• Tidak ada hasil yang ditemukan

Chapter V: Reactive Contracts

5.6 Conclusion

strategy that guarantees it (lines 9βˆ’10); otherwise it will throw an error saying that such a robust strategy does not exist (line 12).

In the 3 island example, if we start out at an initial configuration where at least one robot is not on the home island, 𝑔min is anything, and 𝐹 = {button1}, then algorithm 2 will return a robust strategy with 𝛾0 =G0(all guarantees) which never allows both robots to be on the β€œhome” island at the same time (because ifbutton1 fails, then the robots will not be able to leave the home island). In particular, if 𝑔min ={♦box_r2_far}, then𝛼invwill be equal tor1_far∨r1_near∨r2_far∨ r2_near.

Chen, Yuxiao, Sumanth Dathathri, Tung Phan-Minh, and Richard M. Murray (2020).

β€œCounter-example Guided Learning of Bounds on Environment Behavior.” In:

Conference on Robot Learning, pp. 898–909. url:http://proceedings.mlr.

press/v100/chen20b.html.

Clarke Jr., Edmund M., Orna Grumberg, Daniel Kroening, Doron Peled, and Helmut Veith (2018).Model checking. MIT press.

Dathathri, Sumanth, Scott C. Livingston, and Richard M. Murray (2017). β€œEnhanc- ing tolerance to unexpected jumps in GR(1) games.” In: Proceedings of the 8th International Conference on Cyber-Physical Systems, ICCPS 2017, Pittsburgh, Pennsylvania, USA, April 18-20, 2017. Ed. by Sonia MartΓ­nez, Eduardo Tovar, Chris Gill, and Bruno Sinopoli. ACM, pp. 37–47. doi: 10 . 1145 / 3055004 . 3055014. url:https://doi.org/10.1145/3055004.3055014.

Denecke, Klaus, Marcel ErnΓ©, and Shelly L. Wismath (2013).Galois connections and applications. Vol. 565. Springer Science & Business Media.

Ehlers, RΓΌdiger and Vasumathi Raman (2016). β€œSlugs: Extensible gr (1) synthesis.”

In:International Conference on Computer Aided Verification. Springer, pp. 333–

339.

Henzinger, Thomas A., Peter W. Kopke, Anuj Puri, and Pravin Varaiya (1998).

β€œWhat’s decidable about hybrid automata?” In:Journal of computer and system sciences57.1, pp. 94–124.

Kim, Eric S., Murat Arcak, and Sanjit A. Seshia (2017). β€œA Small Gain Theorem for Parametric Assume-Guarantee Contracts.” In:Proceedings of the 20th Inter- national Conference on Hybrid Systems: Computation and Control. HSCC ’17.

Pittsburgh, Pennsylvania, USA: ACM, pp. 207–216. isbn: 978-1-4503-4590-3.

doi: 10.1145/3049797.3049805. url: http://doi.acm.org/10.1145/

3049797.3049805.

Kim, Eric S., Sadra Sadraddini, Calin Belta, Murat Arcak, and Sanjit A. Seshia (2017). β€œDynamic contracts for distributed temporal logic control of traffic net- works.” In:2017 IEEE 56th Annual Conference on Decision and Control (CDC).

IEEE, pp. 3640–3645.

Livingston, Scott C., Pavithra Prabhakar, Alex B. Jose, and Richard M. Murray (May 2013). β€œPatching task-level robot controllers based on a local πœ‡-calculus formula.” In:2013 IEEE International Conference on Robotics and Automation, pp. 4588–4595. doi:10.1109/ICRA.2013.6631229.

Majumdar, Rupak, Nir Piterman, and Anne-Kathrin Schmuck (2019). β€œEnvironmentally- friendly GR(1) Synthesis.” In:arXiv preprint arXiv:1902.05629.

Maoz, Shahar and Jan Oliver Ringert (2015). β€œGR (1) synthesis for LTL specification patterns.” In: Proceedings of the 2015 10th Joint Meeting on Foundations of Software Engineering. ACM, pp. 96–106.

Outrata, Jan and Vilem Vychodil (2012). β€œFast algorithm for computing fixpoints of Galois connections induced by object-attribute relational data.” In: Information Sciences185.1, pp. 114–127.

Phan-Minh, Tung (2019a).Reactive Contracts.https://github.com/tungminhphan/

reactive_contracts, accessed April 30 2019.

– (2019b). TLA+ specifications for an Automated Valet Parking Garage. https:

/ / github . com / tungminhphan / reactive _ contracts / blob / master / scenarios/AutomatedValetParking.tla, accessed May 2 2019.

Piterman, Nir, Amir Pnueli, and Yaniv Sa’ar (2006). β€œSynthesis of reactive (1) de- signs.” In:International Workshop on Verification, Model Checking, and Abstract Interpretation. Springer, pp. 364–380.

C h a p t e r 6

ASSUME-GUARANTEE PROFILES 1

6.1 Introduction

Autonomous vehicles will certainly have to function alongside humansβ€”that is, unless or until a fully-automated transportation infrastructure can be built. The interaction between self-driving cars and humans will inevitably result in unforeseen safety and legality situations. Self-driving car manufacturers are expected to be responsible for ensuring that the behavior of their cars minimizes the risk of collision.

However, the current rules are often designed heuristically on a case by case basis, lacking transparency, predictability, and performance (Paden et al., 2016; Shalev- Shwartz, Shammah, and Shashua, 2017).

If self-driving cars were to agree to restrict their state space to a region defined by some behavioral contract, there would be less uncertainty in behavior prediction, thereby making it significantly easier to choose mutually beneficial and safe actions.

The process of identifying the party responsible for an accident would also be simplified. Furthermore, car manufacturers could even begin to optimize their car behavior to refine and customize driving preferences.

Formal methods offer many tools and frameworks for designing and proving speci- fications that guarantee high-level behaviors such as safety and liveness in complex systems like self-driving cars. However, in related approaches, specifications for self-driving cars are often scenario-specific and are formulated independently of one another (Shalev-Shwartz, Shammah, and Shashua, 2017). State space explo- sion also greatly limits the scalability of these methods (Baier and Katoen, 2008;

Wongpiromsarn, Karaman, and Frazzoli, 2011).

A more general approach involves designing β€œrulebooks” for self-driving cars (Censi et al., 2019). These rulebooks order the set of rules for self-driving cars according to a hierarchy taking the form of a preorder, which intentionally leaves ambiguity in their behaviors. The authors in (Censi et al., 2019) do not consider allowing agents to make assumptions about one another. As a consequence, they do not address how to accommodate for the unpredictable and law-evasive nature of human drivers. In light of these issues, we propose a framework that can be used to:

1The material in this chapter comes from joint work with Karena X. Cai and Richard M. Murray.

1. Identify high-level specifications and their relationships as part of a hierar- chical structure that describes a self-driving car’s desirable behavior on the road.

2. Define consistency, coverage, and completeness for a set of specifications.

3. Introduce an assume-guarantee contract formalism for specification structures and notions of rationality and blame.

4. Present a basic and consistent set of axioms for self-driving cars that can be refined and built upon.

5. Demonstrate with game-theoretic examples how rational autonomous vehicle behaviors can be computed/agreed upon under the assumption that they are aware of each other’s specification structures.

We ultimately want to be able to guarantee that self-driving cars will behave correctly and not be responsible for accidents. This chapter offers a step in that direction.

6.2 Overview

In a dynamic and interactive environment, the problem of providing guarantees for a single agent without making any assumption on the behaviors of other agents is ill- posed. We show the inherent coupling between the assumptions on the environment and the system’s guarantees in Fig. 6.1. Our framework of assume-guarantee profiles is intended to explicitly address this issue.

Definition 6.2.1(Assume-guarantee profile). An assume-guarantee profile for an agent is a 2-tuple(A,G)where

β€’ A is a set of behavioral preferences or characteristics that the agent assumes its environment to have.

