Ivy: Safety Verification by Interactive Generalization

Size: px
Start display at page:

Download "Ivy: Safety Verification by Interactive Generalization"

Transcription

1 Ivy: Safety Verification by Interactive Generalization Oded Padon Verification Day 1-June-2016 [PLDI 16] Oded Padon, Kenneth McMillan, Aurojit Panda, Mooly Sagiv, Sharon Shoham. Ivy: Safety Verification by Interactive Generalization.

2 Motivation Software is everywhere Distributed systems are everywhere Verification is needed to ensure safety of critical systems 2

3 Why Verify Distributed Systems? Distributed systems are notoriously hard to get right Bugs occur on rare scenarios Hard to test/reproduce Testing covers tiny fraction of behaviors Leaves most bugs for production Even small protocols can be tricky

4 Safety of Transition Systems Transition System Bad Reach Initial System S is safe if no bad state is reachable R 0 = Init Initial states, reachable in 0 transitions R i+1 = R i { and R i } R = R 0 R 1 R 2 Safety: R Bad = K-Safety: R K Bad = 4

5 Inductive Invariants Transition System Inv Bad Reach Initial System S is safe if no bad state is reachable System S is safe iff there exists an inductive invariant Inv s.t.: Inv Bad = (Safety) Init Inv (Initiation) if σ Inv and σ σ then σ Inv (Consecution) 5

6 Counterexample To Induction (CTI) States σ,σ are a CTI of Inv if: σ Inv σ Inv σ σ Inv σ Inv σ Inv A CTI may indicate: A bug in the system A bug in the safety property A bug in the inductive invariant Too weak Too strong 6

7 Strengthening & Weakening from CTI Strengthening Inv σ Inv σ Inv Weakening Inv σ Inv σ' σ σ 7

8 Modeling with Logic SAT/SMT has made huge progress in the last decade Great impact on verification: Z3, Dafny, IronClad/IronFleet, and more State: finite first-order structure over vocabulary V Initial states and safety property (first-order formulas): Init(V) initial states Bad(V) bad states Transition relation: first-order formula TR(V, V ) V is a copy of V describing the state [LPAR 10] K.R.M. Leino: Dafny: An Automatic Program Verifier for Functional Correctness [SOSP 15] C. Hawblitzel, J. Howell, M. Kapritsos, J.R. Lorch, B. Parno, M. Roberts, S. Setty, B. Zill: IronFleet: proving practical distributed systems correct 8

9 Inductive Invariant Inv is an inductive invariant if: Initiation: Init Inv Safety: Inv Bad Consecution: Inv TR Inv InitInv unsat InvBad unsat InvTRInv unsat System State Space Inv Bad Reach Initial 9

10 Challenges 1. Formal specification: Modeling the system (TR, Init) Formalizing the safety property (Bad) Specifying in logic 2. Deduction Checking inductiveness Undecability of implication checking Arithmetic, quantifier alternation, unbounded state 3. Inductive Invariants for Deductive Verification (Inv) Hard to specify Hard to infer Undecable even when deduction is decable 10

11 Existing approaches Automated invariant inference Model checking Exploit finite state / finite abstraction Abstract Interpretation Sound abstraction Limited for infinite state systems due to undecability Use SMT for deduction with manual program annotations (e.g. Dafny) Requires programmer effort to prove inductive invariants SMT solver may diverge (matching loops, arithmetic) Interactive theorem provers (e.g. Coq, Isabelle/HOL) Programmer gives inductive invariant and proves it Huge programmer effort (~50 lines of proof per line of code) 11

12 Our Approach in Ivy Restrict the specification language for decability Deduction is decable with SAT solvers Challenge: model systems in a restricted language I can dece inductiveness! Finding inductive invariants: Combine automated techniques with human guance Key: generalization from counterexamples to induction Graphical user interaction Decability allows reliable automated checks 12

13 Expressiveness Expressiveness vs. Automation COQ Dafny Ivy Static Analysis Types Automation Coq Dafny Ivy Static Analysis Invariant User User User + System System Deduction User System (Z3) + User System (EPR Z3) System 13

14 Relational Modeling Language (RML) Designed to make verification tasks decable Yet expressive enough to model systems Finite relations and stratified function symbols Used to describe system state E.g., pending packets, nodes local data structures Also used to record ghost information Stratification: function f: A B, so no function g: B A Universally quantified axioms Total orders, partial orders, lists, trees, rings, quorums, No numerics Simple (quantifier-free) updates Imperative constructs with non-determinism Turing-Complete Universal inductive invariants are decable to check I can dece inductiveness! 14

15 Effectively Propositional Logic EPR a.k.a. Bernays-Schönfinkel-Ramsey class Limited fragment of first-order logic Restricted quantifier prefix: ** φ Q.F. No * * No function symbols Possible to add stratified function symbols No arithmetic Small model property x 1,, x n. y 1,,y m.φ Q.F. has a model iff it has a model of at most n+k elements (k - number of constant symbols) Satisfiability is decable NEXPTIME / 2 Supported by theorem provers (e.g., Z3, iprover, Vampire) F. Ramsey. On a problem in formal logic. Proc. London Math. Soc

16 Using EPR for Verification System Model V vocabulary with relations and stratified function symbols TR(V, V ) transition relation * * Alternation-Free: Init(V) initial states Boolean combination of Bad(V) bad states closed (e.g. * and assertion * formulas violation) * * * * Inv(V) is an inductive invariant if: A-F Init(V) Inv(V) InitInv unsat Inv(V) TR(V,V ) Inv(V ) InvTRInv unsat Inv(V) Bad(V) InvBad unsat Decable to check SAT( * * ) 16

17 Example: Leader Election in a Ring Nodes are organized in a ring Each node has a unique numeric Protocol: Each node sends its to the A node that receives a message passes it (to the ) if the in the message is higher than the node s own A node that receives its own becomes the leader Theorem: The protocol selects at most one leader [CACM 79] E. Chang and R. Roberts. An improved algorithm for decentralized extrema-finding in circular configurations of processes 17

18 Example: Leader Election in a Ring Nodes are organized in a ring Each node has a unique numeric Protocol: Each node sends its to the A node that receives a message passes it (to the ) if the in the message is higher than the node s own A node that receives its own becomes the leader Theorem: The protocol selects at most one leader [CACM 79] E. Chang and R. Roberts. An improved algorithm for decentralized extrema-finding in circular configurations of processes 18

19 Leader Election Protocol (RML) (ID, ID) total order on node s btw (Node, Node, Node) the ring topology : Node ID relate a node to its pending(id, Node) pending messages leader(node) leader(n) means n is the leader while true do { } // send(n1) n1 := *; n2 := *; assume (n1, n2); pending.insert([n1], n2) conjecture I 0 // receive(n1) m, n1 := pending.remove(); if [n1] = m then: // found leader leader.insert(n1) else if [n1] m then: // pass message n2 := *; assume (n1, n2); pending.insert(m, n2) = x, y: Node. x y leader(x) [x] [y]

20 Bounded Model Checking (BMC) Leader Protocol Bound k Safety Property I 0 : At most one leader BMC VC Generator Verification Condition: Init(V 0 ) TR(V 0, V 1 ) TR(V k-1, V k ) I 0 (V k ) EPR Solver Counterexample Trace Proof 20

21 BMC(2) n 1 L n 1 L n 2 1 L initial I 0 n 1 L n 2 1 L n 2 1 L snd(n 1 ) rcv(n 2 ) I 0 I 0

22 Leader Protocol 2 nd attempt Axiom x, y: Node. [x] = [y] x = y BMC(1) OK BMC(2) OK BMC(3) OK BMC(4) OK BMC(5) OK BMC(6) OK BMC(7) OK BMC(8) OK Looks good, let s find an inductive invariant!

23 Invariant Inference in Ivy Model Candate Inductive Invariant Inductive Invariant Found Yes Inductive? No Modify candate invariant Find minimal CTI Generalize from CTI User Automation

24 Interactive Generalization from CTI Generalize from CTI User Automation 1. Generalize by removing facts to form a conjecture User graphically selects which facts to remove 2. Check if the conjecture is true up to K: BMC(K) User determines the right K to use Ivy uses a SAT solver - sound & complete 3. Automatically remove more facts: Interpolate(K) Ivy uses the SAT solver to discover more facts that can be removed User examines the result it could be wrong

25 Algorithmic Deductive Verification (1) Leader Protocol Inv = I 0 Bad = I 0 VC Generator Init Inv Inv(V) TR(V,V ) Inv(V ) Inv(V) Bad(V) CTI EPR Solver I 0 I 0 pnd 1 n 1 L 2 n 2 L rcv(n 1 ) 1 n 1L 2 n 2 L

26 Generalize from CTI (1) pnd 1 n 1 L 2 n 2 L Only the highest can be self pending 1. Each node sends its to the 2. A node that receives a message passes it (to the in the ring) if the in the message is higher than the node s own 3. A node that receives its own becomes the leader

27 Generalize from CTI (1) pnd 1 n 1 L 2 n 2 L Only the highest can be self pending Project to {pnd,, } pnd 1 2 C 1 = n 1, n 2 : Node. n 1 n 2 pnd([n 1 ], n 1 ) [n] 1 [n 2 ] [n 1 ] [n 2 ] n 1 n 2 BMC VC Generator (K=3, C 1 ) BMC(3) Init(V 0 )TR(V 0,V 1 )TR(V 1,V 2 )TR(V 1,V 3 )C 1 (V 3 ) EPR Solver Proof

28 Generalize from CTI (1) pnd 1 n 1 L 2 n 2 L Project to {pnd,, } Only the highest can be self pending pnd 1 n 1 2 C 1 = n 1, n 2 : Node. n 1 n 2 pnd([n 1 ], n 1 ) [n] 1 [n 2 ] [n 1 ] [n 2 ] Interp(3) n 2 C I 1 = n 1, n 2 : Node. pnd([n 1 ], n 1 ) [n] 1 [n 2 ] [n 1 ] [n 2 ] BMC VC Generator (K=3, C 1 ) Lookd good, add to the invariant as I 1 Init(V 0 )TR(V 0,V 1 )TR(V 1,V 2 )TR(V 1,V 3 )C 1 (V 3 ) EPR Solver Proof + Minimal UNSAT core

29 Algorithmic Deductive Verification (2) Leader Protocol Inv = I 0 I 1 Bad = I 0 VC Generator Init Inv Inv(V) TR(V,V ) Inv(V ) Inv(V) Bad(V) CTI EPR Solver I 0 I 1 I 1 1 n 1 L pnd 2 n 2 L 2 n 3 L rcv(n 1 ) 1 n 1 L pnd 2 n 2 L 2 n 3 L

30 1 n 1 L pnd 2 n 2 L Generalize from CTI (2) 2 n 3 L Cannot bypass nodes with higher s 1. Each node sends its to the 2. A node that receives a message passes it (to the in the ring) if the in the message is higher than the node s own 3. A node that receives its own becomes the leader

31 1 pnd n 1 L 2 n 2 L Generalize from CTI (2) 2 n 3 L Project to {pnd,, } 1 pnd 2 2 Cannot bypass nodes with higher s C 2 = n 1, n 2, n 3 : Node. (n 1,n 2,n 3 ) ([n 1 ],[n 2 ],[n 3 ]) [n 1 ] [n 2 ] [n 3 ] pnd([n 2 ], n 1 ) n 1 n 2 n 3 BMC VC Generator (K=3, C 2 ) BMC(3) Init(V 0 )TR(V 0,V 1 )TR(V 1,V 2 )TR(V 1,V 3 )C 2 (V 3 ) EPR Solver Counterexample Trace

32 1 pnd n 1 L 2 n 2 L Generalize from CTI (2) 2 n 3 L Project to {pnd,,,btw} 1 n 1 pnd 2 n 2 btw BMC(3) 2 n 3 Cannot bypass nodes with higher s C 2 = n 1, n 2, n 3 : Node. (n 1,n 2,n 3 ) ([n 1 ],[n 2 ],[n 3 ]) [n 1 ] [n 2 ] [n 3 ] pnd([n 2 ], n 1 ) btw(n 1, n 2, n 3 ) BMC VC Generator (K=3, C 2 ) Init(V 0 )TR(V 0,V 1 )TR(V 1,V 2 )TR(V 1,V 3 )C 2 (V 3 ) EPR Solver Proof

33 1 pnd n 1 L 2 n 2 L Generalize from CTI (2) 2 n 3 L Project to {pnd,,,btw} 1 n 1 n 1 pnd 2 n 2 btw Interp(3) pnd 2 n 2 btw 2 n 3 n 3 2 Cannot bypass nodes with higher s C 2 = n 1, n 2, n 3 : Node. (n 1,n 2,n 3 ) ([n 1 ],[n 2 ],[n 3 ]) [n 1 ] [n 2 ] [n 3 ] pnd([n 2 ], n 1 ) btw(n 1, n 2, n 3 ) This looks good, add to the invariant as I 2 C 2 = n 1, n 2, n 3 : Node. btw(n 1, n 2, n 3 ) pnd([n 2 ], n 1 ) [n 2 ] [n 3 ] I 2

34 Algorithmic Deductive Verification (3) Leader Protocol Inv = I 0 I 1 I 2 Bad = I 0 VC Generator Init Inv Inv(V) TR(V,V ) Inv(V ) Inv(V) Bad(V) EPR Solver Proof I 0 I 1 I 2 is an inductive invariant for the leader protocol, which proves the protocol is safe

35 Completeness and Interaction Complexity Any generalization from CTI adds one universal clause to the invariant The invariant is constructed in CNF If there is a universal invariant with N clauses, it can be obtained by the user in N generalization steps Assuming the user is optimal If the user is sub-optimal, backtracking (weakening) may be needed

36 Verified Protocols Protocol Model Types Relations & Functions Property (# Literals) Invariant (# Literals) CTI Gen. Steps Leader in Ring Learning Switch DB Chain Replication Chord Lock Server 500 Coq lines [Verdi] Distributed Lock 1 week [IronFleet] Paxos Raft (1h) (1h) Work in progress

37 Ivy Summary & Lessons Learned Ivy: RML modeling language that makes deduction decable Interactive generalization for finding inducting invariants Application to the domain of distributed protocols User intuition and machine heuristics complement each other: User has the ability to ignore irrelevant facts and intuition that leads to better generalizations Machine is better at finding bugs and corner cases The safety of many protocols can be proven w/o reasoning about arithmetic operations or set cardinalities Many important properties can be captured in a (parametric) model that abstracts the actual numerical values Unbounded topologies Unique paths (ring, trees, ) 37

38 Expressiveness Current & Future Work COQ Dafny Ivy Static Analysis Types Automation More expressiveness, keeping decability System, Spec, Invariant (proof) Verifying more systems (Paxos and Raft are ) Inferring inductive invariants (more) automatically Better theoretical understanding of limitations and tradeoffs 38

Verification of Distributed Protocols Using Decidable Logic

Verification of Distributed Protocols Using Decidable Logic Verification of Distributed Protocols Using Decidable Logic Sharon Shoham Tel Aviv University Programming Languages Mentoring Workshop 2019 The research leading to these results has received funding from

More information

Modularity for decidability of deductive verification with applications to distributed systems. Mooly Sagiv

Modularity for decidability of deductive verification with applications to distributed systems. Mooly Sagiv Modularity for decability of deductive verification with applications to distributed systems Mooly Sagiv http://microsoft.github.io/ivy/ Contributors Marcelo Taube, Giuliano Losa, Kenneth McMillan, Oded

More information

Modularity for decidability of deductive verification with applications to distributed systems. Mooly Sagiv

Modularity for decidability of deductive verification with applications to distributed systems. Mooly Sagiv Modularity for decidability of deductive verification with applications to distributed systems Mooly Sagiv Contributors Marcelo Taube, Giuliano Losa, Kenneth McMillan, Oded Padon, Sharon Shoham http://microsoft.github.io/ivy/

More information

Ivy: Interactive Verification of Parameterized Systems via Effectively Propositional Reasoning

Ivy: Interactive Verification of Parameterized Systems via Effectively Propositional Reasoning Ivy: Interactive Verification of Parameterized Systems via Effectively Propositional Reasoning Abstract The design and implementation of parametric systems can be very tricky even for experienced researchers.

More information

Decidability of Inferring Inductive Invariants

Decidability of Inferring Inductive Invariants Decidability of Inferring Inductive Invariants Oded Padon Tel Aviv University, Israel odedp@mail.tau.ac.il Neil Immerman University of Massachusetts, Amherst, USA immerman@cs.umass.edu Sharon Shoham The

More information

or simply: IC3 A Simplified Description

or simply: IC3 A Simplified Description Incremental Construction of Inductive Clauses for Indubitable Correctness or simply: IC3 A Simplified Description Based on SAT-Based Model Checking without Unrolling Aaron Bradley, VMCAI 2011 Efficient

More information

IC3 and Beyond: Incremental, Inductive Verification

IC3 and Beyond: Incremental, Inductive Verification IC3 and Beyond: Incremental, Inductive Verification Aaron R. Bradley ECEE, CU Boulder & Summit Middle School IC3 and Beyond: Incremental, Inductive Verification 1/62 Induction Foundation of verification

More information

Hoare Logic I. Introduction to Deductive Program Verification. Simple Imperative Programming Language. Hoare Logic. Meaning of Hoare Triples

Hoare Logic I. Introduction to Deductive Program Verification. Simple Imperative Programming Language. Hoare Logic. Meaning of Hoare Triples Hoare Logic I Introduction to Deductive Program Verification Işıl Dillig Program Spec Deductive verifier FOL formula Theorem prover valid contingent Example specs: safety (no crashes), absence of arithmetic

More information

Bounded Quantifier Instantiation for Checking Inductive Invariants

Bounded Quantifier Instantiation for Checking Inductive Invariants Bounded Quantifier Instantiation for Checking Inductive Invariants Yotam M. Y. Feldman 1, Oded Padon 1, Neil Immerman 2, Mooly Sagiv 1, and Sharon Shoham 1 1 Tel Aviv University, Tel Aviv, Israel 2 UMass,

More information

SAT-Based Verification with IC3: Foundations and Demands

SAT-Based Verification with IC3: Foundations and Demands SAT-Based Verification with IC3: Foundations and Demands Aaron R. Bradley ECEE, CU Boulder & Summit Middle School SAT-Based Verification with IC3:Foundations and Demands 1/55 Induction Foundation of verification

More information

Deductive Verification

Deductive Verification Deductive Verification Mooly Sagiv Slides from Zvonimir Rakamaric First-Order Logic A formal notation for mathematics, with expressions involving Propositional symbols Predicates Functions and constant

