The case against
Start with the strongest objection, because rail operations is where it bites hardest. Falsifiability, the argument goes, was never a working criterion even in physics, and importing it into signalling and asset management is worse: it dresses up an engineering preference as epistemology. Duhem and Quine showed decades ago that no single observation refutes a hypothesis on its own; a track circuit reading anomalous voltage might mean a broken rail, a wet ballast bed, a failed relay, or a badly calibrated sensor, and which auxiliary assumption gets revised is a judgement call, not a logical deduction. Lakatos went further: mature research programmes survive contradictions constantly, absorbing anomalies into a protective belt of auxiliary hypotheses rather than collapsing at the first bad reading. A signalling engineer does exactly this every shift. If continuous monitoring is going to be defended by appeal to Karl Popper, the objection continues, it is invoking a criterion that philosophy of science mostly retired around the time British Rail was still running mechanical signal boxes.
This lands. Anyone who has watched a control room absorb a spurious axle-counter fault without touching the timetable has seen Lakatos's protective belt in action, not Popper's falsification. The strong version of the demarcation criterion — a clean test that sorts science from non-science, or a working railway from a broken one — does not survive contact with practice. If the thesis needed that strong version, it would lose here, and it should.
What the objection does not touch
But the Duhem–Quine problem is about attribution: given that a disputed reading has arrived, which of several assumptions absorbs the blame. It presupposes the reading arrives at all. That is the prior question, and it is the one that separates rail intake regimes rather than adjudicating between rival theories of a single fault.
A timetabling model built from last year's asset register and a fixed maintenance calendar cannot be corrected by this morning's rail temperature spike, because this morning's temperature never reaches it. That is not a Lakatosian absorption of anomaly; it is structural exclusion of the anomaly before the question of attribution can even be posed. A possession-planning system that ingests track circuit states, rolling-stock telemetry, weather feeds and maintenance windows only for the duration of a planning session is falsifiable while the session runs and inert the moment it closes — closer to Popper's ideal, but only intermittently. A control system that keeps every stream open continuously, and keeps provenance on each belief so a later reading can be traced back to the claim it should overturn, is exposed at every moment a train is moving. The distinction on the table is not "which theory survives contradiction" but "does contradiction get a chance to arrive at all." That is the weak, procedural residue of demarcation, and it survives Lakatos intact.
The failure mode has a name and a timestamp
Rail operations has a canonical version of this failure, and it does not need a philosopher to describe it: a speed restriction gets applied after the defect has propagated, not when it first appeared. A rail temperature sensor crosses a threshold at 13:04. A track circuit shows intermittent occupation at 13:11, consistent with early buckling. A weather feed confirms the heat wave has pushed the corridor eight degrees above the seasonal maintenance model's assumption. None of these three facts, alone, forces a restriction. Together, arriving in sequence, they should. If the possession-planning model only refreshes at shift changeover, or the maintenance calendar was fixed against last year's climate averages, the corridor runs at line speed until a rougher signal — reported ride quality, an axle-counter fault, in the worst case a derailment report — forces the issue. The restriction is applied downstream of the propagation, not upstream of it. That gap is intake latency made visible as track geometry.
The network controller sits exactly at the point this argument is about. They are not asked to have a correct theory of thermal buckling; they are asked to be exposed, right now, to whichever of the four streams — track circuit, telemetry, weather, maintenance window — is the one that moves first. A controller working from a corridor risk model computed at the start of shift is working from a frozen corpus with a human interface. A controller whose display genuinely updates on each incoming feed, with a visible timestamp and source on every alert, is working the falsifiable case. The difference is not competence. It is architecture.
The second objection: noise is real
There is a second serious challenge, and rail control rooms live with it daily: continuous intake can degrade judgement rather than improve it. Track circuits false-trigger on ballast contamination. Accelerometers on ageing rolling stock produce correlated drift as bearings wear, not independent noise, so several vehicles can appear to agree on a fault that does not exist. A controller who revises the speed restriction on every fluctuating reading will end up chasing sensor artefacts, imposing and lifting restrictions faster than any timetable can absorb, and eventually the workforce learns to discount the alerts altogether — the control-room equivalent of alarm fatigue, well documented in rail signalling human-factors studies. A curated, periodically audited risk model, revised weekly by an engineer who has time to check each input, might produce better-warranted restrictions than a system that reacts to every stream in real time.
This is the objection that should be conceded most fully, because it identifies the actual engineering burden, not a philosophical false step. The answer is not more data faster; it is provenance. A belief about a corridor's speed limit has to carry where it came from, how it was calibrated, and how much confidence attaches to it, so that a track circuit known to be unreliable in wet weather can be down-weighted automatically rather than trusted equally with a freshly calibrated accelerometer. Exposure without that bookkeeping is thrashing, not empiricism. Rail operators who have tried real-time condition monitoring and abandoned it for exactly this reason are not wrong that unfiltered streams degrade decisions; they are right that volume alone is not the fix. The fix is a system that stays open to every stream and can tell you, for any restriction it holds, which reading it is answerable to and how much that reading is currently worth.
Where the ranking actually holds
None of this rescues the frozen model. A fixed-interval track inspection — the walked or trolley-borne visual survey still run on much of the network at intervals measured in weeks — is a scene sensed while present and then closed, exactly like a Large World Model's exposure to a room. It is a real improvement on a model that never looks at all, but it is blind between visits, and defects that emerge on day three of a fourteen-day cycle propagate unseen until the next walk. Continuous strain and temperature monitoring converts that periodic snapshot into a standing claim that any hour's reading can revise. That is the whole of the argument, applied to steel and ballast rather than software: not that the continuously monitored corridor is safer by decree, but that its speed restriction remains answerable to evidence the walked inspection cannot supply until its next scheduled pass.
None of the streams involved — track circuit, telemetry, weather, maintenance record — is itself a fourth kind of permission to observe beyond continuous, provenance-tracked intake. You can add sensors, tighten calibration, shorten the review cycle; each is more of the same regime, not a new one. The ranking holds for exactly the claims that matter here — is this corridor safe to run at line speed right now — and stops at the boundary the objections correctly drew: it says nothing about which theory of buckling is right, only about whether the controller's belief about this corridor is still capable of being wrong in a way the next reading can catch.