Common-Witness Certificates and Sharp Feature Bounds for Counterfactual Image Auditing
Abstract
Structured image editors may satisfy every regional plausibility constraint separately although no single latent explanation is compatible with the complete output. We formulate this local-to-global failure through a common-witness grade and its witness nerve. The framework separates auditing from causal identification: shared exogeneity alone permits every coupling of the regime marginals, whereas a scientifically justified witness relation yields exactly the relation-supported couplings and hence sharp feature-level partial-identification bounds. For quasiconvex regional losses, classical Helly theory gives finite incompatibility certificates. For the labeled witness structures generated by the audit, we derive a heterogeneous action-stratified certificate, a sharp tolerant certificate for finite witness atlases, and a blocker-hypergraph repair formula. Fractional Helly theory converts dense local compatibility into a large jointly coherent subset. Simultaneous confidence regions for regime marginals provide finite-sample outer confidence bounds for the complete identified interval; Bonferroni–Clopper–Pearson bands give a nonasymptotic multinomial construction. In controlled MNIST rotations and finite paired studies on Morpho-MNIST and smallNORB, archived summaries report coherent-pair acceptance of 0.9593–0.9778, while regional-action patchworks retain local acceptance of 0.9702–0.9804 but have global acceptance of 0–0.1138. Synthetic studies exercise sharp bounds, certificate recovery, and structured computation up to feature states and regional constraints. The method audits a prespecified feature relation; it does not identify unrestricted pixel-level counterfactuals.
keywords
counterfactual images, partial identification, Helly theorem, optimal transport, finite-sample inference, infeasibility certificatesMSC
52A35, 62G15, 62P30, 68T45, 90C051 Introduction
Counterfactual image editing asks what the image of the same unit would have been under another intervention. In an augmented structural causal model (ASCM), both potential images are evaluated at the same exogenous state. That semantic convention does not reveal their joint distribution. Pan and Bareinboim show that unrestricted pixel-level counterfactuals are generally not identified from image–label samples, even when a latent causal diagram is supplied [21]. Their feature-based relaxation is therefore a bound on declared care-set quantities, not recovery of the true pixel coupling.
We study a complementary auditing failure. An edited image can satisfy each protected-region constraint with a different latent explanation while no one explanation satisfies all regions simultaneously. Formally, a witness for each region need not be one witness for every region. This global-witness gap is invisible to an audit that aggregates independent local passes.
The gap becomes scientifically informative only when the witness family is anchored outside the candidate pair. Examples include a validated renderer, paired interventions, or a design guarantee. A similarity score fitted only to unpaired images is not, by itself, cross-world information. We encode an externally justified witness family by regional costs, use their common sublevel intersections to audit an image pair, and project the resulting admissibility rule to a prespecified finite feature. The projection is then an explicit assumption in a support-only partial-identification model; it is not inferred from the causal graph.
The contribution is a certificate-to-inference pipeline:
- 1.
We turn regional costs into a graded feasibility complex. For the labeled witness structures produced by this audit, we derive exact certificate-size and repair formulas: a sharp certificate for a finite atlas with witnesses and exceptional roles, a blocker-hypergraph description of minimal explanations, and a heterogeneous action-stratified certificate with size . Classical Helly, union-of-convex-set, fractional-Helly, and tolerance results supply the underlying intersection principles [6, 2, 8, 20, 15].
- 2.
We separate this audit from identification. A boundary proposition records that shared exogeneity alone admits every coupling. Once an external relation is declared, its relation-supported couplings give the exact identified set in a stated support-only two-regime feature model. No coupling inside that set is silently selected.
- 3.
We propagate simultaneous marginal confidence regions through the coupling program to obtain finite-sample outer confidence bounds for the complete oracle interval. Controlled and finite paired studies illustrate the local-to-global separation, while synthetic programs check the predicted interval and computational behavior. We report the empirical information boundary explicitly. The accompanying public repository contains the implementation, tests, configurations, and retained outputs; external datasets must be obtained from their original sources.
The main line is
Technical extensions, full protocols, and secondary analyses are indexed in the Supplementary Material.
2 Related work and positioning
Pan and Bareinboim establish the nonidentification boundary for counterfactual image editing and propose feature-level causal bounds [21]; later work develops a disentangled causal latent editor [22]. Our object is different: an externally anchored same-witness audit followed by a support-only partial-identification analysis. It neither replaces their construction nor weakens their impossibility theorem.
Partial identification of joint potential-outcome functionals has a long history [18, 3, 26, 11, 10, 27]. Coupling and transport methods make the remaining cross-world ambiguity explicit [25, 23, 7]. The linear program and its transport dual are established tools. The contribution here is their placement after an auditable, externally sourced relation, together with a precise support-only sharpness statement.
Helly’s theorem and fractional Helly theory control intersections of convex families [6, 14, 13]. Amenta and Eckhoff–Nischke treat unions of convex components and the generalized pigeonhole mechanism [2, 8]; tolerance variants are also established [20, 15]. Our certificate theorems are exact labeled specializations for the witness structures arising in the audit, with sharpness and blocker-based repair. We do not claim that finite-feature bounding, transport duality, or Helly theory is new.
Finally, Theorem 7 is confidence-set propagation. Its importance here is the estimand: it covers the entire identified interval. Clopper–Pearson bands are conservative but nonasymptotic [5]; more efficient simultaneous multinomial regions can be substituted if their joint coverage is proved [12, 24, 19].
3 Setting and the common-witness audit
3.1 Feature target and identification boundary
Let denote an intervention and the corresponding potential image, where is a standard Borel space. We prespecify a measurable finite feature
and assume that the single-world laws are identified from randomized intervention data or another valid causal argument. Image samples alone do not generally provide this identification.
Write . Our targets are bounded linear functionals
| (1) |
Transition probabilities, average feature changes, and numerators of conditional feature queries have this form. A conditional query with a positive identified denominator is obtained by dividing the corresponding numerator by that fixed quantity.
Proposition 1 (Shared-exogeneity saturation).
Let be probability laws on a common standard Borel space. Every coupling is the joint potential-outcome law of a two-regime structural model with one exogenous variable shared across interventions.
Proof.
On the probability space with law , let be the coordinate map and set . Then satisfies and . Both worlds use the same realization of .
Proposition 1 is a boundary lemma, not a novelty claim. It shows that using the same witness twice cannot by itself overcome the causal hierarchy. Information enters only through restrictions on admissible exogenous states, response functions, or cross-world pairs.
3.2 Regional losses, grade, and nerve
Let be a declared witness space and let , , measure the violation of role by witness for the factual–candidate pair . When is fixed or clear from context, we suppress it from the notation. Thus, for example, denotes ; the same convention applies to all witness sets, grades, and tolerant quantities defined below.
The ASCM response type and the auditing witness are distinct objects unless an external scientific argument identifies them. At tolerance , put
| (2) |
Compactness and lower semicontinuity are imposed whenever an attained minimizer is used; the measurable version is given in Supplement S1.
Definition 2 (Common-witness grade and nerve).
For nonempty , define
| (3) |
The witness nerve at scale is
| (4) |
If , then . Consequently is a simplicial complex, maximal faces are maximal jointly explainable role sets, and minimal nonfaces are minimal incompatibility explanations. Under attainment, has one global witness exactly when .
To permit a prespecified number of regional exceptions, define
| (5) |
and . The integer is a within-pair role budget; it is not a probability mass of inadmissible feature pairs.
3.3 From image witnesses to a feature relation
The audit induces the existential feature projection
| (6) |
The causal model must separately assume . The relation is therefore an externally declared Layer-3 restriction, not a consequence of its definition. An existential feature projection can also be an outer relaxation of the image-level problem; it is lossless only under a feature-saturation or conditional-fiber condition (Supplement S3). Without an external anchor, the honest default is .
4 Combinatorial certificates and repair
We first give the finite-atlas result used directly by the experiments, then place its convex analogue in the classical Helly context.
4.1 Finite atlases
Theorem 3 (Exact finite-atlas tolerant certificate).
Suppose is finite with and . Then
| (7) |
Thus tolerant incompatibility has a certificate using at most roles. The bound is best possible.
Proof.
For fixed , arrange its costs in nonincreasing order, . Deleting at most roles leaves the smallest possible maximum , hence
For every , choose containing roles with its largest costs and put . Then . The st largest cost of each on equals its st largest cost on , so . Monotonicity gives the reverse inequality for every subfamily.
