## Computer-Assisted Mathematics at Work -- The Hahn-Banach Theorem in Isabelle/Isar (2000)

### Cached

### Download Links

Venue: | TYPES FOR PROOFS AND PROGRAMS: TYPES’99, LNCS |

Citations: | 7 - 4 self |

### BibTeX

@INPROCEEDINGS{Bauer00computer-assistedmathematics,

author = {Gertrud Bauer and Markus Wenzel},

title = {Computer-Assisted Mathematics at Work -- The Hahn-Banach Theorem in Isabelle/Isar},

booktitle = {TYPES FOR PROOFS AND PROGRAMS: TYPES’99, LNCS},

year = {2000},

publisher = {}

}

### OpenURL

### Abstract

We present a complete formalization of the Hahn-Banach theorem in the simply-typed set-theory of Isabelle/HOL, such that both the modeling of the underlying mathematical notions and the full proofs are intelligible to human readers. This is achieved by means of the Isar environment, which provides a framework for high-level reasoning based on natural deduction. The final result is presented as a readable formal proof document, following usual presentations in mathematical textbooks quite closely. Our case study demonstrates that Isabelle/Isar is capable to support this kind of application of formal logic very well, while being open for an even larger scope.

### Citations

864 |
A Formulation of the Simple Theory of Types
- Church
- 1940
(Show Context)
Citation Context ..., one for general linear spaces, and one for normed vector spaces. We show how the underlying mathematical notions can be expressed in a very natural way, employing the simply-typed set theory of HOL =-=[11, 15]-=-. We also present a proof in Isabelle/Isar, which closely follows the original one [16]. 4.1 Structure of the Proof Theorem (Hahn-Banach). Let F be a subspace of a real vector space E, let p be a semi... |

210 | PVS: Combining specification, proof checking, and model checking
- Owre, Rajan, et al.
- 1996
(Show Context)
Citation Context ...ds. The latter provide systematic ways to exhibit errors and counterexamples, rather than prove correctness. This is mainly the area of Model Checking, but general purpose theorem provers such as PVS =-=[23]-=- are usually positioned here as well. Getting back to actual verification, we observe that current tactical provers (e.g. Isabelle [25] or Coq [12]) are usually quite inaccessible to non-specialistsus... |

199 |
editors. Introduction to HOL: a theorem proving environment for higher order logic
- Gordon, Melham
- 1993
(Show Context)
Citation Context ... proof checkers and proof assistants have emerged, just consider de Bruijn’s pioneering AUTOMATH project [21], or major contemporary theorem proving environments like Coq [12], Isabelle [25], and HO=-=L [15]-=-. This line of development represents tools for actual verification, in the sense that a very high level of confidence in correctness of the results is achieved. There is a wider picture of formal too... |

186 |
Isabelle: The next 700 theorem provers
- Paulson
- 1990
(Show Context)
Citation Context ...for advanced applications. The resulting architecture fully preserves machine-checkable correctness as provided by the primitive level. 3.1 Logical Foundations We closely follow Isabelle’s meta-logi=-=c [24], which-=- is an intuitionistic ∀/⇒/ ≡ - fragment of higher-order logic. Logical syntax is that of simply-typed λ-calculus. Proof rules are the standard ones for minimal logic, with definitional equality... |

83 | An overview of the Mizar project
- Rudnicki
- 1992
(Show Context)
Citation Context ... framework based on type theory to support multi-lingual formal documents [17]. These efforts would ultimately result in a complete mathematical vernacular based on natural language (e.g. [9]). Mizar =-=[26, 29, 19, 35] h-=-as pioneered a rather different approach, by providing a higher-level proof language as its input format in the first place — avoiding the kind of machine-oriented transformations of tactical provin... |

81 | Isar — a generic interpretative approach to readable formal proof documents
- Wenzel
- 1999
(Show Context)
Citation Context ...lle/Isar system [32] as an environment for computer-assisted formal mathematics. Isar (which stands for Intelligible semiautomated reasoning) offers a generic approach to high-level natural deduction =-=[31]. From-=- the user’s point of view, formal proof documents are the most fundamental concept of Isar. Following the basic structure of mathematical textbooks, iterating definition — theorem — proof, the a... |

