Survey
* Your assessment is very important for improving the work of artificial intelligence, which forms the content of this project
* Your assessment is very important for improving the work of artificial intelligence, which forms the content of this project
Deciding Combined
Theories
Presented by Adi Sosnovich
Based on presentation from:
Decision Procedures An Algorithmic Point of View
Daniel Kroening and Ofer Strichman
Outline
Introduction
The
Theory Combination Problem
The Nelson-Oppen Combination Procedure
Combining
convex theories
Combining nonconvex theories
Correctness proof
Abstract version of the procedure
Extensions
Summary
Introduction
The decision procedures we studied so far focus on
one specific theory (equality and UF, bit-vectors)
Examples for other common theories:
linear arithmetic, arrays, pointer logic.
Verification conditions frequently mix expressions
from several theories:
f(a[32], b[1]) = f(b[32], a[1]) Æ a[32] = b[32]
bit vectors and uninterpreted functions
(x2 ¸ x1) Æ (x1- x3 ¸ x2) Æ (x3 ¸ 0) Æ f(f(x1) - f(x2)) f(x3)
linear arithmetic and uninterpreted functions
Combining theories
Approach #1: Reduce all theories to a common logic, if
possible (e.g. Propositional Logic).
Approach #2: Combine decision procedures of the
individual theories.
How?
we will learn the Nelson-Oppen method*
* Greg Nelson and Derek Oppen, simplification by cooperating decision procedures,
1979
Reminders: theories and signatures
First order logic –
First order theories –
Symbols (Boolean connectives and quantifiers over variables), Syntax
(wff-s ).
Axioms, inference rules.
Additional axioms and symbols characterizing the theory.
The signature of a theory T holds the set of functions and predicates
of the theory.
“First order quantifier-free theories with equality” – the
equality predicate must be part of the signature.
Additional reminders
Let be a signature.
A -interpretation A with domain A over a set of
variables V is a map which interprets:
Each
variable as a domain element
Each constant as a domain element
Each function symbol as a function of the same arity in the
domain
Each predicate symbol of arity n as a subset of An.
Additional reminders
A formula is satisfied by an interpretation A if it
evaluates to true under A.
If is satisfied by A , we say that A is a model of .
A formula over a set of V variables is satisfiable if
it is satisfied by some interpretation over V.
Additional reminders
Given a - theory , a T-model is a interpretation
that satisfies all axioms in T.
A formula over a set of V variables is T-satisfiable, if
it is satisfied by some T-model over V.
The Theory-Combination problem
Given theories T1 and T2 with signatures 1 and 2,
the combined theory T1 © T2
has
signature 1 [ 2 and
the
union of their axioms.
Let be a 1 [ 2 formula.
The problem: Does T1 © T2 ² ?
The problem
The Theory-Combination problem is undecidable (even when
the individual theories are decidable).
Under certain restrictions, it becomes decidable.
We will assume the following restrictions:
T1 and T2 are quantifier-free first-order theories with equality.
Disjoint signatures (other than equality): 1 Å 2 = ;
There is a decision procedure for each of the theories
T1 and T2 are theories that are interpreted over an infinite domain
(e.g. Linear arithmetic over R , but not finite-width bit vectors).
There are extensions to the basic N.O. procedure that
overcome each of these restrictions.
The Nelson-Oppen method
The Nelson-Oppen combination procedure solves the
theory combination problem for theories that comply
with the restrictions.
The input formula must be a conjunction of literals.
The Nelson-Oppen method (1)
Purification: validity-preserving transformation of
the formula after which predicates from different
theories are not mixed.
1.
Replace an `alien’ sub-expression with a new auxiliary
variable a
2.
Constrain the formula with a =
Transform
… into
x1· f(x1)
x1· a1 Æ a1 = f(x1)
Uninterpreted Functions
Pure expressions, shared variables
Arithmetic
Purification in more details (formal description)
For term t, let hd(t) be the root symbol.
