Appendix A. Quantales
As we in this paper advocate the use of
quantales for operations represented in HACCP’s risk matrices, in this appendix, we present a sufficiently self-contained explanation of the algebraic properties of quantales as semigroups that are join-preserving over complete lattices. For more detail on quantales, see [
35].
These algebras can also be understood as an “algebraization” of “semi-quantitative” risk estimation as proposed and generally outlined in [
3] based on arithmetic operations.
Many readers may be familiar with a wide range of algebraic structures, whereas familiarity with quantales is less common, in particular to the extent where quantales are suitable and advocated in applications involving many-valued logic and its logical operators.
As explained in
Section 4, “semi-quantification” implicitly invites the introduction of transformations of numeric values into symbolic values, where the order relation is preserved and “quantity” is replaced by “quality”. In order to understand algebraic operations and their properties from this transformation point of view, let us first note how the fundamental arithmetic operation “addition on the real line” is a binary operation ‘+’ on the set
of real numbers, i.e.,
where we obviously use the infix notation ‘
’ more than the prefix notation ‘
’.
Arithmetic multiplication ‘’ is similar, and we may note how addition logically appears to “reside between OR and AND”, whereas multiplication has an “AND-like flavour”, in the sense that “a AND b” expectedly is less true than both a and b separately, i.e., and , whereas “a OR b” expectedly is more true than both a and b separately, i.e., and .
In what follows, we define quantales as semigroups that are join-preserving over complete lattices, and we therefore, and for sake of self-containment, also include definitions of semigroups and lattices.
Semigroups, Lattices and Quantales
A
semigroup consists of a (base) set
X and an operation
that is
associative, i.e., satisfies
for all
.
Here we should note that an operator ‘∗’ not fulfilling associativity will not be able to uniquely compute ‘’ unless parentheses are included. A risk matrix indeed typically combines only two values, but the same operation or similar operations often need to combine several severities or occurrences into one overall severity or occurrence to be used in the risk matrix.
A semigroup is said to be
commutative if
for all
.
Here we may note how commutativity is quite a restrictive condition, as it disables the operation ‘∗’ to distinguish, whenever necessary, between
and
, as discussed in
Section 4.
Commutativity must be a matter of choice in a certain context for the risk matrix. If the operation is commutative, then the risk matrix is symmetric around its diagonal, and then a “very high” occurrence combined with a “very low” severity would provide the same overall risk value as compared with the situation with a “very low” occurrence combined with a “very high” severity. In some cases, a risk matrix may indeed be symmetric, but, in most case, imposing commutativity for the operator would be a restriction not complying with reality and practicability of the risk management context.
We should also recall how addition and multiplication are commutative semigroups, where e.g., ‘’ is not distinguished from ‘’.
Before introducing lattices, we may first note how in a risk matrix the ‘∗’ operation is used for combining characterizations that appear in some order, i.e., one characterization is “less than”, or “less than or equal”, to another characterization , i.e., or . In these circumstances, for a third characterization q we would at least, for expect to have and .
For quantales our requirement is slightly stronger as we require that operating with a “maximum” of a certain number of characterizations amounts to the same value as applying the maximum on operating separately with each of the characterizations, i.e., intuitively we have “a ∗ (maximum of C)”, where “C” is a set of characterizations, to be the same as “maximum for all c in C of the separate operations (a ∗ c)”, and we would require that condition to be valid also similarly for “(maximum of C) ∗ a” to be the same as “maximum for all c in C of the separate operations (c ∗ a)”. This requirement for quantales is said to mean that ‘∗’ is “join-preserving in both variables”, as defined below.
Formally, for orders between elements, a
lattice consists of binary operations ∧, called ‘meet’ (“minimum”), and ∨, called ‘join’ (“maximum”), that are, respectively, idempotent (
and
), commutative and associative, and further satisfying the absorption laws
for all
. For lattices, idempotency of ∨ and ∧ follows from the absorption laws.
