This document provides an indicative state of progress on formal guarantees for the Axiom.jl next-generation ML framework as of 2026-08-14. It consolidates information from:
-
EXPLAINME.adoc— Implementation evidence for README claims -
README.md— Project overview (if exists) -
src/layers/,src/dsl/,src/verification/,src/proof_export/— Core implementation
| Component | Status | Details |
|---|---|---|
Neural network layers |
✅ LANDED (tested) |
Dense, Conv2d, Sequential, Chain, Residual, BatchNorm, LayerNorm, Dropout, Pool layers |
Invertible layers |
✅ LANDED (tested) |
CouplingLayer, ActNorm, Invertible1x1Conv, RevBlock, NormalizingFlow |
Activation functions |
✅ LANDED |
relu, sigmoid, tanh, softmax, gelu, leaky_relu (and in-place variants) |
Compile-time shape verification |
✅ PARTIAL |
|
|
✅ LANDED |
Runtime assertion checking |
|
✅ PARTIAL |
Julia-native via SMTLib.jl; Zig SMT runner optional |
Verification properties |
✅ LANDED |
ValidProbabilities, FiniteOutput, NoNaN, NoInf |
Verification checker |
✅ LANDED |
|
Proof certificates |
✅ LANDED |
ProofCertificate, generate_certificate, save_certificate, load_certificate |
Verification telemetry |
✅ LANDED |
reset_verification_telemetry!, verification_result_telemetry, verification_telemetry_report |
REST serving |
✅ LANDED |
serve_rest(model; host, port, background) |
GraphQL serving |
✅ LANDED |
serve_graphql(model; …) |
gRPC serving |
✅ LANDED |
serve_grpc(model; …), generate_grpc_proto |
PyTorch import |
✅ LANDED |
from_pytorch (checkpoint import and JSON descriptor) |
ONNX export |
✅ LANDED |
to_onnx (Sequential/Pipeline models) |
Zig backend |
Zig SIMD/multi-threading backend not yet wired |
|
SMT runner (Zig) |
Optional via AXIOM_SMT_RUNNER=zig and AXIOM_ZIG_LIB |
|
Proof assistant export |
✅ LANDED |
export_lean, export_coq, export_isabelle, proof_obligation_manifest, reconcile_proof_bundle |
Overall: Axiom.jl is a production-ready ML framework with compile-time
shape verification (partial), verification properties and certificates, and
multiple serving backends. The @axiom DSL and @prove verification are
implemented but not yet complete — the Julia-native backend works, and the
Zig SMT runner is available as an option.
| Layer Type | Implementation | Status | Evidence |
|---|---|---|---|
Dense |
Forward pass with optional bias and activation |
✅ Landed |
|
Conv2d |
Correct output spatial dimensions |
✅ Landed |
|
Sequential |
Linear chain of layers |
✅ Landed |
|
Chain |
Flexible layer composition |
✅ Landed |
Core composition mechanism |
Residual |
Skip connection wrapper |
✅ Landed |
Residual blocks |
BatchNorm |
Batch normalization |
✅ Landed |
|
LayerNorm |
Layer normalization |
✅ Landed |
|
Dropout |
Dropout with training/inference modes |
✅ Landed |
|
MaxPool2d |
2D max pooling |
✅ Landed |
|
AvgPool2d |
2D average pooling |
✅ Landed |
|
GlobalAvgPool |
Global average pooling |
✅ Landed |
|
Flatten |
Dimension flattening |
✅ Landed |
|
Honest assessment: All standard layers are implemented and tested. The Conv2d spatial dimension computation is explicitly verified in tests.
