Score
Designs, builds, or analyzes transforms and protocols that convert interactive challenge–response proofs into non‑interactive proofs by deterministically deriving the verifier’s challenge (for example via a hash of commitments, claimed outputs, or committed seeds) so as to preserve soundness, extractability, and binding. This work includes specifying and proving the Fiat–Shamir binding properties, constructing commitment/seed handling to enable offline reproducibility, and analyzing adversary behaviors (rewinding, probe-aware or null-space attacks) to close malleability and other attack surfaces.
Dafny’s automated verification lacks flexibility and debuggability for complex program properties—e.g., loop invariant refinement and inductive hypothesis selection. To address this, we design and implement the first Interactive Proof Mode (IPM) deeply integrated into the Dafny compiler framework. Methodologically, we introduce a hierarchical imperative proof protocol and an incremental state synchronization mechanism to enable fine-grained user intervention; extend SMT solver interaction, support proof-state snapshot management, and define a structured command language—all while preserving Dafny’s existing verification pipeline. Evaluation on multiple benchmarks demonstrates that our prototype significantly improves verification controllability and efficiency. This work establishes a novel human–machine collaboration paradigm for formal verification tools, advancing interactive theorem proving within industrial-strength program verifiers.
This work addresses the fundamental challenge that cross-platform nondeterminism undermines the reliability of AI system verification, thereby eroding the foundation of trustworthy AI. We propose the “Determinism Thesis,” asserting that deterministic inference is both necessary and sufficient for achieving key trustworthiness properties—including fairness, robustness, privacy, security, and alignment. To realize this, we develop a pure integer inference engine that eliminates nondeterminism inherent in IEEE 754 floating-point arithmetic and introduce “trust entropy” to quantify the cost of nondeterminism. Implemented in Rust, our system integrates hash-consistency validation with on-chain blockchain proofs. Across 82 cross-architecture (ARM/x86) tests—using models up to 6.7B parameters—it achieves zero hash mismatches, perfect output consistency across four geographically distributed nodes, and successful verification via 356 on-chain transactions.
Existing formal verification approaches struggle to balance expressiveness and automation, particularly when addressing complex protocol features such as state dependency, temporal behavior, unbounded executions, and conditional secrecy. This work proposes a modular verification framework that integrates type systems with trace-based reasoning, co-designing language constructs and automation to achieve protocol-specific automation without sacrificing expressiveness. Built upon the Lean theorem prover, we develop the LeanDY library, which extends the DY* model and combines interactive proof with domain-specific automation. Using this framework, we successfully formalize SegWit-style blockchain primitives and payment channel protocols, verifying punishment mechanisms that rely on chain liveness as well as their core security properties.
This work investigates whether memory-bounded learners/testers can overcome inherent resource limitations by interacting with an untrusted but computationally unbounded third party. We systematically characterize the feasibility boundaries of interactive delegated learning and testing in both classical and quantum communication settings. We establish, for the first time, that classical interaction cannot circumvent fundamental memory-based lower bounds for learning or testing; in contrast, quantum communication enables exponential speedups. Leveraging this insight, we design the first efficient quantum interactive verification protocols for several fundamental problems—including distribution property testing and function approximation—enabling a verifier with only $O(log n)$ memory to solve tasks previously requiring polynomial resources. Our approach integrates techniques from interactive proofs, quantum complexity theory, property testing, and the quantum random access model. The results formally establish the universal limitations of classical interaction in delegated computation and reveal the pivotal role of quantum communication in resource-constrained delegation.
Database transaction isolation anomalies—particularly those arising from design flaws—are prevalent in production systems, yet existing approaches lack a mathematically rigorous, systematic, and tool-supported formal verification framework. This paper introduces the first fully automated verification framework for transaction isolation, built in Isabelle/HOL. It enables full-path formal verification of core isolation properties—including strict serializability—for the first time. The framework precisely models concurrent transaction semantics, defines formal isolation specifications, and integrates counterexample generation. Applied during protocol design, it uncovers deep correctness flaws: it formally verifies that Strict Two-Phase Locking satisfies strict serializability, and—critically—identifies for the first time that the TAPIR protocol violates atomic visibility, automatically generating an executable counterexample. This work establishes a verifiable, reusable theoretical foundation and practical toolset for database isolation assurance.
This work addresses the lack of a composable, verifiable framework for mechanized cryptographic proofs that integrates with general-purpose mathematical libraries. It introduces HOPSCOTCH, the first game-hopping proof framework deeply integrated with Lean 4’s Mathlib, which models security definitions as indistinguishability between stateful probabilistic oracles via shallow embedding and employs state abstraction to enable flexible oracle transformations. The framework formalizes the structure of game-hopping reasoning, automates the derivation of computational soundness theorems, and successfully verifies the IND-CCA security of Encrypt-then-MAC, the security of ElGamal under the DDH assumption, the reduction from one-time secrecy to public-key IND-CPA, and the first mechanized proof of a non-constant-depth GGM pseudorandom function construction.
This work addresses the challenge of systematically comparing Tamarin and ProVerif, which stems from their differing semantics and verification mechanisms. The authors propose a faithful translation from Tamarin to ProVerif that supports most Tamarin features by encoding multiset rewriting semantics, reformulating formulas, and modeling synchronized events, while explicitly characterizing cases that cannot be translated. The translation preserves soundness and completeness for trace properties with existential guarantees; for inherently non-faithful constructs such as XOR, it employs a best-effort encoding strategy. Empirical evaluation on 121 Tamarin models—covering 562 out of 566 lemmas—demonstrates that, excluding XOR-related tasks, ProVerif is faster in 92.3% of cases, achieving a median speedup of 6.74× and reducing peak memory consumption by up to 6.24×.
This work addresses the challenges of scale and complexity in formally verifying production-grade cryptographic libraries, where existing approaches fall short of end-to-end automation. We present CryptoProver, a system that achieves, for the first time, fully automated verification of real-world cryptographic implementations such as curve25519-dalek and RustCrypto’s chacha20. CryptoProver integrates large language models with the Verus verifier to automatically synthesize internal specifications and verifiable proofs from high-level API contracts, without requiring source code modifications. By leveraging a pre-defined trusted library, mechanical gating, and isolation mechanisms, the system ensures specification strength and cross-module consistency. In experiments, CryptoProver completed verification within 11.4 hours at an API cost of \$466.99, successfully covering core cryptographic components relied upon by widely deployed systems including Signal (with 218 million downloads) and Shadowsocks.