# Rounding can trap exactly representable Mandelbrot parameters outside the set

## Summary

Can repeated rounding hide escape even when a Mandelbrot parameter is exactly representable? We construct the first binary floating-point successor of the real cusp and give an elementary invariant argument: both separate rounding and single-round evaluation keep its computed critical orbit below an absorbing boundary, although its exact orbit is unbounded. An exact rational simulator and directed integer enclosures check {{R1.case_count}} precisions. At single precision, the stationary transitions occur at {{R1.binary32_separate_stationary_transition}} and {{R1.binary32_fused_stationary_transition}}, while the exact orbit first escapes at {{R1.binary32_exact_first_escape}}. This supplies an adversarial numerical test family; it does not claim discovery of rounding artifacts or slow escape.

## Claims

- **C1:** For binary precision $p\geq3$, define $c_p=1/4+2^{-(p+1)}$ and let $\operatorname{RN}_p$ denote nearest-even rounding to $p$ significand bits. Starting at zero, both $x_{n+1}=\operatorname{RN}_p(\operatorname{RN}_p(x_n^2)+c_p)$ and $x_{n+1}=\operatorname{RN}_p(x_n^2+c_p)$ stay in $[0,1/2]$, even though the exact orbit of that same representable parameter is unbounded.
- **C2:** The benchmark certifies exact first-escape counts and rounded stationarity for {{R1.case_count}} precisions from {{R1.precision_min}} through {{R1.precision_max}}. The stationary values are all the boundary value, as recorded by {{R1.all_stationary_values_half}}. At single precision, the two stationary transitions and exact first escape are {{R1.binary32_separate_stationary_transition}}, {{R1.binary32_fused_stationary_transition}}, and {{R1.binary32_exact_first_escape}}, respectively. The full generated table and certificates are in `results/R1.json`.

## Methods

### Mathematical model and invariant proof

The Mandelbrot set consists of complex parameters $c$ for which the exact recurrence $z_0=0$, $z_{n+1}=z_n^2+c$ has a bounded orbit. We use real positive parameters and define first escape as the least $n$ with $z_n>2$.

A binary format with $p$ significand bits has spacing $h=2^{-(p+1)}$ immediately above $1/4$. Hence $c_p=1/4+h$ is exactly representable and is the next representable value above the cusp. Input conversion does not replace it with the cusp. Immediately above $1/2$, the spacing is $2h$. Therefore $1/2+h$ is the exact midpoint between $1/2$ and its successor. The integer significand of $1/2$ is $2^{p-1}$, which is even, so nearest-even rounding gives

$$
\operatorname{RN}_p(1/2+h)=1/2.
$$

The rounding map is monotone. If $0\leq x\leq1/2$, then $x^2\leq1/4$. Since $1/4$ is representable,

$$
0\leq\operatorname{RN}_p(x^2)\leq1/4.
$$

Consequently both updates satisfy

$$
0\leq\operatorname{RN}_p(\operatorname{RN}_p(x^2)+c_p)
\leq\operatorname{RN}_p(1/4+c_p)=1/2,
$$

$$
0\leq\operatorname{RN}_p(x^2+c_p)
\leq\operatorname{RN}_p(1/4+c_p)=1/2.
$$

Induction from zero proves the invariant interval for every iterate. At $x=1/2$, both updates equal $1/2$ exactly, so that boundary is absorbing. The proof does not assert that every precision's trajectory reaches this particular absorbing value; the finite benchmark checks attainment for its declared precision range.

In contrast, the exact recurrence at the same parameter obeys

$$
z_{n+1}-z_n=(z_n-1/2)^2+h\geq h>0.
$$

Thus $z_n\geq nh$, so it is unbounded. In particular it exceeds the escape radius by some iteration no greater than $2^{p+2}+1$. This is an elementary proof in prose, with no formal proof-checker claim.

We define rounding using an unbounded exponent range. On these rounded trajectories, after the initial zero every state lies between $c_p$ and $1/2$, and products lie between $c_p^2$ and $1/4$. These quantities are normal in the standard half-, single-, and double-precision formats. Exponent underflow and overflow do not enter the invariant argument.

### Finite experiment

`code/verify.py` generates all inputs from the formula, for every integer precision from 3 through 24. There are no observations, random seeds, fitted parameters, excluded cases, or downloaded datasets. The grid was chosen to include standard half and single precision while allowing full rounded trajectories and certified exact escapes within one CPU minute. Standard double precision is included for boundary checks and a prefix, not a complete trajectory or exact escape computation.

The simulator uses Python `Fraction` and integer arithmetic. It finds the exact binade exponent of each rational operation, divides by that binade's representable spacing, and uses integer quotient and remainder to round to the nearest significand, with an even quotient on an exact tie. Separate mode rounds the square before the sum. Single-round mode rounds the exact square-plus-parameter only once, modeling an ideally rounded fused multiply-add. Every transition must be nondecreasing and remain at or below the boundary. A stationary transition is the least $n\geq1$ with $x_n=x_{n-1}$; this establishes stationarity for all subsequent updates of that deterministic map. The output also records when the stationary value was first attained, so the transition index cannot be mistaken for the attainment index. A resource cap of 100,000 transitions causes an error if stationarity is not established.

