<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Conflict-Abduction-Negation in Policy-Making</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Etienne Houzé</string-name>
          <email>etienne.houze@telecom-paris.fr</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Ada Diaconescu</string-name>
          <email>ada.diaconescu@telecom-paris.fr</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Jean-Louis Dessalles</string-name>
          <email>jean-louis.dessalles@telecom-paris.fr</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="editor">
          <string-name>Reasoning, Multi-agent system, Explanation</string-name>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>AMPM'21: First Workshop in Agent-based Modeling &amp; Policy-Making</institution>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>EDF R&amp;D</institution>
          ,
          <addr-line>7 boulevard Gaspard Monge, 91120, Palaiseau</addr-line>
          ,
          <country country="FR">France</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Télécom Paris</institution>
          ,
          <addr-line>19 place Marguerite Perey, 91120, Palaiseau</addr-line>
          ,
          <country country="FR">France</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>In many real-world events that would require additional regulation, the causal chain leading to the event can be hard to determine. This is partly due to the distribution of knowledge across multiple agents, the a-priori unknown number an competence of such agents and their heterogeneous expertise. In this case, coordination is key to the understanding of the phenomenon. In this paper, we informally describe a novel approach to analyze complex sequences. This method originates from the study of smart homes, where collaboration between heterogeneous components is required, too. Our proposal is named D-CAS, which stands for Decentralized Conflict-Abduction-Negation. It is a high-level process that coordinates components' expertise to generate an explanatory reasoning in smart homes. We transfer our smart home solution to socio-technical systems in general. We illustrate the general concept via two fictional example cases: i) an autonomous car crash and ii) a crime perpetrated after social media fake news. In both cases, we examine how D-CAN could manage the communications and be used as a general framework to formalize interactions between experts and organize the discussion, helping to unravel a multi-domain causal chain. Using D-CAN helps identifying causes and responsible and can thus be helpful in a broader perspective of policy-making, e.g. to audit the potential flaws of current legislation.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <sec id="sec-1-1">
        <title>1.1. Problem presentation</title>
        <p>Policy makers often have to update regulation after tragic events occur. In such events, the
causality chain and the responsibility of the diferent parties involved can be hard to identify, as
knowledge of complex situations is scattered across experts with distinct domains. This can
compromise the identification of eficient and fair regulation. To help the process, we propose
to design a general solution to facilitate communication between experts and therefore the
understanding of complex causal chains. We illustrate this via two fictional, yet realistic events.
As they serve only as examples, we do not blame nor judge any involved party and do not draw
any conclusion regarding the responsibility.
nEvelop-O
LGOBE</p>
        <p>https://explainableai.fr (E. Houzé); https://adadiaconescu.there-you-are.com (A. Diaconescu);</p>
        <p>© 2021 Copyright for this paper by its authors. Use permitted under Creative Commons License Attribution 4.0 International (CC BY 4.0).</p>
        <p>In a first situation, suppose that an autonomous car, from manufacturer  has just crashed
while its driver  was not using the wheel. This crash occurred at an intersection in a city that
is supervised by some local authority  . The car manufacturer has two main branches in its
production chain, the software team   and the car engineering team   . Considering the
situation of the accident, precise knowledge about all elements of this crash can be considered
to be split between these actors. The distinction is clear, meaning that no domain knowledge is
sub-domain of another domain. In this situation, which is represented by Figure 1a, how can
one understand the causal chain leading to the event of the crash? Should a new regulation
introduce tighter control for the manufacturer, better road infrastructure or limitation to the
driver’s use of automated driving?</p>
        <p>A similar example can be observed when considering a fictional crime. The police discovers
that the main suspect had previously read and shared fake news on a social media platform,
in a private group. Here, expertise from psychiatrists, the social media group, other members
of the private group or the suspect him/herself can help understanding the process that led
to the crime. Unfolding the chain of events is key to prove whether the suspect is guilty or
innocent and to understand how policy changes can be performed to avoid similar situations in
the future.</p>
        <p>Both these cases highlight the important role played by causal understanding in
policymaking. However this knowledge can be hard to acquire in situation where diferent actors hold
part of the information. Furthermore, the number and domains of the diferent experts vary
on a case-by-case basis. Here, coordinated communication is key to the success of the causal
unraveling. Our contribution is to use an existing algorithm used for smart home explanations,
named D-CAN, where diferent heterogeneous devices contribute to a system-wide explanation.
D-CAN is based on an previously established cognitive process, CAN.</p>
        <p>(a)
(b)</p>
      </sec>
      <sec id="sec-1-2">
        <title>1.2. Related works</title>
        <p>
          The investigation of complex causal chains is not new: diferent methods already exist to account
for the investigation of past cases. For instance, the Why-Because Analysis (WBA) which is
often used in reports following aircraft crashes [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ]. However, to the best of our knowledge, they
are more often used to explore and validate an investigation after its completion rather than
being used as a driving mechanism for the reasoning.
        </p>
        <p>
          The notion of causality is the basis of WBA explanation. Recent advances in the study of this
phenomenon show the importance of “contrastive explanation” [
          <xref ref-type="bibr" rid="ref5 ref6">6, 5</xref>
          ] where the object of the
explanation is the diference between an expected state of afairs and the actual observation.
From this basis, we can draw a parallel between explanation and spontaneous argumentative
reasoning [
          <xref ref-type="bibr" rid="ref1">1</xref>
          ] each sentence is relevant because it tries to solve an existing conflict.
        </p>
        <p>
          In a broader perspective, STAMP (System Theoretic Accident Model)[
          <xref ref-type="bibr" rid="ref3">3</xref>
          ] proposes an accident
model that is based on systems and control theories. It incorporates an event-based causal
modeling at the level of the process itself, but incorporates it in a larger model, encompassing
system development and system operations, that are modeled as multi-layered control loops.
This approach can model real-life accidents, such as airplane failures [
          <xref ref-type="bibr" rid="ref4">4</xref>
          ], but it requires expert
knowledge from the investigator, spanning the generation, the process itself and its monitoring.
        </p>
        <p>
          A similar issue may arise when considering the standard theory of Argumentation which is
mainly due to Dung’s formalism [
          <xref ref-type="bibr" rid="ref7">7</xref>
          ]. In this framework, a binary relation of attack is defined
over a set of arguments, which allows to define which arguments are acceptable to defend
which proposition. While this theory models formal argumentative debates such as law or
medicine, it fails to encompass the runtime changes of beliefs or arguments that exist in mundane
argumentation. In addition, knowing all arguments and attack relations requires a high level of
expertise, which may be impossible to maintain for topics covering several areas.
2. Decentralized Conflict-Abduction-Negation
        </p>
      </sec>
      <sec id="sec-1-3">
        <title>2.1. Principles of CAN</title>
        <p>
          The Conflict-Abduction-Negation (CAN) process was first designed as a generic cognitive model
to account for argumentative reasoning[
          <xref ref-type="bibr" rid="ref1">1</xref>
          ].
        </p>
        <p>
          At the core of CAN lies the notion of conflict [
          <xref ref-type="bibr" rid="ref1">1</xref>
          ]: a conflict occurs when an observation is
in contradiction with a prior belief or desire of the agent. To formalize the notion of conflict,
we represent the agent’s perception of the world as a set of Boolean predicates  . In addition,
an agent can associate a necessity ( ) to each predicate  . This necessity ( ) is a number
conveying information about the strength and nature of the agent’s prior opinion regarding  ’s
value. A positive necessity means that the agent wishes or expects  to be true, while ( ) &lt; 0
means that the agent wishes or expects it to be false. The internal state of the agent’s perception
of the world and its opinions can be modeled by a set of predicates and necessities. Note that a
necessity set to 0 means that the agent has no opinion regarding a predicate.
        </p>
        <p>A conflict occurs when the predicate’s value contradicts the sign of the associated necessity.
