{"id":"5ab20ee0-0f6a-4c95-87e2-7db6ab0119a9","arxiv_id":"2508.20204","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":1,"one_line_summary":"For stochastic difference inclusions with convex set-valued dynamics and a concave barrier, safety probabilities can be certified by checking the barrier condition at the mean disturbance.","lead":"This paper derives safety certificates for stochastic systems with adversarial, set-valued uncertainty by combining concave barrier functions with convex set-valued dynamics. The approach bounds the worst-case probability of reaching an unsafe set using a deterministic condition at the mean disturbance, which could simplify verification problems in robust control.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Example 37 (and 36) violate Assumption 21; Remark 24's equality substitution is false, so the paper's central expectation-substitution simplification is not supported as stated.","rationale":"The reader's weakest assumption—Assumption 21 and its violation by Example 37—is the same load-bearing issue I identify. The central theorem is conditional on convexity of G, and the paper's main claimed simplification is that one may replace random inputs by their expectations. That replacement is valid only as a Jensen inequality when λ_k is concave, but Remark 24 asserts an equality and Example 37 applies the substitution to a λ_1 that is not concave. My check confirms the numerical claim would produce a non-supermartingale. Example 36 also fails the convexity assumption, so the paper's numerical support is unreliable. However, I found no internal contradiction in Theorem 35 itself under Assumption 21; the proof may need minor clarifications (e.g., handling states with B>Δ), but the core argument appears mathematically plausible. Therefore the reader's conditional verdict remains appropriate: the paper should be revised to remove or correct the flawed examples and Remark 24, but the main theorem is not evidently false.","tokens_in":17222,"tokens_out":34942,"duration_ms":403959,"concrete_test":"Directly verify two claims in Example 37. (1) Compute E[λ_1(X,v)] for v∼U[-0.2,0.2]: λ_1(X,v)=tr(X)+2max(v,0), so E[λ_1]=tr(X)+0.1. Since B(X)=tr(X), this violates Definition 29. (2) Test convexity of gph G with X1=X2=I, v1=0.2, v2=-0.2, θ=1/2: show I+0.1(M(γ1)-M(γ2))∉G(I,0)={I} for γ1=1, γ2=0. If both hold, Example 37 is invalid and Remark 24's equality is false. As a secondary check, run the same convexity test on Example 36 with x1=(1,0), x2=(0,1), v=0, θ=1/2 to show the graph is not convex.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The paper's central simplification is Lemma 30: when G has convex graph and B is concave, λ_1(x,v)=sup_{x+∈G(x,v)}B(x+) is concave in v, so E[λ_1(x,v)] ≤ λ_1(x,E[v]) by Jensen. This is only an inequality. Remark 24 and Example 37 instead treat it as an equality, substituting E[v] into λ_j. In Example 37, G(X,v)={UXU^T+M(γ)v : γ∈[0,1]} with v∼U[-0.2,0.2]. This G is not a convex set-valued map: take X1=X2=I, v1=0.2, v2=-0.2, θ=1/2; then G(I,0)={I}, but 0.5G(I,0.2)+0.5G(I,-0.2) contains I+0.1(M(γ1)-M(γ2)), which is not I for γ1=1, γ2=0. Hence Lemma 22 does not apply. Indeed λ_1(X,v)=tr(X)+2max(v,0), which is convex, not concave, in v; direct computation gives E[λ_1]=tr(X)+0.1 > B(X)=tr(X), so B is not a supermartingale and Theorem 35 cannot be invoked. Example 36 has the same problem: G(x,v)={\\tilde A(γ)x+bv} has a non-convex graph. Thus the numerical validation and Remark 24 do not support the central claim as stated. The theorem itself may be correct under Assumption 21, but the claimed 'effective substitution' requires the Jensen inequality and a valid convex-G example; both are currently missing.