Next Article in Journal
Co-Management of Communication and Computational Energy in Wirelessly Connected Mobile Robots
Previous Article in Journal
Reliability-Aware Multi-Modal Sentiment Analysis Under Missing and Corrupted Modalities
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

An Auditable Human-Centric Architecture for EEG-Triggered Fragrance Selection During Sleep Preparation

1
Department of Electrical and Mechanical Technology, National Changhua University of Education, Changhua City 50007, Taiwan
2
Singapore American School, Singapore 738547, Singapore
3
Hsinchu International School, Hsinchu City 30091, Taiwan
*
Author to whom correspondence should be addressed.
Electronics 2026, 15(16), 3625; https://doi.org/10.3390/electronics15163625
Submission received: 27 July 2026 / Revised: 12 August 2026 / Accepted: 13 August 2026 / Published: 14 August 2026

Abstract

Consumer electroencephalography (EEG)-triggered fragrance delivery raises a narrow control problem: a noisy state estimate must not bypass user authority, and each actuator decision should remain reconstructible. We present a domain-specific control architecture that maps versioned Sleep Readiness Index (SRI) records to bounded ranking among three user-authorised cartridge identifiers. Input quality, permission, exposure limits, and an independent stop monitor constrain every proposed pulse. For 105 synthetic records with complete strict-v1 metadata, the validator derived Q = 1 for every record, committed a 29-record baseline, completed two simulated acknowledged pulses with one completed cooldown, entered Stop at the fixture cap, issued one DISARM, and verified a 114-event hash chain. A paired legacy OSC fixture used legacy profile and provenance fields and lacked source continuity telemetry; it accepted no quality-eligible record, remained in Calibrate, and emitted no proposal. The replay validates controller mechanics and software consistency only: its acknowledgements, SRI changes, and rewards are synthetic, and no cartridge–SRI relationship, meaningful preference learning, device operation, physiological benefit, or sleep improvement is demonstrated.

1. Introduction

Consumer sleep technology is not a treatment for chronic insomnia, for which multicomponent cognitive behavioural therapy is strongly recommended [1]. This paper considers a narrower wellness use case: fragrance timed from an EEG-derived state estimate rather than delivered continuously or by a fixed timer. Pleasant odours have been associated with respiration-coupled autonomic effects [2], five-minute essential oil exposures with changes in electroencephalography (EEG) band power [3,4], and lavender exposure with resting-state network changes [5]; none establishes that EEG-triggered fragrance improves sleep. The Phase-1 framework described by Lu et al. defined a within-session Sleep Readiness Index (SRI), preprocessing pipeline, and gross artefact gates for a four-channel headset [6]; the present work treats that estimator as a versioned input and specifies the replay pathway.
Before monitoring, the user authorises up to three fixed-content cartridge identifiers, denoted A–C. The controller is specified to update only a within-session numerical ranking among those identifiers. After a confirmed fixed-duration pulse, timely explicit feedback is used when available; otherwise, an unvalidated mapping from a time-aligned SRI change supplies a heuristic update. No measured cartridge–SRI pairs were used to define or validate that mapping, so the resulting scores are not demonstrated measures of preference or effectiveness. The controller does not modify fragrance composition, pulse duration, or trigger timing; whether its ranking improves any outcome remains untested.
Wearable headband, glasses-form, and in-ear EEG systems can yield spectral features under controlled protocols [7,8,9], but use outside the laboratory still requires explicit artefact handling [10]. The controller must therefore make a bounded decision from a delayed, noisy proxy and retain enough information to reconstruct that decision. A 15-participant, eyes-closed olfactory neurofeedback proof of concept used a predefined alpha-power threshold [11]; an end-to-end learned policy requires data and validation that are unavailable in this setting.
The primary contribution is neither a new EEG marker nor a new bandit algorithm. It is a domain-specific decision architecture that joins versioned EEG input, revocable user permission, deterministic exposure limits, bounded cartridge ranking, conservative treatment of uncertain actuation, an independent stop path, and an ordered decision record. The accompanying reference replay makes that downstream control specification executable and tests its nominal path and legacy input fail-closed behaviour. No clinical efficacy, diagnostic accuracy, or physical safety claim is made; Section 6.3 states the evidence boundary.

2. Related Work

2.1. Consumer EEG-Driven Biofeedback Loops

Reviews of low-cost headsets describe their preprocessing requirements and sensitivity gap from clinical systems [12]. Dry electrode performance is measure- and device-dependent: Kleeva et al. reported band-specific spectral differences and Muse limitations, whereas Ehrhardt et al. found a lower signal-to-noise ratio and underestimated mismatch negativity and theta measures despite recoverable mismatch negativity and resting connectivity estimates [13,14]. Muse-class event-related components have been assessed in a semantic relatedness task [15], while wearable artefact practice spans motion, muscle, ocular, and contact effects [10]. Glasses and in-ear devices extend the form factor [7,9]; portable prefrontal alpha has also been studied in relation to sleep quality and eye state [8,16]. Comfort, placement simplicity, and perceived measurement accuracy were treated as joint criteria in a 35-respondent expert opinion survey [17].
Continuous quality estimation differs from trial rejection or signal reconstruction. Quality scores have combined EEG and motion evidence [18], and low-density dry EEG movement studies have evaluated active electrodes with artefact subspace methods [19]. In a nine-participant treadmill walking experiment using isolated high-density EEG movement artefacts, forehead acceleration correlated poorly with electrode artefacts [20]; transfer to a four-channel bedroom headset remains unknown. With four channels, artefact evidence can inhibit actuation but cannot certify a neural source.

2.2. Olfactory Delivery Hardware and Digital Olfaction Paradigms

Fragrance responses are not uniform: EEG, cardiac, and self-report measures can diverge across odours [21], while an exploratory COVID-19 group comparison found EEG neurodynamic differences that persisted across resting and odour stimulation conditions [22]. The thresholded neurofeedback prototype does not specify the actuator authority, interlocks, and decision record required by the present architecture. Nor do the cited olfactory studies validate the proposed ≤1.5 s pulse or the 60 s SRI association window.

2.3. Spectral Estimation and Controller Inputs

The inherited ratio draws on established functional interpretations of alpha and theta oscillations in cognition and memory [23]; its use as a within-session relaxation proxy is author-defined, not clinically validated, by Phase-1 [6]. The reference SciPy estimator branch uses Welch averaging for its short-window band power estimate [24]; the NumPy-only fallback uses a different filter and periodogram and therefore requires a distinct interface identity. Recent classification studies illustrate heterogeneous spectral features and dataset-specific formulations [25,26], while reviews document wider variation in preprocessing and feature extraction [27,28]. We adopt the documented Phase-1 SRI definition and trial-level quality fields as interface inputs, then add controller-side persistence and bounded cartridge score updating. Evidence from ambulatory photoplethysmography reinforces a general constraint: a wearable quality estimate must be evaluated under the motion conditions in which it will operate [29]. It does not validate the EEG gate proposed here. Taken together, these studies do not specify how a qualifying signal should be converted into authorised actuation while preserving a replayable decision history.

