PLJul 1

Trustworthy Runtime Verification via Bisimulation (Extended Experience Report)

arXiv:2607.013638.26 citations
Predicted impact top 32% in PL · last 90 daysOriginality Incremental advance
AI Analysis

For developers of safety-critical systems using runtime verification, this work provides a method to produce formal assurance arguments that compiled monitors are correct, addressing a key challenge in certification.

The paper presents CopilotVerifier, a tool that generates proofs of correctness for compiled Copilot monitors, establishing bisimulation equivalence between source and compiled code. The approach achieves increased compiler assurance at moderate cost by leveraging existing SMT-backed tools.

When runtime verification is used to monitor safety-critical systems, it is essential that monitoring code behaves correctly. The Copilot runtime verification framework pursues this goal by automatically generating C monitor programs from a high-level DSL embedded in Haskell. In safety-critical domains, every piece of deployed code must be accompanied by an assurance argument that is convincing to human auditors. However, it is difficult for auditors to determine with confidence that a compiled monitor cannot crash and implements the behavior required by the Copilot semantics. In this paper we describe CopilotVerifier, which runs alongside the Copilot compiler, generating a proof of correctness for the compiled output. The proof establishes that a given Copilot monitor and its compiled form produce equivalent outputs on equivalent inputs, and that they either crash in identical circumstances or cannot crash. The proof takes the form of a bisimulation broken down into a set of verification conditions. We leverage two pieces of SMT-backed technology: the Crucible symbolic execution library for LLVM and the What4 solver interface library. Our results demonstrate that dramatically increased compiler assurance can be achieved at moderate cost by building on existing tools. This paves the way to our ultimate goal of generating formal assurance arguments that are convincing to human auditors.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes