379 research outputs found
Generalized Strong Preservation by Abstract Interpretation
Standard abstract model checking relies on abstract Kripke structures which
approximate concrete models by gluing together indistinguishable states, namely
by a partition of the concrete state space. Strong preservation for a
specification language L encodes the equivalence of concrete and abstract model
checking of formulas in L. We show how abstract interpretation can be used to
design abstract models that are more general than abstract Kripke structures.
Accordingly, strong preservation is generalized to abstract
interpretation-based models and precisely related to the concept of
completeness in abstract interpretation. The problem of minimally refining an
abstract model in order to make it strongly preserving for some language L can
be formulated as a minimal domain refinement in abstract interpretation in
order to get completeness w.r.t. the logical/temporal operators of L. It turns
out that this refined strongly preserving abstract model always exists and can
be characterized as a greatest fixed point. As a consequence, some well-known
behavioural equivalences, like bisimulation, simulation and stuttering, and
their corresponding partition refinement algorithms can be elegantly
characterized in abstract interpretation as completeness properties and
refinements
Generalizing the Paige-Tarjan Algorithm by Abstract Interpretation
The Paige and Tarjan algorithm (PT) for computing the coarsest refinement of
a state partition which is a bisimulation on some Kripke structure is well
known. It is also well known in model checking that bisimulation is equivalent
to strong preservation of CTL, or, equivalently, of Hennessy-Milner logic.
Drawing on these observations, we analyze the basic steps of the PT algorithm
from an abstract interpretation perspective, which allows us to reason on
strong preservation in the context of generic inductively defined (temporal)
languages and of possibly non-partitioning abstract models specified by
abstract interpretation. This leads us to design a generalized Paige-Tarjan
algorithm, called GPT, for computing the minimal refinement of an abstract
interpretation-based model that strongly preserves some given language. It
turns out that PT is a straight instance of GPT on the domain of state
partitions for the case of strong preservation of Hennessy-Milner logic. We
provide a number of examples showing that GPT is of general use. We first show
how a well-known efficient algorithm for computing stuttering equivalence can
be viewed as a simple instance of GPT. We then instantiate GPT in order to
design a new efficient algorithm for computing simulation equivalence that is
competitive with the best available algorithms. Finally, we show how GPT allows
to compute new strongly preserving abstract models by providing an efficient
algorithm that computes the coarsest refinement of a given partition that
strongly preserves the language generated by the reachability operator.Comment: Keywords: Abstract interpretation, abstract model checking, strong
preservation, Paige-Tarjan algorithm, refinement algorith
Linear Time Logics - A Coalgebraic Perspective
We describe a general approach to deriving linear time logics for a wide
variety of state-based, quantitative systems, by modelling the latter as
coalgebras whose type incorporates both branching behaviour and linear
behaviour. Concretely, we define logics whose syntax is determined by the
choice of linear behaviour and whose domain of truth values is determined by
the choice of branching, and we provide two equivalent semantics for them: a
step-wise semantics amenable to automata-based verification, and a path-based
semantics akin to those of standard linear time logics. We also provide a
semantic characterisation of the associated notion of logical equivalence, and
relate it to previously-defined maximal trace semantics for such systems.
Instances of our logics support reasoning about the possibility, likelihood or
minimal cost of exhibiting a given linear time property. We conclude with a
generalisation of the logics, dual in spirit to logics with discounting, which
increases their practical appeal in the context of resource-aware computation
by incorporating a notion of offsetting.Comment: Major revision of previous version: Sections 4 and 5 generalise the
results in the previous version, with new proofs; Section 6 contains new
result
Incompleteness of States w.r.t. Traces in Model Checking
Cousot and Cousot introduced and studied a general past/future-time
specification language, called mu*-calculus, featuring a natural time-symmetric
trace-based semantics. The standard state-based semantics of the mu*-calculus
is an abstract interpretation of its trace-based semantics, which turns out to
be incomplete (i.e., trace-incomplete), even for finite systems. As a
consequence, standard state-based model checking of the mu*-calculus is
incomplete w.r.t. trace-based model checking. This paper shows that any
refinement or abstraction of the domain of sets of states induces a
corresponding semantics which is still trace-incomplete for any propositional
fragment of the mu*-calculus. This derives from a number of results, one for
each incomplete logical/temporal connective of the mu*-calculus, that
characterize the structure of models, i.e. transition systems, whose
corresponding state-based semantics of the mu*-calculus is trace-complete
Fair Testing
In this paper we present a solution to the long-standing problem of characterising the coarsest liveness-preserving pre-congruence with respect to a full (TCSP-inspired) process algebra. In fact, we present two distinct characterisations, which give rise to the same relation: an operational one based on a De Nicola-Hennessy-like testing modality which we call should-testing, and a denotational one based on a refined notion of failures. One of the distinguishing characteristics of the should-testing pre-congruence is that it abstracts from divergences in the same way as MilnerÂżs observation congruence, and as a consequence is strictly coarser than observation congruence. In other words, should-testing has a built-in fairness assumption. This is in itself a property long sought-after; it is in notable contrast to the well-known must-testing of De Nicola and Hennessy (denotationally characterised by a combination of failures and divergences), which treats divergence as catrastrophic and hence is incompatible with observation congruence. Due to these characteristics, should-testing supports modular reasoning and allows to use the proof techniques of observation congruence, but also supports additional laws and techniques. Moreover, we show decidability of should-testing (on the basis of the denotational characterisation). Finally, we demonstrate its advantages by the application to a number of examples, including a scheduling problem, a version of the Alternating Bit-protocol, and fair lossy communication channel
Disjunctive bases: normal forms and model theory for modal logics
We present the concept of a disjunctive basis as a generic framework for
normal forms in modal logic based on coalgebra. Disjunctive bases were defined
in previous work on completeness for modal fixpoint logics, where they played a
central role in the proof of a generic completeness theorem for coalgebraic
mu-calculi. Believing the concept has a much wider significance, here we
investigate it more thoroughly in its own right. We show that the presence of a
disjunctive basis at the "one-step" level entails a number of good properties
for a coalgebraic mu-calculus, in particular, a simulation theorem showing that
every alternating automaton can be transformed into an equivalent
nondeterministic one. Based on this, we prove a Lyndon theorem for the full
fixpoint logic, its fixpoint-free fragment and its one-step fragment, a Uniform
Interpolation result, for both the full mu-calculus and its fixpoint-free
fragment, and a Janin-Walukiewicz-style characterization theorem for the
mu-calculus under slightly stronger assumptions.
We also raise the questions, when a disjunctive basis exists, and how
disjunctive bases are related to Moss' coalgebraic "nabla" modalities. Nabla
formulas provide disjunctive bases for many coalgebraic modal logics, but there
are cases where disjunctive bases give useful normal forms even when nabla
formulas fail to do so, our prime example being graded modal logic. We also
show that disjunctive bases are preserved by forming sums, products and
compositions of coalgebraic modal logics, providing tools for modular
construction of modal logics admitting disjunctive bases. Finally, we consider
the problem of giving a category-theoretic formulation of disjunctive bases,
and provide a partial solution
- …