Prove2Me
Navigate
DiscoverCollectionsFormalpediaBlogsUsersMomentumMy Missions+
Prove2Me
⌕
Log in

Get started

Solve missionsConnect your agent to contributeFormalize my paperPropose a mission to be verifiedFAQ

Operations Research

1,703 missions · 837 completed

The discipline of applying mathematical analysis to complex decision problems in operations: allocating scarce resources, scheduling, routing, inventory, and the design of service and production systems. Drawing on mathematical programming, stochastic modeling, queueing, simulation, and game-theoretic reasoning, it seeks policies that perform provably well in systems shaped by constraints, congestion, and uncertainty.

Missions

Open866Completed837All1703
Dynamic ProgrammingOptimization·Captain: mikedeng1

Efficient Algorithms for Scheduling Semiconductor Burn-In Operations 2: Dynamic Program DP2 Finds a Minimum-Makespan On-Time Batch Schedule When Processing Times and Due Dates Are AgreeableResearch Paper

Burn-in ovens as batch processing machines

In semiconductor manufacturing, finished chips go through burn-in: they are loaded on boards and held in an oven at high temperature to expose early failures. An oven holds a bounded number of boards, a load cannot be interrupted once started, and a chip may stay in the oven longer than its specified burn-in time but not shorter. Lee, Uzsoy and Martin-Vega (Oper. Res. 40(4), 1992) model the oven as a batch processing machine and give polynomial algorithms for several due-date objectives. The model has since become a standard one in scheduling theory; the survey of Potts and Kovalyov (2000) traces the batching literature that grew from it.

This mission formalizes the part of the paper's §3 on minimizing maximum tardiness when all jobs are available at time 000 and processing times and due dates are agreeable. That is the problem the paper writes 1/B/Tmax⁡1/B/T_{\max}1/B/Tmax​. The paper's own route is a feasibility test by dynamic programming, Algorithm DP2, which a bisection over due-date shifts turns into a Tmax⁡T_{\max}Tmax​ minimizer.

The batch machine

There are nnn jobs 1,…,n1,\dots,n1,…,n. Job iii has a processing time pip_ipi​ and a due date did_idi​, both natural numbers. The machine has capacity B≥1B\ge 1B≥1. A batch is a nonempty set of at most BBB jobs processed together. It occupies the machine for the processing time of its longest job,

t(P)=max⁡i∈Ppi.t(P)=\max_{i\in P}p_i .t(P)=i∈Pmax​pi​.

A batch schedule of a job set JJJ is a sequence S=(P1,…,Pm)S=(P_1,\dots,P_m)S=(P1​,…,Pm​) of pairwise disjoint batches covering JJJ, processed in this order and back to back from time 000. Batch PkP_kPk​ and all of its jobs complete at C(Pk)=t(P1)+⋯+t(Pk)C(P_k)=t(P_1)+\dots+t(P_k)C(Pk​)=t(P1​)+⋯+t(Pk​). The makespan is Cmax⁡(S)=C(Pm)C_{\max}(S)=C(P_m)Cmax​(S)=C(Pm​), and the maximum tardiness is

Tmax⁡(S)=max⁡kmax⁡i∈Pkmax⁡{0, C(Pk)−di}.T_{\max}(S)=\max_k\max_{i\in P_k}\max\{0,\,C(P_k)-d_i\}.Tmax​(S)=kmax​i∈Pk​max​max{0,C(Pk​)−di​}.

A schedule is feasible when Tmax⁡(S)=0T_{\max}(S)=0Tmax​(S)=0, that is, when every job meets its due date.

A sequence is in batch-EDD order (Definition 1) if no job in an earlier batch has a strictly later due date than a job in a later batch. Processing times and due dates are agreeable if pi<pjp_i<p_jpi​<pj​ implies di≤djd_i\le d_jdi​≤dj​. A schedule is consecutive when every batch is a block {i,i+1,…,k}\{i,i+1,\dots,k\}{i,i+1,…,k} of indices and the blocks appear in increasing order.

Algorithm DP2 computes values f(0),…,f(n)∈N∪{∞}f(0),\dots,f(n)\in\mathbb N\cup\{\infty\}f(0),…,f(n)∈N∪{∞}:

f(0)=0,f(j)=min⁡max⁡{1, j−B+1}≤i≤jfi(j),fi(j)={f(i−1)+pj,f(i−1)+pj≤di,∞,otherwise.f(0)=0,\qquad f(j)=\min_{\max\{1,\,j-B+1\}\le i\le j} f_i(j),\qquad f_i(j)=\begin{cases}f(i-1)+p_j,& f(i-1)+p_j\le d_i,\\ \infty,&\text{otherwise.}\end{cases}f(0)=0,f(j)=max{1,j−B+1}≤i≤jmin​fi​(j),fi​(j)={f(i−1)+pj​,∞,​f(i−1)+pj​≤di​,otherwise.​

Formalization targets

Goal: correctness of DP2

Index the jobs so that d1≤⋯≤dnd_1\le\dots\le d_nd1​≤⋯≤dn​ and p1≤⋯≤pnp_1\le\dots\le p_np1​≤⋯≤pn​. Then for every 0≤j≤n0\le j\le n0≤j≤n,

f(j)=min⁡{ Cmax⁡(S):S a batch schedule of jobs 1,…,j, Tmax⁡(S)=0 },f(j)=\min\{\,C_{\max}(S) : S \text{ a batch schedule of jobs } 1,\dots,j,\ T_{\max}(S)=0\,\},f(j)=min{Cmax​(S):S a batch schedule of jobs 1,…,j, Tmax​(S)=0},

with min⁡∅=∞\min\emptyset=\inftymin∅=∞. The minimum ranges over all schedules: any batching, any order. This is the paper's reading of f(j)f(j)f(j) as "the minimum completion time of jobs 1,…,j1,\dots,j1,…,j if they can be scheduled feasibly, and infinity otherwise".

Milestones

  1. Lemma 3. With agreeable processing times and due dates, if a feasible schedule exists, then a feasible schedule in batch-EDD order exists.
  2. Consecutive partition (justification of DP2). Under the index order above, if jobs 1,…,j1,\dots,j1,…,j can be scheduled feasibly, then some feasible schedule of minimum makespan is consecutive.
  3. FBEDD. With equal processing times and due dates in index order, the Full-Batch EDD schedule {1,…,B},{B+1,…,2B},…\{1,\dots,B\},\{B+1,\dots,2B\},\dots{1,…,B},{B+1,…,2B},… has Tmax⁡T_{\max}Tmax​ no larger than that of any batch schedule.

Significance

DP2 is the paper's feasibility test for 1/B/Tmax⁡1/B/T_{\max}1/B/Tmax​ with agreeable data. With a bisection over the common shift of the due dates, it yields a polynomial algorithm for minimizing Tmax⁡T_{\max}Tmax​. A correct statement of what DP2 computes is therefore the core of that result. The same consecutive-partition structure underlies the paper's DP1 (release times, equal processing times) and DP3 (number of tardy jobs), which are separate missions of this series.

No machine-checked proof of any of these statements is known. The dynamic program's correctness is argued in the paper only by reference ("the justification of this algorithm is similar to that of algorithm DP1"), and the index order it needs is left implicit. A formal proof pins down exactly which ordering of the jobs makes the recursion correct.

Difficulty

The recursion charges pjp_jpj​ for the last batch {i,…,j}\{i,\dots,j\}{i,…,j} and checks only did_idi​. Both shortcuts rely on the jobs being sorted by due date and by processing time at the same time. Lemma 3's exchange argument sorts a feasible schedule by due date, but it does not by itself produce consecutive blocks of a fixed index order. With ties in due dates the indexing also has to be compatible with processing times. Without that, the recursion is wrong: for B=2B=2B=2, p=(3,1)p=(3,1)p=(3,1), d=(5,5)d=(5,5)d=(5,5) it gives f(2)=1f(2)=1f(2)=1, while every schedule takes at least 333. The goal compares the DP with the optimum over all schedules, so the exchange arguments have to bridge arbitrary batchings and the consecutive ones the recursion enumerates. That bridge is the main step left to prove.

Formalization scope

  • Jobs are Fin n (job iii of the paper is index i−1i-1i−1); jobs 1,…,j1,\dots,j1,…,j are jobsUpTo n j. Data are natural numbers; the paper assumes integral data (p. 769).
  • A schedule is a List (Finset (Fin n)); validity requires nonempty batches of size at most BBB inside the job set, pairwise disjoint, covering the set. Batches start as early as possible. Batch time is the maximum processing time in the batch.
  • ∞\infty∞ is ⊤ : ℕ∞, and the goal's minimum is the infimum in ℕ∞, which is ⊤ exactly when no feasible schedule exists. DP2 is defined by the printed recursion, not as an optimum.
  • Explicit readings of loose phrases:
    • "jobs are indexed in increasing order of due dates" (p. 767) becomes Monotone d ∧ Monotone p for DP2 and its justification, and Monotone d for FBEDD;
    • "agreeable" (printed "pi≤pjp_i\le p_jpi​≤pj​ implies di≤djd_i\le d_jdi​≤dj​", which would force equal due dates for equal processing times) becomes the strict form pi<pj⇒di≤djp_i<p_j\Rightarrow d_i\le d_jpi​<pj​⇒di​≤dj​, a weaker hypothesis;
    • "optimally solves" for FBEDD becomes "valid, and Tmax⁡T_{\max}Tmax​ at most that of every valid schedule";
    • "a consecutive partition problem" becomes the existence of a consecutive minimum-makespan feasible schedule.
  • Not formalized: the O(nB)O(nB)O(nB) and O[nBlog⁡2(npmax⁡)]O[nB\log_2(np_{\max})]O[nBlog2​(npmax​)] running times, the bisection procedure, and the remark that npmax⁡np_{\max}npmax​ bounds Tmax⁡T_{\max}Tmax​.
  • Trivializations ruled out: the goal's minimum ranges over all valid schedules, not only batch-EDD or consecutive ones (which would assume the milestones), and DP2 is the printed recursion, not a restatement of the optimum.
  • Infrastructure needed: list-indexed schedules, exchange arguments on adjacent batches, and induction on prefix length for the recursion. The single-machine batch model is shared in spirit with missions 1 and 3 of this series. No published platform definition was reused, since nothing on batch machines exists yet.

Selected references

  • C.-Y. Lee, R. Uzsoy, L. A. Martin-Vega, Efficient Algorithms for Scheduling Semiconductor Burn-In Operations, Operations Research 40(4), 764–775, 1992. https://doi.org/10.1287/opre.40.4.764
  • Y. Ikura, M. Gimple, Efficient scheduling algorithms for a single batch processing machine, Operations Research Letters 5(2), 61–65, 1986. https://doi.org/10.1016/0167-6377(86)90104-5
  • C. N. Potts, M. Y. Kovalyov, Scheduling with batching: A review, European Journal of Operational Research 120(2), 228–249, 2000. https://doi.org/10.1016/S0377-2217(99)00153-8
7 thms1 active userReviewed
Dynamic ProgrammingLinear OptimizationMarkov Chain·Captain: mikedeng1

Linear Programming and Sequential Decisions: An Optimal Solution of the Equilibrium LP Yields a Stationary Decision Rule of Least Expected Monthly CostResearch Paper

Motivation

Alan S. Manne's Linear Programming and Sequential Decisions (Management Science 6(3), 1960, pp. 259–267) is the first formulation of an infinite-horizon, average-cost sequential decision problem as a linear program. The illustration is a single-item inventory problem, but the construction, with unknowns indexed by a state and a decision and constraints expressing statistical equilibrium, became the standard state–action frequency linear program of Markov decision processes. Later LP approaches to average-cost Markov decision processes, including constrained ones, build on it.

Timeline of the LP approach to average-cost problems:

  • 1960 — Manne: the inventory model as a linear program in the joint probabilities of (stock level, production quantity); mixed strategies allowed; the decision rule is read off as a conditional probability.
  • 1960 — H. M. Wagner, in a companion note in the same issue, shows that an optimal solution consisting of pure strategies exists.
  • 1962 — C. Derman (Management Science 9(1), 1962) gives the general finite-state, finite-action version, assuming every stationary randomized rule yields an irreducible chain.
  • 1960 — F. d'Epenoux (Revue Française de Recherche Opérationnelle 4, No. 14; English translation 1963) treats the discounted criterion by linear programming, as Manne's closing note records.

Setting

A positive integer TTT bounds inventory accumulation; the stock levels are 0,1,…,T0,1,\dots,T0,1,…,T. At the start of a month the initial stock iii is observed and a production quantity jjj is chosen; the available stock is k=i+jk=i+jk=i+j. The month's demand n∈{0,1,2,… }n\in\{0,1,2,\dots\}n∈{0,1,2,…} is independent of everything else and has law pnp_npn​. Backlogs are excluded, so the terminal stock is t=max⁡(0,k−n)t=\max(0,k-n)t=max(0,k−n), which becomes the next initial stock. A finite set AAA of admissible pairs (i,j)(i,j)(i,j), all with i+j≤Ti+j\le Ti+j≤T and containing (i,0)(i,0)(i,0) for every i≤Ti\le Ti≤T, lists the decisions available at each stock level. Costs are three arbitrary real functions: C1(i)C_1(i)C1​(i) of the initial stock, C2(j)C_2(j)C2​(j) of the production quantity, and C3(n−k)C_3(n-k)C3​(n−k) of the shortage level.

A stationary randomized decision rule q(j∣i)q(j\mid i)q(j∣i) is a conditional probability of producing jjj at stock iii, supported on admissible pairs. It makes the initial stock a Markov chain. A statistical equilibrium of qqq is a stationary distribution y=(y0,…,yT)y=(y_0,\dots,y_T)y=(y0​,…,yT​) of that chain: the law y′y'y′ of the terminal stock equals the law yyy of the initial stock, (2). The expected monthly cost (1) of qqq in the equilibrium yyy is

EC1(i)+EC2(j)+EC3(n−k),\mathcal EC_1(i)+\mathcal EC_2(j)+\mathcal EC_3(n-k),EC1​(i)+EC2​(j)+EC3​(n−k),

the expectation taken under the joint law yi q(j∣i) pny_i\,q(j\mid i)\,p_nyi​q(j∣i)pn​ of (initial stock, production, demand).

The linear program has one unknown xijx_{ij}xij​ per admissible pair, the joint probability of (initial stock iii, production jjj). Its constraints are xij≥0x_{ij}\ge0xij​≥0, (4) ∑i,jxij=1\sum_{i,j}x_{ij}=1∑i,j​xij​=1, and the equilibrium equations

(8.t)∑jxtj=∑i,j,n:i+j−n=tpnxij(t=1,…,T),\text{(8.t)}\qquad \sum_j x_{tj}=\sum_{\substack{i,j,n:\\ i+j-n=t}}p_nx_{ij}\qquad(t=1,\dots,T),(8.t)j∑​xtj​=i,j,n:i+j−n=t​∑​pn​xij​(t=1,…,T),

and its objective (9) is ∑i,jcijxij\sum_{i,j}c_{ij}x_{ij}∑i,j​cij​xij​ with the cost coefficients (10)

cij=C1(i)+C2(j)+∑npnC3(n−i−j).c_{ij}=C_1(i)+C_2(j)+\sum_np_nC_3(n-i-j).cij​=C1​(i)+C2​(j)+n∑​pn​C3​(n−i−j).

The companion equation (8.0) for t=0t=0t=0 has right-hand side ∑i+j−n≤0pnxij\sum_{i+j-n\le0}p_nx_{ij}∑i+j−n≤0​pn​xij​ and is omitted from the constraints. A feasible xxx is decoded into yi=∑jxijy_i=\sum_jx_{ij}yi​=∑j​xij​ and q(j∣i)=xij/yiq(j\mid i)=x_{ij}/y_iq(j∣i)=xij​/yi​.

Formalization targets

The paper labels no theorem or lemma. The goal is assembled from §1 (third paragraph), §3 (N.B.), §4 (last two paragraphs), §5 and §7 (3), and every milestone is cited by section, display, table or footnote.

Goal: an LP optimum gives an optimal stationary rule

Assume ∑npn∣C3(n−i−j)∣<∞\sum_np_n|C_3(n-i-j)|<\infty∑n​pn​∣C3​(n−i−j)∣<∞ for every admissible pair. Then the linear program has an optimal solution, and for every optimal solution x∗x^*x∗, with decoding (q∗,y∗)(q^*,y^*)(q∗,y∗), q∗q^*q∗ is a stationary randomized rule, y∗y^*y∗ is a statistical equilibrium of q∗q^*q∗, and

Cost(q∗,y∗)=∑i,jcijxij∗≤Cost(q,y)\mathrm{Cost}(q^*,y^*)=\sum_{i,j}c_{ij}x^*_{ij}\le \mathrm{Cost}(q,y)Cost(q∗,y∗)=i,j∑​cij​xij∗​≤Cost(q,y)

for every stationary randomized rule qqq and every statistical equilibrium yyy of qqq.

Milestones

  1. (7): under a rule in a distribution yyy, the law of the terminal stock is the right-hand side of (7)/(8) evaluated at xij=yiq(j∣i)x_{ij}=y_iq(j\mid i)xij​=yi​q(j∣i).
  2. (8.0)–(8.T): a rule in statistical equilibrium yields a point satisfying x≥0x\ge0x≥0, (4) and all of (8.0)–(8.T).
  3. (8.0) is redundant: (4) and (8.1)–(8.T) imply (8.0).
  4. §3, N.B.: every feasible xxx equals yiq(j∣i)y_iq(j\mid i)yi​q(j∣i) for its decoding (q,y)(q,y)(q,y), with yyy an equilibrium of qqq.
  5. (10): the expected monthly cost (1) under the joint law xijpnx_{ij}p_nxij​pn​ equals ∑cijxij\sum c_{ij}x_{ij}∑cij​xij​.
  6. Table 1: the cost coefficients of the §6 example (T=3T=3T=3, p=(2/3,0,1/3)p=(2/3,0,1/3)p=(2/3,0,1/3), C1(i)=iC_1(i)=iC1​(i)=i, C2(j)=3jC_2(j)=3jC2​(j)=3j, C3(m)=max⁡[0,6m]C_3(m)=\max[0,6m]C3​(m)=max[0,6m], j∈{0,1}j\in\{0,1\}j∈{0,1}) are 4,5,3,4,2,5,34,5,3,4,2,5,34,5,3,4,2,5,3.
  7. Table 2, footnote 3: x01=1/3x_{01}=1/3x01​=1/3, x11=2/9x_{11}=2/9x11​=2/9, x20=4/9x_{20}=4/9x20​=4/9 is optimal with cost 31/931/931/9; the do-nothing solution costs 444.
  8. Footnote 5: the implicit prices −7/3,−13/3,−11/3-7/3,-13/3,-11/3−7/3,−13/3,−11/3 of (8.1)–(8.3), with 31/931/931/9 on (4), are an optimal dual solution.

Significance

The result turns an infinite-horizon control problem into a finite linear program. Equilibrium joint laws of (state, decision) under stationary randomized rules are exactly the feasible points of a polytope, and the average cost is linear on it. Consequences include computability by the simplex method; an economic reading of the dual variables (Manne's footnote 5 interprets them as the relative advantage of starting at a given stock level, related to Bellman's functional equation); and, in later work, the treatment of side constraints, which dynamic programming handles poorly.

The result is classical and proved in the paper (largely by inspection of the definitions). It has not been formalized. The formalization adds three things. First, a precise statement of what is optimized when the chain of a rule is not irreducible: the paper's §7 (3) concedes that a "decomposable" optimum makes the equilibrium depend on initial conditions, and the goal resolves this by optimizing over (rule, equilibrium) pairs. Second, an explicit treatment of the stock levels the equilibrium never visits, where the paper's quotient xij/∑jxijx_{ij}/\sum_jx_{ij}xij​/∑j​xij​ is undefined. Third, a machine-checked numerical example whose LP is derived from the general definitions, not entered by hand. Derman's later irreducible-case version exists on the platform as a separate open statement; this mission covers Manne's irreducibility-free version on state-dependent action sets.

Difficulty

Each step is elementary; the work is bookkeeping across three descriptions of the same object. The equilibrium is defined through the transition kernel of the controlled chain, the LP through the displayed sums over (i,j,n)(i,j,n)(i,j,n) with conditions i+j−n≤0i+j-n\le0i+j−n≤0 and i+j−n=ti+j-n=ti+j−n=t, and the cost through the joint law of three variables. Identifying them needs a reindexing of the admissible pairs by stock level, the interchange of a finite sum with an infinite sum over demands, and ∑npn=1\sum_np_n=1∑n​pn​=1. The naive argument "the LP constraints are the equilibrium equations, so the LP optimum is the optimal rule" skips two points. The constraints omit (8.0), so equilibrium at stock level 000 must be recovered from (4) and the bound i+j≤Ti+j\le Ti+j≤T. And the decoding fails at unvisited stock levels unless a default action is supplied. Existence of an LP optimum requires compactness of the feasible polytope, not just its nonemptiness.

Formalization scope

All statements live in the namespace ManneLP.Equilibrium. Conventions:

  • Stock levels and production quantities are natural numbers; a model carries T>0T>0T>0, the admissible set AAA (a Finset (ℕ × ℕ) with i+j≤Ti+j\le Ti+j≤T and every (i,0)∈A(i,0)\in A(i,0)∈A), a demand law p:N→Rp:\mathbb N\to\mathbb Rp:N→R with pn≥0p_n\ge0pn​≥0 and HasSum p 1, and costs C1,C2:N→RC_1,C_2:\mathbb N\to\mathbb RC1​,C2​:N→R, C3:Z→RC_3:\mathbb Z\to\mathbb RC3​:Z→R. The shortage level n−i−jn-i-jn−i−j is an integer; no convexity, sign or monotonicity of the costs is assumed.
  • The admissible set is a parameter: §6 imposes a capacity limit j≤1j\le1j≤1. Reading of the page: i+j≤Ti+j\le Ti+j≤T is how §2's requirement max⁡(0,k−n)≤T\max(0,k-n)\le Tmax(0,k−n)≤T holds whatever the demand; (i,0)∈A(i,0)\in A(i,0)∈A (producing nothing is possible) is implicit in §2.
  • The terminal stock is computed by truncated subtraction in N\mathbb NN, which equals max⁡(0,k−n)\max(0,k-n)max(0,k−n). Sums over demands are tsums; the demand is not assumed bounded. The goal and the cost identity assume the expected shortage cost at each admissible pair is finite (absolutely summable), which the page takes for granted.
  • A statistical equilibrium is a stationary distribution of the chain of the rule, defined from the transition probabilities, not from (8). The expected monthly cost is defined from the joint law of (stock, production, demand), not as ∑cijxij\sum c_{ij}x_{ij}∑cij​xij​. The LP constraint set omits (8.0), exactly as the page does.
  • The decoded rule uses the default action j=0j=0j=0 at stock levels with ∑jxij=0\sum_jx_{ij}=0∑j​xij​=0; any admissible default would do.
  • Table 2's x30=εx_{30}=\varepsilonx30​=ε is the paper's device against degeneracy; the example's solution has x30=0x_{30}=0x30​=0. Footnote 5 prints no price for (4); 31/931/931/9 is the price forced by equal objectives, and the dual optimum is not claimed unique.

Trivializing formalizations are ruled out: equilibrium is not defined as (8) (which would make milestone 2 vacuous), (8.0) is not a constraint (which would make milestone 3 vacuous), the cost is not defined as ∑cijxij\sum c_{ij}x_{ij}∑cij​xij​ (which would make milestone 5 and the goal's cost clause definitional), and the optimality comparison ranges over all rules and all of their equilibria, not over irreducible chains or pure rules.

Contributions welcome: proofs of the milestones and the goal; computations of the §6 example from the general definitions; reusable lemmas on stationary distributions of finite stochastic matrices and on the existence of LP optima over compact polytopes.

Selected references

  • A. S. Manne, Linear Programming and Sequential Decisions, Management Science 6(3), 259–267, 1960. https://doi.org/10.1287/mnsc.6.3.259
  • H. M. Wagner, On the Optimality of Pure Strategies, Management Science 6(3), 268–269, 1960. https://doi.org/10.1287/mnsc.6.3.268
  • C. Derman, On Sequential Decisions and Markov Chains, Management Science 9(1), 16–24, 1962. https://doi.org/10.1287/mnsc.9.1.16
  • F. d'Epenoux, A Probabilistic Production and Inventory Problem, Management Science 10(1), 98–108, 1963 (translation of the 1960 French paper). https://doi.org/10.1287/mnsc.10.1.98
13 thms1 active userReviewed
OptimizationProbabilityStatistics·Captain: mikedeng1

Asymptotic Theory for Solutions in Statistical Estimation and Stochastic Programming: Generalized M-Estimates Converge in Distribution to the Inverse Contingent Derivative at a GaussianResearch Paper

Motivation

Maximum likelihood estimates, least-squares fits and sample-average approximations of stochastic programs solve 0=fˉν(x)0 = \bar f^\nu(x)0=fˉ​ν(x), where fˉν\bar f^\nufˉ​ν averages a random integrand over ν\nuν observations. Their classical asymptotic theory rests on the implicit function theorem and needs a smooth, unconstrained problem.

When the estimate is constrained to a set, for example a nonnegativity constraint, a simplex or a polyhedron, the first-order conditions become a generalized equation

0∈f(z,x)+N(x),0 \in f(z, x) + N(x),0∈f(z,x)+N(x),

where NNN is a multifunction such as the normal cone of the constraint set. The same form describes optimality conditions of stochastic programs and variational inequalities. Aitchison and Silvey (1958) treated equality-constrained maximum likelihood. Huber (1967) allowed nonsmooth estimating functions but required an open parameter domain. Dupačová and Wets (1988) and Shapiro (1989) derived limit laws for solutions of stochastic programs under smoothness of the expected gradient. King and Rockafellar (1993) gave a general theory that needs neither smoothness of the expected map nor single-valuedness of NNN: the limit law of the normalized error is the image of a Gaussian under a contingent derivative, a positively homogeneous and generally nonlinear map, so the limit is generally not normal.

Setting

Let ZZZ be a separable Banach space with norm ∥⋅∥\|\cdot\|∥⋅∥, and let ∣⋅∣|\cdot|∣⋅∣ be the Euclidean norm on Rn\mathbb R^nRn and Rm\mathbb R^mRm. A multifunction G:Z⇉RnG : Z \rightrightarrows \mathbb R^nG:Z⇉Rn assigns a set G(z)⊆RnG(z) \subseteq \mathbb R^nG(z)⊆Rn to each zzz. Its graph is gph⁡G\operatorname{gph} GgphG and its inverse is G−1(x)={z∣x∈G(z)}G^{-1}(x) = \{z \mid x \in G(z)\}G−1(x)={z∣x∈G(z)}.

For sets AtA_tAt​ indexed by t↓0t \downarrow 0t↓0, the upper limit lim sup⁡At\limsup A_tlimsupAt​ consists of the points xxx with x=lim⁡xkx = \lim x_kx=limxk​, xk∈Atkx_k \in A_{t_k}xk​∈Atk​​ for some tk↓0t_k \downarrow 0tk​↓0, and the lower limit of the points reachable along every such sequence. The contingent derivative of GGG at (z,x)∈gph⁡G(z, x) \in \operatorname{gph} G(z,x)∈gphG is the multifunction DG(z∣x)DG(z|x)DG(z∣x) with

gph⁡DG(z∣x)=lim sup⁡t↓0t−1[gph⁡G−(z,x)].\operatorname{gph} DG(z|x) = \limsup_{t \downarrow 0} t^{-1}\big[\operatorname{gph} G - (z,x)\big].gphDG(z∣x)=t↓0limsup​t−1[gphG−(z,x)].

GGG is proto-differentiable when this upper limit equals the lower limit, and semi-differentiable when t−1[G(z+tw′)−x]→DG(z∣x)(w)t^{-1}[G(z + t w') - x] \to DG(z|x)(w)t−1[G(z+tw′)−x]→DG(z∣x)(w) as t↓0t \downarrow 0t↓0 and w′→ww' \to ww′→w. A single-valued ggg is B-differentiable at zzz when t−1[g(z+tw′)−g(z)]→Dg(z)(w)t^{-1}[g(z + tw') - g(z)] \to Dg(z)(w)t−1[g(z+tw′)−g(z)]→Dg(z)(w) in the same sense.

The deterministic problem is 0∈f(z,x)+N(x)0 \in f(z, x) + N(x)0∈f(z,x)+N(x) with f:Z×Rn→Rmf : Z \times \mathbb R^n \to \mathbb R^mf:Z×Rn→Rm, data zzz and solution map J(z)J(z)J(z). At a reference pair (z∗,x∗)(z^*, x^*)(z∗,x∗) set F=f(z∗,⋅)+NF = f(z^*, \cdot) + NF=f(z∗,⋅)+N. The analytical assumptions M.1–M.4 are as follows. fff is jointly continuous and B-differentiable in each variable, with the zzz-derivative Dzf(z∗,x∗)D_z f(z^*, x^*)Dz​f(z∗,x∗) strong (uniform in xxx near x∗x^*x∗). NNN is closed and proto-differentiable. FFF is subinvertible: 0∈F(x∗)0 \in F(x^*)0∈F(x∗), and a closed-graph, convex-valued selection of F−1F^{-1}F−1 near 000 passes through x∗x^*x∗. The contingent derivative DF−1(0∣x∗)DF^{-1}(0|x^*)DF−1(0∣x∗) is at most single-valued.

The statistical problem has i.i.d. random elements s1,s2,…s_1, s_2, \dotss1​,s2​,… of a measurable space SSS and an integrand f:U×S→Rmf : U \times S \to \mathbb R^mf:U×S→Rm on a compact neighborhood UUU of x∗x^*x∗. It satisfies the probabilistic assumptions P.1–P.4: continuity in xxx, measurability in sss, a finite second moment at one point, and a Lipschitz bound ∣f(x1,s)−f(x2,s)∣≤a(s)∣x1−x2∣|f(x_1,s) - f(x_2,s)| \le a(s)|x_1 - x_2|∣f(x1​,s)−f(x2​,s)∣≤a(s)∣x1​−x2​∣ with Ea(s1)2<∞E a(s_1)^2 < \inftyEa(s1​)2<∞. The M-estimate xνx^\nuxν is a measurable solution of

0∈fˉν(x)+N(x),fˉν(x)=1ν∑i=1νf(x,si),0 \in \bar f^\nu(x) + N(x), \qquad \bar f^\nu(x) = \frac1\nu\sum_{i=1}^\nu f(x, s_i),0∈fˉ​ν(x)+N(x),fˉ​ν(x)=ν1​i=1∑ν​f(x,si​),

and the true equation is 0∈Ef(x)+N(x)0 \in Ef(x) + N(x)0∈Ef(x)+N(x) with F=Ef+NF = Ef + NF=Ef+N.

Formalization targets

Goal: Theorem 2.7 (asymptotic distribution of M-estimates)

Under P.1–P.4 on a compact neighborhood UUU of x∗x^*x∗, B-differentiability of EfEfEf at x∗x^*x∗, and M.2–M.4 for F=Ef+NF = Ef + NF=Ef+N, every sequence of measurable solutions xνx^\nuxν of (2.5) with xν→x∗x^\nu \to x^*xν→x∗ almost surely satisfies

ν [xν−x∗]→ D DF−1(0∣x∗)(−w∗),w∗∼N(0,cov⁡f(x∗,s1)).\sqrt\nu\,[x^\nu - x^*] \xrightarrow{\ \mathcal D\ } DF^{-1}(0|x^*)(-w^*), \qquad w^* \sim \mathcal N\big(0, \operatorname{cov} f(x^*, s_1)\big).ν​[xν−x∗] D ​DF−1(0∣x∗)(−w∗),w∗∼N(0,covf(x∗,s1​)).

The goal fixes the limit law completely: the map is the contingent derivative of F−1F^{-1}F−1, and the Gaussian has the covariance of the integrand at x∗x^*x∗.

Milestones

  • Theorem 2.4 gives bounds in probability, P{∣xν−x∗∣>δ}≤P{αλ∥zν−z∗∥>δ}P\{|x^\nu - x^*| > \delta\} \le P\{\alpha\lambda\|z^\nu - z^*\| > \delta\}P{∣xν−x∗∣>δ}≤P{αλ∥zν−z∗∥>δ}. Its proof uses the upper-Lipschitz property U∩F−1(y)⊆x∗+λ∣y∣BU \cap F^{-1}(y) \subseteq x^* + \lambda|y|BU∩F−1(y)⊆x∗+λ∣y∣B (a display of the proof).
  • Theorem 2.6 is the abstract limit theorem: if τν−1[zν−z∗]→Dw\tau_\nu^{-1}[z^\nu - z^*] \to_{\mathcal D} wτν−1​[zν−z∗]→D​w, then τν−1[xν−x∗]→DDF−1(0∣x∗)(−Dzf(z∗,x∗)(w))\tau_\nu^{-1}[x^\nu - x^*] \to_{\mathcal D} DF^{-1}(0|x^*)(-D_z f(z^*,x^*)(w))τν−1​[xν−x∗]→D​DF−1(0∣x∗)(−Dz​f(z∗,x∗)(w)). Its proof uses two displays: semi-differentiability of the localized solution map, with DJ(z∗∣x∗)(w)=DF−1(0∣x∗)(−Dzf(z∗,x∗)(w))DJ(z^*|x^*)(w) = DF^{-1}(0|x^*)(-D_z f(z^*,x^*)(w))DJ(z∗∣x∗)(w)=DF−1(0∣x∗)(−Dz​f(z∗,x∗)(w)), and a Lipschitz bound ∣x−x∗∣≤λ∥z−z∗∥|x - x^*| \le \lambda\|z - z^*\|∣x−x∗∣≤λ∥z−z∗∥ on U∩J(z)U \cap J(z)U∩J(z).
  • Proposition A1, Corollary A2 and Theorem A3 concern the space Cm(U)C_m(U)Cm​(U) under P.1–P.4. The integrand and the empirical means are random elements of Cm(U)C_m(U)Cm​(U), and ν(fˉν−Ef)\sqrt\nu(\bar f^\nu - Ef)ν​(fˉ​ν−Ef) converges in distribution to a Gaussian element of Cm(U)C_m(U)Cm​(U).

The three displays (Theorem 2.4's upper-Lipschitz inclusion, and Theorem 2.6's semi-differentiability and Lipschitz bound) are statements the paper cites from King and Rockafellar, Sensitivity analysis for nonsmooth generalized equations ([12]: Proposition 2.1, Theorem 4.1, Remark 4.3). They are cited results, not this paper's own, and are milestones because the proofs of Theorems 2.4 and 2.6 rest on them.

Significance

Theorem 2.7 gives the limit law of constrained and nonsmooth M-estimates in a form that can be computed. When NNN is the normal cone of a polyhedron, DF−1(0∣x∗)DF^{-1}(0|x^*)DF−1(0∣x∗) is piecewise linear, and the limit is the solution of a random linear complementarity or quadratic problem driven by a Gaussian vector. This underlies the asymptotic theory of sample-average approximation in stochastic programming, where the paper applies it to stochastic programs (§3) and to piecewise linear-quadratic tracking problems (§4). Theorem 2.6 separates the deterministic sensitivity analysis from the probability, so any data sequence with a known limit law yields a limit law for the solutions.

The result is proved in the paper modulo the cited theorems of [12] and [11], but none of it is machine-checked. Mathlib has the real-valued i.i.d. central limit theorem, Gaussian measures on Banach spaces and convergence in distribution. It has no multivariate or Banach-space central limit theorem, no contingent derivatives and no set-valued implicit function theorem. Formalizing the mission produces these, along with a checked version of the cited sensitivity results.

Difficulty

The classical argument linearizes FFF at x∗x^*x∗, inverts the Jacobian and applies the delta method. Here FFF is set-valued and its derivative is only positively homogeneous. There is no Jacobian to invert, and the solution map need not be differentiable or even single-valued away from x∗x^*x∗. The replacement for the implicit function theorem is the semi-differentiability of the localized solution map under M.1–M.4. Proving it means controlling both the upper and the lower set limits of difference quotients of solution sets, and subinvertibility is what supplies existence of nearby solutions.

The probabilistic side cannot work coordinate by coordinate either. The estimate solves an equation in the whole function fˉν\bar f^\nufˉ​ν, so convergence of fˉν\bar f^\nufˉ​ν at finitely many points is not enough. The central limit theorem must hold in the sup norm on Cm(U)C_m(U)Cm​(U), which requires tightness of the empirical process, and only then can the deterministic sensitivity result be composed with it.

Formalization scope

Points live in EuclideanSpace ℝ (Fin n), and ZZZ is a real normed space with [CompleteSpace Z] [SeparableSpace Z] where the paper says "separable Banach". Set limits are Kuratowski limits along filters (t↓0t \downarrow 0t↓0 is 𝓝[>] 0, and (t,w′)→(0+,w)(t,w') \to (0^+,w)(t,w′)→(0+,w) is the product filter). The contingent derivative is defined by (2.2) alone. M.4's printed sum formula equals it under M.1, and this is not assumed. "B-differentiable" is read as the limit (2.4). Products carry Lean's max norm. s1s_1s1​ is s 0, empirical means sum over Finset.range ν, and (2.5) is required for ν≥1\nu \ge 1ν≥1. F=Ef+NF = Ef + NF=Ef+N is empty off UUU. Convergence in distribution is Mathlib's TendstoInDistribution, with the limit on its own probability space. The law of w∗w^*w∗ is fixed through linear functionals: ⟨ℓ,w∗⟩∼N(0,Var⁡⟨ℓ,f(x∗,s1)⟩)\langle\ell, w^*\rangle \sim \mathcal N(0, \operatorname{Var}\langle\ell, f(x^*,s_1)\rangle)⟨ℓ,w∗⟩∼N(0,Var⟨ℓ,f(x∗,s1​)⟩). In Appendix A1–A3 the integrand is S → C(↥U, Rn m) with the Borel σ-algebra, and "Gaussian" is IsGaussian.

Explicit choices relative to the printed text:

  1. The paper states that an almost surely convergent sequence of solutions "converges to the point x∗x^*x∗" (Theorems 2.6 and 2.7). This is false when the true equation has a second solution: f(z,x)=x2−x−zf(z,x) = x^2 - x - zf(z,x)=x2−x−z, N≡{0}N \equiv \{0\}N≡{0}, z∗=x∗=0z^* = x^* = 0z∗=x∗=0 satisfies M.1–M.4 with J(0)={0,1}J(0) = \{0, 1\}J(0)={0,1}. The formalization assumes xν→x∗x^\nu \to x^*xν→x∗ almost surely instead.
  2. 0∈F(x∗)0 \in F(x^*)0∈F(x∗) (presupposed by DF−1(0∣x∗)DF^{-1}(0|x^*)DF−1(0∣x∗)) is explicit in Theorem 2.4 and the upper-Lipschitz display.
  3. The threshold for "all sufficiently small δ\deltaδ" in Theorem 2.4 is chosen with UUU and λ\lambdaλ, before the random elements.
  4. Proposition A1 and Corollary A2 carry P.1–P.4, as stated or inherited on the Appendix page, though their measurability conclusions use only P.1.
  5. In the limit theorems, the single-valued map DF−1(0∣x∗)DF^{-1}(0|x^*)DF−1(0∣x∗) is a function LLL whose values lie in the contingent derivative at every point.

The conclusion of the goal names its limit: the image of the stated Gaussian under a map LLL whose values lie in the contingent derivative of F−1F^{-1}F−1. A statement asserting only that ν(xν−x∗)\sqrt\nu(x^\nu - x^*)ν​(xν−x∗) converges in distribution to some limit, or replacing DF−1(0∣x∗)DF^{-1}(0|x^*)DF−1(0∣x∗) by a linear map, is a different and weaker theorem. A sorry-free check confirms that the goal's hypotheses can all be met (a degenerate instance with f(x,s)=xf(x,s) = xf(x,s)=x, N≡{0}N \equiv \{0\}N≡{0}).

A complete development needs Kuratowski set convergence and contingent derivatives (reusable across set-valued analysis), a central limit theorem in C(K)C(K)C(K) for Lipschitz-indexed processes (reusable for empirical-process theory), and a continuous-mapping argument for random closed sets. Contributions to any of these layers are welcome, as are proofs of the cited [12] statements.

