It is proved in Lean!
What does that mean?
James B. Wilson
Professor of Mathematics
Colorado State University
Tank
Ye
The
Subject
AI is having a moment.
Lean is having a moment within that moment.
Within Math we're having a ... crisis?
- AI searches, combines, generates ideas,
- Converts to Lean to try and prove,
- While failing, adapt and retry.
What should we know? trust? ask? do?
...what is different (th)is time?
This is not new
Epigram McBride-McKinna (Edinbrugh)
NuPrl, Constable (Cornell)
1980
1990
2000
2010
2020
System F, Girard
MLTT, Martin-L\(\"o\)f
Computation has been this capable for 5000 years.
So what's new? Speed & Volume.
What's our history? We adapt.
Thm. (Minsky) The Abacus is Turing Complete
...this could have been any one of the others.
While Lean is our subject today
What is \(\mathsf{L}\exists\forall\mathsf{ N}\)?
- Programming language
- Functional (Haskell syntax),
- strongly/statically typed
- Type checker
- Dependent,
- Inductive,
- multi-sorted calculus of construction.
- Proof checker
- Proof irrelevant,
- (mere) Propositions as type
- Proof assistant
- Elaborator
- Tactic script,
- SAT (mod Theory), Linear program solver,
native_decide
Curry-Howard-Lambek Correspondence
Lemma "Division Algorithm". For natural numbers \(m\) and \(n\neq 0\), \(m=qn+r\) for some \(q\) and \(r\lt n\).
Proof. If \(m\lt n\) then \(m=0\cdot n+m\) already. Otherwise, by induction on \(m-n\) we have \(m-n=qn+r\) with \(r<n\). So \[m=(1+q)n+r\] \(\Box\)
Proof or Program ?
\(\neg P\)
Program avatar \(f: P \to \emptyset\)
\(P\Rightarrow Q\) ... modus ponens
Program avatar \(f: P \to Q\)
P | Q
Program avatar \(x\in P\sqcup Q\)
Program avatar \((p,q) \in P \times Q\)
Curry-Howard-Lambek
P & Q
\(P\sqcup Q\)
\(S\)
\(S\sqcup T\)
\(T\)
\(Q\)
\(P\)
P
P & Q
Q
S & T
T
S
\(P\)
\(P\times Q\)
\(Q\)
\(S\times T\)
\(T\)
\(S\)
\(P\)
\(P\times Q\)
\(Q\)
\(S\times T\)
\(T\)
\(S\)
\[\begin{array}{lr} P & \Rightarrow Q\\ P \\ \hline Q\end{array}\]
\[\begin{array}{rl} f & : P\to Q\\ x & \in P \\ \hline f(x) &\in Q\end{array}\]
\(\forall x.P(x)\) Program avatar \(\prod_{x\in X} P_x\)
\(\exists x.P(x)\) Program avatar \(\bigsqcup_{x\in X} P_x\)
Curry-Howard-Lambek++
\(\mathbb{N}\sqcup\{\infty\}\) conductive reaches infinity!
\(\mathbb{N}\)
\(F(\mathbb{N}):=\mathbb{N}^0\sqcup\mathbb{N}^1\)
\(\mathbb{N}^0\)
\(\mathbb{N}^1\)
Program avatar \(\omega:\mathbb{N}\sqcup\{\infty\}\to F(\mathbb{N}\sqcup\{\infty\})\). universal "F-coalgebra"
\(F(\mathbb{N}):=\mathbb{N}^0\sqcup\mathbb{N}^1\)
\(\mathbb{N}\)
\(\mathbb{N}^0\)
\(\mathbb{N}^1\)
reset
next
Program avatar \(\omega:F(\mathbb{N})\to \mathbb{N}\). "F-algebra"
\(F(\mathbb{N}):=\mathbb{N}^0\sqcup\mathbb{N}^1\)
\(\mathbb{N}\)
\(\mathbb{N}^0\)
\(\mathbb{N}^1\)
reset
next
\(\mathbb{N}\)
Equality, real numbers, topologies etc. come from inductive and conductive constructions.
Flavors
- Calculus of Inductive Constructions
- Martin-L\(\"o\)f Type Theories
before
Curry-Howard-Lambek Correspondence
Lemma "Division Algorithm". For natural numbers \(m\) and \(n\neq 0\), \(m=qn+r\) for some \(q\) and \(r\lt n\).
Proof. If \(m\lt n\) then \(m=0\cdot n+m\) already. Otherwise, by induction on \(m-n\) we have \(m-n=qn+r\) with \(r<n\). So \[m=(1+q)n+r\] \(\Box\)
\[proof:\prod_{m,n\in \mathbb{N}} \left((\text{Id}(n, 0)\to \emptyset)\to \bigsqcup_{q\in\mathbb{N}}\bigsqcup_{r\in \{1,\ldots,n-1\}} \text{Id}(m,q\cdot n+r)\times \text{LT}( r,n)\right)\]
Proposition / Data Type
Program / data of that type
For peasant math...maybe.
Is that enough for math?
