{"id":"d4fd5ab7-d07d-48cf-9d83-4850bd6bdc7d","arxiv_id":"2507.22385","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"A score-based test, built on Doob's h-transform, gives necessary and sufficient conditions for almost sure controlled set invariance of Itô diffusions over finite and infinite horizons.","lead":"The paper derives a test, based on score functions (gradients of log-likelihoods), that certifies when a controlled stochastic system can be kept inside a safe set with probability one. If the test passes, it constructs all controllers that achieve this guarantee; if it fails, it proves no Markovian controller can.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Theorem 4's claim that all a.s.-invariant controllers solve Gu = s∞ is false: adding any bounded drift to the h-transform control preserves the entrance-boundary property and yields another valid controller.","rationale":"The reader's verdict identified the regularity of u and the A2/Example 4 issue as the weakest assumptions. The regularity concern is real and closely related to the counterexample above, but the reader did not draw the sharper conclusion: the claimed characterization of all controllers is false even in the uniformly elliptic, well-posed setting of Example 5. The A2 concern about degenerate diffusions is separate and valid, but the counterexample here operates inside A1-A3, so it is more fundamental. The paper's main advertised result has two components: (a) a necessary and sufficient existence test s_T ∈ R(G) or s∞ ∈ R(G), and (b) a constructive characterization of all controllers as solutions of Gu = s_T or Gu = s∞. Component (b) is directly refuted by the entrance-boundary construction: there are infinitely many a.s.-invariant Markovian controllers besides the h-transform drift. Component (a) may still be true, but the proof as written (Appendix B and D) is a one-line equating of the controlled process to the h-transform process, which assumes the false uniqueness. Therefore the central theorm as stated is incorrect, and a rejection of the current version is warranted; a revised version might salvage an existence-only statement if the necessity direction can be proved without the false uniqueness, but that is not what the paper currently establishes.","tokens_in":25159,"tokens_out":20471,"duration_ms":259815,"concrete_test":"Verify the counterexample analytically and computationally. (1) For the SDE dX_t = (π cot(πX_t) + 1) dt + dW_t on (0,1), compute the scale function S(x) = ∫ exp(-2∫(π cot(πy)+1)dy) dx and speed measure m(dx) = 2 S'(x)^{-1} dx; check that S(0+) = -∞, S(1-) = +∞, and the speed measure integrals near 0 and 1 are finite, which classifies both boundaries as entrance. (2) Simulate 10^4 Euler-Maruyama paths with step 10^{-4} on [0,100] and record any exit from (0,1); zero exits confirm that uc attains a.s. infinite-horizon set invariance while violating equation (43), refuting the all-controllers characterization in Theorem 4.","verdict_should_be":"REJECT","load_bearing_attack":"The central necessity step in Theorems 2 and 4 equates any a.s.-invariant controlled process with the Doob h-transform process (27)/(39), concluding that every such controller must solve G u = s_T or G u = s∞. This uniqueness assertion is false under the paper's own assumptions. Take the infinite-horizon setting of Example 5 in one dimension: X = (0,1), f = 0, σ = 1, G = 1. The principal eigenfunction is ψ0(x) = sin(πx), so s∞(x) = π cot(πx), and Theorem 4 claims that the only a.s.-invariant controller is u0 = π cot(πx). However, for any nonzero constant c, the Markovian controller uc(x) = π cot(πx) + c also achieves a.s. set invariance. The SDE dX_t = (π cot(πX_t) + c) dt + dW_t has scale density s(x) ~ x^{-2} near 0 and ~ (1-x)^{-2} near 1; hence the scale function diverges to -∞ and +∞ at the boundaries, and the speed measure is integrable near each boundary. By Feller's boundary classification, both boundaries are entrance, i.e., unattainable from the interior, so P_x(τ_(0,1) = ∞) = 1 for every x ∈ (0,1). Thus uc is a valid a.s.