For
example: hd(f(x)) = f
Then for i,j ∈{1,2} and i j, repeat the following
transformations as long as possible:
If
function f∈ i and hd(t) ∈ j
F f ( t1 ,..., t ,..., tn ) F f ( t1 ,..., w,..., tn ) w = t
If
predicate p∈ i and hd(t) ∈ j
F p ( t1 ,..., t ,..., tn ) F p ( t1 ,..., w,..., tn ) w = t
If
hd(s)∈ i and hd(t) ∈ j
F s = t F w = t w = s
Purification – detailed example
F: x¸1 Æ 2¸x Æ f(x) f(1) Æ f(x) f(2)
Theories involved: TEUF and TZ
Since f ∈ EUF and 1 ∈ Z , replace f(1) by f(w1) and add
w1=1.
Similarly, replace f(2) by f(w2) and add w2=2.
Now, the literals x¸1 , 2¸x , w1=1 , w2=2 , are TZ –literals,
and the literals f(x) f(w1) , f(x) f(w2) are TEUF –literals
Formula after purification:
x¸1 Æ 2¸x Æ f(x) f(w1) Æ f(x) f(w2) Æw1=1Æw2=2
Purification – another example
F: f(x)=x+y Æ z+y ¸x Æ y¸x+z Æ y=1 Æ f(x) f(2)
In the first literal hd(f(x))= f∈ EUF and hd(x+y) =+∈ Z ,
Thus, replace the literal with: w1=x+y Æ w1=f(x)
In the last literal, f∈ EUF but 2∈ Z , therefore replace it by
f(x) f(w2) Æ w2=2
Formula after purification:
w1=x+y Æ z+y ¸x Æ y¸x+z Æ y=1 Æ w2=2 Æ
w1=f(x) Æ f(x) f(w2)
The Nelson-Oppen method (2)
After purification we are left with several sets of pure
expressions F1,…,Fn such that:
Fi
belongs to some ‘pure’ theory which we can decide.
Shared
variables are allowed, i.e. it is possible that for
some i,j: vars(Fi) Å vars(Fj) ;.
is satisfiable $ F1 Æ … Æ Fn is satisfiable
If
sati reports that any Fi is unsat, then is unsat
But
We
the converse is not true in general
need a way for the decision procedures to communicate
with each other about shared variables
The Nelson-Oppen method* (3)
1.
Purify into F1Æ … Æ Fn.
2.
If 9i. Fi is unsatisfiable, return `unsatisfiable’ .
3.
If 9i,j. Fi implies an equality not implied by Fj, add
it to Fj and goto step 2.
4.
Return `satisfiable’.
* So far only for ‘convex’ theories – to be explained
Example(1)
f(x1,0) ¸ x3 Æ f(x2,0) · x3 Æ (x1 ¸ x2) Æ (x2 ¸ x1) Æ
( x3 – f(x1,0) ¸ 1)
Purification:
a1 ¸ x3 Æ a2 · x3 Æ (x1 ¸ x2) Æ (x2 ¸ x1) Æ
( x3 – a1¸ 1) Æ a0 = 0 Æ a1 = f(x1, a0) Æ a2 = f(x2, a0)
Neither F1 nor F2 is contradictory, thus we proceed to step (3)
Example (1) – cont’d
Linear Arithmetic
EUF
a1 ¸ x3
a1 = f(x1, a0)
a2 · x3
a2 = f(x2, a0)
x1 ¸ x2
x2 ¸ x1
x3 – a1¸1
a0=0
x1 = x2
x1 = x2
a1 = a2
a1 = a2
a1 = x3
False
Example(2)
(x2 ¸ x1) Æ (x1 – x3 ¸ x2) Æ (x3 ¸ 0) Æ f(f(x1) – f(x2)) f(x3)
Purification:
(x2 ¸ x1) Æ (x1 – x3 ¸ x2) Æ (x3 ¸ 0 ) Æ f(a1) f(x3) Æ
a 1 = a2 – a3 Æ
a2 = f(x1)
Æ
a3 = f(x2)
Æ
Example (2) – cont’d
Arithmetic
EUF
x2 ¸ x1
f(a1) f(x3)
x1 – x3 ¸ x2
a2 = f(x1)
x3 ¸ 0
a3 = f(x2)
a1 = a2 – a3
x3 = 0
x1 = x2
x1 = x2
a2 = a3
a2 = a3
a1 = 0
a1 = x3
a1 = x3
False
Wait, it’s not so simple…
Consider: : 1 · x Æ x · 2 Æ p(x) Æ :p(1) Æ :p(2 )
x2Z
Arithmetic over Z
Uninterpreted
predicates
1 · x
p(x)
x·2
:p(1)
:p(2)
Neither theories imply an equality, and both are
satisfiable.
But is unsatisfiable!
Some theories have it, some don’t
Definition: A theory T is convex if for all
conjunctions it holds that
( ! Çi=1..n xi=yi for some finite n > 1 )
( ! xi = yi for some i 2 {1..n})
Convex: Linear Arithmetic over R, EUF
Non-convex: Almost anything else…
Convexity: examples
Linear arithmetic over R is convex
: x1 · 1 Æ x1 ¸ 0 implies an infinite disjunction of equalities,
: x1 · 1 Æ x1 ¸ 1 ! x1 = 1
implies a singleton
: x1 · 1 Æ x1 ¸ 2
implies everything
Linear arithmetic over Z is not convex
: 1 · x1 Æ x1 · 2 Æ u = 1 Æ v = 2
Although
! (x1 = u Ç x1 = v)
It is not the case that ! x1 = u Ç ! x1 = v
Convexity: examples
The conjunctive fragment of equality logic is convex
: x1 = x2 Æ x2 = x3 Æ x5 = x3 ! x5 = x2 Ç x5 = x1
! x5 = x2 and
! x5 = x1
Many theories used in practice are in fact nonconvex.
It makes them computaionally harder to combine with other
theories.
So why is convexity important ?
Recall:
: 1 · x Æ x · 2 Æ p(x) Æ :p(1) Æ :p(2)
x2Z
Arithmetic over Z
Uninterpreted
predicates
1 · x
p(x)
x·2
:p(1)
:p(2)
Neither theories imply an equality, and both are
satisfiable.
So why is convexity important ? (cont’d)
But: 1· x Æ x · 2 imply the disjunction x = 1 Ç x = 2
Since the theory is non-convex we cannot propagate
either x=1 or x=2.
We can only propagate the disjunction itself.
So why is convexity important ? (cont’d)
Propagate the disjunction and perform case-splitting.
Arithmetic over Z
Uninterpreted
predicates
1 · x
p(x)
x·2
:p(1) Æ :p(2)
x=1Çx=2
x=1Çx=2
Split!
h¢i Æ x = 1 h¢i Æ x = 2
False
False
So why is convexity important? (cont’d)
Conclusion: when the theory is non-convex, we must
case-split.
This adds a splitting step in Nelson-Oppen.
As a result:
Convex
theories: Polynomial
Non-Convex theories: Exponential
The (full) Nelson-Oppen method
1.
Purify into ’: F1Æ…Æ Fn.
2.
If 9i. Fi is unsatisfiable, return `unsatisfiable’ .
3.
If 9i,j. Fi implies an equality not implied by Fj, add it to Fj
and goto step 2.
4.
5.
If 9i. Fi ! (x1= y1Ç…Ç xk= yk) but 8j Fi 9 xj= yj,
apply recursively to ’Æ x1= y1, … ,’Æ xk= yk.
If any of them is satisfiable, return ‘satisfiable’. Otherwise
return ‘unsatisfiable’.
Return `satisfiable’.
Example(3)
Consider the ( E [ Z)-formula :
(x ¸ 1) Æ ( 3 ¸ x) Æ (f(x) f(1)) Æ (f(x) f(3)) Æ (f(1) f(2))
Purification:
(x ¸ 1) Æ ( 3 ¸ x) Æ a1 =1 Æ a2 =2 Æ a3 =3 Æ
(f(x) f(a1)) Æ (f(x) f(a3)) Æ (f(a1) f(a2))
Example(3)
Arithmetic over Z
Uninterpreted functions
1 · x
f(x) f(a1)
x·3
f(x) f(a3)
a1 =1
f(a2) f(a1)
a2 =2
a3 =3
x = a1 Ç x = a2 Ç x = a3
x = a1 Ç x = a2 Ç x = a3
h¢i Æ x = a1
Split!
h¢i Æ x = a2
False
Neither decision procedure discovers any contradiction or new equality
Thus F is satisfiable in the combined theory
Equality Propagation
For a convex theory:
It
is sufficient to test each equality possible of the form
x=y.
Any equality implied should be propagated to the other
theories.
For a non-convex theory:
The procedure must find disjunction of equalities implied
by some Fk.
The disjunctions should be as small as possible since the
N.O method must branch on each disjunct
A disjunction is minimal if it is implied by Fk and each
smaller disjunction is not implied by Fk .
Equality Propagation
Simple procedure to find minimal disjunction:
Observation: any
disjunction that contains a minimal
disjunction implied by Fk - is also implied by Fk .
The
idea: strip off extra disjuncts one-by-one
Start with the disjunction of all equalities at once
Remove disjuncts that their removal preserves the implication.
Correctness is hard to prove…
Theorem: N.O. returns unsatisfiable if and only if its input
formula is unsatisfiable.
We will prove this theorem for the case of combining two
convex theories.
The generalization is not hard.
Correctness Proof
() is satisfiable! N.O. returns ‘satisfiable’
(That’s the simple side)
Assume is satisfiable and let be a satisfying assignment of .
Let A = {a1,…,an} be the purification (auxiliary) variables.
Claim: there exists an assignment to the A variables such that
extended with this assignment satisfies F1Æ F2.
(because F1Æ F2 and are equisatisfiable)
Let ’ be this extended assignment.
Example for the assignment extension
f(x1,0) ¸ x3 Æ f(x2,0) · x3 Æ (x1 ¸ x2) Æ (x2 ¸ x1) Æ
( x3 – f(x1,0) ¸ 0)
Purification:
a1 ¸ x3 Æ a2 · x3 Æ (x1 ¸ x2) Æ (x2 ¸ x1) Æ
( x3 – a1¸ 0) Æ a0 = 0 Æ a1 = f(x1, a0) Æ a2 = f(x2, a0)
Satisfying assignment for :
:{ x1 ! 1, x2 !1, x3!1 }
Extended satisfying assignment:
’:{a0 ! 0, a1 ! 1,a2 ! 1, x1 ! 1, x2 !1, x3!1 }
Correctness Proof
Lemma 1:
Let be satisfiable. After Each loop iteration F1Æ F2 is satisfiable in the
combined theory.
Proof by induction on the number of loop iterations.
Base: for iteration #0: F1,0Æ F2,0 is satisfiable (’ is the satisfying
assignment)
Induction Step: assuming correctness up to iteration j, and we shall
prove for j+1:
For any x=y added in step (3) there exists i s.t Fi,j ! x=y in Ti .
Correctness Proof
’ |= Fi,j in Ti by the Induction Hypothesis.
Fi,j ! x=y and ’ |= Fi,j implies that ’ |= x=y .
’ |= Fi,j for all i , therefore ’ |= Fi,j Æ (x=y) , in Ti , for all i.
’ |= Fi,j+1 , in Ti , for all i.
Conclusion: The algorithm will not return unsat in
step (2).
Proof ()
() If N.O. returns ‘satisfiable’, is satisfiable.
(This will require several definition and lemmas)
Observation: The algorithm always terminates
There are only finitely many equalities over the variables in the formula
Lemma 2:
Let Fi‘ denote the formula Fi upon termination of the
algorithm. Upon termination with the answer ‘satisfiable’ , any
equality between ‘ variables that is implied by any of the Fi‘
is also implied by all Fj‘ for any j.