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper studies safety of discrete-time stochastic difference inclusions of the form x^+ ∈ G(x,v), where v is stochastic and an adversary chooses the next state from the set G(x,v). It develops barrier-function conditions for bounding the probability of reaching an unsafe set. Under an upper semicontinuity/measurability assumption on G and, crucially, Assumption 21 that G is a convex set-valued map, the paper argues that for a concave barrier B one may replace the random input v by its expectation in the one-step condition and obtain a supermartingale barrier certificate. The main result, Theorem 35, bounds the reach probability by δ/Δ under the deterministic condition sup_{x^+∈G(x,E[v])} B(x^+) ≤ B(x). Numerical examples on linear and matrix-valued dynamics are presented as illustrations.","tokens_in":17650,"tokens_out":14772,"duration_ms":165874,"significance":"If the main theorem is correct, the paper offers a clean and useful sufficient condition: for concave barriers and convex-graph set-valued maps, checking the barrier condition at the expected disturbance suffices for a supermartingale certificate. The proof strategy is simple and mostly self-contained, relying on Jensen's inequality and standard supermartingale arguments. However, the paper overstates the result: the expectation substitution is an inequality, not an equality, and the paper's two main numerical examples do not satisfy Assumption 21 and therefore do not validate the machinery. The central theorem is plausible and likely fixable, but the current presentation and examples are not reliable as stated.","major_comments":[{"comment":"The equality E[sup_{k∈[1,N]} λ_k(x,v_0,...,v_{k-1})] = λ_j(x,E[v_0],...,E[v_{j-1}]) is false in general. Concavity of λ_j gives only the Jensen upper bound E[λ_j] ≤ λ_j(E[v_0],...,E[v_{j-1}]); equality holds only if λ_j is affine or the random variables are degenerate. This is not a cosmetic issue: the simplification used in Remark 24, in condition (32), and in Example 37 relies on the equality. The correct sufficient condition should be an inequality, e.g., λ_j(x,E[v_0],...,E[v_{j-1}]) ≤ ρΔ, not an equality.","section":"§4, Remark 24"},{"comment":"The map G(X,v)={UXU^T+M(γ)v | γ∈[0,1]} does not have a convex graph. Take X1=X2=I, v1=0.2, v2=-0.2, and θ=1/2. Then G(I,0)={I}, but (1/2)G(I,0.2)+(1/2)G(I,-0.2) contains I+0.1(M(γ1)-M(γ2)), which is not I for γ1=1, γ2=0. Hence Assumption 21 and Lemma 22 do not apply. In fact λ_1(X,v)=tr(X)+2max(v,0), which is convex in v, and for v∼U[-0.2,0.2] one has E[λ_1]=tr(X)+0.1>B(X), so B is not a supermartingale. Thus the claimed bound 1-δ/Δ and Figure 2 are not supported by Theorem 35; the true finite-horizon expectation is tr(X)+0.1N, not tr(X).","section":"§6, Example 37"},{"comment":"The assertion that the dynamics x^+∈{(γA1+(1-γ)A2)x+bv} are convex because they are linear in (x,v) is incorrect. A set-valued map that is affine in the parameter γ need not have a convex graph. For the matrices in the example, take C=A1-A2, x1=(1,0), x2=(0,1), v1=v2=1, γ1=1, γ2=0. Graph convexity would require some γ∈[0,1] with γ C(x1+x2)=γ1 C x1+γ2 C x2, but for the given C this equation has no solution. Therefore Assumption 21 is not verified, and the sufficient condition (29) at E[v] cannot be justified by Lemma 30. The numerical results in Section 6 therefore do not demonstrate the paper's main result.","section":"§6, Example 36"}],"minor_comments":[{"comment":"The statement says the probability is 'less than δ/Δ', but the proof yields the non-strict inequality ≤ δ/Δ. The statement should be 'less than or equal to δ/Δ', or the proof should be adjusted.","section":"§5, Theorem 35"},{"comment":"There is a typo: the second matrix is labeled 'A1 =' but the context indicates it should be A2. Please correct.","section":"§6, Example 36"},{"comment":"The conditional expectation notation E[Z_k | Z_j] is imprecise; the condition should be with respect to the filtration generated by the random inputs up to time j, not merely the single random variable Z_j. This is a clarity issue in an otherwise standard argument.","section":"§5, Lemma 33"},{"comment":"The augmented variable ζ=(v,v^2) has a non-convex support. If the argument relies on extending G and λ to the convex hull of the support, this extension and the domain of the Jensen inequality should be stated explicitly.","section":"§4, Example 27"},{"comment":"The definition uses a strict inequality '< ρ' while the derived bounds are non-strict. For consistency, either use '≤ ρ' in the definition or note that the strict version follows by taking ρ slightly larger.","section":"§2, Definition 14"}],"recommendation":"major_revision","confidential_remarks":"The central theorem under Assumption 21 appears sound and is the paper's main contribution, but the claimed 'effective substitution' is oversold as an equality and the two numerical examples violate Assumption 21. These are load-bearing issues for the paper's validation and framing, but they are fixable: replace the equality in Remark 24 with Jensen's inequality, and provide examples that actually satisfy the convex-graph assumption. If the authors cannot provide such examples, the paper's practical relevance would be substantially weakened."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"The core idea is genuinely useful: under a convexity assumption on the set-valued map and concavity of the barrier, Jensen's inequality lets you verify a one-step supermartingale condition at the mean of the noise instead of over the full distribution. That is a real simplification for a class of stochastic difference inclusions with adversarial selections. The paper is self-contained, the measurability lemmas are handled carefully with Rockafellar-Wets machinery, and the unbounded-horizon supermartingale extension is a natural contribution. No fitted parameters and no load-bearing reliance on the authors' earlier work.\n\nBut the current version has three soft spots I would not call minor. First, Remark 24 asserts an equality E[sup λ] = λ(E[v]); Jensen only gives an inequality. The paper's 'effective substitution' is therefore overstated. Second, the two worked examples do not satisfy Assumption 21. In Example 37, G(X,v)={UXU^T+M(γ)v} has a graph that is not convex (the stress-test counterexample is correct), and the resulting λ1(X,v)=tr(X)+2max(v,0) is convex in v, so the expectation is larger than B(X); the claimed supermartingale is false. Example 36 has the same structural problem. The numerical sections thus do not validate the theory. Third, the proof of Lemma 31 applies the induction hypothesis to intermediate states x+ that may lie in the unsafe set, where condition (25) is not assumed. A stopped-process argument would likely fix this, but the paper does not give one. Lemma 23 is also stated without a proof, and Theorem 35 says 'less than' while the proof yields '≤'.\n\nThe main theorem may well be correct under Assumption 21; the logic is plausible and the concavity+Jensen trick is worth pursuing. But the paper overreaches in its examples and in the equality claim. I would send it to peer review because the idea deserves referee time, but it needs major revision: fix the Jensen statement, provide a valid convex-graph example, and rewrite the induction with a proper stopping time. As it stands I wouldn't cite it.","headline":"A promising verification trick undermined by an overclaimed equality and examples that violate the paper's own convexity assumption; the main theorem may hold but needs repair.","tokens_in":18119,"tokens_out":8220,"would_cite":false,"duration_ms":91643,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["93E03","93C55"],"pacs":[],"model":"deepseek-v4-flash","headline":"Concave barriers plus convex set-valued dynamics give a delta/Delta safety bound by replacing random inputs with their mean.","keywords":["stochastic difference inclusions","barrier functions","safety verification","concave barrier","convex set-valued maps","supermartingale","probabilistic reachability","mean-field verification"],"falsifier":"Take the system of Example 37 with v uniformly distributed on [-0.2, 0.2] and B(X) = tr(X). Directly computing lambda_1(X, v) = tr(X) + 2 max(v, 0) shows it is convex in v, giving E[lambda_1(X, v)] = tr(X) + 0.1 > tr(X) = lambda_1(X, E[v]). Thus B satisfies the mean-input condition (25) but fails the true supermartingale inequality, contradicting Lemma 30 and Theorem 35 for this instance; simulating many trajectories and counting hits of the unsafe set would reveal whether the claimed delta/Delta = 0.25 bound actually holds or is violated.","tokens_in":1624,"feed_emoji":"🛡️","tokens_out":2079,"duration_ms":78256,"temperature":0.7,"pith_summary":"This paper studies discrete-time systems whose next state is chosen adversarially from a set G(x, v) that depends on the current state and a