It is proved in Lean!

What does that mean?

James B. Wilson

Professor of Mathematics 

Colorado State University 

Tank
Ye

The
Subject

AI is having a moment.

Lean is having a moment within that moment.

Within Math we're having a ... crisis?

  • AI searches, combines, generates ideas,
  • Converts to Lean to try and prove,
  • While failing, adapt and retry.

 

What should we know? trust? ask? do?

 

...what is different (th)is time?

This is not new

Epigram McBride-McKinna (Edinbrugh)

NuPrl, Constable (Cornell)

1980

1990

2000

 

2010

 

2020

 

Paulson, Cambridge & Tech. Uni. Munich

T. Couqand, et. al. INRIA et. al.

Norell-C. Coquand (Chalmers)

Brady (St. Andrews)

System F, Girard 

MLTT, Martin-L\(\"o\)f

 

Computation has been this capable for 5000 years.

So what's new?  Speed & Volume.

What's our history? We adapt.

Thm. (Minsky) The Abacus is Turing Complete

...this could have been any one of the others.

While Lean is our subject today

What is \(\mathsf{L}\exists\forall\mathsf{ N}\)?

  • Programming language
    • Functional (Haskell syntax),
    • strongly/statically typed
  • Type checker
    • Dependent,
    • Inductive,
    • multi-sorted calculus of construction.
  • Proof checker
    • Proof irrelevant,
    • (mere) Propositions as type
  • Proof assistant
    • Elaborator
    • Tactic script,
    • SAT (mod Theory), Linear program solver, native_decide

Curry-Howard-Lambek Correspondence

Lemma "Division Algorithm".  For natural numbers \(m\) and \(n\neq 0\), \(m=qn+r\) for some \(q\) and \(r\lt n\).

Proof.  If \(m\lt n\) then \(m=0\cdot n+m\) already.  Otherwise, by induction on \(m-n\) we have \(m-n=qn+r\) with \(r<n\).  So \[m=(1+q)n+r\] \(\Box\)

Proof or Program ?

\(\neg P\)

Program avatar \(f: P \to \emptyset\)

\(P\Rightarrow Q\) ... modus ponens

Program avatar \(f: P \to Q\)

P | Q

Program avatar \(x\in P\sqcup Q\)

Program avatar \((p,q) \in P \times Q\)

Curry-Howard-Lambek

P & Q

\(P\sqcup Q\)

\(S\)

\(S\sqcup T\)

\(T\)

\(Q\)

\(P\)

P

P & Q

Q

S & T

T

S

\(P\)

\(P\times Q\)

\(Q\)

\(S\times T\)

\(T\)

\(S\)

\(P\)

\(P\times Q\)

\(Q\)

\(S\times T\)

\(T\)

\(S\)

\[\begin{array}{lr} P & \Rightarrow Q\\ P \\ \hline Q\end{array}\]

\[\begin{array}{rl} f & : P\to Q\\ x & \in P \\ \hline f(x) &\in Q\end{array}\]

\(\forall x.P(x)\)   Program avatar \(\prod_{x\in X} P_x\)

\(\exists x.P(x)\)   Program avatar \(\bigsqcup_{x\in X} P_x\)

Curry-Howard-Lambek++

\(\mathbb{N}\sqcup\{\infty\}\) conductive reaches infinity!

\(\mathbb{N}\)

\(F(\mathbb{N}):=\mathbb{N}^0\sqcup\mathbb{N}^1\)

\(\mathbb{N}^0\)

\(\mathbb{N}^1\)

Program avatar \(\omega:\mathbb{N}\sqcup\{\infty\}\to F(\mathbb{N}\sqcup\{\infty\})\). universal "F-coalgebra"

\(F(\mathbb{N}):=\mathbb{N}^0\sqcup\mathbb{N}^1\)

\(\mathbb{N}\)

\(\mathbb{N}^0\)

\(\mathbb{N}^1\)

 reset

 next

Program avatar \(\omega:F(\mathbb{N})\to \mathbb{N}\). "F-algebra"

\(F(\mathbb{N}):=\mathbb{N}^0\sqcup\mathbb{N}^1\)

\(\mathbb{N}\)

\(\mathbb{N}^0\)

\(\mathbb{N}^1\)

 reset

 next

\(\mathbb{N}\)

Equality, real numbers, topologies etc. come from inductive and conductive constructions.

