Score
Designs and implements federated reactor-based systems (e.g., using LF), coordinating logical time, message ordering, and scheduling across nodes to ensure deterministic execution. Builds synchronization and runtime mechanisms and analyzes end-to-end timing and ordering to guarantee reproducible behavior across distributed federates.
Distributed systems relying on physical clock synchronization suffer from high overhead, poor scalability, and difficulties in formal verification. To address these challenges, this paper proposes Timetide—a deterministic programming model integrating multi-clock synchronization semantics with clock-free logical synchronization. Its core innovation lies in the first-ever unification of multi-clock language semantics and logical synchronization, eliminating the need for clock synchronization protocols or clock gating while guaranteeing strong determinism in distributed execution. Timetide supports seamless distributed compilation and end-to-end formal verification, effectively mitigating the impact of network latency. Experimental evaluation demonstrates that Timetide achieves high scalability while significantly enhancing system reliability and correctness assurance. By enabling rigorous verification of distributed behavior, it establishes a novel paradigm for building verifiable distributed systems.
This work addresses the nondeterminism inherent in ROS 2 applications, which arises from their publish-subscribe communication model and distributed deployment, leading to unpredictable callback execution orders that complicate concurrency management and hinder safety analysis. To resolve this, the authors propose an automated, non-intrusive transformation method that converts native ROS 2 applications into deterministic programs based on Lingua Franca, without modifying the original codebase. By leveraging Lingua Franca’s logical time semantics, the approach guarantees identical execution order and end-to-end latency for the same inputs. This is the first technique to provide deterministic execution for ROS 2 applications while preserving compatibility and enabling advanced features such as federated execution and fault tolerance. Experimental evaluation on synthetic benchmarks and the Autoware autonomous driving stack demonstrates the method’s efficacy and its clear advantage over the inherently nondeterministic behavior of native ROS 2.
This work addresses critical limitations in conventional LLM agent loop paradigms—namely implicit dependencies, unbounded recovery, and variable execution histories—which hinder debuggability and controllability. To overcome these issues, the paper introduces SGH, a structured graph framework that, for the first time, integrates classical scheduling theory into LLM agent execution. SGH explicitly models control flow using a static directed acyclic graph (DAG), cleanly separating planning, execution, and recovery into three distinct logical layers. It further incorporates a strict escalation protocol and formal node state machines to enforce rigorous execution semantics. The framework is systematically evaluated across 70 systems, analyzing trade-offs among controllability, expressiveness, and implementability, while providing formal guarantees of termination and correctness. Seven traceable experimental suites are designed to empirically validate its efficacy.
This paper addresses the verification of concurrency correctness for shared communication channels in process-oriented languages with cooperative scheduling (e.g., ProcessJ). It proposes explicitly modeling the runtime environment—particularly resource supply capacity—within formal verification frameworks. Methodologically, it employs CSP to abstractly specify and concretely implement shared channels, and conducts refinement verification using the FDR tool. The key contribution is the identification and formal demonstration that channel behavioral correctness depends not only on program logic but critically on the sufficiency of runtime resources; thus, conventional verification models that omit environmental constraints are fundamentally inadequate. Experimental evaluation confirms that this environment-aware modeling strategy effectively bridges the gap between formal specifications and actual execution behavior, establishing a new paradigm for concurrent system verification that reconciles theoretical rigor with engineering realism.
Informal Hoare-style reasoning in distributed systems lacks formal foundations, undermining its reliability and semantic correspondence with standard models—especially for compositional verification in Byzantine fault-tolerant settings. Method: We propose the Sync/Async dual-language framework, grounded in functional denotational semantics and trace-driven operational semantics. Leveraging monadic modeling and language compilation techniques, it rigorously compiles asynchronous fault-tolerant behaviors into synchronous programs while preserving safety properties across compilation. Contribution/Results: Our approach establishes, for the first time, a provably equivalent link between Hoare-style reasoning and formal semantics, enabling modular and compositional safety proofs. Implemented in the Rocq toolchain, it verifies the safety of BOSCO and SeqPaxos and generates executable code—demonstrating both theoretical soundness and practical applicability.
This work addresses the challenge of coordination in large language model (LLM)-based multi-agent systems, where nondeterministic LLM behavior can lead to subtle, hard-to-detect errors such as deadlocks or message mismatches. The paper introduces ZipperGen, a novel framework that formally incorporates Message Sequence Charts (MSCs) into LLM-driven multi-agent coordination for the first time. It employs a domain-specific language to decouple communication structure from LLM behavior and uses syntax-guided projection to derive local agent programs from a global specification, guaranteeing deadlock freedom by construction. This approach enables a verifiable coordination mechanism that is disentangled from LLM nondeterminism and supports runtime generation of structurally sound workflows. The framework’s ability to independently verify coordination properties is demonstrated through its application to consensus protocol diagnostics.
This work addresses timing uncertainty in embedded systems arising from the coupling of hardware interrupts, buffering mechanisms, and distributed communication. The paper proposes a federated GNSS correction data pipeline based on Lingua Franca, introducing explicit logical time semantics to this domain for the first time. It unifies the modeling of interrupt ticks, ring buffer evolution, and physical-logical jitter within a coherent framework. By integrating a time-triggered GNSS receiver, UART interrupt stream modeling, FIFO buffer analysis, and a federated execution architecture, the approach enables analyzable and predictable end-to-end timing behavior. Experimental results demonstrate that the pipeline achieves deterministic and reproducible timing performance.
This work addresses the reliability challenges of production-grade large language model (LLM) agents, which stem from the lack of a clear architectural abstraction delineating stochastic outputs from deterministic system behavior. To bridge this gap, the paper introduces the Stochastic-Deterministic Boundary (SDB) as a core architectural primitive, formalized as a four-tuple contract. Centered on three key concerns—coordination, state, and control—it defines six composable runtime modes. The contributions include a five-step methodology for mode selection, a replay-based divergence diagnosis mechanism, and the insight that architectural momentum becomes critical for long-term reliability once model variance diminishes. By integrating distributed systems patterns such as Saga and event-driven orchestration, the authors construct a verifiable, rollback-capable, and monitorable LLM agent runtime. Empirical validation across five real-world workloads demonstrates its efficacy, and a reference implementation for a 90-day contract renewal agent is open-sourced, significantly enhancing sustained operational reliability.
This work addresses the challenge of achieving bounded, verifiable, and deterministic coordination in safety-critical real-time autonomous systems operating under uncertainty. It proposes a hardware-enforced semantic coordination architecture that, for the first time, directly maps a topic-based communication space Petri net (TB-CSPN) coordination mechanism onto the FPGA hardware layer. By leveraging hardware primitives to construct a native semantic coordination layer, the approach ensures deterministic execution of time synchronization, semantic gating, authorization constraints, and bounded coordination behaviors—without relying on software mediation. The design decouples low-level interaction management from high-level semantic reasoning, thereby preserving software adaptability while guaranteeing hardware-level reliability. This integration yields a highly dependable real-time system architecture with formally verifiable safety assurances, deterministic coordination, and bounded latency.
This work addresses the lack of structural constraints against data leakage in existing federated learning protocols, which hinders trustworthy collaboration under heterogeneous privacy requirements. The authors propose a novel federated transmission protocol, FSTP, which uniquely embeds data encapsulation directly into its architectural design. By leveraging Rust’s type system to prevent raw data exposure at compile time, and integrating unlinkable contextual identity isolation, a Blocklace-based partially ordered event log, and an erasable hash chain, FSTP enables tamper-resistant, cross-domain unlinkable, and verifiable collaboration. The protocol supports “prove-without-exposing” federated interactions and has been integrated into Velyzor, a governance platform for high-security institutions. Both the protocol specification and reference implementation are publicly available under the Apache 2.0 license.