Abstract: A computer-implemented system is disclosed for deterministically controlling an unverified output transition to mitigate hallucinations in a probabilistic model. An enterprise ontology (108) is compiled into an executable Reasoning Control Flow Graph (RFG) comprising a plurality of typed nodes and edges representing permissible state transitions. A formal context is constructed in memory (102) from an immutable event space (110) of enterprise objects and ontology-derived attributes via an incidence relation, establishing an observer-independent ground truth. A symbolic validation layer is interposed between a probabilistic model and an execution environment to receive non-authoritative output transitions. These transitions are mapped to an unverified attribute set using canonical identifiers. An FCA component (120) computes a formal concept closure of the set, transforming probabilistic inferences into symbolically grounded states. Transitions are validated against a closure-based admissibility condition. The system deterministically executes, rejects, or decomposes transitions prior to dissemination, ensuring mathematically verified enterprise reasoning. FIG. 1
Description:BACKGROUND
Technical Field
[0001] The embodiments herein generally relate to enterprise decision intelligence and analytics, and more specifically, to ontology-driven systems and the formal mathematical validation of machine reasoning. The invention further relates to symbolic grounding, the deterministic execution of cross-entity reasoning flows, and the safe integration of probabilistic language models as non-authoritative proposers within a formally enforced enterprise reasoning substrate. The invention further relates to a system for providing a symbolic validation layer, operating as an independent agent firewall, that certifies or rejects AI-generated outputs prior to acceptance, dissemination, or execution.
Description of the Related Art
[0002] Enterprise organizations currently rely on business intelligence (BI), rule engines, and generative AI systems to analyze complex operations such as compliance, procurement, and supply chain management. Conventional BI systems are designed to compute metrics but fail to provide formal reasoning constraints. While rule engines can enforce deterministic logic, they generally require manual authoring, scale poorly, and do not naturally generalize across evolving ontologies and heterogeneous data.
[0003] The recent adoption of generative AI systems and agent frameworks has introduced significant risks, as these systems create plausible text rather than true text. Because these models are probabilistic, they are prone to hallucination, producing reasoning that is often unverifiable, non-compliant, and non-auditable in regulated environments. A critical "probabilistic gap" exists in large language models (LLMs) because they lack awareness of domain invariants and cannot distinguish between unknown data, indeterminate/ambiguous states, or impossible transitions that violate physical or business logic.
[0004] Existing industry fixes, such as Retrieval-Augmented Generation (RAG) and Guardrails, are insufficient for enterprise-grade safety. RAG systems merely retrieve text chunks without validating the underlying logic, while keyword-based guardrails often miss structural errors in reasoning. These existing safety architectures remain fundamentally heuristic or probabilistic rather than deterministic.
[0005] Accordingly, there is a need for a system that compiles enterprise semantics directly into executable reasoning structures, enforces mathematical correctness of reasoning steps, and deterministically rejects invalid reasoning paths prior to execution, without requiring manual rule authoring or relying on unreliable probabilistic confidence scores.
SUMMARY
[0006] In view of the foregoing, there is provided a computer-implemented method for deterministically controlling an unverified output transition for improving deterministic functioning of a probabilistic model by mitigating hallucinations through the enforcement of symbolic admissibility over probabilistic outputs. The method comprises: (i) compiling, by one or more processors, an enterprise ontology into an executable Reasoning Control Flow Graph (RFG) comprising a plurality of typed nodes and edges representing permissible state transitions; (ii) constructing a formal context, in a memory, from an immutable event space of a plurality of enterprise objects and ontology-derived attributes via an incidence relation, to establish an observer-independent ground truth, wherein the immutable event space comprises a layer that serves as ground truth for the system's reasoning and validation processes; (iii) interposing a symbolic validation layer between a probabilistic model and an execution environment by receiving an unverified output transition within the reasoning control flow graph from the probabilistic model, wherein the unverified output transition comprises a non-authoritative transition representing a potential movement between semantic assertions or a relationship assertion that is unverified for execution; (iv) mapping the unverified output transition into an unverified attribute set by resolving the semantic assertions within the unverified output transition to canonical attribute identifiers in an ontology-derived vocabulary; (v) computing, via a formal concept analysis (FCA) component, a formal concept closure of the unverified attribute set with respect to the formal context and transforming the unverified output transition from a probabilistic inference into a structurally valid and symbolically grounded state for validation; (vi) validating the unverified output transition by determining whether a closure-based admissibility condition is satisfied, wherein the closure-based admissibility condition requires the unverified output transition to be supported by and derivable from the computed formal concept closure; and (vii) deterministically controlling the unverified output transition by executing the unverified output transition within the reasoning control flow graph only upon successful validation, or preventing execution and deterministically rejecting, constraining, or decomposing the unverified output transition prior to dissemination to eliminate the risk of hallucinated or non-compliant output.
[0007] In some embodiments, the method comprises mapping the unverified output transition into the unverified attribute set by (i) performing symbol extraction to identify entities and relations within the unverified output transition, (ii) performing event anchoring by tracing the identified entities and relations to specific event identifiers within the immutable event space, and (iii) mapping the unverified output transition into the unverified attribute set, wherein the unverified attribute set is a subset of the ontology-derived attribute vocabulary determined by the anchored event identifiers. In some embodiments, the unverified attribute set that are unresolvable to the ontology-derived attribute vocabulary, that lack a corresponding record in the immutable event space, or that violate symbolic grounding requirements are deterministically rejected or constrained to a closure-valid admissible subset. The closure-valid admissible subset refers to a restricted portion of the unverified attribute set comprising attributes determined to be members of the computed formal concept closure, for the unverified attribute set.
[0008] In some embodiments, the formal concept closure is computed by (i) computing a supporting object set comprising the plurality of enterprise objects in the immutable event space that exhibits all attributes in the unverified attribute set and (ii) computing a closure attribute set comprising all attributes exhibited by every object in the supporting object set. In some embodiments, the unverified output transition is validated by checking whether a lattice implication path exists between a first reasoning state and a second reasoning state within a formal concept lattice derived from the formal context.
[0009] In some embodiments, the ontology-derived attributes comprise an evidence flag extracted from unstructured text documents, the evidence flag is mapped to the incidence relation of the formal context, and the reasoning control flow graph comprises a specialized node type selected from the group comprising an entity node, an event node, a metric node, a risk node, and a decision node. In some embodiments, the method comprises discretizing numerical data from the plurality of enterprise objects into interval-based attributes for inclusion in the formal context.
[0010] In some embodiments, the unverified output transition is deterministically controlled by (i) permitting the unverified output transition to an execution queue accessible for downstream execution when the closure-based admissibility condition is satisfied, and (ii) deterministically rejecting the unverified output transition and preventing the dissemination of a corresponding second reasoning state to the reasoning control flow graph when the closure-based admissibility condition is not satisfied. In some embodiments, the unverified output transition is controlled by partially admitting the unverified output transition and replacing the unverified attribute set with a subset of attributes contained in the formal concept closure prior to execution.
[0011] In some embodiments, the method comprises generating an audit proof artifact for the unverified output transition that is executed, wherein the audit proof comprises at least one of a formal concept closure computation, a reference to the supporting objects in the immutable event space, a timestamped record of the reasoning control flow graph, an implication reference, a deterministic rejection reason, a counterexample object set, or a minimal witness set. In some embodiments, the unverified output transition is rejected by generating a proof artifact that identifies a minimal witness set of counterexample objects from the formal context that violate the unverified output transition.
[0012] In some embodiments, the closure-based admissibility condition is satisfied when the unverified attribute set is equal to its formal concept closure. The unverified output transition comprises a proposed implication from an attribute set to the unverified attribute set. The closure-based admissibility condition is satisfied, and the validation permits execution only if the unverified attribute set is a subset of the formal concept closure.
[0013] In some embodiments, the plurality of enterprise objects is stored in a time-ordered, append-only event space to ensure truth monotonicity during the computing of the formal concept closure. In some embodiments, the formal context is dynamically updated in real-time as new enterprise objects by ingesting enterprise data sources and maps observations to the incidence relation to dynamically update the reasoning control flow graph, and the formal concept closure computation is performed using a precomputed adjacency matrix representation of the incidence relation that is stored in the memory.
[0014] In some embodiments, the method comprises a deriving canonical implication base from the formal context. The canonical implication base comprises a base derived from a pseudo-intent identification algorithm, such as a Duquenne-Guigues base, and the unverified output transition is validated further by determining whether the unverified output transition is supported by an implication present in or derivable from the canonical implication base.
[0015] In another aspect, there is provided a computer-implemented system for deterministically controlling an unverified output transition to improve deterministic functioning of a probabilistic model by mitigating hallucinations through the enforcement of symbolic admissibility over probabilistic outputs. The computer-implemented system comprises: one or more processors; and a memory storing instructions that, when executed by the one or more processors, cause the system to: (i) compile an enterprise ontology into an executable Reasoning Control Flow Graph (RFG) comprising a plurality of typed nodes and edges representing permissible state transitions; (ii) construct a formal context, in the memory, from an immutable event space of a plurality of enterprise objects and ontology-derived attributes via an incidence relation to establish an observer-independent ground truth; (iii) interpose a symbolic validation layer between a probabilistic model and an execution environment by receiving an unverified output transition within the reasoning control flow graph from the probabilistic model, wherein the unverified output transition comprises a non-authoritative transition representing a potential movement between semantic assertions or a relationship assertion that is unverified for execution; (iv) map the unverified output transition into an unverified attribute set by resolving the semantic assertions within the transition to canonical attribute identifiers in an ontology-derived vocabulary; (v) compute, via a formal concept analysis (FCA) component, a formal concept closure of the unverified attribute set with respect to the formal context to transform the unverified output transition from a probabilistic inference into a structurally valid and symbolically grounded state for validation; (vi) validate the unverified output transition by determining whether a closure-based admissibility condition is satisfied, wherein the closure-based admissibility condition requires the unverified output transition to be supported by and derivable from the computed formal concept closure; and (vii) deterministically control the unverified output transition by executing the unverified output transition within the reasoning control flow graph only upon successful validation, or preventing execution and deterministically reject, constrain, or decompose the unverified output transition prior to dissemination to eliminate the risk of hallucinated or non-compliant output.
[0016] In some embodiments, the system maps the unverified output transition into the unverified attribute set by (i) performing symbol extraction to identify entities and relations within the unverified output transition, (ii) performing event anchoring by tracing to specific event identifiers within the immutable event space, and (iii) mapping the unverified output transition into the unverified attribute set, wherein the unverified attribute set is a subset of the ontology-derived attribute vocabulary determined by the anchored event identifiers. In some embodiments, the system computes the formal concept closure by (i) computing a supporting object set comprising the plurality of enterprise objects in the immutable event space that exhibits all attributes in the unverified attribute set and (ii) computing a closure attribute set comprising all attributes exhibited by every object in the supporting object set.
[0017] In some embodiments, the unverified output transition is deterministically controlled by (i) permitting the unverified output transition to an execution queue accessible for downstream execution when the closure-based admissibility condition is satisfied, and (ii) deterministically rejecting the unverified output transition and preventing the dissemination of a corresponding second reasoning state to the reasoning control flow graph when the closure-based admissibility condition is not satisfied. In some embodiments, the unverified output transition is validated by checking whether a lattice implication path exists between a first reasoning state and a second reasoning state within a formal concept lattice derived from the formal context.
[0018] In another aspect, there is provided a non-transitory computer-readable medium storing instruction that, when executed by one or more processors, cause the one or more processors to perform a method of deterministically controlling an unverified output transition for improving deterministic functioning of a probabilistic model by mitigating hallucinations through the enforcement of symbolic admissibility over probabilistic outputs. The method comprises: (i) compiling, by one or more processors, an enterprise ontology into an executable Reasoning Control Flow Graph (RFG) comprising a plurality of typed nodes and edges representing permissible state transitions; (ii) constructing a formal context, in a memory, from an immutable event space of a plurality of enterprise objects and ontology-derived attributes via an incidence relation, to establish an observer-independent ground truth, wherein the immutable event space comprises a layer that serves as ground truth for the system's reasoning and validation processes; (iii) interposing a symbolic validation layer between a probabilistic model and an execution environment, wherein the unverified output transition comprises a non-authoritative transition representing a potential movement between semantic assertions or a relationship assertion that is unverified for execution; (iv) mapping the unverified output transition into an unverified attribute set by resolving the semantic assertions to canonical attribute identifiers in an ontology-derived vocabulary; (v) computing, via a formal concept analysis (FCA) component, a formal concept closure of the unverified attribute set with respect to the formal context and transforming the unverified output transition from a probabilistic inference into a structurally valid and symbolically grounded state for validation; (vi) validating the unverified output transition by determining whether a closure-based admissibility condition is satisfied, wherein the closure-based admissibility condition requires the unverified output transition to be supported by and derivable from the computed formal concept closure; and (vii) deterministically controlling the unverified output transition by executing it only upon successful validation, or preventing execution and deterministically rejecting, constraining, or decomposing the unverified output transition prior to dissemination to eliminate the risk of hallucinated or non-compliant output.
[0019] In some embodiments, the unverified output transition is deterministically controlled (i) by permitting the unverified output transition to an execution queue accessible for downstream execution when the closure-based admissibility condition is satisfied, and (ii) deterministically rejecting the unverified output transition and preventing the dissemination of a corresponding second reasoning state to the reasoning control flow graph when the closure-based admissibility condition is not satisfied.
[0020] In some embodiments, the unverified output transition is mapped into the unverified attribute set by performing symbol extraction, performing event anchoring by tracing to specific event identifiers within the immutable event space, and mapping to a subset of the ontology-derived attribute vocabulary. In some embodiments, the formal concept closure is computed by computing a supporting object set and computing a closure attribute set comprising all attributes exhibited by every object in the supporting object set.
[0021] These and other aspects of the embodiments herein will be better appreciated and understood when considered in conjunction with the following description and the accompanying drawings. It should be understood, however, that the following descriptions, while indicating preferred embodiments and numerous specific details thereof, are given by way of illustration and not of limitation. Many changes and modifications may be made within the scope of the embodiments herein without departing from the spirit thereof, and the embodiments herein include all such modifications.
BRIEF DESCRIPTION OF THE DRAWINGS
[0022] The embodiments herein will be better understood from the following detailed description with reference to the drawings, in which:
[0023] FIG. 1 illustrates a computer-implemented system for deterministically controlling an unverified output transition to improve deterministic functioning of a probabilistic model by mitigating hallucinations through the enforcement of symbolic admissibility over probabilistic outputs according to an embodiment herein;
[0024] FIG. 2 illustrates an exemplary enterprise ontology fragment being compiled by an ontology compiler into an executable Reasoning Control Flow Graph (RFG) according to an embodiment herein;
[0025] FIG. 3 illustrates a conceptual diagram of the construction of a formal context (K=(G,M,I)) from enterprise data sources and ontology mappings to establish an observer-independent ground truth according to an embodiment herein;
[0026] FIG. 4 illustrates a logic flow for closure-gated execution, depicting the computing of a formal concept closure (A'') for a candidate state (A) and the subsequent validation of a proposed transition (B) based on a closure-based admissibility condition to mitigate hallucinations according to an embodiment herein;
[0027] FIG. 5 illustrates the algorithmic derivation of a canonical implication base (e.g., a Duquenne-Guigues base) from the formal context and its application in validating an unverified output transition along an RFG edge according to an embodiment herein;
[0028] FIG. 6 illustrates a block diagram of multi-source evidence integration, showing the extraction of an evidence flag from unstructured text documents via NLP extraction and its mapping to the incidence relation for inclusion in the formal context according to an embodiment herein;
[0029] FIG. 7 illustrates exemplary domain implementations of the system of FIG. 1 across various enterprise sectors, including retail logistics, demonstrating the versatility of the enterprise ontology compilation into executable Reasoning Control Flow Graphs (RFGs) according to an embodiment herein;
[0030] FIGS. 8A & 8B illustrate a computer-implemented method for deterministically controlling an unverified output transition for improving deterministic functioning of a probabilistic model by mitigating hallucinations through the enforcement of symbolic admissibility over probabilistic outputs according to an embodiment herein; and
[0031] FIG. 9 is a representative hardware environment for practicing the embodiments herein.
DETAILED DESCRIPTION OF PREFERRED EMBODIMENTS
[0032] The embodiments herein and the various features and advantageous details thereof are explained more fully with reference to the non-limiting embodiments that are illustrated in the accompanying drawings and detailed in the following description. Descriptions of well-known components and processing techniques are omitted so as to not unnecessarily obscure the embodiments herein. The examples used herein are intended merely to facilitate an understanding of ways in which the embodiments herein may be practiced and to further enable those of skill in the art to practice the embodiments herein. Accordingly, the examples should not be construed as limiting the scope of the embodiments herein.
[0033] As mentioned, there remains a need for a computer-implemented system and a method for deterministically controlling an unverified output transition to improve deterministic functioning of a probabilistic model by mitigating hallucinations through the enforcement of symbolic admissibility over probabilistic outputs. The embodiments herein provide a computer-implemented system and a method for deterministically controlling an unverified output transition to improve the deterministic functioning of a probabilistic model by mitigating hallucinations through the enforcement of symbolic admissibility over probabilistic outputs. Referring now to the drawings, and more particularly to FIGS. 1 through 9, where similar reference characters denote corresponding features consistently throughout the figures, preferred embodiments are shown.
[0034] Definitions:
[0035] Ontology: A formal specification of enterprise entities, attributes, relationships, constraints, and derived semantics.
[0036] Reasoning Control Flow Graph (RFG): A typed executable graph representing permissible reasoning states and transitions. It consists of typed nodes (e.g., Entity, Event, Metric, Risk, Decision) and edges representing permissible state transitions compiled from an ontology and validated by formal closure constraints.
[0037] Formal Context (K=(G,M,I)): An FCA structure where (G) is a set of enterprise objects (instances or cohorts), (M) is a set of ontology-derived attributes, and (I) is an incidence relation indicating which objects exhibit which attributes.
[0038] Immutable Event Space: A layer that serves as the observer-independent ground truth for the system's reasoning and validation processes. It captures enterprise reality as time-ordered, append-only storage, ensuring truth monotonicity, i.e., the principle that history cannot be rewritten and raw reality is preserved.
[0039] Derivation and Closure: For an attribute set (A), the derivation (A′) identifies objects exhibiting all attributes in the attribute set (A), and the formal concept closure (A'') identifies all attributes exhibited by every object in that supporting set.
[0040] Closed Set: An attribute set is considered closed if it is equal to its formal concept closure.
[0041] Implication Validity: A proposed implication is valid if and only if the attributes in the proposed implication are a subset of the formal concept closure.
[0042] Canonical Implication Base: A minimal complete set of implications representing all valid attribute implications derivable from the formal context, such as a Duquenne-Guigues base.
[0043] Symbolic Admissibility: The enforcement of a condition where probabilistic outputs are only permitted if they are supported by and derivable from the computed formal concept closure.
[0044] Agent Firewall (Symbolic Validation Layer): An independent subsystem positioned between AI proposers and downstream consumers that treats AI-generated outputs as non-authoritative proposals. It performs symbolic admissibility checks to certify or reject outputs prior to dissemination.
[0045] Closure-Gated Execution (CGE): An execution policy where a reasoning transition is allowed only if specific closure conditions (e.g., A = A'' or B ⊆ A'') are satisfied.
[0046] Deterministic Functioning: Evidenced by the repeated generation of the same persona-specific notification and suppression outcomes for identical input sequences.
[0047] Hallucination Mitigation: The prevention of unsupported entities, causal explanations, recommendations, or risk states from being delivered to end users.
[0048] Event Anchoring: The process of tracing identified entities and relations within an unverified transition to specific event identifiers within the immutable event space.
[0049] Data folding: A method used to compress enterprise data into FCA-compatible objects and attributes, which can then be used to form lattices and implication bases.
[0050] Unverified output transition: A proposed change in reasoning state within the RFG generated by a probabilistic model (e.g., a generative AI model) prior to symbolic validation. This may include a movement between semantic assertions or a proposed relationship assertion.
[0051] Closure-based admissibility condition: A set of validation rules used to certify a transition, selected from the group comprising: (i) a closed-set condition (A = A''); (ii) a subset closure condition (B⊆A′′); (iii) implication lattice validation (existence of a lattice path); and (iv) canonical implication validation (membership in a canonical base).
[0052] FIG. 1 illustrates a computer-implemented system 100 for deterministically controlling an unverified output transition to improve deterministic functioning of a probabilistic model by mitigating hallucinations through the enforcement of symbolic admissibility over probabilistic outputs according to an embodiment herein. The system 100 is designed to interpose a symbolic validation layer (also referred to as an Agent Firewall) between a probabilistic model and an execution environment.
[0053] The system 100 comprises a memory 102, one or more processors 104, an ontology compiler 112, a formal context builder 114, a mapping component 116, a formal concept analysis (FCA) component 120 and a validation guard 122. The one or more processors 104 are configured to execute instructions stored in the memory 102 to drive the various functional modules of the system 100. In some embodiments, the memory 102 stores a precomputed adjacency matrix representation of the incidence relation to perform the formal concept closure computation.
[0054] An input and data layer 106 of the system 100 provides the foundational ground truth for the system's reasoning processes. The input and data layer 106 includes an enterprise ontology 108, which is a formal specification of enterprise entities, attributes, relationships, and constraints. The input and data layer 106 further includes an immutable event space 110, which comprises a layer that serves as an observer-independent ground truth for reasoning and validation.
[0055] In some embodiments, the plurality of enterprise objects is stored in the immutable event space 110 as a time-ordered, append-only storage to ensure truth monotonicity during the computing of the formal concept closure. In some embodiments, the input and data layer 106 ingests both structured and unstructured enterprise data sources. In some embodiments, the system 100 discretizes numerical data from the enterprise objects into interval-based attributes for inclusion in a formal context.
[0056] The ontology compiler 112 is configured to compile the enterprise ontology 108 into an executable Reasoning Control Flow Graph (RFG). The RFG comprises a plurality of typed nodes and edges representing permissible state transitions. In some embodiments, the RFG comprises specialized node types selected from the group comprising entity nodes, event nodes, metric nodes, risk nodes, and decision nodes.
[0057] The formal context builder 114 is provided to construct a formal context in the memory 102 from the immutable event space 110 and ontology-derived attributes via an incidence relation. The formal context allows the system 100 to establish the mathematical "Map of Possibility" for enterprise reasoning.
[0058] The mapping component 116 receives an unverified output transition from a probabilistic model. The unverified output transition comprises a non-authoritative transition representing a potential movement between semantic assertions or a relationship assertion that is unverified for execution. The mapping component 116 maps the unverified output transition into an unverified attribute set by resolving semantic assertions to canonical attribute identifiers in an ontology-derived vocabulary.
[0059] In some embodiments, the mapping component 116 maps the transition by performing symbol extraction to identify entities and relations, and event anchoring by tracing these symbols to specific event identifiers within the immutable event space 110. In some embodiments, members of the unverified attribute set that are unresolvable, lack a corresponding record in the immutable event space 110, or violate symbolic grounding requirements are deterministically rejected or constrained to a closure-valid admissible subset.
[0060] The formal concept analysis (FCA) component 120 is configured to compute a formal concept closure of the unverified attribute set with respect to the formal context. This process transforms the probabilistic inference into a structurally valid and symbolically grounded state for validation. In some embodiments, the formal concept closure is computed by computing a supporting object set (objects exhibiting all attributes in the unverified attribute set) and a closure attribute set (all attributes exhibited by every object in that supporting set).
[0061] The validation guard 122 is configured to validate the unverified output transition by determining whether a closure-based admissibility condition is satisfied. The closure-based admissibility condition requires the unverified output transition to be supported by and derivable from the computed formal concept closure. In some embodiments, the condition is satisfied when the unverified attribute set is equal to its formal concept closure. In some embodiments, the validation guard 122 checks whether a lattice implication path exists within a formal concept lattice. In some embodiments, the system 100 further validates the transition against a canonical implication base, such as a Duquenne-Guigues base.
[0062] An output layer 124 of the system 100 comprises an execution engine 126 that deterministically controls the unverified output transition. The execution engine 126 executes the transition within the RFG only upon successful validation, or prevents execution to eliminate the risk of hallucinated or non-compliant output.
[0063] In some embodiments, the execution engine 126 deterministically controls the transition by permitting it to an execution queue 128 for downstream execution when the condition is satisfied, and deterministically rejecting the transition and preventing dissemination when it is not satisfied. In some embodiments, the transition is controlled by partially admitting it and replacing the unverified attribute set with a subset of attributes actually contained in the formal concept closure.
[0064] The system 100 further includes an audit and proof store 130. In some embodiments, the system 100 generates an audit proof artifact for an executed transition, comprising a formal concept closure computation, a reference to supporting objects in the immutable event space 110, a timestamped record of the RFG, an implication reference, or a minimal witness set of counterexample objects for rejections.
[0065] The system 100 mitigates hallucinations through the enforcement of symbolic admissibility over probabilistic outputs, unlike conventional guardrails or retrieval methods that remain probabilistic. By interposing a symbolic validation layer (an "Agent Firewall") between a probabilistic model and an execution environment, the system 100 ensures that no output is disseminated unless it is supported by and derivable from a computed formal concept closure. This transforms a "plausible" inference into a structurally valid and symbolically grounded state.
[0066] The system 100 provides a rigorous foundation for reasoning by constructing a formal context from an immutable event space 110. This immutable event space 110 serves as an observer-independent ground truth, ensuring truth monotonicity during the computation of reasoning states. Through event anchoring, every entity and relation identified via symbol extraction is traced to specific event identifiers within this event space, ensuring that reasoning is based on "raw reality" rather than model interpretation.
[0067] A primary advantage is the use of formal concept closure and formal concept lattices to define a "Map of Possibility" for the enterprise. The system 100 validates unverified transitions by checking for a lattice implication path or ensuring that the unverified attribute set is equal to its formal concept closure. This allows for deterministic control, where the system 100 can deterministically reject, constrain, or decompose invalid transitions to eliminate the risk of non-compliant output.