More information

Scalable and Accurate Verification of Data Flow Systems. Cesare Tinelli The University of Iowa

Scalable and Accurate Verification of Data Flow Systems. Cesare Tinelli The University of Iowa Scalable and Accurate Verification of Data Flow Systems Cesare Tinelli The University of Iowa Overview AFOSR Supported Research Collaborations NYU (project partner) Chalmers University (research collaborator)

More information

Bounded Model Checking with SAT/SMT. Edmund M. Clarke School of Computer Science Carnegie Mellon University 1/39

Bounded Model Checking with SAT/SMT. Edmund M. Clarke School of Computer Science Carnegie Mellon University 1/39 Bounded Model Checking with SAT/SMT Edmund M. Clarke School of Computer Science Carnegie Mellon University 1/39 Recap: Symbolic Model Checking with BDDs Method used by most industrial strength model checkers:

More information

Understanding IC3. Aaron R. Bradley. ECEE, CU Boulder & Summit Middle School. Understanding IC3 1/55

Understanding IC3. Aaron R. Bradley. ECEE, CU Boulder & Summit Middle School. Understanding IC3 1/55 Understanding IC3 Aaron R. Bradley ECEE, CU Boulder & Summit Middle School Understanding IC3 1/55 Further Reading This presentation is based on Bradley, A. R. Understanding IC3. In SAT, June 2012. http://theory.stanford.edu/~arbrad

More information

Quantifiers. Leonardo de Moura Microsoft Research

Quantifiers. Leonardo de Moura Microsoft Research Quantifiers Leonardo de Moura Microsoft Research Satisfiability a > b + 2, a = 2c + 10, c + b 1000 SAT a = 0, b = 3, c = 5 Model 0 > 3 + 2, 0 = 2 5 + 10, 5 + ( 3) 1000 Quantifiers x y x > 0 f x, y = 0

More information

FMCAD 2013 Parameter Synthesis with IC3

FMCAD 2013 Parameter Synthesis with IC3 FMCAD 2013 Parameter Synthesis with IC3 A. Cimatti, A. Griggio, S. Mover, S. Tonetta FBK, Trento, Italy Motivations and Contributions Parametric descriptions of systems arise in many domains E.g. software,

More information

arxiv: v1 [cs.lo] 29 May 2014

arxiv: v1 [cs.lo] 29 May 2014 Under consideration for publication in Theory and Practice of Logic Programming 1 arxiv:1405.7739v1 [cs.lo] 29 May 2014 (Quantified) Horn Constraint Solving for Program Verification and Synthesis Andrey

More information

SAT-based Model Checking: Interpolation, IC3, and Beyond

SAT-based Model Checking: Interpolation, IC3, and Beyond SAT-based Model Checking: Interpolation, IC3, and Beyond Orna GRUMBERG a, Sharon SHOHAM b and Yakir VIZEL a a Computer Science Department, Technion, Haifa, Israel b School of Computer Science, Academic

More information

Floyd-Hoare Style Program Verification

Floyd-Hoare Style Program Verification Floyd-Hoare Style Program Verification Deepak D Souza Department of Computer Science and Automation Indian Institute of Science, Bangalore. 9 Feb 2017 Outline of this talk 1 Overview 2 Hoare Triples 3

More information

Model Checking: An Introduction

Model Checking: An Introduction Model Checking: An Introduction Meeting 3, CSCI 5535, Spring 2013 Announcements Homework 0 ( Preliminaries ) out, due Friday Saturday This Week Dive into research motivating CSCI 5535 Next Week Begin foundations

More information

Tutorial 1: Modern SMT Solvers and Verification

Tutorial 1: Modern SMT Solvers and Verification University of Illinois at Urbana-Champaign Tutorial 1: Modern SMT Solvers and Verification Sayan Mitra Electrical & Computer Engineering Coordinated Science Laboratory University of Illinois at Urbana

More information

Abstractions and Decision Procedures for Effective Software Model Checking

Abstractions and Decision Procedures for Effective Software Model Checking Abstractions and Decision Procedures for Effective Software Model Checking Prof. Natasha Sharygina The University of Lugano, Carnegie Mellon University Microsoft Summer School, Moscow, July 2011 Lecture

More information

Proof Certificates for SMT-based Model Checkers for Infinite State Systems. Alain Mebsout and Cesare Tinelli FMCAD 2016 October 5 th, 2016

Proof Certificates for SMT-based Model Checkers for Infinite State Systems. Alain Mebsout and Cesare Tinelli FMCAD 2016 October 5 th, 2016 Proof Certificates for SMT-based Model Checkers for Infinite State Systems Alain Mebsout and Cesare Tinelli FMCAD 2016 October 5 th, 2016 Motivation Model checkers return error traces but no evidence when

More information

Ranking Verification Counterexamples: An Invariant guided approach

Ranking Verification Counterexamples: An Invariant guided approach Ranking Verification Counterexamples: An Invariant guided approach Ansuman Banerjee Indian Statistical Institute Joint work with Pallab Dasgupta, Srobona Mitra and Harish Kumar Complex Systems Everywhere

More information

Solving SAT Modulo Theories

Solving SAT Modulo Theories Solving SAT Modulo Theories R. Nieuwenhuis, A. Oliveras, and C.Tinelli. Solving SAT and SAT Modulo Theories: from an Abstract Davis-Putnam-Logemann-Loveland Procedure to DPLL(T) Mooly Sagiv Motivation

More information

Software Verification using Predicate Abstraction and Iterative Refinement: Part 1

Software Verification using Predicate Abstraction and Iterative Refinement: Part 1 using Predicate Abstraction and Iterative Refinement: Part 1 15-414 Bug Catching: Automated Program Verification and Testing Sagar Chaki November 28, 2011 Outline Overview of Model Checking Creating Models

More information

Proof Certificates for SMT-based Model Checkers. Alain Mebsout and Cesare Tinelli SMT 2016 July 2 nd, 2016

Proof Certificates for SMT-based Model Checkers. Alain Mebsout and Cesare Tinelli SMT 2016 July 2 nd, 2016 Proof Certificates for SMT-based Model Checkers Alain Mebsout and Cesare Tinelli SMT 2016 July 2 nd, 2016 Motivation Model checkers return error traces but no evidence when they say yes Complex tools 2

More information

02 Propositional Logic

02 Propositional Logic SE 2F03 Fall 2005 02 Propositional Logic Instructor: W. M. Farmer Revised: 25 September 2005 1 What is Propositional Logic? Propositional logic is the study of the truth or falsehood of propositions or

More information

Heuristics for Efficient SAT Solving. As implemented in GRASP, Chaff and GSAT.

Heuristics for Efficient SAT Solving. As implemented in GRASP, Chaff and GSAT. Heuristics for Efficient SAT Solving As implemented in GRASP, Chaff and GSAT. Formulation of famous problems as SAT: k-coloring (1/2) The K-Coloring problem: Given an undirected graph G(V,E) and a natural

More information

Combinations of Theories for Decidable Fragments of First-order Logic

Combinations of Theories for Decidable Fragments of First-order Logic Combinations of Theories for Decidable Fragments of First-order Logic Pascal Fontaine Loria, INRIA, Université de Nancy (France) Montreal August 2, 2009 Montreal, August 2, 2009 1 / 15 Context / Motivation

More information

From SAT To SMT: Part 1. Vijay Ganesh MIT

From SAT To SMT: Part 1. Vijay Ganesh MIT From SAT To SMT: Part 1 Vijay Ganesh MIT Software Engineering & SMT Solvers An Indispensable Tactic for Any Strategy Formal Methods Program Analysis SE Goal: Reliable/Secure Software Automatic Testing

More information

Computational Logic and the Quest for Greater Automation

Computational Logic and the Quest for Greater Automation Computational Logic and the Quest for Greater Automation Lawrence C Paulson, Distinguished Affiliated Professor for Logic in Informatics Technische Universität München (and Computer Laboratory, University

More information

Inductive Theorem Proving

Inductive Theorem Proving Introduction Inductive Proofs Automation Conclusion Automated Reasoning P.Papapanagiotou@sms.ed.ac.uk 11 October 2012 Introduction Inductive Proofs Automation Conclusion General Induction Theorem Proving

More information

Propositional and Predicate Logic. jean/gbooks/logic.html

Propositional and Predicate Logic.   jean/gbooks/logic.html CMSC 630 February 10, 2009 1 Propositional and Predicate Logic Sources J. Gallier. Logic for Computer Science, John Wiley and Sons, Hoboken NJ, 1986. 2003 revised edition available on line at http://www.cis.upenn.edu/

More information

SAT/SMT/AR Introduction and Applications

SAT/SMT/AR Introduction and Applications SAT/SMT/AR Introduction and Applications Ákos Hajdu Budapest University of Technology and Economics Department of Measurement and Information Systems 1 Ákos Hajdu About me o PhD student at BME MIT (2016

More information

SMT-Based Verification of Parameterized Systems

SMT-Based Verification of Parameterized Systems SMT-Based Verification of Parameterized Systems Arie Gurfinkel SEI/CMU, USA University of Waterloo, Canada arie.gurfinkel@uwaterloo.ca Sharon Shoham Tel Aviv University, Israel sharon.shoham@gmail.com

More information

Nonlinear Control as Program Synthesis (A Starter)

Nonlinear Control as Program Synthesis (A Starter) Nonlinear Control as Program Synthesis (A Starter) Sicun Gao MIT December 15, 2014 Preliminaries Definition (L RF ) L RF is the first-order language over the reals that allows arbitrary numerically computable

More information

COP4020 Programming Languages. Introduction to Axiomatic Semantics Prof. Robert van Engelen

COP4020 Programming Languages. Introduction to Axiomatic Semantics Prof. Robert van Engelen COP4020 Programming Languages Introduction to Axiomatic Semantics Prof. Robert van Engelen Assertions and Preconditions Assertions are used by programmers to verify run-time execution An assertion is a

More information

Topics in Model-Based Reasoning

Topics in Model-Based Reasoning Towards Integration of Proving and Solving Dipartimento di Informatica Università degli Studi di Verona Verona, Italy March, 2014 Automated reasoning Artificial Intelligence Automated Reasoning Computational

More information

Efficient E-matching for SMT Solvers. Leonardo de Moura, Nikolaj Bjørner Microsoft Research, Redmond

Efficient E-matching for SMT Solvers. Leonardo de Moura, Nikolaj Bjørner Microsoft Research, Redmond Efficient E-matching for SMT Solvers Leonardo de Moura, Nikolaj Bjørner Microsoft Research, Redmond The Z3tting Z3 is an inference engine tailored towards formulas arising from program verification tools

More information

Property Directed Abstract Interpretation

Property Directed Abstract Interpretation Property Directed Abstract Interpretation Noam Rinetzky 1 and Sharon Shoham 2 1 Tel Aviv University, Israel 2 The Academic College of Tel Aviv Yaffo, Israel Abstract. Recently, Bradley proposed the PDR/IC3

More information

Leonardo de Moura Microsoft Research

Leonardo de Moura Microsoft Research Leonardo de Moura Microsoft Research Logic is The Calculus of Computer Science (Z. Manna). High computational complexity Naïve solutions will not scale Is formula F satisfiable modulo theory T? SMT solvers

More information

Axiomatic Semantics: Verification Conditions. Review of Soundness and Completeness of Axiomatic Semantics. Announcements

Axiomatic Semantics: Verification Conditions. Review of Soundness and Completeness of Axiomatic Semantics. Announcements Axiomatic Semantics: Verification Conditions Meeting 12, CSCI 5535, Spring 2009 Announcements Homework 4 is due tonight Wed forum: papers on automated testing using symbolic execution 2 Questions? Review

More information

Integrating Induction and Deduction for Verification and Synthesis

Integrating Induction and Deduction for Verification and Synthesis Integrating Induction and Deduction for Verification and Synthesis Sanjit A. Seshia Associate Professor EECS Department UC Berkeley DATE 2013 Tutorial March 18, 2013 Bob s Vision: Exploit Synergies between

More information

ArgoCaLyPso SAT-Inspired Coherent Logic Prover

ArgoCaLyPso SAT-Inspired Coherent Logic Prover ArgoCaLyPso SAT-Inspired Coherent Logic Prover Mladen Nikolić and Predrag Janičić Automated Reasoning GrOup (ARGO) Faculty of Mathematics University of, February, 2011. Motivation Coherent logic (CL) (also

More information

a > 3, (a = b a = b + 1), f(a) = 0, f(b) = 1

a > 3, (a = b a = b + 1), f(a) = 0, f(b) = 1 Yeting Ge New York University Leonardo de Moura Microsoft Research a > 3, (a = b a = b + 1), f(a) = 0, f(b) = 1 Dynamic symbolic execution (DART) Extended static checking Test-case generation Bounded model

More information

Integrating Induction, Deduction and Structure for Synthesis

Integrating Induction, Deduction and Structure for Synthesis Integrating Induction, Deduction and Structure for Synthesis Sanjit A. Seshia Associate Professor EECS Department UC Berkeley Students & Postdocs: S. Jha, W.Li, A. Donze, L. Dworkin, B. Brady, D. Holcomb,

More information

The State Explosion Problem

The State Explosion Problem The State Explosion Problem Martin Kot August 16, 2003 1 Introduction One from main approaches to checking correctness of a concurrent system are state space methods. They are suitable for automatic analysis

More information

Last Time. Inference Rules

Last Time. Inference Rules Last Time When program S executes it switches to a different state We need to express assertions on the states of the program S before and after its execution We can do it using a Hoare triple written

More information

Automated Program Verification and Testing 15414/15614 Fall 2016 Lecture 3: Practical SAT Solving

Automated Program Verification and Testing 15414/15614 Fall 2016 Lecture 3: Practical SAT Solving Automated Program Verification and Testing 15414/15614 Fall 2016 Lecture 3: Practical SAT Solving Matt Fredrikson mfredrik@cs.cmu.edu October 17, 2016 Matt Fredrikson SAT Solving 1 / 36 Review: Propositional

More information

Interpolation and Symbol Elimination in Vampire

Interpolation and Symbol Elimination in Vampire Interpolation and Symbol Elimination in Vampire Kryštof Hoder 1, Laura Kovács 2, and Andrei Voronkov 1 1 University of Manchester 2 TU Vienna Abstract. It has recently been shown that proofs in which some

More information

Validating QBF Invalidity in HOL4

Validating QBF Invalidity in HOL4 Interactive Theorem Proving (ITP) 14 July, 2010 Quantified Boolean Formulae Quantified Boolean Formulae Motivation System Overview Related Work QBF = propositional logic + quantifiers over Boolean variables

More information

Lecture 2: Symbolic Model Checking With SAT

Lecture 2: Symbolic Model Checking With SAT Lecture 2: Symbolic Model Checking With SAT Edmund M. Clarke, Jr. School of Computer Science Carnegie Mellon University Pittsburgh, PA 15213 (Joint work over several years with: A. Biere, A. Cimatti, Y.

More information

Formal Verification Techniques. Riccardo Sisto, Politecnico di Torino

Formal Verification Techniques. Riccardo Sisto, Politecnico di Torino Formal Verification Techniques Riccardo Sisto, Politecnico di Torino State exploration State Exploration and Theorem Proving Exhaustive exploration => result is certain (correctness or noncorrectness proof)

More information

Software Verification with Abstraction-Based Methods

Software Verification with Abstraction-Based Methods Software Verification with Abstraction-Based Methods Ákos Hajdu PhD student Department of Measurement and Information Systems, Budapest University of Technology and Economics MTA-BME Lendület Cyber-Physical

More information

Lecture Notes on Software Model Checking

Lecture Notes on Software Model Checking 15-414: Bug Catching: Automated Program Verification Lecture Notes on Software Model Checking Matt Fredrikson André Platzer Carnegie Mellon University Lecture 19 1 Introduction So far we ve focused on

More information

A Short Introduction to Hoare Logic

A Short Introduction to Hoare Logic A Short Introduction to Hoare Logic Supratik Chakraborty I.I.T. Bombay June 23, 2008 Supratik Chakraborty (I.I.T. Bombay) A Short Introduction to Hoare Logic June 23, 2008 1 / 34 Motivation Assertion checking

More information

Solvers for the Problem of Boolean Satisfiability (SAT) Will Klieber Aug 31, 2011

Solvers for the Problem of Boolean Satisfiability (SAT) Will Klieber Aug 31, 2011 Solvers for the Problem of Boolean Satisfiability (SAT) Will Klieber 15-414 Aug 31, 2011 Why study SAT solvers? Many problems reduce to SAT. Formal verification CAD, VLSI Optimization AI, planning, automated

More information

Artificial Intelligence Chapter 7: Logical Agents

Artificial Intelligence Chapter 7: Logical Agents Artificial Intelligence Chapter 7: Logical Agents Michael Scherger Department of Computer Science Kent State University February 20, 2006 AI: Chapter 7: Logical Agents 1 Contents Knowledge Based Agents

More information

Notes. Corneliu Popeea. May 3, 2013

Notes. Corneliu Popeea. May 3, 2013 Notes Corneliu Popeea May 3, 2013 1 Propositional logic Syntax We rely on a set of atomic propositions, AP, containing atoms like p, q. A propositional logic formula φ Formula is then defined by the following

More information

Property Checking By Logic Relaxation

Property Checking By Logic Relaxation Property Checking By Logic Relaxation Eugene Goldberg eu.goldberg@gmail.com arxiv:1601.02742v1 [cs.lo] 12 Jan 2016 Abstract We introduce a new framework for Property Checking (PC) of sequential circuits.

