唯讀植入式架構:醫療智能系統中的知、判、授權與行分離原則
Read-Only Implant Architecture: Separation of Sensing, Inference, Authorization and Action
作者:Neo.K
機構:EveMissLab(一言諾科技有限公司)
系列:資訊優先體內智能與自適應微納系統系列 — Paper 03
版本:Version 1.0 — First Public Edition
日期:2026 年 8 月
摘要
本文提出 Read-Only Implant Architecture(ROIA)與知—判—授權—行分離。核心為:
Know=Infer=Authorize=Act
「唯讀」不是不能校準或更新,而是沒有直接改變宿主生理狀態的 therapeutic actuator。
1. 四種權限
知:
K:B(t)→Y(t)
判:
J:Y(t−τ:t)→P(Hk)
授權:
U:(H^,a∗,C,R)→{Allow,Deny,Escalate}
行:
A:B(t)→B(t+1)
關鍵:
K⇏J⇏U⇏A
2. ROIA
若:
Ai=∅
則體內節點可以 sensing、通信、校準與維護,但沒有 therapeutic authority。
ROIA 是:
Read-Only with respect to host physiology
而非 Read-Only Memory。
3. 資訊平面與治療平面
Pinfo=Pther
兩者間必須有 Authorization Boundary。
目的不是假設每層不犯錯,而是:
Prevent one error from automatically inheriting all downstream authority
4. 三種授權模式
- U0:No Therapeutic Authority
- U1:Human-Authorized Action
- U2:Preauthorized Bounded Closed Loop
對 U2 定義 Authority Envelope:
EA=(Ω,A,D,T,C)
只有:
at∈EA
才能執行。
5. 模型能力與權限分離
ModelUpgrade⇏AuthorityUpgrade
AI 可以改善,但不能因為更準就自行增加治療範圍。
6. Safety Controller
主模型:
M:X→H
安全控制:
G:(H,C,D,A)→{Allow,Block,Escalate}
提出行動的智能,不應必然是唯一驗證該行動的權威。
7. 最小醫療權限
Privilege(Ni)=Minimum(Functioni)
命令分為 Read、Configuration、Maintenance、Therapeutic Control;ROIA 允許前三者,但 therapeutic control 為空。
結論
AI 能力不等於醫療權限:
AI Capability=Medical Authority
最安全的智能有時正是「知道很多,但被刻意設計成不能直接動手」。