Flavors

  • Calculus of Inductive Constructions 
  • Martin-L\(\"o\)f Type Theories

before

Curry-Howard-Lambek Correspondence

Lemma "Division Algorithm".  For natural numbers \(m\) and \(n\neq 0\), \(m=qn+r\) for some \(q\) and \(r\lt n\).

Proof.  If \(m\lt n\) then \(m=0\cdot n+m\) already.  Otherwise, by induction on \(m-n\) we have \(m-n=qn+r\) with \(r<n\).  So \[m=(1+q)n+r\] \(\Box\)

\[proof:\prod_{m,n\in \mathbb{N}} \left((\text{Id}(n, 0)\to \emptyset)\to \bigsqcup_{q\in\mathbb{N}}\bigsqcup_{r\in \{1,\ldots,n-1\}} \text{Id}(m,q\cdot n+r)\times \text{LT}( r,n)\right)\]

Proposition / Data Type

Program / data of that type

For peasant math...maybe.

Is that enough for math?

  • \(\forall X\in A, A\cap X=\emptyset\)
  • \(A\subset B\subset A \Leftrightarrow \forall P, P(A)\Leftrightarrow P(B)\)
  • \(\prod_{X\in A} X=\emptyset \Rightarrow \exists X\in A, X=\emptyset\)

Set Theory coherence

  • Specification:
    • Given set \(A\) and property* \(P(x)\)
    • There is a set \(\{a\in A\mid P(a)\}\)
  • Pairing:
    • Given sets \(A,B\)
    • There is a set \(\{A,B\}\)
  • Union
    • Given a set \(\mathcal{F}\)
    • There is a set \(\bigcup_{X\in F} X\)
  • Images (Replacement)\(\dagger\)
    • Given a set \(A\) and definable \(x\mapsto M\)
    • There is a set \(\{M[x:=a]\mid a\in A\}\)

*Predicate \(\dagger\) Only needed for uncountable stuff.

Set Theory Builders

 

  • Power set
    • Given set \(A\)
    • \(\{ X\subset A\}\) is a set.
  • Infinity axiom(s)
    • There are sets modeling \(\mathbb{N}\)
    • (Optional) There are sets with inaccessible cardinality(s)

Meta-tools

  • "sorry" (holes) are meta values with the effect of "Proof.  Clearly. \(\Box\)"
  • axioms: actually introduce data of specific types by definition.

"Axiom (theorem)" of unique choice & "proof irrelevance" make sorry's and axioms possible and easy.  Just put in \(\{*\}\).

Theorem (Gentzen).  A first order sufficiently countable (\(\varepsilon_0\)) proof is unique up to replacing all modus ponens and reducing tautologies.

Coro.  For proposition \(P\), if it "data" is its proofs \(p:P\) then by Gentzen \(P=\{p\}\).  All singleton sets are equivalent.  So proofs are irrelevant and such propositions are "mere propositions" (0-level).

Some things we know are out of this world, and harder to formalize

Higher order & Meta concepts

Proof.   A property \(P\) either begins with \(\forall ...\) in which case it is true of any subset.  Otherwise, choose one \(r_P\in \mathbb{R}\) making \(P(r)=\exists r...\) true.  

Now \(\mathbb{R}'=\{r_P\mid P\}\) is countable as properties are finite strings.

And every \(P\) true of \(\mathbb{R}\) is true of \(\mathbb{R}'\) 

Thm. Skolem.