2.4. Human–Automation and Runtime Assurance

Human–automation frameworks distinguish information acquisition, analysis, decision selection, and action implementation and allow authority to remain with the operator at selected stages [30]. Runtime assurance architectures likewise separate a performance controller from an independent mechanism that can restrict unsafe outputs [31]. Here the ranking policy automates only cartridge choice: the user controls permission and arming, while deterministic checks and a separate stop path govern actuation. The additional contribution is application-specific rather than a new general assurance theory: each pulse is tied to a versioned EEG record, the current permission state, a typed adapter outcome, a conservative exposure count, and a hash-linked decision trace. Because no diffuser dynamics model or proved safe set is supplied, the design is not claimed to provide formal runtime assurance.

3. Materials and Methods

3.1. Use Case and Human Authority

The proposed 15–20 min bedroom session begins with an explicit start and a two-minute quiet calibration. The interface may show the raw SRI and a separately labelled 0–100 display score, but the controller consumes only the raw ratio; neither quantity is presented as a sleep or efficacy measure. A session is configured with up to three cartridge options, denoted A–C; the architecture does not prescribe three universal oils. Before deployment, each identifier would need to be bound to a fixed formulation record containing ingredients, concentration, manufacturer or lot, and nominal pulse setting. No formulation or physical cartridge was manufactured or tested in this study, so the neutral labels avoid implying evidence for particular oils. Limiting the active set to three reduces the authorisation burden and fragmentation of sparse feedback, although the three-pulse cap permits little within-session updating.
Human-centric denotes authority over actuation. The user defines the authorised set U t and arms the system; emergency stop then outranks quality inhibition, finite-state logic, and the bandit proposal. The deny list D t includes both pre-session exclusions and cartridges masked after discomfort. The policy cannot restore a denied cartridge or re-arm the actuator, and explicit feedback supersedes the SRI-derived reward. A decision coordinator attaches a monotonically increasing authorisation version h t to the committed snapshot ( U t , D t , L t , S t ) . Permission, deny list, latch, or stop-state changes advance this version, allowing a stale proposal to be rejected before transmission.

3.2. Hardware Stack and Data Plane

The inspected Phase-1 path nominally forwards four EEG channels (TP9, AF7, AF8, TP10) at 256 Hz over Open Sound Control (OSC) [6]. Its current records lack the source timestamp, sequence, and drop evidence needed to establish complete analysis window support. The inspected diffuser path likewise lacks the host-selectable cartridge and bounded-duration pulse interface required by this architecture. These findings follow the inspection on 24–27 July 2026 of the available acquisition and diffuser integration snapshots; the private source snapshots are not deposited.
The cartridge-selective adapter is therefore an interface requirement, not an implemented component. It would enforce a host-independent one-shot no longer than d max , accept an independently routed DISARM, and handle command identifiers idempotently. ACK_FIRED would be permitted only after completion and would include start/end timing and reported valve-open duration; interrupted or unverifiable actuation would return a non-confirming outcome. Figure 1 shows how the decision coordinator, independent stop monitor, adapter, and audit writer are separated.

3.3. Control Variable and Signal Quality Requirements

The controller input s t is the Phase-1 raw, clamped SRI ratio in [0.1, 20], not the separately mapped 0–100 display score [6]. For the four channels C = { TP 9 ,   AF 7 ,   AF 8 ,   TP 10 } , it is the mean of channel-wise clipped ratios, not a ratio formed after averaging powers. It is then standardised against the calibration mean μ 0 and guarded standard deviation before applying an exponential moving average (EMA):
s t = 1 | C | c C clip [ 0.1 , 20 ] P α , t , c + P θ , t , c max ( P β , t , c , 10 9 ) , z t = s t μ 0 max ( σ 0 , σ min ) , z ¯ t = z t , z ¯ t 1 = , λ z t + ( 1 λ ) z ¯ t 1 , otherwise , 0 < λ 1 .
Here P θ , P α , and  P β integrate 4–8, 8–13, and 13–30 Hz, respectively; 10 9 is the inspected implementation’s numerical beta-power floor. The reference λ = 0.2 gives an effective memory of about five accepted updates, while σ min prevents division by a near-zero baseline deviation. Here t indexes estimator records; pulse commands and their delayed rewards use the separate index k. The Phase-1 estimator uses a 5 s analysis window; a 2–4 s update hop is a proposed overlapping window adaptation for this controller rather than a Phase-1 measurement result. Elapsed EMA memory therefore depends on the hop, and overlapping estimates are correlated. The SRI is an author-defined, non-specific spectral ratio, not a probability of relaxation or sleep readiness. Eye closure can elevate alpha, theta is not specific to drowsiness, and undetected cranial muscle activity can inflate the beta denominator and create a false low-SRI trigger [10,16,23]. Eye condition and posture must therefore be pre-specified and held constant between calibration and monitoring.

Signal Quality Profiles

Two input profiles must be distinguished. The inspected OSC stream is labelled legacy-observe-v0: it can support non-actuating analysis but cannot establish complete window provenance and therefore cannot complete actuation-enabled calibration or enter Monitor. The actuation-eligible strict-v1 profile requires a finite SRI, analyser validity and good status, four ordered channels, the full scheduled sample count, source sequence continuity, source timestamps, complete support, and zero reported drops; any failed condition gives Q t = 0 . Host arrival time is not an accepted substitute.
The reference implementation includes a validator that derives Q t from these fields; its nominal inputs contain no free Q t value. All provenance in that replay is synthetic, so this check demonstrates interface and controller consistency rather than a working exporter. A paired legacy OSC fixture uses legacy profile and provenance values and omits sequence, timestamp, support, and drop evidence; the validator therefore derives Q t = 0 for every record, keeps the latch low, and emits no proposal. Archive S1 labels this fixture legacy-osc-inspected; it instantiates this manuscript’s legacy-observe-v0 case. An optional metadata record M t Q may carry reason-coded channel status, auxiliary coverage and age, and a heuristic index ρ t ; without labelled calibration, ρ t is a ranking index rather than an artefact-free probability. Quality gates actuation and reward eligibility but never assigns a posterior value directly. Table 1 separates current trial checks from unimplemented evidence.
The replay manifest must pin the estimator branch and dependencies, quality profile version, windowing, bands, timestamp convention, clock tolerance, transport continuity rule, and missing stream policy.