-invariant controller that does not solve (43). The same construction works for finite horizon because for t < T the solution h_T of (28) satisfies h_T(t,x) ≈ c(t) dist(x,∂X), so ∇ log h_T has a 1/dist singularity at the boundary; adding a bounded perturbation leaves the boundaries unattainable up to time T. Consequently, the 'characterizes all controllers' statement in Theorem 4 (and likewise Theorem 2) is not merely unproved but false, and the necessity proof in Appendix B relies on the same false uniqueness. The paper also fails to specify any regularity or boundedness condition on u that would exclude uc while retaining the singular h-transform controller u0, so the claim cannot be repaired by a natural restriction of the controller class.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper proposes a score-based test for almost-sure set invariance of controlled Itô diffusions. For a prescribed finite horizon T, the authors define h_T as the solution of a Dirichlet BVP and the score s_T = Σ ∇ log h_T, then claim that a Markovian controller exists if and only if s_T is pointwise in the range of the input matrix G, and that when this holds all invariant controllers are exactly the solutions of Gu = s_T. An analogous statement is made for the infinite horizon using the principal Dirichlet eigenfunction ψ_0 and s_∞ = Σ ∇ log ψ_0. The paper also contains an inverse-optimality result and several semi-analytic and numerical examples, including Feynman-Kac and inverse power iteration computations.","tokens_in":25541,"tokens_out":13216,"duration_ms":168924,"significance":"If the main theorems were correct, the paper would provide a computationally checkable necessary-and-sufficient certificate for a strong safety notion, together with an explicit characterization of all safe controllers. The score-based reformulation is original and the numerical examples are constructive. However, the central necessary-and-sufficient claim and the 'all controllers' characterization are false: there exist invariant controlled diffusions that do not coincide with the Doob h-transform process and do not solve Gu = s_∞. The paper does not provide machine-checked proofs or reproducibility artifacts, but the appearance of a decisive counterexample means the main contribution as stated cannot stand.","major_comments":[{"comment":"The claim that all a.s.-invariant controllers solve Gu = s_∞ is false. Consider Example 5 in one dimension: X = (0,1), f = 0, σ = 1, G = 1, ψ_0(x) = sin(πx), so s_∞(x) = π cot(πx). For any constant c ≠ 0, the Markovian controller u_c(x) = π cot(πx) + c also achieves a.s. invariance: the SDE dX_t = (π cot(πX_t) + c) dt + dW_t has scale density s(x) = sin^{-2}(πx)e^{-2cx}, the scale function diverges to -∞ at 0 and +∞ at 1, and the speed measure is integrable near both boundaries, so by Feller's boundary classification both 0 and 1 are entrance boundaries and P_x(τ_{(0,1)} = ∞) = 1 for every x ∈ (0,1). This controller does not solve (43). The same construction works for the finite horizon case because h_T(t,x) is proportional to the distance to ∂X for t<T, so adding a bounded drift to the h-transform drift preserves non-attainment of the boundary up to time T. Therefore the characterization in Theorem 4 (and, analogously, Theorem 2) is not merely unproved but wrong.","section":"IV-B, Theorem 4"},{"comment":"The necessity step in Theorems 2 and 4 is invalid. The proofs equate an arbitrary controlled diffusion that is a.s. invariant with the Doob h-transform conditioned process. However, the conditional law P(· | τ_X > T) is only one probability measure supported on paths that stay in X; there are many absolutely continuous measures with the same diffusion coefficient that are also supported on such paths, as the family of controllers u_c in the previous comment shows. Consequently, the condition s_T ∈ R(G) or s_∞ ∈ R(G) is at best sufficient for existence, and the falsification claim that violation of the range condition implies non-existence of any controller does not follow from the provided arguments.","section":"III-B and IV-B, proofs in Appendices B and D"},{"comment":"The asymptotic expansion in Eq. (35) is not correct as written. For fixed t, h_T(t,x) = P_x(τ_X > T - t) tends to 0 as T → ∞, whereas the right-hand side e^{λ_0 t} ψ_0(x) does not tend to 0. The correct leading-order behavior is h_T(t,x) = c e^{-λ_0 (T - t)} ψ_0(x) + o(e^{-λ_0 