β€’ G is a set of behavioral preferences or characteristics that it is obligated to behave according to as long as its environment makes decisions in accordance withA.

To model the sets of behavioral preferences or characteristics mentioned in Defi- nition 6.2.1, we propose a mathematical object termedspecification structure that describes a hierarchy on sets of what we calldimensional properties. A property

Figure 6.1: A high-level system architecture capturing the inherent coupling of the behavioral specifications for an agent and its environment is shown in the bottom figure. The details of each agent’s architecture for defining its behavior are shown in the top. Each agent identifies the best action to take by using the oracle to define which specifications will be satisfied if an action is taken, and using a consistent evaluator to rank those actions based on a hierarchical ordering defined in the specification structure.

is a desirable attribute that can either be satisfied or not satisfied. A dimensional property is a property whose satisfaction is independent of the satisfaction of other properties. Examples of dimensional properties include safety, lawfulness, cour- tesy, and comfort. Safety does not necessarily imply comfort and vice versa. The guarantee we make in our assume-guarantee contract is that the self-driving car will act in accordance with the specification structure. Intuitively, this means of all subsets of specifications that the car can satisfy, it will choose to satisfy the one that is ranked highest in priority with respect to the specification structure. We define this more rigorously in the next section.

6.3 Evaluator and Evaluated Structure

Before presenting the formal definition of a specification structure, we make the following assumption about the predictive capabilities of a self-driving car.

Assumption 1(Oracle). We assume that each autonomous agent relies on anoracle (Sipser, 2012) that provides predictions to its queries about the satisfaction of dimensional properties of interest for any action or strategy that it is considering.

The input to the oracle is a set of dimensional properties, a potential action or strategy

the car can choose to take, and the current world state configuration. The output of the oracle is some prediction of what specifications (dimensional properties) will be satisfied if a strategy is followed. In the simplest case, the oracle could return a valuation of a set of a Boolean variables, each indicating whether or not a property is violated.

Although many decision/optimization problems currently posed for autonomous ve- hicles are of high computational complexities, not to mention undecidable (Madani, Hanks, and Condon, 2003; Papadimitriou and Tsitsiklis, 1987), we expect future technology to be capable of approximating the oracle to an acceptable level of fi- delity (see (Lefèvre, Vasquez, and Laugier, 2014) for a sample of related methods).

If a set of dimensional properties is simply partially ordered, then there may not be enough structure to uniquely identify which action should be taken.

Example 6.3.1. Consider a set 𝑆 ={π‘Ž, 𝑏, 𝑐, 𝑑 , 𝑒} that is partially ordered (a poset) such that 𝑏 β‰Ί π‘Ž, 𝑐 β‰Ί π‘Ž, 𝑑 β‰Ί 𝑐, and𝑒 β‰Ί 𝑐. Here, each element in the set represents a dimensional property like safety, the law, performance, etc. By this partial order, the node 𝑏 cannot be compared to 𝑐 or 𝑑 or 𝑒. For a self-driving car, any action will result in satisfying a subset of the dimensional properties. Since 𝑏 cannot be compared to𝑐or 𝑑 or𝑒, it is ambiguous whether a self-driving car should take an action that satisfies the propertiesπ‘Ž,𝑏, and𝑐or an action that satisfiesπ‘Ž,𝑏, and𝑑. With only a partial ordering on the dimensional properties, there can be ambiguity in choosing the best subset of properties that can be satisfied. In order to resolve this, we introduce the idea ofconsistent evaluators, which are a class of functions that can endow some posets with a unique weak order on their powersets. Being weakly ordered means that all subsets are comparable, but some subsets may have equal values to each other (these are considered indistinguishable). Any of these evaluators must, in addition to basing its evaluations on the original partial order, somehow try its best to resolve any apparently missing information in a transparent and consistent way.

