{"id":"https://openalex.org/W7141636852","doi":"https://doi.org/10.48550/arxiv.2603.24595","title":"Model2Kernel: Model-Aware Symbolic Execution For Safe CUDA Kernels","display_name":"Model2Kernel: Model-Aware Symbolic Execution For Safe CUDA Kernels","publication_year":2026,"publication_date":"2026-03-06","ids":{"openalex":"https://openalex.org/W7141636852","doi":"https://doi.org/10.48550/arxiv.2603.24595"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2603.24595","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.24595","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2603.24595","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5130807622","display_name":"Mengting He","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"He, Mengting","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5053725485","display_name":"Shihao Xia","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Xia, Shihao","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5130767840","display_name":"Haomin Jia","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Jia, Haomin","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5130790800","display_name":"Wenfei Wu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wu, Wenfei","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5130742443","display_name":"Linhai Song","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Song, Linhai","raw_affiliation_strings":[],"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5130807622"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.7222999930381775,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.7222999930381775,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10054","display_name":"Parallel Computing and Optimization Techniques","score":0.06480000168085098,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.03269999846816063,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/cuda","display_name":"CUDA","score":0.8596000075340271},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.682200014591217},{"id":"https://openalex.org/keywords/kernel","display_name":"Kernel (algebra)","score":0.5527999997138977},{"id":"https://openalex.org/keywords/memory-model","display_name":"Memory model","score":0.33869999647140503},{"id":"https://openalex.org/keywords/thread","display_name":"Thread (computing)","score":0.3352000117301941},{"id":"https://openalex.org/keywords/memory-address","display_name":"Memory address","score":0.3328000009059906},{"id":"https://openalex.org/keywords/crash","display_name":"Crash","score":0.3215000033378601}],"concepts":[{"id":"https://openalex.org/C2778119891","wikidata":"https://www.wikidata.org/wiki/Q477690","display_name":"CUDA","level":2,"score":0.8596000075340271},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8223000168800354},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.682200014591217},{"id":"https://openalex.org/C74193536","wikidata":"https://www.wikidata.org/wiki/Q574844","display_name":"Kernel (algebra)","level":2,"score":0.5527999997138977},{"id":"https://openalex.org/C173608175","wikidata":"https://www.wikidata.org/wiki/Q232661","display_name":"Parallel computing","level":1,"score":0.4429999887943268},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.3919000029563904},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.37610000371932983},{"id":"https://openalex.org/C12186640","wikidata":"https://www.wikidata.org/wiki/Q6815743","display_name":"Memory model","level":3,"score":0.33869999647140503},{"id":"https://openalex.org/C138101251","wikidata":"https://www.wikidata.org/wiki/Q213092","display_name":"Thread (computing)","level":2,"score":0.3352000117301941},{"id":"https://openalex.org/C153247305","wikidata":"https://www.wikidata.org/wiki/Q835713","display_name":"Memory address","level":3,"score":0.3328000009059906},{"id":"https://openalex.org/C183469790","wikidata":"https://www.wikidata.org/wiki/Q333501","display_name":"Crash","level":2,"score":0.3215000033378601},{"id":"https://openalex.org/C50630238","wikidata":"https://www.wikidata.org/wiki/Q971505","display_name":"General-purpose computing on graphics processing