Skip to main content
QUICK REVIEW

[论文解读] Undecidability of a Theory of Strings, Linear Arithmetic over Length, and String-Number Conversion

Vijay Ganesh, Murphy Berzish|arXiv (Cornell University)|May 30, 2016
Web Application Security Vulnerabilities参考文献 26被引用 10
一句话总结

本文证明了将字符串方程、字符串长度上的线性算术以及字符串到数字的转换相结合的、一阶、多 sorted、无量词的理论的可满足性问题是不可判定的。作者通过从幂算术进行约化来建立这一结论,并表明字符串-数字转换谓词可用字词方程和长度函数来表达,揭示了这些构造之间的深层联系,并突显了实际字符串求解器的固有复杂性。

ABSTRACT

In recent years there has been considerable interest in theories over string equations, length function, and string-number conversion predicate within the formal verification, software engineering, and security communities. SMT solvers for these theories, such as Z3str2, CVC4, and S3, are of immense practical value in exposing security vulnerabilities in string-intensive programs. Additionally, there are many open decidability and complexity-theoretic questions in the context of theories over strings that are of great interest to mathematicians. Motivated by the above-mentioned applications and open questions, we study a first-order, many-sorted, quantifier-free theory $T_{s,n}$ of string equations, linear arithmetic over string length, and string-number conversion predicate and prove three theorems. First, we prove that the satisfiability problem for the theory $T_{s,n}$ is undecidable via a reduction from a theory of linear arithmetic over natural numbers with power predicate, we call power arithmetic. Second, we show that the string-numeric conversion predicate is expressible in terms of the power predicate, string equations, and length function. This second theorem, in conjunction with the reduction we propose for the undecidability theorem, suggests that the power predicate is expressible in terms of word equations and length function if and only if the string-numeric conversion predicate is also expressible in the same fragment. Such results are very useful tools in comparing the expressive power of different theories, and for establishing decidability and complexity results. Third, we provide a consistent axiomatization $Γ$ for the functions and predicates of $T_{s,n}$. Additionally, we prove that the theory $T_Γ$ , obtained via logical closure of $Γ$, is not a complete theory.

研究动机与目标

  • 确定一种广泛使用的字符串理论的可判定性状态,该理论结合了字词方程、长度函数和字符串-数字转换。
  • 研究字符串-数值转换谓词是否可仅用字词方程和长度函数来表达。
  • 为该理论中的函数和谓词提供一个一致且最小的公理化体系,并评估其完备性。

提出的方法

  • 通过从已知的不可判定理论——幂算术——进行约化,以证明字符串理论的不可判定性。
  • 构建一种形式编码,利用字符串连接、长度约束和字符串-数字转换来模拟幂运算。
  • 证明字符串-数值转换谓词可基于字词方程和长度函数来定义,使用逻辑与代数构造。
  • 为理论中的函数和谓词定义一个一致的公理化体系 Γ。
  • 对 Γ 进行逻辑闭包以形成理论 TΓ,随后分析其完备性。
  • 利用已知的字词方程可满足性结果和 Makanin 算法,来定位可表达性与复杂性发现的上下文背景。

实验结果

研究问题

  • RQ1无量词理论 T_{s,n}(包含字符串方程、长度函数和字符串-数字转换)的可满足性问题是否可判定?
  • RQ2字符串-数值转换谓词是否可仅用字词方程和长度函数来表达?
  • RQ3是否存在一个一致且最小的公理化体系,用于 T_{s,n} 中的函数和谓词?
  • RQ4此类公理化体系的逻辑闭包是否完备?
  • RQ5在该理论片段中,字符串-数值转换谓词的可表达性与幂谓词之间存在何种关系?

主要发现

  • 通过从幂算术的约化,证明了理论 T_{s,n} 的可满足性问题是不可判定的。
  • 字符串-数值转换谓词可基于字词方程和长度函数来表达,建立了这些构造之间的深层理论联系。
  • 在此理论片段中,字符串-数值转换谓词的可表达性等价于幂谓词的可表达性。
  • 可以为 T_{s,n} 的函数和谓词构造一个一致且最小的公理化体系 Γ。
  • 该公理化体系的逻辑闭包 TΓ 不是一个完备理论,表明在形式化该理论完整语义方面存在固有的局限性。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。