arXiv · 2404.18280
Tracy, Traces, and Transducers: Computable Counterexamples and Explanations for HyperLTL Model-Checking
Abstract
HyperLTL model-checking enables the automated verification of information-flow properties for security-critical systems. However, it only provides a binary answer. Here, we introduce two paradigms to compute counterexamples and explanations for HyperLTL model-checking, thereby considerably increasing its usefulness. Both paradigms are based on the maxim ``counterexamples/explanations are Skolem functions for the existentially quantified trace variables''. Our first paradigm is complete (everything can be explained), but restricted to ultimately periodic system traces. The second paradigm works with (Turing machine) computable Skolem functions and is therefore much more general, but also shown incomplete (not everything can computably be explained). Finally, we prove that it is decidable whether a given finite transition system and a formula have computable Skolem functions witnessing that the system satisfies the formula. Our algorithm also computes transducers implementing computable Skolem functions, if they exist.
Explore related subjects
Keep this discovery
Sarah Winter, Martin Zimmermann. 2024-04-28. Tracy, Traces, and Transducers: Computable Counterexamples and Explanations for HyperLTL Model-Checking. https://arxiv.org/abs/2404.18280
Cite the original work for its findings. Save a collection to share your selection of sources.