← All papers
First page of FloatLib: Verified Floating-Point Arithmetic in Lean

FloatLib: Verified Floating-Point Arithmetic in Lean

Robert Joseph George, Will Adkisson, Anima Anandkumar

cs.LO Sep 16, 2026 · v1 cs.PL
Presents FloatLib, a Lean 4 library providing verified arbitrary-precision floating-point arithmetic with machine-checked correctness and certified efficient execution.
We present FloatLib, a verified arbitrary-precision floating-point arithmetic library in Lean 4 that combines broad format coverage, machine-checked correctness, and efficient certified execution. To our knowledge, FloatLib is the first Lean library to unify IEEE binary and decimal arithmetic, arbitrary-width posits, P3109, and user-defined formats and rounding rules behind interchangeable certified software backends. Every certified backend is proved equal to a complete encoded specification, preserving signed zeros and exceptional values, while numerical theorems connect execution to real rounding, error bounds, and exactness. FloatLib combines exhaustive certified tables for small formats with verified word and limb kernels based on guard-and-sticky invariants and independently checked quotient candidates. Its posit development additionally proves standard rounding thresholds and exact quire accumulation within capacity for arbitrary widths. Across matched workloads, FloatLib achieves speedups of up to 1.46x over FLoPS and 116x over Universal, while remaining slower in some regimes such as binary arithmetic against MPFR. Independent conformance testing includes more than 102 million TestFloat evaluations with zero differences under the tested relation. We release the library, proofs, benchmarks, evaluation data, and guide as open source.

Verified numerical programs require arithmetic specifications and theorems connecting executed floating-point operations to their real-valued meaning, including rounding, error bounds, and exceptional-value behavior. Existing verified libraries lack unified coverage of diverse formats behind interchangeable certified backends.

FloatLib is structured in four layers: exact numerical representations, word and limb kernels, format models, and certified execution. It unifies IEEE binary and decimal arithmetic, arbitrary-width posits, P3109, and user-defined formats behind interchangeable certified software backends. Each certified backend is proved equal to a complete encoded specification via a run_eq_spec equality, preserving signed zeros and exceptional values, while numerical theorems connect execution to real rounding and exactness. It combines exhaustive certified tables for small formats with verified kernels using guard-and-sticky invariants and independently checked quotient candidates.

FloatLib achieves speedups up to 1.46x over FLoPS and 116x over Universal, though remaining slower than MPFR in some binary regimes. Independent conformance testing included over 102 million TestFloat evaluations with zero differences under the tested relation.

FamilyRepresentationRepresentative contract
BinaryParameterized fields, bias, exceptional encodingsIEEE-style real rounding and exactness
DecimalCoefficient and quantum; BID/DPDDatum-level arithmetic, rounding error, status
PositRegime, two exponent bits; n≥2Standard rounding; exact accumulation in 16n-bit quire
P3109Width, precision, signednessDestination projection, saturation, mixed-format
MX32 lanes with common E8M0 scaleQuantization; one-round exact dot product
Numerical families in FloatLib and representative guarantees