Satisfiability Modulo Theories (SMT) solvers have been successfully applied to solve many problems in formal verification such as bounded model checking (BMC) for many classes of systems from integrated circuits to cyber-physical systems. Typically, BMC is performed by checking satisfiability of a possibly long, but quantifier-free formula. However, BMC problems can naturally be encoded as quantified formulas over the number of BMC steps. In this approach, we then use decision procedures supporting quantifiers to check satisfiability of these quantified formulas. This approach has previously been applied to perform BMC using a Quantified Boolean Formula (QBF) encoding for purely discrete systems, and then discharges the QBF checks using QBF solvers. In this paper, we present a new quantified encoding of BMC for rectangular hybrid automata (RHA), which requires using more general logics due to the real (dense) time and real-valued state variables modeling continuous states. We have implemented a preliminary experimental prototype of the method using the HyST model transformation tool to generate the quantified BMC (QBMC) queries for the Z3 SMT solver. We describe experimental results on several timed and hybrid automata benchmarks, such as the Fischer and Lynch-Shavit mutual exclusion algorithms. We compare our approach to quantifier-free BMC approaches, such as those in the dReach tool that uses the dReal SMT solver, and the HyComp tool built on top of nuXmv that uses the MathSAT SMT solver. Based on our promising experimental results, QBMC may in the future be an effective and scalable analysis approach for RHA and other classes of hybrid automata as further improvements are made in quantifier handling in SMT solvers such as Z3.
翻译:在正式核查中,成功应用了“满足性”Mudulo Theories(SMT)解答器来解决许多问题,例如,从集成电路到网络物理系统等许多系统类别的封装模型检查(BMC),通常,BMC通过检查一个可能长但无量化的公式的可证实性来进行。然而,BMC问题自然可以被编码成与BMC步骤数量相比的量化公式。在这个方法中,我们随后使用支持量化公式的决定程序来检查这些量化公式的可识别性。这个方法以前用来使用纯离散系统(QBMC)的定型模型检查(BMC),然后用QBFFC的可证实性检查。在本文件中,我们用一个新的量化的BMC(BMC)编码来计算矩混合混合的自动自动数据。在真实(ense)时间和真实值的状态变现变现状态模型中,我们用了一个方法进行初步实验性原型BMC的原型模型,在S-Rimal Q(SMD) 的S-model 解算算方法中,作为S-modialalalalalalalalalalalalalalalalalalalalalalalal alial alial dal dal 。我们用了Smal ma) 。