acceptodds
Under review as a conference paper at ICLR 2027

Deployment Risk Control for Sequential Prediction Systems

Abstract

Deployed prediction systems are maintained while they serve: operators recalibrate thresholds, repair inputs, switch to backups, or abstain, often on the system's own feedback. Yet the available controllers certify pieces of this loop — a coverage recursion, a change detector, a single gate — and no unit of accountability spans the interventions, the outputs they serve, and the decisions they drive. We show that deployment risk control is invariance control of one scalar: the running risk-budget balance. Formalizing deployment as a sequential intervention process (SIP), we prove a characterization: a controller is budget-compliant on every trajectory iff it confines this scalar to an invariant interval, iff exponential transforms of the balance are universal-null e-processes; at the boundaries compliance forces the controller's action, so all design freedom lives strictly inside. A constructive two-ledger theorem achieves the invariant: a deterministic ledger keeps the booked risk proxy within of budget on every trajectory, and an intervention ledger bounds interventions fired while their nulls hold, uniformly over stopping times. A certified bridge carries the same ledgers to decision losses, and a gated meta-policy selects among the controllers themselves under one composite anytime-valid budget. We recover ACI, conformal PID, and online CRC as special cases. Under injected degradation on six real streams, the unified policy holds the booked budget at – smaller width than NexCP, the only one of three external baselines that also holds it there; replaying the CDC FluSight and COVID-19 hubs end to end, the certified answer was restraint.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.