For sharpness, take and partition the roles into disjoint blocks of size . Fix and set for and otherwise. The complete family has tolerant grade . Every proper role set omits a role from some ; for that witness, at most retained roles have cost , so its tolerant grade is at most . Thus all roles can be necessary.
The proof is an exact consequence of the labeled finite-atlas structure. We do not claim that tolerant Helly theory is new; generic tolerance transfers and modern tolerance complexes are studied in [20, 15]. The audit-specific value of Theorem 3 is its sharp certificate and the explicit repair formula below.
Proposition 4 (Blocker duality and exact repair).
For fixed , let
Then
| (8) |
Minimal -tolerant incompatibility explanations are the inclusion-minimal -fold transversals of the bad-role hypergraph. Each has at most roles. For ,
| (9) |
Proof.
For fixed , all retained costs are at most after at most deletions exactly when at most members of belong to . This proves (8); negating it yields the multiple-transversal description. Choosing bad roles for every witness gives the size bound. Finally, is exactly the number of deletions required for witness , and minimizing over proves (9).
Rowwise order selection computes , one valid certificate, and the exact repair number in selection time (or by sorting). Enumeration of all minimal transversals can still be exponential [1].
4.2 Convex and action-stratified atlases
For a compact convex witness set of affine dimension , continuous quasiconvex role losses have convex closed sublevel sets. The classical Helly theorem then gives
| (10) |
Indeed, at the maximum local grade every sublevel sets intersect, so the complete family intersects. Equation (10) is a direct application of Helly’s theorem, not a new intersection theorem.
Many audits have a discrete requested action and continuous nuisance parameters. The resulting witness space is a labeled disjoint union rather than one convex set.
Theorem 5 (Heterogeneous action-stratified certificate).
Suppose , where is nonempty, compact, convex, and has affine dimension . Assume every role loss is continuous and quasiconvex on each stratum. Define
and . Then
| (11) |
The bound is sharp for every dimension list when .
Proof.
Let . Applying (10) within stratum gives , , with . Put . Monotonicity gives
for every . Hence and .
For sharpness, create one block of roles per stratum and take . For set
The complete block has grade one in its stratum, so the full-family grade is one. If is removed, choose stratum and vertex ; every remaining cost is zero. Thus every proper subfamily has grade zero.
Classical results for unions of convex sets already imply closely related Helly numbers [2, 8]. The content of Theorem 5 is the audit-specialized exact grade equality, heterogeneous dimension sum, and sharp labeled construction, not a claim of a fundamentally new general Helly theorem.
The witness nerve also quantifies approximate coherence. Let and let count its feasible -faces. If is the largest number of roles explained by one witness and , Kalai’s exact fractional-Helly bound gives
| (12) |
In particular, if at least an fraction of the -subsets are feasible, one witness explains at least
| (13) |
roles [14, 13, 9]. The complete proof and exact integer inversion are in Supplement S4. Dense local compatibility yields a large coherent core, not global compatibility.
If estimated losses obey , then every tolerant grade changes by at most and
| (14) |
This is a deterministic robustness statement; statistical use requires an independently justified uniform error bound. Finite-net outer approximation and exact nerve recovery away from critical grades are in Supplement S4.
5 Sharp feature bounds
For a declared relation , let
| (15) |
Equivalently, fixes row sums and fixes column sums. The transpose is needed because left multiplication by sums the original matrix down its rows, producing one total for each column.
The support-only feature model contains every two-regime feature SCM with these marginals and , with no other response function, latent-DAG, or full-image restriction.
Theorem 6 (Sharp support-only identified interval).
If is nonempty, then the sharp identified set for (1) in the support-only feature model is
| (16) |
Both endpoints and every intermediate value are attainable.
Proof.
The feasible set is a nonempty compact convex polytope and is linear, so its image is a closed interval with attained endpoints. Every model in the declared class induces a feasible coupling. Conversely, Proposition 1 realizes every feasible coupling as a shared-exogenous feature SCM, and mixtures realize all intermediate values.
Sharpness is relative to the displayed model. If a fixed full-image law, latent DAG, or nonsaturated image relation imposes further restrictions, the feature program can be only outer. This qualification prevents an audit relation from being mistaken for identification of the Pan–Bareinboim pixel counterfactual.