In a practical setting, if a self-driving car manufacturer wanted to impose a total order instead of a weak order on the powerset, they would have to face the challenging task of defining how any one set of dimensional properties is strictly better or worse than another set of dimensional properties. This is arguably not only impractical because of the exponential growth in the size of the powerset, but also because sometimes a strictcomparison among sets of properties is simply unnecessary. A consistent

evaluator, which allows for sets in the powerset to have equal value, therefore allows for a more practical way of resolving comparisons between subsets of specfications.

We refer to chains (antichains) of partially-ordered sets in our definitions and proofs, so we present the definitions here.

Definition 6.3.1 (Chain/Antichain). A chain (antichain) is a subset of a partially ordered set such that any two distinct elements in the subset are comparable (incom- parable).

Definition 6.3.2 (Consistent evaluator). Given a set of dimensional properties P and its powerset 2P, we say that 𝑓 : 2P →𝑇, where𝑇is a totally ordered set with≀ as the ordering relation, is aconsistent evaluatorforPif for all subsets𝑃1, 𝑃2 βŠ† P, the following hold:

1. 𝑃1β‰ βˆ… β‡’ 𝑓(βˆ…) < 𝑓(𝑃1).

2. βˆ€π‘1 ∈ 𝑃1 :: βˆ€π‘2 ∈ 𝑃2 :: 𝑓({𝑝1}) = 𝑓({𝑝2}) β‡’ (𝑓(𝑃1) ≀ 𝑓(𝑃2) β‡’ 𝑓(𝑃1βˆ’ {𝑝1}) ≀ 𝑓(𝑃2βˆ’ {𝑝2})).

3. (βˆ€π‘1 ∈ 𝑃1 :: βˆ€π‘2 ∈ 𝑃2 :: 𝑓({𝑝1}) β‰  𝑓({𝑝2})) β‡’ (max

π‘βˆˆπ‘ƒ1

𝑓({𝑝}) <

maxπ‘žβˆˆπ‘ƒ2

𝑓({π‘ž}) β‡’ 𝑓(𝑃1) < 𝑓(𝑃2)).

IfPis partially ordered by and𝔄(𝑃,) is the set of all antichains ofP, we further require that for any𝑝1, 𝑝2 ∈ P

4. 𝑝1 β‰Ί 𝑝2 β‡’ 𝑓({𝑝1}) < 𝑓({𝑝2}).

5. ({𝑝1, 𝑝2} ∈ 𝔄(𝑃,)∧ 𝑓({𝑝1}) < 𝑓({𝑝2})) β‡’ βˆƒπ‘ , 𝑑 ∈ P :: 𝑝1β‰Ί π‘ βˆ§ 𝑓({𝑠}) ≀ 𝑓({𝑝2}) ∧ 𝑓({𝑝1}) ≀ 𝑓({𝑑}) βˆ§π‘‘ β‰Ί 𝑝2.

Intuitively, the conditions in Definition 6.3.2 mean

1. The evaluator will assign the worst value when no property is satisfied. This ensures that every property included inPmatters to the evaluator.

2. Properties of equal value to the evaluator can be disregarded without affecting the result of the evaluation.

3. For sets that do not have properties with the same values, the one with the most highly valued property is preferable.

4. If there exists a pre-imposed hierarchy between some of the properties, then the evaluator must respect it.

5. Given a pre-imposed hierarchy on the properties, the evaluator must be impar- tial: it will only assign different values to two properties whose relationship is not defined in the hierarchy when they are comparable via two β€œproxies.”

Example 6.3.2. Consider a partially ordered set𝑄in which𝑝is the greatest element and all other elements belong to an antichain. Then we can define 𝑓 as the function 𝑓(π‘„Λœ) B 1π‘βˆˆπ‘„Λœ|𝑄| + |π‘„Λœ βˆ’ {𝑝}|for all Λœπ‘„ βŠ† 𝑄where1is the indicator function. This function evaluates any subset with the maximal element in it as the cardinality of𝑄 plus the dimension of the subset with the element 𝑝 thrown out. It also evaluates any subset without the maximal element as the dimension of that subset. One can easily verify that 𝑓 is a consistent evaluator for𝑄.

Figure 6.2: A poset that does not admit a consistent evaluator. The values in parentheses denote the value of the singleton set containing that node given by the evaluator 𝑓𝑖. In both cases, requirement 5 is violated.

Example 6.3.3 (Poset without consistent evaluator). Consider the poset with the structure shown in Fig. 6.2 and for simplicity, assume𝑇 = N0. We cannot define a consistent evaluator that satisfies all five requirements on this partially-ordered set. In order to satisfy requirement 4, such that the partial order established in the poset is preserved, the consistent evaluator function 𝑓1 on the left and 𝑓2 on the right can, WLOG, assign all nodes on the right branch of the poset with the values shown in Fig. 6.2. To respect the partial order, by requirements 4 and 5 of consistent evaluators, 𝑝2 must be assigned a value in {0,1}. The left figure shows what happens if the function takes on the value 1 for the left node, i.e., 𝑓1({𝑝2}) = 1. If this happens, then 𝑓1({𝑝1}) < 𝑓1({𝑝2}), but there is no proxy node that is comparable to 𝑝2in the poset and has a value equal to 𝑓1({𝑝1}). This clearly violates requirement 5. The right figure shows what happens if the function

takes on the value 0, i.e. 𝑓2({𝑝1}) = 0. A similar violation is incurred by 𝑓2 (see (Phan-Minh, Cai, and Murray, 2019)).

Through the previous examples, we see that not all posets admit a consistent evalu- ator. The natural question to ask is: what makes posets consistently evaluable? The next theorem will answer this question. Before stating the theorem, we will give one more definition. First observe that for any set of maximal antichains𝔄of a set partially ordered by , there exists aninduced total preorder ←(i.e., a preorder in which any two elements are comparable) defined by:

βˆ€π΄1, 𝐴2 βˆˆπ”„:: 𝐴1← 𝐴2β‡’ βˆƒπ‘Ž1 ∈ 𝐴1::βˆƒπ‘Ž2∈ 𝐴2::π‘Ž1 β‰Ί π‘Ž2.

Observe that←is indeed a total preorder because of the maximality assumption on the antichains.

Theorem 1. A finite poset𝑃of dimensional properties has a consistent evaluator if and only if it can be partitioned by a set𝔄of𝑁 maximal antichains such that

1. 𝔄’s induced total preorder is a total order.

2. For each dimensional property, there exists a maximal chain containing it of length𝑁.

Lemma 3. Condition 1 of Theorem 1 is equivalent to the fact that the maximal antichains can be assigned ranks in such a way the partial order is respected.

Proof (Sketch). Define the ranks in accordance with the induced total order on the

antichains and verify.

We are ready to give a proof for Theorem 1.

Proof. (β‡’): Suppose that𝑃is a poset of dimensional properties with the ordering relation such that 𝑃 has a consistent evaluator 𝑓. Since 𝑃 is finite, the set 𝑓𝑃 B {𝑓({𝑝}) | 𝑝 ∈ 𝑃} is also finite. Furthermore, the range of 𝑓 being totally ordered implies that we can write 𝑓𝑃 = {𝑧1, 𝑧2, . . . , 𝑧𝑛} for 𝑛 = |𝑓𝑃| such that 𝑧1 < 𝑧2 < . . . < 𝑧𝑛. For each 𝑧𝑖 ∈ 𝑓𝑃, let π‘“βˆ’1(𝑧𝑖) βŠ† 𝑃 be defined by π‘“βˆ’1(𝑧𝑖) B {𝑝 | 𝑝 ∈ 𝑃 ∧ 𝑓({𝑝}) = 𝑧𝑖}. Observe that requirement 4 of Definition 6.3.2 implies that for each𝑖, π‘“βˆ’1(𝑧𝑖) is an antichain. Consequently, the π‘“βˆ’1(𝑧𝑖)’s form a partition of 𝑃 by antichains. By ranking each π‘“βˆ’1(𝑧𝑖) by the corresponding 𝑧𝑖,

it also follows that the antichains respect the partial order defined by . To show maximality, suppose that there exists 𝑗 ∈ [𝑛] such that π‘“βˆ’1(𝑧𝑗) is not a maximal antichain. This implies that there exists π‘˜ ∈ [𝑛] βˆ’ {𝑗} and there is a property π‘žβ˜… ∈ π‘“βˆ’1(π‘§π‘˜) such that {π‘žβ˜…} βˆͺ π‘“βˆ’1(𝑧𝑗) is an antichain. WLOG, suppose 𝑗 < π‘˜ so that 𝑧𝑗 < π‘§π‘˜ implies βˆ€π‘ž ∈ π‘“βˆ’1(𝑧𝑗) :: 𝑓({π‘ž}) < 𝑓({π‘žβ˜…}). If π‘˜ = 𝑗 + 1, the existence of any Λœπ‘ž ∈ π‘“βˆ’1(𝑧𝑗) such that 𝑓(π‘žΛœ) < 𝑓(π‘žβ˜…) implies, by requirement 5 of Definition 6.3.2, that there exists π‘ž0 ∈ π‘“βˆ’1(𝑧𝑗) such that π‘ž0 β‰Ί π‘žβ˜…. But this contradicts the assumption that {π‘žβ˜…} βˆͺ π‘“βˆ’1(𝑧𝑗) is an antichain. Suppose up to π‘˜ =𝑑 with π‘˜ +1 ≀ 𝑑 < 𝑛, there exists no π‘žβ˜… ∈ π‘“βˆ’1(π‘§π‘˜) such that {π‘žβ˜…} βˆͺ π‘“βˆ’1(𝑧𝑗) is an antichain. We will show that this also holds for π‘˜ = 𝑑 +1. Indeed, by the induction hypothesis, π‘žβ˜…can only potentially come from π‘“βˆ’1(𝑧𝑑+1). Since for any π‘ž ∈ π‘“βˆ’1(𝑧𝑗), 𝑓({π‘ž}) < 𝑓({π‘žβ˜…}), by requirement 5, there is π‘ž1 and π‘ž2 such that π‘ž β‰Ί π‘ž1 and π‘ž2 β‰Ί π‘žβ˜… while 𝑓({π‘ž1}) ≀ 𝑓({π‘žβ˜…}) and 𝑓({π‘ž}) ≀ 𝑓({π‘ž2}). By requirement 4,π‘ž2must belong to one of π‘“βˆ’1(𝑧𝑗), π‘“βˆ’1(𝑧𝑗+1), . . . , π‘“βˆ’1(𝑧𝑑+1). By the induction hypothesis, there is a π‘ž0 ∈ π‘“βˆ’1(𝑧𝑗) such that π‘ž0 β‰Ί π‘ž2. Thus π‘ž0 β‰Ί π‘žβ˜…, a contradiction. From this, we conclude Lemma 3 and hence 1) hold.

To see that 2) holds, observe that any property 𝑝 ∈ π‘“βˆ’1(𝑧𝑗), if 𝑗 β‰  𝑛 and 𝑛 β‰₯ 2, then by requirement 5 and the antichain property of the π‘“βˆ’1(𝑧𝑗), there exists π‘ž ∈ π‘“βˆ’1(𝑧𝑗+1)such that 𝑝 β‰Ί π‘ž. Similarly, if 𝑗 β‰ 1 and𝑛 β‰₯ 2, there existsπ‘Ÿ ∈ π‘“βˆ’1(π‘§π‘—βˆ’1) such thatπ‘Ÿ β‰Ί 𝑝. Applying this argument toπ‘Ÿ and/orπ‘ž inductively yields a chain of length𝑛that containsπ‘ž. This chain is maximal by the contradiction resulting from applying the pigeonhole principle to the assignment of properties from any chain of greater length to the maximal antichains.

(⇐): We can easily verify that requirements 1-4 of a consistent evaluator are satisfied. Now, we show that requirement 5 holds as well. Let us show this by contradiction. Consider that there exists a node 𝑝1 and 𝑝2 such that 𝑓({𝑝1}) <

𝑓({𝑝2}), but there does not exist a node 𝑠 or 𝑑 such that 𝑝1 β‰Ί 𝑠, 𝑑 β‰Ί 𝑝2, and 𝑓({𝑝2}) = 𝑓({𝑠})and 𝑓({𝑝1}) = 𝑓({𝑑}). WLOG, consider 𝑝1to be a node where there does not exist a node 𝑠such that 𝑝1 β‰Ί 𝑠and 𝑓({𝑝2}) = 𝑓({𝑠}). Since there is no node that is directly comparable to 𝑝1 in the antichain with value equal to 𝑓({𝑝2}), there exists a maximal chain containing𝑝1that has length strictly less than π‘š. This is a violation of property 2) characterizing the poset𝑃. Is it possible that there may be multiple such decompositions of maximal antichains, making the ordering that is induced via the corresponding rankings non-unique and

hence the β€œconsistent evaluator” not very consistent? Luckily, the answer is a reassuring negative.

Theorem 2. The partition in Theorem 1 is unique.

Proof. Suppose that𝑃1, 𝑃2, . . . , π‘ƒπ‘š is also a partition of maximal antichains of 𝑃 with ranksπ‘Ÿ(𝑃1) < π‘Ÿ(𝑃2) < . . . < π‘Ÿ(π‘ƒπ‘š)that respect the partial order. Suppose that π‘š ≠𝑛where𝑛= |𝑓𝑃|. Ifπ‘š > 𝑛, then by 2) of Theorem 1, there is a chain of length π‘š. However, assigning theseπ‘šproperties to the π‘“βˆ’1(𝑧𝑖) means by the pigeonhole principle that there are at least two properties that are assigned to the same π‘“βˆ’1(𝑧𝑗) for some 𝑗, implying that π‘“βˆ’1(𝑧𝑗) is not an antichain, namely, a contradiction. It follows thatπ‘š ≀ 𝑛. Similarly, we can argue that π‘š β‰₯ 𝑛and thereforeπ‘š =𝑛. Now, we claim that 𝑃𝑖 = π‘“βˆ’1(𝑧𝑖) for all𝑖 ∈ {1,2, . . . , 𝑛}. Suppose this is not the case, then there exists𝑝 ∈ π‘ƒπ‘˜ such that𝑝 ∈ π‘“βˆ’1(π‘§β„Ž)forπ‘˜ β‰  β„Ž. Then by 2), there are two chains of length 𝑛: 𝑝1 β‰Ί 𝑝2 β‰Ί . . . β‰Ί 𝑝𝑛 and 𝑓1 β‰Ί 𝑓2 β‰Ί . . . β‰Ί 𝑓𝑛 such that𝑝𝑖 ∈ 𝑃𝑖 and 𝑓𝑖 ∈ π‘“βˆ’1(𝑧𝑖). We also have π‘π‘˜ = π‘“β„Ž = 𝑝. WLOG, assume β„Ž < π‘˜. This implies that 𝑝1 β‰Ί 𝑝2 β‰Ί . . . β‰Ί π‘π‘˜ = 𝑝 = π‘“β„Ž β‰Ί π‘“β„Ž+1 β‰Ί . . . β‰Ί 𝑓𝑛. However, this chain has lengthπ‘˜+π‘›βˆ’β„Ž > 𝑛sinceπ‘˜ > β„Ž. This contradicts the fact that𝑃can be partitioned

into𝑛antichains.

We have defined the necessary and sufficient properties posets need to have so they can be consistently evaluated. It turns out that not all of these posets are β€œintuitive”

as shown in Example 6.3.4. This prompts us to introduce a class of posets that are consistently evaluable but also easier to deal with.

Figure 6.3: Both posets admit consistent evaluators. The value the consistent evaluator assigns on each singleton that consists of the node is written in parentheses.

Note that the poset on the left has the additional graded property while the one on the right does not.

Example 6.3.4. Consider the posets in Fig. 6.3. Any evaluator 𝑓 that assigns the values according to the values in the parentheses, shown in the figure, can easily