Probabilistically Checkable Proofs
Total Page:16
File Type:pdf, Size:1020Kb
Probabilistically checkable proofs The MIT Faculty has made this article openly available. Please share how this access benefits you. Your story matters. Citation Sudan, Madhu. “Probabilistically checkable proofs.” Commun. ACM 52.3 (2009): 76-84. As Published http://dx.doi.org/10.1145/1467247.1467267 Publisher Association for Computing Machinery Version Author's final manuscript Citable link http://hdl.handle.net/1721.1/52308 Terms of Use Article is made available in accordance with the publisher's policy and may be subject to US copyright law. Please refer to the publisher's site for terms of use. Probabilistically checkable proofs ∗ Madhu Sudan MIT CSAIL, 32 Vassar Street, Cambridge, MA 02139, USA ABSTRACT be confident that if the proof was buggy you would be able Can a proof be checked without reading it? That certainly to find an error by such a superficial reading? seems impossible, no matter how much reviewers of mathe- Alas, the current day formats of proofs don’t allow such matical papers may wish for this. But theoretical computer simple checks. It is possible to build a “proof” of any “as- science has shown that we can get very close to this objec- sertion” (in particular ones that are not true) with just one tive! Namely random consistency checks could reveal errors single error, which is subtly hidden. Indeed, if you think in proofs, provided one is careful in choosing the format in back to the “proofs” of “1 = 2” that you may have seen in which proofs should be written. In this article we explain the past, they reveled in this flaw of current proof systems. this notion, constructions of such probabilistically checkable Fortunately this shortcoming of proofs is not an inherent proofs, and why this is important to all of combinatorial flaw of logic. Over the past two decades, theoretical com- optimization. puter scientists have come up with novel formats for writing proofs of mathematical assertions. Associated with these formats are probabilistic algorithms that reviewers could Categories and Subject Descriptors (should?) use to verify the proofs. A reviewer using such F.4.1 [Mathematical Logic and Formal Languages]: a verification algorithm would be spared from reading the Mathematical Logic; F.0 [Theory of Computation]: Gen- entire proof (and indeed will only read a “constant number eral of bits of the proof” - a notion we will elaborate on, and explain later). Any researcher who has a proof of a theorem can rewrite the proof in the prescribed format and offer it General Terms to the reviewer, with the assurance that the reviewer will be Algorithms, Theory, Verification convinced of this new proof. On the other hand if someone claims a faulty assertion to be a theorem, and offers any Keywords proof (whether in the new format or not), the reviewer will discover an error with overwhelming probability. Randomness, Logic, Compuational Complexity, Combinato- In what follows we will attempt to formalize some of the rial Optimization notions that we have been using in a casual sense above. The central notion that will emerge is that of a “Probabilis- 1. INTRODUCTION tically Checkable Proof (PCP)”. Existence of such formats and verification algorithms often runs contrary to our in- The task of verifying a mathematical proof is extremely tuition. Nevertheless they do exist, and in Section 4 we onerous, and the problem is compounded when a reviewer discuss two different approaches that have been used thus really suspects a fatal error in the proof but still has to find far to construct such PCPs. an explicit one so as to convincingly reject a proof. Is there PCPs are arguably fascinating objects. They offer a cer- any way to simplify this task? Wouldn’t it be great if it tain robustness to the logical process of verification that may were possible to scan the proof cursorily (i.e., flip the pages not have been suspected before. While the process of prov- randomly, reading a sentence here and a sentence there) and ing and verifying theorems may seem of limited interest (say, ∗Research supported in part by NSF Awards CCR-0726525 only to mathematicians), we stress that the notion of a “con- and CCR-0829672. The views expressed in this article are vincing” argument/evidence applies much more broadly in those of the author and not endorsed by NSF. all walks of life. PCPs introduce the fascinating possibility that in all such cases, the time taken to assess the validity of the evidence in supporting some claims, may be much smaller than the volume of the evidence. In addition to this philosophical interest in PCPs, there is a very different Permission to make digital or hard copies of all or part of this work for (and much more concrete) reason to study PCPs. It turns personal or classroom use is granted without fee provided that copies are out that PCPs shed light in the area of combinatorial op- not made or distributed for profit or commercial advantage and that copies timization. Unfortunately this light is “dark”: The ability bear this notice and the full citation on the first page. To copy otherwise, to to construct PCPs mostly says that for many optimization republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. problems where we knew that optimal solutions were (NP- Copyright 200X ACM X-XXXXX-XX-X/XX/XX ...