T}) (up to normalization), so the displayed limit does not exist. The proof of Theorem 3 in Appendix C relies on this limit; although the logarithmic gradient ∇ log h_T may still converge to ∇ log ψ_0 after cancellation of the exponential factors, the derivation as written needs to be repaired.","section":"IV-A, Eq. (35) and Appendix C"},{"comment":"Equation (49) states u(t,x) = s_T(t,x) = ∇_x h_T(t,x), but the definition (32) gives s_T = Σ ∇_x log h_T = ∇_x h_T / h_T when Σ = I. The displayed formula drops the 1/h_T factor and is inconsistent with equation (34). This error affects the analytic controller formula in Example 1 and the subsequent numerical illustrations in Figures 2-4.","section":"VI-A, Example 1, Eq. (49)"},{"comment":"The controlled diffusion in Example 4, Eq. (54), is degenerate and violates Assumption A2, yet the text asserts that 'the proposed computational framework still applies thanks to the same input and noise channels in (54)' without proof. Assumption A2 is used to guarantee positivity of the transition density and the invertibility of Σ in the Girsanov argument of Theorem 1. If the framework applies to this degenerate setting, a separate justification or a relaxed assumption is required; otherwise the example does not illustrate the stated theory.","section":"VI-A, Example 4"}],"minor_comments":[{"comment":"Assumption A1 states a Lipschitz condition only for f and a growth condition for σ, not a Lipschitz condition for σ; the cited existence-uniqueness theorem for strong solutions requires Lipschitz continuity of both drift and diffusion coefficients.","section":"II, Assumption A1"},{"comment":"The notation h_T ∈ C^{1,2}([0,T]; X) is nonstandard; the intended space is C^{1,2}([0,T] × X).","section":"III-A, Theorem 1"},{"comment":"The series solution in Eq. (48) appears to place the exponential time dependence incorrectly: the factor exp(-(T-t)) in (48b) should involve the modal rates π² m_i² / (2ℓ_i²), and the exponentials in (48c) should include the factor (T-t).","section":"VI-A, Example 1, Eq. (48)"},{"comment":"The Weyl chamber W_n in Example 8 is unbounded, so it does not satisfy Assumption A3; the example is presented without noting or resolving this violation.","section":"VI-B, Example 8"},{"comment":"The paper never specifies the regularity class of the Markovian controller u (e.g., local boundedness, Borel measurability, or an integrability condition), although such regularity is needed for the Girsanov argument and for well-posedness of the controlled SDE.","section":"I and II"}],"recommendation":"reject","confidential_remarks":"The decisive counterexample in my major comment 1 shows that the central 'characterizes all controllers' claim is false, and the necessity of the range condition is not established. This is a load-bearing error, not a local fix. If the authors choose to reformulate the paper as giving only sufficient conditions and a constructive controller, the score-based viewpoint and the numerical examples may still be of interest, but that would be a substantially different claim from the one submitted."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Quick take on arXiv:2507.22385. The construction is genuinely nice: from the Dirichlet eigenfunction you compute a score field, and if it lies in the range of the input matrix, you can build an a.s.-invariant controller by solving a linear system. That is a real sufficient condition, computationally cheap, and the Feynman-Kac / inverse-power-iteration numerics and the inverse optimality result are useful additions. The Weyl chamber example is a nice bonus.\n\nBut the headline claim — necessary and sufficient, with 'all' controllers characterized — is false. The stress-test counterexample checks out. In the 1D infinite-horizon instance (Example 5), the paper's unique controller is u0 = π cot(πx). For any nonzero constant c, u_c = u0 + c is also a.s.-invariant: the scale density is (sin πx)^{-2}e^{-2cx}, so both boundaries are entrance, and the process never exits (0,1). This controller is no more or less regular than u0, so it is admissible under the paper's own loose regularity assumptions and it does not satisfy Gu = s∞. The same construction works for finite horizon because h_T(t,x) ~ dist(x,∂X) near the boundary, so a bounded perturbation still leaves the boundaries unattainable up to time T. Consequently the 'characterizes all controllers' clauses in Theorems 2 and 4 are wrong; the necessity proof in Appendix B assumes exactly what it needs to prove, equating any invariant process with the h-transform conditioned process.\n\nThe smaller issues the reader flagged are real too: Eq. (35) states a limit that doesn't exist as written (h_T → 0; the e^{λ0t}ψ0 term appears only up to normalization), Eq. (49) drops the log in the score, the Radon-Nikodym derivative in Eq. (24) has the wrong denominator (h_T(t,x) instead of h_T(0,x0)), and Example 4 uses a degenerate diffusion violating Assumption A2 without proof.\n\nNet: the paper has a good sufficient-condition machine and a fresh reformulation, but the central necessary/sufficient and all-controller characterization is not just unproved — it is false. That is a load-bearing flaw. A serious referee should still see it, because the counterexample is subtle and the sufficient direction deserves to be preserved in the literature, but the paper needs a major revision, likely retreating to a sufficiency claim with honest limitations. I would not cite the necessity or characterization claims as they stand.","headline":"The score-range test is a neat sufficient construction, but the 'all controllers' claim is false: adding a bounded drift to the h-transform control preserves almost-sure invariance.","tokens_in":26118,"tokens_out":12861,"would_cite":false,"duration_ms":161813,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["93E20","60J60","60H10","35K20"],"pacs":[],"model":"deepseek-v4-flash","headline":"For a controlled Itô diffusion, keeping a prescribed region invariant with probability one over a finite or infinite horizon is exactly equivalent to a range condition on a score vector field computed from a Dirichlet problem.","keywords":["controlled set invariance","Itô diffusion","Doob h-transform","score vector field","Dirichlet boundary value problem","almost sure safety","Markovian control","Feynman-Kac path integral"],"falsifier":"Take the one-dimensional problem $X=(0,1)$, $T<\\infty$, $G=1$, $\\sigma=1$, $f=0$, and compare the paper's controller $s_T$ with the infinite-horizon controller $u(x)=\\pi\\cot(\\pi x)$, which also keeps the diffusion inside $(0,1)$ up to any finite $T$. If Euler-Maruyama paths under $u(x)=\\pi\\cot(\\pi x)$ never hit the boundary in the small-step limit, then the paper's claim that all almost surely invariant controllers are exactly the solutions of $Gu=s_T$ is false; exhibiting any data where the range test fails yet a Markovian controller keeps paths inside would likewise refute the necessity direction.","tokens_in":2049,"feed_emoji":"🛡️","tokens_out":2461,"duration_ms":230060,"temperature":0.7,"pith_summary":"The paper asks when a controlled diffusion—a stochastic differential equation with a control input—can be confined to a given region of state space for all times up to a deadline, or forever, with probability one. It claims a complete answer: compute the score vector field $s_T(t,x)=\\Sigma(t,x)\\nabla_x\\log h_T(t,x)$ from the uncontrolled dynamics and the region, then test whether that field lies pointwise in the range of the input matrix. If it does, controllers exist and all of them are the solutions of a static linear system; if it does not, no Markovian controller can work. This matters because it turns a probabilistic safety question into a PDE solve followed by a linear-algebra check, with no conservative approximations.","feed_headline":"One range check decides if a noisy system can be kept safe","feed_subtitle":"A score field from two PDE solves certifies safe controllers, or proves none can exist.","key_machinery":"The machinery is Doob's h-transform. For the uncontrolled diffusion (2), the probability $h_T(t,x)=P_x(\\tau_X>T)$ of not exiting $X$ before $T$ solves a Dirichlet boundary value problem, and conditioning the diffusion on that survival event changes its drift by the score vector field $s_T=\\Sigma\\nabla_x\\log h_T$, the diffusion-weighted log-gradient of $h_T$. The controlled diffusion (1) shares the same diffusion coefficient as (2), so it can realize the conditioned process exactly when $Gu=s_T$ is solvable; this equivalence carries the entire argument. In the infinite-horizon case the same construction is run with the principal eigenfunction $\\psi_0$, whose log-gradient is time-independent, yielding time-invariant feedback when $G$ and $\\sigma$ are autonomous. Computationally, $h_T$ is obtained by Feynman-Kac path integrals and $\\psi_0$ by inverse power iteration.","core_discovery":"The central discovery is that almost sure set invariance for the controlled diffusion (1) with data $(f,\\sigma,X,X_T,[0,T])$ holds if and only if the score vector field $s_T(t,x):=\\Sigma(t,x)\\nabla_x\\log h_T(t,x)$ belongs to the range of $G(t,x)$ for every $(t,x)\\in[0,T]\\times X$, where $h_T$ is the unique solution of the backward Kolmogorov/Dirichlet problem (28) with terminal condition $1$ on $X_T$ and zero on the lateral boundary. The infinite-horizon analogue replaces $h_T$ with the principal Dirichlet eigenfunction $\\psi_0$ of $-\\mathcal{L}$ and requires $s_\\infty:=\\Sigma\\nabla_x\\log\\psi_0\\in R(G)$. When the condition holds, every certified Markovian controller is a solution of $G(t,x)u(t,x)=s(t,x)$; when it fails, no Markovian controller exists. The finite-horizon test can also enforce hitting a target subset $X_T$ at the terminal time by changing only the terminal condition in the Dirichlet problem.","pith_inferences":["Because feasibility is the rank condition $s\\in R(G)$, the framework also gives a design rule that the paper does not develop explicitly: enlarging the control authority $R(G)$ is exactly what can turn an infeasible safety specification into a feasible one.","The Weyl-chamber example suggests a general recipe: for any domain whose principal eigenfunction is known, the h-transform drift gives an interacting-particle or repulsive-dynamics interpretation of set invariance, potentially connecting to multi-agent collision avoidance.","A data-driven variant is conceivable: estimate the score field from sampled trajectories of the uncontrolled process instead of solving the PDE, then apply the same range test; the paper's score vocabulary points toward this but does not pursue it.","The degenerate single-input example indicates that the range test may extend beyond uniform ellipticity when input and noise enter through the same channel; proving the necessary-and-sufficient status in that regime is a natural open extension."],"forward_implications":["When the range condition fails anywhere in $I\\times X$, the paper rules out the existence of any Markovian controller for almost sure set invariance, so the search for one can stop and weaker safety specifications must be considered.","When the condition holds, the set of certified controllers is exactly the affine family $u=u_{\\mathrm{part}}+v$ with $v$ in the nullspace of $G$; with a wide full-row-rank input matrix, any nullspace vector can be added without breaking invariance.","The finite-horizon certified controller is a time-varying state feedback even when $G$ and $\\sigma$ are autonomous, while the infinite-horizon certified controller is time-invariant under the same autonomy conditions.","The same two-step test covers the additional requirement of hitting a target set $X_T$ at time $T$ by changing only the terminal condition in the Dirichlet BVP, leaving the controller construction unchanged.","Under the matching condition $GG^\\top=\\Sigma$, the certified controller coincides with the optimal controller of an inverse stochastic optimal control problem whose running cost penalizes the boundary with infinite cost."],"supporting_citations":[{"why":"Originates the Doob h-transform used to construct the conditioned diffusion (27).","marker":"[30]"},{"why":"Provides the classical potential-theory treatment of h-transforms behind Theorems 1 and 3.","marker":"[31]"},{"why":"Supplies the textbook h-transform construction for space-time diffusions used in the finite-horizon derivation.","marker":"[42]"},{"why":"Girsanov theorem and SDE well-posedness used to identify the conditioned process's drift and equate it with the controlled process.","marker":"[1]"},{"why":"Uniform ellipticity, positive transition density, and Feynman-Kac representation for the Dirichlet boundary value problem defining $h_T$.","marker":"[3]"},{"why":"Existence and uniqueness theory for the parabolic Dirichlet problems defining $h_T$.","marker":"[2]"},{"why":"Spectral facts for the Dirichlet eigenproblem, including the principal eigenvalue and positive eigenfunction, underlying $s_\\infty$.","marker":"[46]"},{"why":"Strict ellipticity and Sobolev regularity of the principal eigenfunction used in the infinite-horizon construction.","marker":"[39]"}],"fun_headline_variants":["Score test decides safe set invariance in one check","One range check on scores certifies safe controllers","If scores fit the range, safe control exists; else not","PDE score fields: necessary and sufficient for safety"],"cache_read_input_tokens":28032,"weakest_assumption_plain":"The proof assumes that any controller achieving almost sure set invariance must drive the controlled process to coincide with the Doob h-transform of the uncontrolled process conditioned to stay in the set, and that this conditioning is unique and well-defined through uniform ellipticity; if another drift can also keep the process inside with probability one, the claimed all-controllers characterization and the necessity direction are not established.","fun_headline_variants_meta":{"raw":{"variants":["Score test decides safe set invariance in one check","One range check on scores certifies safe controllers","If scores fit the range, safe control exists; else not","PDE score fields: necessary and sufficient for safety"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000616,"raw_usage":{"total_tokens":2869,"prompt_tokens":962,"completion_tokens":1907,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":578,"completion_tokens_details":{"reasoning_tokens":1844}},"tokens_in":578,"tokens_out":1907,"duration_ms":16756,"temperature":1.0,"reasoning_tokens":1844,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-06T11:45:33.488266+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Take the one-dimensional problem $X=(0,1)$, $T<\\infty$, $G=1$, $\\sigma=1$, $f=0$, and compare the paper's controller $s_T$ with the infinite-horizon controller $u(x)=\\pi\\cot(\\pi x)$, which also keeps the diffusion inside $(0,1)$ up to any finite $T$. If Euler-Maruyama paths under $u(x)=\\pi\\cot(\\pi x)$ never hit the boundary in the small-step limit, then the paper's claim that all almost surely invariant controllers are exactly the solutions of $Gu=s_T$ is false; exhibiting any data where the range test fails yet a Markovian controller keeps paths inside would likewise refute the necessity direction.","supporting_citations":[{"cited_title":"Conditional Brownian motion and the boundary limits of harmonic functions,","cited_arxiv_id":null,"evidence_quote":"Originates the Doob h-transform used to construct the conditioned diffusion (27)."},{"cited_title":"Springer, 1984, vol","cited_arxiv_id":null,"evidence_quote":"Provides the classical potential-theory treatment of h-transforms behind Theorems 1 and 3."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Supplies the textbook h-transform construction for space-time diffusions used in the finite-horizon derivation."},{"cited_title":"Oksendal, Stochastic differential equations: an introduction with applications","cited_arxiv_id":null,"evidence_quote":"Girsanov theorem and SDE well-posedness used to identify the conditioned process's drift and equate it with the controlled process."},{"cited_title":"Karatzas and S","cited_arxiv_id":null,"evidence_quote":"Uniform ellipticity, positive transition density, and Feynman-Kac representation for the Dirichlet boundary value problem defining $h_T$."},{"cited_title":"Friedman, Partial differential equations of parabolic type","cited_arxiv_id":null,"evidence_quote":"Existence and uniqueness theory for the parabolic Dirichlet problems defining $h_T$."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Spectral facts for the Dirichlet eigenproblem, including the principal eigenvalue and positive eigenfunction, underlying $s_\\infty$."},{"cited_title":"Gilbarg and N","cited_arxiv_id":null,"evidence_quote":"Strict ellipticity and Sobolev regularity of the principal eigenfunction used in the infinite-horizon construction."}],"review_version":1}