No Stable Self: What Self-Referential Anomaly Defence Can Certify for a Continually Learning System, Why Every Located Guarantee Holds the Benign Distribution Still, and Why Immunology's Own Answer Is a Damage Signal From Outside
Abstract
Immune-inspired security proposes that a system can protect itself by learning what it normally is and treating departures from that as threats. Continual learning makes departure the normal case: the system is supposed to change, so a poisoning campaign and a legitimate shift in the data both reach the defender as an unexplained change. This paper asks what a defence that takes its reference from the system's own history can certify in that setting, and finds the answer narrower than either side of the debate states. Three readings of "self" are separated: a frozen reference, a tolerised self that absorbs whatever persists, and a damage-keyed rule that does not need a self at all. The stationarity objection defeats only the first. The second is what many working continual defences use, and it fails differently: retrained anomaly detectors and network coordinate systems have been shown to tolerate change that is slow enough, which is also how immunology's own discontinuity theory describes the biological immune system. That continual-learning and test-time-adaptation defences fail the same way is a prediction carried over from those results, not yet tested. Every positive guarantee located here, from online centroid detectors to Byzantine aggregation to a 2026 theory of poisoning in continual learning, either holds the benign distribution fixed, bounds how far it may move, or assumes attacks are rare; none survives an unbounded legitimate shift together with a persistent minority attacker. The paper argues that the transferable lesson of immunology is the danger model rather than self/non-self discrimination, and that in a learning system a damage signal has to come from supervision held outside the update loop: trusted data, provenance, labels or a restoration point. Where such an anchor has been costed, it was cheap: one study priced its renewal at 50 analyst labels a month, and another gives a static size of 100 clean examples. Whether it can be kept fresh as legitimate data moves, and at what cost, is the open part.
Questions about this paper
Who wrote "No Stable Self"?
Pranay Mahendrakar wrote "No Stable Self: What Self-Referential Anomaly Defence Can Certify for a Continually Learning System, Why Every Located Guarantee Holds the Benign Distribution Still, and Why Immunology's Own Answer Is a Damage Signal From Outside", published 7 Oct 2026. Pranay Mahendrakar is an Indian AI specialist and LLM engineer based in Bengaluru, India. He is the Managing Director of SonyTech, Nodal Coordinator at IIRS-ISRO, and an instructor at Tutorials Point. His work covers large language models, natural language processing, computer vision and retrieval-augmented generation. He publishes open-access research papers and is the author of three books: Just AI With Pranay, Multiverse of AI and It's Me LLM.
Is "No Stable Self" free to read?
Yes. "No Stable Self" by Pranay Mahendrakar is open access under a Creative Commons Attribution 4.0 licence, with the full PDF available from Zenodo at https://doi.org/10.5281/zenodo.23213949. There is no paywall and no account required.
How do I cite "No Stable Self"?
Cite the DOI: Mahendrakar, P. (2026). No Stable Self: What Self-Referential Anomaly Defence Can Certify for a Continually Learning System, Why Every Located Guarantee Holds the Benign Distribution Still, and Why Immunology's Own Answer Is a Damage Signal From Outside. Zenodo. https://doi.org/10.5281/zenodo.23213949 A BibTeX entry is provided on this page.