Score
Designs and produces formal interface specifications and contracts — such as API and protocol definitions, interface abstractions, and versioned standards — that precisely describe operations, message and data formats, pre/post-conditions, and compatibility constraints. Defines and applies interface management practices (versioning, standardization, and contract design), specifies implementation requirements, and creates validation, adaptation, and conformance criteria to ensure interoperable and maintainable implementations.
This work addresses the challenge of reliably conveying intent, requirements, and constraints in human–AI–tool collaborative software development by proposing a specification-centric Bosque API (BAPI) ecosystem. The system introduces a highly expressive specification language that, for the first time, enables cross-language interoperability, automated test generation, formal verification, and execution sandboxing across the entire API lifecycle—from requirement definition and implementation to invocation and validation. By providing end-to-end specification guarantees, BAPI significantly enhances system correctness, security, and the efficiency of human–AI collaboration, offering a novel infrastructure for software development in the era of AI agents.
Current RESTful API design quality assessment relies heavily on manual inspection, lacking early, automated validation mechanisms for non-functional requirements—particularly interoperability, modularity, and maintainability. Method: This paper proposes an OpenAPI-based static analysis approach that implements a configurable rule engine. It formalizes 75 design principles derived from scholarly literature and industry standards into structured, machine-checkable constraints, enabling customizable rule activation/deactivation and traceable feedback to align requirements engineering with architectural governance. Contribution/Results: Following the design science research paradigm, we developed and evaluated a prototype tool. Empirical evaluation and expert review demonstrate that the method significantly improves API design compliance and consistency, achieving 82% automation coverage. It effectively supports continuous architectural governance in agile development environments, bridging the gap between design-time assurance and operational API lifecycle management.
In software design, paradigm-implied semantic expectations—such as data abstraction consistency and feedback-control closed-loop behavior—are often left implicit, leading to design deviations and verification challenges. To address this, we introduce the concept of *design obligations*: explicit, logically formalizable, and verifiable specifications that codify such implicit constraints inherent to design paradigms. Leveraging formal modeling and paradigm semantics analysis, we establish two obligation frameworks—one for data-abstraction-based systems and another for feedback-driven adaptive systems—precisely capturing their core semantic requirements. We demonstrate that common design flaws stem from obligation violations and show how these obligations enable rigorous compliance verification and pedagogical application. This work bridges the semantic gap between design intent and implementation, providing both theoretical foundations and a methodological framework for paradigm-driven design assurance.
SLICE框架通过三个阶段生成代码,解决了在满足功能需求的同时执行输入条件的问题,提高了代码生成的准确性。
Addressing the “oracle absence” and “error attribution difficulty” challenges in network protocol parser verification, this paper proposes an LLM-driven framework for RFC semantic parsing and feedback-based oracle refinement. First, large language models automatically translate unstructured RFC text into formal message specifications. Second, an iterative, quasi-oracle is constructed to support specification-guided fuzz testing and cross-language (C/Python/Go) protocol implementation verification. Finally, vulnerabilities are precisely traced back to their originating RFC clauses. This work is the first to integrate LLM-based semantic understanding with dynamic oracle refinement. Evaluated on nine mainstream protocols, it discovers 69 vulnerabilities—36 of which have been confirmed—surpassing state-of-the-art approaches in both effectiveness and efficiency. It also demonstrates, for the first time, the feasibility of fully automated derivation of test oracles directly from natural-language protocol specifications.
Current code-generating agents often produce inconsistent programs under semantically equivalent but evolutionarily distinct specifications, revealing sensitivity to the phrasing trajectory of requirements. This work proposes SpecPath, a diagnostic framework that reframes requirement evolution evaluation as an “active contract resolution” problem. By fixing the codebase, final contract, verifier, and execution budget while systematically varying only the historical paths leading to the same contract, SpecPath enables rigorous assessment of agent behavioral consistency. Experiments across five software tasks and fourteen agent configurations reveal that 35% of code blocks successful under direct specifications fail on at least one semantically equivalent evolutionary path, thereby uncovering a previously undocumented lack of specification-path invariance in contemporary coding agents.
This study addresses the lack of systematic mechanisms in existing digital twin services to express and enforce data quality requirements—such as accuracy, completeness, and timeliness—at the model level during runtime, which undermines service reliability. To bridge this gap, the authors propose a contract-based approach to data quality management that formalizes a theory of data contracts, integrates it into the digital twin architecture, and introduces a domain-specific language (DSL) to support declarative specification and automated monitoring of these contracts. This work achieves, for the first time, a closed-loop integration of model-driven data contracts within digital twins, ensuring end-to-end data quality from the modeling phase through runtime execution. The proposed method significantly enhances the trustworthiness of downstream services, including simulation, what-if analysis, and machine learning–based prediction.
研究通过对比分析三种SBOM生成工具在JavaScript和Rust项目中的表现,揭示了因SBOM规范模糊导致的系统性差异问题,并建议未来需明确标准化规则以提高互操作性和合规性。
Current approaches to automated program synthesis lack effective governance mechanisms to ensure the compliance of generated code. This work proposes Protocol-Driven Development (PDD), a model that treats machine-executable protocols as primary artifacts and delineates the space of valid implementations through structural, behavioral, and operational invariants. PDD mandates that every implementation be accompanied by a verifiable chain of compliance evidence. By integrating formal methods, property-based testing, policy-as-code, and software provenance techniques, PDD establishes a unified framework for protocol specification and verification. This framework enables trustworthy admission control over automatically synthesized code, guaranteeing that all adopted implementations strictly adhere to protocol constraints and are backed by complete, auditable proofs of compliance.
This study addresses the proliferation of functional redundancy in service-oriented architectures caused by heterogeneous clients, which undermines system evolvability and maintainability. To mitigate this issue, the authors propose a novel reference architecture that synergistically integrates metadata-driven mechanisms with pattern languages. By leveraging metadata management and a plugin-based design, the approach effectively constrains service redundancy while enhancing reuse capabilities. The work innovatively combines metadata mechanisms and pattern languages in architectural construction and validates its efficacy through a triangulated evaluation method incorporating scenario-based assessment and real-world case studies. Empirical results demonstrate that the majority of system changes during evolution require no code modifications—only configuration adjustments or the addition of pluggable components—thereby significantly improving architectural stability and reuse efficiency.