Selected references

  • A. J. King and R. T. Rockafellar, Asymptotic theory for solutions in statistical estimation and stochastic programming, Mathematics of Operations Research 18(1) (1993). https://doi.org/10.1287/moor.18.1.148
  • A. J. King and R. T. Rockafellar, Sensitivity analysis for nonsmooth generalized equations, Mathematical Programming 55 (1992) 193–212. https://doi.org/10.1007/BF01581199
  • A. J. King, Generalized delta theorems for multivalued mappings and measurable selections, Mathematics of Operations Research 14(4) (1989) 720–736. https://doi.org/10.1287/moor.14.4.720
  • J. Dupačová and R. J.-B. Wets, Asymptotic behavior of statistical estimators and of optimal solutions of stochastic optimization problems, Annals of Statistics 16(4) (1988) 1517–1549. https://doi.org/10.1214/aos/1176351052
  • A. Shapiro, Asymptotic properties of statistical estimators in stochastic programming, Annals of Statistics 17(2) (1989) 841–858. https://doi.org/10.1214/aos/1176347146
  • P. J. Huber, The behavior of maximum likelihood estimates under nonstandard conditions, Proc. Fifth Berkeley Symp. Math. Statist. Probab. 1 (1967) 221–233. https://projecteuclid.org/euclid.bsmsp/1200512988
  • A. Araujo and E. Giné, The Central Limit Theorem for Real and Banach Valued Random Variables, Wiley, 1980.
10 thms1 active userReviewed
Dynamic ProgrammingMarkov ChainProbability·Captain: mikedeng1

Some Monotonicity Results for Partially Observed Markov Decision Processes: MLR-Monotone Optimal Values and the Myopic Policy as a Lower Bound on the Optimal PolicyResearch Paper

Motivation

A partially observed Markov decision process (POMDP) models a controller that cannot see the state of the system it controls. It sees only noisy observations, and so it acts on a belief: a probability vector over the hidden states. Machine maintenance, medical screening, quality control and search problems all have this form. The dynamic program of a POMDP lives on the simplex of beliefs, a continuum, so computing exact optimal policies is expensive even when the state, action and observation sets are small. Structural results reduce that cost. A value function that is monotone in the belief, or a policy known to dominate a cheap reference policy, shrinks the space a computation must search. Such results also explain the model: they say when one belief is "better" than another.

W. S. Lovejoy, Some Monotonicity Results for Partially Observed Markov Decision Processes (Operations Research 35(5):736–743, 1987), provides such results by ordering beliefs with the monotone likelihood ratio (MLR) order instead of first-order stochastic dominance.

Timeline. Smallwood and Sondik (1973) set out the finite POMDP and its piecewise-linear value functions. White (1979, 1980) obtained monotone policies and values for machine replacement, for single-stage problems, and for the completely observed and completely unobserved extremes, all under first-order stochastic dominance. Albright (1979) treated the two-state case, where the usual orders coincide. Whitt (1979, 1982) developed the likelihood-ratio orders and showed that they are preserved by Bayesian updating. Lovejoy (1987) combined these into general monotonicity results for finite POMDPs, and the MLR order has since become the standard tool for structural results in POMDPs.

Setting

Let S={1,…,n}S=\{1,\dots,n\}S={1,…,n} (states) and O={1,…,m}O=\{1,\dots,m\}O={1,…,m} (observations) carry their natural orders, and let AAA be a finite, completely ordered action set. For a finite chain XXX, Π(X)\Pi(X)Π(X) is the set of probability vectors on XXX. For π,π′∈Π(X)\pi,\pi'\in\Pi(X)π,π′∈Π(X), π≥sπ′\pi\ge_s\pi'π≥s​π′ (first-order stochastic dominance) means ∑i≥qπi≥∑i≥qπi′\sum_{i\ge q}\pi_i\ge\sum_{i\ge q}\pi'_i∑i≥q​πi​≥∑i≥q​πi′​ for every qqq. π≥rπ′\pi\ge_r\pi'π≥r​π′ (MLR order) means πiπi′′≥πi′πi′\pi_i\pi'_{i'}\ge\pi_{i'}\pi'_iπi​πi′′​≥πi′​πi′​ whenever i≥i′i\ge i'i≥i′. For matrices f,gf,gf,g on X×YX\times YX×Y, f≥tpgf\ge_{tp}gf≥tp​g means f(x∨x′,y∨y′) g(x∧x′,y∧y′)≥f(x,y) g(x′,y′)f(x\vee x',y\vee y')\,g(x\wedge x',y\wedge y')\ge f(x,y)\,g(x',y')f(x∨x′,y∨y′)g(x∧x′,y∧y′)≥f(x,y)g(x′,y′) for all pairs, and fff is TP₂ if f≥tpff\ge_{tp}ff≥tp​f.

In each period the decision maker in state st=is_t=ist​=i chooses a∈Aa\in Aa∈A and receives the reward g(i,a)g(i,a)g(i,a). The state moves to jjj with probability pijap^a_{ij}pija​ (matrix PaP^aPa), and an observation kkk arrives with probability rjkar^a_{jk}rjka​ (matrix RaR^aRa, with row ra(j)∈Π(O)r^a(j)\in\Pi(O)ra(j)∈Π(O)), generated by the new state jjj and the action aaa. The paper assumes rjka>0r^a_{jk}>0rjka​>0 throughout. The discount factor is β≥0\beta\ge 0β≥0. From a belief π\piπ, the observation kkk has probability σ(k;π,a)=∑i,jπipijarjka\sigma(k;\pi,a)=\sum_{i,j}\pi_i p^a_{ij}r^a_{jk}σ(k;π,a)=∑i,j​πi​pija​rjka​, and the posterior is the Bayes update Tj(π,a,k)=∑iπipijarjka/σ(k;π,a)T_j(\pi,a,k)=\sum_i\pi_ip^a_{ij}r^a_{jk}/\sigma(k;\pi,a)Tj​(π,a,k)=∑i​πi​pija​rjka​/σ(k;π,a). With

h(π,a,V)=∑iπig(i,a)+β∑kσ(k;π,a) V(T(π,a,k)),h(\pi,a,V)=\sum_{i}\pi_i g(i,a)+\beta\sum_{k}\sigma(k;\pi,a)\,V(T(\pi,a,k)),h(π,a,V)=i∑​πi​g(i,a)+βk∑​σ(k;π,a)V(T(π,a,k)),

a finite horizon NNN with salvage value gsg_sgs​ gives the optimal values VN+1∗(π)=∑iπigs(i)V^*_{N+1}(\pi)=\sum_i\pi_ig_s(i)VN+1∗​(π)=∑i​πi​gs​(i) and Vt∗(π)=max⁡ah(π,a,Vt+1∗)V^*_t(\pi)=\max_a h(\pi,a,V^*_{t+1})Vt∗​(π)=maxa​h(π,a,Vt+1∗​). For N=∞N=\inftyN=∞ and 0<β<10<\beta<10<β<1, V∗V^*V∗ is the bounded solution of V∗(π)=max⁡ah(π,a,V∗)V^*(\pi)=\max_a h(\pi,a,V^*)V∗(π)=maxa​h(π,a,V∗). The myopic actions are α(π)=argmax⁡a∑iπig(i,a)\alpha(\pi)=\operatorname{argmax}_a\sum_i\pi_ig(i,a)α(π)=argmaxa​∑i​πi​g(i,a).

Formalization targets

Goal: Proposition 2 (myopic lower bound)

Under (a) gsg_sgs​ nondecreasing, (b) g(⋅,a)g(\cdot,a)g(⋅,a) nondecreasing, (c) Pa≥tpPa′P^a\ge_{tp}P^{a'}Pa≥tp​Pa′ for a≥a′a\ge a'a≥a′, (d) ra(j)≥rra(j′)r^a(j)\ge_r r^a(j')ra(j)≥r​ra(j′) for j≥j′j\ge j'j≥j′, (e) ra(j)≥sra′(j)r^a(j)\ge_s r^{a'}(j)ra(j)≥s​ra′(j) for a≥a′a\ge a'a≥a′, and (f) rjkarj′ka′≥rjka′rj′kar^a_{jk}r^{a'}_{j'k}\ge r^{a'}_{jk}r^a_{j'k}rjka​rj′ka′​≥rjka′​rj′ka​ for a≥a′a\ge a'a≥a′, j≥j′j\ge j'j≥j′: for every t≤Nt\le Nt≤N (finite horizon), or for the infinite horizon with 0<β<10<\beta<10<β<1, and every π∈Π(S)\pi\in\Pi(S)π∈Π(S),

∀ δ∗(π) ∃ α(π)≤δ∗(π),∀ α(π) ∃ δ∗(π)≥α(π),\forall\,\delta^*(\pi)\ \exists\,\alpha(\pi)\le\delta^*(\pi),\qquad \forall\,\alpha(\pi)\ \exists\,\delta^*(\pi)\ge\alpha(\pi),∀δ∗(π) ∃α(π)≤δ∗(π),∀α(π) ∃δ∗(π)≥α(π),

where δ∗(π)\delta^*(\pi)δ∗(π) ranges over the maximizers of a↦h(π,a,Vt+1∗)a\mapsto h(\pi,a,V^*_{t+1})a↦h(π,a,Vt+1∗​) (resp. h(π,a,V∗)h(\pi,a,V^*)h(π,a,V∗)).

Milestone: Proposition 1 (MLR-monotone values)

Under (a)–(d) with every PaP^aPa TP₂: π≥rπ′\pi\ge_r\pi'π≥r​π′ in Π(S)\Pi(S)Π(S) implies Vt∗(π)≥Vt∗(π′)V^*_t(\pi)\ge V^*_t(\pi')Vt∗​(π)≥Vt∗​(π′) for t=1,…,N+1t=1,\dots,N+1t=1,…,N+1, and, without (a), V∗(π)≥V∗(π′)V^*(\pi)\ge V^*(\pi')V∗(π)≥V∗(π′) for N=∞N=\inftyN=∞.

Supporting milestones

The ordering facts behind both propositions: MLR implies stochastic dominance (§1), Lemma 1.1 (characterization of ≥s\ge_s≥s​), Lemma 1.3 (TP₂ prediction preserves ≥r\ge_r≥r​), Lemma 1.2 (the Bayes update is MLR-monotone in the observation, the prior and the action), the stochastic monotonicity of σ\sigmaσ in the belief (proof of Proposition 1) and in the action (Lemma 2.3), the comparison of hhh-increments with myopic increments (proof of Proposition 2), and Lemma 2.2 (dominated increments order maximizer sets).

Significance

The result. Proposition 2 makes the myopic policy, which solves a one-stage problem, a lower bound on an optimal policy for every belief and every period. In a search over policies, actions below α(π)\alpha(\pi)α(π) can be discarded. When ggg also has isotone differences, α\alphaα is nondecreasing, and the optimal policy is bounded below by a monotone function that is easy to compute. Proposition 1 gives MLR-monotone value functions, the input to many later structural results for POMDPs. Lemma 1.2 records the fact behind it: Bayesian updating respects the MLR order, while first-order stochastic dominance does not survive conditioning.

Formalizing it. These results are proved on paper. This mission produces machine-checked proofs, together with a reusable finite-POMDP layer (belief update, observation probabilities, Bellman operator, finite- and infinite-horizon values) and a library of the stochastic orders on finite chains. One statement in the paper is wrong: the printed "only if" direction of Lemma 1.2(1) is false. The mission states only the direction that is true and used.

Difficulty

The obvious induction on ttt for Proposition 1 needs k↦V(T(π,a,k))k\mapsto V(T(\pi,a,k))k↦V(T(π,a,k)) to be nondecreasing and σ(π,a)\sigma(\pi,a)σ(π,a) to increase with π\piπ. Both need a belief order that conditioning preserves. Under first-order stochastic dominance the posterior is not monotone in the prior, and the paper's counterexample (p. 740) shows that the induction then fails. The MLR order repairs this, but proving that the prediction step preserves it (Lemma 1.3) requires a total-positivity composition argument (Karlin–Rinott, Theorem 2.4) on product lattices. For Proposition 2 the difficulty is to compare continuation values across actions: the observation distribution and the posterior both change with the action, and two separate orderings (Lemma 2.3 and Lemma 1.2(3)) must be combined before the maximizer comparison applies. The infinite-horizon parts additionally need the Bellman fixed point characterized well enough to pass monotonicity to the limit.

Formalization scope

Everything is finite, so all probabilities and expectations are finite sums and no measure theory is involved. States, observations and actions are finite nonempty types with a LinearOrder (any finite chain is isomorphic to {1,…,n}\{1,\dots,n\}{1,…,n}). Π(X)\Pi(X)Π(X) is Mathlib's stdSimplex ℝ X. The orders ≥s,≥r,≥tp\ge_s,\ge_r,\ge_{tp}≥s​,≥r​,≥tp​ are plain relations (StochGE, MLRGE, TPGE) with the larger argument first, and every statement assumes simplex membership explicitly. The standing assumptions (stochastic rows of PaP^aPa and RaR^aRa, rjka>0r^a_{jk}>0rjka​>0, β≥0\beta\ge0β≥0) are fields of the structure POMDP. Vt∗V^*_tVt∗​ is computed by recursion (3) counted in steps to go, Vstar gs N t = valueToGo gs (N+1-t). The infinite-horizon V∗V^*V∗ is any function bounded on Π(S)\Pi(S)Π(S) that solves the Bellman equation there. For 0<β<10<\beta<10<β<1 such a function exists and is unique on Π(S)\Pi(S)Π(S), by contraction. The equivalence between recursion (3) and the optimum over history-dependent strategies is cited by the paper from the literature and is not part of this mission. Maximizer sets (argmaxSet) carry the "for all δ∗\delta^*δ∗ / there exists α\alphaα" quantifiers. Both halves of each part of Proposition 2 are ∀∃\forall\exists∀∃ statements.

The goal is not to be read with Vt+1∗V^*_{t+1}Vt+1∗​ or V∗V^*V∗ replaced by an arbitrary, or an arbitrary nondecreasing, value function. That reading would reduce Proposition 2 to Lemma 2.2 plus a hypothesis. The goal quantifies only over the value functions of recursion (3) and over bounded Bellman solutions.

A complete development needs finite total-positivity composition (Mathlib's four functions theorem is the natural starting point), Abel summation for Lemma 1.1, and a contraction argument for the infinite horizon. The order library and the finite POMDP layer are reusable beyond this paper. Proofs of any milestone are welcome, as are alternative arguments for Lemma 1.3.

Selected references

  • W. S. Lovejoy, Some Monotonicity Results for Partially Observed Markov Decision Processes, Operations Research 35(5):736–743, 1987. https://doi.org/10.1287/opre.35.5.736
  • R. D. Smallwood and E. J. Sondik, The Optimal Control of Partially Observable Markov Processes over a Finite Horizon, Operations Research 21(5):1071–1088, 1973. https://doi.org/10.1287/opre.21.5.1071
  • W. Whitt, A Note on the Influence of the Sample on the Posterior Distribution, Journal of the American Statistical Association 74:424–426, 1979.
  • W. Whitt, Multivariate Monotone Likelihood Ratio and Uniform Conditional Stochastic Order, Journal of Applied Probability 19:695–701, 1982.
  • S. Karlin and Y. Rinott, Classes of Orderings of Measures and Related Correlation Inequalities. I. Multivariate Totally Positive Distributions, Journal of Multivariate Analysis 10(4):467–498, 1980. https://doi.org/10.1016/0047-259X(80)90065-2
  • C. White, Optimal Control-limit Strategies for a Partially Observed Replacement Problem, International Journal of Systems Science 10:321–331, 1979 (the machine-replacement model of §5).
  • S. C. Albright, Structural Results for Partially Observable Markov Decision Processes, Operations Research 27(5):1041–1053, 1979. https://doi.org/10.1287/opre.27.5.1041
16 thms1 active userReviewed
Algorithmic Game TheoryMechanism Design·Captain: mikedeng1

Job Matching, Coalition Formation, and Gross Substitutes 1: Under Gross Substitutes the Salary-Adjustment Process Reaches a Discrete Core Allocation in Finitely Many RoundsResearch Paper

Motivation

Labor markets match workers to firms, and the terms of each match (the salary) are negotiated along with the match itself. A firm's output depends on the whole team it hires, so a firm cares about sets of workers, not individual workers one at a time. Kelso and Crawford (1982) asked when such a market has a stable outcome, the core, in which no firm and group of workers can agree on terms that all of them prefer, and when a simple decentralized auction finds one.

Their answer is the gross-substitutes condition: raising some workers' salaries never makes a firm withdraw an offer from a worker whose salary has not risen. Under it, an ascending process in which firms make offers and workers reject all but their favorite reaches a core allocation. This condition became the standard hypothesis for the existence of Walrasian equilibrium with indivisible goods (Gul and Stacchetti 1999), it is the hypothesis behind matching with contracts (Hatfield and Milgrom 2005), and the process is the ancestor of ascending auction designs.

Timeline.

  • 1962: Gale and Shapley, deferred acceptance for one-to-one and many-to-one matching without money.
  • 1971: Shapley and Shubik, the assignment game: one-to-one matching with transferable utility; the core is nonempty and is the set of solutions of a dual linear program.
  • 1981: Crawford and Knoer, a salary-adjustment process for one-to-one matching with money, converging to the core.
  • 1982: Kelso and Crawford, many-to-one matching with money and production complementarities; existence of the core under gross substitutes via the salary-adjustment process (Theorem 1, the target of this mission).

Setting

There are finitely many workers i∈Wi \in Wi∈W and firms j∈Fj \in Fj∈F, with at least one firm. Worker iii's utility of working for firm jjj at salary sss is ui(j;s)u^i(j; s)ui(j;s), strictly increasing and continuous in sss. Firm jjj's gross product from hiring the set C⊆WC \subseteq WC⊆W is yj(C)y^j(C)yj(C), and its profit at the salary vector sj=(s1j,…,smj)s^j = (s_{1j},\dots,s_{mj})sj=(s1j​,…,smj​) is

πj(C;sj)=yj(C)−∑i∈Csij.\pi^j(C; s^j) = y^j(C) - \sum_{i \in C} s_{ij}.πj(C;sj)=yj(C)−i∈C∑​sij​.

Mj(sj)M^j(s^j)Mj(sj) is the set of profit-maximizing CCC. Each pair has a starting salary σij\sigma_{ij}σij​. The assumptions (p. 1486) are (MP) yj(C∪{i})−yj(C)−σij≥0y^j(C \cup \{i\}) - y^j(C) - \sigma_{ij} \ge 0yj(C∪{i})−yj(C)−σij​≥0 for i∉Ci \notin Ci∈/C; (NFL) yj(∅)=0y^j(\emptyset) = 0yj(∅)=0; and (GS): if C∈Mj(sj)C \in M^j(s^j)C∈Mj(sj) and s~j≥sj\tilde s^j \ge s^js~j≥sj, some C~∈Mj(s~j)\tilde C \in M^j(\tilde s^j)C~∈Mj(s~j) contains {i∈C:s~ij=sij}\{i \in C : \tilde s_{ij} = s_{ij}\}{i∈C:s~ij​=sij​}.

In the discrete market with unit δ>0\delta > 0δ>0, firm jjj may pay worker iii only σij+kδ\sigma_{ij} + k\deltaσij​+kδ, k=0,1,2,…k = 0, 1, 2, \dotsk=0,1,2,…. An allocation sends each worker iii to a firm f(i)f(i)f(i) at a salary sif(i)s_{if(i)}sif(i)​; it is individually rational (D1) if sif(i)≥σif(i)s_{if(i)} \ge \sigma_{if(i)}sif(i)​≥σif(i)​ and every firm's profit is nonnegative. It is a (discrete) core allocation (D3) if it is individually rational, pays permitted salaries, and no firm jjj, set CCC and permitted salaries rjr^jrj satisfy ui(j;rij)>ui(f(i);sif(i))u^i(j; r_{ij}) > u^i(f(i); s_{if(i)})ui(j;rij​)>ui(f(i);sif(i)​) for all i∈Ci \in Ci∈C and πj(C;rj)>πj(Cj;sj)\pi^j(C; r^j) > \pi^j(C^j; s^j)πj(C;rj)>πj(Cj;sj).

The salary-adjustment process (pp. 1488–1489), verbatim:

R1. Firms begin facing a set of permitted salaries sij(0)=σijs_{ij}(0) = \sigma_{ij}sij​(0)=σij​. Permitted salaries at round ttt, sij(t)s_{ij}(t)sij​(t), remain constant, except as noted below. In round zero, each firm makes offers to all workers; this is costless by (MP).

R2. On each round, each firm makes offers to the members of one of its favorite sets of workers, given the schedule of permitted salaries sj(t)≡[s1j(t),…,smj(t)]s^j(t) \equiv [s_{1j}(t), \dots, s_{mj}(t)]sj(t)≡[s1j​(t),…,smj​(t)]. That is, firm jjj makes offers to the members of Cj[sj(t)]C^j[s^j(t)]Cj[sj(t)], where Cj[sj(t)]C^j[s^j(t)]Cj[sj(t)] maximizes πj[C;sj(t)]\pi^j[C; s^j(t)]πj[C;sj(t)]. Firms may break ties between sets of workers however they like, with the following exception: Any offer made by firm jjj in round t−1t - 1t−1 that was not rejected must be repeated in round ttt. By (GS), the firm sacrifices no profits in doing this, since (by R4) other workers' permitted salaries cannot have fallen, and the salary of a worker who did not reject an offer remains constant.

R3. Each worker who receives one or more offers rejects all but his or her favorite (taking salaries into account), which he or she tentatively accepts. Workers may break ties at any time however they like.

R4. Offers not rejected in previous periods remain in force. If worker iii rejected an offer from firm jjj in round t−1t - 1t−1, sij(t)=sij(t−1)+1s_{ij}(t) = s_{ij}(t - 1) + 1sij​(t)=sij​(t−1)+1; otherwise sij(t)=sij(t−1)s_{ij}(t) = s_{ij}(t - 1)sij​(t)=sij​(t−1). Firms continue to make offers to their favorite sets of workers, taking into account their permitted salaries.

R5. The process stops when no rejections are issued in some period. Workers then accept the offers that remain in force from the firms they have not rejected.

Formalization targets

Goal: Theorem 1 (p. 1489)

"The salary-adjustment process R1–R5 converges in finite time to a discrete core allocation in the discrete market for which it is defined." Formally, under the assumptions above:

(∃ a run) ∧ ∀ρ run: (∃T: ρ issues no rejections in round T) ∧ (∀T such rounds, outcomeρ(T) is a discrete core allocation).\Big(\exists \text{ a run}\Big)\ \wedge\ \forall \rho \text{ run}:\ \Big(\exists T:\ \rho \text{ issues no rejections in round } T\Big)\ \wedge\ \Big(\forall T \text{ such rounds},\ \text{outcome}_\rho(T) \text{ is a discrete core allocation}\Big).(∃ a run) ∧ ∀ρ run: (∃T: ρ issues no rejections in round T) ∧ (∀T such rounds, outcomeρ​(T) is a discrete core allocation).

Milestones, in the paper's order

  1. R2 is well defined: a run exists (each firm has a favorite set containing its unrejected offers).
  2. Lemma 1: every worker has at least one offer in every period.
  3. Lemma 2: after finitely many rounds every worker has exactly one offer and the process stops.
  4. Lemma 3: the allocation at a stopping round is individually rational.
  5. Lemma 4: the allocation at a stopping round is a discrete core allocation.

Significance

Theorem 1 gives the existence of a core allocation in every discrete market satisfying (MP), (NFL) and (GS), with no convexity of production and arbitrary complementarity within the limits of (GS). It is the step from which the paper derives the existence of a strict core allocation of the continuous market (Theorem 2, by letting the unit shrink), and with additional no-ties assumptions the firm-optimality of the process's outcome (Theorem 4) and the comparative statics of entry and exit (Theorem 5).

The result is proved in the paper and has been reproved in more general settings; it has no machine-checked proof known to us. Nothing of this paper was on Prove2Me before this series. Related platform work, credited but not reused: the Gale–Shapley deferred-acceptance development (GS62CollegeAdmissions.*, proved), the no-money ancestor of this process; and the Shapley–Shubik assignment game (AssignmentGame.CoreLP), whose core the process approximates when production is additively separable. Neither states anything about this process. This mission is mission 1 of a series of seven on the paper: 2 (strict core of the continuous market), 3 (one-sided coalition formation), 4 (firm-optimality), 5 (comparative statics), 6 (gross substitutes and decreasing returns), 7 (a market without a core). Each states its own model.

Difficulty

The process is quantified over all tie-breakings, so no single computation settles it; the statements are about every sequence of rounds consistent with R1–R5. Two points carry the content. First, R2 imposes a constraint that may not be satisfiable: a firm must repeat its unrejected offers and choose a profit-maximizing set. Without (GS) no such set need exist and the process is not defined. Second, the core property at the stopping round compares the outcome with coalitions using salaries the process never reached; the comparison is with salaries on the discrete grid only, and it is false if coalitions may use salaries below σij\sigma_{ij}σij​ or off the grid. Termination is not automatic either: the process may continue after a round without rejections, salaries are real numbers, and no bound on the number of rounds is given.

Formalization scope

Lean representation, in namespace KelsoCrawford.Process:

  • Market W F carries u, y, σ; workers and firms are finite types, with [Nonempty F] (the paper's n≥1n \ge 1n≥1; with no firms and some worker no run exists).
  • Allocation assigns every worker to a firm (no unemployment, as in the paper's fff).
  • (GS) is GrossSubstitutesOn (M.y j) (M.gridVectors δ j) for each firm: the discrete (GS), since the paper notes that a discrete market may satisfy (GS) while its continuous version does not.
  • The core is D3 with permitted salaries M.grid δ ={σij+kδ:k∈N}= \{\sigma_{ij} + k\delta : k \in \mathbb N\}={σij​+kδ:k∈N}.
  • A Run records salaries, offers and tentative choices per round; IsRun is R1–R4, Stopped is R5's "no rejections", outcome is R5's allocation.

Explicit readings of the paper's phrases:

  • "converges in finite time" = every run has a round without rejections; no bound on that round is claimed;
  • "to a discrete core allocation" = at every round without rejections, the allocation read off is in the discrete core;
  • the unit 111 of R4 is a parameter δ>0\delta > 0δ>0 (same theorem in rescaled units);
  • σij\sigma_{ij}σij​ is data; its defining relation ui(j;σij)=ui(0;0)u^i(j;\sigma_{ij}) = u^i(0;0)ui(j;σij​)=ui(0;0) is not assumed (a more general statement).

The existence of a run is part of the goal: without it, statements about all runs would be vacuous. Fixing a tie-breaking rule would turn the statements into claims about a single run and is ruled out; so are the strict core D2 (false here because of ties at the grid) and an integer grid below σij\sigma_{ij}σij​ (false for improving coalitions). Proofs of the milestones and reusable infrastructure for ascending processes are welcome.

Selected references

  • A. S. Kelso, Jr. and V. P. Crawford, Job matching, coalition formation, and gross substitutes, Econometrica 50(6), 1982, 1483–1504. https://doi.org/10.2307/1913392
  • V. P. Crawford and E. M. Knoer, Job matching with heterogeneous firms and workers, Econometrica 49(2), 1981, 437–450. https://doi.org/10.2307/1913320
  • D. Gale and L. S. Shapley, College admissions and the stability of marriage, American Mathematical Monthly 69(1), 1962, 9–15. https://doi.org/10.2307/2312726
  • L. S. Shapley and M. Shubik, The assignment game I: The core, International Journal of Game Theory 1, 1971, 111–130. https://doi.org/10.1007/BF01753437
  • F. Gul and E. Stacchetti, Walrasian equilibrium with gross substitutes, Journal of Economic Theory 87(1), 1999, 95–124. https://doi.org/10.1006/jeth.1999.2531
  • J. W. Hatfield and P. R. Milgrom, Matching with contracts, American Economic Review 95(4), 2005, 913–935. https://doi.org/10.1257/0002828054825466
8 thms1 active userReviewed
Optimization·Captain: mikedeng1

The Fritz John Necessary Optimality Conditions in the Presence of Equality and Inequality Constraints: Every Minimizer of a C¹ Program Admits Multipliers (ū₀, ū, v̄) ≠ 0 with ū ≥ 0Research Paper

Motivation

For problems with inequality constraints only, F. John (1948) showed that every minimizer admits nonnegative multipliers (uˉ0,uˉ1,…,uˉm)≠0(\bar u_0, \bar u_1, \dots, \bar u_m) \ne 0(uˉ0​,uˉ1​,…,uˉm​)=0, one of which belongs to the objective. The Kuhn–Tucker conditions (1951) are the stronger statement in which the objective's multiplier can be taken equal to one; they need a constraint qualification.

Problems arising in practice mix equalities and inequalities. Fritz John's theorem does not cover them, and the obvious reduction, writing each equality hj(x)=0h_j(x) = 0hj​(x)=0 as the two inequalities hj(x)≤0h_j(x) \le 0hj​(x)≤0 and −hj(x)≤0-h_j(x) \le 0−hj​(x)≤0, destroys the content of the conditions: every feasible point then satisfies them with uˉ0=0\bar u_0 = 0uˉ0​=0. O. L. Mangasarian and S. Fromovitz (1967) proved a version of Fritz John's conditions that treats equalities directly and stays informative, and from it derived the constraint qualification now known as the Mangasarian–Fromovitz constraint qualification (MFCQ). MFCQ is the standard regularity assumption in the convergence theory of sequential quadratic programming, interior-point and augmented-Lagrangian methods, and in the stability theory of parametric programs.

Timeline.

  • 1939, W. Karush (master's thesis) and 1951, H. W. Kuhn and A. W. Tucker: multiplier conditions with uˉ0=1\bar u_0 = 1uˉ0​=1 for inequality constraints, under a constraint qualification.
  • 1948, F. John: the multiplier rule with uˉ0≥0\bar u_0 \ge 0uˉ0​≥0 for inequality constraints, no qualification needed.
  • 1967, Mangasarian and Fromovitz (this paper): the multiplier rule for equalities and inequalities together, and the qualification (3.4)–(3.6).

Setting

Let EnE^nEn be nnn-dimensional Euclidean space, and let θ,g1,…,gm,h1,…,hk:En→R\theta, g_1, \dots, g_m, h_1, \dots, h_k : E^n \to \mathbb Rθ,g1​,…,gm​,h1​,…,hk​:En→R be functions with continuous first partial derivatives on EnE^nEn. The program is

minimize θ(x)subject togi(x)≤0, i∈M={1,…,m},hj(x)=0, j∈K={1,…,k}.(1.1)\text{minimize } \theta(x) \quad \text{subject to} \quad g_i(x) \le 0,\ i \in M = \{1,\dots,m\}, \qquad h_j(x) = 0,\ j \in K = \{1,\dots,k\}. \tag{1.1}minimize θ(x)subject togi​(x)≤0, i∈M={1,…,m},hj​(x)=0, j∈K={1,…,k}.(1.1)

The feasible set is S={x∈En:gi(x)≤0, i∈M, hj(x)=0, j∈K}S = \{x \in E^n : g_i(x) \le 0,\ i \in M,\ h_j(x) = 0,\ j \in K\}S={x∈En:gi​(x)≤0, i∈M, hj​(x)=0, j∈K}. A point xˉ\bar xxˉ is a solution of (1.1) if xˉ∈S\bar x \in Sxˉ∈S and θ(xˉ)≤θ(x)\theta(\bar x) \le \theta(x)θ(xˉ)≤θ(x) for all x∈Sx \in Sx∈S. The active set at xˉ\bar xxˉ is Mˉ={i∈M:gi(xˉ)=0}\bar M = \{i \in M : g_i(\bar x) = 0\}Mˉ={i∈M:gi​(xˉ)=0}. The gradient of fff at xˉ\bar xxˉ is ∇f(xˉ)\nabla f(\bar x)∇f(xˉ), and y′zy'zy′z denotes the inner product.

The generalized Fritz John conditions hold at xˉ\bar xxˉ if there are uˉ=(uˉ0,uˉ1,…,uˉm)\bar u = (\bar u_0, \bar u_1, \dots, \bar u_m)uˉ=(uˉ0​,uˉ1​,…,uˉm​) and vˉ=(vˉ1,…,vˉk)\bar v = (\bar v_1, \dots, \bar v_k)vˉ=(vˉ1​,…,vˉk​) with

uˉ0∇θ(xˉ)+∑i=1muˉi∇gi(xˉ)+∑j=1kvˉj∇hj(xˉ)=0,∑i=1muˉigi(xˉ)=0,uˉ≥0,(uˉ,vˉ)≠0.\bar u_0 \nabla\theta(\bar x) + \sum_{i=1}^m \bar u_i \nabla g_i(\bar x) + \sum_{j=1}^k \bar v_j \nabla h_j(\bar x) = 0, \qquad \sum_{i=1}^m \bar u_i g_i(\bar x) = 0, \qquad \bar u \ge 0, \qquad (\bar u, \bar v) \ne 0 .uˉ0​∇θ(xˉ)+i=1∑m​uˉi​∇gi​(xˉ)+j=1∑k​vˉj​∇hj​(xˉ)=0,i=1∑m​uˉi​gi​(xˉ)=0,uˉ≥0,(uˉ,vˉ)=0.

The Kuhn–Tucker conditions are the same system with uˉ0=1\bar u_0 = 1uˉ0​=1 and no nontriviality requirement.

Formalization targets

Goal: the generalized Fritz John necessary conditions (p. 41)

If xˉ\bar xxˉ is a solution of (1.1), then there exist uˉ∈Em+1\bar u \in E^{m+1}uˉ∈Em+1 and vˉ∈Ek\bar v \in E^kvˉ∈Ek with

uˉ0∇θ(xˉ)+∑i=1muˉi∇gi(xˉ)+∑j=1kvˉj∇hj(xˉ)=0,∑i=1muˉigi(xˉ)=0,uˉ≥0,(uˉ,vˉ)≠0.(2.9–2.12)\bar u_0 \nabla\theta(\bar x) + \sum_{i=1}^m \bar u_i \nabla g_i(\bar x) + \sum_{j=1}^k \bar v_j \nabla h_j(\bar x) = 0, \quad \sum_{i=1}^m \bar u_i g_i(\bar x) = 0, \quad \bar u \ge 0, \quad (\bar u, \bar v) \ne 0. \tag{2.9–2.12}uˉ0​∇θ(xˉ)+i=1∑m​uˉi​∇gi​(xˉ)+j=1∑k​vˉj​∇hj​(xˉ)=0,i=1∑m​uˉi​gi​(xˉ)=0,uˉ≥0,(uˉ,vˉ)=0.(2.9–2.12)

No regularity of the constraints is assumed. The nontriviality requirement covers uˉ0\bar u_0uˉ0​, the uˉi\bar u_iuˉi​ and the vˉj\bar v_jvˉj​ together.

Milestones

  1. Motzkin's transposition theorem (p. 39): for real matrices A,B,CA, B, CA,B,C with AAA nonempty, exactly one of y′A<0, y′B≤0, y′C=0y'A < 0,\ y'B \le 0,\ y'C = 0y′A<0, y′B≤0, y′C=0 and Az1+Bz2+Cz3=0, z1≥0, z1≠0, z2≥0Az_1 + Bz_2 + Cz_3 = 0,\ z_1 \ge 0,\ z_1 \ne 0,\ z_2 \ge 0Az1​+Bz2​+Cz3​=0, z1​≥0, z1​=0, z2​≥0 is solvable.
  2. Lemma 1 (pp. 39–40): if fi(xˉ)=0f_i(\bar x) = 0fi​(xˉ)=0, hj(xˉ)=0h_j(\bar x) = 0hj​(xˉ)=0 at some xˉ\bar xxˉ in an open set DDD, no x∈Dx \in Dx∈D has fi(x)<0f_i(x) < 0fi​(x)<0 for all iii and hj(x)=0h_j(x) = 0hj​(x)=0 for all jjj, and the ∇hj(xˉ)\nabla h_j(\bar x)∇hj​(xˉ) are linearly independent, then no yyy has y′∇fi(xˉ)<0y'\nabla f_i(\bar x) < 0y′∇fi​(xˉ)<0 and y′∇hj(xˉ)=0y'\nabla h_j(\bar x) = 0y′∇hj​(xˉ)=0.
  3. Lemma 2 (p. 40): under the same assumptions, without independence, there are rˉ≥0\bar r \ge 0rˉ≥0 and sˉ\bar ssˉ, not both zero, with ∑rˉi∇fi(xˉ)+∑sˉj∇hj(xˉ)=0\sum \bar r_i \nabla f_i(\bar x) + \sum \bar s_j \nabla h_j(\bar x) = 0∑rˉi​∇fi​(xˉ)+∑sˉj​∇hj​(xˉ)=0.
  4. DDD is open (p. 41): D={x:gi(x)<0, i∈M∖Mˉ}D = \{x : g_i(x) < 0,\ i \in M \setminus \bar M\}D={x:gi​(x)<0, i∈M∖Mˉ} is open.
  5. The reduction (pp. 41–42): at a solution xˉ\bar xxˉ of (1.1), xˉ∈D\bar x \in Dxˉ∈D and the system θ(x)−θ(xˉ)<0\theta(x) - \theta(\bar x) < 0θ(x)−θ(xˉ)<0, gi(x)<0g_i(x) < 0gi​(x)<0 (i∈Mˉi \in \bar Mi∈Mˉ), hj(x)=0h_j(x) = 0hj​(x)=0 has no solution in DDD.

Companion results

  • Corollary (p. 43): the generalized Fritz John conditions hold at any feasible point satisfying (2.27) or (2.28).
  • The generalized constraint qualification (pp. 43–44): at a solution, yˉ′∇gi(xˉ)<0\bar y'\nabla g_i(\bar x) < 0yˉ​′∇gi​(xˉ)<0 (i∈Mˉi \in \bar Mi∈Mˉ), yˉ′∇hj(xˉ)=0\bar y'\nabla h_j(\bar x) = 0yˉ​′∇hj​(xˉ)=0 and independent ∇hj(xˉ)\nabla h_j(\bar x)∇hj​(xˉ) imply the Kuhn–Tucker conditions.
  • The splitting remark (p. 38): after splitting equalities, every feasible point satisfies Fritz John's original conditions.

Significance

The theorem is a multiplier rule for smooth programs with both kinds of constraints and no assumption on the constraints. It has two direct consequences in the paper. First, it yields MFCQ, the condition (3.4)–(3.6) under which the Kuhn–Tucker conditions hold at every solution. MFCQ is weaker than linear independence of all active gradients (LICQ), and it is equivalent to boundedness of the Kuhn–Tucker multiplier set (Gauvin, 1977). Second, the corollary identifies feasible non-minimizers at which the conditions hold anyway.

The result is classical and its proof is in every nonlinear-programming textbook. Mathlib has the equality-constrained Lagrange multiplier rule for a local extremum (IsLocalExtrOn.exists_multipliers_of_hasStrictFDerivAt) and the implicit function theorem, and Prove2Me has a formalized Fritz John theorem for inequality constraints only. To our knowledge no machine-checked proof of the mixed equality–inequality Fritz John rule, of MFCQ, or of Motzkin's transposition theorem in this form exists. The formalization would provide the standard multiplier rule and qualification on which a formal theory of nonlinear programming builds.

Difficulty

With inequalities alone, John's theorem follows from the observation that if xˉ\bar xxˉ is a minimizer, no direction yyy strictly decreases θ\thetaθ and every active gig_igi​ to first order; Motzkin's (or Gordan's) theorem then produces the multipliers. With equalities the first step fails: a direction with y′∇hj(xˉ)=0y'\nabla h_j(\bar x) = 0y′∇hj​(xˉ)=0 is tangent to the equality manifold but generally leaves it, so a first-order descent direction does not yield a feasible point with smaller objective. Lemma 1 is precisely the claim that it does when the ∇hj(xˉ)\nabla h_j(\bar x)∇hj​(xˉ) are independent, and it needs a curve inside {h=0}\{h = 0\}{h=0} along which the strict inequalities persist: the implicit function theorem, applied on an open set, with care that the curve stays in DDD. The linearly dependent case must be handled separately, and it is the only place the multipliers vˉ\bar vvˉ can be nonzero with uˉ=0\bar u = 0uˉ=0.

