A single reading leaves the count open
A tokamak control system has to hold the electron density. It sets the operating point, governs fueling and the approach to the density limit, and enters disruption avoidance. ITER's primary diagnostic for real-time density control is a five-channel Toroidal Interferometer and Polarimeter, and the way such an instrument works has an awkward property. The interferometer measures a phase proportional to the line-integrated density, wrapped into a single fringe.
Most of the measurement lives in the number of whole fringes accumulated since the discharge began, and that number is not uniquely determined by the instantaneous wrapped-phase measurement. Recovering it takes additional information and explicit assumptions: in practice the history of the signal, and whatever other channels the instrument carries. When edge-localized modes, fast density rises, pellet injection or a disruption refract the beam, cut the signal amplitude and break phase continuity, the recovered count can jump by whole fringes. The density handed to the control loop inherits the error.
Count and density can part company
The correction approaches Engineering Note EN-003 reviews compare two wavelengths, consult a polarimeter, run phase counters and model-based observers, and more recently machine-learning classifiers. What the note observes about them is a shared framing: they treat the problem primarily as fringe-count recovery. Decide the count, then report the density that follows from it.
The loop, though, consumes the density, and in a two-color instrument the two quantities can separate. Some count errors move the density by a small fraction of a fringe while moving the inferred optical path by many micrometers. An unresolved count can therefore sit beside a density that is perfectly usable, and a rule that withholds the density until the count is resolved discards good measurements.
A tolerance on the density, not on the count
The proposal is to move one decision. Instead of resolving the integer and reporting what follows, the estimator marginalizes the posterior over integer hypotheses and over the continuous uncertainty, reports the probability that the density error exceeds a stated tolerance through a conservative bound, and declares the density available when that bound stays within a chosen risk level. With or without a resolved fringe count. The count is still reported, as a separate quantity.
Three principles shape it, and the note states them plainly. A wrapped observation does not determine the integer on its own, so every recovered count rests on an assumption that has to be named. The decision belongs on the quantity the loop consumes. And reliability is a measured number: a claim of reliability names its data, its baseline, its tolerance and the number at which it fails.
Two wavelength pairs, two different answers
The note then builds a Gaussian model with assumed priors and phase noise and runs two million simulated decisions per case, for the DIII-D prototype of ITER's instrument and for the ITER wavelength pair. The two behave nothing alike, and that contrast is the most useful thing in the illustration.
For the prototype the most probable fringe count is wrong in 29 percent of decisions, and the count confidence stayed below 99 percent in every one of them. A rule that releases the density only once count confidence reaches 99 percent would therefore have withheld every prototype density. The marginalized estimate keeps all of them available and still cuts the errors beyond a 0.05-fringe tolerance fourfold, from 132 to 33 in two million decisions, at full availability.
The ITER pair behaves the other way around. There the estimate gains nothing, both versions failing on exactly the same decisions, and what helps is withholding. Holding back 13.9 percent of decisions, for an availability of 86.1 percent, lowers the error rate roughly a hundredfold. The gain and its cost belong together: withholding buys accuracy with measurements the control loop does not get.
The gate did not earn its keep
The note is built so that two claims can be tested separately: a better estimate, and a better rule for when to release it. It reports them separately too, and in this illustration they came out differently. The simulations support an estimation benefit in the prototype case. They do not establish an additional benefit from the density-risk gate, and they do not rule one out either.
With the estimate held fixed, the density-risk gate and a conventional count-confidence gate accepted identical sets of decisions, at every tested availability, for both wavelength pairs. Two configurations are not the field, so this settles nothing about gating in general. What it does remove is the easy assumption that moving the criterion onto the density must help. Whether a density criterion gates better than a count criterion anywhere is left standing as a question for measured data, and the note supplies both the structural reason the two agreed here and the conditions under which they should part.
Where the claims end
The claims stop at the density measurement. EN-003 adds one decision on top of established measurement physics, and plasma behavior, confinement, burn, materials and magnets lie outside it. So does any statement about fusion performance. Every number is model-conditional: it rests on assumed priors and an assumed per-color noise covariance, and depends on stated search bounds, which can change the result on their own.
These model-conditional findings come with a protocol for testing them. It calls for raw-signal replay and bench optics with independent truth, and comparison at matched availability against hard branch selection, integer-aperture acceptance, deployed correctors and machine-learning baselines, with the estimate and the gate compared separately. It names falsifiers, invalidators and a retirement criterion, and says what a clean loss would retire. The note is open for evaluation by groups with access to interferometer-polarimeter records.