Certification, Not Search: Deployment-Time Model Sharing under Hard Per-Cell Risk Contracts
Abstract
Deployment under hard per-cell risk contracts must decide which trained predictors to store, which cells may share them, and when local fallback is required, while minimizing serialized model, payload, and routing cost. Existing procedures commit to a sharing structure during training: multi-task models fix parameter sharing, mixture-of-experts learns routing, and clustering fixes partitions before deployment. Deployment still requires a separate decision: whether a sharing structure can be certified against a per-cell risk budget from the calibration data actually available. We propose Certified Shared Decoder Selection (CSDS), a deployment-time framework that builds a finite candidate portfolio, certifies every cell–action pair from calibration data, and selects the shared subset and the per-cell assignment minimizing a declared additive coding-cost proxy over the certified action set. Because the contract is cell-separable, certifying the individual cell–action pairs certifies every deployment plan simultaneously. This property of the contract, rather than of the testing procedure, is what makes a deployment portfolio certifiable at all: testing the plan family directly yields a bound looser than the entire risk budget, certifying nothing. Experiments on five 30-seed tabular contract settings, predictor-family controls, and a four-domain transformer-adapter deployment show that CSDS reduces deployment cost against both all-local deployment and a calibration-tuned clustered router, with no observed contract violation. Matched controls that hold the candidate set and the fitted predictors fixed identify certification, not subset search, as the scarce resource, while the certificate family and its failure-budget allocation remain live deployment decisions. Code is provided in the supplementary material.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.