L∃∀N-verified Quantum Information Theory

  • RRS to QIC891, Fall 2026

  • Lecture 1, 2026-09-15

\Gamma ⊢ t : T

Lecture logistics

  • Some change of rooms. Space Room from today (15th) to September 22

  • 24th in Sky, 29th in Time, and 1st of October in Sky again

  • A repository with these slides and Lean code will be made public

  • PSI Room Office hours

Learning outcomes

  • Create a Lean project repository from scratch

  • Understand math in a Lean way

  • Be able to assess the quality of AI-written code

Assignment: one project at the end

  • Overarching Goal: Make a contributing Pull Request to the Github repository of Physlib, Quantumlib, Lean-QuantumInfo, or Mathlib.

    • Meaning: your work is also an actual citable contribution!

    • (Of course, it will not be judged by whether the PR was accepted)

  • A list of suggestions will be posted on the course webpage

    • This includes non-QI options

    • Projects that are not exactly formalization are also welcome. Maybe you want to build your own kernel? Let's teach each other!

Maths under a different guise

  1. Set theory and the Zermelo--Frankel axioms, with the axiom of choice

  2. Type theory

What kind of differences do we expect to find? Is \mathbb{R} a set or a type, in Lean?

variable {x : ℝ} #check x -- as declared above, x is of type ℝ /- type judgment is defined to output the RHS -/
x : ℝ
#check (x : ℝ)
x : ℝ
#check (Set ℝ) -- the set built from type ℝ is another data term in Type
Set ℝ : Type

Maths as code

import Mathlib.Tactic
-- import Mathlib.Topology.Basic

import VersoSlides
import Verso.Doc.Concrete

open VersoSlides
/- Preamble of this exact slide you're reading -/
  • Are these two things different after all?

Propositions as Types paradigm

Theorem-proving code

-- Check definition of a topological space in mathlib #check TopologicalSpace -- Check that √2 is irrational
TopologicalSpace.{u} (X : Type u) : Type u
#check irrational_sqrt_two -- Verify a simple identity using the ring tactic
irrational_sqrt_two : Irrational √2
example (a b : ℝ) : (a + b)^2 = a^2 + 2*a*b + b^2 := by ring -- Or a numeric check #reduce (2 : ℕ) + 2 -- should print 4 /- from PatrickMassot/GlimpseOfLean -/
4
def continuous_at (f : ℝ → ℝ) (x₀ : ℝ) := ∀ ε > 0, ∃ δ > 0, ∀ x, |x - x₀| ≤ δ → |f x - f x₀| ≤ ε #check continuous_at
continuous_at (f : ℝ → ℝ) (x₀ : ℝ) : Prop

Quantumlib and Physlib more broadly

Coding, mathematics, and possibly theoretical physics without context-switching

In what do we trust?

  • The main source of trust: the Lean KERNEL

  • The "flow of trust". What else should we rely on?

    • Lean elaborator: what you're writing is being translated honestly to the kernel

    • Hardware

    • Possibly, the Lean compiler

    • Possibly, external type-checkers

  • The Lean Kernel Arena (LKA) 🏟️

    • def: Ongoing adversarial multi-implementation conformance suite.

Lean@leanprover announcement on Twitter of the LKA

The diversity is the point. A bug that lets one kernel accept an invalid proof would have to exist in every kernel at once to go undetected.

🏟️

arena.lean-lang.org

The Lean Kernel

  • Soundness

    • def: a kernel is sound iff it never accepts a proof term of False. By ex falso, proving False implies anything can be proven. Catastrophic ⚠️

    • Accepting an incorrect proof.

  • Completeness

    • def: Rejecting a correct proof.

LKA Tutorial Test Cases

List of test cases

What if the Lean Kernel has bugs?

  • The landscape is rapidly changing. A fully trusted kernel, and thus a fully trusted Lean should pass an audit.

  • First bugs have been reported as early as a month ago!

  • Two Postmortem.

Wikipedia definition:

Post-mortem is debugging of the program after it has already crashed.

Postmortem, 2026-08-01

Kernel Soundness Bug #14576

  • nanoda external checker in Rust

  • lean4lean external checker in Lean

Postmortem, 2026-08-24

Kernel Soundness Bug Hunt

  • lake check --paranoid

    • lean4checker

  • lean-inductive-models

    • “Lean's theory of inductive types is well understood”

The role of Lean in view of AI

Autoformalization of Fermat's Last Theorem (Lean FRO project)

  • Years-long project led by Kevin Buzzard.

Autoformalization of Fermat's Last Theorem

“On the Navier-Stokes Millennium Prize Problem”

Reported controversy (as of 15th of September, ~10:30):

And the solutions themselves: