Proof-Aware Engineering of Cyber-Physical Systems
Proof-Aware Engineering of Cyber-Physical Systems
Disciplines
Computer Sciences (80%); Mathematics (20%)
Keywords
-
Cyber-Physical Systems,
Verification,
Component-Based Modeling,
Model Refinement,
Model Transformation
Motivation Cyber-physical systems (CPS) are operated in many safety-critical areas where lives are at stake, such as in road traffic and robotics. CPS are almost impossible to get right without proper analysis of their behavior, which emerges from combined discrete dynamics (the cyber part, e.g., setting the acceleration of a car) and the entailed continuous dynamics (the physical part, e.g., motion of a car). Thus, formal verification techniques to analyze CPS are of paramount importance to provide correctness guarantees for all of the infinitely many possible states of a CPS---not just for some, as in testing or simulation. Problem Formal verification rests on models of a CPS, which capture these infinitely many possible states. Current methods make a trade-off between full automation and modeling expressiveness: Reachability analysis methods focus on full automation and are therefore restricted to less expressive classes of CPS. Theorem proving methods, in contrast, rely on human guidance to make progress despite undecidability so that more realistic models can be verified. To make human guidance possible, however, the inherent complexities of CPS practically mandate incremental development, which requires full re-verification after every change with current theorem proving methods. At the same time, we want the correctness properties that are verified formally for a model also to hold for an actual implementation. For this, we have to resolve a gap between modeling concepts that are beneficial for verification (e.g., non-deterministic control) and those that are appropriate for implementation (e.g., deterministic control) in a way that preserves correctness. The vision of this project is to reduce verification effort despite incremental CPS engineering, and at the same time ensure implementation correctness despite conceptual gaps to modeling. Research Challenges To work towards achieving this vision, we will base on our prior experience with CPS to make the concepts, methods, techniques, and tools for incremental engineering of CPS proof-aware. Proof-aware Refinement: Develop provably correct refinement operations that change the structure of models (e.g., share duplicated control decision) or the behavior of models (e.g., introduce sensor uncertainty) and automatically derive proof obligations to retain correctness. Proof-aware Composition: Develop provably correct composition operators to connect verified CPS components (e.g., asynchronously communicate), automatically derive proof obligations to establish overall system correctness and adapt components to their new environment. Proof-aware Implementation: Develop provably correct transformation operators (e.g., non- deterministic sensor input into sensor access through a driver) that turn a CPS model into code automatically. Evaluation The expected benefits of the proposed research include reduced effort w.r.t. modeling, verification, and implementation of CPS, as well as increased implementation correctness. We will demonstrate the feasibility of the proposed approach with case studies in the area of road traffic and robotics, based on a proof-of-concept prototype.
Cyber-physical systems in road traffic, aircraft, robotics, medical devices, and many other safety-critical areas ask for highest safety standards. The project ProofAwareCPS developed modeling and theorem proving techniques to assemble cyber-physical systems from components with mathematical proof in a way that lifts proofs about components to full system-level proofs about the emerging behavior of the interacting components in a cyber-physical system. A unique characteristic of cyber-physical systems is their combined computer-based control decisions (e.g., how to control the brakes, throttle, and steering in a self-driving car) and the entailed physical motion (e.g., how the car itself moves in reaction to those decisions) in relation to other agents in the system's environment (e.g., pedestrians crossing streets). ProofAwareCPS targeted a comprehensive approach for such hybrid software-controlled physical behavior and the project results apply specifically not only to the control software, but also to the physical behavior. As fundamental pillars of the approach, ProofAwareCPS studied three topics: proof-aware composition, proof-aware refinement, and proof-aware implementation. Proof-aware composition exploits the structure of templates for describing components and their interaction to provide a proof technique to lift component proofs to system proofs; the proof technique can be (and is) implemented as a proof tactic in theorem provers for cyber-physical systems to automate compositional verification. Proof-aware refinement describes techniques to develop and adapt systems and proofs incrementally, which is not only useful for model and proof maintenance, but also at the heart of the generic composition proof developed in the project. Proof-aware implementation tackles translation from component models into executable control and monitoring software in a popular programming language for immediate practical applicability of verified models of cyber-physical systems. The project results facilitate distributed, model-based development of cyber-physical systems with safety guarantees. The developed modeling and proof techniques were demonstrated with modeling and verification case studies in the area of road traffic control and collision avoidance in robotics.
- Universität Linz - 100%
- Wieland Schwinger, Universität Linz , associated research partner
- Bernhard Beckert, Karlsruher Institut für Technologie - Germany
- André Platzer, Carnegie Mellon University - USA
- Rance Cleaveland, University of Maryland - USA
Research Output
- 73 Citations
- 13 Publications
- 1 Disseminations
-
2019
Title A Component-Based Hybrid Systems Verification and Implementation Tool in KeYmaera X (Tool Demonstration) DOI 10.1007/978-3-030-23703-5_5 Type Book Chapter Author Müller A Publisher Springer Nature Pages 91-110 -
2018
Title Tactical contract composition for hybrid system component verification DOI 10.1007/s10009-018-0502-9 Type Journal Article Author Müller A Journal International Journal on Software Tools for Technology Transfer Pages 615-643 Link Publication -
2016
Title A Component-Based Approach to Hybrid Systems Safety Verification DOI 10.1007/978-3-319-33693-0_28 Type Book Chapter Author Müller A Publisher Springer Nature Pages 441-456 -
2020
Title Associative, proof-aware Composition of Cyber-physical Systems Type Other Author Andreas Müller Link Publication -
2020
Title Towards CPS Verification Engineering Type Conference Proceeding Abstract Author Werner Retschitzegger Conference 22nd International Conference on Information Integration and Web-based Applications and Services (iiWAS) -
2017
Title Change and Delay Contracts for Hybrid System Component Verification Type Other Author Andreas Müller Link Publication -
2017
Title Component-based Deductive Verification of Cyber-Physical System Type Other Author Andreas Müller Link Publication -
2017
Title A Benchmark for Component-based Hybrid Systems Safety Verification DOI 10.29007/9jm3 Type Conference Proceeding Abstract Author Müller A Pages 65-54 Link Publication -
2017
Title Change and Delay Contracts for Hybrid System Component Verification DOI 10.1007/978-3-662-54494-5_8 Type Book Chapter Author Müller A Publisher Springer Nature Pages 134-151 -
2020
Title Towards CPS Verification Engineering DOI 10.1145/3428757.3429146 Type Conference Proceeding Abstract Author Müller A Pages 367-371 Link Publication -
2015
Title Logic-Based Modeling Approaches for Qualitative and Hybrid Reasoning in Dynamic Spatial Systems DOI 10.1145/2764901 Type Journal Article Author Mitsch S Journal ACM Computing Surveys (CSUR) Pages 1-40 -
2015
Title Verified Traffic Networks: Component-Based Verification of Cyber-Physical Flow Systems DOI 10.1109/itsc.2015.128 Type Conference Proceeding Abstract Author Muller A Pages 757-764 -
2015
Title Component-based CPS Verification: A Recipe for Reusability Type Conference Proceeding Abstract Author Andreas Müller Conference Doctoral Symposium of Formal Methods, co-located with the 20th International Symposium on Formal Methods (FM 2015) Pages 33-37 Link Publication
-
2016
Title Lange Nacht der Forschung Type Participation in an open day or visit at my research institution