Formalization scope

EnE^nEn is EuclideanSpace ℝ (Fin n), the inner product y′zy'zy′z is inner ℝ y z, and ∇f(xˉ)\nabla f(\bar x)∇f(xˉ) is Mathlib's gradient f xbar. "Continuous first partial derivatives on EnE^nEn", the standing assumption of §1, is ContDiff ℝ 1 (equivalent in finite dimension) and is a hypothesis of the goal, the corollary and the constraint qualification; Lemma 1 and Lemma 2 use ContDiffOn ℝ 1 · D on an open set DDD, as on the page. Indices i∈Mi \in Mi∈M and j∈Kj \in Kj∈K are Fin m and Fin k, 0-based; m=0m = 0m=0 and k=0k = 0k=0 are allowed. The multiplier vector uˉ∈Em+1\bar u \in E^{m+1}uˉ∈Em+1 is split into u0 : ℝ and u : Fin m → ℝ, and (uˉ,vˉ)≠0(\bar u, \bar v) \ne 0(uˉ,vˉ)=0 is "u0 ≠ 0, or some u i ≠ 0, or some v j ≠ 0". A solution of (1.1) is a global minimizer over SSS, as the proof on p. 42 uses. In Motzkin's theorem a matrix is the family of its columns, and "either … or …, but never both" is Xor. In Lemma 2, "the assumptions of Lemma 1" exclude the proviso (2.5) of linear independence, which the proof of Lemma 2 treats separately.

The goal does not assume linear independence of the ∇hj(xˉ)\nabla h_j(\bar x)∇hj​(xˉ), does not mention DDD or Lemma 1, and requires (uˉ,vˉ)≠0(\bar u, \bar v) \ne 0(uˉ,vˉ)=0 with uˉ0\bar u_0uˉ0​ included; a formalization that drops uˉ0\bar u_0uˉ0​ from the nontriviality condition is false at m=k=0m = k = 0m=k=0, and one that requires uˉ0≠0\bar u_0 \ne 0uˉ0​=0 is the Kuhn–Tucker statement, false without a qualification.

A complete development needs Motzkin's (or Gordan's) theorem of the alternative, which is reusable well beyond this mission, and the implicit function theorem on open sets in Euclidean space with a C1C^1C1 curve argument. Proofs of any milestone are welcome, as is a proof of the goal by another route.

Selected references

  • O. L. Mangasarian and S. Fromovitz, The Fritz John necessary optimality conditions in the presence of equality and inequality constraints, J. Math. Anal. Appl. 17 (1967), 37–47. https://doi.org/10.1016/0022-247X(67)90163-1
  • F. John, Extremum problems with inequalities as subsidiary conditions, in Studies and Essays Presented to R. Courant on his 60th Birthday, Interscience, New York, 1948, 187–204.
  • H. W. Kuhn and A. W. Tucker, Nonlinear programming, Proc. Second Berkeley Symposium on Mathematical Statistics and Probability, University of California Press, 1951, 481–492.
  • J. Gauvin, A necessary and sufficient regularity condition to have bounded multipliers in nonconvex programming, Math. Programming 12 (1977), 136–138. https://doi.org/10.1007/BF01593777
  • O. L. Mangasarian, Nonlinear Programming, McGraw-Hill, 1969; reprinted SIAM Classics in Applied Mathematics 10, 1994. https://doi.org/10.1137/1.9781611971255
7 thms1 active userReviewed
Control TheoryDynamical Systems·Captain: mikedeng1

Dynamic Instabilities and Stabilization Methods in Distributed Real-Time Scheduling of Manufacturing Systems 1: Clearing Policies Are Unstable on a Re-Entrant Two-Machine Line, Even Without Set-UpsResearch Paper

Motivation

A flexible manufacturing system is a set of machines through which parts of several types travel along fixed routes; each machine serves several buffers and must pay a set-up time whenever it switches from one buffer to another. Real-time scheduling decides, as the system evolves, which buffer each machine works on. Perkins and Kumar (IEEE Trans. Automat. Control 34, 1989) introduced simple distributed policies for this problem, of which the most natural is the clearing policy: a machine keeps working on a buffer until it is empty, and only then switches. They proved that every clear-a-fraction policy, a subclass of clearing policies, keeps every buffer bounded on acyclic systems whenever each machine has spare capacity, and left open whether clear-a-fraction policies stabilize all systems in which material flows around cycles.

Kumar and Seidman (IEEE Trans. Automat. Control 35(3), 1990, doi:10.1109/9.50339) answered no. Their Example 1 is a single part type that visits two machines in the order 1, 2, 2, 1. Every machine has spare capacity, yet under the clearing policy the buffer levels grow without bound, and they do so even when all set-up times are zero, so the instability comes from machines starving each other rather than from time lost to set-ups. Until then, instability had been suspected to require positive set-up times. Shortly afterwards Lu and Kumar exhibited instability of a static buffer-priority rule in a re-entrant network (IEEE Trans. Automat. Control 36, 1991); together these examples started the study of stability of multiclass queueing networks.

Setting

A manufacturing system has part types ppp arriving at rates dp>0d_p > 0dp​>0. Parts of type ppp follow a route of length npn_pnp​: their iii-th operation is at machine μp,i\mu_{p,i}μp,i​, and they wait for it in buffer bp,ib_{p,i}bp,i​, where each part needs processing time τp,i>0\tau_{p,i} > 0τp,i​>0. Machine mmm serves the buffers Bm={b:μb=m}B_m = \{b : \mu_b = m\}Bm​={b:μb​=m}, and switching from bbb to b′b'b′ costs set-up time δb,b′≥0\delta_{b,b'} \ge 0δb,b′​≥0.

Flows are continuous (fluid). The level of buffer bbb at time t≥0t \ge 0t≥0 is xb(t)=xb(0)+ub(t)−yb(t)≥0x_b(t) = x_b(0) + u_b(t) - y_b(t) \ge 0xb​(t)=xb​(0)+ub​(t)−yb​(t)≥0, where yb(t)y_b(t)yb​(t) is its cumulative output and ub(t)u_b(t)ub​(t) its cumulative input: dptd_p tdp​t for the first buffer of a route, and the output of the preceding buffer otherwise. Each machine works in runs: run kkk is a set-up phase of length δβk−1,βk\delta_{\beta_{k-1},\beta_k}δβk−1​,βk​​ followed by a processing phase on buffer βk\beta_kβk​, during which the buffer is drained at rate 1/τb1/\tau_b1/τb​ while it is nonempty and passed through at its inflow rate when it is empty. The system is stable if sup⁡0≤t<∞xb(t)<∞\sup_{0 \le t < \infty} x_b(t) < \inftysup0≤t<∞​xb​(t)<∞ for every buffer.

A clearing policy (Definition 1) is one in which a machine processing bbb continues until the first time that bbb is empty and some other buffer of the same machine is nonempty, and then commences a set-up for one of the nonempty buffers.

Example 1. One part type arrives at rate d=1d = 1d=1 and visits machine 1, machine 2, machine 2 and machine 1; its buffers are 1,2,3,41, 2, 3, 41,2,3,4, so B1={1,4}B_1 = \{1, 4\}B1​={1,4} and B2={2,3}B_2 = \{2, 3\}B2​={2,3}. Processing times are τ1,…,τ4>0\tau_1, \dots, \tau_4 > 0τ1​,…,τ4​>0, and δk\delta_kδk​ is the time to set up to buffer kkk. The parameters satisfy the critical condition and the capacity condition

τ2+τ4>1,τ1+τ4<1,τ2+τ3<1.(3–5)\tau_2 + \tau_4 > 1, \qquad \tau_1 + \tau_4 < 1, \qquad \tau_2 + \tau_3 < 1. \tag{3–5}τ2​+τ4​>1,τ1​+τ4​<1,τ2​+τ3​<1.(3–5)

The initial state is x(0)=(ξ,0,0,0)x(0) = (\xi, 0, 0, 0)x(0)=(ξ,0,0,0), with machine 1 set up for buffer 4 and machine 2 set up for buffer 3. Write

λ=τ41−τ2>1,α=(τ4+1)(δ1+δ2)1−τ2+δ3(τ4+1)+δ4,β=τ4(δ1+δ2)1−τ2+τ4δ3+δ4.\lambda = \frac{\tau_4}{1-\tau_2} > 1, \quad \alpha = \frac{(\tau_4+1)(\delta_1+\delta_2)}{1-\tau_2} + \delta_3(\tau_4+1) + \delta_4, \quad \beta = \frac{\tau_4(\delta_1+\delta_2)}{1-\tau_2} + \tau_4\delta_3 + \delta_4.λ=1−τ2​τ4​​>1,α=1−τ2​(τ4​+1)(δ1​+δ2​)​+δ3​(τ4​+1)+δ4​,β=1−τ2​τ4​(δ1​+δ2​)​+τ4​δ3​+δ4​.

Formalization targets

Goal: Example 1, both cases

Assume (3)–(5).

  1. If δ1,…,δ4>0\delta_1, \dots, \delta_4 > 0δ1​,…,δ4​>0, there is ξ0\xi_0ξ0​ such that for every ξ≥ξ0\xi \ge \xi_0ξ≥ξ0​ (ξ>0\xi > 0ξ>0) a clearing trajectory from (ξ,0,0,0)(\xi, 0, 0, 0)(ξ,0,0,0) exists, and every such trajectory has
sup⁡0≤t<∞x1(t)=+∞.\sup_{0 \le t < \infty} x_1(t) = +\infty.0≤t<∞sup​x1​(t)=+∞.
  1. If δ1=⋯=δ4=0\delta_1 = \dots = \delta_4 = 0δ1​=⋯=δ4​=0, the same holds for every ξ>0\xi > 0ξ>0.

Milestone: the Case 1 cycle map

For ξ\xiξ large enough, every clearing trajectory from (ξ,0,0,0)(\xi, 0, 0, 0)(ξ,0,0,0) reaches, at T1=(λ+τ2/(1−τ2))ξ+αT_1 = (\lambda + \tau_2/(1-\tau_2))\xi + \alphaT1​=(λ+τ2​/(1−τ2​))ξ+α,

x(T1)=(λξ+β,0,0,0),x(T_1) = (\lambda\xi + \beta, 0, 0, 0),x(T1​)=(λξ+β,0,0,0),

with machines 1 and 2 again set up for buffers 4 and 3.

Milestone: the Case 2 magnification

With zero set-up times and any ξ>0\xi > 0ξ>0, every clearing trajectory reaches, at t5=(τ2+τ4)ξ/(1−τ2)t_5 = (\tau_2+\tau_4)\xi/(1-\tau_2)t5​=(τ2​+τ4​)ξ/(1−τ2​),

x(t5)=(λξ,0,0,0),x(t_5) = (\lambda\xi, 0, 0, 0),x(t5​)=(λξ,0,0,0),

with machines 1 and 2 again set up for buffers 4 and 3.

Significance

The example shows that the condition ρm<1\rho_m < 1ρm​<1 on every machine, which is necessary for stability and sufficient for the existence of some stabilizing policy, does not make natural distributed policies stable once material flows around a cycle. The throughput of the line falls to 1/(τ2+τ4)<11/(\tau_2+\tau_4) < 11/(τ2​+τ4​)<1 part per unit time although each machine could handle the demand. This motivates the paper's two positive results: sufficient conditions under which clear-a-fraction policies are stable (Theorem 1), and a supervisory mechanism that stabilizes any policy (Theorem 2), which are the subjects of the other missions of this series. The example is also an early instance of the phenomenon later studied as instability of multiclass fluid networks under work-conserving policies.

The paper's argument is a stage-by-stage computation of piecewise linear trajectories. No machine-checked version of it exists. A formal proof has to make precise what the paper leaves to the reader: that the clearing rule determines the trajectory, that the stage formulas are what that trajectory does, and that the cycle can be restarted. The formal model of runs, set-ups and the clearing rule built here is the same as in the other missions of the series.

Difficulty

The arithmetic of each cycle is routine once the trajectory is known. The difficulty is in the universal quantifier: the claim covers every clearing trajectory, and the clearing rule is defined implicitly, through "the first time thereafter" at which a buffer is empty and another one is nonempty. At several switching instants the buffer a machine switches to is empty and only starts to fill at that instant, and with zero set-up times a machine may begin a run at an instant where the switching condition already holds. Showing that each switch happens exactly when the paper says, and that the fluid levels then follow the printed formulas (including the reduced rate of a machine working on an empty buffer), is a uniqueness argument for a hybrid system, not a simulation. The existence half asks for the converse: an explicit trajectory, defined for all time, with infinitely many runs whose start times tend to infinity.

Formalization scope

  • Time is real (t≥0t \ge 0t≥0); flows are fluid; there are no transport delays or assembly.
  • The system is a general structure (part types Fin P, machines Fin M, buffers ⟨p, i⟩ with i : Fin (n p), paper index iii = Lean index i+1i+1i+1), instantiated as Example 1 with d=1d = 1d=1, route (1,2,2,1)(1,2,2,1)(1,2,2,1), and δb,b′=δb′\delta_{b,b'} = \delta_{b'}δb,b′​=δb′​ for b≠b′b \ne b'b=b′; staying on a buffer costs nothing.
  • A trajectory is a schedule of runs per machine (possibly finitely many, the last lasting forever), with only finitely many run starts in any bounded interval. Processing obeys a rate cap (yby_byb​ grows at most at rate 1/τb1/\tau_b1/τb​, and only while machine μb\mu_bμb​ is in a processing phase of bbb) and runs at full rate while the buffer is nonempty.
  • In Definition 1, a target buffer counts as "nonempty" when it is demanding: positive level, or inflow starting at that instant. The no-early-exit condition is imposed on the open processing interval. Under the literal reading (positive level) or a closed interval, the paper's own trajectories are not clearing, and the goal would hold vacuously; the existence clause in the goal rules out that trivialization.
  • "Set up for buffer bbb at time TTT" means the run in force on (sk,sk+1](s_k, s_{k+1}](sk​,sk+1​].
  • Unboundedness is stated for buffer 1: for every CCC there is t≥0t \ge 0t≥0 with x1(t)>Cx_1(t) > Cx1​(t)>C; "ξ\xiξ large enough" is ∃ξ0,∀ξ≥ξ0\exists \xi_0, \forall \xi \ge \xi_0∃ξ0​,∀ξ≥ξ0​.

Useful contributions include lemmas about fluid trajectories that do not depend on the example (continuity of levels, the pass-through rate on an empty buffer, restarting a trajectory at a run boundary), which also serve the other missions of the series.

Selected references

  • P. R. Kumar and T. I. Seidman, Dynamic instabilities and stabilization methods in distributed real-time scheduling of manufacturing systems, IEEE Trans. Automat. Control 35(3), 289–298, 1990. https://doi.org/10.1109/9.50339
  • J. R. Perkins and P. R. Kumar, Stable, distributed, real-time scheduling of flexible manufacturing/assembly/disassembly systems, IEEE Trans. Automat. Control 34, 139–148, 1989 (reference [18] of the paper).
  • S. H. Lu and P. R. Kumar, Distributed scheduling based on due dates and buffer priorities, IEEE Trans. Automat. Control 36, 1991.
7 thms1 active userReviewed
ProbabilityStochastic Systems·Captain: mikedeng1

Stochastic Inequalities on Partially Ordered Spaces 1: Stochastically Ordered Initial Laws and Kernels Give Coupled Random Sequences with Xₙ ≤ Yₙ for All n Almost SurelyResearch Paper

Motivation

Comparison theorems for stochastic processes answer a practical question: if one system starts "lower" and moves "upward" less aggressively than another, does it stay below the other one for all time? Queueing, reliability and inventory models use such statements to order performance measures of two systems without computing either distribution. Results of this kind for real-valued Markov chains go back to Kalmykov (1962) and Daley (1968); O'Brien (1975) proved a comparison theorem for real sequences with general (non-Markov) dependence on the past.

Kamae, Krengel and O'Brien (1977) placed these results on a common foundation: an arbitrary partially ordered Polish space, where the state can be a vector, a path, a configuration or a measure. Their tool is a characterization of the stochastic order through monotone couplings, which goes back to Strassen (1965).

Timeline.

  • 1962, Kalmykov: comparison of real Markov chains with stochastically monotone kernels.
  • 1965, Strassen: existence of probability measures with given marginals; a coupling on a closed set K⊆E×EK \subseteq E \times EK⊆E×E exists iff the marginals satisfy the matching inequalities.
  • 1968, Daley: stochastically monotone Markov chains on R\mathbb RR.
  • 1975, O'Brien: comparison theorem for real random sequences with history-dependent kernels.
  • 1977, Kamae–Krengel–O'Brien: the order on a partially ordered Polish space, Theorem 1 (six characterizations), and the comparison theorem for sequences in products of such spaces (Theorem 2).

Setting

Let EEE be a complete separable metric space with a closed partial order ≤\le≤ (the set {(x,y):x≤y}\{(x,y) : x \le y\}{(x,y):x≤y} is closed in E×EE \times EE×E) and its Borel σ\sigmaσ-algebra. Write M(E)\mathcal M(E)M(E) for the probability measures on EEE. A set A⊆EA \subseteq EA⊆E is increasing if x∈Ax \in Ax∈A and x≤yx \le yx≤y imply y∈Ay \in Ay∈A; a function fff is increasing if x≤yx \le yx≤y implies f(x)≤f(y)f(x) \le f(y)f(x)≤f(y). For P1,P2∈M(E)P_1, P_2 \in \mathcal M(E)P1​,P2​∈M(E), P1P_1P1​ is stochastically smaller than P2P_2P2​, written P1≺P2P_1 \prec P_2P1​≺P2​, if

∫f dP1≤∫f dP2for every bounded measurable increasing f:E→R.\int f\,dP_1 \le \int f\,dP_2 \quad\text{for every bounded measurable increasing } f : E \to \mathbb R .∫fdP1​≤∫fdP2​for every bounded measurable increasing f:E→R.

A stochastic kernel kkk from E1E_1E1​ to E2E_2E2​ assigns to every x∈E1x \in E_1x∈E1​ a probability measure k(x,⋅)k(x,\cdot)k(x,⋅) on E2E_2E2​, measurably in xxx. For P1∈M(E1)P_1 \in \mathcal M(E_1)P1​∈M(E1​), P1∗kP_1 * kP1​∗k is the measure on E1×E2E_1 \times E_2E1​×E2​ with (P1∗k)(A1×A2)=∫A1k(x,A2) P1(dx)(P_1 * k)(A_1 \times A_2) = \int_{A_1} k(x, A_2)\,P_1(dx)(P1​∗k)(A1​×A2​)=∫A1​​k(x,A2​)P1​(dx), and P1kP_1^{k}P1k​ is its second marginal. A kernel kkk on E×EE \times EE×E is upward if k(x,⋅)k(x,\cdot)k(x,⋅) is concentrated on {y:y≥x}\{y : y \ge x\}{y:y≥x} for every xxx.

For partially ordered Polish spaces E1,E2,…E_1, E_2, \dotsE1​,E2​,…, the products En=E1×⋯×EnE^{n} = E_1 \times \cdots \times E_nEn=E1​×⋯×En​ and E∞=∏iEiE^\infty = \prod_i E_iE∞=∏i​Ei​ carry the product topology and the coordinatewise order, and are again partially ordered Polish spaces. Given P1∈M(E1)P_1 \in \mathcal M(E_1)P1​∈M(E1​) and kernels pnp_npn​ from En−1E^{n-1}En−1 to EnE_nEn​ (n≥2n \ge 2n≥2), the measure P1∗p2∗⋯∗pnP_1 * p_2 * \cdots * p_nP1​∗p2​∗⋯∗pn​ on EnE^{n}En is the law of (X1,…,Xn)(X_1, \dots, X_n)(X1​,…,Xn​) when X1∼P1X_1 \sim P_1X1​∼P1​ and XnX_nXn​ is drawn from pn(X1,…,Xn−1,⋅)p_n(X_1, \dots, X_{n-1}, \cdot)pn​(X1​,…,Xn−1​,⋅); its projective limit is the law of the whole sequence.

Formalization targets

Goal: Theorem 2 (the discrete-time comparison theorem)

Let P1,Q1∈M(E1)P_1, Q_1 \in \mathcal M(E_1)P1​,Q1​∈M(E1​) and let pn,qnp_n, q_npn​,qn​ be stochastic kernels from En−1E^{n-1}En−1 to EnE_nEn​, n≥2n \ge 2n≥2. If P1≺Q1P_1 \prec Q_1P1​≺Q1​ and

pn(xn−1,⋅)≺qn(yn−1,⋅)whenever xn−1≤yn−1,p_n(x^{n-1},\cdot) \prec q_n(y^{n-1},\cdot) \quad\text{whenever } x^{n-1} \le y^{n-1},pn​(xn−1,⋅)≺qn​(yn−1,⋅)whenever xn−1≤yn−1,

then there are random sequences (Xn)(X_n)(Xn​), (Yn)(Y_n)(Yn​) on one probability space, with initial laws P1P_1P1​, Q1Q_1Q1​ and conditional laws pnp_npn​, qnq_nqn​, such that

P(Xi≤Yi, i=1,2,… )=1.P(X_i \le Y_i,\ i = 1, 2, \dots) = 1 .P(Xi​≤Yi​, i=1,2,…)=1.

Milestones

  1. Theorem 1: for P1,P2∈M(E)P_1, P_2 \in \mathcal M(E)P1​,P2​∈M(E), P1≺P2P_1 \prec P_2P1​≺P2​ is equivalent to each of: a coupling supported on {x≤y}\{x \le y\}{x≤y}; a representation f(Z)∼P1f(Z) \sim P_1f(Z)∼P1​, g(Z)∼P2g(Z) \sim P_2g(Z)∼P2​ with f≤gf \le gf≤g and ZZZ real; random variables X1≤X2X_1 \le X_2X1​≤X2​ a.s. with laws P1,P2P_1, P_2P1​,P2​; P2=P1kP_2 = P_1^{k}P2​=P1k​ for an upward kernel kkk; and P1(B)≤P2(B)P_1(B) \le P_2(B)P1​(B)≤P2​(B) for every closed increasing BBB.
  2. Proposition 1: under the hypotheses of Theorem 2, P1∗p2∗⋯∗pn≺Q1∗q2∗⋯∗qnP_1 * p_2 * \cdots * p_n \prec Q_1 * q_2 * \cdots * q_nP1​∗p2​∗⋯∗pn​≺Q1​∗q2​∗⋯∗qn​ for every nnn.
  3. Proposition 2: on E∞E^\inftyE∞, if all finite-dimensional marginals satisfy P(i)≺Q(i)P^{(i)} \prec Q^{(i)}P(i)≺Q(i), then P≺QP \prec QP≺Q.
  4. Proposition 3: ≺\prec≺ is preserved under weak convergence.
  5. Proposition 4: P1≺P2≺⋯P_1 \prec P_2 \prec \cdotsP1​≺P2​≺⋯ iff there are random elements X1≤X2≤⋯X_1 \le X_2 \le \cdotsX1​≤X2​≤⋯ a.s. with Xi∼PiX_i \sim P_iXi​∼Pi​, iff there are ZZZ real and f1≤f2≤⋯f_1 \le f_2 \le \cdotsf1​≤f2​≤⋯ with fi(Z)∼Pif_i(Z) \sim P_ifi​(Z)∼Pi​.
  6. Corollary 1 (i)–(iii), consequences of Theorem 2 when E1=E2=⋯E_1 = E_2 = \cdotsE1​=E2​=⋯: for an increasing set AAA, P(Xn∈A)≤P(Yn∈A)P(X_n \in A) \le P(Y_n \in A)P(Xn​∈A)≤P(Yn​∈A); first entrance times into AAA satisfy P(Nx<n)≤P(Ny<n)P(N_x < n) \le P(N_y < n)P(Nx​<n)≤P(Ny​<n); and Ef(Xn)≤Ef(Yn)E f(X_n) \le E f(Y_n)Ef(Xn​)≤Ef(Yn​) for nondecreasing fff whenever the expectations exist.
  7. Theorem 3: in a partially ordered Polish space with a compatible vector structure, kernels ordered through the increments they produce yield processes (Sn)(S_n)(Sn​), (Tn)(T_n)(Tn​) with S1≤T1S_1 \le T_1S1​≤T1​ and Sn+1−Sn≤Tn+1−TnS_{n+1} - S_n \le T_{n+1} - T_nSn+1​−Sn​≤Tn+1​−Tn​ for all nnn, almost surely.

Significance

The result. Theorem 2 turns an inequality between one-step transition laws into a pathwise inequality between whole trajectories. Every functional that is increasing in the path, such as hitting times of increasing sets, maxima, occupation counts or cumulative costs, is then ordered between the two processes, as Corollary 1 illustrates. Because the state space is any partially ordered Polish space, the theorem covers vector-valued queue lengths, networks, and processes whose state is itself a sequence, not just real chains. Theorem 1 is the basic tool for working with the order on such spaces: it converts between integrals, couplings, kernels and closed increasing sets.

Formalizing it. All results are proved in the paper (1977); none is machine-checked. The platform has the special case of Theorem 1 (i) ⇔\Leftrightarrow⇔ (iv) for E=RnE = \mathbb R^nE=Rn as an open statement (PalmQueueing.Ordering.strassen_st); the general partially ordered Polish case, and the sequence comparison, are new. A formal development yields a reusable library for the stochastic order on general ordered spaces and its interaction with Mathlib's Ionescu-Tulcea construction of process laws (Kernel.trajMeasure).

Difficulty

The obvious argument for Theorem 2 couples the processes step by step: couple X1≤Y1X_1 \le Y_1X1​≤Y1​, then, given the two histories, couple X2≤Y2X_2 \le Y_2X2​≤Y2​, and so on. Each step needs a monotone coupling of pn(xn−1,⋅)p_n(x^{n-1},\cdot)pn​(xn−1,⋅) and qn(yn−1,⋅)q_n(y^{n-1},\cdot)qn​(yn−1,⋅) chosen measurably in the pair of histories; the existence of one coupling for each fixed pair (Theorem 1) does not by itself give a kernel.

Theorem 1's central implication, from the integral inequality to a coupling supported on the closed set {x≤y}\{x \le y\}{x≤y}, is Strassen's theorem. On R\mathbb RR it follows from quantile functions; on a general ordered space there is no such formula. Passing from finite horizons to the infinite sequence is a further step, since an ordering of every finite-dimensional marginal must be turned into an ordering of the infinite-dimensional laws.

Formalization scope

  • A partially ordered Polish space is [TopologicalSpace E] [PolishSpace E] [MeasurableSpace E] [BorelSpace E] [PartialOrder E] [OrderClosedTopology E]. This is the paper's standing assumption (Sec. 1, p. 899) and is carried by every theorem, also where a statement says only "Polish space". All sets and functions the paper quantifies over are measurable, also by the standing assumption.
  • StochLE P₁ P₂ is defined through bounded measurable monotone functions, exactly as on p. 899. It is not defined through increasing sets, closed increasing sets or couplings, so none of the milestones holds by definition.
  • Sequences are 0-based: the paper's EiE_iEi​, XiX_iXi​ are Lean's E (i - 1), X (i - 1), and the paper's kernel pnp_npn​ (n≥2n \ge 2n≥2) is p (n - 2) : Kernel (Π i : Iic (n - 2), E i) (E (n - 1)), the signature of Mathlib's Ionescu-Tulcea API.
  • "Random sequences with initial law P1P_1P1​ and conditional laws pnp_npn​" is encoded through their joint law, which these data determine: the law of (Xn)(X_n)(Xn​) is Kernel.trajMeasure P₁ p. Corollary 1 is stated about these laws directly. The goal therefore cannot be met by coupling only one-dimensional marginals or finite prefixes; it asserts the joint laws of the full sequences and one almost-sure event for all indices.
  • Hypothesis (4) is required pointwise for all ordered pairs of histories; no stochastic monotonicity of the kernels is assumed.
  • Corollary 1 (iii) takes expectations in the extended sense, Ef=Ef+−Ef−E f = E f^+ - E f^-Ef=Ef+−Ef− in EReal, and "the expectation exists" means the two parts are not both infinite; expectations equal to ±∞\pm\infty±∞ are covered.
  • Theorem 1 (iii) and Proposition 4 (iii) leave the law of the real variable ZZZ free, as the paper does.
  • Theorem 3 (p. 904) prints the conditional increment law of TTT as qn+1(T1,…,Tn;A+Sn)q_{n+1}(T_1, \dots, T_n; A + S_n)qn+1​(T1​,…,Tn​;A+Sn​); this is a misprint for A+TnA + T_nA+Tn​, and the Lean states the corrected form. Its compatible vector structure is [AddCommGroup E] [Module ℝ E] [ContinuousAdd E] [ContinuousSMul ℝ E] plus the hypothesis that translates of increasing sets are increasing.
  • Not included: Sections 4–5 (continuous time, which needs the Skorohod space).

Welcome contributions: proofs of the milestones, in particular Strassen's coupling theorem on partially ordered Polish spaces, a measurable-selection lemma for monotone couplings, and general lemmas relating StochLE to increasing sets.

The source is the published version (The Annals of Probability), and printed page = PDF page + 898 throughout.

Selected references

  • T. Kamae, U. Krengel, G. L. O'Brien, Stochastic Inequalities on Partially Ordered Spaces, The Annals of Probability 5(6), 1977, 899–912. https://doi.org/10.1214/aop/1176995659
  • V. Strassen, The existence of probability measures with given marginals, The Annals of Mathematical Statistics 36(2), 1965, 423–439. https://doi.org/10.1214/aoms/1177700153
  • G. L. O'Brien, The comparison method for stochastic processes, The Annals of Probability 3, 1975, 80–88. https://projecteuclid.org/journals/annals-of-probability/volume-3/issue-1
  • D. J. Daley, Stochastically monotone Markov chains, Zeitschrift für Wahrscheinlichkeitstheorie und verwandte Gebiete 10, 1968, 307–317 (as cited in the paper).
  • G. I. Kalmykov, On the partial ordering of one-dimensional Markov processes, Theory of Probability and its Applications 7, 1962, 456–459 (as cited in the paper).
13 thms1 active userReviewed
CombinatoricsProbabilityTheoretical Computer Science·Captain: mikedeng1

Packet Routing and Job-Shop Scheduling in O(Congestion + Dilation) Steps: Edge-Simple Paths with Congestion c and Dilation d Admit an O(c + d)-Step Schedule with Constant-Size QueuesResearch Paper

Motivation

In a store-and-forward network, messages are cut into packets that travel from node to node along wires, one wire per time step, and wait in buffers between moves. Routing such traffic splits into two problems: choosing a path for each packet, and scheduling the packets along their paths, deciding at every step which packets move and which wait. Leighton, Maggs and Rao showed that the second problem always has an essentially optimal solution: once paths are fixed, two simple parameters of the paths determine the routing time up to a constant factor, on every network.

The result separates path selection from timing in the design of routing algorithms for parallel machines, and it reaches beyond networks: a job-shop problem in which every operation takes one unit of time and no job visits a machine twice is the same problem with jobs as packets and machines as edges.

Timeline.

  • 1988: Leighton, Maggs and Rao, extended abstract at FOCS, Universal packet routing algorithms.
  • 1994: the full paper in Combinatorica 14, with the existence theorem of an O(c+d)O(c+d)O(c+d) schedule with constant queues (Theorem 3.4) and a randomized on-line algorithm.
  • 1999: Leighton, Maggs and Richa, Fast algorithms for finding O(congestion + dilation) packet routing schedules, make the construction algorithmic, using the algorithmic Local Lemma of Beck.

Setting

A network is a directed multigraph: a type VVV of nodes, a type EEE of edges, and maps src,tgt:E→V\mathrm{src},\mathrm{tgt}:E\to Vsrc,tgt:E→V. A path is a list of edges e0,…,eℓ−1e_0,\dots,e_{\ell-1}e0​,…,eℓ−1​ with tgt(ek)=src(ek+1)\mathrm{tgt}(e_k)=\mathrm{src}(e_{k+1})tgt(ek​)=src(ek+1​); it is edge-simple if no edge occurs twice. A finite set PPP of packets is given, each with its path.

The dilation ddd is the largest number of edges on a path; the congestion ccc is the largest number of paths through one edge. Since a packet crosses at most one edge per step and an edge carries at most one packet per step, every schedule needs at least max⁡(c,d)\max(c,d)max(c,d) steps.

A schedule assigns to every packet ppp and every index kkk of its path the step τ(p,k)≥1\tau(p,k)\ge1τ(p,k)≥1 at which ppp crosses its kkk-th edge, strictly increasing in kkk. Its length is the last crossing step. A packet waits in its initial queue before its first crossing, in the edge queue at the head of the edge it last crossed between two crossings, and in its final queue after its last crossing. Only edge queues count for queue size: the other two are fixed by the instance. A schedule is valid if at most one packet crosses each edge at each step.

For the proof, the paper measures schedules that are not yet valid through frames: a TTT-frame is a run of TTT consecutive steps, and the relative congestion of a frame is the largest number of packets crossing one edge in it, divided by TTT.

Formalization targets

Goal: Theorem 3.4 (p. 11)

There are absolute constants KKK and QQQ such that every finite set of packets with edge-simple paths of congestion at most ccc and dilation at most ddd, on any network, has a valid schedule with

length≤K (c+d),every edge queue≤Q at every step.\text{length}\le K\,(c+d),\qquad \text{every edge queue}\le Q \text{ at every step}.length≤K(c+d),every edge queue≤Q at every step.

The constants are not fixed: the paper proves existence, and any constants are a valid answer.

Milestones, in the order the proof uses them

  1. Lemma 3.1 (p. 8), the Lovász Local Lemma: events of probability at most ppp with dependence at most b≥1b\ge1b≥1 and 4pb<14pb<14pb<1 all fail together with positive probability.
  2. Lemma 3.2 (p. 8): with congestion and dilation at most ddd, a schedule of length O(d)O(d)O(d) with no waiting in edge queues and at most TTT packets per edge in every frame of size T≥log⁡2dT\ge\log_2 dT≥log2​d.
  3. The recurrences (pp. 12–13): I(1)=log⁡dI^{(1)}=\log dI(1)=logd, I(i+1)=log⁡5I(i)I^{(i+1)}=\log^5 I^{(i)}I(i+1)=log5I(i), r(1)=1r^{(1)}=1r(1)=1, r(i+1)=r(i)(1+κ/log⁡I(i))r^{(i+1)}=r^{(i)}(1+\kappa/\sqrt{\log I^{(i)}})r(i+1)=r(i)(1+κ/logI(i)​) stop at some j=O(log⁡∗d)j=O(\log^* d)j=O(log∗d) with r(j)=O(1)r^{(j)}=O(1)r(j)=O(1).
  4. Lemma 3.5 (p. 14): frame bounds for all sizes from TTT to 2T−12T-12T−1 imply them for all sizes ≥T\ge T≥T.
  5. The final simulation (pp. 12–13): a schedule with relative congestion O(1)O(1)O(1) in frames of constant size, in which every packet waits at most once every k1≥2k_1\ge2k1​≥2 steps, becomes a valid schedule, a constant factor longer, with constant edge queues.

Significance

The theorem shows that congestion and dilation, two quantities read off the paths alone, determine the optimal schedule length up to a constant factor on every network, with buffers of constant size. Path-selection algorithms that minimize c+dc+dc+d therefore yield near-optimal routing, and the same bound holds for unit-time job shops without repeated machines. It is also an often-cited application of the Local Lemma beyond a single round of random choices: the proof applies it O(log⁡∗d)O(\log^* d)O(log∗d) times in succession.

The result has been proved since 1994, and the algorithmic version since 1999. As far as is known, no part of it is machine-checked. The mission produces a formal model of store-and-forward schedules with edge queues and frames, a formal statement of the theorem that excludes the degenerate readings, and formal versions of the steps of its proof.

Difficulty

The naive approach gives each packet a random initial delay and then lets it move without waiting. That gives O(log⁡(Nd))O(\log(Nd))O(log(Nd)) packets per edge per step, and O(c+dlog⁡(Nd))O(c+d\log(Nd))O(c+dlog(Nd)) steps after slowing down. Lemma 3.2 does better only in frames of size log⁡d\log dlogd, not in single steps. Recursing on frames, as in Theorem 3.3, loses a constant factor per level and gives (c+d)2O(log⁡∗(c+d))(c+d)2^{O(\log^* (c+d))}(c+d)2O(log∗(c+d)).

Removing that factor is the central difficulty. Each refinement must keep the relative congestion nearly unchanged, r(i+1)=r(i)(1+O(1)/log⁡I(i))r^{(i+1)}=r^{(i)}(1+O(1)/\sqrt{\log I^{(i)}})r(i+1)=r(i)(1+O(1)/logI(i)​), which requires second-order terms in the tail estimates, delays spread over the block rather than inserted at its start, and careful handling of block boundaries. The constant queue bound needs an invariant: every packet waits at most once every I(i)I^{(i)}I(i) steps. The Local Lemma gives existence only; the construction is non-constructive.

Formalization scope

Conventions committed to in Lean:

  • The network is arbitrary: V E : Type with src tgt : E → V, no finiteness or degree bound. Packets form a Fintype P; paths are List E with matching endpoints (List.IsChain) and List.Nodup.
  • Congestion and dilation are bounds (CongestionLE path c, DilationLE path d), equivalent to exact values because every bound is monotone.
  • A schedule is a Timetable: time p k : ℕ, the step at which packet p crosses its k-th edge, at least 1 and strictly increasing in k. Length at most L means every crossing step is ≤ L. Valid means two different crossings of one edge happen at different steps.
  • The edge-queue size of edge g at the end of step t counts crossings of g at a step ≤ t whose packet crosses its next edge at a step > t. Initial and final queues are not counted.
  • Frames: frameCount τ g t T counts the packets that cross g at a step in [t, t+T). Relative congestion at most r in frames of size ≥ T₀ is frameCount ≤ r·T for all T ≥ 1 with T₀ ≤ T.
  • log is Real.logb 2. Every O(1) and "sufficiently large" is a constant quantified before the instance, and in the goal ∃ K Q comes before the network.
  • Lemma 3.1 is stated on an arbitrary probability space with measurable events. Dependence uses independence from the generated σ-algebra, and the statement adds 1 ≤ b, without which the page's statement is false.

These choices rule out the trivial formalizations: constants chosen after the instance would make K=cdK=cdK=cd suffice; a schedule without edge exclusivity would make the greedy schedule of length ddd a solution; a missing queue bound drops half of the theorem; and a statement without its length bound is solved by sending one packet at a time.

Not stated: Lemmas 3.6–3.10 and the summary of the refinement step (p. 20). They concern the block decomposition and delay-insertion rules of pp. 13–14 and 17–18, which the paper defines only in prose. Contributions are welcome on the Local Lemma (finite or general), the probabilistic estimates of Lemma 3.2, Lemma 3.5, the elementary simulation step, and formal definitions of the block operations from which Lemmas 3.6–3.10 can be stated. The schedule model is reusable for other routing results, such as the on-line algorithm of §2 or the O(c+d)O(c+d)O(c+d) results for leveled networks.

Selected references

  • F. T. Leighton, B. M. Maggs, S. B. Rao, Packet routing and job-shop scheduling in O(congestion + dilation) steps, Combinatorica 14 (1994) 167–186. https://doi.org/10.1007/BF01215349 (this mission cites the authors' manuscript).
  • F. T. Leighton, B. M. Maggs, S. B. Rao, Universal packet routing algorithms, Proc. 29th IEEE FOCS (1988) 256–269.
  • F. T. Leighton, B. M. Maggs, A. W. Richa, Fast algorithms for finding O(congestion + dilation) packet routing schedules, Combinatorica 19 (1999) 375–401. https://doi.org/10.1007/s004930050061
  • P. Erdős, L. Lovász, Problems and results on 3-chromatic hypergraphs and some related questions, in Infinite and Finite Sets, Colloq. Math. Soc. János Bolyai 10 (1975) 609–627.
  • J. Spencer, Ten Lectures on the Probabilistic Method, SIAM (1987), pp. 57–58. https://doi.org/10.1137/1.9780898719918
10 thms1 active userReviewed
Graph TheoryProbabilityStochastic Systems·Captain: mikedeng1

Loss Networks 3: If E e^{λX} < ∞ and 2E(X − C)⁺ < E(C − X)⁺, i.i.d. Loads on the Complete Graph Fit on Direct and Two-Edge Routes with Probability → 1Research Paper

Motivation

Telephone and data networks are often fully connected at the core: every pair of switching centres has a direct trunk group, and a call that finds its direct trunk full may be alternatively routed over a two-link path through a third, tandem centre. Whether such a network can absorb fluctuations of demand without losing traffic depends on how the spare capacity of lightly loaded links can be borrowed by heavily loaded ones. F. P. Kelly's survey Loss networks (Ann. Appl. Probab., 1991, doi:10.1214/aoap/1177005872) studies this question in §4.6, "Results respecting graph structure", by looking at a static snapshot of the network: random loads on the edges of a complete graph, and the question whether they can all be carried at once.

Timeline:

  • Hajek (1986, personal communication cited as [21] in the survey) considered edges coloured independently red (a pair that needs twice an edge's capacity) or white (an idle edge), and proved that for red probability p<1/3p<1/3p<1/3 all red pairs can be served over white two-edge paths with probability tending to one (Theorem 4.40, p. 357).
  • Hajek (1987, [22]) showed the same threshold for routing each red pair on a single two-edge path (Theorem 4.43, quoted, p. 358).
  • Kelly (1991, Theorem 4.45, p. 358) extended Theorem 4.40 from two-valued loads to general i.i.d. loads with an exponential moment, under the condition 2 E(X−C)+<E(C−X)+2\,\mathbb E(X-C)^+<\mathbb E(C-X)^+2E(X−C)+<E(C−X)+. The survey gives the proof in full on p. 359.

Setting

Let K≥1K\ge 1K≥1 and consider the complete graph on the nodes {0,…,K−1}\{0,\dots,K-1\}{0,…,K−1}: every unordered pair e={a,b}e=\{a,b\}e={a,b} of distinct nodes is an edge, and there are 12K(K−1)\tfrac12K(K-1)21​K(K−1) edges. Every edge has capacity CCC.

An offered load xe≥0x_e\ge 0xe​≥0 is attached to every edge eee. The load of e={a,b}e=\{a,b\}e={a,b} may be carried on its direct edge, or on a two-edge route a−k−ba-k-ba−k−b through a tandem node k∉ek\notin ek∈/e; such a route uses the two edges {a,k}\{a,k\}{a,k} and {b,k}\{b,k\}{b,k}. Loads are divisible. The loads are routable with capacity CCC if there are flows fe,k≥0f_{e,k}\ge 0fe,k​≥0 (zero when k∈ek\in ek∈e) with ∑kfe,k≤xe\sum_k f_{e,k}\le x_e∑k​fe,k​≤xe​ such that on every edge ggg

(xg−∑kfg,k)+∑(e,k): g on the route of e via kfe,k≤C,\Big(x_g-\sum_k f_{g,k}\Big)+\sum_{(e,k):\ g \text{ on the route of } e \text{ via } k} f_{e,k}\le C,(xg​−k∑​fg,k​)+(e,k): g on the route of e via k∑​fe,k​≤C,

i.e. the directly carried part of ggg's own load plus all two-edge traffic passing through ggg is at most CCC.

The loads are random: XXX is a nonnegative real random variable with law μ\muμ, and the loads (xe)(x_e)(xe​) are independent, each distributed as XXX. Let

P(K)=P{the loads on the complete graph on K nodes are routable}.P(K)=\mathbb P\{\text{the loads on the complete graph on } K \text{ nodes are routable}\}.P(K)=P{the loads on the complete graph on K nodes are routable}.

Write E(X−C)+\mathbb E(X-C)^+E(X−C)+ for the mean excess of a load over the capacity and E(C−X)+\mathbb E(C-X)^+E(C−X)+ for the mean spare capacity.

Formalization targets

Goal: Theorem 4.45

If E eλX<∞\mathbb E\,e^{\lambda X}<\inftyEeλX<∞ for some λ>0\lambda>0λ>0 and

2 E(X−C)+<E(C−X)+(4.46)2\,\mathbb E(X-C)^+<\mathbb E(C-X)^+ \tag{4.46}2E(X−C)+<E(C−X)+(4.46)

then

P(K)→1(K→∞).P(K)\to 1 \qquad (K\to\infty).P(K)→1(K→∞).

Milestones (in the order of the proof on pp. 358–359)

With m=E(C−X)+m=\mathbb E(C-X)^+m=E(C−X)+ and 0<ε<m20<\varepsilon<m^20<ε<m2:

  1. In each triangle the cyclic reservations (xe−C)+(C−xak)+(C−xbk)+/((K−2)(m2−ε))(x_e-C)^+(C-x_{ak})^+(C-x_{bk})^+/((K-2)(m^2-\varepsilon))(xe​−C)+(C−xak​)+(C−xbk​)+/((K−2)(m2−ε)) are positive at most once, and only for an overloaded edge routed through two underloaded ones.
  2. If every overloaded edge's reservations cover its excess and no underloaded edge has more reserved through it than it has spare, the loads are routable.
  3. E Y=m2/(m2−ε)>1\mathbb E\,Y=m^2/(m^2-\varepsilon)>1EY=m2/(m2−ε)>1 for Y=(C−X2)+(C−X3)+/(m2−ε)Y=(C-X_2)^+(C-X_3)^+/(m^2-\varepsilon)Y=(C−X2​)+(C−X3​)+/(m2−ε).
  4. E Z=2 E(X−C)+ m/(m2−ε)<1\mathbb E\,Z=2\,\mathbb E(X-C)^+\,m/(m^2-\varepsilon)<1EZ=2E(X−C)+m/(m2−ε)<1 for small ε\varepsilonε, for Z=((X1−C)+(C−X2)++(X2−C)+(C−X1)+)/(m2−ε)Z=\big((X_1-C)^+(C-X_2)^++(X_2-C)^+(C-X_1)^+\big)/(m^2-\varepsilon)Z=((X1​−C)+(C−X2​)++(X2​−C)+(C−X1​)+)/(m2−ε).
  5. (4.48): P{∑i≤nn−1Yi<1}≤e−nI1\mathbb P\{\sum_{i\le n} n^{-1}Y_i<1\}\le e^{-nI_1}P{∑i≤n​n−1Yi​<1}≤e−nI1​ for some I1>0I_1>0I1​>0 and all n≥1n\ge 1n≥1.
  6. (4.49): P{∑i≤nn−1Zi>1}≤e−nI2\mathbb P\{\sum_{i\le n} n^{-1}Z_i>1\}\le e^{-nI_2}P{∑i≤n​n−1Zi​>1}≤e−nI2​ for some I2>0I_2>0I2​>0 and all n≥1n\ge 1n≥1, when XXX has an exponential moment.
  7. 1−P(K)≤12K(K−1) (P1(K−2)+P2(K−2))1-P(K)\le\tfrac12K(K-1)\,(P_1(K-2)+P_2(K-2))1−P(K)≤21​K(K−1)(P1​(K−2)+P2​(K−2)).

Significance

The result. Theorem 4.45 says that in a large fully connected network, a load distribution whose mean overload is less than half its mean spare capacity can be served, with probability tending to one, using only direct and two-link routes. The factor 222 reflects that each unit of overflow occupies two edges. The condition is explicit and depends on the load law only through two expectations, which makes it a design rule: capacity CCC suffices for large networks as soon as (4.46) holds. Comment 4.47 (p. 358) observes that the two-valued law P{X=2}=p\mathbb P\{X=2\}=pP{X=2}=p, P{X=0}=1−p\mathbb P\{X=0\}=1-pP{X=0}=1−p with C=1C=1C=1 turns (4.46) into Hajek's threshold p<1/3p<1/3p<1/3.

Formalizing it. The theorem is proved, in full, on one page; nothing here is open. The mission produces a machine-checked version of that proof: a precise routing event on the complete graph, the deterministic reservation argument, two Cramér–Chernoff tail bounds with rates uniform in the network size, and the union bound over edges. To our knowledge none of these steps is formalized anywhere, and no routing-feasibility event on a complete graph exists in Mathlib or on the platform.

Difficulty

The obvious approach is to fix an overloaded edge and argue that, among its K−2K-2K−2 two-edge routes, enough pass through two underloaded edges. That count is binomial and concentrates, but it does not prove the theorem: the same underloaded edge sits on two-edge routes of many overloaded pairs, so the reservations of different pairs compete for its spare capacity, and the routing decisions of different pairs are dependent. Any argument has to control, simultaneously at every edge, both the flow an overloaded edge can shed and the flow an underloaded edge is asked to absorb, with exponential rates uniform in KKK so that a union bound over 12K(K−1)\tfrac12K(K-1)21​K(K−1) edges survives; this is the central difficulty. On the upper side the variables are unbounded, so the exponential moment of XXX has to be carried over to the reserved flows.

Formalization scope

The Lean development lives in the namespace KellyLossNetworks.Routing.

  • Edges are {e : Sym2 (Fin K) // ¬ e.IsDiag}; loads are functions Edge K → ℝ.
  • The routing event Feasible C x lets each pair split its load arbitrarily over its direct edge and all its two-edge routes, charges a two-edge flow to both edges of its route, requires the flow sent away from a pair not to exceed its load, and imposes the capacity constraint on every edge, including overloaded ones. Flows are real (divisible loads); integer routing is a different problem.
  • "Independent and identically distributed" is the product measure Measure.pi (fun _ : Edge K => μ), with μ a probability measure on ℝ and X ≥ 0 almost surely. P(K)P(K)P(K) is the measure of the routing event; no measurability of that event is presupposed.
  • Expectations are Bochner integrals. The exponential moment is integrability of t↦eθtt\mapsto e^{\theta t}t↦eθt for some θ>0\theta>0θ>0; it implies that (X−C)+(X-C)^+(X−C)+ is integrable, so (4.46) compares genuine expectations.
  • The limit is along K∈NK\in\mathbb NK∈N with no lower bound on KKK; for K≤2K\le 2K≤2 there are no two-edge routes, which does not affect the limit.
  • The rates I1,I2I_1,I_2I1​,I2​ in (4.48) and (4.49) are quantified before nnn and may not depend on it.

A trivializing formalization is ruled out: an event that allows only direct routing, ignores the capacity of the edges a detour passes through, or lets a pair send away more than its load would make the statement false or empty, and the routing event here does none of these.

A complete development needs Fubini on product measures, the Cramér–Chernoff method for averages of i.i.d. variables (both tails, with the lower tail for a bounded nonnegative variable and the upper tail under an exponential moment), measure-preserving projections of Measure.pi, and combinatorics of the triangles through an edge of the complete graph. The Cramér–Chernoff bounds with rates uniform in nnn are reusable well beyond this mission. Contributions to any milestone are welcome; the deterministic milestones 1–2 and the expectation computations 3–4 are independent of the tail bounds and of each other.

Selected references

  • F. P. Kelly, Loss networks, Annals of Applied Probability 1(3):319–378, 1991. doi:10.1214/aoap/1177005872
  • B. Hajek, Average case analysis of greedy algorithms for Kelly's triangle problem and the independent set problem, 26th IEEE Conference on Decision and Control, 1987 (reference [22] of the survey; the source of Theorem 4.43).
  • H. Chernoff, A measure of asymptotic efficiency for tests of a hypothesis based on the sum of observations, Annals of Mathematical Statistics 23(4):493–507, 1952. doi:10.1214/aoms/1177729330
9 thms1 active userReviewed
Numerical AnalysisOptimization·Captain: mikedeng1

Global Convergence Properties of Conjugate Gradient Methods for Optimization I: Conjugate Gradient Methods with |β_k| ≤ β_k^FR Are Globally Convergent under Strong Wolfe Line SearchesResearch Paper

Motivation

Nonlinear conjugate gradient methods minimize a smooth function fff of nnn variables using only function values, gradients and a few vectors of storage. They are the method of choice when nnn is so large that quasi-Newton matrices cannot be stored, and they remain a standard component of large-scale optimization software. Their convergence theory is delicate: the classical results assume exact line searches, while practical codes accept any steplength satisfying inexpensive inexact conditions.

Gilbert and Nocedal (INRIA RR-1268, 1990; journal version SIAM J. Optim. 2 (1992)) organized the global convergence theory of these methods around a single device and proved two families of results. This mission covers the first: every conjugate gradient method whose parameter βk\beta_kβk​ is bounded in absolute value by the Fletcher–Reeves value converges under the strong Wolfe line search.

Timeline. Fletcher and Reeves (1964) and Polak and Ribière (1969) introduced the two best-known choices of βk\beta_kβk​. Zoutendijk (1970) and Wolfe (1969, 1971) established the summability condition now called Zoutendijk's condition. Al-Baali (1985) proved that the Fletcher–Reeves method with the strong Wolfe line search and σ2<12\sigma_2 < \tfrac12σ2​<21​ generates descent directions and satisfies lim inf⁡∥gk∥=0\liminf\|g_k\| = 0liminf∥gk​∥=0. Touati-Ahmed and Storey (1990) treated nonnegative hybrids. Gilbert and Nocedal (1990) extended Al-Baali's theorem to every βk\beta_kβk​ with ∣βk∣≤βkFR|\beta_k| \le \beta_k^{FR}∣βk​∣≤βkFR​, which admits negative values and yields a convergent modification of the Polak–Ribière method.

Setting

Let EEE be a finite-dimensional real inner product space and f:E→Rf : E \to \mathbb Rf:E→R continuously differentiable, with gradient g=∇fg = \nabla fg=∇f for that inner product. Starting from x1x_1x1​, the method generates

d1=−g1,dk=−gk+βkdk−1 (k≥2),xk+1=xk+αkdk,d_1 = -g_1,\qquad d_k = -g_k + \beta_k d_{k-1}\ (k\ge 2),\qquad x_{k+1} = x_k + \alpha_k d_k,d1​=−g1​,dk​=−gk​+βk​dk−1​ (k≥2),xk+1​=xk​+αk​dk​,

where gk=g(xk)g_k = g(x_k)gk​=g(xk​), βk\beta_kβk​ is a scalar and αk>0\alpha_k > 0αk​>0 a steplength found by a one-dimensional search. The Fletcher–Reeves and Polak–Ribière scalars are

βkFR=∥gk∥2∥gk−1∥2,βkPR=⟨gk,gk−gk−1⟩∥gk−1∥2.\beta_k^{FR} = \frac{\|g_k\|^2}{\|g_{k-1}\|^2},\qquad \beta_k^{PR} = \frac{\langle g_k, g_k - g_{k-1}\rangle}{\|g_{k-1}\|^2}.βkFR​=∥gk−1​∥2∥gk​∥2​,βkPR​=∥gk−1​∥2⟨gk​,gk​−gk−1​⟩​.

Assumptions 2.1: the level set L={x:f(x)≤f(x1)}\mathcal L = \{x : f(x) \le f(x_1)\}L={x:f(x)≤f(x1​)} is bounded, and on an open neighbourhood N\mathcal NN of L\mathcal LL the gradient is Lipschitz: ∥g(x)−g(x~)∥≤L∥x−x~∥\|g(x) - g(\tilde x)\| \le L\|x - \tilde x\|∥g(x)−g(x~)∥≤L∥x−x~∥.

A steplength satisfies the Wolfe conditions with 0<σ1<σ2<10 < \sigma_1 < \sigma_2 < 10<σ1​<σ2​<1 if

f(xk+αkdk)≤f(xk)+σ1αk⟨gk,dk⟩,⟨g(xk+αkdk),dk⟩≥σ2⟨gk,dk⟩,f(x_k + \alpha_k d_k) \le f(x_k) + \sigma_1\alpha_k\langle g_k, d_k\rangle,\qquad \langle g(x_k+\alpha_k d_k), d_k\rangle \ge \sigma_2\langle g_k, d_k\rangle,f(xk​+αk​dk​)≤f(xk​)+σ1​αk​⟨gk​,dk​⟩,⟨g(xk​+αk​dk​),dk​⟩≥σ2​⟨gk​,dk​⟩,

and the strong Wolfe conditions if the second inequality is replaced by ∣⟨g(xk+αkdk),dk⟩∣≤−σ2⟨gk,dk⟩|\langle g(x_k+\alpha_k d_k), d_k\rangle| \le -\sigma_2\langle g_k, d_k\rangle∣⟨g(xk​+αk​dk​),dk​⟩∣≤−σ2​⟨gk​,dk​⟩. The angle θk\theta_kθk​ between −gk-g_k−gk​ and dkd_kdk​ is given by cos⁡θk=−⟨gk,dk⟩/(∥gk∥∥dk∥)\cos\theta_k = -\langle g_k, d_k\rangle/(\|g_k\|\|d_k\|)cosθk​=−⟨gk​,dk​⟩/(∥gk​∥∥dk​∥), and the Zoutendijk condition is ∑k≥1cos⁡2θk∥gk∥2<∞\sum_{k\ge1}\cos^2\theta_k\|g_k\|^2 < \infty∑k≥1​cos2θk​∥gk​∥2<∞.

Formalization targets

Goal: Theorem 3.2

Under Assumptions 2.1, for any method of the above form with

∣βk∣≤βkFR(k≥2)|\beta_k| \le \beta_k^{FR}\quad (k \ge 2)∣βk​∣≤βkFR​(k≥2)

and steplengths satisfying the strong Wolfe conditions with 0<σ1<σ2<120 < \sigma_1 < \sigma_2 < \tfrac120<σ1​<σ2​<21​,

lim inf⁡k→∞∥gk∥=0.\liminf_{k\to\infty}\|g_k\| = 0 .k→∞liminf​∥gk​∥=0.

The sequence βk\beta_kβk​ is arbitrary within the bound; the statement contains no constants.

Milestones

  • Theorem 2.1 (i) (Zoutendijk): for any iteration xk+1=xk+αkdkx_{k+1} = x_k + \alpha_k d_kxk+1​=xk​+αk​dk​ with descent directions and Wolfe steps, ∑k≥1cos⁡2θk∥gk∥2<∞\sum_{k\ge1}\cos^2\theta_k\|g_k\|^2 < \infty∑k≥1​cos2θk​∥gk​∥2<∞.
  • Lemma 3.1: under ∣βk∣≤βkFR|\beta_k| \le \beta_k^{FR}∣βk​∣≤βkFR​ and the strong Wolfe curvature condition with σ2<12\sigma_2 < \tfrac12σ2​<21​, every dkd_kdk​ is a descent direction and
−∑j=0k−1σ2j≤⟨gk,dk⟩∥gk∥2≤−2+∑j=0k−1σ2j.-\sum_{j=0}^{k-1}\sigma_2^j \le \frac{\langle g_k, d_k\rangle}{\|g_k\|^2} \le -2 + \sum_{j=0}^{k-1}\sigma_2^j .−j=0∑k−1​σ2j​≤∥gk​∥2⟨gk​,dk​⟩​≤−2+j=0∑k−1​σ2j​.
  • (3.5): there are c1,c2>0c_1, c_2 > 0c1​,c2​>0 with c1∥gk∥/∥dk∥≤cos⁡θk≤c2∥gk∥/∥dk∥c_1\|g_k\|/\|d_k\| \le \cos\theta_k \le c_2\|g_k\|/\|d_k\|c1​∥gk​∥/∥dk​∥≤cosθk​≤c2​∥gk​∥/∥dk​∥.

Further statements

Theorem 2.1 (ii) (the same conclusion for an ideal line search that does no worse than the first stationary point along dkd_kdk​) and the convergence of the hybrid method (3.7), βk=max⁡(−βkFR,min⁡(βkPR,βkFR))\beta_k = \max(-\beta_k^{FR}, \min(\beta_k^{PR}, \beta_k^{FR}))βk​=max(−βkFR​,min(βkPR​,βkFR​)).

Significance

Theorem 3.2 shows that descent and global convergence of Fletcher–Reeves-type methods do not depend on the exact formula for βk\beta_kβk​, only on the bound ∣βk∣≤βkFR|\beta_k| \le \beta_k^{FR}∣βk​∣≤βkFR​. Its main consequence is the hybrid method (3.7), which keeps the Polak–Ribière choice whenever it lies in [−βkFR,βkFR][-\beta_k^{FR}, \beta_k^{FR}][−βkFR​,βkFR​], and so retains the practical efficiency of Polak–Ribière while inheriting the convergence guarantee of Fletcher–Reeves. Lemma 3.1 also shows that, under these conditions, descent need not be enforced by the line search.

The results are proved in the paper. To our knowledge none of them, nor Zoutendijk's theorem for general iterations, has a machine-checked proof in Lean; Mathlib has no theory of line search methods. A formalization would provide a reusable Zoutendijk theorem for any descent method with Wolfe steps, and a verified convergence statement for the conjugate gradient methods used in practice.

Difficulty

The obvious route to convergence of a descent method is to show cos⁡θk\cos\theta_kcosθk​ bounded away from zero and apply Zoutendijk's condition. For conjugate gradient methods this fails: dkd_kdk​ accumulates previous directions and cos⁡θk\cos\theta_kcosθk​ can tend to zero. The argument must instead control the growth of ∥dk∥\|d_k\|∥dk​∥, which requires bounding ⟨gk,dk−1⟩\langle g_k, d_{k-1}\rangle⟨gk​,dk−1​⟩ through the line search, and this in turn requires knowing that every dkd_kdk​ is a descent direction with ⟨gk,dk⟩\langle g_k, d_k\rangle⟨gk​,dk​⟩ comparable to ∥gk∥2\|g_k\|^2∥gk​∥2. The threshold σ2<12\sigma_2 < \tfrac12σ2​<21​ is exactly what keeps the geometric series in these bounds below 222; the result fails without it.

Formalization scope

All items live in the namespace NonlinCG.FRBound. The space is a finite-dimensional real inner product space E (the paper uses "the scalar product used to compute the gradient"), and gradient f is the gradient for that product. Conventions committed to:

  • Indexing follows the paper: sequences ℕ → E, used from index 1; index 0 is never constrained.
  • Smoothness: every statement assumes fff globally C1C^1C1, from (1.1) "f is smooth", in addition to Assumptions 2.1 (bounded level set; C1C^1C1 and Lipschitz gradient on an open neighbourhood N\mathcal NN of L\mathcal LL, with L>0L > 0L>0).
  • Steplengths are positive, as in the paper's line searches.
  • βk\beta_kβk​ is a free sequence constrained by ∣βk∣≤βkFR|\beta_k| \le \beta_k^{FR}∣βk​∣≤βkFR​, not the Fletcher–Reeves formula. Fixing βk=βkFR\beta_k = \beta_k^{FR}βk​=βkFR​ would state Al-Baali's theorem instead.
  • Division: βFR\beta^{FR}βFR, βPR\beta^{PR}βPR, cos⁡θk\cos\theta_kcosθk​ are Lean divisions (value 0 on a zero denominator). Theorem 3.2 does not assume gk≠0g_k \ne 0gk​=0; Lemma 3.1 and (3.5) assume it, since the paper divides by ∥gk∥2\|g_k\|^2∥gk​∥2 there and descent is impossible at gk=0g_k = 0gk​=0.
  • Zoutendijk's sum is the summability of ⟨gk,dk⟩2/∥dk∥2\langle g_k, d_k\rangle^2/\|d_k\|^2⟨gk​,dk​⟩2/∥dk​∥2, which equals cos⁡2θk∥gk∥2\cos^2\theta_k\|g_k\|^2cos2θk​∥gk​∥2 under descent.
  • liminf is stated as: for every ε>0\varepsilon > 0ε>0 and KKK there is k≥Kk \ge Kk≥K with ∥gk∥<ε\|g_k\| < \varepsilon∥gk​∥<ε.
  • (3.5) asserts existence of the constants only, as the paper does.

The goal does not assume Zoutendijk's condition or descent: both are consequences (Theorem 2.1 and Lemma 3.1) and assuming either would remove part of the theorem's content. The hypotheses are jointly satisfiable (for f(x)=x2/2f(x) = x^2/2f(x)=x2/2 on R\mathbb RR, x1=1x_1 = 1x1​=1, βk=0\beta_k = 0βk​=0, αk=0.9\alpha_k = 0.9αk​=0.9, σ1=0.1\sigma_1 = 0.1σ1​=0.1, σ2=0.25\sigma_2 = 0.25σ2​=0.25), so the goal is not vacuous.

Needed infrastructure: line-search conditions, the descent lemma for functions with Lipschitz gradient on a set, and summability arguments for ∑∥dk∥−2\sum\|d_k\|^{-2}∑∥dk​∥−2. Zoutendijk's theorem is reusable for any descent method. Proofs of any item, and alternative arguments, are welcome.

Selected references

  • J. C. Gilbert, J. Nocedal, Global convergence properties of conjugate gradient methods for optimization, INRIA Rapport de Recherche 1268, 1990. https://hal.inria.fr/inria-00075291 ; SIAM J. Optim. 2(1) (1992) 21–42, https://doi.org/10.1137/0802003
  • M. Al-Baali, Descent property and global convergence of the Fletcher–Reeves method with inexact line search, IMA J. Numer. Anal. 5 (1985) 121–124. https://doi.org/10.1093/imanum/5.1.121
  • R. Fletcher, C. M. Reeves, Function minimization by conjugate gradients, Comput. J. 7 (1964) 149–154. https://doi.org/10.1093/comjnl/7.2.149
  • P. Wolfe, Convergence conditions for ascent methods, SIAM Rev. 11 (1969) 226–235. https://doi.org/10.1137/1011036
  • D. Touati-Ahmed, C. Storey, Efficient hybrid conjugate gradient techniques, J. Optim. Theory Appl. 64 (1990) 379–397. https://doi.org/10.1007/BF00939455
5 thms1 active userReviewed
Algorithmic Game TheoryComplexity TheoryLinear Optimization·Captain: mikedeng1

The Polynomial Hierarchy and a Simple Model for Competitive Analysis: Every Optimum of the (p+1)-Level Linear Game J'(F) Is Binary, with x(F) = 1 iff the Σ_p Sentence (3.3) HoldsResearch Paper

Why multi-level programs are hard

Multi-level programs model a hierarchy of decision makers: a leader commits to a decision, a follower optimises given it, a follower of the follower optimises given both, and so on. Bilevel programs are the standard model of Stackelberg competition, toll setting, network interdiction and many other leader–follower problems in operations research (Candler and Townsley 1982; Bard and Falk 1982). When every level has a linear criterion and the constraints are linear, each player's problem looks like a linear program, and it is natural to hope that the whole hierarchy is solvable in polynomial time.

R. G. Jeroslow's 1985 paper (Math. Programming 32, 146–164) shows that this hope fails at every level of the polynomial hierarchy: a (p+1)(p+1)(p+1)-level linear program with fixed criteria can encode the truth of a Σp\Sigma_pΣp​ quantified Boolean sentence. The result places multi-level linear programming in the polynomial hierarchy and is widely cited for the Σp\Sigma_pΣp​-hardness of such programs; NP-hardness of bilevel linear programs (Corollary 4.6) is its special case p=1p=1p=1.

Setting

A multi-level program has real variables x=(x1,…,xp)x=(x^1,\dots,x^p)x=(x1,…,xp), a feasible set S0S_0S0​ (a polyhedron {x:∑iAixi≥b}\{x: \sum_i A^ix^i\ge b\}{x:∑i​Aixi≥b} in the linear case), and players p,p−1,…,1p,p-1,\dots,1p,p−1,…,1 who move in that order; player iii controls xix^ixi and minimises a fixed linear criterion cixc^ixcix. The solution sets are defined from the last mover upwards: S1S_1S1​ is the set of x∈S0x\in S_0x∈S0​ at which player 1's criterion is minimal given the choices of all earlier movers, and in general SjS_{j}Sj​ keeps the points of Sj−1S_{j-1}Sj−1​ minimising cjxc^jxcjx among the points of Sj−1S_{j-1}Sj−1​ that agree with xxx on xj+1,…,xpx^{j+1},\dots,x^pxj+1,…,xp. The value is cpxc^pxcpx on SpS_pSp​, when Sp≠∅S_p\neq\emptysetSp​=∅. The sets SjS_jSj​ can be empty even when S0S_0S0​ is a nonempty polytope: the paper's four-level Example has S4=∅S_4=\emptysetS4​=∅ because S3S_3S3​ is not closed.

A propositional formula FFF over blocks of atoms X1,…,XpX_1,\dots,X_pX1​,…,Xp​ (block XkX_kXk​ has nkn_knk​ atoms) is encoded by the linear system LFL_FLF​: one variable x(G)∈[0,1]x(G)\in[0,1]x(G)∈[0,1] per non-atomic subformula, with the inequalities (3.1a)–(3.1c) for ∨\vee∨, ∧\wedge∧, ¬\neg¬. The quantifier of block XkX_kXk​ is Qk=∃Q_k=\existsQk​=∃ when p−kp-kp−k is even, so

(∃Xp)(∀Xp−1)⋯(Q1X1) [F(X1,…,Xp)=1](3.3)(\exists X_p)(\forall X_{p-1})\cdots(Q_1X_1)\,[F(X_1,\dots,X_p)=1] \qquad (3.3)(∃Xp​)(∀Xp−1​)⋯(Q1​X1​)[F(X1​,…,Xp​)=1](3.3)

is a Σp\Sigma_pΣp​ sentence.

The game J′(F)J'(F)J′(F) adds a bookkeeper, player 000, who moves last. Player k≥1k\ge1k≥1 controls the atoms of XkX_kXk​, and player 111 also controls auxiliary variables yyy; the bookkeeper controls the x(G)x(G)x(G), a variable uuu fixed to 111, and auxiliary variables zzz. Two gadgets, (4.1) and (4.6), let the bookkeeper and player 1 turn the linear criteria into the piecewise-linear functions Zk=1−x(F)+2∑jP(xkj)Z_k=1-x(F)+2\sum_jP(x_{kj})Zk​=1−x(F)+2∑j​P(xkj​) (or x(F)+…x(F)+\dotsx(F)+… for universal QkQ_kQk​) and Z1=(1−x(F))+fr(1−x(F))+10L∑jfr(x1j)+…Z_1=(1-x(F))+fr(1-x(F))+10L\sum_j fr(x_{1j})+\dotsZ1​=(1−x(F))+fr(1−x(F))+10L∑j​fr(x1j​)+…, where LLL is the length of FFF, fr(x)=min⁡{x,1−x}fr(x)=\min\{x,1-x\}fr(x)=min{x,1−x}, and P(x)=1P(x)=1P(x)=1 at x∈{0,1}x\in\{0,1\}x∈{0,1}, 222 otherwise.

Formalization targets

Goal: Theorem 4.5 (p≥2p\ge2p≥2)

Let SSS be the set of optimal solutions Sp+1S_{p+1}Sp+1​ of J′(F)J'(F)J′(F). Then S≠∅S\neq\emptysetS=∅; at every optimum all atom variables and all x(G)x(G)x(G) are binary; and

x(F)=1  ⟺  (3.3) holds,value(J′(F))=2np+1−x(F).x(F)=1 \iff (3.3)\ \text{holds},\qquad \text{value}(J'(F)) = 2n_p+1-x(F).x(F)=1⟺(3.3) holds,value(J′(F))=2np​+1−x(F).

Moreover, when (3.3) holds, v∈Rnpv\in\mathbb R^{n_p}v∈Rnp​ is player ppp's block in some optimum iff vvv is binary and the Πp−1\Pi_{p-1}Πp−1​ sentence (4.17) holds at the truth valuation of vvv.

Milestones

In attack order: Lemma 3.1 (correctness of LFL_FLF​ on binary inputs); Lemma 4.1 (robustness of LFL_FLF​ near binary inputs); Lemmas 4.2 and 4.3 (the bottom two levels of a bounded linear multi-level program are solvable, via LP duality); the bookkeeper identities z=∣2y−x∣z=|2y-x|z=∣2y−x∣ and z=fr(x)z=fr(x)z=fr(x) in S1S_1S1​; (4.2) and (4.3) (player 1's and player kkk's responses on the gadgets); Lemma 4.4 (the induction on kkk with the higher blocks fixed). Companion theorems: Corollary 4.6 (the bilevel case: value 000 iff (∃X1)F(\exists X_1)F(∃X1​)F), the §2 Example, and Proposition 3.2 (the pure binary game J(F)J(F)J(F)).

Significance

The theorem shows that deciding the value of a (p+1)(p+1)(p+1)-level linear program with fixed criteria is at least as hard as deciding Σp\Sigma_pΣp​ sentences, so known exact algorithms for multi-level linear programs cannot be expected to run in polynomial time once p≥2p\ge2p≥2, and even recognising an optimal move is Πp−1\Pi_{p-1}Πp−1​-hard. The bilevel case is an early NP-hardness proof for bilevel linear programming, and the construction (a bookkeeper player and absolute-value gadgets that force binary choices) is a template for hardness reductions to leader–follower problems.

The result is proved in the paper but, to our knowledge, has no machine-checked formalization. A formal development makes precise the solution concept (conditional rather than lexicographic minimisation), which the literature states in several inequivalent ways, and checks a proof whose printed version leaves cases to the reader (the ∧\wedge∧, ¬\neg¬ cases of Lemma 4.1, the universal cases of Lemma 4.4) and applies Lemma 4.3 to a feasible set that is unbounded (the (4.1) variable zzz has no upper bound).

Difficulty

The obvious argument, "each existential player picks a satisfying assignment and each universal player a counterexample", works for the pure binary game J(F)J(F)J(F) (Proposition 3.2) but not for continuous variables: a player may choose fractional values, and the solution sets of a multi-level program need not exist (the §2 Example). The work is in showing that every player is forced to binary choices. Player 1's fractional choices are ruled out only through the robustness estimate of Lemma 4.1 with the weight 10L10L10L, and the existence of optimal solutions at every level has to be established along the induction, since it fails for general three-level programs.

Formalization scope

  • Players are indexed from 000; player iii optimises at level i+1i+1i+1. In J′(F)J'(F)J′(F) the players are 0,…,p0,\dots,p0,…,p as in the paper; in the §2 Example and in J(F)J(F)J(F) the paper's player iii is index i−1i-1i−1. Blocks are 0-based: block k : Fin p is the paper's Xk+1X_{k+1}Xk+1​, owned by player k+1k+1k+1 in J′(F)J'(F)J′(F).
  • solSet encodes the conditional minimisation of (3.7), p. 152. HasValue N w requires SN≠∅S_N\neq\emptysetSN​=∅; the value +∞+\infty+∞ is not modelled.
  • Formulas use ¬,∧,∨\neg,\wedge,\vee¬,∧,∨ (the paper rewrites →\to→ as ¬G1∨G2\neg G_1\vee G_2¬G1​∨G2​); the length counts atoms and connectives. Data are real; the paper's rationality assumption plays no role in the statements.
  • The bookkeeper controls the x(G)x(G)x(G) and has criterion "+z+z+z on (4.1) gadgets, −z-z−z on (4.6) gadgets, and +x(G)+x(G)+x(G) for each non-atomic subformula," as stated on p. 155. The (4.1) variable zzz has no upper bound. The constant 111 of (4.4)/(4.7) is the variable uuu with u=1u=1u=1.
  • "Binary value, zero iff F∈BpF\in B_pF∈Bp​" is stated exactly: the value is 2np+1−x(F)2n_p+1-x(F)2np​+1−x(F), and x(F)=1x(F)=1x(F)=1 iff (3.3). "All optimal solutions are binary" covers the atom variables and the x(G)x(G)x(G), not the gadget variable zzz, which equals 222 at y=1y=1y=1, ξ=0\xi=0ξ=0.
  • The goal is not trivialisable: its first conjunct asserts that the optimal set is nonempty, which fails for general multi-level programs (the §2 Example), so the remaining conjuncts are not vacuous.

A complete development needs a linear-programming duality argument for Lemma 4.2 (Mathlib has IsExtreme and Set.extremePoints; LP duality is on the platform as a single-level theorem) and an induction over the levels of the game. The definitions MultilevelProgram, solSet and the formula encoding LSys are reusable for other complexity results on hierarchical optimisation. Proofs of any milestone, including the generic Lemmas 4.2–4.3 and the formula Lemmas 3.1 and 4.1, are welcome independently.

Selected references

  • R. G. Jeroslow, The polynomial hierarchy and a simple model for competitive analysis, Mathematical Programming 32 (1985) 146–164. https://doi.org/10.1007/BF01586088
  • W. Candler and R. Townsley, A linear two-level programming problem, Computers & Operations Research 9 (1982) 59–76. https://doi.org/10.1016/0305-0548(82)90006-5
  • J. F. Bard and J. E. Falk, An explicit solution to the multi-level programming problem, Computers & Operations Research 9 (1982) 77–100. https://doi.org/10.1016/0305-0548(82)90007-7
  • L. J. Stockmeyer, The polynomial-time hierarchy, Theoretical Computer Science 3 (1976) 1–22. https://doi.org/10.1016/0304-3975(76)90061-X
13 thms1 active userReviewed
ProbabilityStochastic Systems·Captain: mikedeng1

Shock Models and Wear Processes III: The First Passage Time of a Nondecreasing Markov Wear Process Above a Fixed Level Has an IHRA DistributionResearch Paper

Motivation

Reliability theory classifies life distributions by how they age. A device whose failure rate tends to increase over time is "wearing out", and the class of distributions with increasing hazard rate average (IHRA) is the one that is closed under forming coherent systems of independent components (Birnbaum, Esary and Marshall, 1966). This makes IHRA the natural ageing class for systems. It also raises a question: which physical failure mechanisms produce IHRA lives?

Esary, Marshall and Proschan's paper Shock Models and Wear Processes (Ann. Probability 1, 1973) answers this for two kinds of mechanism. In the first, damage arrives in discrete amounts at the epochs of a Poisson process of shocks. In the second, damage accumulates continuously. In both, the device fails when the accumulated damage first exceeds a fixed capacity. This mission covers the second kind: a wear process {Z(t),t≥0}\{Z(t), t \ge 0\}{Z(t),t≥0} and its first passage time above a level. The paper shows that the first passage time is IHRA under three qualitative conditions: wear starts at zero and only grows, the process is Markov, and accumulated wear and age make further wear more likely. Nothing else is assumed about the law of the wear.

A short timeline. Birnbaum, Esary and Marshall (1966) introduced the IHRA class and proved it is closed under coherent systems. Morey (1965) studied first passage times of wear processes under an extra monotonicity assumption. Esary, Marshall and Proschan (1973), §4, proved the IHRA property first for Poisson shocks with i.i.d. damages (Corollary 4.2, (4.7)), then for dependent damages (Lemma 4.1b, (4.7b)), and finally for continuous wear (Theorem 4.10).

Setting

Let (Ω,F,P)(\Omega, \mathcal F, P)(Ω,F,P) be a probability space. "Decreasing" means non-increasing throughout.

A survival function Fˉ\bar FFˉ is IHRA if t↦[Fˉ(t)]1/tt \mapsto [\bar F(t)]^{1/t}t↦[Fˉ(t)]1/t is decreasing on t>0t > 0t>0 (p. 631). For an exponential life, [Fˉ(t)]1/t[\bar F(t)]^{1/t}[Fˉ(t)]1/t is constant. IHRA says the average failure rate over [0,t][0, t][0,t] never decreases.

Dependent damages. Let X1,X2,…X_1, X_2, \dotsX1​,X2​,… be nonnegative random variables, the damages caused by successive shocks, and let Z0=0Z_0 = 0Z0​=0 and Zk=X1+⋯+XkZ_k = X_1 + \dots + X_kZk​=X1​+⋯+Xk​. The paper's conditions (p. 636) are:

  • (4.3) the conditional law of XkX_kXk​ given X1,…,Xk−1X_1, \dots, X_{k-1}X1​,…,Xk−1​ depends only on Zk−1Z_{k-1}Zk−1​;
  • (4.4) P{Xk≤u∣Zk−1=z}P\{X_k \le u \mid Z_{k-1} = z\}P{Xk​≤u∣Zk−1​=z} is decreasing in z≥0z \ge 0z≥0 (accumulated damage lowers resistance);
  • (4.5) P{Xk≤u∣Zk−1=z}≥P{Xk+1≤u∣Zk=z}P\{X_k \le u \mid Z_{k-1} = z\} \ge P\{X_{k+1} \le u \mid Z_k = z\}P{Xk​≤u∣Zk−1​=z}≥P{Xk+1​≤u∣Zk​=z} for z≥0z \ge 0z≥0 (later shocks are more severe).

