{"id":"https://openalex.org/W1592005626","doi":"https://doi.org/10.1109/syscon.2015.7116737","title":"Digital system robustness via design constraints: The lesson of formal methods","display_name":"Digital system robustness via design constraints: The lesson of formal methods","publication_year":2015,"publication_date":"2015-04-01","ids":{"openalex":"https://openalex.org/W1592005626","doi":"https://doi.org/10.1109/syscon.2015.7116737","mag":"1592005626"},"language":"en","primary_location":{"id":"doi:10.1109/syscon.2015.7116737","is_oa":false,"landing_page_url":"https://doi.org/10.1109/syscon.2015.7116737","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2015 Annual IEEE Systems Conference (SysCon) Proceedings","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://www.osti.gov/biblio/1242123","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5102487921","display_name":"Jackson R. Mayo","orcid":null},"institutions":[{"id":"https://openalex.org/I192454743","display_name":"Sandia National Laboratories California","ror":"https://ror.org/058m7ey48","country_code":"US","type":"facility","lineage":["https://openalex.org/I1330989302","https://openalex.org/I1330989302","https://openalex.org/I192454743","https://openalex.org/I198811213","https://openalex.org/I198811213","https://openalex.org/I4210104735"]},{"id":"https://openalex.org/I4210104735","display_name":"Sandia National Laboratories","ror":"https://ror.org/01apwpt12","country_code":"US","type":"facility","lineage":["https://openalex.org/I1330989302","https://openalex.org/I198811213","https://openalex.org/I4210104735"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Jackson R. Mayo","raw_affiliation_strings":["Sandia National Laboratories, California, USA","Sandia National Laboratories, P.O. Box 969, Livermore, California 94551-0969, USA"],"affiliations":[{"raw_affiliation_string":"Sandia National Laboratories, California, USA","institution_ids":["https://openalex.org/I4210104735","https://openalex.org/I192454743"]},{"raw_affiliation_string":"Sandia National Laboratories, P.O. Box 969, Livermore, California 94551-0969, USA","institution_ids":["https://openalex.org/I192454743"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5107252170","display_name":"Robert C. Armstrong","orcid":null},"institutions":[{"id":"https://openalex.org/I192454743","display_name":"Sandia National Laboratories California","ror":"https://ror.org/058m7ey48","country_code":"US","type":"facility","lineage":["https://openalex.org/I1330989302","https://openalex.org/I1330989302","https://openalex.org/I192454743","https://openalex.org/I198811213","https://openalex.org/I198811213","https://openalex.org/I4210104735"]},{"id":"https://openalex.org/I4210104735","display_name":"Sandia National Laboratories","ror":"https://ror.org/01apwpt12","country_code":"US","type":"facility","lineage":["https://openalex.org/I1330989302","https://openalex.org/I198811213","https://openalex.org/I4210104735"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Robert C. Armstrong","raw_affiliation_strings":["Sandia National Laboratories, California, USA","Sandia National Laboratories, P.O. Box 969, Livermore, California 94551-0969, USA"],"affiliations":[{"raw_affiliation_string":"Sandia National Laboratories, California, USA","institution_ids":["https://openalex.org/I4210104735","https://openalex.org/I192454743"]},{"raw_affiliation_string":"Sandia National Laboratories, P.O. Box 969, Livermore, California 94551-0969, USA","institution_ids":["https://openalex.org/I192454743"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5046715616","display_name":"Geoffrey C. Hulette","orcid":null},"institutions":[{"id":"https://openalex.org/I192454743","display_name":"Sandia National Laboratories California","ror":"https://ror.org/058m7ey48","country_code":"US","type":"facility","lineage":["https://openalex.org/I1330989302","https://openalex.org/I1330989302","https://openalex.org/I192454743","https://openalex.org/I198811213","https://openalex.org/I198811213","https://openalex.org/I4210104735"]},{"id":"https://openalex.org/I4210104735","display_name":"Sandia National Laboratories","ror":"https://ror.org/01apwpt12","country_code":"US","type":"facility","lineage":["https://openalex.org/I1330989302","https://openalex.org/I198811213","https://openalex.org/I4210104735"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Geoffrey C. Hulette","raw_affiliation_strings":["Sandia National Laboratories, California, USA","Sandia National Laboratories, P.O. Box 969, Livermore, California 94551-0969, USA"],"affiliations":[{"raw_affiliation_string":"Sandia National