random input v. Its central claim is that when G has a convex graph and the barrier function B is concave, the difficult worst-case expectation over adversarial choices and random inputs can be replaced by a single check at the mean input: sup_{x+ in G(x, E[v])} B(x+) <= B(x). If B is at most delta on the initial set and at least Delta on the unsafe set, then the probability of ever reaching the unsafe set is at most delta/Delta, over any finite or infinite horizon. The value is that safety verification becomes a mean-field, convex-optimization problem rather than a dynamic game over distributions and adversarial picks.","feed_headline":"Replace noise by its mean: barrier bound delta/Delta for stochastic systems","feed_subtitle":"One convexity condition turns hard stochastic verification into a mean-field check.","key_machinery":"The load-bearing object is the pair (B, G): a concave, nonnegative, upper semicontinuous barrier function B together with a set-valued map G whose graph is convex. This combination guarantees that each worst-case barrier value lambda_k(x, v0, ..., v_{k-1}) = sup over G-compositions of B is concave in the random arguments. Concavity then allows Jensen's inequality to replace every random input v by its expectation E[v] in the supermartingale check, reducing the adversarial stochastic evolution to a deterministic mean-input system. The resulting condition sup_{x+ in G(x,E[v])} B(x+) <= B(x) is a convex verification problem and yields the closed-form probability bound delta/Delta.","core_discovery":"The paper establishes that, under Assumptions 4, 5, and 21 (upper semicontinuity, measurability, and convexity of the set-valued map's graph), a concave nonnegative barrier function B that satisfies the one-step mean-input condition sup_{x+ in G(x,E[v])} B(x+) <= B(x) on the safe set is automatically a supermartingale barrier. Consequently, if B <= delta on the initial set X0 and B >= Delta on the unsafe set Xu, the probability of reaching Xu from X0, regardless of adversarial choices and over any time horizon, is at most delta/Delta (Theorem 35). The key step is that concavity of B and convexity of G make the marginal value lambda_k concave in the random input, so Jensen's inequality permit","pith_inferences":["When the convexity assumption on G fails, the mean-substitution step can break: if lambda_1(x, v) is convex rather than concave in v, Jensen gives the reverse inequality, so a barrier can satisfy the mean-input check while failing the true supermartingale inequality.","A testable alternative to convex G is to verify concavity of lambda_k(x, v0, ..., v_{k-1}) in the random arguments directly; for systems with non-convex graphs but concave marginals, the same delta/Delta bound should still hold.","The delta/Delta bound is likely conservative; in practice, reach probabilities may be far smaller. A sharper bound might be obtained by tracking the actual distribution of the barrier process rather than only its expectation.","The mean-input reduction suggests a design principle for stochastic safety: to make a system safe, choose the set-valued dynamics so that its mean image contracts the level sets of a concave barrier, which is a convex-design problem."],"forward_implications":["Safety verification for a broad class of stochastic set-valued systems reduces to checking one convex condition at the mean disturbance, instead of solving a dynamic game or computing high-dimensional expectations.","The delta/Delta bound holds for infinite time horizons whenever the mean-input decrease condition holds, so a single local check certifies safety forever.","The framework naturally covers distributional robustness: families of distributions parameterized by a set can be encoded in G, and the mean-substitution result applies to every member of the family simultaneously.","For linear or affine dynamics, the supermartingale condition becomes a set of linear inequalities, making the certificate computable by standard convex optimization.","The result unifies the deterministic barrier-certificate bound with the stochastic setting: the deterministic bound delta/Delta appears as the special case with no random input."],"supporting_citations":[{"why":"Supplies