[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83587-en":3,"doc-seo-83587-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83587,8796095360427,"Lucas Martin","https://ap-avatar.wpscdn.com/davatar_994ba38a5ba835b3df7d355c54d3ed8d",8,"Research & Report","Trustworthy Runtime Verification via Bisimulation (Extended Experience Report)","Runtime verification monitors safety-critical cyber-physical systems, making correctness of the generated monitoring code essential. Copilot automatically produces C monitor programs from a high-level Haskell-embedded DSL, yet auditors must be confident that compiled monitors neither crash unexpectedly nor implement the intended Copilot semantics. CopilotVerifier runs with the compiler to generate machine-checked proof that the Copilot monitor and compiled code are equivalent and fail identically, using bisimulation-based verification conditions and SMT-backed tooling with moderate cost.","arXiv :2607 .0 1363v 1 [ cs .PL] 1 Jul 2026  \nTrustworthy Runtime Verification via Bisimulation  \n(Extended Experience Report)  \nRYAN G . SCOTT  \nGalois, Inc., USA  \n(email: [rscott@galois.com](rscott@galois.com))  \nIVAN PEREZ  \nKBR @ NASA Ames Research Center, USA  \n(email: [ivan.perezdominguez@nasa.gov](ivan.perezdominguez@nasa.gov))  \nALWY N E . GOOD LOE  \nNASA Langley Research Center, USA  \n([email:](email: a.goodloe@nasa.gov)[ a.goodloe@nasa.gov](email: a.goodloe@nasa.gov))  \nMIKE DODDS  \nGalois, Inc., USA  \n([email:](email: miked@galois.com)[ miked@galois.com](email: miked@galois.com))  \nROBERT DOCK INS∗  \nAmazon, USA  \n(email: [rdoc@amazon.com](rdoc@amazon.com))  \nAbstract  \nWhen runtime verification is used to monitor safety-critical systems, it is essential that monitoring code behaves correctly. The Copilot runtime verification framework pursues this goal by automatically generating C monitor programs from a high-level DSL embedded in Haskell. In safety-critical domains, every piece of deployed code must be accompanied by an assurance argument that is convincing to human auditors. However, it is difficult for auditors to determine with confidence that a compiled monitor cannot crash and implements the behavior required by the Copilot semantics.  \nIn this paper we describe CopilotVerifier, which runs alongside the Copilot compiler, generating a proof of correctness for the compiled output. The proof establishes that a given Copilot monitor and its compiled form produce equivalent outputs on equivalent inputs, and that they either crash in identical circumstances or cannot crash. The proof takes the form of a bisimulation broken down into a set of verification conditions. We leverage two pieces of SMT-backed technology: the Crucible symbolic execution library for LLVM and the What4 solver interface library. Our results demonstrate that dramatically increased compiler assurance can be achieved at moderate cost by building on existing tools. This paves the way to our ultimate goal of generating formal assurance arguments that are convincing to human auditors.  \n1 Introduction  \nSafety-critical cyber-physical systems (CPSs) are subject to strict regulation to ensure public safety. Historically, such systems are constructed using conservative requirements-driven practices, yielding predictable systems that are amenable to verification by testing [66, 68] .  \n∗Author’s paper contributions were made while working at Galois, Inc.  \n© 2025 Copyright held by the owner/author(s) .  \nThis work is licensed under a Creative Commons Attribution 4 .0 International License.  \nDRAFT PAPER UNDER REVIEW  \n2 Ryan G. Scott, Ivan Perez, Alwyn E. Goodloe, Mike Dodds, and Robert Dockins  \nThere is increasingly a desire to use off-the-shelf components and employ techniques like machine learning to build autonomous systems, but these cannot be assured using traditional approaches [18, 19, 21, 51] .  \nRuntime verification (RV) [27, 40] addresses this problem by monitoring a system under observation and responding to property violations during the mission. For example, an RV system might monitor engine heat levels, aircraft location within an authorized airspace, or autopilot changes between flight modes. While not static formal verification, RV provides a significant improvement in assurance for systems over testing alone.  \nCopilot [58, 60, 62] is a language and toolchain for writing RV monitors. Monitors are written in a high-level, stream-based domain-specific language (DSL) that is embedded in Haskell. Copilot is equipped with a compiler that generates C code, which can then be linked against other application code for use in production. Among others, Copilot is used at NASA to write both programs and runtime monitors for experimental vehicles (e.g., drones, rovers) .  \nWhen used in safety-critical applications, Copilot monitors also form part of the safety case that justifies the system’s mission readiness. As a result, monitors must be tru","cbCaijft1iP1Jjb4","https://ap.wps.com/l/cbCaijft1iP1Jjb4","pdf",499772,5,1,31,"English","en",105,"# Abstract\n# Introduction\n## Safety-critical CPS and runtime verification\n## Copilot and monitor compilation\n## Verification approaches\n## CopilotVerifier contributions","[{\"question\":\"What problem does CopilotVerifier address in runtime verification?\",\"answer\":\"It addresses the challenge of producing convincing evidence that a compiled Copilot monitor is correct—specifically that it implements the intended semantics and does not crash unexpectedly.\"},{\"question\":\"How does CopilotVerifier verify correctness?\",\"answer\":\"It runs alongside the Copilot compiler and generates a correctness proof by establishing bisimulation-based equivalence between the Copilot monitor and the compiled C output.\"},{\"question\":\"Which tools support the proof construction in CopilotVerifier?\",\"answer\":\"The proof leverages the Crucible symbolic execution library for LLVM and the What4 solver interface library backed by SMT.\"}]",1784189029,78,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"trustworthy-runtime-verification-via-bisimulation-extended-experience-report","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/trustworthy-runtime-verification-via-bisimulation-extended-experience-report/83587/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-07-27","2026-07-16",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What problem does CopilotVerifier address in runtime verification?","Question",{"text":76,"@type":77},"It addresses the challenge of producing convincing evidence that a compiled Copilot monitor is correct—specifically that it implements the intended semantics and does not crash unexpectedly.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How does CopilotVerifier verify correctness?",{"text":81,"@type":77},"It runs alongside the Copilot compiler and generates a correctness proof by establishing bisimulation-based equivalence between the Copilot monitor and the compiled C output.",{"name":83,"@type":74,"acceptedAnswer":84},"Which tools support the proof construction in CopilotVerifier?",{"text":85,"@type":77},"The proof leverages the Crucible symbolic execution library for LLVM and the What4 solver interface library backed by SMT.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":20,"slug":138},19,"General","general"]