Score
Designs and implements runtime instrumentation and monitoring systems that observe executing systems and assess property satisfaction under probabilistic behaviors, including monitors expressed in probabilistic logic (e.g., probabilistic datalog) and algorithms for stochastic policy verification. Builds estimators and analyses that compute sound probability bounds on violations and integrate those bounds into runtime decisions and controls.
This paper addresses the fundamental limitation in runtime monitoring that branching-time properties—such as those expressible in modal μ-calculus—are inherently unmonitorable over a single execution trace. To overcome this, we propose a novel multi-round execution monitoring paradigm. Integrating monitoring theory, formal semantics, and game theory, we establish—for the first time—a precise theoretical characterization linking the syntactic structure of branching-time formulas to the minimum number of execution rounds required for monitoring, and rigorously prove that multi-round monitoring strictly extends classical monitorability boundaries. Our main contributions are: (1) a systematic characterization of observational power in multi-round monitoring; (2) tight upper and lower bounds on the minimal round complexity; and (3) confirmation that several canonical branching-time properties—including key safety and liveness specifications—become effectively monitorable within two or three rounds. This work provides both a theoretical foundation and a practical methodology for dynamic verification of complex concurrent and interactive behaviors.
This work addresses the challenges of model uncertainty and unpredictability in partially observable or black-box systems during runtime by proposing a unified theoretical framework that integrates epistemic logic with temporal logic. Leveraging automata theory, it systematically formalizes core concepts—including specification, diagnosis, opacity, and monitorability—and synthesizes lightweight online monitors through offline analysis. The approach is extended to real-time systems, resolving key issues related to their temporal semantics and algorithmic complexity. Furthermore, the study precisely characterizes the fundamental limits of runtime verification, thereby establishing a constructive and implementable foundation for practical deployment of monitoring mechanisms.
Existing runtime monitors support only Boolean specification verification, making it infeasible to progressively approximate quantitative properties—such as average response time—over infinite traces. Method: This paper establishes the first unified formal framework for quantitative approximate monitoring, introducing quantitative monitors whose estimates monotonically improve as observation prefixes grow, and rigorously modeling the trade-off between estimation accuracy and resource consumption (specifically, register count). Contribution/Results: We prove that register count strictly determines the theoretical upper bound on achievable accuracy; moreover, each additional register strictly increases the attainable precision—demonstrating an irreducible, non-compensatory relationship between resources and accuracy. Our framework conservatively extends classical Boolean monitoring theory while ensuring soundness. The proposed approach provides provably optimal, resource-bounded approximate monitoring for critical performance metrics, enabling verifiable, deployment-aware runtime assurance.
Runtime verification of temporal properties—such as those expressed in Metric Interval Temporal Logic (MITL)—is challenging in partially observable real-time systems, particularly when critical internal events (e.g., latent faults) remain unobservable. Method: This paper proposes an active prediction approach grounded in prior formal assumptions: system behavior is modeled as a timed automaton and integrated into a runtime verification framework to enable online inference of unobservable internal events. For the first time, formal system assumptions are deeply embedded into the real-time monitoring pipeline, combining constraint-driven temporal observation modeling with assumption-guided online verification. The approach is implemented within the UPPAAL toolchain. Contribution/Results: Experimental evaluation demonstrates that the method predicts property satisfaction/violation up to several time units in advance. In case studies involving smart grids and medical devices, monitoring success rates for properties dependent on unobservable events improve by 47%, significantly enhancing both the foresight and completeness of runtime verification.
This paper addresses hyperproperties—higher-order system requirements encompassing information-flow security, knowledge reasoning, and robustness, which span multiple execution traces—by proposing the first unified logical and algorithmic framework covering the entire verification lifecycle. Methodologically, it rigorously characterizes the expressive power and decidability boundaries of classical temporal logics (LTL, CTL, S1S) over hyperproperties; then introduces a novel multi-trace synchronization modeling and quantifier alternation handling mechanism grounded in higher-order temporal logic, constraint solving, and symbolic automata. Key contributions include: (i) a comprehensive taxonomy and complexity-theoretic characterization of hyperproperty logics; (ii) an open-source verification toolchain supporting HyperLTL and HyperCTL*; and (iii) end-to-end support for core verification tasks—including satisfiability checking, model checking, runtime monitoring, and controller synthesis.
This work addresses the challenge of inaccurate and noise-amplified verification in stream-based runtime monitoring caused by sensor noise. To tackle this issue, the paper introduces RLola, a novel extension of the Lola specification language that incorporates slack variables to symbolically model sensor noise, thereby avoiding the aliasing problems inherent in interval arithmetic. The approach leverages SMT solving to enable precise offline verification and formally delineates a sublanguage amenable to constant-memory online monitoring. Experimental evaluation within the RTLola framework demonstrates that RLola achieves superior accuracy and computational efficiency, effectively uncovering specification violations that are missed by purely online monitoring techniques.