[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-82539-en":3,"doc-seo-82539-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},82539,549758146520,"Patrick","https://ap-avatar.wpscdn.com/avatar/80002397d8c0411e94?_k=1775819394049821470",8,"Research & Report","Checked Program Recovery from Execution Video: A Sound Oracle for Untrusted Generators","Tools recover programs from behavior observations generated by an untrusted model or search, but candidates lack correctness guarantees. This work studies trustworthy recovery of a runnable Scratch program from an execution recording: the video reveals what happens yet not the code, and many programs can yield the same footage. It introduces a two-tier validation oracle with verdict asymmetry, combining static certification for lens-equivalence and renderer-only refutation, yielding sound acceptance and controlled abstention.","Checked Program Recovery from Execution Video: A Sound Oracle for Untrusted Generators  \nYuan Si and Jialu Zhang∗  \nUniversity of Waterloo, Waterloo, Canada  \n[yuan.si@uwaterloo.ca](yuan.si@uwaterloo.ca), [jialu.zhang@uwaterloo.ca](jialu.zhang@uwaterloo.ca)  \narXiv :2607 .00635v 1 [ cs . SE] 1 Jul 2026  \nAbstract—A growing class of tools recovers a program from observations of its behavior using an untrusted generator, a neural model or a search, that proposes candidates with no correctness guarantee. We study how to make such recovery trustworthy, in the concrete setting of recovering a runnable Scratch program from a recording of its execution. The recording shows what the program does but never its code; many programs produce the same video, so the source cannot be recovered, and the right target is a program that behaves the same as far as the camera can tell, made precise with a lens. The core is a two-tier validation oracle with a deliberate verdict asymmetry. A static checker proves lens-equivalence to a reference and issues a certificate that, granting the partial-order independence quotient adequate, never accepts a wrong program; a renderer can only refute or witness finite agreement, never certify. Around it, VID2PROG reads each sprite’s motion, visibility, and timing from the video and a known-asset manifest and synthesizes a candidate sourcefree; a closed loop renders and runs recovery again for ground truth. Under the exact lens the oracle makes no false accept on 246 labeled differing pairs, including an adversarial battery built to trap its concurrency quotient; on inputs outside the vocabulary and on real projects it abstains or refutes, accepting none we test. In-vocabulary recoveries reproduce their source frame for frame and 80% earn a static certificate, while whole real projects, mostly outside the vocabulary, recover at 14%, a vocabulary-bound rate the system never inflates with a wrong answer. A frontier vision-language model recovers none of the matched programs single-shot, which oracle-in-the-loop repair lifts only to a few while the structured pipeline recovers all, the gap a sound checker makes for an untrusted generator.  \nI. INTRODUCTION  \nA twenty-second screen recording of a Scratch game carries enough information for a person to grasp what the program does, and a neural model or a structured search can be asked [to turn that recording back into a runnable](to turn that recording back into a runnable .sb3 file a learner)[ .sb3](to turn that recording back into a runnable .sb3 file a learner)[ file a learner](to turn that recording back into a runnable .sb3 file a learner)[ ](to turn that recording back into a runnable .sb3 file a learner)[could open and edit. The code never appears on screen](could open and edit. The code never appears on screen) ; [what](what)[ ](what)the camera captures is the rendered output of an execution, sprites moving, costumes cycling, the stage redrawing thirty times a second. Reconstructing an executable program from this signal is the problem we study, and the difficulty that organizes the paper is not only producing a candidate but trusting it: a recovered program is the output of an untrusted generator that perceives and guesses, and matching a handful of frames is no proof it behaves like the original. Our answer is a sound checker that certifies a candidate or refuses it, and is never allowed to do the reverse.  \nCorresponding author: Jialu Zhang.  \nScratch is among the largest novice programming communities, with over a hundred million publicly shared projects, and learners produce far more recordings of running projects than they keep as editable source. A recording whose source is lost cannot be analyzed, tested, tutored, or remixed; recovering an editable program reopens it to every tool that reads source.  \nThis problem sits apart from the inverse problems software engineering knows. Binary decompilation reads instructions that encode the computation direct","cbCaiu1m3G36EJDw","https://ap.wps.com/l/cbCaiu1m3G36EJDw","pdf",406939,3,1,12,"English","en",105,"# Introduction\n## Video-to-program recovery problem\n## Trust and verification via an oracle\n## Lens-based observational equivalence","[{\"question\":\"Why is recovering the original Scratch source from a screen recording ill-posed?\",\"answer\":\"Many distinct Scratch programs can produce the same visible execution video. Variables never rendered, branches never taken, and independent scripts in different orders can leave no camera-visible trace, so the original code cannot be uniquely inferred.\"},{\"question\":\"How does the paper make program recovery trustworthy despite using an untrusted generator?\",\"answer\":\"It uses a two-tier validation oracle with deliberate verdict asymmetry: a static checker that can certify lens-equivalence to a reference, and a renderer that can only refute a candidate or witness finite agreement, never certify correctness.\"},{\"question\":\"What does “lens-equivalence” mean in this context?\",\"answer\":\"It formalizes which execution facts are visible to the camera under a fixed lens. A recovered program is accepted only when it is proven equivalent to a reference with respect to those observable facts.\"}]",1784181397,30,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"checked-program-recovery-from-execution-video-a-sound-oracle-for-untrusted-generators","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":20},"https://docshare.wps.com/document/research-report/",{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/checked-program-recovery-from-execution-video-a-sound-oracle-for-untrusted-generators/82539/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-22","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why is recovering the original Scratch source from a screen recording ill-posed?","Question",{"text":75,"@type":76},"Many distinct Scratch programs can produce the same visible execution video. Variables never rendered, branches never taken, and independent scripts in different orders can leave no camera-visible trace, so the original code cannot be uniquely inferred.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the paper make program recovery trustworthy despite using an untrusted generator?",{"text":80,"@type":76},"It uses a two-tier validation oracle with deliberate verdict asymmetry: a static checker that can certify lens-equivalence to a reference, and a renderer that can only refute a candidate or witness finite agreement, never certify correctness.",{"name":82,"@type":73,"acceptedAnswer":83},"What does “lens-equivalence” mean in this context?",{"text":84,"@type":76},"It formalizes which execution facts are visible to the camera under a fixed lens. A recovered program is accepted only when it is proven equivalent to a reference with respect to those observable facts.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,122,127,130,134],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":29,"slug":121},"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]