$5.00. )hard to find, even near-optimal solutions are hard to find. Completeness If A is a theorem (in V0), then A is a theo- We discuss these connections soon after we discuss the defi- rem in V . Furthermore there is a proof of A in V that nitions of PCPs, in Section 3. is at most a polynomial factor longer than its proof in V0. Soundness If A is not a theorem (in V0) then A is not a 2. DEFINITIONS theorem in V . We start by formalizing what we mean by “theorems”, “‘proofs”, a “format” for proving them, and what it means By allowing different verifiers, or proof systems, for the to “change” such a format, i.e., what changes are allowed, same system of logic, one encounters many different ways and what qualities should be preserved. Hopefully, in the in which theorems can be proved. As an example, we show process we will also manage to establish some links between how the NP-completeness of the famous problem 3SAT al- the topic of this article and computer science. lows one to produce formats for proofs that “localize” er- To answer these questions we go to back to the essentials rors in erroneous proofs. Recall that an instance of 3SAT of mathematical logic. A system of logic attempts to clas- is a logical formula φ = C1 ∧ · · · ∧ Cm where Cj is the dis- sify “assertions” based on their “truth value”, i.e., separate junction of 3 literals (variables or their complement). The true theorems from false assertions. In particular, theorems NP-completeness of 3SAT implies the following: Given any are those assertions that have “proofs”. In such a system assertion A and integer N, there is a 3CNF formula φ (of every sentence, including theorems, assertions, and proofs, length bounded by a polynomial in N) such that φ is satisfi- is syntactically just a finite string of letters from a finite able if and only if A has a proof of length at most N (in V0). alphabet. (Without loss of generality the alphabet may be Thus the deep logical question about the truth of A seems binary i.e., {0, 1}.) The system of logic prescribes some ax- to reduce to a merely combinatorial question about the sat- ioms and some derivation rules. For an assertion to be true, isfiability of φ. The natural evidence for the satisfiability of it must be derivable from the axioms by applying a sequence φ would be an assignment and this is what we refer to as a of derivation rules. A proof of an assertion A may thus be a “format” for proofs. The advantage of this format is that in sequence of more and more complex assertions ending in the order to reject an “erroneous proof”, i.e., an assignment x assertion A, with each intermediate assertion being accom- that fails to satisfy φ, one only needs to point to one clause panied with an explanation of how the assertion is derived of φ that is not satisfied and thus only point to the three from previous assertions, or from the axioms. The exact set bits of the proof of x that this clause depends on to reveal of derivation rules used and the complexity of a single step the error. Thus errors are easily localized in this format. of reasoning may vary from one logical system to another, Can one go further and even “find” this error efficiently? but the intent is that eventually all logical systems (based This is where probabilistically checkable proofs come in. In on the same axioms) should preserve two essentials aspects: what follows we will attempt to describe verifiers that can The set of theorems provable in any given system of logic verify proofs of satisfiability of 3CNF formulae (noticing that should be the same as in any other. Furthermore, proofs by the discussion above, this is as general as verifying proofs should be “easy” to verify in each. of any mathematical statement in any formal system). This final attempt to abstract the nature of a logical sys- tem leaves us with the question: What is “easy”? It is this 2.1 Probabilistically checkable proofs aspect that led to the development of Turing and Church’s We start by formalizing the notion of the number of bits work on the Turing machine.