Formal Software Verification

1.4. Logical Equivalence🔗

A valuation assigns a truth value to each propositional variable. A proposition is a tautology when it is true under every valuation. Two propositions A and B are logically equivalent, written A ≡ B, when they have the same truth value under every valuation, that is, when A ↔ B is a tautology.

The classical equivalences of Table 1.4.1 appear constantly in proofs.

Name

Equivalence

De Morgan

¬(P ∧ Q) ≡ ¬P ∨ ¬Q

De Morgan

¬(P ∨ Q) ≡ ¬P ∧ ¬Q

Double negation

¬¬P ≡ P

Contrapositive

P → Q ≡ ¬Q → ¬P

Material implication

P → Q ≡ ¬P ∨ Q

Table 1.4.1. The classical equivalences.

A truth table verifies each equivalence. For the second De Morgan law, the columns for ¬(P ∨ Q) and ¬P ∧ ¬Q agree on all four valuations, as Table 1.4.2 shows.

P

Q

P ∨ Q

¬(P ∨ Q)

¬P

¬Q

¬P ∧ ¬Q

T

T

T

F

F

F

F

T

F

T

F

F

T

F

F

T

T

F

T

F

F

F

F

F

T

T

T

T

Table 1.4.2. Truth table for the second De Morgan law.

1.4.1. Examples🔗

Each equivalence below is verified by a truth table. Two propositions are equivalent when their final columns agree in every row, and a tautology has a column that is true in every row.

Example 1. Double negation returns the original proposition, verified in Table 1.4.3.

P

¬P

¬¬P

T

F

T

F

T

F

Table 1.4.3. Truth table for ¬¬P ≡ P.

Example 2. The excluded middle P ∨ ¬P is a tautology, verified in Table 1.4.4.

P

¬P

P ∨ ¬P

T

F

T

F

T

T

Table 1.4.4. Truth table for P ∨ ¬P.

Example 3. Non-contradiction ¬(P ∧ ¬P) is a tautology, verified in Table 1.4.5.

P

¬P

P ∧ ¬P

¬(P ∧ ¬P)

T

F

F

T

F

T

F

T

Table 1.4.5. Truth table for ¬(P ∧ ¬P).

Example 4. The first De Morgan law, verified in Table 1.4.6.

P

Q

P ∧ Q

¬(P ∧ Q)

¬P

¬Q

¬P ∨ ¬Q

T

T

T

F

F

F

F

T

F

F

T

F

T

T

F

T

F

T

T

F

T

F

F

F

T

T

T

T

Table 1.4.6. Truth table for ¬(P ∧ Q) ≡ ¬P ∨ ¬Q.

Example 5. Disjunction commutes, verified in Table 1.4.7.

P

Q

P ∨ Q

Q ∨ P

T

T

T

T

T

F

T

T

F

T

T

T

F

F

F

F

Table 1.4.7. Truth table for P ∨ Q ≡ Q ∨ P.

Example 6. Disjunction is idempotent, verified in Table 1.4.8.

P

P ∨ P

T

T

F

F

Table 1.4.8. Truth table for P ∨ P ≡ P.

Example 7. The contrapositive, verified in Table 1.4.9.

P

Q

P → Q

¬Q

¬P

¬Q → ¬P

T

T

T

F

F

T

T

F

F

T

F

F

F

T

T

F

T

T

F

F

T

T

T

T

Table 1.4.9. Truth table for P → Q ≡ ¬Q → ¬P.

Example 8. Material implication, verified in Table 1.4.10.

P

Q

P → Q

¬P

¬P ∨ Q

T

T

T

F

T

T

F

F

F

F

F

T

T

T

T

F

F

T

T

T

Table 1.4.10. Truth table for P → Q ≡ ¬P ∨ Q.

Example 9. The biconditional is the conjunction of its two implications, verified in Table 1.4.11.

P

Q

P ↔ Q

P → Q

Q → P

(P → Q) ∧ (Q → P)

T

T

T

T

T

T

T

F

F

F

T

F

F

T

F

T

F

F

F

F

T

T

T

T

Table 1.4.11. Truth table for P ↔ Q ≡ (P → Q) ∧ (Q → P).

Example 10. The negation of an implication, verified in Table 1.4.12.

P

Q

P → Q

¬(P → Q)

¬Q

P ∧ ¬Q

T

T

T

F

F

F

T

F

F

T

T

T

F

T

T

F

F

F

F

F

T

F

T

F

Table 1.4.12. Truth table for ¬(P → Q) ≡ P ∧ ¬Q.

1.4.2. Logical Calculi🔗

Truth tables decide any propositional question, but their size grows exponentially in the number of variables, and they do not extend to the quantifiers of Lecture 2. A calculus answers the same questions by derivation rather than by computation.

A calculus fixes a set of axioms, which are propositions taken as given, and a set of inference rules, each of which produces a proposition from propositions already derived. A derivation is a finite sequence of rule applications, and a proposition that ends a derivation is a theorem of the calculus. Valuations play no part in this. A derivation rewrites symbols according to the rules alone, and that is what lets a machine check it.

Two properties tie a calculus to the semantics of the previous sections. A calculus is sound when every theorem is a tautology, and complete when every tautology is a theorem. Post proved both for the propositional calculus in 1921, in the paper that also introduced the truth-table method.E. L. Post, Introduction to a General Theory of Elementary Propositions, American Journal of Mathematics 43, 1921, pp. 163–185.

Propositional logic admits several calculi, and they differ in the shape of their rules rather than in the theorems they prove.

An axiomatic calculus, in the style of Hilbert and Ackermann,D. Hilbert and W. Ackermann, Grundzüge der theoretischen Logik, Julius Springer, Berlin, 1928. takes many axioms and one rule. The system of Łukasiewicz and Tarski needs three axiom schemes over → and ¬, with modus ponens as its only rule.J. Łukasiewicz and A. Tarski, Untersuchungen über den Aussagenkalkül, Comptes Rendus des Séances de la Société des Sciences et des Lettres de Varsovie, Classe III, 23, 1930, pp. 30–50.

  A → (B → A)
  (A → (B → C)) → ((A → B) → (A → C))
  (¬A → ¬B) → (B → A)

Each scheme stands for every proposition of its shape, so P → (Q → P) and (P ∧ Q) → (R → (P ∧ Q)) are both instances of the first. Deriving a theorem as simple as P → P takes five steps here, and finding the steps is an art.

Resolution goes to the other extreme, with one rule on propositions written as clauses, which is what machine provers search with.J. A. Robinson, A Machine-Oriented Logic Based on the Resolution Principle, Journal of the ACM 12(1), 1965, pp. 23–41.

Natural deduction sits between the two. It has no axioms and two rules for each connective, one that introduces the connective and one that eliminates it, and its derivations may rest on assumptions that a later rule discharges. Gentzen designed it to follow the steps a mathematician actually takes.G. Gentzen, Untersuchungen über das logische Schließen. I, Mathematische Zeitschrift 39, 1935, pp. 176–210. The sequent calculus, from the same paper, carries the assumptions explicitly to the left of a turnstile ⊢ and serves proof-theoretic arguments.

1.4.3. The Calculus of This Course🔗

This course uses natural deduction. Its introduction and elimination rules are the ones Lean's tactics implement, and a Lean proof term corresponds to one of its derivations. The next section presents the rules, and the rest of the lecture develops the corresponding proofs in Lean.