🤖 AI Summary
This work addresses the lack of formal correctness guarantees in code generated by large language models (LLMs), which hinders compliance with safety-critical software certification standards such as DO-178C, IEC 61508, and ISO 26262. To bridge this gap, the authors propose Forge, a closed-loop pipeline that integrates model-driven engineering with multiple formal verification techniques—including Dafny for deductive verification, FDR4 for CSP refinement checking, and Isabelle for Z-Machine theorem proving—to automatically extract formal models from LLM-generated Java code and iteratively refine it. Forge establishes a fully automated feedback loop that requires no manual intervention, successfully producing verifiable evidence aligned with industry certification requirements and thereby advancing the certifiability of AI-generated code in safety-critical domains.
📝 Abstract
Vibe coding -- accepting LLM-generated source from natural-language intent with minimal review -- is fast and may be adequate for low-criticality consumer software. But for safety-critical systems governed by DO-178C, IEC 61508, or ISO 26262, it offers no path to certification: large language models (LLMs) provide no formal correctness guarantees, and existing remedies target verification-aware languages (Dafny, Verus, Lean) that are scarce in pretraining data and absent from industrial toolchains.
This paper closes the gap. We present Forge (Formal method Oriented Refinement loop for GEnerated code): a closed-loop pipeline that guides vibe coding through formal verification using established Model-Driven Engineering (MDE) infrastructure. Through vibe coding, we generate Java source code; our pipeline then extracts -- via model transformations -- formal artefacts in three different formalisms, each checked by a complementary verifier: deductive verification (Dafny), Communicating Sequential Processes (CSP) refinement via the Failures-Divergences Refinement checker (FDR4), and theorem proving using Z-Machines in Isabelle; every verification failure becomes a structured correction prompt that drives the next code-generation iteration. The LLM is the draft generator, the MDE chain is the discriminator, and the developer never has to read the formal models.
Empirically, we find that the pipeline produces standards-relevant verification evidence for LLM-generated Java -- a step toward certification.