[0068] The system 100 scales without manual rule authoring by deriving a canonical implication base, specifically a Duquenne-Guigues base, directly from the formal context. This allows the system 100 to compile inference edges in the Reasoning Control Flow Graph (RFG) that are minimal, complete, and mathematically reproducible, avoiding the brittle nature of manually authored rule engines. The system 100 generates audit proof artifacts for every executed transition, providing a "why" explanation that is devoid of probabilistic narratives. These artifacts include formal concept closure computations, references to supporting objects in the event space, and, in the case of rejections, a minimal witness set of counterexample objects that justify why a transition was blocked. This ensures the system 100 is audit-ready and safe for highly regulated environments.
[0069] The system 100 allows organizations to leverage powerful probabilistic models while restricting them to the role of non-authoritative proposers. The model may suggest a candidate attribute set or candidate RFG path, but the system 100 retains deterministic control, executing the proposal only when the closure-based admissibility condition is satisfied. This effectively "encloses" the AI within a symbolic validation layer. The system 100 is capable of compiling an enterprise ontology that spans structured data and unstructured text documents. By extracting evidence flags from unstructured sources and mapping them to the incidence relation, the system 100 can perform closure-valid execution based on both operational data and document-extracted requirements, such as contract clauses or compliance obligations.
[0070] The system 100 is architected to ensure that reasoning outcomes are mathematically grounded rather than probabilistic. In some embodiments, “improving deterministic functioning” is evidenced by the repeated generation of the same persona-specific notification and suppression outcomes for identical input sequences, ensuring that the same data always leads to the same certified result. In some embodiments, “mitigating hallucinations” is evidenced by the system preventing unsupported entities, unsupported causal explanations, unsupported recommendations, or unsupported risk states from appearing in notifications delivered to end users.
[0071] In some embodiments, the system 100 is implemented within an airport operations domain to manage complex operational convergences. In this embodiment, the input and data layer 106 receives an event sequence comprising a delayed inbound flight, a constrained gate, degraded HVAC at the assigned gate, and a missed baggage-transfer milestone. The one or more processors 104 execute the ontology compiler 112 to generate an RFG that routes notifications to specific personas, such as a Gate Operations Manager, a Maintenance Supervisor, or an Airport Duty Manager. In some embodiments, deterministic functioning is demonstrated when replaying this identical airport event sequence 100 times results in the Gate Operations Manager receiving the same gate-reassignment notification in every single test iteration, while no unrelated persona receives a notification in any run. In some embodiments, hallucination mitigation is demonstrated during these runs by the execution engine 126 ensuring that no notification states that an aircraft has a mechanical defect or that weather caused the disruption unless such an event is present in the immutable event space 110.
[0072] In some embodiments, the system 100 is implemented within a parking domain where the formal context builder 114 constructs a context from events including repeated overstay violations, inconsistent occupancy sensor changes, and missing payment registrations. In this embodiment, the symbolic validation layer interposes a validation guard 122 to ensure deterministic persona-specific routing and deterministic suppression. In some embodiments, an Enforcement Officer receives a notification for a specific bay priority while a Customer Service Agent is suppressed with absolute deterministic consistency for the same sequence because the closure-based admissibility condition for customer-facing context is not satisfied. In some embodiments, the system mitigates hallucinations by ensuring no notification states that payment fraud occurred or that a vehicle is stolen unless such assertions are supported by linked source events in the formal context.
[0073] In some embodiments, the system 100 is utilized for procurement compliance and supply chain risk management. The input and data layer 106 monitors for unacknowledged purchase orders, missed shipment milestones, and low inventory thresholds. The FCA component 120 computes the formal concept closure for these attributes to determine if an escalation condition is satisfied for a Procurement Head. In some embodiments, the system 100 deterministically controls the output by suppressing a Finance Approver across all evaluated trial cycles because the specific financial exposure conditions are not present in the formal concept closure. In some embodiments, the system ensures structural validity by preventing the AI from stating a supplier is bankrupt or a contract is terminated unless such a state transition is mathematically supported by the incidence relation.
[0074] Across these exemplary domain embodiments, the audit and proof store 130 generates artifacts that confirm high-integrity outcomes. In some embodiments, experimental evaluation of the system 100 yields a persona-notification consistency of 100% reproducible outcomes and a rate of zero for unsupported notification content, unsupported causal explanations, or unsupported recommendations delivered to end users. This confirms the system's ability to move from probabilistic uncertainty to mathematical correctness.
[0075] FIG. 2 illustrates an exemplary enterprise ontology fragment being compiled by an ontology compiler 112 into an executable Reasoning Control Flow Graph (RFG) according to an embodiment herein. The enterprise ontology fragment serves as a formal specification of enterprise entities, attributes, and relationships, as demonstrated by the illustrated components including Supplier, Invoice, and Payment Terms. The ontology compiler 112 is configured to transform these high-level semantic definitions into the discrete, executable structures of the RFG. The RFG comprises a plurality of typed nodes and edges representing permissible state transitions.
[0076] The plurality of typed nodes represent specific semantic states, including entity nodes (e.g., ENTITY: SUPPLIER and ENTITY: INVOICE), metric nodes (e.g., Metric: DefectRate), risk nodes (e.g., Risk: HighPaymentRisk), and decision nodes (e.g., Decision: Hold Payment). In some embodiments, the reasoning control flow graph comprises a specialized node type selected from the group comprising an entity node, an event node, a metric node, a risk node, and a decision node.
[0077] The connection from ENTITY: SUPPLIER to Decision: Hold Payment represents a direct compliance or relationship constraint defined within the ontology. The ontology compiler 112 compiles ontology relationships into the RFG. The edges labelled “hasRelation” represent the semantic links between nodes, such as the direct link from the Supplier entity to the Hold Payment decision node, which shows a high-level constraint (e.g., a supplier-level block) that bypasses intermediate metric evaluations.
[0078] The edges illustrated in the RFG represent the permissible state transitions compiled from the ontology relationships and derived semantics. In some embodiments, the ontology relationships generate cross-entity edges in the RFG, such as a transition from a Supplier node to an Invoice node. In some embodiments, temporal predicates generate event attributes in the ontology-derived vocabulary or temporal edges in the graph. In some embodiments, the system 100 compiles inference edges, such as the transition from a metric node to a risk node (e.g., from DefectRate to HighPaymentRisk), representing a potential movement between semantic assertions.
[0079] In some embodiments, a cross-entity metric is computed only upon closure-valid execution of a corresponding RFG transition. The final stage of the illustrated RFG fragment includes an action edge leading to a Decision: Hold Payment node, which represents a permitted actionable outcome or a decision outcome. Every transition represented by the edges in FIG. 2 is intended to be interposed by a symbolic validation layer to ensure that the transition is supported by and derivable from a computed formal concept closure prior to execution.
[0080] FIG. 3 illustrates a conceptual diagram of the construction of a formal context (K=(G,M,I)) from enterprise data sources and ontology mappings to establish an observer-independent ground truth according to an embodiment herein. The construction of this formal context provides the mathematical substrate required for the enforcement of symbolic admissibility over probabilistic outputs.
[0081] The system 100 utilizes a mapping component 116 to ingest data from a variety of enterprise data sources, which may include a Database 302, an Event Log 304, and a Knowledge Graph 306. The mapping component 116 is configured to transform these raw data observations into a structured formal context in the memory 102. The formal context is defined by (G, M, I), where G represents a plurality of enterprise objects (shown as rows in the illustrated table of FIG. 3, such as Invoice 001, Invoice 002, and Supplier A), M represents ontology-derived attributes (shown as columns, such as Delay > 30, Tier = Gold, and Risk = high), and I represents the incidence relation (indicated by the checkmarks and crosses in the table).
[0082] In some embodiments, the plurality of enterprise objects is stored in an immutable event space 110 that is time-ordered and append-only to ensure truth monotonicity during the computing of a formal concept closure. In some embodiments, the formal context is dynamically updated in real-time as new enterprise objects by ingesting enterprise data sources and maps observations to the incidence relation to dynamically update the reasoning control flow graph (RFG). The formal concept closure computation is performed using a precomputed adjacency matrix representation of the incidence relation that is stored in the memory 102. In some embodiments, the formal concept closure computation is performed using a symbolic reasoning mechanism selected from a group including lattice-based reasoning, constraint validation, and implication graph reasoning.
[0083] The ontology-derived attributes M in the formal context include canonical attribute identifiers resolved from an ontology-derived vocabulary. In some embodiments, the system 100 discretizes numerical data from the enterprise data sources into interval-based attributes, such as the illustrated "Delay > 30" attribute, for inclusion in the formal context. In some embodiments, the attributes M further comprise an evidence flag extracted from unstructured text documents via NLP extraction, which is then mapped to the incidence relation I.
