarity-as-discount\ninside the aggregation** — the same similarity infrastructure the auto-merge programme is\nbuilding becomes the dependence dial's input. Improving claim-similarity does not replace the\nweakest-link arithmetic; it completes the other channel.\n\n## 9c. \"How hard can it be to never count a subgraph twice?\" — the founder's question, answered by his own invariant\n\nGrounded against the full merge corpus (the soft-canonical clustering programme and its\n2026-08-26/31 rulings), the answer has a clean shape, worked out in detail in the merge doc's new\nstrength-side addendum\n([soft-canonical-clustering-and-reversible-merge-semantics.md](soft-canonical-clustering-and-reversible-merge-semantics.md)\n§ Addendum Aug 31): double-counting decomposes into **five cases**; merge exactly solves the first\n(one proposition, two nodes); the founder's own **one-step invariant** proves merge can never\nsolve the rest (dedup below pushes all residual double-counting one edge-step up, into the\naggregation layer); and the residual cases are covered by instruments that are deterministic and\nmostly built — path-multiplicity plus fair-share (the pathological criterion is simply *more than\none path from an evidence node to one aggregation point*, computable with no model), edge\nsupersession (live), and the two proposed dials of § 9b (novelty weighting; source-as-node).\n\n**The deep dovetail**: cluster-carries-the-strength — the founder's ~2008 idea, the sameness\nladder's stage four — IS the binary point of the § 9b dial, and the merge arc's graded\narticulation vocabulary (congruent / includes / overlaps / excludes) IS the dial's scale. One\ngraded pairwise classifier feeds the merge catalogue, the containment bookkeeping (the CORE-style\nentailment check), and the novelty weights. The lazy evidence-gate review calibrates all three in\none sitting with a graded label set — REVISED same day after the founder challenged\nexhaustiveness: seven keys (same / contains, both directions / **opposes** / overlaps /\nunrelated / can't-tell), a principled coarsening of MacCartney & Manning's provably exhaustive\nseven semantic relations plus the confession key. The four-way draft had dropped the exclusion\nrelations — the empirically worst hole, since embeddings score a claim and its negation as\nnear-identical (NevIR; the 2026 cross-encoder study) and a contradiction filed as \"overlap\"\nwould feed the novelty dial with the wrong sign. Full revision: the merge doc's Aug-31 addendum\n§ 3.\n\n---\n\n**Reference list (small-print pool for the presentation)**: Klement, Mesiar & Pap, *Triangular\nNorms* (Kluwer 2000) + position paper I (Prop. 6.1) · Pollock, \"Defeasible reasoning with variable\ndegrees of justification,\" *AIJ* 133 (2001) · Prakken, \"A study of accrual of arguments,\" ICAIL\n2005 · Freeman, *Argument Structure* (Springer 2011) + \"Reply to Yu and Zenker,\" *Informal Logic*\n2023 · Yu & Zenker, *Informal Logic* 42(2) 2022 · Walton, *Argument Structure: A Pragmatic Theory*\n(1996) · Cohen, *The Probable and the Provable* (OUP 1977) · Pardo, \"The Paradoxes of Legal\nProof,\" *B.U. L. Rev.* 99 (2019) · Allen & Pardo, \"Relative Plausibility and Its Critics\" (2019) ·\nClermont, \"Death of Paradox,\" *Notre Dame L. Rev.* 88 (2013) · Tideman, \"Independence of clones,\"\n*Soc Choice Welf* 4 (1987) · Cheng & Friedman, \"Sybilproof reputation mechanisms,\" P2PEcon 2005 ·\nJiang et al., \"Core: Robust Factual Precision,\" *Findings of ACL 2025* (arXiv:2407.03572) · Peng\net al., \"SemEval-2025 Task 7,\" SemEval 2025 · Amgoud & Ben-Naim, \"Axiomatic foundations of\nacceptability semantics,\" KR 2016; Amgoud et al. 2017; Amgoud, KR 2025 · Munro, Bloch & Lesot,\narXiv:2603.06067 · Kim & Pearl 1983 (noisy-OR); Henrion 1989 (noisy-MAX); Díez & Druzdzel 2002\n(noisy-AND/MIN); Heckerman & Breese, \"Causal independence\" (1994) · Fréchet–Hoeffding bounds (Fréchet 1935; Hoeffding 1940; Nelsen, *An Introduction to Copulas*) · Good, *Probability and the Weighing of Evidence* (1950) — additive log-odds for independent evidence · Potyka, KR 2018 (QEM) ·\nNouioua & Risch (necessary support) · StealthRL (arXiv:2602.08934); \"Adversarial Paraphrasing\"\n(NeurIPS 2025) — detector-evasion transfer results · Amgoud, Bonzon, Delobelle, Doder, Konieczny\n& Maudet, \"Gradual Semantics Accounting for Similarity between Arguments,\" KR 2018; Amgoud &\nDavid, AAAI 2021 · Denœux, \"Conjunctive and disjunctive combination of belief functions induced\nby nondistinct bodies of evidence,\" *AIJ* 172 (2008); Pichon & Denœux, *JAR* 2009 (t-norm/uninorm\nfamilies between cautious and Dempster) · Jøsang, *Subjective Logic* (Springer 2016); Jøsang,\nWang & Zhang, \"Multi-source fusion in subjective logic,\" FUSION 2017; Jøsang 2009 (fission) ·\nHedges, Tipton & Johnson, \"Robust variance estimation in meta-regression with dependent effect\nsize estimates,\" *Res. Synth. Methods* 1 (2010); Pustejovsky & Tipton 2022 (working models);\nFisher & Tipton, `robumeta` · MacCartney & Manning, \"Natural logic and natural language inference\" / \"An extended model of natural logic\" (IWCS 2009) — the seven basic semantic relations · Weller et al., \"NevIR: Negation in Neural Information Retrieval\" (EACL 2024) · Bovens & Hartmann, *Bayesian Epistemology* (OUP 2003); Claveau,\n\"The independence condition in the variety-of-evidence thesis,\" *Phil. Sci.* 2013; Landes,\n*Synthese* 2021; Landes & Destercke, ISIPTA 2025.\n\nCross-references: [what-the-necessary-default-changes.md](what-the-necessary-default-changes.md)\n(plain-language layer) · [strength-layer-audit.md](strength-layer-audit.md) (the measured defects)\n· [decomposition-axes.md](decomposition-axes.md) (separability floor) ·\n[the-jhu-decomposition-line.md](the-jhu-decomposition-line.md) (CORE's gaming finding first\nentered the corpus here) ·\n[soft-canonical-clustering-and-reversible-merge-semantics.md](soft-canonical-clustering-and-reversible-merge-semantics.md)\n(the merge programme the hunch belongs to) ·\n[fractal-scales-and-temporal-frame.md](fractal-scales-and-temporal-frame.md) (payoff-removal\nbefore detection; adversary classes) · `deliberus/support_semantics.py`, `deliberus/graph/qbaf.py`\n(implementation).\n\n## 9d. The deflation mirror — what the weakest-part rule makes cheap in the OTHER direction (2026-09-02, founder question)\n\nFounder: *\"the irreplaceable human value and action also still definitely makes them able to game\nand manipulate the system, right? Unless the similarity sensitivity and auto merge can somehow\ndefeat any human saboteurs.\"*\n\n**Yes, and the shape is exact.** Min removed the payoff on *adding parts to inflate*; by the same\narithmetic it created a payoff on *asserting requirements to deflate*. The honest move — *\"this\nclaim also requires X, and nobody has established X\"* — and the saboteur's — *\"this claim requires\nthat the moon is cheese\"* — are one operation: mint a required part at 0.5 and the whole is capped\nat 0.5. ~~And the entailment check cannot tell them apart, because a genuinely missing consideration\nis by definition NOT derivable from the parent's sentence~~ — **withdrawn 2026-09-02 on founder\nchallenge and tested against thirteen real arguments\n([derivability-of-missing-considerations.md](derivability-of-missing-considerations.md)): a missing\nconsideration is not derivable from the sentence ALONE, but almost every one is derivable from the\nsentence plus meaning, scheme critical questions, domain knowledge and known lenses — 0 of 47\ngraded considerations were corpus-absent; the corpus-absent residue was evidence (stake\ntestimony), not considerations.** So the sort below is rewritten around the *derivable requirement\nspace*, not sentence entailment. This is the payoff-relocation question\n([fractal-scales-and-temporal-frame.md](fractal-scales-and-temporal-frame.md) § fair meiosis)\nfiring on the ruling that prompted it: *what still pays* is asserting a requirement; *is that\nexactly the behaviour we want?* — only when the requirement is argued.\n\n**Where it stands in the shipped code (verified 2026-09-02).** The hard ceiling\n(`necessary_ceiling`) reads only EXPLICITLY tagged `necessary` children, and **nothing in the\ncodebase writes that tag yet** — no endpoint, no UX control, no backfill has run (`rg\nsupport_semantics` outside tests finds only `qbaf.py` and `hinge.py`, both readers). An untagged\nspurious child joins the min-energy group instead, where it removes at most the whisper (three\nparts at 0.9 → 0.507 falls back to 0.500). So the deflation door is closed today **by accident** —\na guard that holds only because nothing sets the property — and it opens the day the backfill pass\nor a tag control ships. Coverage-gated lifting raises the stakes further: the more a verified\ndecomposition lifts its parent, the more a spurious part can take away.\n\n**Why merge and similarity do not defend.** They catch *redundancy-shaped* gaming — cloning, thin\nslicing, paraphrased duplicates; the Amgoud–David novelty discount (§ 9b) is built for exactly that\nfamily. A spurious requirement is *novelty-shaped*: new content, nothing to merge with, no\nsimilarity to discount. Different attack family, different defense — and strategy-class, where the\ncorpus's own rule is payoff-removal before detection and no instrument here has yet met a motivated\nstakeholder.\n\n**The defense that fits the blessed rulings** (no verdict acts; contributions argue for themselves;\nbare judgments are telemetry): **a necessity assertion is itself a claim, carries its own strength,\nand the cap applies through that strength.** Sorting rule, machine-runnable (corrected 2026-09-02):\na required part **inside the parent's derivable requirement space** — literal content, conceptual\nrequirements, the scheme's critical questions, domain preconditions, known alternative frames\n(rungs 0–4 of the ladder in the derivability doc) — is one the machine could pre-populate for\n*every* claim uniformly as a latent potential, so asserting it selectively earns nothing: the\nscrutiny was already there for everyone, which is payoff removal on the deflation attack in the\nsame shape min was on the inflation attack. A required part **outside** that space (rung 5, the\ngenuinely corpus-absent) is a *proposed requirement*: it caps nothing until its necessity is\nargued — a claim *\"W requires X\"* with support — and then caps in proportion to that argument's\nstrength, which an opponent can attack. The saboteur's *moon is cheese* fails the derivability\njudge under every rung; a plausible spurious requirement passes it and is thereby simply a\nlegitimate critical question anyone could have asked. The saboteur's move is thereby converted into an evidence-object (the Jagged-Judges shape:\nchallenges become record objects), and the honest contributor pays only the cost of saying why the\nconsideration is required, which is the cost the graph already charges for everything else.\nResidue stated honestly: the persistence asymmetry stays (asserting is cheaper than rebutting),\nsybil and source-independence remain undefended at every layer, and a well-argued spurious\nrequirement is simply a good argument that needs answering — which is the system working.\n\n**BUILT 2026-09-17** (founder: *\"Build the designed completion.\"*), in the form the derivability doc § 4 corrected it to — the cap counts by *relevance strength*, never by mere existence. `support_semantics.requirement_weight` gives each part a weight in [0, 1] that scales the weakest-part cap (`1 − w·(1 − part)`): an explicit `necessary` tag is the operator's word (1.0); a confirmed part — cut from the source, or by a person, or a ratified machine link — is *presumed* required at a modest, rebuttable 0.5; an unconfirmed machine proposal presumes nothing (0.0). Arguing tightens: `POST /claims/{id}/parts/{part}/requirement` mints an ordinary attackable claim *\"W requires X: …\"* (linked `ARGUES_REQUIREMENT`, pointer on the decomposition edge, never overwritten), and the part's weight follows that claim's own computed strength — at or above neutral it can only raise the weight, reaching the full cap at 1.0; below neutral the \"not applicable\" answer has won and the cap closes. The hinge and the slicing study mirror the same weight, and the badge query now names its non-propagating types (`REPORTS`, `CLASSIFIES_TERMINUS`, `ARGUES_REQUIREMENT`) instead of relying on their edges carrying no scheme. Measured on the live graph the day it shipped: 10 of 87 decomposed mothers carry a cap and **0 change strength**, because a presumed cap of 0.5 bites only a whole reading above ≈ 0.54 and today's wholes sit at or below neutral with their questions unanswered — the mechanism is live for the day strengths move, and the two slicing-sensitive claims keep their sensitivity honestly (the flip filing is the fully-required reading). The presumed weights are de-baked constants, changeable by ruling.\n\n**Consequence for the whisper decision (§ 7): the lift and the cap share one gate.** Entailed\nparts get the full weakest-part treatment both ways, with a raised — never total — up-weight once\ncoverage passes (Popper's asymmetry: one failing part refutes regardless of completeness;\nestablished parts confirm only under closure, and confirmation holism leaves unstated auxiliaries\nno sentence-level check can see). Non-entailed required parts get no automatic cap and a\nstrength-weighted cap once argued. One rule, not two — and it is what makes coverage-gated lifting\nsafe to ship.\n\n## 9e. How attack-proof is the requirement cap? — the founder's reception, and the first honest answer (2026-09-19)\n\n**The founder, on the shipped cap** (verbatim): *\"Well, ideally the RELEVANCE (which I guess all this\nis about) is judged provisionally by the machine/LLM-passes or whatever and then humans can challenge\nit but I'm wary of saboteurs/spammers adding bogus parts that aren't actually relevant. I'm open to\nmaking the relevance claims explicit like you say, but I wonder how foolproof / attack-proof this way\nof dealing with this issue is, we'll have to explore that going forward I guess. But we will make do\nwith what we've settled now on this issue.\"*\n\n**What that settles, and what it does not.** The cap as built stays (*\"we will make do with what\nwe've settled now\"*). His direction for where it should go is one step past what shipped: **the\nmachine judges relevance first, provisionally, and people challenge that judgment.** His question —\nhow attack-proof is it — is open. What follows is Claude's first pass at it, unruled.\n\n### In plain words: what is built\n\nTake *\"Dr Smith is a credible expert\"*, split into *she has published*, *she holds a post*, *her field\nmatches*. *Weakest part decides* means the whole can look no stronger than its weakest part, like a\nchain. The danger: anyone could add a bogus part (*\"she must own a boat\"*), leave it unsupported, and\nsink the whole. So each part limits the whole only as firmly as it has been shown that the whole\nreally **needs** that part:\n\n- a part cut from the source text, or added by a person, is *presumed* half-needed (weight 0.5);\n- a link a machine merely proposed, which nobody confirmed, limits nothing (weight 0);\n- anyone can write the need down as its own claim — *\"credibility requires her field to match,\n  because …\"* — and the limit then follows how well **that** claim holds up: well supported, it bites\n  fully, chain-style; shown to be bogus, it stops limiting at all.\n\n### The exposure that remains, computed from the shipped function\n\n`necessary_ceiling` gives a whole's ceiling as `1 − weight × (1 − part strength)`. For a part a\nperson added (weight 0.5):\n\n| The bogus part is … | Its strength | The whole's ceiling |\n|---|---|---|\n| added and left alone (nobody has looked) | 0.5 | **0.75** |\n| added, then argued down | 0.1 | **0.55** |\n| added, then fully refuted | 0.0 | **0.50** |\n\nSo **one cheap move — adding an irrelevant part — takes any claim out of the green band** (green\nstarts at 0.8), and a little more effort pins it near neutral, until somebody answers with a\n*not required* argument that wins. The attacker's move costs one contribution; the defender's\ncosts an argument. **That is not attack-proof. It needs a defender to show up.**\n\nThree more doors, stated so nobody has to rediscover them:\n\n1. **Propped-up requirements.** A requirement claim's strength is computed from its own supports\n   and attacks, like any claim, so several accounts supporting a spurious requirement push its\n   weight toward 1 and the bogus part then sinks the whole completely. This is the known\n   weakness — *the strength layer is an aggregate and is brigadeable* — arriving through a new door.\n   Nothing at any layer defends against many accounts acting as one.\n2. **The mirror: closing a cap that should stay.** Whoever wants a weak claim to look strong can\n   attack every *legitimate* requirement claim. An argued requirement that falls below neutral drops\n   to weight 0, which is **below** the presumed 0.5, so a won rebuttal removes the limit entirely.\n3. **What already blunts both.** A drive-by attack or support moves nothing: an edge whose own\n   critical questions are unanswered computes to 0.5 and contributes exactly zero, and an\n   unexamined requirement claim leaves the presumed weight in place. Only *examined* argument moves\n   a requirement. The one move that works with no examination at all is the first table above:\n   the presumed 0.5 on a person-added part.\n\n### The next design step his direction points at (proposed, unbuilt, unruled)\n\n**Replace the flat presumption on person-added parts with a machine relevance proposal.** A\npropose-only pass reads the whole and the part and proposes how much the whole needs it, with its\nreasoning stored beside the number (the same shape as the horizon classifier: a proposal shown\nbeside the computed value, never silently the value). *\"She must own a boat\"* starts near 0, so\nadding it pays nothing. To make a bogus part bite, the attacker now has to **argue** the requirement\nand win — which moves the cost onto the attacker. That is the payoff-removal shape the threat model\nasks for before any detector (`fractal-scales-and-temporal-frame.md` § Three classes of adversary):\nadding irrelevant parts stops paying, so there is nothing to detect. Adding a *relevant* weak part\nstill bites, and should: that is criticism, which is the system working.\n\nCautions that ride with it: the judge and the extractor share a model family (same-hand bias), so a\nsecond family is the better judge; the pass needs an *undecided* answer that falls back to the modest\npresumption, never a forced guess; a plausible spurious requirement will fool it sometimes, and then\nit is an ordinary argument that needs answering; and the first register it meets will break its\ncategories (the three-runs law). None of this touches many-accounts-as-one, which stays undefended.\n\n**State**: the cap is live in production (deployed 2026-09-19) and accepted for now. Attack-proofness is an open\nexploration — `TODO.md` § the weakest-link decision stack, item 6; ledger row O13.\n"}