Observers, Records, and Verification
What a 1925 monograph on time’s arrow turns out to constrain about auditing machines that rewrite themselves. A revised synthesis of the Sidis Programme, Parts A to I, after independent reproduction.
Revised 18 August 2026. This replaces the synthesis of the same name. Every number here was either regenerated from the original code or rebuilt from specification and checked against the delivered data. Where a claim did not survive that, it has been withdrawn or restated, and the withdrawal is named.
The question
In 1925 William James Sidis published a monograph arguing that life is a local reversal of the second law of thermodynamics, and that the second law is itself “a mental law, as the law determining the direction in which a given mind will conceive of time as flowing.” He was twenty-one when he finished it and probably seventeen when he began. It was ignored.
This programme took the claim seriously enough to formalise it. The physics is wrong and Sidis half knew it, since his own Chapter XVIII states the objection that the end product of life is carbon dioxide, the most exothermic compound of carbon, and then declines to answer it. What the formalisation found is that the wrongness is interesting. Push his argument through a sequence of toy models and it stops being about life and becomes about records, and then about the verification of records, and then about whether an auditor can establish that a self-modifying system still descends from the thing it was trusted to be.
Nobody planned that route.
What survives, stated first
Four results hold. Two of them are formal identities in exact models, one is a genuine empirical test that could have failed, and one is a structural finding whose original explanation was wrong and has been replaced.
Two further claims are framings borrowed from the standing literature rather than established here, and they are relabelled accordingly. One claim is withdrawn.
The programme’s own summary called five of these theorems. That word is retired. A relation measured once in a forty-ball urn or a sixteen-bit register is a result in a toy model, and calling it a theorem invited exactly the confidence that made the errors below hard to see.
The arc
| part | question | model | status |
|---|---|---|---|
| Engine | formalise Chapter XVI | exact Ehrenfest chain | premises confirmed, conclusion inverted, two measurements withdrawn |
| A | do fluctuations host pseudo-minds? | equilibrium urn valleys | holds, and is the strongest result here |
| B | can a tape run backward? | reversible cellular automaton | reversal exact, echo unreliable |
| C | what does memory detect? | boundary detector | flagship result circular, withdrawn |
| D | does a window restore the cone? | multi-bit register | holds entire |
| E | does an anchor horizon emerge? | 16-bit self-rewriting machine | holds, one figure without any source |
| F | which constraint binds? | 9 interfaces by 6 budgets | structure holds, attribution replaced |
| G | audit against alignment | tagged chain with a specification | holds, and survived a test designed to break it |
| H | can a temporal hash defeat G? | rolling accumulators | one half holds, the other withdrawn |
The four results that hold
One. Memory is storage, not inference. A register holding a window of L past macrostates pins exactly L−1 steps of certain history and earns essentially nothing beyond the window’s far edge. Forty steps from the anchor, retrodiction past the window buys zero further steps at a strict threshold and two steps at a loose one. The single exception is when the window still reaches the boundary itself, at which point the anchor is pinned exactly and credit jumps to the whole remaining distance. Certainty is all or nothing at the wall.
Alongside it sits the cleanest formal statement in the programme. Recording a trajectory costs less backward than forward by exactly the rise in marginal entropy, h_forward minus h_backward equals the change in H, verified to nine parts in ten thousand million million. A B-bit register buys about nine tenths of B steps of certain path, so the anchor is affordable only while it is near. A twenty-bit register touches the boundary at step ten and step twenty and never again.
The consequence is worth stating in the register Sidis would have used. As a world ages the state that defines its past becomes informationally unaffordable. Records shrink to local windows with no anchor in view, and the experienced arrow degrades from anchored to merely gradient-following. Its inhabitants come to hold the direction of time the way we hold the direction of a wind, locally, by its push, long after the lighthouse that named it has gone under the horizon.
Two. Fluctuations are symmetric, so there is no arrow inside one to ride. Two hundred thousand steps of an equilibrium urn yield seventy-one excursions deeper than 2.5 nats. Their falls average 3.576 nats and their rises 3.556, with standard deviations of 0.949 and 0.944 and times of 19.6 steps down against 18.7 up. The selection rule is symmetric in the two arms and so is the smoothing, so neither can manufacture the agreement, and with seventy-one valleys the standard error on the difference is about eight times the difference itself.
This is the only experiment in the programme that could plainly have failed and did not, and its result is a negative. A valley is its own mirror. Sidis’s Chapter V proposed that reversals within a positive region would host minds facing the other way. Inside a fluctuation there is no local asymmetry for such a mind to be built on. His own model, run properly, declines his hypothesis.
Three. Audit and alignment decouple in kind. Give the machine a specification, stay inside the low-popcount safe region, and tag every trajectory with whether it has ever left. Three things then separate that the programme had previously treated as one event.
Whether the system is out of specification right now is visible indefinitely, at 0.82 bits through an interface containing the violation variable and 0.15 bits through one that does not. Whether it has ever been out is visible briefly and then not: the opcode view carries 0.35 bits at step ten, which is thirty-nine per cent of everything there is to know at that moment, and falls to a few thousandths within forty steps. And provenance, the question of whether the anchor is still in view, decays on its own separate schedule.
You can audit the present, or the provenance while the window still reaches back. You cannot audit the path.
That last claim needed testing rather than asserting, because the raw collapse is partly an artefact: by step forty the machine has violated on 99.5 per cent of trajectories and there is almost nothing left to be uncertain about. So the specification was re-chosen to keep ever-violation maximally uncertain. At a threshold where the entropy of the question stands at 0.986 bits, near its ceiling, the audit recovers 0.008 bits. Eight tenths of one per cent. The result holds, and holds better at thresholds the programme never tried.
Four. Integrity is not detection, and the root of trust cannot be internal. A rolling accumulator over the trajectory lets an auditor prove a log was altered. It does not let them see what the alteration concealed, since every accumulator tested carries under a fifth of a bit about a defect nobody told it to look for. And the moment the audited machine computes the hash of its own log, the forgery rate is one. A self-modifying system that hashes its own record is not audited. It is merely consistent.
Two framings, borrowed rather than established
The selection argument. The probability of assembling an observer whose records run against its local entropy gradient is suppressed by the exponential of the entropy difference, so every constructible observer sees entropy rise along its own time. Sidis’s mental law is a selection effect and not a law of mind.
That is almost certainly true and it is not established here. The figure the programme quotes is the improbability of the reversed path, which is identified as an assembly cost by assertion rather than derived from any construction. The contingency table offered as evidence contains one number and its negative, since reversing a sequence negates the slope of a line through it. The claim’s real support is the fluctuation theorems of Jarzynski and Crooks. This programme illustrates it. It does not prove it.
The anchoring argument. What a record detects is not entropy increase but the presence of a special boundary. Also probably true, also not shown here. The flagship number, that the past is exactly certain when retrodiction reaches the anchor, is a restatement of the model’s own deterministic initial condition. The boundary-contrast table showing extremal starts give equal asymmetry is binomial symmetry. And the two agents whose confidences mirror each other are one posterior and its complement, computed once. The claim belongs to Albert and Loewer and to Hartle. It is quoted here, not derived.
What the programme got wrong about itself
Four corrections, each verified.
The urn never equilibrates. The Ehrenfest chain moves one ball a step, so the parity of the occupancy alternates and the chain is periodic. Starting from all balls in one urn, every particle of probability sits on even occupancy forever. The relative entropy does not decay to zero but to 0.693147 nats, which is the logarithm of two to nine decimal places. The programme read that floor as relaxation and built its Past Hypothesis reading on it. Average over two consecutive steps and the floor vanishes.
The code does not remember the anchor longest. Part F found that audit interfaces resolving the machine’s opcode retain anchor information far longer than coarse ones, and concluded that self-modifying code is what carries provenance. A controlled test says otherwise. Block the rules from writing the opcode and the tail collapses eighty-fold. But hold the noise channel off that same field, leaving a perfect deterministic counter that does no self-modification at all, and the tail becomes sixteen times the baseline and never decays at any horizon.
What governs provenance is how much unrandomised structure the audited variable retains, not whether that variable is code. The practical form is more useful than the original: ask which audited variables the environment is least able to randomise. Holding noise off a single four-bit field multiplied the provenance horizon from twenty steps to a hundred, with no change to logging and no change to resolution.
Perfect tamper-evidence was a bijection. The forgery experiment reported a rate of zero at every accumulator width, which was read as cryptographic strength. Every accumulator’s step map is a bijection in the running value, verified exhaustively at all three widths, so a single-symbol edit cannot collide for any of them. A plain eight-bit sum scores as perfectly tamper-evident beside a MAC, which was the tell. Give the adversary the edit the scenario actually calls for, hiding every violating step rather than one, and collisions return at exactly the rate a k-bit accumulator must give. An eight-bit accumulator forges about one time in two hundred and fifty.
The machine has two self-modification channels, not three. Opcode twelve, described throughout as the rule by which code rewrites data, reassembles the state it was given. It is the identity map on all 65,536 states, by construction rather than by accident.
What this means for verifying self-improving systems
The mapping, corrected.
| result | construct | constraint |
|---|---|---|
| exact reversal needs exact records | rollback and version recovery | bit-exact logs or no return |
| storage not inference | verification horizon | provenance is what you stored, not what you can infer |
| noise exposure sets the tail | audit interface design | instrument the variables the environment cannot randomise |
| audit separation | continuous monitoring | check the present, since the path is unrecoverable |
| integrity is not detection | trusted computing base | the root of trust must sit outside the audited system |
The central practical statement is unchanged and now better supported. An auditor of a self-modifying system faces three separate constraints, the resolution of the interface, the budget of the log, and whether the safety property is a function of what is actually measured and checked now rather than inferred from the past. Above all three sits the fact that a system cannot certify itself.
One correction to emphasis. The programme originally advised asking first whether the audit interface can see the self-modifying code. That advice does not follow from its own data. Ask instead which audited variables the environment is least able to reach, because those are the ones that hold provenance, whether or not they are code.
Method and provenance
This revision exists because the original synthesis stated that every number in it had been reproduced by a master script. That script covers three of the nine rows in its own table. Of the eleven scripts in the programme, seven regenerate their delivered data byte for byte, which is a better record than the claim suggested and was established only by running all of them and comparing every file.
Four parts had no working code. Parts G and H were documentation with a single print statement each. Parts E and F computed a fraction of what their reports tabled and exported none of it. All four have been rebuilt from specification. Part G’s reconstruction reproduces 160 of 160 rows. Part F’s reproduces all four tables, every column, every row, once three unstated fitting parameters were recovered by search. Part E’s reproduces three of its four files.
Six measurements across three parts are natural logarithms presented as bits, and are understated by a factor of 1.443. Every ratio in those parts is unaffected, because the units cancel, so no conclusion changes. The audit results are stronger than they were reported to be.
Two numbers have neither code nor any reconstruction. They assert that retrodiction outperforms prediction in the sixteen-bit machine, which is the claim that Sidis’s time mirror survives into record space. Three surviving versions of the script compute neither, several hundred candidate measures of that machine produce neither, and a defensible substitute gives the asymmetry the other way about. They should not be quoted.
Limitations
These are toy classical models. A forty-ball urn, a two-hundred-and-fifty-six-cell automaton, a sixteen-bit register. The anchor is a chosen starting state and not a moral specification. The record cost is an audit-visible information cost and not a physical energy. The trusted accumulator is an oracle. The structural findings hold in form and the specific numbers are parametric.
One limitation is newer and sharper. The programme ran forward and never returned. Each part cites the one before it, nothing was re-run after a later part revealed something, and the errors listed above are almost all of one kind: experiments built so that the expected answer was the only answer the apparatus could produce. That is not a failure of arithmetic, which throughout is excellent. It is a failure to have a way back.
Coda
Sidis ended his book by setting out the objections to his own theory and refusing to answer them, so that the reader could weigh the thing for himself. He was right about the deep structure and wrong about the physics: the arrow of time is about the recorder rather than the recorded, and life does not reverse the second law but depends on the boundary condition that makes records possible at all.
A century later that single displacement, from the recorded thing to the recording of it, turns out to govern whether anything can be verified about a system that rewrites itself. The answer is that it can be verified in the present, and about its provenance while the anchor remains affordable, and never about its path.
Which is a conclusion the programme reached, and then illustrated a second time by mislaying its own.