AI & Computingpreprint2026-08-07

What Two Gates Buy You: Selective-Risk Guarantees and the Non-Identifiability of Abstention Cascades — Product Laws, Error Diversity, and Why Unlabeled Logs Can Certify Coverage but Never Risk

Open access10 citations

Abstract

Production retrieval-augmented systems increasingly abstain through *cascades* of heterogeneous gates — a cheap mechanical check before the model call, a content-aware rule inside it. What does the second gate actually buy, when does gate ordering matter, and what can be certified from the logs such a system keeps? We give a complete elementary analysis of the two-gate abstention cascade.【proved】(i) Residual bad-answer mass factorizes exactly as β₁·(θβ₂)·p_bad, where θ measures error dependence between gates on bad queries; conditional independence (θ = 1) yields the product law, and a dependence cap θ ≤ θ̄ yields a distribution-robust guarantee (Theorem 1). (ii) Selective risk splits cleanly into a numerator governed solely by miss rates and dependence and a denominator loss governed solely by friction: blocking good queries never reduces residual bad mass, it only shrinks the answered set (Theorem 2). (iii) The marginal value of the second gate is its *error diversity* net of its friction: adding it multiplies residual bad mass by θβ₂ and good coverage by 1 − α₂|₁, so — under a non-degeneracy hypothesis (the single-gate system answers some bad and some good mass, and gate 2 passes some good queries) — residual mass improves iff θβ₂ < 1 but selective risk improves iff θβ₂ < 1 − α₂|₁; a cascade of two individually weak but differently-fooled gates beats one strong gate, while a second gate whose errors are determined by the first (θβ₂ = 1) leaves residual mass unchanged and is *strictly harmful* to selective risk whenever it adds any friction (Theorem 3). (iv) Risk is ordering-invariant; gate order is a pure cost decision, and cheap-gate-first is essentially always cost-optimal (Proposition 4). (v) From production logs recording only pass/block and answer/abstain events, coverage is identifiable but selective risk is not: we exhibit two parameter settings with identical observable aggregates (coverage 0.738, stage pass rates 0.84 and 123/140) whose true selective risks differ exactly tenfold (1/82 vs 5/41) — verified by simulation (Proposition 5). All closed-form equalities of Theorems 1(a) and 2 are Monte Carlo-verified over a 1,440-cell frozen grid (max |empirical − formula| ≤ 3.8 × 10⁻³ at 200,000 draws/cell, within binomial noise). We map the model onto the tokyo-insight civic-RAG engine's shipped two-gate architecture (with file-level provenance), report *no* empirical abstain or risk rates — none exist, and we state why — and convert Proposition 5 into a concrete audit specification: exactly what a labeled sample must record before any deployed cascade may claim a selective-risk number. Theory paper T6 of the MOBIUS 2026-08 theory series (six papers, T1–T6). Version 0.1, deposited as a preprint; journal submission of a revised version is planned, and the journal version may differ. AI co-observer: Claude Fable 5 (Anthropic), working method only; the registered author is the human author alone.

// Source

View paper (DOI)Open access versionOpenAlexZenodo (CERN European Organization for Nuclear Research)Published 2026-08-07

Authors: Toeda Taiko

Institutions: Yulius