For instance,  can be true while its associated necessities ( ) is negative. The couple ( ,  =
( )) models the conflict, whose intensity is given by the absolute value | | . Similarly, a conflict
can occur if a predicate  is observed to be false while its associated necessity is positive. It is
also important to note that if ( ,  ) is a conflict, then its negation (¬ , − ) also constitutes a
conflict of the same intensity.</p>
        <p>CAN relies on the identification of conflicts ( ,  ) which can then be propagated to either
their causes, consequences or negations. i) Abduction denotes the process of inferring a causal
hypothesis to an observed phenomenon. In CAN, this means that, if  is found to be the cause
of  , then the conflicts ( ,  ) is propagated onto (,  ) ; ii) Negation allows to consider potential
actions and alternative scenarios by considering the opposite of a conflict.</p>
        <p>
          CAN can be considered an alternative to the classic Argumentation Theory [
          <xref ref-type="bibr" rid="ref1 ref7">1, 7</xref>
          ]. It provides
a minimalist model, where conflicts and their relevance is evaluated at runtime rather than
in a formal attack/defend classification. It is, however, compatible: the output of CAN can be
represented as a set of formal arguments and attacks, following the inference knowledge shown
by the procedure.
        </p>
      </sec>
      <sec id="sec-1-4">
        <title>2.2. Decentralization</title>
        <p>D-CAN extends this process by observing that knowledge, i.e. predicates values and their
associated necessities, can be only locally defined and therefore a inter-agent process is possible
without relying on an omniscient knowledge base. A coordinator is necessary to maintain
coherence between calls and provide a unique interface with the user, but it can be kept minimal
and generic, in the sense that it simply routes requests to the relevant expert component. This
means that in the smart home for instance, when requested to give an explanation for a low
temperature, the coordinator component will route the request to the temperature controller
component, which will inquire the conflict by observing its measures and trying to identify a
possible cause thanks to its local knowledge. The request is then sent back to the coordinator,
which will once again route it to the next component.</p>
        <p>The detailed process is shown in Algorithm 1. The coordinator identifies the expert
responsible for the conflict proposition  , then asks it to inspect the problem with its local knowledge
(line 6) and waits for its answer. This latter can be either a causes inferred via inference,
a consideration of the negation of the current conflict, or the abandon of the conflict. The
coordinator updates its knowledge accordingly: this eventually propagates the conflict onto
the inferred cause, the negation or another conflict occurring elsewhere in the system. The
algorithm terminates once all conflicts have been examined and handled, solved or discarded.</p>
        <p>
          Figure 1b illustrates a possible Smart Home architecture to enable D-CAN: a central
coordinator is connected to Local Explanatory Components located on several low-power computers,
each acting as a local expert in the knowledge domain covered by its associated device. This
allows the process to be decentralized, in the sense that the knowledge of the system is
distributed among various experts. Note that contrary to our previous work[
          <xref ref-type="bibr" rid="ref2">2</xref>
          ], we use D-CAN
instead of D-CAS (where Simulation replaces Negation). The motivation for this change is that
cyber-physical systems can not simply deny an observation but instead can run a simulation.
Since we are considering a generalization to other domains here, this modification is irrelevant,
hence the use of D-CAN.
end
answer = responsible.investigate((P, N)) ;
switch Answer do
case ABDUCTION do
(P, N) ← Answer.Hypothesis ;
responsible ← locate(P) ;
end
case NEGATION do
assessTrue(Answer.Action) ;
        </p>
        <p>Conflict ← findConsequences() ;</p>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>3. Application to the examples</title>
      <p>To illustrate how D-CAN can fare in real-life situation, we consider its application to the two
examples presented in the introduction of this paper.</p>
      <sec id="sec-2-1">
        <title>3.1. Playing the examples</title>
        <p>For the car crash example, a possibility of a mental D-CAN unraveling is presented in Table 1:
the successive calls between agents are represented, as well as the content of these calls, i.e. a
conflict-like object. In this example, the trace shows the following discussion: the driver first
thinks that the car failed to stop correctly, which might indicate a problem with the manufacturer
 . The latter conducts internal examination but rules out the possibility of a mechanical or a
software failure. The driver is then asked for more details about the situation, to find another
cause for the crash. She thus indicates that the area was not correctly lit, which triggers an
inquiry with the local authorities  . Note that the intensity of conflicts proposed by abductive
reasoning is lower than that of the incoming conflict. This gap translates the uncertainty
regarding the outcome of abduction. In addition, it prevents from ending up considering causal
chains that are too long: after a number of abductive hypotheses, a low intensity prevent the
Sender
External
Coordinator
Coordinator



D
M
 
 
Coordinator 
Coordinator</p>
        <p>Target
Coordinator</p>
