Method and system for converting an input computer program into an output computer program

The method converts input computer programs into output programs with target global accuracy by synthesizing composite mathematical functions based on dependency graphs, addressing the challenges of floating-point errors and black-box implementations, and enabling formal verification of the achieved accuracy.

JP7696514B2Active Publication Date: 2025-06-20MITSUBISHI ELECTRIC R&D CENTRE EUROPE BV
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024555617
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-02-25
Filing Date
2023-01-30
Publication Date
2025-06-20
Estimated Expiration
2043-01-30

AI Technical Summary

Technical Problem

Existing computer programs struggle to maintain global accuracy due to floating-point rounding errors and approximations of mathematical functions, especially when using black-box implementations of mathematical functions, making it difficult to formally prove that the global error remains below a target upper limit.

Method used

A method and system that convert an input computer program into an output program with a target global accuracy by receiving a target internal accuracy for each mathematical function, analyzing the program to create a dependency graph, and using synthesis tools to generate composite mathematical functions that achieve the target internal accuracy, thereby ensuring the target global accuracy is met.

Benefits of technology

The proposed solution enables the generation of a computer program that achieves a predetermined target global accuracy, even with black-box mathematical function implementations, and allows for formal verification of this accuracy, thereby overcoming the limitations of existing technologies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007696514000001
    Figure 0007696514000001
  • Figure 0007696514000002
    Figure 0007696514000002
  • Figure 0007696514000003
    Figure 0007696514000003
Patent Text Reader

Abstract

The present disclosure relates to a computer-implemented method of converting an input computer program into an output computer program having a target global precision, the method including receiving a target internal precision for each mathematical function contained in the input computer program, and analyzing the input computer program to determine a dependency graph describing dependencies between mathematical function calls. The mathematical functions are processed according to the dependency graph by: for each processed mathematical function, using a value range determination tool, generating a value range for the processed mathematical function based on each composite mathematical function obtained for the mathematical functions on which the processed mathematical function depends according to the dependency graph; and using a composition tool, generating a composite mathematical function having the target internal precision. The output computer program is generated by replacing each mathematical function call with a call to its corresponding composite mathematical function.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to computer program development, and more particularly, to a method and system for converting an input computer program including mathematical functions applied to floating-point variables into an output computer program that achieves a target global accuracy. The target global accuracy corresponds to the upper limit of the global error allowed in the output computer program, and these errors are related to the approximation of mathematical functions and / or the rounding error of floating-point numbers.

Background Art

[0002] Numerical calculations are ubiquitously present in various industrial fields that require them, such as signal processing or image processing, automatic control, etc. For example, such numerical calculations are widely used in computer programs of embedded systems for various applications such as automotive control or nuclear power plant control.

[0003] However, such numerical calculations have inherent calculation errors related to the approximation being performed.

[0004] For example, a computer program operating on an embedded system is affected by rounding errors because the number of significant digits of computer operations, particularly floating-point operations, is finite. In fact, such a computer program uses the corresponding floating-point approximation instead of using the actual number, and this approximation causes errors. Although this error can be ignored in some cases, especially when there are overlapping loops, it may accumulate during the execution of the computer program and become non-ignorable.

[0005] Another factor contributing to computational error is the approximation made when implementing mathematical functions. For example, the implementation of mathematical functions for physical systems depends on approximations due to floating-point arithmetic, but also on the fact that the mathematical models of the physical systems themselves are approximations. For example, trigonometric functions such as the cosine and sine functions are approximated by polynomial functions, but these polynomials introduce errors in numerical calculations. Also, when a physical system is modeled by, for example, a differential equation, such a differential equation can be solved by a mathematical function (e.g., the Runge-Kutta method), but the resulting solution is only an approximation of the actual solution of the differential equation that models the physical system.

[0006] These two sources of error (i.e., floating-point rounding error and approximation of mathematical functions) are particularly difficult to predict and debug. This is especially true when using a mathematical function library such as libm in a computer program. The reason is that the actual implementation of the mathematical functions is generally a black box and architecture-dependent.

[0007] However, it is important that the global error (i.e., floating-point rounding error and / or approximation of mathematical functions) specific to a computer program can be determined and that it can be ensured that the global error of the computer program is maintained below a desired target upper bound.

[0008] Current solutions target the verification of the numerical accuracy of computer programs. These techniques are either empirical / probabilistic or based on formal verification methods. Tools in the former category give results for any computer program with mathematical function calls, while tools in the latter category cannot be used with black-box implementations of mathematical functions and cannot statically verify their accuracy.

[0009] Therefore, according to the current solutions, in some cases, the global error can be obtained (however, it is not possible to formally prove it when a black box implementation of a mathematical function is used), but it is not possible to guarantee that the global error due to floating-point rounding errors and / or approximations of mathematical functions is maintained below the target upper limit. SUMMARY OF THE INVENTION PROBLEM TO BE SOLVED BY THE INVENTION

[0010] The present disclosure aims to improve this situation. In particular, the present disclosure proposes a solution that enables obtaining a computer program having a predetermined target global accuracy (i.e., a global error less than a predetermined upper limit) even when a black box implementation of a mathematical function is used, thereby overcoming at least some of the limitations of the prior art described above.

[0011] Also, in at least some embodiments, the present disclosure aims to propose a solution that enables formally proving that the obtained computer program achieves the target global accuracy. MEANS FOR SOLVING THE PROBLEM

[0012] For this purpose, according to a first aspect, the present disclosure relates to a computer-implemented method for converting an input computer program into an output computer program having a target global accuracy. The input computer program includes a mathematical function applied to a floating-point variable, and the target global accuracy corresponds to a limit of the global error caused by approximation of the mathematical function and / or floating-point rounding error. The method includes receiving a target internal accuracy for each mathematical function included in the input computer program, where the target internal accuracy corresponds to each limit of the internal error of the mathematical function required to achieve the target global accuracy, and Analyzing an input computer program to obtain a dependency graph that describes dependencies between mathematical function calls, including, this method, processing mathematical functions according to the dependency graph, further including, said processing, for each mathematical function to be processed, using a value range determination tool to generate a value range for each variable of the mathematical function to be processed based on any composite mathematical function obtained for the mathematical functions on which the mathematical function to be processed depends according to the dependency graph, using a synthesis tool to generate a composite mathematical function having the target internal accuracy of the mathematical function to be processed based on the value ranges of the variables of the mathematical function to be processed, including, this method further includes generating an output computer program by replacing each mathematical function call in the input computer program with a call to its corresponding composite mathematical function.

[0013] Thus, the proposed solution depends on mathematical function synthesis that replaces an implementation of a mathematical function (which may be a black box, may have insufficient target internal accuracy, or may be too complex to formally verify) with a composite implementation that jointly achieves the target internal accuracy (a target accuracy local to the corresponding mathematical function) that enables achieving the target global accuracy set for the computer program.

[0014] Synthesis tools typically require prior knowledge of the range of values of the variables used by the mathematical functions being synthesized. Such ranges of values can be determined by using value range determination tools such as abstract interpretation tools or statistical tools. However, in the case of overlapping mathematical functions, that is, mathematical functions called within another mathematical function, the range of values of the calling mathematical function depends on the called mathematical function and may change when the synthesized function is used instead. Therefore, when determining the range of values of the calling mathematical function, the range needs to be determined by replacing the called mathematical function with a call to the corresponding synthesized implementation. Thus, the proposed solution is to obtain a dependency graph between calls to mathematical functions, and the mathematical functions are processed (synthesized) according to the order provided by the dependency graph. The called mathematical function is processed first to obtain its synthesized version that achieves the target internal accuracy of this mathematical function. The synthesized version of the called mathematical function is then used during the processing of the calling mathematical function, particularly during the determination of the range of values of the variables of the calling mathematical function that will be used subsequently by the synthesis tool.

[0015] Accordingly, by combining a value range determination tool (e.g., an abstract interpretation tool) with a synthesis tool according to a dependency graph that describes the dependencies between calls to mathematical functions, the present disclosure enables the input computer program to be converted into an output computer program that achieves the target global accuracy, provided that achieving the target internal accuracy of the mathematical functions enables achieving the target global accuracy of the entire output computer program.

[0016] In certain embodiments, the conversion method can further include one or more of the following optional features considered alone or in any technically possible combination.

[0017] In certain embodiments, the conversion method further includes annotating the output computer program based on a target global accuracy and verifying the annotation of the output computer program by using a formal verification tool.

[0018] Accordingly, by annotating the output computer program using the target global accuracy, it is possible to formally verify that the target global accuracy is indeed achieved by the output computer program.

[0019] In certain embodiments, the output computer program can be further annotated based on the range of values of a mathematical function and the target internal accuracy of a composed mathematical function.

[0020] In certain embodiments, the formal verification tool is a deductive verification tool.

[0021] In certain embodiments, the deductive verification tool uses an automated theorem prover.

[0022] In certain embodiments, the deductive verification tool uses different automated theorem provers for the proof obligation regarding approximation of a mathematical function and the proof obligation regarding rounding error of a floating point number.

[0023] In certain embodiments, when the generated output computer program does not achieve the target global accuracy, the method further includes repeating the following steps until an output computer program that achieves the target global accuracy is generated, namely, updating the target internal accuracy by further restricting all or part of the target internal accuracy; repeating the processing of the mathematical functions of the input computer program to generate an updated composed mathematical function based on the updated target internal accuracy; generating an output computer program based on the updated composed mathematical function; and repeating the above steps.

[0024] Thus, if the target internal accuracy is not sufficient to achieve the target global accuracy of the output computer program, all or part of the constraints on the target internal accuracy can be repeatedly increased (i.e., the target upper limit of the internal error of all or part of the mathematical function can be repeatedly decreased) until the generated synthetic mathematical function gives an output computer program that actually achieves the set target global accuracy.

[0025] In certain embodiments, different synthetic mathematical functions are synthesized for the same mathematical function having different call positions in the input computer program.

[0026] In fact, it is not necessary to have the same target internal accuracy for all call positions, and the same mathematical function can be called at different positions in the input computer program. In such cases, for example, different synthetic mathematical functions with different respective target internal accuracies for the same mathematical function can be generated to reduce the computational complexity at call positions that allow a larger internal error.

[0027] In certain embodiments, the value range determination tool is an abstract interpretation tool.

[0028] According to a second aspect, the present disclosure relates to a computer program product comprising instructions that, when executed by at least one processor, cause the at least one processor to execute a conversion method according to any one of the embodiments of the present disclosure.

[0029] According to a third aspect, the present disclosure relates to a computer-readable storage medium comprising instructions that, when executed by at least one processor, cause the at least one processor to execute a conversion method according to any one of the embodiments of the present disclosure.

[0030] According to a fourth aspect, the present disclosure relates to a system for converting an input computer program into an output computer program having a target global accuracy, where the input computer program includes mathematical functions applied to floating-point variables, the target global accuracy corresponds to a limit of global error due to approximation of the mathematical functions and / or rounding error of the floating-point numbers, the system includes at least one processor and at least one memory, and the at least one processor is configured to execute a conversion method according to any one of the embodiments of the present disclosure.

[0031] The present invention will be better understood by reading the following description. The following description is given by way of example only and is not in any way limiting, and is made with reference to the figures.

[0032] In these figures, the same reference numerals throughout the figures indicate the same or similar elements. For clarity, the elements shown are not to scale unless otherwise explicitly specified.

[0033] Also, the order of the steps represented in the figures is provided for illustrative purposes only and is not intended to limit the present disclosure, which can also be applied when the same steps are executed in a different order.

Brief Description of the Drawings

[0034]

Figure 1

Figure 2

Figure 3A

Figure 3B

Figure 4

Figure 5

Figure 6

Figure 7

DETAILED DESCRIPTION OF THE INVENTION

[0035] FIG. 1 schematically shows the main steps of a method 10 for converting an input computer program into an output computer program.

[0036] The conversion method 10 is executed by a computer system (not shown). In a preferred embodiment, the computer system includes one or more processors (which may belong to the same computer or different computers), and one or more memories (magnetic hard disks, optical disks, electronic memories, or any computer-readable storage medium) in which a computer program product is stored in the form of a set of program code instructions for performing all or part of the steps of the conversion method 10. Alternatively, or in combination therewith, the computer system can include one or more programmable logic circuits (such as FPGAs, PLDs, etc.) adapted to perform all or part of the above steps of the conversion method 10, and / or one or more application-specific integrated circuits (ASICs), etc. In other words, the computer system includes a set of means configured by software (a specific computer program product) and / or hardware (processors, FPGAs, PLDs, ASICs, etc.) to perform the steps of the conversion method 10.

[0037] In the present disclosure, the goal of the transformation is to achieve a target global accuracy. The target global accuracy corresponds to the upper limit of an acceptable global error. The global error corresponds to a combination of errors resulting from the approximation of all mathematical functions and all floating-point rounding errors performed by the output computer program.

[0038] The input computer program corresponds to a computer program in source code that can be written in any computer language, for example, the C computer language or the C++ computer language or the Fortran computer language. The input computer program is intended to operate on an embedded system to perform tasks related to, for example, signal processing or image processing, automatic control, etc. The input computer program includes assignments applied to floating-point variables, control structures (conditional branches, switches, loops, etc.), mathematical operations (addition, multiplication, etc.) and mathematical function (exp, log, sin, cos, etc.) calls. According to a non-limiting example, the mathematical functions are functions included in the library libm.

[0039] As described above, the implementations of the mathematical functions included in the input computer program are usually black boxes in the sense that their source codes are not available. Usually, those implementations are included as calls to mathematical functions in an external library such as the libm library.

[0040] As shown in FIG. 1, the conversion method 10 includes a step S10 of receiving the target internal accuracy of each mathematical function used in the input computer program. The target internal accuracy of a mathematical function corresponds to the upper limit of the internal error corresponding to all the approximations (of the mathematical model) made in the mathematical function under consideration and all the rounding errors of floating-point numbers. Therefore, the target internal accuracy takes into account the errors local to the relevant mathematical function, while the target global accuracy takes into account, inter alia, the global errors at the computer program level that depend on the local errors of all the mathematical functions called. In the present disclosure, the obtained target internal accuracy is such that when the implementations of the mathematical functions enable the achievement of their respective target internal accuracies, the target global accuracy will also be achieved (or at least considered to be achieved) by the computer program.

[0041] How the target internal accuracy is actually determined is outside the scope of the present disclosure, and the target internal accuracy is assumed to be provided as an input to the conversion method 10. However, it should be noted that such target internal accuracy can be obtained, for example, by using statistical tools such as Monte Carlo operations. In fact, such techniques can be used to determine the impact of the accuracy degradation of a given mathematical function of a computer program, and thus can be used to evaluate the impact of the internal accuracy of the given mathematical function on the global accuracy of the computer program (see, for example, [Defour2020]).

[0042] In the present disclosure, it should be noted that for each mathematical function, a single target internal accuracy can be obtained regardless of the number of different call positions of the same mathematical function, or multiple different target internal accuracies can be obtained for the same mathematical function, for example, one for each call position of this mathematical function or one for each different target internal accuracy obtained for the same mathematical function. In fact, when a given mathematical function (e.g., sin) has several call positions within a computer program, the contribution of the mathematical function to the global error may vary for each call position. As will be described later, the call of a mathematical function is replaced by the call of a composite mathematical function having a desired target internal accuracy so that different composite mathematical functions can be generated for different call positions of the same mathematical function. Of course, it is also possible to generate a single composite mathematical function for a given mathematical function and achieve a target internal accuracy corresponding to the lowest value of the upper limit of the internal error that can achieve the target global accuracy.

[0043] As shown in FIG. 1, the conversion method 10 also includes step S11 of analyzing the input computer program to obtain a dependency graph that describes the dependency relationships between calls of mathematical functions. Basically, during the analysis step S11, the computer system implementing the conversion method 10 analyzes the input computer program to identify the mathematical functions called by the input computer program, their call positions, and the mathematical functions called to process the results of previous calls of mathematical functions (i.e., to identify the dependency relationships between calls of mathematical functions).

[0044] Figure 2 schematically represents the source code of a simple exemplary input computer program. In this example, the input computer program calls four different mathematical functions, namely, log2 (logarithm with base 2), pow (power), exp (exponential function), and log (logarithm). As can be seen from Figure 2, the variables that the mathematical function pow receives as input do not depend on the results of any other mathematical functions, and the result of the mathematical function pow is not used by any other mathematical function. The variables that the mathematical function log receives as input do not depend on the results of any other mathematical functions, and the result of the mathematical function log is not used by any other mathematical function. The variables that the mathematical function exp receives as input do not depend on the results of any other mathematical functions, but the result of this mathematical function exp is used by the mathematical function log2 called inside the loop. The result of the mathematical function log2 called inside the loop is not used by any other mathematical function. On the other hand, the mathematical function log2 is also called outside the loop, the variables that this mathematical function receives as input do not depend on the results of other mathematical functions, and its result is not used by any other mathematical function.

[0045] Figure 3A schematically represents a dependency graph when each call of the same mathematical function is associated with its respective target internal accuracy. Therefore, the mathematical function log2 that is called twice in the input computer program of Figure 2 appears twice in the dependency graph. Each mathematical function that does not use the results of other mathematical functions is the starting point of a dependency path. In the example of Figure 3A, there are four such paths starting from the mathematical functions log2, pow, exp, and log.

[0046] Figure 3B schematically shows a dependency graph when the same mathematical function is associated with a single target internal accuracy regardless of the number of call positions in the input computer program. Therefore, the mathematical function log2, which is called twice in the input computer program of FIG. 2, appears only once in the dependency graph. Since the mathematical function log2 called inside the loop processes the result of the mathematical function exp, the call position of this mathematical function log2 is considered to be the call position that requires the lowest value of the upper limit of the internal error of this mathematical function so that only this call position is considered in the dependency graph. In FIG. 3B, there are three paths starting from the mathematical functions pow, exp, and log.

[0047] It should be noted that step S10 can also be executed after the execution of step S11 in order to first create a list of the called mathematical functions and then obtain the respective target internal accuracies of those mathematical functions based on this list. For example, it is possible to obtain the target internal accuracy for each occurrence of each mathematical function in the dependency graph.

[0048] When the computer system obtains the target internal accuracy of the mathematical functions of the input computer program and the dependency graph, the computer system processes the mathematical functions according to the dependency graph. In particular, the mathematical functions on the same path are processed continuously from the start of the path, and a composite mathematical function of each mathematical function in the dependency graph is generated.

[0049] More specifically, for each processed mathematical function, the conversion method 10 includes the following steps S12 and S13. - S12 uses a value range determination tool to generate the value range of each variable of the processed mathematical function based on each composite mathematical function obtained for the mathematical functions on which the processed mathematical function depends according to the dependency graph. - S13 uses a synthesis tool to generate a composite mathematical function having the target internal accuracy of the processed mathematical function based on the value range of each variable of the processed mathematical function.

[0050] For example, considering the dependency graph in FIG. 3B, three paths will be processed.

[0051] The path starting from the mathematical function pow contains only the mathematical function pow. Therefore, the mathematical function pow is processed first, and a value range determination tool is used to generate the value ranges of its input and output variables. Since the mathematical function pow does not depend on another mathematical function, no other composite mathematical functions are used to generate the value range of the mathematical function pow. Then, a synthesis tool is used to generate a composite mathematical function pow with the required target internal accuracy. The same applies to the path starting from the mathematical function log.

[0052] The path starting from the mathematical function exp also contains the mathematical function log2. Therefore, the mathematical function exp is processed first, and a value range determination tool is used to generate the value ranges of its input and output variables. Since the mathematical function exp does not depend on another mathematical function, no other composite mathematical functions are used to generate the value range of the mathematical function exp. Then, a synthesis tool is used to generate a composite mathematical function exp with the required target internal accuracy. Then, the mathematical function log2 is processed, and a value range determination tool is used to generate the value ranges of its input and output variables. Since the mathematical function log2 depends on the mathematical function exp, the composite implementation of the mathematical function exp is used by the value range determination tool to generate the value range of the mathematical function log2. Then, a synthesis tool is used to generate a composite mathematical function log2 with the required target internal accuracy.

[0053] Any value range determination tool known to those skilled in the art can be used to determine the value range. For example, statistical tools such as Monte Carlo operations can be used to determine the value range of a mathematical function.

[0054] In a preferred embodiment, an abstract interpretation tool is used to determine the value range. Any abstract interpretation tool known to those skilled in the art can be used. For example, Fluctuat is an abstract interpretation tool developed at CEA (French Alternative Energies and Atomic Energy Commission) and is designed to analyze the floating-point rounding errors of large-scale C / C++ computer programs in a fully automated manner (see [Goubault2013]). Fldlib is another example of an abstract interpretation tool that can be used and was developed by Vedrine et al. RAI (Runtime Abstract Interpretation, see [Ve'drine2021]) is another exemplary tool that combines abstract interpretation and runtime verification and can be used to determine the value range of variables of mathematical functions in a dependency graph.

[0055] For the generation of composite mathematical functions, any composite tool known to those skilled in the art can be used. For example, Sollya [Chevillard2010] is a composite tool that can be used to develop safe floating-point computer programs. Given a mathematical formula, Sollya attempts to provide both a polynomial approximation of this formula and an upper bound on the error committed when approximating this formula. Subsequently, Sollya proposes a floating-point implementation of the polynomial approximation that keeps the error within a reasonable interval. In other words, Sollya provides an implementation of a mathematical function where the contribution of rounding errors does not destroy the quality of the polynomial approximation. Also, the Metalibm ANR project is working on the development of tools to automate the generation of mathematical functions and digital filters that meet several criteria such as target accuracy, memory, speed, architecture, etc. All Metalibm tools can generate C functions that meet user criteria, and the target accuracy criteria are achieved by using Sollya theory.

[0056] Once all paths of the dependency graph have been processed, a composite mathematical function (and, optionally, each call position of the same mathematical function) for each mathematical function called in the input computer program that achieves the target internal accuracy set for that mathematical function is obtained. The transformation method 10 includes step S14 of generating an output computer program by replacing each mathematical function call in the input computer program with a call to its corresponding composite mathematical function. Thus, in the output computer program, each mathematical function call has been replaced with a call to a composite mathematical function that has a known (white box) implementation and achieves the target internal accuracy. When the target internal accuracy enables the achievement of the target global accuracy, the output computer program will, in principle, achieve the target global accuracy set for this program.

[0057] At this stage, the target global accuracy of the output computer program is not formally proven. However, optionally, the transformation method 10 can further include automatically annotating the output computer program based on the target global accuracy and, preferably, a predetermined value range of the input variables of the input computer program (e.g., received together with the target global accuracy). Based on such annotation and the fact that the implementation of the composite mathematical function is known at this point, it is possible to formally prove the target global accuracy set for the output computer program using a formal verification tool during the optional formal verification step S15 of the transformation method 10.

[0058] In a preferred embodiment, the output computer program can be further annotated based on the value range of the mathematical function and the target internal accuracy of the composite mathematical function in order to formally prove the target internal accuracy of the composite mathematical function of the output computer program.

[0059] For the formal verification of the output computer program, any formal verification tool known to those skilled in the art can be used. For example, the formal verification of a computer program enhanced with numerical precision annotations (assertions) can be performed using a deductive verification tool that automatically offloads the proof obligation to a dedicated prover. For example, some Frama-C [Kirchner2015] plugins have methods and rounding error analysis capabilities in their specification languages. This was first used in the Caduceus plugin [Boldo2007] based on the Why platform, which is responsible for communicating with dedicated provers such as Gappa or the Coq proof assistant. Another non-limiting example of a deductive verification tool that can be used is the Jessie plugin [Ayad2010] based on the Why3 theory of floating-point numbers.

[0060] Examples of provers that can be used by deductive verification tools include automated theorem provers such as CoqInterval [Daumas2005] and Gappa [Daumas2010]. CoqInterval is a tool for the Coq proof assistant based on the Flocq Coq formalization of floating-point arithmetic and interval arithmetic calculations (intervals with floating-point lower and upper bounds). Using interval arithmetic, this tool can automatically prove inequalities regarding real-valued expressions. Therefore, this tool can be used to limit the approximation error of algebraic expressions that approximate mathematical functions or models. Gappa is a tool designed to verify the arithmetic properties of simple numerical programs. Gappa is particularly sufficient to automatically prove the limits of the rounding error of an algorithm under some assumptions. Also, from a Gappa script, a certificate can be obtained that can be automatically verified by the Coq proof assistant so that the limits are formally verified. Also, synthesis tools such as the Sollya tool and the Metalibm tool may generate Gappa scripts that the Gappa tool can use to formally prove the target internal precision of the synthesized mathematical functions generated by such synthesis tools.

[0061] Therefore, the conversion method 10 can formally prove the target global accuracy of the output computer program and the target internal accuracy of the composite implementation of the mathematical functions as required. If the target internal accuracy of all composite mathematical functions is proven but the target global accuracy of the output computer program is not proven, this means that the target internal accuracy obtained during step S10 is not sufficient to achieve the target global accuracy. If it is essential to achieve the target global accuracy set for the output computer program, the steps of the conversion method 10 can be repeated by gradually further restricting all or part of the target internal accuracy set for the mathematical functions until an output computer program that achieves the target global accuracy is generated. In the present disclosure, "further restricting" the target internal accuracy means reducing the target upper limit of the internal error of the corresponding mathematical function.

[0062] FIG. 4 considers an exemplary input computer program including three mathematical functions f1, f2, and f3, and schematically shows the execution of successive steps of the conversion method 10 when considering the use of an abstract interpretation tool in determining the value ranges of the mathematical functions. The dependency graph of these mathematical functions f1, f2, and f3 obtained during step S11 is shown in FIG. 5 and includes a single path having the mathematical function f1 as the starting point, followed by the mathematical function f2, and then f3.

[0063] The conversion method receives as input the following. - An input computer program (source code), - A target global accuracy ε set for the output computer program, - Target internal accuracies ε1, ε2, and ε3 set for the mathematical functions f1, f2, and f3, respectively.

[0064] As shown in Figure 4, the conversion method 10 processes a mathematical function according to the dependency graph in Figure 5, and first processes the mathematical function f1. An abstract interpretation tool (e.g., Fluctuat) is used to generate the range D1 of the values of the mathematical function f1. A synthesis tool uses the mathematical function f1, the range D1 of the values, and the target internal accuracy ε1 to generate a synthesized mathematical function p1. In this example, the synthesis tool also synthesizes a certificate c1 as a predicate to ensure that the target internal accuracy ε1 is guaranteed by p1 in D1.

[0065] Next, the mathematical function f2 is processed. An abstract interpretation tool is used to generate the range D2 of the values by also using the synthesized mathematical function p1. A synthesis tool uses the mathematical function f2, the range D2 of the values, and the target internal accuracy ε2 to generate a synthesized mathematical function p2 and a certificate c2.

[0066] Next, the mathematical function f3 is processed. An abstract interpretation tool is used to generate the range D3 of the values by also using the synthesized mathematical function p2 and the synthesized mathematical function p1. A synthesis tool uses the mathematical function f3, the range D3 of the values, and the target internal accuracy ε3 to generate a synthesized mathematical function p3 and a certificate c3.

[0067] As shown in Figure 4, the conversion method 10 then generates an output computer program by replacing the calls to the mathematical functions f1, f2, and f3 with calls to the synthesized implementations p1, p2, and p3 (synthesized mathematical functions), respectively.

[0068] As described above, in some cases, the output computer program can also be enhanced with some annotations corresponding to, for example, the following assumptions, proof obligations, or local assertions. - Global preconditions regarding the output computer program, including the range of values of the input to the output computer program that the user can provide, - Global postconditions regarding the output computer program corresponding to the fulfillment of a target global accuracy ε that must be satisfied by the entire output computer program, - Assertions (each a loop invariant) corresponding to value ranges D1, D2, and D3 at the call sites of the synthetic mathematical functions (each at the position of the loop entry), - Postconditions of the synthetic mathematical functions p1, p2, and p3 corresponding respectively to the target internal precisions ε1, ε2, and ε3 guaranteed respectively by the synthesis with respect to the value ranges D1, D2, and D3.

[0069] All these annotations are used, for example, by a deductive verification tool, based on, for example, Why3 or Frama-C.

[0070] Then, if necessary, the transformation method 10 performs a formal verification of the automatically generated annotations, taking into account a formal proof of the target global precision as a final goal. In the example shown in Figure 4, the transformation method 10 uses a deductive verification tool to offload the proof obligations (annotations) to a dedicated automatic theorem prover. For example, - The proof obligations regarding the (mathematical) method error can be offloaded to a tool such as Interval, which is based on interval arithmetic that automatically examines inequalities on real arithmetic expressions, or Sollya, which is based on the Metalibm technology, - The proof obligations regarding the rounding error can be offloaded to a dedicated theorem prover such as Gappa, which proves the target internal precision, - The proof obligations regarding an abstract interpretation tool such as Fluctuat are already guaranteed since abstract interpretation is a formal method, and thus this is reused as a back-end prover, - The proof obligations regarding the statistical tools used to obtain the value ranges of the mathematical functions can be offloaded to an abstract interpretation tool or an interactive theorem prover.

[0071] Figure 6 schematically represents the execution of successive steps of the transformation method 10 when considering another exemplary input computer program that includes three mathematical functions f1, f2, and f3. The dependency graph of these mathematical functions f1, f2, and f3 obtained during step S11 is shown in Figure 7 and includes the following two paths. - A first path having a mathematical function f1 as a starting point and a subsequent mathematical function f2. - A second path having a mathematical function f3 as a starting point (and as a single mathematical function).

[0072] As shown in Figure 6, these two paths are processed in parallel. Otherwise, the steps of transformation method 10 remain unchanged.

[0073] Therefore, the present disclosure proposes a methodology for automatically generating an output computer program from an input computer program that achieves a target global accuracy regarding approximation of mathematical functions and floating-point rounding errors. This is achieved by combining a value range determination tool (such as an abstract interpretation tool or a statistical tool) and a synthesis tool based on a dependency graph that describes the dependencies between calls to mathematical functions. The target global accuracy of the output computer program can also be formally verified, if necessary, by annotating the output computer program and using, for example, a deductive (formal) verification tool.

[0074] The proposed transformation method 10 is fully automatic, provides a comprehensive guarantee of numerical accuracy, and optimizes mathematical function implementations. The transformation method 10 reduces both the development time and the verification time of software that relies on intensive use of floating-point numerical calculations.

[0075] It is emphasized that the present disclosure is not limited to the above exemplary embodiments. Modifications of the above exemplary embodiments are also within the scope of the present disclosure.

[0076] (References) [Defour2020] Defour, D., de Oliveira Castro, P., Is,toan, M., & Petit, E. (2020, June), “Custom-precision mathematical library explorations for code profiling and optimization”, In 2020 IEEE 27th Symposium on Computer Arithmetic (ARITH) (pp. 121-124), IEEE. [Goubault2013] Goubault, E., Putot, S. (2013, June), “Static analysis by abstract interpretation of numerical programs and systems, and FLUCTUAT”, In International Static Analysis Symposium (pp. 1-3), Springer, Berlin, Heidelberg. [Ve'drine2021] Ve'drine, F., Jacquemin, M., Kosmatov, N., & Signoles, J. (2021), “Runtime Abstract Interpretation for Numerical Accuracy and Robustness”, In International Conference on Verification, Model Checking, and Abstract Interpretation (pp. 243-266), Springer, Cham. [Chevillard2010] Chevillard S., Joldes, M., & Lauter C. (2010, September), “Sollya: An environment for the development of numerical codes”, In International Congress on Mathematical Software (pp. 28-31), Springer, Berlin, Heidelberg. [Kirchner2015] Kirchner F., Kosmatov N., Prevosto V., Signoles J., & Yakobowski B. (2015), “Frama-C: A software analysis perspective”, Formal Aspects of Computing, 27(3), pp. 573-609. [Boldo2007] Boldo S., & Fillia^tre J. C. (2007, June), “Formal verification of floating-point programs”, In 18th IEEE Symposium on Computer Arithmetic (ARITH'07) (pp. 187-194), IEEE. [Ayad2010] Ayad A., & Marche' C. (2010, July), “Multi-prover verification of floating-point programs”, In International Joint Conference on Automated Reasoning (pp. 127-141), Springer, Berlin, Heidelberg. [Daumas2005] Daumas M., Melquiond G., & Munoz C. (2005, June), “Guaranteed proofs using interval arithmetic”, In 17th IEEE Symposium on Computer Arithmetic (ARITH'05) (pp. 188-195), IEEE. [Daumas2010] Daumas M., & Melquiond G. (2010), “Certification of bounds on expressions involving rounded operators”, ACM Transactions on Mathematical Software (TOMS), 37(1), pp. 1-20.

Claims

1. A computer-implemented method for converting an input computer program into an output computer program that achieves a target global accuracy, wherein the input computer program includes a mathematical function applied to a floating-point variable, and the target global accuracy corresponds to a limit of a global error caused by approximation of the mathematical function and / or rounding error of the floating-point number, the method comprising: receiving a target internal accuracy for each mathematical function included in the input computer program, wherein the target internal accuracy corresponds to each limit of the internal error of the mathematical function required to achieve the target global accuracy; analyzing the input computer program to obtain a dependency graph that describes dependencies between mathematical function calls; including The method processing the mathematical functions according to the dependency graph, further including The processing includes, for each of the mathematical functions to be processed, using a value range determination tool to generate a value range for each variable of the mathematical function to be processed based on each composite mathematical function obtained for the mathematical functions on which the mathematical function to be processed depends according to the dependency graph; using a synthesis tool to generate a composite mathematical function having the target internal accuracy of the mathematical function to be processed based on the value range of each variable of the mathematical function to be processed; including The method further includes generating the output computer program by replacing each of the mathematical function calls in the input computer program with a call to its corresponding composite mathematical function.

2. The method according to claim 1, further comprising annotating the output computer program based on the target global accuracy and verifying the annotation of the output computer program by using a formal verification tool.

3. The method according to claim 2, wherein the output computer program is further annotated based on a value range of the mathematical function and a target internal accuracy of the composite mathematical function.

4. The method according to claim 2 or 3, wherein the formal verification tool is a deductive verification tool.

5. The method according to claim 4, wherein the deductive verification tool uses an automated theorem prover.

6. The method according to claim 5, wherein the deductive verification tool uses different automated theorem provers for a proof obligation regarding approximation of a mathematical function and a proof obligation regarding rounding error of a floating point number.

7. When the generated output computer program does not achieve the target global accuracy, the method includes the following steps until an output computer program that achieves the target global accuracy is generated, namely: updating the target internal accuracy by further restricting all or part of the target internal accuracy; repeating the processing of the mathematical function of the input computer program to generate an updated composite mathematical function based on the updated target internal accuracy; generating the output computer program based on the updated composite mathematical function; and further repeating the above steps. The method according to claim 2 or 3.

8. The method according to any one of claims 1 to 3, wherein different composite mathematical functions are synthesized for the same mathematical function having different call positions in the input computer program.

9. The method according to any one of claims 1 to 3, wherein the value range determination tool is an abstract interpretation tool.

10. A computer program product comprising instructions which, when executed by at least one processor, cause the at least one processor to execute the method according to any one of claims 1 to 3. **Claim 11** A computer-readable storage medium comprising instructions which, when executed by at least one processor, cause the at least one processor to execute the method according to any one of claims 1 to 3. **Claim 12** A system for converting an input computer program into an output computer program having a target global accuracy, the input computer program including a mathematical function applied to a floating-point variable, the target global accuracy corresponding to a limit of a global error caused by approximation of the mathematical function and / or rounding error of the floating-point, the system comprising at least one processor and at least one memory, the at least one processor being configured to execute the method according to any one of claims 1 to 3.

Citation Information

Patent Citations

  • Program conversion method, data processor using the same and program

    JP2004062830A

  • Compiling techniques for providing limited accuracy and enhanced performance granularity

    US20100125836A1

  • Acceleration of shader programs by compiler precision selection

    WO2020247073A1