Abstract
<title>Abstract</title> <p>Visual anomaly localizers are commonly initialized from normal images, yet the deployment stream may drift and may also contain unlabeled defects. Updating on that stream creates a causal and evidential problem: an event must be scored before it can influence the model, while any retained information can become an unreported source of memory. We formulate this setting as a first-arrival prequential contract with hidden target truth, complete accounting of future-readable state, and reversible state transitions. A bounded baseline, BSPAL, implements the contract using source-calibrated admission, a fixed quarantine, coordinate-median proposals, atomic commits, probation, and rollback. We establish bounded-state, first-arrival causality, local median, and state-restoration properties, and connect the contract to executable leakage, ordering, restart, and byte-accounting checks. The empirical evidence is reported with a strict scope. A post-seal audit found that the VisA role split used in the historical benchmark computation had not closed physical-instance and near-duplicate isolation; all 20 inspected cross-role pairs were confirmed as physical-group matches. The resulting efficacy estimates are therefore retained only as an audit trace and receive no performance interpretation. A separate read-only reconstruction recovered persistent-state measurements from 945 hash-bound run ledgers: all were below the configured 32 MiB cap, with a maximum of 1,180,438 bytes; direct latency remained unmeasured. Accordingly, the claims are limited to the evaluation contract, its transactional implementation, and the integrity finding; no benchmark improvement is claimed.</p>