Developing a Numerical Algorithm with CIVL Model Checking in the Loop

📅 2026-09-25
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the challenge of directly verifying numerical algorithms in large-scale scientific simulation frameworks, where system complexity and insufficient unit test coverage hinder validation. Focusing on Cloud-in-Cell (CIC) algorithm development for Flash-X, we propose a "model-checking-in-the-loop" workflow. By abstracting infrastructure details to extract interfaces, we construct small, self-contained C models and embed the CIVL model checker with symbolic execution into the development cycle as design guardrails. This approach successfully verifies physical properties such as mass conservation alongside memory safety, and uncovers concurrency defects overlooked by randomized testing. Consequently, it significantly enhances algorithmic reliability, offering an efficient new paradigm for the formal verification of complex scientific computing systems.
📝 Abstract
Verifying a numerical algorithm in a large scientific simulation framework is challenging: the framework is too big to model-check, and the unit tests exercise only sampled inputs. We report a case study in which we developed a new cloud-in-cell (CIC) deposition algorithm for Flash-X, a large-scale multiphysics simulation framework, keeping the CIVL model checker in the development loop. Rather than verify the algorithm within Flash-X's hefty infrastructure, we extract only the interfaces that the algorithm needs into a small, self-contained C model, which abstracts away implementation details of the Flash-X infrastructure that are unrelated to the new algorithm. The new algorithm is then built and checked within this C model. The CIVL model checker enables verification of the required physical properties of the CIC deposition algorithm using symbolic values for the particle positions. It proves two physical properties---mass conservation and the deposition location---for the continuum of admissible positions in the simulation domain. CIVL also verifies the algorithm's memory safety and freedom from MPI deadlocks and data race conditions over all rank distributions within specified bounds. Writing the verifying properties first and continuously checking them at each stage of the bottom-up prototyping workflow turned CIVL into a design guardrail that greatly increased confidence in the extended algorithm. During our case study, CIVL surfaced a concurrency defect in the algorithm that our random-seed-based tests failed to exercise. This paper shows our workflow, with the goal of helping readers understand its benefits, cost, and tradeoffs compared with testing.
Problem

Research questions and friction points this paper is trying to address.

numerical algorithm verification
model checking
scientific simulation framework
concurrency defects
unit testing limitations
Innovation

Methods, ideas, or system contributions that make the work stand out.

Model Checking
CIVL
Numerical Algorithm Verification
Cloud-in-Cell Deposition
Concurrency Defect Detection
🔎 Similar Papers
No similar papers found.