- The paper establishes a constructive correspondence between lattice witnesses and finitary winning strategies in primal and dual fixpoint games, with ordinal degree measures guaranteeing termination.
- Witness existence precisely characterizes strict lower bounds and non-upper bounds for least fixpoints, under continuity, co-continuity, irreducibility, and properness assumptions.
- The framework generates certificates for bisimilarity, Kantorovich behavioural metrics, and Markov-chain termination probabilities, including formula-, linear-programming-, and tree-based witnesses.
Overview
The paper develops a lattice-theoretic framework for constructing witnesses — abstract counterparts of distinguishing formulas — that certify lower bounds for least fixpoints of monotone functions, or certify that a given element is not an upper bound. The setting is a Galois connection α⊣γ between a "logic universe" L (where witnesses live) and a "behaviour universe" B (where the behaviour function beh is defined), with the compatibility condition α∘log=beh∘α, which guarantees α(μlog)=μbeh and preservation of all Kleene iteration stages (2603.11908). This generalizes the Galois-connection account of the Hennessy-Milner theorem from prior work by the same group.
The central contribution is a bidirectional correspondence between witnesses and winning strategies in two fixpoint games on continuous lattices: a primal way-below game (where the witness guides the existential player ∃) and a dual game (obtained by dualizing the greatest-fixpoint game, where the witness guides the universal player ∀). Both directions are constructive: witnesses yield finitary strategies, and strategies yield witnesses via inductive definitions whose termination is controlled by ordinal-valued degree measures.
Witnesses and degrees
A primal witness for b∈B is an element a∈L with L0 and L1; a dual witness satisfies L2. Existence is characterized exactly: assuming L3 continuous with a join basis of irreducibles, a primal witness for basis element L4 exists iff L5, and a dual witness exists iff L6. The proof reduces to the fact that the left adjoint L7 preserves directed suprema, so L8 can be witnessed on a basis element below L9.
Two ordinal-valued measures organize the constructions: the degree B0, the least B1 with B2, and the co-degree B3, the least B4 with B5. Key properties include additivity of degree over finite joins (B6) and the bound B7 relating a witness to the co-degree of its target. These ensure that recursive witness construction terminates.
Fixpoint games and finitary strategies
The paper introduces a new variant of the fixpoint games of Baldan, König, Mika-Michalski, and Padoan: the primal way-below game, in which B8 must play B9 with beh0 and beh1 answers with beh2. Its soundness and completeness rest on continuity of beh3: beh4 has a winning strategy from beh5 iff beh6. Notably, when beh7 is Scott-continuous, beh8 has a finitary winning strategy — each move is a finite join of basis elements of strictly smaller degree — so the game terminates within beh9 steps. The argument uses compactness of sets of the form α∘log=beh∘α0 and openness of α∘log=beh∘α1.
Continuity of the lattice is essential, not incidental: the paper gives a counterexample on a non-continuous lattice where α∘log=beh∘α2 wins although α∘log=beh∘α3. For such settings the dual game applies instead, requiring only co-continuity plus co-properness of α∘log=beh∘α4 (inverse images of downward closures of basis elements are co-compact). Under these hypotheses, α∘log=beh∘α5 possesses a finitary winning strategy that is uniform over α∘log=beh∘α6's moves: a single finite set α∘log=beh∘α7 of basis elements covers all replies, each decreasing the co-degree, so α∘log=beh∘α8 wins within α∘log=beh∘α9 steps. In the bisimilarity instantiation, the dual game coincides with a coupling game, and the primal game recovers the classical Stirling-style bisimulation game.
Witness–strategy correspondence
The technical core is a pair of translations along the Galois connection, mediated by three auxiliary choice functions (α(μlog)=μbeh0, α(μlog)=μbeh1, α(μlog)=μbeh2) whose existence follows from the basis/irreducibility lemmas:
- Witnesses to strategies: given a primal witness α(μlog)=μbeh3 for α(μlog)=μbeh4 and a finitary strategy for α(μlog)=μbeh5 in the way-below game on α(μlog)=μbeh6, one obtains a valid move α(μlog)=μbeh7 in the game on α(μlog)=μbeh8; every reply α(μlog)=μbeh9 admits a sub-witness of strictly smaller degree. Dually, a dual witness yields a move for ∃0 in the dual game via ∃1.
- Strategies to witnesses: given a finitary winning strategy ∃2, the witness is defined inductively as ∃3, with ∃4; analogously for the dual game using ∃5.
An immediate consequence is that these are effective procedures: computing a distinguishing formula reduces to solving the local inequalities defining the strategy at each step.
Case studies
Three instantiations validate the framework. First, bisimilarity on finitely branching transition systems reproduces distinguishing formulas à la Cleaveland: the witness is a Hennessy-Milner formula built as ∃6 over recursively computed sub-witnesses, and the primal game mirrors the standard bisimulation game.
Second, behavioural metrics for labelled Markov chains under the Kantorovich lifting. Here ∃7, the logic side consists of sets of random variables closed under ∃8, truncated subtraction, and max, and ∃9 maps a set of functions to the sup-norm distance it induces. The instantiation of probabilistic systems into this Galois-connection framework is itself new relative to earlier work. Strategy computation reduces to linear programming over coupling polytopes: since optima are attained at vertices, one solves inequalities ∀0 subject to ∀1, yielding basis elements ∀2. A practical benefit noted by the authors: because the framework certifies strict lower bounds rather than exact distances, it sidesteps the known impossibility of witnessing exact behavioural distance by a single formula.
Third, a new case study on termination probabilities in Markov chains, where witnesses are trees: a tree rooted at ∀3 with children of distinct roots under-approximates the termination probability via the functional ∀4, and ∀5 maps a set of trees to the pointwise supremum of their values. The authors prove both that ∀6 under-approximates ∀7 and that ∀8, so the framework applies verbatim; the resulting certificates are explicit tree-shaped proofs of lower bounds on termination probability.
Limitations and open questions
Several assumptions carry real weight. The primal game's completeness fails without continuity of ∀9, as the counterexample shows, and the dual route requires co-properness of b∈B0 — a condition whose verification is nontrivial even in the metric case, where it rests on a compactness argument the authors themselves flag for rechecking. Finitary strategies additionally require Scott-continuity of the behaviour function, which excludes systems where fixpoints are reached only at transfinite stages. The auxiliary functions b∈B1, b∈B2, b∈B3 are defined by existence guarantees rather than algorithms, so concrete instantiations must supply effective choices. Open questions raised include the treatment of characteristic formulas, the use of the dual game on the logic side, connections to the codensity game (which would involve simultaneous play on both lattices), and links to recent proof-system-based approaches to apartness and lower-bound witnesses.
Conclusion
The paper provides a uniform, constructive account of witnesses for least-fixpoint statements over lattices, establishing exact correspondences between witnesses and finitary winning strategies in a primal and a dual fixpoint game, with termination guaranteed by ordinal degree measures. It subsumes known constructions for bisimilarity and probabilistic behavioural metrics and delivers a new certification method for termination probabilities in Markov chains, while making precise which domain-theoretic hypotheses (continuity, co-continuity, properness) each guarantee requires.