[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-86279-en":3,"doc-seo-86279-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},86279,1099514068365,"Aurelia","https://ap-avatar.wpscdn.com/avatar/10000253d8d9f28188e?_k=1776742907772140068",8,"Research & Report","Mizzle: A Complete Concurrent Incorrectness Logic for Preventing False Alarms in Agentic Bug Finding","Large language models are increasingly used to find bugs in real programs, yet they generate many false alarms that consume developer time. Mizzle prevents false alarms by requiring each LLM bug report to be accompanied by a machine-checked proof in a program logic establishing that the reported bug is real. Mizzle is an incorrectness separation logic for concurrent OCaml-like programs, mechanized in Rocq on top of Iris, and proven sound and complete. It supports stuckness, non-linearizability, and races.","arXiv :2607 . 1 16 1 1v 1 [ cs .PL] 13 Jul 2026  \nMizzle: A Complete Concurrent Incorrectness Logic for Preventing False Alarms in Agentic Bug Finding  \nALEXANDRE MOINE, New York University, USA SAM WESTRICK, New York University, USA JOSEPH TASSAROTTI∗ , New York University, USA  \nLarge language models are increasingly used to find bugs in real-world programs, but they also produce a flood of false alarms that waste developers’ time. We propose a method to prevent these false alarms by requiring an LLM to accompany each bug report with a machine-checked proof, in a program logic, that the reported bug is real. We follow the approach of incorrectness logics, whose under-approximate reasoning establishes that a claimed behavior is genuinely reachable, and hence a true positive. In our case, however, the logic must model a realistic programming language, have a mechanization so that proofs can be checked, and be complete, so that no real bug is ruled out for want of a derivation.  \nWe present Mizzle, an incorrectness separation logic for concurrent programs written in a substantial subset of OCaml, parametric in the notion of incorrectness. We mechanize Mizzle in the Rocq proof assistant on top of the Iris framework, and we prove that it is both sound (that is, it never justifies a false alarm) and complete (that is, every incorrect execution admits a derivation) . We instantiate Mizzle with three notions of incorrectness: stuckness (triggering undefined behavior), the non-linearizability of a data structure, and the presence of a race. As a proof of concept, we illustrate how an LLM can use Mizzle in order to certify the existence of a bug.  \n1 Introduction  \nFalse alarms in bug-finding tools waste developers’ time. Interpreting a tool’s output and determining whether a bug is real or spurious can sometimes take a great deal of effort. If a tool raises too many false alarms, a developer might begin to ignore its findings or stop using it altogether. As a result, some bug-finding tools are designed to avoid all false alarms and only report true positives: when they claim there is a bug, then the program really exhibits the buggy behavior. But how can one show formally that the analyses conducted by these tools really result in only true positives? Traditionally, doing so required ad-hoc proofs that could be quite challenging; in particular, manually crafting a formal semantics reduction of the program reaching a buggy state is prohibitively tedious. An alternative that has emerged in recent years is to use Incorrectness Logic [O’Hearn 2020] as a formal foundation for justifying that a program analysis only yields true positives. Whereas traditional Hoare logic over-approximates a program’s behaviors, so that specifications show that a program’s behaviors must belong to some set, incorrectness logics instead use under-approximation, so that a specification shows that some set of behaviors is a subset of a program’s behaviors; i.e., they are actual observable behaviors. By reformulating an analysis in terms of derivations in an incorrectness logic, one can thereby show that the analysis does not generate false alarms. This approach has been successfully applied to a number of static-analysis and bug-finding methods [Raad et al. 2020; Le et al. 2022; Raad et al. 2022, 2023] .  \nToday, developers are awash in bug reports coming from a whole new class of bug-finding tools: large language models. Unfortunately, just as with traditional bug-finding tools, false alarms from LLMs also waste developers’ time. Indeed, developers have become so inundated with spurious reports from LLMs that some popular open source projects like curl have announced closing their  \n∗ Also affiliated with Amazon Web Services. This paper does not reflect the views of Amazon Web Services.  \nAuthors’ Contact Information: Alexandre Moine, [alexandre.moine@nyu.edu](alexandre.moine@nyu.edu), New York University, New York, USA; Sam  \nWestrick, [shw8119@nyu.edu](shw81","cbCaip1lYYgKGY8Z","https://ap.wps.com/l/cbCaip1lYYgKGY8Z","pdf",685751,2,1,28,"English","en",105,"# Introduction\n## Motivation: false alarms in bug finding and LLMs\n## Goal: formal guarantees against spurious reports\n## Approach: proof-carrying bug reports via incorrectness logic\n## Mizzle: soundness, completeness, and incorrectness notions\n## Proof-of-concept integration with an LLM","[{\"question\":\"What problem does Mizzle address in agentic bug finding?\",\"answer\":\"Mizzle addresses the flood of false alarms produced by LLM-based bug-finding tools, which waste developers’ time when reports are not actually realizable in the program.\"},{\"question\":\"How does Mizzle ensure that an LLM’s bug report is a true positive?\",\"answer\":\"Mizzle requires the LLM to accompany each bug report with a machine-checked proof in an incorrectness logic showing the reported buggy behavior is real.\"},{\"question\":\"What guarantees does the Mizzle logic provide?\",\"answer\":\"Mizzle is proven sound, meaning it never justifies false alarms, and complete, meaning every incorrect execution admits a derivation.\"}]",1784210000,71,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"mizzle-a-complete-concurrent-incorrectness-logic-for-preventing-false-alarms-in-agentic-bug-finding","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/mizzle-a-complete-concurrent-incorrectness-logic-for-preventing-false-alarms-in-agentic-bug-finding/86279/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-25","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does Mizzle address in agentic bug finding?","Question",{"text":75,"@type":76},"Mizzle addresses the flood of false alarms produced by LLM-based bug-finding tools, which waste developers’ time when reports are not actually realizable in the program.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does Mizzle ensure that an LLM’s bug report is a true positive?",{"text":80,"@type":76},"Mizzle requires the LLM to accompany each bug report with a machine-checked proof in an incorrectness logic showing the reported buggy behavior is real.",{"name":82,"@type":73,"acceptedAnswer":83},"What guarantees does the Mizzle logic provide?",{"text":84,"@type":76},"Mizzle is proven sound, meaning it never justifies false alarms, and complete, meaning every incorrect execution admits a derivation.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]