stochastic‑latent‑bounds

Sound stochastic Lyapunov certificates for high‑dimensional physical systems, via invertible latent transports

View My GitHub Profile

Overview
Results
   Tightness (exp3)
   Scaling (exp1)
   Hot‑swap gate (exp2)
   Effort ladder (exp1b)
   C‑MAPSS fleet (exp4)
   Air quality (exp5)
   Grid physics (exp6)
   Transport baselines (exp7)
   Transport baselines (exp7)
   Nonlinear separation test (exp9)
   Supremacy at D=200 (exp10)
   Reactor scale, D=176 (exp11)
   Vortex street, fluid domain (exp12)
   Robot arm, real trajectories (exp13)
   Rigor: CIs, ablations (exp8)
Paper
Mathematics
API

1. Tightness of the Ito bound (exp3)

N-link arm (n_links=4, latent factor d=2). Noise floor β = 0.00680, tolerance tol = 0.05, so the certificate constant is β+tol = 0.05680 and the guaranteed noise-ball radius is (β+tol)/α = 0.2840.

box half‑width wtight upperC-S uppertight − βC-S − βtight certifies (≤β+tol)C-S certifies (≤β+tol)
0.0010.00690.22760.00010.2208yesno
0.0030.00750.22850.00070.2217yesno
0.010.01500.23700.00820.2302yesno
0.030.08250.30770.07560.3009nono
0.10.93241.17220.92561.1654nono
0.311.404211.706711.397411.6999nono
Bound excess over the noise floor versus box half-width (log-log). The Cauchy‑Schwarz bound's excess is bounded away from zero; the tight interval trace vanishes as the box shrinks.
Bound excess over the noise floor versus box half-width (log-log). The Cauchy‑Schwarz bound's excess is bounded away from zero; the tight interval trace vanishes as the box shrinks.

2. Certified volume vs dimension (exp1)

Dd (η)βfactor cert. frac.full cert. frac.nodes fac/fullseconds fac/fullworld‑model rel. errλₖmetric ok
820.00010.6490.0004030 / 4030883 / 1360.20820.721yes
1230.00020.0000.0004030 / 4030898 / 1120.17720.626yes
1640.00030.0000.0001982 / 4030910 / 2310.23260.571yes
2040.00080.0000.0001278 / 4030932 / 3700.33021.270yes
Certified fraction of the region under the same node and time budget. Factor mode searches only the d-dimensional η-box; full mode searches all D coordinates.
Certified fraction of the region under the same node and time budget. Factor mode searches only the d-dimensional η-box; full mode searches all D coordinates.
certificate: L W + α W ≤ β + tol  (α=0.05, κ=1.0, σ=0.05, tol=0.05)

3. Gated online hot‑swap (exp2)

gateacceptedrejectedunsafe swapsunsafe fractionfallback roundsseconds
sound0800.00021506
naive8081.000049
Probe violation fraction over the stream. The plant's damping halves halfway through; the sound gate swaps only what the interval bound certifies, the naive gate swaps everything.
Probe violation fraction over the stream. The plant's damping halves halfway through; the sound gate swaps only what the interval bound certifies, the naive gate swaps everything.

4. Effort ladder: budget needed to reach equal quality (exp1b)

Node budget is doubled per rung and both modes re-certified at every rung, so the comparison stays equal-effort. The stop rule is factor mode reaching the target fraction (or the budget cap); the ladder itself is the claim: the effort factor mode needs is set by the latent dimension d, while full mode does not finish at any affordable budget once D grows.

armnode budgetfactor cert. frac.full cert. frac.
arm4_d2 (D=8, d=2)40300.6490.000
arm4_d2 (D=8, d=2)80600.6490.000
arm4_d2 (D=8, d=2)161200.6490.000
arm4_d2 (D=8, d=2)322400.6490.000
arm6_d3 (D=12, d=3)40300.0000.000
arm6_d3 (D=12, d=3)80600.0160.000
arm6_d3 (D=12, d=3)161200.2660.000
arm6_d3 (D=12, d=3)322400.5910.000
arm8_d4 (D=16, d=4)40300.0000.000
arm8_d4 (D=16, d=4)80600.0000.000
arm8_d4 (D=16, d=4)161200.0000.000
arm8_d4 (D=16, d=4)322400.0000.000
arm10_d4 (D=20, d=4)40300.0000.000
arm10_d4 (D=20, d=4)80600.0000.000

5. Real fleet data: NASA C-MAPSS aging drift (exp4)

The plants are linear-Gaussian (Ornstein‑Uhlenbeck) models identified from the NASA C-MAPSS FD001 fleet (Kaggle behrad3d/nasa-cmaps): 5 variable sensor channels per engine cycle, healthy era = first half of each engine's life, aged era = second half. The identified aging shift is real: attractor moves 2.82 sd, ||ΔA|| = 0.40. Transport + latent world model trained on the healthy identified plant (world-model fit vs exact push-forward: 11.91).

quantityvalue
noise floor β (identified diffusion)4.90e-02
factor cert. frac. (d=2 of D=5)0.000
full cert. frac. (all D)0.000
era probe: viol. frac. healthy0.086
era probe: viol. frac. aged0.156
shadow gate: unsafe swaps (sound / naive)0 / 8
Certificate-violation fraction under each identified fleet era. The aging drift moves the plant out of the certified envelope; the gate exists to catch exactly this.
Certificate-violation fraction under each identified fleet era. The aging drift moves the plant out of the certified envelope; the gate exists to catch exactly this.

