Mechanised Hypersafety Proofs about Structured Data
Name
3656403.pdf
Size
580.74 KB
Format
Adobe PDF
Checksum (MD5)
0a002979c727d299200ad4331a5adc1a
Author(s) • • • •
Gladshtein, Vladimir
Zhao, Qiyuan
Ahrens, Willow
Amarasinghe, Saman
Sergey, Ilya
Date Issued
June 20, 2024
Journal
Proceedings of the ACM on Programming Languages
Publisher
Association for Computing Machinery
Citation
Gladshtein, Vladimir, Zhao, Qiyuan, Ahrens, Willow, Amarasinghe, Saman and Sergey, Ilya. 2024. "Mechanised Hypersafety Proofs about Structured Data." Proceedings of the ACM on Programming Languages, 8 (PLDI).
Version
Final published version
Abstract
Arrays are a fundamental abstraction to represent collections of data. It is often possible to exploit structural properties of the data stored in an array (e.g., repetition or sparsity) to develop a specialised representation optimised for space efficiency. Formally reasoning about correctness of manipulations with such structured data is challenging, as they are often composed of multiple loops with non-trivial invariants. In this work, we observe that specifications for structured data manipulations can be phrased as hypersafety properties, i.e., predicates that relate traces of k programs. To turn this observation into an effective verification methodology, we developed the Logic for Graceful Tensor Manipulation (LGTM), a new Hoare-style relational separation logic for specifying and verifying computations over structured data. The key enabling idea of LGTM is that of parametrised hypersafety specifications that allow the number k of the program components to depend on the program variables. We implemented LGTM as a foundational embedding into Coq, mechanising its rules, meta-theory, and the proof of soundness. Furthermore, we developed a library of domain-specific tactics that automate computer-aided hypersafety reasoning, resulting in pleasantly short proof scripts that enjoy a high degree of reuse. We argue for the effectiveness of relational reasoning about structured data in LGTM by specifying and mechanically proving correctness of 13 case studies including computations on compressed arrays and efficient operations over multiple kinds of sparse tensors.
MIT Department
Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science
Terms of Use
Creative Commons Attribution-ShareAlike
Persistent DSpace Link
DOI of Published Version
https://doi.org/10.1145/3656403