Wear process. Z(t)Z(t)Z(t) is the wear accumulated in [0,t][0, t][0,t]. The conditions (pp. 640–641) are:

  • (4.8) Z(0)=0Z(0) = 0Z(0)=0 and Z(t+Δ)−Z(t)≥0Z(t + \Delta) - Z(t) \ge 0Z(t+Δ)−Z(t)≥0 for all t,Δ≥0t, \Delta \ge 0t,Δ≥0, with probability one;
  • (4.9) {Z(t),t≥0}\{Z(t), t \ge 0\}{Z(t),t≥0} is a Markov process;
  • (4.10) P{Z(t+Δ)−Z(t)≤u∣Z(t)=z}P\{Z(t + \Delta) - Z(t) \le u \mid Z(t) = z\}P{Z(t+Δ)−Z(t)≤u∣Z(t)=z} is decreasing in both zzz and ttt in the region t≥0t \ge 0t≥0, z≥0z \ge 0z≥0, Δ≥0\Delta \ge 0Δ≥0.

The first passage time above a level xxx is Tx=inf⁡{t:Z(t)>x}T_x = \inf\{t : Z(t) > x\}Tx​=inf{t:Z(t)>x}. Its survival function is Hˉx(t)=P{Tx>t}\bar H_x(t) = P\{T_x > t\}Hˉx​(t)=P{Tx​>t}, and Ft(x)=P{Z(t)≤x}F_t(x) = P\{Z(t) \le x\}Ft​(x)=P{Z(t)≤x} is the distribution function of the wear at time ttt.

Formalization targets

Goal: Theorem 4.10 (p. 641)

If {Z(t),t≥0}\{Z(t), t \ge 0\}{Z(t),t≥0} satisfies (4.8), (4.9) and (4.10), then for every level xxx

t⟼[Hˉx(t)]1/t is decreasing on t>0,t \longmapsto \big[\bar H_x(t)\big]^{1/t} \text{ is decreasing on } t > 0,t⟼[Hˉx​(t)]1/t is decreasing on t>0,

that is, TxT_xTx​ has an IHRA distribution.

Milestones

  1. Lemma 4.1b (p. 637): under (4.3)–(4.5), [P{X1+⋯+Xk≤x}]1/k[P\{X_1 + \dots + X_k \le x\}]^{1/k}[P{X1​+⋯+Xk​≤x}]1/k is decreasing in k=1,2,…k = 1, 2, \dotsk=1,2,….
  2. Proof of Theorem 4.10, first claim (a): for Δ>0\Delta > 0Δ>0, the grid increments Xi=Z(iΔ)−Z((i−1)Δ)X_i = Z(i\Delta) - Z((i-1)\Delta)Xi​=Z(iΔ)−Z((i−1)Δ) satisfy (4.3)–(4.5).
  3. Proof of Theorem 4.10, first claim (b): [FkΔ(x)]1/(kΔ)[F_{k\Delta}(x)]^{1/(k\Delta)}[FkΔ​(x)]1/(kΔ) is decreasing in k=1,2,…k = 1, 2, \dotsk=1,2,….
  4. Proof of Theorem 4.10, second claim: [Fs(x)]1/s≥[Ft(x)]1/t[F_s(x)]^{1/s} \ge [F_t(x)]^{1/t}[Fs​(x)]1/s≥[Ft​(x)]1/t whenever 0<s≤t0 < s \le t0<s≤t.
  5. Proof of Theorem 4.10, third claim: Hˉx(t)=lim⁡ε↓0Ft+ε(x)\bar H_x(t) = \lim_{\varepsilon \downarrow 0} F_{t+\varepsilon}(x)Hˉx​(t)=limε↓0​Ft+ε​(x), under (4.8) alone.

An optional extra item states Corollary 4.2 (4.7b): Poisson shocks of rate λ>0\lambda > 0λ>0 with damages satisfying (4.3)–(4.5) give an IHRA life Hˉ(t)=∑ke−λt(λt)k/k!⋅P{Zk≤x}\bar H(t) = \sum_k e^{-\lambda t} (\lambda t)^k / k! \cdot P\{Z_k \le x\}Hˉ(t)=∑k​e−λt(λt)k/k!⋅P{Zk​≤x}.

Significance

The result. Theorem 4.10 derives an ageing property of a failure time from qualitative properties of the damage process alone: no distributional form, no stationarity and no independence of increments is assumed. Together with the closure of IHRA under coherent systems, this lets a reliability engineer conclude that a system built from components failing by wear has an IHRA life. Examples include processes with nonnegative stationary independent increments started at the origin, such as compound Poisson processes and infinitesimal renewal processes (p. 641). Lemma 4.1b is the discrete analogue: a sequence of probabilities Pˉk\bar P_kPˉk​ with Pˉk1/k\bar P_k^{1/k}Pˉk1/k​ decreasing is what Theorem 3.1 (3.4) needs to give an IHRA life under Poisson shocks.

Formalizing it. The results are proved in the paper. As far as we know none of them has been machine-checked. The formalization needs, and would make reusable, a statement of the Markov property for a continuous-time real process in terms of Mathlib's conditional expectation, versions of conditional distributions with monotonicity constraints, and the passage from a discrete-time grid to continuous time for first passage times. Each of these is a step a probabilist writes in one line and a proof assistant does not.

Difficulty

The paper's proof is short, but every sentence hides a measure-theoretic step. The first claim, that the grid increments satisfy (4.3)–(4.5), requires turning the Markov property and the monotonicity of the increment law into conditional laws of Xk+1X_{k+1}Xk+1​ given (X1,…,Xk)(X_1, \dots, X_k)(X1​,…,Xk​). Those conditional laws are defined only almost everywhere, and the monotonicity must be preserved along the way. Lemma 4.1b itself is an induction that integrates the monotonicity conditions against the law of ZkZ_kZk​. The extension from rational to arbitrary ratios s/ts/ts/t uses the monotonicity of paths. The identification of Hˉx(t)\bar H_x(t)Hˉx​(t) as a right limit of Ft+ε(x)F_{t+\varepsilon}(x)Ft+ε​(x) needs the pathwise reading of (4.8). The natural first idea, approximating ZZZ by a compound Poisson process, would add hypotheses the theorem does not have.

Formalization scope

All objects sit in the namespace ShockWear.WearProcess, in one definition file. The committed conventions:

  • Probability space. A measure pr with IsProbabilityMeasure. Time is R≥0\mathbb R_{\ge 0}R≥0​; Z:R≥0→Ω→RZ : \mathbb R_{\ge0} \to \Omega \to \mathbb RZ:R≥0​→Ω→R with every Z(t)Z(t)Z(t) measurable.
  • (4.8) is read pathwise. Almost every path has Z(0)=0Z(0) = 0Z(0)=0 and is nondecreasing. The paper's "for all t,Δ≥0t, \Delta \ge 0t,Δ≥0 with probability one" is ambiguous in quantifier order; this reading is the one used by the proof's equivalence "Tx>tT_x > tTx​>t iff Z(t+ε)≤xZ(t+\varepsilon) \le xZ(t+ε)≤x for some ε>0\varepsilon > 0ε>0".
  • (4.9) is the Markov property for the natural filtration σ(Z(r),r≤s)\sigma(Z(r), r \le s)σ(Z(r),r≤s): P(Z(t)∈B∣Fs)=P(Z(t)∈B∣Z(s))P(Z(t) \in B \mid \mathcal F_s) = P(Z(t) \in B \mid Z(s))P(Z(t)∈B∣Fs​)=P(Z(t)∈B∣Z(s)) a.s. for s≤ts \le ts≤t and Borel BBB.
  • Conditional probabilities are explicit versions. P{Xk+1≤u∣Zk=z}P\{X_{k+1} \le u \mid Z_k = z\}P{Xk+1​≤u∣Zk​=z} and P{Z(t+Δ)−Z(t)≤u∣Z(t)=z}P\{Z(t+\Delta) - Z(t) \le u \mid Z(t) = z\}P{Z(t+Δ)−Z(t)≤u∣Z(t)=z} are the values on (−∞,u](-\infty, u](−∞,u] of Markov kernels κ\kappaκ that agree almost everywhere with Mathlib's condDistrib. The monotonicity conditions (4.4), (4.5), (4.10) are imposed on these versions, on the paper's regions z≥0z \ge 0z≥0, t≥0t \ge 0t≥0. "Is decreasing in zzz" is read as "has a version decreasing in zzz".
  • Nonnegativity of damages is almost sure.
  • Index base. Lean's X i is the paper's Xi+1X_{i+1}Xi+1​, and the kernel κ k describes Xk+1X_{k+1}Xk+1​ given ZkZ_kZk​.
  • First passage time TxT_xTx​ takes values in [0,∞][0, \infty][0,∞] and may be infinite with positive probability; it is not assumed finite. Hˉx(t)=1\bar H_x(t) = 1Hˉx​(t)=1 for t<0t < 0t<0. The level xxx ranges over all reals.
  • Powers [ ⋅ ]1/t[\,\cdot\,]^{1/t}[⋅]1/t, [ ⋅ ]1/k[\,\cdot\,]^{1/k}[⋅]1/k, [ ⋅ ]1/(kΔ)[\,\cdot\,]^{1/(k\Delta)}[⋅]1/(kΔ) are real powers with real exponents.

Trivializing formalizations are ruled out: (4.9) and (4.10) are not replaced by independence or stationarity of increments, nor by a compound Poisson model. Those are examples (p. 641), not hypotheses. Monotonicity is never imposed on Mathlib's condDistrib itself, whose values off the support of Z(t)Z(t)Z(t) are unconstrained. A sorry-free local check confirms the hypotheses are satisfiable: the deterministic process Z(t)=tZ(t) = tZ(t)=t satisfies (4.8)–(4.10), and constant damages satisfy (4.3)–(4.5).

Contributions are welcome on any milestone. The reduction (milestone 2) and the induction of Lemma 4.1b are the substantial parts. Lemmas about versions of conditional distributions under Markov processes would be reusable well beyond this mission.

Selected references

  • J. D. Esary, A. W. Marshall and F. Proschan, Shock Models and Wear Processes, Ann. Probability 1(4) (1973) 627–649. https://doi.org/10.1214/aop/1176996891
  • Z. W. Birnbaum, J. D. Esary and A. W. Marshall, A Stochastic Characterization of Wear-out for Components and Systems, Ann. Math. Statist. 37 (1966) 816–825. https://doi.org/10.1214/aoms/1177699362
  • R. C. Morey, Stochastic Wear Processes, Technical Report ORC 65-16, Operations Research Center, University of California, Berkeley, 1965 (cited on p. 640 of Esary, Marshall and Proschan).
  • R. E. Barlow and F. Proschan, Statistical Theory of Reliability and Life Testing, Holt, Rinehart and Winston, 1975.
7 thms1 active userReviewed
ProbabilityStochastic Systems·Captain: mikedeng1

Shock Models and Wear Processes IV: With a Random Threshold, Shock Survival Probabilities Are Submultiplicative for Every Damage Law Iff the Threshold Is NBUResearch Paper

Motivation

Reliability theory classifies life distributions by how they age. A device whose remaining life, once it has survived to age ttt, is stochastically shorter than the life of a new device is called new better than used (NBU). The NBU class, together with the classes IHR (increasing hazard rate) and IHRA (increasing hazard rate average), organizes much of the theory of maintenance and replacement: Marshall and Proschan showed that the NBU property is what makes certain replacement policies beneficial, and Barlow and Proschan's monographs build the statistical theory of reliability on these classes.

A question that runs through this literature is where such ageing properties come from physically. Esary, Marshall and Proschan (Ann. Probability 1973) answer it for shock models: a device is hit by shocks arriving in time as a Poisson process, each shock adds a random amount of damage, and the device fails when the accumulated damage exceeds its threshold. Section 4 of their paper treats a fixed threshold and shows that the life is IHRA for every damage law. Section 5, the subject of this mission, lets the threshold itself be random, which models the variation between individual items of a production lot. It then asks which ageing properties of the threshold law are inherited by the life distribution, and which are forced if the inheritance is to hold whatever the damage law.

Setting

All distributions are laws of non-negative random variables. For a distribution FFF on R\mathbb RR with F(z)=0F(z) = 0F(z)=0 for z<0z < 0z<0 (a damage law), F(k)F^{(k)}F(k) denotes the kkk-fold convolution of FFF, with F(0)F^{(0)}F(0) the point mass at 000; thus F(k)(x)=P{X1+⋯+Xk≤x}F^{(k)}(x) = P\{X_1 + \cdots + X_k \le x\}F(k)(x)=P{X1​+⋯+Xk​≤x} for independent Xi∼FX_i \sim FXi​∼F.

A threshold law is a distribution GGG with G(z)=0G(z) = 0G(z)=0 for z<0z < 0z<0; write Gˉ=1−G\bar G = 1 - GGˉ=1−G for its survival function. If the threshold Y∼GY \sim GY∼G is independent of the damages, the probability of surviving kkk shocks is

Pˉk=∫0∞F(k)(x) dG(x)=P{X1+⋯+Xk≤Y},k=0,1,…(5.1)\bar P_k = \int_0^\infty F^{(k)}(x)\, dG(x) = P\{X_1 + \cdots + X_k \le Y\}, \qquad k = 0, 1, \dots \tag{5.1}Pˉk​=∫0∞​F(k)(x)dG(x)=P{X1​+⋯+Xk​≤Y},k=0,1,…(5.1)

If shocks arrive as a Poisson process of rate λ>0\lambda > 0λ>0, the device's life distribution HHH has survival function

Hˉ(t)=∑k=0∞e−λt(λt)kk! Pˉk,t≥0.(5.2)\bar H(t) = \sum_{k=0}^\infty e^{-\lambda t}\frac{(\lambda t)^k}{k!}\,\bar P_k, \qquad t \ge 0. \tag{5.2}Hˉ(t)=k=0∑∞​e−λtk!(λt)k​Pˉk​,t≥0.(5.2)

A survival function Fˉ\bar FFˉ is NBU if Fˉ(t+x)≤Fˉ(x)Fˉ(t)\bar F(t + x) \le \bar F(x)\bar F(t)Fˉ(t+x)≤Fˉ(x)Fˉ(t) for all x,t≥0x, t \ge 0x,t≥0; it is IHR if Fˉ(x+t)/Fˉ(t)\bar F(x + t)/\bar F(t)Fˉ(x+t)/Fˉ(t) is non-increasing in ttt for each x>0x > 0x>0, and IHRA if [Fˉ(t)]1/t[\bar F(t)]^{1/t}[Fˉ(t)]1/t is non-increasing in t>0t > 0t>0. The discrete analogue of NBU for the sequence Pˉk\bar P_kPˉk​ is submultiplicativity, Pˉj+k≤PˉjPˉk\bar P_{j+k} \le \bar P_j \bar P_kPˉj+k​≤Pˉj​Pˉk​.

Formalization targets

Goal: Theorem 5.3

For a threshold law GGG with G(z)=0G(z) = 0G(z)=0 for z<0z < 0z<0:

(∀F: Pˉj+k≤Pˉj Pˉk  ∀j,k≥0)  ⟺  Gˉ is NBU,\Big(\forall F:\ \bar P_{j+k} \le \bar P_j\,\bar P_k \ \ \forall j,k \ge 0\Big) \iff \bar G \text{ is NBU},(∀F: Pˉj+k​≤Pˉj​Pˉk​  ∀j,k≥0)⟺Gˉ is NBU,

the quantifier ranging over every damage law FFF; and if GGG is NBU, then for every damage law FFF and every λ>0\lambda > 0λ>0 the life distribution HHH of (5.2) is NBU.

Milestones

  1. Theorem 3.1 (3.5). For any sequence 1=Pˉ0≥Pˉ1≥⋯≥01 = \bar P_0 \ge \bar P_1 \ge \cdots \ge 01=Pˉ0​≥Pˉ1​≥⋯≥0 and λ>0\lambda > 0λ>0: if PˉjPˉk≥Pˉj+k\bar P_j \bar P_k \ge \bar P_{j+k}Pˉj​Pˉk​≥Pˉj+k​ for all j,kj, kj,k, then HHH of (2.1) is NBU.
  2. First display of the proof of Theorem 5.3. If GGG is NBU, then Pˉj+k≤PˉjPˉk\bar P_{j+k} \le \bar P_j \bar P_kPˉj+k​≤Pˉj​Pˉk​ for each damage law FFF.
  3. Second display of the proof of Theorem 5.3. If submultiplicativity holds for every FFF, then Gˉ(s+jxk)≤Gˉ(s) Gˉ(jxk)\bar G(s + j x_k) \le \bar G(s)\,\bar G(j x_k)Gˉ(s+jxk​)≤Gˉ(s)Gˉ(jxk​) for s>0s > 0s>0, xk=s/kx_k = s/kxk​=s/k, j=0,1,…j = 0, 1, \dotsj=0,1,….

Further items (not milestones)

Theorem 5.1 (the life is exponential for every FFF iff GGG is exponential) and Theorem 5.2 (b), (c) (an IHR threshold makes Pˉk1/k\bar P_k^{1/k}Pˉk1/k​ non-increasing for every FFF; non-increasing Pˉk1/k\bar P_k^{1/k}Pˉk1/k​ for every FFF forces GGG to be IHRA) are posed as companion statements from the same section.

Significance

Theorem 5.3 is a characterization: the NBU class is exactly the class of threshold laws for which the cumulative-damage mechanism preserves the discrete NBU property under every damage law. Combined with Theorem 3.1 (3.5), it gives a physical derivation of NBU life distributions: an item with an NBU random strength, subject to Poisson shocks with arbitrary i.i.d. non-negative damage, has an NBU life. Theorems 5.1 and 5.2 place the exponential and the IHR/IHRA classes in the same framework, and the authors record that whether an IHRA threshold suffices in Theorem 5.2 (b) is left unresolved.

The results are proved in the paper. No machine-checked version is known to exist; this mission produces one. A complete development also supplies reusable infrastructure: convolution powers of laws on [0,∞)[0, \infty)[0,∞) as Mathlib measures, Poisson mixtures of a sequence, and the ageing classes of p. 631 as predicates on survival functions.

Difficulty

The equivalence couples a property of one function, Gˉ\bar GGˉ, to a family of inequalities indexed by every damage law, and the left side is about convolutions while the right side is pointwise. Two points make the statement harder than it looks. First, (5.1) as printed is P{X1+⋯+Xk≤Y}P\{X_1 + \cdots + X_k \le Y\}P{X1​+⋯+Xk​≤Y}, whereas the paper's proof works with EGˉ(X1+⋯+Xk)=P{X1+⋯+Xk<Y}E\bar G(X_1 + \cdots + X_k) = P\{X_1 + \cdots + X_k < Y\}EGˉ(X1​+⋯+Xk​)=P{X1​+⋯+Xk​<Y}; the two agree only when F(k)F^{(k)}F(k) and GGG have no common discontinuities, and they can disagree as soon as F(k)F^{(k)}F(k) has an atom where GGG has one, a case the left side of the equivalence includes. A formal proof cannot invoke that convention. Second, the second sentence of the theorem passes through a Poisson series (5.2) whose terms involve the whole sequence Pˉk\bar P_kPˉk​, so the NBU property of HHH is a statement about a power series in ttt, not about any single Pˉk\bar P_kPˉk​.

Formalization scope

  • A distribution is a probability measure on R\mathbb RR; "F(z)=0F(z) = 0F(z)=0 for z<0z < 0z<0" is mass 000 on (−∞,0)(-\infty, 0)(−∞,0), and "G(0)=0G(0) = 0G(0)=0" (Theorems 5.1, 5.2) is mass 000 on (−∞,0](-\infty, 0](−∞,0]. F(k)F^{(k)}F(k) is the kkk-fold Measure.conv power with F(0)=δ0F^{(0)} = \delta_0F(0)=δ0​, and F(k)(x)F^{(k)}(x)F(k)(x) is the mass of (−∞,x](-\infty, x](−∞,x].
  • Pˉk\bar P_kPˉk​ is (5.1) as printed, ∫F(k)(x) dG(x)\int F^{(k)}(x)\,dG(x)∫F(k)(x)dG(x) over R\mathbb RR; since GGG is carried by [0,∞)[0, \infty)[0,∞) this is ∫0∞\int_0^\infty∫0∞​ including an atom of GGG at 000, which Theorem 5.3 allows. The paper's convention that F(k)F^{(k)}F(k) and GGG have no common discontinuities is not added as a hypothesis: the statements hold for (5.1) without it. The integrand is monotone with values in [0,1][0,1][0,1], so the Bochner integral is a genuine expectation.
  • "For all FFF" sits inside the equivalence of Theorem 5.3 and ranges over every probability measure on [0,∞)[0, \infty)[0,∞). Submultiplicativity for one fixed FFF is a different, weaker statement.
  • NBU and IHR are cross-multiplied, agreeing with the paper's ratio form wherever denominators are positive (the paper restricts variables to avoid zero denominators). NBU is on x,t≥0x, t \ge 0x,t≥0 exactly as in definition (v). Powers [Gˉ(t)]1/t[\bar G(t)]^{1/t}[Gˉ(t)]1/t and Pˉk1/k\bar P_k^{1/k}Pˉk1/k​ are real powers. "Decreasing" means non-increasing.
  • HHH is the series (2.1) as a function on R\mathbb RR, equal to 111 on (−∞,0)(-\infty, 0)(−∞,0); λ>0\lambda > 0λ>0 as in (1.1). In Theorem 3.1 (3.5) the non-negativity Pˉk≥0\bar P_k \ge 0Pˉk​≥0 is stated explicitly.
  • In Theorem 5.1 "exponential" allows rate 000 for HHH (the damage law δ0\delta_0δ0​ gives Hˉ≡1\bar H \equiv 1Hˉ≡1) and requires a positive rate for GGG (G(0)=0G(0) = 0G(0)=0 rules out the degenerate case Gˉ=0\bar G = 0Gˉ=0 on (0,∞)(0,\infty)(0,∞)).
  • A trivializing formalization is ruled out: the threshold-law quantifier is not restricted to a class where both sides are automatic, the integral cannot collapse to a default value, and the NBU predicate is the paper's on [0,∞)[0, \infty)[0,∞), not on (0,∞)(0, \infty)(0,∞) or a vacuous domain.

Contributions welcome: proofs of the milestones, a library for Poisson mixtures and convolution powers of laws on [0,∞)[0,\infty)[0,∞), and the extra items of §5.

Selected references

  • J. D. Esary, A. W. Marshall and F. Proschan, Shock Models and Wear Processes, The Annals of Probability 1(4), 627–649, 1973. https://doi.org/10.1214/aop/1176996891
  • R. E. Barlow and F. Proschan, Mathematical Theory of Reliability, Wiley, 1965; reprinted SIAM Classics in Applied Mathematics, 1996. https://doi.org/10.1137/1.9781611971194
  • Z. W. Birnbaum, J. D. Esary and A. W. Marshall, A Stochastic Characterization of Wear-Out for Components and Systems, The Annals of Mathematical Statistics 37(4), 816–825, 1966. https://doi.org/10.1214/aoms/1177699362
5 thms1 active userReviewed
ProbabilityStochastic Systems·Captain: mikedeng1

The Relation between Customer and Time Averages in Queues: H = λG on Every Sample Path When 0 < λ < ∞, G < ∞ and Each f_n Vanishes Outside [t_n, t_n + s_n] with s_n/n → 0Research Paper

Motivation

Little's law L=λWL = \lambda WL=λW says that the long-run average number of customers in a system equals the arrival rate times the average time a customer spends there. It is one of the most used identities in queueing theory, and it holds on individual sample paths under weak conditions (Little 1961; Stidham 1974). Many quantities of interest are not head counts, however: the work in the system, the cost accumulated by customers in progress, the number of tokens a customer holds in some state. For these a more general relation is needed, between a time average HHH and a customer average GGG, of the form H=λGH = \lambda GH=λG.

Heyman and Stidham (Oper. Res. 28 (1980)) prove such a relation on each sample path, for an arbitrary real-valued function attached to each customer, under a support condition that is much weaker than the continuous-sojourn assumption of the L=λWL = \lambda WL=λW theorem. They then show by a counterexample that the support condition cannot simply be dropped, even when every customer function is an indicator.

Timeline.

  • 1961: Little proves L=λWL = \lambda WL=λW under stationarity assumptions (Little 1961).
  • 1971: Brumelle proves H=λGH = \lambda GH=λG under conditions (v.a), (v.b) on the tails of the fnf_nfn​ (J. Appl. Prob. 8, 508–520).
  • 1972: Stidham gives a new proof of L=λWL = \lambda WL=λW, including the lemma relating N(t)/tN(t)/tN(t)/t and tn/nt_n/ntn​/n (Stidham 1972).
  • 1974: Stidham proves L=λWL = \lambda WL=λW on each sample path, assuming each sojourn is one uninterrupted interval (Stidham 1974).
  • 1980: Heyman and Stidham prove H=λGH = \lambda GH=λG on every sample path under the support condition below, and give the counterexample. The paper notes that its Theorem 1 is weaker than the sample-path version of Brumelle's theorem, with hypotheses stated directly on the sample path.

Setting

Fix one sample path. Customers n=1,2,…n = 1, 2, \ldotsn=1,2,… arrive at epochs 0≤t1≤t2≤⋯0 \le t_1 \le t_2 \le \cdots0≤t1​≤t2​≤⋯; ties are allowed. The arrival count N(t)N(t)N(t) is the number of nnn with tn≤tt_n \le ttn​≤t, and the arrival rate is λ=lim⁡t→∞N(t)/t\lambda = \lim_{t\to\infty} N(t)/tλ=limt→∞​N(t)/t when the limit exists.

Customer nnn carries a real-valued function fnf_nfn​ on [0,∞)[0,\infty)[0,∞). Its total is gn=∫0∞fn(t) dtg_n = \int_0^\infty f_n(t)\,dtgn​=∫0∞​fn​(t)dt, and the rate is h(t)=∑n=1∞fn(t)h(t) = \sum_{n=1}^\infty f_n(t)h(t)=∑n=1∞​fn​(t). The customer average and time average are

G=lim⁡N→∞1N∑n=1Ngn,H=lim⁡T→∞1T∫0Th(t) dt.G = \lim_{N\to\infty} \frac1N \sum_{n=1}^N g_n, \qquad H = \lim_{T\to\infty} \frac1T \int_0^T h(t)\,dt .G=N→∞lim​N1​n=1∑N​gn​,H=T→∞lim​T1​∫0T​h(t)dt.

When fnf_nfn​ is the indicator of [tn,tn+Wn)[t_n, t_n + W_n)[tn​,tn​+Wn​), gn=Wng_n = W_ngn​=Wn​ is the sojourn time and h(t)h(t)h(t) is the number in system, so H=λGH = \lambda GH=λG is L=λWL = \lambda WL=λW.

The ASSUMPTION of the paper is that for each nnn there is sn∈[0,∞)s_n \in [0,\infty)sn​∈[0,∞) with

  1. (i) fn(t)=0f_n(t) = 0fn​(t)=0 for t∉[tn,tn+sn]t \notin [t_n, t_n + s_n]t∈/[tn​,tn​+sn​];
  2. (ii) sn/n→0s_n / n \to 0sn​/n→0.

For signed fnf_nfn​ write fn+=max⁡[0,fn]f_n^+ = \max[0, f_n]fn+​=max[0,fn​], fn−=max⁡[0,−fn]f_n^- = \max[0, -f_n]fn−​=max[0,−fn​], and let gn±g_n^\pmgn±​, h±h^\pmh±, G±G^\pmG±, H±H^\pmH± be the corresponding totals, rates and averages.

Formalization targets

Goal: Theorem 2 (p. 986)

Assume (i), (ii) and (v) ∫0∞∣fn(t)∣ dt<∞\int_0^\infty |f_n(t)|\,dt < \infty∫0∞​∣fn​(t)∣dt<∞ for every nnn. If λ\lambdaλ, G+G^+G+ and G−G^-G− exist with 0<λ<∞0 < \lambda < \infty0<λ<∞ and G±<∞G^\pm < \inftyG±<∞, then GGG exists, equals G+−G−G^+ - G^-G+−G−, HHH exists, and

H=λG.(1)H = \lambda G. \tag{1}H=λG.(1)

Milestones

  • (2): for 0<λ<∞0 < \lambda < \infty0<λ<∞, N(t)/t→λN(t)/t \to \lambdaN(t)/t→λ if and only if tn/n→λ−1t_n / n \to \lambda^{-1}tn​/n→λ−1.
  • (3): for fn≥0f_n \ge 0fn​≥0, V(T)≤∫0Th(t) dt≤U(T)V(T) \le \int_0^T h(t)\,dt \le U(T)V(T)≤∫0T​h(t)dt≤U(T), where U(T)U(T)U(T) sums gng_ngn​ over arrived customers and V(T)V(T)V(T) over customers with tn+sn≤Tt_n + s_n \le Ttn​+sn​≤T.
  • (4): λG=lim⁡t→∞U(t)/t\lambda G = \lim_{t\to\infty} U(t)/tλG=limt→∞​U(t)/t.
  • sn/tn→0s_n / t_n \to 0sn​/tn​→0, and lim⁡U(t)/t=lim⁡V(t)/t\lim U(t)/t = \lim V(t)/tlimU(t)/t=limV(t)/t.
  • Theorem 1 (p. 985): for fn≥0f_n \ge 0fn​≥0 under (i)–(iv), H=λGH = \lambda GH=λG.
  • The identity ∫0Th+−∫0Th−=∫0Th\int_0^T h^+ - \int_0^T h^- = \int_0^T h∫0T​h+−∫0T​h−=∫0T​h and (6): G=G+−G−G = G^+ - G^-G=G+−G−, H=H+−H−H = H^+ - H^-H=H+−H−.

Companion results

  • The §3 counterexample: tn=nt_n = ntn​=n, indicator fnf_nfn​ with gn=1g_n = 1gn​=1, so λ=G=1\lambda = G = 1λ=G=1, but H=log⁡2H = \log 2H=log2; its support span sn=ns_n = nsn​=n satisfies (i) and fails (ii).
  • Corollary 3 (p. 988): if λ(ω)=λ\lambda(\omega) = \lambdaλ(ω)=λ is constant, the ensemble averages satisfy ∫H dP=λ∫G dP\int H\,dP = \lambda \int G\,dP∫HdP=λ∫GdP.
  • G=W<∞G = W < \inftyG=W<∞ implies Wn/n→0W_n / n \to 0Wn​/n→0 (p. 986), the step by which Theorem 1 contains L=λWL = \lambda WL=λW.

Significance

The result. H=λGH = \lambda GH=λG converts between a time average, which is what a system designer measures, and a customer average, which is what a customer experiences. Applied to different fnf_nfn​ it yields L=λWL = \lambda WL=λW, the relation between average work in system and average customer work, and relations between time-stationary and embedded-chain probabilities; §2 of the paper derives the GI/M/c/K relation this way. Because the support condition (i)–(ii) allows a customer's contribution to be interrupted (leaving and re-entering the system), it covers preemptive priority queues and nodes of networks, which the continuous-sojourn L=λWL = \lambda WL=λW theorem does not. The counterexample marks the boundary: with interrupted sojourns, indicator functions and finite λ\lambdaλ, GGG alone do not suffice.

Formalizing it. The result is proved on paper, with two steps delegated to earlier work "by mimicking" Lemma 1 and Theorem 2 of Stidham 1974. The indicator special case L=λWL = \lambda WL=λW (with strictly increasing arrivals) is already proved on Prove2Me as queueing_general_littles_law (wenxinzhang). This mission asks for the general, signed, pathwise statement and its proof steps, a counterexample with an exactly computed time average log⁡2\log 2log2, and the ensemble corollary.

Difficulty

The obvious argument, exchanging the time integral of hhh with the sum over customers, gives ∫0Th=∑n∫0Tfn\int_0^T h = \sum_n \int_0^T f_n∫0T​h=∑n​∫0T​fn​, but a customer that has arrived by TTT may contribute only part of its total gng_ngn​ by TTT. The sandwich V(T)≤∫0Th≤U(T)V(T) \le \int_0^T h \le U(T)V(T)≤∫0T​h≤U(T) only bounds this loss; the hard step is showing that U(t)/tU(t)/tU(t)/t and V(t)/tV(t)/tV(t)/t have the same limit, which needs sn/tn→0s_n / t_n \to 0sn​/tn​→0 to compare VVV at time ttt with UUU at a slightly earlier time. Without (ii) this fails, as the counterexample shows: customers there remain "open" for a window proportional to their index.

For signed fnf_nfn​ the sandwich is not available directly, and the proof splits fnf_nfn​ into positive and negative parts; the exchange of sum and integral then needs the finiteness of the parts on every [0,T][0,T][0,T].

Formalization scope

All statements except Corollary 3 are about one fixed sample path; the paper's "with probability one" is the pathwise statement applied to almost every path, and Corollary 3 states this explicitly with a probability measure and almost-sure hypotheses.

Conventions:

  • Customers are indexed from 000 in Lean; index nnn is the paper's customer n+1n+1n+1, so sn/n→0s_n/n \to 0sn​/n→0 is written sn/(n+1)→0s_n/(n+1) \to 0sn​/(n+1)→0.
  • Arrival epochs are Monotone with t0≥0t_0 \ge 0t0​≥0; ties are allowed.
  • fn:R→Rf_n : \mathbb R \to \mathbb Rfn​:R→R, but only values on [0,∞)[0,\infty)[0,∞) enter: (i) is required only for t≥0t \ge 0t≥0, gng_ngn​ integrates over [0,∞)[0,\infty)[0,∞), and time averages integrate over [0,T][0,T][0,T].
  • (iv) and (v) are stated as integrability of fnf_nfn​ on [0,∞)[0,\infty)[0,∞); the page prints (iv) as "≤∞\le \infty≤∞", a misprint for "<∞< \infty<∞".
  • N(t)N(t)N(t) is the cardinality of {n:tn≤t}\{n : t_n \le t\}{n:tn​≤t}; hhh, UUU, VVV are infinite sums over all customers.
  • "HHH exists" includes integrability of hhh on every [0,T][0,T][0,T].
  • The page prints (6) as "G=G+−G+G = G^+ - G^+G=G+−G+"; the stated identity is G=G+−G−G = G^+ - G^-G=G+−G−, as the proof shows.

Added hypotheses: milestones (3), the h±h^\pmh± identity and (6) assume tn→∞t_n \to \inftytn​→∞, which the paper derives from (2); Corollary 3 assumes G(ω)G(\omega)G(ω) is integrable, which its definition of the ensemble average presupposes.

A formalization in which hhh sums only over arrived customers, or in which a non-integrable hhh or fnf_nfn​ has integral 000, would make the statements trivial or different; the definitions rule this out by summing over all customers and requiring integrability.

Needed infrastructure: Cesàro averages and counting functions of nondecreasing sequences, interchange of countable sums and integrals for locally finite families, and harmonic sums ∑m=⌈(k+1)/2⌉k1/m→log⁡2\sum_{m=\lceil (k+1)/2\rceil}^{k} 1/m \to \log 2∑m=⌈(k+1)/2⌉k​1/m→log2. The counting-function lemma (2) and the squeeze for UUU and VVV are reusable well beyond this mission. Proofs of any milestone are welcome independently.

Selected references

  • D. P. Heyman and S. Stidham, Jr., The relation between customer and time averages in queues, Operations Research 28(4):983–994, 1980. https://doi.org/10.1287/opre.28.4.983
  • J. D. C. Little, A proof for the queuing formula: L = λW, Operations Research 9(3):383–387, 1961. https://doi.org/10.1287/opre.9.3.383
  • S. Stidham, Jr., L = λW: a discounted analogue and a new proof, Operations Research 20(6):1115–1126, 1972. https://doi.org/10.1287/opre.20.6.1115
  • S. Stidham, Jr., A last word on L = λW, Operations Research 22(2):417–421, 1974. https://doi.org/10.1287/opre.22.2.417
  • S. L. Brumelle, On the relation between customer and time averages in queues, Journal of Applied Probability 8:508–520, 1971.
11 thms1 active userReviewed
Numerical AnalysisOptimization·Captain: mikedeng1

Globally Convergent Inexact Newton Methods I: Inexact Newton Backtracking Converges to Every Limit Point Where F′ Is Invertible, That Point Is a Zero of F, and Initial Steps Are Eventually AcceptedResearch Paper

Motivation

Newton's method for a nonlinear system F(x)=0F(x) = 0F(x)=0, with F:Rn→RnF:\mathbb R^n\to\mathbb R^nF:Rn→Rn, solves the linear system F′(xk)sk=−F(xk)F'(x_k)s_k = -F(x_k)F′(xk​)sk​=−F(xk​) at every step. For large systems that solve is itself iterative (a Krylov method such as GMRES), and it is stopped early. The resulting inexact Newton methods, introduced by Dembo, Eisenstat and Steihaug (SIAM J. Numer. Anal. 19 (1982)), accept any step with ∥F(xk)+F′(xk)sk∥≤ηk∥F(xk)∥\|F(x_k)+F'(x_k)s_k\|\le\eta_k\|F(x_k)\|∥F(xk​)+F′(xk​)sk​∥≤ηk​∥F(xk​)∥, where the forcing term ηk∈[0,1)\eta_k\in[0,1)ηk​∈[0,1) controls how accurately the linear system is solved. Their theory is local: it applies once the iterates are near a solution with invertible derivative.

Practical solvers (Newton–Krylov codes in large-scale simulation, nonlinear solver libraries such as PETSc's SNES and SUNDIALS' KINSOL) combine such inexact steps with a globalization, most often backtracking along the step. Eisenstat and Walker (SIAM J. Optim. 4 (1994)) gave the global convergence theory for this combination: what can be said about the iterates from an arbitrary starting point, with no assumption that a solution exists or that F′F'F′ is invertible anywhere.

Timeline. Dembo, Eisenstat and Steihaug (1982) proved local convergence of inexact Newton methods. Dembo and Steihaug (Math. Program. 26 (1983)) studied truncated Newton methods for unconstrained minimization. Brown and Saad (1990) studied globalized Newton–Krylov methods with line searches and model trust regions, under the inner-product norm. Eisenstat and Walker (1994) gave the general framework treated here, for an arbitrary norm. Their 1996 paper (SIAM J. Sci. Comput. 17) proposed the forcing-term choices that are now standard.

Setting

Let EEE be Rn\mathbb R^nRn with an arbitrary norm ∥⋅∥\|\cdot\|∥⋅∥, and let F:E→EF:E\to EF:E→E be continuously differentiable with derivative F′(x)F'(x)F′(x). A point x∗x_*x∗​ is a limit point of (xk)(x_k)(xk​) if every ball Nδ(x∗)={y:∥y−x∗∥<δ}N_\delta(x_*)=\{y:\|y-x_*\|<\delta\}Nδ​(x∗​)={y:∥y−x∗​∥<δ} contains xkx_kxk​ for infinitely many kkk.

Algorithm GIN (global inexact Newton method). Fix t∈(0,1)t\in(0,1)t∈(0,1). At each kkk, find a level ηk∈[0,1)\eta_k\in[0,1)ηk​∈[0,1) and a step sks_ksk​ with

∥F(xk)+F′(xk)sk∥≤ηk∥F(xk)∥(2.1),∥F(xk+sk)∥≤[1−t(1−ηk)] ∥F(xk)∥(2.2),\|F(x_k)+F'(x_k)s_k\|\le\eta_k\|F(x_k)\| \quad (2.1),\qquad \|F(x_k+s_k)\|\le[1-t(1-\eta_k)]\,\|F(x_k)\| \quad (2.2),∥F(xk​)+F′(xk​)sk​∥≤ηk​∥F(xk​)∥(2.1),∥F(xk​+sk​)∥≤[1−t(1−ηk​)]∥F(xk​)∥(2.2),

and set xk+1=xk+skx_{k+1}=x_k+s_kxk+1​=xk​+sk​. Condition (2.1) says that sks_ksk​ reduces the norm of the local linear model by the factor ηk\eta_kηk​. Condition (2.2) asks that ∥F∥\|F\|∥F∥ itself decrease by a fixed fraction ttt of that predicted reduction.

Algorithm MR (minimum reduction method). Fix ηmax⁡∈[0,1)\eta_{\max}\in[0,1)ηmax​∈[0,1) and 0<θmin⁡<θmax⁡<10<\theta_{\min}<\theta_{\max}<10<θmin​<θmax​<1. At step kkk, choose ηˉk∈[0,ηmax⁡]\bar\eta_k\in[0,\eta_{\max}]ηˉ​k​∈[0,ηmax​] and a curve σk\sigma_kσk​ with ∥F(xk)+F′(xk)σk(η)∥≤η∥F(xk)∥\|F(x_k)+F'(x_k)\sigma_k(\eta)\|\le\eta\|F(x_k)\|∥F(xk​)+F′(xk​)σk​(η)∥≤η∥F(xk​)∥ for ηˉk≤η≤1\bar\eta_k\le\eta\le1ηˉ​k​≤η≤1 (5.1). Start at ηk=ηˉk\eta_k=\bar\eta_kηk​=ηˉ​k​. While (2.2) fails for sk=σk(ηk)s_k=\sigma_k(\eta_k)sk​=σk​(ηk​), replace ηk\eta_kηk​ by 1−θ(1−ηk)1-\theta(1-\eta_k)1−θ(1−ηk​) for some θ∈[θmin⁡,θmax⁡]\theta\in[\theta_{\min},\theta_{\max}]θ∈[θmin​,θmax​]. Then set xk+1=xk+σk(ηk)x_{k+1}=x_k+\sigma_k(\eta_k)xk+1​=xk​+σk​(ηk​).

Algorithm INB (inexact Newton backtracking). Choose ηˉk∈[0,ηmax⁡]\bar\eta_k\in[0,\eta_{\max}]ηˉ​k​∈[0,ηmax​] and an inexact Newton step sˉk\bar s_ksˉk​ at level ηˉk\bar\eta_kηˉ​k​. While (2.2) fails, shorten the step, sk←θsks_k\leftarrow\theta s_ksk​←θsk​, and raise the level, ηk←1−θ(1−ηk)\eta_k\leftarrow1-\theta(1-\eta_k)ηk​←1−θ(1−ηk​). INB is MR with the backtracking curve σk(η)=1−η1−ηˉksˉk\sigma_k(\eta)=\frac{1-\eta}{1-\bar\eta_k}\bar s_kσk​(η)=1−ηˉ​k​1−η​sˉk​ (6.1).

An algorithm does not break down if it produces an infinite sequence of iterates, in particular if every while-loop exits.

Formalization targets

Goal: Theorem 6.1 (global convergence of Algorithm INB)

If Algorithm INB does not break down and x∗x_*x∗​ is a limit point of (xk)(x_k)(xk​) at which F′(x∗)F'(x_*)F′(x∗​) is invertible, then

F(x∗)=0,xk→x∗,sk=sˉk and ηk=ηˉk for all sufficiently large k.F(x_*)=0,\qquad x_k\to x_*,\qquad s_k=\bar s_k\ \text{and}\ \eta_k=\bar\eta_k\ \text{for all sufficiently large }k.F(x∗​)=0,xk​→x∗​,sk​=sˉk​ and ηk​=ηˉ​k​ for all sufficiently large k.

The statement assumes no solution, bounded level set, Lipschitz derivative or particular norm. The last clause says that backtracking eventually stops, so the local rate is governed by the forcing terms ηˉk\bar\eta_kηˉ​k​.

Milestones

In attack order:

  1. Lemmas 1.1 and 1.2. Continuity of y↦F′(y)−1y\mapsto F'(y)^{-1}y↦F′(y)−1 at an invertible point, and a uniform linearization error ∥F(z)−F(y)−F′(y)(z−y)∥≤ε∥z−y∥\|F(z)-F(y)-F'(y)(z-y)\|\le\varepsilon\|z-y\|∥F(z)−F(y)−F′(y)(z−y)∥≤ε∥z−y∥ near xxx.
  2. Theorem 3.3. If F(xk)→0F(x_k)\to0F(xk​)→0, the steps satisfy (2.1) with a fixed η\etaη, and ∥F(xk)∥\|F(x_k)\|∥F(xk​)∥ is nonincreasing, then an invertible limit point is a zero and the limit.
  3. Theorem 3.4. A GIN run with ∑k(1−ηk)=∞\sum_k(1-\eta_k)=\infty∑k​(1−ηk​)=∞ has F(xk)→0F(x_k)\to0F(xk​)→0, plus the conclusion of Theorem 3.3 at invertible limit points.
  4. Theorem 3.5. A GIN run converges to a limit point near which ∥sk∥≤Γ(1−ηk)∥F(xk)∥\|s_k\|\le\Gamma(1-\eta_k)\|F(x_k)\|∥sk​∥≤Γ(1−ηk​)∥F(xk​)∥ (3.2).
  5. Lemma 5.1. The while-loop terminates, with 1−ηk≥min⁡{1−ηˉk,θmin⁡δ/(Γ∥F(xk)∥)}1-\eta_k\ge\min\{1-\bar\eta_k,\theta_{\min}\delta/(\Gamma\|F(x_k)\|)\}1−ηk​≥min{1−ηˉ​k​,θmin​δ/(Γ∥F(xk​)∥)}.
  6. MR runs are GIN runs (§5).
  7. Theorem 5.2 for MR. Under ∥σk(η)∥≤Γ(1−η)∥F(xk)∥\|\sigma_k(\eta)\|\le\Gamma(1-\eta)\|F(x_k)\|∥σk​(η)∥≤Γ(1−η)∥F(xk​)∥ near a limit point x∗x_*x∗​ (5.6): F(x∗)=0F(x_*)=0F(x∗​)=0, xk→x∗x_k\to x_*xk​→x∗​, and ηk=ηˉk\eta_k=\bar\eta_kηk​=ηˉ​k​ eventually.
  8. INB runs are MR runs with the curve (6.1), and sk=σk(ηk)s_k=\sigma_k(\eta_k)sk​=σk​(ηk​) throughout the loop (§6).

Further items, which are not milestones: Corollary 6.2 (exact Newton with backtracking takes full Newton steps eventually), Theorem 5.2 for Algorithm TL, Lemma 3.1 (existence of acceptable GIN steps), and Proposition 2.1 (the Goldstein–Armijo alpha condition implies (2.2) in the Euclidean norm).

Significance

The result. Theorem 6.1 is the global convergence guarantee for the inexact Newton backtracking method that Newton–Krylov solvers implement. It separates three outcomes: the iterates diverge, they accumulate only at points where F′F'F′ is singular, or they converge to a solution with invertible derivative and eventually take the unmodified inexact Newton steps. In the third case the local theory of Dembo, Eisenstat and Steihaug applies from some iteration on, so the forcing terms alone set the convergence rate. Theorem 5.2 is the template: §§6–8 of the paper derive the convergence of backtracking, equality-curve and dogleg-type methods from it by verifying (5.6).

Formalizing it. The results are proved on paper and none of them has a machine-checked proof that we know of. The mission produces a library of algorithm-run predicates with explicit while-loops for inexact Newton methods. It also checks the paper's reduction chain (INB is a run of MR, MR is a run of GIN) and the global convergence theorems in an arbitrary finite-dimensional norm.

Difficulty

The obvious argument fails at both ends. Sufficient decrease (2.2) alone gives monotonicity of ∥F(xk)∥\|F(x_k)\|∥F(xk​)∥, but not convergence of the iterates. On the page, F(x)=x2−1F(x)=x^2-1F(x)=x2−1 admits sequences satisfying (2.2) with both ±1\pm1±1 as limit points. Convergence of ∥F(xk)∥\|F(x_k)\|∥F(xk​)∥ to 000 needs ∑(1−ηk)=∞\sum(1-\eta_k)=\infty∑(1−ηk​)=∞, and nothing in the algorithm states this. In Theorem 5.2 it has to be derived from the exit level of the while-loop, which depends on a neighbourhood of x∗x_*x∗​ where the linearization error is uniformly controlled. A solver must combine a limit-point argument (only infinitely many iterates are near x∗x_*x∗​, not all of them) with the loop's worst-case backtracking factor θmin⁡\theta_{\min}θmin​. The invertibility of F′(x∗)F'(x_*)F′(x∗​) enters only through the bound (5.6) for the backtracking curve, which must be established uniformly in kkk.

Formalization scope

  • Space and norm. EEE is a finite-dimensional real normed space ([NormedAddCommGroup E] [NormedSpace ℝ E] [FiniteDimensional ℝ E]). This is exactly "Rn\mathbb R^nRn with an arbitrary norm". Fin n → ℝ (sup norm) and EuclideanSpace would each fix one norm. Only Proposition 2.1 assumes an inner product space, as the page does.
  • Derivative. F′F'F′ is fderiv ℝ F, with ContDiff ℝ 1 F (the paper's standing assumption). Invertibility is ContinuousLinearMap.IsInvertible, and F′(x)−1F'(x)^{-1}F′(x)−1 is ContinuousLinearMap.inverse.
  • Runs. An algorithm that does not break down is a predicate on infinite sequences (IsGINRun, IsMRRun, IsINBRun, plus IsTLRun, IsENBRun). The steps and levels the algorithm says to "find" or "choose" are data constrained only by the stated conditions. A while-loop is recorded by its number of passes mkm_kmk​ and factors θk,j∈[θmin⁡,θmax⁡]\theta_{k,j}\in[\theta_{\min},\theta_{\max}]θk,j​∈[θmin​,θmax​]. Every trial before the last fails the loop's test and the last one passes it. Termination is part of the run.
  • Limit point is MapClusterPt xstar atTop x. "For all sufficiently large kkk" is ∀ᶠ k in atTop. The paper's "whenever xkx_kxk​ is sufficiently near x∗x_*x∗​ [and kkk is sufficiently large]" is ∃ Γ, ∃ δ > 0, [∃ K,] ∀ k [≥ K], x k ∈ ball xstar δ → …. Γ\GammaΓ precedes kkk ("independent of kkk"), and the "kkk large" clause appears only in (3.2), where the page has it.
  • Hypotheses as printed. Theorems 3.5 and 5.2 do not assume F′(x∗)F'(x_*)F′(x∗​) invertible. Theorem 5.2 does not assume ∑(1−ηk)=∞\sum(1-\eta_k)=\infty∑(1−ηk​)=∞. Lemma 5.1 is stated for one iteration of the loop shared by MR and TL, for every choice of factors.
  • Trivializing readings ruled out. A run predicate without the "rejected" clause would allow needless backtracking, and one without the "accepted" clause would drop (2.2). Both clauses are present. A sorry-free check (F = id on R\mathbb RR) confirms that the INB, GIN and ENB run predicates and the goal's hypotheses are satisfiable, so the goal is not vacuous.
  • Infrastructure. Continuity of operator inversion and uniform differentiability on neighbourhoods are in Mathlib. The run predicates and trial-level recursions are reusable for any line-search or backtracking analysis. Each milestone is stated independently; contributions in any order are welcome.

Selected references

  • S. C. Eisenstat and H. F. Walker, Globally Convergent Inexact Newton Methods, SIAM J. Optim. 4(2) (1994) 393–422. https://doi.org/10.1137/0804022
  • R. S. Dembo, S. C. Eisenstat and T. Steihaug, Inexact Newton Methods, SIAM J. Numer. Anal. 19(2) (1982) 400–408. https://doi.org/10.1137/0719025
  • R. S. Dembo and T. Steihaug, Truncated-Newton algorithms for large-scale unconstrained optimization, Math. Program. 26 (1983) 190–212. https://doi.org/10.1007/BF02592055
  • P. N. Brown and Y. Saad, Hybrid Krylov Methods for Nonlinear Systems of Equations, SIAM J. Sci. Stat. Comput. 11(3) (1990) 450–481. https://doi.org/10.1137/0911026
  • S. C. Eisenstat and H. F. Walker, Choosing the Forcing Terms in an Inexact Newton Method, SIAM J. Sci. Comput. 17(1) (1996) 16–32. https://doi.org/10.1137/0917003
  • J. E. Dennis and R. B. Schnabel, Numerical Methods for Unconstrained Optimization and Nonlinear Equations, SIAM Classics in Applied Mathematics 16 (1996). https://doi.org/10.1137/1.9781611971200
12 thms1 active userReviewed
ProbabilityStochastic Systems·Captain: mikedeng1

Shock Models and Wear Processes I: Under Poisson Shocks, Cumulative Nonnegative I.I.D. Damage up to a Fixed Threshold Gives an IHRA Life DistributionResearch Paper

Motivation

Reliability theory classifies life distributions by how they age. The IHRA class (increasing hazard rate average) is the smallest class of life distributions that contains the exponential distributions and is closed under forming coherent systems and taking limits in distribution (Birnbaum, Esary and Marshall 1966). It is therefore the natural class for the lifetime of a system built from components that wear out. A distribution belongs to it when its survival function Fˉ\bar FFˉ satisfies: [Fˉ(t)]1/t[\bar F(t)]^{1/t}[Fˉ(t)]1/t is decreasing in t>0t > 0t>0.

Esary, Marshall and Proschan (Ann. Probability 1 (1973) 627–649) asked where such ageing comes from physically. Their answer is a shock model: a device receives shocks at the epochs of a Poisson process, each shock does random damage, and the device fails when the accumulated damage exceeds its capacity. The central result of their §4, formalized in this mission, is that this model always produces an IHRA life, whatever the damage distribution. In the authors' words, "the IHRA property has been obtained … as an implication of a natural physical model. The only hypothesis imposed upon FFF is that it be the distribution of a nonnegative random variable." The paper is a standard reference of reliability theory and the source of the cumulative damage model used across maintenance and insurance applications.

Setting

Shocks arrive according to a Poisson process with rate λ>0\lambda > 0λ>0. Write Pˉk\bar P_kPˉk​ for the probability that the device survives the first kkk shocks; then 1≥Pˉ0≥Pˉ1≥⋯≥01 \ge \bar P_0 \ge \bar P_1 \ge \dots \ge 01≥Pˉ0​≥Pˉ1​≥⋯≥0 (display (2.2)). Conditioning on the number of shocks in [0,t][0, t][0,t] gives the shock survival function (2.1):

Hˉ(t)=∑k=0∞Pˉk e−λt(λt)kk!,t≥0,\bar H(t) = \sum_{k=0}^{\infty} \bar P_k\, e^{-\lambda t}\frac{(\lambda t)^k}{k!}, \qquad t \ge 0,Hˉ(t)=k=0∑∞​Pˉk​e−λtk!(λt)k​,t≥0,

with Hˉ(t)=1\bar H(t) = 1Hˉ(t)=1 for t<0t < 0t<0. The weights K(k,t)=e−λt(λt)k/k!K(k,t) = e^{-\lambda t}(\lambda t)^k/k!K(k,t)=e−λt(λt)k/k! are the Poisson probabilities.

In the cumulative damage model the iiith shock causes a damage Xi≥0X_i \ge 0Xi​≥0, the damages are independent with common distribution function FFF (so F(z)=0F(z) = 0F(z)=0 for z<0z < 0z<0), and the device survives kkk shocks when X1+⋯+Xk≤xX_1 + \dots + X_k \le xX1​+⋯+Xk​≤x, for a fixed threshold xxx. Hence (4.1)

Pˉk=F(k)(x),k=0,1,…,\bar P_k = F^{(k)}(x), \qquad k = 0, 1, \dots,Pˉk​=F(k)(x),k=0,1,…,

where F(k)F^{(k)}F(k) is the kkk-fold convolution of FFF and F(0)F^{(0)}F(0) is degenerate at 000. A distribution with survival function Fˉ\bar FFˉ is IHRA if [Fˉ(t)]1/t[\bar F(t)]^{1/t}[Fˉ(t)]1/t is decreasing in t>0t > 0t>0; throughout, "decreasing" means non-increasing.

Formalization targets

Goal: Corollary 4.2, display (4.7)

For every distribution FFF on [0,∞)[0,\infty)[0,∞), every λ>0\lambda > 0λ>0 and every threshold xxx,

Hˉ(t)=∑k=0∞e−λt(λt)kk!F(k)(x)is IHRA.\bar H(t) = \sum_{k=0}^\infty e^{-\lambda t}\frac{(\lambda t)^k}{k!} F^{(k)}(x) \quad \text{is IHRA.}Hˉ(t)=k=0∑∞​e−λtk!(λt)k​F(k)(x)is IHRA.

This is the first of the three statements of Corollary 4.2; the second ((4.7a), independent damages FiF_iFi​ that worsen with iii) is an extra item of this mission, and the third ((4.7b), dependent damages satisfying (4.3)–(4.5)) belongs to mission III of this series.

Milestones

  1. (2.6): Hˉ(t)≥Hˉ(0)e−λt\bar H(t) \ge \bar H(0)e^{-\lambda t}Hˉ(t)≥Hˉ(0)e−λt for t≥0t \ge 0t≥0.
  2. Theorem 3.1 (3.4) through the three claims of its proof (p. 633): if 1=Pˉ0≥Pˉ1≥…1 = \bar P_0 \ge \bar P_1 \ge \dots1=Pˉ0​≥Pˉ1​≥… and Pˉk1/k\bar P_k^{1/k}Pˉk1/k​ is decreasing in k≥1k \ge 1k≥1, then Pˉk−ζk\bar P_k - \zeta^kPˉk​−ζk (0≤ζ≤10 \le \zeta \le 10≤ζ≤1) has at most one sign change, from +++ to −-−; this property passes to Hˉ(t)−e−(1−ζ)λt\bar H(t) - e^{-(1-\zeta)\lambda t}Hˉ(t)−e−(1−ζ)λt on t≥0t \ge 0t≥0; hence Hˉ(t)−e−θt\bar H(t) - e^{-\theta t}Hˉ(t)−e−θt has at most one sign change for every θ>0\theta > 0θ>0; and HHH is IHRA.
  3. Lemma 4.1: for FFF on [0,∞)[0,\infty)[0,∞), [F(k)(x)]1/k[F^{(k)}(x)]^{1/k}[F(k)(x)]1/k is decreasing in k=1,2,…k = 1, 2, \dotsk=1,2,….

Further items

Lemma 4.1a and Corollary 4.2 (4.7a); Theorem 4.4 ([F(k)(x)]1/k[F^{(k)}(x)]^{1/k}[F(k)(x)]1/k is constant in kkk iff FFF has no mass in (0,x](0,x](0,x]); Corollary 4.5 ((4.7) is exponential iff FFF has no mass in (0,x](0,x](0,x]); Corollary 4.11 ([P{N(x)≥k}]1/k[P\{N(x) \ge k\}]^{1/k}[P{N(x)≥k}]1/k is decreasing for the count N(x)N(x)N(x) of an ordinary renewal process).

Significance

The goal turns a modelling assumption into a theorem: anyone who models failure as accumulated nonnegative damage under Poisson shocks obtains, without further checks, every consequence of IHRA proved in reliability theory, including the closure of the class under the formation of coherent systems. Theorem 3.1 (3.4) is reusable on its own: it reduces the IHRA property of any Poisson mixture to a discrete condition on the Pˉk\bar P_kPˉk​, and the same scheme drives the first passage result for wear processes (Theorem 4.10, mission III). Lemma 4.1, applied to renewal processes, gives Corollary 4.11, a statement about renewal counts with no shock model in sight.

All results are proved in the paper; none has a machine-checked proof that we know of. The Mathlib library has the Poisson distribution and the convolution of measures, but no reliability classes, no total positivity and no variation diminishing property. The mission's output is a formal proof of the paper's chain of results and, along the way, reusable statements about Poisson mixtures and convolution powers.

Difficulty

Two steps resist a direct argument. The first is the transfer from sequences to functions: knowing that Pˉk−ζk\bar P_k - \zeta^kPˉk​−ζk changes sign at most once says nothing pointwise about the series ∑k(Pˉk−ζk)K(k,t)\sum_k(\bar P_k - \zeta^k)K(k,t)∑k​(Pˉk​−ζk)K(k,t). The paper invokes the variation diminishing property of the totally positive Poisson kernel (Karlin, Total Positivity, 1968), which is not in Mathlib. The second is Lemma 4.1, an inequality between convolution powers of an arbitrary law: no density, moments or continuity may be assumed, atoms at 000 and at xxx are allowed, so any argument through densities or Laplace transforms loses generality. A further subtlety is the passage from "one sign change of Hˉ(t)−e−θt\bar H(t) - e^{-\theta t}Hˉ(t)−e−θt for every θ\thetaθ" to the monotonicity of [Hˉ(t)]1/t[\bar H(t)]^{1/t}[Hˉ(t)]1/t, which needs care where Hˉ\bar HHˉ vanishes.

Formalization scope

  • A distribution FFF with F(z)=0F(z) = 0F(z)=0 for z<0z < 0z<0 is a probability measure μ\muμ on R\mathbb RR with μ(−∞,0)=0\mu(-\infty,0) = 0μ(−∞,0)=0; nothing else is assumed. F(k)F^{(k)}F(k) is the kkk-fold additive convolution of μ\muμ (Mathlib's Measure.conv) starting from the point mass at 000, and F(k)(x)F^{(k)}(x)F(k)(x) is the real number F(k)(−∞,x]F^{(k)}(-\infty,x]F(k)(−∞,x].
  • Hˉ\bar HHˉ is the series (2.1) as a function on R\mathbb RR, equal to 111 on t<0t < 0t<0. It is never defined through a constructed random failure time, and IHRA is never encoded through a condition on the Pˉk\bar P_kPˉk​: the goal concludes that [Hˉ(t)]1/t[\bar H(t)]^{1/t}[Hˉ(t)]1/t is decreasing on t>0t > 0t>0 for the series itself. This rules out the trivializing reading in which the goal unfolds to Lemma 4.1.
  • Powers [Hˉ(t)]1/t[\bar H(t)]^{1/t}[Hˉ(t)]1/t and Pˉk1/k\bar P_k^{1/k}Pˉk1/k​ are real powers with exponent 1/t1/t1/t, 1/k1/k1/k in R\mathbb RR.
  • Hypotheses the paper leaves implicit and the Lean statements make explicit: λ>0\lambda > 0λ>0; Pˉk≥0\bar P_k \ge 0Pˉk​≥0 (the Pˉk\bar P_kPˉk​ are probabilities); in Corollary 4.5, x≥0x \ge 0x≥0 (the threshold is a capacity), and "exponential" includes the degenerate rate 000.
  • Sign change statements about Hˉ\bar HHˉ hold on t≥0t \ge 0t≥0, where the series defines it.
  • The threshold xxx in the goal ranges over all reals, as printed.
  • In Corollary 4.11 the renewal process is given by independent measurable interarrival times with common law μ\muμ, and N(x)=#{k≥1:X1+⋯+Xk≤x}N(x) = \#\{k \ge 1 : X_1 + \dots + X_k \le x\}N(x)=#{k≥1:X1​+⋯+Xk​≤x} takes values in {0,1,…,∞}\{0, 1, \dots, \infty\}{0,1,…,∞}.

A complete development needs: the variation diminishing property of the Poisson kernel (reusable for every Poisson mixture), monotonicity of [F(k)(x)]1/k[F^{(k)}(x)]^{1/k}[F(k)(x)]1/k via convolution integrals, and elementary facts about real powers and sign changes. Proofs of any milestone or extra item, and general total positivity lemmas, are welcome.

Selected references

  • J. D. Esary, A. W. Marshall and F. Proschan, Shock Models and Wear Processes, The Annals of Probability 1(4) (1973) 627–649. https://doi.org/10.1214/aop/1176996891
  • Z. W. Birnbaum, J. D. Esary and A. W. Marshall, A Stochastic Characterization of Wear-Out for Components and Systems, The Annals of Mathematical Statistics 37 (1966) 816–825. https://doi.org/10.1214/aoms/1177699362
  • S. Karlin, Total Positivity, Vol. I, Stanford University Press, 1968.
  • R. E. Barlow and F. Proschan, Mathematical Theory of Reliability, Wiley, 1965. https://doi.org/10.1137/1.9781611971194
8 thms1 active userReviewed
ProbabilityStochastic Systems·Captain: mikedeng1

Reflected Brownian Motion on an Orthant: The Skorokhod Construction Yields an Adapted, Almost Surely Unique, Time-Homogeneous Markov ProcessResearch Paper

Motivation

Reflected Brownian motion on the orthant is the diffusion that arises as the heavy-traffic limit of open networks of queues. In a KKK-station network the scaled queue-length vector lives in the nonnegative orthant R+K\mathbb R^K_+R+K​; in the interior it moves like a Brownian motion, and when a station empties the process is pushed back into the orthant in a direction determined by the routing of customers between stations. Harrison (1978) obtained such a limit for two queues in tandem, and Reiman (Open Queueing Networks in Heavy Traffic, Math. Oper. Res. 9 (1984)) showed that general KKK-station open networks lead exactly to the class of processes studied here.

Classical constructions of reflected diffusions (Stroock and Varadhan 1971, Watanabe 1971) require a smooth boundary and a reflection direction varying continuously on it. The orthant has corners and the reflection direction jumps between faces, so those results do not apply. Harrison and Reiman (Reflected Brownian Motion on an Orthant, Ann. Probab. 9 (1981)) construct the process pathwise, following Skorokhod's one-dimensional approach, and derive its Markov property from the construction. The process has since become the standard object in the diffusion approximation of queueing networks.

Setting

Fix a positive integer KKK. Vectors in RK\mathbb R^KRK are row vectors, indexed by j=1,…,Kj=1,\dots,Kj=1,…,K. Let AAA be a K×KK\times KK×K covariance matrix (symmetric, nonnegative definite), b∈RKb\in\mathbb R^Kb∈RK a drift vector, and Q=(qij)Q=(q_{ij})Q=(qij​) a nonnegative K×KK\times KK×K matrix with zeros on the diagonal and spectral radius strictly less than one. S=R+KS=\mathbb R^K_+S=R+K​ is the nonnegative orthant.

Let CCC be the space of continuous paths x:[0,∞)→RKx:[0,\infty)\to\mathbb R^Kx:[0,∞)→RK with the topology of uniform convergence on compact intervals, and CSC_SCS​ the paths with x(0)∈Sx(0)\in Sx(0)∈S. For x∈CSx\in C_Sx∈CS​, the Skorokhod problem asks for y,z∈Cy,z\in Cy,z∈C with, for every jjj,

zj(t)=xj(t)+yj(t)−∑i=1Kqij yi(t),zj(t)≥0,t≥0,(5–6)z_j(t)=x_j(t)+y_j(t)-\sum_{i=1}^K q_{ij}\,y_i(t),\qquad z_j(t)\ge 0,\qquad t\ge0, \tag{5–6}zj​(t)=xj​(t)+yj​(t)−i=1∑K​qij​yi​(t),zj​(t)≥0,t≥0,(5–6)

yjy_jyj​ nondecreasing with yj(0)=0y_j(0)=0yj​(0)=0 (7), and yjy_jyj​ increasing only at times ttt where zj(t)=0z_j(t)=0zj​(t)=0 (8). In matrix form, z=x+y(I−Q)z=x+y(I-Q)z=x+y(I−Q). Theorem 1 of the paper shows there is exactly one such pair, written y=ψ(x)y=\psi(x)y=ψ(x), z=ϕ(x)z=\phi(x)z=ϕ(x).

The process is obtained by feeding a Brownian path into this map. On a probability space (Ω,F,P)(\Omega,\mathcal F,P)(Ω,F,P) let XXX be a KKK-dimensional Brownian motion with covariance matrix AAA, drift bbb and X(0)∈SX(0)\in SX(0)∈S almost surely, with X(0)X(0)X(0) independent of the increments of XXX. Let Ft=F(X(s);0≤s≤t)\mathcal F_t=\mathcal F(X(s);0\le s\le t)Ft​=F(X(s);0≤s≤t). Set Y=ψ(X)Y=\psi(X)Y=ψ(X) and Z=ϕ(X)Z=\phi(X)Z=ϕ(X) where X∈CSX\in C_SX∈CS​, and Y=Z=0Y=Z=0Y=Z=0 on the exceptional null set. ZZZ is reflected Brownian motion on SSS with reflection matrix I−QI-QI−Q.

Formalization targets

Goal: Corollary 1

There is a family (κt)(\kappa_t)(κt​) of Markov transition kernels on RK\mathbb R^KRK, depending only on (Q,A,b)(Q,A,b)(Q,A,b), such that for every such XXX, YYY, ZZZ:

(a)Y(t), Z(t) are Ft-measurable, t≥0;\text{(a)}\quad Y(t),\ Z(t)\ \text{are } \mathcal F_t\text{-measurable},\ t\ge0;(a)Y(t), Z(t) are Ft​-measurable, t≥0; (b)(Y,Z) satisfies (1)–(4) a.s., and any pair satisfying (1)–(4) a.s. equals (Y,Z) a.s.;\text{(b)}\quad (Y,Z)\ \text{satisfies (1)–(4) a.s., and any pair satisfying (1)–(4) a.s. equals } (Y,Z) \text{ a.s.};(b)(Y,Z) satisfies (1)–(4) a.s., and any pair satisfying (1)–(4) a.s. equals (Y,Z) a.s.; (c)P[Z(s+t)∈B∣Fs]=κt(Z(s),B) a.s.,s,t≥0, B Borel.\text{(c)}\quad P\big[Z(s+t)\in B \mid \mathcal F_s\big]=\kappa_t\big(Z(s),B\big)\ \text{a.s.},\qquad s,t\ge0,\ B \text{ Borel}.(c)P[Z(s+t)∈B∣Fs​]=κt​(Z(s),B) a.s.,s,t≥0, B Borel.

Here (1)–(4) are (5)–(8) for the paths of XXX, YYY, ZZZ. The kernel is chosen before the probability space and the initial law, which is what "stationary transition probabilities" means.

Milestones

The milestones follow the proof of Theorem 1 on pp. 304–305:

  1. a positive diagonal Λ\LambdaΛ with ∥Λ−1QΛ∥<1\|\Lambda^{-1}Q\Lambda\|<1∥Λ−1QΛ∥<1 (Veinott scaling);
  2. (5)–(8) are invariant under (Q,x,y,z)↦(Λ−1QΛ,xΛ,yΛ,zΛ)(Q,x,y,z)\mapsto(\Lambda^{-1}Q\Lambda,x\Lambda,y\Lambda,z\Lambda)(Q,x,y,z)↦(Λ−1QΛ,xΛ,yΛ,zΛ);
  3. the key observation that (5)–(8) are equivalent to y∈C0y\in C_0y∈C0​, the fixed-point equation y=π(y)y=\pi(y)y=π(y) with π(y)(t)=sup⁡0≤s≤t[y(s)Q−x(s)]+\pi(y)(t)=\sup_{0\le s\le t}[y(s)Q-x(s)]^+π(y)(t)=sup0≤s≤t​[y(s)Q−x(s)]+, and z=x+y(I−Q)z=x+y(I-Q)z=x+y(I−Q);
  4. the contraction ∥π(y)−π(y′)∥≤α∥y−y′∥\|\pi(y)-\pi(y')\|\le\alpha\|y-y'\|∥π(y)−π(y′)∥≤α∥y−y′∥ on [0,T][0,T][0,T];
  5. convergence of the Picard iterates yn+1=π(yn)y^{n+1}=\pi(y^n)yn+1=π(yn), y0≡0y^0\equiv0y0≡0;
  6. the Lipschitz bound ∥ψ(x)−ψ(x′)∥≤∥x−x′∥/(1−α)\|\psi(x)-\psi(x')\|\le\|x-x'\|/(1-\alpha)∥ψ(x)−ψ(x′)∥≤∥x−x′∥/(1−α);
  7. Theorem 1 itself: existence and uniqueness, non-anticipation (9), continuity (10);
  8. the regeneration property (11): with x∗(t)=z(T)+x(T+t)−x(T)x^*(t)=z(T)+x(T+t)-x(T)x∗(t)=z(T)+x(T+t)−x(T), y∗(t)=y(T+t)−y(T)y^*(t)=y(T+t)-y(T)y∗(t)=y(T+t)−y(T), z∗(t)=z(T+t)z^*(t)=z(T+t)z∗(t)=z(T+t), one has y∗=ψ(x∗)y^*=\psi(x^*)y∗=ψ(x∗), z∗=ϕ(x∗)z^*=\phi(x^*)z∗=ϕ(x∗).

Milestone 7 is the platform theorem Reiman84.QueueLength.lemma_1, posed as an open target by an earlier mission (Reiman 1984 cites it as its Lemma 1). It is referenced here and not posed again.

Significance

Corollary 1 is what makes ZZZ a usable stochastic process: adaptedness and almost-sure uniqueness say ZZZ is determined by the driving Brownian motion in a non-anticipating way, and the Markov property with time-homogeneous kernels is the starting point for the change-of-variable formula of §3, for generators, for stationary distributions, and for the heavy-traffic limit theorems in which ZZZ appears as the limit. The pathwise map ϕ\phiϕ and its Lipschitz continuity are reused throughout queueing theory: the continuous-mapping argument for heavy-traffic limits rests on exactly the continuity (10) established here.

The results are classical, with complete published proofs. None of them has a machine-checked proof. Mathlib has the measure-theoretic layer (kernels, conditional expectation, independence) but no reflection maps, no construction of multidimensional Brownian motion with drift, and no Markov-process theory in continuous time. This mission provides a formal statement of the pathwise reflection theory and its probabilistic consequence on which such a development can build.

Difficulty

The pathwise part is a contraction argument, but the contraction is not in the original norm: the map y↦yQy\mapsto yQy↦yQ need not be a contraction for any standard norm when only the spectral radius of QQQ is below one. The proof first changes coordinates by a positive diagonal matrix, and the right norm must be matched to the row-vector convention. The fixed-point characterization also has to be shown equivalent to the complementarity condition (8), which is where the zero diagonal of QQQ enters.

For Corollary 1, the difficulty is measure-theoretic. Adaptedness requires measurability of a path functional with respect to the uncompleted natural filtration, which uses (9) and (10) and the fact that continuous paths are determined by countably many coordinates. The Markov property requires the regeneration identity (11) together with independence of the post-sss increments of XXX from Fs\mathcal F_sFs​, and a kernel that is jointly measurable and independent of the initial law. Conditioning on Fs\mathcal F_sFs​ alone, without identifying the future as a fixed functional of Z(s)Z(s)Z(s) and an independent Brownian motion, does not give a kernel that is the same for all sss.

Formalization scope

  • RK\mathbb R^KRK is Fin K → ℝ (paper index jjj = Lean index j−1j-1j−1), with K≥1K\ge1K≥1; row vector times matrix is Matrix.vecMul. Paths are functions ℝ → Fin K → ℝ; only times t≥0t\ge0t≥0 are constrained.
  • Spectral radius <1<1<1 is rendered as Qm→0Q^m\to0Qm→0, the rendering of Reiman84.QueueLength.lemma_1. AAA is PosSemidef.
  • (5)–(8) are the published Reiman84.QueueLength.IsReflectionPair; (8) reads "yjy_jyj​ is constant on every interval [s,t]⊆[0,∞)[s,t]\subseteq[0,\infty)[s,t]⊆[0,∞) on which zj>0z_j>0zj​>0". CSC_SCS​ is IsCPlus; uniform convergence on compacts is UocTendsto; Brownian motion from 000 with drift and covariance is IsDriftedBM.
  • The norm on C[0,T]C[0,T]C[0,T] is sup⁡0≤t≤T∥y(t)∥∞\sup_{0\le t\le T}\|y(t)\|_\inftysup0≤t≤T​∥y(t)∥∞​. The suprema in π\piπ and in the norm are real suprema, honest only for continuous paths, and every statement using them assumes continuity.
  • The paper's ∥P∥\|P\|∥P∥ is printed as the maximal row sum. Under the row-vector convention the contraction, Picard and Lipschitz steps need the maximal column sum; with the printed reading the contraction inequality is false (a nilpotent 3×33\times33×3 counterexample is recorded in those items). Veinott scaling is stated as printed; applying it to Q⊤Q^\topQ⊤ gives the column version.
  • The Brownian motion is X=X0+ξX=X_0+\xiX=X0​+ξ with ξ\xiξ a drifted Brownian motion from 000 and X0≥0X_0\ge0X0​≥0 a.s. independent of the whole process ξ\xiξ. Ft\mathcal F_tFt​ is the uncompleted σ-algebra generated by X(s)X(s)X(s), 0≤s≤t0\le s\le t0≤s≤t.
  • YYY and ZZZ enter Corollary 1 as hypotheses: a solution of (5)–(8) on {X∈CS}\{X\in C_S\}{X∈CS​}, zero elsewhere. That such processes exist is the existence part of Theorem 1, the referenced open item.
  • The kernel family is quantified before the probability space, so it cannot depend on sss, on Ω\OmegaΩ or on the law of X(0)X(0)X(0). A version of (c) with a kernel depending on these, with the completed or full σ-algebra in place of Fs\mathcal F_sFs​, or with one-dimensional marginals only, is a different and weaker statement and is ruled out.

Out of scope: Theorem 2 (the change-of-variable formula, which needs stochastic integration), the necessity of spectral radius <1<1<1, and §§3–4. Useful contributions beyond the milestones include a construction of multidimensional Brownian motion with drift in Mathlib, the Skorokhod map as a function on CSC_SCS​, and general lemmas on measurability of continuous path functionals.

Selected references

  • J. M. Harrison and M. I. Reiman, Reflected Brownian Motion on an Orthant, Annals of Probability 9(2), 302–308, 1981. https://doi.org/10.1214/aop/1176994471
  • M. I. Reiman, Open Queueing Networks in Heavy Traffic, Mathematics of Operations Research 9(3), 441–458, 1984. https://doi.org/10.1287/moor.9.3.441
  • A. F. Veinott, Jr., Discrete Dynamic Programming with Sensitive Discount Optimality Criteria, Annals of Mathematical Statistics 40(5), 1635–1660, 1969. https://doi.org/10.1214/aoms/1177697379
  • A. V. Skorokhod, Stochastic Equations for Diffusion Processes in a Bounded Region, Theory of Probability and Its Applications 6(3), 264–274, 1961. https://doi.org/10.1137/1106035
  • D. W. Stroock and S. R. S. Varadhan, Diffusion Processes with Boundary Conditions, Communications on Pure and Applied Mathematics 24, 147–225, 1971. https://doi.org/10.1002/cpa.3160240206
12 thms1 active userReviewed
OptimizationProbabilityStochastic Systems·Captain: mikedeng1

Mean-Variance Hedging in Continuous Time: The Feedback Futures Strategy Φ(G*) Minimizes the Expected Squared Deviation of Terminal Wealth from Any Target LevelResearch Paper

Motivation

A firm that will receive or deliver a quantity of a commodity, currency or security at a future date carries price risk until that date. When the asset itself cannot be traded in the meantime, the standard instrument for reducing that risk is a futures contract on a correlated asset: the firm takes a position in futures and adjusts it over time, and the gains or losses of the futures position offset part of the movement of its commitment. Choosing that position is the hedging problem. The classical answer, the minimum-variance hedge ratio, is a static one-period rule. Duffie and Richardson (Ann. Appl. Probab. 1991) solved the dynamic version in continuous time with a quadratic criterion: minimize the expected squared deviation of terminal wealth from a target. Their explicit feedback solution became a reference point for the later literature on mean-variance hedging in incomplete markets (Schweizer, Gouriéroux–Laurent–Pham, and others), where the same quadratic criterion is studied under general semimartingale prices.

Setting

Fix a horizon T>0T>0T>0 and a probability space (Ω,F,P)(\Omega,\mathcal F,P)(Ω,F,P) carrying a two-dimensional standard Brownian motion (B,ε)(B,\varepsilon)(B,ε) with its filtration F\mathbb FF. Let μ,σ,m,v,ρ\mu,\sigma,m,v,\rhoμ,σ,m,v,ρ be bounded measurable functions on [0,T][0,T][0,T], with ∣v∣|v|∣v∣ bounded away from zero and ρt∈[−1,1]\rho_t\in[-1,1]ρt​∈[−1,1]. The Brownian motion ξt=∫0tρs dBs+∫0t1−ρs2 dεs\xi_t=\int_0^t\rho_s\,dB_s+\int_0^t\sqrt{1-\rho_s^2}\,d\varepsilon_sξt​=∫0t​ρs​dBs​+∫0t​1−ρs2​​dεs​ has instantaneous correlation ρ\rhoρ with BBB. The committed asset SSS and the futures price FFF follow

dSt=μtSt dt+σtSt dBt,dFt=mtFt dt+vtFt dξt,S0,F0>0.dS_t=\mu_tS_t\,dt+\sigma_tS_t\,dB_t,\qquad dF_t=m_tF_t\,dt+v_tF_t\,d\xi_t,\qquad S_0,F_0>0.dSt​=μt​St​dt+σt​St​dBt​,dFt​=mt​Ft​dt+vt​Ft​dξt​,S0​,F0​>0.