If the external science supports only a violation-mass budget , replace hard support by
| (17) |
The same compactness argument makes its optimized interval sharp in the corresponding budget model and nested in . The smallest feasible budget is the Hall deficiency
by max-flow/min-cut and the finite Hall–Strassen criterion [25]. These established transport results, their duals, and the Polish-space extension are collected in Supplements S2–S3. The parameter is sensitivity input, not a probability learned from unpaired images.
For sparse , the two endpoint programs use one variable per allowed edge and nonzeros in the marginal equality matrix. The relation is first checked for feasibility; infeasibility is reported rather than hidden by renormalization.
6 Finite-sample outer inference
Let be any random simultaneous confidence region for the two regime marginals satisfying
| (18) |
For a fixed known relation define the union of compatible couplings
| (19) |
Theorem 7 (Outer coverage of the complete oracle interval).
Let be the sharp interval over . If the random endpoints are measurable, then
| (20) |
If the random feasible set is empty, reporting the vacuous payoff range preserves the guarantee.
Proof.
A distribution-free concrete choice uses independent within-regime samples. If is the count in cell among observations, construct a two-sided Clopper–Pearson interval for each of the marginal cells at cellwise noncoverage . In beta-quantile notation its endpoints are
| (21) | ||||
| (22) |
Each count is marginally binomial, so Bonferroni gives simultaneous coverage despite dependence among cells within a multinomial sample [5]. Here, exact means finite-sample coverage of at least the nominal level, not equality or shortest possible width. Hoeffding bands provide a simpler alternative. The inference target is the complete oracle interval, not one selected coupling.
If a random outer relation satisfies , the same containment argument and a union bound give coverage at least when the program uses . Sample splitting alone does not establish this outer-relation property. Compatibility tests and independent finite-panel variants, with their required sampling assumptions, are in Supplement S4.
7 Audit and optimization pipeline
The operational procedure keeps its information sources separate:
- 1.
Prespecify , protected roles, allowed descendants, the witness atlas, tolerance, and any role or relation-violation budget.
- 2.
For a candidate pair compute or and return a short blocking-role certificate and exact repair count when the audit fails.
- 3.
Project the externally justified audit to a feature relation and state explicitly whether that projection is exact or outer.
- 4.
Estimate the two single-world marginals and solve the lower and upper support or budget transport programs, using simultaneous marginal bands when finite-sample coverage is required.
- 5.
Return the identified interval, outer confidence interval, and incompatibility explanation. Selecting a point inside the interval requires a separate declared decision rule.
For nonconvex neural witness spaces not represented by a verified finite atlas, a verified global optimizer would be needed; the certificates above do not validate an arbitrary local neural search.
8 Numerical studies
The numerical studies address three questions that correspond directly to the theory: whether regional plausibility can coexist with global incompatibility, whether a declared relation can sharpen feature-level bounds without concealing infeasibility or misspecification, and whether the resulting optimization and certificate computations remain tractable in structured large instances. The studies are not presented as evidence that an unrestricted pixel-level counterfactual is identified.
Status of the numerical evidence
The accompanying public repository contains the implementation, tests, configurations, retained outputs, and integrity manifests supporting the numerical studies. External datasets are not redistributed and must be obtained from their original sources. The repository documents the scope of the retained evidence and the limitations of exact historical and cross-platform replay.
8.1 Common-witness audits
Controlled rotation audit.
We first use the official MNIST training and test partitions [16] in a controlled renderer experiment. For a source image , one angle
is applied to the whole image, followed by clipped independent Gaussian measurement noise with standard deviation . The witness atlas is the same declared set of five renderer responses. For rectangular region , the discrepancy of angle is
The local and common-witness scores are
Thus permits a different angle in each region, whereas requires one angle to explain every region. A split of training images sets the order-statistic threshold and a disjoint -image split assesses relation violations. The archived protocol evaluates the official test images at three seeds and four fixed partitions ( and regions). These are twelve configurations, not independent test units: the same images recur. The principal negative control selects angles separately by region, so it is constructed to satisfy the local quantifier while violating the common-angle quantifier. Because every split uses the same specified renderer, this is held-out validation within a controlled mechanism, not independent scientific validation of a causal relation.
Separately fitted editor and witness.
The second study uses paired responses supplied by Morpho-MNIST [4] and smallNORB [17]. Morpho-MNIST provides index-matched plain, thin, and thick digits; these are benchmark-generated transformations rather than physical interventions. smallNORB provides physical toy objects photographed under factorially varied pose and illumination. Lighting is paired with lightings and , holding object, pose, and camera fixed. These are matched photographs, not observations of the same stochastic unit in two counterfactual worlds.
An action-conditional latent-residual editor is fitted on units disjoint from a separate PCA–ridge witness. The editor is an experimental vehicle rather than a claimed architectural contribution. The witness divides each image into a fixed grid and normalizes each regional discrepancy by an action-specific held-out threshold . For normalized costs , the relevant scores are
A strictly positive is required; the protocol uses a positive calibration quantile, and any zero quantile would require a positive floor fixed before evaluation. A score at most one is accepted. The free score asks whether some declared action explains the complete image; only the requested-action score tests compliance with the requested edit. The negative control alternates paired actions across the sixteen regions. It can therefore be locally plausible even though no single action explains the image.
The relation panel contains Morpho-MNIST base digits and ten smallNORB physical objects. The editor evaluation uses a disjoint Morpho-MNIST base digits and fifteen smallNORB physical objects, with three prespecified editor seeds. Repeated actions and views are dependent measurements of the same base digit or object and are not counted as new independent units. In particular, the smallNORB threshold was calibrated from only five physical objects and is an empirical rule, not a distribution-free conformal guarantee.
| Study | Evaluation unit | Coherent | Patch local | Patch global | AUROC |
|---|---|---|---|---|---|
| MNIST rotations | /setting | – | – | – | – |
| Morpho-MNIST | digits | ||||
| smallNORB | objects |
Table 1 shows the intended local-to-global separation in all three studies. In the controlled renderer, patchworks retain approximately the same local acceptance as coherent pairs but almost never admit one global angle. The learned-witness study shows the same qualitative separation, although the Morpho-MNIST free-action global acceptance of is materially above zero. On the disjoint editor sets, the conditional editor’s archived mean whole-image SSIM is versus for conditional ridge on Morpho-MNIST, and versus on smallNORB. We report the corresponding improvements only to appropriate precision, and : the latter is practically very small.
The smallNORB aggregate also conceals important object-level uncertainty. Requested-action acceptance ranges from to across ten objects. Zero global patchwork acceptances among ten objects has one-sided Clopper–Pearson upper limit . Consequently, the reported AUROC supports finite-panel separation of the constructed control but does not establish population-perfect detection or a population patchwork acceptance below .
8.2 Sharp bounds and finite-sample outer inference
A three-state synthetic feature provides a direct numerical check of the support-constrained coupling program. With only the two regime marginals, the sharp target interval is . Imposing the declared one-step relation narrows it to . A misspecification control places of the true coupling mass outside that relation, and the constrained interval then fails to cover the true target. The negative control is essential: narrowing is created by the added relation, not by the observed marginals alone.
For finite-sample inference, independent samples from each regime are drawn at
with repetitions per sample size. The archived Hoeffding outer intervals cover the complete oracle identified interval in all repetitions, with mean width decreasing from to . A later analysis applies the exact Bonferroni–Clopper–Pearson construction in (21)–(22) to the same archived cell counts. Its reported mean widths decrease from to , reductions of – relative to Hoeffding, and all intervals again cover. These successes are an implementation check under the stated simulation law, not evidence of exact nominal calibration; the coverage guarantee follows from the theorem. The exact-band comparison is post-confirmatory and descriptive because it was specified after the Hoeffding outcomes had been inspected.
The controlled audit-to-bound panel also records a necessary negative result. It fixes ten images per digit, for units, and the raw witness relation contains of the candidate pairs. The hard-support transport program is infeasible and is reported as such; no renormalization or silent relaxation is used. With the predeclared empirical violation budget , the archived interval is , compared with without the image relation, and contains the hidden paired target . However, balancing the panel by digit violates the i.i.d. premise of the intended pooled binomial guarantee. A post-hoc stratified sensitivity calculation uses and gives , also containing . Neither relaxed result is a confirmatory confidence statement; a new independent panel with the stratified procedure fixed in advance would be required.