[0084] The incidence relation I established in FIG. 3 represents the objective reality of which enterprise objects G exhibit which attributes M. For example, as illustrated, Invoice 001 exhibits the attributes "Delay > 30" and "Risk = high" but does not exhibit "Tier = Gold". This mathematical mapping serves as the "Map of Possibility" that the FCA component 120 uses to compute formal concept closures and validate unverified output transitions. In some embodiments, the formal concept closure computation is performed using a precomputed adjacency matrix representation of this incidence relation stored in the memory 102 to improve the deterministic functioning and speed of the probabilistic model. In some embodiments, the formal concept closure computation is performed using a symbolic reasoning mechanism selected from a group including lattice-based reasoning, constraint validation, and implication graph reasoning.
[0085] As illustrated in the formal context table of FIG. 3, objects within G may comprise multi-entity composite objects created via data folding. Comparing invoices and suppliers in the same formal context is achieved through data folding. This allows for the simultaneous comparison of disparate entities, such as invoices and suppliers, within a single incidence relation. In FIG. 3, the symbol ✔ indicates incidence relation membership, where the object exhibits the attribute, and whereas ✖ indicates the absence of that attribute.
[0086] FIG. 4 illustrates a logic flow for closure-gated execution, depicting the computing of a formal concept closure (A'') for a candidate state (A) and the subsequent validation of a proposed transition (B) based on a closure-based admissibility condition to mitigate hallucinations according to an embodiment herein. This process is executed by the one or more processors 104 using the formal context (K=(G,M,I)) stored in the memory 102. The logic flow begins with a candidate state (A), which represents a set of semantic assertions or attributes currently active within the Reasoning Control Flow Graph (RFG). To ensure this state is symbolically grounded, the FCA component 120 performs the computing of the formal concept closure (A'').
[0087] In some embodiments, the formal concept closure is computed by computing a supporting object set (A′) comprising the plurality of enterprise objects in the immutable event space 110 that exhibit all attributes in the unverified attribute set (A), and then computing a closure attribute set (A'') comprising all attributes exhibited by every object in that supporting object set. This mathematical transformation ensures the transition moves from a probabilistic inference into a structurally valid and symbolically grounded state for validation.
[0088] In some embodiments, the supporting object set (A′) identifies the specific set of enterprise objects within the formal context that exhibit every attribute present in the candidate attribute set. The closure attribute set (A'') is then computed as the set of all attributes exhibited by every object in A′.
[0089] The system 100 then receives a proposed transition (B), which represents an unverified output transition or a relationship assertion provided by a probabilistic model. The validation guard 122 evaluates this proposal by determining whether a closure-based admissibility condition is satisfied. As illustrated in FIG. 4, the system 100 checks if the proposed step (B) is a subset of the formal concept closure (A'') (i.e., B⊆A′′).
[0090] In some embodiments, the closure-based admissibility condition is satisfied when the unverified attribute set is equal to its formal concept closure (A = A''). In some embodiments, the unverified output transition is validated by checking whether a lattice implication path exists between a first reasoning state and a second reasoning state within a formal concept lattice derived from the formal context. In some embodiments, the transition is further validated by determining whether it is supported by an implication present in or derivable from a canonical implication base, such as a Duquenne-Guigues base.
[0091] If the closure-based admissibility condition is satisfied, the system 100 determines the transition is mathematically valid and proceeds to Execute Transition. In some embodiments, this is achieved by permitting the unverified output transition to an execution queue 128 accessible for downstream execution. If the condition is not satisfied, a hallucination is detected, and the execution engine 126 performs a Deterministic Rejection. This prevents execution prior to dissemination to eliminate the risk of hallucinated or non-compliant output. In some embodiments, the system 100 partially admits the transition by replacing the unverified attribute set with a subset of attributes actually contained in the formal concept closure prior to execution.
[0092] Following the deterministic control of the transition, the system 100 utilizes the audit and proof store 130 to generate an audit proof artifact. In some embodiments, the audit proof comprises a formal concept closure computation, a reference to the supporting objects in the immutable event space 110, a timestamped record of the RFG, a deterministic rejection reason, or a minimal witness set of counterexample objects from the formal context that violate the transition.
[0093] FIG. 5 illustrates the algorithmic derivation of a canonical implication base (e.g., a Duquenne-Guigues base) from the formal context and its application in validating an unverified output transition along an RFG edge according to an embodiment herein. This process represents a high-integrity mechanism for improving the deterministic functioning of the system 100 by deriving minimal, complete reasoning rules directly from enterprise reality. As illustrated in FIG. 5, the one or more processors 104 access the formal context K = (G, M, I) stored in the memory 102. This context is constructed via the mapping component 116 which ingests data from a Database 302, Event Log 304, and Knowledge Graph 306, establishing the incidence relation between enterprise objects G and ontology-derived attributes M.
[0094] As illustrated in the formal context table of FIG. 5, objects within G may comprise multi-entity composite objects created via data folding. This allows for the simultaneous comparison of disparate entities, such as invoices and suppliers, within a single incidence relation. In FIG. 5, the symbol ✔ indicates incidence relation membership (the object exhibits the attribute), whereas ✖ indicates the absence of that attribute.
[0095] The system 100 executes a specific algorithm, such as the Duquenne-Guigues algorithm, to identify pseudo-intents and generate the canonical implication base. The canonical implication base comprises a minimal complete set of implications (e.g., P⇒Q and X,Y⇒Z) that represent all valid attribute relationships derivable from the formal context. In some embodiments, the formal concept closure computation is performed using a precomputed adjacency matrix representation of the incidence relation stored in the memory 102 to accelerate the derivation of these implications.
[0096] Once the canonical implication base is established, it is utilized by the symbolic validation layer (or Agent Firewall) to verify unverified output transitions received from a probabilistic model. When the probabilistic model proposes a movement between semantic assertions, the validation guard 122 determines whether the proposed transition is supported by an implication present in or derivable from the canonical implication base. This ensures that any inference edge within the Reasoning Control Flow Graph (RFG) is mathematically grounded in the established ground truth. In some embodiments, the ontology-derived attributes include evidence flags extracted from unstructured text documents, and the RFG comprises specialized node types such as entity nodes, event nodes, metric nodes, risk nodes, and decision nodes. In some embodiments, the system 100 discretizes numerical data from the enterprise objects into interval-based attributes to facilitate the derivation of these implications.
[0097] If a proposed transition (e.g., an implication P⇒Q proposed by an AI) is found within the canonical implication base, the execution engine 126 permits the transition to the execution queue 128. In some embodiments, the plurality of enterprise objects is stored in a time-ordered, append-only event space to ensure truth monotonicity during this entire derivation and validation process.
[0098] If the transition is not supported, the system 100 performs a deterministic rejection to eliminate the risk of hallucinated or non-compliant output. Following this deterministic control, the audit and proof store 130 generates an audit proof artifact. In some embodiments, the audit proof includes an implication reference to the specific rule in the canonical implication base that authorized the execution, or a minimal witness set of counterexample objects that justified a rejection. The flow in FIG. 5 depicts the transformation of the formal context into a canonical implication base, which then populates the RFG with validated inference edges and closure guards to ensure deterministic reasoning.
[0099] FIG. 6 illustrates a block diagram of multi-source evidence integration, showing the extraction of an evidence flag from unstructured text documents via NLP extraction and its mapping to the incidence relation for inclusion in the formal context according to an embodiment herein. The multi-source evidence integration is critical for establishing a comprehensive, observer-independent ground truth that spans both operational data and textual requirements. As shown in FIG. 6, the system 100 utilizes one or more processors 104 to ingest data from disparate sources, which may include, but is not limited to, ERP systems and unstructured documents. These inputs are resolved into an attribute set, which represents the specific set of canonical attributes extracted from both structured and unstructured streams for a given object cohort prior to mapping to the incidence relation. The unstructured documents, such as contracts, emails, or policy PDFs, are processed via an NLP extraction to identify specific semantic markers. In some embodiments, the ontology-derived attributes comprise an evidence flag extracted from these unstructured text documents, which may include markers such as "Indemnity Clause Found" or "Limitation of Liability Missing".
[00100] Simultaneously, the Structured Data (ERP) provides operational attributes, such as a "PO Date: 2023-10-01". These multi-source inputs are fed into the mapping component 116, which resolves these assertions to canonical attribute identifiers in an ontology-derived vocabulary. The resulting Attribute Set, which as illustrated contains both structured (PO_Date) and unstructured (Indemnity_Clause) attributes, is then mapped to the incidence relation of the formal context.
[00101] In some embodiments, a reasoning transition is executed only when closure validity is satisfied using at least one attribute derived from these unstructured documents. This ensures a "Dual Evidence Validation" where a step must be supported by both operational facts and document-extracted compliance or legal attributes. The FCA component 120 computes a formal concept closure for this combined attribute set to ensure the system reaches a Valid State.