        <p>Coordinator</p>
        <p>D
M
 
M</p>
        <p>Coordinator
Coordinator</p>
        <p>Content
(crash, -50)
(crash, -50)
(car_no_stop, -45)
(car_no_stop, -45)
(software_issue, -40)
(-software_issue, -40)
(mechanical_issue, -40)
(-mechanical_issue, -40)
(-car_no_stop, -45)
(crash, -50)
(-light, 40)
(-light, 40)
…</p>
        <sec id="sec-2-1-1">
          <title>Comments</title>
          <p>Initial request
Routing
Abductive reasoning
Routing
Abductive reasoning
No problem found
No problem found
No problem found
Asking again
Second hypothesis
Other Abductive hypothesis
Inquiring Local authorities
Successive calls in the example of the car crash
conflict to get propagated. In case he/she wants more information, the coordinator can ask
again with more intensity, which will propagate the conflict further.</p>
        </sec>
        <sec id="sec-2-1-2">
          <title>Sender</title>
          <p>External
Coordinator
Suspect
Coordinator
External
Coordinator
Suspect
Coordinator
Social Media Company
Coordinator
Social Media Company</p>
          <p>Coordinator
Target
Coordinator
Suspect
Coordinator
Social Media Company</p>
          <p>End of the first try. Trying again, with more intensity...
Coordinator
Suspect
Coordinator
Coordinator
Police
Social Media Company
…
(crime, -80)
(crime, -80)
(fake_news, -75)
(fake_news, -75)
(hate_group, -70)
(hate_group, -70)</p>
        </sec>
        <sec id="sec-2-1-3">
          <title>Content</title>
          <p>(crime, -50)
(crime, -50)
(fake_news, -45)
(fake_news, -45)
(- fake_news, -45)</p>
        </sec>
        <sec id="sec-2-1-4">
          <title>Comments</title>
          <p>Initial request
Routing
Abductive Reasoning
Routing
Giving up
Initial request
Routing
Abductive Reasoning
Routing
Abduction
Routing
Successive calls in the example of the fake-news crime</p>
          <p>The second example, the fake-news-related crime, illustrates another possibility of D-CAN.
As necessities encode the intensity of a conflict and the underlying request, it is possible that
this intensity is not high enough to trigger some possibilities: think, for instance, of a test that
would require a considerable amount of work, or an information one of the agents is not keen
on disclosing. If the problem to solve appears minor, it might be better not to consider doing
this test or revealing sensible information, as it would not be worth the trouble. In this case, the
reasoning explores other branches of the reasoning first. This is what happens in the rationale
exposed in Table 2: as it is costly for the social network company to investigate and disclose
personal information, at first it does not answer the request for more information about the fake
news. However, as no other branch is found in the rationale, the process can be re-launched,
this time with a higher intensity, which will be suficient to provoke a reaction from the social
media company. Then, the reasoning can go on and, for instance, the police may be called
to acquire more information about the original posters of the hate group on the social media
platform.</p>
        </sec>
      </sec>
      <sec id="sec-2-2">
        <title>3.2. A tree representation of reasoning</title>
        <p>The main advantage of using D-CAN in deliberative discussions is normalization: all inquiries
and relations are represented using the same grammar of predicates and necessities, as do agents’
beliefs and reasoning. Therefore, it is possible to transcribe the reasoning and represent every
step by a tree graph, whose nodes represents call. Figure 2 illustrates this by showing the tree
representing the rationale of the car crash example detailed in Table 1. The tree visualization
reads from left to right, and top to bottom. It shows each request to a diferent expert agent,
the diferent examined conflicts and the outcomes of the calls. This visualization tool ofers an
option to display an interpretable description and keep a track of the diferent calls and conflicts,
retracing the entire reasoning.</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>4. Perspectives and conclusions</title>
      <p>We propose a new approach on multi-agent exploration of causal chains for policy-making
based on an existing process for smart-home systems, D-CAN. We use two basic but realistic
examples to illustrate the ability of D-CAN to coordinate requests and formalize interactions,
which allows to generate visualization of the reasoning.</p>
      <p>This work can be considered as preliminary, as it is still in very early stage and many issues
have not been addressed yet. For instance, we modeled agents in a simple manner to keep
the minimal aspect of D-CAS. Thus, we represent requests as simple conflict-like objects and
agent’s knowledge as a collection of instantiated predicates and necessities. While powerful and
eficient in the case of smart home devices, this representation can prove insuficient for human
agents, where other variables can be taken into consideration: deception, genuine mistakes
and misunderstanding are part of any human organization. While D-CAN helps tackling the
third of these issues, understanding how to support handling the former two remains for future
development</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>J.-L.</given-names>
            <surname>Dessalles</surname>
          </string-name>
          , “
          <article-title>A Cognitive Approach to Relevant Argument Generation,” in Principles and Practice of Multi-Agent Systems</article-title>
          , LNAI
          <volume>9935</volume>
          ,
          <year>2016</year>
          , pp.