Proof ()
Assume falsely that is unsat, and the algorithm returnes ‘sat’.
Let E1,…,Em be a set of equivalence classes of the variables in
s.t x,y are in the same class iff F1’! x=y in T1
From Lemma 2, x,y are in the same class Ei iff F2’! x=y in
T2
Let ri for i in {1,…,m} be a representative element of the
class Ei .
We define a constraint ∆ as follows:
∆ = Æi≠j(ri ≠rj)
Proof ()
Lemma 3
Given that both T1 and T2 have an infinite domain and are convex, ∆ is
T1–consistent with F1’ and T2 -consistent with F2’ .
Proof Sketch
Let x and y be two variables that are not implied to be equal.
Owing to convexity, they do not have to be equal to satisfy Fi’ .
As the domain is infinite, there are always values left in the domain that
we can choose in order to make x and y different.
Owing to convexity, they do not have to be equal to satisfy Fi’
the theory was non-convex, it wouldn’t be necessarily
true
If
For example:
: z · x Æ x · y Æ p(x) Æ :p(y) Æ :p(z) Æ y=2 Æ z=1
Adding ∆ to F1’ will cause a conflict
That is because the theory is not convex and a finite disjunction is
implied by F1’
As
the domain is infinite, there are always values left in the
domain that we can choose in order to make x and y
different.
If
the domain was finite, it wouldn’t be necessarily true
For example:
Consider a theory
F1’ : g(x1) g(x3) Æ g(x2) g(x3)
T1 :
Adding x1 x2 to F1’ will cause a conflict
in the given theory
That is because the domain size is finite
and its size is up to 2.
1: A function g,
Axioms that only
allow solutions with
2 distinct values.
Proof ()
Conclusion from the Lemma:
There are satisfying assignments 1 and 2 for F1’ Æ ∆ and F2’ Æ ∆
in T1 and T2 , respectively.
These assignments are maximally diverse
Two variables assigned equal values by them, must be equal.
Note that 1 |= x=y iff 2 |= x=y , for every pair of variables x,y.
Given this property, it is easy to build a mapping M (an
isomorphism) from domain elements to domain elements such
that 2(x) is mapped to 1(x) for any variable x.
Not necessarily possible unless the assignments are maximally diverse.
Example
(x ¸ y) Æ (y ¸ x) Æ (z ¸ y) Æ (w ¸ z) Æ (f(z) f(y)) Æ
(f(x) f(w))
E2
E1
x,y
z
E3
w
Assignments that satisfy F1’ and F2’ that are not maximally diverse:
α1 = {x→1, y→1, z→1 , w→1}
α2 = {x→5, y→5, z→3 , w→4}
We cannot build here the mapping M
Example
(x ¸ y) Æ (y ¸ x) Æ (z ¸ y) Æ (w ¸ z) Æ (f(z) f(y)) Æ
(f(x) f(w))
E2
E1
x,y
z
E3
w
Assignments that satisfy F1’ Æ ∆ and F2’ Æ ∆ are maximally diverse:
α1 = {x→1, y→1, z→2 , w→3}
α2 = {x→5, y→5, z→3 , w→4}
We can build here a mapping M: M(1)=5, M(2)=3, M(3)=4,…
Example
(x ¸ y) Æ (y ¸ x) Æ (z ¸ y) Æ (w ¸ z) Æ (f(z) f(y)) Æ
(f(x) f(w))
Defining an interpretation that satisfies both F1’ Æ ∆ and F2’ Æ ∆
based on the isomorphism M:
Option 1:
If we choose the mapping : M: M(5)=1, M(3)=2, M(4)=3,…
α2 = {x→5, y→5, z→3 , w→4} z ¸ y iff M(z) ¸ M(y)
Option 2: the mapping M: M(1)=5, M(2)=3, M(3)=4,…
α1 = {x→1, y→1, z→2 , w→3} f(z) = M-1(f(M(z))
Note that we rely on the fact that the signatures are disjoint
Proof ()
Using the mapping M, we can obtain a model α’ for F1’ Æ F2’
in the combined theory.