A lattice indeed defines a partial order, but not always the other way around. Given a lattice, the partial order ‘≤’ is defined by if and only if , or equivalently, if and only if .
A finite lattice, i.e., a lattice with a finite base set, is a complete lattice with ⊥ as the smallest element, given the partial order generated by the lattice, and ⊤ as the largest element.
A lattice is
distributive if
for all
.
Whenever X is 2-pointed or 3-pointed, i.e., or , the chain is the only lattice.
For the 4-pointed set
, the chain and the diamond
are the only lattices.
The diamond lattice is an example that shows why we should be careful here about the understanding of “minimum” and “maximum”. From the lattice point of view, we have “1 join 2 = 3”, i.e., the “maximum” of ‘1’ and ‘2’ is not one of ‘1’ or ‘2’. Similarly, “1 meet 2 = 0”, i.e., the “minimum” of ‘1’ and ‘2’ is again not one of ‘1’ or ‘2’.
For the 5-pointed set
, there are 5 lattices, below depicted as in [
28].
For 6-pointed sets, there are 15 lattices, for 7-pointed sets, there are 53 lattices, and so on.
We are now in position to introduce the structure of a
quantale , where
is a semigroup over a complete lattice
, so that the semigroup operation is
join-preserving in both variables, i.e., satisfying
for all
and all
.
The theory of quantales uses the convention that the supremum of the empty set is the bottom element, i.e.,
, which implies the condition
for all
. In some applications, this condition may seem to be unnecessarily strong, but for the purpose of using quantales for representing characterization values in HACCP, the condition is in most cases quite suitable, as a “complete unacceptable” or “total problem” value for either occurrence or severity provides complete unacceptability or total problem in the overall risk assessment.
As a special case of a quantale, note how a distributive lattice is a quantale with the join as the semigroup operation in the risk matrix.
Quantales may be equipped with further properties. Here, we mention a few of them. For an overview of additional properties of quantales, see [
33].
A
balanced quantale is a quantale satisfying
This may seem a natural property always to be fulfilled, and in most practical cases it is indeed so, but in such situations we may simultaneously have
, for some
.
A
unital quantale is a quantale with a unit
satisfying
for all
, i.e., operating with the unit
e leaves the value of operating with
x unchanged.
As we have pointed out, the use of arithmetic operations in risk matrices limits the number of operations to one or just a few. When using quantales in risk matrices, the number of choices for operations is very large as the number of elements in the set of characterizations is allowed to be larger. There are 2 quantales on a 2-pointed set, 12 quantales on a 3-pointed set, 129 quantales on a 4-pointed set, 1852 quantales on a 5-pointed set, and 33,391 quantales on a 6-pointed set, 11,329 of which are quantales over the 6-point chain. All lattices and quantales up to 6 points are listed and shown in [
28].
Table A1 shows the number of quantales per lattice in the case of the 5-point lattices [
28].
Table A1.
Number of quantales per lattice with 5 elements.
Table A1.
Number of quantales per lattice with 5 elements.
| Lattice (♯) | Number of Quantales |
|---|
| 1 | 213 |
| 2 | 78 |
| 3 | 337 |
| 4 | 221 |
| 5 | 1003 |
As pointed out in
Section 4, units in unital quantales are candidates for being interpreted as “unknown” or “not yet known” values appearing in a risk matrix. From an application point of view, unital quantales over lattices with the unit being a sideline element may be particularly interesting. Lattice nr 13 (out of 15 6-point lattices) in [
28] has ‘not (yet) known’ as “optimistically” sidelined with the generic 5-scale.
There are 2830 quantales for the 6-point lattice nr 13. Of these, 57 are unital with the sidelined ‘not known’ as the unit, so that
for all values
x in the generic 5-scale, i.e., aggregation with unknown values is not affected or enforced by missing values.
We conclude this Appendix by showing how quantale operations define implication operators.