8.3 Structured computational checks
The archived computations use sparse edge variables for banded transport and short dual certificates for repeated-simplex minimax instances. These tests check the implementations against known optima and residual conditions; they do not claim comparable scaling for dense arbitrary relations, face enumeration, or nonconvex neural witness optimization.
| Structured problem | Largest instance | Representation | Time (s) |
|---|---|---|---|
| Sparse coupling | states | edges | |
| Affine minimax, | roles | -role certificate | |
| Affine minimax, | roles | -role certificate | |
| Affine minimax, | roles | -role certificate | |
| Helly-tight | roles | dimension | |
| Finite-atlas sharpness | roles | proper faces |
All archived scaling cases are reported as successful in seconds total with peak resident memory GiB. At states, sparse transport replaces dense state pairs by edge variables; the reported marginal residuals are below . Across the affine cases, the largest reported primal, stationarity, or duality error is . Constructed leave-one-out atlases with accept every nonempty proper role set and reject the full set, attaining the finite-atlas certificate bound. These are numerical verification and structured-scaling results, not an empirical claim about naturally occurring high-order image obstructions.
8.4 Empirical scope
The experiments validate the declared computations and local-to-global failure mode on controlled or finite paired response families. They do not establish the scientific correctness of an arbitrary relation, identify an unrestricted counterfactual image, or infer a joint multi-regime image law. Morpho-MNIST is synthetic, and smallNORB has only ten physical objects in the relation panel. The reported large-state computations rely on supplied sparse or repeated structure.
9 Scope, information boundary, and limitations
We first clarify the scope of the results. Unrestricted pixel-level counterfactuals are generally not identified from unpaired regime marginals. Accordingly, the framework targets sharp bounds for prespecified finite-dimensional image features under a declared support restriction. This is the identified object of the analysis rather than an approximation to an otherwise identified pixel-level counterfactual.
The witness atlas and the cross-world relation are additional scientific inputs, not consequences of the observed regime marginals. The witness atlas determines the coherence question being audited, whereas the relation determines the admissible feature couplings used for partial identification. If either is misspecified, the audit may reject coherent pairs or the identified interval may exclude the true target. Sample splitting can assess empirical performance but cannot by itself establish the causal validity of these inputs. Likewise, violation budgets are sensitivity parameters unless they are independently calibrated.
A further information boundary arises from feature projection. Projecting an image-level relation onto a coarse feature space can discard image-level restrictions. The feature-level and image-level analyses coincide only under the feature-saturation or conditional-fiber conditions stated in the Supplementary Material.
The current experiments provide controlled evaluations on MNIST, Morpho-MNIST, and smallNORB, together with synthetic and computational studies. They validate the predicted local–global separation, sharp-bound calculations, finite-sample coverage, and structured computational scaling in these settings. Evaluation on broader natural-image domains and empirical validation of the multi-regime extension are left for future work.
10 Conclusion
Local regional plausibility need not imply one globally coherent counterfactual explanation. The common-witness grade records this distinction as a feasibility complex. Finite and action-stratified witness structures yield short exact certificates and repair counts; an externally justified feature relation then narrows, but does not select within, the coupling of the regime marginals. Optimizing over all compatible couplings gives sharp feature bounds in the stated support-only model, and simultaneous marginal confidence regions give finite-sample outer coverage of the complete oracle interval. The resulting pipeline is mathematically explicit about where information enters and where ambiguity remains. Its validity in a new application rests on prespecification, external validation of the witness relation, and reproducible evidence at the correct independent unit.
Code and data availability
The implementation code, experiment runners, tests, protocols, retained aggregate outputs, and reproduction instructions are available here. External datasets are not redistributed and must be obtained from the original sources cited in the Supplementary Material. Documented reproduction limitations are provided in the repository.
References
- [1] (2003) On the maximum feasible subsystem problem, IISs and IIS-hypergraphs. Mathematical Programming 95 (3), pp. 533–554. External Links: Document Cited by: §4.1.
- [2] (1996) A short proof of an interesting helly-type theorem. Discrete & Computational Geometry 15 (4), pp. 423–427. External Links: Document Cited by: item 1, §2, §4.2.
- [3] (1997) Bounds on treatment effects from studies with imperfect compliance. Journal of the American Statistical Association 92 (439), pp. 1171–1176. External Links: Document Cited by: §2.
- [4] (2019) Morpho-MNIST: quantitative assessment and diagnostics for representation learning. Journal of Machine Learning Research 20 (178), pp. 1–29. External Links: Link Cited by: §8.1.
