Model inspection device, model inspection method, and program
The model checking apparatus and method address the limitation of unknown internal configurations by calculating overall feature amounts for components with unknown structures, enabling model checking on black box models and overcoming the state space explosion problem.
Patent Information
- Application Number
- JP2023217272
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-22
- Publication Date
- 2025-07-03
- Estimated Expiration
- 2043-12-22
AI Technical Summary
Existing model checking techniques fail to handle models with components having unknown internal configurations, leading to the state space explosion problem and limiting the applicability of model checking to white box models.
A model checking apparatus and method that acquires partial feature amounts for components with unknown internal configurations, calculates overall feature amounts, and inspects the state transition model using a compositional principle to enable model checking even for black box models.
Enables model checking on models with components having unknown internal configurations, overcoming the state space explosion problem and expanding the applicability beyond white box models.
Smart Images

Figure 2025100131000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a model checking apparatus, a model checking method, and a program.
Background Art
[0002] Model checking, which is a type of formal verification, is a technique for verifying whether a model derived from the design of hardware or software satisfies a formal specification by exhaustive complete search. Model checking has attracted attention as an automatic verification technique, and various model checking techniques have been proposed.
[0003] For example, Non-Patent Document 1 discloses an element reduction divide-and-conquer algorithm that processes a Markov decision process having a hierarchical structure of components in a divide-and-conquer manner in order to solve the state space explosion problem of probabilistic model checking.
Prior Art Documents
Non-Patent Documents
[0004]
Non-Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] However, the prior art does not assume that the model to be inspected includes components with unknown internal configurations.
[0006] One aspect of the present invention aims to perform model checking on a model including components with unknown internal configurations in view of the above technical problems. **Means for Solving the Problems**
[0007] To solve the above problems, a model checking apparatus according to one aspect of the present invention includes a model acquisition unit that acquires a state transition model for state transitions between a plurality of components, a partial feature amount acquisition unit that acquires predetermined partial feature amounts for the components, an overall feature amount calculation unit that calculates an overall feature amount of the state transition model based on the partial feature amounts for each component, and an inspection execution unit that inspects the state transition model based on the overall feature amount. **Advantages of the Invention**
[0008] According to one aspect of the present invention, it is possible to perform model checking on a model including components with unknown internal configurations. **Brief Description of the Drawings**
[0009]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Embodiment for Carrying Out the Invention
[0010] Hereinafter, each embodiment of the present invention will be described with reference to the accompanying drawings. In the present specification and the drawings, for components having substantially the same functional configuration, the same reference numerals are given and redundant descriptions are omitted.
[0011] [Embodiment] One embodiment of the present invention is a model checking system that performs model checking of a state transition model. The state transition model in this embodiment includes a plurality of components and is a model in which state transitions occur between the components.
[0012] The state transition model in this embodiment may be a quantitative state transition model that calculates quantitative indicators. The quantitative indicators may include transition probabilities or gains. Examples of the quantitative state transition model include a Markov decision process or a mean payoff game. The Markov decision process is a probability model in which state transitions occur probabilistically. When the state transition model is a Markov decision process, the quantitative indicators may include the reachability probability from input to output and the expected reward (expected value of gain).
[0013] [Background] The probabilistic system model can handle the uncertainties inherent in real-world systems. In probabilistic model checking, quantitative inspection results can be obtained, so a more detailed evaluation is possible than in qualitative verification.
[0014] An example of a probabilistic system model is a Markov Decision Process (MDP). Model checking of a Markov Decision Process is highly practical because it can not only verify the specification (i.e., calculate the optimal expected reward) but also synthesize the optimal control strategy. Theoretically, probabilistic model checking has the problem that the problem contains continuous quantities (i.e., probabilities), but many efficient algorithms for performing probabilistic model checking have been proposed.
[0015] However, even with the efficient algorithms proposed conventionally, there is a problem that verification cannot be realistically performed when the model to be inspected becomes complex. This is because when the model to be inspected becomes complex, a so-called state space explosion problem occurs, and the model size becomes huge exceeding the memory size of the verification machine.
[0016] An effective countermeasure against the state space explosion problem is element-reducing divide-and-conquer. Element-reducing divide-and-conquer has a model structure in which many small components are combined in multiple layers and is processed by a divide-and-conquer method. In particular, in a model with repetitions between components, intermediate results can be obtained by repeatedly using the calculation results for each component, leading to an improvement in processing performance.
[0017] In model checking of Markov Decision Processes, many element-reducing model checking techniques have been proposed for various settings. For example, in probabilistic automata, a technique for processing a composite Markov Decision Process by parallel composition has been proposed (see Reference 1). In Reference 1, an assume-guarantee style verification algorithm based on multi-objective probabilistic model checking is adopted. However, this technique has the problem that the contract conditions between the parallel components required for processing need to be discovered manually and is not fully automatic.
[0018] [Reference 1] Kwiatkowska, M.Z., Norman, G., Parker, D., Qu, H., "Compositional probabilistic verification through multi-objective model checking", Information and Computation. vol. 232, pp. 38-65, 2013.
[0019] As another example, there is a hierarchical model checking method for Markov decision processes (see Reference 2). Reference 2 deals with a sequential composition rather than a parallel composition, and assumes that there is parametric uniformity among components (in other words, the shapes of the components are the same, but the parameter values may vary), and presents a model checking algorithm for calculating the optimal expected reward. However, this method has problems such as many restrictions on the way of combining components and no allowance for backtracking.
[0020] [Reference 2] Junges, S., Spaan, M.T.J., "Abstraction-refinement for hierarchical probabilistic models", CAV 2022, pp. 102-123, 2022.
[0021] Non-Patent Document 1 discloses an element-reducing divide-and-conquer algorithm for solving these problems. Non-Patent Document 1 proposes a method of synthesizing a Markov decision process using a formal graphical language called String Diagram and calculating the optimal expected reward. In this method, there is a high degree of freedom in the way of combining components, and it is possible to perform model checking automatically.
[0022] One of the important elements of the factorized divide-and-conquer algorithm is to have the principle of compositionality as a conservation law of algebraic structures. More specifically, in the factorized divide-and-conquer algorithm, a compositional solution is specified as a homomorphism of an appropriate monoidal category. Another important element of the factorized divide-and-conquer algorithm is an equation called the factorization equation. The factorization equation is an extension of the equation regarding the reachability probability to the expected reward.
[0023] However, the factorized divide-and-conquer algorithm assumes that the internal composition is known for all components included in the model to be inspected. In other words, it does not assume model checking for a model that includes components with unknown internal composition.
[0024] Unknown internal composition means that only the input and output are clear, and the behavior from the input to the output is not clear. For example, a state transition model can be represented as a graph consisting of nodes and edges. As an example, unknown internal composition means that, among other things, the number of nodes, the connections between nodes, the gains obtained at nodes, the transition probabilities of edges, etc. are not disclosed.
[0025] Figures 1 and 2 are diagrams showing an example of a composite Markov decision process. As shown in Figure 1, the composite Markov decision process A includes components B and C. Components B and C may be Markov decision processes or other models. The composite Markov decision process A shown in Figure 1 can be divided as shown in Figure 2. In Figure 2, ; represents sequential composition, the circled + represents sum, and the arrow represents a constant wire.
[0026] In model checking of a Markov decision process, it is necessary to calculate the expected value of gain based on the behavior when an action is selected in each state (position). In FIG. 2, if the internal configurations of components B and C are not disclosed, the behavior of the composite Markov decision process A cannot be derived. As a result, model checking for the composite Markov decision process A cannot be performed.
[0027] This embodiment aims to enable model checking for a model including components with unknown internal configurations. In this embodiment, a method is proposed that enables model checking if the mathematical features used for model checking are known even if the internal configurations of the components included in the model are unknown. In one aspect, model checking can be executed for a model including components with unknown internal configurations.
[0028] <Overview of Model Checking> The overview of the model checking in this embodiment will be described with reference to FIGS. 3 to 5.
[0029] FIG. 3 is a diagram showing an example of a white box model. A white box model is a state transition model in which the internal configuration of a component is known.
[0030] As shown in FIG. 3, the state transition model MDP(A) includes components CompMDP(B1) and CompMDP(B2). The internal configuration of the component CompMDP(B1) shown in FIG. 3, such as the number of positions P11 to P14, the connections between them, and the transition probabilities between them, is clear. Similarly, the internal configuration of the component CompMDP(B2), such as the number of positions P21 to P24, the connections between them, and the transition probabilities between them, is clear.
[0031] FIG. 4 is a diagram showing an example of a black box model. The black box model is a state transition model in which the internal structure of components is unknown. The black box model includes a state transition model in which the internal structure of some components is unknown and the internal structure of other components is known.
[0032] Although the inputs and outputs of the components CompMDP(B1) and CompMDP(B2) shown in FIG. 4 are clear, their internal structures are not. In FIG. 4, the internal structures of both components CompMDP(B1) and CompMDP(B2) included in the state transition model MDP(A) are unknown, but the internal structure may be unknown for only one of the components.
[0033] FIG. 5 is a diagram showing an example of a black box model with known mathematical features. Although the internal structure of the component CompMDP(B1) shown in FIG. 5 is not clear, the mathematical feature CompMDP'(B1) is disclosed. Similarly, although the internal structure of the component CompMDP(B2) shown in FIG. 5 is not clear, the mathematical feature CompMDP'(B2) is disclosed.
[0034] The mathematical feature CompMDP' is a performance index corresponding to the behavior, performance, or contract of each component. As shown in FIG. 5, the model checking in this embodiment is a method that enables model checking even for a black box model as long as the mathematical features of each component are disclosed.
[0035] Note that in the model checking in this embodiment, the state transition model may include components with known internal structures. At this time, the mathematical features may not be disclosed for the components with known internal structures. For the components with known internal structures, since the behavior of the model can be derived, the mathematical features may be calculated based on the behavior of the model.
[0036] <Constitutive principle> In this embodiment, in order to enable model checking for a black box model, the compositional principle is used. FIG. 6 is a diagram for explaining the compositional principle.
[0037] In FIG. 6, [·] represents a mathematical feature. FIG. 6 shows that in order to calculate the mathematical features [A;B] of the model, the mathematical features [A] and [B] of the components are calculated respectively, and the calculation results are combined.
[0038] By using the compositional principle, even if the internal structure of component B is unknown, if the mathematical feature [B] is known, it is possible to calculate the mathematical feature [A;B] of the model. In order to make the mathematical feature known, for example, it is only necessary to disclose only the mathematical feature without disclosing the internal structure from the provider of component B. Also, for example, various inputs may be given to component B, and the mathematical feature may be calculated based on the output for each input.
[0039] <Mathematical Feature> The mathematical feature in this embodiment will be described in more detail. The mathematical feature includes a quantitative index used for model checking and predetermined additional information. The additional information is information used to calculate one quantitative index from a plurality of quantitative indexes. When the state transition model is a Markov decision process, the quantitative index is the expected value of the gain, and the additional information is the reachability probability.
[0040] The mathematical feature of a multi-input multi-output state transition model can be represented by Equation (1). Here, the state transition model is a Markov decision process.
[0041]
Equation
[0042] However, τ is a scheduler. The scheduler is a function that determines the action to be taken at each position. RPr τ(i, j) is the probability of reaching output j from input i in a certain scheduler τ. ERw τ (i, j) is the expected value of the gain obtained until reaching output j from input i in a certain scheduler τ. As shown in Equation (1), the mathematical feature can be said to be information that lists the probability of reaching and the expected value of the gain for all combinations of input i, output j, and scheduler τ.
[0043] Hereinafter, the mathematical feature of each component is also referred to as a "partial feature", and the mathematical feature of the entire model is also referred to as an "overall feature". However, both the partial feature and the overall feature can be represented by Equation (1).
[0044] The overall feature of model A including components B and C can be calculated by the algorithm shown in Equation (2). Model A has m inputs from the left r and m inputs from the right l and n inputs to the left r and n outputs to the right l and is a Markov decision process.
[0045]
Equation
[0046] However, seqComp is sequential composition, sum is the sum, τ is the scheduler of model A, p τ i,j is the probability of reaching output j from input i in scheduler τ, and r τ i,j is the expected value of the gain obtained until reaching output j from input i in scheduler τ.
[0047] Model checking using all feature quantities can be performed by the algorithm shown in Equation (3). Here, it is assumed that model A is a Markov decision process with one input and one output. As shown in Equation (3), in model checking for a Markov decision process with one input and one output, the maximum expected reward for each scheduler τ is calculated.
[0048]
Number
[0049] However, p τ is a set of reachability probabilities in scheduler τ, and r τ is a set of expected values of gains in scheduler τ.
[0050] <Overall Configuration> The overall configuration of the model checking system in this embodiment will be described with reference to FIG. 7. FIG. 7 is a block diagram showing an example of the overall configuration of the model checking system.
[0051] As shown in FIG. 7, the model checking system 1000 includes a model checking device 10 and a terminal device 20. The model checking device 10 and the terminal device 20 are connected so as to be able to perform data communication via a communication network N such as a LAN (Local Area Network) or the Internet.
[0052] The model checking device 10 is an information processing device such as a personal computer, a workstation, or a server that performs model checking. The model checking device 10 receives a state transition model to be inspected from the terminal device 20 and executes model checking on the state transition model. The model checking device 10 transmits an inspection result indicating the result of the model checking to the terminal device 20.
[0053] The terminal device 20 is an information processing terminal such as a personal computer, a smartphone, or a tablet terminal operated by a user of the model checking system 1000. The terminal device 20 transmits the state transition model input by the user to the model checking device 10. The terminal device 20 receives the inspection result from the model checking device 10 and presents the inspection result to the user.
[0054] Note that the overall configuration of the model checking system 1000 shown in FIG. 7 is an example, and there can be various system configuration examples according to the application and purpose. For example, one or more of the model checking device 10 and the terminal device 20 may be included in multiple units in the model checking system 1000. For example, the model checking device 10 may be realized by a plurality of computers, or may be realized as a cloud computing service. For example, the model checking system 1000 may be realized by a stand-alone computer. The classification of devices such as the model checking device 10 and the terminal device 20 shown in FIG. 7 is an example.
[0055] <Hardware Configuration> The model checking device 10 and the terminal device 20 in the present embodiment may be realized by, for example, a computer. FIG. 8 is a block diagram showing an example of the hardware configuration of a computer.
[0056] As shown in FIG. 8, the computer 500 has a CPU (Central Processing Unit) 501, a ROM (Read Only Memory) 502, a RAM (Random Access Memory) 503, an HDD (Hard Disk Drive) 504, an input device 505, a display device 506, a communication I / F (Interface) 507, and an external I / F 508. The CPU 501, the ROM 502, and the RAM 503 form a so-called computer. Each hardware of the computer 500 is connected to each other via a bus line 509. Note that the input device 505 and the display device 506 may be connected to the external I / F 508 and used.
[0057] The CPU 501 is an arithmetic unit that realizes the control and functions of the entire computer 500 by reading programs and data from a storage device such as the ROM 502 or HDD 504 onto the RAM 503 and executing processing. The computer 500 may have a GPU (Graphics Processing Unit) in addition to or instead of the CPU 501.
[0058] The ROM 502 is an example of a non-volatile semiconductor memory (storage device) that can retain programs and data even when the power is turned off. The ROM 502 functions as a main storage device that stores various programs, data, etc. necessary for the CPU 501 to execute various programs installed in the HDD 504. Specifically, the ROM 502 stores boot programs such as BIOS (Basic Input / Output System) and EFI (Extensible Firmware Interface) that are executed when the computer 500 is started up, as well as data such as OS (Operating System) settings and network settings.
[0059] The RAM 503 is an example of a volatile semiconductor memory (storage device) in which programs and data are erased when the power is turned off. The RAM 503 is, for example, DRAM (Dynamic Random Access Memory), SRAM (Static Random Access Memory), or the like. The RAM 503 provides a working area in which various programs installed in the HDD 504 are expanded when executed by the CPU 501.
[0060] The HDD 504 is an example of a non-volatile storage device that stores programs and data. Programs and data stored in the HDD 504 include an OS, which is basic software that controls the entire computer 500, and applications that provide various functions on the OS. Note that the computer 500 may use a storage device (for example, SSD: Solid State Drive, etc.) that uses flash memory as a storage medium instead of the HDD 504.
[0061] The input device 505 includes a touch panel used by the user to input various signals, operation keys and buttons, a keyboard and a mouse, a microphone for inputting audio data such as voice, etc.
[0062] The display device 506 is composed of a display such as a liquid crystal or an organic EL (Electro-Luminescence) for displaying a screen, a speaker for outputting audio data such as voice, etc.
[0063] The communication I / F 507 is an interface for connecting to a communication network and enabling the computer 500 to perform data communication.
[0064] The external I / F 508 is an interface with an external device. Examples of the external device include a drive device 510, etc.
[0065] The drive device 510 is a device for setting a recording medium 511. The recording medium 511 here includes media that optically, electrically or magnetically record information, such as CD-ROMs, flexible disks, magneto-optical disks, etc. The recording medium 511 may also include semiconductor memories that electrically record information, such as ROMs, flash memories, etc. Thereby, the computer 500 can read and / or write to the recording medium 511 via the external I / F 508.
[0066] Note that various programs installed in the HDD 504 are installed, for example, when a distributed recording medium 511 is set in a drive device 510 connected to the external I / F 508 and the various programs recorded on the recording medium 511 are read by the drive device 510. Alternatively, various programs installed in the HDD 504 may be installed by being downloaded from another network different from the communication network via the communication I / F 507.
[0067] <Functional Configuration> The functional configuration of the model checking system 1000 in this embodiment will be described with reference to FIG. 9. FIG. 9 is a block diagram showing an example of the functional configuration of the model checking system.
[0068] ≪Model Checking Device≫ As shown in FIG. 9, the model checking device 10 in this embodiment includes a component acquisition unit 101, a component storage unit 102, a model acquisition unit 103, a partial feature quantity calculation unit 104, a partial feature quantity acquisition unit 105, an overall feature quantity calculation unit 106, and an inspection execution unit 107.
[0069] The component acquisition unit 101, the model acquisition unit 103, the partial feature quantity calculation unit 104, the partial feature quantity acquisition unit 105, the overall feature quantity calculation unit 106, and the inspection execution unit 107 are realized, for example, by the processing executed by the CPU 501 on the RAM 503 by the program expanded from the HDD 504 shown in FIG. 8.
[0070] The component storage unit 102 is realized, for example, by the RAM 503 or the HDD 504 shown in FIG. 8.
[0071] The component acquisition unit 101 acquires component information regarding the component. The component acquisition unit 101 may acquire the component information by receiving the component information from the terminal device 20. The component acquisition unit 101 may acquire the component information input by the user via the input device 505.
[0072] The component information includes information indicating the component and predetermined partial feature quantities for the component. The component information includes information regarding components with unknown internal configurations. The component information may include information regarding components with known internal configurations.
[0073] The component storage unit 102 stores the component information acquired by the component acquisition unit 101. The component storage unit 102 may store component information including the partial feature amounts calculated by the partial feature amount calculation unit 104.
[0074] The model acquisition unit 103 acquires a state transition model to be inspected (hereinafter also referred to as the "target model"). The model acquisition unit 103 may acquire the target model by receiving the target model from the terminal device 20. The model acquisition unit 103 may acquire the target model input by the user via the input device 505.
[0075] The target model is a state transition model that includes a plurality of components as states and transitions between states of each component. The state transition model may be a quantitative state transition model. The quantitative state transition model may be a Markov decision process or a mean payoff game. The target model may include components with unknown internal configurations.
[0076] The partial feature amount calculation unit 104 calculates partial feature amounts related to the components included in the target model acquired by the model acquisition unit 103. The partial feature amount calculation unit 104 calculates partial feature amounts related to the components with known internal configurations among the components included in the target model. The partial feature amount calculation unit 104 does not have to calculate partial feature amounts for components for which partial feature amounts have been acquired by the partial feature amount acquisition unit 105.
[0077] The partial feature amount acquisition unit 105 acquires partial feature amounts from the component storage unit 102 based on the target model acquired by the model acquisition unit 103. The partial feature amount acquisition unit 105 acquires partial feature amounts related to the components with unknown internal configurations among the components included in the target model. The partial feature amount acquisition unit 105 may acquire the partial feature amounts if the partial feature amounts related to the components with known internal configurations are stored in the component storage unit 102.
[0078] The overall feature calculation unit 106 calculates the overall features regarding the target model acquired by the model acquisition unit 103 based on the partial features calculated by the partial feature calculation unit 104 and the partial features acquired by the partial feature acquisition unit 105.
[0079] The inspection execution unit 107 executes a model inspection based on the overall features calculated by the overall feature calculation unit 106. The inspection execution unit 107 may execute the model inspection based on the element reduction-based divide and conquer algorithm. The inspection execution unit 107 transmits the inspection result of the target model to the terminal device 20. The inspection execution unit 107 may output the inspection result of the target model to the display device 506 of the model inspection device 10.
[0080] ≪Terminal Device≫ As shown in FIG. 9, the terminal device 20 in the present embodiment includes a component input unit 201, a model input unit 202, and a result display unit 203.
[0081] The component input unit 201, the model input unit 202, and the result display unit 203 are realized, for example, by processes executed by the CPU 501 on the RAM 503 from a program expanded from the HDD 504 shown in FIG. 8.
[0082] The component input unit 201 receives an input of component information according to a user's operation. The component input unit 201 transmits the received component information to the model inspection device 10.
[0083] The model input unit 202 receives an input of a target model according to a user's operation. The model input unit 202 transmits the received target model to the model inspection device 10.
[0084] The result display unit 203 receives the inspection result of the target model from the model inspection device 10. The result display unit 203 outputs the received inspection result to the display device 506 of the terminal device 20.
[0085] <Model Inspection Method> A model checking method executed by the model checking system 1000 in this embodiment will be described with reference to FIG. 10. FIG. 10 is a flowchart showing an example of the model checking method.
[0086] In step S1, the component input unit 201 of the terminal device 20 receives an input of component information in response to a user operation. Next, the component input unit 201 transmits the received component information to the model checking device 10.
[0087] In step S2, the component acquisition unit 101 of the model checking device 10 receives component information from the terminal device 20. Next, the component acquisition unit 101 receives the input of the received component information. Then, the component acquisition unit 101 stores the received component information in the component storage unit 102.
[0088] In step S3, the model input unit 202 of the terminal device 20 receives an input of a target model in response to a user operation. Next, the model input unit 202 transmits the received target model to the model checking device 10.
[0089] In step S4, the model acquisition unit 103 of the model checking device 10 receives the target model from the terminal device 20. Next, the model acquisition unit 103 receives the input of the received target model.
[0090] The processing from step S5 to step S9 is executed for each component included in the target model acquired in step S4.
[0091] In step S5, the model acquisition unit 103 of the model checking device 10 selects an unprocessed component from the components included in the target model. Hereinafter, the selected component is referred to as the "target component". The model acquisition unit 103 determines whether the internal configuration of the target component is known or unknown.
[0092] When the internal structure of the target component is known (YES), the model acquisition unit 103 sends information about the target component to the partial feature quantity calculation unit 104 and proceeds to step S6. On the other hand, when the internal structure of the target component is unknown (NO), the model acquisition unit 103 sends information about the target component to the partial feature quantity acquisition unit 105 and proceeds to step S8.
[0093] In step S6, the partial feature quantity calculation unit 104 of the model inspection device 10 receives information about the target component from the model acquisition unit 103. Next, the partial feature quantity calculation unit 104 derives the behavior of the target component and calculates the partial feature quantity based on the derived behavior. Then, the partial feature quantity acquisition unit 105 sends the calculated partial feature quantity to the overall feature quantity calculation unit 106.
[0094] The partial feature quantity calculation unit 104 may determine whether the partial feature quantity regarding the target component is stored in the component storage unit 102. When the partial feature quantity regarding the target component is stored in the component storage unit 102, instead of calculating the partial feature quantity, the partial feature quantity may be read from the component storage unit 102.
[0095] In step S7, the partial feature quantity calculation unit 104 of the model inspection device 10 generates component information using the partial feature quantity regarding the target component calculated in step S6 and the information indicating the target component. Next, the partial feature quantity calculation unit 104 stores the generated component information in the component storage unit 102. When the partial feature quantity is read from the component storage unit 102 in step S6, the partial feature quantity calculation unit 104 may not execute step S7.
[0096] In step S8, the partial feature quantity acquisition unit 105 of the model inspection device 10 receives information about the target component from the model acquisition unit 103. Next, the partial feature quantity acquisition unit 105 determines whether the partial feature quantity regarding the target component is stored in the component storage unit 102.
[0097] If the partial feature amount regarding the target component is stored (YES), the partial feature amount acquisition unit 105 proceeds to step S9. On the other hand, if the partial feature amount regarding the target component is not stored (NO), the partial feature amount acquisition unit 105 ends the model inspection method. If the target model includes a component whose internal structure is unknown and whose partial feature amount cannot be obtained, the model inspection for the target model cannot be executed.
[0098] In step S9, the partial feature amount acquisition unit 105 of the model inspection apparatus 10 reads out the partial feature amount regarding the target component from the component storage unit 102. Next, the partial feature amount acquisition unit 105 sends the read partial feature amount to the overall feature amount calculation unit 106.
[0099] In step S10, the overall feature amount calculation unit 106 of the model inspection apparatus 10 receives the partial feature amounts regarding the components included in the target model from the partial feature amount calculation unit 104 and the partial feature amount acquisition unit 105. Next, the overall feature amount calculation unit 106 calculates the overall feature amount regarding the target model based on the received partial feature amounts. Then, the overall feature amount calculation unit 106 sends the calculated overall feature amount to the inspection execution unit 107.
[0100] In step S11, the inspection execution unit 107 of the model inspection apparatus 10 receives the overall feature amount from the overall feature amount calculation unit 106. Next, the inspection execution unit 107 executes a model inspection based on the received overall feature amount. For example, the inspection execution unit 107 may execute a model inspection for the target model based on the element reduction-based divide-and-conquer algorithm.
[0101] In step S12, the inspection execution unit 107 of the model inspection device 10 transmits the inspection result to the terminal device 20. The inspection result includes the result of the model inspection executed in step S11. For example, when the target model is a Markov decision process, the inspection result may include the optimal expected reward and the control strategy for obtaining the optimal expected reward. Note that the control strategy is a combination of actions to be taken at each position of the Markov decision process.
[0102] In step S13, the result display unit 203 of the terminal device 20 receives the inspection result from the model inspection device 10. Next, the result display unit 203 outputs the inspection result to the display device 506 of the terminal device 20.
[0103] The user can analyze the target model by referring to the inspection result output to the display device 506 of the terminal device 20. For example, when the user discovers a defect in the target model, after correcting the defect, steps S3 to S13 may be executed again for the corrected target model.
[0104] <Effect of the Embodiment> The model inspection device 10 in the present embodiment acquires predetermined partial feature amounts for components of a state transition model that transitions states among a plurality of components, calculates the overall feature amount of the state transition model based on the partial feature amounts for each component, and inspects the state transition model based on the overall feature amount. Conventional model inspection does not assume that the model to be inspected includes components with unknown internal configurations. In one aspect, according to the present embodiment, it is possible to execute model inspection on a state transition model including components with unknown internal configurations.
[0105] The model checker 10 may acquire predetermined partial feature amounts for components with unknown internal configurations. The model checker 10 may calculate partial feature amounts for components with known internal configurations. Therefore, according to the present embodiment, even in a state transition model in which components with unknown internal configurations and components with known internal configurations are mixed, model checking can be executed.
[0106] The state transition model may be a quantitative state transition model that calculates quantitative metrics. The quantitative metrics may include transition probabilities or gains. The quantitative state transition model may be a Markov decision process or a mean payoff game. The partial feature amounts may include the reachability probability from the input to the output of the component and the expected value of the gain. The overall feature amounts may include the expected value of the gain of the state transition model. Therefore, according to the present embodiment, even if a component with an unknown internal configuration is included in a quantitative state transition model including a Markov decision process or a mean payoff game, model checking can be executed.
[0107] As described above, according to the present embodiment, even for a black box model, if the mathematical feature amounts indicating the behavior of each component are known, model checking becomes possible. Model checking has been studied very actively and industrial applications have also been attempted, but there has been a major constraint that it must be a white box model, so the applicability has been limited.
[0108] The present embodiment is not limited to a Markov decision process. It is applicable as long as the target system is a model that can be represented by a graph consisting of nodes and edges. For example, it can also be applied to parity games or mean payoff games.
[0109] [Application Example] The model checking described in the above embodiments can be applied to ensuring the safety and reliability of any information system. Here, any information system includes, for example, software, hardware (e.g., integrated circuits (ICs), etc.), cyber-physical systems (e.g., automobiles, aircraft, electrical products, power generation plants, etc.), information systems including artificial intelligence (AI) as a component, and the like.
[0110] As an application example, an example of applying model checking to automotive development will be described. An automobile manufacturer receives components from many suppliers and manufactures the final product, the automobile. When the automobile manufacturer inspects the model derived from the design of the automobile, the supplier can disclose only the mathematical features to the automobile manufacturer without disclosing the internal configuration of the component, and the automobile manufacturer can execute the model checking.
[0111] At this time, since the supplier knows the internal configuration of the component, it can calculate the mathematical feature amounts based on its behavior. Also, the supplier may provide the mathematical feature amounts determined by business judgment based on the experimentally obtained mathematical feature amounts or design specifications, etc. as a performance guarantee of the component.
[0112] [Supplementary Explanation] Each function of the above-described embodiments can be realized by one or more processing circuits. Here, the "processing circuit" in this specification includes a processor programmed to execute each function by software, such as a processor implemented by an electronic circuit, an ASIC (Application Specific Integrated Circuit), a DSP (Digital Signal Processor), an FPGA (Field Programmable Gate Array) designed to execute each function described above, and devices such as conventional circuit modules.
[0113] As described in detail above regarding the embodiments of the present invention, the present invention is not limited to these embodiments, and various modifications or changes are possible within the scope of the gist of the present invention described in the claims.
Explanation of Reference Numerals
[0114] 10 Model checking device 20 Terminal device 101 Component acquisition unit 102 Component storage unit 103 Model acquisition unit 104 Partial feature amount calculation unit 105 Partial feature amount acquisition unit 106 Overall feature amount calculation unit 107 Inspection execution unit 201 Component input unit 202 Model input unit 203 Result display unit 1000 Model checking system
Claims
1. A model acquisition unit configured to acquire a state transition model for state transitions among a plurality of components; A partial feature amount acquisition unit configured to acquire predetermined partial feature amounts for the components; An overall feature amount calculation unit configured to calculate an overall feature amount of the state transition model based on the partial feature amounts for each of the components; An inspection execution unit configured to inspect the state transition model based on the overall feature amount; A model inspection apparatus comprising the above.
2. The model inspection apparatus according to Claim 1, wherein the partial feature amount acquisition unit is configured to acquire the partial feature amounts for the components with unknown internal configurations. Model inspection apparatus.
3. The model inspection apparatus according to Claim 2, further comprising a partial feature amount calculation unit configured to calculate the partial feature amounts for the components with known internal configurations. Model inspection apparatus.
4. The model inspection apparatus according to any one of Claims 1 to 3, wherein the state transition model is a quantitative state transition model that calculates quantitative indicators. Model inspection apparatus.
5. The model inspection apparatus according to Claim 4, wherein the quantitative indicators include transition probabilities or gains. Model inspection apparatus.
6. The model inspection apparatus according to Claim 4, wherein the quantitative state transition model is a Markov decision process or a mean payoff game. Model inspection apparatus.
7. The model inspection apparatus according to Claim 4, wherein the partial feature amounts include the reach probabilities from the inputs to the outputs of the components and the expected values of the gains. Model inspection apparatus.
8. The model inspection apparatus according to Claim 7, wherein the overall feature amount includes the expected value of the gain of the state transition model. Model inspection apparatus.
9. A model inspection method in which a computer executes a procedure for acquiring a state transition model for state transitions among a plurality of components, a procedure for acquiring predetermined partial feature amounts for the components, a procedure for calculating an overall feature amount of the state transition model based on the partial feature amounts for each of the components, and a procedure for inspecting the state transition model based on the overall feature amount. Model inspection method.
10. A procedure for a computer to acquire a state transition model for state transitions among a plurality of components, A procedure for obtaining predetermined partial feature amounts for the component, A procedure for calculating the overall feature amount of the state transition model based on the partial feature amounts for each component, A procedure for inspecting the state transition model based on the overall feature amount, A program for causing the above to be executed.
Citation Information
Patent Citations
System test method and system test kit
JP2019537779A
Cited By
Model inspection device, model inspection method, automobile manufacturing method, and program
WO2025135015A1