- \(\forall X\in A, A\cap X=\emptyset\)
- \(A\subset B\subset A \Leftrightarrow \forall P, P(A)\Leftrightarrow P(B)\)
- \(\prod_{X\in A} X=\emptyset \Rightarrow \exists X\in A, X=\emptyset\)
Set Theory coherence
- Specification:
- Given set \(A\) and property* \(P(x)\)
- There is a set \(\{a\in A\mid P(a)\}\)
- Pairing:
- Given sets \(A,B\)
- There is a set \(\{A,B\}\)
- Union
- Given a set \(\mathcal{F}\)
- There is a set \(\bigcup_{X\in F} X\)
- Images (Replacement)\(\dagger\)
- Given a set \(A\) and definable \(x\mapsto M\)
- There is a set \(\{M[x:=a]\mid a\in A\}\)
*Predicate \(\dagger\) Only needed for uncountable stuff.
Set Theory Builders
- Power set
- Given set \(A\)
- \(\{ X\subset A\}\) is a set.
- Infinity axiom(s)
- There are sets modeling \(\mathbb{N}\)
- (Optional) There are sets with inaccessible cardinality(s)
Meta-tools
- "sorry" (holes) are meta values with the effect of "Proof. Clearly. \(\Box\)"
- axioms: actually introduce data of specific types by definition.
"Axiom (theorem)" of unique choice & "proof irrelevance" make sorry's and axioms possible and easy. Just put in \(\{*\}\).
Theorem (Gentzen). A first order sufficiently countable (\(\varepsilon_0\)) proof is unique up to replacing all modus ponens and reducing tautologies.
Coro. For proposition \(P\), if it "data" is its proofs \(p:P\) then by Gentzen \(P=\{p\}\). All singleton sets are equivalent. So proofs are irrelevant and such propositions are "mere propositions" (0-level).
Some things we know are out of this world, and harder to formalize
Higher order & Meta concepts
Proof. A property \(P\) either begins with \(\forall ...\) in which case it is true of any subset. Otherwise, choose one \(r_P\in \mathbb{R}\) making \(P(r)=\exists r...\) true.
Now \(\mathbb{R}'=\{r_P\mid P\}\) is countable as properties are finite strings.
And every \(P\) true of \(\mathbb{R}\) is true of \(\mathbb{R}'\)
Thm. Skolem.
There is a countable subset \(\mathbb{R}'\subset\mathbb{R}\) where every property of \(\mathbb{R}\) is also a property of \(\mathbb{R}'\). So \(\mathbb{R}'\) is both countable and uncountable.
Proof.
1 = 3.1415...
2 = 0.10101...
3 = 9.99999...
...
So where is 4.20....?
Thm. Cantor
There is no surjection \(f:\mathbb{N}\to \mathbb{R}\)


Tactics and Elaborators
What is Lean's power?
Proposition proof
Goal:
- given steps in a proof,
- fill in the missing parts of proposition
E.g. for \(m,n:\mathbb{N}\), \(n+m=m+n\) infers that \(+:\mathbb{N}^2\to \mathbb{N}\) and \(=:\mathbb{N}^2\to \mathsf{Prop}\)
\(p: ?\)
Elaborator
\(?: P\)
Tactic
Goal:
- given proposition
- fill in the missing parts of proof
E.g. for \(m,n:\mathbb{N}\), \(n+m=m+n\) by rewriting steps
Person
Computer
data : Type
=
Some Lean tactics
- simp tries to simplify the given data and types. Over time has grown to a "blast" tactic (throw everything at it)
- calc tries to carry out a computation
- cases/refine splits the inductive types into parts
- rw (rewrite), e.g. m+n=n+m
- intro/assumption, " Assume P..."
- aesop --- search for me...
The
Concern
Hardware is...alive?
Material Science Failures
In June 26, IBM fit
100,000,000,000 transistors

- electro-migration -- wires move from constant current (especially on corners)
- electro-chemical migration -- dendrites grow inside chip, moved by current, cause shorts.
- dielectric breakdown -- insulation failure
- transistor aging -- slows timing so fails
- thermo cycling -- heat/cooling causes stress
- tin whiskers (spontaneously growing wires).
- Cosmic rays.
Material Science failures
Chips really do change their hardware, often within a year. Error correcting codes and redundancy can help.
We can live in bunkers for a year until data center chips fail and AI stops its take over.
Moral: live fast die young
Maybe you can write a bug in your Java, but what if Java is the bug?!
Do we trust the kernel?
Academic concern: who watches the watch dog?
- Lean Kernel 5000 lines of C++
- C++ is core specification is 500 pages, code base is 2 million LOC.
- Other Lean kernels in Scala & Rust.
- C was unsound by design!
- Java & Scala are unsound (Amin-Tate, 2016),
- Rust... culture is to fix / close unsoundness as discovered
...but it's not actually academic!
- Ken Thompson (Turing awardee) who co-authored C compiler built in a quine!
- Thompson Reflections on trusting trust
Code the self replicates;
so any compiler built from that compiler inherits this parasite.