As Fi’ implies Fi , α’ is also a model for F1 Æ F2 in the
combined theory, which contradicts our assumption that is
unsatisfiable.
Proof - More details
Theorem 1
1 and 2 be signatures with 1 ∩ 2 = Ø , and for
i=1,2 let Fi be a set of i –formulas, and Vi the set of
variables appearing in Fi. Let V = V1 ∩ V2 .
Let
Then F1 Æ F2 is satisfiable iff there exists an
interpretation A satisfying F1 and an interpretation B
satisfying F2 such that :
|A|=|B|
xA=yA iff xB=yB for every pair of variables x,y in V
The proof is based on an isomorphism and obtaining an interpretation
satisfying F1 Æ F2
There is another theorem in logic saying that formula is satisfiable iff there
exist isomorphic interpretations satisfying the sub-formulas
Proof - More details
There exist A and B which are interpretations over
infinite domains since the theories are restricted to
infinite domains
How can we be sure that we can obtain interpretations
of the same cardinality?
Proof - More details
Theorem 2 - Löwenheim–Skolem theorem
The
theorem states that if a countable first-order theory has
an infinite model, then for every infinite cardinal number κ
it has a model of size κ. The result implies that first-order
theories are unable to control the cardinality of their infinite
models.
Therefore
we can obtain interpretations of the same
cardinality for infinite domains
Proof ()
Proof sketch summary:
Based on Lemma 3 there are interpretations A , B over infinite domains
satisfying F1 and F2 respectively
The assignments of the interpretations are maximally diverse and
therefore
1 |= x=y iff 2 |= x=y , for every pair of variables x,y.
Based on Theorem 2 there exist interpretations A, B of the same
infinite cardinality : |A|=|B|
Based on Theorem 1 , F1 Æ F2 is satisfiable
Correctness for convex and non-convex theories
On
the case-splitting:
If on all branches the conjunction is unsatisfiable, then the original
formula is necessarily unsatisfiable.
If there exists a branch on which the conjunction is satisfiable, then
the original formula is satisfiable and no other branches need to be
checked.
Abstract (non-deterministic) version for the
Nelson-Oppen procedure
Let V be the set of variables used in F1 ,…,Fn .
A partition P of V induces equivalence classes
Every assignment to V’s variables induces such a
partition
Denote by R the equivalence relation corresponding
to these classes
The arrangement corresponding to P is:
ar(P) = [ÆviRvj, i<j(vi = vj) ] Æ [ƬviRvj,i<j(vi ≠vj) ]
Abstract (non-deterministic) version for the
Nelson-Oppen procedure
For example, if V={x1,x2,x3}, and
P = {{x1,x2},{x3}}
ar(P) :=
x1=x2 Æ x1 ≠ x3 Æ x2 ≠ x3
Abstract (non-deterministic) version for the
Nelson-Oppen procedure
The abstract version of the Nelson-Oppen procedure:
1.
Purification – the same as in the deterministic version.
2.
Choose nondeterministically a partition P of V’s
variables.
3.
If one of Fi Æ ar(P) is unsatisfiable, return unsat.
Otherwise, return sat.
Abstract version - example
Consider the ( E [ Z)-formula :
F: (x ¸ 1) Æ ( 2 ¸ x) Æ (f(x) f(1)) Æ (f(x) f(2))
After purification we have:
F1: (f(x) f(y)) Æ (f(x) f(z))
F2: (x ¸ 1) Æ ( 2 ¸ x) Æ (y = 1) Æ ( z = 2)
1. {x = y , x = z , y = z }
Inconsistent with F1
2. {x = y , x z , y z }
Inconsistent with F1
3. {x y , x = z , y z }
Inconsistent with F1
4. {x y , x z , y = z }
Inconsistent with F2
5. {x y , x z , y z }
Inconsistent with F2
Abstract (non-deterministic) version for the
Nelson-Oppen procedure
The nondeterministic step can be replaced with a
deterministic one, by trying all such partitions
possible.