Given a quantale
,
right implication is for
defined as
and similarly,
left implication is for
defined as
The right and left implications appear in Galois connections as follows. We first fix an element . Then we define by , and by . Doing so will make and form a Galois connection. Similarly, if we define by , and by , then and will form a Galois connection.
In the special case when
, and the quantale is the 2-valued Boolean ‘
’ operator, then the left and right implications coincide and are the same as the Boolean implication ‘⇒’, i.e.,
Generelly, whenever a quantale is commutative, left and right implications will coincide.
Table A2 shows the left and right implications for the commutative quantale nr 6.15.9177 in [
28]. The implication matrices coincide once the right-hand side left implication matrix has been transposed.
Table A2.
Coinciding right ↘ and left ↙ implications for the commutative quantale in
Table 5.
Table A2.
Coinciding right ↘ and left ↙ implications for the commutative quantale in
Table 5.
| ↘ | 0 | 1 | 2 | 3 | 4 | 5 | ↙ | 0 | 1 | 2 | 3 | 4 | 5 |
| 0 | 5 | 5 | 5 | 5 | 5 | 5 | 0 | 5 | 0 | 0 | 0 | 0 | 0 |
| 1 | 0 | 2 | 2 | 4 | 4 | 5 | 1 | 5 | 2 | 1 | 0 | 0 | 0 |
| 2 | 0 | 1 | 2 | 3 | 4 | 5 | 2 | 5 | 2 | 2 | 0 | 0 | 0 |
| 3 | 0 | 0 | 0 | 2 | 2 | 5 | 3 | 5 | 4 | 3 | 2 | 1 | 0 |
| 4 | 0 | 0 | 0 | 1 | 2 | 5 | 4 | 5 | 4 | 4 | 2 | 2 | 0 |
| 5 | 0 | 0 | 0 | 0 | 0 | 5 | 5 | 5 | 5 | 5 | 5 | 5 | 5 |
Table A3 shows the left and right implications for the non-commutative quantale nr 6.15.8746 in [
28], and we can see that the implication matrices do not coincide.
In
Table A3 we see e.g., how
whereas
reflecting a situation due to the underlying quantale being non-commutative.
Table A3.
Coinciding right ↘ and left ↙ implications for the non-commutative quantale in
Table 6.
Table A3.
Coinciding right ↘ and left ↙ implications for the non-commutative quantale in
Table 6.
| ↘ | 0 | 1 | 2 | 3 | 4 | 5 | ↙ | 0 | 1 | 2 | 3 | 4 | 5 |
| 0 | 5 | 5 | 5 | 5 | 5 | 5 | 0 | 5 | 0 | 0 | 0 | 0 | 0 |
| 1 | 0 | 3 | 3 | 3 | 4 | 5 | 1 | 5 | 4 | 1 | 1 | 0 | 0 |
| 2 | 0 | 1 | 3 | 3 | 4 | 5 | 2 | 5 | 4 | 3 | 2 | 0 | 0 |
| 3 | 0 | 1 | 2 | 3 | 4 | 5 | 3 | 5 | 4 | 3 | 3 | 0 | 0 |
| 4 | 0 | 1 | 1 | 1 | 4 | 5 | 4 | 5 | 4 | 4 | 4 | 4 | 0 |
| 5 | 0 | 0 | 0 | 0 | 0 | 5 | 5 | 5 | 5 | 5 | 5 | 5 | 5 |
Appendix B. Probability Theory
Risk, as we have seen, is not mathematically well-defined, but rather generally described as something undesirable, for which we want to know the probability of its occurrence, where related events include risk sources. In [
21], risk is defined as an effect of uncertainty on objectives, where “effect” is understood as a deviation. From functional modeling point of view, risk sources and hazards need not be distinguished, where hazards in [
21] are defined as sources of potential harm.
Whereas risk is allowed to be vaguely defined, probability is in this paper understood exclusively as in probability theory-based on strict mathematical notations, where a probability measure is a function that maps events to values in the unit interval, and where events are elements in a -algebra over a sample space.
Uncertainty is a further concept used within probability, not to be confused with the use of uncertainty in many-valued logic, where “degree of uncertainty” is synonymous with “degree of truth”, i.e., a value
q in a quantale
Q can be called a “degree of uncertainty”. In [
16], uncertainty (within probability theory) is viewed as “related to a lack of knowledge about possible outcomes”, and it is further said that “
Risk is measurable uncertainty; Uncertainty is unmeasurable risk”. In [
21], the view of uncertainty is similar, as it is defined as a “
state, even partial, of deficiency of information related to understanding or knowledge”. Since we view risk in the mutually complementary functional contexts of probability theory and algebra, we avoid trying to search for a consensual definition of uncertainty in risk management.
We now provide an overview of mathematical notations used in probability theory, and we will restrict to the case where random variables are real-valued. Notions like “measure” and “measurable” are strictly defined within measure theory, upon which probability theory resides, but we avoid defining measure-theoretic notions in this brief overview of mathematical notations in probability theory. For detail concerning measure theoretic notions, see [
36].
Notions in probability theory build upon a set
S of
samples, where
S is often called the
sample space. In this paper, we view a
risk source, also known as a hazard, as a “sample” in some sample space (of risk sources). In [
21], ‘event’ is generally seen as a subset of risk sources, or a subset of hazards. However, in [
21] there is no strictly defined connection between the concepts of ‘risk source’, ‘event’ and ‘hazard’, and how they appear within the concepts of ‘probability’ as they are mathematically well defined within probability theory.
The notion of randomness, over the sample space S, is defined by the real-valued random variable as being a (measurable) function , where is the continuous range of real numbers assigned to samples, and over we assume to have the Borel -algebra (not further explained in this paper). Thus, when a risk source is viewed as an element , we have as the value or “observed measurement” of the risk source s. Note indeed that the value is just the numerical value assigned to and describing the risk source, without any auxiliary information per se about other characteristics of the risk source.
The use of ‘space’ in ‘sample space’ is a bit misleading since S is just a set without any structure whatsoever. We should thus call S a ‘sample set’ rather than a ‘sample space’, since the use of ‘space’ falsely indicates that S would possess some structure beyond being just a set of points.
There is often a confusion between the notions of “sample”, “outcome” and “event”, in particular in the situation involving real-valued random variables, where the confusion between “sample” and “outcome” is due to the notation “”, which is not a statement, but is the set of samples, i.e., not a set of values in . Thus, whereas s is a “sample”, an “outcome” may be understood as the sample together with its value given by the underlying random variable , i.e., we might speak of an “outcome of a sample”, rather than “outcome as a sample”.
Needless to say, a random variable is not a “variable” as understood in logic and computer science, but indeed a function that, we could say, “randomly assigns” real numbers to samples.
In statistical analysis, the random variable is unfortunately often “hidden” or ignored altogether in the sense that samples are identified with their observed values, i.e., the sample space S is viewed as . Therefore, the random variable becomes trivially and moreover just chosen to be the identity function. In this case, there is obviously no distinction between “sample” and “outcome”. It is indeed important to realize that in analysis we compute with values and not with the samples s.
Kolmogorov’s axiomatic foundations of probability theory [
37] was written in German, and the sample set was simply called a “set of elements” (
eine Menge von Elementen), and the elements were named
elementare Ereignisse, which in the English translation [
38] appear as “elementary events”. Events as sets of samples are in [
37] named
zufällige Ereignisse, and in the English translation [
38] appearing as
random events.
In the common nomenclature for probability theory, there is seldom explanations on the distinction between “sample” and “outcome”, other than an “outcome” being seen as a sample in a “trial” or “experiment”, which is seen as a sequence of samples s with their values . The notion of “sampling”, or “conducting an experiment”, or “executing a trial”, usually refers to creating such a sequence of samples by repeatedly “drawing” samples from a set of samples.
In many practical situations, “sampling” means selecting a subpopulation, e.g., of humans, from a larger population, sometimes called a “lot”, and making observations on individual humans in that subpopulation, with the objective to arrive at conclusions concerning the lot, i.e., the whole population.
In [
30], a
lot is basically a population, as a set of elements, defined by a collection of criteria that determine whether or not an element qualifies to be a member of that population. The sample set is then a randomly chosen subset of the lot set, so that the elements in the sample set can be seen “representative” for the elements in the lot set. Probability theory uses the sample set, but does not define the lot set, and in this paper it suffices to view a lot as corresponding to a population, defined in a wider sense. For risk management in food safety, we may recall the definition of lot in [
39], saying that
by a lot of unsatisfactory quality is meant one that contains more than a specified proportion of defective pieces. In food production, we would expect
no more than a certain proportion of delivered lots to be unsatisfactory in quality. As analysis will be restricted to the use of the sample set, it is important to ensure lot quality, techniques for which are provided, e.g., in [
40].
We now come to the formal definition of probability, which is defined within a ‘probability space’, building upon a selected sample set S. A probability is a “probability of an event”, where an event is a subset of samples in S, and the probability is a value in the unit interval . An event is formally defined as an element of a -algebra over S, i.e., closed under formation of complements and unions of subsets of S, and we may denote this -algebra as . An event is thus a subset of S, i.e., . A probability is now defined as a function, the probability function (as a measurable function) , which is required to satisfy and whenever .
The triple forms a probability space. Now note that for an event we indeed have its probability . However, we still have not defined “distribution”, for which we will need a random variable . A “distribution” is thus not given until we have a random variable, and once we do have both a probability space and a random variable , we will be able to define the intertwining of probability and the distribution of it.
There is a widespread confusion about “distribution” and “distribution function”. Textbooks almost always include precise definitions e.g., for PDFs and CDFs, where a PDF is a probability density function and a CDF is a cumulative distribution function.
Before sorting out this confusion, we need to note the shorthand notational praxis in probability theory related to the informal expression “”. Formally and precisely, an expression like “” is the probability value in of the event “”, which, as already pointed out above, is the subset of samples , .
We are now in a position to discuss the “distributions” and the “distribution functions”. We usually understand a CDF to be given by a PDF as follows. A PDF is a function
such that
Note that if
only for a finite set of values
, then we call
f a
probability mass function, and it fulfills the property
Given such a PDF
f, we can define the corresponding CDF
by
and we thereby assume that
is the probability of the event “
”, i.e., we assume that
Doing so gives us the impression that we first have a PDF, then we can define a CDF, and that essentially defines the probability function. However, in probability theory, it is just the other way around, since we are first given the probability space, including the probability measure
Then we select a real-valued random variable
so that we can define
F according to (
A7). In order to define
f, we need to rely on the
Radon-Nikodym Theorem, that guarantees the existence a function
f of the form (
A2) satisfying
where
and
is the
Lebesque measure over the Borel
-algebra over
. Thus, we first have
P, using which we define
F according to (
A7), and given
P, we use (
A10) to arrive at the existence of
f. Finally, the relation between
F and
f is given by (
A6), which means that
i.e., a PDF is the derivative of its corresponding CDF, and, because of (
A10), this derivative is called the
Radon-Nikodym derivative.
We conclude this Appendix by providing a brief overview of probabilistic methods for quantifying risk sources within food safety.
Guides and guidelines for adoption of probabilistic methodology are many, one of which is the guidance [
30] that the European Food Safety Authority (EFSA) requested from the
Panel on Plant Protection Products and their Residues to provide on probabilistic methodology. The focus in [
30] is on methodology in support of conducting dietary exposure assessments for pesticides, and particularly on the way assumptions about probabilistic models affect experts in their decisions on various judgments, e.g., concerning inclusion and exclusion of risk sources.
In [
30], probabilistic assessment is outlined mainly for
basic assessment rather than
refined assessment, where basic probabilistic assessment aims to focus on upper and lower bound probability distributions for assumed but not found “true” distributions. These distributions, considered to be upper and lower bounds, are called, respectively, “pessimistic” and “optimistic” models.