80 | Proof General: A generic tool for proof development
- Aspinall
- 2000
(Show Context)
Citation Context ... are usually quite inaccessible to non-specialistsusers. This issue has been addressed in several ways, e.g. by providing graphical user interfaces to help users putting together tactic scripts (e.g. =-=[1, 2])-=-. Another major approach is to relate representations of formal proof objects directly with natural language, e.g. narrating λ-terms in plain English (or even French) [13]. There is also a more gener... |

74 | Type classes and overloading in higher-order logic. Theorem Proving in Higher Order Logics, LNCS volume 1275, SpringerVerlag
- Wenzel
- 1997
(Show Context)
Citation Context ...duce constant declarations with Isabelle-style mixfix annotations for concrete syntax. The structure of general groups over some carrier type is defined by employing Isabelle’s Axiomatic Type Classe=-=s [30, 34]-=-, which provide a useful mechanism for abstract algebraic concepts. Finally we establish the two basic consequences of the group axioms as formally proven theorems. theory Group = HOL: consts prod :: ... |

43 |
Isabelle: A Generic Theorem Prover. LNCS 828
- Paulson
- 1994
(Show Context)
Citation Context ...ful mechanized proof checkers and proof assistants have emerged, just consider de Bruijn’s pioneering AUTOMATH project [21], or major contemporary theorem proving environments like Coq [12], Isabell=-=e [25]-=-, and HOL [15]. This line of development represents tools for actual verification, in the sense that a very high level of confidence in correctness of the results is achieved. There is a wider picture... |

38 | Extracting text from proofs
- Coscoy, Hahn, et al.
- 1997
(Show Context)
Citation Context ...ther tactic scripts (e.g. [1, 2]). Another major approach is to relate representations of formal proof objects directly with natural language, e.g. narrating λ-terms in plain English (or even French)=-= [13]-=-. There is also a more general grammatical framework based on type theory to support multi-lingual formal documents [17]. These efforts would ultimately result in a complete mathematical vernacular ba... |

23 |
Declarative Theorem Proving for Operational Semantics
- Syme
- 1998
(Show Context)
Citation Context ...laim the same level of formal correctness, as established by major proof checkers, such as Coq or Isabelle. It could be still possible to give fully formal foundations for Mizar in principle. DECLARE =-=[27, 28] is -=-another more recent development of combining Mizar concepts and tactical proving into a “declarative” theorem proving system, suited for non-trivial meta-theoretical studies such as operational se... |

18 | A Two-Level Approach Towards Lean Proof-Checking
- Barthe, Ruys, et al.
- 1995
(Show Context)
Citation Context ...mitive inferences [31]. First of all, suppose we believe in the basic logical framework (see §3.1), and know how to implement it at the highest conceivable level of correctness (cf. the discussion in=-= [3, 4]-=-). Furthermore, we may formulate correctness (or even completeness) results of Isar proofs related to primitive ones by virtue of the operational semantics. While this would tell us that the Isar mach... |

12 |
Predicate calculus and program semantics. Texts and monographs in computer science
- Dijkstra, Scholten
- 1990
(Show Context)
Citation Context ...e more general than shown here. Calculational elements may be even combined with plain natural deduction (e.g. [33, §6]), without having to subscribe to a fully calculational view of logic in general=-= [14]. In-=- the next example we review slightly more involved logical reasoning: Smullyan’s Drinkers’ principle (e.g. [3]) is a puzzle of pure classical logic. It states that there is some individual such th... |

10 |
Some features of the Mizar language. Presented at a workshop in
- Trybulec
- 1993
(Show Context)
Citation Context ... framework based on type theory to support multi-lingual formal documents [17]. These efforts would ultimately result in a complete mathematical vernacular based on natural language (e.g. [9]). Mizar =-=[26, 29, 19, 35] h-=-as pioneered a rather different approach, by providing a higher-level proof language as its input format in the first place — avoiding the kind of machine-oriented transformations of tactical provin... |

7 | The Hahn-Banach theorem in type theory
- Cederquist, Coquand, et al.
- 1997
(Show Context)
Citation Context ...s proof (cf. [20]). There are some machine-checked formalizations as well, notably a Mizar version [22] (which is based on Tarski-Grothendieck set-theory), and a formulation in Martin-Löf Type Theory=-= [10]-=- that has been checked with the Agda system. In contrast to the Mizar and Isar versions, which basically share the same presentation of Hahn-Banach in a classical setting of functional analysis (using... |

7 | Three tactic theorem proving
- Syme
- 1999
(Show Context)
Citation Context ...laim the same level of formal correctness, as established by major proof checkers, such as Coq or Isabelle. It could be still possible to give fully formal foundations for Mizar in principle. DECLARE =-=[27, 28] is -=-another more recent development of combining Mizar concepts and tactical proving into a “declarative” theorem proving system, suited for non-trivial meta-theoretical studies such as operational se... |

6 | An Outline of PC Mizar
- Muzalewski
- 1993
(Show Context)
Citation Context ... framework based on type theory to support multi-lingual formal documents [17]. These efforts would ultimately result in a complete mathematical vernacular based on natural language (e.g. [9]). Mizar =-=[26, 29, 19, 35] h-=-as pioneered a rather different approach, by providing a higher-level proof language as its input format in the first place — avoiding the kind of machine-oriented transformations of tactical provin... |

5 |
Protocols for interactive e-proof
- Aspinall
- 2000
(Show Context)
Citation Context ... are usually quite inaccessible to non-specialistsusers. This issue has been addressed in several ways, e.g. by providing graphical user interfaces to help users putting together tactic scripts (e.g. =-=[1, 2])-=-. Another major approach is to relate representations of formal proof objects directly with natural language, e.g. narrating λ-terms in plain English (or even French) [13]. There is also a more gener... |

5 | 1996] The quest for correctness
- Barendregt
(Show Context)
Citation Context ...ematics actually work in non-trivial applications, and show the results to other people. Further, being able to communicate machinecheckable formal concepts adequately has an important cultural value =-=[3]-=-, influencing the way that formal logic is perceived as an issue of practical relevance in general. The particular case of formal proof in education has been addressed many times before (e.g. [8]). We... |

5 |
The Coq Proof Assistant User’s Guide, version 6.1. INRIA-Rocquencourt et CNRSENS
- Cornes, Courant, et al.
- 1996
(Show Context)
Citation Context ...s, many successful mechanized proof checkers and proof assistants have emerged, just consider de Bruijn’s pioneering AUTOMATH project [21], or major contemporary theorem proving environments like Co=-=q [12]-=-, Isabelle [25], and HOL [15]. This line of development represents tools for actual verification, in the sense that a very high level of confidence in correctness of the results is achieved. There is ... |

5 |
The Hahn–Banach theorem: the life and times
- Narici, Beckenstein
- 1997
(Show Context)
Citation Context ...user interface support only. Together with the existing Proof General interface [1], we already obtain a reasonable working environment for actual applications. We have chosen the Hahn-Banach Theorem =-=[16, 20]-=- as a realistic case study of computer-assisted mathematics performed in Isabelle/Isar. The theorem has 2sbeen completely formalized (in two versions), together with any required notions of functional... |

5 |
The Isabelle/Isar Reference Manual. Technische Universität
- Wenzel
- 2002
(Show Context)
Citation Context ...epts and tactical proving into a “declarative” theorem proving system, suited for non-trivial meta-theoretical studies such as operational semantics. Our present work employs the Isabelle/Isar sys=-=tem [32] a-=-s an environment for computer-assisted formal mathematics. Isar (which stands for Intelligible semiautomated reasoning) offers a generic approach to high-level natural deduction [31]. From the user’... |

