Skip to content
Conference Open access

Show Me The Money: An Exercise in Proof-Driven Software Understanding

Jul 2026 · International Conference on Computer Aided Verification · Vol abs/2607.16499, pp. 230-243 · 0 citations · 14 references
Computer Science

TL;DR

This work demonstrates how the strategic combination of theorem proving and model checking provides a path for delivering robust assurance to legacy systems.

Abstract

We present a case study on proof-driven software understanding of mature, security-critical infrastructure. While formal methods are traditionally applied during the design phase, we present our experience applying formal reasoning onto a mature industrial C++ codebase. We focus on a formal analysis of the core algorithm that implements the Stellar blockchain's SDEX order book. By combining large language models (LLMs), Prototype Verification System (PVS), and SeaHorn, we are able to prove core properties of the production codebase. Our approach also identified an inconsistency in documentation related to the reachability of an exception location. Most importantly, however, we produce artifacts that make it easy for code changes to be checked against established invariants. This work demonstrates how the strategic combination of theorem proving and model checking provides a path for delivering robust assurance to legacy systems.

Read PDF

Similar papers

Jul 2026

Foundational Refinement Proofs for Deployed Bytecode, at the Price of Tokens

It is concluded that foundational mechanized proofs can now be bought at the price of tokens, and that this shift can reshape how verification frameworks are architected.

Lefteris Lazaropoulos, Zoe Paraskevopoulou · 0 citations
Open access 2026

Don't Just Translate: Verify - LLM-Guided Solidity Migration with Semantic Guarantees

: Smart contracts operate in immutable blockchain environments where preserving correctness during software evolution is critical. The transition from Solidity 0.5.x to 0.8.x introduces important safety improvements but also semantic changes that make manual migration of legacy contracts error-prone. Although large lan...

Arnab Mukherjee, S. Bandyopadhyay, Raju Halder et al. · 0 citations
Jul 2026

Open-Source LLM-Driven Formal Verification: A Multi-Agent Pipeline for RTL Repair

A multi-agent pipeline that couples an LLM with an open-source formal backend to repair RTL through counterexample-guided iteration and additionally reports a practical limitation of the Yosys bind directive relevant to the open-source formal verification community.

Hailey Tran · 0 citations
Review Sep 2026

Trust the Spec, Not the Code - A Specification-First, AI-Assisted Case Study in Online Banking

It is argued that AI removes much of that cost: natural language enriched with lightweight mathematics, written in \LaTeX, can serve as an intermediate specification language that is precise enough to reason over and prove, while a large language model reviews it for ambiguity, drafts proofs, and generates the implemen...

E. Farchi · 0 citations
Review Sep 2026

Scaling Verification of Cryptographic Software with Aeneas, Rust, and Lean

This work develops a new methodology for verifying cryptographic software and extends SymCrypt with experimental optimizations and implementations of algorithms such as FrodoKEM, ML-DSA, and HPKE to explore the scalability of writing, adapting, and verifying cryptographic code.

Ho Son, C. Fournet, Jonathan Protzenko et al. · 0 citations

SymCert: Verifying SMT-Based Policy Analyses

SymCert is presented, a framework implemented in Lean for building verified SMT-based analyses of Cedar policies that provide a verified symbolic compiler and authorizer for reducing policies to SMT formulas, a hierarchy enforcer for ensuring well-formedness of counterexamples, and a counterex-ample extractor for provi...

Emina Torlak · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.