🤖 AI Summary
This work formalizes causal reasoning within the framework of toposes, addressing the rigorous verification of interventions, mechanism grafting, and an intuitionistic do-calculus. Leveraging Cubical Agda, it models causal worlds as presheaf categories (1-toposes), defines interventions via characteristic maps of subobject classifiers, and conducts reasoning in the internal intuitionistic language. The main contributions include the first machine-verified core of a topos-theoretic causal model; a correction of the missing Lawvere–Tierney axiom by introducing the double-negation topology; the identification of a novel phenomenon termed the “contextuality barrier”; a proof that interventions and Pearl’s rules are j-stable under arbitrary topologies; and the establishment of an equivalence between counterfactual transportability and j-stability.
📝 Abstract
Topos causal models recast causal inference inside a topos: a causal world is a presheaf, an intervention is a characteristic map into the subobject classifier, and reasoning is carried out in the intuitionistic internal language. We give the first machine-checked account of this 1-topos core, in Cubical Agda, over a previously verified probability monad and do-calculus. We build the classifier of sieves and realise the intervention $\mathrm{do}(X := x_0)$ as a characteristic map with its classification theorem; prove the sheaf gluing of independent mechanisms, which the source asserts but never proves; and machine-check the Kripke-Joyal forcing clauses of the internal language. In the modal layer we find and repair a gap: the three standard Lawvere-Tierney axioms do not force a closure operator. With the missing law restored, we exhibit the double-negation topology as a concrete instance and show that interventions and Pearl's rules are stable under every topology. Transportability of a counterfactual across a cover of regimes then coincides with this $j$-stability, understood as invariance across the cover. We further add a phenomenon the programme does not consider: a machine-checked contextuality obstruction, where pairwise-consistent local data admit no global model. The development assumes no axioms and typechecks under Agda's --safe flag, with the ordered field discharged concretely at $\mathbb{Q}$; the scope is the presheaf (1-topos) fragment, with type-level sheafification and the directed lift left to future work.