6. Real environmental data: Beijing air‑quality drift (exp5)

A second physical domain: an Ornstein‑Uhlenbeck plant identified from hourly multi‑pollutant records at Aotizhongxin (Beijing PRSA; 10 channels, hourly 2013–2017). The drift event is the real seasonal regime shift: heating season (Nov‑Mar, municipal schedule) vs the rest of the year. Identified shift: attractor moves 3.85 sd, ||ΔA|| = 0.48. Same pipeline as exp4, zero domain‑specific code.

quantityvalue
noise floor β (identified diffusion)3.86e-01
factor cert. frac. (d=2 of D=10)0.000
full cert. frac. (all D)0.000
era probe: viol. frac. non‑heating0.270
era probe: viol. frac. heating0.303
shadow gate: unsafe swaps (sound / naive)0 / 8
Certificate-violation fraction under the two seasonal regimes of the identified air‑quality plant. The heating‑season shift is the drift event the hot‑swap gate is designed for.
Certificate-violation fraction under the two seasonal regimes of the identified air‑quality plant. The heating‑season shift is the drift event the hot‑swap gate is designed for.

7. Real grid physics: ETTm2 transformer load regimes (exp6)

A third physical domain — electricity‑grid physics: the ETTm2 benchmark (transformer oil temperature OT + 6 load channels, 15‑min sampling, two years). The drift event is the real daily load regime: high‑load era (08–20h) vs low‑load era (21–07h). Identified shift: attractor moves 1.08 sd, ||ΔA|| = 0.06. Same pipeline as exp4/exp5, again zero domain‑specific code beyond the CSV loader.

quantityvalue
noise floor β (identified diffusion)1.26e+00
factor cert. frac. (d=2 of D=7)0.000
full cert. frac. (all D)0.000
era probe: viol. frac. high‑load0.627
era probe: viol. frac. low‑load0.637
shadow gate: unsafe swaps (sound / naive)0 / 8

Honest reading. At native 15‑minute sampling the ETTm2 plant is noise‑dominated: the identified per‑cycle diffusion puts the noise floor at β ≈ 1.3, the certified practical‑stability ball covers most of the claimed region, and the sound verifier certifies 0% of it at this budget. We report this negative result with its mechanism rather than tuning it away: the pointwise certificate closes on 37% of probes, the violation fraction still separates the real load regimes, and the hot‑swap gate remains exactly sound under the genuine regime shift — 0 unsafe swaps vs 8/8 unsafe for the naive gate. Certificate training on raw per‑step differences fits noise in this regime (the two‑stage push‑forward refit, math.md §11, is the fix for the model; the region stays bounded by the plant’s own noise‑to‑drift ratio).

Certificate‑violation fraction under the two real load regimes of the identified transformer plant. The daily regime cycle is a recurrent, predictable drift event.
Certificate‑violation fraction under the two real load regimes of the identified transformer plant. The daily regime cycle is a recurrent, predictable drift event.

8. Transport baselines: does the learned map matter? (exp7)

The claim under test: the certificate works because the transport is learned, not because any low‑dimensional projection would do. Three coordinate maps — a fixed PCA map, a fixed random orthogonal map, and the learned invertible transport — through the identical downstream protocol (same latent‑dynamics training budget, fixed quadratic certificate, region construction, node budget, and probe seeds). The fixed maps use exact linear interval arithmetic, so the comparison is not skewed by enclosure looseness.

domaintransportfactor cert. frac.full cert. frac.
C‑MAPSS (D=8)PCA1.0000.000
C‑MAPSS (D=8)Random1.0000.000
C‑MAPSS (D=8)Learned0.0000.000
Air quality (D=10)PCA0.0000.000
Air quality (D=10)Random0.0000.000
Air quality (D=10)Learned0.0000.000
ETTm2 (D=7)PCA0.0000.000
ETTm2 (D=7)Random0.0000.000
ETTm2 (D=7)Learned0.0000.000

What the table actually shows — and why we report it. On the real‑data domains the identified plants are linear‑Gaussian (Ornstein‑Uhlenbeck) models, and for a linear plant any orthogonal coordinate map supports the same factorised certificate: PCA and random projections certify the region too (pointwise violations 0.000 on the fleet domain). This is an honest scope statement, not a defeat: the certificate machinery needs a factorisation, and linear plants factor trivially. The learned transport’s claim is about nonlinear plants, where the map must undo the dynamics’ own curvature — exp9 (below) runs the identical comparison on the nonlinear N‑link arm.