More information

- Introduction to propositional, predicate and higher order logics

- Introduction to propositional, predicate and higher order logics Lecture 1: Deductive Verification of Reactive Systems - Introduction to propositional, predicate and higher order logics - Deductive Invariance Proofs Cristina Seceleanu MRTC, MdH E-mail: cristina.seceleanu@mdh.se

More information

Reasoning about State Constraints in the Situation Calculus

Reasoning about State Constraints in the Situation Calculus Reasoning about State Constraints in the Situation Calculus Joint work with Naiqi Li and Yi Fan Yongmei Liu Dept. of Computer Science Sun Yat-sen University Guangzhou, China Presented at IRIT June 26,

More information

Solving Quantified Verification Conditions using Satisfiability Modulo Theories

Solving Quantified Verification Conditions using Satisfiability Modulo Theories Solving Quantified Verification Conditions using Satisfiability Modulo Theories Yeting Ge, Clark Barrett, Cesare Tinelli Solving Quantified Verification Conditions using Satisfiability Modulo Theories

More information

Integrating a SAT Solver with an LCF-style Theorem Prover

Integrating a SAT Solver with an LCF-style Theorem Prover Integrating a SAT Solver with an LCF-style Theorem Prover A Fast Decision Procedure for Propositional Logic for the System Tjark Weber webertj@in.tum.de PDPAR 05, July 12, 2005 Integrating a SAT Solver

More information

CS 4700: Foundations of Artificial Intelligence

CS 4700: Foundations of Artificial Intelligence CS 4700: Foundations of Artificial Intelligence Bart Selman selman@cs.cornell.edu Module: Knowledge, Reasoning, and Planning Part 2 Logical Agents R&N: Chapter 7 1 Illustrative example: Wumpus World (Somewhat

More information

CS156: The Calculus of Computation

CS156: The Calculus of Computation CS156: The Calculus of Computation Zohar Manna Winter 2010 It is reasonable to hope that the relationship between computation and mathematical logic will be as fruitful in the next century as that between

More information

The Impact of Craig s Interpolation Theorem. in Computer Science

The Impact of Craig s Interpolation Theorem. in Computer Science The Impact of Craig s Interpolation Theorem in Computer Science Cesare Tinelli tinelli@cs.uiowa.edu The University of Iowa Berkeley, May 2007 p.1/28 The Role of Logic in Computer Science Mathematical logic

More information

Symbolic Computation and Theorem Proving in Program Analysis

Symbolic Computation and Theorem Proving in Program Analysis Symbolic Computation and Theorem Proving in Program Analysis Laura Kovács Chalmers Outline Part 1: Weakest Precondition for Program Analysis and Verification Part 2: Polynomial Invariant Generation (TACAS

More information

Temporal Prophecy for Proving Temporal Properties of Infinite-State Systems

Temporal Prophecy for Proving Temporal Properties of Infinite-State Systems Temporal Prophecy for Proving Temporal Properties of Infinite-State Systems Oded Padon, Jochen Hoenicke, Kenneth L. McMillan, Andreas Podelski, Mooly Sagiv and Sharon Shoham Tel Aviv University, Israel

More information

Model Checking. Boris Feigin March 9, University College London

Model Checking. Boris Feigin March 9, University College London b.feigin@cs.ucl.ac.uk University College London March 9, 2005 Outline 1 2 Techniques Symbolic 3 Software 4 Vs. Deductive Verification Summary Further Reading In a nutshell... Model checking is a collection

More information

Axiomatic Semantics. Lecture 9 CS 565 2/12/08

Axiomatic Semantics. Lecture 9 CS 565 2/12/08 Axiomatic Semantics Lecture 9 CS 565 2/12/08 Axiomatic Semantics Operational semantics describes the meaning of programs in terms of the execution steps taken by an abstract machine Denotational semantics

More information

The TLA + proof system

The TLA + proof system The TLA + proof system Stephan Merz Kaustuv Chaudhuri, Damien Doligez, Leslie Lamport INRIA Nancy & INRIA-MSR Joint Centre, France Amir Pnueli Memorial Symposium New York University, May 8, 2010 Stephan

More information

Propositional Reasoning

Propositional Reasoning Propositional Reasoning CS 440 / ECE 448 Introduction to Artificial Intelligence Instructor: Eyal Amir Grad TAs: Wen Pu, Yonatan Bisk Undergrad TAs: Sam Johnson, Nikhil Johri Spring 2010 Intro to AI (CS

More information

WHAT IS AN SMT SOLVER? Jaeheon Yi - April 17, 2008

WHAT IS AN SMT SOLVER? Jaeheon Yi - April 17, 2008 WHAT IS AN SMT SOLVER? Jaeheon Yi - April 17, 2008 WHAT I LL TALK ABOUT Propositional Logic Terminology, Satisfiability, Decision Procedure First-Order Logic Terminology, Background Theories Satisfiability

More information

Formal methods in analysis

Formal methods in analysis Formal methods in analysis Jeremy Avigad Department of Philosophy and Department of Mathematical Sciences Carnegie Mellon University May 2015 Sequence of lectures 1. Formal methods in mathematics 2. Automated

More information

ILP = Logic, CS, ML Stop counting, start reasoning

ILP = Logic, CS, ML Stop counting, start reasoning ILP = Logic, CS, ML Stop counting, start reasoning Gilles Richard AOC team The story so far Several actors K. Brouwer K. Godel J. Herbrand A. Colmerauer R. Kowalski S. Muggleton L. Brouwer (1881-1966)

More information

Information Flow Analysis via Path Condition Refinement

Information Flow Analysis via Path Condition Refinement Information Flow Analysis via Path Condition Refinement Mana Taghdiri, Gregor Snelting, Carsten Sinz Karlsruhe Institute of Technology, Germany FAST September 16, 2010 KIT University of the State of Baden-Wuerttemberg

More information

Logical Abduction and its Applications in Program Verification. Isil Dillig MSR Cambridge

Logical Abduction and its Applications in Program Verification. Isil Dillig MSR Cambridge Logical Abduction and its Applications in Program Verification? Isil Dillig MSR Cambridge What is Abduction? Abduction: Opposite of deduction 2 / 21 What is Abduction? Abduction: Opposite of deduction

More information

Axiomatic Semantics. Operational semantics. Good for. Not good for automatic reasoning about programs

Axiomatic Semantics. Operational semantics. Good for. Not good for automatic reasoning about programs Review Operational semantics relatively l simple many flavors (small vs. big) not compositional (rule for while) Good for describing language implementation reasoning about properties of the language eg.

