Preprint
Article

This version is not peer-reviewed.

Adversarial Evidence-Plane Robustness for Bounded Agent Assurance:Deterministic Mutation Testing of Claim Admissibility

Submitted:

07 September 2026

Posted:

08 September 2026

You are already at the latest version

Abstract
Assurance for autonomous agents depends on operational evidence about policy decisions, actions, execution, effects, provenance, and enforcement. This study tests whether bounded assurance claims remain semantically admissible when that evidence is adversarially degraded. Three co-primary questions address deviation existence (B1), observable action-path reconstruction (B2), and containment/enforcement-boundary localization (B3). A deterministic mutation harness applied 14 frozen single-operator evidence-plane attacks to three known-ground-truth baselines, producing 42 adversarial cases and 126 claim evaluations. A prospectively frozen strongest-safe oracle and closed-world semantic scorer classified the 126 claim evaluations into three predefined categories: exact safe, safe conservative, and unsafe false establishment. All 42 cases were valid. Of the 126 claim evaluations, 56 were exact safe, 47 safe conservative, and 23 unsafe false establishment. The resulting Unsafe False Establishment Rate (UFER) was 23/126 = 0.18254, so the pre-specified zero-UFER target failed. Unsafe outcomes were B1 3/42, B2 19/42, and B3 1/42. Exploratory forensics classified 21 unsafe evaluations as substantive semantic incompatibilities and two as possible scorer-normalization artifacts. The dominant B2 mechanism was global ineligibility after localized evidentiary degradation. These results distinguish semantic safety from information retention: evidence defects must not induce propositions beyond the boundary justified by surviving admissible evidence.
Keywords: 
;  ;  ;  ;  ;  ;  ;  ;  ;  
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.