If the question is unsafe to ask a real human, then it seems like most ways of asking the question within the tree structure are also unsafe
I agree, and retract my complaint. The hierarchical structure does make the problem more subtle, but doesn’t rule out the approach you outlined.
A second potential problem is that I would really like to synthesize potentially problematic data in advance. This can’t be done using quite the technique you suggest, though you could imagine somehow forcing the synthesized data to look much like data that will actually appear (and really you want to do something like that anyway). The situation seems tricky and pretty subtle.
I agree, and retract my complaint. The hierarchical structure does make the problem more subtle, but doesn’t rule out the approach you outlined.
A second potential problem is that I would really like to synthesize potentially problematic data in advance. This can’t be done using quite the technique you suggest, though you could imagine somehow forcing the synthesized data to look much like data that will actually appear (and really you want to do something like that anyway). The situation seems tricky and pretty subtle.