The requirement in the N.O. procedure for sharing
implied equalities can be understood as optimization
over an exhaustive search, rather then a necessity for
correctness.
Abstract (non-deterministic) version for the
Nelson-Oppen procedure
Advantages of the abstract presentation:
Abstracting implementation details (typically by
nondeterminism) is helpful for clarity, generality,
simplicity of proofs.
Can
help in designing concrete procedures in a more
modular way
Practical efficiency of the non-deterministic method
Phase 2 is formulated as “guess and check”
The number of equivalence relations increases
significantly with the number of shared variables.
The number of equivalence relations is given by the
sequence of Bell numbers which grows superexponentially
For
example: 12 shared variables induce over 4 million
equivalence relations
Practical efficiency of the non-deterministic method
In fact, there is no need to guess the entire
equivalence relation at once
Instead it can be constructed incrementally
In practice, implementations are based on the
deterministic method
Example for incremental “optimization” of the
nondeterministic method
(a1 = x+y) Æ (y+z ¸ x) Æ (y ¸ x+z) Æ (y=1) Æ (a2=2) Æ (a1 = f(x)) Æ
(f(x) f(a2))
Shared variables: x,a1,a2
We attempt to construct an arrangement incrementally
Suppose x=a1 => from F1, a1 = x+y implies y=0 which contradicts
(y=1) in F1. => x a1
F1 Æ (x a1) and F2 Æ (x a1) are satisfiable
Suppose x=a2 => from F2 (f(x) f(a2)) thus contradiction => x a2
F1 Æ (x a1) Æ (x a2) and F2 Æ (x a1) Æ (x a2) are satisfiable
Suppose a1=a2 => no contradiction exists.
We discovered the arrangement {{a1,a2},{x}}, so F is
satisfiable in the combined theory
Stably Infinite Theories
Definition: A -theory T is Stably-infinite if for every
quantifier-free -formula
is satisfiable ,
can be satisfied by an interpretation with an infinite
domain.
The requirement that Ti has an infinite domain can be
generalized to the requirement that Ti is stablyinfinite.
Correctness
of N.O. procedure is preserved for stably
infinite theories
Stably Infinite Theories
Example 1:
Consider
the theory Ta,b with the signature {a,b,=}
a,b are constants
The axiom: for all x : (x=a) or (x=b)
For
every T-interpretation, the domain has at most 2
elements.
Hence, Ta,b is not stably infinite
Stably Infinite Theories
Example 2:
theory TE is stably infinite
Proof:
The
Let F be a formula with arbitrary satisfying TE -interpretation I:
(DI, αI).
Let A be any infinite set disjoint from DI
Then construct a new interpretation J (DJ, αJ) :
DJ = DI ∪ A
v1 = J v2
T
F
v1 = I v2
if v1 , v2 DI
if v1 , v2 are the same element
otherwise
J is a TE -interpretation satisfying F with infinite domain.
Hence, TE is stably infinite.
The problem with a non-stably infinite theory
Definition: A -theory T is Stably-infinite if for every
quantifier-free -formula
is satisfiable ,
can be satisfied by an interpretation with an infinite
domain.
Specifically, this means that no theory with a finite
domain is stably infinite.
Problem: non-stably infinite theories
Consider a theory T1:
1: A function f,
Axioms that only allow
solutions with 2 distinct values.
And a theory T2:
2: A function g,
Domain: N
Recall that the combined theory T1 © T2 has the union of the axioms.
Hence the solution to any formula 2 T1 © T2 cannot have more than 2 distinct
values.
