Skip to main content
QUICK REVIEW

[論文レビュー] Undecidability of a Theory of Strings, Linear Arithmetic over Length, and String-Number Conversion

Vijay Ganesh, Murphy Berzish|arXiv (Cornell University)|May 30, 2016
Web Application Security Vulnerabilities参考文献 26被引用数 10
ひとこと要約

この論文は、文字列方程式、文字列長に関する線形算術、および文字列から数値への変換を組み合わせた一階多様 sorted 量化子なし理論における充足可能性問題が、決定不能であることを証明している。著者らは、累乗算術への還元を用いてこれを確立し、文字列-数値変換述語が単語方程式と長さ関数の観点から表現可能であることを示した。これにより、これらの構成要素の間の深い関係が明らかになり、実用的な文字列ソルバーの本質的な複雑性が強調された。

ABSTRACT

In recent years there has been considerable interest in theories over string equations, length function, and string-number conversion predicate within the formal verification, software engineering, and security communities. SMT solvers for these theories, such as Z3str2, CVC4, and S3, are of immense practical value in exposing security vulnerabilities in string-intensive programs. Additionally, there are many open decidability and complexity-theoretic questions in the context of theories over strings that are of great interest to mathematicians. Motivated by the above-mentioned applications and open questions, we study a first-order, many-sorted, quantifier-free theory $T_{s,n}$ of string equations, linear arithmetic over string length, and string-number conversion predicate and prove three theorems. First, we prove that the satisfiability problem for the theory $T_{s,n}$ is undecidable via a reduction from a theory of linear arithmetic over natural numbers with power predicate, we call power arithmetic. Second, we show that the string-numeric conversion predicate is expressible in terms of the power predicate, string equations, and length function. This second theorem, in conjunction with the reduction we propose for the undecidability theorem, suggests that the power predicate is expressible in terms of word equations and length function if and only if the string-numeric conversion predicate is also expressible in the same fragment. Such results are very useful tools in comparing the expressive power of different theories, and for establishing decidability and complexity results. Third, we provide a consistent axiomatization $Γ$ for the functions and predicates of $T_{s,n}$. Additionally, we prove that the theory $T_Γ$ , obtained via logical closure of $Γ$, is not a complete theory.

研究の動機と目的

  • 文字列方程式、長さ関数、および文字列-数値変換を組み合わせた広く使われている文字列理論の決定可能性の状態を特定すること。
  • 文字列-数値変換述語が、単に単語方程式と長さ関数のみを用いて表現可能かどうかを調査すること。
  • 理論に含まれる関数および述語のための一貫性があり最小限の公理化を提供し、その完全性を評価すること。

提案手法

  • 決定不能であることが知られている累乗算術への還元を用いて、文字列理論の決定不能性を証明する。
  • 文字列連結、長さ制約、および文字列-数値変換を用いて累乗演算をシミュレートする形式的符号化の構築。
  • 論理的および代数的構成を用いて、文字列-数値変換述語が単語方程式と長さ関数の観点から定義可能であることを示す。
  • 理論の関数および述語のための一貫性のある公理化 Γ の定義。
  • Γ の論理的閉包を形成し、理論 TΓ を得た後、その完全性を分析する。
  • 単語方程式の充足可能性に関する既知の結果および Makanin のアルゴリズムを用いて、表現可能性および複雑性の結果を文脈づける。

実験結果

リサーチクエスチョン

  • RQ1文字列方程式、長さ関数、および文字列-数値変換を含む量化子なし理論 T_{s,n} における充足可能性問題は決定可能か?
  • RQ2文字列-数値変換述語は、単に単語方程式と長さ関数のみを用いて表現可能か?
  • RQ3T_{s,n} の関数および述語のための一貫性があり最小限の公理化が存在するか?
  • RQ4そのような公理化の論理的閉包は完全な理論か?
  • RQ5この断片における文字列-数値変換述語の表現可能性と累乗述語との関係は何か?

主な発見

  • 累乗算術への還元により、理論 T_{s,n} における充足可能性問題が決定不能であることが証明された。
  • 文字列-数値変換述語が単語方程式と長さ関数の観点から表現可能であることが示され、これらの構成要素の間の深い理論的関係が確立された。
  • この断片における文字列-数値変換述語の表現可能性は、累乗述語の表現可能性と同値である。
  • 理論 T_{s,n} の関数および述語のための一貫性があり最小限の公理化 Γ を構築可能である。
  • この公理化の論理的閉包 TΓ は完全な理論ではないため、理論の完全な意味論を形式化する上での本質的な制限が示された。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。