The Kind 2 Model Checker

A Champion, A Mebsout, C Sticksel… - … Conference on Computer …, 2016 - Springer
Kind 2 is an open-source, multi-engine, SMT-based model checker for safety properties of
finite-and infinite-state synchronous reactive systems. It takes as input models written in an …

Incremental linearization for satisfiability and verification modulo nonlinear arithmetic and transcendental functions

A Cimatti, A Griggio, A Irfan, M Roveri… - ACM Transactions on …, 2018 - dl.acm.org
Satisfiability Modulo Theories (SMT) is the problem of deciding the satisfiability of a first-
order formula with respect to some theory or combination of theories; Verification Modulo …

CoCoSpec: A mode-aware contract language for reactive systems

A Champion, A Gurfinkel, T Kahsai, C Tinelli - International Conference on …, 2016 - Springer
Contract-based software development has long been a leading methodology for the
construction of component-based reactive systems, embedded systems in particular …

Towards development of complete and conflict-free requirements

A Moitra, K Siu, A Crapo, H Chamarthi… - 2018 IEEE 26th …, 2018 - ieeexplore.ieee.org
Writing requirements is no easy task. Common problems include ambiguity in statements,
specifications at the wrong level of abstraction, statements with inconsistent references to …

Review of formal agile methods as cost-effective airworthiness certification processes

MA Blooshi, S Jafer, K Patel - Journal of Aerospace Information Systems, 2018 - arc.aiaa.org
SAFETY-CRITICAL software systems are part of our daily life and any error in these systems
can result in catastrophic consequences, with the worst-case scenario being loss of human …

Invariant checking of NRA transition systems via incremental reduction to LRA with EUF

A Cimatti, A Griggio, A Irfan, M Roveri… - … 2017, Held as Part of the …, 2017 - Springer
Abstract Model checking invariant properties of designs, represented as transition systems,
with non-linear real arithmetic (NRA), is an important though very hard problem. On the one …

Requirements analysis of a quad-redundant flight control system

J Backes, D Cofer, S Miller, MW Whalen - NASA Formal Methods …, 2015 - Springer
In this paper we detail our effort to formalize and prove requirements for the Quad-redundant
Flight Control System (QFCS) within NASA's Transport Class Model (TCM). We use a …

Simulation-based elicitation of accuracy requirements for the environmental perception of autonomous vehicles

R Philipp, H Qian, L Hartjen, F Schuldt… - Leveraging Applications of …, 2021 - Springer
Novel methods for safety validation of autonomous vehicles are needed in order to enable a
successful release of self-driving cars to the public. Decomposition of safety validation is one …

Automating requirements analysis and test case generation

A Moitra, K Siu, AW Crapo, M Durling, M Li… - Requirements …, 2019 - Springer
Writing clear and unambiguous requirements that are conflict-free and complete is no easy
task. Incorrect requirements lead to errors being introduced early in the design process. The …

Run-time assurance and formal methods analysis nonlinear system applied to nonlinear system control

KH Gross, MA Clark, JA Hoffman… - Journal of Aerospace …, 2017 - arc.aiaa.org
Exhaustive testing of complex and autonomous systems is intractable and cost prohibitive;
however, design analysis techniques such as formal methods and design methodologies …