inject runtime checks into code artifacts

Designs and implements mechanisms that generate and insert runtime assertions, monitors, or other executable checks into program artifacts, including tools that perform runtime code generation and instrumentation to verify invariants, pre/postconditions, types, or security properties during execution. Builds analyses and transformations to synthesize appropriate checks, determine insertion points in code artifacts, and manage their runtime behavior (performance, failure handling, and observable effects).

injectruntimechecksinto

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
0.31
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$203K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

This work addresses the challenges of model uncertainty and unpredictability in partially observable or black-box systems during runtime by proposing a unified theoretical framework that integrates epistemic logic with temporal logic. Leveraging automata theory, it systematically formalizes core concepts—including specification, diagnosis, opacity, and monitorability—and synthesizes lightweight online monitors through offline analysis. The approach is extended to real-time systems, resolving key issues related to their temporal semantics and algorithmic complexity. Furthermore, the study precisely characterizes the fundamental limits of runtime verification, thereby establishing a constructive and implementable foundation for practical deployment of monitoring mechanisms.

black-box systemsmonitoringpartial observability

This paper addresses the fundamental limitation in runtime monitoring that branching-time properties—such as those expressible in modal μ-calculus—are inherently unmonitorable over a single execution trace. To overcome this, we propose a novel multi-round execution monitoring paradigm. Integrating monitoring theory, formal semantics, and game theory, we establish—for the first time—a precise theoretical characterization linking the syntactic structure of branching-time formulas to the minimum number of execution rounds required for monitoring, and rigorously prove that multi-round monitoring strictly extends classical monitorability boundaries. Our main contributions are: (1) a systematic characterization of observational power in multi-round monitoring; (2) tight upper and lower bounds on the minimal round complexity; and (3) confirmation that several canonical branching-time properties—including key safety and liveness specifications—become effectively monitorable within two or three rounds. This work provides both a theoretical foundation and a practical methodology for dynamic verification of complex concurrent and interactive behaviors.

Extends monitorability of branching-time properties via multiple executionsInvestigates enhanced monitoring capabilities over multiple system runsLinks property syntax structure to required number of system runs

Diagnosing Violations of State-based Specifications in iCFTL

Sep 22, 2025
CS
Cristina Stratan
🏛️ University of Luxembourg

To address the challenge of root-cause localization for iCFTL state specification violations, this paper proposes a static-dynamic collaborative diagnosis method based on backward data-flow analysis. First, backward data-flow analysis statically identifies potential violation-inducing statements; then, program instrumentation and runtime validation generate enriched execution traces to enable precise attribution. This work is the first to apply backward data-flow analysis to iCFTL specification violation diagnosis, significantly improving both diagnostic accuracy and interpretability. Experimental evaluation across 10 real-world projects and 112 specifications demonstrates that the approach precisely localizes violating statements in 90% of cases, reduces manual code review effort by over 90%, achieves an average diagnosis time of ≤7 minutes, incurs memory overhead <25 MB, and imposes runtime performance overhead <30%.

Generating informative verdicts for violated iCFTL specificationsIdentifying relevant statements causing specification violationsReducing manual inspection needed to diagnose runtime violations

This work addresses the lack of security and verifiability in large language models for project-level code generation by proposing and evaluating an end-to-end Detect–Repair–Verify (DRV) workflow tailored for multilingual web applications. The approach generates executable code at three granularities—project, requirement, and function—integrating static and dynamic analysis, automated repair, and test-driven verification. Under unified resource constraints, the study systematically compares generative, single-round, and iterative variants of DRV. It introduces the first project-level benchmark for secure code generation that supports multiple prompting granularities, enabling a comprehensive evaluation of DRV’s efficacy. The findings reveal limitations in using vulnerability reports to guide repairs and identify common post-repair failure modes such as regressions and semantic drift. Experimental results demonstrate that the iterative DRV variant significantly enhances security while preserving functional correctness.

Code SecurityDetect-Repair-VerifyEmpirical Study

Quantitative and Approximate Monitoring

May 18, 2021
TA
Thomas A. Henzinger
🏛️ IST Austria

Existing runtime monitors support only Boolean specification verification, making it infeasible to progressively approximate quantitative properties—such as average response time—over infinite traces. Method: This paper establishes the first unified formal framework for quantitative approximate monitoring, introducing quantitative monitors whose estimates monotonically improve as observation prefixes grow, and rigorously modeling the trade-off between estimation accuracy and resource consumption (specifically, register count). Contribution/Results: We prove that register count strictly determines the theoretical upper bound on achievable accuracy; moreover, each additional register strictly increases the attainable precision—demonstrating an irreducible, non-compensatory relationship between resources and accuracy. Our framework conservatively extends classical Boolean monitoring theory while ensuring soundness. The proposed approach provides provably optimal, resource-bounded approximate monitoring for critical performance metrics, enabling verifiable, deployment-aware runtime assurance.

Analyzing precision-cost trade-offs in monitor resource usageDeveloping approximate monitors for numerical value estimationGeneralizing runtime verification to quantitative trace properties

Latest Papers

What's happening recently
View more

This work addresses the high cost of manually writing formal specifications and the limitations of existing large language model (LLM)-based approaches that require white-box access to source code, thereby posing intellectual property and deployment constraints. The authors propose a black-box-driven method that leverages only test code and dynamic execution traces to generate candidate Java Modeling Language (JML) specifications via an LLM. These candidates are locally validated using bounded model checking, and an iterative feedback loop refines them based on verification outcomes. This approach is the first to enable fully automated formal specification generation without any access to the program’s internal structure. Evaluated on the SpecGenBench benchmark, it demonstrates that test-derived information effectively guides specification synthesis, while also highlighting critical challenges in checker compatibility and diagnostic feedback, substantially enhancing industrial applicability.

dynamic execution tracesformal specificationsLLM

Existing large code models struggle to generate executable intermediate formal specifications, limiting precise verification and repair of program behavioral errors. This work proposes SpecCoder, a novel framework that focuses on generating executable inline assertions at critical program locations, thereby transforming static annotations into verifiable evidence. SpecCoder employs verification-guided training, fine-tuning the Qwen2.5-Coder series models using correct programs, behavioral mutants, and multi-round specification refinement trajectories. Evaluated on the HumanExec benchmark, SpecCoder substantially improves the correctness (+55.8%), completeness (+358.1%), and assertion validity (+26.6%) of inline specifications, significantly enhancing program verification and repair capabilities.

code LLMsexecutable assertionsformal specifications

This work proposes CopilotVerifier, an automated verification framework designed to enhance the correctness and trustworthiness of runtime monitoring code in safety-critical systems by complementing the Copilot compiler. CopilotVerifier is the first to decompose the bisimulation relation between source programs and their compiled C code into verifiable conditions. By integrating symbolic execution (via Crucible) with SMT solving (through What4), the framework automatically generates formal proofs that guarantee semantic equivalence—ensuring identical outputs and consistent crash behaviors under equivalent inputs. This approach significantly strengthens compiler assurance with modest computational overhead and lays the groundwork for producing human-auditable formal arguments of correctness.

bisimulationcompiler correctnessformal assurance

This work addresses the limitations of traditional structural coverage metrics in embedded software testing, which are often confined to the unit level and fail to reflect true coverage completeness in integration and system testing. Instrumentation-based approaches risk perturbing runtime behavior, while pure tracing techniques suffer from unreliability under high compiler optimization. To overcome these challenges, the paper proposes an integration-test-driven coverage strategy featuring a novel “integration-first” closed-loop workflow. By synergistically combining embedded tracing with hybrid runtime analysis (hRA) to preserve semantic boundaries, and leveraging source-to-target mapping for evidential traceability alongside Hyper Coverage for cross-variant merging, the approach establishes a unified evidence-integration mechanism. Evaluated on -O3-optimized release binaries, it reliably achieves branch, condition, and MC/DC coverage measurements and precisely identifies source code lines consistently uncovered across all variants, thereby significantly enhancing confidence in the test completeness of embedded systems.

compiler optimizationembedded softwareintegration testing

This work addresses the significant runtime overhead commonly incurred by assertion checking in dynamically typed languages. It proposes a novel approach that, for the first time, systematically incorporates multi-calling-context information into a goal-directed, multi-variant abstract interpretation framework. By performing top-down inference of program properties under distinct calling contexts and selectively integrating the runtime semantics of assertions, the method substantially reduces redundant checks while preserving the ability to provide hints about unverified properties. An implementation in the Ciao system demonstrates that this technique markedly decreases the number of runtime checks and improves execution performance compared to existing approaches.

abstract interpretationassertion propertiesdynamic languages

Hot Scholars

FF

Fangcheng Fu

Shanghai Jiao Tong University
machine learningdeep learningMLSysdistributed computation
LH

Lewei He

South China Normal University
3D PrintingDeep Learning
AR

Ahmad-Reza Sadeghi

Technische Universität Darmstadt
System SecurityPrivacyHardware Security
RL

Ruixuan Li

Professor of Computer Science, Huazhong University of Science and Technology
Distributed systemssecurity and privacydata management
TT

Thu-Trang Nguyen

VNU University of Engineering and Technology
Automated Software EngineeringProgram AnalysisCode GenerationAI