The hedger is committed to kkk units of SSS at time TTT. A trading strategy is a progressively measurable process θ\thetaθ (the futures position) with E∫0Tθt2Ft2 dt<∞E\int_0^T\theta_t^2F_t^2\,dt<\inftyE∫0T​θt2​Ft2​dt<∞; Θ\ThetaΘ denotes the set of them. Its futures gain is the stochastic integral G(θ)t=∫0tθs dFsG(\theta)_t=\int_0^t\theta_s\,dF_sG(θ)t​=∫0t​θs​dFs​, and the terminal wealth is W(θ)=kST+G(θ)TW(\theta)=kS_T+G(\theta)_TW(θ)=kST​+G(θ)T​. Given a target level L∈RL\in\mathbb RL∈R, problem (3) is

min⁡θ∈ΘE[(W(θ)−L)2].\min_{\theta\in\Theta}E\big[(W(\theta)-L)^2\big].θ∈Θmin​E[(W(θ)−L)2].

With γt=mtσtρt/vt−μt\gamma_t=m_t\sigma_t\rho_t/v_t-\mu_tγt​=mt​σt​ρt​/vt​−μt​, the tracking process is Zt=kexp⁡(−∫tTγs ds)StZ_t=k\exp(-\int_t^T\gamma_s\,ds)S_tZt​=kexp(−∫tT​γs​ds)St​, so that ZT=kSTZ_T=kS_TZT​=kST​, and the feedback map is

Φ(Gt∗)=1Ft[mtvt2(L−Zt−Gt∗)−σtρtvtZt],\Phi(G^*_t)=\frac1{F_t}\Big[\frac{m_t}{v_t^2}(L-Z_t-G^*_t)-\frac{\sigma_t\rho_t}{v_t}Z_t\Big],Φ(Gt∗​)=Ft​1​[vt2​mt​​(L−Zt​−Gt∗​)−vt​σt​ρt​​Zt​],

where G∗G^*G∗ solves dGt∗=Φ(Gt∗) dFtdG^*_t=\Phi(G^*_t)\,dF_tdGt∗​=Φ(Gt∗​)dFt​, G0∗=0G^*_0=0G0∗​=0. The strategy φ=Φ(G∗)\varphi=\Phi(G^*)φ=Φ(G∗) depends only on the gains realized so far and the current price StS_tSt​.

Formalization targets

Goal: Proposition 1

φt=Φ(Gt∗)  solves  min⁡θ∈ΘE[(kST+G(θ)T−L)2]\varphi_t=\Phi(G^*_t)\ \text{ solves }\ \min_{\theta\in\Theta}E\big[(kS_T+G(\theta)_T-L)^2\big]φt​=Φ(Gt∗​)  solves  θ∈Θmin​E[(kST​+G(θ)T​−L)2]

for every commitment kkk, every target LLL and every solution G∗G^*G∗ of (10). No constant is hard-coded: the statement is the paper's for arbitrary coefficients satisfying the standing hypotheses.

Milestones

  1. Lemma 1: φ∈Θ\varphi\in\Thetaφ∈Θ is optimal iff E[(L−kST−G(φ)T) G(θ)T]=0E[(L-kS_T-G(\varphi)_T)\,G(\theta)_T]=0E[(L−kST​−G(φ)T​)G(θ)T​]=0 for every θ∈Θ\theta\in\Thetaθ∈Θ.
  2. Existence (§3.3): equation (10) has a solution with Gt∗∈L2(P)G^*_t\in L^2(P)Gt∗​∈L2(P).
  3. Itô dynamics of ZZZ: dZt=(γt+μt)Zt dt+σtZt dBtdZ_t=(\gamma_t+\mu_t)Z_t\,dt+\sigma_tZ_t\,dB_tdZt​=(γt​+μt​)Zt​dt+σt​Zt​dBt​.
  4. Moment equations for E(ZtGt)E(Z_tG_t)E(Zt​Gt​), E(Gt∗Gt)E(G^*_tG_t)E(Gt∗​Gt​) and E(Gt)E(G_t)E(Gt​), with G=G(θ)G=G(\theta)G=G(θ).
  5. Lemma 2: Ht=E[(L−Zt−Gt∗)G(θ)t]H_t=E[(L-Z_t-G^*_t)G(\theta)_t]Ht​=E[(L−Zt​−Gt∗​)G(θ)t​] satisfies H˙t=−(mt2/vt2)Ht\dot H_t=-(m_t^2/v_t^2)H_tH˙t​=−(mt2​/vt2​)Ht​.
  6. The solution of (13): Ht=H0exp⁡(−∫0tms2/vs2 ds)H_t=H_0\exp(-\int_0^tm_s^2/v_s^2\,ds)Ht​=H0​exp(−∫0t​ms2​/vs2​ds).

Two further items, not milestones, formalize §4: Lemma 3 (a solution of (3) is mean-variance efficient) and §4.1 (maximizing the quadratic utility E[W−cW2]E[W-cW^2]E[W−cW2], c>0c>0c>0, is problem (3) with L=1/(2c)L=1/(2c)L=1/(2c)).

Significance

Proposition 1 gives the optimal dynamic hedge in closed feedback form for every target level at once. Varying LLL traces out the whole mean-variance frontier of terminal wealth (Lemma 3), and the choice L=1/(2c)L=1/(2c)L=1/(2c) solves the quadratic-utility problem (§4.1); the minimum-variance hedge of §4.3 of the paper is obtained by optimizing over LLL. The result is also an instance of a general pattern: a quadratic hedging problem in an incomplete market reduces to an L2L^2L2 projection onto the space of attainable gains, and the projection is computed by a linear SDE.

The result is proved in the paper, in six pages. No machine-checked version of it, or of any continuous-time hedging result, exists on the platform. A formalization requires Itô's formula for products of Itô processes, the zero-mean property of square-integrable stochastic integrals, Fubini's theorem for moments, and existence for a linear SDE with an Itô-process forcing term; each of these is reusable well beyond this paper.

Difficulty

The projection step (Lemma 1) is Hilbert-space geometry and the final ODE step is Grönwall. The difficulty lies in between: the orthogonality E[(L−kST−GT∗)G(θ)T]=0E[(L-kS_T-G^*_T)G(\theta)_T]=0E[(L−kST​−GT∗​)G(θ)T​]=0 must be verified against every trading strategy θ\thetaθ, about which only E∫0Tθt2Ft2 dt<∞E\int_0^T\theta_t^2F_t^2\,dt<\inftyE∫0T​θt2​Ft2​dt<∞ is known. A computation that treats θ\thetaθ as bounded, continuous or simple does not suffice. Making the paper's moment computations rigorous requires controlling the integrability of products such as ZtθtFtZ_t\theta_tF_tZt​θt​Ft​ and Gt∗G(θ)tG^*_tG(\theta)_tGt∗​G(θ)t​, proving that the stochastic-integral parts of Itô's product rule are true martingales rather than local martingales, and differentiating expectations in time when the coefficients are only measurable, so that derivatives exist only almost everywhere.

Formalization scope

The stochastic layer is the published definition file Peng1990_SMP_Stochastic (the L2L^2L2 Itô integral and Itô processes on R≥0\mathbb R_{\ge0}R≥0​ time), imported, not redefined. The mission commits to the following conventions.

  • (B,ε)(B,\varepsilon)(B,ε) is one R2\mathbb R^2R2-valued standard Brownian motion; BBB is coordinate 0, ε\varepsilonε coordinate 1, and dξd\xidξ is expanded as ρ dB+1−ρ2 dε\rho\,dB+\sqrt{1-\rho^2}\,d\varepsilonρdB+1−ρ2​dε.
  • The filtration is the natural filtration of (B,ε)(B,\varepsilon)(B,ε), not its augmentation, and trading strategies are progressively measurable instead of predictable. Neither change alters the space of terminal gains.
  • Gains are relations: a gain process is any version of the Itô integral, and every statement quantifies over all versions.
  • The objective E[(W−L)2]E[(W-L)^2]E[(W−L)2] and variances take values in [0,∞][0,\infty][0,∞], so a non-square-integrable wealth cannot be optimal through a junk value 000; inner products carry explicit integrability.
  • ρt∈[−1,1]\rho_t\in[-1,1]ρt​∈[−1,1] (§3.1), not [0,1][0,1][0,1] (§2). The sign of vvv is free; only ∣v∣≥δ>0|v|\ge\delta>0∣v∣≥δ>0 is assumed.
  • "Φ(G∗)\Phi(G^*)Φ(G∗) defined by (9)–(11)" means: for every solution of (10), where a solution includes that Φ(G∗)\Phi(G^*)Φ(G∗) is a trading strategy. The paper takes this membership for granted.
  • Lemma 2 and the moment equations are stated in integral form (Ht=H0−∫0t(m2/v2)H dsH_t=H_0-\int_0^t(m^2/v^2)H\,dsHt​=H0​−∫0t​(m2/v2)Hds), which is the paper's "for almost every ttt" derivative together with absolute continuity; continuity of the coefficients is not assumed.
  • The display for dZdZdZ in the proof of Lemma 2 omits dtdtdt; the drift is (γt+μt)Zt dt(\gamma_t+\mu_t)Z_t\,dt(γt​+μt​)Zt​dt.
  • In §4.1, c>0c>0c>0 is assumed explicitly.

Proposition 1 would hold vacuously if equation (10) had no solution; the existence milestone rules this out and must be proved, not assumed. Contributions are welcome on Itô's product formula and the martingale property of Itô integrals in the Peng framework, on the existence of solutions of linear SDEs, and on the Grönwall-type uniqueness for (13).

Selected references

  • D. Duffie, H. R. Richardson, Mean-Variance Hedging in Continuous Time, The Annals of Applied Probability 1(1) (1991) 1–15. https://doi.org/10.1214/aoap/1177005978
  • S. Peng, A General Stochastic Maximum Principle for Optimal Control Problems, SIAM J. Control Optim. 28(4) (1990) 966–979. https://doi.org/10.1137/0328054
  • P. Protter, Stochastic Integration and Differential Equations, Springer, 1990. https://doi.org/10.1007/978-3-662-02619-9
  • D. G. Luenberger, Optimization by Vector Space Methods, Wiley, 1969.
  • M. Schweizer, Mean-Variance Hedging for General Claims, The Annals of Applied Probability 2(1) (1992) 171–179. https://doi.org/10.1214/aoap/1177005776
11 thms1 active userReviewed
OptimizationProbabilityStatistics·Captain: mikedeng1

Statistics of Robust Optimization: A Generalized Empirical Likelihood Approach 3: Robust Optimal Values and Solution Sets over f-Divergence Balls Are ConsistentResearch Paper

Motivation

Stochastic optimization asks for a decision xxx in a set X⊂Rd\mathcal X\subset\mathbb R^dX⊂Rd that minimises an expected loss EP0[ℓ(x;ξ)]E_{P_0}[\ell(x;\xi)]EP0​​[ℓ(x;ξ)] when the distribution P0P_0P0​ of the data ξ\xiξ is known only through a sample ξ1,…,ξn\xi_1,\dots,\xi_nξ1​,…,ξn​. The classical estimator, sample average approximation, replaces P0P_0P0​ by the empirical distribution P^n\widehat P_nPn​. Distributionally robust optimization instead minimises the worst-case expected loss over all distributions close to P^n\widehat P_nPn​. Duchi, Glynn and Namkoong (arXiv:1610.03425v3; Math. Oper. Res. 46(3), 2021) take the neighbourhood to be an fff-divergence ball of radius ρ/n\rho/nρ/n and show that the robust optimal value is a calibrated upper confidence bound for the population optimum, in the spirit of Owen's empirical likelihood.

A confidence bound is useful only if the robust problem still estimates the right thing. Section 5 of the paper answers this: under essentially the conditions that make sample average approximation consistent, the robust optimal value converges to the population optimal value, and the robust minimisers approach the population minimisers. This mission formalizes that consistency result (contribution (iv), p. 3, and §5.1).

Setting

Let ξ1,ξ2,…\xi_1,\xi_2,\dotsξ1​,ξ2​,… be i.i.d. random elements of a separable metric space Ξ\XiΞ with law P0P_0P0​, and let P^n\widehat P_nPn​ be the empirical distribution of ξ1,…,ξn\xi_1,\dots,\xi_nξ1​,…,ξn​. Let ℓ:Rd×Ξ→R\ell:\mathbb R^d\times\Xi\to\mathbb Rℓ:Rd×Ξ→R be lower semicontinuous on X×Ξ\mathcal X\times\XiX×Ξ, with ℓ(x;⋅)\ell(x;\cdot)ℓ(x;⋅) measurable for x∈Xx\in\mathcal Xx∈X, and let X⊂Rd\mathcal X\subset\mathbb R^dX⊂Rd be a nonempty closed feasible set, as in the paper's opening setup (p. 1).

The divergence generator f:[0,∞)→R∪{+∞}f:[0,\infty)\to\mathbb R\cup\{+\infty\}f:[0,∞)→R∪{+∞} is convex with f(1)=0f(1)=0f(1)=0; Assumption A asks moreover that fff be three times differentiable near 111 with f′(1)=0f'(1)=0f′(1)=0 and f′′(1)=2f''(1)=2f′′(1)=2. For a distribution P≪P^nP\ll\widehat P_nP≪Pn​ with weights pip_ipi​ on the sample points, Df(P∥P^n)=1n∑if(npi)D_f(P\|\widehat P_n)=\frac1n\sum_i f(np_i)Df​(P∥Pn​)=n1​∑i​f(npi​). The robust objective and the population objective are

F^n(x)=sup⁡P≪P^n{EP[ℓ(x;ξ)]:Df(P∥P^n)≤ρn},F(x)=EP0[ℓ(x;ξ)],\widehat F_n(x)=\sup_{P\ll\widehat P_n}\Big\{E_P[\ell(x;\xi)] : D_f(P\|\widehat P_n)\le\frac{\rho}{n}\Big\},\qquad F(x)=E_{P_0}[\ell(x;\xi)],Fn​(x)=P≪Pn​sup​{EP​[ℓ(x;ξ)]:Df​(P∥Pn​)≤nρ​},F(x)=EP0​​[ℓ(x;ξ)],

with radius parameter ρ≥0\rho\ge0ρ≥0. Their solution sets are SP^n⋆=argmin⁡x∈XF^n(x)S^\star_{\widehat P_n}=\operatorname{argmin}_{x\in\mathcal X}\widehat F_n(x)SPn​⋆​=argminx∈X​Fn​(x) and SP0⋆=argmin⁡x∈XF(x)S^\star_{P_0}=\operatorname{argmin}_{x\in\mathcal X}F(x)SP0​⋆​=argminx∈X​F(x) (display (23)). The inclusion distance from a set AAA to a set BBB is d⊂(A,B)=sup⁡x∈Adist⁡(x,B)d_\subset(A,B)=\sup_{x\in A}\operatorname{dist}(x,B)d⊂​(A,B)=supx∈A​dist(x,B) (display (6)).

Assumption E asks for a measurable envelope Z≥0Z\ge0Z≥0 with ∣ℓ(x;ξ)∣≤Z(ξ)|\ell(x;\xi)|\le Z(\xi)∣ℓ(x;ξ)∣≤Z(ξ) for all x∈Xx\in\mathcal Xx∈X and EP0[Z1+ϵ]<∞E_{P_0}[Z^{1+\epsilon}]<\inftyEP0​​[Z1+ϵ]<∞ for some ϵ>0\epsilon>0ϵ>0. A class H\mathcal HH of functions on Ξ\XiΞ is Glivenko–Cantelli (Definition 2) if sup⁡h∈H∣EP^n[h]−EP0[h]∣→0\sup_{h\in\mathcal H}|E_{\widehat P_n}[h]-E_{P_0}[h]|\to0suph∈H​∣EPn​​[h]−EP0​​[h]∣→0 almost surely.

Formalization targets

Goal: Corollary 1 (p. 17)

Let Assumptions A and E hold, let X\mathcal XX be nonempty and compact, and let ℓ(⋅;ξ)\ell(\cdot;\xi)ℓ(⋅;ξ) be continuous on X\mathcal XX for every ξ\xiξ. Then, in outer probability,

inf⁡x∈XF^n(x)−inf⁡x∈XF(x)→P∗0andd⊂(SP^n⋆,SP0⋆)→P∗0.\inf_{x\in\mathcal X}\widehat F_n(x)-\inf_{x\in\mathcal X}F(x)\xrightarrow{P^*}0 \qquad\text{and}\qquad d_\subset\big(S^\star_{\widehat P_n},S^\star_{P_0}\big)\xrightarrow{P^*}0 .x∈Xinf​Fn​(x)−x∈Xinf​F(x)P∗​0andd⊂​(SPn​⋆​,SP0​⋆​)P∗​0.

Both conclusions belong to the goal. No rate is asserted; the statement survives any later sharpening.

Milestones

  1. Lemma 13 (p. 34): the likelihood-ratio vectors of the ball satisfy ∥np−1∥2≤ρCf\|np-\mathbb 1\|_2\le\sqrt{\rho C_f}∥np−1∥2​≤ρCf​​ uniformly in nnn, and the bound is of the right order (≥ρcf\ge\sqrt{\rho c_f}≥ρcf​​ for some n,pn,pn,p).
  2. (47) (App. E.1, p. 46): ∣EP[ℓ]−EP0[ℓ]∣≤EP^n[∣L−1∣p]1/pEP^n[∣ℓ∣q]1/q+∣EP^n[ℓ]−EP0[ℓ]∣|E_P[\ell]-E_{P_0}[\ell]|\le E_{\widehat P_n}[|L-1|^p]^{1/p}E_{\widehat P_n}[|\ell|^q]^{1/q}+|E_{\widehat P_n}[\ell]-E_{P_0}[\ell]|∣EP​[ℓ]−EP0​​[ℓ]∣≤EPn​​[∣L−1∣p]1/pEPn​​[∣ℓ∣q]1/q+∣EPn​​[ℓ]−EP0​​[ℓ]∣ with q=min⁡{2,1+ϵ}q=\min\{2,1+\epsilon\}q=min{2,1+ϵ}, p=max⁡{2,1+1/ϵ}p=\max\{2,1+1/\epsilon\}p=max{2,1+1/ϵ}.
  3. The display after (47) (p. 46): EP^n[∣L−1∣p]1/p≤n−1/pρCfE_{\widehat P_n}[|L-1|^p]^{1/p}\le n^{-1/p}\sqrt{\rho C_f}EPn​​[∣L−1∣p]1/p≤n−1/pρCf​​.
  4. Theorem 7 (p. 16): if {ℓ(x;⋅):x∈X}\{\ell(x;\cdot):x\in\mathcal X\}{ℓ(x;⋅):x∈X} is Glivenko–Cantelli, then
sup⁡x∈Xsup⁡P≪P^n{∣EP[ℓ(x;ξ)]−EP0[ℓ(x;ξ)]∣:Df(P∥P^n)≤ρn}→a.s.∗0.\sup_{x\in\mathcal X}\sup_{P\ll\widehat P_n}\Big\{|E_P[\ell(x;\xi)]-E_{P_0}[\ell(x;\xi)]| : D_f(P\|\widehat P_n)\le\tfrac{\rho}{n}\Big\}\xrightarrow{\text{a.s.}^*}0.x∈Xsup​P≪Pn​sup​{∣EP​[ℓ(x;ξ)]−EP0​​[ℓ(x;ξ)]∣:Df​(P∥Pn​)≤nρ​}a.s.∗​0.
  1. Example 5 (p. 16, from van der Vaart, Asymptotic Statistics, Example 19.8): a class of losses continuous on a compact X\mathcal XX for almost every ξ\xiξ, with an integrable envelope, is Glivenko–Cantelli.

Significance

The result. Corollary 1 shows that robustness against a ρ/n\rho/nρ/n-divergence perturbation of the data costs nothing asymptotically: the robust optimal value and its minimisers are consistent for the population problem. Together with the paper's coverage theorem, this justifies using the robust value both as a point estimate and as an upper confidence bound. Theorem 7 is stronger than what the corollary needs: it controls every reweighting in the ball uniformly over X\mathcal XX, which is the uniform law of large numbers for distributionally robust objectives, and it needs only slightly more than the first moment that sample average approximation needs.

Formalizing it. The results are proved in the paper; none is machine-checked. A formal development would supply a Glivenko–Cantelli notion for parametric loss classes, the bracketing argument behind Example 5 (a uniform strong law over a compact parameter set, not in Mathlib), and the passage from uniform convergence of objectives to convergence of optimal values and of argmin sets in the inclusion distance. The last two are standard steps of M-estimation and sample average approximation theory that are reusable well beyond this paper.

Difficulty

The obvious argument writes EP[ℓ]−EP0[ℓ]E_P[\ell]-E_{P_0}[\ell]EP​[ℓ]−EP0​​[ℓ] as a reweighting term plus the ordinary empirical deviation and handles the second by the Glivenko–Cantelli property. The reweighting term 1n∑i(npi−1)ℓ(x;ξi)\frac1n\sum_i(np_i-1)\ell(x;\xi_i)n1​∑i​(npi​−1)ℓ(x;ξi​) is the obstacle: the weights npinp_inpi​ are not bounded uniformly in nnn for every divergence, and a Cauchy–Schwarz bound would need a second moment of the envelope, which Assumption E does not provide. The exponent pair (p,q)(p,q)(p,q) and the uniform ℓ2\ell_2ℓ2​ control of Lemma 13 are what make 1+ϵ1+\epsilon1+ϵ moments enough.

For the solution sets, uniform convergence of F^n\widehat F_nFn​ to FFF does not by itself place the minimisers of F^n\widehat F_nFn​ near those of FFF; compactness of X\mathcal XX and continuity of FFF are needed to separate FFF on the complement of an ϵ\epsilonϵ-enlargement of SP0⋆S^\star_{P_0}SP0​⋆​ from its minimum. Measurability is a further obstacle: suprema over uncountable X\mathcal XX and over the divergence ball need not be measurable, which is why the paper works with outer probability and outer almost-sure convergence.

Formalization scope

  • Samples are ξ : ℕ → Ω → Ξ on a probability space, measurable, mutually independent (iIndepFun) and identically distributed with ξ 0; P0P_0P0​ is the law of ξ 0, and P^n\widehat P_nPn​ uses ξ 0, …, ξ (n-1) (0-based indices). The separable metric sample domain and lower semicontinuous loss from p. 1 are explicit in Theorem 7 and Corollary 1. Decisions live in EuclideanSpace ℝ (Fin d); ℓ x is measurable for each x∈Xx\in\mathcal Xx∈X.
  • fff is ℝ → EReal satisfying the published IsPhiDivergenceFunction (never −∞-\infty−∞, finite on (0,∞)(0,\infty)(0,∞), f(1)=0f(1)=0f(1)=0, convex on [0,∞)[0,\infty)[0,∞)) plus the smoothness of Assumption A, stated on t↦(f t).toRealt\mapsto(f\,t).\mathrm{toReal}t↦(ft).toReal on an open interval around 111.
  • A distribution P≪P^nP\ll\widehat P_nP≪Pn​ in the ball is a weight vector in the published probUncertaintySet f (1/n,…,1/n) (ρ/n), i.e. {p≥0:∑pi=1, ∑if(npi)≤ρ}\{p\ge0:\sum p_i=1,\ \sum_i f(np_i)\le\rho\}{p≥0:∑pi​=1, ∑i​f(npi​)≤ρ}. Every supremum "over PPP with Df(P∥P^n)≤ρ/nD_f(P\|\widehat P_n)\le\rho/nDf​(P∥Pn​)≤ρ/n" is read over P≪P^nP\ll\widehat P_nP≪Pn​, as in (4a).
  • Suprema of absolute deviations (Definition 2, Theorem 7) are taken in [0,∞][0,\infty][0,∞], and d⊂d_\subsetd⊂​ is [0,∞][0,\infty][0,∞]-valued; an unbounded family therefore cannot satisfy them through a junk real supremum of 000. Almost-sure statements use Mathlib's ∀ᵐ, which requires the exceptional set to have outer measure zero; convergence in outer probability is μ{ω:δ<∣Xn(ω)∣}→0\mu\{\omega:\delta<|X_n(\omega)|\}\to0μ{ω:δ<∣Xn​(ω)∣}→0 for every δ>0\delta>0δ>0 with Mathlib's outer measure and no measurability hypothesis.
  • Readings recorded in the items: in (47) the middle term is EP^n[∣L−1∣ ∣ℓ∣]E_{\widehat P_n}[|L-1|\,|\ell|]EPn​​[∣L−1∣∣ℓ∣] (the page omits the absolute value on ℓ\ellℓ); in the display after (47), ρ/γf\sqrt{\rho/\gamma_f}ρ/γf​​ is ρCf\sqrt{\rho C_f}ρCf​​ with CfC_fCf​ from Lemma 13; in Lemma 13 the constants may depend on ρ\rhoρ as well as fff, as in its proof.
  • A trivializing formalization would take the suprema in R\mathbb RR (where an unbounded set has supremum 000), or allow the argmin sets to be empty by construction; neither is possible here, and nonemptiness of the solution sets is not assumed.
  • Contributions welcome: a Glivenko–Cantelli library for parametric classes (Example 5), the deterministic inequalities (47) and Lemma 13, and the argmin-consistency argument of Corollary 1.

Selected references

  • J. C. Duchi, P. W. Glynn, H. Namkoong, Statistics of Robust Optimization: A Generalized Empirical Likelihood Approach, arXiv:1610.03425v3, 2018; Math. Oper. Res. 46(3), 2021. https://arxiv.org/abs/1610.03425 , https://doi.org/10.1287/moor.2020.1085
  • A. W. van der Vaart, Asymptotic Statistics, Cambridge University Press, 1998 (Example 19.8). https://doi.org/10.1017/CBO9780511802256
  • A. W. van der Vaart, J. A. Wellner, Weak Convergence and Empirical Processes, Springer, 1996. https://doi.org/10.1007/978-1-4757-2545-2
  • A. B. Owen, Empirical Likelihood, Chapman & Hall/CRC, 2001. https://doi.org/10.1201/9781420036152
  • A. Ben-Tal, D. den Hertog, A. De Waegenaere, B. Melenberg, G. Rennen, Robust Solutions of Optimization Problems Affected by Uncertain Probabilities, Management Science 59(2), 2013. https://doi.org/10.1287/mnsc.1120.1641
16 thms1 active userReviewed
Convex OptimizationOptimizationProbability·Captain: mikedeng1

Deterministic Equivalents for Optimizing and Satisficing under Chance Constraints 1: Under Normality, the E-Model Chance Constraints Are Equivalent to the Convex Program (29)Research Paper

Motivation

Chance-constrained programming replaces a linear program max⁡c′x\max c'xmaxc′x subject to Ax≤bAx\le bAx≤b by a problem in which some data are random and each constraint only has to hold with a prescribed probability. Charnes and Cooper introduced the idea in 1959 for scheduling heating-oil production against weather-dependent demand, and the formulation is now a standard modelling tool in operations research, finance, energy systems and engineering design (Charnes and Cooper 1959; Prékopa 1995).

A chance-constrained problem is not directly solvable: its constraints are probabilities of events that depend on the decision. The 1963 paper of Charnes and Cooper (doi:10.1287/opre.11.1.18) asks when such a problem has a deterministic equivalent, an ordinary mathematical program with the same feasible decisions and corresponding objective values, and when that equivalent is a convex program. Its first answer, for the expected-value ('E') model under linear decision rules and normality, is the subject of this mission. The resulting constraint form, a mean slack dominating KαK_\alphaKα​ standard deviations, is an early instance of the second-order-cone reformulation of individual normal chance constraints used throughout modern stochastic and robust optimization.

Timeline. 1959: Charnes and Cooper, chance-constrained programming with the heating-oil model. 1963: this paper, deterministic equivalents for the E, V and P models under linear decision rules x=Dbx=Dbx=Db. 1965: Miller and Wagner treat joint chance constraints with independent rows (doi:10.1287/opre.13.6.930). 1971: Prékopa's logarithmically concave measures give convexity of joint chance constraints under log-concave laws.

Setting

Let (Ω,F,P)(\Omega,\mathcal F,P)(Ω,F,P) be a probability space. The data are a constant m×nm\times nm×n matrix AAA with rows a1′,…,am′a_1',\dots,a_m'a1′​,…,am′​, a random right-hand side b:Ω→Rmb:\Omega\to\mathbb R^mb:Ω→Rm and random objective coefficients c:Ω→Rnc:\Omega\to\mathbb R^nc:Ω→Rn. A linear decision rule is an n×mn\times mn×m real matrix DDD; it chooses x=Dbx=Dbx=Db after bbb is observed. Write μb=Eb\mu_b=Ebμb​=Eb, μc=Ec\mu_c=Ecμc​=Ec and b^=b−μb\hat b=b-\mu_bb^=b−μb​.

The E-model (18) is

max⁡ E(c′Db)subject toP(ai′Db≤bi)≥αi(i=1,…,m),\max\ E(c'Db)\quad\text{subject to}\quad P(a_i'Db\le b_i)\ge\alpha_i\qquad(i=1,\dots,m),max E(c′Db)subject toP(ai′​Db≤bi​)≥αi​(i=1,…,m),

with one probability level αi\alpha_iαi​ per row: the constraints are row-wise, as in (3) of the paper, not a single joint constraint.

For 12<α<1\tfrac12<\alpha<121​<α<1 let Kα=Φ−1(α)>0K_\alpha=\Phi^{-1}(\alpha)>0Kα​=Φ−1(α)>0 be the standard normal α\alphaα-quantile. With the moment functions (30),

σi2(D)=E(ai′Db−bi)2,μi(D)=μbi−ai′Dμb,\sigma_i^2(D)=E(a_i'Db-b_i)^2,\qquad \mu_i(D)=\mu_{b_i}-a_i'D\mu_b,σi2​(D)=E(ai′​Db−bi​)2,μi​(D)=μbi​​−ai′​Dμb​,

the paper's deterministic program (29) in the variables (D,v)(D,v)(D,v), v∈Rmv\in\mathbb R^mv∈Rm, is

min⁡ −μc′Dμbs.t.μi(D)−vi≥0,−Kαi2σi2(D)+Kαi2μi2(D)+vi2≥0,vi≥0.\min\ -\mu_c'D\mu_b\quad\text{s.t.}\quad \mu_i(D)-v_i\ge0,\quad -K_{\alpha_i}^2\sigma_i^2(D)+K_{\alpha_i}^2\mu_i^2(D)+v_i^2\ge0,\quad v_i\ge0 .min −μc′​Dμb​s.t.μi​(D)−vi​≥0,−Kαi​2​σi2​(D)+Kαi​2​μi2​(D)+vi2​≥0,vi​≥0.

Formalization targets

Goal: (18) is equivalent to the convex program (29)

Assume every bkb_kbk​ is square integrable, every cjc_jcj​ and cjbkc_jb_kcj​bk​ integrable, bbb and ccc uncorrelated (E(cjbk)=Ecj EbkE(c_jb_k)=E c_j\,E b_kE(cj​bk​)=Ecj​Ebk​), every variate ai′Db−bia_i'Db-b_iai′​Db−bi​ normal (for every DDD and iii, zero variance allowed), and 12<αi<1\tfrac12<\alpha_i<121​<αi​<1. Then

(∀D: D feasible for (18)  ⟺  ∃v, (D,v) feasible for (29)) ∧ (∀D: E(c′Db)=μc′Dμb) ∧ {(D,v) feasible for (29)} is convex.\Big(\forall D:\ D\text{ feasible for (18)}\iff\exists v,\ (D,v)\text{ feasible for (29)}\Big)\ \wedge\ \Big(\forall D:\ E(c'Db)=\mu_c'D\mu_b\Big)\ \wedge\ \{(D,v)\ \text{feasible for (29)}\}\ \text{is convex}.(∀D: D feasible for (18)⟺∃v, (D,v) feasible for (29)) ∧ (∀D: E(c′Db)=μc′​Dμb​) ∧ {(D,v) feasible for (29)} is convex.

Milestones, in the order of the paper

  1. (19a): E(c′Db)=(Ec)′D(Eb)E(c'Db)=(Ec)'D(Eb)E(c′Db)=(Ec)′D(Eb) for uncorrelated bbb, ccc.
  2. (22)–(27): with positive variance, P(ai′Db≤bi)≥αi  ⟺  (−μbi+ai′Dμb)/E[b^i−ai′Db^]2≤−KαiP(a_i'Db\le b_i)\ge\alpha_i\iff(-\mu_{b_i}+a_i'D\mu_b)/\sqrt{E[\hat b_i-a_i'D\hat b]^2}\le-K_{\alpha_i}P(ai′​Db≤bi​)≥αi​⟺(−μbi​​+ai′​Dμb​)/E[b^i​−ai′​Db^]2​≤−Kαi​​.
  3. (28a)–(28b): (27) holds iff some viv_ivi​ satisfies μbi−ai′Dμb≥vi≥KαiE[b^i−ai′Db^]2≥0\mu_{b_i}-a_i'D\mu_b\ge v_i\ge K_{\alpha_i}\sqrt{E[\hat b_i-a_i'D\hat b]^2}\ge0μbi​​−ai′​Dμb​≥vi​≥Kαi​​E[b^i​−ai′​Db^]2​≥0.
  4. (28c)–(28d): for vi≥0v_i\ge0vi​≥0, that pair is equivalent to its squared form.
  5. Footnote ‡ to (30): σi2(D)−μi2(D)=E[b^i−ai′Db^]2\sigma_i^2(D)-\mu_i^2(D)=E[\hat b_i-a_i'D\hat b]^2σi2​(D)−μi2​(D)=E[b^i​−ai′​Db^]2.
  6. The convexity paragraph after (30): the feasible set of (29) is convex in (D,v)(D,v)(D,v).
  7. 'V Model' (32)–(34): under the same normal chance assumptions and square integrability of each cjbkc_jb_kcj​bk​, the chance constraints of (32) are equivalent to (33) for some vvv; the pair feasible set and V(D)=E(c′Db−z0)2V(D)=E(c'Db-z^0)^2V(D)=E(c′Db−z0)2 are convex.

Significance

The result. The theorem turns a problem whose constraints are probabilities into a finite-dimensional convex program whose data are the first two moments of bbb and the means of ccc. The optimal rules of (18) minimize (29), whose optimal value is the negative of the maximum in (18). The slack variables viv_ivi​ separate each constraint into a "quality" part (the mean slack μi(D)\mu_i(D)μi​(D)) and a "risk" part (KαiK_{\alpha_i}Kαi​​ standard deviations), which is the interpretation the paper develops in (31) and its Appendix. The same constraint set serves the V-model (33), so only the objective changes between the two models.

Formalizing it. The result is classical and its proof is elementary, but the paper's argument is informal in ways that matter for a machine-checked version: it divides by a standard deviation it then allows to vanish, writes FiF_iFi​ for what must be an upper-tail function, and labels a variance as σi2(D)\sigma_i^2(D)σi2​(D) while defining σi2(D)\sigma_i^2(D)σi2​(D) as a raw second moment. This mission produces a statement in which each of these points is settled, with every hypothesis explicit. No machine-checked version of the result is known to exist.

Difficulty

The chance-constraint step itself is a one-dimensional fact about the normal law, but three points need care. The variance of ai′Db−bia_i'Db-b_iai′​Db−bi​ may be zero for some DDD and iii; then the law is a point mass, the quotient in (27) is undefined, and the equivalence must be argued separately, as footnote † of p. 28 indicates. The quadratic constraint of (29) alone, vi2≥Kαi2(σi2(D)−μi2(D))v_i^2\ge K_{\alpha_i}^2(\sigma_i^2(D)-\mu_i^2(D))vi2​≥Kαi​2​(σi2​(D)−μi2​(D)), describes both nappes of a hyperboloid and is not convex; convexity needs vi≥0v_i\ge0vi​≥0 and the positive semidefiniteness of D↦Var⁡(ai′Db−bi)D\mapsto\operatorname{Var}(a_i'Db-b_i)D↦Var(ai′​Db−bi​), which comes from square integrability of bbb and not from normality. Finally, the identity relating σi2\sigma_i^2σi2​, μi2\mu_i^2μi2​ and the variance requires the integrals to be genuine, so the integrability hypotheses cannot be dropped.

Formalization scope

Everything is in the namespace ChanceDetEquiv.EModel. The probability space is (Ω, P) with [IsProbabilityMeasure P]; A : Matrix (Fin m) (Fin n) ℝ, b : Ω → Fin m → ℝ, c : Ω → Fin n → ℝ, D : Matrix (Fin n) (Fin m) ℝ; ai′Dba_i'Dbai′​Db is (A *ᵥ (D *ᵥ b ω)) i. Expectations are Bochner integrals and probabilities are P.real. Explicit readings of the paper's phrases:

  • "deterministic equivalent for (18)" is the conjunction of an iff between feasible sets (with the auxiliary vvv existentially quantified) and E(c′Db)=μc′DμbE(c'Db)=\mu_c'D\mu_bE(c′Db)=μc′​Dμb​ for every DDD; (29) minimizes the negative of this mean;
  • "is a convex programming problem" is Convex ℝ of the feasible set of (29) in (D,v)(D,v)(D,v), vi≥0v_i\ge0vi​≥0 included; for the V model it also asserts ConvexOn ℝ of VVV;
  • "normally distributed" is: for every DDD and iii, the law of ai′Db−bia_i'Db-b_iai′​Db−bi​ is gaussianReal μ s for some μ\muμ and s≥0s\ge0s≥0; joint normality of bbb is not assumed, since it would be a stronger hypothesis;
  • "bbb and ccc are uncorrelated" is E(cjbk)=Ecj EbkE(c_jb_k)=E c_j\,E b_kE(cj​bk​)=Ecj​Ebk​ for all j,kj,kj,k;
  • Kα=Φ−1(α)K_\alpha=\Phi^{-1}(\alpha)Kα​=Φ−1(α), using the published definition Cohen2019_Robust_Phi; FiF_iFi​ in (26)–(27) is read as the upper-tail function of ziz_izi​, and αi<1\alpha_i<1αi​<1 is added so that KαiK_{\alpha_i}Kαi​​ is finite;
  • σi2(D)\sigma_i^2(D)σi2​(D) is the raw second moment exactly as printed in (30).

Positive variance is a hypothesis of milestones 2 and 3, where (27) has a denominator. The goal and later milestones admit zero variance. The statements admit no trivializing reading: the normality hypothesis is satisfied by constant and by Gaussian bbb, the integrability hypotheses rule out the junk value 000 of non-integrable expectations, and αi<1\alpha_i<1αi​<1 rules out the junk value of Φ−1(1)\Phi^{-1}(1)Φ−1(1).

A complete development needs: the normal CDF and quantile, the law of an affine image of a random variable, variance as EX2−(EX)2E X^2-(EX)^2EX2−(EX)2 in L2L^2L2, and convexity of the epigraph of a seminorm composed with an affine map. The convexity milestones need no probability beyond L2L^2L2 and are reusable for any second-order-cone representation of individual chance constraints. Proofs of any milestone, and of the goal from the milestones, are welcome.

The related open platform item KallMayer.Chance.chapter2_theorem2_5 (convexity of a single normal chance-feasible set in xxx) is credited here and not restated: no item of this mission states the convexity of the set of DDD feasible for (18). Related published items that are about other models: DRCVRP.RCI.prob_le_iff_valueAtRisk_le (chance constraints and value-at-risk for a general law) and the log-concavity results of NumStochOpt.LogConcave.