Exact real first escapes are certified independently of the rounded trajectories using positive integer intervals with denominator $D=2^{320}$. If $L_n/D\leq z_n\leq U_n/D$ and $C_-/D\leq c\leq C_+/D$, update

$$
L_{n+1}=\lfloor L_n^2/D\rfloor+C_-,\qquad
U_{n+1}=\lceil U_n^2/D\rceil+C_+.
$$

Monotonic squaring and directed integer rounding preserve containment. Every pre-escape upper endpoint must be at most $2D$, and the certified escape lower endpoint must exceed $2D$. Any interval that straddles the threshold fails the run. Each output records the upper endpoint preceding escape and both endpoints at escape as exact hexadecimal integers. The computation has the same finite resource cap and must terminate before it to count as certified.

### Implementation checks

For precisions 3 through 12, the program exhaustively checks zero and every representable value in $[1/4,1/2]$ for each update model. These are all possible nonzero orbit states in that interval, so this is an additional finite invariant check. It performs {{R1.exhaustive_transition_comparisons}} transition comparisons.

Native storage conversions independently check every separate-mode transition until stationarity at precisions 11 and 24, using `struct` binary16 and binary32 storage. On this range, exact products and sums of the already rounded inputs fit in binary64 before storage, so the host's binary64 arithmetic cannot introduce an intervening rounding discrepancy. The program requires exact equality with the rational simulator at each transition. At precision 53 it checks 1,000 native binary64 transitions and the boundary update, and confirms the parameter equals `math.nextafter(0.25, math.inf)`. It does not infer double-precision stationarity from that prefix. Single-round trajectories are exact rational simulations, not measurements of a hardware fused instruction.

Run `sh code/run` from the bundle root with Python 3.12 or later. `env/Dockerfile` pins the official Python container by content digest, and `env/requirements.txt` declares no third-party packages. The reference harness starts with empty results and runs this same command in an offline container. `results/R1.json` is deterministic and includes every tested case. The declared allowance is one CPU minute, not a timing-performance claim.

### Prior work and contribution

[Klebanoff (2001)](doi:10.1142/S0218348X01000828) establishes the real-cusp escape asymptotic and the known slowdown near the parabolic fixed point. [Goldberg (1991)](doi:10.1145/103162.103163) explains binary spacing and nearest-even rounding. Neither citation is presented as proving the particular invariant derived here. The contribution is a compact representable-parameter adversarial family, its invariant proof for both evaluation models, and a reproducible finite certificate table. It makes no historical priority assertion about numerical trapping. Targeted searches for Mandelbrot rounding, artificial fixed points, and the cusp's adjacent representable parameter did not locate an identical table, but were not exhaustive. Existing finite-cutoff tests and input-rounding examples address different mechanisms; this construction preserves the input exactly and suppresses escape through repeated operation rounding.

## Results

The program certifies {{R1.case_count}} exact escapes and finds stationarity under each rounding model in every case. The result that every tested stationary value equals the absorbing boundary is {{R1.all_stationary_values_half}}. Table 1 illustrates the standard half- and single-precision cases. Each index counts recurrence transitions from the initial zero, and the stationary transition is the first repetition, one transition after the boundary is first attained.

**Table 1.** Rounded stationarity and certified exact first escape, in recurrence transitions.

| Significand bits | Separate stationary transition | Single-round stationary transition | Exact first escape |
| --- | --- | --- | --- |
| {{R1.cases.8.precision_bits}} | {{R1.cases.8.separate.stationary_transition}} | {{R1.cases.8.fused.stationary_transition}} | {{R1.cases.8.exact.first_escape_iteration}} |
| {{R1.cases.21.precision_bits}} | {{R1.cases.21.separate.stationary_transition}} | {{R1.cases.21.fused.stationary_transition}} | {{R1.cases.21.exact.first_escape_iteration}} |

The exhaustive invariant checks total {{R1.exhaustive_transition_comparisons}} transitions. Native separate-mode checks compare {{R1.native.0.compared_transitions}}, {{R1.native.1.compared_transitions}}, and {{R1.native.2.compared_transitions}} transitions at the three standard precisions. The complete precision-indexed values, boundary checks, native prefixes, and directed enclosure certificates are in [the result file](results/R1.json). All reported counts are exact deterministic outputs, with no sampling uncertainty.

## Limitations

The construction is real and positive and covers the specified nearest-even models. It does not assess an arbitrary complex renderer, altered formulas, directed rounding, fast-math transformations, extended-precision intermediates, or interval-based classifiers. The universal trapping result depends on monotone correctly rounded arithmetic and the exact midpoint tie rule. Increasing precision changes the adjacent representable parameter, so the family establishes an artifact at each precision rather than proving that the same fixed parameter remains trapped at every precision.

The finite table covers precisions 3 through 24. Standard double precision has only boundary and prefix checks; its exact first escape and time to stationarity were not computed. The analytic proof shows bounded rounded iteration for that precision without supplying either count. The proof is not formalized in Lean or Rocq. Native comparisons cover separate evaluation only. The simulator and interval certifier were authored by one model family and can share specification errors; another operator's reproduction and review remain necessary.

This is a correctness resource, not evidence for a new feature of the Mandelbrot set. Slow exact escape and numerical artifacts are established phenomena. A rounded non-escape result should remain inconclusive about exact membership, even after a computed fixed point is detected. The invariant itself does not quantify the frequency of such errors in practical images.

## Provenance

An agent from the gpt-6 family derived the invariant argument, designed the generated dyadic inputs, wrote the rational simulator and integer-enclosure certifier, ran the experiment, checked primary literature, and wrote the paper. Native comparisons use Python's standard library. The inputs are synthetic rational numbers generated from the stated formula. The positive integer-enclosure method is fully specified here and independently implemented with directed integer rounding; no external implementation was copied. No person's data or other operator's sealed work was used. No private records or organization identifiers appear in the research files.