- [5] (1934) The use of confidence or fiducial limits illustrated in the case of the binomial. Biometrika 26 (4), pp. 404–413. External Links: Document Cited by: §2, §6.
- [6] (1963) Helly’s theorem and its relatives. In Convexity, Proceedings of Symposia in Pure Mathematics, Vol. 7, pp. 101–180. Cited by: item 1, §2.
- [7] (2024) Transport-based counterfactual models. Journal of Machine Learning Research 25 (136), pp. 1–59. External Links: Link Cited by: §2.
- [8] (2009) Morris’s pigeonhole principle and the helly theorem for unions of convex sets. Bulletin of the London Mathematical Society 41 (4), pp. 577–588. External Links: Document Cited by: item 1, §2, §4.2.
- [9] (1985) An upper-bound theorem for families of convex sets. Geometriae Dedicata 19 (2), pp. 217–227. External Links: Document Cited by: §4.2.
- [10] (2017) Partial identification of functionals of the joint distribution of potential outcomes. Journal of Econometrics 197 (1), pp. 42–59. External Links: Document Cited by: §2.
- [11] (2010) Sharp bounds on the distribution of treatment effects and their statistical inference. Econometric Theory 26 (3), pp. 931–951. External Links: Document Cited by: §2.
- [12] (1965) On simultaneous confidence intervals for multinomial proportions. Technometrics 7 (2), pp. 247–254. External Links: Document Cited by: §2.
- [13] (1984) Intersection patterns of convex sets. Israel Journal of Mathematics 48 (2–3), pp. 161–174. External Links: Document Cited by: §2, §4.2.
- [14] (1979) A problem of geometry in . Proceedings of the American Mathematical Society 75 (2), pp. 284–288. External Links: Document Cited by: §2, §4.2.
- [15] (2023) Leray numbers of tolerance complexes. Combinatorica 43, pp. 985–1006. External Links: Document Cited by: item 1, §2, §4.1.
- [16] (1998) Gradient-based learning applied to document recognition. Proceedings of the IEEE 86 (11), pp. 2278–2324. External Links: Document Cited by: §8.1.
- [17] (2004) Learning methods for generic object recognition with invariance to pose and lighting. In Proceedings of the 2004 IEEE Computer Society Conference on Computer Vision and Pattern Recognition, Vol. 2, pp. 97–104. External Links: Document Cited by: §8.1.
- [18] (1990) Nonparametric bounds on treatment effects. American Economic Review 80 (2), pp. 319–323. Cited by: §2.
- [19] (2000) Constructing two-sided simultaneous confidence intervals for multinomial proportions for small counts in a large number of cells. Journal of Statistical Software 5 (6), pp. 1–24. External Links: Document Cited by: §2.
- [20] (2011) Tolerance in helly-type theorems. Discrete & Computational Geometry 45 (2), pp. 348–357. External Links: Document Cited by: item 1, §2, §4.1.
- [21] (2024) Counterfactual image editing. In Proceedings of the 41st International Conference on Machine Learning, Proceedings of Machine Learning Research, Vol. 235, pp. 39087–39101. External Links: Link Cited by: §1, §2.
- [22] (2025) Counterfactual image editing with disentangled causal latent space. In Advances in Neural Information Processing Systems, Vol. 38. External Links: Link Cited by: §2.
- [23] (1998) Mass transportation problems, volume i: theory. Springer, New York. External Links: Document Cited by: §2.
- [24] (1995) Simultaneous confidence intervals and sample size determination for multinomial proportions. Journal of the American Statistical Association 90 (429), pp. 366–369. External Links: Document Cited by: §2.
- [25] (1965) The existence of probability measures with given marginals. Annals of Mathematical Statistics 36 (2), pp. 423–439. External Links: Document Cited by: §2, §5.
- [26] (2000) Probabilities of causation: bounds and identification. Annals of Mathematics and Artificial Intelligence 28, pp. 287–313. External Links: Document Cited by: §2.
- [27] (2022) Partial counterfactual identification from observational and experimental data. In Proceedings of the 39th International Conference on Machine Learning, Proceedings of Machine Learning Research, Vol. 162, pp. 26548–26558. External Links: Link Cited by: §2.