{"id":"727bfb92-c4fa-4cff-9e3c-7a8eae235cb1","arxiv_id":"2504.12218","paper_version":2,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":7.0,"correctness_risk":"low","formal_verification":"none","parameter_count":2,"one_line_summary":"Accountable liveness is achievable in x-partially-synchronous networks if and only if x < 1/2 and the adversary controls fewer than n/2 nodes.","lead":"The paper defines a new network model that interpolates between synchronous and partially synchronous networks, and proves that consensus protocols can make liveness violations accountable exactly when the network is mostly synchronous and adversarial nodes are a minority. It gives a protocol that produces certificates of guilt against many adversary nodes after a liveness violation, and shows the frontier is fundamental.","discovery_kind":"first_principles","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Theorem 3 overstates its scope: the x≥1/2 impossibility is proved using τ_S-safety and fails for the stated 0-safe assumption.","rationale":"I read the paper as making a conditional mathematical claim: under the x-partial-synchrony model, non-trivial accountable liveness for optimally-resilient atomic broadcast protocols is achievable exactly when x<1/2 and τ_AL_max<n/2. The positive construction in Secs. 3–5 is substantial and the combinatorial adjudication argument appears internally coherent. The main load-bearing problem I find is in the formal statement and proof of Theorem 3, which is one half of the characterization. The theorem claims impossibility for protocols that are only 0-safe, but the proof uses a split-brain safety violation in E5 that contradicts τ_S-safety for the protocol's actual safety resilience. For τ_S=0 the partition used in the proof cannot even be formed, and the indistinguishability/certificate-replay argument requires honest nodes to be a strict majority of the certificate, which fails for small τ_S. This does not refute the characterization for the paper's intended baseline protocols, which have τ_S≈n/3, but it means the theorem as stated is broader than the proof supports. The reader's conditional verdict remains appropriate; the concern is different from the reader's identified weakest assumption about the realism of the x-partial-synchrony model, so I record disagreement on that specific identification.","tokens_in":41308,"tokens_out":38502,"duration_ms":399044,"concrete_test":"Analytically re-derive the certificate-replay step of the proof of Theorem 3 under the assumption τ_S=0. Determine whether the certificate produced in E_B against p′∈P2 can be reproduced in E_C when P2 is honest: the accusation set must contain more than n/2 messages; with |P1|+|P3|=τ_L<n/2 at least one accusation is signed by a P2 node, which cannot be replayed without forging honest signatures. If this is unavoidable, the theorem as stated is not proven; then re-state it for τ_S≥2 and verify whether the abstract's characterization still holds for the baseline τ_S=τ_L=floor((n−1)/3) protocols.","verdict_should_be":"UNCHANGED","load_bearing_attack":"Theorem 3 (Sec. 6.2) is stated for protocols that are only 0-safe under partial synchrony, but its proof in Sec. C.2 requires the full τ_S-safety of the protocol. The split-brain construction partitions P into P1 (size τ_L+1), P2 (size τ_L+1), and P3 = n−2(τ_L+1), and concludes a contradiction from a safety violation in E5 'even though |P3|≤τ_S'. With only 0-safety, i.e., τ_S=0, optimal resilience gives n=2τ_L+1, so |P3|=−1 and the partition is impossible. Even if one sets that aside, the certificate-replay step needs |P1|+|P3| = n−(τ_L+1) > n/2 so that the honest nodes in E_C can reproduce the certificate against p′∈P2 without requiring signatures from P2, which are honest in E_C and would not self-accuse. With τ_S=0 this sum is τ_L < n/2, and with τ_S=1 it is exactly n/2, still not a strict majority. Thus the impossibility for x≥1/2 is established only for protocols with τ_S≥2, such as the baseline τ_S≈n/3 protocols, not for the stated 0-safe class. The claimed 'if and only if' characterization must be scoped accordingly, or the proof must be repaired.","agreement_with_reader":"disagree"},"referee_report":null,"author_rebuttal":null,"desk_editor":null,"rs_alignment":null,"lean_confirmation":null,"pith_extraction":null,"created_at":"2026-08-16T12:36:05.717041+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":null,"supporting_citations":[],"review_version":1}