5 | Miscellaneous Isabelle/Isar examples for higher-order logic. Part of the Isabelle distribution, http://isabelle.in.tum.de/library/ HOL/Isar examples/document.pdf - Wenzel - 2001 |

4 | The Hahn-Banach theorem for real vector spaces
- Bauer
- 2001
(Show Context)
Citation Context ...s performed in Isabelle/Isar. The theorem has 2sbeen completely formalized (in two versions), together with any required notions of functional analysis, using Isabelle/HOL set-theory as logical basis =-=[6, 5]-=-. This particular example shall serve as a basis for a general assessment of the requirements of large-scale formalized mathematics. Why does intelligible reasoning matter anyway? It is certainly fun ... |

4 |
Teaching people to write Proofs: a Tool
- Burstall
- 1998
(Show Context)
Citation Context ...alue [3], influencing the way that formal logic is perceived as an issue of practical relevance in general. The particular case of formal proof in education has been addressed many times before (e.g. =-=[8]-=-). We even raise the general philosophical principle that any important (or even critical) piece of formal code (proofs or programs) should be in itself open for human understanding. Informal explanat... |

4 | Hahn-Banach theorem
- Nowak, Trybulec
- 1993
(Show Context)
Citation Context ... basic notions. The subsequent numbers give a rough comparison of three Hahn-Banach proofs, where Heuser’s is with pen-and-paper. basic notions special lemmas main proof Heuser [16] ? – 3 pages Mi=-=zar [22]-=- ? 25 pages 8 pages Isar [6] 35 pages 16 pages 5 pages While the Mizar proof differs from ours in many details, both have a similar level of abstraction. Also note that the Mizar version refers to a l... |

3 | Mathematical vernacular in type theory-based proof assistants
- Callaghan, Luo
- 1998
(Show Context)
Citation Context ... grammatical framework based on type theory to support multi-lingual formal documents [17]. These efforts would ultimately result in a complete mathematical vernacular based on natural language (e.g. =-=[9]).-=- Mizar [26, 29, 19, 35] has pioneered a rather different approach, by providing a higher-level proof language as its input format in the first place — avoiding the kind of machine-oriented transform... |

3 |
Funktionalanalysis: Theorie und Anwendung
- Heuser
- 1986
(Show Context)
Citation Context ...user interface support only. Together with the existing Proof General interface [1], we already obtain a reasonable working environment for actual applications. We have chosen the Hahn-Banach Theorem =-=[16, 20]-=- as a realistic case study of computer-assisted mathematics performed in Isabelle/Isar. The theorem has 2sbeen completely formalized (in two versions), together with any required notions of functional... |

3 |
Mizar: An impression. Unpublished paper
- Wiedijk
- 1999
(Show Context)
Citation Context |

2 |
Lesbare Formale Beweise in Isabelle/Isar — Der Satz von Hahn-Banach
- Bauer
- 1999
(Show Context)
Citation Context ...s performed in Isabelle/Isar. The theorem has 2sbeen completely formalized (in two versions), together with any required notions of functional analysis, using Isabelle/HOL set-theory as logical basis =-=[6, 5]-=-. This particular example shall serve as a basis for a general assessment of the requirements of large-scale formalized mathematics. Why does intelligible reasoning matter anyway? It is certainly fun ... |

2 | The type theory and type checker of GF - Mienpii, Ranta - 1999 |

1 |
Using Axiomatic Type Classes in Isabelle, 2000. Part of the Isabelle documentation, http://isabelle.in.tum.de/doc/axclass.pdf
- Wenzel
(Show Context)
Citation Context ...duce constant declarations with Isabelle-style mixfix annotations for concrete syntax. The structure of general groups over some carrier type is defined by employing Isabelle’s Axiomatic Type Classe=-=s [30, 34]-=-, which provide a useful mechanism for abstract algebraic concepts. Finally we establish the two basic consequences of the group axioms as formally proven theorems. theory Group = HOL: consts prod :: ... |