Score
Design and implement execution engines and schedulers that guarantee deterministic program behavior by enforcing a fixed ordering of operations and deterministic scheduling across runs, ensuring semantics are preserved and outputs are repeatable. Build pipelined execution and scheduling mechanisms — including separation of stateless and stateful tasks, speculative execution of stateless stages, and overlap with coordination/consensus — that maintain state consistency while reducing end-to-end latency.
This work addresses the nondeterminism inherent in ROS 2 applications, which arises from their publish-subscribe communication model and distributed deployment, leading to unpredictable callback execution orders that complicate concurrency management and hinder safety analysis. To resolve this, the authors propose an automated, non-intrusive transformation method that converts native ROS 2 applications into deterministic programs based on Lingua Franca, without modifying the original codebase. By leveraging Lingua Franca’s logical time semantics, the approach guarantees identical execution order and end-to-end latency for the same inputs. This is the first technique to provide deterministic execution for ROS 2 applications while preserving compatibility and enabling advanced features such as federated execution and fault tolerance. Experimental evaluation on synthetic benchmarks and the Autoware autonomous driving stack demonstrates the method’s efficacy and its clear advantage over the inherently nondeterministic behavior of native ROS 2.
Concurrent programming faces a fundamental tension between expressiveness and determinism; conventional shared-memory models suffer from schedule-dependent behavior and non-reproducible outputs due to destructive updates. Method: This paper introduces Clock-Synchronized Memory (CSM), the first shared-memory abstraction that guarantees deterministic semantics for general-purpose concurrent programs—extending beyond the restricted primitives (e.g., registers, signals) supported in traditional synchronous programming (SP). Grounded in the formal mathematical semantics of SP, we design CSM memory primitives, a clock-synchronization protocol, and rigorously defined access rules, ensuring full compatibility with existing SP compilation and verification toolchains. Results: Experiments demonstrate that CSM significantly enhances expressiveness, modularity, and code reusability of concurrent programs while preserving formal verifiability. It provides a theoretically sound and practically deployable deterministic concurrency infrastructure for safety-critical systems.
Non-determinism in parallel programs severely impedes formal verification. To address this, we propose a novel verification paradigm grounded in *internal determinism*: first, we define the notion of *schedule-independent safety*, reducing correctness of parallel programs to verification over a single execution path; second, we develop Musketeer Separation Logic to establish its theoretical foundation and design Angelic Logic to support dynamic single-path verification; third, we devise the affine type system MiniDet, fully machine-verified within the Iris framework in Rocq (a Coq-based proof assistant), enabling verified deterministic primitives such as concurrent hash sets. This work is the first to systematically exploit internal determinism to simplify concurrent verification. All theoretical results—including syntax, semantics, soundness proofs, and implementation—are end-to-end formally verified in Coq (Rocq), yielding the first fully verified, end-to-end framework for deterministic parallel programming.
Real-time concurrent systems face challenges in reconciling priority-based scheduling with behavioral determinism. Method: This paper introduces a novel “constructive reduction” scheduling mechanism within an extended CCS framework incorporating clocks and priorities, the first such application to synchronous programming semantics. We define the class of “coherent processes,” establish confluence theory under strong priority semantics, and enforce closure of operators over coherence via a “pivotality” condition. Contributions: (1) We prove confluence for a broad class of coherent processes in clock- and priority-augmented CCS; (2) we enable constructive, deterministic modeling of multicast concurrency and shared-memory communication; (3) we overcome Milner’s classical CCS limitation of priority-freedom, substantially extending both the applicability and expressive power of confluence theory for real-time concurrent systems.
Large language model inference lacks output determinism due to floating-point non-associativity, dynamic batching, and varying GPU reduction orders. This work proposes a scheduling-based speculative validation mechanism that introduces speculative execution into deterministic inference for the first time. By employing lightweight validate-and-rollback cycles combined with fixed-shape reduction scheduling, the approach incurs overhead only for requests requiring determinism, while remaining compatible with dynamic batching and requiring minimal modification to existing GPU kernels. The method decouples determinism guarantees from low-level implementation details, achieving high throughput and significantly outperforming baseline strategies such as disabling dynamic batching or rewriting kernel functions.
This work addresses the challenge of reconciling program determinism with pipeline optimization in asynchronous dataflow compilation by introducing Wavelet, a framework that achieves the first end-to-end formal verification for such compilers. Wavelet integrates a capability-based type system augmented with memory fences and the Lean theorem prover to provide modular, semantics-preserving proofs for core compiler transformations, guaranteeing that the generated dataflow graphs satisfy both forward simulation and determinism. Experimental results demonstrate that code produced by Wavelet matches the size of that generated by the unverified RipTide compiler while offering rigorous correctness guarantees.
This work addresses the synthesis of asynchronous automata from a global deterministic finite-state automaton (DFA) specification in distributed systems where fairness assumptions are relaxed and communication may be intermittent. Focusing on processes exhibiting “connected communication”—meaning that if two processes do not communicate within a bounded delay \(d\), they never communicate again—the paper proposes a generalized Zielonka-style construction. This approach leverages trace-closed regular language theory and integrates the delay parameter \(d\) with the depth of process separation, thereby supporting a broader class of practical architectures, such as client-server models. The resulting asynchronous automata exhibit only polynomial blowup in the number of local states per process relative to the size of the original DFA, with exponential complexity confined to the parameters \(d\) and separation depth.
Traditional distributed systems struggle to support modern autonomous infrastructures that integrate stochastic models and autonomous agents. This work proposes the Post-Deterministic Distributed System (PDDS) model, introducing for the first time its five architectural pillars. Its core innovation is a "cognitive state replication" mechanism that extends consistency from data visibility to knowledge visibility, alongside a novel fault classification framework. By leveraging protocol-driven development, verifiable agent infrastructure, and semantic quorum guarantees, PDDS enables coordination among semantically equivalent yet executionally divergent agents. This approach achieves verifiable semantic rollback and cross-agent reasoning consistency, establishing a theoretical foundation for trustworthy autonomous systems.
This work addresses the reliability challenges of production-grade large language model (LLM) agents, which stem from the lack of a clear architectural abstraction delineating stochastic outputs from deterministic system behavior. To bridge this gap, the paper introduces the Stochastic-Deterministic Boundary (SDB) as a core architectural primitive, formalized as a four-tuple contract. Centered on three key concerns—coordination, state, and control—it defines six composable runtime modes. The contributions include a five-step methodology for mode selection, a replay-based divergence diagnosis mechanism, and the insight that architectural momentum becomes critical for long-term reliability once model variance diminishes. By integrating distributed systems patterns such as Saga and event-driven orchestration, the authors construct a verifiable, rollback-capable, and monitorable LLM agent runtime. Empirical validation across five real-world workloads demonstrates its efficacy, and a reference implementation for a 90-day contract renewal agent is open-sourced, significantly enhancing sustained operational reliability.