The Samata Latch: Designed Internal State for In-Context Binding Integrity
Abstract
When a context window contains two assignments to the same binding at the same privilege level, nothing in the standard transformer architecture or its training defines which assignment governs. The model resolves the conflict silently. We measure how, using a pre-registered inference battery (six open-weights models, three framings, controlled geometry of context dilution, injection position, and repetition). In the competent Qwen3-8B condition tested (the ladder's only competent model), the resolution is position-locked: last wins. It adopts a format-identical late-position counter-assignment in 14 claim-bearing cells, including all three pre-registered primary cells (capitulation up to 0.927) while holding 0.91-0.98 clean competence. Its base variant never reaches competence anywhere, so the capitulation regime sits exactly where instruction tuning lives. To our knowledge no prior work jointly measures and enforces resolution of conflicting assignments of a single binding within one privilege class. We propose the latch: a small, designed, trained-in write-once internal state with structural (symbolic) readout that makes the resolution an explicitly designed property of the implemented latch. At toy scale, against baselines trained to competence, it yields zero breaches across 72 injected cells (rule-of-three 95% upper bound ~4.2% per-cell) at 4.4-8.8x less training, with a free, per-example-verifiable record of the executed binding. All claims are per-framing (framing alone moves headline statistics by up to 0.79 on identical items and seeds), and we disclose 16 wrong-or-partial predictions alongside what survived.