3.4. Cartridge Ranking and Cold-Start Calibration

A session pins one update hop T hop . In the proposed controller interface, each estimator record carries its complete analysis support [ i , r i ] , with  r i i = T window and record timestamp τ i = r i . For T cal = 120  s, calibration schedules N cal = 1 + ( T cal T window ) / T hop records with right edges r i = τ cal + T window + i T hop , i = 0 , , N cal 1 . Thus every accepted support interval lies wholly within [ τ cal , τ cal + T cal ] ; no pre-calibration sample enters the baseline. Every candidate record must have Q t = 1 and finite s t ; a missing, rejected, or version-mismatched record clears the candidate. For accepted values s i , the committed statistics use the population convention: μ 0 = N cal 1 i s i and σ 0 = [ N cal 1 i ( s i μ 0 ) 2 ] 1 / 2 . The controller commits ( μ 0 , σ 0 ) only when σ min σ 0 σ max , where σ max is deployment-pinned, and no validated value is reported here. If any guard fails or σ max is unset, the controller remains in Calibrate, logs the failure, keeps the actuator latch low, and displays quality status only until an explicit retry or stop. After a valid commit, the controller enters Monitor with z ¯ = , V = , exposure count n = 0 , and  τ last = τ start T cool on the monotonic clock. Each cartridge option starts from the replayable Beta ( 1 , 1 ) prior, while the latch reflects the user’s explicit arming choice; these initial values and the baseline are logged.

4. Closed-Loop Controller

The control loop has five steps: validate the input, update the baseline-relative estimate, require a persistent trigger, recheck permission and exposure limits, and rank the eligible cartridges before requesting one fixed-duration pulse. An independent stop monitor can terminate this sequence at any point. After a confirmed outcome, a non-actuating reward tracker updates only the selected cartridge’s score and cannot issue actuator commands. The equations and pseudocode below formalise these operations; they do not describe a deployed controller.

4.1. Finite-State Machine

The controller has five specified modes: Idle, Calibrate, Monitor, Cooldown, and terminal Stop. Intervention is an atomic, guarded handoff whose acknowledged outcome enters Cooldown or Stop; it is not a mode held between SRI updates. Failed calibration leaves the controller in Calibrate; Algorithm 1 therefore begins only after a baseline has been committed. The independent stop monitor accepts an emergency stop, session termination, or user disarm event in every nonterminal mode; dispatches DISARM exactly once; lowers the latch; and enters Stop. Figure 2 gives the transitions, and Table 2 gives the reference settings.
Let V t contain up to the most recent W accepted Monitor-mode indices since the latest buffer reset event. The persistence buffer is cleared after quality rejection, on every Cooldown update, and after any persistence-triggered decision is consumed, whether inhibited or handed off, as specified in Algorithm 1. Any Q t = 0 also sets z ¯ t = ; the next accepted record reinitialises the EMA, so the pre-gap state cannot support a post-gap decision. Accepted Cooldown records may rebuild the EMA but do not enter V t . The persistence flag is
P t = I | V t | = W i V t I ( z ¯ i < κ ) W min .
The reference settings require seven of ten updates below κ = 0.5 . Because the windows overlap, this is a dwell rule rather than evidence from seven independent observations.
Algorithm 1 One post-calibration controller update.
Require: Validated record w t = ( s t , Q t , τ t ) , post-calibration state X t , authorised set U t , parameters Θ
Ensure: Updated state, at most one pulse request, and ordered decision records
if  m t = Stop  then
       return
end if
if a stop or disarm event is pending then
       enter Stop, lower the latch, issue one DISARM, and record the event
       return
end if
if  Q t = 0 or s t is non-finite then
       clear z ¯ t and V t ; record quality inhibition; return
end if
 update ( z t , z ¯ t ) by Equation (1)
if  m t = Cooldown  then
       clear V t ; return to Monitor only after T cool ; return
end if
 append t to V t ; compute P t by Equation (2)
if  P t = 0  then
       record no trigger; return
end if
 snapshot authorisation version and eligible set E t = U t D t
if the latch is low or E t =  then
       record inhibition; clear V t ; return
end if
 select a k by Equation (4); form a fixed-duration request
if the final locked recheck fails Equation (6) then
       record every failed condition; clear V t ; return
end if
 persist the request and hand it to the adapter once
 record the typed adapter outcome; update count, mode, and cooldown anchor
 clear V t

4.2. Reward Shaping Around an Acknowledged Pulse

For pulse k, ACK_FIRED certifies the completion of the bounded one-shot. Its host-monotonic receipt time τ k ack is the conservative cooldown anchor. The acknowledgement also supplies start and end times mapped to the host clock, ( τ ^ k on , τ ^ k off ) , with mapping uncertainty ϵ k ; these are adapter telemetry, not independently measured exposure. If that mapping is missing, non-monotonic, or outside its declared uncertainty bound, the SRI-derived reward is ineligible. With a valid mapping, the pre-index set I k contains only records whose complete support lies in [ τ ^ k on T post , τ ^ k on ϵ k ] and the post set I k + only records supported within [ τ ^ k off + ϵ k , τ ^ k off + T post ] . Windows that straddle either boundary and all samples acquired during the command are excluded. SRI-based finalisation requires both sets to be nonempty and to contain every session-scheduled record satisfying the respective containment rule; every selected record must be finite and accepted. Each ACK_FIRED outcome appends an event containing the command, cartridge identifier, schedule version, τ k ack , and the explicit feedback deadline τ k ack + T post , then opens a pending reward state keyed to that command. With valid clock mapping, the outcome event stores I k and the mapped boundaries; otherwise it stores explicit nulls and the SRI ineligibility reason. The SRI association uses unsmoothed standardised records, so Δ Z k = | I k + | 1 i I k + z i | I k | 1 i I k z i . Timely explicit feedback y k { 0 , 1 } appends one finalisation event with r k = y k , leaves I k + and Δ Z k null, and atomically closes the pending state. To resolve an exact deadline tie, the decision coordinator processes feedback received through the deadline before the deadline event. Only a scheduled estimator event strictly after the deadline may append an SRI-based finalisation event; it stores I k + , the completeness result, Δ Z k , and either a finite r k or null.
r k = y k , timely explicit feedback , 1 + exp ( k r Δ Z k ) 1 , both windows complete and accepted , , otherwise .
The fixture sets k r = 1.2 only to exercise the update path; it was not fitted to measured cartridge responses. The association window and sigmoid mapping are unvalidated design choices. This value maps a one-unit increase to approximately 0.77 and no change to 0.5 . Here Δ Z k is the difference in mean standardised controller inputs; it is not the relative SRI quantity denoted by Δ R in Phase-1. We write k r , rather than the Phase-1 display mapping symbol k, to keep reward shaping distinct from score presentation [6]. A discomfort report ( y k = 0 ) also adds a k to the session deny list through the serial authority stream. Late feedback is logged and cannot create a second posterior update; late discomfort enters the same stream and therefore precedes any later dispatch whose authority snapshot it invalidates. If r k = , the prior parameters are retained. The non-actuating reward tracker is the sole writer of pending reward states and cartridge parameters. It may close an open state once after entry to Stop, but it consumes only scheduled estimator and feedback events and has no actuator command interface.

4.3. Thompson Sampling Cartridge Ranking

In the bandit notation below, each cartridge option is an arm in A . Thompson sampling ranks those options by posterior sampling [32], but command k samples only the eligible set E t k = U t k D t k :
θ a , k Beta ( α a , k , β a , k ) , a E t k , a k = arg   max a E t k θ a , k .
Before the draw, the decision coordinator applies every earlier reward finalisation, reserves decision sequence q k , and records posterior version ν k for a fixed snapshot with authorisation version h k . A later-sequenced finalisation first affects draw k + 1 . Ties use a fixed cartridge identifier order; after final revalidation, the committed proposal would store ( q k , h k , ν k , u k ) , the draws, and a per-decision seed. The versioned session configuration pins the pseudo-random generator and cartridge draw order. When the linked reward is finalised, each arm’s parameter pair is advanced by
( α a , k + 1 , β a , k + 1 ) = ( α a , k , β a , k ) + I ( a = a k ) ( r k , 1 r k ) , a A , r k .
In Equation (5), binary feedback gives the standard beta-Bernoulli update; an SRI-derived value is a unit mass soft-label heuristic, not an exact posterior observation. Neither the resulting parameters nor their samples are validated probabilities of user preference or cartridge effectiveness. If r k = , every pair is retained unchanged. The bandit selects cartridge identity only. Commanded valve-on duration d 0 is fixed by the user-approved session configuration and remains subject to d max ; neither quantity is a measured chemical or inhaled dose.

4.4. Safety Admissibility

A proposed action ( a , d ) at monotonic time τ t is admissible only when
Safe t ( a , d ) ¬ S t ( m t = Monitor ) L t Q t ( a E t ) ( n t < N max ) ( τ t τ last T cool ) ( 0 < d d max ) ,
where S t { 0 , 1 } marks emergency stop or session end, m t is the current mode, L t { 0 , 1 } is the actuator latch, and  n t { 0 , , N max } is a conservative exposure-accounting count. The dispatched pulse outcomes are ACK_FIRED, ACK_REJECTED, ACK_UNKNOWN, and STOP_PREEMPTED. ACK_FIRED certifies a completed bounded pulse, whereas ACK_REJECTED certifies that actuation never began. A timeout, malformed or weaker response, or interrupted outcome without that certificate maps to ACK_UNKNOWN; controller pre-emption while awaiting the outcome maps to STOP_PREEMPTED. The first, third, and fourth outcomes consume one exposure count because the adapter confirmed actuation or the command may have left the host; ACK_REJECTED consumes none. AUTHORITY_REJECTED instead records failed final revalidation before transmission. ABORTED_DECISION records a reserved sequence that never reached a durable proposal; it has no command identifier, consumes no exposure count, leaves the latch low, enters Stop, and is never replayed. A command identifier is counted at most once: a late acknowledgement may refine its audit annotation but cannot alter the conservative count or restore a nonterminal mode. A disarm acknowledgement is logged but cannot restore a nonterminal mode. The proposed adapter must enforce d d max with a host-independent one-shot watchdog. DISARM is a distinct high-priority safety command rather than a pulse retry; if it interrupts an active one-shot, the adapter reports an interrupted or uncertain outcome, and the SRI-derived reward remains undefined. The remaining Boolean variables satisfy Q t , P t { 0 , 1 } , with  U t , D t A , E t = U t D t , and  α a , k , β a , k > 0 . Civil time is stored separately for review and never drives cooldown. A failed clause suppresses emission and records each failed reason; terminal events, a cap-reaching completed pulse, and non-confirming pulse acknowledgements enter Stop.
In Algorithm 1, X t contains the mode, smoothed value, persistence buffer, exposure count, cooldown anchor, latch, deny list, authorisation version, and command sequence. The input validator already derived Q t from the named profile; Θ contains the fixed settings in Table 2. Detailed handoff outcomes are defined in Section 4.4 and recorded with an idempotent command identifier.
Immediately before handoff, the decision coordinator rechecks authorisation, latch, eligibility, stop state, cap, cooldown, and duration while holding the relevant state lock. A persisted action request and idempotent command identifier precede one bounded adapter attempt; acknowledgement waiting does not hold the lock. Invalid or uncertain handoffs would not be retried, and uncertain actuation would be counted conservatively. Recovery would consume an outstanding reservation as ABORTED_DECISION; an unresolved durable proposal would use retained adapter status when available and otherwise become ACK_UNKNOWN. The recovered session would remain in Stop. These crash recovery and durable reconciliation behaviours are requirements, not tested implementation results.
A completed ACK_FIRED at host-monotonic outcome time τ o would increment n, anchor cooldown there, and enter Stop at the cap or Cooldown otherwise. ACK_UNKNOWN and STOP_PREEMPTED count possible exposure and stop; ACK_REJECTED stops without increasing the count. Every stop transition would lower the latch and issue one distinctly keyed DISARM; it would never emit or retry a pulse.

5. Safety and Auditability

5.1. Interlocks and Safety Predicate

Equation (6) defines intended command admissibility but is not evidence of clinical safety. Authorisation and a sensitivity deny list cannot exclude unknown sensitivities, incorrect cartridges, room accumulation, respiratory disease, or third-party exposure. The session, cooldown, and pulse limits are specified to constrain controller failures, as summarised in Table 3; the specification requires every rejection to be logged.

5.2. Tamper-Evident, Hash-Chained Decision Log

In the specified design, the decision coordinator assigns each decision, proposal, outcome, authorisation, stop, acknowledgement, and reward event at the point where the corresponding state change is ordered. It would hand finalised, consecutively numbered event payloads to one local audit writer. That writer would append only the next sequence number against the current terminal digest and reject gaps or duplicates, preventing concurrent producers from forking the chain.
Each record captures its decision context: state delta, failed clauses, authority, configuration and posterior versions, sampled draws and seed, selected cartridge identifier, and commanded duration. For a dispatched command, it also stores the identifier, acknowledgement outcome, host-monotonic receipt/start/end times, clock mapping identity and uncertainty, adapter-reported duration, estimator support, and the record identifiers used for reward calculation. The record concludes with Q t , available quality metadata, civil time, and the action or inhibition reason. Inapplicable fields are explicit nulls; raw waveforms are excluded by default. Each event is converted to bytes by a versioned serialisation rule before hashing. The illustrative generator, executed with Python 3.9.6, sorts keys, removes optional whitespace, encodes UTF-8, and otherwise follows Python’s json.dumps semantics; this is deterministic for the fixture, not a cross-language canonicalisation standard. A deployable schema must pin string and number encoding, key order, and test vectors. Every record stores the full Secure Hash Algorithm 256-bit (SHA-256) digest of its predecessor; a reviewer interface may display a prefix but must verify the complete chain. Stronger secure audit designs use additional cryptographic protection and interaction with a trusted system [33]; the proposed local chain does neither. Internal modification breaks verification, but a privileged process can recompute or truncate the chain unless the record count and terminal digest are retained separately. The design is therefore tamper-evident under a trusted terminal digest assumption, not immutable; Figure 3 shows the intended review view.

6. Reference Replay and Validation Boundary

Archive S1 supplies a standard library Python reference implementation of the downstream input validator, baseline commit, controller transitions, simulated adapter outcomes, reward updates, and hash-linked event writer. It consumes retained SRI records and does not derive the SRI from EEG, implement the inspected OSC bridge, or communicate with a diffuser.

6.1. Executed Conformance Replay

The nominal input contains 105 deterministic records with synthetic strict-v1 provenance: four ordered channels, scheduled and observed sample counts, source sequences and timestamps, complete 5 s support intervals, and zero reported drops. The validator derives Q t from these fields; a free Q t field is rejected. The configuration uses a two-pulse cap, rather than the architecture’s three-pulse reference setting, so that terminal cap behaviour can be exercised in a short fixture. Table 4 reports the retained exact output checks.
The expected output file fixes the event sequence and terminal digest, allowing an independent run to detect software drift. Adapter acknowledgements and pre/post SRI values are predefined fixture values, and the resulting rewards are synthetic; no physiological response was measured after a physical cartridge selection. Figure 4 displays a separate visual fixture retained to show the three-pulse reference configuration; it is not generated by the new replay.

6.2. Remaining Validation

A conforming device exporter and recorded device corpus are the next integration prerequisites. The exporter must preserve source sequences, timestamps, drop telemetry, and complete support; the current path cannot supply them. Recorded device evaluation must also label contact, motion, ocular, muscle, line, and cardiac-coupled contamination and report false clean and false inhibition rates by session. The present persistence settings imply a best-case evidence span of 23–41 s before transport, computation, and acknowledgement; no measured end-to-end timing trace is available. A wearable electrocardiography study used simultaneous reference recordings to assess temporal fidelity [34]; an analogous clock-aligned comparison would be required here.
The cartridge-selective adapter still requires hardware timing, watchdog, acknowledgement, restart, and fault injection tests. Human evaluation would first test whether users understand authorisation, inhibition, firing, and emergency stop. Testing the ranking strategy would require fixed documented cartridges, randomised or counterbalanced selections, repeated observations, explicit feedback, and comparison with fixed or random selection. Any efficacy claim would additionally require an outcome independent of the SRI and an appropriate sham or no-pulse condition. These studies require prospective protocols; they are not the results of this paper.

6.3. Evidence Boundary

Table 5 separates the executed software evidence from unavailable integration and human evidence.

7. Discussion

7.1. Current Engineering Utility and Design Trade-Offs

The current deliverable is an inspectable reference for input validation, permission and quality checks, state transitions, exposure accounting, reward bookkeeping, and audit logging. It is not a validated adaptive or personalised system. The ranking policy can choose only among authorised cartridge identifiers; it cannot increase duration, bypass a quality rejection, restore a denied cartridge, or re-arm the actuator.
No measured cartridge–response pair was used in this study. The SRI-derived reward is an unvalidated temporal association heuristic: because intervention follows a low-SRI trigger, spontaneous recovery or regression toward the session mean could reward an ineffective cartridge. The parameter updates were not shown to recover user preference or cartridge effectiveness, and three permitted exposures provide little within-session information. Explicit feedback is more direct, but that pathway has not been evaluated with participants.
Treating the SRI as a versioned external input avoids duplicating the Phase-1 signal processing [6], but reproduction still requires a conforming estimator and exporter.

7.2. Limitations and Threats to Validity

The present evidence supports synthetic controller consistency only. The inspected acquisition stream cannot satisfy strict-v1, the cartridge-selective adapter remains unavailable, and neither chemical exposure nor sleep was measured. The SRI is a non-specific spectral proxy; session standardisation does not identify signal source or correct later drift. Dry electrode findings differ by device and outcome [13,14], and acceleration results from high-density treadmill recordings do not establish transfer to this four-channel setting [20]. False clean windows could enable a decision, whereas false inhibition reduces availability.
Self-report, EEG, and cardiac measures can diverge across fragrances [21], so efficacy cannot be inferred from the controller input alone. Respiration is not measured or phase-locked, even though odour can alter breathing, and breathing can modulate EEG [2,11]. Cooldown and pulse caps limit timing and count, not room concentration, perceived intensity, or adaptation. A later efficacy study would therefore need an outcome independent of the SRI and comparison with non-adaptive and sham or no-pulse conditions.
Finally, the hash chain supports investigation but prevents neither live compromise nor deletion. Deployment would require hardware-enforced limits, authenticated commands, verified cartridge identity, independently retained terminal digests, and a separate adversarial threat model.

8. Conclusions

This paper supplies an auditable controller specification and executable synthetic replay for EEG-triggered fragrance selection. The replay verifies the implementation of baseline formation, persistence gating, permission and exposure checks, simulated outcome handling, reward bookkeeping, disarming, and audit chain checks; the legacy input run fails closed. It does not validate the SRI as a measure of cartridge response, demonstrate meaningful preference learning, or establish real-world effectiveness. A conforming device exporter, physical adapter, recorded device and fault testing, and human evaluation remain necessary.

Supplementary Materials

The following supporting information can be downloaded at https://www.mdpi.com/article/10.3390/electronics15163625/s1. Archive S1, supplementary-code.zip, contains four Python figure generators, the non-deployable reference controller, retained input and expected output files, seven focused tests, pinned figure dependencies, a README, and the figure manifest. All included evidence is schematic or synthetic; no participant data or device-integrated software is included.

Author Contributions

Conceptualisation, S.-J.L. and C.-W.L.; methodology, S.-J.L.; software, H.-S.L. and C.-L.K.; validation, H.-S.L. and C.-L.K.; formal analysis, S.-J.L.; writing—original draft preparation, S.-J.L.; writing—review and editing, H.-S.L., C.-L.K. and C.-W.L.; visualisation, S.-J.L.; supervision, C.-W.L. All authors have read and agreed to the published version of the manuscript.

Funding

This research received no external funding.

Data Availability Statement

No participant data were created or analysed. Archive S1 contains the four figure generators, non-deployable reference controller, retained synthetic replay input and expected output, focused tests, dependencies, README, and figure manifest. Figure 1 and Figure 2 are non-empirical schematics; Figure 3 and Figure 4 and the controller replay are deterministic synthetic fixtures. The private implementation snapshots inspected for context are not deposited. No conforming device exporter, device-integrated controller, cartridge-selective adapter, recorded device corpus, labelled quality corpus, measured timing trace, operational device log, aggregate fault injection output, or sleep outcome is available.

Acknowledgments

During the preparation of this manuscript, the authors used OpenAI Codex (GPT-5-based model; accessed 24 July–12 August 2026) for literature metadata checks, drafting and revising text, controller formalisation, Python figure code, and reference replay tests. It did not generate or analyse participant data. The authors reviewed and edited the output and take full responsibility for the publication.

Conflicts of Interest

The authors declare no conflicts of interest.