There is a countable subset \(\mathbb{R}'\subset\mathbb{R}\) where every property of \(\mathbb{R}\) is also a property of \(\mathbb{R}'\).  So \(\mathbb{R}'\) is both countable and uncountable.

Proof.

1 = 3.1415...

2 = 0.10101...

3 = 9.99999...

...

So where is 4.20....?

 

Thm. Cantor

There is no surjection \(f:\mathbb{N}\to \mathbb{R}\)

Tactics and Elaborators

What is Lean's power?

Proposition proof

Goal:

  • given steps in a proof,
  • fill in the missing parts of proposition

E.g. for \(m,n:\mathbb{N}\), \(n+m=m+n\) infers that \(+:\mathbb{N}^2\to \mathbb{N}\) and \(=:\mathbb{N}^2\to \mathsf{Prop}\)

\(p: ?\)

Elaborator

\(?: P\)

Tactic 

Goal:

  • given proposition
  • fill in the missing parts of proof

E.g. for \(m,n:\mathbb{N}\), \(n+m=m+n\) by rewriting steps

Person

Computer

data : Type

=

Some Lean tactics

  • simp tries to simplify the given data and types. Over time has grown to a "blast" tactic (throw everything at it)
  • calc tries to carry out a computation
  • cases/refine splits the inductive types into parts
  • rw (rewrite), e.g. m+n=n+m
  • intro/assumption, " Assume P..."
  • aesop --- search for me...

The
Concern

Hardware is...alive?

Material Science Failures

In June 26, IBM fit 

100,000,000,000 transistors

  • electro-migration -- wires move from constant current (especially on corners)
  • electro-chemical migration -- dendrites grow inside chip, moved by current, cause shorts.
  • dielectric breakdown -- insulation failure
  • transistor aging -- slows timing so fails 
  • thermo cycling -- heat/cooling causes stress
  • tin whiskers (spontaneously growing wires). 
  • Cosmic rays.

Material Science failures

Chips really do change their hardware, often within a year.  Error correcting codes and redundancy can help.

We can live in bunkers for a year until data center chips fail and AI stops its take over.

Moral: live fast die young

Maybe you can write a bug in your Java, but what if Java is the bug?!

Do we trust the kernel?

Academic concern: who watches the watch dog?

  • Lean Kernel 5000 lines of C++
  • C++ is core specification is 500 pages, code base is 2 million LOC.
  • Other Lean kernels in Scala & Rust.
  • C was unsound by design!
  • Java & Scala are unsound (Amin-Tate, 2016),
  • Rust... culture is to fix / close unsoundness as discovered

...but it's not actually academic!

  • Ken Thompson (Turing awardee) who co-authored C compiler built in a quine!
  • Thompson Reflections on trusting trust

Code the self replicates;

so any compiler built from that compiler inherits this parasite.

Sorry, meta variables, and unreachable

Hidden holes

theorem fermats_last_thm (n a b c : Nat) (h : n > 2) :

                                                   a^n + b^n ≠ c^n

              := by sorry

Obviously want to avoid this!

"Can't have sorry" is too blunt.

  • Prove a contradiction/negation \(f:P\to \emptyset\) must lead to unprovable terms in \(\emptyset\).
  • How to "Prove the unprovable"?  With a sorry!
  • So sorry that is unreachable is not only ok, it is necessary. 
  • So presence of "sorry" is not enough to declare incomplete proof.

(at least to me)

Logic is a foreign language

  • English Math: There is a \(c\) where \(\log x\leq x-c\).
  • AI prompted Lean: ∀ x : ℝ, 0 < x → ∃ c : ℝ, Real.log x ≤ x - c
  • Back: Every \(x>0\) has some \(c\) where \(\log x\leq x-c\)
  • \(\mathsf{L}\forall\exists\mathsf{N}\neq \mathsf{L}\exists\forall\mathsf{N}\) but our AI introduced the implicit \(\forall x\) in a place different than we likely intended.

