• Home
  • Search
  • Boosting SMT solver performance on mixed-bitwise-arithmetic expressions
  • Cite Icon19
  • https://doi.org/10.1145/3453483.3454068Copy DOI Icon

Boosting SMT solver performance on mixed-bitwise-arithmetic expressions

  • Jun 18, 2021
  • Dongpeng Xu +6 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Satisfiability Modulo Theories (SMT) solvers have been widely applied in automated software analysis to reason about the queries that encode the essence of program semantics, relieving the heavy burden of manual analysis. Many SMT solving techniques rely on solving Boolean satisfiability problem (SAT), which is an NP-complete problem, so they use heuristic search strategies to seek possible solutions, especially when no known theorem can efficiently reduce the problem. An emerging challenge, named Mixed-Bitwise-Arithmetic (MBA) obfuscation, impedes SMT solving by constructing identity equations with both bitwise operations (and, or, negate) and arithmetic computation (add, minus, multiply). Common math theorems for bitwise or arithmetic computation are inapplicable to simplifying MBA equations, leading to performance bottlenecks in SMT solving. In this paper, we first scrutinize solvers' performance on solving different categories of MBA expressions: linear, polynomial, and non-polynomial. We observe that solvers can handle simple linear MBA expressions, but facing a severe performance slowdown when solving complex linear and non-linear MBA expressions. The root cause is that complex MBA expressions break the reduction laws for pure arithmetic or bitwise computation. To boost solvers' performance, we propose a semantic-preserving transformation to reduce the mixing degree of bitwise and arithmetic operations. We first calculate a signature vector based on the truth table extracted from an MBA expression, which captures the complete MBA semantics. Next, we generate a simpler MBA expression from the signature vector. Our large-scale evaluation on 3000 complex MBA equations shows that our technique significantly boost modern SMT solvers' performance on solving MBA formulas.

Similar Papers
  • Dissertation
  • Citations7

Finite model finding in satisfiability modulo theories

  • Feb 05, 2014
  • Andrew Joseph Reynolds
  • Research Article
  • Citations3

Don’t care in SMT: building flexible yet efficient abstraction/refinement solvers

  • Nov 10, 2009
  • International Journal on Software Tools for Technology Transfer
  • Andreas Bauer +3
  • Research Article

Model Checking for Rectangular Hybrid Systems: A Quantified Encoding Approach

  • Jul 14, 2022
  • Electronic Proceedings in Theoretical Computer Science
  • Luan V Nguyen +2
  • Book Chapter
  • Citations1

SMT Solvers: Foundations and Applications

  • Jan 01, 2016
  • BjØRner Nikolaj
  • Research Article
  • Citations9

Local Search For Satisfiability Modulo Integer Arithmetic Theories

  • Jul 25, 2023
  • ACM Transactions on Computational Logic
  • Shaowei Cai +2
  • Research Article
  • Citations9

Extending ACL2 with SMT Solvers

  • Sep 18, 2015
  • Electronic Proceedings in Theoretical Computer Science
  • Yan Peng +1
  • Book Chapter
  • Citations19

BanditFuzz: A Reinforcement-Learning Based Performance Fuzzer for SMT Solvers

  • Jan 01, 2020
  • Joseph Scott +2
  • Book Chapter
  • Citations265

Efficient E-Matching for SMT Solvers

  • Jan 01, 2007
  • Leonardo De Moura +1
  • Book Chapter
  • Citations29

Combinations of Theories for Decidable Fragments of First-Order Logic

  • Jan 01, 2009
  • Pascal Fontaine
  • Conference Article
  • Citations5

Model Synthesis for Communication Traces of System Designs

  • Oct 01, 2021
  • Hao Zheng +4
  • Conference Article

Approximating Quantified SMT-Solving with SAT

  • Jun 01, 2011
  • Xianjin Fu +2
  • Conference Article
  • Citations7

SMT-based scheduling for multiprocessor real-time systems

  • Jun 01, 2016
  • Zhuo Cheng +3
  • Conference Article
  • Citations2

An SMT Approach to Bounded Model Checking of Design in State Transition Matrix

  • Jan 01, 2010
  • Weiqiang Kong +5
  • Book Chapter
  • Citations23

JavaSMT: A Unified Interface for SMT Solvers in Java

  • Jan 01, 2016
  • Egor George Karpenkov +2
  • Research Article
  • Citations23

Approximate counting in SMT and value estimation for probabilistic programs

  • Apr 12, 2017
  • Acta Informatica
  • Dmitry Chistikov +2
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.