| Layer Type | Implementation | Status | Evidence |
|---|---|---|---|
CouplingLayer |
Affine coupling for normalizing flows |
✅ Landed |
|
ActNorm |
Activation normalization |
✅ Landed |
Invertible normalization |
Invertible1x1Conv |
Invertible 1x1 convolution |
✅ Landed |
Invertible convolution |
RevBlock |
Reversible block |
✅ Landed |
Reversible architecture |
NormalizingFlow |
Flow composition |
✅ Landed |
Flow model wrapper |
Each invertible layer provides:
- forward — forward pass
- inverse — inverse transformation
- log_abs_det_jacobian — log determinant of Jacobian
- forward_and_log_det — combined forward + Jacobian computation
| Component | What it does | Status | Evidence |
|---|---|---|---|
|
Defines models with shape annotations |
✅ Landed |
|
Shape-mismatch detection |
Catches dimension mismatches at macro-expansion time |
✅ Landed |
Pattern-based detection |
Conv → Dense mismatch |
Example from README works |
✅ Landed |
Catches incompatible layer composition |
Runtime assertion |
|
✅ Landed |
|
Honest caveat: The "compile time" verification happens at macro-expansion time, not Julia’s actual compile pass. For the Conv → Dense mismatch example, the error is raised when the model is constructed, not when the file is parsed. This is earlier than a runtime crash but is not type-level verification.
Comparison to PyTorch: The README’s PyTorch comparison is directionally accurate — Axiom.jl catches shape errors earlier than PyTorch’s runtime errors, but it’s not a full dependent type system.
| Component | What it does | Status | Evidence |
|---|---|---|---|
Property types |
ValidProbabilities, FiniteOutput, NoNaN, NoInf |
✅ Landed |
|
Verification checker |
|
✅ Landed |
|
VerificationResult |
Result with passed::Bool |
✅ Landed |
Return type with status |
Proof certificates |
ProofCertificate type and operations |
✅ Landed |
|
Telemetry system |
reset!, verification_result_telemetry, verification_telemetry_report |
✅ Landed |
|
Verification workflow:
1. Define properties to check (ValidProbabilities, FiniteOutput, NoNaN, NoInf)
2. Run verify(model, properties, data)
3. Get VerificationResult with passed status
4. Optionally generate and save ProofCertificate
| Function | Purpose | Status | Evidence |
|---|---|---|---|
export_lean |
Export proof obligations to Lean |
✅ Landed |
|
export_coq |
Export proof obligations to Coq |
✅ Landed |
|
export_isabelle |
Export proof obligations to Isabelle |
✅ Landed |
|
proof_obligation_manifest |
Generate manifest of proof obligations |
✅ Landed |
|
reconcile_proof_bundle |
Reconcile proof bundles |
✅ Landed |
|
Purpose: The proof export system allows Axiom.jl models to be verified in external proof assistants (Lean, Coq, Isabelle). This enables formal verification of ML model properties beyond what Julia can express.
| API | Implementation | Status | Evidence |
|---|---|---|---|
REST |
|
✅ Landed |
|
GraphQL |
|
✅ Landed |
|
gRPC |
|
✅ Landed |
|
Note: HTTP is a hard dependency in Project.toml. Tests verify the
serving functions exist and that gRPC proto generation produces valid .proto files.
| Feature | Implementation | Status | Evidence |
|---|---|---|---|
PyTorch import |
|
✅ Landed |
|
ONNX export |
|
✅ Landed |
|
PyCall dependency |
Optional weak dependency extension (AxiomPyTorchExt) |
✅ Landed |
Declared as weak dependency |
| Component | What it provides | Status | Evidence |
|---|---|---|---|
SIMD operations |
Hand-vectorised assembly kernels |
Design intent, not yet implemented |
|
Multi-threading |
Parallel execution backend |
Via Zig FFI |
|
SMT runner |
External SMT solver via Zig |
Optional via AXIOM_SMT_RUNNER=zig and AXIOM_ZIG_LIB |
Honest caveat: The vector_add_asm function currently uses Julia’s
native + dispatch rather than inline assembly. The name anticipates
LLVM intrinsic injection once the Zig FFI backend is wired.
