Adversarial Causal Intervention Falsification

arXiv cs.LG Papers

Summary

Introduces Adversarial Causal Intervention Falsification (ACIF), a sequential game where a structural causal generator proposes observational and interventional distributions while an adversarial experimentalist selects interventions to falsify it. The paper provides theoretical guarantees, including finite-sample convergence and model-selection, bridging causal generative modeling, active discovery, and experimental design.

arXiv:2608.06427v1 Announce Type: new Abstract: Generative models can reproduce an observational distribution while encoding an incorrect causal structure. We study a sequential game in which a structural causal generator proposes observational and interventional distributions, while an adversarial experimentalist selects interventions intended to maximally falsify the generator. The discriminator is therefore not merely a real-versus-synthetic classifier: it is indexed by an intervention and tests whether the generator reproduces the corresponding post-intervention law. We introduce Adversarial Causal Intervention Falsification (ACIF), formulate oracle and implementable versions of the game, and distinguish three objects that are often conflated: observational fit, interventional equivalence over an admissible query class, and point identification of a structural causal model. For finite model and intervention classes, we prove: (i) an exact reduction of the adversarial objective to a worst-intervention integral probability metric; (ii) identification up to interventional equivalence, with point identification under a separating intervention family; (iii) existence of mixed-strategy equilibria; (iv) finite-sample uniform convergence and margin-based model-selection guarantees; and (v) a logarithmic elimination guarantee for a disagreement-driven sequential design under a balanced-separation condition. We also give a complete linear-Gaussian example in which two observationally indistinguishable causal directions are separated by a single well-chosen intervention. The framework clarifies what an adversarial causal discriminator can and cannot certify, and provides a principled bridge between causal generative modeling, active causal discovery, and experimental design.
Original Article
View Cached Full Text

Cached at: 08/10/26, 08:00 AM

# Learning Structural Generators by Selecting the Experiments That Expose Them
Source: [https://arxiv.org/html/2608.06427](https://arxiv.org/html/2608.06427)
## Adversarial Causal Intervention Falsification: Learning Structural Generators by Selecting the Experiments That Expose Them

###### Abstract

Generative models can reproduce an observational distribution while encoding an incorrect causal structure\. We study a sequential game in which a structural causal generator proposes observational and interventional distributions, while an adversarial experimentalist selects interventions intended to maximally falsify the generator\. The discriminator is therefore not merely a real\-versus\-synthetic classifier: it is indexed by an intervention and tests whether the generator reproduces the corresponding post\-intervention law\. We introduce Adversarial Causal Intervention Falsification \(ACIF\), formulate oracle and implementable versions of the game, and distinguish three objects that are often conflated: observational fit, interventional equivalence over an admissible query class, and point identification of a structural causal model\. For finite model and intervention classes, we prove: \(i\) an exact reduction of the adversarial objective to a worst\-intervention integral probability metric; \(ii\) identification up to interventional equivalence, with point identification under a separating intervention family; \(iii\) existence of mixed\-strategy equilibria; \(iv\) finite\-sample uniform convergence and margin\-based model\-selection guarantees; and \(v\) a logarithmic elimination guarantee for a disagreement\-driven sequential design under a balanced\-separation condition\. We also give a complete linear\-Gaussian example in which two observationally indistinguishable causal directions are separated by a single well\-chosen intervention\. The framework clarifies what an adversarial causal discriminator can and cannot certify, and provides a principled bridge between causal generative modeling, active causal discovery, and experimental design\.

Keywords:causal discovery; structural causal models; generative adversarial networks; active learning; intervention design; model falsification; integral probability metrics\.

## 1Introduction

A flexible generator can match the observational distribution of a system without learning its causal organization\. This is not a defect of neural networks; it is a consequence of causal non\-identifiability\. Distinct structural causal models \(SCMs\) can induce the same joint observational distribution while making incompatible predictions under intervention\. Consequently, a discriminator trained only to distinguish observed samples from synthetic observational samples cannot certify causal validity\.

This paper develops a different adversarial game\. A*structural generator*proposes a causal data\-generating process\. An*experimental adversary*chooses an intervention\. An intervention\-indexed critic then tries to distinguish samples generated by the true intervened system from samples generated by the proposed SCM under the same intervention\. The generator survives only if it matches the target system across the interventions selected by its strongest adversary\.

The proposal is related to, but distinct from, three neighboring literatures\. Causal generative models impose causal structure on deep generators and can produce interventional or counterfactual samples\(Kocaoglu et al\.,[2018](https://arxiv.org/html/2608.06427#bib.bib10); Pawlowski et al\.,[2020](https://arxiv.org/html/2608.06427#bib.bib12); Xia et al\.,[2021](https://arxiv.org/html/2608.06427#bib.bib16)\)\. Active causal discovery selects informative experiments to orient edges or reduce uncertainty over causal graphs\(He and Geng,[2008](https://arxiv.org/html/2608.06427#bib.bib8); Hauser and Bühlmann,[2012b](https://arxiv.org/html/2608.06427#bib.bib7); Agrawal et al\.,[2019](https://arxiv.org/html/2608.06427#bib.bib1); Tigas et al\.,[2023](https://arxiv.org/html/2608.06427#bib.bib15)\)\. Adversarial goodness\-of\-fit methods search for discriminators that expose discrepancies between real and simulated data\(Goodfellow et al\.,[2014](https://arxiv.org/html/2608.06427#bib.bib5); Arjovsky et al\.,[2017](https://arxiv.org/html/2608.06427#bib.bib2); Drouin et al\.,[2025](https://arxiv.org/html/2608.06427#bib.bib4)\)\. ACIF combines these ideas around a specific estimand: the worst post\-intervention discrepancy over a declared class of feasible causal queries\.

The conceptual contribution is to replace the informal statement “the discriminator verifies causality” with a precise statement: the discriminator can certify, at best,*interventional equivalence over the query class it is allowed to test*\. Point identification requires the query class to separate the candidate SCMs\. This distinction determines both the theorems and the algorithm\.

#### Contributions\.

1. 1\.We define an intervention\-indexed adversarial objective whose population value is the largest integral probability metric \(IPM\) discrepancy between the true and generated post\-intervention laws\.
2. 2\.We characterize the zero set of the game as an interventional equivalence class and give conditions under which the true SCM is uniquely identified\.
3. 3\.We introduce a prospective, implementable selector that chooses interventions using disagreement among surviving generators, since the true post\-intervention law is unavailable before the experiment is conducted\.
4. 4\.We establish uniform convergence, margin\-based recovery, mixed\-strategy equilibrium, and sequential elimination guarantees\.
5. 5\.We provide worked discrete and linear\-Gaussian examples, practical algorithms, failure modes, and an empirical protocol suitable for evaluating the method without overstating causal identification\.

## 2Background and related work

### 2\.1Structural causal models and interventions

An SCMMMover variablesX=\(X1,…,Xd\)X=\(X\_\{1\},\\ldots,X\_\{d\}\)consists of a directed acyclic graphGG, exogenous variablesU=\(U1,…,Ud\)U=\(U\_\{1\},\\ldots,U\_\{d\}\), and assignments

Xj=fj​\(XpaG⁡\(j\),Uj\),j=1,…,d\.X\_\{j\}=f\_\{j\}\(X\_\{\\operatorname\{pa\}\_\{G\}\(j\)\},U\_\{j\}\),\\qquad j=1,\\ldots,d\.\(1\)Under causal sufficiency theUjU\_\{j\}are jointly independent\. A hard interventionq=\(S,a\)q=\(S,a\)replaces the structural assignments forj∈Sj\\in SbyXj=ajX\_\{j\}=a\_\{j\}\. The resulting distribution is denotedPMqP\_\{M\}^\{q\}\. We include the null interventionq=∅q=\\varnothing, for whichPM∅P\_\{M\}^\{\\varnothing\}is observational\.

Observational Markov equivalence prevents identification of a unique DAG from conditional independences alone\. Interventions refine observational equivalence into interventional Markov equivalence\(Hauser and Bühlmann,[2012a](https://arxiv.org/html/2608.06427#bib.bib6)\)\. Active intervention design exploits this refinement by choosing targets that orient unresolved edges or maximize expected information gain\(Hauser and Bühlmann,[2012b](https://arxiv.org/html/2608.06427#bib.bib7); Agrawal et al\.,[2019](https://arxiv.org/html/2608.06427#bib.bib1); Tigas et al\.,[2023](https://arxiv.org/html/2608.06427#bib.bib15)\)\.

### 2\.2Causal generative models

CausalGAN showed that an adversarially trained generator, structured according to a supplied causal graph, can reproduce observational and interventional distributions under idealized conditions\(Kocaoglu et al\.,[2018](https://arxiv.org/html/2608.06427#bib.bib10)\)\. Deep SCMs, causal normalizing flows, and related models extend this program to high\-dimensional and counterfactual settings\(Pawlowski et al\.,[2020](https://arxiv.org/html/2608.06427#bib.bib12); Xia et al\.,[2021](https://arxiv.org/html/2608.06427#bib.bib16); Khemakhem et al\.,[2021](https://arxiv.org/html/2608.06427#bib.bib9)\)\. These methods answer causal queries only relative to their graph, structural restrictions, and data support\. ACIF is complementary: it asks which intervention should be performed to most effectively challenge the current causal generator\.

### 2\.3Adversarial testing and active experimentation

A GAN optimizes a discrepancy between a data distribution and a generated distribution through a learned critic\(Goodfellow et al\.,[2014](https://arxiv.org/html/2608.06427#bib.bib5)\)\. Wasserstein GANs and IPM\-based generative models make the discrepancy interpretation explicit\(Arjovsky et al\.,[2017](https://arxiv.org/html/2608.06427#bib.bib2); Sriperumbudur et al\.,[2012](https://arxiv.org/html/2608.06427#bib.bib14)\)\. Recent adversarial causal tuning searches jointly over causal simulation pipelines and discriminators that expose poor fit\(Drouin et al\.,[2025](https://arxiv.org/html/2608.06427#bib.bib4)\)\. Our focus is narrower and more causal: the adversary acts in the space of interventions, and the theoretical target is a family of post\-intervention laws\.

### 2\.4Differentiable and active causal discovery

A second relevant thread treats intervention targets as part of the estimation problem rather than as fixed metadata\. Differentiable causal discovery from interventional data \(DCDI\) formulates structure learning from mixed observational and interventional samples as a continuous, augmented\-Lagrangian\-constrained optimization over a weighted adjacency matrix, and shows that interventional data materially improves identifiability relative to purely observational scores\(Brouillard et al\.,[2020](https://arxiv.org/html/2608.06427#bib.bib3)\)\. Building on this line, active intervention targeting \(AIT\) learns which nodes to intervene on next, using a differentiable proxy for graph uncertainty, and shows empirically that adaptively chosen interventions reach the correct structure with substantially fewer experiments than randomly targeted ones\(Scherrer et al\.,[2021](https://arxiv.org/html/2608.06427#bib.bib13)\)\. ACIF differs from both in what it treats as the object of falsification: DCDI and AIT search over graphs using a likelihood\-style or adjacency\-matrix score, whereas ACIF poses the selection problem directly in terms of an adversarially chosen, intervention\-indexed two\-sample discrepancy, and it characterizes the population game \(equivalence classes, separating families, mixed\-strategy equilibria\) rather than only the estimator\. Sections[6](https://arxiv.org/html/2608.06427#S6)and[8\.3](https://arxiv.org/html/2608.06427#S8.SS3)make the connection to this literature concrete: the disagreement acquisition rule in \([4](https://arxiv.org/html/2608.06427#S3.E4)\) is the ACIF analogue of the acquisition functions used by AIT and by earlier score\-based active\-structure\-learning methods\(He and Geng,[2008](https://arxiv.org/html/2608.06427#bib.bib8); Hauser and Bühlmann,[2012b](https://arxiv.org/html/2608.06427#bib.bib7); Agrawal et al\.,[2019](https://arxiv.org/html/2608.06427#bib.bib1); Tigas et al\.,[2023](https://arxiv.org/html/2608.06427#bib.bib15)\), specialized to a worst\-case, critic\-detectable notion of disagreement rather than an expected information gain\.

The finite\-model sequential\-elimination result in[Theorem15](https://arxiv.org/html/2608.06427#Thmtheorem15)is also best understood against the classical theory of query\-based active learning\. Generalized binary search \(GBS\) shows that a greedy rule which repeatedly queries the point most evenly splitting the surviving hypothesis set identifies the truth inO​\(log⁡\|ℋ\|\)O\(\\log\|\\mathcal\{H\}\|\)queries whenever a geometric “neighborliness” or balanced\-split condition holds, and that this rate is information\-theoretically optimal\(Nowak,[2011](https://arxiv.org/html/2608.06427#bib.bib11)\)\.[14](https://arxiv.org/html/2608.06427#Thmtheorem14)is the causal\-falsification analogue of that condition: it asks that some affordable intervention split the surviving SCMs into two well\-separated, comparably sized groups\.[Theorem15](https://arxiv.org/html/2608.06427#Thmtheorem15)is therefore not a new information\-theoretic result so much as a transplant of the GBS argument into the setting where queries are interventions and disagreement is measured by an intervention\-indexed IPM rather than by a binary label\. This connection also explains*when*the guarantee can fail: path\-like or line\-shaped hypothesis classes, in which no single intervention removes more than anO​\(1/\|ℳ\|\)O\(1/\|\\mathcal\{M\}\|\)fraction of candidates, violate balanced separation and force near\-linear elimination, exactly as in the classical GBS lower bounds\.[Section8\.3](https://arxiv.org/html/2608.06427#S8.SS3)exhibits both regimes on the same worked family of models\.

## 3Problem formulation

### 3\.1Candidate generators, interventions, and critics

LetM⋆∈ℳM\_\{\\star\}\\in\\mathcal\{M\}be the unknown true SCM\. Letℳ\\mathcal\{M\}be a candidate class of structural generators and𝒬\\mathcal\{Q\}a set of admissible interventions\. An intervention may encode a target set, value, duration, environment, cost, or safety restriction\. Letc​\(q\)≥0c\(q\)\\geq 0denote its cost\.

For eachq∈𝒬q\\in\\mathcal\{Q\}, letℱq\\mathcal\{F\}\_\{q\}be a symmetric class of measurable critic functionsf:𝒳→\[−B,B\]f:\\mathcal\{X\}\\to\[\-B,B\]\. Define the intervention\-specific IPM

dq​\(M⋆,M\):=supf∈ℱq\|𝔼X∼PM⋆q​f​\(X\)−𝔼X∼PMq​f​\(X\)\|\.d\_\{q\}\(M\_\{\\star\},M\):=\\sup\_\{f\\in\\mathcal\{F\}\_\{q\}\}\\left\|\\mathbb\{E\}\_\{X\\sim P\_\{M\_\{\\star\}\}^\{q\}\}f\(X\)\-\\mathbb\{E\}\_\{X\\sim P\_\{M\}^\{q\}\}f\(X\)\\right\|\.\(2\)Examples include total variation, maximum mean discrepancy, and Wasserstein\-1 distance under suitable choices ofℱq\\mathcal\{F\}\_\{q\}\.

###### Definition 1\(ACIF population value\)\.

For a penalty parameterλ≥0\\lambda\\geq 0, define

Vλ​\(M\):=supq∈𝒬\{dq​\(M⋆,M\)−λ​c​\(q\)\}\.V\_\{\\lambda\}\(M\):=\\sup\_\{q\\in\\mathcal\{Q\}\}\\left\\\{d\_\{q\}\(M\_\{\\star\},M\)\-\\lambda c\(q\)\\right\\\}\.\(3\)The ACIF estimator minimizesVλ​\(M\)V\_\{\\lambda\}\(M\)overM∈ℳM\\in\\mathcal\{M\}\.

Whenλ=0\\lambda=0, the adversary selects the intervention with the largest post\-intervention discrepancy\. Forλ\>0\\lambda\>0, the adversary balances falsification power against cost\.

### 3\.2Oracle and prospective games

The objective in \([3](https://arxiv.org/html/2608.06427#S3.E3)\) is an oracle objective: it assumes access toPM⋆qP\_\{M\_\{\\star\}\}^\{q\}for everyqq\. In a real experiment, that distribution is unknown until interventionqqis conducted\. We therefore distinguish two settings\.

#### Retrospective ACIF\.

A dataset already contains samples from several environments or interventions\. The adversary reweights or selects among these observed environments to expose generator misspecification\.

#### Prospective ACIF\.

Before collecting data under a new intervention, the selector uses an ensemble or version space𝒱t⊆ℳ\\mathcal\{V\}\_\{t\}\\subseteq\\mathcal\{M\}and chooses the intervention on which surviving models disagree most:

At​\(q\):=supM,M′∈𝒱tdq​\(M,M′\)−λ​c​\(q\),qt∈arg​maxq∈𝒬⁡At​\(q\)\.A\_\{t\}\(q\):=\\sup\_\{M,M^\{\\prime\}\\in\\mathcal\{V\}\_\{t\}\}d\_\{q\}\(M,M^\{\\prime\}\)\-\\lambda c\(q\),\\qquad q\_\{t\}\\in\\operatorname\*\{arg\\,max\}\_\{q\\in\\mathcal\{Q\}\}A\_\{t\}\(q\)\.\(4\)After observing data fromPM⋆qtP\_\{M\_\{\\star\}\}^\{q\_\{t\}\}, models inconsistent with the new evidence are downweighted or removed\.

This distinction is essential\. A selector cannot maximize the unknown true discrepancy before experimentation; it can maximize predicted disagreement, expected information gain, or a robust lower bound on expected falsification power\.

### 3\.3Interventional equivalence

###### Definition 2\(𝒬\\mathcal\{Q\}\-interventional equivalence\)\.

Two SCMsMMandM′M^\{\\prime\}are equivalent over𝒬\\mathcal\{Q\}, writtenM≡𝒬,ℱM′M\\equiv\_\{\\mathcal\{Q\},\\mathcal\{F\}\}M^\{\\prime\}, if

dq​\(M,M′\)=0for every​q∈𝒬\.d\_\{q\}\(M,M^\{\\prime\}\)=0\\quad\\text\{for every \}q\\in\\mathcal\{Q\}\.\(5\)When everyℱq\\mathcal\{F\}\_\{q\}is measure determining, this is equivalent toPMq=PM′qP\_\{M\}^\{q\}=P\_\{M^\{\\prime\}\}^\{q\}for allq∈𝒬q\\in\\mathcal\{Q\}\.

###### Definition 3\(Separating intervention family\)\.

The family𝒬\\mathcal\{Q\}is separating forℳ\\mathcal\{M\}relative toℱ\\mathcal\{F\}if for every distinctM,M′∈ℳM,M^\{\\prime\}\\in\\mathcal\{M\}, there existsq∈𝒬q\\in\\mathcal\{Q\}such thatdq​\(M,M′\)\>0d\_\{q\}\(M,M^\{\\prime\}\)\>0\.

The definition makes clear that causal identification is a joint property of the model class, available interventions, and critic richness\.

## 4Population theory

### 4\.1The adversarial reduction

Define the signed critic payoff

L​\(M,q,f\)=𝔼PM⋆q​f​\(X\)−𝔼PMq​f​\(X\)−λ​c​\(q\)\.L\(M,q,f\)=\\mathbb\{E\}\_\{P\_\{M\_\{\\star\}\}^\{q\}\}f\(X\)\-\\mathbb\{E\}\_\{P\_\{M\}^\{q\}\}f\(X\)\-\\lambda c\(q\)\.\(6\)Becauseℱq\\mathcal\{F\}\_\{q\}is symmetric, absolute values can be absorbed by replacingffwith−f\-f\.

###### Theorem 4\(Worst\-intervention IPM representation\)\.

Suppose everyℱq\\mathcal\{F\}\_\{q\}is symmetric\. Then

supq∈𝒬supf∈ℱqL​\(M,q,f\)=Vλ​\(M\)\.\\sup\_\{q\\in\\mathcal\{Q\}\}\\sup\_\{f\\in\\mathcal\{F\}\_\{q\}\}L\(M,q,f\)=V\_\{\\lambda\}\(M\)\.\(7\)Consequently, the oracle adversary chooses an intervention attaining the largest critic\-detectable post\-intervention discrepancy net of cost\.

