A neural CPU you can audit step by step
Neural networks can learn to execute algorithms, but a correct final answer hides the state transitions that produced it, and hidden transitions are exactly what you cannot audit. A new preprint builds a learned executor that makes every transition visible: which operation ran, which registers it read and wrote, and what the memory did at each step, all supervised against a reference machine. Under simulated 8-bit arithmetic it holds its exact instruction path through programs of 1,000 instructions. It is simultaneously a recipe for trustworthy learned computers and a measuring stick that shows how far living tissue is from being one.
Source: A Symbolic Neural CPU for Quantization-Simulated Writeback and Interpretable Program Execution, arXiv:2607.10021, preprint, 10 Jul 2026. Primary source. Read: the full arXiv HTML version, including the executor architecture, the benchmark and training protocol, the long-horizon quantization results, the controller ablations, and the stated limits in the memory-pressure tasks.
What the work claims
This is a methods paper, an architecture plus an evaluation discipline, and its claims are correspondingly bounded: not a new capability, but a demonstration that a learned executor can be made inspectable at the level a computer would actually be audited. The author introduces a trace-supervised symbolic neural CPU, a factorized architecture combining a recurrent controller, an explicit operation router over a fixed differentiable arithmetic-logic unit bank, destination-masked register writeback, complete trajectory supervision, and matched fixed-point replay. Every quantity a verifier would want is exposed at every step: the selected operation, the source and destination registers, the register trajectory, the memory signals, and the writeback semantics.1
The evidence is a controlled benchmark study on a principal 16-wide profile, a register width of 16, trained on programs of 10 to 60 instructions, 3,000 training programs and 500 validation programs, and evaluated on held-out lengths up to 200 with a long-horizon extension to 1,000. Three headline results are reported. The non-quantized executor reproduces the reference execution exactly, with final error effectively zero at every reported length. The eight-bit, quantization-aware executor preserves the symbolic operation path through programs of 1,000 instructions: operation-gate agreement stays at 100 percent through length 700 and at or above 98.7 percent through length 1,000 for the aggregated family, while the two primary trained instances hold 100 percent at every length to 1,000. And when the same execution is scored against a matched fixed-point replay, a reference interpreter run under the same low-precision writeback semantics, the residual numerical drift disappears entirely, identifying it as an artifact of comparing continuous arithmetic against a low-precision reference, not execution failure.1
Around the core result sit the supporting claims an auditor would ask for. Ablations across recurrent, transformer, temporal-convolution, temporal-graph, and state-space controllers show that supervision of the operation gate is necessary for an inspectable execution path. Endpoint accuracy alone is explicitly rejected as a definition of success; scoring uses final state, full trace error, gate agreement, deterministic hard execution, and the replay criterion. Extensions probe generality: a value-memory interface, hybrid adaptive leaky integrate-and-fire controllers, candidate-constrained symbolic control trained by behavior cloning and actor-critic reinforcement learning, and a bridge to the RV32I base-integer instruction set. Honest limits are stated: hidden-opcode memory-pressure tasks, where the instruction stream itself must be carried in state, expose weaknesses in delayed state use and temporal binding.1
How it works
Three design choices do the heavy lifting, and each is a general principle rather than a trick. The first is factorization: instead of one opaque recurrent state that must simultaneously decide what to do and do it, the architecture separates control from execution. A controller steps the machine, the router selects one operation from a fixed bank of differentiable arithmetic-logic functions, and the result is written back only to the register the destination mask names. Factorization makes the trace meaningful: because the operation and its operands are explicit objects, they can be compared against the reference machine step by step, and errors can be localized to the gate, the arithmetic, or the writeback rather than averaged into a single loss.1
The second choice is trajectory supervision. Standard training rewards only the final answer; this executor is supervised on every intermediate register state, so correctness is enforced at the transition level, the level at which a real central processing unit would be audited. The third, matched fixed-point replay, is the subtle one. The eight-bit executor quantizes the selected arithmetic-logic output before writing it back, simulated quantization-aware training; but the continuous reference interpreter keeps infinite precision, so a register drift appears that is semantically meaningless, since a real eight-bit machine would have rounded identically. Replaying the reference under the same writeback projection makes the executor exact: the drift is a mismatch of reference semantics, not an execution error, a distinction with consequences for any low-precision or analog computing substrate.1
The quantitative texture matters. Against the continuous reference, the eight-bit executor's register error stays in the thousandths band, about 2.46 times 10 to the minus 3 at length 1,000, while its operation choices remain effectively exact: the numerical noise does not corrupt logical routing. Gate agreement is where long programs show strain: the aggregated 98.7 percent floor at length 1,000 corresponds to roughly one deviating operation in seventy active steps, which is why the author reports the primary trained instances separately, at a perfect 100 percent.
Where a skeptic should push
The most load-bearing assumption is that visible-opcode execution is the right regime in which to demonstrate trustworthiness. In the principal benchmark the instruction stream is available to the router, so the model is supervised on which operation to execute, and gate agreement in that setting measures whether it preserves and executes a supplied symbolic instruction, a real but easier task than discovering the program. The paper's own hidden-opcode memory-pressure variant, where the instruction stream must be reconstructed from state, is where performance sags and the stated limits appear; that variant is the honest proxy for any real deployment, and it is also where the least evidence is reported. The headline exactness is demonstrated most cleanly in the regime where the answer is partly handed over.1
Second, the scale is toy-like and should be read as a proof of discipline, not of machinery: a 16-wide register profile, a compact operation set, thousands of training programs, and a single-author implementation with no independent replication behind it. The RV32I bridge is described as a semantic bridge, a test that the design principles can express a standardized instruction set, not a demonstration of a competitive learned processor. Third, the statistical footing is thin for audit language: four trained instances in the key eight-bit condition and a worst-case aggregate gate agreement of 98.7 percent at the longest programs, which for verification purposes is not a rounding error but a failure rate. None of this overturns the contribution; it calibrates it. The paper shows what inspectable execution requires and that it is achievable with discipline at small scale, not that any existing large learned system comes close.
Audit-grade execution is what tissue cannot give
For organoid intelligence and biological computing, the uncomfortable use of this paper is as a measuring stick. The field's demonstrations are endpoint evaluations: the culture played a game, the dish classified a stimulus, the population moved the right variable. This paper formalizes why that standard can never establish trust on its own, because a correct endpoint is compatible with arbitrary hidden state transitions, and it builds the alternative: supervise and expose the trajectory, judge low-precision systems against a matched replay under their own arithmetic, and refuse endpoint accuracy as a success criterion. Each commitment is currently absent from biocomputing practice, and each maps onto a concrete methodological upgrade.1
The opportunity is the trajectory-supervision blueprint for in-material training. If an organoid is to be trained to perform a known computation, the training signal need not stop at the outcome: closed-loop stimulation can shape intermediate population states to follow the trajectory of a reference algorithm, step by step, in the same way this executor is supervised at every transition. Done properly, that would make a tissue computation inspectable for the first time, because the reference trajectory defines what each intermediate state should look like and the measured deviation becomes an auditable error signal rather than noise. The writeback-semantics lesson transfers even more directly. Living tissue is the ultimate low-precision, drift-prone substrate, and this paper's central methodological point is that such systems must be scored against a reference expressed in their own transfer function, not in digital exact arithmetic. For wetware benchmarking that means building a matched replay from the culture's own measured input-output map and scoring deviations there, a concrete, adoptable methodology that would retire a whole class of inflated claims.
The threat is that the audit gap is architectural, and this paper makes that visible. Auditability here rests on named operations, explicit registers, and destination-masked writes; a hundred-thousand-neuron culture offers a low-dimensional electrode projection of none of that. If the governance of biological computing ever demands this grade of transition-level assurance, and the dual-use and ethics literature around computing on living neural tissue pushes in that direction, the bar this paper sets is one tissue cannot currently meet, leaving the field exposed at both ends: over-regulation that treats every endpoint demo as unverifiable, and under-regulation that lets endpoint demos claim more than they establish. The calibrated position this paper supports is unsparing about the second: until a biological computer can show its work, the honest sentence is that the endpoint metric moved. Hype correction, in this field, is not a rhetorical stance but an evaluation standard, and it now exists in precise form.
The bottom line
Established within its regime: a factorized, trace-supervised learned executor reproduces reference execution exactly on the 16-wide benchmark, holds its logical operation path through 1,000-instruction programs under simulated eight-bit arithmetic with 100 percent gate agreement through length 700 and at least 98.7 percent at length 1,000 for the aggregated instances, and shows that residual drift against a continuous reference is a semantics mismatch that a matched fixed-point replay eliminates. Not established: robustness when the instruction stream must be reconstructed rather than supplied, since the hidden-opcode memory-pressure tasks expose exactly those weaknesses; scale beyond the toy profile; or independent replication. What would confirm the framework is progress on the hidden-opcode regime with verified instances at every reported length; what would break its thesis is a demonstration that trajectory supervision ceases to bind behavior once the operation bank or program distribution broadens. For biological computing the contribution is a standard: show the work, score the substrate under its own arithmetic, and treat endpoints alone as no evidence at all.
Frequently asked questions
What does trace-supervised mean?
Training and evaluation score every intermediate state of the computation, not just the final answer. For each step the model's chosen operation, its source and destination registers, and the register values are compared against a reference machine, so correctness is enforced and audited at the transition level.
What is quantization-simulated writeback?
The executor simulates eight-bit arithmetic by rounding, or quantizing, the output of the selected arithmetic-logic operation before writing it back into the register file, the way a real low-precision processor would. This makes training and evaluation reflect the behavior of hardware with finite-precision arithmetic.
Why does matched fixed-point replay matter?
A low-precision executor compared against an infinite-precision reference will show numerical drift even when it behaves exactly like a real eight-bit machine. Replaying the reference interpreter under the same writeback semantics removes that artifact, separating genuine execution errors from a mismatch between the model's arithmetic and the reference's.
How exact is the execution at long program lengths?
Under eight-bit simulation, operation-gate agreement is reported at 100 percent through programs of 700 instructions and at or above 98.7 percent through 1,000 for the aggregated instances, with the primary trained instances holding 100 percent at every length tested. Register error against the continuous reference stays around a few thousandths at the longest lengths.
Why does the paper reject endpoint accuracy as a success criterion?
Because a correct final answer is compatible with arbitrary hidden state transitions, which is precisely what a verifier cannot audit. The paper scores final state, full trajectory error, operation-gate agreement, deterministic hard execution, and matched fixed-point replay instead, evaluating the model at the level at which a computer would actually be inspected.
Could an organoid ever be audited this way?
Only partially, and that is the point. Tissue has no named operations, registers, or write masks, and an electrode array observes a low-dimensional projection of the state. What can transfer is the methodology: shape intermediate population states toward a reference trajectory during closed-loop training, and score the culture against a replay built from its own measured transfer function rather than digital arithmetic.
References
- J. L. L. de Jesus Silva. A Symbolic Neural CPU for Quantization-Simulated Writeback and Interpretable Program Execution. arXiv:2607.10021, 2026. https://arxiv.org/abs/2607.10021. Accessed 2026-10-04.