Home/Concepts/Internalism versus externalism about justification in semiconductor manufacturing
Internalism versus externalism about justification in semiconductor manufacturing
If justification requires reliable connection to the facts, then a system's epistemic standing is a function of its intake, not of its internal tidiness. This has a sharp…
The two positions, stated plainly
A yield engineer at a fab has a belief: this lot is healthy. What makes that belief justified?
Internalism says: look inside the engineer's head, or inside the model's weights. If the reasoning is coherent — the SPC chart is within control limits, the belief coheres with everything else known about the process, the engineer can articulate why each control limit was set where it was — then the belief is justified, full stop. Two engineers with identical dashboards and identical training are equally justified even if one of them is looking at a chart built from sensor readings that silently stopped updating six hours ago.
Externalism says that cannot be right. Justification requires that the belief actually be hooked up to the fact it's about. An engineer reasoning flawlessly from a stale chart is not justified, whatever it feels like from the inside — no more than a thermometer sealed in a box is a good measure of the room once someone has cut the wire. The reading hasn't changed. The connection has.
Semiconductor fabs are an unusually clean testing ground for this dispute, because the whole discipline is instrumented to answer exactly the question epistemology asks in the abstract: is this belief still connected to the thing it's about? Inline metrology, yield telemetry, equipment logs and materials lots are, collectively, the wire to the world. The characteristic failure of the industry — a lot excursion caught at final test rather than at the step that caused it — is what happens when that wire is cut somewhere upstream and nobody notices until the bill arrives.
Where the wire gets cut
A furnace drifts two degrees off setpoint during an oxidation step. The furnace's own log records the drift faithfully. Nothing downstream reads that log before the wafers move on. The next twelve process steps each generate internally coherent readings: CD-SEM measurements within spec, particle counts within spec, overlay within spec. Every individual belief formed at every individual step is well-supported by the evidence available at that step. The engineer signing off on step fourteen has excellent internalist warrant — the data in front of them is clean, the reasoning from that data is sound.
What none of those steps had was a connection to the fact that mattered: the furnace excursion three weeks earlier. That fact sits in a log nobody queried, because nobody at step fourteen had reason to query it. The belief "this lot is healthy" was formed by a process that was, at every local point, reliable — and the whole chain was, globally, disconnected from the one upstream event that determined the outcome. The excursion surfaces at final test as a bin-3 fail cluster, and the postmortem takes a week to walk back through equipment logs to find the furnace. Internalist warrant was intact at every step. Externalist warrant had a hole in it from day one, and nothing internal to any single step could have shown that hole, because the hole was between steps, in a connection that no single reading covers.
This is the industrial version of the Gettier problem: justified, true (at the time), and still not enough, because the justification and the truth were connected by luck rather than by tracking. A belief formed from a reading that happens to still be accurate, without any live link certifying that it is, has the form of knowledge without the substance.
The lineage read as an intake problem
A model trained on a fixed corpus of historical fab data — years of past lots, past excursions, past yield outcomes — can be extraordinarily coherent. It can predict yield impact from a given defect signature with well-calibrated confidence, because the corpus contains thousands of matched examples. That is real, internalist warrant, and dismissing it would be a mistake. It is also warrant that says nothing about this furnace, this week, because the corpus closed before this week existed. The model doesn't know its own beliefs have gone dark; there is no signal inside a frozen weight set marking which of its generalisations are still current and which describe a process that has since been re-tuned, re-calibrated, or replaced.
A model given a bounded scene — a single lot's inline metrology, live, from photolithography through etch — restores the connection for as long as that lot is in front of it. It can catch that this run's overlay is trending against three prior runs, because it is watching the live stream, not a memory of one. But the scene ends at final test, or at shift change, or at the boundary of whichever tool's data feed was wired in. Beliefs formed inside the scene persist as ordinary memory once the scene closes, and nothing marks that they've stopped being checked. The tool that flagged the furnace drift three weeks ago, if it only ever saw that one tool's data, has no way to connect its old observation to this week's excursion at final test, because the connection between them runs through equipment logs and materials-lot tracking that were never in its scene.
The position with no further rung above it is the one where inline metrology, yield telemetry, equipment logs and materials lots are all streaming continuously into a belief set that revises as they update and decays when they go quiet, with each belief carrying a record of which stream last touched it and when. That is not a stronger form of coherence. It is a different kind of warrant entirely — the kind that can answer "is this still connected?" rather than only "is this internally consistent?".
What provenance actually buys
Provenance is the part of this that does the real work, and it's worth being precise about what it is not. It is not a promise that every stream is trustworthy. A particle counter can be miscalibrated; a lot-tracking record can have a transcription error; an equipment log can be missing an entry because a technician forgot to scan a wafer carrier. Continuous intake exposes a system to all of that. What provenance gives the system is the ability to say, for any given belief, which sensor produced it, when, and whether that sensor's last several readings have been internally consistent with neighbouring sensors — which is exactly the audit a human root-cause team performs by hand, a week late, after final test has already flagged the problem.
| internalist warrant | externalist warrant | |
|---|---|---|
| frozen historical model | high — coherent with corpus | unknown — no signal on currency |
| live single-lot scene | high while scene is open | high while scene is open, unmarked after |
| continuous streamed intake with provenance | variable, tracked explicitly | gradeable, per-belief, per-stream |
Objection: reliability has no fixed meaning here
A defender of internalism can press the generality problem: what counts as "the" belief-forming process for a CD-SEM reading? Is it that tool, that tool type, that fab's whole metrology suite, that metrology technique in general? Reliability scores differ wildly depending on the grain chosen, and externalism has never settled which grain is correct. If the key term is that unstable, building an argument about fab architecture on top of it looks unsafe.
That is a fair complaint against fine-grained reliabilism, and it is not solved here. But the comparative claim needed for this argument is much coarser than anything the generality problem threatens: a belief about this lot's oxide thickness, whose only causal ancestry is a corpus that closed before this lot existed, stands in a worse relation to the fact than a belief formed from this morning's inline metrology on this tool. That ranking survives under every reasonable way of specifying the process. The generality problem is a live wound in the general theory of reliabilism; it is not a wound in this narrower claim.
Objection: not everything decays
Much of what a fab believes is not perishable at all. The physics of oxide growth, the chemistry of a given etch recipe, the geometry of a design rule — these do not go stale the way a furnace's calibration does. A model trained once on the relevant materials science is fully warranted indefinitely, and no amount of streaming telemetry adds anything to that warrant.
This is a real limit on the thesis, not a technicality to be waved off. The claim was never that all beliefs decay at the same rate, or that continuous intake is needed everywhere. It is that a system cannot tell, from the inside, which of its own beliefs are the perishable ones without some record of when each was last checked against the world. The oxide chemistry and the furnace's current calibration look identical from inside a coherent model; only provenance distinguishes the belief that needs re-checking from the one that doesn't. That is a narrower claim than "streaming beats frozen." It is closer to: without provenance, a system cannot even locate the boundary between the two.