Method and system for generating code delta consistency check based on bidirectional slicing model

CN122816679APending Publication Date: 2026-09-25SHANGHAI FORMAL TECH INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611316361.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-08-28
Publication Date
2026-09-25

AI Technical Summary

Technical Problem

随着系统规模扩大、版本迭代频繁,现有主流校验方案存在根本性缺陷,难以兼顾校验精度、迭代效率与合规可审查要求

Benefits of technology

其一,本发明新增依赖边变更集记录迭代引发的依赖边新增、删除、权重修改操作,每次局部变更仅比对变更节点一跳邻域内依赖边,增量更新依赖边集合,针对大规模架构重构场景自动切换全量重建模式,既保证常规迭代依赖关系实时精准更新,又规避极端场景增量比对的缺陷。区别于现有技术固定不变的静态依赖结构,本方案始终基于最新依赖图开展影响传播,从底层根源减少一致性校验的漏判、误判,提升高安全软件校验可信度。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122816679A_ABST
    Figure CN122816679A_ABST
Patent Text Reader

Abstract

The application relates to the technical field of industrial software research and development, and particularly discloses a model generation code increment consistency verification method and system based on bidirectional slices, which integrates multiple types of configurations to build a bidirectional slice graph containing multiple types of nodes and associated edges, obtains a change object set through dependency extraction and version comparison, realizes incremental atomic update of a dependency edge through a dependency edge change set, obtains an affected slice set through bidirectional slices with a special attenuation factor according to the updated dependency edge, outputs a verification conclusion in combination with two-level threshold values based on five-dimensional weighted evaluation indexes after hierarchical verification, can dynamically and synchronously generate changes in a dependency structure, accurately locks a minimum verification range through bidirectional tracing, supports reuse of historical verification results, avoids resource loss in full-amount verification, realizes auditability of a verification process through quantitative determination standards, and is suitable for high-safety control system model code consistency increment verification scenes such as aviation, rail transit and nuclear energy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of industrial software development technology, and in particular to a method and system for incremental consistency verification of model-generated code based on bidirectional slicing. Background Technology

[0002] High-safety software in sectors such as aviation, rail transit, and nuclear energy generally employs a model-driven development approach, relying on visual models to automatically generate embedded code, coupled with a rigorous consistency verification process. However, as systems expand in scale and version iterations become more frequent, existing mainstream verification schemes have fundamental flaws, making it difficult to balance verification accuracy, iteration efficiency, and compliance / audit requirements.

[0003] While existing full regression verification schemes yield reliable results, local modifications still require a complete retest of the entire system, resulting in significant computational overhead and long iteration cycles. Static mapping matrices rely on manual judgment of the impact range, and the mapping relationships gradually become invalid with iterations. They also suffer from low automation and are prone to missed or false positives. Simple code syntax tree comparisons can only identify changes in the code text and cannot trace back to the model logic, resulting in verification blind spots. Simple incremental synchronization tools rely on static dependency relationships for analysis, ignoring the dynamic changes in dependency structures during iterations, which can easily lead to missed or false positives in verification. Furthermore, they require manual annotation and marking, resulting in high redundancy.

[0004] The core common problem with existing technologies is that dependencies are stored statically and are not updated synchronously with version iterations, resulting in distorted baselines for impact range analysis. Furthermore, they only support one-way analysis and lack bidirectional traceability between models and code, making it impossible to accurately pinpoint the minimum affected scope. This leads to either full verification resulting in wasted resources or static manual analysis causing insufficient accuracy. In addition, existing technologies lack unified quantitative delivery judgment standards, and verification and release rely on subjective human experience, lacking reproducible and auditable objective evaluation criteria, making it difficult to meet the stringent compliance requirements of high-security industries.

[0005] Therefore, there is an urgent need for a method and system for incremental consistency verification of generated code based on bidirectional slicing to solve the above problems. Summary of the Invention

[0006] The purpose of this invention is to provide a method for incremental consistency verification of model-generated code based on bidirectional slicing, comprising the following steps: Retrieve the model configuration, interface configuration, constraint configuration, and validation rules associated with the object to be processed; Based on the model configuration, interface configuration, constraint configuration, and verification rules, a unified processing object is constructed. The unified processing object includes a bidirectional slice graph, a set of dependency edges, a set of changed objects, and a set of affected slices. The bidirectional slice graph is a directed graph. The nodes of the directed graph include model nodes, code nodes, interface nodes, and test nodes. The edges of the directed graph include model internal dependency edges, code internal dependency edges, model-code mapping edges, code-model tracing edges, and interface-test association edges. The unified processing object is subjected to structured decomposition, boundary extraction, and dependency extraction to obtain an initial bidirectional slice graph and an initial set of dependency edges; Based on the initial bidirectional slice graph and the initial dependency edge set, a version comparison is performed on the object to be processed to identify the changed objects and obtain the set of changed objects. Based on the set of changed objects, perform incremental updates on the initial set of dependent edges to obtain the updated set of dependent edges; Based on the updated set of dependent edges and the set of changed objects, perform bidirectional slicing to obtain the set of affected slices; Based on the affected slice set, constraint filtering, differential verification, and conflict detection are performed to obtain an incremental consistency report and mismatch location results; Based on the incremental consistency report and the mismatch location results, an evaluation index is calculated, and based on the comparison results of the evaluation index with the preset threshold, a correction suggestion or reinforcement suggestion is output. Output the list of affected slices, the incremental consistency report, the mismatch location results, and the correction or reinforcement suggestions.

[0007] Furthermore, this invention also discloses a model generation code incremental consistency verification system based on bidirectional slicing, comprising: The acquisition module is used to acquire the model configuration, interface configuration, constraint configuration, and validation rules associated with the object to be processed. The building module is used to construct a unified processing object based on the model configuration, the interface configuration, the constraint configuration, and the verification rules. The unified processing object includes a bidirectional slice graph, a set of dependency edges, a set of changed objects, and a set of affected slices. The bidirectional slice graph is a directed graph. The nodes of the directed graph include model nodes, code nodes, interface nodes, and test nodes. The edges of the directed graph include model internal dependency edges, code internal dependency edges, model-code mapping edges, code-model tracing edges, and interface-test association edges. The processing module is used to perform structured decomposition, boundary extraction, and dependency extraction on the unified processing object to obtain an initial bidirectional slice graph and an initial set of dependency edges. The comparison module is used to perform version comparison on the object to be processed based on the initial bidirectional slice graph and the initial dependency edge set, identify the objects that have changed, and obtain the set of changed objects; The update module is used to perform incremental updates on the initial dependency edge set based on the changed object set, so as to obtain the updated dependency edge set. The first execution module is used to perform bidirectional slicing based on the updated set of dependency edges and the set of changed objects to obtain the set of affected slices; The second execution module is used to perform constraint filtering, differential verification and conflict detection based on the affected slice set, and obtain incremental consistency report and mismatch location results; The calculation module is used to calculate the evaluation index based on the incremental consistency report and the mismatch location result, and output correction suggestions or reinforcement suggestions based on the comparison result of the evaluation index and the preset threshold. The output module is used to output the list of affected slices, the incremental consistency report, the mismatch location results, and the correction or reinforcement suggestions.

[0008] The beneficial effects of this application are as follows: Firstly, this invention adds a dependency edge change set to record the addition, deletion, and weight modification operations of dependency edges triggered by iteration. Each local change only compares dependency edges within the one-hop neighborhood of the changed node, incrementally updating the dependency edge set. For large-scale architecture refactoring scenarios, it automatically switches to a full reconstruction mode, ensuring both real-time and accurate updates of dependency relationships in regular iterations and avoiding the shortcomings of incremental comparisons in extreme scenarios. Unlike the fixed static dependency structure of existing technologies, this solution always conducts impact propagation based on the latest dependency graph, reducing missed and false positives in consistency checks from the root cause and improving the reliability of high-security software verification.

[0009] Secondly, this invention supports bidirectional slice propagation from model to code and from code to model. It is equipped with customized decay factors and propagation termination thresholds that adapt to four different types of dependency edges, quantifying the degree of impact of changes on each node. It only locks the local slice subsets of real associations for verification, without having to perform full regression verification on the entire system module. In scenarios with small local changes, historical valid verification results can be reused, significantly shortening the iteration verification time. It balances verification completeness and iteration efficiency, solving the defects of traditional full regression in terms of resource waste and excessive cycle.

[0010] Third, this invention constructs a weighted evaluation formula based on five dimensions: slice recognition accuracy, recall completeness, verification coverage completeness, incremental processing efficiency, and historical result reuse. Combined with a two-level threshold division and a three-level delivery judgment standard, it transforms the traditional subjective release judgment based on human experience into an objective quantitative standard that can be automatically calculated and reproduced. The entire verification process automatically retains processing records such as version fingerprints, change records, timestamps, and responsible person identification, and outputs standardized verification reports and mismatch location lists, which are fully adapted to the requirements of high-safety industries such as avionics and nuclear energy. Attached Figure Description

[0011] Figure 1 This is a schematic diagram of a method flow proposed in an embodiment of this application.

[0012] Figure 2 This is a diagram of the overall architecture for bidirectional slicing and incremental consistency verification proposed in an embodiment of the present invention. Detailed Implementation

[0013] The following section, in conjunction with the accompanying drawings, system module architecture, and a high-security industrial software R&D engineering scenario, provides a more complete and detailed description of the incremental consistency verification method for model generation code based on bidirectional slicing, as described in this invention. The implementation of this invention is not limited to the specific engineering examples described below. Any equivalent substitutions or adaptive adjustments made to parameters, graph structures, and module logic based on the technical ideas of this invention fall within the protection scope of this invention.

[0014] The realization of the purpose, functional features, and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings, such as... Figure 1 As shown, this application provides a method for incremental consistency verification of model-generated code based on bidirectional slicing, including the following steps: S1. Obtain the model configuration, interface configuration, constraint configuration, and validation rules associated with the object to be processed; As described in step S1 above, the input sources for the execution flow of this invention are divided into four types of structured configuration files, all of which are retrieved from the version control system to obtain complete data for the current iteration version, wherein: The model configuration includes the high-level model file corresponding to the object to be processed, the UUID mapping table of model elements, the description of the data flow / control flow inside the model, the definition of the model parameter thresholds, and the configuration parameters of the model generation code; if it is a flight control / avionics model, the model configuration also includes hardware port mapping and periodic scheduling timing configuration. The interface configuration includes the system internal and external interaction interface ID, interface parameter data type, parameter value range, interface input and output dependency relationship, cross-module interface constraints, and multi-subsystem interaction timing rules; The constraint configuration includes functional equivalence constraints, data type matching constraints, periodic scheduling constraints, security threshold constraints, interface timing constraints, resource exclusivity constraints, and boundary exception handling constraints. All constraints are bound to a unique constraint ID for subsequent verification of completeness statistics. The verification rules include the mapping between test cases and model / code elements, test coverage judgment rules, consistency mismatch grading standards, delivery release threshold rules, and historical verification result reuse judgment rules.

[0015] The system reads four types of configurations in batches through the file parsing interface, performs data format verification and integrity verification, removes configuration fragments with damaged or missing fields, outputs a standardized structured dataset, and transmits it to the subsequent unified processing object construction stage.

[0016] S2. Construct a unified processing object based on the model configuration, the interface configuration, the constraint configuration, and the verification rules; The unified processing object is the core data carrier of this invention, which fully includes four basic data structures: bidirectional slice graph, dependent edge set, changing object set, and affected slice set. The bidirectional slice graph is a directed graph and is the underlying carrier for storing, traversing, and updating dependencies throughout the entire process. The basic classification architecture of directed graph nodes and edges is a conventional architecture in the field of slice analysis, which will not be elaborated here.

[0017] S21. The mathematical definition of the directed graph is G=(V, E), and the node set V and edge set E are initialized step by step. The node set V is divided into four types of nodes, all assigned a globally unique UUID: model nodes correspond to every model submodule, parameter, and logical unit within the model configuration; code nodes correspond to every function, global variable, structure, and conditional branch code block automatically generated by the model; interface nodes correspond to every input / output interface and parameter port within the interface configuration; and test nodes correspond to every automated test case and test assertion within the verification rules. The node classification method follows the conventional classification methods used for model code consistency verification.

[0018] The edge set E contains five types of directed edges, each storing a four-tuple structure. This storage structure is a conventional graph data storage structure. This invention uses a dependency strength weight parameter in the range of 0-1 to differentiate the degree of dependency tightness: intra-model dependency edges represent the data flow and control flow associations between model nodes; intra-code dependency edges represent the function call and variable read / write dependencies between code nodes; model-code mapping edges are forward mappings, pointing from model nodes to the corresponding generated code nodes; code-model tracing edges are reverse tracings, pointing from code nodes to the source model nodes; and interface-test association edges represent the association between interface nodes and test nodes that cover the interface.

[0019] The construction of the model-code mapping edge is divided into two priority strategies: first, the original mapping logs output by the code generator are read first to establish the mapping relationship; when there are no logs, the name similarity and structural similarity heuristic matching are used to establish the mapping. This dual matching strategy is an optimized design of this invention, which is different from the conventional single matching technology.

[0020] S22. Initialize the remaining three types of data structures; Dependency edge set: The index structure is built based on the edge data of the bidirectional slice graph. It is configured with forward and reverse bidirectional indexes to support fast addition, deletion, modification and query. The bidirectional index is a common technique for graph retrieval, which will not be elaborated here. Change object set: Initially an empty set, with three types of change marker fields (add, modify, delete) to store elements changed in version iterations; Affected slice set: Initially an empty set, with preset storage fields such as node set, propagation path, impact score, and association constraints.

[0021] After completing the initialization of all data structures, the four types of data structures are encapsulated into a unified processing object, a global version fingerprint and timestamp are added, and then the object is passed down to the dependency extraction module.

[0022] S3. The dependency extraction module performs structured decomposition, boundary extraction, and dependency extraction on the unified processing object to obtain an initial bidirectional slice graph and an initial set of dependency edges. The dependency extraction module is the core unit of the pre-parsing in this invention, performing structured decomposition, boundary extraction, and basic dependency identification. The technical improvement of this invention lies in the unified extraction of dependencies across four dimensions: model, code, interface, and test, breaking the limitations of conventional single-dimensional parsing and fully executing a three-layer progressive processing logic. S31. Structured decomposition: Traverse all nodes within the unified processing object, group them according to module level, scheduling cycle, and security level, and remove invalid or isolated nodes; S32. Boundary Extraction: Identify the interaction boundaries between the system and its internal and external environments, as well as the functional boundaries of modules. Mark boundary nodes and attach unique labels. The priority verification logic for boundary nodes is a standard verification strategy for high-security systems. S33. Dependency Extraction: Parse model data flow and control flow dependencies, code AST syntax tree dependencies, match the association between model and code, interface and test, filter redundant and duplicate edges, and complete the construction of the initial graph and dependency edge set.

[0023] S4. Based on the initial bidirectional slice graph and the initial dependency edge set, perform version comparison on the object to be processed, identify the objects that have changed, and obtain the set of changed objects; This step identifies changed objects based on version hash comparison. Hash value comparison and node addition / deletion / modification determination logic are common methods for software version iteration. Adaptation and optimization are completed to fit the four types of node systems of this invention. The complete logic is as follows: S41. Read the bidirectional slice map of the previous iteration history and the initial bidirectional slice map of the current iteration to form a version comparison data source; S42. Perform hash digest comparison on each node with the same UUID to determine the node change status; S43. Unify the three types of nodes: new, deleted, and modified, add change information, timestamp, and responsibility identifier, and encapsulate them into a set of changed objects to achieve accurate positioning of changed objects.

[0024] S5. Based on the set of changed objects, perform incremental update on the initial set of dependent edges to obtain the updated set of dependent edges; This step differs from existing technologies in that it avoids the conventional approach of full reconstruction and no update of the static dependency graph. The one-hop neighbor local range comparison mechanism, the multi-type dependency edge change record system, the atomic transaction rollback mechanism, and the structural reconstruction degradation strategy are all targeted designs of this invention, and are divided into three main sub-steps: S51, the step of performing incremental updates on the initial dependency edge set based on the changed object set to obtain the updated dependency edge set includes: Starting with each object in the set of changed objects, obtain the one-hop neighbor node of the object in the initial bidirectional slice graph to obtain the local node range; For each edge within the local node range, perform a difference analysis before and after the change to obtain the dependent edge change set; The dependency edge change set is applied to the initial dependency edge set to obtain the updated dependency edge set.

[0025] Starting with each changed node in the set of changed objects, all directly connected one-hop neighbor nodes in the initial bidirectional slice graph are retrieved, and the changed node and its neighbor nodes are merged to form a local comparison range. This local neighborhood-limited comparison logic abandons the inefficient method of conventional full graph traversal, accurately narrows the change comparison range, and significantly reduces computational overhead.

[0026] S52, the step of performing a difference analysis before and after the change on each edge within the local node range to obtain the dependent edge change set includes: Obtain the first version bidirectional slice image of the object to be processed before the change and the second version bidirectional slice image after the change; For each edge within the local node range, compare the existence state and weight value of the edge in the first version of the bidirectional slice graph and the second version of the bidirectional slice graph; When the edge exists in the first version of the bidirectional slice graph but does not exist in the second version of the bidirectional slice graph, the edge is recorded as a deletion operation; When the edge does not exist in the first version of the bidirectional slice graph but exists in the second version of the bidirectional slice graph, the edge is recorded as an addition operation; When the edge exists in both the first version of the bidirectional slice graph and the second version of the bidirectional slice graph, but the change in the weight value exceeds the preset weight change threshold, the edge is recorded as a weight modification operation. By summing all deletion, addition, and weight modification operations, the dependency edge change set is obtained. When the number of nodes in the changed object set exceeds a preset percentage threshold of the total number of nodes in the system, or when the change type of the object to be processed is structural reconstruction, switch to full dependency edge reconstruction mode.

[0027] In this step, the edge existence state comparison is a conventional technique, used only to facilitate understanding of the technical solution. The weight change threshold, node proportion downgrade threshold, and structured reconstruction judgment rules are all customized parameters of this invention. The specific design method is as follows: S521. Read the bidirectional slice graphs of the two versions before and after the change, and compare the differences only for the edges within the local node range to avoid redundant calculations by traversing the entire graph. S522. Set a threshold for judging weight changes. When the difference in weight changes of the same edge exceeds 0.05, it is judged as a substantial weight modification. This threshold is a parameter that has been measured and calibrated by a large number of high-security projects. S523. Establish three types of exclusive change record rules: simultaneous deletion, simultaneous addition, and simultaneous weight modification, and structurally summarize to form a dependent change set. This multi-dimensional change record system is a technical design that is not available in existing technologies. S524. Set up a dual degradation mechanism: preset a threshold of 30% of the total number of system nodes, and adapt to structural reconstruction scenarios. If either condition is met, the incremental comparison will be abandoned and the full dependency edge reconstruction mode will be switched. This dual fault tolerance degradation strategy is a unique improvement of the present invention to address the defects of the existing technology.

[0028] S53, the step of applying the dependency edge change set to the initial dependency edge set to obtain the updated dependency edge set includes: Obtain the edge identifier corresponding to the deletion operation in the dependent edge change set, and remove the edge corresponding to the edge identifier from the initial dependent edge set; Obtain the newly added edge corresponding to the addition operation in the dependent edge change set, and add the newly added edge to the initial dependent edge set; Obtain the edge identifier and updated weight value corresponding to the weight modification operation in the dependent edge change set, and update the weight value of the edge corresponding to the edge identifier in the initial dependent edge set to the updated weight value; During the removal, addition, and update processes, the reverse index of the initial dependent edge set is updated synchronously. If any operation fails, all executed change operations are rolled back, restoring the initial set of dependent edges to its state before the incremental update.

[0029] In this step, the bidirectional index synchronous update and the full transaction atomic rollback mechanism are optimized designs of this invention, ensuring absolute consistency of the update of the dependent edge set: S531. Based on the operation type of the dependent edge change set, perform the old edge deletion, new edge addition, and edge weight modification operations in sequence; S532. By designing a bidirectional index real-time synchronization mechanism, the forward and reverse index data are updated synchronously with each edge operation to avoid mismatch between the index and the entity data. S533. Configure an atomic transaction fault tolerance mechanism. If any operation fails, a global rollback will be performed to restore the original state of the dependent edge set. This fault tolerance mechanism is specifically designed for high-security verification scenarios and is different from the conventional unprotected update logic. S534. After no anomalies are found, output the updated set of dependency edges to complete the incremental synchronous evolution of dependency relationships.

[0030] S6. Based on the updated set of dependent edges and the set of changed objects, perform bidirectional slicing to obtain the set of affected slices. Specific steps include: Extract model nodes from the set of changed objects to obtain the set of starting nodes for the forward slice; Based on the set of starting nodes for the forward slice and the updated set of dependency edges, the forward slice result is obtained by propagating sequentially along the directions of the model internal dependency edges, model-code mapping edges, code internal dependency edges, and interface-test association edges in the updated set of dependency edges; Extract code nodes from the set of changed objects to obtain the set of reverse slice starting nodes; The forward slicing results and the reverse slicing results are combined to obtain the affected slice set.

[0031] In this step, the basic propagation logic of forward and reverse bidirectional slicing follows the conventional approach to slicing analysis, while the four types of attenuation factors, fixed propagation termination threshold, and propagation order of differentiated edge types are all calibration parameters and rules of this invention, representing core technical improvements. S61. The specific execution process for forward slicing is as follows: S611. Select model nodes from the set of changing objects as the starting nodes for forward slicing to form a set of starting nodes; S612. Based on the set of starting nodes for the reverse slice and the set of updated dependency edges, propagate sequentially along the reverse direction of the code-internal dependency edges, the code-model tracing edges, and the reverse direction of the model-internal dependency edges in the updated dependency edge set to obtain the reverse slice result. The propagation path priority is: model-internal dependency edges, model-code mapping edges, code-internal dependency edges, and interface-test association edges. This path order adapts to the business logic of model-driven code generation. S613. This invention achieves accurate iterative calculation of influence scores by setting four types of edge attenuation factors and using calculation formulas. Each parameter is the optimal value calibrated by multi-item field measurements. (Data flow dependence edge decay factor within the model); (Model-code mapping edge decay factor); (The control flow inside the code depends on the edge decay factor). (Interface - Test associated edge decay factor). S614. Set a propagation termination threshold. When the node's influence score is below 0.05, the propagation will immediately stop. This threshold is a calibration parameter adapted to high-security scenarios. S615. Record all propagation nodes, paths, and impact scores to form a positive slice result.

[0032] S62. The reverse slice execution process (code propagation back to model nodes) is as follows: S621. Select code nodes from the set of changed objects as the starting nodes for reverse slicing. S622, Customized Backpropagation Path: Reverse the internal dependency edges of the code, the code-model tracing edge, and the internal dependency edges of the model to achieve accurate tracing from code to model and make up for the defects of conventional one-way slicing technology; S623. Based on the set of starting nodes of the reverse slice and the set of updated dependency edges, propagate sequentially along the reverse direction of the code-internal dependency edges, the code-model tracing edges and the reverse direction of the model-internal dependency edges in the updated dependency edge set to obtain the reverse slice result. By reusing the attenuation factor and propagation termination threshold proposed in this invention, the calculation of the reverse influence score and the determination of propagation termination are completed. S624. Summarize the reverse slicing results.

[0033] S63. Merge the forward slicing results and the reverse slicing results to obtain the affected slice set.

[0034] The union of forward and reverse slice results is used to remove duplicates, and the node propagation information and influence score are bound together to generate an affected slice set. Merging and deduplicating sets is a conventional data processing method. The difference between this invention and the prior art is that it retains the influence score dimension data to achieve quantitative differentiation of the degree of influence.

[0035] It should be further explained that the step of propagating sequentially along the directions of the model-internal dependency edges, model-code mapping edges, code-internal dependency edges, and interface-test association edges in the updated dependency edge set includes: Get the current impact score of the current propagation node; Based on the current influence score of the current propagation node, when propagating along the internal dependency edges of the model to the downstream model node, the current influence score is multiplied by the first decay factor to obtain the influence score of the downstream model node; Based on the influence score of the downstream model node, when propagating along the model-code mapping edge to the corresponding code node, the influence score of the downstream model node is multiplied by the second decay factor to obtain the influence score of the corresponding code node; Based on the influence score of the corresponding code node, when propagating along the internal dependency edge of the code to the downstream code node, the influence score of the corresponding code node is multiplied by the third decay factor to obtain the influence score of the downstream code node; Based on the influence score of the downstream code node, when propagating along the interface-test association edge to the corresponding test node, the influence score of the downstream code node is multiplied by the fourth decay factor to obtain the influence score of the corresponding test node; When the influence score of any node during the propagation process falls below the preset influence propagation termination threshold, the propagation from that node will stop.

[0036] S7. The step of performing constraint filtering, differential verification, and conflict detection based on the affected slice set to obtain an incremental consistency report and mismatch location results includes: Based on the affected slice set, a subset of constraints associated with nodes in the affected slice set is selected from the constraint configuration; Based on the constraint subset, functional equivalence verification, data type consistency verification, and constraint satisfaction verification are performed on each slice in the affected slice set to obtain the differential verification results; Detect whether the changed objects in the set of changed objects have interface mismatch or resource competition with the unchanged parts of the objects to be processed, and obtain the conflict detection result; Perform a retention analysis on the boundary conditions and abnormal paths in the affected slice set to confirm whether the changes introduce new abnormal behaviors and obtain the retention analysis results; The differential verification results, conflict detection results, and retention analysis results are summarized to generate the incremental consistency report and the mismatch location results.

[0037] This invention precisely binds multi-dimensional verification logic with incremental slicing results, performing verification only on the affected local area, thus abandoning the inefficient mode of conventional full-scale verification. It includes the following four layers of verification logic: S71. Constraint Filtering: Based on the matching and association constraints of the affected slice nodes, a subset of local constraints is filtered out, the total number of constraints to be verified is counted, and the local constraints are accurately filtered for incremental verification and optimization design. S72. Differentiation verification: Perform functional equivalence, data type consistency, and constraint satisfaction verification in sequence, and count the number of constraints that were actually verified. S73. Conflict Detection: Identify interface mismatches and resource contention conflicts between modified nodes and static nodes; S74. Boundary Preservation Analysis: Review the logical integrity of boundary conditions and abnormal paths, and investigate new anomaly risks introduced by changes; S75. Summarize all verification results, generate a structured incremental consistency report and accurate mismatch location results, so that the problem can be traced and located.

[0038] S8. The step of calculating evaluation indicators based on the incremental consistency report and the mismatch location results, and outputting correction or reinforcement suggestions based on the comparison results of the evaluation indicators and preset thresholds, includes: The slice accuracy is obtained by dividing the actual number of affected and identified elements by the total number of identified elements; The slice recall rate is obtained by dividing the number of elements that were actually affected and identified by the total number of elements that were actually affected. The completeness of the verification is obtained by dividing the number of constraints that have been verified by the total number of constraints that should be verified. The processing turnover efficiency is obtained by dividing the baseline full processing time by the current incremental processing time and then normalizing it. The reusability of historical results is obtained by dividing the number of historical verification results reused in this instance by the total number of results to be verified in this instance. The evaluation index is obtained by weighting and summing the slice accuracy, slice recall, verification completeness, processing turnover efficiency, and historical result reusability. When the evaluation index is greater than or equal to the first preset threshold, it is determined to be deliverable; When the evaluation index is greater than or equal to the second preset threshold and less than the first preset threshold, a review suggestion is output. When the evaluation index is less than the second preset threshold, reinforcement suggestions are output and the process is prevented from proceeding to the next stage.

[0039] In this step, the basic statistical standards for slice accuracy, slice recall, verification completeness, turnover efficiency, and historical reuse are based on industry-standard statistical logic. The weighting coefficient ratios for the five indicators, the overall calculation formula for the comprehensive evaluation indicators, and the dual-threshold three-level judgment system have all been calibrated through high-security project testing, which is different from the crude verification mode of existing technologies that lack quantification and rely on purely manual experience.

[0040] Slicing accuracy is used to characterize the precision of identifying the impact range of bidirectional slices. It refers to the proportion of elements that are actually affected by the changes and are indeed affected by the iteration among all elements determined by the system. The slice accuracy value is calculated by statistically analyzing the number of elements that are actually affected and correctly identified, and the number of elements that are misidentified as unaffected. The value is normalized to between 0 and 1.

[0041] Slice recall is used to characterize the completeness of the identification of the scope of influence of bidirectional slices. It refers to the proportion of the affected elements actually identified by the system to the total number of actually affected elements in this iteration. The slice recall value is calculated by counting the number of actually affected and identified elements and the number of affected elements that were missed and not detected. The value range is normalized to between 0 and 1.

[0042] The completeness of the check is used to characterize the coverage completeness of this incremental check. It refers to the number of constraint entries that the system actually completed the check for, and is the proportion of the total number of all necessary check constraints after this slice screening. The value range is normalized to between 0 and 1.

[0043] The processing turnover efficiency is used to characterize the efficiency improvement effect of incremental verification compared to traditional full verification. It is determined by the ratio of the baseline time of full verification under the same project configuration to the actual time of this incremental verification. At the same time, an upper limit truncation rule is set to constrain the final value within the range of 0 to 1 to avoid abnormal overflow of the efficiency ratio.

[0044] Historical result reusability is used to characterize the reuse value of historical verification assets. It refers to the proportion of the number of valid historical verification entries that can be directly reused in the current iteration without repeated verification to the total number of all necessary verification entries in the current iteration. The numerical range is normalized to between 0 and 1.

[0045] S81. This invention overcomes the shortcomings of existing technologies, such as single-dimensional evaluation and lack of quantitative standards. It uses a five-dimensional weighted comprehensive evaluation index. The weighting coefficients for each dimension are fitted and calibrated based on hundreds of iterations of test data from high-safety software in fields such as aviation, rail transit, and nuclear energy. The specific calculation formula is as follows: in, For slicing accuracy, Weighting coefficients for accuracy; For slice recall, This is the weighting coefficient for recall. To verify completeness, The weighting coefficient for completeness; To improve turnover efficiency, The weighting coefficient for efficiency; For the reusability of historical results, This is the weighting coefficient for reusability.

[0046] The aforementioned weighting ratio prioritizes the accuracy, completeness, and verification integrity of the tilted slices, aligning with the core R&D principle of prioritizing security and secondarily considering efficiency in high-security systems. This approach differs from the equal weighting and efficiency-first design of general industrial scheduling algorithms, demonstrating strong adaptability to specific scenarios.

[0047] S83. This invention establishes a two-level fixed threshold and a three-level delivery judgment system. The threshold parameters are statistically calibrated based on the risk tolerance threshold for high-security software delivery. Specifically, the method is as follows: First preset threshold (delivery qualification threshold): 0.85; Second preset threshold (risk warning threshold): 0.70.

[0048] When the comprehensive evaluation index value is greater than or equal to 0.85, it is determined that the incremental consistency verification result fully meets the high-security software delivery standard, with no risk of missed detection or false detection, and can directly enter the next R&D process. When the comprehensive evaluation index value is greater than or equal to 0.70 and less than 0.85, the verification result is judged to be basically compliant, but there are slight slice deviations or insufficient local verification coverage. There are no core security risks. The system automatically outputs manual review suggestions and marks the slice nodes and verification items that need to be checked. When the comprehensive evaluation index value is less than 0.70, it is determined that there is a serious defect in this incremental verification, with large slice recognition deviation and insufficient verification completeness, posing a potential security mismatch risk. The system will forcibly output reinforcement and rectification suggestions, lock the current version, and prevent it from entering the subsequent development stages such as integration, testing, and delivery.

[0049] S9. Output the list of affected slices, the incremental consistency report, the mismatch location results, and the correction or reinforcement suggestions; like Figure 2The diagram shown illustrates the overall architecture of the bidirectional slicing and incremental consistency verification proposed in this invention. The difference between this invention and existing technologies lies in the first construction of a bidirectional slicing graph. This bidirectional slicing graph is a directed graph containing multiple types of nodes and multiple types of associated edges. Nodes include model nodes, code nodes, interface nodes, and test nodes. Edges include model-internal dependency edges, code-internal dependency edges, model-code mapping edges, code-model tracing edges, and interface-test association edges, capable of simultaneously carrying bidirectional tracing relationships between the model and code sides. The bidirectional slicing graph is parsed to output a dependency edge set, which completely records the association and propagation relationships between all objects in the graph. Subsequently, dependency extraction processing is performed, identifying the propagation path triggered by changes based on the dependency edge set, locating all objects affected by the changes, and finally outputting a list of affected slices. This list of affected slices limits the scope of subsequent incremental consistency verification, eliminating the need for a full comparison of all models and code; consistency verification is only performed on objects within the list, achieving incremental verification, reducing verification computation overhead, and simultaneously ensuring the completeness of tracing verification between model modifications and code changes based on bidirectional association relationships.

[0050] This invention also includes a system human-computer interaction terminal and a results archiving module, used to simultaneously output four types of standardized deliverables: first, a tabular list of affected slices, accurately listing all affected nodes, node types, impact scores, and propagation paths; second, a complete incremental consistency report, summarizing verification statistics, constraint execution status, conflict detection results, and boundary anomaly analysis conclusions; third, refined mismatch location results, annotating each mismatch location, severity level, associated constraint ID, and risk cause; and fourth, a tiered document of correction, review, and reinforcement / rectification suggestions. All output files are automatically bound to a global version fingerprint, timestamp, and responsible person identifier, meeting the stringent requirements of high-security software compliance review, third-party verification, and project audit.

[0051] S10, Optional: Perform incremental reuse steps.

[0052] The basic idea of ​​storing historical data and reusing results is a common approach in software iterative development. This invention, through the design of a precise reuse filtering mechanism based on a set of changing objects, incremental verification logic of local recalculation and global merging, and a multi-field joint processing record archiving system, differs from the traditional extensive mode of full reuse and indiscriminate reuse, and belongs to the core optimization technology points.

[0053] The system automatically initiates the incremental reuse optimization process only when the current iteration involves minor local changes, does not trigger structural refactoring, and the proportion of changed nodes is less than the 30% threshold, significantly reducing the computational cost of redundant verification. S101. Retrieve the historical verification result database stored locally and read the static node verification records that have passed compliance verification in the historical iterations; S102. Based on the current set of changed objects, accurately filter historical data, retain only valid historical verification results that have not been changed and have no related iteration impact, and remove old data that is invalid or has related changes; S103. Local recalculation and secondary fine-grained verification are performed only on the affected slice subsets directly associated with the changed object set, without having to repeatedly verify all system nodes and all constraints, which greatly improves iteration efficiency. S104. Merge and splice the valid historical verification results with the current incremental recalculation verification results to generate a complete and fully covered consistency verification report, taking into account both verification completeness and iterative efficiency. S105. Unify and update global processing records. Each processing record should contain at least two of the following: rule hit information, difference location, timestamp, version fingerprint, and responsibility identifier, to achieve full-link traceability and auditability for each incremental iteration.

[0054] The following three examples illustrate three typical iteration scenarios of high-security software, demonstrating the differentiated advantages of this invention compared to existing conventional technologies.

[0055] Example 1: Local change in the unit of flight control model interface parameters (small-scale incremental change, triggering incremental reuse) During the iterative development of a flight control model for a civil aircraft, the R&D personnel only modified the unit of the altitude acquisition interface parameter from the international standard meter to the imperial foot. This iteration only involved 1 interface node and 2 model parameter nodes. The number of nodes in the changed object set accounted for only 1.2% of the total number of nodes in the system, which was far below the 30% degradation threshold. Therefore, the structural reconstruction judgment was not triggered, and the system started the incremental update and incremental reuse mechanism normally.

[0056] After completing model configuration and interface security constraint reading, the system constructs a unified processing object. The dependency extraction module generates an initial bidirectional slice graph and an initial dependency edge set. Through version hash comparison, it accurately identifies three change nodes and generates a set of changed objects. Starting from the change node, the system extracts the local comparison range of one-hop neighbors, completes the dependency edge difference analysis between the two versions, and generates a dependency edge change set. Only one new internal dependency edge is added; there are no deletions or weight modifications. Incremental updates to the dependency edge set are completed through an atomic transaction mechanism, synchronously refreshing the bidirectional index data without data anomalies or rollbacks.

[0057] The bidirectional slicing process utilizes the four types of attenuation factors designed in this invention to calculate the impact score. The forward slicing accurately identifies 3 model nodes, 5 generated code functions, and 2 interface test cases as affected objects, while the reverse slicing outputs no additional changed nodes. The incremental verification module only filters constraints on locally affected subsets, completing functional equivalence, data consistency, interface conflict, and boundary anomaly checks, without detecting any mismatches or conflicts.

[0058] The final measured results for each sub-indicator are as follows: slice precision 0.98, slice recall 0.97, verification completeness 1.0, processing turnover efficiency 0.92, and historical result reusability 0.91. Substituting these values ​​into the weighted calculation formula proposed in this invention yields: If the value exceeds the first preset threshold of 0.85, the system determines that the verification result of this iteration meets the delivery standards and can proceed normally to the next development stage. This iteration fully reused the historical verification results of the remaining unchanged modules of the system, completing the entire verification process in 12 minutes, while the traditional full regression verification benchmark of the same scale took 118 minutes, demonstrating a significant improvement in iteration efficiency. The system automatically archives complete processing records, retaining full-dimensional traceability information such as interface change location, version fingerprint, development responsible person, and verification results.

[0059] Example 2: The logic of the track control code's amplitude limiting function has been modified (the weight of the trigger dependency edge has been changed). In the iterative development of onboard control safety software for rail transit, researchers optimized the internal execution logic of the onboard amplitude limiting protection function. After optimization, the frequency of program calls to this function significantly increased, and the dependency strength of the control flow dependencies within the corresponding code underwent substantial changes. This iteration only changed one code node, and the percentage of changed nodes was far below the 30% threshold. The system executed a standard incremental update process.

[0060] After the system version comparison identifies changes to the target code node, it extracts the local range of the one-hop neighbors corresponding to that node, including three upstream model nodes and two interaction interface nodes. During the local edge difference comparison, it detects that the weight of the original control flow dependency edge has changed from 0.5 to 0.9, with a weight difference of 0.4, which is greater than the weight change threshold of 0.05. The system determines this as a substantial modification and records the weight modification operation in the dependency edge change set.

[0061] After updating the weights of the dependency edge set and synchronizing the index, the bidirectional slices rely on the decay factor to propagate the impact, accurately identifying the abnormal recovery path associated with the limiting function as the newly affected range, and automatically including two associated test cases into the affected slice set. The incremental verification module performs special boundary checks and conflict detection for the newly affected paths, confirming that all limiting safety constraints are met and there are no abnormal issues such as interface mismatch or resource contention.

[0062] The comprehensive evaluation index for this iteration was calculated to be 0.87, which is greater than the delivery threshold of 0.85. The system determined that the software was ready for delivery and simultaneously output a suggestion for manual review, prompting the R&D personnel to focus on checking the verification records of newly added abnormal paths to further ensure the operational safety of the track control software. Finally, all results were archived and the version was locked.

[0063] Example 3: Full reconfiguration of the top-level interface of the nuclear energy control system (structural reconfiguration, automatic degradation full reconstruction mode). A nuclear safety monitoring system underwent an architecture upgrade and iteration, completing the full replacement of the top-level interactive interfaces and the reorganization of the subsystem architecture. The number of nodes changed in this iteration accounted for 42% of the total number of nodes in the system, exceeding the 30% threshold of this invention. At the same time, the system automatically identified this iteration as a structural reconstruction change, triggering the dual downgrade judgment conditions.

[0064] The system automatically abandons the logic of local incremental comparison and dependency edge change set generation, and switches to the full dependency edge reconstruction mode. It clears the original initial dependency edge set and fully reconstructs the full dependency relationship and bidirectional index structure based on the latest version of the bidirectional slice graph, thus completely avoiding the risk of missed detection in local comparison under large-scale architecture changes.

[0065] This iteration performed full bidirectional slicing and full constraint verification. No historical verification results were reusable, and the reusability of historical results was 0. The final comprehensive evaluation index was 0.76, falling within the threshold range of 0.70 to 0.85. The system automatically generated a manual review suggestion, requiring safety compliance engineers to manually review each item of the full verification results. Only after confirming that there are no safety hazards can the version be archived, strictly adhering to the ultra-high safety level delivery requirements of the nuclear energy control system.

[0066] This invention also discloses a model generation code incremental consistency verification system based on bidirectional slicing, comprising: The acquisition module is used to acquire the model configuration, interface configuration, constraint configuration, and validation rules associated with the object to be processed. The building module is used to construct a unified processing object based on the model configuration, the interface configuration, the constraint configuration, and the verification rules. The unified processing object includes a bidirectional slice graph, a set of dependency edges, a set of changed objects, and a set of affected slices. The bidirectional slice graph is a directed graph. The nodes of the directed graph include model nodes, code nodes, interface nodes, and test nodes. The edges of the directed graph include model internal dependency edges, code internal dependency edges, model-code mapping edges, code-model tracing edges, and interface-test association edges. The processing module is used to perform structured decomposition, boundary extraction, and dependency extraction on the unified processing object to obtain an initial bidirectional slice graph and an initial set of dependency edges. The comparison module is used to perform version comparison on the object to be processed based on the initial bidirectional slice graph and the initial dependency edge set, identify the objects that have changed, and obtain the set of changed objects; The update module is used to perform incremental updates on the initial dependency edge set based on the changed object set, so as to obtain the updated dependency edge set. The first execution module is used to perform bidirectional slicing based on the updated set of dependency edges and the set of changed objects to obtain the set of affected slices; The second execution module is used to perform constraint filtering, differential verification and conflict detection based on the affected slice set, and obtain incremental consistency report and mismatch location results; The calculation module is used to calculate the evaluation index based on the incremental consistency report and the mismatch location result, and output correction suggestions or reinforcement suggestions based on the comparison result of the evaluation index and the preset threshold. The output module is used to output the list of affected slices, the incremental consistency report, the mismatch location results, and the correction or reinforcement suggestions.

[0067] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in this application and in the embodiments can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (SSRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).

[0068] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, apparatus, article, or method that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, apparatus, article, or method. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, apparatus, article, or method that includes that element.

[0069] The above description is merely a preferred embodiment of the present invention and does not limit the scope of this application. Any equivalent results or equivalent process transformations made based on the content of the present invention's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the scope of protection of this application.

Claims

1. A method for incremental consistency verification of model-generated code based on bidirectional slicing, characterized in that, Includes the following steps: Retrieve the model configuration, interface configuration, constraint configuration, and validation rules associated with the object to be processed; Based on the model configuration, interface configuration, constraint configuration, and verification rules, a unified processing object is constructed. The unified processing object includes a bidirectional slice graph, a set of dependency edges, a set of changed objects, and a set of affected slices. The bidirectional slice graph is a directed graph. The nodes of the directed graph include model nodes, code nodes, interface nodes, and test nodes. The edges of the directed graph include model internal dependency edges, code internal dependency edges, model-code mapping edges, code-model tracing edges, and interface-test association edges. The unified processing object is subjected to structured decomposition, boundary extraction, and dependency extraction to obtain an initial bidirectional slice graph and an initial set of dependency edges; Based on the initial bidirectional slice graph and the initial dependency edge set, a version comparison is performed on the object to be processed to identify the changed objects and obtain the set of changed objects. Based on the set of changed objects, perform incremental updates on the initial set of dependent edges to obtain the updated set of dependent edges; Based on the updated set of dependent edges and the set of changed objects, perform bidirectional slicing to obtain the set of affected slices; Based on the affected slice set, constraint filtering, differential verification, and conflict detection are performed to obtain an incremental consistency report and mismatch location results; Based on the incremental consistency report and the mismatch location results, an evaluation index is calculated, and based on the comparison results of the evaluation index with the preset threshold, a correction suggestion or reinforcement suggestion is output. Output the list of affected slices, the incremental consistency report, the mismatch location results, and the correction or reinforcement suggestions.

2. The incremental consistency verification method for model generation code based on bidirectional slicing according to claim 1, characterized in that, The step of performing incremental updates on the initial dependency edge set based on the changed object set to obtain the updated dependency edge set includes: Starting with each object in the set of changed objects, obtain the one-hop neighbor node of the object in the initial bidirectional slice graph to obtain the local node range; For each edge within the local node range, perform a difference analysis before and after the change to obtain the dependent edge change set; The dependency edge change set is applied to the initial dependency edge set to obtain the updated dependency edge set.

3. The incremental consistency verification method for model generation code based on bidirectional slicing according to claim 2, characterized in that, The step of performing a difference analysis before and after the change on each edge within the local node range to obtain the dependent edge change set includes: Obtain the first version bidirectional slice image of the object to be processed before the change and the second version bidirectional slice image after the change; For each edge within the local node range, compare the existence state and weight value of the edge in the first version of the bidirectional slice graph and the second version of the bidirectional slice graph; When the edge exists in the first version of the bidirectional slice graph but does not exist in the second version of the bidirectional slice graph, the edge is recorded as a deletion operation; When the edge does not exist in the first version of the bidirectional slice graph but exists in the second version of the bidirectional slice graph, the edge is recorded as an addition operation; When the edge exists in both the first version of the bidirectional slice graph and the second version of the bidirectional slice graph, but the change in the weight value exceeds the preset weight change threshold, the edge is recorded as a weight modification operation. By summing all deletion, addition, and weight modification operations, the dependency edge change set is obtained. When the number of nodes in the changed object set exceeds a preset ratio threshold of the total number of nodes in the system, or when the change type of the object to be processed is structural reconstruction, switch to full dependency edge reconstruction mode.

4. The incremental consistency verification method for model generation code based on bidirectional slicing according to claim 2, characterized in that, The step of applying the dependency edge change set to the initial dependency edge set to obtain the updated dependency edge set includes: Remove the corresponding edge from the initial dependent edge set according to the edge identifier corresponding to the deletion operation in the dependent edge change set; According to the newly added edge corresponding to the addition operation in the dependent edge change set, the newly added edge is added to the initial dependent edge set; Based on the edge identifier and updated weight value corresponding to the weight modification operation in the dependent edge change set, the weight value of the corresponding edge in the initial dependent edge set is updated to the updated weight value. During the removal, addition, and update processes, the index structure of the initial dependent edge set is updated synchronously. If any operation fails, all executed change operations will be rolled back.

5. The incremental consistency verification method for model generation code based on bidirectional slicing according to claim 1, characterized in that, The step of performing bidirectional slicing based on the updated set of dependency edges and the set of changed objects to obtain the set of affected slices includes: Model nodes are extracted from the set of changed objects and used as the starting nodes for forward slicing; Based on the forward slice starting node and the updated set of dependent edges, the forward slice result is obtained by propagating along the edges in the first propagation direction set in sequence. Extract code nodes from the set of changed objects and use them as the starting nodes for reverse slicing; Based on the reverse slice starting node and the updated set of dependent edges, the reverse slice result is obtained by propagating along the edges in the second propagation direction set in sequence. The forward slicing results and the reverse slicing results are combined to obtain the affected slice set.

6. The incremental consistency verification method for model generation code based on bidirectional slicing according to claim 5, characterized in that, The step of propagating sequentially along the edges in the first propagation direction set includes: Get the current impact score of the current propagation node; When propagating along the internal dependency edges of the model to the downstream model node, the current influence score is multiplied by the first decay factor to obtain the influence score of the downstream model node; When propagating along the model-code mapping edge to the corresponding code node, the influence score of the downstream model node is multiplied by the second decay factor to obtain the influence score of the corresponding code node; When propagating along the internal dependency edges of the code to the downstream code node, the influence score of the corresponding code node is multiplied by the third decay factor to obtain the influence score of the downstream code node; When propagating along the interface-test association edge to the corresponding test node, the influence score of the downstream code node is multiplied by the fourth decay factor to obtain the influence score of the corresponding test node; When the influence score of any node during the propagation process falls below the preset influence propagation termination threshold, the propagation from that node will stop.

7. The incremental consistency verification method for model generation code based on bidirectional slicing according to claim 1, characterized in that, The steps of performing constraint filtering, differential verification, and conflict detection based on the affected slice set to obtain an incremental consistency report and mismatch location results include: Based on the affected slice set, a subset of constraints associated with nodes in the affected slice set is selected from the constraint configuration; Based on the constraint subset, functional equivalence verification, data type consistency verification, and constraint satisfaction verification are performed on each slice in the affected slice set to obtain the differential verification results; Detect whether the changed objects in the set of changed objects conflict with the unchanged parts of the objects to be processed, and obtain the conflict detection result; Preservation analysis is performed on the boundary conditions and outlier paths in the affected slice set to obtain the preservation analysis results; The differential verification results, conflict detection results, and retention analysis results are summarized to generate the incremental consistency report and the mismatch location results.

8. The incremental consistency verification method for model generation code based on bidirectional slicing according to claim 1, characterized in that, The step of calculating evaluation indicators based on the incremental consistency report and the mismatch location results, and outputting correction or reinforcement suggestions based on the comparison results of the evaluation indicators with preset thresholds, includes: The slicing accuracy is obtained based on the actual number of affected and identified elements and the total number of identified elements; The slice recall rate is obtained, which is determined based on the number of elements that were actually affected and identified and the total number of elements that were actually affected. Obtain the verification completeness, which is determined based on the number of constraints that have been verified and the total number of constraints that should be verified. The processing turnover efficiency is obtained, which is determined based on the baseline full processing time and the current incremental processing time. Obtain the reusability of historical results, which is determined based on the number of historical verification results reused this time and the total number of results to be verified this time; The evaluation index is obtained by weighting and summing the slice accuracy, slice recall, verification completeness, processing turnover efficiency, and historical result reusability. When the evaluation index is greater than or equal to the first preset threshold, it is determined to be deliverable; When the evaluation index is greater than or equal to the second preset threshold and less than the first preset threshold, a review suggestion is output. When the evaluation index is less than the second preset threshold, reinforcement suggestions are output.

9. The incremental consistency verification method for model generation code based on bidirectional slicing according to claim 1, characterized in that, It also includes incremental reuse steps: When only a local object changes, retrieve the historical verification results database; Based on the set of changed objects, retrieve the historical verification results corresponding to the unchanged parts from the historical verification result database; Local recalculation and local re-verification are performed on the affected subsets related to the changed object set to obtain incremental verification results; The historical verification results are merged with the incremental verification results to generate a complete consistency report; Update the processing record, which includes at least two of the following: rule hit information, difference location, timestamp, version fingerprint, and responsibility identifier.

10. A model generation code incremental consistency verification system based on bidirectional slicing, characterized in that, include: The acquisition module is used to acquire the model configuration, interface configuration, constraint configuration, and validation rules associated with the object to be processed. The building module is used to construct a unified processing object based on the model configuration, the interface configuration, the constraint configuration, and the verification rules. The unified processing object includes a bidirectional slice graph, a set of dependency edges, a set of changed objects, and a set of affected slices. The bidirectional slice graph is a directed graph. The nodes of the directed graph include model nodes, code nodes, interface nodes, and test nodes. The edges of the directed graph include model internal dependency edges, code internal dependency edges, model-code mapping edges, code-model tracing edges, and interface-test association edges. The processing module is used to perform structured decomposition, boundary extraction, and dependency extraction on the unified processing object to obtain an initial bidirectional slice graph and an initial set of dependency edges. The comparison module is used to perform version comparison on the object to be processed based on the initial bidirectional slice graph and the initial dependency edge set, identify the objects that have changed, and obtain the set of changed objects; The update module is used to perform incremental updates on the initial dependency edge set based on the changed object set, so as to obtain the updated dependency edge set. The first execution module is used to perform bidirectional slicing based on the updated set of dependency edges and the set of changed objects to obtain the set of affected slices; The second execution module is used to perform constraint filtering, differential verification and conflict detection based on the affected slice set, and obtain incremental consistency report and mismatch location results; The calculation module is used to calculate the evaluation index based on the incremental consistency report and the mismatch location result, and output correction suggestions or reinforcement suggestions based on the comparison result of the evaluation index and the preset threshold. The output module is used to output the list of affected slices, the incremental consistency report, the mismatch location results, and the correction or reinforcement suggestions.