So this formula is unsatisfiable:
: f(x1) f(x2) Æ g(x1) g(x3) Æ g(x2) g(x3)
Problem: non-stably infinite theories
: f(x1) f(x2) Æ g(x1) g(x3) Æ g(x2) g(x3)
T1
T2
f(x1) f(x2)
g(x1) g(x3)
g(x2) g(x3)
No equalities to propagate: Satisfiable !
Solution to non-stable infinite theories
Nelson-Oppen method cannot be used.
Recently a solution to this problem was suggested by Tinelli &
Zarba [TZ05]
Extension 1: Shiny Theory with non-stably infinite theory
Tinelli & Zarba [TZ05]
Smooth Theory
is smooth if for every quantifier free formula , for
every T-model A satisfying , and for every cardinal
number k > |A|, there exists a T-model B satisfying s.t
|B|=k.
T
Minimal cardinality
mincardT()
– the smallest cardinality of a T-model
satisfying .
If T is stably-finite, then for every satisfiable formula
mincardT() is a natural number
Extension 1: Shiny Theory with non-stably
infinite theory
Shiny Theory
A
theory T is shiny if:
T is smooth
T is stably finite
mincardT is computable
Examples
for some shiny theories: equality (over an
arbitrary signature), partial orders, total orders
The combination method
that T1 is shiny and T2 is some theory (not
necessarily stably infinite)
Assume
Extension 1: Shiny Theory with non-stably
infinite theory - The combination method
1.
Purification
2.
Choose nondeterministically a partition P of V’s variables.
3.
If F1 Æ ar(P) is satisfiable go to the next step. Otherwise
output fail.
4.
Compute n = mincardT1(F1 Æ ar(P) )
5.
Construct a set δn of literals whose purpose is to force models
with cardinality at least n.
•
•
6.
Generate n new variables w1,…,wn not occurring in F1 Æ F2
Let δn ={wi ≠ wj | 1≤ i<j ≤ n }
If F2 Æ ar(P) Æ δn is satisfiable, output succeed. Otherwise
output fail.
Extension 1: Shiny Theory with non-stably
infinite theory
If there exists an equivalence relation for which the
check phase outputs succeed then the formula is
satisfiable in the combined theory, otherwise it is
unsatisfiable
In N.O we assume that T2 is stably infinite, and
therefore the constraint δn is guaranteed to hold.
In this extended variant of N.O there is a propagation
of certain cardinality constraints in addition to
propagating equality constraints.
Back to the example
: f(x1) f(x2) Æ g(x1) g(x3) Æ g(x2) g(x3)
T1
T2
f(x1) f(x2)
g(x1) g(x3)
g(x2) g(x3)
If x1 x2 ∈ Ei in the partition , then we will output fail because F1 is unsat
Back to the example
: f(x1) f(x2) Æ g(x1) g(x3) Æ g(x2) g(x3)
T1
T2
f(x1) f(x2)
g(x1) g(x3)
g(x2) g(x3)
If x1 x2 ∉ Ei in the partition , then F2 is satisfiable.
In addition, we have mincard(F2Æ(x1 ≠x2 ))=3
In the third step: F1Æ(x1 ≠x2 )Æ δ3 is T1-unsatisfiable
We therefore declare that is unsat.
Extension 2: combining stably-finite theories
Assuming all combined theories are stably-finite (in
particular, it has a small model property), it computes,
if possible, the upper bound on the minimal satisfying
assignment, and propagates this information between
the theories.
Extension 2: combining stably-finite theories
Assume all combined theories are stably finite (i.e. have a small model
property), and one has only finite models. The bound Ni on the
minimal satisfying assignment of formulas in theory Ti is computable.
Transfer Ni between theories.
If there is no solution to theory j with cardinality at least N_i (for all i),
return unsatisfiable.
…
Summary
The N.O. combination method provides a general
means of reasoning simultaneously about several
theories using the individual decision procedures.
In practice, the main application of N.O. procedure is
the combination of equality logic with UF with other
theories, for example linear arithmetic.
It is implemented in this way in most state-of-the-art
solvers.