Papers
Topics
Authors
Recent
Search
2000 character limit reached

Witnesses for Fixpoint Games on Lattices

Published 12 Mar 2026 in cs.LO | (2603.11908v1)

Abstract: We construct witnesses that can be used to derive strategies in fixpoint games and provide proof that the least fixpoint of a function is either above or not below some given bound. We rely on a lattice-theoretical approach, including a Galois connection that connects a lattice representing the "logic universe", where the witness lives, with another lattice representing the "behaviour universe", over which the function is defined. In fact we consider two types of games -- primal and dual games -- and in both cases show how to derive winning strategies in the game from witnesses and construct witnesses from strategies. The two games differ wrt. their rules and the choice of basis of the lattice. The theory can be instantiated to well-known examples: in particular we compare with the construction of distinguishing formulas in standard bisimilarity and behavioural metrics for probabilistic systems. As a new case study we consider witnesses for certifying lower bounds for the termination probability for Markov chains.

Authors (2)

Summary

  • The paper establishes a constructive correspondence between lattice witnesses and finitary winning strategies in primal and dual fixpoint games, with ordinal degree measures guaranteeing termination.
  • Witness existence precisely characterizes strict lower bounds and non-upper bounds for least fixpoints, under continuity, co-continuity, irreducibility, and properness assumptions.
  • The framework generates certificates for bisimilarity, Kantorovich behavioural metrics, and Markov-chain termination probabilities, including formula-, linear-programming-, and tree-based witnesses.

Overview

The paper develops a lattice-theoretic framework for constructing witnesses — abstract counterparts of distinguishing formulas — that certify lower bounds for least fixpoints of monotone functions, or certify that a given element is not an upper bound. The setting is a Galois connection αγ\alpha \dashv \gamma between a "logic universe" L\mathbb{L} (where witnesses live) and a "behaviour universe" B\mathbb{B} (where the behaviour function beh\mathsf{beh} is defined), with the compatibility condition αlog=behα\alpha \circ \mathsf{log} = \mathsf{beh} \circ \alpha, which guarantees α(μlog)=μbeh\alpha(\mu\,\mathsf{log}) = \mu\,\mathsf{beh} and preservation of all Kleene iteration stages (2603.11908). This generalizes the Galois-connection account of the Hennessy-Milner theorem from prior work by the same group.

The central contribution is a bidirectional correspondence between witnesses and winning strategies in two fixpoint games on continuous lattices: a primal way-below game (where the witness guides the existential player \exists) and a dual game (obtained by dualizing the greatest-fixpoint game, where the witness guides the universal player \forall). Both directions are constructive: witnesses yield finitary strategies, and strategies yield witnesses via inductive definitions whose termination is controlled by ordinal-valued degree measures.

Witnesses and degrees

A primal witness for bBb \in \mathbb{B} is an element aLa \in \mathbb{L} with L\mathbb{L}0 and L\mathbb{L}1; a dual witness satisfies L\mathbb{L}2. Existence is characterized exactly: assuming L\mathbb{L}3 continuous with a join basis of irreducibles, a primal witness for basis element L\mathbb{L}4 exists iff L\mathbb{L}5, and a dual witness exists iff L\mathbb{L}6. The proof reduces to the fact that the left adjoint L\mathbb{L}7 preserves directed suprema, so L\mathbb{L}8 can be witnessed on a basis element below L\mathbb{L}9.

Two ordinal-valued measures organize the constructions: the degree B\mathbb{B}0, the least B\mathbb{B}1 with B\mathbb{B}2, and the co-degree B\mathbb{B}3, the least B\mathbb{B}4 with B\mathbb{B}5. Key properties include additivity of degree over finite joins (B\mathbb{B}6) and the bound B\mathbb{B}7 relating a witness to the co-degree of its target. These ensure that recursive witness construction terminates.

Fixpoint games and finitary strategies

The paper introduces a new variant of the fixpoint games of Baldan, König, Mika-Michalski, and Padoan: the primal way-below game, in which B\mathbb{B}8 must play B\mathbb{B}9 with beh\mathsf{beh}0 and beh\mathsf{beh}1 answers with beh\mathsf{beh}2. Its soundness and completeness rest on continuity of beh\mathsf{beh}3: beh\mathsf{beh}4 has a winning strategy from beh\mathsf{beh}5 iff beh\mathsf{beh}6. Notably, when beh\mathsf{beh}7 is Scott-continuous, beh\mathsf{beh}8 has a finitary winning strategy — each move is a finite join of basis elements of strictly smaller degree — so the game terminates within beh\mathsf{beh}9 steps. The argument uses compactness of sets of the form αlog=behα\alpha \circ \mathsf{log} = \mathsf{beh} \circ \alpha0 and openness of αlog=behα\alpha \circ \mathsf{log} = \mathsf{beh} \circ \alpha1.

