L∃∀N-verified Quantum Information TheoryRRS to QIC891, Fall 2026
Lecture 1, 2026-09-15
\Gamma ⊢ t : TSome change of rooms. Space Room from today (15th) to September 22
24th in Sky, 29th in Time, and 1st of October in Sky again
A repository with these slides and Lean code will be made public
PSI Room Office hours
Create a Lean project repository from scratch
Understand math in a Lean way
Be able to assess the quality of AI-written code
Overarching Goal: Make a contributing Pull Request to the Github repository of Physlib, Quantumlib, Lean-QuantumInfo, or Mathlib.
Meaning: your work is also an actual citable contribution!
(Of course, it will not be judged by whether the PR was accepted)
A list of suggestions will be posted on the course webpage
This includes non-QI options
Projects that are not exactly formalization are also welcome. Maybe you want to build your own kernel? Let's teach each other!
Set theory and the Zermelo--Frankel axioms, with the axiom of choice
Type theory
What kind of differences do we expect to find? Is \mathbb{R} a set or a type, in Lean?
variable {x : ℝ}
#checkx : ℝ x -- as declared above, x is of type ℝ
/- type judgment is defined to output the RHS -/
x : ℝ#checkx : ℝ (x : ℝ)
x : ℝ#checkSet ℝ : Type (Set ℝ)
-- the set built from type ℝ is another data term in Type
Set ℝ : Type
import Mathlib.Tactic
-- import Mathlib.Topology.Basic
import VersoSlides
import Verso.Doc.Concrete
open VersoSlides
/- Preamble of this exact slide you're reading -/
Are these two things different after all?
-- Check definition of a topological space in mathlib
#checkTopologicalSpace.{u} (X : Type u) : Type u TopologicalSpace
-- Check that √2 is irrational
TopologicalSpace.{u} (X : Type u) : Type u#checkirrational_sqrt_two : Irrational √2 irrational_sqrt_two
-- Verify a simple identity using the ring tactic
irrational_sqrt_two : Irrational √2example (a b : ℝ) : (a + b)^2 = a^2 + 2*a*b + b^2 := byx:ℝa:ℝb:ℝ⊢ (a + b) ^ 2 = a ^ 2 + 2 * a * b + b ^ 2 ringAll goals completed! 🐙
-- Or a numeric check
#reduce4 (2 : ℕ) + 2 -- should print 4
/- from PatrickMassot/GlimpseOfLean -/
4def continuous_at (f : ℝ → ℝ) (x₀ : ℝ) :=
∀ ε > 0, ∃ δ > 0, ∀ x, |x - x₀| ≤ δ → |f x - f x₀| ≤ ε
#checkcontinuous_at (f : ℝ → ℝ) (x₀ : ℝ) : Prop continuous_at
continuous_at (f : ℝ → ℝ) (x₀ : ℝ) : Prop
Coding, mathematics, and possibly theoretical physics without context-switching
The main source of trust: the Lean KERNEL
It's a folder on Github for all to see.
The "flow of trust". What else should we rely on?
Lean elaborator: what you're writing is being translated honestly to the kernel
Hardware
Possibly, the Lean compiler
Possibly, external type-checkers
The Lean Kernel Arena (LKA) 🏟️
def: Ongoing adversarial multi-implementation conformance
suite.
Lean@leanprover announcement on Twitter of the LKA
The diversity is the point. A bug that lets one kernel accept an invalid proof would have to exist in every kernel at once to go undetected.
Soundness
def: a kernel is sound iff it never accepts a proof term of
False. By ex falso, proving False
implies anything can be proven. Catastrophic ⚠️
Accepting an incorrect proof.
Completeness
def: Rejecting a correct proof.
The landscape is rapidly changing. A fully trusted kernel, and thus a fully trusted Lean should pass an audit.
First bugs have been reported as early as a month ago!
Two Postmortem.
Wikipedia definition:
Post-mortem is debugging of the program after it has already crashed.
nanoda external checker in Rust
lean4lean external checker in Lean
lake check --paranoid
lean4checker
lean-inductive-models
“Lean's theory of inductive types is well understood”
Years-long project led by Kevin Buzzard.
Accelerated by Anthropic.
Reported controversy (as of 15th of September, ~10:30):
Nature news: “Who gets credit in the AI era? OpenAI maths bombshell sparks debate”
Nature editorial: “AI companies must work with the research community to protect attribution”
Wikipedia: Navier-Stokes priority controversy
And the solutions themselves: