A 256-Token Memory Summary Solves 0-2 of 16 Delegation-Revocation Cases That a Live Query Solves 15-16 Times
ResidualAuth proves two authorization histories can share identical current permissions and identical all-pairs reachability yet demand opposite decisions after the same direct-edge revocation, and formalizes the residual authorization state needed to tell them apart, showing exponentially many future-distinct states can share one transitive closure. Across four open-weight models a fixed 256-token summary solved 0-2 of 16 paired episodes and sham reads solved 0 of 16, while authenticated current-query reads solved 15-16 of 16. In a held-out online-memory diagnostic, exact ledger serializations fit all 128 four-coordinate pairs at both 768 and 1,024 tokens, whereas factually supported model-written memories solved at most 1 of 128 per model, and a hard gate reduced eight observed unauthorized effects to zero.
↳ Follow the thread