the definition of convex set-valued maps and the graph-inclusion identity used in Definition 19 and Lemma 20.","marker":"[2]"},{"why":"Provides Proposition 2.9, which transfers upper semicontinuity to the marginal (worst-case) function in Lemma 20.","marker":"[10]"},{"why":"Gives the supermartingale definitions and the maximal inequality used in Theorem 35 and Remark 34.","marker":"[16]"},{"why":"Introduces barrier certificates for deterministic hybrid systems, the starting point for the barrier-function approach.","marker":"[19]"},{"why":"Extends barrier certificates to stochastic systems, establishing the stochastic barrier methodology this paper builds on.","marker":"[20]"},{"why":"Provides the measurability and outer-semicontinuity results (Theorems 14.13, 14.14, and related propositions) used in Lemmas 7, 11, and 41.","marker":"[22]"}],"fun_headline_variants":["Concave barrier turns stochastic safety into mean-field check","Stochastic safety bound: replace noise by its mean","Delta/Delta safety via convexity and concave barriers","Mean-field barrier condition bounds violation probability","Concavity simplifies stochastic barrier proofs"],"cache_read_input_tokens":19712,"weakest_assumption_plain":"The whole simplification depends on the set-valued map G having a convex graph; if that convexity fails, the worst-case barrier value is not guaranteed to be concave in the random input, so replacing the input by its mean is not justified and the supermartingale argument collapses.","fun_headline_variants_meta":{"raw":{"variants":["Concave barrier turns stochastic safety into mean-field check","Stochastic safety bound: replace noise by its mean","Delta/Delta safety via convexity and concave barriers","Mean-field barrier condition bounds violation probability","Concavity simplifies stochastic barrier proofs"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000213,"raw_usage":{"total_tokens":1244,"prompt_tokens":716,"completion_tokens":528,"prompt_tokens_details":{"cached_tokens":256},"prompt_cache_hit_tokens":256,"prompt_cache_miss_tokens":460,"completion_tokens_details":{"reasoning_tokens":458}},"tokens_in":460,"tokens_out":528,"duration_ms":6407,"temperature":1.0,"reasoning_tokens":458,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-05T15:15:44.438225+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Take the system of Example 37 with v uniformly distributed on [-0.2, 0.2] and B(X) = tr(X). Directly computing lambda_1(X, v) = tr(X) + 2 max(v, 0) shows it is convex in v, giving E[lambda_1(X, v)] = tr(X) + 0.1 > tr(X) = lambda_1(X, E[v]). Thus B satisfies the mean-input condition (25) but fails the true supermartingale inequality, contradicting Lemma 30 and Theorem 35 for this instance; simulating many trajectories and counting hits of the unsafe set would reveal whether the claimed delta/Delta = 0.25 bound actually holds or is violated.","supporting_citations":[{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Supplies the definition of convex set-valued maps and the graph-inclusion identity used in Definition 19 and Lemma 20."},{"cited_title":"Robust nonlinear control design: state-space and Lyapunov techniques","cited_arxiv_id":null,"evidence_quote":"Provides Proposition 2.9, which transfers upper semicontinuity to the marginal (worst-case) function in Lemma 20."},{"cited_title":"Stochastic differential equations: an introduction with applications","cited_arxiv_id":null,"evidence_quote":"Gives the supermartingale definitions and the maximal inequality used in Theorem 35 and Remark 34."},{"cited_title":"Prajna and A","cited_arxiv_id":null,"evidence_quote":"Introduces barrier certificates for deterministic hybrid systems, the starting point for the barrier-function approach."},{"cited_title":"Stochastic safety verification using barrier certificates","cited_arxiv_id":null,"evidence_quote":"Extends barrier certificates to stochastic systems, establishing the stochastic barrier methodology this paper builds on."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Provides the measurability and outer-semicontinuity results (Theorems 14.13, 14.14, and related propositions) used in Lemmas 7, 11, and 41."}],"review_version":1}