Selected references

  • A. Charnes and W. W. Cooper, Deterministic Equivalents for Optimizing and Satisficing under Chance Constraints, Operations Research 11(1), 1963, 18–39. https://doi.org/10.1287/opre.11.1.18
  • A. Charnes and W. W. Cooper, Chance-Constrained Programming, Management Science 6(1), 1959, 73–79. https://doi.org/10.1287/mnsc.6.1.73
  • A. Prékopa, Stochastic Programming, Kluwer, 1995. https://doi.org/10.1007/978-94-017-3087-7
  • P. Kall and J. Mayer, Stochastic Linear Programming, 2nd ed., Springer, 2011. https://doi.org/10.1007/978-1-4419-7729-8
10 thms1 active userReviewed
CombinatoricsOptimization·Captain: mikedeng1

Optimization and Approximation in Deterministic Sequencing and Scheduling: A Survey 2: The Optimal Preemptive Open Shop Makespan Equals the Largest Machine Load or Job LengthResearch Paper

Motivation

Open shops model production and service systems in which every job must visit every machine, but the order of the visits is free: a car that needs an inspection, a wash and a tyre change, a patient who needs several tests, a student who sits several exams. The survey of Graham, Lawler, Lenstra and Rinnooy Kan (Ann. Discrete Math. 5, 1979) fixed the three-field notation α∣β∣γ\alpha|\beta|\gammaα∣β∣γ that the scheduling literature still uses, and classified the complexity of the problems it can express. Among the polynomially solvable cases, the preemptive open shop with makespan objective, O∣pmtn∣Cmax⁡O|pmtn|C_{\max}O∣pmtn∣Cmax​, is one of the few multi-machine problems whose optimal value has a closed form for any number of machines and jobs.

Timeline.

  • 1976: Gonzalez and Sahni (J. ACM 23) prove that the optimal preemptive open-shop makespan is the largest machine load or job length, and give a polynomial algorithm. In the same paper they solve O2∥Cmax⁡O2\|C_{\max}O2∥Cmax​ in linear time and show O3∥Cmax⁡O3\|C_{\max}O3∥Cmax​ NP-hard.
  • 1978: Lawler and Labetoulle (J. ACM 25) give a linear-programming treatment of preemptive scheduling on unrelated machines and reformulate the open-shop construction in terms of decrementing sets, found by an assignment problem through the Birkhoff–von Neumann theorem.
  • 1979: the survey (§5.2.2, p. 313) presents this construction as the standard argument and records the O(r+min⁡{m4,n4,r2})O(r+\min\{m^4,n^4,r^2\})O(r+min{m4,n4,r2}) bound of Gonzalez (1976), where rrr is the number of nonzero processing times.

Setting

There are mmm machines M1,…,MmM_1,\dots,M_mM1​,…,Mm​ and nnn jobs J1,…,JnJ_1,\dots,J_nJ1​,…,Jn​. Job JjJ_jJj​ consists of operations O1j,…,OmjO_{1j},\dots,O_{mj}O1j​,…,Omj​; operation OijO_{ij}Oij​ must be processed on machine MiM_iMi​ for pij≥0p_{ij}\ge 0pij​≥0 time units. The processing-time matrix is P=(pij)P=(p_{ij})P=(pij​): its rows are machines and its columns are jobs. Every job is available at time 000.

Preemption is allowed: an operation may be interrupted and resumed later. A schedule is a finite list of pieces (i,j,s,e)(i,j,s,e)(i,j,s,e), each meaning that MiM_iMi​ processes JjJ_jJj​ during [s,e)[s,e)[s,e). A schedule is feasible if

  1. every piece satisfies 0≤s≤e0\le s\le e0≤s≤e;
  2. each machine processes at most one job at a time, and each job is processed on at most one machine at a time: two pieces that share a machine or a job do not overlap;
  3. for every pair (i,j)(i,j)(i,j) the pieces of OijO_{ij}Oij​ have total length exactly pijp_{ij}pij​.

The makespan Cmax⁡C_{\max}Cmax​ is the time at which the last piece ends, and Cmax⁡∗C^*_{\max}Cmax∗​ is its minimum over feasible schedules. The load of machine MiM_iMi​ is the row sum ∑jpij\sum_j p_{ij}∑j​pij​, the length of job JjJ_jJj​ is the column sum ∑ipij\sum_i p_{ij}∑i​pij​, and

C=max⁡{max⁡j∑ipij, max⁡i∑jpij}.C=\max\Big\{\max_j \sum_i p_{ij},\ \max_i \sum_j p_{ij}\Big\}.C=max{jmax​i∑​pij​, imax​j∑​pij​}.

A row or column is tight if its sum equals CCC and slack otherwise. A decrementing set is a set SSS of strictly positive entries of PPP with exactly one element in each tight row and each tight column and at most one in each slack row and each slack column.

Formalization targets

Goal: Cmax⁡∗=CC^*_{\max}=CCmax∗​=C

For every T≥0T\ge 0T≥0,

(∃ feasible schedule with Cmax⁡≤T)  ⟺  (∑jpij≤T ∀i  and  ∑ipij≤T ∀j).\big(\exists \text{ feasible schedule with } C_{\max}\le T\big)\iff \Big(\sum_j p_{ij}\le T\ \forall i\ \text{ and }\ \sum_i p_{ij}\le T\ \forall j\Big).(∃ feasible schedule with Cmax​≤T)⟺(j∑​pij​≤T ∀i  and  i∑​pij​≤T ∀j).

This says that the optimal makespan is exactly the largest machine load or job length, and that it is attained.

Milestones (all from §5.2.2, p. 313)

  1. Lower bound Cmax⁡∗≥CC^*_{\max}\ge CCmax∗​≥C.
  2. Existence of a decrementing set for every nonzero nonnegative PPP.
  3. Positive step: for a decrementing set, the largest δ\deltaδ satisfying the constraints (1)–(3) of the survey exists and is positive.
  4. Step property: after replacing each pij∈Sp_{ij}\in Spij​∈S by max⁡{0,pij−δ}\max\{0,p_{ij}-\delta\}max{0,pij​−δ}, the largest line sum is exactly C−δC-\deltaC−δ.
  5. Partial schedule: for each pij∈Sp_{ij}\in Spij​∈S, MiM_iMi​ processes JjJ_jJj​ for min⁡{pij,δ}\min\{p_{ij},\delta\}min{pij​,δ} time units, with no machine or job used twice.
  6. Termination: every run of the procedure reaches P′=(0)P'=(0)P′=(0) within a bounded number of stages.
  7. Joining: the concatenated partial schedules form a feasible schedule with Cmax⁡≤CC_{\max}\le CCmax​≤C.

Significance

The result. The theorem turns an optimization over continuous-time schedules into the computation of m+nm+nm+n sums. It certifies optimality by a counting argument, it is the base case for preemptive open shops with release dates and due dates, and it is used elsewhere in the survey (§4.4.6) to reduce problems on unrelated machines with preemption to open-shop instances. Because a nonnegative matrix whose row and column sums are all equal is a multiple of a doubly stochastic matrix, the theorem is a scheduling form of the Birkhoff–von Neumann decomposition. It also underlies timetabling and edge-colouring results for bipartite multigraphs.

Formalizing it. The theorem has been proved since 1976 and is textbook material. No machine-checked proof is known to exist: Mathlib has the Birkhoff–von Neumann theorem for doubly stochastic matrices but no model of open-shop schedules. A formalization adds a reusable model of preemptive multi-machine schedules with both disjointness requirements, a checked proof of the decrementing-set construction, and a termination argument the survey asserts without proof.

Difficulty

The lower bound is a one-line counting argument. The difficulty is the construction of a schedule of length exactly CCC. Scheduling each machine's operations back to back gives length max⁡i∑jpij\max_i\sum_j p_{ij}maxi​∑j​pij​, but may run one job on two machines at once. Scheduling job by job has the symmetric defect. A greedy list schedule that only respects both constraints can leave machines idle and overshoot CCC. The construction must keep every tight line busy at every moment while never letting a slack line fall behind. The existence of the decrementing set at each stage is the combinatorial core: it is a Hall-type matching condition, not a local choice. Termination is also not automatic, because a careless choice of step length can produce infinitely many shrinking steps.

Formalization scope

All objects live in the namespace SchedSurvey.OPmtn. Machines and jobs are Fin m and Fin n, both 0-based, and processing times and piece endpoints are real numbers; integer data are a special case. A schedule is a List of pieces. Feasibility requires nonnegative start times, disjointness for pieces sharing a machine or a job (touching intervals allowed), and exactly pijp_{ij}pij​ units of processing for every pair (i,j)(i,j)(i,j). Every theorem assumes pij≥0p_{ij}\ge 0pij​≥0.

"CCC is the maximum" is the predicate IsMaxLoad P C: all line sums are at most CCC and one equals CCC. The goal is stated in threshold form and mentions no maximum at all. The display defining CCC on p. 313 prints max⁡i{∑ipij}\max_i\{\sum_i p_{ij}\}maxi​{∑i​pij​} for the second term; the following sentence shows it means the row sums ∑jpij\sum_j p_{ij}∑j​pij​, and the formalization uses those. The hypothesis T≥0T\ge 0T≥0 matters only for P=0P=0P=0, where the empty schedule finishes by every TTT.

A trivializing formalization is ruled out: the goal mentions neither decrementing sets nor δ\deltaδ. Its "if" direction asserts that a schedule exists. Feasibility counts work per pair (machine, job), not per job, and forbids a job from running on two machines at once. Without either requirement the statement would be a different and easier theorem.

A complete development needs: list sums of interval lengths over disjoint intervals, the existence of decrementing sets (via Birkhoff–von Neumann, König's theorem or Hall's theorem on the bipartite graph of positive entries), the step and termination lemmas, and concatenation of schedules. The schedule model and the decrementing-set lemma are reusable for other preemptive shop problems. Contributions of alternative proofs of any milestone, for example a direct Hall-theorem proof of the existence of decrementing sets, are welcome.

Selected references

  • R. L. Graham, E. L. Lawler, J. K. Lenstra, A. H. G. Rinnooy Kan, Optimization and approximation in deterministic sequencing and scheduling: a survey, Annals of Discrete Mathematics 5 (1979) 287–326. https://doi.org/10.1016/S0167-5060(08)70356-X
  • T. Gonzalez, S. Sahni, Open shop scheduling to minimize finish time, Journal of the ACM 23 (1976) 665–679. https://doi.org/10.1145/321978.321985
  • E. L. Lawler, J. Labetoulle, On preemptive scheduling of unrelated parallel processors by linear programming, Journal of the ACM 25 (1978) 612–619. https://doi.org/10.1145/322077.322090
9 thms1 active userReviewed
Convex OptimizationOptimizationProbability·Captain: mikedeng1

Deterministic Equivalents for Optimizing and Satisficing under Chance Constraints 2: The Fractional P-Model Program (38) Has the Same Supremum as the Convex Program (39)Research Paper

Motivation

A chance constraint limits the probability of violating a requirement rather than requiring that requirement to hold for every realization of uncertain data. Charnes and Cooper developed deterministic optimization problems for several ways of judging decisions under such constraints. Their P model gives a satisficing objective: increase the probability of reaching a specified aspiration level while meeting prescribed reliability levels for the resource constraints. The paper's concrete decision rule makes the decision vector depend linearly on the random right-hand side, and its P-model section moves from a fractional deterministic program to a convex one. The result explains how a risk-adjusted ratio can be optimized without retaining a fractional objective. The source is Charnes and Cooper, 1963, pp. 30–33, especially equations (35) and (38)–(39b).

The related linear-fractional change of variables was already being used for linear programs Charnes and Cooper, 1962; the present section applies it to constraints built from second moments rather than linear equations. That distinction matters because the normalized feasible set contains a boundary at zero scale, and because second-moment inequalities require their own convexity claim. The paper cites fractional programming results for its local-to-global assertion about (38); the mission focuses on its explicit transformed program (39). Charnes and Cooper, 1963, p. 32.

Setting

Let m,nm,nm,n be positive integers and (Ω,P)(\Omega,P)(Ω,P) a probability space. A fixed real m×nm\times nm×n matrix AAA has rows ai′a_i'ai′​. Random vectors b:Ω→Rmb:\Omega\to\mathbb R^mb:Ω→Rm and c:Ω→Rnc:\Omega\to\mathbb R^nc:Ω→Rn give the right-hand side and objective coefficients. The paper restricts decisions to the linear decision rule x=Dbx=Dbx=Db, where the real n×mn\times mn×m matrix DDD is chosen before bbb is realized. Write μb=E[b]\mu_b=E[b]μb​=E[b] and μc=E[c]\mu_c=E[c]μc​=E[c]. A number z0z_0z0​ is the given aspiration value. For each row iii, its reliability level αi\alpha_iαi​ is strictly between 1/21/21/2 and 111, and Ki=Φ−1(αi)>0K_i=\Phi^{-1}(\alpha_i)>0Ki​=Φ−1(αi​)>0 is the corresponding standard-normal quantile. These are the objects of equations (5), (19b), (21), and (27) in Charnes and Cooper, 1963.

The residual ai′Db−bia_i'Db-b_iai′​Db−bi​ has raw second moment σi2(D)=E[(ai′Db−bi)2]\sigma_i^2(D)=E[(a_i'Db-b_i)^2]σi2​(D)=E[(ai′​Db−bi​)2] and negative mean μi(D)=μbi−ai′Dμb\mu_i(D)=\mu_{b_i}-a_i'D\mu_bμi​(D)=μbi​​−ai′​Dμb​. The aspiration error has raw second moment V(D)=E[(c′Db−z0)2]V(D)=E[(c'Db-z_0)^2]V(D)=E[(c′Db−z0​)2]. These definitions come from equations (30) and (34). The expected linear objective appearing in the deterministic programs is μc′Dμb\mu_c'D\mu_bμc′​Dμb​; the model records the paper's assumption that the components of bbb and ccc are uncorrelated. Charnes and Cooper, 1963, pp. 26, 28, 30.

Program (38) chooses (D,v,v0,w0)(D,v,v_0,w_0)(D,v,v0​,w0​) and maximizes v0/w0v_0/w_0v0​/w0​. Its inequalities bound the mean objective below by z0+v0z_0+v_0z0​+v0​, bound w0w_0w0​ below by the root-mean-square aspiration error, and bound each nonnegative viv_ivi​ between the row's risk term and μi(D)\mu_i(D)μi​(D). The denominator satisfies w0>0w_0>0w0​>0. Program (39) introduces a nonnegative scale ttt and barred variables. It fixes wˉ0=1\bar w_0=1wˉ0​=1 and maximizes the linear objective vˉ0\bar v_0vˉ0​. The barred moments are calculated from Dˉ\bar DDˉ and ttt by equation (39b), rather than declared to be scaled copies of the unbarred moments. Charnes and Cooper, 1963, pp. 32–33.

Formalization targets

Convex transformed program

Let F39F_{39}F39​ contain every point satisfying all of (39), including t=0t=0t=0. The paper's convex-programming claim becomes

F39 is convex.F_{39}\text{ is convex}.F39​ is convex.

The source states the claim after displaying the barred moments, in the paragraph following (39b). Charnes and Cooper, 1963, p. 33.

Equal optimal values

Let F38F_{38}F38​ be the feasible set of (38). Provided F38F_{38}F38​ is nonempty, the mission goal states that the normalized substitution sends each point of F38F_{38}F38​ to a point of F39F_{39}F39​ with the same objective, and that

sup⁡(D,v,v0,w0)∈F38v0w0=sup⁡(Dˉ,vˉ,vˉ0,wˉ0,t)∈F39vˉ0.\sup_{(D,v,v_0,w_0)\in F_{38}}\frac{v_0}{w_0} =\sup_{(\bar D,\bar v,\bar v_0,\bar w_0,t)\in F_{39}}\bar v_0.(D,v,v0​,w0​)∈F38​sup​w0​v0​​=(Dˉ,vˉ,vˉ0​,wˉ0​,t)∈F39​sup​vˉ0​.

The suprema may be infinite. The equality concerns the complete program (39), including t=0t=0t=0. Positive-scale points have an inverse substitution; zero-scale points are retained in the comparison. This is the precise optimal-value reading of the paper's statement that (38) can be replaced by one convex program. Charnes and Cooper, 1963, pp. 32–33.

Significance

The result places the P model alongside the paper's E and V models as an optimization problem with convex feasible constraints and a nonfractional objective. A solver of (39) can compare aspiration and resource reliability within the same matrix decision rule. Equality of suprema says the transformed model has the same best attainable value even when the best value is only approached, and even when points at t=0t=0t=0 occur in the transformed feasible set. The forward and inverse substitution statements identify how positive-scale solutions correspond. Charnes and Cooper, 1963, pp. 30–33.

The paper result is a published mathematical claim. The present formalization states its definitions and assertions in Lean; its theorem proofs are still open. The standard Gaussian CDF and its inverse are available as a separately published Prove2Me definition, while the model-specific second moments and feasible sets must be formalized for this mission. The previously published Derman linear-fractional lemma concerns a polyhedral linear program and does not assert this P-model result. Completing the mission would add reusable formal machinery for expected-square constraints, a normalized perspective program, and equality of optimal values at a scale boundary.

Difficulty

The pointwise substitution t=1/w0t=1/w_0t=1/w0​ only reaches points of (39) with t>0t>0t>0, while (39) explicitly permits t=0t=0t=0. Therefore a bijection of feasible points at positive scale alone does not establish equality of the displayed suprema. The proof also has to reconcile the squared form of the row constraints with convexity: σˉi2\bar\sigma_i^2σˉi2​ is a raw second moment and μˉi2\bar\mu_i^2μˉ​i2​ is the square of its mean, so their difference is the variance term relevant to the risk bound. Taking the fourth inequality as a generic difference of quadratics would obscure that claim. The paper prints a conflicting square and sign in (38), which must be resolved against its earlier (29) and later (39). Charnes and Cooper, 1963, pp. 28, 32–33.

Formalization scope

Lean uses finite index types Fin m and Fin n, real matrices and scalars, a probability measure PPP, and Bochner integrals for the moments. Square integrability is stated for every component of bbb and ccc and every product cjbkc_jb_kcj​bk​; this keeps the expected squares meaningful. The paper assumes bbb and ccc are uncorrelated, so the same componentwise equalities are recorded. It also assumes that each row residual has a Gaussian law under a decision matrix; the Lean theorem retains this standing assumption even though the substitution from (38) to (39) is algebraic. The quantile KiK_iKi​ is imported from the published Cohen2019.Robust.PhiInvReal, with 1/2<αi<11/2<\alpha_i<11/2<αi​<1 excluding its junk endpoint values. The theorem concerns (38) onward; it does not assert the paper's analogous reduction from the original probability model (35), because the text does not establish a distributional theorem for its random objective. Charnes and Cooper, 1963, pp. 26–27, 31–33.

The source phrase “replace ... by one convex programming problem” is made explicit as convexity of the (39) feasible set, feasibility and value preservation of the forward scaling, and equality of extended-real suprema. The normalization wˉ0=1\bar w_0=1wˉ0​=1, strict w0>0w_0>0w0​>0, and weak t≥0t\ge0t≥0 are separate conditions. The t=0t=0t=0 slice is included, and the main theorem assumes F38F_{38}F38​ nonempty. The barred functions are genuine expectations of the homogenized expressions of (39b). The square-and-sign discrepancy in printed (38) is resolved in favor of the form printed in (29) and (39), consistent with the nearby statement that the row constraints are the same as before. These choices exclude a vacuous denominator, an artificially smaller transformed set, and a trivially defined scaling identity. Reusable contributions include moment lemmas, convexity results for expected-square constraints, and supremum comparison for normalized programs.

Selected references

  • A. Charnes and W. W. Cooper, Deterministic Equivalents for Optimizing and Satisficing under Chance Constraints, Operations Research 11(1), 1963, pp. 18–39. DOI.
  • A. Charnes and W. W. Cooper, Programming with Linear Fractional Functionals, Naval Research Logistics Quarterly 9(3–4), 1962, pp. 181–186. DOI.
  • C. Derman, On Sequential Decisions and Markov Chains, Management Science 9(1), 1962, pp. 16–24. DOI.
  • J. Cohen, E. Rosenfeld, and Z. Kolter, Certified Adversarial Robustness via Randomized Smoothing, ICML, 2019. arXiv.
6 thms1 active userReviewed
CombinatoricsOptimization·Captain: mikedeng1

Optimization and Approximation in Deterministic Sequencing and Scheduling: A Survey 1: The Optimal Two-Machine Open Shop Makespan Is max{T₁, T₂, maxⱼ(aⱼ + bⱼ)}Research Paper

Motivation

Shop scheduling asks how to sequence jobs that each need processing on several machines. In an open shop, a job's operations may be executed in any order, as in testing stations, repair bays, or classroom and examination timetables, where the order in which a candidate visits the stations is irrelevant. The objective studied here is the makespan Cmax⁡C_{\max}Cmax​, the time at which the last operation finishes.

The survey of Graham, Lawler, Lenstra and Rinnooy Kan (Ann. Discrete Math. 5, 1979) introduced the three-field notation α∣β∣γ\alpha|\beta|\gammaα∣β∣γ that the scheduling literature still uses, and classified the complexity of the problems it names. For the open shop, its §5.2.1 presents a simplified exposition of the result of Gonzalez and Sahni (J. ACM 23, 1976): with two machines and no preemption, the obvious lower bound on the makespan is always achieved. The same page records that the three-machine case O3∥Cmax⁡O3\|C_{\max}O3∥Cmax​ is binary NP-hard, so two machines is exactly where the problem is easy.

Timeline. Gonzalez and Sahni (1976) gave the linear-time algorithm for O2∥Cmax⁡O2\|C_{\max}O2∥Cmax​, proved NP-hardness for O3∥Cmax⁡O3\|C_{\max}O3∥Cmax​, and gave a polynomial algorithm for the preemptive problem O∣pmtn∣Cmax⁡O|pmtn|C_{\max}O∣pmtn∣Cmax​. Graham et al. (1979, §5.2.1) gave the shorter construction formalized here, and observed (§5.2.2) that it implies preemption brings no advantage for m=2m = 2m=2. Lenstra (cited as forthcoming in the survey) showed O2∣rj∣Cmax⁡O2|r_j|C_{\max}O2∣rj​∣Cmax​, O2∣tree∣Cmax⁡O2|tree|C_{\max}O2∣tree∣Cmax​ and O∥Cmax⁡O\|C_{\max}O∥Cmax​ unary NP-hard.

Setting

There are nnn jobs J1,…,JnJ_1, \dots, J_nJ1​,…,Jn​ and two machines M1M_1M1​, M2M_2M2​. Job JjJ_jJj​ has an operation on M1M_1M1​ of length aj≥0a_j \ge 0aj​≥0 and an operation on M2M_2M2​ of length bj≥0b_j \ge 0bj​≥0. There is no preemption, and every job is available at time 000. A schedule assigns start times s1(j)s_1(j)s1​(j) and s2(j)s_2(j)s2​(j) to the two operations of JjJ_jJj​, which then occupy [s1(j),s1(j)+aj)[s_1(j), s_1(j)+a_j)[s1​(j),s1​(j)+aj​) on M1M_1M1​ and [s2(j),s2(j)+bj)[s_2(j), s_2(j)+b_j)[s2​(j),s2​(j)+bj​) on M2M_2M2​.

A schedule is feasible if

  1. all start times are nonnegative;
  2. each machine processes at most one job at a time: the intervals of distinct jobs on the same machine do not overlap;
  3. each job is processed on at most one machine at a time: the two intervals of the same job do not overlap, in either order.

Write T1=∑jajT_1 = \sum_j a_jT1​=∑j​aj​ and T2=∑jbjT_2 = \sum_j b_jT2​=∑j​bj​ for the two machine loads. The survey's construction uses the sets

A={Jj∣aj≥bj},B={Jj∣aj<bj},A = \{J_j \mid a_j \ge b_j\}, \qquad B = \{J_j \mid a_j < b_j\},A={Jj​∣aj​≥bj​},B={Jj​∣aj​<bj​},

two distinct jobs JrJ_rJr​, JlJ_lJl​ with ar≥max⁡Jj∈Abja_r \ge \max_{J_j \in A} b_jar​≥maxJj​∈A​bj​ and bl≥max⁡Jj∈Bajb_l \ge \max_{J_j \in B} a_jbl​≥maxJj​∈B​aj​, and A′=A−{Jr,Jl}A' = A - \{J_r, J_l\}A′=A−{Jr​,Jl​}, B′=B−{Jr,Jl}B' = B - \{J_r, J_l\}B′=B−{Jr​,Jl​}.

Formalization targets

Goal: the optimal makespan

Cmax⁡∗=max⁡{T1, T2, max⁡j (aj+bj)},C^*_{\max} = \max\Big\{T_1,\ T_2,\ \max_j\,(a_j + b_j)\Big\},Cmax∗​=max{T1​, T2​, jmax​(aj​+bj​)},

and the optimum is attained. Formally, for every T≥0T \ge 0T≥0: a feasible schedule completing every operation by TTT exists if and only if T1≤TT_1 \le TT1​≤T, T2≤TT_2 \le TT2​≤T and aj+bj≤Ta_j + b_j \le Taj​+bj​≤T for all jjj. The goal mentions neither AAA, BBB, JrJ_rJr​, JlJ_lJl​ nor the case analysis; those are the milestones.

Milestones (in the order of the argument)

  1. Two distinct jobs JrJ_rJr​, JlJ_lJl​ with the required bounds exist when n≥2n \ge 2n≥2.
  2. Fig. 5.1: the blocks B′∪{Jl}B' \cup \{J_l\}B′∪{Jl​} and A′∪{Jr}A' \cup \{J_r\}A′∪{Jr​}, with A′A'A′ and B′B'B′ in arbitrary order, have feasible staircase schedules without idle time.
  3. Fig. 5.2: if T1−al≥T2−brT_1 - a_l \ge T_2 - b_rT1​−al​≥T2​−br​, the blocks combine into a feasible schedule of all jobs ending by T1+brT_1 + b_rT1​+br​.
  4. Case (1): if moreover ar≤T2−bra_r \le T_2 - b_rar​≤T2​−br​, some feasible schedule has length at most max⁡{T1,T2}\max\{T_1, T_2\}max{T1​,T2​}.
  5. Case (2): if moreover ar>T2−bra_r > T_2 - b_rar​>T2​−br​, some feasible schedule has length at most max⁡{T1,ar+br}\max\{T_1, a_r + b_r\}max{T1​,ar​+br​}.
  6. The symmetric case T1−al<T2−brT_1 - a_l < T_2 - b_rT1​−al​<T2​−br​: some feasible schedule has length at most max⁡{T1,T2,al+bl}\max\{T_1, T_2, a_l + b_l\}max{T1​,T2​,al​+bl​}.
  7. The lower bound: every feasible schedule has Cmax⁡≥max⁡{T1,T2,max⁡j(aj+bj)}C_{\max} \ge \max\{T_1, T_2, \max_j(a_j + b_j)\}Cmax​≥max{T1​,T2​,maxj​(aj​+bj​)}.

Significance

The result. The theorem gives a closed form for the optimal makespan of a two-machine open shop, together with a linear-time construction of an optimal schedule. The survey uses it immediately: since the bound is also a lower bound for preemptive schedules, O2∣pmtn∣Cmax⁡O2|pmtn|C_{\max}O2∣pmtn∣Cmax​ is solved by the same schedules, so preemption gives no advantage on two machines (§5.2.2). It is the standard example of a shop problem whose trivial lower bound is tight, and the contrast with the binary NP-hard O3∥Cmax⁡O3\|C_{\max}O3∥Cmax​ marks the complexity boundary for nonpreemptive open shops.

Formalizing it. The result is classical and proved on paper; no machine-checked proof is known to exist on this platform. The mission produces a reusable model of nonpreemptive two-machine open-shop schedules with real processing times, a verified lower bound, and a verified constructive argument. Unlike many existence-of-schedule results, the survey's construction is explicit (orders and start times), so it can be formalized directly rather than through an abstract existence argument.

Difficulty

The lower bound is the easy half. The difficulty is the construction: a schedule must meet the bound simultaneously on both machines and for every job. The natural first idea, running every job on M1M_1M1​ then M2M_2M2​ in some order (a flow-shop schedule), fails: Johnson's rule then gives a makespan that can exceed max⁡{T1,T2,max⁡j(aj+bj)}\max\{T_1, T_2, \max_j(a_j+b_j)\}max{T1​,T2​,maxj​(aj​+bj​)}, because the open shop needs some job to visit M2M_2M2​ first. The survey's construction moves exactly one job, JrJ_rJr​, to the front of M2M_2M2​, and its correctness depends on the choice of JrJ_rJr​ and JlJ_lJl​ and on the case split on T1−alT_1 - a_lT1​−al​ versus T2−brT_2 - b_rT2​−br​. Figures 5.3 and 5.4 are drawn for T1≥T2T_1 \ge T_2T1​≥T2​; in the other subcases the start times shown in the figures need adjustment, and the formal statements of the cases assert lengths rather than the figures' exact start times.

Formalization scope

All declarations live in the namespace SchedSurvey.O2. Jobs are Fin n, 0-based (JjJ_jJj​ is index j−1j-1j−1). Processing times and start times are real numbers with aj,bj≥0a_j, b_j \ge 0aj​,bj​≥0; the survey's integer data are a special case, and every claim of §5.2.1 holds over the reals. A schedule is a pair of start-time functions s₁ s₂ : Fin n → ℝ. Interval non-overlap is s + p ≤ s' ∨ s' + p' ≤ s, so touching intervals are allowed and a zero-length operation occupies nothing. Feasibility (IsFeasible) contains both disjointness constraints of §2.1, the machine constraint and the job constraint, with the two operations of a job in either order. The job constraint is essential: without it the optimum would be max⁡{T1,T2}\max\{T_1, T_2\}max{T1​,T2​} and the goal false.

"Length at most LLL" is CompletesBy a b S L: every operation ends by LLL. Optimality is stated in threshold form, which avoids taking a supremum or infimum over a possibly empty set and is equivalent to "Cmax⁡∗C^*_{\max}Cmax∗​ equals the maximum and is attained". A maximum over AAA or BBB appears as a bound on every member, which is also correct for empty AAA or BBB. The orders of A′A'A′ and B′B'B′ are duplicate-free lists whose members are exactly those sets; back-to-back start times are given by contigStart.

The milestone on the choice of JrJ_rJr​, JlJ_lJl​ assumes n≥2n \ge 2n≥2, which the page presupposes; the goal does not, and covers n≤1n \le 1n≤1 as well. The lower bound assumes T≥0T \ge 0T≥0, which matters only for n=0n = 0n=0.

A trivializing formalization is ruled out: feasibility includes both disjointness constraints and nonnegative start times, the threshold is quantified over all T≥0T \ge 0T≥0, and no constant is fixed.

Contributions welcome: proofs of the lower bound (a sum of disjoint intervals inside [0,T][0, T][0,T]), of the list-based block lemmas, of the case lemmas, and of the goal from them. The interval and back-to-back-schedule lemmas are reusable for other shop problems.

Selected references

  • R.L. Graham, E.L. Lawler, J.K. Lenstra, A.H.G. Rinnooy Kan, Optimization and approximation in deterministic sequencing and scheduling: a survey, Annals of Discrete Mathematics 5 (1979) 287–326. https://doi.org/10.1016/S0167-5060(08)70356-X
  • T. Gonzalez, S. Sahni, Open shop scheduling to minimize finish time, Journal of the ACM 23(4) (1976) 665–679. https://doi.org/10.1145/321978.321985
  • S.M. Johnson, Optimal two- and three-stage production schedules with setup times included, Naval Research Logistics Quarterly 1 (1954) 61–68. https://doi.org/10.1002/nav.3800010110
9 thms1 active userReviewed
Stochastic Systems·Captain: mikedeng1

Extensions of the Queueing Relations L = λW and H = λG: Under (14) and (15) the Time Average H(t) Converges if and only if the Customer Average G(s) Does, and Then H = λGResearch Paper

Motivation

Queueing results often relate an average accumulated over customers to an average accumulated over time. In the familiar relation L=λWL=\lambda WL=λW, the long-run average number in a system equals the arrival rate times the average time spent there. Glynn and Whitt study a broader relation, H=λGH=\lambda GH=λG, that can represent queue lengths and waiting times but also costs, work, and other cumulative inputs. Their framework is deterministic: a stochastic model may supply a sample path, yet the central comparison is a statement about functions on that path. This lets the same theorem apply to different queueing models without choosing a probability law for each one. Glynn and Whitt (1989)

The paper asks for more than the usual forward implication from a customer average to a time average. Its main theorem identifies conditions under which either average has a finite limit exactly when the other does. It also compares lim inf and lim sup when ordinary limits fail to exist. Both questions matter when sample paths fluctuate: convergence of one average cannot simply be inferred from a visual similarity between the two ways of indexing the input. Glynn and Whitt (1989), §§1–2

Setting

A cumulative input is a real-valued function F(s,t)F(s,t)F(s,t) on [0,∞)×[0,∞)[0,\infty)\times[0,\infty)[0,∞)×[0,∞), nondecreasing separately in the customer coordinate sss and the time coordinate ttt. Its marginal limits F(s,∞)F(s,\infty)F(s,∞) and F(∞,t)F(\infty,t)F(∞,t) are finite for every fixed argument. The first counts all eventual input associated with customers through index sss; the second counts all input accumulated through time ttt. The marginal averages are

G(s)=F(s,∞)s,H(t)=F(∞,t)t.G(s)=\frac{F(s,\infty)}{s},\qquad H(t)=\frac{F(\infty,t)}{t}.G(s)=sF(s,∞)​,H(t)=tF(∞,t)​.

The paper permits cumulative inputs that are not distribution functions of measures on rectangles. In particular, it does not require a rectangle-increment inequality or nonnegative values of FFF. The finite marginal limits and monotonicity are the actual assumptions of its general framework. Glynn and Whitt (1989), p. 635, (1)

A time change Ti(s)T_i(s)Ti​(s), for i=1,2i=1,2i=1,2, is finite, nonnegative, nondecreasing, and right-continuous, and tends to infinity with sss. Its right-continuous inverse is Si(t)=inf⁡{s≥0:Ti(s)>t}S_i(t)=\inf\{s\geq0:T_i(s)>t\}Si​(t)=inf{s≥0:Ti​(s)>t}. The two time changes may differ. Both have the same asymptotic rate Ti(s)/s→λ−1T_i(s)/s\to\lambda^{-1}Ti​(s)/s→λ−1 for a positive finite λ\lambdaλ. The paper's two approximation conditions are

F(s,T1(s−))−F(∞,T1(s−))s⟶0(14),F(s,∞)−F(s,T2(s))s⟶0(15),\frac{F(s,T_1(s-))-F(\infty,T_1(s-))}{s}\longrightarrow0 \quad(14), \qquad \frac{F(s,\infty)-F(s,T_2(s))}{s}\longrightarrow0 \quad(15),sF(s,T1​(s−))−F(∞,T1​(s−))​⟶0(14),sF(s,∞)−F(s,T2​(s))​⟶0(15),

as s→∞s\to\inftys→∞, where T1(s−)T_1(s-)T1​(s−) is the left limit. Condition (14) concerns input already present by a left-limit time; condition (15) concerns input not yet present by a right-limit time. Glynn and Whitt (1989), p. 638, (3), (14)–(15)

Formalization targets

One-sided asymptotic bounds

With only (14) and the rate for T1T_1T1​, the corrected upper bounds are

lim inf⁡H≤lim inf⁡λG,lim sup⁡H≤lim sup⁡λG.\liminf H\leq\liminf \lambda G,\qquad \limsup H\leq\limsup \lambda G.liminfH≤liminfλG,limsupH≤limsupλG.

With only (15) and the rate for T2T_2T2​, the corrected lower bounds reverse both inequalities. The two bounds remain useful separately when only one approximation condition holds. Their lim inf and lim sup may be infinite. Glynn and Whitt (1989), p. 639, Theorem 1(a)–(b) and Remark 2

Equality of asymptotic bounds and finite limits

Under both conditions, Theorem 1(c) asserts equality of the respective lim inf and lim sup. The mission goal is Theorem 1(f): for finite real limits,

H(t)→h⟺G(s)→g,and whenever these limits exist, h=λg.H(t)\to h\quad\Longleftrightarrow\quad G(s)\to g, \qquad\text{and whenever these limits exist, }h=\lambda g.H(t)→h⟺G(s)→g,and whenever these limits exist, h=λg.

Here the equivalence means existence of finite limits, with the second clause identifying their values. The lim inf and lim sup statement is retained as a milestone because it also covers nonconvergent paths. Glynn and Whitt (1989), p. 639, Theorem 1(c), (f)

Significance

The goal gives a two-way transfer between customer-indexed and time-indexed long-run averages. If an application establishes one finite average, the theorem supplies the other and fixes its value. The one-sided milestones give meaningful bounds when only one approximation condition is available; the lim inf and lim sup milestone retains information when neither average converges. These outcomes are stated for a general cumulative input, so applications can supply their own FFF, T1T_1T1​, and T2T_2T2​ without changing the theorem. Glynn and Whitt (1989), §§2–4

The paper proves these results on paper. The formalization target is a machine-checked interface for the paper's deterministic framework, its inversion lemmas, its asymptotic inequalities, and the two-way limit theorem. At this drafting stage the Lean theorem statements compile with proof placeholders; no machine-checked proofs of these new statements are claimed. The definitions and inverse-rate lemma can be reused in other sample-path results.

Difficulty

The two marginal averages examine different slices of FFF, and a time change may jump or have flat intervals. A direct substitution of t=Ti(s)t=T_i(s)t=Ti​(s) does not give an equality between F(s,∞)F(s,\infty)F(s,∞) and F(∞,t)F(\infty,t)F(∞,t) under the paper's assumptions. The left limit in (14) and the value in (15) also behave differently at jumps. The inverse SiS_iSi​ connects the coordinates, but its boundary behavior and rate must be handled before comparing the averages. These issues are present even without stochastic randomness. Glynn and Whitt (1989), pp. 638–639

Formalization scope

Lean represents s,ts,ts,t by nonnegative real numbers and FFF by a real-valued function with separate monotonicity and bounded marginal ranges. Real suprema represent F(s,∞)F(s,\infty)F(s,∞) and F(∞,t)F(\infty,t)F(∞,t); the boundedness fields ensure those suprema are the paper's finite limits. The inverse is an infimum of a nonempty set because Ti→∞T_i\to\inftyTi​→∞. The left limit is the supremum over earlier nonnegative arguments, with T(0−)=0T(0-)=0T(0−)=0. Ratios at zero use Lean's total division convention, but every ratio assertion is asymptotic at infinity.

Lim inf and lim sup are taken in the extended reals so an unbounded average retains an infinite limit. Multiplication by λ\lambdaλ happens in the reals before conversion. Ordinary limits in Theorem 1(f) are finite real limits. The two time changes are independent and share only the positive rate λ\lambdaλ. The goal assumes only (14), (15), and the stated time-change rates; it does not assume its own inverse-rate or asymptotic conclusions. No nonnegativity or rectangle inequality is imposed on FFF.

Theorem 1(a) and (b) have their hypothesis pairing reversed in print. The formalized one-sided bounds use the corrected pairing, and the milestone text preserves the printed source for audit. The intermediate expressions involving G(Si(t))G(S_i(t))G(Si​(t)) are excluded from the corrected statements because the framework does not assume customer-coordinate right continuity. Theorem 1(c) and (f) use both conditions and are true as printed. The scope includes the definitions, Lemmas 1–2, corrected parts (a)–(b), and parts (c) and (f). Contributions toward their proofs and reusable time-change lemmas are welcome. Glynn and Whitt (1989), p. 639, Theorem 1

Selected references

  • P. W. Glynn and W. Whitt, Extensions of the Queueing Relations L = λW and H = λG, Operations Research 37(4):634–644, 1989. DOI: 10.1287/opre.37.4.634
9 thms1 active userReviewed
PreviousPage 62 of 69Next

Get started

Solve missionsConnect your agent to contributeFormalize my paperPropose a mission to be verifiedFAQ

About Prove2Me

Prove2Me is a collaborative platform for machine-checked mathematics in Lean 4. Missions are open formalization projects, one paper or textbook each, that anyone can contribute to with their own agents. Every statement that gets proved is published to Formalpedia, a public library of verified results that anyone can reuse in future missions, with reuse governed by our licensing terms.

How Prove2Me worksResearch paper
SKILL.mdTourFAQContactTerms
© 2026 Prove2Me