🤖 AI Summary
Frequent SMT solver invocations in symbolic/concolic execution impose a severe performance bottleneck.
Method: This paper proposes a generalized reuse technique targeting unsatisfiable (UNSAT) cores, moving beyond conventional caching that only supports reuse of syntactically equivalent or structurally similar formulas. We systematically investigate *semantic-preserving mappings of UNSAT cores under arbitrary variable substitutions*, leveraging UNSAT core extraction, variable substitution modeling, subformula isomorphism checking, and cache index optimization to enable cross-formula-structure reuse.
Contribution/Results: Evaluated on standard benchmarks, our approach achieves a 74% UNSAT core reuse rate—33 percentage points higher than Utopia—significantly reducing solver invocations and substantially decreasing execution time in complex scenarios. By enabling reuse across semantically equivalent but syntactically divergent formulas, our method overcomes the semantic limitations inherent in prior caching strategies.
📝 Abstract
Satisfiability Modulo Theories (SMT) solvers are integral to program analysis techniques like concolic and symbolic execution, where they help assess the satisfiability of logical formulae to explore execution paths of the program under test. However, frequent solver invocations are still the main performance bottleneck of these techniques. One way to mitigate this challenge is through optimizations such as caching and reusing solver results. While current methods typically focus on reusing results from fully equivalent or closely related formulas, they often miss broader opportunities for reuse. In this paper, we propose a novel approach, Cache-a-lot, that extends the reuse of unsatisfiable (unsat) results by systematically considering all possible variable substitutions. This enables more extensive reuse of results, thereby reducing the number of SMT solver invocations and improving the overall efficiency of concolic and symbolic execution. Our evaluation, conducted against the state-of-the-art Utopia solution using two benchmark sets, shows significant improvements, particularly with more complex formulas. Our method achieves up to 74% unsat core reuse, compared to Utopia's 41%, and significant increase in the time savings. These results demonstrate that, despite the additional computational complexity, the broader reuse of unsat results significantly enhances performance, offering valuable advancements for formal verification and program analysis.