acceptodds
Under review as a conference paper at ICLR 2027

Protocol-Certified Workflow Search for Cellular Perturbation-Response Prediction

Abstract

Language model agents now automate the whole modelling pipeline for cellular perturbation response, selecting among candidate workflows by a single validation score. We argue that this score is the wrong contract, because the protocol violations that matter most in this domain all *raise* it: leaking held out rows into selection, fitting normalization on the full corpus, admitting post treatment measurements as inputs, exploiting plate identity under a plate based split, selecting responsive genes with the model's own output, or requerying validation until the last edit looks good. None of these raises an exception, and validity is a property of the dependence structure among artifacts rather than of any single statement: execution feedback observes only crashes, and a local assertion observes only one statement, so neither reaches them. A search rewarded by that score therefore has a structural incentive to find them, and our audit confirms it: across nine violation categories the worst offender is not a weak agent but our own closed loop scaffold with certification disabled, at a 0.278 macro average violation rate against 0.169 for a generic AutoML pipeline. VᴇʀɪCᴇʟʟ moves admissibility out of the generator into a verifier. A taint labelled provenance graph collapses a heterogeneous family of protocol errors into one non interference property, discharged by a sound type and effect analysis composed with fail closed reference monitors; an audited reusable holdout bounds the adaptive generalization gap; and a claim checker ties every reported number to certified evidence. Certification cuts the macro average violation rate to 0.007 at verifier precision and recall above 0.93, and the validation to test gap from 0.120 to 0.016, while improving accuracy where signal exists (LINCS L1000 PCC 0.463 → 0.557, BBBC021 PCC 0.264 → 0.355) and costing nothing where it does not. Throughout, *certified* means machine checked protocol validity relative to a written contract and a bounded validation reuse gap, not biological correctness.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.