###### Proof\.

Fixqq\. By symmetry ofℱq\\mathcal\{F\}\_\{q\},

supf∈ℱq\(𝔼PM⋆q​f−𝔼PMq​f\)=supf∈ℱq\|𝔼PM⋆q​f−𝔼PMq​f\|=dq​\(M⋆,M\)\.\\sup\_\{f\\in\\mathcal\{F\}\_\{q\}\}\\left\(\\mathbb\{E\}\_\{P\_\{M\_\{\\star\}\}^\{q\}\}f\-\\mathbb\{E\}\_\{P\_\{M\}^\{q\}\}f\\right\)=\\sup\_\{f\\in\\mathcal\{F\}\_\{q\}\}\\left\|\\mathbb\{E\}\_\{P\_\{M\_\{\\star\}\}^\{q\}\}f\-\\mathbb\{E\}\_\{P\_\{M\}^\{q\}\}f\\right\|=d\_\{q\}\(M\_\{\\star\},M\)\.Subtracting the constantλ​c​\(q\)\\lambda c\(q\)and taking the supremum overqqgives \([3](https://arxiv.org/html/2608.06427#S3.E3)\)\. ∎

### 4\.2Identification and its limits

###### Theorem 5\(Identification up to interventional equivalence\)\.

AssumeM⋆∈ℳM\_\{\\star\}\\in\\mathcal\{M\},λ=0\\lambda=0, and everydqd\_\{q\}is a pseudometric\. Then

arg​minM∈ℳ⁡V0​\(M\)=\{M∈ℳ:M≡𝒬,ℱM⋆\}\.\\operatorname\*\{arg\\,min\}\_\{M\\in\\mathcal\{M\}\}V\_\{0\}\(M\)=\\\{M\\in\\mathcal\{M\}:M\\equiv\_\{\\mathcal\{Q\},\\mathcal\{F\}\}M\_\{\\star\}\\\}\.\(8\)The minimum value is zero\.

###### Proof\.

Because eachdqd\_\{q\}is nonnegative,V0​\(M\)≥0V\_\{0\}\(M\)\\geq 0\. Sincedq​\(M⋆,M⋆\)=0d\_\{q\}\(M\_\{\\star\},M\_\{\\star\}\)=0for allqq,V0​\(M⋆\)=0V\_\{0\}\(M\_\{\\star\}\)=0, so the minimum is zero\. A modelMMattains zero if and only ifsupqdq​\(M⋆,M\)=0\\sup\_\{q\}d\_\{q\}\(M\_\{\\star\},M\)=0\. Nonnegativity implies this holds if and only ifdq​\(M⋆,M\)=0d\_\{q\}\(M\_\{\\star\},M\)=0for everyqq, which is preciselyM≡𝒬,ℱM⋆M\\equiv\_\{\\mathcal\{Q\},\\mathcal\{F\}\}M\_\{\\star\}\. ∎

###### Corollary 6\(Point identification\)\.

Under the conditions of[Theorem5](https://arxiv.org/html/2608.06427#Thmtheorem5), if𝒬\\mathcal\{Q\}is separating forℳ\\mathcal\{M\}, thenM⋆M\_\{\\star\}is the unique minimizer ofV0V\_\{0\}\.

###### Proof\.

IfM≠M⋆M\\neq M\_\{\\star\}, separation gives aqqwithdq​\(M,M⋆\)\>0d\_\{q\}\(M,M\_\{\\star\}\)\>0, henceV0​\(M\)\>0=V0​\(M⋆\)V\_\{0\}\(M\)\>0=V\_\{0\}\(M\_\{\\star\}\)\. ∎

###### Proposition 8\(Effect of intervention costs\)\.

Letλ\>0\\lambda\>0and suppose the null interventionq0q\_\{0\}hasc​\(q0\)=0c\(q\_\{0\}\)=0\. ThenVλ​\(M⋆\)=0V\_\{\\lambda\}\(M\_\{\\star\}\)=0\. A false modelMMis distinguishable in the penalized game only if there existsqqsuch that

dq​\(M⋆,M\)\>λ​c​\(q\)\.d\_\{q\}\(M\_\{\\star\},M\)\>\\lambda c\(q\)\.\(9\)Thus cost penalization can intentionally enlarge the set of practically indistinguishable models\.

###### Proof\.

For the true model every discrepancy is zero, so the supremum of−λ​c​\(q\)\-\\lambda c\(q\)is zero becauseq0q\_\{0\}is available\. For a false model,Vλ​\(M\)\>0V\_\{\\lambda\}\(M\)\>0exactly when some penalized discrepancy is positive\. ∎

### 4\.3Mixed strategies

For finiteℳ\\mathcal\{M\}and𝒬\\mathcal\{Q\}, defineD​\(M,q\)=dq​\(M⋆,M\)−λ​c​\(q\)D\(M,q\)=d\_\{q\}\(M\_\{\\star\},M\)\-\\lambda c\(q\)\. A randomized generator uses a distributionμ∈Δ​\(ℳ\)\\mu\\in\\Delta\(\\mathcal\{M\}\)and a randomized adversary usesπ∈Δ​\(𝒬\)\\pi\\in\\Delta\(\\mathcal\{Q\}\), with bilinear payoff

Φ​\(μ,π\)=∑M,qμ​\(M\)​π​\(q\)​D​\(M,q\)\.\\Phi\(\\mu,\\pi\)=\\sum\_\{M,q\}\\mu\(M\)\\pi\(q\)D\(M,q\)\.\(10\)
###### Theorem 9\(Finite mixed\-strategy equilibrium\)\.

Ifℳ\\mathcal\{M\}and𝒬\\mathcal\{Q\}are finite, then

minμ∈Δ​\(ℳ\)⁡maxπ∈Δ​\(𝒬\)⁡Φ​\(μ,π\)=maxπ∈Δ​\(𝒬\)⁡minμ∈Δ​\(ℳ\)⁡Φ​\(μ,π\),\\min\_\{\\mu\\in\\Delta\(\\mathcal\{M\}\)\}\\max\_\{\\pi\\in\\Delta\(\\mathcal\{Q\}\)\}\\Phi\(\\mu,\\pi\)=\\max\_\{\\pi\\in\\Delta\(\\mathcal\{Q\}\)\}\\min\_\{\\mu\\in\\Delta\(\\mathcal\{M\}\)\}\\Phi\(\\mu,\\pi\),\(11\)and a saddle\-point pair\(μ⋆,π⋆\)\(\\mu^\{\\star\},\\pi^\{\\star\}\)exists\.

###### Proof\.

The simplices are compact and convex, andΦ\\Phiis continuous and bilinear\. The result follows from the finite\-dimensional minimax theorem\. ∎

A mixed intervention strategy is useful when no single experiment simultaneously separates all plausible models\. The equilibrium distribution concentrates experimental budget on interventions that protect against the most difficult remaining alternatives\.

## 5Finite\-sample theory

### 5\.1Empirical objective

Suppose that for eachq∈𝒬q\\in\\mathcal\{Q\}we observenqn\_\{q\}independent samplesXq,1,…,Xq,nq∼PM⋆qX\_\{q,1\},\\ldots,X\_\{q,n\_\{q\}\}\\sim P\_\{M\_\{\\star\}\}^\{q\}, and can generatemqm\_\{q\}independent samplesX~q,1M,…,X~q,mqM∼PMq\\widetilde\{X\}\_\{q,1\}^\{M\},\\ldots,\\widetilde\{X\}\_\{q,m\_\{q\}\}^\{M\}\\sim P\_\{M\}^\{q\}\. Define

d^q​\(M⋆,M\)=supf∈ℱq\|1nq​∑i=1nqf​\(Xq,i\)−1mq​∑i=1mqf​\(X~q,iM\)\|,\\widehat\{d\}\_\{q\}\(M\_\{\\star\},M\)=\\sup\_\{f\\in\\mathcal\{F\}\_\{q\}\}\\left\|\\frac\{1\}\{n\_\{q\}\}\\sum\_\{i=1\}^\{n\_\{q\}\}f\(X\_\{q,i\}\)\-\\frac\{1\}\{m\_\{q\}\}\\sum\_\{i=1\}^\{m\_\{q\}\}f\(\\widetilde\{X\}\_\{q,i\}^\{M\}\)\\right\|,\(12\)and

V^λ​\(M\)=maxq∈𝒬⁡\{d^q​\(M⋆,M\)−λ​c​\(q\)\}\.\\widehat\{V\}\_\{\\lambda\}\(M\)=\\max\_\{q\\in\\mathcal\{Q\}\}\\\{\\widehat\{d\}\_\{q\}\(M\_\{\\star\},M\)\-\\lambda c\(q\)\\\}\.\(13\)
For a general critic class, define the expected Rademacher complexities

ℜnq​\(ℱq;PM⋆q\)\\displaystyle\\mathfrak\{R\}\_\{n\_\{q\}\}\(\\mathcal\{F\}\_\{q\};P\_\{M\_\{\\star\}\}^\{q\}\)=𝔼​supf∈ℱq1nq​∑i=1nqσi​f​\(Xq,i\),\\displaystyle=\\mathbb\{E\}\\sup\_\{f\\in\\mathcal\{F\}\_\{q\}\}\\frac\{1\}\{n\_\{q\}\}\\sum\_\{i=1\}^\{n\_\{q\}\}\\sigma\_\{i\}f\(X\_\{q,i\}\),\(14\)ℜmq​\(ℱq;PMq\)\\displaystyle\\mathfrak\{R\}\_\{m\_\{q\}\}\(\\mathcal\{F\}\_\{q\};P\_\{M\}^\{q\}\)=𝔼​supf∈ℱq1mq​∑i=1mqσi​f​\(X~q,iM\)\.\\displaystyle=\\mathbb\{E\}\\sup\_\{f\\in\\mathcal\{F\}\_\{q\}\}\\frac\{1\}\{m\_\{q\}\}\\sum\_\{i=1\}^\{m\_\{q\}\}\\sigma\_\{i\}f\(\\widetilde\{X\}\_\{q,i\}^\{M\}\)\.\(15\)
###### Theorem 10\(Uniform convergence over finite model and intervention classes\)\.

Assumeℳ\\mathcal\{M\}and𝒬\\mathcal\{Q\}are finite and\|f​\(x\)\|≤B\|f\(x\)\|\\leq Bfor allqq,f∈ℱqf\\in\\mathcal\{F\}\_\{q\}, andxx\. With probability at least1−δ1\-\\delta, simultaneously for everyM∈ℳM\\in\\mathcal\{M\},

\|V^λ\(M\)−Vλ\(M\)\|≤maxq∈𝒬\[\\displaystyle\|\\widehat\{V\}\_\{\\lambda\}\(M\)\-V\_\{\\lambda\}\(M\)\|\\leq\\max\_\{q\\in\\mathcal\{Q\}\}\\Bigg\[2​ℜnq​\(ℱq;PM⋆q\)\+2​ℜmq​\(ℱq;PMq\)\\displaystyle 2\\mathfrak\{R\}\_\{n\_\{q\}\}\(\\mathcal\{F\}\_\{q\};P\_\{M\_\{\\star\}\}^\{q\}\)\+2\\mathfrak\{R\}\_\{m\_\{q\}\}\(\\mathcal\{F\}\_\{q\};P\_\{M\}^\{q\}\)\(16\)\+B2​log⁡\(4​\|ℳ\|​\|𝒬\|/δ\)nq\+B2​log⁡\(4​\|ℳ\|​\|𝒬\|/δ\)mq\]\.\\displaystyle\+B\\sqrt\{\\frac\{2\\log\(4\|\\mathcal\{M\}\|\|\\mathcal\{Q\}\|/\\delta\)\}\{n\_\{q\}\}\}\+B\\sqrt\{\\frac\{2\\log\(4\|\\mathcal\{M\}\|\|\\mathcal\{Q\}\|/\\delta\)\}\{m\_\{q\}\}\}\\Bigg\]\.\(17\)

###### Proof\.

For each fixed\(M,q\)\(M,q\), apply the standard symmetrization and bounded\-difference bound separately to the real and generated empirical processes\. A union bound over\|ℳ\|​\|𝒬\|\|\\mathcal\{M\}\|\|\\mathcal\{Q\}\|pairs gives simultaneous control of\|d^q−dq\|\|\\widehat\{d\}\_\{q\}\-d\_\{q\}\|\. Finally,

\|maxq⁡aq−maxq⁡bq\|≤maxq⁡\|aq−bq\|,\\left\|\\max\_\{q\}a\_\{q\}\-\\max\_\{q\}b\_\{q\}\\right\|\\leq\\max\_\{q\}\|a\_\{q\}\-b\_\{q\}\|,which transfers the bound toV^λ\\widehat\{V\}\_\{\\lambda\}\. ∎

[Theorem10](https://arxiv.org/html/2608.06427#Thmtheorem10)is stated at the level of abstract Rademacher complexities so that it applies uniformly across critic classes; the rate it delivers, however, depends heavily on which classℱq\\mathcal\{F\}\_\{q\}is chosen, and this choice is where the “critic\-detectable” qualifier in[Theorem4](https://arxiv.org/html/2608.06427#Thmtheorem4)does real work\.

###### Corollary 12\(Margin\-based exact recovery\)\.

SupposeM⋆M\_\{\\star\}is the unique population minimizer and

Δ:=minM≠M⋆⁡\{Vλ​\(M\)−Vλ​\(M⋆\)\}\>0\.\\Delta:=\\min\_\{M\\neq M\_\{\\star\}\}\\\{V\_\{\\lambda\}\(M\)\-V\_\{\\lambda\}\(M\_\{\\star\}\)\\\}\>0\.\(18\)If the right\-hand side of[Theorem10](https://arxiv.org/html/2608.06427#Thmtheorem10)is at mostΔ/2\\Delta/2for everyMM, then every empirical minimizer ofV^λ\\widehat\{V\}\_\{\\lambda\}equalsM⋆M\_\{\\star\}\.

###### Proof\.

Uniform error at mostΔ/2\\Delta/2implies, for everyM≠M⋆M\\neq M\_\{\\star\},

V^λ​\(M\)≥Vλ​\(M\)−Δ/2≥Vλ​\(M⋆\)\+Δ/2≥V^λ​\(M⋆\)\.\\widehat\{V\}\_\{\\lambda\}\(M\)\\geq V\_\{\\lambda\}\(M\)\-\\Delta/2\\geq V\_\{\\lambda\}\(M\_\{\\star\}\)\+\\Delta/2\\geq\\widehat\{V\}\_\{\\lambda\}\(M\_\{\\star\}\)\.Strict uniqueness follows when the uniform error is strictly belowΔ/2\\Delta/2; with the weak inequality, any tie\-breaking rule favoring the smaller confidence set recoversM⋆M\_\{\\star\}\. ∎

### 5\.2A simple bounded\-critic sample complexity

For transparent rates, suppose eachℱq\\mathcal\{F\}\_\{q\}is a finite class with\|ℱq\|≤K\|\\mathcal\{F\}\_\{q\}\|\\leq K, generated samples are arbitrarily abundant, andnq=nn\_\{q\}=n\. Hoeffding’s inequality and a union bound give the following\.

###### Corollary 13\(Finite critic class\)\.

With probability at least1−δ1\-\\delta,

supM,q\|d^q​\(M⋆,M\)−dq​\(M⋆,M\)\|≤2​B​2​log⁡\(2​\|ℳ\|​\|𝒬\|​K/δ\)n\.\\sup\_\{M,q\}\|\\widehat\{d\}\_\{q\}\(M\_\{\\star\},M\)\-d\_\{q\}\(M\_\{\\star\},M\)\|\\leq 2B\\sqrt\{\\frac\{2\\log\(2\|\\mathcal\{M\}\|\|\\mathcal\{Q\}\|K/\\delta\)\}\{n\}\}\.\(19\)Therefore, exact recovery under marginΔ\\Deltais guaranteed when

n≥32​B2Δ2​log⁡2​\|ℳ\|​\|𝒬\|​Kδ\.n\\geq\\frac\{32B^\{2\}\}\{\\Delta^\{2\}\}\\log\\frac\{2\|\\mathcal\{M\}\|\|\\mathcal\{Q\}\|K\}\{\\delta\}\.\(20\)

## 6Sequential adversarial intervention selection

### 6\.1Version\-space algorithm

Letd^q,t​\(M⋆,M\)\\widehat\{d\}\_\{q,t\}\(M\_\{\\star\},M\)be an empirical discrepancy after collecting data through roundtt\. Letβt​\(q,M\)\\beta\_\{t\}\(q,M\)be a valid confidence radius\. Define the version space

𝒱t=\{M∈ℳ:d^qs,t​\(M⋆,M\)≤βt​\(qs,M\)​for all​s≤t\}\.\\mathcal\{V\}\_\{t\}=\\left\\\{M\\in\\mathcal\{M\}:\\widehat\{d\}\_\{q\_\{s\},t\}\(M\_\{\\star\},M\)\\leq\\beta\_\{t\}\(q\_\{s\},M\)\\text\{ for all \}s\\leq t\\right\\\}\.\(21\)The prospective adversary selectsqt\+1q\_\{t\+1\}by pairwise disagreement as in \([4](https://arxiv.org/html/2608.06427#S3.E4)\)\.

Algorithm 1Adversarial Causal Intervention Falsification \(finite version space\)1:Candidate SCMs

ℳ\\mathcal\{M\}, interventions

𝒬\\mathcal\{Q\}, cost

cc, penalty

λ\\lambda, confidence level

δ\\delta
2:Initialize

𝒱0←ℳ\\mathcal\{V\}\_\{0\}\\leftarrow\\mathcal\{M\}
3:for

t=0,1,2,…t=0,1,2,\\ldotsdo

4:if

\|𝒱t\|=1\|\\mathcal\{V\}\_\{t\}\|=1then

5:returnthe remaining model

6:endif

7:

qt\+1←arg​maxq∈𝒬⁡\{supM,M′∈𝒱td^q​\(M,M′\)−λ​c​\(q\)\}q\_\{t\+1\}\\leftarrow\\operatorname\*\{arg\\,max\}\_\{q\\in\\mathcal\{Q\}\}\\left\\\{\\sup\_\{M,M^\{\\prime\}\\in\\mathcal\{V\}\_\{t\}\}\\widehat\{d\}\_\{q\}\(M,M^\{\\prime\}\)\-\\lambda c\(q\)\\right\\\}
8:Conduct intervention

qt\+1q\_\{t\+1\}and collect a batch from the real system

9:Train or update the intervention\-indexed critic for

qt\+1q\_\{t\+1\}
10:Remove models whose discrepancy exceeds the confidence threshold

11:endfor

### 6\.2Elimination under balanced separation

The next result formalizes when disagreement\-driven selection rapidly shrinks the candidate set\.

###### Assumption 14\(Balanced separation\)\.

There exist constantsρ∈\(0,1\)\\rho\\in\(0,1\)andγ\>0\\gamma\>0such that for every version space𝒱⊆ℳ\\mathcal\{V\}\\subseteq\\mathcal\{M\}containingM⋆M\_\{\\star\}with\|𝒱\|\>1\|\\mathcal\{V\}\|\>1, there is an interventionq∈𝒬q\\in\\mathcal\{Q\}and a partition𝒱=𝒱1∪𝒱2\\mathcal\{V\}=\\mathcal\{V\}\_\{1\}\\cup\\mathcal\{V\}\_\{2\}satisfying

\|𝒱1\|≤\(1−ρ\)​\|𝒱\|,\|𝒱2\|≤\(1−ρ\)​\|𝒱\|,\|\\mathcal\{V\}\_\{1\}\|\\leq\(1\-\\rho\)\|\\mathcal\{V\}\|,\\qquad\|\\mathcal\{V\}\_\{2\}\|\\leq\(1\-\\rho\)\|\\mathcal\{V\}\|,\(22\)and

infM∈𝒱1,M′∈𝒱2dq​\(M,M′\)≥γ\.\\inf\_\{M\\in\\mathcal\{V\}\_\{1\},M^\{\\prime\}\\in\\mathcal\{V\}\_\{2\}\}d\_\{q\}\(M,M^\{\\prime\}\)\\geq\\gamma\.\(23\)

###### Theorem 15\(Logarithmic elimination\)\.

Suppose[14](https://arxiv.org/html/2608.06427#Thmtheorem14)holds,M⋆∈ℳM\_\{\\star\}\\in\\mathcal\{M\}, and every selected intervention is estimated accurately enough that all pairwise discrepancies are withinγ/4\\gamma/4of their population values\. Suppose the selection rule chooses an intervention whose maximum pairwise disagreement is withinγ/4\\gamma/4of the best available disagreement and the update eliminates every model at population distance at leastγ\\gammafrom the truth under the selected intervention while retainingM⋆M\_\{\\star\}\. Then ACIF identifiesM⋆M\_\{\\star\}in at most

T≤⌈log⁡\|ℳ\|−log⁡\(1−ρ\)⌉T\\leq\\left\\lceil\\frac\{\\log\|\\mathcal\{M\}\|\}\{\-\\log\(1\-\\rho\)\}\\right\\rceil\(24\)rounds\.

###### Proof\.

At any non\-singleton version space, balanced separation provides an interventionqqand two subsets separated by at leastγ\\gamma\. Accurate discrepancy estimates and approximate maximization ensure that the selected intervention has enough detectable disagreement to distinguish the side containingM⋆M\_\{\\star\}from the opposite side\. The update retains the side containingM⋆M\_\{\\star\}and eliminates the other side\. Each side has cardinality at most\(1−ρ\)​\|𝒱t\|\(1\-\\rho\)\|\\mathcal\{V\}\_\{t\}\|, so

\|𝒱t\+1\|≤\(1−ρ\)​\|𝒱t\|\.\|\\mathcal\{V\}\_\{t\+1\}\|\\leq\(1\-\\rho\)\|\\mathcal\{V\}\_\{t\}\|\.Induction yields\|𝒱T\|≤\(1−ρ\)T​\|ℳ\|\|\\mathcal\{V\}\_\{T\}\|\\leq\(1\-\\rho\)^\{T\}\|\\mathcal\{M\}\|\. The displayed bound is the smallest integerTTfor which this quantity is at most one\. ∎

## 7Differentiable ACIF for structural neural generators

For a large or continuous model class, letMθM\_\{\\theta\}be a differentiable SCM generator and letπψ​\(q∣𝒮t\)\\pi\_\{\\psi\}\(q\\mid\\mathcal\{S\}\_\{t\}\)be an intervention policy conditioned on a state summary𝒮t\\mathcal\{S\}\_\{t\}of posterior or ensemble uncertainty\. LetDω,qD\_\{\\omega,q\}be an intervention\-indexed critic\. A retrospective objective is

minθ⁡maxψ,ω⁡𝔼q∼πψ​\[𝔼PM⋆q​Dω,q​\(X\)−𝔼PMθq​Dω,q​\(X\)−λ​c​\(q\)\]\.\\min\_\{\\theta\}\\max\_\{\\psi,\\omega\}\\mathbb\{E\}\_\{q\\sim\\pi\_\{\\psi\}\}\\left\[\\mathbb\{E\}\_\{P\_\{M\_\{\\star\}\}^\{q\}\}D\_\{\\omega,q\}\(X\)\-\\mathbb\{E\}\_\{P\_\{M\_\{\\theta\}\}^\{q\}\}D\_\{\\omega,q\}\(X\)\-\\lambda c\(q\)\\right\]\.\(25\)For prospective selection,PM⋆qP\_\{M\_\{\\star\}\}^\{q\}is unavailable before choosingqq\. One practical acquisition function is ensemble disagreement:

At​\(q\)=𝔼θ,θ′∼Πt​d^q​\(Mθ,Mθ′\)\+κ​Varθ,θ′∼Πt⁡\[d^q​\(Mθ,Mθ′\)\]−λ​c​\(q\),A\_\{t\}\(q\)=\\mathbb\{E\}\_\{\\theta,\\theta^\{\\prime\}\\sim\\Pi\_\{t\}\}\\widehat\{d\}\_\{q\}\(M\_\{\\theta\},M\_\{\\theta^\{\\prime\}\}\)\+\\kappa\\,\\operatorname\{Var\}\_\{\\theta,\\theta^\{\\prime\}\\sim\\Pi\_\{t\}\}\\left\[\\widehat\{d\}\_\{q\}\(M\_\{\\theta\},M\_\{\\theta^\{\\prime\}\}\)\\right\]\-\\lambda c\(q\),\(26\)whereΠt\\Pi\_\{t\}is an approximate posterior or bootstrap ensemble\. After the experiment, the newly observed samples enter \([25](https://arxiv.org/html/2608.06427#S7.E25)\)\.

#### Acyclicity and modularity\.

If the graph is learned, a smooth acyclicity penalty such as

h​\(A\)=tr⁡\(eA⊙A\)−dh\(A\)=\\operatorname\{tr\}\(e^\{A\\odot A\}\)\-d\(27\)can be added\(Zheng et al\.,[2018](https://arxiv.org/html/2608.06427#bib.bib17)\)\. Modular generators reuse unchanged mechanisms across interventions, while the intervened mechanisms are replaced or shifted\. This is the structural property that permits extrapolation from observed interventions to unobserved ones\.

#### Stabilization\.

In practice, the selector and critic can collude around easy distributional artifacts rather than causally meaningful differences\. Useful restrictions include: balanced intervention batches, critic regularization, cross\-fitting, sample splitting between intervention selection and model evaluation, and a held\-out set of interventions used only for final falsification\.

## 8Worked examples

### 8\.1Two observationally equivalent linear\-Gaussian SCMs

Consider centered variables\(X,Y\)\(X,Y\)with observational covariance

Σ=\(1ρρ1\),\|ρ\|<1\.\\Sigma=\\begin\{pmatrix\}1&\\rho\\\\ \\rho&1\\end\{pmatrix\},\\qquad\|\\rho\|<1\.\(28\)The same observational distribution𝒩​\(0,Σ\)\\mathcal\{N\}\(0,\\Sigma\)can be generated by either causal direction:

MX→Y:\\displaystyle M\_\{X\\to Y\}:\\quadX=UX,Y=ρ​X\+1−ρ2​UY,\\displaystyle X=U\_\{X\},\\qquad Y=\\rho X\+\\sqrt\{1\-\\rho^\{2\}\}\\,U\_\{Y\},\(29\)MY→X:\\displaystyle M\_\{Y\\to X\}:\\quadY=VY,X=ρ​Y\+1−ρ2​VX,\\displaystyle Y=V\_\{Y\},\\qquad X=\\rho Y\+\\sqrt\{1\-\\rho^\{2\}\}\\,V\_\{X\},\(30\)where all noises are independent standard normal\.

Under the interventionqa=do⁡\(X=a\)q\_\{a\}=\\operatorname\{do\}\(X=a\),

MX→Y:\\displaystyle M\_\{X\\to Y\}:\\quadY∣do⁡\(X=a\)∼𝒩​\(ρ​a,1−ρ2\),\\displaystyle Y\\mid\\operatorname\{do\}\(X=a\)\\sim\\mathcal\{N\}\(\\rho a,1\-\\rho^\{2\}\),\(31\)MY→X:\\displaystyle M\_\{Y\\to X\}:\\quadY∣do⁡\(X=a\)∼𝒩​\(0,1\)\.\\displaystyle Y\\mid\\operatorname\{do\}\(X=a\)\\sim\\mathcal\{N\}\(0,1\)\.\(32\)Thus the two SCMs are observationally indistinguishable but interventionally distinct\.

For the critic class of all 1\-Lipschitz functions, the IPM is Wasserstein\-1\. A simple lower bound follows by choosingf​\(y\)=yf\(y\)=y:

W1​\(𝒩​\(ρ​a,1−ρ2\),𝒩​\(0,1\)\)≥\|ρ​a\|\.W\_\{1\}\\left\(\\mathcal\{N\}\(\\rho a,1\-\\rho^\{2\}\),\\mathcal\{N\}\(0,1\)\\right\)\\geq\|\\rho a\|\.\(33\)Therefore, under a constraint\|a\|≤A\|a\|\\leq Aand zero intervention cost, the adversary selectsa∈\{−A,A\}a\\in\\\{\-A,A\\\}\. If the cost is quadratic,c​\(qa\)=a2c\(q\_\{a\}\)=a^\{2\}, the lower\-bound acquisition is

\|ρ​a\|−λ​a2,\|\\rho a\|\-\\lambda a^\{2\},\(34\)which is maximized at

\|a⋆\|=min⁡\{A,\|ρ\|2​λ\}\.\|a^\{\\star\}\|=\\min\\left\\\{A,\\frac\{\|\\rho\|\}\{2\\lambda\}\\right\\\}\.\(35\)The example illustrates the role of intervention strength: stronger interventions can amplify causal discrepancies, but only until cost, safety, or support constraints dominate\. We verified \([33](https://arxiv.org/html/2608.06427#S8.E33)\)–\([33](https://arxiv.org/html/2608.06427#S8.E33)\) numerically by direct maximization of\|ρ​a\|−λ​a2\|\\rho a\|\-\\lambda a^\{2\}overa∈\[0,A\]a\\in\[0,A\]\(bounded scalar optimization,ρ=0\.6\\rho=0\.6,A=3A=3\): the closed\-forma⋆=min⁡\{A,\|ρ\|/2​λ\}a^\{\\star\}=\\min\\\{A,\|\\rho\|/2\\lambda\\\}matches the numerically optimized value to four decimal places for everyλ∈\{0\.02,0\.05,0\.1,0\.2,0\.5\}\\lambda\\in\\\{0\.02,0\.05,0\.1,0\.2,0\.5\\\}tested, and the transition from the cost\-insensitive regime \(a⋆=Aa^\{\\star\}=A\) to the cost\-dominated regime \(a⋆=\|ρ\|/2​λ<Aa^\{\\star\}=\|\\rho\|/2\\lambda<A\) occurs at exactlyλ=\|ρ\|/2​A=0\.1\\lambda=\|\\rho\|/2A=0\.1as predicted; e\.g\. atλ=0\.2\\lambda=0\.2both methods returna⋆=1\.5a^\{\\star\}=1\.5with acquisition value0\.450\.45, and atλ=0\.5\\lambda=0\.5both returna⋆=0\.6a^\{\\star\}=0\.6with acquisition value0\.180\.18\. This is a minimal sanity check, but it is worth stating plainly: the closed\-form intervention\-strength rule in this subsection is not merely a stylized illustration, it is the exact maximizer of the adversary’s penalized objective\.

XXYYMX→YM\_\{X\\to Y\}XXYYMY→XM\_\{Y\\to X\}Same observational law𝒩​\(0,Σ\)\\mathcal\{N\}\(0,\\Sigma\)Different laws underdo⁡\(X=a\)\\operatorname\{do\}\(X=a\)Figure 1:Observational equivalence does not imply interventional equivalence\. ACIF selects an intervention that exposes the difference\.
### 8\.2Three\-node Markov\-equivalent chain

Consider three DAGs with the same skeleton and no collider:

G1:X1→X2→X3,G2:X1←X2→X3,G3:X1←X2←X3\.G\_\{1\}:X\_\{1\}\\to X\_\{2\}\\to X\_\{3\},\\qquad G\_\{2\}:X\_\{1\}\\leftarrow X\_\{2\}\\to X\_\{3\},\\qquad G\_\{3\}:X\_\{1\}\\leftarrow X\_\{2\}\\leftarrow X\_\{3\}\.\(36\)Under a faithful observational distribution they belong to the same observational Markov equivalence class\. Intervening on the middle variableX2X\_\{2\}is especially informative: it deletes incoming edges intoX2X\_\{2\}and reveals whether changes propagate toX1X\_\{1\},X3X\_\{3\}, both, or neither\. A critic over the joint post\-intervention distribution can exploit mean shifts, variance changes, or conditional dependence changes\.

Suppose each directed edge has linear coefficientb≠0b\\neq 0, each noise has variance one, and the intervention isdo⁡\(X2=a\)\\operatorname\{do\}\(X\_\{2\}=a\)\. Then the mean vectors predicted by the three graphs have the schematic forms

μ1​\(a\)\\displaystyle\\mu\_\{1\}\(a\)=\(0,a,b​a\),\\displaystyle=\(0,a,ba\),\(37\)μ2​\(a\)\\displaystyle\\mu\_\{2\}\(a\)=\(b​a,a,b​a\),\\displaystyle=\(ba,a,ba\),\(38\)μ3​\(a\)\\displaystyle\\mu\_\{3\}\(a\)=\(b​a,a,0\),\\displaystyle=\(ba,a,0\),\(39\)when parameters are normalized symmetrically for illustration\. The middle\-node intervention produces pairwise mean separation proportional to\|b​a\|\|ba\|and distinguishes all three candidates in one experiment\. Intervening only on an endpoint generally separates fewer orientations\. This is precisely the type of intervention the disagreement acquisition in \([4](https://arxiv.org/html/2608.06427#S3.E4)\) favors\.

### 8\.3Numerical illustration: disagreement\-driven selection versus random selection

The three\-node example shows*qualitatively*that intervening on the right node separates more candidate structures per experiment than intervening on an endpoint\. We now report a small, fully reproducible computation that turns this into a*quantitative*comparison, directly implementing[Algorithm1](https://arxiv.org/html/2608.06427#alg1)and testing[Theorem15](https://arxiv.org/html/2608.06427#Thmtheorem15), rather than only asserting the algorithm’s behavior\.

#### Setup\.

Take a44\-node path skeletonX1−X2−X3−X4X\_\{1\}\\\!\-\\\!X\_\{2\}\\\!\-\\\!X\_\{3\}\\\!\-\\\!X\_\{4\}with linear\-Gaussian mechanisms of coefficient magnitude0\.80\.8\. Every acyclic orientation of the three skeleton edges is a valid DAG \(a path skeleton has no colliders to create cycles\), giving a candidate classℳ\\mathcal\{M\}of\|ℳ\|=23=8\|\\mathcal\{M\}\|=2^\{3\}=8SCMs, all observationally compatible with the same undirected skeleton\. The admissible interventions are𝒬=\{do⁡\(Xi=a\):i∈\{1,2,3,4\},a∈\{−1\.5,1\.5\}\}\\mathcal\{Q\}=\\\{\\operatorname\{do\}\(X\_\{i\}=a\):i\\in\\\{1,2,3,4\\\},\\,a\\in\\\{\-1\.5,1\.5\\\}\\\}, anddq​\(M,M′\)d\_\{q\}\(M,M^\{\\prime\}\)is taken to be theℓ1\\ell\_\{1\}distance between the two post\-intervention mean vectors \(the analogue of the linear\-critic lower bound used in[Equation33](https://arxiv.org/html/2608.06427#S8.E33)\)\. For each candidate true modelM⋆∈ℳM\_\{\\star\}\\in\\mathcal\{M\}, we ran[Algorithm1](https://arxiv.org/html/2608.06427#alg1)with the exact disagreement acquisition \([4](https://arxiv.org/html/2608.06427#S3.E4)\) \(λ=0\\lambda=0, noiseless outcomes, elimination by exact mean disagreement\) and compared it against a policy that selectsqt\+1q\_\{t\+1\}uniformly at random from𝒬\\mathcal\{Q\}at every round, averaged over200200random seeds per true model\.

#### Results\.

Disagreement\-driven selection identifies the true model in11or22rounds for every one of the88candidates \(mean1\.501\.50rounds\), while random selection needs on average2\.242\.24rounds to reach the same singleton version space – roughly50%50\\%more experiments for this class\. The single most informative intervention is always a hard intervention on the middle nodesX2X\_\{2\}orX3X\_\{3\}: at the full version space \(\|𝒱0\|=8\|\\mathcal\{V\}\_\{0\}\|=8\), intervening onX2X\_\{2\}\(orX3X\_\{3\}\) partitions the88candidates into groups of size at most22, achieving a split fractionρ=1−2/8=0\.75\\rho=1\-2/8=0\.75in the sense of[14](https://arxiv.org/html/2608.06427#Thmtheorem14), whereas intervening on an endpoint node \(X1X\_\{1\}orX4X\_\{4\}\) partitions the same88candidates far less evenly, because the edge orientation nearest the endpoint alone determines whether the effect propagates at all\. Substitutingρ=0\.75\\rho=0\.75and\|ℳ\|=8\|\\mathcal\{M\}\|=8into the bound of[Theorem15](https://arxiv.org/html/2608.06427#Thmtheorem15)gives

T≤⌈log⁡8−log⁡\(0\.25\)⌉=2,T\\leq\\left\\lceil\\frac\{\\log 8\}\{\-\\log\(0\.25\)\}\\right\\rceil=2,\(40\)which matches the simulation exactly: the disagreement policy never needs more than22rounds, and the bound is tight for everyM⋆M\_\{\\star\}requiring22rounds\. Table[1](https://arxiv.org/html/2608.06427#S8.T1)summarizes the outcome; full simulation code is a direct transcription of[Algorithm1](https://arxiv.org/html/2608.06427#alg1)\.

Table 1:Rounds to unique identification,44\-node path family,\|ℳ\|=8\|\\mathcal\{M\}\|=8, averaged over true models \(random policy additionally averaged over200200seeds per true model\)\.
#### Interpretation\.

This example also demonstrates the failure mode flagged in the remark following[Theorem15](https://arxiv.org/html/2608.06427#Thmtheorem15): had the candidate class instead been built so that*every*intervention only ever separates one candidate from the rest \(for instance, a class of\|ℳ\|\|\\mathcal\{M\}\|models that differ pairwise only in a single, distinct edge each, with no intervention capable of testing two edges at once\), the same disagreement rule degrades to near\-linear elimination, because[14](https://arxiv.org/html/2608.06427#Thmtheorem14)would fail withρ=O​\(1/\|ℳ\|\)\\rho=O\(1/\|\\mathcal\{M\}\|\)\. The gap between the two policies in Table[1](https://arxiv.org/html/2608.06427#S8.T1)is therefore itself evidence for, not just an application of, the theory in[Section6](https://arxiv.org/html/2608.06427#S6): it isolates the balanced\-separation condition as the quantity governing how much an adversarial experimentalist can outperform a naive one, in line with the classical generalized\-binary\-search rate\(Nowak,[2011](https://arxiv.org/html/2608.06427#bib.bib11)\)discussed in[Section6](https://arxiv.org/html/2608.06427#S6)and mirroring the empirical gains reported for active intervention targeting on larger neural causal models\(Scherrer et al\.,[2021](https://arxiv.org/html/2608.06427#bib.bib13)\)\.

### 8\.4Binary treatment with distributional causal effects

LetT∈\{0,1\}T\\in\\\{0,1\\\}, covariatesZZ, and outcomeYY\. Two generators can agree on the average treatment effect while disagreeing on tails or heterogeneity:

𝔼M1​\[Y∣do⁡\(T=1\)\]−𝔼M1​\[Y∣do⁡\(T=0\)\]=𝔼M2​\[Y∣do⁡\(T=1\)\]−𝔼M2​\[Y∣do⁡\(T=0\)\],\\mathbb\{E\}\_\{M\_\{1\}\}\[Y\\mid\\operatorname\{do\}\(T=1\)\]\-\\mathbb\{E\}\_\{M\_\{1\}\}\[Y\\mid\\operatorname\{do\}\(T=0\)\]=\\mathbb\{E\}\_\{M\_\{2\}\}\[Y\\mid\\operatorname\{do\}\(T=1\)\]\-\\mathbb\{E\}\_\{M\_\{2\}\}\[Y\\mid\\operatorname\{do\}\(T=0\)\],\(41\)but

PM1​\(Y∣do⁡\(T=t\),Z=z\)≠PM2​\(Y∣do⁡\(T=t\),Z=z\)\.P\_\{M\_\{1\}\}\(Y\\mid\\operatorname\{do\}\(T=t\),Z=z\)\\neq P\_\{M\_\{2\}\}\(Y\\mid\\operatorname\{do\}\(T=t\),Z=z\)\.\(42\)An intervention\-indexed neural critic can test the entire conditional outcome distribution rather than a single estimand\. The selector may choose treatment arms and covariate strata where model disagreement is largest\. However, overlap and ethical constraints must be encoded in𝒬\\mathcal\{Q\}andc​\(q\)c\(q\); ACIF does not justify infeasible or unsafe experiments\.