[00102] In some embodiments, the Reasoning Control Flow Graph (RFG) comprises a specialized node type selected from the group comprising an entity node, an event node, a metric node, a risk node, and a decision node, allowing the unstructured evidence flags to trigger specific risk or decision states. In some embodiments, the system 100 deterministically controls the output transition by permitting it to an execution queue 128 only if the closure-based admissibility condition is satisfied across all integrated evidence types.
[00103] In some embodiments, the system 100 generates an audit proof artifact for the validated transition, which includes references to the specific unstructured text spans or evidence pointers that served as the basis for the evidence flag. In some embodiments, the plurality of enterprise objects used in this mapping is stored in a time-ordered, append-only event space to ensure truth monotonicity as the formal context is dynamically updated with new evidence. In some embodiments, the system 100 provides graduated admission, where an AI-generated proposal is partially admitted by constraining it to the specific subset of attributes, including extracted evidence flags, that are confirmed within the formal concept closure.
[00104] FIG. 7 illustrates exemplary domain implementations of the system of FIG. 1 across various enterprise sectors, including retail logistics, demonstrating the versatility of the enterprise ontology compilation into executable Reasoning Control Flow Graphs (RFGs) according to an embodiment herein. FIG. 7 provides the requisite visual evidence of the system's ability to achieve deterministic functioning and mitigate hallucinations by grounding reasoning in a domain-specific formal context constructed from an immutable event space 110.
[00105] Each domain implementation including procurement, retail logistics, airport operations, and legal compliance, shown in FIG. 7 represents an executable RFG where nodes correspond to compiled semantic states and edges correspond to permissible state transitions. The effectiveness of these implementations is measured through repeated empirical testing. The permissible state transitions are treated as unverified output transitions when proposed by a probabilistic model and are subject to symbolic admissibility checks by the validation guard 122. In some embodiments, the RFG for any given domain comprises specialized node types selected from the group comprising an entity node, an event node, a metric node, a risk node, and a decision node.
[00106] As illustrated in the procurement domain implementation of FIG. 7, the system 100 compiles an RFG that manages supplier-related risks. Here, an event node (e.g., Delay > 30) and an entity node (e.g., Supplier Cluster) converge through an inference edge to a risk node (e.g., HighPaymentRisk), eventually leading to a decision node (e.g., Escalate). In some embodiments, the system discretizes numerical data (such as raw delay days) from the plurality of enterprise objects into interval-based attributes (like Delay > 30) for inclusion in the formal context. In some embodiments, the unverified output transition leading to the Escalate decision is permitted only if the closure-based admissibility condition is satisfied, requiring the transition to be supported by and derivable from the computed formal concept closure.
[00107] The Retail Logistics implementation of FIG. 7 demonstrates a sequential reasoning path: DispatchLate (Event) → ReturnRisk (Risk) → Offer Discount (Decision). In some embodiments, the system 100 validates the transition from DispatchLate to ReturnRisk by checking whether a lattice implication path exists between these reasoning states within a formal concept lattice derived from the formal context. In some embodiments, the deterministic control of this transition prevents the system 100 from inventing "post-hoc" narratives or confusing correlation with causation by enforcing causal integrity through the immutable event space 110.
[00108] In the airport operations implementation, complex operational convergence is modeled. Multiple event nodes (e.g., HVAC Down and Peak Hour) convergence upon a risk node (e.g., Passenger Discomfort), which triggers a decision node (e.g., Reassign Gate). In some embodiments, the FCA component 120 computes the formal concept closure for this convergence by computing a supporting object set of terminal-time slices that exhibit these conditions and then computing a closure attribute set to verify if Passenger Discomfort is mathematically guaranteed. In some embodiments, the deterministic functioning is evidenced by the repeated generation of the same gate-reassignment notification in every single test iteration for identical input sequences.
[00109] The Legal Compliance implementation highlights the integration of unstructured data. A structured entity node (e.g., HighValue Deal) is combined with an unstructured evidence flag (e.g., Missing_LoL_Clause) to identify LiabilityExposure (Risk) and recommend an Insert Cap (Decision). In some embodiments, the ontology-derived attributes comprise an evidence flag extracted from unstructured text documents (like contracts) via NLP extraction, which is then mapped to the incidence relation of the formal context. In some embodiments, a reasoning transition (e.g., to LiabilityExposure) is executed only when closure validity is satisfied using both structured operational data and document-extracted attributes.
[00110] In some embodiments, for any executed transition in these domains, the system 100 utilizes the audit and proof store 130 to generate an audit proof artifact comprising a formal concept closure computation, a reference to supporting objects, or a minimal witness set of counterexample objects if a transition was rejected.
[00111] FIGS. 8A & 8B illustrate a computer-implemented method for deterministically controlling an unverified output transition for improving deterministic functioning of a probabilistic model by mitigating hallucinations through the enforcement of symbolic admissibility over probabilistic outputs according to an embodiment herein. At step 802, an enterprise ontology 108 is compiled into an executable Reasoning Control Flow Graph (RFG) by one or more processors 104. The RFG comprises a plurality of typed nodes and edges representing permissible state transitions. In some embodiments, the ontology-derived attributes comprise an evidence flag extracted from unstructured text documents, and the reasoning control flow graph comprises a specialized node type selected from the group comprising an entity node, an event node, a metric node, a risk node, and a decision node.
[00112] At step 804, a formal context is constructed in a memory 102 from an immutable event space 110 of a plurality of enterprise objects and ontology-derived attributes via an incidence relation. This construction establishes an observer-independent ground truth, where the immutable event space 110 serves as a layer for the system's reasoning and validation processes. In some embodiments, the plurality of enterprise objects is stored in a time-ordered, append-only event space to ensure truth monotonicity during the computing of the formal concept closure, and the formal context is dynamically updated in real-time as new objects are added by ingesting enterprise data sources. In some embodiments, the method comprises discretizing numerical data from the plurality of enterprise objects into interval-based attributes for inclusion in the formal context.
[00113] At step 806, a symbolic validation layer is interposed between a probabilistic model and an execution environment by receiving an unverified output transition within the reasoning control flow graph from the probabilistic model. The unverified output transition comprises a non-authoritative transition representing a potential movement between semantic assertions or a relationship assertion that is unverified for execution. At step 808, the unverified output transition is mapped into an unverified attribute set by resolving the semantic assertions within the transition to canonical attribute identifiers in an ontology-derived vocabulary. In some embodiments, the unverified output transition is mapped by performing symbol extraction to identify entities and relations, and performing event anchoring by tracing these symbols to specific event identifiers within the immutable event space 110. The unverified attribute set is a subset of the ontology-derived attribute vocabulary determined by the anchored event identifiers. In some embodiments, members of the unverified attribute set that are unresolvable, lack a corresponding record in the immutable event space 110, or violate symbolic grounding requirements are deterministically rejected or constrained to a closure-valid admissible subset.
[00114] At step 810, a formal concept closure of the unverified attribute set is computed via a formal concept analysis (FCA) component 120 with respect to the formal context. This computation transforms the unverified output transition from a probabilistic inference into a structurally valid and symbolically grounded state for validation. In some embodiments, the formal concept closure is computed by computing a supporting object set comprising the plurality of enterprise objects that exhibit all attributes in the unverified attribute set, and computing a closure attribute set comprising all attributes exhibited by every object in that supporting set. In some embodiments, the formal concept closure computation is performed using a precomputed adjacency matrix representation of the incidence relation stored in the memory 102. In some embodiments, the formal concept closure computation is performed using a symbolic reasoning mechanism selected from a group including lattice-based reasoning, constraint validation, and implication graph reasoning.
[00115] At step 812, the unverified output transition is validated by determining whether a closure-based admissibility condition is satisfied. The closure-based admissibility condition requires the unverified output transition to be supported by and derivable from the computed formal concept closure. In some embodiments, the closure-based admissibility condition is satisfied when the unverified attribute set is equal to its formal concept closure. In some embodiments, the transition is validated by checking whether a lattice implication path exists between a first reasoning state and a second reasoning state within a formal concept lattice. In some embodiments, the method comprises deriving a canonical implication base (such as a Duquenne-Guigues base) from the formal context, and the transition is validated further by determining whether it is supported by an implication present in or derivable from the canonical implication base.
[00116] At step 814, the unverified output transition is deterministically controlled by executing the transition within the reasoning control flow graph only upon successful validation. If validation is unsuccessful, the system prevents execution and deterministically rejects, constrains, or decomposes the unverified output transition prior to dissemination to eliminate the risk of hallucinated or non-compliant output. In some embodiments, this is controlled by permitting the unverified output transition to an execution queue 128 when satisfied, or deterministically rejecting the transition and preventing the dissemination of a corresponding second reasoning state when not satisfied. In some embodiments, the transition is controlled by partially admitting the transition and replacing the unverified attribute set with a subset of attributes contained in the formal concept closure prior to execution. In some embodiments, the method comprises generating an audit proof artifact for the executed transition, comprising at least one of a closure computation, a reference to supporting objects, a timestamped record of the RFG, an implication reference, a deterministic rejection reason, or a minimal witness set of counterexample objects.
[00117] FIG. 9 is a representative hardware environment for practicing the embodiments herein. The hardware environment comprises a CPU 10 coupled to various devices via a system bus 12. The system includes RAM 14 and ROM 16 for volatile and non-volatile memory, and a storage drive 13 (such as a hard disk units or optical drive 11) connected via an I/O adapter 18 to provide persistent storage for event records and bias matrices. User interaction is facilitated through a user interface adapter 19, which connects peripheral devices such as a keyboard 15, mouse 17, microphone 22, and speaker 24. Visual output is provided on a display device 23 via a display adapter 21, which may render a graphical user interface (GUI) 36 for configuring interpretation parameters. Connectivity to external event streams is maintained through a communications adapter 20 (linked to a network 25) and a transceiver 26, while a signal converter 28 and signal comparator 27 may be utilized for real-time processing and symbolic resolution of high-volume event signals received from external networks prior to their ingestion by the mapping component 116.
[00118] The foregoing description of the specific embodiments will so fully reveal the general nature of the embodiments herein that others can, by applying current knowledge, readily modify and/or adapt for various applications such specific embodiments without departing from the generic concept, and, therefore, such adaptations and modifications should and are intended to be comprehended within the meaning and range of equivalents of the disclosed embodiments. It is to be understood that the phraseology or terminology employed herein is for the purpose of description and not of limitation. Therefore, while the embodiments herein have been described in terms of preferred embodiments, those skilled in the art will recognize that the embodiments herein can be practiced with modification within the scope of appended claims.
, Claims:1/We Claim:
1. A computer-implemented method for deterministically controlling an unverified output transition for improving deterministic functioning of a probabilistic model by mitigating hallucinations through the enforcement of symbolic admissibility over probabilistic outputs, wherein the method comprises:
compiling, by one or more processors (104), an enterprise ontology (108) into an executable Reasoning Control Flow Graph (RFG) comprising a plurality of typed nodes and edges representing permissible state transitions;
constructing a formal context, in a memory (102), from an immutable event space (110) of a plurality of enterprise objects and ontology-derived attributes via an incidence relation, to establish an observer-independent ground truth, wherein the immutable event space (110) comprises a layer that serves as ground truth for the system's reasoning and validation processes;
interposing a symbolic validation layer between a probabilistic model and an execution environment by receiving an unverified output transition within the reasoning control flow graph from the probabilistic model, wherein the unverified output transition comprises a non-authoritative transition representing a potential movement between semantic assertions or a relationship assertion that is unverified for execution;
mapping the unverified output transition into an unverified attribute set by resolving the semantic assertions within the unverified output transition to canonical attribute identifiers in an ontology-derived vocabulary;
computing, via a formal concept analysis (FCA) component (120), a formal concept closure of the unverified attribute set with respect to the formal context and transforming the unverified output transition from a probabilistic inference into a structurally valid and symbolically grounded state for validation;
validating the unverified output transition by determining whether a closure-based admissibility condition is satisfied, wherein the closure-based admissibility condition requires the unverified output transition to be supported by and derivable from the computed formal concept closure; and
deterministically controlling the unverified output transition by executing the unverified output transition within the reasoning control flow graph only upon successful validation, or preventing execution and deterministically rejecting, constraining, or decomposing the unverified output transition prior to dissemination to eliminate the risk of hallucinated or non-compliant output.
2. The computer-implemented method as claimed in claim 1, wherein the unverified output transition is mapped into the unverified attribute set by
performing symbol extraction to identify entities and relations within the unverified output transition;
performing event anchoring by tracing the identified entities and relations to specific event identifiers within the immutable event space (110); and
mapping the unverified output transition into the unverified attribute set, wherein the unverified attribute set is a subset of the ontology-derived attribute vocabulary determined by the anchored event identifiers,
wherein the unverified attribute set that are unresolvable to the ontology-derived attribute vocabulary, that lack a corresponding record in the immutable event space (110), or that violate symbolic grounding requirements are deterministically rejected or constrained to a closure-valid admissible subset, wherein the closure-valid admissible subset refers to a restricted portion of the unverified attribute set comprising attributes determined to be members of the computed formal concept closure, for the unverified attribute set.
3. The computer-implemented method as claimed in claim 1, wherein the formal concept closure is computed by
computing a supporting object set comprising the plurality of enterprise objects in the immutable event space (110) that exhibits all attributes in the unverified attribute set; and
computing a closure attribute set comprising all attributes exhibited by every object in the supporting object set.
4. The computer-implemented method as claimed in claim 1, wherein the unverified output transition is validated by checking whether a lattice implication path exists between a first reasoning state and a second reasoning state within a formal concept lattice derived from the formal context.
5. The computer-implemented method as claimed in claim 1, wherein the ontology-derived attributes comprise an evidence flag extracted from unstructured text documents, and the evidence flag is mapped to the incidence relation of the formal context, wherein the reasoning control flow graph comprises a specialized node type selected from the group comprising an entity node, an event node, a metric node, a risk node, and a decision node.
6. The computer-implemented method as claimed in claim 1, wherein the method comprises discretizing numerical data from the plurality of enterprise objects into interval-based attributes for inclusion in the formal context.
7. The computer-implemented method as claimed in claim 1, wherein the unverified output transition is deterministically controlled by
permitting the unverified output transition to an execution queue (128) accessible for downstream execution when the closure-based admissibility condition is satisfied; and
deterministically rejecting the unverified output transition and preventing the dissemination of a corresponding second reasoning state to the reasoning control flow graph when the closure-based admissibility condition is not satisfied,
wherein the unverified output transition is controlled by partially admitting the unverified output transition and replacing the unverified attribute set with a subset of attributes contained in the formal concept closure prior to execution.
8. The computer-implemented method as claimed in claim 1, wherein the method comprises generating an audit proof artifact for the unverified output transition that is executed, wherein the audit proof comprises at least one of a formal concept closure computation, a reference to the supporting objects in the immutable event space (110), a timestamped record of the reasoning control flow graph, an implication reference, a deterministic rejection reason, a counterexample object set, or a minimal witness set, wherein the unverified output transition is rejected by generating a proof artifact that identifies a minimal witness set of counterexample objects from the formal context that violate the unverified output transition.
9. The computer-implemented method as claimed in claim 1, wherein the closure-based admissibility condition is satisfied when the unverified attribute set is equal to its formal concept closure, and wherein the unverified output transition comprises a proposed implication from an attribute set to the unverified attribute set, wherein the closure-based admissibility condition is satisfied, and the validation permits execution only if the unverified attribute set is a subset of the formal concept closure.
10. The computer-implemented method as claimed in claim 1, wherein the plurality of enterprise objects is stored in a time-ordered, append-only event space to ensure truth monotonicity during the computing of the formal concept closure, wherein the formal context is dynamically updated in real-time as new enterprise objects by ingesting enterprise data sources and maps observations to the incidence relation to dynamically update the reasoning control flow graph, wherein the formal concept closure computation is performed using a precomputed adjacency matrix representation of the incidence relation that is stored in the memory (102).
11. The computer-implemented method as claimed in claim 1, wherein the method comprises deriving a canonical implication base from the formal context, wherein the canonical implication base comprises a base derived from a pseudo-intent identification algorithm, comprising Duquenne-Guigues base, wherein the unverified output transition is validated further by determining whether the unverified output transition is supported by an implication present in or derivable from the canonical implication base.
12. A computer-implemented system (100) for deterministically controlling an unverified output transition to improve deterministic functioning of a probabilistic model by mitigating hallucinations through the enforcement of symbolic admissibility over probabilistic outputs, the computer-implemented system (100) comprising:
one or more processors (104); and
a memory (102) storing instructions that, when executed by the one or more processors (104), cause the system (100) to:
compile an enterprise ontology (108) into an executable Reasoning Control Flow Graph (RFG) comprising a plurality of typed nodes and edges representing permissible state transitions;
construct a formal context, in the memory (102), from an immutable event space (110) of a plurality of enterprise objects and ontology-derived attributes via an incidence relation to establish an observer-independent ground truth;
interpose a symbolic validation layer between a probabilistic model and an execution environment by receiving an unverified output transition within the reasoning control flow graph from the probabilistic model, wherein the unverified output transition comprises a non-authoritative transition representing a potential movement between semantic assertions or a relationship assertion that is unverified for execution;
map the unverified output transition into an unverified attribute set by resolving the semantic assertions within the transition to canonical attribute identifiers in an ontology-derived vocabulary;
compute, via a formal concept analysis (FCA) component (120), a formal concept closure of the unverified attribute set with respect to the formal context to transform the unverified output transition from a probabilistic inference into a structurally valid and symbolically grounded state for validation;
validate the unverified output transition by determining whether a closure-based admissibility condition is satisfied, wherein the closure-based admissibility condition requires the unverified output transition to be supported by and derivable from the computed formal concept closure; and
deterministically control the unverified output transition by executing the unverified output transition within the reasoning control flow graph only upon successful validation, or preventing execution and deterministically reject, constrain, or decompose the unverified output transition prior to dissemination to eliminate the risk of hallucinated or non-compliant output.