Abbreviations

The following abbreviations are used in this manuscript:
EEGElectroencephalography
EMAExponential Moving Average
SHA-256Secure Hash Algorithm 256-bit
SRISleep Readiness Index

References

  1. Edinger, J.D.; Arnedt, J.T.; Bertisch, S.M.; Carney, C.E.; Harrington, J.J.; Lichstein, K.L.; Sateia, M.J.; Troxel, W.M.; Zhou, E.S.; Kazmi, U.; et al. Behavioral and Psychological Treatments for Chronic Insomnia Disorder in Adults: An American Academy of Sleep Medicine Clinical Practice Guideline. J. Clin. Sleep Med. 2021, 17, 255–262. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  2. Ghibaudo, V.; Turrel, M.; Granget, J.; Souilhol, M.; Garcia, S.; Plailly, J.; Buonviso, N. Pleasant Odors Specifically Promote a Soothing Autonomic Response and Brain–Body Coupling Through Respiratory Modulation. Sci. Rep. 2025, 15, 36417. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  3. Gong, X.; Yang, Y.; Xu, T.; Yao, D.; Lin, S.; Chang, W. Assessing the Anxiolytic and Relaxation Effects of Cinnamomum camphora Essential Oil in University Students: A Comparative Study of EEG, Physiological Measures, and Psychological Responses. Front. Psychol. 2024, 15, 1423870. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  4. Liu, J.; Liu, M.; Peng, L.; He, H.; Sun, R.; Chang, W. Effects of Inhaling Cunninghamia lanceolata Essential Oil on the Physiological and Psychological Relaxation of University Students. Front. Psychol. 2025, 16, 1638492. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  5. Kupers, R.; Dousteyssier, O.; Delforge, J.; Gonnot, V.; Kantono, K.; Blerot, B.; Pêtre, A.; Dricot, L.; Heinecke, A. Long-Lasting Effects of Lavender Exposure on Brain Resting-State Networks in Healthy Women. Front. Neurosci. 2025, 19, 1555922. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  6. Lu, C.-Y.; Su, W.-Z.; Chien, T.-H.; Liao, C.-W. A Deployable Engineering Framework for Olfactory-Induced Relaxation Assessment: Modular Architecture and Signal Processing Pipeline for Wearable EEG. Eng 2026, 7, 198. [Google Scholar] [CrossRef] [Scilit]
  7. Zanetti, R.; Aminifar, A.; Atienza, D. EEG Glasses for Real-Time Brain Electrical Activity Monitoring. Sci. Rep. 2025, 15, 43574. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  8. Han, C.; Zhang, Z.; Lin, Y.; Huang, S.; Mao, J.; Xiang, W.; Wang, F.; Liang, Y.; Chen, W.; Zhao, X. Monitoring Sleep Quality Through Low α-Band Activity in the Prefrontal Cortex Using a Portable Electroencephalogram Device: Longitudinal Study. J. Med. Internet Res. 2025, 27, e67188. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  9. Fu, Z.; So, K.P.; Wu, X.; Khotsaenlee, A.; Wong, S.W.H.; Tin, C.; Chan, R.H.M. A Feasibility Study of Using an In-Ear EEG System for a Quantitative Assessment of Stress and Mental Workload. Sensors 2026, 26, 442. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  10. Arpaia, P.; De Luca, M.; Di Marino, L.; Duran, D.; Gargiulo, L.; Lanteri, P.; Moccaldi, N.; Nalin, M.; Picciafuoco, M.; Visani, E. A Systematic Review of Techniques for Artifact Detection and Artifact Category Identification in Electroencephalography from Wearable Devices. Sensors 2025, 25, 5770. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  11. Ninenko, I.; Medvedeva, A.; Efimova, V.L.; Kleeva, D.F.; Morozova, M.; Lebedev, M.A. Olfactory Neurofeedback: Current State and Possibilities for Further Development. Front. Hum. Neurosci. 2024, 18, 1419552. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  12. LaRocco, J.; Le, M.D.; Paeng, D.-G. A Systemic Review of Available Low-Cost EEG Headsets Used for Drowsiness Detection. Front. Neuroinform. 2020, 14, 553352. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  13. Kleeva, D.; Ninenko, I.; Lebedev, M.A. Resting-State EEG Recorded with Gel-Based vs. Consumer Dry Electrodes: Spectral Characteristics and Across-Device Correlations. Front. Neurosci. 2024, 18, 1326139. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  14. Ehrhardt, N.M.; Niehoff, C.; Oßwald, A.-C.; Antonenko, D.; Lucchese, G.; Fleischmann, R. Comparison of Dry and Wet Electroencephalography for the Assessment of Cognitive Evoked Potentials and Sensor-Level Connectivity. Front. Neurosci. 2024, 18, 1441799. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  15. Begue Hayes, H.; Magne, C. Exploring the Utility of the Muse Headset for Capturing the N400: Dependability and Single-Trial Analysis. Sensors 2024, 24, 7961. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  16. Zhang, Y.; Zhang, Z.; Du, F.; Song, J.; Huang, S.; Mao, J.; Xiang, W.; Wang, F.; Liang, Y.; Chen, W.; et al. Shared Oscillatory Mechanisms of Alpha-Band Activity in Prefrontal Regions in Eyes Open and Closed State Using a Portable EEG Acquisition Device. Sci. Rep. 2024, 14, 26719. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  17. Al-Daraghmeh, M.Y.; Stone, R.T.; Mgaedeh, F.Z. Explore the Ideal Human Body Part for Medical Wearable Sensors. Smart Wearable Technol. 2026, 2, A4. [Google Scholar] [CrossRef] [Scilit]
  18. Nahmias, D.O.; Kontson, K.L. Quantifying Signal Quality from Unimodal and Multimodal Sources: Application to EEG with Ocular and Motion Artifacts. Front. Neurosci. 2021, 15, 566004. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  19. Yang, S.-Y.; Lin, Y.-P. Movement Artifact Suppression in Wearable Low-Density and Dry EEG Recordings Using Active Electrodes and Artifact Subspace Reconstruction. IEEE Trans. Neural Syst. Rehabil. Eng. 2023, 31, 3844–3853. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  20. Kline, J.E.; Huang, H.J.; Snyder, K.L.; Ferris, D.P. Isolating Gait-Related Movement Artifacts in Electroencephalography during Human Walking. J. Neural Eng. 2015, 12, 046022. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  21. Morozova, M.; Gabrielyan, I.; Kleeva, D.; Efimova, V.; Lebedev, M. Scents Modulate Anxiety Levels, but Electroencephalographic and Electrocardiographic Assessments Could Diverge from Subjective Reports: A Pilot Study. Front. Behav. Neurosci. 2025, 19, 1534716. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  22. Chernykh, M.; Zyma, I.; Vodianyk, B.; Subin, Y.; Seleznov, I.; Popov, A.; Kiyono, K. Comparative EEG Study of Neurodynamics upon Olfactory Stimulation in COVID-19 Patients. Front. Hum. Neurosci. 2025, 19, 1571477. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  23. Klimesch, W. EEG Alpha and Theta Oscillations Reflect Cognitive and Memory Performance: A Review and Analysis. Brain Res. Rev. 1999, 29, 169–195. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  24. Welch, P.D. The Use of Fast Fourier Transform for the Estimation of Power Spectra: A Method Based on Time Averaging over Short, Modified Periodograms. IEEE Trans. Audio Electroacoust. 1967, 15, 70–73. [Google Scholar] [CrossRef] [Scilit]
  25. Risqiwati, D.; Wibawa, A.D.; Pane, E.S.; Yuniarno, E.M.; Islamiyah, W.R.; Purnomo, M.H. Effective Relax Acquisition: A Novel Approach to Classify Relaxed State in Alpha Band EEG-Based Transformation. Brain Inform. 2024, 11, 12. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  26. Zayed, A.; Belhadj, N.; Ben Khalifa, K.; Valderrama, C.; Bedoui, M.H. A Novel Hybrid Approach for Drowsiness Detection Using EEG Scalograms to Overcome Inter-Subject Variability. Sensors 2025, 25, 5530. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  27. Mdluli, B.; Khumalo, P.; Maswanganyi, R.C. Signal Preprocessing, Decomposition and Feature Extraction Methods in EEG-Based BCIs. Appl. Sci. 2025, 15, 12075. [Google Scholar] [CrossRef] [Scilit]
  28. Ayuso-Moreno, R.; Rubio-Morales, A.; Durán-Rufaco, A.; García-Calvo, T.; González-Ponce, I. EEG-Based Assessment of Mental Fatigue in Students: A Systematic Review of Measurement Methods and Data Processing Protocols. Appl. Sci. 2026, 16, 234. [Google Scholar] [CrossRef] [Scilit]
  29. Huang, J.; Wu, Y.; Li, F.; Zhang, D.; Tan, S. Assessing Pulse Rate Variability from a Wrist-Worn PPG Device Against ECG-Derived Heart Rate Variability in Ambulatory Settings. Smart Wearable Technol. 2026, 2, A3. [Google Scholar] [CrossRef] [Scilit]
  30. Parasuraman, R.; Sheridan, T.B.; Wickens, C.D. A Model for Types and Levels of Human Interaction with Automation. IEEE Trans. Syst. Man. Cybern. Part A Syst. Hum. 2000, 30, 286–297. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  31. Hobbs, K.L.; Mote, M.L.; Abate, M.C.L.; Coogan, S.D.; Feron, E.M. Runtime Assurance for Safety-Critical Systems: An Introduction to Safety Filtering Approaches for Complex Control Systems. IEEE Control Syst. 2023, 43, 28–65. [Google Scholar] [CrossRef] [Scilit]
  32. Russo, D.J.; Van Roy, B.; Kazerouni, A.; Osband, I.; Wen, Z. A Tutorial on Thompson Sampling. Found. Trends Mach. Learn. 2018, 11, 1–96. [Google Scholar] [CrossRef] [Scilit]
  33. Schneier, B.; Kelsey, J. Secure Audit Logs to Support Computer Forensics. ACM Trans. Inf. Syst. Secur. 1999, 2, 159–176. [Google Scholar] [CrossRef] [Scilit]
  34. Gopal, S.; Bhat, P.; Sivaram, S.; Prabhu, M.; Karthikeyan, V.J.; Roy, P.; Subramanian, M.; Subramanya, I. From Wires to Wearables (2): Temporal Fidelity Assessment of the Sydäntek Wearable ECG System Against a Legacy Cloud-Based Standard. Smart Wearable Technol. 2025. [Google Scholar] [CrossRef] [Scilit]
Figure 1. Local architecture and evidence boundary. Solid outlines denote inspected interfaces; dashed outlines denote specified or proposed components. The inspected bridge does not supply an actuation-eligible window record. The policy ranks eligible cartridges, the decision coordinator performs the final checks and orders events, the independent stop monitor owns the direct DISARM path, and one audit writer appends the resulting records. This schematic is not a device integration or sleep outcome result.
Figure 1. Local architecture and evidence boundary. Solid outlines denote inspected interfaces; dashed outlines denote specified or proposed components. The inspected bridge does not supply an actuation-eligible window record. The policy ranks eligible cartridges, the decision coordinator performs the final checks and orders events, the independent stop monitor owns the direct DISARM path, and one audit writer appends the resulting records. This schematic is not a device integration or sleep outcome result.