Factor certified fraction for fixed PCA / random‑projection maps vs the learned invertible transport, identical protocol on all three real domains. A learned column of — means the domain's full‑run JSON had not landed at generation time.
Factor certified fraction for fixed PCA / random‑projection maps vs the learned invertible transport, identical protocol on all three real domains. A learned column of — means the domain's full‑run JSON had not landed at generation time.

9. The nonlinear test: learned transport vs fixed maps (exp9)

The decisive separation. On the nonlinear 4‑link arm (D=8, d=2) the coordinate map must actively undo the dynamics’ sin/cos curvature — no orthogonal map can. Same protocol, budgets and seeds as section 8. The learned transport certifies 64.9% of the region factor‑mode; PCA certifies 2.0% and a random orthogonal map 0.0%. The certified upper bound at the worst point is ~55× tighter for the learned map than PCA and ~245× tighter than random — the gap is in the bound quality, not just the fraction: the learned coordinates align the region with the contracting directions the certificate exploits.

mapfactor certified frac.pointwise viol.noise floor βworst certified upper
PCA0.0200.3120.00511.440
Random projection0.0000.5980.00249.258
Learned invertible transport (ours)0.6490.4797.58e-050.205
Factor certified fraction on the nonlinear N‑link plant: fixed linear maps vs the learned invertible transport, identical protocol (exp9).
Factor certified fraction on the nonlinear N‑link plant: fixed linear maps vs the learned invertible transport, identical protocol (exp9).

Together with section 8 this closes the argument: on linear‑Gaussian identified plants any orthogonal map suffices (the machinery, not the map, is the contribution there); on genuinely nonlinear plants the learned diffeomorphic transport is what makes the region certifiable at all.

10. Computational supremacy at D=200 (exp10)

The curse-of-dimensionality headline. A 100‑link planar arm has 200 state coordinates. The identical protocol — same transport family, same interval bound, same branch‑and‑bound — certifies a d‑2 factorisation of it, while the full‑dimensional verifier makes no progress at the same budget. The sweep across D = 40, 100, 200 turns the headline into the law: certified volume tracks the latent dimension d, not the state dimension D (Theorem 4 of the math supplement).

systemfactor certifiedfull certifiedfactor nodesfull nodesfactor seconds
arm10 (D=20, d=2)0.0000.0006225459.1

11. Chemical-reactor scale: CSTR sensor array, D=176 (exp11)

results/exp11_cstr.json not present.

12. Grand-challenge fluid domain: Kármán vortex street (exp12)

Karman vortex street: steady configuration, stochastic dotted cloud, drift-speed distributions

results/exp12_fluid.json pending on the compute box (chain: exp10 → exp12 → exp11 → 5-seed exp9); this section fills in when the run lands.

13. Robotics: SARCOS 7-DoF arm, real trajectories (exp13)

results/exp13_robotics.json pending (queued behind the exp10/12/11 chain on the compute box).

14. Statistical rigor: identification stability, CIs, ablations (exp8)

Identification stability. Fit/holdout parameter agreement on independent data halves: relative ||ΔA|| and ||Δσ|| between half‑fits. On C‑MAPSS and air quality the measured era‑drift signals (||ΔA|| ≈ 0.40–0.48) clear these floors by an order of magnitude, so the reported drift is signal, not identification noise. On ETTm2 the identification itself is era‑dependent (rel ||ΔA|| ≈ 6 across the timeline split), consistent with the noise‑dominated verdict of section 6 — reported as a finding, not hidden.

domainsplitrel ||ΔA||rel ||Δσ||
C‑MAPSSodd vs even engines0.0210.010rel ||db|| = 1.490
ETTm2first vs last 40% of timeline6.0150.115
Air qualityfirst vs last 40% of timeline0.4630.227

Bootstrap CIs. Percentile intervals (2000 resamples) for the pointwise certificate‑violation fraction over 2048 fixed region probes under the real plant.

domainviol. frac.95% CIprobesresamples
C‑MAPSS0.078[0.067, 0.090]20482000
Air quality0.417[0.395, 0.439]20482000
ETTm20.616[0.596, 0.638]20482000
Sensitivity of the pointwise certificate to the evaluation‑points parameter κ, diffusion scaling, and region scaling, on the C‑MAPSS checkpoint.
Sensitivity of the pointwise certificate to the evaluation‑points parameter κ, diffusion scaling, and region scaling, on the C‑MAPSS checkpoint.

Seed stability. Certificate re‑training from 3 seeds (fixed quadratic V; the learned latent dynamics varies): violation fraction 0.086 ± 0.000, noise floor β relative std 0.000.

How to reproduce