## 9Implementation blueprint

### 9\.1Data structure

Each sample should carry an environment labelee, intervention targetSeS\_\{e\}, intervention value or mechanism descriptoraea\_\{e\}, observed variables, and any design probabilities\. For randomized experiments, treatment assignment probabilities should be stored to permit design\-aware evaluation\. For soft interventions, the model must represent which mechanism changed rather than pretending that the variable was fixed\.

### 9\.2Training loop

A practical neural implementation alternates four operations:

1. 1\.Generator update:fit observational and accumulated interventional data under a modular SCM architecture\.
2. 2\.Critic update:for each observed intervention, distinguish real post\-intervention samples from generated samples under the same intervention\.
3. 3\.Uncertainty update:maintain bootstrap generators, a variational posterior, or an ensemble of graph/mechanism candidates\.
4. 4\.Intervention selection:maximize ensemble disagreement or expected falsification power, subject to cost and feasibility\.

A robust objective is

minθmaxω∑e∈ℰtwe\[\\displaystyle\\min\_\{\\theta\}\\max\_\{\\omega\}\\sum\_\{e\\in\\mathcal\{E\}\_\{t\}\}w\_\{e\}\\Big\[𝔼PM⋆qeDω,e\(X\)−𝔼PMθqeDω,e\(X\)\]\\displaystyle\\mathbb\{E\}\_\{P\_\{M\_\{\\star\}\}^\{q\_\{e\}\}\}D\_\{\\omega,e\}\(X\)\-\\mathbb\{E\}\_\{P\_\{M\_\{\\theta\}\}^\{q\_\{e\}\}\}D\_\{\\omega,e\}\(X\)\\Big\]\(43\)\+η​h​\(Aθ\)\+τ​Ω​\(θ\),\\displaystyle\+\\eta h\(A\_\{\\theta\}\)\+\\tau\\Omega\(\\theta\),\(44\)wherewew\_\{e\}may be selected adversarially over the simplex,h​\(Aθ\)h\(A\_\{\\theta\}\)enforces acyclicity, andΩ\\Omegaregularizes mechanisms\.

### 9\.3Evaluation metrics

A credible empirical study should report more than observational sample quality\. Recommended metrics are:

1. 1\.observational held\-out log score or two\-sample distance;
2. 2\.held\-out interventional IPM averaged over interventions;
3. 3\.worst\-intervention IPM;
4. 4\.structural Hamming distance when a ground\-truth graph exists;
5. 5\.error in target causal estimands, including distributional and heterogeneous effects;
6. 6\.number and total cost of interventions required to reach a fixed identification confidence;
7. 7\.calibration of the surviving model set or posterior\.

## 10Suggested experiments

### 10\.1Synthetic benchmarks

Use linear Gaussian, nonlinear additive\-noise, post\-nonlinear, and discrete Bayesian\-network SCMs\. Generate observational data first, then allow each method a fixed intervention budget\. Compare:

1. 1\.random intervention selection;
2. 2\.edge\-orientation heuristics;
3. 3\.expected\-information\-gain design;
4. 4\.gradient\-based intervention targeting;
5. 5\.ACIF disagreement selection;
6. 6\.oracle worst\-discrepancy selection as an unattainable upper benchmark\.

Vary graph size, density, intervention cost, sample size per experiment, hidden confounding, critic capacity, and model misspecification\. The primary endpoint should be held\-out worst\-intervention error after each unit of experimental cost\.

### 10\.2Semi\-synthetic and real interventional data

Suitable applications include gene perturbation data, flow\-cytometry networks, or other datasets with multiple known interventions\. The retrospective version can hide a subset of interventions during training and test whether the learned generator predicts them\. A prospective simulation can reveal interventions sequentially according to each acquisition policy\.

### 10\.3Ablations

Ablate the intervention selector, critic family, cost term, ensemble size, acyclicity penalty, and modularity constraints\. A particularly important ablation compares a single observational discriminator with intervention\-indexed critics\. The expected result is not necessarily better observational realism, but better transport to held\-out interventions\.

## 11Failure modes and scope

#### Non\-identifiability\.

If the admissible interventions do not separate the candidate models, the method can identify only an equivalence class\. This is a mathematical limitation, not a training failure\.

#### Model misspecification\.

IfM⋆∉ℳM\_\{\\star\}\\notin\\mathcal\{M\}, ACIF returns a minimax approximation: the model with the smallest worst\-intervention discrepancy\. A small value has meaning only relative to the intervention and critic classes\.

#### Latent confounding\.

A DAG with independent exogenous noises is inappropriate when hidden common causes remain\. One should enlarge the model class to acyclic directed mixed graphs, latent\-variable SCMs, or explicitly confounded structural generators\.

#### Adaptive overfitting\.

Repeatedly choosing interventions based on the same critics can overfit the acquisition rule\. Held\-out interventions, confidence sequences, and sample splitting mitigate this problem\.

#### Support and extrapolation\.

An intervention far outside the observational support can generate a large discriminator signal for reasons unrelated to causal orientation\. Feasible intervention sets, overlap penalties, and mechanistic priors should prevent meaningless extrapolation\.

#### Ethics and feasibility\.

The maximally discriminating intervention may be expensive, harmful, or impossible\. The admissible set𝒬\\mathcal\{Q\}must be defined before optimization, and costs should reflect operational and ethical constraints\. The mathematical adversary is subordinate to the experimental protocol\.

## 12Discussion

ACIF reframes causal generative learning as repeated model criticism\. The generator is not rewarded merely for producing realistic observations\. It must survive the interventions on which plausible causal explanations disagree most\. This changes the role of the discriminator from a generic sample\-quality judge to a family of causal falsification tests indexed by experimental actions\.

The framework also clarifies the relation between adversarial learning and classical scientific reasoning\. A causal hypothesis gains credibility not because it cannot be distinguished from observed data in one regime, but because it continues to predict data after carefully chosen perturbations\. The correct mathematical endpoint is therefore not “causality verified,” but “no admissible critic can distinguish the model from the system over the tested intervention family, at the available resolution\.”

Several extensions are immediate\. First, intervention selection can target a downstream causal estimand rather than full model identification\. Second, a robust adversary can select both an intervention and a subpopulation\. Third, sequential design can incorporate long\-horizon value, where an intervention is useful because it unlocks more informative later experiments\. Fourth, the generator can output a set or posterior of SCMs, allowing the adversary to optimize reduction in decision\-relevant uncertainty rather than forcing premature point selection\.

The numerical illustration in[Section8\.3](https://arxiv.org/html/2608.06427#S8.SS3)is deliberately small, but it makes the theory falsifiable in the ordinary sense:[Theorem15](https://arxiv.org/html/2608.06427#Thmtheorem15)predicts a specific round count onceρ\\rhois computed from the candidate class, and the simulation matches that prediction exactly rather than merely being consistent with it in direction\. The same exercise also locates ACIF relative to the differentiable causal discovery literature it builds on\(Brouillard et al\.,[2020](https://arxiv.org/html/2608.06427#bib.bib3); Scherrer et al\.,[2021](https://arxiv.org/html/2608.06427#bib.bib13)\): those methods demonstrate, empirically and at scale, that adaptively chosen interventions outperform random ones; the contribution here is a population\-level account of*why*, in terms of a worst\-intervention IPM and a balanced\-separation condition that connects directly to the classical rate for generalized binary search\(Nowak,[2011](https://arxiv.org/html/2608.06427#bib.bib11)\)\. Scaling the finite\-model\-class analysis to the continuous, neural setting of[Equation25](https://arxiv.org/html/2608.06427#S7.E25)– whereℳ\\mathcal\{M\}is uncountable andρ\\rhomust be estimated rather than computed exactly – is the most direct next step, and the synthetic\-benchmark protocol of[Section8](https://arxiv.org/html/2608.06427#S8)is designed to be extendable to that setting without modification\.

## 13Conclusion

We introduced Adversarial Causal Intervention Falsification, a minimax framework in which a structural generator is challenged by an adversary that selects interventions\. The population game reduces to a worst\-intervention IPM\. Its minimizers are exactly the models interventionally equivalent to the truth over the allowed query class, and the truth is uniquely identified when that class separates the candidates\. Finite\-sample and sequential results show how critic complexity, causal margins, and intervention geometry govern recovery\. The framework does not circumvent causal assumptions; instead, it makes their consequences explicit and uses experiments strategically to falsify incorrect structural generators\.

## Appendix AAdditional proofs and technical details

### A\.1Measure\-determining critics

A function classℱ\\mathcal\{F\}is measure determining if

𝔼P​f=𝔼Q​ffor every​f∈ℱ\\mathbb\{E\}\_\{P\}f=\\mathbb\{E\}\_\{Q\}f\\quad\\text\{for every \}f\\in\\mathcal\{F\}impliesP=QP=Q\. Bounded continuous functions are measure determining on standard metric spaces\. The unit ball of a characteristic reproducing\-kernel Hilbert space yields maximum mean discrepancy, while 1\-Lipschitz functions yield Wasserstein\-1 when first moments are finite\.

###### Lemma 17\(Monotonicity in the intervention class\)\.

If𝒬1⊆𝒬2\\mathcal\{Q\}\_\{1\}\\subseteq\\mathcal\{Q\}\_\{2\}andλ=0\\lambda=0, then

V0𝒬1​\(M\)≤V0𝒬2​\(M\)V^\{\\mathcal\{Q\}\_\{1\}\}\_\{0\}\(M\)\\leq V^\{\\mathcal\{Q\}\_\{2\}\}\_\{0\}\(M\)\(45\)for everyMM, and the equivalence class under𝒬2\\mathcal\{Q\}\_\{2\}is contained in the equivalence class under𝒬1\\mathcal\{Q\}\_\{1\}\.

###### Proof\.

The supremum over a larger set cannot decrease\. IfMMagrees withM⋆M\_\{\\star\}under every intervention in𝒬2\\mathcal\{Q\}\_\{2\}, it agrees under every intervention in the subset𝒬1\\mathcal\{Q\}\_\{1\}\. ∎

###### Lemma 18\(Robustness to approximate optimization\)\.

LetM^\\widehat\{M\}satisfy

V^λ​\(M^\)≤infM∈ℳV^λ​\(M\)\+εopt\.\\widehat\{V\}\_\{\\lambda\}\(\\widehat\{M\}\)\\leq\\inf\_\{M\\in\\mathcal\{M\}\}\\widehat\{V\}\_\{\\lambda\}\(M\)\+\\varepsilon\_\{\\mathrm\{opt\}\}\.\(46\)IfsupM\|V^λ​\(M\)−Vλ​\(M\)\|≤εstat\\sup\_\{M\}\|\\widehat\{V\}\_\{\\lambda\}\(M\)\-V\_\{\\lambda\}\(M\)\|\\leq\\varepsilon\_\{\\mathrm\{stat\}\}, then

Vλ​\(M^\)≤infM∈ℳVλ​\(M\)\+2​εstat\+εopt\.V\_\{\\lambda\}\(\\widehat\{M\}\)\\leq\\inf\_\{M\\in\\mathcal\{M\}\}V\_\{\\lambda\}\(M\)\+2\\varepsilon\_\{\\mathrm\{stat\}\}\+\\varepsilon\_\{\\mathrm\{opt\}\}\.\(47\)

###### Proof\.

LetM⋆∈arg​minM⁡Vλ​\(M\)M^\{\\star\}\\in\\operatorname\*\{arg\\,min\}\_\{M\}V\_\{\\lambda\}\(M\)\. Then

Vλ​\(M^\)\\displaystyle V\_\{\\lambda\}\(\\widehat\{M\}\)≤V^λ​\(M^\)\+εstat\\displaystyle\\leq\\widehat\{V\}\_\{\\lambda\}\(\\widehat\{M\}\)\+\\varepsilon\_\{\\mathrm\{stat\}\}≤V^λ​\(M⋆\)\+εopt\+εstat\\displaystyle\\leq\\widehat\{V\}\_\{\\lambda\}\(M^\{\\star\}\)\+\\varepsilon\_\{\\mathrm\{opt\}\}\+\\varepsilon\_\{\\mathrm\{stat\}\}≤Vλ​\(M⋆\)\+2​εstat\+εopt\.\\displaystyle\\leq V\_\{\\lambda\}\(M^\{\\star\}\)\+2\\varepsilon\_\{\\mathrm\{stat\}\}\+\\varepsilon\_\{\\mathrm\{opt\}\}\.∎

### A\.2Connection to hypothesis testing

For a fixed interventionqqand candidate modelMM, testing

H0:PM⋆q=PMqH\_\{0\}:P\_\{M\_\{\\star\}\}^\{q\}=P\_\{M\}^\{q\}\(48\)against a composite alternative can be implemented with a two\-sample statistic induced byℱq\\mathcal\{F\}\_\{q\}\. ACIF adds an outer optimization overqq\. When the same data are used both to selectqqand testH0H\_\{0\}, ordinary fixed\-testpp\-values are invalid\. Prospective experimentation avoids part of this issue becauseqqis chosen before its outcome data are collected\. Retrospective selection requires selective\-inference corrections, sample splitting, or a held\-out evaluation set\.

## Appendix BPseudocode for a neural implementation

Algorithm 2Differentiable ensemble ACIF1:Observational data

𝒟0\\mathcal\{D\}\_\{0\}, feasible interventions

𝒬\\mathcal\{Q\}, ensemble size

KK
2:Train

KKstructural generators

\{Mθk\}k=1K\\\{M\_\{\\theta\_\{k\}\}\\\}\_\{k=1\}^\{K\}using bootstrap or posterior sampling

3:for

t=1,…,Tt=1,\\ldots,Tdo

4:forcandidate intervention

q∈𝒬q\\in\\mathcal\{Q\}do

5:Generate samples from

PMθkqP\_\{M\_\{\\theta\_\{k\}\}\}^\{q\}for all

kk
6:Estimate pairwise critic distances and acquisition

At​\(q\)A\_\{t\}\(q\)
7:endfor

8:Select

qt∈arg​maxq⁡At​\(q\)q\_\{t\}\\in\\operatorname\*\{arg\\,max\}\_\{q\}A\_\{t\}\(q\)subject to feasibility and budget

9:Conduct

qtq\_\{t\}and append real samples to

𝒟t\\mathcal\{D\}\_\{t\}
10:Update intervention\-indexed critics using real and generated samples

11:Update or resample the structural\-generator ensemble

12:endfor

13:Return the ensemble, its interventional predictions, and held\-out falsification scores

## Appendix CChecklist for claims in an empirical paper

A paper using ACIF should explicitly state:

1. 1\.the candidate SCM class and whether latent confounding is allowed;
2. 2\.the intervention family and why each intervention is feasible;
3. 3\.the critic class and the distributional discrepancies it can detect;
4. 4\.whether intervention selection is oracle, retrospective, or prospective;
5. 5\.the uncertainty representation used before new experiments;
6. 6\.whether point identification or only equivalence\-class recovery is theoretically possible;
7. 7\.how adaptive selection is separated from final evaluation;
8. 8\.which results are empirical findings and which are assumptions or simulations\.

## References

- Agrawal et al\. \(2019\)Agrawal, R\., Squires, C\., Yang, K\. D\., Shanmugam, K\., and Uhler, C\. \(2019\)\. ABCD\-strategy: Budgeted experimental design for targeted causal structure discovery\.*Proceedings of AISTATS*, 3400–3409\.
- Arjovsky et al\. \(2017\)Arjovsky, M\., Chintala, S\., and Bottou, L\. \(2017\)\. Wasserstein generative adversarial networks\.*Proceedings of ICML*, 214–223\.
- Brouillard et al\. \(2020\)Brouillard, P\., Lachapelle, S\., Lacoste, A\., Lacoste\-Julien, S\., and Drouin, A\. \(2020\)\. Differentiable causal discovery from interventional data\.*Advances in Neural Information Processing Systems*, 33:21865–21877\.
- Drouin et al\. \(2025\)Drouin, A\., Andrews, B\., et al\. \(2025\)\. Adversarial causal tuning for realistic time\-series generation\.*arXiv preprint arXiv:2506\.02084*\.
- Goodfellow et al\. \(2014\)Goodfellow, I\., Pouget\-Abadie, J\., Mirza, M\., Xu, B\., Warde\-Farley, D\., Ozair, S\., Courville, A\., and Bengio, Y\. \(2014\)\. Generative adversarial nets\.*Advances in Neural Information Processing Systems*, 27\.
- Hauser and Bühlmann \(2012a\)Hauser, A\. and Bühlmann, P\. \(2012a\)\. Characterization and greedy learning of interventional Markov equivalence classes of directed acyclic graphs\.*Journal of Machine Learning Research*, 13:2409–2464\.
- Hauser and Bühlmann \(2012b\)Hauser, A\. and Bühlmann, P\. \(2012b\)\. Two optimal strategies for active learning of causal models from interventional data\.*arXiv preprint arXiv:1205\.4174*\.
- He and Geng \(2008\)He, Y\.\-B\. and Geng, Z\. \(2008\)\. Active learning of causal networks with intervention experiments and optimal designs\.*Journal of Machine Learning Research*, 9:2523–2547\.
- Khemakhem et al\. \(2021\)Khemakhem, I\., Monti, R\., Leech, R\., and Hyvärinen, A\. \(2021\)\. Causal autoregressive flows\.*Proceedings of AISTATS*, 3520–3528\.
- Kocaoglu et al\. \(2018\)Kocaoglu, M\., Snyder, C\., Dimakis, A\. G\., and Vishwanath, S\. \(2018\)\. CausalGAN: Learning causal implicit generative models with adversarial training\.*International Conference on Learning Representations*\.
- Nowak \(2011\)Nowak, R\. D\. \(2011\)\. The geometry of generalized binary search\.*IEEE Transactions on Information Theory*, 57\(12\):7893–7906\.
- Pawlowski et al\. \(2020\)Pawlowski, N\., Coelho de Castro, D\., and Glocker, B\. \(2020\)\. Deep structural causal models for tractable counterfactual inference\.*Advances in Neural Information Processing Systems*, 33:857–869\.
- Scherrer et al\. \(2021\)Scherrer, N\., Bilaniuk, O\., Annadani, Y\., Goyal, A\., Schwab, P\., Schölkopf, B\., Mozer, M\. C\., Bengio, Y\., Bauer, S\., and Ke, N\. R\. \(2021\)\. Learning neural causal models with active interventions\.*arXiv preprint arXiv:2109\.02429*\.
- Sriperumbudur et al\. \(2012\)Sriperumbudur, B\. K\., Fukumizu, K\., Gretton, A\., Schölkopf, B\., and Lanckriet, G\. R\. G\. \(2012\)\. On the empirical estimation of integral probability metrics\.*Electronic Journal of Statistics*, 6:1550–1599\.
- Tigas et al\. \(2023\)Tigas, P\., Jesson, A\., Gal, Y\., Foster, A\., and Bauer, S\. \(2023\)\. Differentiable multi\-target causal Bayesian experimental design\.*Proceedings of ICML*, 34263–34279\.
- Xia et al\. \(2021\)Xia, K\., Lee, K\.\-Z\., Bengio, Y\., and Bareinboim, E\. \(2021\)\. The causal\-neural connection: Expressiveness, learnability, and inference\.*Advances in Neural Information Processing Systems*, 34\.
- Zheng et al\. \(2018\)Zheng, X\., Aragam, B\., Ravikumar, P\. K\., and Xing, E\. P\. \(2018\)\. DAGs with NO TEARS: Continuous optimization for structure learning\.*Advances in Neural Information Processing Systems*, 31\.

Similar Articles

Information-Directed Sampling for Causal Bandits

arXiv cs.LG

This paper studies contextual causal bandits with non-manipulable variables, proposing causal variants of Thompson Sampling and Information-Directed Sampling (IDS) that exploit shared causal mechanisms to accelerate decision-making. Theoretical regret bounds and experiments on synthetic tasks show that the proposed methods outperform causal and non-causal baselines.

CausaLab: A Scalable Environment for Interactive Causal Discovery Toward AI Scientists

Hugging Face Daily Papers

CausaLab is a scalable environment for evaluating LLM agents on interactive causal discovery, assessing both predictive accuracy and faithful recovery of underlying causal mechanisms. Experiments reveal a gap between prediction and mechanism recovery, highlighting limits in current LLM agents as experimental causal reasoners.