units","level":3,"score":0.314300000667572},{"id":"https://openalex.org/C123657996","wikidata":"https://www.wikidata.org/wiki/Q12271","display_name":"Architecture","level":2,"score":0.3057999908924103},{"id":"https://openalex.org/C28180684","wikidata":"https://www.wikidata.org/wiki/Q4080983","display_name":"Memory safety","level":3,"score":0.28439998626708984},{"id":"https://openalex.org/C202491316","wikidata":"https://www.wikidata.org/wiki/Q272683","display_name":"Instruction set","level":2,"score":0.2816999852657318},{"id":"https://openalex.org/C2779639559","wikidata":"https://www.wikidata.org/wiki/Q7661178","display_name":"Symbolic execution","level":3,"score":0.28040000796318054},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.26930001378059387},{"id":"https://openalex.org/C97686452","wikidata":"https://www.wikidata.org/wiki/Q7604153","display_name":"Static analysis","level":2,"score":0.26269999146461487},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.26030001044273376},{"id":"https://openalex.org/C2777472644","wikidata":"https://www.wikidata.org/wiki/Q16968992","display_name":"Approximate inference","level":3,"score":0.2567000091075897}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2603.24595","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.24595","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2603.24595","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.24595","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[{"display_name":"Industry, innovation and infrastructure","score":0.6520966291427612,"id":"https://metadata.un.org/sdg/9"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"The":[0],"widespread":[1],"adoption":[2],"of":[3,15,111],"large":[4],"language":[5],"models":[6,181],"(LLMs)":[7],"has":[8],"made":[9],"GPU-accelerated":[10],"inference":[11,20,59,95],"a":[12],"critical":[13],"part":[14],"modern":[16],"computing":[17],"infrastructure.":[18],"Production":[19],"systems":[21],"rely":[22],"on":[23,70,177],"CUDA":[24,90,112,178],"kernels":[25,33,113,129,179],"to":[26,37,41,78,123,131,167],"implement":[27],"core":[28],"transformer":[29],"operations,":[30],"yet":[31],"these":[32],"are":[34],"highly":[35],"susceptible":[36],"memory-safety":[38],"bugs":[39,53,92,171,196],"due":[40],"model-dependent":[42],"tensor":[43,162],"layouts,":[44],"intricate":[45],"memory":[46,91,109,163,170],"indexing,":[47],"and":[48,85,130,164,180,186],"massive":[49],"thread-level":[50],"parallelism.":[51],"Such":[52],"can":[54,87],"corrupt":[55],"model":[56,127,140,145],"weights,":[57],"crash":[58],"services,":[60],"or":[61,76,142],"even":[62],"enable":[63],"adversarial":[64],"attacks.":[65],"Existing":[66],"techniques":[67],"either":[68,136],"depend":[69],"unavailable":[71],"hardware,":[72],"incur":[73],"high":[74],"overhead,":[75],"fail":[77],"handle":[79],"kernel":[80,133],"inputs":[81],"with":[82],"variable":[83],"lengths,":[84],"none":[86],"effectively":[88],"detect":[89],"in":[93,115,172],"LLM":[94,116,188],"systems.":[96],"This":[97],"paper":[98],"presents":[99],"Model2Kernel,":[100],"the":[101,108,139,175],"first":[102],"practical":[103],"system":[104],"for":[105,160],"automatically":[106],"verifying":[107],"safety":[110],"used":[114],"inference.":[117],"Model2Kernel":[118,150,191],"performs":[119],"model-aware":[120],"dynamic":[121,161],"analysis":[122],"determine":[124],"how":[125],"each":[126],"invokes":[128],"classify":[132],"arguments":[134],"as":[135],"fixed":[137],"by":[138,144,157],"architecture":[141],"controlled":[143],"users.":[146],"Using":[147],"this":[148],"information,":[149],"then":[151],"applies":[152],"CUDA-specialized":[153],"symbolic":[154],"execution,":[155],"supported":[156],"new":[158],"abstractions":[159],"thread":[165],"identifiers,":[166],"accurately":[168],"pinpoint":[169],"kernels.":[173],"In":[174],"evaluation":[176],"from":[182],"vLLM,":[183],"Hugging":[184],"Face,":[185],"recent":[187],"research":[189],"papers,":[190],"discovers":[192],"353":[193],"previously":[194],"unknown":[195],"while":[197],"producing":[198],"only":[199],"nine":[200],"false":[201],"positives,":[202],"demonstrating":[203],"its":[204],"effectiveness.":[205]},"counts_by_year":[],"updated_date":"2026-03-28T06:16:51.555046","created_date":"2026-03-28T00:00:00"}
