[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-85941-en":3,"doc-seo-85941-105":29,"detail-sidebar-cat-0-en-105":90},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":13,"seo_description":14,"update_tm":27,"read_time":28},85941,7971461740909,"Levi","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",8,"Research & Report","K-ESBMC: An Executable Formal Semantics of IEC 61131-3 Ladder Diagram for Validating Verifier Translations","Automated verifiers for IEC 61131-3 Ladder Diagram (LD) improve safety by turning diagrams into model-checker inputs. Yet unverified front-end translations may diverge from the standard, silently missing violations or creating false alarms. K-ESBMC introduces executable formal semantics of IEC 61131-3 LD in the K framework. It provides an interpreter and deductive verifier from one definition, models key LD constructs and the retentive scan cycle, and validates translations via differential testing against OpenPLC/MATIEC and other verifiers.","K-ESBMC: AN EXECUTABLE FORMAL SEMANTICS OF IEC 61131-3 LADDER DIAGRAM FOR VALIDATING VERIFIER  \nTRANSLATIONS  \nA PREPRINT  \nPierre Dantas*  \nDepartment of Computer Science The University of Manchester Manchester, UK  \n[pierre.dantas@manchester.ac.uk](pierre.dantas@manchester.ac.uk)[ ](pierre.dantas@manchester.ac.uk)ORCID: 0000-0001-6390-9340  \nLucas Cordeiro*  \nDepartment of Computer Science The University of Manchester Manchester, UK  \n[lucas.cordeiro@manchester.ac.uk](lucas.cordeiro@manchester.ac.uk)[ ](lucas.cordeiro@manchester.ac.uk)ORCID: 0000-0002-6235-4272  \narXiv :2607 . 10499v 1 [ cs .PL] 11 Jul 2026  \nWaldir Junior*  \nElectrical Engineering  \nFederal University of Amazonas (UFAM)  \nManaus, AM, Brazil  \n[waldirjr@ufam.edu.br](waldirjr@ufam.edu.br)  \nORCID: 0000-0003-3095-0042  \nJuly 2026  \nABSTRACT  \nAutomated verifiers for IEC 61131-3 Ladder Diagram (LD) enhance safety by translating diagrams into model-checker inputs. Still, their unverified front-end translations risk silently returning incorrect results (missing violations or raising false alarms) when they diverge from the standard. We address this gap with K-ESBMC, an executable formal semantics of IEC 61131-3 LD built in the K framework. K-ESBMC models contacts, coils, timers, counters, edge blocks, and the retentive scan cycle, generating both an interpreter and a deductive verifier from a single definition. Validated scan-for-scan against OpenPLC/MATIEC; K-ESBMC serves as an independent reference oracle to test the ESBMC-PLC LD→GOTO translation differentially. It agrees with ESBMC on most programs and reproduces injected violations with concrete witnesses. Every disagreement exposesa genuine ESBMC defect – confirmed by OpenPLC and two other verifiers – revealing two failure modes: an unsound skip that certifies unsafe programs, and an imprecise havoc that produces spurious counterexamples. For the combinational and latch fragment, we machine-check in kprove that K-ESBMC ’s rules implement the standard’s input/output relation, elevating the correctness argument from empirical to formal. K-ESBMC provides a reusable, standard-faithful oracle for auditing any LD verifier’s translation, offering a general approach to verifying the soundness of translation-based verification tools.  \nKeywords executable formal semantics · K framework · IEC 61131-3 · Ladder Diagram · PLC · reference oracle · differential testing · translation validation · scan cycle · function blocks · ESBMC · BMC · model checking · OpenPLC · PLCopen XML  \n∗The authors contributed equally to this research.  \n1 Introduction  \nProgrammable Logic Controllers (PLCs) run much of the world’s safety-critical automation, and Ladder Diagram (LD)– the graphical, relay-inspired notation of International Electrotechnical Commission (IEC) 61131-3 – remains the language in which that logic is most often written and certified. Because a PLC fault can injure people or damage a plant, LD programs are natural targets for formal verification. A line of automated tools now checks safety properties of IEC 61131-3 programs by translating them into the input language of a model checker. The ESBMC-PLC family [6, 7, 8], for instance, lowers an LD diagram into a GOTO Intermediate Representation (IR) and discharges the resulting verification conditions with Satisfiability Modulo Theories (SMT)-based Bounded Model Checking (BMC) and k-induction.  \n1.1 The Trust Gap  \nEvery such tool rests on an unstated assumption: that its front-end – the translation from the diagram to the verifier’s model – faithfully reflects IEC 61131-3. A verifier is only as sound as this translation, yet the translation is itself unverified code. In the ESBMC-PLC line, the LD→GOTO rules were designed to match an informal reference formalization, but were never proven equivalent to the standard. When the translation and the standard disagree, theverifier can silently return the wrong answer: it can certify a hazardous program as safe (if the translation ","cbCaiulp5jjndbPu","https://ap.wps.com/l/cbCaiulp5jjndbPu","pdf",295110,1,19,"English","en",105,"# Introduction\n## The Trust Gap\n## An Executable Reference Semantics\n## Grounding and Using the Semantics","[{\"question\":\"What problem does K-ESBMC address in IEC 61131-3 LD verification tools?\",\"answer\":\"It addresses the trust gap where LD-to-verifier translations may not faithfully match the IEC 61131-3 standard, leading to missed violations or false alarms.\"},{\"question\":\"How does K-ESBMC work at a high level?\",\"answer\":\"It defines an executable formal semantics for IEC 61131-3 LD in the K framework, generating both an interpreter and a deductive verifier from the same rewrite-rule definition.\"},{\"question\":\"How is K-ESBMC used to validate translation-based verification results?\",\"answer\":\"It is validated scan-for-scan against OpenPLC/MATIEC, then used as an independent reference oracle for differential testing of ESBMC-PLC’s LD→GOTO translation, including reproduction of injected violations with concrete witnesses.\"}]",1784207280,48,{"code":4,"msg":30,"data":31},"ok",{"site_id":24,"language":23,"slug":32,"title":13,"keywords":33,"description":14,"schema_data":34,"social_meta":85,"head_meta":87,"extra_data":89,"updated_unix":27},"k-esbmc-an-executable-formal-semantics-of-iec-61131-3-ladder-diagram-for-validating-verifier-translations","",{"@graph":35,"@context":84},[36,53,67],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,47,50],{"item":40,"name":41,"@type":42,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":46},"https://docshare.wps.com/document/","Document",2,{"item":48,"name":12,"@type":42,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":42,"position":52},"https://docshare.wps.com/document/k-esbmc-an-executable-formal-semantics-of-iec-61131-3-ladder-diagram-for-validating-verifier-translations/85941/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":23,"description":14,"dateModified":61,"datePublished":61,"encodingFormat":60,"isAccessibleForFree":62,"interactionStatistic":63},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":40,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-16",true,{"@type":64,"interactionType":65,"userInteractionCount":4},"InteractionCounter",{"@type":66},"ViewAction",{"@type":68,"mainEntity":69},"FAQPage",[70,76,80],{"name":71,"@type":72,"acceptedAnswer":73},"What problem does K-ESBMC address in IEC 61131-3 LD verification tools?","Question",{"text":74,"@type":75},"It addresses the trust gap where LD-to-verifier translations may not faithfully match the IEC 61131-3 standard, leading to missed violations or false alarms.","Answer",{"name":77,"@type":72,"acceptedAnswer":78},"How does K-ESBMC work at a high level?",{"text":79,"@type":75},"It defines an executable formal semantics for IEC 61131-3 LD in the K framework, generating both an interpreter and a deductive verifier from the same rewrite-rule definition.",{"name":81,"@type":72,"acceptedAnswer":82},"How is K-ESBMC used to validate translation-based verification results?",{"text":83,"@type":75},"It is validated scan-for-scan against OpenPLC/MATIEC, then used as an independent reference oracle for differential testing of ESBMC-PLC’s LD→GOTO translation, including reproduction of injected violations with concrete witnesses.","https://schema.org",{"og:url":51,"og:type":86,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":88,"canonical":51},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":91},[92,96,100,104,109,114,119,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":45,"category_name":93,"show_sort_weight":94,"slug":95},"Story & Novel",90,"story-novel",{"id":46,"doc_module":4,"doc_module_name":45,"category_name":97,"show_sort_weight":98,"slug":99},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":45,"category_name":101,"show_sort_weight":102,"slug":103},"Exam",70,"exam",{"id":105,"doc_module":4,"doc_module_name":45,"category_name":106,"show_sort_weight":107,"slug":108},5,"Comic",60,"comic",{"id":110,"doc_module":4,"doc_module_name":45,"category_name":111,"show_sort_weight":112,"slug":113},6,"Technology",50,"technology",{"id":115,"doc_module":4,"doc_module_name":45,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":45,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":45,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":45,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":45,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":21,"doc_module":4,"doc_module_name":45,"category_name":135,"show_sort_weight":105,"slug":136},"General","general"]