Laboratories, California, USA","institution_ids":["https://openalex.org/I4210104735","https://openalex.org/I192454743"]},{"raw_affiliation_string":"Sandia National Laboratories, P.O. Box 969, Livermore, California 94551-0969, USA","institution_ids":["https://openalex.org/I192454743"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5102487921"],"corresponding_institution_ids":["https://openalex.org/I192454743","https://openalex.org/I4210104735"],"apc_list":null,"apc_paid":null,"fwci":1.7865,"has_fulltext":false,"cited_by_count":6,"citation_normalized_percentile":{"value":0.88198813,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":95},"biblio":{"volume":null,"issue":null,"first_page":"109","last_page":"114"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9988999962806702,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9988999962806702,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9984999895095825,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10142","display_name":"Formal Methods in Verification","score":0.996399998664856,"subfield":{"id":"https://openalex.org/subfields/1703","display_name":"Computational Theory and Mathematics"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8372229337692261},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.5968109369277954},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.590194582939148},{"id":"https://openalex.org/keywords/correctness","display_name":"Correctness","score":0.5221055746078491},{"id":"https://openalex.org/keywords/formal-methods","display_name":"Formal methods","score":0.4694136083126068},{"id":"https://openalex.org/keywords/undecidable-problem","display_name":"Undecidable problem","score":0.4507465660572052},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.43740925192832947},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.4190866947174072},{"id":"https://openalex.org/keywords/formal-verification","display_name":"Formal verification","score":0.4120534360408783},{"id":"https://openalex.org/keywords/software-engineering","display_name":"Software engineering","score":0.3737374544143677}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8372229337692261},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.5968109369277954},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.590194582939148},{"id":"https://openalex.org/C55439883","wikidata":"https://www.wikidata.org/wiki/Q360812","display_name":"Correctness","level":2,"score":0.5221055746078491},{"id":"https://openalex.org/C75606506","wikidata":"https://www.wikidata.org/wiki/Q1049183","display_name":"Formal methods","level":2,"score":0.4694136083126068},{"id":"https://openalex.org/C192034797","wikidata":"https://www.wikidata.org/wiki/Q3502995","display_name":"Undecidable problem","level":3,"score":0.4507465660572052},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.43740925192832947},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.4190866947174072},{"id":"https://openalex.org/C111498074","wikidata":"https://www.wikidata.org/wiki/Q173326","display_name":"Formal verification","level":2,"score":0.4120534360408783},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.3737374544143677},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C153269930","wikidata":"https://www.wikidata.org/wiki/Q430001","display_name":"Decidability","level":2,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/syscon.2015.7116737","is_oa":false,"landing_page_url":"https://doi.org/10.1109/syscon.2015.7116737","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2015 Annual IEEE Systems Conference (SysCon) Proceedings","raw_type":"proceedings-article"},{"id":"pmh:oai:osti.gov:1242123","is_oa":true,"landing_page_url":"https://www.osti.gov/biblio/1242123","pdf_url":null,"source":{"id":"https://openalex.org/S4306402487","display_name":"OSTI OAI (U.S. Department of Energy Office of Scientific and Technical Information)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I139351228","host_organization_name":"Office of Scientific and Technical Information","host_organization_lineage":["https://openalex.org/I139351228"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":null}],"best_oa_location":{"id":"pmh:oai:osti.gov:1242123","is_oa":true,"landing_page_url":"https://www.osti.gov/biblio/1242123","pdf_url":null,"source":{"id":"https://openalex.org/S4306402487","display_name":"OSTI OAI (U.S. Department of Energy Office of Scientific and Technical Information)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I139351228","host_organization_name":"Office of Scientific and Technical