More information

Synthesizing from Components: Building from Blocks

Synthesizing from Components: Building from Blocks Synthesizing from Components: Building from Blocks Ashish Tiwari SRI International 333 Ravenswood Ave Menlo Park, CA 94025 Joint work with Sumit Gulwani (MSR), Vijay Anand Korthikanti (UIUC), Susmit Jha

More information

Model Checking, Theorem Proving, and Abstract Interpretation: The Convergence of Formal Verification Technologies

Model Checking, Theorem Proving, and Abstract Interpretation: The Convergence of Formal Verification Technologies Model Checking, Theorem Proving, and Abstract Interpretation: The Convergence of Formal Verification Technologies Tom Henzinger EPFL Three Verification Communities Model checking: -automatic, but inefficient

More information

Overview, cont. Overview, cont. Logistics. Optional Reference #1. Optional Reference #2. Workload and Grading

Overview, cont. Overview, cont. Logistics. Optional Reference #1. Optional Reference #2. Workload and Grading Course staff CS389L: Automated Logical Reasoning Lecture 1: ntroduction and Review of Basics şıl Dillig nstructor: şil Dillig E-mail: isil@cs.utexas.edu Office hours: Thursday after class until 6:30 pm

More information

Safety and Liveness Properties

Safety and Liveness Properties Safety and Liveness Properties Lecture #6 of Model Checking Joost-Pieter Katoen Lehrstuhl 2: Software Modeling and Verification E-mail: katoen@cs.rwth-aachen.de November 5, 2008 c JPK Overview Lecture

More information

EECS 144/244: Fundamental Algorithms for System Modeling, Analysis, and Optimization

EECS 144/244: Fundamental Algorithms for System Modeling, Analysis, and Optimization EECS 144/244: Fundamental Algorithms for System Modeling, Analysis, and Optimization Discrete Systems Lecture: State-Space Exploration Stavros Tripakis University of California, Berkeley Stavros Tripakis:

More information

Satisfiability Modulo Theories

Satisfiability Modulo Theories Satisfiability Modulo Theories Bruno Dutertre SRI International Leonardo de Moura Microsoft Research Satisfiability a > b + 2, a = 2c + 10, c + b 1000 SAT a = 0, b = 3, c = 5 Model 0 > 3 + 2, 0 = 2 5 +

More information

Introduction to Axiomatic Semantics

Introduction to Axiomatic Semantics #1 Introduction to Axiomatic Semantics #2 How s The Homework Going? Remember that you can t just define a meaning function in terms of itself you must use some fixed point machinery. #3 Observations A

More information

Counterexample-Guided Abstraction Refinement

Counterexample-Guided Abstraction Refinement Counterexample-Guided Abstraction Refinement Edmund Clarke Orna Grumberg Somesh Jha Yuan Lu Helmut Veith Seminal Papers in Verification (Reading Group) June 2012 O. Rezine () Verification Reading Group

More information

Lecture Notes on SAT Solvers & DPLL

Lecture Notes on SAT Solvers & DPLL 15-414: Bug Catching: Automated Program Verification Lecture Notes on SAT Solvers & DPLL Matt Fredrikson André Platzer Carnegie Mellon University Lecture 10 1 Introduction In this lecture we will switch

More information

Formal Verification of Mobile Network Protocols

Formal Verification of Mobile Network Protocols Dipartimento di Informatica, Università di Pisa, Italy milazzo@di.unipi.it Pisa April 26, 2005 Introduction Modelling Systems Specifications Examples Algorithms Introduction Design validation ensuring

More information

Foundations of Artificial Intelligence

Foundations of Artificial Intelligence Foundations of Artificial Intelligence 7. Propositional Logic Rational Thinking, Logic, Resolution Joschka Boedecker and Wolfram Burgard and Frank Hutter and Bernhard Nebel Albert-Ludwigs-Universität Freiburg

More information

LOGIC PROPOSITIONAL REASONING

LOGIC PROPOSITIONAL REASONING LOGIC PROPOSITIONAL REASONING WS 2017/2018 (342.208) Armin Biere Martina Seidl biere@jku.at martina.seidl@jku.at Institute for Formal Models and Verification Johannes Kepler Universität Linz Version 2018.1

More information

SAT Solvers: Theory and Practice

SAT Solvers: Theory and Practice Summer School on Verification Technology, Systems & Applications, September 17, 2008 p. 1/98 SAT Solvers: Theory and Practice Clark Barrett barrett@cs.nyu.edu New York University Summer School on Verification

More information

Lecture Notes: Axiomatic Semantics and Hoare-style Verification

Lecture Notes: Axiomatic Semantics and Hoare-style Verification Lecture Notes: Axiomatic Semantics and Hoare-style Verification 17-355/17-665/17-819O: Program Analysis (Spring 2018) Claire Le Goues and Jonathan Aldrich clegoues@cs.cmu.edu, aldrich@cs.cmu.edu It has

More information

COMP219: Artificial Intelligence. Lecture 20: Propositional Reasoning

COMP219: Artificial Intelligence. Lecture 20: Propositional Reasoning COMP219: Artificial Intelligence Lecture 20: Propositional Reasoning 1 Overview Last time Logic for KR in general; Propositional Logic; Natural Deduction Today Entailment, satisfiability and validity Normal

More information

Intelligent Agents. Pınar Yolum Utrecht University

Intelligent Agents. Pınar Yolum Utrecht University Intelligent Agents Pınar Yolum p.yolum@uu.nl Utrecht University Logical Agents (Based mostly on the course slides from http://aima.cs.berkeley.edu/) Outline Knowledge-based agents Wumpus world Logic in

More information

Warm-Up Problem. Is the following true or false? 1/35

Warm-Up Problem. Is the following true or false? 1/35 Warm-Up Problem Is the following true or false? 1/35 Propositional Logic: Resolution Carmen Bruni Lecture 6 Based on work by J Buss, A Gao, L Kari, A Lubiw, B Bonakdarpour, D Maftuleac, C Roberts, R Trefler,

More information

Alan Bundy. Automated Reasoning LTL Model Checking

Alan Bundy. Automated Reasoning LTL Model Checking Automated Reasoning LTL Model Checking Alan Bundy Lecture 9, page 1 Introduction So far we have looked at theorem proving Powerful, especially where good sets of rewrite rules or decision procedures have

More information

Soundness and Completeness of Axiomatic Semantics

Soundness and Completeness of Axiomatic Semantics #1 Soundness and Completeness of Axiomatic Semantics #2 One-Slide Summary A system of axiomatic semantics is sound if everything we can prove is also true: if ` { A } c { B } then ² { A } c { B } We prove

More information

An Introduction to Z3

An Introduction to Z3 An Introduction to Z3 Huixing Fang National Trusted Embedded Software Engineering Technology Research Center April 12, 2017 Outline 1 SMT 2 Z3 Huixing Fang (ECNU) An Introduction to Z3 April 12, 2017 2

More information