Inverted Engineering.


Software developers used to be paid to construct logic. We wrestled with the elegance of every line. Today, our profession has been radically inverted. We are no longer the authors; we are editors-in-chief in a newsroom under constant fire. AI agents bombard us with suggestions every second, and our task has shifted: we must find the truth inside a lie that looks alarmingly plausible.

We call this Inverted Engineering.

The Plausibility Trap

The greatest risk with AI-generated code is not that it is obviously wrong. The compiler catches syntax errors. The risk is that the code looks perfect. It is neatly formatted, uses the right variable names and appears logical. That invites the deadly “LGTM” reflex – “Looks Good To Me”. We approve the code because the surface looks right.

But AI optimises for plausibility, not truth. It chooses the statistically most likely path, not necessarily the correct one. An algorithm can be syntactically brilliant while hallucinating business processes that do not exist.

The Method: Interrogate Code Instead of Reading It

To survive this flood, we must stop reading code as if it were literature. We must treat it like a crime scene. Forensics, not copy-editing.

Three strategies help us regain control:

1. Clean-Room Verification (The Digital Double) Do not try to validate the logic simply by reading it. Use the opponent’s weapons. Feed the generated code, without comments, into a different AI model and instruct it: “Create a specification based on this code.” Compare this reverse-generated specification with your original requirement. Every discrepancy exposes a hallucination. If the code does things you did not ask for, reject it.

2. The Strategy of Ignoring (Black-Box Testing) An efficient reviewer often does not read the code first. They read the prompt. If the requirement is “Calculate VAT for Austria”, do not inspect the code to check whether the formula is correct. Write a test case using the specific Austrian small-business threshold (€35,000). Run the AI code against that test. If it fails because the AI has hallucinated the statistically more likely German tax rules, you have found the error in seconds without wading through spaghetti code.

3. The Inception Review When you find errors, do not fix them yourself. That merely trains your ability to act as a rubbish collector. Force the creator, human or machine, to change perspective. Instead of commenting “Input sanitisation is missing here”, ask: “You are an attacker with access to the logs. How would you use this code to take over the admin session?” This breaks automation bias. It forces the creator to abandon passive consumption and actively prove the solution’s robustness.

Conclusion: The Sceptic Is Always Right

A developer’s value today is no longer measured in lines of code, but in lines of rejected code. We must be suspicious of elegance. A solution that seems too smooth often hides a logical abyss.

Inverted Engineering means reversing the burden of proof: code is guilty (faulty) until its innocence (correctness) has been established beyond doubt through tests and forensic analysis. Anyone who merely reads and nods has already lost.

Leave a Reply