symbolic step verification

Designs and implements tools and systems that verify individual computation or derivation steps using symbolic methods by constructing symbolic representations, generating and solving constraints, and performing symbolic execution or reasoning to check intermediate steps and certify final results. This includes building symbolic verifiers, constraint verifiers, and intermediate-step checkers that detect and report incorrect substeps and produce feedback for correction or schema refinement.

symbolicstepverification

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
0.14
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$217K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

Verifying a Sparse Matrix Algorithm Using Symbolic Execution

Oct 15, 2025
AC
Alexander C. Wilton
🏛️ University of Delaware

Scientific software—characterized by mathematical complexity and aggressive optimization—often harbors subtle defects undetectable by conventional unit testing, especially in sparse matrix algorithms where boundary violations and logical inconsistencies frequently occur. This paper proposes a symbolic execution–based verification method tailored for sparse matrix algorithms. By extending mainstream unit testing frameworks with lightweight formal verification techniques, it achieves deep semantic coverage of critical control paths. The approach significantly enhances correctness assurance: it successfully identifies previously undetected defects—including numerical overflow, index out-of-bounds errors, and violations of mathematical equivalence—in canonical sparse matrix operations such as SpMV and ILU factorization under CSR format. Experimental evaluation demonstrates a 37% improvement in path coverage over pure dynamic testing and establishes, for the first time, reproducible and interpretable algorithm-level trustworthiness verification within industrial-grade scientific computing libraries.

Applying symbolic execution for stronger verificationDetecting subtle bugs in scientific softwareVerifying sparse matrix algorithm correctness

Divide, Conquer and Verify: Improving Symbolic Execution Performance

Oct 05, 2023
CS
Christopher Scherb
🏛️ University of Applied Sciences and Arts, Northwestern Switzerland

Symbolic execution provides formal verification guarantees but suffers from path explosion and high SMT-solving complexity, limiting scalability to real-world software. To address this, we propose the first divide-and-conquer symbolic execution framework based on program slicing: the program is decomposed into independent slices, each executed symbolically in isolation; memory and control-flow side effects are then modeled and incrementally merged, thereby avoiding global path explosion. Our core contributions are (1) a composable side-effect merging mechanism and (2) a constraint decomposition strategy—enabling, for the first time, incremental and formally verifiable modular symbolic execution. Experimental evaluation demonstrates that our approach achieves a 3.2× speedup in path exploration while reducing memory overhead by 57%, all while preserving formal correctness guarantees.

Addressing path explosion and SMT complexity in symbolic executionImproving performance for real-world software verificationUsing divide-and-conquer with sliced execution and side effects

Towards Verifying Procedural Programs using Constrained Rewriting Induction

Aug 30, 2014
CK
Cynthia Kop
🏛️ University of Innsbruck | University of Copenhagen | Nagoya University

This work addresses the safety verification of procedural programs featuring global variables, arrays, function calls, and arbitrary data types. The proposed method automates verification without requiring an explicit specification language. It compiles programs into Logic Constraint Term Rewriting Systems (LCTRSs) and—novelty—the first adaptation of rewriting induction to this framework. A lightweight equation generalization strategy is introduced to jointly verify memory safety and functional correctness. Built upon extended integer Term Rewriting Systems (TRSs) and LCTRS modeling, the approach enables end-to-end automated verification of integer arithmetic and array operations in realistic programs. Experimental evaluation demonstrates that the method significantly improves automation and practicality for procedural program verification, all without reliance on external specification languages.

Handling global variables, function calls, and array operationsProving equivalence between implementations without explicit specificationsVerifying procedural programs using constrained rewriting induction

Accurate and Extensible Symbolic Execution of Binary Code based on Formal ISA Semantics

Apr 05, 2024
ST
Sören Tempel
🏛️ Technische Universität Braunschweig | DFKI | University of Bremen

Binary program symbolic execution suffers from semantic distortion and implementation errors introduced during intermediate representation (IR) translation. Method: This paper proposes the first instruction-level symbolic execution framework directly grounded in formal ISA semantics (Rock/Sail), bypassing conventional IR abstractions by compiling machine-readable ISA specifications into SMT-solvable symbolic semantic models and integrating them into a binary analysis platform. Contributions/Results: (1) The first end-to-end automated pipeline from formal ISA semantics to symbolic execution; (2) Demonstrated scalability on RISC-V—modeling new instructions requires only a few hours; (3) Discovered five previously unknown ISA semantic implementation bugs in angr; (4) Achieved high-fidelity branch modeling and solving capability. The framework significantly improves the accuracy, trustworthiness, and development efficiency of binary symbolic execution.

Machine LanguageSoftware VerificationSymbolic Execution

Latest Papers

What's happening recently
View more

Amid the growing representational capacity of foundation models, this work examines the necessity and evolving role of explicit symbolic reasoning. Grounded in the principle of compression, it proposes a modeling–reasoning trade-off theory: symbolic reasoning functions not as an intrinsic component of intelligence but as a compensatory mechanism for information loss in simplified models. As models increasingly approximate reality, reliance on such symbolic scaffolding naturally diminishes. Through theoretical analysis, computational modeling, and an AI-philosophical framework, the study offers a unified account of the historical significance of symbolic methods and the empirical success of modern large language models. It further repositions symbolic reasoning’s future value—not as a core reasoning engine, but as an interpretable interface in human–AI interaction, crucial for enabling human oversight, verification, and trust calibration.

artificial intelligencefoundation modelsmodeling-reasoning trade-off

Traditional simulation struggles to cover rare corner-case scenarios, while formal verification is hindered by limited scalability and high usability barriers. To address these challenges, this work proposes Forbench—a word-level symbolic simulation framework that seamlessly integrates symbolic execution into conventional RTL simulation workflows. By leveraging an SMT solver to support symbolic signals and state transitions, Forbench enables systematic exploration of design behaviors while preserving the semantics of traditional simulation. It further provides a simulation-like Python interface for defining constraints, enabling co-simulation, and performing property checking. Forbench significantly improves verification efficiency without compromising coverage and substantially lowers the barrier to adopting formal methods.

formal verificationpre-silicon verificationsimulation

Existing symbolic execution approaches often lack a formal foundation aligned with the concrete semantics of programming languages, typically being constructed in an ad hoc and fragmented manner. This work proposes a symbolic Structural Operational Semantics (SOS) rule format that, for the first time, relies solely on the algebraic signature of the source language to uniformly capture both concrete and symbolic operational semantics, thereby enabling language-agnostic generation of symbolic execution semantics. Within this framework, we formally derive symbolic semantics and rigorously prove their soundness and completeness relative to the concrete semantics, demonstrating applicability to arbitrary programming languages.

concrete semanticsformal semanticslanguage independence

This work presents the first complete formal verification in Lean 4 of the informal Euclidean domain algorithms originally described in the 1986 ICON language. By separating concerns into mathematical definitions, computable implementations, and output formatting, the project constructs a computable mirror atop Mathlib’s `EuclideanDomain` hierarchy and integrates a regression testing infrastructure to reproduce the original outputs. All 14 algorithms are formally specified, with core procedures such as integer GCD and the extended Euclidean algorithm accompanied by machine-checked correctness proofs. The formalization precisely delineates the boundaries between computability and mathematical correctness while fully replicating the benchmark results reported in Ericson’s technical report.

Algorithm CorrectnessEuclidean DomainFormalization

This work addresses the bottleneck of loop invariant synthesis in formal verification by introducing VerIbmc, the first fully local neurosymbolic framework that operates without reliance on cloud-based large language model APIs. The approach integrates deterministic symbolic reasoning, locally deployed open-source large language models (ranging from 7B to 120B parameters), the ESBMC model checker, and a structured feedback mechanism, supporting both Chain-of-Thought and Tree-of-Thought prompting strategies. Evaluated on 499 benchmark problems, the best configuration (GPT-OSS-120B) solves 431 instances (86.4%), matching the performance of state-of-the-art cloud-based tools. Notably, the symbolic component alone solves 75 problems and substantially enhances the efficacy of weaker models, achieving efficient verification while preserving code privacy and minimizing computational cost.

cloud API dependencyformal software verificationloop invariant synthesis

Hot Scholars

JP

Joost-Pieter Katoen

Distinguished Professor of Computer Science, RWTH Aachen University and University of Twente
formal methodsmodel checkingconcurrency theoryprobabilistic programming
LC

Lucas C. Cordeiro

Professor of Computer Science, University of Manchester
Formal MethodsAutomated VerificationSoftware TestingProgram Synthesis
GL

Guoqiang Li

School of Computer Science, Shanghai Jiao Tong University
formal verificationprogramming language theoryknowledge reasoning and verification
YX

Yingfei Xiong

Associate Professor, Peking University
Software EngineeringProgramming LanguagesProgram RepairProgram Synthesis