为医疗数据互通设计安全边界接口,用数学方法控制模型输出准入
Logit-Boundary Geometric Belief Interfaces and Sparse Sheaf-Enclave Protocols: A Self-Contained Substrate for Secure Network Electronic Health Record (EHR) Interoperability
- 以逻辑值边界定义模型输出的可接受范围,决定是否通过、审查或隔离
- 40亿参数模型在测试中全部被拒,369次因解析失败,399次因格式不符
- 适合关注医疗系统安全边界与大模型可信交互的研究者使用
医疗数据互通是边界问题:旧系统、生成模型、术语服务、身份体系和人工审核各自具有丰富内部状态,但实际交换需依赖类型化声明、有限不确定性、溯源信息及明确接受或拒绝。本文提出一种数学与工程结合的接口架构。核心思想是逻辑值边界:模型可提出局部分类的预阈值分数,但确定性判断基底决定该提案是否可接受、需审查或必须隔离,再进行FHIR交易。由此构建的几何信念接口(GBI)融合有限边界语义、局部狄利克雷证据、细胞层叠与映射锥诊断、咨询式几何审计图,以及去中心化加密层叠-密室(DCSE)协议草图,实现故障闭合部署。该框架不宣称临床真相、全局对齐或端到端安全,仅定义模型与系统间证书生成的校验机制。配套冻结合成基准GBI BoundaryBench v0.1评估Qwen3-4B-Instruct-2507在256个保留任务上三种证据模式下的表现(共768次执行)。所有执行完成,但无一通过基准合约:369次在安全解析阶段被拒,399次在模式验证阶段被拒,覆盖率零,结果为确定性隔离。此实证结果刻意局限——仅一个40亿参数开源模型在单一冻结接口下表现——旨在揭示准入边界特性,非泛化至LLM能力或临床安全。附录采用Julia语言验证数值证书,使用标准库。
原文摘要 · Abstract (English)
Electronic health-record interoperability is a boundary problem: legacy systems, generative models, terminology services, identity systems, and human reviewers may each expose rich internal states, while operational exchange requires a narrow shared interface of typed claims, bounded uncertainty, provenance, and explicit admission or abstention. This paper details a mathematical and engineering architecture for that interface. The organizing idea is the logit boundary: a discovery model may propose pre-threshold scores over a local categorical decision, but a deterministic judgment substrate decides whether the proposal is admissible, requires review, or must be quarantined before any Fast Healthcare Interoperability Resources (FHIR) transaction is constructed. The resulting Geometric Belief Interface (GBI) combines finite boundary semantics, local Dirichlet evidence, cellular-sheaf and mapping-cone diagnostics, advisory geometric audit charts, and a Decentralized Cryptographic Sheaf-Enclave (DCSE) protocol sketch for fail-closed deployment. The framework does not establish clinical truth, global representation alignment, or end-to-end safety; it defines certificate-producing checks at a model-to-system boundary. A companion frozen synthetic benchmark, GBI BoundaryBench v0.1, evaluated Qwen3-4B-Instruct-2507 on 256 held-out tasks across three evidence modes (768 canonical executions). All executions completed, but none produced an output accepted by the benchmark contract: 369 were rejected during safe parsing and 399 during schema validation, yielding zero coverage and deterministic quarantine. This empirical result is deliberately narrow - one 4B open-weight model under one frozen interface - and is reported as evidence about the admission boundary, not as a general claim about LLM capability or clinical safety. A Julia appendix verifies numerical certificates using standard libraries.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。