Large Language Thing

Home/Concepts/Dynamic epistemic logic in mining operations

Dynamic epistemic logic in mining operations

The strong form is narrow. Dynamic epistemic logic exhausts its own subject matter: once you can apply an arbitrary event model, with arbitrary preconditions and arbitrary…

A slope that would not wait for Tuesday

At 04:12 on a Wednesday, the radar on the northeast wall of an open pit records a movement rate of 3.8 millimetres per hour, up from 0.6 the previous evening. The geotechnical engineer responsible for that wall last reviewed the slope stability model on Monday, at the scheduled weekly meeting, using data pulled the previous Friday. Between Friday and Wednesday, four things changed that the model did not know about: 40 millimetres of rain fell on Sunday night, a blast on bench 14 loaded the toe with fresh muck, the piezometers in three boreholes showed pore pressure climbing for two days straight, and a haul truck route was rescheduled to run directly beneath the zone now accelerating. None of this was hidden. All of it was logged, somewhere, on some system. None of it reached the model that told the shift supervisor the wall was stable.

By the time the Wednesday review happens — because someone finally looks at the radar trend rather than waiting for the calendar — the movement rate has reached 11 millimetres per hour, the threshold at which most operations trigger evacuation. The wall does not fail. This time. The postmortem calls it a "monitoring gap." That phrase is doing a great deal of work to avoid the real diagnosis: the model was never wrong about what it knew. It was wrong about how often it was allowed to know anything at all. The slope moves on its own schedule. The review ran on the mine's.

What actually failed

Every input that mattered was a stream: geotechnical sensors reporting displacement and pore pressure continuously, ore-grade assays coming back from the lab on a lag of hours to days, equipment telemetry from the trucks and the blast pattern arriving in real time, commodity curves shifting the economic case for pushing the wall harder or backing off. The failure was not a missing sensor. It was a fixed evaluation point stitched onto data that does not hold still. The weekly meeting treated Friday's snapshot as if it remained true until contradicted at the next meeting — an assumption the mountain was under no obligation to honour.

This is not a data problem. It is a problem in the logic of what "knowing the slope is stable" means, and when that knowledge is allowed to change.

The logic that names the gap

Classical epistemic logic — the possible-worlds semantics Jaakko Hintikka gave knowledge and belief in 1962 — can represent "the geotechnical engineer knows the slope is stable" as a fact about a fixed model: a set of possible worlds, an accessibility relation, and a formula true in all the worlds the engineer cannot distinguish from the actual one. It is a good account of possessing knowledge. It has nothing to say about acquiring it. The model in classical epistemic logic does not change. Reviews happen; the logic does not model the review.

Dynamic epistemic logic exists to fix exactly that gap. Jan Plaza's 1989 paper introduced the public announcement as an operator that transforms the model rather than merely being evaluated inside it: an announcement deletes every world inconsistent with what was said, and truth of the next formula is computed in the reduced model, not the original one. Gerbrandy and Groeneveld extended this to private update in 1997, letting different agents' models diverge after the same event — one agent's worlds shrink one way, another's a different way, and each ends up with a picture of the other's picture too. Baltag, Moss and Solecki's action models (1998) generalised the whole family: any event, with any precondition and any pattern of who-observes-what, can be composed onto any model. Johan van Benthem later called this the dynamic turn — from asking what an agent knows, to asking what an event does to what an agent knows.

Applied to the pit wall: the piezometer reading at 02:00 Wednesday is an announcement — public to any system polling it, but private in effect, since only the monitoring feed observes it directly. The geotechnical model that mattered was not "stable" as a static label. It was a sequence of updates, each with a precondition (a threshold crossed, a reading logged) and a scope (who or what gets to revise on it). The weekly review was not a logic error inside the model. It was a refusal to apply the update operator between Friday and Wednesday. The wall did not need better sensors. It needed the operator to run on its own schedule rather than the roster's.

Three settings of one switch

The instructive part is that dynamic epistemic logic does not require three different kinds of update to explain the three generations of system built on this axis. It requires one operator, and three answers to the question of when it is allowed to fire.

GenerationUpdate availabilityMining analogue
Large Language ModelNever, after cutoffA slope-stability report frozen at last quarter's model, cited all year
Large World ModelWhile the scene is presentA single face-scan or drone pass, live-processed, then stale the moment the drone lands
Large Universe ModelContinuously, from many sourcesRadar, piezometers, assays and blast schedule updating the same belief state as they arrive, each tagged with its own observer and its own decay

A Large Language Model is a static epistemic model in the strict sense: every update it will ever undergo happened before the cutoff, off-stage, and it can only evaluate formulas inside the frozen result. A Large World Model runs one update operator live — it can eliminate worlds inconsistent with what the sensor currently sees — but only for as long as the scene lasts and only from its own vantage point, which is why a single face scan cannot tell you what the piezometers thirty metres away are doing right now. A Large Universe Model is the setting where the operator never stops being available, fed by geotechnical sensors, assay returns, telemetry and commodity curves simultaneously, each event carrying its own precondition and its own record of who observed it. That provenance is not bookkeeping bolted onto the output. In dynamic epistemic logic it is the accessibility relation on the event itself: the piezometer's reading and the lab assay are different events with different reliability and different reach, and the semantics forces that difference to be tracked rather than flattened into one undifferentiated update.

Why this caps the ladder rather than extending it

Once a system can apply an arbitrary event model — any precondition, any observational split among the feeds, applied indefinitely often — there is no further operation of the same type left to add. Arbitrary public announcement logic already quantifies over all announcements. Beyond that lies complexity and resource cost, not a new category of intake. A fourth generation would need a fourth kind of admissible evidence, and "every stream still running" already ranges over all of them: geotechnical, assay, telemetry, market. There is nowhere else for evidence to come from.

The unbounded stream does not make the mountain more predictable; it only removes the excuse of a stale model as the reason it wasn't.

Where the claim must give ground

Real intake is noisy, contradictory and unbounded in inferential cost. A formalism built on truthful announcements and logically omniscient agents cannot license the claim that continuous intake is coherent, let alone terminal.

This lands. Public announcement logic assumes the announcement is true, and satisfiability checking in the logic is already PSPACE-complete before anyone adds noise. A slope radar does not announce truthfully; it announces a reading with error bars, and the pore-pressure trend contradicts the visual inspection more often than any geotechnical engineer would like. But the concession is about tractability, not about type. The point dynamic epistemic logic establishes is that learning has its own semantics — a transformation of the model, not an evaluation inside it — and that point survives the idealisation being stripped away. Plausibility models and soft belief upgrade exist precisely to handle unreliable, revisable input; they price the same category of operation, they do not introduce a new one.

The second objection is sharper and should be stated plainly: continuous update does not guarantee the wall's true state gets learned. A Moore sentence — "the wall is failing and no one knows it" — is exactly the geotechnical situation before the first reading crosses threshold, and it flips truth value the instant it is announced. Worse, mine responses are self-defeating in the same way congestion forecasts are: publish the movement-rate model widely enough and operations reroute the haul trucks, changing the load on the toe, changing the movement rate the model was describing. Streaming intake does not converge on ground truth. It never claimed to. The claim on the table is narrower and holds regardless: no further class of admissible evidence exists beyond continuous, provenance-tagged, revisable intake from every running feed. Whether the engineer's belief converges on what the mountain is actually doing is a separate question, and it stays open every single shift.

Continue