Sound and Precise Symbolic Automata Model for Stateful Software Systems
Xinlong Wu, Ruiyu Zhou, Peisen Yao, Qingkai Shi
Abstract
Abstract Verifying stateful software systems remains challenging due to complex control structures and intricate state interactions, often necessitating pre-existing behavioral models. We introduce , an abstract interpreter that automatically derives sound and precise symbolic finite automata models. In tests on real-world applications, generates sound and precise automata within minutes and, when employed in dynamic model checking, achieves 1.6 × –3.4 × code coverage compared to the state of the art. These findings demonstrate that can effectively connect code to model-based verification for stateful software systems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4efe8fa9-c397-497f-a7ca-7be83fdab273Builds on10
- SFADiff: Automated Evasion Attacks and Fingerprinting Using Black-box Differential Automata LearningGeorge Argyros, Ioannis Stais, Suman Jana, Angelos D. Keromytis et al.CCS 2016 · 65 citations
- Back in Black: Towards Formal, Black Box Analysis of Sanitizers and FiltersGeorge Argyros, Ioannis Stais, Aggelos Kiayias, Angelos D. KeromytisS&P 2016 · 46 citations
- FuzzUSB: Hybrid Stateful Fuzzing of USB Gadget StacksKyungtae Kim, Taegyu Kim, Ertza Warraich, Byoungyoung Lee et al.S&P 2022 · 32 citations
- Aragog: Scalable Runtime Verification of Shardable Networked SystemsNofel Yaseen, Behnaz Arzani, Ryan Beckett, Selim Ciraci et al.OSDI 2020 · 19 citations
- Program analysis via efficient symbolic abstractionPeisen Yao, Qingkai Shi, Heqing Huang, Charles ZhangOOPSLA 2021 · 12 citations
Related papers
- Active Learning of Symbolic Automata for Reactive Programs via Dynamic Symbolic MapperYoel Kim, Yunja ChoiFSE 2026
- Learning Concise Models from Long Execution TracesNatasha Yogananda Jeppu, Thomas F. Melham, Daniel Kroening, John O'LearyDAC 2020
- SAIL: Sound Abstract Interpreters with LLMsQiuhan Gu, Avaljot Singh, Gagandeep SinghPLDI 2026
- SpecMAS: A Multi-Agent System for Self-Verifying System Generation via Formal Model CheckingRishabh Agrawal, Kaushik T. Ranade, Aja Khanal, Kalyan S. Basu et al.NeurIPS 2025 · 1 citation
- Compiling with Abstract InterpretationDorian Lesbre, Matthieu LemerrePLDI 2024 · 6 citations