| Path | Purpose | Status |
|---|---|---|
|
Module entry point |
✅ Landed — exports all public API |
|
Neural network layer implementations |
✅ Landed — dense.jl, conv.jl, batchnorm.jl, layernorm.jl, dropout.jl, pool.jl, flatten.jl, coupling.jl |
|
Domain-specific language |
✅ Landed — axiom_macro.jl, ensure.jl, prove.jl |
|
Verification system |
✅ Landed — properties.jl, checker.jl, certificates.jl, telemetry.jl |
|
Proof assistant export |
✅ Landed — Lean, Coq, Isabelle export |
|
Serving APIs |
✅ Landed — REST, GraphQL, gRPC |
|
Framework interoperability |
✅ Landed — PyTorch, ONNX |
|
Implementation evidence |
✅ Current |
|
Architecture overview |
✅ Current |
|
Contribution guidelines |
✅ Current |
|
Change history |
✅ Current |
| Action | Command |
|---|---|
Instantiate |
|
Precompile |
|
Run tests |
|
Import |
|
Define model |
|
Verify shapes |
Shape mismatches caught at model construction |
Verify properties |
|
Export to ONNX |
|
Serve REST |
|
Expected Results: - Package instantiates successfully - Package precompiles without errors - All tests pass - Shape verification catches dimension mismatches - Verification properties check correctly - Serving APIs work as documented
| Gap | Impact | Resolution |
|---|---|---|
|
Not true type-level verification |
Macro-expansion time, not Julia compile time |
Zig backend |
SIMD kernels not yet hand-vectorised |
Zig FFI backend wiring pending |
TensorFlow integration |
Not implemented |
Only PyTorch import currently |
Framework maturity |
Newer framework vs PyTorch |
Growing ecosystem |
Status: ✅ UPSTREAM DEPENDENCY
Axiom.jl uses SMTLib.jl for the @prove verification system:
| Integration | Purpose | Status |
|---|---|---|
Julia-native SMT |
|
✅ Landed |
Zig SMT runner |
Optional external SMT solver via Zig |
|
Solver support |
Z3, CVC5, Yices, MathSAT auto-detected |
✅ Landed (via SMTLib.jl) |
Relationship: SMTLib.jl is the symbolic verification tier for the
ecosystem. Axiom.jl consumes it for @prove verification.
| Project | Integration | Status |
|---|---|---|
SMTLib.jl |
Symbolic verification backend |
✅ Upstream dependency |
PolyglotFormalisms.jl |
Proposed cross-language semantic equivalence |
✅ Planned |
ProvenCrypto.jl |
Verification certificates |
✅ Planned |
Axiology.jl |
Value framework for ML model checking |
✅ Downstream integration |
| Aspect | Status | Confidence |
|---|---|---|
Neural network layers |
✅ Landed |
High — all standard layers implemented and tested |
Invertible layers |
✅ Landed |
High — normalizing flow components complete |
Activation functions |
✅ Landed |
High — all common activations supported |
|
✅ Landed |
Medium — macro-expansion time, not type-level |
|
✅ Landed |
High — runtime checking works |
|
✅ Partial |
Medium — Julia-native works, Zig runner optional |
Verification properties |
✅ Landed |
High — ValidProbabilities, FiniteOutput, NoNaN, NoInf |
Verification checker |
✅ Landed |
High — verify() function works |
Proof certificates |
✅ Landed |
High — certificate generation and persistence |
Proof export |
✅ Landed |
High — Lean, Coq, Isabelle export |
REST/GraphQL/gRPC |
✅ Landed |
High — all serving APIs implemented |
PyTorch import |
✅ Landed |
High — checkpoint and JSON descriptor import |
ONNX export |
✅ Landed |
High — model export works |
Zig backend |
Low — SIMD kernels not yet hand-vectorised |
|
Documentation accuracy |
✅ Current |
High — EXPLAINME provides honest caveats |
Honest headline: Axiom.jl is a production-ready ML framework with
compile-time shape verification (at macro-expansion time), verification
properties and certificates, and multiple serving backends. The core
functionality is landed and tested. The @axiom DSL provides earlier
error detection than PyTorch, though not full dependent types. Proof export
to Lean/Coq/Isabelle enables external formal verification.
-
EXPLAINME.adoc — Implementation evidence (authoritative)
-
ARCHITECTURE.md — Architecture overview
-
CONTRIBUTING.md — Contribution guidelines
-
CHANGELOG.adoc — Change history
-
src/Axiom.jl — Module entry point
-
src/layers/ — Neural network layer implementations
-
src/dsl/ — Domain-specific language (@axiom, @ensure, @prove)
-
src/verification/ — Verification system
-
src/proof_export.jl — Proof assistant export
-
src/serving/api.jl — Serving APIs
-
src/integrations/interop.jl — Framework interoperability
-
SMTLib.jl — Upstream symbolic verification backend
-
proven — Upstream formal proof library
-
Axiology.jl — Downstream value framework
-
PolyglotFormalisms.jl — Downstream cross-language verification