Electronics 15 03625 g001
Figure 2. Proposed five-mode controller and independent stop path. A valid baseline permits monitoring; a confirmed sub-cap pulse enters Cooldown, whereas a cap-reaching or uncertain outcome enters Stop without retry. Definite non-actuation adds no exposure; confirmed or uncertain actuation is counted conservatively. Quality rejection clears the exponential moving average and persistence buffer. The downward arrow denotes lowering the actuator latch. This is a specification schematic, not a validation result.
Figure 2. Proposed five-mode controller and independent stop path. A valid baseline permits monitoring; a confirmed sub-cap pulse enters Cooldown, whereas a cap-reaching or uncertain outcome enters Stop without retry. Definite non-actuation adds no exposure; confirmed or uncertain actuation is counted conservatively. Quality rejection clears the exponential moving average and persistence buffer. The downward arrow denotes lowering the actuator latch. This is a specification schematic, not a validation result.
Electronics 15 03625 g002
Figure 3. A filtered illustrative view of eight rows from a 128-record deterministic log; hidden routine ticks explain the identifier gaps. The generator replays the exponential moving average and persistence gate, checks nominal authority and exposure rules, resolves support records, recomputes the displayed reward, and verifies the full fixture-specific hash chain. Binary Q is assigned under fixture-direct-q-v1; authority races, restart, DISARM, and non-ACK_FIRED outcomes are absent. Hash prefixes are displayed, while the full terminal digest is pinned in the generator. The hash symbol prefixes command numbers, the asterisk marks the linked reward overlay, and the ellipsis indicates a deliberately shortened digest; no log content is missing. This is synthetic software evidence, not an empirical result.
Figure 3. A filtered illustrative view of eight rows from a 128-record deterministic log; hidden routine ticks explain the identifier gaps. The generator replays the exponential moving average and persistence gate, checks nominal authority and exposure rules, resolves support records, recomputes the displayed reward, and verifies the full fixture-specific hash chain. Binary Q is assigned under fixture-direct-q-v1; authority races, restart, DISARM, and non-ACK_FIRED outcomes are absent. Hash prefixes are displayed, while the full terminal digest is pinned in the generator. The hash symbol prefixes command numbers, the asterisk marks the linked reward overlay, and the ellipsis indicates a deliberately shortened digest; no log content is missing. This is synthetic software evidence, not an empirical result.
Electronics 15 03625 g003
Figure 4. Separate deterministic 15 min visual fixture for the three-pulse reference configuration. Panels show the baseline-relative trajectory, ten-record persistence buffer with five assigned Q = 0 inputs, and simulated controller events. The third ACK_FIRED reaches the cap, and the stop monitor issues one DISARM; rewards are 0.56 , null because of incomplete support, and  0.15 . The scalar SRI and Q are generated directly, not from an EEG waveform or strict-v1 validator, and the imposed post-pulse changes are not physiological effects.
Figure 4. Separate deterministic 15 min visual fixture for the three-pulse reference configuration. Panels show the baseline-relative trajectory, ten-record persistence buffer with five assigned Q = 0 inputs, and simulated controller events. The third ACK_FIRED reaches the cap, and the stop monitor issues one DISARM; rewards are 0.56 , null because of incomplete support, and  0.15 . The scalar SRI and Q are generated directly, not from an EEG waveform or strict-v1 validator, and the imposed post-pulse changes are not physiological effects.
Electronics 15 03625 g004
Table 1. Signal quality feature requirements. Checks marked present are trial-level Phase-1 outputs, not an implemented controller gate; no fusion parameters, thresholds, or category performance are established.
Table 1. Signal quality feature requirements. Checks marked present are trial-level Phase-1 outputs, not an implemented controller gate; no fusion parameters, thresholds, or category performance are established.
Evidence FamilyCandidate Evidence and Interpretive LimitImplementation Status
EEG signal integrityCompleteness, finite values, duration, flatline/clipping, amplitude, and total power; gross gating only.Trial validity present; strict window mapping and clipping proposed.
Channel comparisonVariance imbalance, agreement, and derivative; four channels provide limited spatial evidence.Imbalance warning present; controller veto, agreement, and derivative proposed.
Spectral contextLow/high-frequency ratios and local main power; source remains ambiguous.Proposed wider-band branch.
Inertial referenceTime–local motion association; neither necessary nor sufficient for EEG contamination.Registered; not forwarded or fused.
Cardiac referencePhotoplethysmography association identifies candidate coupling, not cerebral origin.Registered; not forwarded or fused.
Table 2. Reference controller settings. Bracketed values are proposed replay bounds, not tested ranges.
Table 2. Reference controller settings. Bracketed values are proposed replay bounds, not tested ranges.
ParameterReference Value [Range]Role
EMA weight λ 0.2 [0.1, 0.4]About five accepted updates
SRI window T window 5 sPhase-1 analysis window [6]
Update hop T hop 2–4 sProposed overlapping cadence
Calibration span T cal 120 s; complete scheduleFinite, Q = 1 , one version
Arming threshold κ 0.5 [0.3, 0.8]Baseline standard deviation units
Persistence ( W , W min ) (10, 7)Fresh accepted updates
Reward slope k r 1.2 [0.8, 1.8]Soft-label sigmoid
Association window T post 60 sSupport-contained pre/post sets
Lower baseline guard σ min 0.001 Phase-1 numerical floor; temporal use unvalidated [6]
Upper baseline guard σ max Set before deploymentNo validated value reported
Cooldown T cool 120 s [90, 180]Minimum pulse interval
Acknowledgement timeout T ack Set before deployment; >0No value or measurement reported
Configured duration d 0 0 < d 0 d max Fixed per session
Duration cap d max 1.5 s [1.0, 2.0]Hard valve-on limit
Session cap N max 3 pulsesHard exposure-accounting limit
Cartridge options | A | 3Proposed slots
PriorBeta(1, 1)Uniform per option
Table 3. Specified engineering interlocks and intended checks; none establishes clinical safety.
Table 3. Specified engineering interlocks and intended checks; none establishes clinical safety.
InterlockHazard AddressedCheck
Authorised set U t Actuation without approvalRevalidate the selected cartridge option at handoff; commit the proposal before one adapter attempt
Sensitivity deny list D t Known sensitivityDenied identifiers are excluded before sampling; unknown sensitivities remain possible
Session cap N max Cumulative exposureCount adapter-confirmed or uncertain actuation; enter Stop at the cap
Cooldown T cool Rapid retriggeringBlock actuation until the monotonic interval has elapsed
Duration cap d max Single over-releaseReject valve-on durations outside ( 0 , d max ] before dispatch
Hardware one-shotStuck host or lost linkProposed adapter watchdog terminates every pulse by d max ; ACK_FIRED follows completion
Baseline guardsInvalid standardisationRequire complete finite Q = 1 calibration and σ 0 [ σ min , σ max ] ; otherwise remain Calibrate, latch low
Command acknowledgementDuplicate or uncertain actuationUse an idempotent identifier and retained handoff status; do not retry an unresolved pulse; count possible actuation once, then stop
Emergency stopDistress or hardware faultPre-empt the acknowledgement wait, lower the latch, send one DISARM, and enter Stop
Quality gateIncomplete or grossly suspect inputReset EMA and persistence, then inhibit; optional profiles also reject missing or stale required inputs (Section 3.3)
Table 4. Executed synthetic reference replay and focused negative checks.
Table 4. Executed synthetic reference replay and focused negative checks.
FixtureObserved Software ResultInterpretation
Synthetic strict-v1 records105/105 records accepted; 29-record baseline; two simulated ACK_FIRED outcomes; one completed cooldown; cap-two Stop; one DISARM; two reward updates; 114-event chain verifiedInternal consistency of the retained record validator, controller, and audit trace only
Legacy OSC preflight0/105 records accepted; baseline not committed; latch low; no proposal, outcome, exposure, or rewardThe inspected transport cannot operate the actuation-enabled controller
Focused unit tests7/7 pass, covering required metadata, free-Q rejection, quality reset, authorisation recheck, exact output, and hash tamperingDeterministic boundary checks; not device or physiological validation
Table 5. Validation boundary for proposed system.
Table 5. Validation boundary for proposed system.
Claim LevelCurrent Status
Reference validator and controllerExecuted on retained synthetic records; exact output and seven focused tests supplied in Archive S1
Cartridge–SRI association and rankingExercised with synthetic acknowledgements and SRI values only; no measured cartridge response, preference convergence, or real-world policy performance
Device strict-v1 exporterNot implemented; the inspected legacy OSC path fails closed and cannot enter actuation-enabled Monitor
Natural artefact quality estimatorRequirements specified in Section 3.3; no labelled corpus, fitted model, or performance metrics
Physical adapter and fault toleranceCartridge-selective adapter, timing trace, watchdog test, and aggregate fault injection outputs unavailable
Human use and sleep outcomesNo participant, usability, chemical dose, polysomnography, or sleep outcome evidence
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Share and Cite

MDPI and ACS Style

Lyu, S.-J.; Lan, H.-S.; Kuo, C.-L.; Liao, C.-W. An Auditable Human-Centric Architecture for EEG-Triggered Fragrance Selection During Sleep Preparation. Electronics 2026, 15, 3625. https://doi.org/10.3390/electronics15163625

AMA Style

Lyu S-J, Lan H-S, Kuo C-L, Liao C-W. An Auditable Human-Centric Architecture for EEG-Triggered Fragrance Selection During Sleep Preparation. Electronics. 2026; 15(16):3625. https://doi.org/10.3390/electronics15163625

Chicago/Turabian Style

Lyu, Sheng-Jhih, Hsuan-Sheng Lan, Chin-Liang Kuo, and Chin-Wen Liao. 2026. "An Auditable Human-Centric Architecture for EEG-Triggered Fragrance Selection During Sleep Preparation" Electronics 15, no. 16: 3625. https://doi.org/10.3390/electronics15163625

APA Style

Lyu, S.-J., Lan, H.-S., Kuo, C.-L., & Liao, C.-W. (2026). An Auditable Human-Centric Architecture for EEG-Triggered Fragrance Selection During Sleep Preparation. Electronics, 15(16), 3625. https://doi.org/10.3390/electronics15163625

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop