Safe Probability Editing Is a Risk Allocation Problem
Abstract
Under distribution shift, adaptation, calibration, and pooling can propose useful probability edits before target labels are available. The deployment question is how a fixed unlabeled cohort should spend a limited risk budget, not only whether every row passes the same pointwise check. Uniform clipping assigns every input the same allowance and therefore ignores large differences in candidate gain per unit risk. We show that an elementary worst-label identity has a consequential operational interpretation: all-outcome regret becomes a conditional-risk currency, turning label-free probability editing into hierarchical cohort allocation. Each row preserves the anchor action and obeys a local catastrophe cap, while a shared ledger distributes fixed worst-case Brier and log-regret budgets across the cohort. Because realized predictive utility is unavailable at edit time, the ledger minimizes intervention from an externally proposed candidate subject to this safety contract. The resulting convex program reduces to two risk prices that decouple the cohort into one-dimensional edits. On 10,000 ImageNetV2 predictions, the same mean budgets and a twofold local cap raise retained update from 19.9% to 30.0% and reduce total squared candidate distance from 176.1 to 123.4, with zero action changes. Across 20 frozen VLCS domain-seed conditions, retained update rises from 14.9% to 22.2% (paired gain 7.30 points; 95% CI 5.94-8.66). Under identical twofold local caps, the ledger achieves the smallest squared candidate-distance objective among five allocation rules. Exact pointwise safe bodies and sparse hulls provide supporting local geometry and scalable extensions. The guarantee is deterministic for the cohort in hand rather than a future-sample population claim. Together, the results show that safety need not mean uniform restraint: risk can be spent where it preserves the most candidate signal, without target labels or action changes.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.