Sorry, meta variables, and unreachable
Hidden holes
theorem fermats_last_thm (n a b c : Nat) (h : n > 2) :
a^n + b^n ≠ c^n
:= by sorry
Obviously want to avoid this!
"Can't have sorry" is too blunt.
- Prove a contradiction/negation \(f:P\to \emptyset\) must lead to unprovable terms in \(\emptyset\).
- How to "Prove the unprovable"? With a sorry!
- So sorry that is unreachable is not only ok, it is necessary.
- So presence of "sorry" is not enough to declare incomplete proof.
(at least to me)
Logic is a foreign language
- English Math: There is a \(c\) where \(\log x\leq x-c\).
- AI prompted Lean: ∀ x : ℝ, 0 < x → ∃ c : ℝ, Real.log x ≤ x - c
- Back: Every \(x>0\) has some \(c\) where \(\log x\leq x-c\)
- \(\mathsf{L}\forall\exists\mathsf{N}\neq \mathsf{L}\exists\forall\mathsf{N}\) but our AI introduced the implicit \(\forall x\) in a place different than we likely intended.
- English: I count on two friends.
- Spanish: Cuento con dos amigos.
- English: I count with two friends.
- English: I see a berry.
-
Irish: Feicim caora.
-
English: I see a sheep.
Translation Game
Natural language allows (and conventions prefer)...
- Unquantified variables.
- Quantifiers may proceed subject.
- Ambiguities like "any"... is that \(\forall\) or \(\exists\)
Sharpened claim,
good!
Documentation in math is clarifying.
Documentation in Lean may backfire.
theorem every_function_is_constant (f : Nat → Nat) : ∀ x, ∃ c, f x = c :=
fun x => ⟨f x, rfl⟩
Quiz: This is accepted by Lean, you ok with it?
- The code says \[\forall x\exists c.(f(x)=c)\] and proves it using \(c:=x\).
- The label suggests it says \[\exists c\forall x.(f(x)=c.\]
/-- We show odd order groups have at least one proper nontrivial normal Hall subgroup. -/
theorem odd_order_thm (G : Type*) [Group G] [Finite G] (hG : Odd (Nat.card G)) :
∃ H : Subgroup G, H.Normal ∧ Nat.Coprime (Nat.card H) H.index :=
⟨⊤, inferInstance, by simp⟩
Checked by machine;
so my brain often glazes over...
Users (and AI) might read more from names and documentation that are possibly detached from the code's real meaning.
Thinko: the documentation promises a "proper nontrivial" but in the end only check normal and Hall. You may fail to notice within the notation.
structure Fraction where
num : Nat
den : Nat
/-- One half is not two quarters. -/
theorem half_ne_two_quarters : (⟨1, 2⟩ : Fraction) ≠ ⟨2, 4⟩ := by
intro h
cases h
- Our fraction data type forgot to include a proper notion of equality.
- The force of "Fraction" name lets us read intention that does not match features.
Tactic: break into "cases" i.e. the two parts num, den created separately
Careful what you use but do not understand
Design may out run Intent
theorem div_zero_harmless (n : Nat) : n / 0 = 0 :=
by simp
Valid proposition.
Right sized tactic
Accurate name
Sometimes Lean / MathLib / AI just defines things differently than you might.
\[m/ n := \begin{cases} q & n\gt 0, m=qn+r, r\lt n\\ 0 & \text{else}\end{cases}\]
Good reason? Makes \(\Box/\Box:\mathbb{N}^2\to \mathbb{N}\) total (required for type checker).
Cautious meets Eager
Mitigation & Reality
Surface level confusion
Include lots of examples! That does wonders to spotlight typos & thinkos, even when you still don't fully understand the code.
Library coherence
Review and refereeing of libraries and tactics towards a consensus.
Kernel Glitches
Cautious people are making line-by-line publicly scrutinized alternative kernels.
Hardware Glitches
Error correction, controlled failure probabilities, & syndromes. An error in hardware likely gets noticed.
Mitigations
Don't trust a certified proofs in your field until you have certified one of your own.
My advice?
Level
Up
Thm. "Ladner Ladders". Either \(P=NP\) or there are infinitely many intermediate complexities. More generally, given any oracle \(O\), there are infinitely many complexities between \(P^O\) and \(NP^O\).
In other words, if AI can do math \(O\) then there are infinitely many levels of difficulty for you to reach next.
There is more to do
There is more to do
Thm. Kleene. Turing machines are only universal in at the 1st level. 2nd, 3rd etc. Kleene algebra actions do not have a universal machine.
So perhaps we let Turing completeness, and for that matter Hilbert natural deduction, and ZFC, and classical logic pause our creativity too long.
Computation is the representation theory of partial combinatory algebras \(\langle S,K\mid Kxy=x, Sxyz=(xz)(yz)\rangle\).
A project ....

A Colorado avalanche destroys the giants


Math needs its aspens to stand back up.
Aspens flex
& recover the forest
Lean-Mean
By James Wilson
Lean-Mean
It is proved in Lean! What does that mean?
- 30