Information","host_organization_lineage":["https://openalex.org/I139351228"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":null},"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.4000000059604645}],"awards":[],"funders":[{"id":"https://openalex.org/F4320306084","display_name":"U.S. Department of Energy","ror":"https://ror.org/01bj3aw27"},{"id":"https://openalex.org/F4320332369","display_name":"National Nuclear Security Administration","ror":"https://ror.org/03sk1we31"},{"id":"https://openalex.org/F4320338291","display_name":"Sandia National Laboratories","ror":"https://ror.org/01apwpt12"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":29,"referenced_works":["https://openalex.org/W144978143","https://openalex.org/W1489391022","https://openalex.org/W1535497513","https://openalex.org/W1976257927","https://openalex.org/W2002089154","https://openalex.org/W2006252547","https://openalex.org/W2014596857","https://openalex.org/W2023035194","https://openalex.org/W2031369606","https://openalex.org/W2040712458","https://openalex.org/W2042194938","https://openalex.org/W2072225385","https://openalex.org/W2073727600","https://openalex.org/W2080309973","https://openalex.org/W2081609411","https://openalex.org/W2085692149","https://openalex.org/W2098456636","https://openalex.org/W2108020239","https://openalex.org/W2115908980","https://openalex.org/W2142958724","https://openalex.org/W2150189917","https://openalex.org/W2167029843","https://openalex.org/W2168115971","https://openalex.org/W2187335384","https://openalex.org/W4248229502","https://openalex.org/W4252948584","https://openalex.org/W4285719527","https://openalex.org/W6605896072","https://openalex.org/W6686760270"],"related_works":["https://openalex.org/W2111870610","https://openalex.org/W1937494301","https://openalex.org/W161255303","https://openalex.org/W1544097700","https://openalex.org/W1488573418","https://openalex.org/W2152752131","https://openalex.org/W1922520186","https://openalex.org/W1946493810","https://openalex.org/W2145025660","https://openalex.org/W1994222400"],"abstract_inverted_index":{"Current":[0],"programming":[1,4,150,191],"languages":[2,194],"and":[3,12,29,33,99,167,193],"models":[5,120,192],"make":[6,37],"it":[7],"easy":[8],"to":[9,26,122,165,189,203],"create":[10],"software":[11],"hardware":[13],"systems":[14,24,38,51],"that":[15,68,171,183,195,205],"fulfill":[16],"an":[17,58,148,177],"intended":[18],"function":[19,28],"but":[20,41],"also":[21],"leave":[22],"such":[23],"open":[25],"unintended":[27],"vulnerabilities.":[30],"Software":[31],"engineering":[32],"code":[34,82],"hygiene":[35],"may":[36],"incrementally":[39],"safer,":[40],"do":[42],"not":[43],"produce":[44,123],"the":[45,53,85,136,153],"wholesale":[46],"change":[47],"necessary":[48],"for":[49],"secure":[50],"from":[52],"outset.":[54],"Yet":[55],"there":[56],"exists":[57],"approach":[59],"with":[60,72,147,173],"impressive":[61],"results:":[62],"We":[63,169,186],"cite":[64],"recent":[65],"examples":[66],"showing":[67],"formal":[69,119,174],"methods,":[70],"coupled":[71],"formally":[73],"informed":[74],"digital":[75,133],"design,":[76],"have":[77,160],"produced":[78],"objectively":[79],"more":[80],"robust":[81],"even":[83],"beyond":[84],"properties":[86],"directly":[87],"proven.":[88],"Though":[89],"discovery":[90],"of":[91,111,125,155,162,179],"zero-day":[92],"vulnerabilities":[93,112],"is":[94,138,176],"almost":[95],"always":[96],"a":[97,107,114,126,140],"surprise":[98],"powerful":[100],"tools":[101],"like":[102],"semantic":[103],"fuzzers":[104],"can":[105,116,196],"cover":[106],"larger":[108],"search":[109],"space":[110],"than":[113,130],"developer":[115],"conceive":[117],"of,":[118],"seem":[121],"robustness":[124],"higher":[127],"qualitative":[128,141],"order":[129],"traditionally":[131],"developed":[132],"systems.":[134],"Because":[135],"claim":[137],"necessarily":[139],"one,":[142],"we":[143,159],"illustrate":[144],"similar":[145],"results":[146],"idealized":[149],"language":[151],"in":[152,201],"form":[154],"Boolean":[156],"networks":[157],"where":[158],"control":[161],"parameters":[163],"related":[164],"stability":[166],"adaptability.":[168],"argue":[170],"verifiability":[172],"methods":[175],"instance":[178],"broader":[180],"design":[181],"constraints":[182],"promote":[184],"robustness.":[185],"draw":[187],"analogies":[188],"real-world":[190],"be":[197],"mathematically":[198],"reasoned":[199],"about":[200],"contrast":[202],"ones":[204],"are":[206],"essentially":[207],"undecidable.":[208]},"counts_by_year":[{"year":2025,"cited_by_count":1},{"year":2022,"cited_by_count":1},{"year":2018,"cited_by_count":1},{"year":2017,"cited_by_count":1},{"year":2016,"cited_by_count":1},{"year":2015,"cited_by_count":1}],"updated_date":"2026-03-20T23:20:44.827607","created_date":"2025-10-10T00:00:00"}
