C9.06.3No single-sensor high-consequence actiondesignresearch

High-consequence actions must not be decided by a single sensor

Aliases: single-sensor ban · independent confirmation · common-mode failure

What it is

Delete, pay, call emergency services, unlock a door: high-consequence actions must not execute on one trigger from one physiological or context sensor. Noise, lift-off, and semantic ambiguity on a single channel become irreversible outcomes. Another independent piece of evidence, or an explicit user confirm, demotes the sensor from actor to proposer.

Why it happens

Single-sensor failure is not just independent random error. Motion artifact can raise optical heart rate and wrist acceleration together; sweat can change EDA and electrode impedance together—two streams that share a common-mode disturbance. Real independent confirmation changes physics or changes the decision-maker: a keypress besides inertia, a spoken confirm besides EDA. Bayesianly, a high prior cost demands a large likelihood ratio; one physiological signal with bounded SNR cannot supply it. Raising the threshold only reports less often; it does not prove “this time is not artifact.”

Studying it

Inject faults: break one channel (lift-off, heat, vibration) and see whether the high-consequence action still fires. Factors: physical independence of the second channel, presence of an explicit confirm. Outcomes: mistaken executions under common-mode disturbance, delay, abandonment. Independence is overstated when both streams are PPG and acceleration in the same watch. The control is “sensor only” versus “sensor plus a confirm dialogue.”

Where it stops holding

Low-consequence preload or pre-light can be single-channel. A trend hint in continuous monitoring (“activity was low today”) is not an action. Some clinical alarm rules require a single sensor to sound; that is a duty to alarm, not permission to administer a drug or lock a door. Independent confirmation raises misses: when the second channel fails, the system should degrade to the safe side (do not execute) and tell the user why nothing moved.

Applying it

  • List every irreversible or safety-involving action and forbid binding it to a single physiological trigger.
  • Prefer a second channel that changes physics or is a voluntary user act, not a second chip in the same package.
  • Keep the confirm short and completable in the current posture; do not send people to another screen in the name of independence.
  • Verify on a vibration table or a sweat protocol that disturbs only the sensor: zero executions of high-consequence actions; then measure whether miss rate of real events after adding confirm is still acceptable.

Related

  • Same group: C9.06.1 False-positive and false-negative costs are asymmetric · C9.06.2 Threshold choice is a product decision, not an algorithm decision · C9.06.4 Medical alarms usually prefer false positives over false negatives; consumer settings often reverse that · C9.06.5 Cost asymmetry should appear as a concrete classification threshold, not only as a stated principle · C9.06.6 Reusing one sensor across functions may require different false-positive tolerances · C9.06.7 Evaluating false-positive cost must include long-term trust loss, not only the harm of a single error
  • Adjacent: C9.08 Sensor Fusion · C8.04 Gaze-Plus-Confirm Combinations
  • Search: common-mode failure · independent confirmation · high-consequence action

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/C9.06.3