Forgetting
When “this state provably no longer contains
X” is a designable property of a system that still works: one
object grading how thoroughly a state forgets, what keeping the system
working costs that grade, and where robust forgetting stops being
purchasable at all.
The systems here are small grown worlds. A state is a positive
integer, a move multiplies it by a member of that state's
menu — the moves the state admits — and a route is the
sequence of moves from the start state 1, its product being the state it
ends at. A world is read at a temperature β: a move
m is taken with probability proportional to
m−β, normalized by the state's
normalizer, the sum of m−β over its
menu. A route's probability is then the product of its moves' weights
divided by the product of the normalizers it passed through — and since
the moves' product is the endpoint, two routes reaching one endpoint
differ only in those interior normalizers. Everything about which
route was taken lives in what the intermediate states could have done
otherwise.
Three worlds carry the census — an exhaustive fiber-by-fiber read,
exact throughout. The depth column takes the
constant menu {2, 3} at every state; plain breadth takes the
squarefree moves 2..30 coprime to the state; and the tuned
amnesiac is a hand-built world — menu 1 → {2, 3}, 2 → {3, 5, 15},
3 → {2, 10} — whose menus were solved to make one endpoint's routes
equiprobable at a named temperature
(the one-way design). A world
free to reuse a prime it already holds recycles; one every move of
which is coprime to the state it acts on cannot.
The certificate's data is three things and a family. A forgotten
datum X, any function of history — the route itself, the first
move, the multiset of moves. A state map Φ, carrying a
history to the still-working present. The weight family, here the
temperatures. The fiber of a state is the set of histories
Φ sends to it, and the posterior of X there is its
conditional distribution on that fiber. What a state keeps is what
Φ keeps — the dated endpoint, the value reached together
with the number of moves, or the age alone.
The certificate
The four grades and
their two witnesses rule
What a state map forgets is graded at one of four grades,
increasing in strength; a certificate for X at Φ is a
witness at one of the three above the lowest. R, readable: X is a
function of Φ, and there is no certificate. P,
possibilistic: every fiber meets at least two X-classes, so
X is not recoverable as a value; the strongest witness for it is
a state-side factoring, a presented split of the history space
into X and a remainder with Φ constant in the X
slot, which needs no weight at all. T, tuned-flat: at one named
temperature the posterior of X is uniform on every fiber's
consistent values. S, robust-flat: uniform at every weight in
the family. Flatness is fiber-uniformity — maximum entropy
behind what the living state logically pins, and never
posterior = prior, since a grown world's state is its present and so
always informs its past possibilistically. It upgrades to
posterior = prior for every prior exactly where the split carries the
WEIGHTS with it, which is the inheritance lemma below.
Grade S is bought two ways, and the two forgetting specimens here
sit there by different witnesses — they differ in which lemma applies,
not in how they are built. Inheritance: where the history space splits
as X against a remainder, with X's prior weight-free and
Φ reading only the remainder, the posterior of X equals
its prior at every state and every weight, with no tuning.
Destination
universality is grade S by that witness: the adapted reader's state
is a function of its metabolism — the resources it is given to
spend — and never of the data it is shown, which is the factoring.
Weight-side symmetry: where the multiset of interior
normalizers agrees along every route of a fiber, the route posterior is
uniform at every β — route weight is proportional to the product
of the reciprocals of those normalizers, and equal multisets have equal
products. The depth column is grade S by that witness, every normalizer
in it being the same polynomial. A third lemma collapses the obvious
alternative to a witness: a quotient through which Φ factors,
each of whose classes meets every X-class, exists if and only if
every Φ-fiber meets every X-class. So “factors
through a quotient killing X” is extensionally the
FULL-SPREAD case of the possibilistic grade — every fiber meeting every
class rather than merely two — and a split witness adds provenance
rather than extension.
Scope. The three lemmas proved, scope-free.
The grading is an observation exhaustive at the census scope — 406
fibers, the depth column read to age 5, breadth to age 3 and the
tuned world to age 2, across
β ∈ {1, 2, 3}, exact in rationals throughout — and the four
grades land whole, with zero fibers they cannot express. The counts
land R 3 and T 2 in the tuned world, R 10 and S 10 in the depth
column, R 18 and P 363 in breadth. The destination-universality row
enters by inheritance together with the factoring measured on the
reader side, which holds under every loss that reads only what the
reader has committed to and
fails outside that family.
verifier:
explore_forgetting_certificate.py
The two clauses are
independent observation
A certificate carries a structural clause — is there a witness? —
and a measure clause — is the posterior flat? Neither implies the
other, and both crossings print. Structural kill without
flatness: at all 363 of breadth's multi-route fibers the state
factors through the quotient that remembers which moves were made and
not the order they came in, so the ORDER is possibilistically dead at
every one of them — and the posterior still reads that order through
the normalizers at β = 1. Flatness
without any structural witness: the tuned world's endpoint 6 at age
2 is flat at β = 1 with the witness absent, which is the
signature of tuning — it buys one temperature and no more, and the
census separates tuned from structural flatness by inspection. What a
world forgets is also fiber-local: that same
tuned world hides the ORDER at endpoint 6 and hides the move SET at
endpoint 30 ({2, 15} against {3, 10}, each admitting exactly one
order).
Scope. Exhaustive at the census scope above.
The crossing in the remaining direction — robust flatness with no
witness — occurs at no fiber here, and whether it can occur at all is
the obstruction the coprimality dichotomy below settles.
verifier:
explore_forgetting_certificate.py
The count
leak rule
A certificate for X does not descend to functions of
X. Take the depth column, which is route-uniform at every
temperature with the weight-side witness present — perfect symmetry,
the strongest grade there is. The posterior of the FIRST MOVE at
the endpoint 2a3b is nonetheless
exactly (a/(a+b),
b/(a+b)) — independent of β, and a leak.
Route-uniformity does not coarsen to feature-uniformity, because a
uniform posterior counted over unequal coarse classes is not uniform.
Two leak channels: the WEIGHT leak, where the measure
itself is asymmetric, and the COUNT leak, where only the geometry of
the fiber is. Every coarsening needs its own flatness clause.
Scope. The
a/(a+b) law proved for the two-move constant menu
— equal route weights with binomial fiber counting — and verified at
every mixed fiber to age 5; other menus were not scanned. The
two-channel reading is an observation.
verifier:
explore_forgetting_certificate.py
Forgetting while the system still works
A still-working system must RETAIN a required function g of
its history while certifying that it no longer holds X. Φ
computes g exactly when g factors through Φ —
equivalently, when Φ's partition of the history space refines
g's — so the admissible state maps are exactly the interval from
g to the partition into single histories, and the question is
whether that interval holds a partition that is spread (every
block meets at least two X-classes) and flat — a cure. It
decomposes fiber by fiber, and the price of a cure is the number
of blocks it takes, summed over fibers. Where X is a function of g
there is nothing to design: the state is readable.
Refinement never
cures, coarsening exposes rule
Two-class conservation. On a g-fiber carrying exactly
two X-classes, of masses m₁ and m₂, every spread
block holds both classes and flatness forces their two masses equal
inside each block; summing over blocks gives m₁ = m₂. So
a two-class fiber is curable only where Φ = g is already
flat: refinement never cures a two-class leak. The count leak is
therefore not merely undescended but UNREMOVABLE while the dated
endpoint is retained — deleting a record's attribute while keeping the
record runs into a parity-style obstruction that no state design
crosses.
The numerator effect. Retention is not monotone the way
admissibility is. Conditioning on a dated endpoint cancels the move
weights in the numerator, the moves' product being the endpoint itself;
conditioning on the AGE alone surfaces them. In the depth column the
posterior of first move 2 at an age fiber is exactly
3β/(2β + 3β) —
3/5 at β = 1 — a strict majority at every temperature, and a
mass majority is partition-free, so every age fiber leaks whatever
state map is built over it. A coarser retained function admits MORE
state maps and certifies FEWER: retaining less exposes more.
Scope. Two-class conservation proved. The
numerator effect's mechanism is proved and its instances measured at
scope: in the depth column with the dated endpoint retained and
X the first move, every fiber whose two exponents differ leaks
(8 of 20), the equal-exponent ones cure at price 1 and the pure powers
are readable, while coarsening to the age alone converts route-uniform
fibers into majority-readable ones — the same reversal holding in the
tuned world. Where the majority test passes and the individual weight
ties a cure would need do exist, no cure assembles at ages 2 or 3
either, so the effect is not a majority artifact.
verifier:
explore_working_amnesiac.py
The no-majority
criterion criterion
On a uniform-weight g-fiber whose X-class counts are
c₁ ≥ ⋯ ≥ cr totalling N, a
spread flat partition exists if and only if
c₁ ≤ N − c₁ — if and only if no class holds a
strict majority. Necessity survives the weighted case as a
MASS-majority test, which is partition-free and therefore runs at any
fiber size, however far past exhaustive search. Sufficiency is exact
subset-mass matching and is NOT claimed weighted, and the distance
between the two is where the real price sits: with unequal weights,
all 118 searchable non-majority breadth fibers fail to cure. In
uniform-weight fibers necessity IS sufficiency; the gap between them
is exactly the exact-subset-sum structure of the weight family.
Scope. Proved at uniform-weight scope, and
cross-validated against exhaustive partition search — capped at 8
routes per fiber — on all 49 uniform fibers inside that cap, with zero
mismatches. The matching-gap count is an observation at the census
scope above.
verifier:
explore_working_amnesiac.py
The strict amnesiac
and the tie desert observation
What the three laws above price is curability; what they leave open is
whether refinement ever STRICTLY beats the coarsest working state. It
does, rarely, and cheaply. In the depth column with the dated
endpoint retained and X the first TWO moves, five fibers cure
STRICTLY: the coarsest working state Φ = g leaks, and a
refinement of it is spread and flat at every temperature. The specimen
is class counts (2, 1, 1) with baseline posterior (½, ¼, ¼), cured at
price 2 by pairing the two singletons. Partition design alone buys a
robust certificate the coarse state does not have — and the ties it
rides need not be symmetric: a designed recycled-prime world whose
one fiber holds two tie classes at different products has a leaking
coarse state cured strictly by pairing at every temperature. But it
is confined to worlds carrying exact weight ties, and plain breadth
is a TIE DESERT: across all its multi-route fibers to age 4 — 363 at
ages up to 3 and 441 one age deeper — the interior-normalizer
product is INJECTIVE: not one pair of routes carries equal products
at β = 1, so no pair ties across all temperatures at once,
and no working state hides the route anywhere in it. For X
the first move, of the 291 fibers inside the search cap 173 die by
mass majority and 118 pass necessity but admit no exact-tie
partition, and none cures. Partition design manufactured no tie
anywhere it was searched, and where a certificate does turn up it is
a symmetry, a tuning — one temperature only — or a recycled-prime
menu design supplying the ties.
Scope. Exhaustive at the census scope above —
the tie scan run one age deeper in breadth, the 441 age-4 fibers —
exact in rationals, the partition search capped at 8 routes per fiber.
The
72 breadth fibers above that cap carry no all-temperature mass
majority — the partition-free test runs at any size — so they stay
genuinely open rather than decidably leaking. At every temperature
at once the desert is proved — the coprimality dichotomy
below bars any all-temperature tie in breadth at any age; at a
single temperature it is a measurement, injective through age 4 and
unsearched beyond.
verifiers:
explore_working_amnesiac.py,
explore_tie_world.py
What robust forgetting costs
That leaves the obstruction the certificate opened: does robust
flatness FORCE a structural witness? It is a factoriality question about
the normalizers. Two routes flat at every temperature means their
interior-normalizer PRODUCTS agree as functions of β; a
weight-side witness means the two MULTISETS agree. So the question is
whether equal products force equal factors — and it settles both ways,
on one axis, and the axis is coprimality. A world free to recycle its
own primes can close a two-route fiber flat at every temperature with
distinct multisets, so robust flatness does not force the witness. In a
coprime world no dated multi-route fiber is flat at every temperature at
any age, so there the answer is yes, vacuously — no multi-route fiber is
flat for the question to test. Both halves, and the dichotomy they
make — the coprimality dichotomy — are
the one-way design. That
leaves how WIDE the recycling door is, which is a question about the
normalizers alone.
Retention is what prices the certificate. Two-class conservation
freezes the count leak, the no-majority criterion prices what is left,
and the numerator effect shows that a certificate is not monotone in
what is kept — a system holding less of its own history does not thereby
forget more of it. And the boundary of robust forgetting is not age but
prime recycling: a world whose menus never
reuse its own primes cannot help writing its history into its weights.
Read as a deletion guarantee — a record removed under a certificate
rather than under a retraining story — the price line is that certified
forgetting costs prime recycling, and that certifying the erasure of a
record never certifies the erasure of its attributes.
How much room that door leaves is the one question the price line does
not answer, and it is a question about unique factorization: two routes
flat at every β means equal PRODUCTS of interior normalizers,
while a structural witness would mean equal MULTISETS, so the door's
width is the gap between the two.
Menu collisions carries it, from
collisions so generic that almost none of them is a failure of
factorization at all down to a bound on how far a genuine failure can
escape one variable.
The worlds turned outward
Because every posterior above is an exact
rational, these worlds also serve as a measuring instrument for tools
that estimate such a posterior from samples. Two published
deletion audits were scored that way, and both state a certainty that
outruns the accuracy behind it — one a band that narrows with data
while its coverage stays where it was, the other a probability more
extreme than its exact posterior over a majority of the audited mass, a
miss more data concentrates rather than cures. The first of the two also
returns, in two
replicates in five at the size its own paper calls converged, a number
its equation has no solution for, and says nothing. One scalar in the
tool's own coefficients decides that, and the same scalar cut at a
different level decides whether the
verdict lands on the wrong side of the midpoint — which is the one
thing an auditor holding no truth can price about their own number, and
the price is measured there too.
Deletion audits carries all of it.