Skip to content

Solver Certificates and Independent Verification

A solver termination label describes an algorithmic run. A mathematical certificate is a separately checkable object whose equalities, cone conditions, signs, and relation to the physical problem have been established with exact arithmetic or rigorous enclosures. This page closes the four-stage worked example by verifying a saved rational separator and its one-dimensional CFT polynomial matrices, then states what additional work a finite-precision SDPB result would require.

Required background. Precision, Convergence, and Numerical Error Budgets fix the refinement and tolerance plan. Automated Crossing-System Generation fixes canonical input and sector order. Helpful background. Forms, adjoints, and isometries clarify adjoints under basis changes.

Evidence cutoff: 2026-08-23. Solver formats and implementations are mutable. Conformal-block software and bootstrap frameworks are surveyed in Rychkov and Su 2024, §§2.1–2.2, pp. 2–3. A production result must name and hash the precise version, build, input, and exported variables. The exact fixture below is stable mathematical data and does not validate any solver release.

Let KK be a closed convex cone and

K∗={s:⟨s,x⟩≥0 for every x∈K}K^*=\{s:\langle s,x\rangle\geq0 \text{ for every }x\in K\}

its dual cone. Use the primal problem

Ax=b,x∈K,minimize cTx,Ax=b, \qquad x\in K, \qquad \text{minimize }c^{\mathsf T}x,

and the dual problem

ATy+s=c,s∈K∗,maximize bTy.A^{\mathsf T}y+s=c, \qquad s\in K^*, \qquad \text{maximize }b^{\mathsf T}y.

Weak duality gives

cTx−bTy=⟨s,x⟩≥0.c^{\mathsf T}x-b^{\mathsf T}y =\langle s,x\rangle\geq0.

The difference is the duality gap. At a primal-dual pair, ⟨s,x⟩\langle s,x\rangle is also the complementarity measure. Because software packages may negate objectives or exchange labels, the exported convention must be translated back to these equations before the words “primal” and “dual” carry mathematical meaning.

For finite-precision candidates, report unscaled residuals such as

rp=∥Ax−b∥21+∥b∥2,rd=∥ATy+s−c∥21+∥c∥2.r_p= \frac{\lVert Ax-b\rVert_2}{1+\lVert b\rVert_2}, \qquad r_d= \frac{\lVert A^{\mathsf T}y+s-c\rVert_2} {1+\lVert c\rVert_2}.

A cone violation is the amount by which a nonnegativity condition or PSD eigenvalue bound crosses below zero. A small equality residual cannot compensate for a negative cone eigenvalue. Likewise, an interval enclosure for λmin⁡\lambda_{\min} that straddles zero is inconclusive; a certified PSD check requires a lower endpoint at or above zero.

For pure feasibility Ax=bAx=b, x∈Kx\in K, a Farkas certificate satisfies

ATy∈K∗,bTy=−1.A^{\mathsf T}y\in K^*, \qquad b^{\mathsf T}y=-1.

Any feasible xx would then obey

−1=bTy=⟨ATy,x⟩≥0,-1=b^{\mathsf T}y =\langle A^{\mathsf T}y,x\rangle\geq0,

which is impossible. This normalization makes the target sign exact. Conic duality and the polynomial-matrix specialization used by SDPB are derived in Simmons-Duffin 2015, §§2.1–2.3 and §2.5, pp. 4–15.

Candidate, reproducible witness, and rigorous certificate

Section titled “Candidate, reproducible witness, and rigorous certificate”

These evidence levels should not be merged:

  1. A solver point is the in-memory or exported variable set associated with a termination status.
  2. A reproducible approximate witness has canonical inputs, hashes, unscaled residuals, cone diagnostics, precision, and an independent numerical evaluation.
  3. A rigorous certificate proves the required equalities and signs, either by exact reconstruction or by outward-rounded enclosures together with an explicit repair or perturbation argument that absorbs residuals without crossing a cone boundary.

Merely observing rp<τr_p<\tau and λmin⁡>−τ\lambda_{\min}>-\tau does not prove exact feasibility. Near a boundary, the residual repair may require a correction larger than the available cone margin. Strict feasibility supplies room for such a proof; weak feasibility may be mathematically valid but numerically delicate.

Worked fixture, stage 4: verify the saved separator

Section titled “Worked fixture, stage 4: verify the saved separator”

For the finite control points x=0,1,2x=0,1,2, place the generators v(x)=(1,x,x2)v(x)=(1,x,x^2) in the columns of

A=(111012014),b=(110),y=(1−21).A= \begin{pmatrix} 1&1&1\\ 0&1&2\\ 0&1&4 \end{pmatrix}, \qquad b=\begin{pmatrix}1\\1\\0\end{pmatrix}, \qquad y=\begin{pmatrix}1\\-2\\1\end{pmatrix}.

Exact multiplication gives

ATy=(101)∈R+3,bTy=−1.A^{\mathsf T}y= \begin{pmatrix}1\\0\\1\end{pmatrix}\in\mathbb R_+^3, \qquad b^{\mathsf T}y=-1.

This is an exact Farkas certificate that bb is outside the finite nonnegative cone. The polynomial identity

yTv(x)=(x−1)2≥0(x≥0)y^{\mathsf T}v(x)=(x-1)^2\geq0 \qquad(x\geq0)

extends the separation to the full half-line cone, and its rank-one PSD Gram matrix closes the continuum check without sampling.

The same saved record also contains the normalized one-dimensional CFT functional

α^[f]=f′′′(1/2)−49f′(1/2)32\widehat\alpha[f] =\frac{f'''(1/2)-49f'(1/2)}{32}

and the exact KK and PP Gram matrices derived on the preceding page. The certificate JSON has SHA-256

25d2c0ba27675101f249645ac67e70a1db2725d01a89b188b097cdcd50fc0bc8

An independent Node verifier parses every integer or fraction into normalized BigInt numerator-denominator pairs. It reconstructs the feasible control, finite dual actions, target sign, functional normalization, KK and PP coefficients, Gram expansions, and exact PSD minors. It also rejects three injected defects: a wrong target sign, an indefinite Gram matrix, and a stale CFT polynomial coefficient. The saved verification record binds the result hash

237dfc99a5de97404c5cb2ab66b5c307ca2ade9bd259fcffdece61613c59a4b1

and can be reproduced from the repository root with

node scripts/verify-conformal-bootstrap-certificate.mjs

The exact output is:

QuantityIndependently reconstructed valueMeaning
Feasible-control residual(0,0,0)(0,0,0)parser and primal-sign control pass
Finite generator actions(1,0,1)(1,0,1)ATyA^{\mathsf T}y is in the dual cone
Excluded-target action−1-1strict target separation passes
Toy Gram principal minors1,1,01,1,0rank-one matrix is PSD
CFT identity action11derivative normalization passes
KK coefficients(133/8,8,1)(133/8,8,1)functional-to-polynomial map has zero residual
PP coefficients(11,133/3,64/3,8/3)(11,133/3,64/3,8/3)lower-envelope polynomial has zero residual
Injected defects3/33/3 rejectedsign, PSD, and stale-data checks fail closed

The program verifies the serialized rational algebra. The analytic proof that gΔ(1/2)>0g_\Delta(1/2)>0 and rΔ≥8Δ/3r_\Delta\geq8\Delta/3 is supplied on Linear Functionals and Positivity, not delegated to the JSON parser. Together, those two independent layers prove the declared Δϕ=1\Delta_\phi=1 gap exclusion. They do not test SDPB performance, generic rational-block error, spin truncation, or a phenomenological bound.

Independent evaluation of numerical output

Section titled “Independent evaluation of numerical output”

A production verifier should not import solver memory or reuse the same matrix-assembly routine. It reads the canonical physical specification, conic input, scaling map, candidate variables, and hashes, then:

  1. checks that physical, generated, solver-input, and certificate hashes identify one problem;
  2. parses numbers at higher precision than the serialized candidate and reconstructs unscaled A,b,cA,b,c;
  3. recomputes equality residuals, objective gap, complementarity, and certified lower bounds for cone eigenvalues;
  4. evaluates the bootstrap functional normalization and sector actions from independently generated blocks;
  5. covers every dimension interval and spin tail by exact polynomials, directed intervals, or proved asymptotics; and
  6. records the verifier version, arithmetic, rounding mode, commands, and output hash.

Interval arithmetic can enclose polynomial minima or matrix eigenvalues on compact intervals. Beyond a finite threshold, an analytic asymptotic estimate or rigorously enclosed recurrence must cover the tail. Dense sampling remains valuable as an adversarial diagnostic, but it never closes a continuum by itself.

Strict primal or dual feasibility with verified margins larger than every residual and enclosure width is robust. At a cone boundary, weak feasibility can be exact while arbitrarily small perturbations change the numerical classification. An “unknown,” stalled, or inconsistent primal-dual run supports no exclusion.

A certificate can also pass the finite conic equations while failing the physical lifting step. For example, the polynomial matrices may be PSD but derived from a block approximation whose error crosses the functional margin. The defensible output is then a verified statement about the finite surrogate, not about exact CFT crossing.

The diagram separates solver output, verification, failure, and the two passing claim ceilings. Inspect the final split: verified dual separation and verified primal feasibility are not interchangeable.

A serialized solver output reaches either a rejected result, a conditional dual exclusion, or finite-primal feasibility only after independent identity, residual, cone, normalization, interval, and tail checks.

Schematic solver-to-claim path. Independent reconstruction acts on the unscaled problem and fails closed when a hash, equality, cone or PSD condition, functional normalization, interval, or tail check fails. Passing dual variables support conditional exclusion under the declared physical approximation controls; passing primal variables establish only finite-conic feasibility, not existence of an exact CFT. The diagram is schematic and not to scale.

The same relationships in structured form are:

GateIndependently verified quantityPassing branchMaximum conclusionFailed or unresolved branch
Identityphysical, generated, input, and output hashesone canonical problemverification may continuewrong problem; reject
Equalitiesoutward-rounded or exact unscaled residualsequations hold or are rigorously repairablecandidate enters cone checksapproximate witness only
Conenonnegative weights or certified PSD lower boundscone membership passesprimal or dual type retainedinfeasible certificate; reject
Functionalidentity normalization and sector signsphysical pairing agreesbootstrap interpretation may continuefinite algebra only
Continuumevery interval and asymptotic tailglobal sign coveredverified finite bootstrap recordsampled result only
Output typedual separator or primal feasible pointdistinct branch labelsconditional exclusion or finite feasibilitynever infer CFT existence

Verifying scaled residuals only. Solver scaling can make an internal residual look small while the physical unscaled equation is poorly satisfied. Invert every scaling map first.

Treating tolerance as proof. A negative eigenvalue smaller than the stopping tolerance is still negative. Rigorous certification requires an exact sign, an outward enclosure, or a proved repair with margin.

Reusing the generator as the verifier. Two executions of the same erroneous block or matrix code share the central failure mode. Independence should cross the most consequential implementation boundary.

Recompute ATyA^{\mathsf T}y and bTyb^{\mathsf T}y for the exact fixture. Use the dual-cone pairing to prove that no x∈R+3x\in\mathbb R_+^3 can solve Ax=bAx=b.

Solution

The three column actions are 11, 00, and 11, so ATy∈R+3A^{\mathsf T}y\in\mathbb R_+^3. If Ax=bAx=b with x≥0x\geq0, then

−1=bTy=xTATy≥0,-1=b^{\mathsf T}y =x^{\mathsf T}A^{\mathsf T}y\geq0,

a contradiction.

Replace yy by yε=(1,−2,1−ε)y_\varepsilon=(1,-2,1-\varepsilon). Show that any ε>0\varepsilon>0 violates the cone condition at v(1)v(1). What may a high-precision run with a tiny positive ε\varepsilon honestly report?

Solution

yεTv(1)=1−2+1−ε=−ε<0y_\varepsilon^{\mathsf T}v(1)=1-2+1-\varepsilon=-\varepsilon<0. The candidate is not in the dual cone, regardless of how small the violation is. Without a rigorous repair that restores all signs while preserving target separation, the run may be reported only as a near-feasible numerical candidate, not as an exclusion certificate.

For release-aware open problems in certifying full numerical-bootstrap pipelines, continue to Numerical Bootstrap Certification. Verified finite statements can feed Single-Correlator Bounds or Numerical Boundary and Defect Bootstrap only with their additional physical assumptions.

  • Rychkov, Slava, and Ning Su. “New Developments in the Numerical Conformal Bootstrap.” Reviews of Modern Physics 96 (2024): 045004. DOI. Open PDF
  • Simmons-Duffin, David. “A Semidefinite Program Solver for the Conformal Bootstrap.” Journal of High Energy Physics 06 (2015): 174. DOI. Open PDF

Original QFT.org content:CC BY 4.0, unless an item supplies different terms. Third-party material retains its own terms.