Continuity of the lattice is essential, not incidental: the paper gives a counterexample on a non-continuous lattice where αlog=behα\alpha \circ \mathsf{log} = \mathsf{beh} \circ \alpha2 wins although αlog=behα\alpha \circ \mathsf{log} = \mathsf{beh} \circ \alpha3. For such settings the dual game applies instead, requiring only co-continuity plus co-properness of αlog=behα\alpha \circ \mathsf{log} = \mathsf{beh} \circ \alpha4 (inverse images of downward closures of basis elements are co-compact). Under these hypotheses, αlog=behα\alpha \circ \mathsf{log} = \mathsf{beh} \circ \alpha5 possesses a finitary winning strategy that is uniform over αlog=behα\alpha \circ \mathsf{log} = \mathsf{beh} \circ \alpha6's moves: a single finite set αlog=behα\alpha \circ \mathsf{log} = \mathsf{beh} \circ \alpha7 of basis elements covers all replies, each decreasing the co-degree, so αlog=behα\alpha \circ \mathsf{log} = \mathsf{beh} \circ \alpha8 wins within αlog=behα\alpha \circ \mathsf{log} = \mathsf{beh} \circ \alpha9 steps. In the bisimilarity instantiation, the dual game coincides with a coupling game, and the primal game recovers the classical Stirling-style bisimulation game.

Witness–strategy correspondence

The technical core is a pair of translations along the Galois connection, mediated by three auxiliary choice functions (α(μlog)=μbeh\alpha(\mu\,\mathsf{log}) = \mu\,\mathsf{beh}0, α(μlog)=μbeh\alpha(\mu\,\mathsf{log}) = \mu\,\mathsf{beh}1, α(μlog)=μbeh\alpha(\mu\,\mathsf{log}) = \mu\,\mathsf{beh}2) whose existence follows from the basis/irreducibility lemmas:

  • Witnesses to strategies: given a primal witness α(μlog)=μbeh\alpha(\mu\,\mathsf{log}) = \mu\,\mathsf{beh}3 for α(μlog)=μbeh\alpha(\mu\,\mathsf{log}) = \mu\,\mathsf{beh}4 and a finitary strategy for α(μlog)=μbeh\alpha(\mu\,\mathsf{log}) = \mu\,\mathsf{beh}5 in the way-below game on α(μlog)=μbeh\alpha(\mu\,\mathsf{log}) = \mu\,\mathsf{beh}6, one obtains a valid move α(μlog)=μbeh\alpha(\mu\,\mathsf{log}) = \mu\,\mathsf{beh}7 in the game on α(μlog)=μbeh\alpha(\mu\,\mathsf{log}) = \mu\,\mathsf{beh}8; every reply α(μlog)=μbeh\alpha(\mu\,\mathsf{log}) = \mu\,\mathsf{beh}9 admits a sub-witness of strictly smaller degree. Dually, a dual witness yields a move for \exists0 in the dual game via \exists1.
  • Strategies to witnesses: given a finitary winning strategy \exists2, the witness is defined inductively as \exists3, with \exists4; analogously for the dual game using \exists5.

An immediate consequence is that these are effective procedures: computing a distinguishing formula reduces to solving the local inequalities defining the strategy at each step.

Case studies

Three instantiations validate the framework. First, bisimilarity on finitely branching transition systems reproduces distinguishing formulas à la Cleaveland: the witness is a Hennessy-Milner formula built as \exists6 over recursively computed sub-witnesses, and the primal game mirrors the standard bisimulation game.

Second, behavioural metrics for labelled Markov chains under the Kantorovich lifting. Here \exists7, the logic side consists of sets of random variables closed under \exists8, truncated subtraction, and max, and \exists9 maps a set of functions to the sup-norm distance it induces. The instantiation of probabilistic systems into this Galois-connection framework is itself new relative to earlier work. Strategy computation reduces to linear programming over coupling polytopes: since optima are attained at vertices, one solves inequalities \forall0 subject to \forall1, yielding basis elements \forall2. A practical benefit noted by the authors: because the framework certifies strict lower bounds rather than exact distances, it sidesteps the known impossibility of witnessing exact behavioural distance by a single formula.

Third, a new case study on termination probabilities in Markov chains, where witnesses are trees: a tree rooted at \forall3 with children of distinct roots under-approximates the termination probability via the functional \forall4, and \forall5 maps a set of trees to the pointwise supremum of their values. The authors prove both that \forall6 under-approximates \forall7 and that \forall8, so the framework applies verbatim; the resulting certificates are explicit tree-shaped proofs of lower bounds on termination probability.

Limitations and open questions

Several assumptions carry real weight. The primal game's completeness fails without continuity of \forall9, as the counterexample shows, and the dual route requires co-properness of bBb \in \mathbb{B}0 — a condition whose verification is nontrivial even in the metric case, where it rests on a compactness argument the authors themselves flag for rechecking. Finitary strategies additionally require Scott-continuity of the behaviour function, which excludes systems where fixpoints are reached only at transfinite stages. The auxiliary functions bBb \in \mathbb{B}1, bBb \in \mathbb{B}2, bBb \in \mathbb{B}3 are defined by existence guarantees rather than algorithms, so concrete instantiations must supply effective choices. Open questions raised include the treatment of characteristic formulas, the use of the dual game on the logic side, connections to the codensity game (which would involve simultaneous play on both lattices), and links to recent proof-system-based approaches to apartness and lower-bound witnesses.

Conclusion

The paper provides a uniform, constructive account of witnesses for least-fixpoint statements over lattices, establishing exact correspondences between witnesses and finitary winning strategies in a primal and a dual fixpoint game, with termination guaranteed by ordinal degree measures. It subsumes known constructions for bisimilarity and probabilistic behavioural metrics and delivers a new certification method for termination probabilities in Markov chains, while making precise which domain-theoretic hypotheses (continuity, co-continuity, properness) each guarantee requires.

Paper to Video (Beta)

No one has generated a video about this paper yet.

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Open Problems

We haven't generated a list of open problems mentioned in this paper yet.