SMT formula automatic generation method, system and application

Through the SMT formula generation method based on tree structure and heuristic strategy, the problem of low solution efficiency when processing complex formulas is solved, and the automation of generating complex SMT formulas is realized, which improves the performance and application breadth of SMT solvers.

CN119940543APending Publication Date: 2025-05-06EAST CHINA NORMAL UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510015891.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-06
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The existing SMT solvers have low solution efficiency when processing complex formulas, which limits the breadth and depth of SMT applications, and lacks a systematic SMT formula generation method, which leads to inconvenience in generating complex formulas.

Method used

The SMT formula generation method based on tree structure and combined with heuristic strategies is adopted. By constructing operation nodes and logical relationships under different theoretical backgrounds, SMT formulas that meet the conventions are randomly generated, and the generated formulas are optimized through mutation strategies.

Benefits of technology

It realizes the generation and resolution complex SMT formulas with high difficulty, improves the performance of SMT solvers, provides a new way to further expand SMT applications, and simplifies the generation and analysis process of SMT formulas.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure HDA0005229906090000011
    Figure HDA0005229906090000011
  • Figure HDA0005229906090000012
    Figure HDA0005229906090000012
  • Figure HDA0005229906090000021
    Figure HDA0005229906090000021
Patent Text Reader

Abstract

The invention discloses an SMT (Surface Mount Technology) formula automatic generation method, which is based on a tree structure and is combined with a heuristic strategy, and comprises the following steps of: 1, configuring an SMT formula random generator, and setting initial complex SMT formula generation parameters; 2, randomly generating one or more initial complex SMT formulas as initial seeds based on the SMT formula generation parameters set in the step 1, and configuring variation times; 3, analyzing a model tree structure of the randomly selected initial seeds, performing mutation operation on the initial seeds through a mutation strategy, and determining whether to perform seed replacement according to solving time; and 4, repeating the operation until the configured variation times are reached, and generating all SMT formulas meeting the requirements. The invention further discloses a system for implementing the method, and the system has wide application value.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of formal verification and automated reasoning, and relates to a method, system and application for automatically generating SMT formulas. Background Art

[0002] The Boolean Satisfiability Problem (SAT) is a decision problem based on propositional logic, which aims to determine whether a given propositional logic formula has a variable assignment that makes it true. In contrast, Satisfiability Modulo Theories (SMT) are extended to determine the satisfiability of first-order logic formulas under various background theories. SMT introduces terms and quantifiers on the basis of propositional logic, and supports background theories such as real numbers, bit vectors, and arrays, enabling it to better abstract complex practical problems.

[0003] With the development of SMT judgment algorithms and solvers, SMT has been widely used in the field of computer science. It can be used for program defect detection and correctness verification, providing a reliable verification method for software systems and improving software quality. In addition, SMT can also be used for parameter optimization and model selection in machine learning, as well as in resource allocation, scheduling, and optimization.

[0004] However, despite the continuous optimization of algorithms and implementations of mainstream SMT solvers such as Z3, Yices2, and CVC5, they still face performance challenges in practical applications. In particular, when dealing with certain complex formulas, the solving efficiency is often limited, which becomes a bottleneck for further expanding the breadth and depth of SMT applications, and is also the starting point for improving the performance of SMT solvers.

[0005] Currently, there is no systematic method for generating SMT formulas, and it is inconvenient to generate complex SMT formulas in large quantities. Summary of the invention

[0006] In order to solve the deficiencies in the prior art, the purpose of the present invention is to provide an SMT formula generation method based on a tree structure and combined with a heuristic strategy, and to construct a corresponding automatic generation system. The generation system can generate complex SMT formulas with high difficulty in solving, providing a new research approach for improving the performance of SMT solvers. The present invention randomly generates SMT formulas that meet the agreement by constructing operation nodes and logical relationships under different theoretical backgrounds, and uses this as a seed, combined with a heuristic strategy, to achieve the automatic generation of complex formulas.

[0007] The purpose of the present invention can be achieved by the following technical solutions:

[0008] The present invention provides a method for automatically generating SMT formulas. The method is based on a tree structure and combined with a heuristic strategy, and comprises the following steps:

[0009] Step 1: Configure the SMT formula random generator and set the initial complex SMT formula generation parameters;

[0010] Step 2: Based on the SMT formula generation parameters set in step 1, one or more initial complex SMT formulas are randomly generated as initial seeds, and the number of mutations is configured;

[0011] Step 3: Analyze the model tree structure of the randomly selected initial seed, perform mutation operation on the initial seed through a mutation strategy, and decide whether to replace the seed according to the solution time;

[0012] Step 4: Repeat the above steps until the number of configuration mutations is reached and all SMT formulas that meet the requirements are generated.

[0013] In step 1, the configuration of the SMT formula random generator is based on the selected SMT formula theoretical background including data types such as floating point numbers, real numbers and bit vectors;

[0014] The SMT formula generation parameters include the initial number of SMT formulas generated and the solution time threshold of each SMT formula.

[0015] In step 2, the generation of the initial seed includes the following steps:

[0016] Step 2.1, define the seed nodes corresponding to the complex SMT formula; define the operands and operators according to the theoretical background, define the operation nodes and randomly initialize the number of operation nodes;

[0017] Step 2.2, maintain the operation node queue, use the operands in the operation node queue or the newly generated operands as the operands of the subsequently generated operation nodes; generate output results according to the operands and operator attributes, add the operation nodes and the newly generated operands to the operation queue; construct the logical relationship between all generated operation nodes, obtain the model tree of the SMT formula and save it;

[0018] Step 2.3: Use the SMT solver to analyze the current SMT formula and calculate the solution time. Repeat the operation to convert all initial complex SMT formulas into seed nodes and add them to the seed queue.

[0019] The seed node contains multiple attributes, including: file address and solution time of complex SMT formula;

[0020] The operands defined according to the theoretical background include: operand length, operand name, operand type, etc.; the operators included in the theoretical background are defined as enumeration classes, which are divided according to the output result type, the number of input operands, etc.;

[0021] The operation node includes: operator name, operator enumeration value, input operand, output result, etc.

[0022] If there is an element that meets the type requirement in the operation node queue, randomly select an element that meets the type requirement as the operand of the current operation node; or,

[0023] If the operation node queue is empty or there is no element that meets the type requirements, a new operand is generated according to the definition of the operand according to the corresponding requirements;

[0024] Generate the output result of the current operation node according to the operands and operator attributes in the operation node;

[0025] Add the current operation node and the newly generated operation number to the operation queue;

[0026] The logical relationship between all the generated operation nodes mentioned above is constructed by including AND, OR and NOT logical operations.

[0027] In step 3, the parsing of the model tree includes the following steps:

[0028] Step 3.1, read the corresponding SMT format file and configure the random generator under the corresponding theoretical background;

[0029] Step 3.2: Parse various types of constant declarations in the current theoretical context and create corresponding operands according to the constant declarations;

[0030] Step 3.3, parse the constraint definition part of the SMT formula, build the arithmetic relationship between operands and between operands and operators according to the constraints, and thus generate operation nodes;

[0031] Step 3.4, parse the constraint definition of the logical relationship part in the SMT formula, combine the constraint definition, stack structure and nested operation relationship, and generate the corresponding logical relationship node;

[0032] Step 3.5: Based on the logical relationship nodes, the model tree structure of the SMT formula is finally formed.

[0033] In step three, the mutation strategy includes:

[0034] 1) Based on the depth of the operation nodes in the model tree structure, the operation nodes used for mutation are selected according to the depth of the operation nodes;

[0035] 2) Based on the variable-clause graph, the operation nodes are regarded as variable nodes, and their complexity is counted according to the clause nodes involved. Finally, the nodes to be mutated are selected according to the complexity;

[0036] 3) Based on the variable graph, the operation nodes are regarded as variable nodes, the number of nodes that the current node can reach is calculated to count its complexity, and finally the nodes used for mutation are selected according to the complexity;

[0037] and / or,

[0038] Randomly use one of the mutation strategies to operate on the selected seed, which specifically includes the following steps:

[0039] Define the augmentation operands, which include properties such as depth, number of clauses involved, and number of reachable nodes;

[0040] Traverse the output results of operands and operation nodes and convert them into enhanced operands, which requires combining the model tree to calculate the depth, and combining the dictionary structure and set structure to calculate the number of clauses involved and the number of reachable nodes;

[0041] Select a mutation strategy and sort the operands according to their corresponding attribute values;

[0042] If the current SMT formula has a node that has no logical relationship with other operation nodes, then a random operation node with the same output result type is generated, where the operands come from the sorted node queue in the previous step;

[0043] If it does not exist, randomly generate two matching operation nodes with the same output result type, where the operation tree also comes from the sorted node queue;

[0044] Build the logical relationship between two operation nodes and add them to the SMT model tree.

[0045] In step 3, the solution time of the mutated SMT formula is calculated;

[0046] If the solution time is longer than the original SMT formula, the mutated SMT formula replaces the original SMT formula and is added to the seed queue;

[0047] If the solution time is less than the original SMT formula but exceeds the set solution time threshold of the SMT formula, the mutated SMT formula is directly added to the seed queue;

[0048] If the solution time is less than the set solution time threshold of the SMT formula, the mutated SMT formula will be directly discarded and the corresponding SMT format file will be deleted;

[0049] Increase the number of mutations of the original SMT formula by one.

[0050] The present invention also provides an automatic generation system for implementing the above generation method, wherein the automatic generation system includes one or more SMT formula random generators and an automated framework for constructing complex SMT formulas.

[0051] The present invention also provides the above-mentioned generation method, or the application of the above-mentioned generation system in the systematic generation of SMT formulas, improving the performance of SMT solvers, etc.

[0052] Compared with the existing technology, the present invention provides a method for automatically generating SMT formulas based on heuristic strategies and a corresponding system, which can realize the function of automatically generating complex SMT formulas, including the following beneficial effects:

[0053] The present invention simplifies and regulates the format of SMT formulas, reduces the difficulty of constructing and parsing SMT formulas, lays a foundation for implementing formulas under different theoretical backgrounds and provides scalability.

[0054] The present invention can provide a random generator for SMT formulas with various theoretical backgrounds, and currently supports theories such as bit vectors, floating point numbers and real numbers, thus bringing diversity and flexibility to the generation of SMT formulas.

[0055] The present invention adopts three mutation strategies to mutate the original SMT formula, which are implemented based on model tree, VCG and VG respectively, so that diversified mutations can be generated for the original formula, which brings unique complexity to each formula and improves the comprehensiveness of the mutation direction to a certain extent.

[0056] The present invention provides an automatic generation system for complex SMT formulas based on heuristic strategies, which realizes dynamic optimization by mutating complex SMT formulas and effectively expands the scale of complex SMT formulas. Finally, a highly automated complex SMT formula generation process is constructed, providing rich resources for solver testing. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without paying any creative work.

[0058] Figure 1 It is the overall flow chart of the present invention.

[0059] Figure 2 2 is a VCG diagram of an embodiment of the present invention.

[0060] Figure 3 It is a VG diagram of an embodiment of the present invention.

[0061] Figure 4 It is a VCG diagram after variation according to an embodiment of the present invention.

[0062] Figure 5 It is a VG diagram after variation of the embodiment of the present invention. DETAILED DESCRIPTION

[0063] The present invention is further described in detail with reference to the following specific examples and drawings. The process, conditions, experimental methods, etc. for implementing the present invention, except for the contents specifically mentioned below, are all common knowledge and common common sense in the art and are not particularly limited by the present invention.

[0064] The present invention provides an automatic generation method of SMT formulas based on a heuristic strategy and a corresponding system. The method configures a corresponding SMT formula random generator according to theoretical backgrounds such as floating point numbers, real numbers and bit vectors, and sets the initial formula quantity and solution time threshold; based on the configured generator, the automatic generation system of the present invention generates a batch of initial complex SMT formulas as seed nodes; then, through the set number of mutations, a formula is randomly selected from the seed queue, its model tree structure is parsed and mutated, and the mutated formula is screened according to the solution time, and if it meets the requirements, it is added to the seed queue, and if it does not meet the requirements, it is directly discarded. The present invention constructs a highly automated complex SMT formula generation process, continuously expands and optimizes the scale of complex SMT formulas, and provides rich resources for the testing of solvers.

[0065] The present invention provides a complex SMT formula automatic generation system based on heuristic strategy, which is used to assist in improving the performance of SMT solver. The generation system in the present invention includes SMT formula random generators under multiple theoretical backgrounds such as floating point numbers, real numbers and bit vectors, and an automated framework for building complex SMT formulas. In order to facilitate the system to generate and process formulas, the format of SMT formulas is simplified and standardized.

[0066] In the present invention, the theoretical background refers to the specific data types used when constructing and generating complex SMT formulas.

[0067] The simplification and normalization processing method is to decompose the SMT formula into operation nodes in the theoretical background and the logical relationship between these operation nodes, so as to simplify the formula generation process. Specifically, the method represents the operations in the theoretical background of floating point numbers, bit vectors and real numbers as operation nodes, such as bit vector addition, floating point multiplication and other operations. In addition, the method constructs the relationship between the operation nodes through logical operations.

[0068] The method also provides a method for automatically generating SMT formulas based on a heuristic strategy using the above system, the method comprising the following steps:

[0069] Step 1: Select the theoretical background of SMT formulas from data types such as floating point numbers, real numbers, and bit vectors, configure the corresponding SMT formula random generator, and set the number of initial complex SMT formulas to be generated and the solution time threshold for each SMT formula.

[0070] Step 2: Based on the initial configuration, use the corresponding SMT formula random generator to generate a batch of initial complex SMT formulas, namely the initial seeds, and configure the number of mutations.

[0071] Step 3: Each time a mutation occurs, a seed is randomly selected from the seed queue of the initial seed and its corresponding model tree structure is parsed. Then, one of the three mutation strategies is used to operate the selected seed, and the solution time of the mutated formula is used to decide whether to replace the original seed and add it to the seed queue.

[0072] Step 4: Repeat step 3 until the number of mutations is reached, and all the SMT formulas generated are complex SMT formulas that meet the requirements.

[0073] In step 2, a batch of initial complex SMT formulas are generated using the corresponding SMT formula random generator, which specifically includes the following steps:

[0074] Define seed nodes, i.e. nodes corresponding to complex SMT formulas, which include attributes such as file address and solution time of complex SMT formulas;

[0075] Define operands based on theoretical background, including properties such as operand length, operand name, and operand type;

[0076] Define the operators included in the theoretical background as enumeration classes and divide them according to the output result type, the number of input operands, etc.;

[0077] Define an operation node, which contains the operator name, operator enumeration value, input operands, and output results, including the association between output results;

[0078] Randomly initialize the number of operation nodes of the current formula;

[0079] Maintain an operation node queue, including all generated operation nodes and operands. The operands of the subsequently generated operation nodes can come from the operation node queue or can be newly generated operands.

[0080] If there is an element that meets the type requirement in the operation node queue, the generator will randomly select an element that meets the type requirement as the operand of the current operation node;

[0081] If the operation node queue is empty or there is no element that meets the type requirements, the generator will generate new operands according to the corresponding requirements based on the definition of the operands;

[0082] Generate the output result of the current operation node according to the operands and operator attributes in the operation node;

[0083] Add the current operation node and the newly generated operation number to the operation queue;

[0084] The logical relationship between all the generated operation nodes is constructed through logical operations such as AND, OR, and NOT, and finally the model tree of the SMT formula is realized and the model tree is saved as an SMT format file;

[0085] Choose an SMT solver as the formula solving tool, such as Z3, Yices, etc., and use the solver to analyze the current SMT formula and calculate its solution time;

[0086] The operation of generating formulas is repeated continuously until the set number of initial complex SMT formulas is reached, and finally all initial complex SMT formulas are converted into seed nodes and added to the seed queue.

[0087] The model tree structure corresponding to the analysis described in step 3 specifically includes the following steps:

[0088] Read the corresponding SMT format file and configure the random generator in the corresponding theoretical background;

[0089] Parse various types of constant declaration parts in the current theoretical context and create corresponding operands according to the constant declaration;

[0090] Parse the constraint definition part of the SMT formula, build the arithmetic relationship between operands and between operands and operators according to the constraints, and generate operation nodes;

[0091] Parse the constraint definition of the logical relationship part in the SMT formula, combine the constraint definition, stack structure and nested operation relationship, and generate the corresponding logical relationship node;

[0092] According to the logical relationship nodes, the model tree structure of the SMT formula is finally formed.

[0093] The three mutation strategies described in step 3 specifically include:

[0094] The first one is based on the depth of the operation node in the model tree structure, and the operation node used for mutation is selected according to the depth of the operation node;

[0095] The second method is to treat the operation node as a variable node, count its complexity according to the clause nodes involved, and finally select the node to be mutated according to the complexity;

[0096] The third method is to treat the operation node as a variable node, calculate the number of nodes that the current node can reach, and then count the complexity. Finally, the node to be mutated is selected according to the complexity.

[0097] The second and third mutation strategies are based on variable-clause graph (VCG) and variable graph (VG), respectively;

[0098] Among them, VCG is a graph structure representation method, which is mainly used for modeling dependencies in logical formulas and constraint solving. VCG abstracts the variables and clauses in the formula into nodes and connects them with edges to intuitively show the dependencies between variables and clauses. VG focuses on representing the direct relationship between variables in the formula, without including the intermediate clause nodes.

[0099] In step 3, one of the three mutation strategies is randomly used to operate on the selected seed, which specifically includes the following steps:

[0100] Define the augmentation operands, which include properties such as depth, number of clauses involved, and number of reachable nodes;

[0101] Traverse the output results of operands and operation nodes and convert them into enhanced operands, which requires combining the model tree to calculate the depth, and combining the dictionary structure and set structure to calculate the number of clauses involved and the number of reachable nodes;

[0102] Select a mutation strategy and sort the operands according to their corresponding attribute values;

[0103] If the current SMT formula has a node that has no logical relationship with other operation nodes, then a random operation node with the same output result type is generated, where the operands come from the sorted node queue in the previous step;

[0104] If it does not exist, randomly generate two matching operation nodes with the same output result type, where the operation tree also comes from the sorted node queue;

[0105] Build the logical relationship between two operation nodes and add them to the SMT model tree.

[0106] The solution time of the mutated formula described in step 3 determines whether to replace the original formula and add it to the seed queue. Specifically:

[0107] Use the SMT solver selected in step 2 to calculate the solution time of the mutated SMT formula;

[0108] If the solution time is greater than the original SMT formula, the mutated SMT formula replaces the original SMT formula and is added to the seed queue;

[0109] If the solution time is less than the original SMT formula but exceeds the set solution time threshold of the SMT formula, the mutated SMT formula is directly added to the seed queue; in a specific implementation, the solution time threshold can be set to 60s;

[0110] If the solution time is less than the set solution time threshold of the SMT formula, the mutated SMT formula will be directly discarded and the corresponding SMT format file will be deleted;

[0111] Increase the number of mutations of the original SMT formula by one.

[0112] During the specific implementation process, the mutated formula takes longer to solve than the original formula.

[0113] The method of the present invention is further illustrated by the following examples.

[0114] Example

[0115] The embodiment of the present invention provides a method for automatically generating SMT formulas based on a heuristic strategy and a corresponding automatic generation system. The overall process of the present invention is as follows: Figure 1 As shown, the specific steps are as follows:

[0116] (1) Select bit vector as the theoretical background of SMT formula and configure the corresponding SMT formula random generator. Then assume that the number of initial complex SMT formulas to be generated is 1 and the solution time threshold of each SMT formula is 0.

[0117] (2) Using the SMT formula random generator of the bit vector to generate an SMT formula with a solution time greater than 0 as an initial seed, the following steps are included:

[0118] (2.1) Initialize the operation node tree contained in the current SMT formula, which is set to 5 in this embodiment;

[0119] (2.2) Initialize the operation queue, which is currently empty;

[0120] (2.3) Randomly generate an operator and determine its type, that is, whether the current operator is a unary operator or a binary operator. If it is a unary operator, select or generate an operand; otherwise, select or generate two operands.

[0121] (2.4) Determine whether the operation queue contains non-Boolean operands or the result is a non-Boolean operation node. If it contains such elements, randomly select one or two as the operands of the current operator. Otherwise, randomly generate one or two new bit vector operands as the operands of the current operator and add the newly generated operands to the operation queue.

[0122] (2.5) Generate an output result for the current operator based on the type of the current operator and the attributes of its operands;

[0123] (2.6) Repeat (2.3)-(2.4) until the number of generated operation nodes reaches 5;

[0124] (2.7) Traverse the operation nodes in the operation queue, and continuously build as many relationships between the operation nodes as possible without duplication through the logical operation "=";

[0125] (2.8) The logical relations in (2.7) are combined through logical operations such as and, or, and not, thereby realizing the overall encapsulation of the logical relations;

[0126] (29.) Select the Z3 solver to solve the current formula, record its solution time, and finally put the formula into the seed queue.

[0127] In an embodiment of the present invention, the generated SMT formula mainly includes 7 bit vector operands, including bv_0 to bv_6 and 2 Boolean variables, z_0 and z_1, which are used to construct complex logical relationships. Specifically, bit vectors bv_2 and bv_3 are obtained by multiplying bv_1 and bv_0. Next, bv_4 is obtained by shifting bv_1 left by bv_2 bits. Then, bv_5 is generated by performing a bitwise OR operation on bv_3 and bv_4. After that, bv_4 and bv_2 are subjected to a bitwise XOR operation to obtain bv_6.

[0128] On this basis, Boolean variables z_0 and z_1 are used to judge and record the equality of specific bit vectors. z_0 indicates whether bv_5 and bv_4 are equal, while z_1 indicates the equality relationship between bv_6 and bv_3. Finally, the results of z_0 and z_1 are combined through logical AND operations to form the overall constraint condition. The corresponding VCG graph and VG graph are shown in Figure 2 and Figure 3 shown.

[0129] Figure 2 or Figure 3 In the figure, the blue circle represents the variable node, the red circle represents the clause node, the connecting line represents the association relationship between the nodes, Variable represents the variable node, and Clause represents the clause node.

[0130] (3) The configuration mutation times is 1, and the maximum mutation times for each seed is 1.

[0131] (4) According to the seed pair obtained in (2), one of the SMT formulas is randomly selected and its corresponding model tree structure is parsed. Then, the SMT formula is mutated according to the VCG-based strategy, and the solution time of the mutated SMT formula is used to determine whether the formula should be added to the seed queue.

[0132] (4.1) Since there is only one SMT formula in the seed queue, random selection will only select the SMT formula generated in (2) as the seed;

[0133] (4.2) Parse the SMT formula selected in (4.1) and convert its operands and the output results of operation nodes into enhanced operands, and calculate the depth of each operand, the number of clauses involved, and the number of reachable nodes;

[0134] (4.3) Since there are nodes in the SMT formula selected in (4.1) that do not establish logical relationships with other nodes, a random operation node with the same output result type as the current operation node is generated. The specific steps are as follows:

[0135] (4.3.1) Randomly generate an operator of the same type as the output result of the above node, and determine whether the operator is a unary operator or a binary operator. If it is a unary operator, select or generate an operand; otherwise, select or generate two operands;

[0136] (4.3.2) Sort the enhanced operands from largest to smallest according to the number of clauses involved in each operand, and select the first one or two as the operands of the current operator. If the number of operands is insufficient, generate new operands;

[0137] (4.3.3) generating an output result for the current operator according to the type of the above operator and the properties of its operands;

[0138] (4.4) Use the logical operation "=" to construct the logical relationship between the above two operation nodes, and add the above logical relationship to the overall logical relationship of the original SMT formula through one of the three logical operators of and, or, and not;

[0139] (4.5) The solution time is calculated by the Z3 solver. The solution time after mutation is slightly longer than that of the original formula. Therefore, the formula is added to the seed queue and removed from the original formula.

[0140] In the embodiment of the present invention, the mutated SMT formula mainly adds new variables, operation nodes and logical relationships compared to the original SMT formula, so that the overall structure and complexity of the formula are significantly improved. A bit vector variable bv_7 is added and defined as the product of bv_5 and bv_6. A Boolean variable z_2 is added, and z_2 is used to indicate the equality of bv_2 and bv_7. In addition, the newly added logical relationship is added to the logical relationship of the original SMT formula through the logical operation and. The corresponding VCG graph and VG graph are shown in the figure below. Figure 4 and Figure 5 shown.

[0141] Figure 4 or Figure 5 In the figure, the blue circle represents the variable node, the red circle represents the clause node, the connecting line represents the association relationship between the nodes, Variable represents the variable node, and Clause represents the clause node.

[0142] The protection content of the present invention is not limited to the above embodiments. Without departing from the spirit and scope of the present invention, changes and advantages that can be thought of by those skilled in the art are included in the present invention and are protected by the attached claims.

Claims

1. A method for automatically generating SMT formulas, characterized in that: The generation method is based on a tree structure and combined with a heuristic strategy, and includes the following steps: Step 1: Configure the SMT formula random generator and set the initial complex SMT formula generation parameters; Step 2: Based on the SMT formula generation parameters set in step 1, one or more initial complex SMT formulas are randomly generated as initial seeds, and the number of mutations is configured; Step 3: Analyze the model tree structure of the randomly selected initial seed, perform mutation operation on the initial seed through a mutation strategy, and decide whether to replace the seed according to the solution time; Step 4: Repeat the above steps until the number of configuration mutations is reached and all SMT formulas that meet the requirements are generated.

2. The generation method according to claim 1, characterized in that: In step 1, the configuration of the SMT formula random generator is based on the theoretical background of the SMT formula of selected data types including floating point numbers, real numbers and bit vectors; The SMT formula generation parameters include the initial number of SMT formulas generated and the solution time threshold of each SMT formula.

3. The generation method according to claim 1, characterized in that: In step 2, the generation of the initial seed includes the following steps: Step 2.1, define the seed nodes corresponding to the complex SMT formula; define the operands and operators according to the theoretical background, define the operation nodes and randomly initialize the number of operation nodes; Step 2.2, maintain the operation node queue, use the operands in the operation node queue or the newly generated operands as the operands of the subsequently generated operation nodes; generate output results according to the operands and operator attributes, add the operation nodes and the newly generated operands to the operation queue; construct the logical relationship between all generated operation nodes, obtain the model tree of the SMT formula and save it; Step 2.3: Use the SMT solver to analyze the current SMT formula and calculate the solution time. Repeat the operation to convert all initial complex SMT formulas into seed nodes and add them to the seed queue.

4. The generation method according to claim 3, characterized in that: The seed node contains multiple attributes, including: the file address and solution time of the complex SMT formula; The operands defined according to the theoretical background include: operand length, operand name, and operand type; the operators included in the theoretical background are defined as enumeration classes, and divided according to the output result type and the number of input operands; The operation node includes: operator name, operator enumeration value, input operand, and output result.

5. The generation method according to claim 3, characterized in that: If there is an element that meets the type requirement in the operation node queue, randomly select an element that meets the type requirement as the operand of the current operation node; or, If the operation node queue is empty or there is no element that meets the type requirements, a new operand is generated according to the definition of the operand according to the corresponding requirements; and / or, Generate the output result of the current operation node according to the operands and operator attributes in the operation node; Add the current operation node and the newly generated operation number to the operation queue; The logical relationship between all the generated operation nodes mentioned above is constructed by including AND, OR and NOT logical operations.

6. The generation method according to claim 1, characterized in that: In step 3, the parsing of the model tree includes the following steps: Step 3.1, read the corresponding SMT format file and configure the random generator under the corresponding theoretical background; Step 3.2: Parse various types of constant declarations in the current theoretical context and create corresponding operands according to the constant declarations; Step 3.3, parse the constraint definition part of the SMT formula, build the arithmetic relationship between operands and between operands and operators according to the constraints, and thus generate operation nodes; Step 3.4, parse the constraint definition of the logical relationship part in the SMT formula, combine the constraint definition, stack structure and nested operation relationship, and generate the corresponding logical relationship node; Step 3.5: Based on the logical relationship nodes, the model tree structure of the SMT formula is finally formed.

7. The generation method according to claim 1, characterized in that: In step three, the mutation strategy includes: Based on the depth of the operation node in the model tree structure, the operation node used for mutation is selected according to the depth of the operation node; or, Based on the variable-clause graph, the operation nodes are regarded as variable nodes, and their complexity is counted according to the clause nodes involved. Finally, the nodes used for mutation are selected according to the complexity; or Based on the variable graph, the operation nodes are regarded as variable nodes, and the number of nodes that the current node can reach is calculated to count its complexity. Finally, the nodes used for mutation are selected according to the complexity. and / or, Randomly use one of the three mutation strategies to operate on the selected seeds, which includes the following steps: Define the augmentation operands, which include the depth, number of clauses involved, and number of reachable nodes attributes; Traverse the output results of operands and operation nodes and convert them into enhanced operands, which requires combining the model tree to calculate the depth, and combining the dictionary structure and set structure to calculate the number of clauses involved and the number of reachable nodes; Select a mutation strategy and sort the operands according to their corresponding attribute values; If the current SMT formula has a node that has no logical relationship with other operation nodes, then a random operation node with the same output result type is generated, where the operands come from the sorted node queue in the previous step; If it does not exist, randomly generate two matching operation nodes with the same output result type, where the operation tree also comes from the sorted node queue; Build the logical relationship between two operation nodes and add them to the SMT model tree.

8. The generation method according to claim 1, characterized in that: In step 3, the solution time of the mutated SMT formula is calculated; If the solution time is longer than the original SMT formula, the mutated SMT formula replaces the original SMT formula and is added to the seed queue; If the solution time is less than the original SMT formula but exceeds the set solution time threshold of the SMT formula, the mutated SMT formula is directly added to the seed queue; If the solution time is less than the set solution time threshold of the SMT formula, the mutated SMT formula will be directly discarded and the corresponding SMT format file will be deleted; Increase the number of mutations of the original SMT formula by one.

9. An automatic generation system for implementing the generation method according to any one of claims 1 to 8, characterized in that: The automatic generation system includes one or more SMT formula random generators and an automatic framework for building complex SMT formulas.

10. Application of the generation method as described in any one of claims 1 to 8, or the automatic generation system as described in claim 9 in the systematic generation of SMT formulas and the improvement of SMT solver performance.