Auditing a Corrector That Can Never Be Scored: A Physics-Admissibility Verifier for Infrared Machine
Abstract
Infrared machine protection at a fusion device must decide which hot-looking surfaces are real and which are reflections. A learned corrector can make that decision, but it can never be scored: no ground-truth temperature field exists for a measured frame, and none ever will. We describe ADMIT, a verifier that audits such a corrector on real instrument data without labels. Every check is a physical invariant the answer must satisfy rather than a distance to a reference: light may not be invented, a surface may not fall below the vessel wall, a correction may only subtract. The check that does the work is the fourth: a region the corrector dismisses must be dismissible without inventing light inside it. The battery runs on 95 archived frames from 33 experiment days and returns a per-method table in minutes. It caught three failures that accuracy metrics did not: a label-free adaptation that reduced its residual by ceasing to make claims, a label-trained network that creates alarms the camera never showed (7,126 pixels above the measured brightness, 0.56 fabricated regions per frame) while holding the best mean error in the study (0.32 K), and a corrector whose aggregate honesty hid an over-claim concentrated exactly in the regions it rejected. We report what the checks can and cannot establish: they are necessary conditions, they inherit the forward operator's error, and they bound a decision rather than certify a field.