          <fpage>3</fpage>
          -
          <lpage>15</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>É.</given-names>
            <surname>Houzé</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.-L.</given-names>
            <surname>Dessalles</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Diaconescu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Menga</surname>
          </string-name>
          , and
          <string-name>
            <given-names>M.</given-names>
            <surname>Schumann</surname>
          </string-name>
          , “
          <article-title>A Decentralized Explanatory System for Intelligent Cyber-Physical Systems,”</article-title>
          <source>in Proceedings of SAI Intelligent Systems Conference</source>
          ,
          <year>2021</year>
          , pp.
          <fpage>719</fpage>
          -
          <lpage>738</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>N.</given-names>
            <surname>Leveson</surname>
          </string-name>
          , “
          <article-title>A new accident model for engineering safer systems,” Safety science</article-title>
          , vol.
          <volume>42</volume>
          , no.
          <issue>4</issue>
          , pp.
          <fpage>237</fpage>
          -
          <lpage>270</lpage>
          ,
          <year>2004</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>C. K.</given-names>
            <surname>Allison</surname>
          </string-name>
          ,
          <string-name>
            <surname>K. M. Revell</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          <string-name>
            <surname>Sears</surname>
            , and
            <given-names>N. A.</given-names>
          </string-name>
          <string-name>
            <surname>Stanton</surname>
          </string-name>
          , “
          <article-title>Systems Theoretic Accident Model and Process (STAMP) safety modelling applied to an aircraft rapid decompression event,” Safety science</article-title>
          , vol.
          <volume>98</volume>
          , pp.
          <fpage>159</fpage>
          -
          <lpage>166</lpage>
          ,
          <year>2017</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>R. R.</given-names>
            <surname>Hofman</surname>
          </string-name>
          and G. Klein, “
          <article-title>Explaining explanation, part 1: theoretical foundations,” IEEE Intelligent Systems</article-title>
          , vol.
          <volume>32</volume>
          , no.
          <issue>3</issue>
          , pp.
          <fpage>68</fpage>
          -
          <lpage>73</lpage>
          ,
          <year>2017</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>T.</given-names>
            <surname>Miller</surname>
          </string-name>
          , “
          <source>Explanation in artificial intelligence: Insights from the social sciences,” Artificial Intelligence</source>
          ,
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>P. M.</given-names>
            <surname>Dung</surname>
          </string-name>
          , “
          <article-title>On the acceptability of arguments and its fundamental role in nonmonotonic reasoning, logic programming and n-person games</article-title>
          ,
          <source>” Artificial intelligence</source>
          , vol.
          <volume>77</volume>
          , no.
          <issue>2</issue>
          , pp.
          <fpage>321</fpage>
          -
          <lpage>357</lpage>
          ,
          <year>1995</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>P.</given-names>
            <surname>Ladkin</surname>
          </string-name>
          and
          <string-name>
            <given-names>K.</given-names>
            <surname>Loer</surname>
          </string-name>
          , “
          <article-title>Analysing aviation accidents using WB-Analysis -- An application of multimodal reasoning</article-title>
          ,”
          <year>1998</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>R. R.</given-names>
            <surname>Hofman</surname>
          </string-name>
          and G. Klein, “
          <article-title>Explaining explanation, part 1: theoretical foundations,” IEEE Intelligent Systems</article-title>
          , vol.
          <volume>32</volume>
          , no.
          <issue>3</issue>
          , pp.
          <fpage>68</fpage>
          -
          <lpage>73</lpage>
          ,
          <year>2017</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>