 

  • English: I count on two friends.
  • Spanish: Cuento con dos amigos.
  • English: I count with two friends.

 

  • English: I see a berry.
  • Irish: Feicim caora.

  • English: I see a sheep.

Translation Game

Natural language allows (and conventions prefer)...

  • Unquantified variables.
  • Quantifiers may proceed subject.
  • Ambiguities like "any"... is that \(\forall\) or \(\exists\)

Sharpened claim,

good!

Documentation in math is clarifying.

Documentation in Lean may backfire.

theorem every_function_is_constant (f : Nat → Nat) : ∀ x, ∃ c, f x = c :=

         fun x => ⟨f x, rfl⟩

Quiz: This is accepted by Lean, you ok with it?

  • The code says \[\forall x\exists c.(f(x)=c)\] and proves it using \(c:=x\).
  • The label suggests it says \[\exists c\forall x.(f(x)=c.\]

/-- We show odd order groups have at least one proper nontrivial normal Hall subgroup. -/

theorem odd_order_thm (G : Type*) [Group G] [Finite G] (hG : Odd (Nat.card G)) :

∃ H : Subgroup G, H.Normal ∧ Nat.Coprime (Nat.card H) H.index :=

         ⟨⊤, inferInstance, by simp⟩

 

Checked by machine; 

so my brain often glazes over...

Users (and AI) might read more from names and documentation that are possibly detached from the code's real meaning.

Thinko: the documentation promises a "proper nontrivial" but in the end only check normal and Hall.  You may fail to notice within the notation.

structure Fraction where

    num : Nat

    den : Nat

 

/-- One half is not two quarters. -/

theorem half_ne_two_quarters : (⟨1, 2⟩ : Fraction) ≠ ⟨2, 4⟩ := by

    intro h

    cases h

 

  • Our fraction data type forgot to include a proper notion of equality.
  • The force of "Fraction" name lets us read intention that does not match features.

Tactic: break into "cases" i.e. the two parts num, den created separately

Careful what you use but do not understand

Design may out run Intent

theorem div_zero_harmless (n : Nat) : n / 0 = 0 :=

     by simp

Valid proposition.

Right sized tactic

Accurate name

Sometimes Lean / MathLib / AI just defines things differently than you might.

\[m/ n := \begin{cases} q & n\gt 0, m=qn+r, r\lt n\\ 0 & \text{else}\end{cases}\]

Good reason? Makes \(\Box/\Box:\mathbb{N}^2\to \mathbb{N}\) total (required for type checker).

Cautious meets Eager 

Mitigation & Reality

Surface level confusion

Include lots of examples!  That does wonders to spotlight typos & thinkos, even when you still don't fully understand the code.

Library coherence

Review and refereeing of libraries and tactics towards a consensus.

Kernel Glitches

Cautious people are making line-by-line publicly scrutinized alternative kernels.

Hardware Glitches

Error correction, controlled failure probabilities, & syndromes.  An error in hardware likely gets noticed.

Mitigations

Don't trust a certified proofs in your field until you have certified one of your own. 

My advice?

Level
Up

Thm. "Ladner Ladders". Either \(P=NP\) or there are infinitely many intermediate complexities.  More generally, given any oracle \(O\), there are infinitely many complexities between \(P^O\) and \(NP^O\).  

 

In other words, if AI can do math \(O\) then there are infinitely many levels of difficulty for you to reach next.

There is more to do

There is more to do

Thm. Kleene.  Turing machines are only universal in at the 1st level. 2nd, 3rd etc. Kleene algebra actions do not have a universal machine.  

 

So perhaps we let Turing completeness, and for that matter Hilbert natural deduction, and ZFC, and classical logic pause our creativity too long.

Computation is the representation theory of partial combinatory algebras \(\langle S,K\mid Kxy=x, Sxyz=(xz)(yz)\rangle\).

A Colorado avalanche destroys the giants

Math needs its aspens to stand back up.

Aspens flex

 & recover the forest