Notably, as stated in [
30],
if the results of the pessimistic model raise no concern for risk managers, it can be assumed that the true dietary exposure would also cause no concern, so the assessment can stop, and such a situation
it is not necessary to conduct the optimistic model run. Perhaps more importantly and rationally,
if both the optimistic and pessimistic estimates raise concern, and if the level of concern indicates an unacceptable risk, then it can be assumed that the true exposure would also raise a similar level of concern, where in that case
further refinement is unlikely to be worthwhile if the assessment is acute, whereas in a chronic assessment, refinement may require the use of parametric modeling. Refined approaches may be needed if pessimistic models turn out to be too conservative, and
as the models are progressively refined, the results of the optimistic and pessimistic runs will gradually converge.
For pessimistic models in basic probabilistic assessment, it is in [
30] proposed that the proportion of residues below the “limit of reporting” should be modeled independently using a binomial distribution, and for basic probabilistic assessment in general it is proposed that lognormal distribution is used. The choice of distribution function is often difficult, and guided only by the general nature of the analysis task. For instance, in predictive microbiology, Weibull’s distribution is typically used for predicting bacterial inactivation. We may note that Weibull’s distribution is often also used in predictive maintenance for analyzing the “remaining useful life” for machines of various kinds.
On the relation between probability theory and many-valued logic, section on “Methods for quantifying uncertainty” in [
41], in its Section 11.1.3 on
Expressing uncertainty using possibility, includes a quite shallow historical background of algebraic methodology for many-valued logic as used in this paper. That subsection, including references to “fuzzy logic” and “possibility theory, ” is very brief and should not be understood as any kind of summary of or introduction to the algebraic and logical foundations of many-valued logic as used in this paper for the very reason to complement probabilistic methodology used in risk management with algebraic and many-valued logical methodology. We may also recall that ever since Lotfi Zadeh introduced “Fuzzy sets” [
42] in 1965, he spoke on numerous occasions about the distinction of fuzzy logic in the broader sense and in the “narrow sense”, the latter being a name for the more theoretical discipline of “fuzzy sets and systems”, particularly focused on the algebraic foundations of fuzzy and many-valued logic. In these algebraic foundations, it was immediately seen how the formal description of “uncertainty” in probability theory connected with probability must not be confused with uncertainty as a truth level in many-valued logic. However, within “fuzzy logic in the broader sense”, essentially referred to in [
41], probability theory was a burden, as the fuzzy systems research community often heard Lotfi Zadeh view fuzzy set theory as an alternative and being in a competitive role as compared with probability, in particular in discussions on the practical use of the concept of “uncertainty”. Fuzzy sets in this broader or broadest view are based on an unstructured view of a “universe of discourse”.
The approach in [
43] on “Possibility theory” was an effort to establish a bridge over the gap between probabilistic and fuzzy views of uncertainty. In [
44], there was an effort to discuss relations between artificial intelligence and uncertainty modeling, in particular
regarding the role of fuzzy set theory and many-valued logics. However, the treatment is more pragmatic and even philosophical than formally logical and mathematical. There were at that time efforts to accelerate developments of “probabilistic logic”, i.e., to identify logical substance
within probability theory, rather than complementary to probability theory.
In [
41], it is implicitly stated that fuzzy methodology in risk management is quite sparse, and this is indeed a correct observation. Some results exist, and are based on traditional fuzzy set modeling, like e.g., seen in [
45], where “fuzzy HACCP” is suggested in the form of a fuzzy decision tree. However, even if providing a brief overview of fault tree analysis, it does not include detail on fuzzy fault tree analysis, which dates back to [
46].
In this paper, our algebraic approach builds upon algebraic structures, e.g., like quantales [
35], and our approach is to view algebra, many-valued logic, and probability theory as appearing complementarily and mutually supportive in relation to each other rather than competitively or mutually exclusive.