13. The computer-implemented system (100) as claimed in claim 12, wherein the system (100) maps the unverified output transition into the unverified attribute set by
performing symbol extraction to identify entities and relations within the unverified output transition;
performing event anchoring by tracing the identified entities and relations to specific event identifiers within the immutable event space (110); and
mapping the unverified output transition into the unverified attribute set, wherein the unverified attribute set is a subset of the ontology-derived attribute vocabulary determined by the anchored event identifiers,
wherein the unverified attribute set that are unresolvable to the ontology-derived attribute vocabulary, that lack a corresponding record in the immutable event space (110), or that violate symbolic grounding requirements are deterministically rejected or constrained to a closure-valid admissible subset, wherein the closure-valid admissible subset refers to a restricted portion of the unverified attribute set comprising attributes determined to be members of the computed formal concept closure, for the unverified attribute set.
14. The computer-implemented system (100) as claimed in claim 12, wherein the system (100) computes the formal concept closure by
computing a supporting object set comprising the plurality of enterprise objects in the immutable event space (110) that exhibits all attributes in the unverified attribute set; and
computing a closure attribute set comprising all attributes exhibited by every object in the supporting object set.
15. The computer-implemented system (100) as claimed in claim 12, wherein the unverified output transition is deterministically controlled by
permitting the unverified output transition to an execution queue (128) accessible for downstream execution when the closure-based admissibility condition is satisfied; and
deterministically rejecting the unverified output transition and preventing the dissemination of a corresponding second reasoning state to the reasoning control flow graph when the closure-based admissibility condition is not satisfied,
wherein the unverified output transition is controlled by partially admitting the unverified output transition and replacing the unverified attribute set with a subset of attributes contained in the formal concept closure prior to execution
16. The computer-implemented system (100) as claimed in claim 12, wherein the unverified output transition is validated by checking whether a lattice implication path exists between a first reasoning state and a second reasoning state within a formal concept lattice derived from the formal context
17. A non-transitory computer-readable medium storing instructions that, when executed by one or more processors (104), cause the one or more processors (104) to perform a method of deterministically controlling an unverified output transition for improving deterministic functioning of a probabilistic model by mitigating hallucinations through the enforcement of symbolic admissibility over probabilistic outputs, wherein the method comprises:
compiling, by one or more processors (104), an enterprise ontology (108) into an executable Reasoning Control Flow Graph (RFG) comprising a plurality of typed nodes and edges representing permissible state transitions;
constructing a formal context, in a memory (102), from an immutable event space (110) of a plurality of enterprise objects and ontology-derived attributes via an incidence relation, to establish an observer-independent ground truth, wherein the immutable event space (110) comprises a layer that serves as ground truth for the system's reasoning and validation processes;
interposing a symbolic validation layer between a probabilistic model and an execution environment by receiving an unverified output transition within the reasoning control flow graph from the probabilistic model, wherein the unverified output transition comprises a non-authoritative transition representing a potential movement between semantic assertions or a relationship assertion that is unverified for execution;
mapping the unverified output transition into an unverified attribute set by resolving the semantic assertions within the unverified output transition to canonical attribute identifiers in an ontology-derived vocabulary;
computing, via a formal concept analysis (FCA) component (120), a formal concept closure of the unverified attribute set with respect to the formal context and transforming the unverified output transition from a probabilistic inference into a structurally valid and symbolically grounded state for validation;
validating the unverified output transition by determining whether a closure-based admissibility condition is satisfied, wherein the closure-based admissibility condition requires the unverified output transition to be supported by and derivable from the computed formal concept closure; and
deterministically controlling the unverified output transition by executing the unverified output transition within the reasoning control flow graph only upon successful validation, or preventing execution and deterministically rejecting, constraining, or decomposing the unverified output transition prior to dissemination to eliminate the risk of hallucinated or non-compliant output.
18. The non-transitory computer-readable medium as claimed in claim 17, wherein the unverified output transition is deterministically controlled by
permitting the unverified output transition to an execution queue (128) accessible for downstream execution when the closure-based admissibility condition is satisfied; and
deterministically rejecting the unverified output transition and preventing the dissemination of a corresponding second reasoning state to the reasoning control flow graph when the closure-based admissibility condition is not satisfied,
wherein the unverified output transition is controlled by partially admitting the unverified output transition and replacing the unverified attribute set with a subset of attributes contained in the formal concept closure prior to execution.
19. The non-transitory computer-readable medium as claimed in claim 17, wherein the unverified output transition is mapped into the unverified attribute set by
performing symbol extraction to identify entities and relations within the unverified output transition;
performing event anchoring by tracing the identified entities and relations to specific event identifiers within the immutable event space (110); and
mapping the unverified output transition into the unverified attribute set, wherein the unverified attribute set is a subset of the ontology-derived attribute vocabulary determined by the anchored event identifiers,
wherein the unverified attribute set that are unresolvable to the ontology-derived attribute vocabulary, that lack a corresponding record in the immutable event space (110), or that violate symbolic grounding requirements are deterministically rejected or constrained to a closure-valid admissible subset, wherein the closure-valid admissible subset refers to a restricted portion of the unverified attribute set comprising attributes determined to be members of the computed formal concept closure, for the unverified attribute set.
20. The non-transitory computer-readable medium as claimed in claim 17, wherein the formal concept closure is computed by
computing a supporting object set comprising the plurality of enterprise objects in the immutable event space (110) that exhibits all attributes in the unverified attribute set; and
computing a closure attribute set comprising all attributes exhibited by every object in the supporting object set.
Dated this 21st April 2026
Arjun Karthik Bala
(IN/PA 1021)
Agent for Applicant
| # | Name | Date |
|---|---|---|
| 1 | 202641051495-STATEMENT OF UNDERTAKING (FORM 3) [22-04-2026(online)].pdf | 2026-04-22 |
| 2 | 202641051495-PROOF OF RIGHT [22-04-2026(online)].pdf | 2026-04-22 |
| 3 | 202641051495-POWER OF AUTHORITY [22-04-2026(online)].pdf | 2026-04-22 |
| 4 | 202641051495-FORM FOR SMALL ENTITY(FORM-28) [22-04-2026(online)].pdf | 2026-04-22 |
| 5 | 202641051495-FORM FOR SMALL ENTITY [22-04-2026(online)].pdf | 2026-04-22 |
| 6 | 202641051495-FORM 1 [22-04-2026(online)].pdf | 2026-04-22 |
| 7 | 202641051495-EVIDENCE FOR REGISTRATION UNDER SSI(FORM-28) [22-04-2026(online)].pdf | 2026-04-22 |
| 8 | 202641051495-EVIDENCE FOR REGISTRATION UNDER SSI [22-04-2026(online)].pdf | 2026-04-22 |
| 9 | 202641051495-DRAWINGS [22-04-2026(online)].pdf | 2026-04-22 |
| 10 | 202641051495-DECLARATION OF INVENTORSHIP (FORM 5) [22-04-2026(online)].pdf | 2026-04-22 |
| 11 | 202641051495-COMPLETE SPECIFICATION [22-04-2026(online)].pdf | 2026-04-22 |
| 12 | 202641051495-Request Letter-Correspondence [30-04-2026(online)].pdf | 2026-04-30 |
| 13 | 202641051495-Power of Attorney [30-04-2026(online)].pdf | 2026-04-30 |
| 14 | 202641051495-FORM28 [30-04-2026(online)].pdf | 2026-04-30 |
| 15 | 202641051495-Form 1 (Submitted on date of filing) [30-04-2026(online)].pdf | 2026-04-30 |
| 16 | 202641051495-Covering Letter [30-04-2026(online)].pdf | 2026-04-30 |
| 17 | 202641051495-FORM-9 [11-06-2026(online)].pdf | 2026-06-11 |
| 18 | 202641051495-MSME CERTIFICATE [16-06-2026(online)].pdf | 2026-06-16 |
| 19 | 202641051495-FORM28 [16-06-2026(online)].pdf | 2026-06-16 |
| 20 | 202641051495-FORM 18A [16-06-2026(online)].pdf | 2026-06-16 |
| 21 | 202641051495-PATENT_APPLICATION_PUBLICATION.pdf | 2026-06-20 |