<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE raweb PUBLIC "-//INRIA//DTD " "raweb2.dtd">
<raweb xml:lang="en" year="2011">
  <identification id="abstraction" isproject="true">
    <shortname>ABSTRACTION</shortname>
    <projectName>Abstract Interpretation and Static Analysis</projectName>
    <theme-de-recherche>Programs, Verification and Proofs</theme-de-recherche>
    <domaine-de-recherche>Algorithmics, Programming, Software and Architecture</domaine-de-recherche>
    <structure_exterieure type="Labs">
      <libelle>Laboratoire d'Informatique de l'Ecole Normale Supérieure (LIENS)</libelle>
    </structure_exterieure>
    <structure_exterieure type="Organism">
      <libelle>CNRS</libelle>
    </structure_exterieure>
    <structure_exterieure type="Organism">
      <libelle>Ecole normale supérieure de Paris</libelle>
    </structure_exterieure>
    <UR name="Rocquencourt"/>
    <keywords>
      <term>Abstract Interpretation</term>
      <term>Formal Methods</term>
      <term>Proofs Of Programs</term>
      <term>Safety</term>
      <term>Semantics</term>
      <term>Static Analysis</term>
    </keywords>
    <moreinfo>
      <p><span class="smallcap" align="left">Abstraction</span>is located at the École normale supérieure, Paris.</p>
    </moreinfo>
  </identification>
  <team id="uid1">
    <person key="abstraction-2007-idm495957196928">
      <firstname>Julien</firstname>
      <lastname>Bertrane</lastname>
      <affiliation>AutreEtablissementPublic</affiliation>
      <categoryPro>Enseignant</categoryPro>
      <research-centre>Rocquencourt</research-centre>
      <moreinfo>— Aug. 2011</moreinfo>
    </person>
    <person key="abstraction-2010-idm79647385984">
      <firstname>Mehdi</firstname>
      <lastname>Bouaziz</lastname>
      <affiliation>AutreEtablissementPublic</affiliation>
      <categoryPro>PhD</categoryPro>
      <research-centre>Rocquencourt</research-centre>
      <moreinfo>Nov. 2011 —</moreinfo>
    </person>
    <person key="abstraction-2007-idm495957179744">
      <firstname>Ferdinanda</firstname>
      <lastname>Camporesi</lastname>
      <affiliation>AutreEtablissementPublic</affiliation>
      <categoryPro>PhD</categoryPro>
      <research-centre>Rocquencourt</research-centre>
    </person>
    <person key="abstraction-2007-idm495957220928">
      <firstname>Patrick</firstname>
      <lastname>Cousot</lastname>
      <affiliation>AutreEtablissementPublic</affiliation>
      <categoryPro>Enseignant</categoryPro>
      <research-centre>Rocquencourt</research-centre>
      <moreinfo>Team leader, Professor, ENS</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="abstraction-2007-idm495957213728">
      <firstname>Radhia</firstname>
      <lastname>Cousot</lastname>
      <affiliation>CNRS</affiliation>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Rocquencourt</research-centre>
      <moreinfo>Senior Researcher, CNRS</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="abstraction-2011-idm355312809568">
      <firstname>David</firstname>
      <lastname>Delmas</lastname>
      <affiliation>EtablissementPrive</affiliation>
      <categoryPro>Visiteur</categoryPro>
      <research-centre>Rocquencourt</research-centre>
      <moreinfo>Sep. 2011 —</moreinfo>
    </person>
    <person key="abstraction-2007-idm495957193264">
      <firstname>Jérôme</firstname>
      <lastname>Feret</lastname>
      <affiliation>INRIA</affiliation>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Rocquencourt</research-centre>
      <moreinfo>Junior Researcher, INRIA Paris–Rocquencourt</moreinfo>
    </person>
    <person key="abstraction-2011-idm355312803328">
      <firstname>Jonathan</firstname>
      <lastname>Hayman</lastname>
      <affiliation>INRIA</affiliation>
      <categoryPro>PostDoc</categoryPro>
      <research-centre>Rocquencourt</research-centre>
      <moreinfo>Nov. 2011 —</moreinfo>
    </person>
    <person key="abstraction-2007-idm495957183424">
      <firstname>Joëlle</firstname>
      <lastname>Isnard</lastname>
      <affiliation>CNRS</affiliation>
      <categoryPro>Assistant</categoryPro>
      <research-centre>Rocquencourt</research-centre>
      <moreinfo>Administrative Head DI, ENS</moreinfo>
    </person>
    <person key="abstraction-2009-idm361193211584">
      <firstname>Vincent</firstname>
      <lastname>Laviron</lastname>
      <affiliation>AutreEtablissementPublic</affiliation>
      <categoryPro>PhD</categoryPro>
      <research-centre>Rocquencourt</research-centre>
    </person>
    <person key="abstraction-2011-idm355312794608">
      <firstname>Marine</firstname>
      <lastname>Meyer</lastname>
      <affiliation>INRIA</affiliation>
      <categoryPro>Assistant</categoryPro>
      <research-centre>Rocquencourt</research-centre>
      <moreinfo>INRIA, Apr. 2011 —</moreinfo>
    </person>
    <person key="abstraction-2007-idm495957206736">
      <firstname>Antoine</firstname>
      <lastname>Miné</lastname>
      <affiliation>CNRS</affiliation>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Rocquencourt</research-centre>
      <moreinfo>Junior Researcher, CNRS</moreinfo>
    </person>
    <person key="gallium-2007-idm352520382384">
      <firstname>Tahina</firstname>
      <lastname>Ramananandro</lastname>
      <affiliation>AutreEtablissementPublic</affiliation>
      <categoryPro>PostDoc</categoryPro>
      <research-centre>Rocquencourt</research-centre>
      <moreinfo>Sep. 2011 —</moreinfo>
    </person>
    <person key="abstraction-2007-idm495957200624">
      <firstname>Xavier</firstname>
      <lastname>Rival</lastname>
      <affiliation>INRIA</affiliation>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Rocquencourt</research-centre>
      <moreinfo>Junior Researcher, INRIA Paris–Rocquencourt</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="abstraction-2011-idm355312781872">
      <firstname>Alessandro</firstname>
      <lastname>Romanel</lastname>
      <affiliation>INRIA</affiliation>
      <categoryPro>PostDoc</categoryPro>
      <research-centre>Rocquencourt</research-centre>
      <moreinfo>Jan. 2011 — Nov. 2011</moreinfo>
    </person>
    <person key="lande-2006-idm546825703360">
      <firstname>Pascal</firstname>
      <lastname>Sotin</lastname>
      <affiliation>AutreEtablissementPublic</affiliation>
      <categoryPro>PostDoc</categoryPro>
      <research-centre>Rocquencourt</research-centre>
      <moreinfo>Oct. 2011 —</moreinfo>
    </person>
    <person key="abstraction-2011-idm355312775728">
      <firstname>Cheng</firstname>
      <lastname>Tie</lastname>
      <affiliation>AutreEtablissementPublic</affiliation>
      <categoryPro>PhD</categoryPro>
      <research-centre>Rocquencourt</research-centre>
      <moreinfo>Oct. 2011 —</moreinfo>
    </person>
    <person key="abstraction-2011-idm355312772656">
      <firstname>Antoine</firstname>
      <lastname>Toubhans</lastname>
      <affiliation>AutreEtablissementPublic</affiliation>
      <categoryPro>PhD</categoryPro>
      <research-centre>Rocquencourt</research-centre>
      <moreinfo>Sep. 2011 —</moreinfo>
    </person>
    <person key="abstraction-2011-idm355312769600">
      <firstname>Caterina</firstname>
      <lastname>Urban</lastname>
      <affiliation>AutreEtablissementPublic</affiliation>
      <categoryPro>PhD</categoryPro>
      <research-centre>Rocquencourt</research-centre>
      <moreinfo>Dec. 2011 —</moreinfo>
    </person>
    <person key="abstraction-2011-idm355312766544">
      <firstname>Yanjun</firstname>
      <lastname>Wen</lastname>
      <affiliation>AutreEtablissementPublic</affiliation>
      <categoryPro>Visiteur</categoryPro>
      <research-centre>Rocquencourt</research-centre>
      <moreinfo>Jun. 2011 —</moreinfo>
    </person>
    <person key="abstraction-2009-idm361193205440">
      <firstname>Matteo</firstname>
      <lastname>Zanioli</lastname>
      <affiliation>AutreEtablissementPublic</affiliation>
      <categoryPro>PhD</categoryPro>
      <research-centre>Rocquencourt</research-centre>
    </person>
  </team>
  <presentation id="uid2">
    <bodyTitle>Overall Objectives</bodyTitle>
    <subsection id="uid3" level="1">
      <bodyTitle>Overall Objectives</bodyTitle>
      <p>Software has known a spectacular development this last decade both in its scope of applicability and its size. Nevertheless, software design, development and engineering methods remain
      mostly manual, hence error-prone. It follows that complex software-based systems are unsafe and insecure, which is not acceptable in safety-critical or mission-critical applications.
      Intellectual and computer-based tools must therefore be developed to cope with the safety and security problems.</p>
      <p>The notions of 
      <i>abstraction</i>and 
      <i>approximation</i>, as formalized by the 
      <i>abstract interpretation theory</i>, are fundamental to design, model, develop, analyze, and verify highly complex systems, from computer-based to biological ones. They also underlie the
      design of safety and security verification 
      <i>tools</i>.</p>
    </subsection>
    <subsection id="uid4" level="1">
      <bodyTitle>Highlights</bodyTitle>
      <p>The paper “Static Analysis and Verification of Aerospace Software by Abstract Interpretation”, written by the team 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid0" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, has been selected in 2011 by the AIAA Intelligent Systems
      Technical Committee as the Best Paper from the AIAA 2010 Infotech@Aerospace Conference.</p>
      <p>The MemCAD ERC Starting Grant (“Memory Compositional Abstract Domains”) was started on October, 1st. 2011 (funded by the European Research Counsil “IDEAS” programme).</p>
    </subsection>
  </presentation>
  <fondements id="uid5">
    <bodyTitle>Scientific Foundations</bodyTitle>
    <subsection id="uid6" level="1">
      <bodyTitle>Abstract Interpretation Theory</bodyTitle>
      <p>The abstract interpretation theory 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid1" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid2" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid3" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, is the main scientific foundation of the work of the 
      <span class="smallcap" align="left">Abstraction</span>project-team. Its main current application is on the safety and security of complex hardware and software computer systems either
      sequential 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid1" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid4" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, or parallel 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid5" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>with shared memory 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid6" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid7" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid8" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>or synchronous message 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid9" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>communication.</p>
      <p>Abstract interpretation is a theory of sound approximation of mathematical structures, in particular those involved in the behavior of computer systems. It allows the systematic derivation
      of sound methods and algorithms for approximating undecidable or highly complex problems in various areas of computer science (semantics, verification and proof, model-checking, static
      analysis, program transformation and optimization, typing, software steganography, etc...) and system biology (pathways analysis).</p>
    </subsection>
    <subsection id="uid7" level="1">
      <bodyTitle>Formal Verification by Abstract Interpretation</bodyTitle>
      <p>The 
      <i>formal verification</i>of a program (and more generally a computer system) consists in proving that its 
      <i>semantics</i>(describing “what the program executions actually do”) satisfies its 
      <i>specification</i>(describing “what the program executions are supposed to do”).</p>
      <p><i>Abstract interpretation</i>formalizes the idea that this formal proof can be done at some level of abstraction where irrelevant details about the semantics and the specification are ignored.
      This amounts to proving that an 
      <i>abstract semantics</i>satisfies an 
      <i>abstract specification</i>. An example of abstract semantics is Hoare logic while examples of abstract specifications are invariance, partial, or total correctness. These examples abstract
      away from concrete properties such as execution times.</p>
      <p>Abstractions should preferably be 
      <i>sound</i>(no conclusion derived from the abstract semantics is wrong with respect to the program concrete semantics and specification). Otherwise stated, a proof that the abstract semantics
      satisfies the abstract specification should imply that the concrete semantics also satisfies the concrete specification. Hoare logic is a sound verification method, debugging is not (since some
      executions are left out), bounded model checking is not either (since parts of some executions are left out). Unsound abstractions lead to 
      <i>false negatives</i>(the program may be claimed to be correct/non erroneous with respect to the specification whereas it is in fact incorrect). Abstract interpretation can be used to design
      sound semantics and formal verification methods (thus eliminating all false negatives).</p>
      <p>Abstractions should also preferably be 
      <i>complete</i>(no aspect of the semantics relevant to the specification is left out). So if the concrete semantics satisfies the concrete specification this should be provable in the abstract.
      However program proofs (for non-trivial program properties such as safety, liveness, or security) are undecidable. Nevertheless, we can design tools that address undecidable problems by
      allowing the tool not to terminate, to be driven by human intervention, to be unsound (e.g. debugging tools omit possible executions), or to be incomplete (e.g. static analysis tools
      may produce false alarms). Incomplete abstractions lead to 
      <i>false positives</i>or 
      <i>false alarms</i>(the specification is claimed to be potentially violated by some program executions while it is not). Semantics and formal verification methods designed by abstract
      interpretation may be complete (e.g.  
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid10" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid11" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid12" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>) or incomplete (e.g. 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid13" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>).</p>
      <p>Sound, automatic, terminating and precise tools are difficult to design. Complete automatic tools to solve non-trivial verification problems cannot exist, by undecidability. However static
      analysis tools producing very few or no false alarms have been designed and used in industrial contexts for specific families of properties and programs 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid14" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. In all cases, abstract interpretation provides a systematic
      construction method based on the effective approximation of the concrete semantics, which can be (partly) automated and/or formally verified.</p>
      <p>Abstract interpretation aims at:</p>
      <simplelist>
        <li id="uid8">
          <p noindent="true">providing a basic coherent and conceptual theory for understanding in a unified framework the multiplicity of ideas, concepts, reasonings, methods, and tools on formal
          program analysis and verification 
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid1" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid3" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>;</p>
        </li>
        <li id="uid9">
          <p noindent="true">guiding the correct formal design of 
          <i>abstract semantics</i>
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid11" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid12" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>and automatic tools for 
          <i>program analysis</i>(computing an abstract semantics) and 
          <i>program verification</i>(proving that an abstract semantics satisfies an abstract specification) 
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid15" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        </li>
      </simplelist>
      <p>Abstract interpretation theory studies semantics (formal models of computer systems), abstractions, their soundness, and completeness.</p>
      <p>In practice, abstract interpretation is used to design analysis, compilation, optimization, and verification tools which must automatically and statically determine properties about the
      runtime behavior of programs. For example the 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>static analyzer (Section 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#uid19" location="intern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>), which was developed by the team over the last decade, aims at proving the
      absence of runtime errors in programs written in the C programming language. It was originally used in the aerospace industry to verify very large, synchronous, time-triggered, real-time,
      safety-critical, embedded software and its scope of application was later broadly widened. 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>is now industrialized by 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.absint.com/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">AbsInt Angewandte Informatik GmbH</ref>and is 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.absint.com/astree/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">commercially available</ref>.</p>
    </subsection>
    <subsection id="uid10" level="1">
      <bodyTitle>Advanced Introductions to Abstract Interpretation</bodyTitle>
      <p>A recent, short, informal, and intuitive introduction to the theory of abstract interpretation can be found in 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid15" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, see also “
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.di.ens.fr/~cousot/AI/IntroAbsInt.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">Abstract</ref>
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.di.ens.fr/~cousot/AI/IntroAbsInt.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">Interpretation</ref>
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.di.ens.fr/~cousot/AI/IntroAbsInt.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">in</ref>
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.di.ens.fr/~cousot/AI/IntroAbsInt.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">a</ref>
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.di.ens.fr/~cousot/AI/IntroAbsInt.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">Nutshell</ref>” 
      <footnote id="uid11" id-text="1"><ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.di.ens.fr/~cousot/AI/IntroAbsInt.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"> www.
        <allowbreak/>di.
        <allowbreak/>ens.
        <allowbreak/>fr/
        <allowbreak/>~cousot/
        <allowbreak/>AI/
        <allowbreak/>IntroAbsInt.
        <allowbreak/>html</ref></footnote>on the web. A more comprehensive introduction is available 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.di.ens.fr/~cousot/AI/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">online</ref> 
      <footnote id="uid12" id-text="2"><ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.di.ens.fr/~cousot/AI/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"> www.
        <allowbreak/>di.
        <allowbreak/>ens.
        <allowbreak/>fr/
        <allowbreak/>~cousot/
        <allowbreak/>AI/
        <allowbreak/></ref></footnote>. The paper entitled “
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.di.ens.fr/~cousot/COUSOTpapers/WCC04.shtml" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">Basic</ref>
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.di.ens.fr/~cousot/COUSOTpapers/WCC04.shtml" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">concepts</ref>
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.di.ens.fr/~cousot/COUSOTpapers/WCC04.shtml" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">of</ref>
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.di.ens.fr/~cousot/COUSOTpapers/WCC04.shtml" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">abstract</ref>
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.di.ens.fr/~cousot/COUSOTpapers/WCC04.shtml" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">interpretation</ref>” 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid16" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>and an elementary “
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://web.mit.edu/afs/athena.mit.edu/course/16/16.399/www/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">course</ref>
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://web.mit.edu/afs/athena.mit.edu/course/16/16.399/www/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">on</ref>
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://web.mit.edu/afs/athena.mit.edu/course/16/16.399/www/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">abstract
      interpretation</ref>” 
      <footnote id="uid13" id-text="3"><ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://web.mit.edu/afs/athena.mit.edu/course/16/16.399/www/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"> web.
        <allowbreak/>mit.
        <allowbreak/>edu/
        <allowbreak/>afs/
        <allowbreak/>athena.
        <allowbreak/>mit.
        <allowbreak/>edu/
        <allowbreak/>course/
        <allowbreak/>16/
        <allowbreak/>16.
        <allowbreak/>399/
        <allowbreak/>www/
        <allowbreak/></ref></footnote>can also be found on the web.</p>
    </subsection>
  </fondements>
  <domaine id="uid14">
    <bodyTitle>Application Domains</bodyTitle>
    <subsection id="uid15" level="1">
      <bodyTitle>Certification of Safety Critical Software</bodyTitle>
      <p/>
      <p>Safety critical software may incur great damage in case of failure, such as human casualties or huge financial losses. These include many kinds of embedded software, such as fly-by-wire
      programs in aircrafts and other avionic applications, control systems for nuclear power plants, or navigation systems of satellite launchers. For instance, the failure of the first launch of
      Ariane 5 (flight Ariane 501) was due to overflows in arithmetic computations. This failure caused the loss of several satellites, worth up to $ 500 millions.</p>
      <p>This development of safe and secure critical software requires formal methods so as to ensure that they do not go wrong, and will behave as specified. In particular, testing, bug finding
      methods, checking of models but not programs do not provide any guarantee that no failure will occur, even of a given type such as runtime errors; therefore, their scope is limited for
      certification purposes. For instance, testing can usually not be performed for 
      <i>all</i>possible inputs due to feasibility and cost reasons, so that it does not prove anything about a large number of possible executions.</p>
      <p>By contrast, program analysis methods such as abstract-interpretation-based static analysis are not subject to unsoundness, since they can 
      <i>formally prove</i>the absence of bugs directly on the program, not on a model that might be erroneous. Yet, these techniques are generally incomplete since the absence of runtime errors is
      undecidable. Therefore, in practice, they are prone to false alarms (
      <i>i.e.</i>, they may fail to prove the absence of runtime errors for a program which is safe). The objective of certification is to ultimately eliminate all false alarms.</p>
      <p>It should be noted that, due to the size of the critical codes (typically from 100 to 1000 kLOCs), only scalable methods can succeed (in particular, software model checking techniques are
      subject to state explosion issues). As a consequence, this domain requires efficient static analyses, where costly abstractions should be used only parsimoniously.</p>
      <p>Furthermore, many families of critical software have similar features, such as the reliance on floating-point intensive computations for the implementation of control laws, including linear
      and non-linear control with feedback, interpolations, and other DSP algorithms. Since we stated that a proof of absence of runtime errors is required, very precise analyses are required, which
      should be able to yield no false alarm on wide families of critical applications. To achieve that goal, significant advantages can be found in the design of domain specific analyzers, such as 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid17" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid18" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, which has been initially designed specifically for synchronous
      embedded software.</p>
      <p>Last, some specific critical software qualification procedures may require additional properties being proved. As an example, the DO-178 regulations (which apply to avionics software)
      require a tight, documented, and certified relation to be established between each development stage. In particular, compilation of high level programs into executable binaries should also be
      certified correct.</p>
      <p>The 
      <span class="smallcap" align="left">Abstraction</span>project-team has been working on both proof of absence of runtime errors and certified compilation over the decade, using abstract
      interpretation techniques. Successful results have been achieved on industrial applications using the 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>analyzer. Following this success, 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>has been licensed to 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.absint.com/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">AbsInt Angewandte Informatik GmbH</ref>to be industrialized, and
      the 
      <span class="smallcap" align="left">Abstraction</span>project-team has strong plans to continue research on this topic.</p>
    </subsection>
    <subsection id="uid16" level="1">
      <bodyTitle>Abstraction of Biological Cell Signaling Networks</bodyTitle>
      <p/>
      <p>Protein-protein interactions consist in complexations and post translational modifications such as phosphorilation. These interactions enable biological organisms to receive, propagate, and
      integrate signals that are expressed as proteins concentrations in order to make decisions (on the choice between cell division and cell death for instance). Models of such interaction networks
      suffer from a combinatorial blow up in the number of species (number of non-isomorphic ways in which some proteins can be connected to each others). This large number of species makes the
      design and the analysis of these models a highly difficult task. Moreover the properties of interest are usually quantitative observations on stochastic or differential trajectories, which are
      difficult to compute or abstract.</p>
      <p>Contextual graph-rewriting systems allow a concise description of these networks, which leads to a scalable method for modeling them. Then abstract interpretation allows the abstraction of
      these systems properties. First qualitative abstractions (such as over approximation of complexes that can be built) provide both debugging information in the design phases (of models) and
      static information that are necessary in order to make other computations (such as stochastic simulations) scale up. Then qualitative invariants also drive efficient quantitative abstractions
      (such as the reduction of ordinary differential semantics).</p>
      <p>The work of the 
      <span class="smallcap" align="left">Abstraction</span>project-team on biological cell signaling networks ranges from qualitative abstractions to quantitative abstractions.</p>
    </subsection>
  </domaine>
  <logiciels id="uid17">
    <bodyTitle>Software</bodyTitle>
    <subsection id="uid18" level="1">
      <bodyTitle>The 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://apron.cri.ensmp.fr/library/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Apron</span></ref>Numerical Abstract Domain Library</bodyTitle>
      <participants>
        <person key="abstraction-2007-idm495957206736">
          <firstname>Antoine</firstname>
          <lastname>Miné</lastname>
          <moreinfo>correspondent</moreinfo>
        </person>
        <person key="PASUSERID">
          <firstname>Bertrand</firstname>
          <lastname>Jeannet</lastname>
          <moreinfo>team PopArt, INRIA-RA</moreinfo>
        </person>
      </participants>
      <p/>
      <p>The 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://apron.cri.ensmp.fr/library/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Apron</span></ref>library is dedicated to the static analysis of the numerical variables of a program by abstract interpretation. Its goal is threefold: provide ready-to-use numerical abstractions under a
      common API for analysis implementers, encourage the research in numerical abstract domains by providing a platform for integration and comparison of domains, and provide a teaching and
      demonstration tool to disseminate knowledge on abstract interpretation.</p>
      <p>The 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://apron.cri.ensmp.fr/library/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Apron</span></ref>library is not tied to a particular numerical abstraction but instead provides several domains with various precision versus cost trade-offs (including intervals, octagons, linear
      equalities and polyhedra). A specific C API was designed for domain developers to minimize the effort when incorporating a new abstract domain: only few domain-specific functions need to be
      implemented while the library provides various generic services and fallback methods (such as scalar and interval operations for most numerical data-types, parametric reduced products, and
      generic transfer functions for non-linear expressions). For the analysis designer, the 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://apron.cri.ensmp.fr/library/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Apron</span></ref>library exposes a higher-level API with C, C++, OCaml, and Java bindings. This API is domain-neutral and supports a rich set of semantic operations, including parallel assignments (useful
      to analyze automata), substitutions (useful for backward analysis), non-linear numerical expressions, and IEEE floating-point arithmetic.</p>
      <p>The 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://apron.cri.ensmp.fr/library/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Apron</span></ref>library is freely available on the web at 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://apron.cri.ensmp.fr/library/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>apron.
      <allowbreak/>cri.
      <allowbreak/>ensmp.
      <allowbreak/>fr/
      <allowbreak/>library</ref>; it is distributed under the LGPL license and is hosted at 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="https://gforge.inria.fr/projects/apron/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">INRIAGForge</ref>. Packages exist for the Debian
      and Fedora Linux distributions. In order to help disseminate the knowledge on abstract interpretation, a simple inter-procedural static analyzer for a toy language is included. An on-line
      version is deployed at 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://pop-art.inrialpes.fr/interproc/interprocweb.cgi" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>pop-art.
      <allowbreak/>inrialpes.
      <allowbreak/>fr/
      <allowbreak/>interproc/
      <allowbreak/>interprocweb.
      <allowbreak/>cgi</ref>.</p>
      <p>The 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://apron.cri.ensmp.fr/library/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Apron</span></ref>library is developed since 2006 and currently consists of 130 000 lines of C, C++, OCaml, and Java.</p>
      <p>Current and past external library users include the Constraint team (LINA, Nantes, France), the Proval/Démon team (LRI Orsay, France), the Analysis of Computer Systems Group (New-York
      University, USA), the Sierum software analysis platform (Kansas State University, USA), NEC Labs (Princeton, USA), EADS CCR (Paris, France), IRIT (Toulouse, France), ONERA (Toulouse, France),
      CEA LIST (Saclay, France), VERIMAG (Grenoble, France), ENSMP CRI (Fontainebleau, France), the IBM T.J. Watson Research Center (USA), the University of Edinburgh (UK).</p>
    </subsection>
    <subsection id="uid19" level="1">
      <bodyTitle>The 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>Static Analyzer of Synchronous Software</bodyTitle>
      <participants>
        <person key="abstraction-2007-idm495957220928">
          <firstname>Patrick</firstname>
          <lastname>Cousot</lastname>
          <moreinfo>project scientifique leader, correspondent</moreinfo>
        </person>
        <person key="abstraction-2007-idm495957213728">
          <firstname>Radhia</firstname>
          <lastname>Cousot</lastname>
        </person>
        <person key="abstraction-2007-idm495957193264">
          <firstname>Jérôme</firstname>
          <lastname>Feret</lastname>
        </person>
        <person key="PASUSERID">
          <firstname>Laurent</firstname>
          <lastname>Mauborgne</lastname>
        </person>
        <person key="abstraction-2007-idm495957206736">
          <firstname>Antoine</firstname>
          <lastname>Miné</lastname>
        </person>
        <person key="abstraction-2007-idm495957200624">
          <firstname>Xavier</firstname>
          <lastname>Rival</lastname>
        </person>
      </participants>
      <p/>
      <p><ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>is a static analyzer for sequential programs based on abstract interpretation 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid1" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid2" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid3" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid4" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
      <p>The 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>static analyzer 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid17" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid18" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid0" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">www.
      <allowbreak/>astree.
      <allowbreak/>ens.
      <allowbreak/>fr</ref>aims at proving the absence of runtime errors in programs written in the C programming language.</p>
      <p><ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>analyzes structured C programs, with complex memory usages, but without dynamic memory allocation nor recursion. This encompasses many embedded programs as found in earth transportation,
      nuclear energy, medical instrumentation, and aerospace applications, in particular synchronous control/command. The whole analysis process is entirely automatic.</p>
      <p><ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>discovers all runtime errors including:</p>
      <simplelist>
        <li id="uid20">
          <p noindent="true">undefined behaviors in the terms of the ANSI C99 norm of the C language (such as division by 0 or out of bounds array indexing);</p>
        </li>
        <li id="uid21">
          <p noindent="true">any violation of the implementation-specific behavior as defined in the relevant Application Binary Interface (such as the size of integers and arithmetic overflows);</p>
        </li>
        <li id="uid22">
          <p noindent="true">any potentially harmful or incorrect use of C violating optional user-defined programming guidelines (such as no modular arithmetic for integers, even though this might
          be the hardware choice);</p>
        </li>
        <li id="uid23">
          <p noindent="true">failure of user-defined assertions.</p>
        </li>
      </simplelist>
      <p>The analyzer performs an abstract interpretation of the programs being analyzed, using a parametric domain (
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>is able to choose the right instantiation of the domain for wide families of software). This analysis produces abstract invariants, which over-approximate the reachable states of the
      program, so that it is possible to derive an 
      <i>over</i>-approximation of the dangerous states (defined as states where any runtime error mentioned above may occur) that the program may reach, and produces alarms for each such possible
      runtime error. Thus the analysis is sound (it correctly discovers 
      <i>all</i>runtime errors), yet incomplete, that is it may report false alarms (
      <i>i.e.</i>, alarms that correspond to no real program execution). However, the design of the analyzer ensures a high level of precision on domain-specific families of software, which means
      that the analyzer produces few or no false alarms on such programs.</p>
      <p>In order to achieve this high level of precision, 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>uses a large number of expressive abstract domains, which allow expressing and inferring complex properties about the programs being analyzed, such as numerical properties (digital
      filters, floating-point computations), Boolean control properties, and properties based on the history of program executions.</p>
      <p><ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>has achieved the following two unprecedented results:</p>
      <simplelist>
        <li id="uid24">
          <p noindent="true"><b>A340–300.</b>In Nov. 2003, 
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>was able to prove completely automatically the absence of any RTE in the primary flight control software of the Airbus A340 fly-by-wire system, a program of 132,000 lines of C
          analyzed in 1h20 on a 2.8 GHz 32-bit PC using 300 MB of memory (and 50mn on a 64-bit AMD Athlon 64 using 580 MB of memory).</p>
        </li>
        <li id="uid25">
          <p noindent="true"><b>A380.</b>From Jan. 2004 on, 
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>was extended to analyze the electric flight control codes then in development and test for the A380 series. The operational application by Airbus France at the end of 2004 was just in
          time before the A380 maiden flight on Wednesday, 27 April, 2005.</p>
        </li>
      </simplelist>
      <p>These research and development successes have led to consider the inclusion of 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>in the production of the critical software for the A350. 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>is currently industrialized by 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.absint.com/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">AbsInt Angewandte Informatik GmbH</ref>and is 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.absint.com/astree/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">commercially available</ref>.</p>
    </subsection>
    <subsection id="uid26" level="1">
      <bodyTitle>The 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astreea.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">AstréeA</span></ref>Static Analyzer of Asynchronous Software</bodyTitle>
      <participants>
        <person key="abstraction-2007-idm495957220928">
          <firstname>Patrick</firstname>
          <lastname>Cousot</lastname>
          <moreinfo>project scientifique leader, correspondent</moreinfo>
        </person>
        <person key="abstraction-2007-idm495957213728">
          <firstname>Radhia</firstname>
          <lastname>Cousot</lastname>
        </person>
        <person key="abstraction-2007-idm495957193264">
          <firstname>Jérôme</firstname>
          <lastname>Feret</lastname>
        </person>
        <person key="abstraction-2007-idm495957206736">
          <firstname>Antoine</firstname>
          <lastname>Miné</lastname>
        </person>
        <person key="abstraction-2007-idm495957200624">
          <firstname>Xavier</firstname>
          <lastname>Rival</lastname>
        </person>
      </participants>
      <p/>
      <p><ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astreea.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">AstréeA</span></ref>is a static analyzer prototype for parallel software based on abstract interpretation 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid9" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid8" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid5" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. It started with support from 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.di.ens.fr/~cousot/projets/THESEE/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Thésée</span></ref>ANR project (2006–2010) and is continuing within the 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astreea.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">AstréeA</span></ref>project (2012–2015).</p>
      <p>The 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astreea.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">AstréeA</span></ref>prototype 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astreea.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">www.
      <allowbreak/>astreea.
      <allowbreak/>ens.
      <allowbreak/>fr</ref>is a fork of the 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>static analyzer (see 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#uid19" location="intern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>) that adds support for analyzing parallel embedded C software.</p>
      <p><ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astreea.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">AstréeA</span></ref>analyzes C programs composed of a fixed set of threads that communicate through a shared memory and synchronization primitives (mutexes, FIFOs, blackboards, etc.), but without recursion
      nor dynamic creation of memory, threads nor synchronization objects. 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astreea.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">AstréeA</span></ref>assumes a real-time scheduler, where thread scheduling strictly obeys the fixed priority of threads. Our model follows the ARINC 653 OS specification used in embedded industrial
      aeronautic software. Additionally, 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astreea.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">AstréeA</span></ref>employs a weakly-consistent memory semantics to model memory accesses not protected by a mutex, in order to take into account soundly hardware and compiler-level program transformations
      (such as optimizations). 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astreea.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">AstréeA</span></ref>checks for the same run-time errors as 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>, with the addition of data-races.</p>
      <p>Compared to 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>, 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astreea.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">AstréeA</span></ref>features: a new iterator to compute thread interactions, a refined memory abstraction that takes into account the effect of interfering threads, and a new scheduler partitioning domain.
      This last domain allows discovering and exploiting mutual exclusion properties (enforced either explicitly through synchronization primitives, or implicitly by thread priorities) to achieve a
      precise analysis.</p>
      <p><ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astreea.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">AstréeA</span></ref>is currently being applied to analyze a large industrial avionic software: 1.6 MLines of C and 15 threads, completed with a 2,500-line model of the ARINC 653 OS developed for the
      analysis. The analysis currently takes 29h on a 2.66 GHz 64-bit intel server using one core and generates around 1,800 alarms. The low computation time (only a few times larger than the
      analysis time by 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>of synchronous programs of a similar size and structure) shows the scalability of the approach (in particular, we avoid the usual combinatorial explosion associated to thread
      interleavings). Precision-wise, the result, while not as impressive as that of 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>, is quite encouraging. Improvements were made this year concerning the precision of 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astreea.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">AstréeA</span></ref>(from 7,600 alarms in 2010 to 1,800 now) and will continue within the scope of the 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astreea.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">AstréeA</span></ref>ANR project (Section 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#uid96" location="intern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>).</p>
      <p>The details of the analysis are described in 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid19" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
    </subsection>
    <subsection id="uid27" level="1">
      <bodyTitle>
        <span class="smallcap" align="left">OpenKappa</span>
      </bodyTitle>
      <participants>
        <person key="PASUSERID">
          <firstname>Monte</firstname>
          <lastname>Brown</lastname>
          <moreinfo>Harvard Medical School</moreinfo>
        </person>
        <person key="PASUSERID">
          <firstname>Vincent</firstname>
          <lastname>Danos</lastname>
          <moreinfo>University of Edinburgh</moreinfo>
        </person>
        <person key="abstraction-2007-idm495957193264">
          <firstname>Jérôme</firstname>
          <lastname>Feret</lastname>
          <moreinfo>Correspondent</moreinfo>
        </person>
        <person key="PASUSERID">
          <firstname>Walter</firstname>
          <lastname>Fontana</lastname>
          <moreinfo>Harvard Medical School</moreinfo>
        </person>
        <person key="PASUSERID">
          <firstname>Russ</firstname>
          <lastname>Harmer</lastname>
          <moreinfo>Harvard Medical School</moreinfo>
        </person>
        <person key="PASUSERID">
          <firstname>Jean</firstname>
          <lastname>Krivine</lastname>
          <moreinfo>Paris VII</moreinfo>
        </person>
      </participants>
      <p/>
      <p><span class="smallcap" align="left">OpenKappa</span>is a collection of tools to build, debug and run models of biological pathways. It contains a compiler for the Kappa Language 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid20" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, a static analyzer 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid21" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>(for debugging models), a simulator 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid22" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, a compression tool for causal traces 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid23" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, and a model reduction tool 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid24" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid25" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid26" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
      <p><span class="smallcap" align="left">OpenKappa</span>is developed since 2007 and, the OCaml version currently consists of 46 000 lines of OCaml. Software are available in OCaml and in Java.
      Moreover, an Eclipse pluggin is available.</p>
      <p><span class="smallcap" align="left">OpenKappa</span>is freely available on the web at 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://kappalanguage.org" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>kappalanguage.
      <allowbreak/>org</ref>under the LGPL license. Discussion groups are also available on line.</p>
      <p>Current external users include the Ecole Polytechnique Federale de Lausanne, the UNAM-Genomics Mexico team. It is used as pedagocical material in graduate lessons at Harvard Medical School,
      and at the Interdisciplinary Approaches to Life science (AIV) Master Program (Université de Médecine Paris-Descartes).</p>
    </subsection>
    <subsection id="uid28" level="1">
      <bodyTitle>Translation Validation</bodyTitle>
      <participants>
        <person key="abstraction-2007-idm495957200624">
          <firstname>Xavier</firstname>
          <lastname>Rival</lastname>
          <moreinfo>correspondent</moreinfo>
        </person>
      </participants>
      <p/>
      <p>The main goal of this software project is to make it possible to certify automatically the compilation of large safety critical software, by proving that the compiled code is correct with
      respect to the source code: When the proof succeeds, this guarantees that no compiler bug did cause incorrect code be generated. Furthermore, this approach should allow to meet some domain
      specific software qualification criteria (such as those in DO-178 regulations for avionics software), since it allows proving that successive development levels are correct with respect to each
      other 
      <i>i.e.</i>, that they implement the same specification. Last, this technique also justifies the use of source level static analyses, even when an assembly level certification would be
      required, since it establishes separately that the source and the compiled code are equivalent.</p>
      <p>The compilation certification process is performed automatically, thanks to a prover designed specifically. The automatic proof is done at a level of abstraction which has been defined so
      that the result of the proof of equivalence is strong enough for the goals mentioned above and so that the proof obligations can be solved by efficient algorithms.</p>
      <p>The current software features both a C to Power-PC compilation certifier and an interface for an alternate source language frontend, which can be provided by an end-user.</p>
    </subsection>
    <subsection id="uid29" level="1">
      <bodyTitle>
        <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://forge.ocamlcore.org/projects/zarith" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">
          <span class="smallcap" align="left">Zarith</span>
        </ref>
      </bodyTitle>
      <participants>
        <person key="abstraction-2007-idm495957206736">
          <firstname>Antoine</firstname>
          <lastname>Miné</lastname>
          <moreinfo>Correspondent</moreinfo>
        </person>
        <person key="PASUSERID">
          <firstname>Xavier</firstname>
          <lastname>Leroy</lastname>
          <moreinfo>INRIA Paris-Rocquencourt</moreinfo>
        </person>
        <person key="PASUSERID">
          <firstname>Pascal</firstname>
          <lastname>Cuoq</lastname>
          <moreinfo>CEA LIST</moreinfo>
        </person>
      </participants>
      <p/>
      <p><ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://forge.ocamlcore.org/projects/zarith" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Zarith</span></ref>is a small (10K lines) OCaml library that implements arithmetic and logical operations over arbitrary-precision integers. It is based on the GNU MP library to efficiently implement
      arithmetic over big integers. Special care has been taken to ensure the efficiency of the library also for small integers: small integers are represented as Caml unboxed integers and use a
      specific C code path. Moreover, optimized assembly versions of small integer operations are provided for a few common architectures.</p>
      <p><ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://forge.ocamlcore.org/projects/zarith" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Zarith</span></ref>is an open-source project hosted at OCamlForge (
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://forge.ocamlcore.org/projects/zarith" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
      <allowbreak/>forge.
      <allowbreak/>ocamlcore.
      <allowbreak/>org/
      <allowbreak/>projects/
      <allowbreak/>zarith</ref>) and distributed under a modified LGPL license.</p>
      <p><ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://forge.ocamlcore.org/projects/zarith" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Zarith</span></ref>is currently used in the 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>analyzer to enable the sound analysis of programs featuring 64-bit (or larger) integers. It is also used in the Frama-C analyzer platform developed at CEA LIST and INRIA Saclay.</p>
    </subsection>
  </logiciels>
  <resultats id="uid30">
    <bodyTitle>New Results</bodyTitle>
    <subsection id="uid31" level="1">
      <bodyTitle>Abstractions of Functions</bodyTitle>
      <participants>
        <person key="abstraction-2007-idm495957220928">
          <firstname>Patrick</firstname>
          <lastname>Cousot</lastname>
        </person>
        <person key="abstraction-2007-idm495957213728">
          <firstname>Radhia</firstname>
          <lastname>Cousot</lastname>
        </person>
      </participants>
      <p/>
      <p>The idea of domain segmentation for arrays 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid27" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>has been extended to the abstraction of functions 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid28" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>by combination of a partionning of their domain of definition
      and a functional or relational abstraction of blocks into their co-domain 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid29" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
    </subsection>
    <subsection id="uid32" level="1">
      <bodyTitle>Analysis of Biological Pathways</bodyTitle>
      <p>We have improved our framework to design and analyze biological networks. This framework focused on protein-protein interaction networks described as graph rewriting systems. Such networks
      can be used to model some signaling pathways that control the cell cycle. The task is made difficult due to the combinatorial blow up in the number of reachable species (
      <i>i.e.</i>, non-isomorphic connected components of proteins).</p>
      <subsection id="uid33" level="2">
        <bodyTitle>Automatic Reduction of Differential Semantics</bodyTitle>
        <participants>
          <person key="abstraction-2007-idm495957179744">
            <firstname>Ferdinanda</firstname>
            <lastname>Camporesi</lastname>
          </person>
          <person key="PASUSERID">
            <firstname>Vincent</firstname>
            <lastname>Danos</lastname>
            <moreinfo>University of Edinburgh</moreinfo>
          </person>
          <person key="abstraction-2007-idm495957193264">
            <firstname>Jérôme</firstname>
            <lastname>Feret</lastname>
          </person>
          <person key="PASUSERID">
            <firstname>Walter</firstname>
            <lastname>Fontana</lastname>
            <moreinfo>Harvard Medical School</moreinfo>
          </person>
          <person key="PASUSERID">
            <firstname>Russ</firstname>
            <lastname>Harmer</lastname>
            <moreinfo>Harvard Medical School</moreinfo>
          </person>
          <person key="PASUSERID">
            <firstname>Jean</firstname>
            <lastname>Krivine</lastname>
            <moreinfo>Paris VII</moreinfo>
          </person>
        </participants>
        <p/>
        <p>We have developed an abstract interpretation-based framework that enables the reduction of the differential semantics for protein-protein interaction networks. Results are sound since
        trajectories in the abstract system are projections of the trajectories in the concrete system.</p>
        <p>The flow of information is a key element in our model reduction framework because it enables the identification of the correlations which are useless when computing observables of
        interest. Thus there is a need of providing good trade-off in the description of the flow of information throughout the biochemical structure of chemical species.</p>
        <p>The notion of symmetries between sites is also important, since knowing that two sites have exactly the same capabilities of interaction enable exact quotienting (or lumping) of the set of
        reachable species.</p>
        <p>In 
        <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid30" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
        <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid31" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we have proposed a heterogeneous over-approximation of the
        flow of information where the flow that is attached to an agent can depend on its relative position in a chemical species. Moreover, we have showed how to use symmetries between sites so as
        to define another model reduction and we have proposed an algebraic product to combine model reductions, the product of two reduced models being the least abstract model which is at least as
        abstract as both model.</p>
      </subsection>
      <subsection id="uid34" level="2">
        <bodyTitle>Automatic Reduction of Stochastic Semantics</bodyTitle>
        <participants>
          <person key="abstraction-2007-idm495957179744">
            <firstname>Ferdinanda</firstname>
            <lastname>Camporesi</lastname>
          </person>
          <person key="abstraction-2007-idm495957193264">
            <firstname>Jérôme</firstname>
            <lastname>Feret</lastname>
          </person>
          <person key="PASUSERID">
            <firstname>Thomas</firstname>
            <lastname>Henzinger</lastname>
            <moreinfo>Institute of Science and Technology, Austria</moreinfo>
          </person>
          <person key="PASUSERID">
            <firstname>Heinz</firstname>
            <lastname>Koeppl</lastname>
            <moreinfo>ETH Zürich</moreinfo>
          </person>
          <person key="PASUSERID">
            <firstname>Tatjana</firstname>
            <lastname>Petrov</lastname>
            <moreinfo>ETH Zürich</moreinfo>
          </person>
        </participants>
        <p/>
        <p>We have proposed an abstract interpretation-based framework for reducing the state-space of stochastic semantics for protein-protein interaction networks. Our framework ensures that the
        trace distribution of the reduced system is the exact projection of the trace distribution of the concrete system. Moreover, when the abstraction is complete, if any pair of concrete states
        that have the same abstraction are equipropable at initial state, any pair of concrete states that share the same abstraction are equiprobable at any time 
        <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>t</mi></math></formula>.</p>
        <p>In 
        <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid32" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we have formalized the model reduction framework for the
        stochastic semantics and we have established the relationships with the notions of lumpability, and bisimulation is established.</p>
      </subsection>
    </subsection>
    <subsection id="uid35" level="1">
      <bodyTitle>Automatic Array Content Analysis by Segmentation</bodyTitle>
      <participants>
        <person key="abstraction-2007-idm495957220928">
          <firstname>Patrick</firstname>
          <lastname>Cousot</lastname>
        </person>
        <person key="abstraction-2007-idm495957213728">
          <firstname>Radhia</firstname>
          <lastname>Cousot</lastname>
        </person>
        <person key="PASUSERID">
          <firstname>Francesco</firstname>
          <lastname>Logozzo</lastname>
          <moreinfo>Microsoft Research (Redmond, USA)</moreinfo>
        </person>
      </participants>
      <p/>
      <p>In 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid27" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we introduce 
      <tt>FunArray</tt>, a parametric segmentation abstract domain functor for the fully automatic and scalable analysis of array content properties. The functor enables a natural, painless and
      efficient lifting of existing abstract domains for scalar variables to the analysis of uniform compound data-structures such as arrays and collections (as well as matrices when instantiating
      the functor on itself). The analysis automatically and semantically divides arrays into consecutive non-overlapping possibly empty segments. Segments are delimited by sets of bound symbolic
      expressions and abstracted uniformly. All bound expressions appearing in a set are equal in the concrete. The 
      <tt>FunArray</tt>can be naturally combined via reduced product with any existing analysis for scalar variables. The bound expressions, the segment abstractions and the reduction operator are
      the three parameters of the analysis. Once the functor has been instantiated with fixed parameters, the analysis is fully automatic.</p>
      <p>We first prototyped 
      <tt>FunArray</tt>in 
      <tt>Arrayal</tt>to adjust and experiment with the abstractions and the algorithms to obtain the appropriate precision/ratio cost. Then it was implemented into 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://research.microsoft.com/en-us/projects/contracts/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">CCCheck</span></ref>(formerly 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://research.microsoft.com/en-us/projects/contracts/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Clousot</span></ref>), an abstract interpretation-based static contract checker for 
      <tt>.NET</tt>by Francesco Logozzo. The precision and the performance of the analysis has been empirically validated by running it on the main libraries of 
      <tt>.NET</tt>and on its own code. It was able to infer thousands of invariants and to verify the implementation with a modest overhead (circa 1%). To the best of our knowledge this is the first
      analysis of this kind applied to such a large code base, and proven to scale.</p>
    </subsection>
    <subsection id="uid36" level="1">
      <bodyTitle>Extrapolation operators for combinations of abstract domains</bodyTitle>
      <participants>
        <person key="PASUSERID">
          <firstname>Agostino</firstname>
          <lastname>Cortesi</lastname>
          <moreinfo>Università Ca'Foscardi di Venizia</moreinfo>
        </person>
        <person key="abstraction-2009-idm361193205440">
          <firstname>Matteo</firstname>
          <lastname>Zanioli</lastname>
        </person>
      </participants>
      <p/>
      <p>Extrapolation operators are crucial to ensure the scalability of the analysis to large software systems. In 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid33" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we set the ground for a systematic design of widening and
      narrowing operators, by comparing the different definitions introduced in the literature and by discussing how to tune them in case of domain abstraction and domains' combination through
      Cartesian and reduced products.</p>
    </subsection>
    <subsection id="uid37" level="1">
      <bodyTitle>Grammar Semantics, Analysis and Parsing</bodyTitle>
      <participants>
        <person key="abstraction-2007-idm495957220928">
          <firstname>Patrick</firstname>
          <lastname>Cousot</lastname>
        </person>
        <person key="abstraction-2007-idm495957213728">
          <firstname>Radhia</firstname>
          <lastname>Cousot</lastname>
        </person>
      </participants>
      <p/>
      <p>In 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid34" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we study the abstract interpretations of a fixpoint
      protoderivation semantics defining the maximal derivations of a transitional semantics of context-free grammars akin to pushdown automata. The result is a hierarchy of bottom-up or top-down
      semantics refining the classical equational and derivational language semantics and including Knuth grammar problems, classical grammar flow analysis algorithms, and parsing algorithms.</p>
    </subsection>
    <subsection id="uid38" level="1">
      <bodyTitle>Information Flow</bodyTitle>
      <p>The analysis of the flow of information in a program consists in detecting the propagation of sensitive information through the program points of this program thanks to a dependency
      analysis.</p>
      <subsection id="uid39" level="2">
        <bodyTitle>Dependency Analysis and Numerical Invariants</bodyTitle>
        <participants>
          <person key="PASUSERID">
            <firstname>Agostino</firstname>
            <lastname>Cortesi</lastname>
            <moreinfo>Università Ca'Foscardi di Venizia</moreinfo>
          </person>
          <person key="abstraction-2009-idm361193205440">
            <firstname>Matteo</firstname>
            <lastname>Zanioli</lastname>
          </person>
        </participants>
        <p/>
        <p>A new framework has been proposed in 
        <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid35" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, that combines variable dependency analysis, based on
        propositional formulas, and variables' value analysis, based on generic numerical domains.</p>
      </subsection>
      <subsection id="uid40" level="2">
        <bodyTitle>Leakage Analysis</bodyTitle>
        <participants>
          <person key="abstraction-2009-idm361193205440">
            <firstname>Matteo</firstname>
            <lastname>Zanioli</lastname>
            <moreinfo>Correspondent</moreinfo>
          </person>
          <person key="PASUSERID">
            <firstname>Pietro</firstname>
            <lastname>Ferrara</lastname>
            <moreinfo>ETH, Zurich</moreinfo>
          </person>
          <person key="PASUSERID">
            <firstname>Agostino</firstname>
            <lastname>Cortesi</lastname>
            <moreinfo>Università Ca' Foscari</moreinfo>
          </person>
        </participants>
        <p/>
        <p>In 
        <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid36" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we present 
        <span class="smallcap" align="left">Sails</span>, a new tool that combines 
        <span class="smallcap" align="left">Sample</span>, a generic static analyzer, and a sophisticated domain for leakage analysis. This tool does not require to modify the original language,
        since it works with mainstream languages like 
        <span class="smallcap" align="left">Java</span>™, and it does not require any manual annotation. 
        <span class="smallcap" align="left">Sails</span>can combine the information leakage analysis with different heap abstractions, inferring information leakage over programs with complex data
        structures. 
        <span class="smallcap" align="left">Sails</span>has been applied to the analysis of the SecuriBench-micro suite. The experimental results underline the effectiveness of the analysis, since 
        <span class="smallcap" align="left">Sails</span>is in position to analyze several benchmarks in about 1 second without producing false alarms in more than 90% of the programs.</p>
      </subsection>
    </subsection>
    <subsection id="uid41" level="1">
      <bodyTitle>Linear Absolute Value Relation Analysis</bodyTitle>
      <participants>
        <person key="PASUSERID">
          <firstname>Liqian</firstname>
          <lastname>Chen</lastname>
          <moreinfo>National Laboratory for Parallel and Distributed Processing, Changsha, P. R. China</moreinfo>
        </person>
        <person key="abstraction-2007-idm495957206736">
          <firstname>Antoine</firstname>
          <lastname>Miné</lastname>
        </person>
        <person key="PASUSERID">
          <firstname>Ji</firstname>
          <lastname>Wang</lastname>
          <moreinfo>National Laboratory for Parallel and Distributed Processing, Changsha, P. R. China</moreinfo>
        </person>
        <person key="abstraction-2007-idm495957220928">
          <firstname>Patrick</firstname>
          <lastname>Cousot</lastname>
        </person>
      </participants>
      <p/>
      <p>We present in 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid37" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>an abstract domain dealing with linear inequalities involving
      variables together with their absolute values. It is an extension of the classical linear relation analysis, which permits to deal with some non convex numerical sets. A first nice result
      states the equivalence between these “linear absolute value inequalities” (AVI) and “interval linear inequalities”, and “extended linear complementary inequalities” (XLCP, pairs of positive
      solutions whose pairwise components are not both not zero). The key contribution is the extension of the double-description of polyhedra to XLCP solutions, which is then used to define the
      standard operations on AVI. The method has been implemented, and experiments show interesting results, with reasonable performances with respect to linear relation analysis.</p>
    </subsection>
    <subsection id="uid42" level="1">
      <bodyTitle>Probabilistic Analysis</bodyTitle>
      <participants>
        <person key="abstraction-2007-idm495957220928">
          <firstname>Patrick</firstname>
          <lastname>Cousot</lastname>
        </person>
        <person key="PASUSERID">
          <firstname>Michaël</firstname>
          <lastname>Monerau</lastname>
        </person>
      </participants>
      <p/>
      <p>The abstract interpretation theory has been widely used in the past decades for verifying properties of computer systems. We have introduced a new extension of this well-known framework to
      the case of probabilistic systems 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid38" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
      <p>The probabilistic abstraction framework we propose allows to systematically lift any classical analysis or verification method to the probabilistic setting by separating in the program
      semantics the probabilistic behavior from the (non-)deterministic behavior. This separation provides new insights for designing novel probabilistic static analyses and verification methods.</p>
      <p>We have defined concrete probabilistic semantics and proposed different ways to abstract them. The approach is expressive and effective. The previous techniques for probabilistic analysis
      are actually abstractions expressible in our framework.</p>
    </subsection>
    <subsection id="uid43" level="1">
      <bodyTitle>Safety</bodyTitle>
      <participants>
        <person key="abstraction-2007-idm495957220928">
          <firstname>Patrick</firstname>
          <lastname>Cousot</lastname>
        </person>
        <person key="abstraction-2007-idm495957213728">
          <firstname>Radhia</firstname>
          <lastname>Cousot</lastname>
        </person>
      </participants>
      <p/>
      <p>The abstract interpretation design principle has been applied to the design of new forward and backward proof, verification and analysis methods for safety 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid29" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. The safety collecting semantics defining the strongest safety
      property of programs is first expressed in a constructive fixpoint form. Safety proof and checking/verification methods then immediately follow by fixpoint induction. Static analysis of
      abstract safety properties such as invariance are constructively designed by fixpoint abstraction (or approximation) to (automatically) infer safety properties.</p>
    </subsection>
    <subsection id="uid44" level="1">
      <bodyTitle>Security</bodyTitle>
      <participants>
        <person key="abstraction-2007-idm495957220928">
          <firstname>Patrick</firstname>
          <lastname>Cousot</lastname>
        </person>
        <person key="abstraction-2007-idm495957213728">
          <firstname>Radhia</firstname>
          <lastname>Cousot</lastname>
        </person>
      </participants>
      <p/>
      <p>We have developed, episodically since 2007, an abstract interpretation framework for security and program securization that is the transformation of a program into a secured program
      satisfying security criteria defined by a human or artificial supervisor (this is verification when no transformation is needed). The securization is based on the notion of responsibility
      analysis determining which choices in the program (inputs, random draws, interrupts, schedules, etc.) can definitely cause or avoid desired or menacing events, or have no control at all on the
      occurrence of these events. Various securization policies (eager, early or late lazy, etc.) have been identified to prevent or enforce the occurrence of events.</p>
    </subsection>
    <subsection id="uid45" level="1">
      <bodyTitle>Shape Analysis</bodyTitle>
      <p>We have extended the 
      <span class="smallcap" align="left">Xisa</span>(eXtensible Inductive Shape Analysis) framework, in order to better deal with low level coding styles and programming languages, and in order to
      analyze recursive programs in a context dependent way. We also introduced a classification for semantic memory models.</p>
      <subsection id="uid46" level="2">
        <bodyTitle>Abstracting Calling-Context with Shapes</bodyTitle>
        <participants>
          <person key="PASUSERID">
            <firstname>Bor-Yuh Evan</firstname>
            <lastname>Chang</lastname>
            <moreinfo>University of Colorado at Boulder (USA)</moreinfo>
          </person>
          <person key="abstraction-2007-idm495957200624">
            <firstname>Xavier</firstname>
            <lastname>Rival</lastname>
          </person>
        </participants>
        <p>Interprocedural program analysis is often performed by computing procedure summaries. While possible, computing adequate summaries is difficult, particularly in the presence of recursive
        procedures. In 
        <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid39" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we propose a complementary framework for interprocedural
        analysis based on a direct abstraction of the calling context. Specifically, our approach exploits the inductive structure of a calling context by treating it directly as a stack of
        activation records. We built an abstraction based on separation logic with inductive definitions. A key element of this abstract domain is the use of parameters to refine the meaning of such
        call stack summaries and thus express relations across activation records and with the heap. In essence, we define an abstract interpretation-based analysis framework for recursive programs
        that permits a fluid per call site abstraction of the call stack—much like how shape analyzers enable a fluid per program point abstraction of the heap.</p>
      </subsection>
      <subsection id="uid47" level="2">
        <bodyTitle>Abstract domains for the analysis of programs manipulating complex data-structures</bodyTitle>
        <participants>
          <person key="abstraction-2007-idm495957200624">
            <firstname>Xavier</firstname>
            <lastname>Rival</lastname>
          </person>
        </participants>
        <p>We proposed a framework for building abstract domains for the static analysis of programs which manipulate complex* data-structures 
        <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid40" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. Our abstract domain is parametric in the choice of a
        numerical abstract domain to represent properties of numeric memory cells and in the choice of a set of inductive definitions to be used in order to summarize unbounded heap regions. It
        features standard primitives for the computation of transfer functions, for the inclusion checking and for the computation of widening iterates. We also proposed an extension to handle
        programs that make use of low-level memory addressing, and proposed an extension of the widening to infer inductive definitions.</p>
      </subsection>
      <subsection id="uid48" level="2">
        <bodyTitle>Composite abstract domain for the analysis of dynamic structures</bodyTitle>
        <participants>
          <person key="abstraction-2007-idm495957200624">
            <firstname>Xavier</firstname>
            <lastname>Rival</lastname>
          </person>
          <person key="abstraction-2011-idm355312772656">
            <firstname>Antoine</firstname>
            <lastname>Toubhans</lastname>
          </person>
        </participants>
        <p>Reduced product is a general operation to combine abstract domains into more powerful abstract domains, which has been especially used to construct numerical abstract domains. However,
        until now, it has not been applied to memory structures. We proposed an instance of a reduced product operation, which can be applied on shape abstract domains based on separation logic and
        on inductive definitions. The advantage of this construction is that it allows to describe more complex heap dynamic data structures without making the design of all abstract operation more
        complex. In the other hand, it incurs a reduction cost, whenever we need to transport some information from one domain to the other. We showed that optimal reduction cannot be achieved, and
        identified the main source of complexity of this operation. A prototype implementation was also carried out. This work was done as part of Antoine Toubhans Master internship.</p>
      </subsection>
    </subsection>
    <subsection id="uid49" level="1">
      <bodyTitle>Static Analysis of Parallel Software</bodyTitle>
      <participants>
        <person key="abstraction-2007-idm495957206736">
          <firstname>Antoine</firstname>
          <lastname>Miné</lastname>
        </person>
      </participants>
      <p/>
      <p>We present in 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid19" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>a static analysis by abstract interpretation to check for
      run-time errors in parallel C programs. Following our work on 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>, we focus on embedded critical programs without recursion nor dynamic memory allocation, but extend the analysis to a static set of threads. Our method iterates a slightly modified
      non-parallel analysis over each thread in turn, until thread interferences stabilize. We prove the soundness of the method with respect to a sequential consistent semantics and a reasonable
      weakly consistent memory semantics. We then show how to take into account mutual exclusion and thread priorities through partitioning over the scheduler state. We present preliminary
      experimental results analyzing a real program with our prototype 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astreea.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">AstréeA</span></ref>(see 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#uid26" location="intern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>) and demonstrate the scalability of our approach.</p>
    </subsection>
    <subsection id="uid50" level="1">
      <bodyTitle>Termination</bodyTitle>
      <participants>
        <person key="abstraction-2007-idm495957220928">
          <firstname>Patrick</firstname>
          <lastname>Cousot</lastname>
        </person>
        <person key="abstraction-2007-idm495957213728">
          <firstname>Radhia</firstname>
          <lastname>Cousot</lastname>
        </person>
      </participants>
      <p/>
      <p>In 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid29" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we have introduced an abstract interpretation for termination.
      Proof, verification and analysis methods for termination all rely on two induction principles: (1) a variant function or induction on data ensuring progress towards the end and (2) some form of
      induction on the program structure.</p>
      <p>So far, no clear design principle did exist for termination as is the case for safety so that the existing approaches are scattered and largely not comparable with each other.</p>
      <p>For (1), we show that this design principle applies equally well to potential and definite termination. The trace-based termination collecting semantics is given a fixpoint definition. Its
      abstraction yields a fixpoint definition of the best variant function. By further abstraction of this best variant function, we derive the Floyd/Turing termination proof method as well as new
      static analysis methods to effectively compute approximations of this best variant function.</p>
      <p>For (2), we introduce a generalization of the syntactic notion of structural induction (as found in Hoare logic) into a semantic structural induction based on the new semantic concept of
      inductive trace cover covering execution traces by segments, a new basis for formulating program properties. Its abstractions allow for generalized recursive proof, verification and static
      analysis methods by induction on both program structure, control, and data. Examples of particular instances include Floyd's handling of loop cut-points as well as nested loops, Burstall's
      intermittent assertion total correctness proof method, and Podelski-Rybalchenko transition invariants.</p>
    </subsection>
    <subsection id="uid51" level="1">
      <bodyTitle>Theories, Solvers and Static Analysis</bodyTitle>
      <participants>
        <person key="abstraction-2007-idm495957220928">
          <firstname>Patrick</firstname>
          <lastname>Cousot</lastname>
        </person>
        <person key="abstraction-2007-idm495957213728">
          <firstname>Radhia</firstname>
          <lastname>Cousot</lastname>
        </person>
        <person key="PASUSERID">
          <firstname>Laurent</firstname>
          <lastname>Mauborgne</lastname>
          <moreinfo>IMDEA Software (Madrid, Spain)</moreinfo>
        </person>
      </participants>
      <p/>
      <p>In 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid41" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we have introduced a reduced product combining algebraic and
      logical abstractions to design program correctness verifiers and static analyzers by abstract interpretation. The key new idea is to show that the Nelson-Oppen procedure for combining theories
      in SMT-solvers computes a reduced product in an observational semantics, so that algebraic and logical abstract interpretations can naturally be combined in a classical way using a reduced
      product on this observational semantics. The main practical benefit is that reductions can be performed within the logical abstract domains, within the algebraic abstract domains, and also
      between the logical and the algebraic abstract domains, including the case of abstractions evolving during the analysis.</p>
    </subsection>
    <subsection id="uid52" level="1">
      <bodyTitle>Underapproximation for Precondition Inference</bodyTitle>
      <participants>
        <person key="abstraction-2007-idm495957220928">
          <firstname>Patrick</firstname>
          <lastname>Cousot</lastname>
        </person>
        <person key="abstraction-2007-idm495957213728">
          <firstname>Radhia</firstname>
          <lastname>Cousot</lastname>
        </person>
        <person key="PASUSERID">
          <firstname>Francesco</firstname>
          <lastname>Logozzo</lastname>
          <moreinfo>Microsoft Research (Redmond, USA)</moreinfo>
        </person>
        <person key="PASUSERID">
          <firstname>Manuel</firstname>
          <lastname>Fähndrichh</lastname>
          <moreinfo>Microsoft Research (Redmond, USA)</moreinfo>
        </person>
      </participants>
      <p/>
      <p>In the context of program design by contracts, programmers often insert assertions in their code to be optionally checked at runtime, at least during the debugging phase. These assertions
      would better be given as a precondition of the method/procedure in which they appear. Potential errors would be discovered earlier and, more importantly, the precondition could be used in the
      context of separate static program analysis as part of the abstract semantics of the code. However in the case of collections (data structures such as arrays, lists, etc) checking both the
      precondition and the assertions at runtime appears superfluous and costly. So the precondition is often omitted since it is checked anyway at runtime by the assertions. It follows that the
      static analysis can be much less precise, a fact that can be difficult to understand since “the precondition and assertions are equivalent” (i.e. at runtime, up to the time at which warnings
      are produced, but not statically) e.g. for separate static analysis. Moreover preconditions are often understood as overapproximations and thus may exclude good runs which is counter-intuitive
      for programmers. On the contrary, with considering underapproximations 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid1" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid2" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>which exclude no good run, ensures that if the precondition is
      violated then a runtime error must definitely be raised later, and if the precondition is not strong enough to catch all errors they will definitely be captures by a later runtime check.</p>
      <p>In 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid42" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we define precisely and formally the contract inference
      problem from intermittent assertions on scalar variables and elements of collections inserted in the code by the programmer. Our definition excludes no good run even when a non-deterministic
      choice (e.g. an interactive input) could lead to a bad one. We then introduce new abstract interpretation-based methods to automatically infer both the static contract precondition of a
      method/procedure and the code to check it at runtime on scalar and collection variables. It has been implemented in 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://research.microsoft.com/en-us/projects/contracts/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">CCCheck</span></ref>(formerly 
      <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://research.microsoft.com/en-us/projects/contracts/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Clousot</span></ref>) by Francesco Logozzo and Manuel Fähndrich.</p>
    </subsection>
    <subsection id="uid53" level="1">
      <bodyTitle>Verification of spreadsheet programs by abstract interpretation</bodyTitle>
      <participants>
        <person key="PASUSERID">
          <firstname>Tie</firstname>
          <lastname>Cheng</lastname>
        </person>
        <person key="abstraction-2007-idm495957200624">
          <firstname>Xavier</firstname>
          <lastname>Rival</lastname>
        </person>
      </participants>
      <p/>
      <p>Spreadsheet tools (Excel, Openoffice) come with powerful languages which can manipulate sheets in various ways. However, no type discipline is enforced, so that the programs may corrupt
      spreadsheet contents in many ways. We proposed an abstraction to describe sets of valid spreadsheet states, and designed a verifier for invariants expressed in this abstract domain. Our
      verifier assumes invariants are defined at the head of loops in the programs (as widening operators for the inference of loop invariants). This work was done as part of Tie Cheng Master
      internship.</p>
    </subsection>
  </resultats>
  <contrats id="uid54">
    <bodyTitle>Contracts and Grants with Industry</bodyTitle>
    <subsection id="uid55" level="1">
      <bodyTitle>Contracts with Industry</bodyTitle>
      <subsection id="uid56" level="2">
        <bodyTitle>Contracts</bodyTitle>
        <subsection id="uid57" level="3">
          <bodyTitle>
            <span class="smallcap" align="left">Anastasy</span>
          </bodyTitle>
          <sanspuceslist>
            <li id="uid58">
              <p noindent="true">Title: 
              <span class="smallcap" align="left">Anastasy</span></p>
            </li>
            <li id="uid59">
              <p noindent="true">Type: Industrial contract</p>
            </li>
            <li id="uid60">
              <p noindent="true">Duration: September 2009 - December 2011</p>
            </li>
            <li id="uid61">
              <p noindent="true">Others partners: Airbus France</p>
            </li>
            <li id="uid62">
              <p noindent="true">Abstract: 
              <span class="smallcap" align="left">Anastasy</span>(
              <em style="UNDERLINE">ANA</em>lyse 
              <em style="UNDERLINE">STA</em>tique a
              <em style="UNDERLINE">SY</em>nchone) is an industrial project with Airbus France on the static program analysis of asynchronous programs by abstract interpretation which objective is
              determined annually. Patrick Cousot is the principal investigator for this action.</p>
            </li>
          </sanspuceslist>
        </subsection>
      </subsection>
      <subsection id="uid63" level="2">
        <bodyTitle>License agreement</bodyTitle>
        <subsection id="uid64" level="3">
          <bodyTitle>
            <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">
              <span class="smallcap" align="left">Astrée</span>
            </ref>
          </bodyTitle>
          <p>In February 2009 was signed an exploitation license agreement between CNRS, École Normale Supérieure, and 
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.absint.com/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">AbsInt Angewandte Informatik GmbH</ref>for the
          industrialization of the 
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>analyzer. 
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>is 
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.absint.com/astree/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">commercially available</ref>from 
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.absint.com/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">AbsInt</ref>since January 2010. Continuous work goes on to
          adapt the 
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>static analyzer to industrial needs, in particular for the automotive industry. Radhia Cousot is the scientific contact.</p>
        </subsection>
      </subsection>
    </subsection>
    <subsection id="uid65" level="1">
      <bodyTitle>Grants with Industry</bodyTitle>
      <subsection id="uid66" level="2">
        <bodyTitle>FNRAE projects</bodyTitle>
        <subsection id="uid67" level="3">
          <bodyTitle>
            <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://ascert.gforge.inria.fr/index.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">
              <span class="smallcap" align="left">Ascert</span>
            </ref>
          </bodyTitle>
          <sanspuceslist>
            <li id="uid68">
              <p noindent="true">Title: Analyses Statiques CERTifiés</p>
            </li>
            <li id="uid69">
              <p noindent="true">Type: 6th call: Verification methods for software and systems</p>
            </li>
            <li id="uid70">
              <p noindent="true">Instrument: FNRAE grant</p>
            </li>
            <li id="uid71">
              <p noindent="true">Duration: April 2009 - March 2012</p>
            </li>
            <li id="uid72">
              <p noindent="true">Coordinator: INRIA (France)</p>
            </li>
            <li id="uid73">
              <p noindent="true">Others partners: INRIA-Bretagne Atlantique, the INRIA Rhône-Alpes, the INRIA Paris-Rocquencourt, and the ENS.</p>
            </li>
            <li id="uid74">
              <p noindent="true">See also: 
              <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://ascert.gforge.inria.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://ascert.gforge.inria.fr/</ref></p>
            </li>
            <li id="uid75">
              <p noindent="true">Abstract: Although static analyzers have demonstrated their ability to prove the absence of large classes of errors in critical software, they are themselves large
              and complex software, so it is natural to question their implementation correctness and the validity of their output. The focus of the 
              <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://ascert.gforge.inria.fr/index.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Ascert</span></ref>project is the use of formal methods to ensure the correctness of an analyzer with respect to the abstraction interpretation theory. Methods to be investigated include the direct
              proof of the analyzer, the proof of a verifier for the analyzer result, and the validation of the inductive invariants generated by the analyzer, using the Coq proof assistant. These
              methods will be applied to the certification of several numerical abstract domains, of an abstract interpreter for imperative programs and its possible extensions to one of the formal
              semantics of the CompCert verified C compiler.</p>
            </li>
          </sanspuceslist>
        </subsection>
        <subsection id="uid76" level="3">
          <bodyTitle>
            <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://perso.univ-perp.fr/mmartel/sardanes.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">
              <span class="smallcap" align="left">Sardanes</span>
            </ref>
          </bodyTitle>
          <sanspuceslist>
            <li id="uid77">
              <p noindent="true">Title: Sémantique, Analyse et tRansformation Des Applications Numériques Embarqués Synchrones</p>
            </li>
            <li id="uid78">
              <p noindent="true">Type: 6th call: Verification methods for software and systems</p>
            </li>
            <li id="uid79">
              <p noindent="true">Instrument: FNRAE grant</p>
            </li>
            <li id="uid80">
              <p noindent="true">Duration: February 2009 - September 2013</p>
            </li>
            <li id="uid81">
              <p noindent="true">Coordinator: Université de Perpignan</p>
            </li>
            <li id="uid82">
              <p noindent="true">Others partners: Université de Perpignan and the ENS.</p>
            </li>
            <li id="uid83">
              <p noindent="true">See also: 
              <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://perso.univ-perp.fr/mmartel/sardanes.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">
              http://perso.univ-perp.fr/mmartel/sardanes.html</ref></p>
            </li>
            <li id="uid84">
              <p noindent="true">Abstract: 
              <span class="smallcap" align="left">Scade</span>is widely used to write critical embedded software, as a specification and verification language. The semantics of 
              <span class="smallcap" align="left">Scade</span>uses real arithmetics whereas it is compiled into a language that uses floating-point arithmetics. The goal of the 
              <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://perso.univ-perp.fr/mmartel/sardanes.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Sardanes</span></ref>project is to use expression transformation so as to ensure that the numerical properties of the programs is preserved during the compilation. Patrick Cousot and Radhia Cousot are
              the principal investigators for this action.</p>
            </li>
          </sanspuceslist>
        </subsection>
      </subsection>
    </subsection>
  </contrats>
  <international id="uid85">
    <bodyTitle>Partnerships and Cooperations</bodyTitle>
    <subsection id="uid86" level="1">
      <bodyTitle>National Initiatives</bodyTitle>
      <subsection id="uid87" level="2">
        <bodyTitle>ANR projects</bodyTitle>
        <subsection id="uid88" level="3">
          <bodyTitle>
            <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.di.ens.fr/~feret/abstractcell/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">
              <span class="smallcap" align="left">AbstractCell</span>
            </ref>
          </bodyTitle>
          <sanspuceslist>
            <li id="uid89">
              <p noindent="true">Title: Formal abstraction of quantitative semantics for protein-protein interaction cellular network models</p>
            </li>
            <li id="uid90">
              <p noindent="true">Instrument: ANR-Chair of Excellence (Junior, long term)</p>
            </li>
            <li id="uid91">
              <p noindent="true">Duration: December 2009 - December 2013</p>
            </li>
            <li id="uid92">
              <p noindent="true">Coordinator: INRIA (France)</p>
            </li>
            <li id="uid93">
              <p noindent="true">Others partners: None</p>
            </li>
            <li id="uid94">
              <p noindent="true">See also: 
              <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.di.ens.fr/~feret/abstractcell" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">
              http://www.di.ens.fr/ feret/abstractcell</ref></p>
            </li>
            <li id="uid95">
              <p noindent="true">Abstract: The overall goal of this project is to investigate formal foundations and computational aspects of both the stochastic and differential approximate
              semantics for rule-based models. We want to relate these semantics formally, then we want to design sound approximations for each of these semantics (by abstract interpretation) and
              investigate scalable algorithms to compute the properties of both the stochastic and the differential semantics. Jérôme Feret is the principal investigator for this project.</p>
            </li>
          </sanspuceslist>
        </subsection>
        <subsection id="uid96" level="3">
          <bodyTitle>
            <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astreea.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">
              <span class="smallcap" align="left">AstréeA</span>
            </ref>
          </bodyTitle>
          <sanspuceslist>
            <li id="uid97">
              <p noindent="true">Title: Static Analysis of Embedded Asynchronous Real-Time Software</p>
            </li>
            <li id="uid98">
              <p noindent="true">Type: ANR Ingénierie Numérique Sécurité 2011</p>
            </li>
            <li id="uid99">
              <p noindent="true">Instrument: ANR grant</p>
            </li>
            <li id="uid100">
              <p noindent="true">Duration: January 2012 - December 2015</p>
            </li>
            <li id="uid101">
              <p noindent="true">Coordinator: Airbus France (France)</p>
            </li>
            <li id="uid102">
              <p noindent="true">Others partners: École normale supérieure (France)</p>
            </li>
            <li id="uid103">
              <p noindent="true">See also: 
              <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astreea.ens.fr" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://www.astreea.ens.fr</ref></p>
            </li>
            <li id="uid104">
              <p noindent="true">Abstract: The focus of the 
              <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astreea.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">AstréeA</span></ref>project is on the development of static analysis by abstract interpretation to check the safety of large-scale asynchronous embedded software. During the 
              <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.di.ens.fr/~cousot/projets/THESEE/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Thésée</span></ref>ANR project (2006–2010), we developed a concrete and abstract models of the ARINC 653 operating system and its scheduler, and a first analyzer prototype. The gist of the 
              <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astreea.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">AstréeA</span></ref>project is the continuation of this effort, following the recipe that made the success of 
              <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>: an incremental refinement of the analyzer until reaching the zero false alarm goal. The refinement concerns: the abstraction of process interactions (relational and
              history-sensitive abstractions), the scheduler model (supporting more synchronisation primitives and taking priorities into account), the memory model (supporting volatile variables),
              and the abstraction of dynamical data-structures (linked lists). Patrick Cousot is the principal investigator for this project.</p>
            </li>
          </sanspuceslist>
        </subsection>
        <subsection id="uid105" level="3">
          <bodyTitle>
            <span class="smallcap" align="left">Verasco</span>
          </bodyTitle>
          <sanspuceslist>
            <li id="uid106">
              <p noindent="true">Title: Formally-verified static analyzers and compilers</p>
            </li>
            <li id="uid107">
              <p noindent="true">Type: ANR Ingénierie Numérique Sécurité 2011</p>
            </li>
            <li id="uid108">
              <p noindent="true">Instrument: ANR grant</p>
            </li>
            <li id="uid109">
              <p noindent="true">Duration: Septembre 2011 - September 2015</p>
            </li>
            <li id="uid110">
              <p noindent="true">Coordinator: INRIA (France)</p>
            </li>
            <li id="uid111">
              <p noindent="true">Others partners: Airbus France (France), IRISA (France), INRIA Saclay (France)</p>
            </li>
            <li id="uid112">
              <p noindent="true">See also: 
              <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.systematic-paris-region.org/fr/projets/verasco" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">
              http://www.systematic-paris-region.org/fr/projets/verasco</ref></p>
            </li>
            <li id="uid113">
              <p noindent="true">Abstract: The usefulness of verification tools in the development and certification of critical software is limited by the amount of trust one can have in their
              results. A first potential issue is 
              <i>unsoundness</i>of a verification tool: if a verification tool fails (by mistake or by design) to account for all possible executions of the program under verification, it can
              conclude that the program is correct while it actually misbehaves when executed. A second, more insidious, issue is 
              <i>miscompilation</i>: verification tools generally operate at the level of source code or executable model; a bug in the compilers and code generators that produce the executable code
              that actually runs can lead to a wrong executable being generated from a correct program.</p>
              <p>The project 
              <span class="smallcap" align="left">Verasco</span>advocates a mathematically-grounded solution to the issues of formal verifying compilers and verification tools. been mechanically
              proved to be free of any miscompilation will be continued. Finally, the tool qualification issues that must be addressed before formally-verified tools can be used in the aircraft
              industry, will be investigated.</p>
            </li>
          </sanspuceslist>
        </subsection>
      </subsection>
    </subsection>
    <subsection id="uid114" level="1">
      <bodyTitle>European Initiatives</bodyTitle>
      <subsection id="uid115" level="2">
        <bodyTitle>EU Project</bodyTitle>
        <subsection id="uid116" level="3">
          <bodyTitle>MBAT</bodyTitle>
          <sanspuceslist>
            <li id="uid117">
              <p noindent="true">Title: Combined Model-based Analysis &amp; Testing of Embedded Systems</p>
            </li>
            <li id="uid118">
              <p noindent="true">Type: Artemis Call 10</p>
            </li>
            <li id="uid119">
              <p noindent="true">Instrument: FP7 project</p>
            </li>
            <li id="uid120">
              <p noindent="true">Duration: November 2011 - October 2014</p>
            </li>
            <li id="uid121">
              <p noindent="true">Coordinator: Daimler (Germany)</p>
            </li>
            <li id="uid122">
              <p noindent="true">Others partners: 38 partners in Austria, Denmark, Estonia, France, Germany, Italy, Sweden, and United Kingdom</p>
            </li>
            <li id="uid123">
              <p noindent="true">See also: 
              <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.artemis-ia.eu/project/index/view/?project=29" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">
              http://www.artemis-ia.eu/project/index/view/?project=29</ref></p>
            </li>
            <li id="uid124">
              <p noindent="true">Abstract: MBAT will mainly focus on providing a technology platform for effective and cost-reducing validation and verification of embedded systems, focusing
              primarily on transportation domain, but also to be used in further domains. The project involves thirty three European industrial (large companies and SMEs) and five academic partners.
              Radhia Cousot is the principal investigator for this project.</p>
            </li>
          </sanspuceslist>
        </subsection>
        <subsection id="uid125" level="3">
          <bodyTitle>MemCad</bodyTitle>
          <sanspuceslist>
            <li id="uid126">
              <p noindent="true">Title: Memory Compositional Abstract Domains</p>
            </li>
            <li id="uid127">
              <p noindent="true">Type: IDEAS</p>
            </li>
            <li id="uid128">
              <p noindent="true">Instrument: ERC Starting Grant (Starting)</p>
            </li>
            <li id="uid129">
              <p noindent="true">Duration: October 2011 - September 2016</p>
            </li>
            <li id="uid130">
              <p noindent="true">Coordinator: INRIA (France)</p>
            </li>
            <li id="uid131">
              <p noindent="true">Others partners: none</p>
            </li>
            <li id="uid132">
              <p noindent="true">See also: 
              <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.di.ens.fr/~rival/memcad.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">
              http://www.di.ens.fr/ rival/memcad.html</ref></p>
            </li>
            <li id="uid133">
              <p noindent="true">Abstract: The MemCAD project aims at setting up a library of abstract domains in order to express and infer complex memory properties. It is based on the abstract
              interpretation frameworks, which allows to combine simple abstract domains into complex, composite abstract domains and static analyzers. While other families of abstract domains (such
              as numeric abstract domains) can be easily combined (making the design of very powerful static analyses for numeric intensive applications possible), current tools for the analysis of
              programs manipulating complex abstract domains usually rely on a monolithic design, which makes their design harder, and limits their efficiency. The purpose of the MemCAD project is to
              overcome this limitation. Our proposal is based on the observation that the complex memory properties that need be reasoned about should be decomposed in combinations of simpler
              properties. Therefore, in static analysis, a complex memory abstract domain could be designed by combining many simpler domains, specific to common memory usage patterns. The benefit of
              this approach is twofold: first it would make it possible to simplify drastically the design of complex abstract domains required to reason about complex softwares, hereby allowing
              certification of complex memory intensive softwares by automatic static analysis; second, it would enable to split down and better control the cost of the analyses, thus significantly
              helping scalability. As part of this project, we propose to build a static analysis framework for reasoning about memory properties, and put it to work on important classes of
              applications, including large softwares.</p>
            </li>
          </sanspuceslist>
        </subsection>
      </subsection>
    </subsection>
    <subsection id="uid134" level="1">
      <bodyTitle>International Initiatives</bodyTitle>
      <subsection id="uid135" level="2">
        <bodyTitle>NSFC Project</bodyTitle>
        <subsection id="uid136" level="3">
          <bodyTitle>NSFC</bodyTitle>
          <sanspuceslist>
            <li id="uid137">
              <p noindent="true">Title: Analysis and Verification of Dependable Cyber-Physical Software</p>
            </li>
            <li id="uid138">
              <p noindent="true">Type: National Natural Science Foundation of China (
              <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.nsfc.gov.cn/english/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">NSFC</span></ref>)</p>
            </li>
            <li id="uid139">
              <p noindent="true">Duration: January 2012 - December 2016</p>
            </li>
            <li id="uid140">
              <p noindent="true">Coordinator: National University of Defense Technology (China)</p>
            </li>
            <li id="uid141">
              <p noindent="true">Others partners: National University of Defense Technology (China), Seoul National University (Korea)</p>
            </li>
            <li id="uid142">
              <p noindent="true">Abstract: The project addresses analysis and verification issues related to dependability properties of Cyber Physical Systems (CPS) software: safety (such as the
              numerical or and memory related runtime errors), quantitative properties (such as the worst-case execution time, upper bound of the memory consumption, etc.), stability and robustness
              (due to intrinsic uncertainty of CPS), as well as properties of hybrid system (which provides a model for describing the coordination of computation and physical, discrete and
              continuous processes). The project is expected to advance the analysis and verification methodology for dependable CPS software so as to contribute to the dependability assurance of CPS
              software in mission critical applications. Patrick Cousot is the principal investigator for this project.</p>
            </li>
          </sanspuceslist>
        </subsection>
        <subsection id="uid143" level="3">
          <bodyTitle>Visiting professors</bodyTitle>
          <p>Yanjun Wen is associate professor at the Department of Computer Science and Technology, College of Computer, National University of Defense Technology, Changsha, P. R. China.
          He is visiting the team from June 2011 to May 2012 and is interested in the static analysis of parallel software by abstract interpretation.</p>
          <p>Roberto Giacobazzi, professor at the University of Verona, Italy, visited in spring 2011.</p>
          <p>Andreas Podelski, professor at the University of Freiburg, Germany, visited in fall 2011.</p>
        </subsection>
        <subsection id="uid144" level="3">
          <bodyTitle>Internship</bodyTitle>
          <p>Marie Pelleau is a third year PhD student from the University of Nantes (France) under the supervision of Frédéric Benhamou, Pascal Van Hentenryck, and Charlotte Truchet. She spent one
          month (November 2011) in the team, under the supervision of Antoine Miné, on the application of numerical abstract domains (and in particular, the Apron library, 
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#uid18" location="intern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>) to constraint programming.</p>
          <p>David Delmas is an engineer at Airbus France on educational leave to pursue the 2nd year of the Parisian Master of Research in Computer Science (MPRI) and a visitor in the team from
          September 2011 to August 2012.</p>
          <p>Suzanne Renard is a third year student at École des Mines de Paris (France). She spent six months (September 2010 to February 2011) in the team, under the supervision of Xavier Rival;
          she was working on the extension of the 
          <span class="smallcap" align="left">xisa</span>shape analysis frameworks in order to express set properties.</p>
        </subsection>
      </subsection>
    </subsection>
  </international>
  <diffusion id="uid145">
    <bodyTitle>Dissemination</bodyTitle>
    <subsection id="uid146" level="1">
      <bodyTitle>Animation of the scientific community</bodyTitle>
      <subsection id="uid147" level="2">
        <bodyTitle>Academy Members, Professional Societies</bodyTitle>
        <p>Patrick Cousot is a member of the 
        <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.acadeuro.org/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">Academia Europaea</ref>.</p>
        <p>Patrick Cousot is member of the IFIP working group WG 2.3 on programming methodology.</p>
        <p>Patrick Cousot is a member of the Board of Trustees and of the Scientific Advisory Board of the 
        <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.imdea.org/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">IMDEA</ref>-
        <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.imdea.org/Institutos/Software/tabid/125/Default.aspx" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">Software</ref>(Instituto
        madrileño de estudios avanzados—Research Institute in Software Development Technology), Madrid, Spain and of the Asian Association for Foundations of Software (AAFS).</p>
      </subsection>
      <subsection id="uid148" level="2">
        <bodyTitle>Collective Responsibilities</bodyTitle>
        <p>Patrick Cousot is director of studies in computer science at ENS and member of the 
        <i>commission de spécialistes</i>(hiring committee) of ENS.</p>
        <p>Patrick Cousot, Antoine Miné and Xavier Rival are members of the lab council of the Laboratoire d'Informatique de l'École Normale Supérieure.</p>
        <p>Jérôme Feret was a member of the 
        <i>comité de sélection</i>(hiring committee) to hire an assistant professor at the Université de Lille 1.</p>
        <p>Antoine Miné was a member of the 
        <i>comité de sélection</i>(hiring committee) to hire an assistant professor at the École normale supérieure de Cachan, antenne de Bretagne (Ker Lann, France).</p>
        <p>Xavier Rival was a member of the 
        <i>comité de sélection</i>(hiring committee) to hire an assistant professor at the Université de Paris 7.</p>
      </subsection>
      <subsection id="uid149" level="2">
        <bodyTitle>Editorial Boards and Program Committees</bodyTitle>
        <p>— Patrick Cousot is member of the advisory board of the 
        <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.brics.dk/~hosc/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">Higher-Order Symbolic Computation</ref>journal (HOSC,
        Springer) and of the 
        <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://jcse.kiise.org/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">Journal of Computing Science and Engineering</ref>(JCSE,
        Kiise).</p>
        <p>Patrick Cousot is member of the steering committees of the Static Analysis Symposium (SAS) and the Verification, Model-Checking and Abstract Interpretation (VMCAI) international
        conference.</p>
        <p>Patrick Cousot was member of the program committees of the 32th ACM SIGPLAN Conference on Programming Language Design and Implementation (PLDI 2011 ERC) , San Jose, CA, USA, June 4-8,
        2011; the 12th International Conference on Verification, Model Checking and Abstract Interpretation (VMCAI 2011), Austin, TX, USA, January 23-25, 2011; the 14th ACM International Conference
        on Hybrid Systems (HSCC 2011), Chicago, IL, USA, April 11-14, 2011; Verified Software: Theories, Tools and Experiments (VSTTE 2012), Philadelphia, USA, January 28-29, 2012; the 19th
        International Static Analysis Symposium (SAS'12), Deauville, France; the 15th ACM International Conference on Hybrid Systems: Computation and Control (HSCC 2012), Beijing, China, April 17-19,
        2012.</p>
        <p>— Radhia Cousot is member of the advisory board of the 
        <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.brics.dk/~hosc/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">Higher-Order Symbolic Computation</ref>journal (HOSC,
        Springer) and the 
        <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://versita.com/cejcs/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">Central European Journal of Computer Science</ref>(CEJCS,
        Versita &amp; Springer).</p>
        <p>Radhia Cousot is member of the steering committees of the Static Analysis Symposium (SAS), the Workshop on Numerical and Symbolic Abstract Domains (NSAD), the Workshop on Static Analysis
        and Systems Biology (SASB) and the Workshop on Tools for Automatic Program AnalysiS (TAPAS).</p>
        <p>Radhia Cousot is the program committee chair of the 40th ACM SIGACT-SIGPLAN Symposium on Principles of Programming Languages (POPL 2013), Rome, Italy, January 23-25, 2013.</p>
        <p>Radhia Cousot was member of the program committees of the 21st European Symposium on Programming (ESOP 2011), Saarbrücken, Germany, March 26-April 3, 2011; the 18th International Static
        Analysis Symposium (SAS'11), Venice, Italy, September 14-16, 2011; the 38th ACM SIGACT-SIGPLAN Symposium on Principles of Programming Languages (POPL 2011), Austin, Texas, USA, January 26-28,
        2011.</p>
        <p>— Jérôme Feret is a member of the editorial board of the 
        <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.frontiers-in-genetics.org" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">Frontiers in Genetics</ref>journal.</p>
        <p>Jérôme Feret is a member of the steering committee of the Workshop on Static Analysis and Systems Biology (SASB).</p>
        <p>Jérôme Feret was co-program committee chair of the 2nd SASB (2011) and is co-program committee chair of the 3rd SASB (2012).</p>
        <p>Jérôme Feret was member of the program committee of the 2nd International Workshop on Interactions between Computer Science and Biology (CS2Bio 2011), the 9th International Conference on
        Computational Methods in Systems Biology (CMSB 2011), the 9th Asian Symposium on Programming Languages (APLAS 2011), the 4th International Conference on Bioinformatics, Biocomputational
        Systems and Biotechnologies (BIOTECHNO 2012). He will be a member of the International Symposium on Foundations of Health Information Engineering and System (FHIES 2012).</p>
        <p>— Antoine Miné was member of the program committee of the 18th International Static Analysis Symposium (SAS'11), the third Workshop on Numerical and Symbolic Abstract Domains (NSAD'11),
        and the First International Workshop on Safety and Security in Cyber-Physical Systems (SSCPS'11).</p>
        <p>Antoine Miné will be program committee co-chair and general chair of the 19th International Static Analysis Symposium (SAS'12), Deauville, France, general chair of the 4th International
        Workshop on Numerical and Symbolic Abstract Domains (NSAD'12), the 3rd International Workshop on Static Analysis and Systems Biology (SASB'12), and the 3rd International Workshop on Tools for
        Automatic Program AnalysiS (TAPAS'12), Deauville, France, and member of the program committee of the Second International Workshop on Safety and Security in Cyber-Physical Systems (SSCPS'12),
        Gaithersburg, Maryland, USA.</p>
        <p>— Xavier Rival was member of the program committee the Conferences on Tools and Algorithms for the Construction and Analysis of Systems (TACAS 2011), Saarbrücken, Germany, March 26-April
        3, 2011.</p>
        <p>Xavier Rival is a member of the program committee the European Symposium On Programming (ESOP 2012).</p>
        <p>Xavier Rival is member of the steering committee of the Workshop on Tools for Automatic Program AnalysiS (TAPAS).</p>
      </subsection>
      <subsection id="uid150" level="2">
        <bodyTitle>Jury of PhD and Habilitation</bodyTitle>
        <p>— Patrick Cousot was in the jury of the habilitation of Xavier Rival, (ENS, Paris, France, June 24, 2011).</p>
        <p>— Jérôme Feret was in the jury of the PhD thesis of Loïc Paulevé (IRCCyn, Nantes, France, October 6, 2011).</p>
        <p>— Antoine Miné was in the jury of the PhD thesis of Khalil Ghorbal (CEA, France, July 28, 2011).</p>
      </subsection>
      <subsection id="uid151" level="2">
        <bodyTitle>Participation in Conferences</bodyTitle>
        <descriptionlist>
          <label>CMSB:</label>
          <li id="uid152">
            <p noindent="true">Ninth International Conference on Computational Methods in Systems Biology (Paris, France, 21–23 September 2011).</p>
            <p noindent="true">Ferdinanda Camporesi, Jérôme Feret, and Alessandro Romanel attended the workshop. Jérôme Feret chaired a session.</p>
          </li>
          <label>ESOP:</label>
          <li id="uid153">
            <p noindent="true">European Symposium on Programming (Saarbrücken, Germany, 30 March – 1st April 2011)</p>
            <p noindent="true">Patrick Cousot, Radhia Cousot, Antoine Miné and Xavier Rival attended the conference. Antoine Miné gave a talk on the static analysis of parallel programs 
            <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid19" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
          </li>
          <label>FOSSACS:</label>
          <li id="uid154">
            <p noindent="true">14th International Conference on Foundations of Software Science and Computation Structures (Saarbrücken, Germany, 29–31 March 2011)</p>
            <p noindent="true">Patrick Cousot, Radhia Cousot attended the conference. Patrick Cousot gave a talk on the reduced product of abstract domains and the combination of decision procedures 
            <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid41" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
          </li>
          <label>MecBIC:</label>
          <li id="uid155">
            <p noindent="true">International Workshop on Membrane Computing and Biologically Inspired Process Calculi (Fontainebleau, France, 23 August 2011).</p>
            <p noindent="true">Jérôme Feret and Alessandro Romanel attended the workshop.</p>
          </li>
          <label>MFPS:</label>
          <li id="uid156">
            <p noindent="true">International Conference on Mathematical Foundations of Programming Semantics (Pittsburg, Pennsylvania, USA, 25–28 May 2011).</p>
            <p noindent="true">Jérôme Feret attended the conference and gave an invited talk on model reduction of differential models 
            <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid30" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
          </li>
          <label>NSAD:</label>
          <li id="uid157">
            <p noindent="true">Second International Workshop on Numerical and Symbolic Abstract Domains (Venice, Italy, 13 September 2011).</p>
            <p noindent="true">Antoine Miné, Patrick Cousot, Radhia Cousot, and Xavier Rival attended the workshop.</p>
          </li>
          <label>POPL:</label>
          <li id="uid158">
            <p noindent="true">ACM Symposium on Principles of Programming Languages (Austin, Texas, USA, 26–28 January 2011).</p>
            <p noindent="true">Patrick Cousot, Radhia Cousot and Xavier Rival attended the conference 
            <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid27" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. Xavier Rival gave a talk on Calling context abstraction
            with shapes 
            <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid39" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
          </li>
          <label>RAIM:</label>
          <li id="uid159">
            <p noindent="true">4ème Rencontres Arithmétique de l'Informatique Mathématique (Perpignan, France, 7–10 February 2011)</p>
            <p noindent="true">Antoine Miné attended and gave a talk on the static analysis of numerical programs manipulating floating-point numbers.</p>
          </li>
          <label>SAS:</label>
          <li id="uid160">
            <p noindent="true">18th International Static Analysis Symposium (Venice, Italy, 14–16 September 2011).</p>
            <p noindent="true">Ferdinanda Camporesi, Patrick Cousot, Radhia Cousot, Jérôme Feret, Antoine Miné, Xavier Rival, and Matteo Zanioli attended the conference. Patrick Cousot gave an
            invited talk on Combining Algebraic Domains and Logical Theories by the Reduced Product. Jérôme Feret gave an invited talk on model reduction of differential models 
            <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid31" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. Antoine Miné chaired a session.</p>
          </li>
          <label>SASB:</label>
          <li id="uid161">
            <p noindent="true">International Workshop on Static Analyis and Systems Biology (Venice, Italy, 13 September 2011).</p>
            <p noindent="true">Ferdinanda Camporesi and Jérôme Feret attended to the workshop. Jérôme Feret co-chaired the workshop and chaired all the sessions.</p>
          </li>
          <label>TACAS:</label>
          <li id="uid162">
            <p noindent="true">17th International Conference on Tools for Automatic Construction and Analysis of Systems (Saarbrücken, Germany, 29–31 March 2011)</p>
            <p noindent="true">Xavier Rival attended the conference and chaired a session.</p>
          </li>
          <label>TAPAS:</label>
          <li id="uid163">
            <p noindent="true">Second International Workshop on Tools for Automatic Program Analysis (Venice, Italy, France, 17 September 2011).</p>
            <p noindent="true">Antoine Miné and Xavier Rival attended the workshop.</p>
          </li>
          <label>VMCAI:</label>
          <li id="uid164">
            <p noindent="true">International Conference on Verification, Model Checking and Abstract Interpretation (Austin, Texas, USA, 23–25 January 2011).</p>
            <p noindent="true">Patrick Cousot, Radhia Cousot attended the conference. Patrick Cousot gave a talk on precondition inference from intermittent assertions and application to contracts on
            collections 
            <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid42" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
          </li>
        </descriptionlist>
      </subsection>
      <subsection id="uid165" level="2">
        <bodyTitle>Invitations and Participation in Seminars</bodyTitle>
        <p>— Ferdinanda Camporesi gave a talk on model reduction of signaling pathways at the Semantics and Abstraction Interpretation Seminar (ENS, Paris, France).</p>
        <p>— Patrick Cousot gave a talk on Unifying proof theoretic/logical and algebraic abstractions for inference and verification, NSF CMACS Meeting, University of Maryland, College Park, MD,
        USA, April 28-29, 2011; on Theories, Solvers and Static Analysis by Abstract Interpretation, 
        <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://ascert.gforge.inria.fr/index.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Ascert</span></ref>Meeting, ENS Paris, France, November 30, 2011; on Program verification by abstract interpretation, NSF CMACS Industry Workshop on Verification of Embedded Control Systems, October 20,
        2011, Carnegie Mellon University, Pittsburgh, PA.</p>
        <p>— Patrick Cousot and Radhia Cousot gave a talk on Method Refactoring by Abstract Interpretation, MSR Talk Series, Microsoft Research, Redmond, WA, USA, September 2, 2011; on Theories,
        Solvers and Static Analysis by Abstract Interpretation, MSR Talk Series, Microsoft Research, Redmond, WA, USA. August 12th, 2011.</p>
        <p>— Jérôme Feret gave a talk on the 
        <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref>analyzer at the Programming Methodology group at ETH Zürich (Zürich, Switzerland) and some talks on model reduction for signaling pathways at the Bison group at ETH Zürich (Zürich,
        Switzerland), at the Focus group at the University of Bologna (Bologna, Italy), at the ANR-SYMBIOTIC meeting (IBISC, Evry, France), at the SysBio meeting of the Systems Biology of cancer
        group at the Institut Curie (Paris, France).</p>
        <p>— Antoine Miné gave a talk on the static analysis of parallel programs at the 68NQRT Seminar, IRISA and INRIA Rennes (France) on the 26 May 2011, at the Semantics and Abstraction
        Interpretation Seminar, École normale supérieure (Paris, France) on the 18 November 2011, and at IMDEA-Software (Madrid, Spain) on the 12 December 2011.</p>
        <p>— Xavier Rival was invited to give a talk on Perspective for compiler certification in avionics at the “Compiler Optimization meets Compiler Verification” Workshop (COCV) at ETAPS 2011,
        Saarbrücken, Germany, March 26-April 3, 2011. Xavier Rival gave a talk on Abstract domains for the static analysis of programs manipulating complex data-structures at Seoul National
        University (Seoul, Korea), on the 26th August, 2011.</p>
      </subsection>
    </subsection>
    <subsection id="uid166" level="1">
      <bodyTitle>Teaching</bodyTitle>
      <sanspuceslist>
        <li id="uid167">
          <p noindent="true">Licence :</p>
          <simplelist>
            <li id="uid168">
              <p noindent="true">Mathematics, 20h, L1, Licence Frontiers in Life Sciences, Université Paris-Descartes, France.</p>
            </li>
            <li id="uid169">
              <p noindent="true">Introduction to static analysis, 8h, L3, École des Mines de Paris, France.</p>
            </li>
            <li id="uid170">
              <p noindent="true">Introduction to algorithmics, 40h, L2, École Polytechnique, Palaiseau, France.</p>
            </li>
            <li id="uid171">
              <p noindent="true">Algorithmics and programming, 40h, L3, École Polytechnique, Palaiseau, France.</p>
            </li>
          </simplelist>
        </li>
        <li id="uid172">
          <p noindent="true">Master :</p>
          <simplelist>
            <li id="uid173">
              <p noindent="true">Computational Biology, 6h, M1, Interdisciplinary Approaches to Life Science (AIV) Master Program, Université Paris-Descartes, France</p>
            </li>
            <li id="uid174">
              <p noindent="true">Abstract interpretation: application to verification and static analysis, 48h, niveau M2, Parisian Master of Research in Computer Science (MPRI), École normale
              supérieure, France.</p>
            </li>
            <li id="uid175">
              <p noindent="true">Rule-based modeling and application to biomolecular networks, 8h, M1-M2, Master of Fundamental Research in Computer Science (MIF), École normale supérieure de Lyon,
              France</p>
            </li>
          </simplelist>
        </li>
        <li id="uid176">
          <p noindent="true">Doctorat :</p>
          <simplelist>
            <li id="uid177">
              <p noindent="true">Abstract Interpretation and its Applications, 19h, University of Bologna / University of Padova, Italy.</p>
            </li>
            <li id="uid178">
              <p noindent="true">Abstract Interpretation-based Tool Construction for Software Verification, 8th LASER Summer School on Software Engineering (LASER 2011), Elba Island, Italy, September
              4-10, 2011.</p>
            </li>
          </simplelist>
        </li>
      </sanspuceslist>
      <p>PhD &amp; HdR :</p>
      <sanspuceslist>
        <li id="uid179">
          <p noindent="true">HdR :</p>
          <simplelist>
            <li id="uid180">
              <p noindent="true">Xavier Rival, Abstract domains for the analysis of programs manipulating complex data-structures 
              <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#abstraction-2011-bid40" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, École Normale Supérieure, June, 24th, 2011.</p>
            </li>
          </simplelist>
        </li>
        <li id="uid181">
          <p noindent="true">PhD in progress :</p>
          <simplelist>
            <li id="uid182">
              <p noindent="true">Mehdi Bouaziz, November 2011, Patrick Cousot, École Normale Supérieure.</p>
            </li>
            <li id="uid183">
              <p noindent="true">Ferdinanda Camporesi, Abstraction of Quantitative Semantics of Rule-based models, January 2009, Radhia Cousot and Jérôme Feret (co-directed thesis with Maurizio
              Gabrielli, University of Bologna).</p>
            </li>
            <li id="uid184">
              <p noindent="true">Tie Cheng, Static analysis of spreadsheet macros, October 2011, Xavier Rival, École Polytechnique</p>
            </li>
            <li id="uid185">
              <p noindent="true">Vincent Laviron, October 2009, Patrick Cousot, École Normale Supérieure.</p>
            </li>
            <li id="uid186">
              <p noindent="true">Antoine Toubhans, Combination of shape abstract domains, October 2011, Xavier Rival, École Doctorale de Paris Centre</p>
            </li>
            <li id="uid187">
              <p noindent="true">Caterina Urban, November 2011, Radhia Cousot, École Normale Supérieure.</p>
            </li>
            <li id="uid188">
              <p noindent="true">Matteo Zanioli, October 2008, Radhia Cousot (co-directed thesis with Agostino Cortesi, University of Venezia).</p>
            </li>
          </simplelist>
        </li>
      </sanspuceslist>
    </subsection>
  </diffusion>
  <biblio id="bibliography" html="bibliography" numero="10" titre="Bibliography">
    <biblStruct id="abstraction-2011-bid0" type="inproceedings" rend="refer" n="refercite:bertrane:2010:inria-00528611:1">
      <identifiant type="hal" value="inria-00528611"/>
      <analytic>
        <title level="a">Static Analysis and Verification of Aerospace Software by Abstract Interpretation</title>
        <author>
          <persName key="abstraction-2007-idm495957196928">
            <foreName>Julien</foreName>
            <surname>Bertrane</surname>
            <initial>J.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957220928">
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957213728">
            <foreName>Radhia</foreName>
            <surname>Cousot</surname>
            <initial>R.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957193264">
            <foreName>Jérôme</foreName>
            <surname>Feret</surname>
            <initial>J.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957210304">
            <foreName>Laurent</foreName>
            <surname>Mauborgne</surname>
            <initial>L.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957206736">
            <foreName>Antoine</foreName>
            <surname>Miné</surname>
            <initial>A.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957200624">
            <foreName>Xavier</foreName>
            <surname>Rival</surname>
            <initial>X.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <title level="m">Proceedings of the American Institue of Aeronautics and Astronautics (AIAA Infotech@Aerospace 2010)</title>
        <loc>Atlanta, Georgia, USA</loc>
        <imprint>
          <publisher>
            <orgName>American Institue of Aeronautics and Astronautics</orgName>
          </publisher>
          <dateStruct>
            <year>2010</year>
          </dateStruct>
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://hal.inria.fr/inria-00528611" type="hal" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>inria-00528611</ref>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid13" type="inproceedings" rend="refer" n="refercite:BlanchetEtAl-PLDI03">
      <analytic>
        <title level="a">A Static Analyzer for Large Safety-Critical Software</title>
        <author>
          <persName key="abstraction-2007-idm495957216768">
            <foreName>Bruno</foreName>
            <surname>Blanchet</surname>
            <initial>B.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957220928">
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957213728">
            <foreName>Radhia</foreName>
            <surname>Cousot</surname>
            <initial>R.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957193264">
            <foreName>Jérôme</foreName>
            <surname>Feret</surname>
            <initial>J.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957210304">
            <foreName>Laurent</foreName>
            <surname>Mauborgne</surname>
            <initial>L.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957206736">
            <foreName>Antoine</foreName>
            <surname>Miné</surname>
            <initial>A.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957203728">
            <foreName>David</foreName>
            <surname>Monniaux</surname>
            <initial>D.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957200624">
            <foreName>Xavier</foreName>
            <surname>Rival</surname>
            <initial>X.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">Proceedings of the ACM SIGPLAN 2003 Conference on Programming Language Design and Implementation (PLDI'03)</title>
        <imprint>
          <publisher>
            <orgName>ACM Press</orgName>
          </publisher>
          <dateStruct>
            <month>June 7–14</month>
            <year>2003</year>
          </dateStruct>
          <biblScope type="pages">196–207</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid46" type="article" rend="refer" n="refercite:Cousot02-TCS">
      <analytic>
        <title level="a">Constructive Design of a Hierarchy of Semantics of a Transition System by Abstract Interpretation</title>
        <author>
          <persName key="abstraction-2007-idm495957220928">
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Theoretical Computer Science</title>
        <imprint>
          <biblScope type="volume">277</biblScope>
          <biblScope type="number">1–2</biblScope>
          <dateStruct>
            <year>2002</year>
          </dateStruct>
          <biblScope type="pages">47–103</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid24" type="article" rend="refer" n="refercite:feret-PNAS">
      <identifiant type="hal" value="inria-00528330"/>
      <analytic>
        <title level="a">Internal coarse-graining of molecular systems</title>
        <author>
          <persName key="abstraction-2007-idm495957193264">
            <foreName>Jérôme</foreName>
            <surname>Feret</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Vincent</foreName>
            <surname>Danos</surname>
            <initial>V.</initial>
          </persName>
          <persName key="moscova-2006-idm117579657776">
            <foreName>Jean</foreName>
            <surname>Krivine</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Russ</foreName>
            <surname>Harmer</surname>
            <initial>R.</initial>
          </persName>
          <persName>
            <foreName>Walter</foreName>
            <surname>Fontana</surname>
            <initial>W.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-editorial-board="yes" x-international-audience="yes">
        <title level="j">Proceeding of the national academy of sciences</title>
        <imprint>
          <biblScope type="volume">106</biblScope>
          <biblScope type="number">16</biblScope>
          <dateStruct>
            <month>Apr</month>
            <year>2009</year>
          </dateStruct>
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://hal.inria.fr/inria-00528330" type="hal" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>inria-00528330</ref>
        </imprint>
      </monogr>
      <affiliation>
        <country>UK</country>
        <country>US</country>
      </affiliation>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid48" type="inproceedings" rend="refer" n="refercite:mauborgne:rival05">
      <analytic>
        <title level="a">Trace Partitioning in Abstract Interpretation Based Static Analyzers</title>
        <author>
          <persName key="abstraction-2007-idm495957210304">
            <foreName>Laurent</foreName>
            <surname>Mauborgne</surname>
            <initial>L.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957200624">
            <foreName>Xavier</foreName>
            <surname>Rival</surname>
            <initial>X.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Mooly</foreName>
            <surname>Sagiv</surname>
            <initial>M.</initial>
          </persName>
        </editor>
        <title level="m">Proceedings of the 14th European Symposium on Programming (ESOP'05)</title>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">3444</biblScope>
          <publisher>
            <orgName>Springer-Verlag</orgName>
          </publisher>
          <dateStruct>
            <year>2005</year>
          </dateStruct>
          <biblScope type="pages">5–20</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid49" type="article" rend="refer" n="refercite:Mine-HOSC06">
      <analytic>
        <title level="a">The Octagon Abstract Domain</title>
        <author>
          <persName key="abstraction-2007-idm495957206736">
            <foreName>Antoine</foreName>
            <surname>Miné</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Higher-Order and Symbolic Computation</title>
        <imprint>
          <biblScope type="volume">19</biblScope>
          <dateStruct>
            <year>2006</year>
          </dateStruct>
          <biblScope type="pages">31–100</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid47" type="inproceedings" rend="refer" n="refercite:Rival-POPL04">
      <analytic>
        <title level="a">Symbolic Transfer Functions-based Approaches to Certified Compilation</title>
        <author>
          <persName key="abstraction-2007-idm495957200624">
            <foreName>Xavier</foreName>
            <surname>Rival</surname>
            <initial>X.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">Conference Record of the 31st Annual ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages</title>
        <imprint>
          <publisher>
            <orgName>ACM Press, New York, United States</orgName>
          </publisher>
          <dateStruct>
            <year>2004</year>
          </dateStruct>
          <biblScope type="pages">1–13</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct dedoublkey="5579" id="abstraction-2011-bid45" type="proceedings" rend="year" n="cite:feret:sasb2010">
      <monogr x-editorial-board="yes" x-international-audience="yes" x-proceedings="yes">
        <title level="m">Static Analysis and Systems Biology – 1st International Workshop, SASB 2010, Perpignan, France, September 13, 2010. PostProceedings</title>
        <title level="s">Electronic Notes in Theoretical Computer Science</title>
        <editor role="editor">
          <persName key="abstraction-2007-idm495957193264">
            <foreName>Jérôme</foreName>
            <surname>Feret</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Andre</foreName>
            <surname>Levchenko</surname>
            <initial>A.</initial>
          </persName>
        </editor>
        <imprint>
          <biblScope type="volume">272</biblScope>
          <publisher>
            <orgName>Elsevier</orgName>
          </publisher>
          <dateStruct>
            <year>2011</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct dedoublkey="1982" id="abstraction-2011-bid40" type="hdrthesis" rend="year" n="cite:xr:hdr">
      <monogr>
        <title level="m">Abstract domains for the analysis of programs manipulating complex data-structures</title>
        <author>
          <persName key="abstraction-2007-idm495957200624">
            <foreName>Xavier</foreName>
            <surname>Rival</surname>
            <initial>X.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="school">École Normale Supérieure</orgName>
          </publisher>
          <dateStruct>
            <month>June</month>
            <year>2011</year>
          </dateStruct>
        </imprint>
      </monogr>
      <note type="typdoc">Habilitation à Diriger des Recherches</note>
    </biblStruct>
    <biblStruct dedoublkey="1574" id="abstraction-2011-bid44" type="article" rend="year" n="cite:BertraneCousotCousotFeretMauborgneMineRival-2011-SEN">
      <analytic>
        <title level="a">Static analysis by abstract interpretation of embedded critical software</title>
        <author>
          <persName key="abstraction-2007-idm495957196928">
            <foreName>Julien</foreName>
            <surname>Bertrane</surname>
            <initial>J.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957220928">
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957213728">
            <foreName>Radhia</foreName>
            <surname>Cousot</surname>
            <initial>R.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957193264">
            <foreName>Jérôme</foreName>
            <surname>Feret</surname>
            <initial>J.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957210304">
            <foreName>Laurent</foreName>
            <surname>Mauborgne</surname>
            <initial>L.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957206736">
            <foreName>Antoine</foreName>
            <surname>Miné</surname>
            <initial>A.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957200624">
            <foreName>Xavier</foreName>
            <surname>Rival</surname>
            <initial>X.</initial>
          </persName>
        </author>
      </analytic>
      <monogr id="rid02053" x-editorial-board="yes" x-international-audience="yes">
        <idno type="issn">0163-5948</idno>
        <title level="j">ACM SIGSOFT Software Engineering Notes</title>
        <imprint>
          <biblScope type="volume">36</biblScope>
          <biblScope type="number">1</biblScope>
          <dateStruct>
            <year>2011</year>
          </dateStruct>
          <biblScope type="pages">1-8</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct dedoublkey="2154" id="abstraction-2011-bid43" type="incollection" rend="year" n="cite:bertrane:2011:inria-00636877:1">
      <identifiant type="hal" value="inria-00636877"/>
      <analytic>
        <title level="a">L'analyseur statique Astrée</title>
        <author>
          <persName key="abstraction-2007-idm495957196928">
            <foreName>Julien</foreName>
            <surname>Bertrane</surname>
            <initial>J.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957193264">
            <foreName>Jérôme</foreName>
            <surname>Feret</surname>
            <initial>J.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957220928">
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957213728">
            <foreName>Radhia</foreName>
            <surname>Cousot</surname>
            <initial>R.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957206736">
            <foreName>Antoine</foreName>
            <surname>Miné</surname>
            <initial>A.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957200624">
            <foreName>Xavier</foreName>
            <surname>Rival</surname>
            <initial>X.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957210304">
            <foreName>Laurent</foreName>
            <surname>Mauborgne</surname>
            <initial>L.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Jean-Louis</foreName>
            <surname>Boulanger</surname>
            <initial>J.-L.</initial>
          </persName>
        </editor>
        <title level="m">Utilisations industrielles des techniques formelles : interprétation abstraite</title>
        <imprint>
          <publisher>
            <orgName>Hermes-Lavoisier</orgName>
          </publisher>
          <dateStruct>
            <month>June</month>
            <year>2011</year>
          </dateStruct>
          <biblScope type="pages">67–113</biblScope>
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://hal.inria.fr/inria-00636877/en" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>inria-00636877/
          <allowbreak/>en</ref>
        </imprint>
      </monogr>
      <affiliation>
        <country>ES</country>
      </affiliation>
    </biblStruct>
    <biblStruct dedoublkey="1791" id="abstraction-2011-bid33" type="article" rend="year" n="cite:Zanioli:widening">
      <identifiant type="doi" value="10.1016/j.cl.2010.09.001"/>
      <analytic>
        <title level="a">Widening and narrowing operators for abstract interpretation</title>
        <author>
          <persName>
            <foreName>Agostino</foreName>
            <surname>Cortesi</surname>
            <initial>A.</initial>
          </persName>
          <persName key="abstraction-2009-idm361193205440">
            <foreName>Matteo</foreName>
            <surname>Zanioli</surname>
            <initial>M.</initial>
          </persName>
        </author>
      </analytic>
      <monogr id="rid00438" x-editorial-board="yes" x-international-audience="yes">
        <idno type="issn">1477-8424</idno>
        <title level="j">Computer Languages, Systems and Structures</title>
        <imprint>
          <biblScope type="volume">37</biblScope>
          <biblScope type="number">1</biblScope>
          <dateStruct>
            <year>2011</year>
          </dateStruct>
          <biblScope type="pages">24 - 42</biblScope>
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://dx.doi.org/10.1016/j.cl.2010.09.001" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>dx.
          <allowbreak/>doi.
          <allowbreak/>org/
          <allowbreak/>10.
          <allowbreak/>1016/
          <allowbreak/>j.
          <allowbreak/>cl.
          <allowbreak/>2010.
          <allowbreak/>09.
          <allowbreak/>001</ref>
        </imprint>
      </monogr>
      <affiliation>
        <country>IT</country>
      </affiliation>
    </biblStruct>
    <biblStruct dedoublkey="0797" id="abstraction-2011-bid34" type="article" rend="year" n="cite:CousotCousot-TCS11-grammar">
      <analytic>
        <title level="a">Grammar semantics, analysis and parsing by abstract interpretation</title>
        <author>
          <persName key="abstraction-2007-idm495957220928">
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957213728">
            <foreName>Radhia</foreName>
            <surname>Cousot</surname>
            <initial>R.</initial>
          </persName>
        </author>
      </analytic>
      <monogr id="rid01946" x-editorial-board="yes" x-international-audience="yes">
        <idno type="issn">0304-3975</idno>
        <title level="j">Theoretical Computer Science</title>
        <imprint>
          <biblScope type="volume">412</biblScope>
          <biblScope type="number">44</biblScope>
          <dateStruct>
            <year>2011</year>
          </dateStruct>
          <biblScope type="pages">6135-6192</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct dedoublkey="0970" subtype="nonparu" id="abstraction-2011-bid32" type="article" rend="year" n="cite:Feret-et-al-TCS">
      <identifiant type="doi" value="10.1016/j.tcs.2011.12.059"/>
      <analytic>
        <title level="a">Lumpability Abstractions of Rule-based Systems</title>
        <author>
          <persName key="abstraction-2007-idm495957193264">
            <foreName>Jérôme</foreName>
            <surname>Feret</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Thomas</foreName>
            <surname>Henzinger</surname>
            <initial>T.</initial>
          </persName>
          <persName>
            <foreName>Heinz</foreName>
            <surname>Koeppl</surname>
            <initial>H.</initial>
          </persName>
          <persName>
            <foreName>Tatjana</foreName>
            <surname>Petrov</surname>
            <initial>T.</initial>
          </persName>
        </author>
      </analytic>
      <monogr id="rid01946" x-editorial-board="yes" x-international-audience="yes">
        <idno type="issn">0304-3975</idno>
        <title level="j">Theorerical Computer Science</title>
        <imprint>
          <dateStruct>
            <year>2012</year>
          </dateStruct>
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://dx.doi.org/10.1016/j.tcs.2011.12.059" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>dx.
          <allowbreak/>doi.
          <allowbreak/>org/
          <allowbreak/>10.
          <allowbreak/>1016/
          <allowbreak/>j.
          <allowbreak/>tcs.
          <allowbreak/>2011.
          <allowbreak/>12.
          <allowbreak/>059</ref>
        </imprint>
      </monogr>
      <note type="bnote">to appear</note>
      <affiliation>
        <country>AT</country>
        <country>CH</country>
        <country>IT</country>
      </affiliation>
    </biblStruct>
    <biblStruct dedoublkey="3386" id="abstraction-2011-bid30" type="inproceedings" rend="year" n="cite:camporesi:2011:inria-00636850:1">
      <identifiant type="hal" value="inria-00636850"/>
      <identifiant type="doi" value="10.1016/j.entcs.2011.09.014"/>
      <analytic>
        <title level="a">Formal reduction for rule-based models</title>
        <author>
          <persName key="abstraction-2007-idm495957179744">
            <foreName>Ferdinanda</foreName>
            <surname>Camporesi</surname>
            <initial>F.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957193264">
            <foreName>Jérôme</foreName>
            <surname>Feret</surname>
            <initial>J.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes" x-invited-conference="yes">
        <editor role="editor">
          <persName>
            <foreName>Michael</foreName>
            <surname>Mislove</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>Joël</foreName>
            <surname>Ouaknine</surname>
            <initial>J.</initial>
          </persName>
        </editor>
        <title level="m">Post-proceedings of the the 27th Conference on the Mathematical Foundations of Programming Semantics - (MFPS'11)</title>
        <loc>Pittsburgh, United States</loc>
        <title level="s">Electronic Notes in Theoretical Computer Science</title>
        <imprint>
          <biblScope type="volume">276</biblScope>
          <publisher>
            <orgName>Elsevier</orgName>
          </publisher>
          <dateStruct>
            <month>September</month>
            <year>2011</year>
          </dateStruct>
          <biblScope type="pages">29-59</biblScope>
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://hal.inria.fr/inria-00636850/en" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>inria-00636850/
          <allowbreak/>en</ref>
        </imprint>
        <meeting id="cid49803">
          <title>Conference on the Mathematical Foundations of Programming Semantics</title>
          <num>27</num>
          <abbr type="sigle">MFPS</abbr>
        </meeting>
      </monogr>
      <affiliation>
        <country>IT</country>
      </affiliation>
    </biblStruct>
    <biblStruct dedoublkey="3593" id="abstraction-2011-bid35" type="inproceedings" rend="year" n="cite:Zanioli-information-flow">
      <analytic>
        <title level="a">Information Leakage Analysis by Abstract Interpretation</title>
        <author>
          <persName>
            <foreName>Agostino</foreName>
            <surname>Cortesi</surname>
            <initial>A.</initial>
          </persName>
          <persName key="abstraction-2009-idm361193205440">
            <foreName>Matteo</foreName>
            <surname>Zanioli</surname>
            <initial>M.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <title level="m">Proceedings of the 37th International Conference on Current Trends in Theory and Practice of Computer Science</title>
        <loc>Novy Smokovec Slovakia</loc>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">6543</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <year>2011</year>
          </dateStruct>
          <biblScope type="pages">545–557</biblScope>
        </imprint>
        <meeting id="cid46980">
          <title>Conference on Current Trends in Theory and Practice of Computer Science</title>
          <num>37</num>
          <abbr type="sigle">SOFSEM</abbr>
        </meeting>
      </monogr>
      <affiliation>
        <country>IT</country>
      </affiliation>
    </biblStruct>
    <biblStruct dedoublkey="2464" id="abstraction-2011-bid29" type="inproceedings" rend="year" n="cite:CousotCousot-POPL12">
      <analytic>
        <title level="a">An Abstract Interpretation Framework for Termination</title>
        <author>
          <persName key="abstraction-2007-idm495957220928">
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957213728">
            <foreName>Radhia</foreName>
            <surname>Cousot</surname>
            <initial>R.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <title level="m">Proceedings of the 39th Annual ACM Symposium on Principles Of Programming Languages (POPL'12)</title>
        <loc>Philadelphia, PA</loc>
        <imprint>
          <publisher>
            <orgName>ACM Press</orgName>
          </publisher>
          <dateStruct>
            <month>January 25–27</month>
            <year>2012</year>
          </dateStruct>
        </imprint>
        <meeting id="cid22344">
          <title>ACM SIGPLAN SIGACT Symposium on Principles of Programming Languages</title>
          <num>39</num>
          <abbr type="sigle">POPL</abbr>
        </meeting>
      </monogr>
      <affiliation>
        <country>US</country>
      </affiliation>
    </biblStruct>
    <biblStruct dedoublkey="2591" id="abstraction-2011-bid27" type="inproceedings" rend="year" n="cite:CousotCousotLogozzo-POPL11">
      <identifiant type="hal" value="inria-00543874"/>
      <analytic>
        <title level="a">A Parametric Segmentation Functor for Fully Automatic and Scalable Array Content Analysis</title>
        <author>
          <persName key="abstraction-2007-idm495957220928">
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957213728">
            <foreName>Radhia</foreName>
            <surname>Cousot</surname>
            <initial>R.</initial>
          </persName>
          <persName>
            <foreName>Francesco</foreName>
            <surname>Logozzo</surname>
            <initial>F.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <title level="m">Proceedings of the 38th Annual ACM Symposium on Principles Of Programming Languages (POPL'11)</title>
        <loc>Austin, Texas, United States</loc>
        <imprint>
          <publisher>
            <orgName>ACM Press</orgName>
          </publisher>
          <dateStruct>
            <year>2011</year>
          </dateStruct>
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://hal.inria.fr/inria-00543874/en" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>inria-00543874/
          <allowbreak/>en</ref>
        </imprint>
        <meeting id="cid22344">
          <title>ACM SIGPLAN SIGACT Symposium on Principles of Programming Languages</title>
          <num>38</num>
          <abbr type="sigle">POPL</abbr>
        </meeting>
      </monogr>
      <affiliation>
        <country>US</country>
      </affiliation>
    </biblStruct>
    <biblStruct dedoublkey="4227" id="abstraction-2011-bid42" type="inproceedings" rend="year" n="cite:CousotCousotLogozzo-VMCAI11">
      <identifiant type="hal" value="inria-00543881"/>
      <analytic>
        <title level="a">Precondition Inference from Intermittent Assertions and Application to Contracts on Collections</title>
        <author>
          <persName key="abstraction-2007-idm495957220928">
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957213728">
            <foreName>Radhia</foreName>
            <surname>Cousot</surname>
            <initial>R.</initial>
          </persName>
          <persName>
            <foreName>Francesco</foreName>
            <surname>Logozzo</surname>
            <initial>F.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <editor role="editor">
          <persName>
            <foreName>Ranjit</foreName>
            <surname>Jhala</surname>
            <initial>R.</initial>
          </persName>
          <persName>
            <foreName>David</foreName>
            <surname>Schmidt</surname>
            <initial>D.</initial>
          </persName>
        </editor>
        <title level="m">Proceedings of the 12th Conference on Verification, Model Checking and Abstract Interpretation (VMCAI'11)</title>
        <loc>Austin, Texas, United States</loc>
        <imprint>
          <publisher>
            <orgName>Springer-Verlag</orgName>
          </publisher>
          <dateStruct>
            <year>2011</year>
          </dateStruct>
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://hal.inria.fr/inria-00543881/en" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>inria-00543881/
          <allowbreak/>en</ref>
        </imprint>
        <meeting id="cid303616">
          <title>International Conference on Verification, Model Checking, and Abstract Interpretation</title>
          <num>12</num>
          <abbr type="sigle">VMCAI</abbr>
        </meeting>
      </monogr>
      <affiliation>
        <country>US</country>
      </affiliation>
    </biblStruct>
    <biblStruct dedoublkey="4741" id="abstraction-2011-bid41" type="inproceedings" rend="year" n="cite:CousotCousotMauborgne-FoSSaCS-11">
      <analytic>
        <title level="a">The Reduced Product of Abstract Domains and the Combination of Decision Procedures</title>
        <author>
          <persName key="abstraction-2007-idm495957220928">
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957213728">
            <foreName>Radhia</foreName>
            <surname>Cousot</surname>
            <initial>R.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957210304">
            <foreName>Laurent</foreName>
            <surname>Mauborgne</surname>
            <initial>L.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <editor role="editor">
          <persName key="pi.r2-2010-idm13291461888">
            <foreName>Martin</foreName>
            <surname>Hofmann</surname>
            <initial>M.</initial>
          </persName>
        </editor>
        <title level="m">Proceedings of Foundations of Software Science and Computational Structures - 14th International Conference, FOSSACS 2011, Held as Part of the Joint European Conferences on
        Theory and Practice of Software, ETAPS 2011</title>
        <loc>Saarbrücken, Germany</loc>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">6604</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>March-April</month>
            <year>2011</year>
          </dateStruct>
          <biblScope type="pages">456-472</biblScope>
        </imprint>
        <meeting id="cid282113">
          <title>International Conference on Foundations of Software Science and Computational Structures</title>
          <num>14</num>
          <abbr type="sigle">FOSSACS</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    <biblStruct dedoublkey="4255" subtype="nonparu" id="abstraction-2011-bid38" type="inproceedings" rend="year" n="cite:CousotMonerau-2011-ProbaAI">
      <analytic>
        <title level="a">Probabilistic Abstract Interpretation</title>
        <author>
          <persName key="abstraction-2007-idm495957220928">
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
          <persName>
            <foreName>Michael</foreName>
            <surname>Monerau</surname>
            <initial>M.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <editor role="editor">
          <persName>
            <foreName>Helmut</foreName>
            <surname>Seidl</surname>
            <initial>H.</initial>
          </persName>
        </editor>
        <title level="m">Proceedings of the 21th European Symposium on Programming (ESOP'12)</title>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>March</month>
            <year>2012</year>
          </dateStruct>
        </imprint>
        <meeting id="cid71137">
          <title>European Symposium on Programming</title>
          <num>21</num>
          <abbr type="sigle">ESOP</abbr>
        </meeting>
      </monogr>
      <note type="bnote">to appear</note>
    </biblStruct>
    <biblStruct dedoublkey="3385" id="abstraction-2011-bid31" type="inproceedings" rend="year" n="cite:feret:2011:inria-00626640:1">
      <identifiant type="hal" value="inria-00626640"/>
      <identifiant type="doi" value="10.1007/978-3-642-23702-7_5"/>
      <analytic>
        <title level="a">Formal Model Reduction</title>
        <author>
          <persName key="abstraction-2007-idm495957193264">
            <foreName>Jérôme</foreName>
            <surname>Feret</surname>
            <initial>J.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes" x-invited-conference="yes">
        <editor role="editor">
          <persName>
            <foreName>Eran</foreName>
            <surname>Yahav</surname>
            <initial>E.</initial>
          </persName>
        </editor>
        <title level="m">Proceedings of the 18th International Static Analysis Symposium (SAS'11)</title>
        <loc>Venice, Italy</loc>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">6887</biblScope>
          <dateStruct>
            <year>2011</year>
          </dateStruct>
          <biblScope type="pages">6–6</biblScope>
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://hal.inria.fr/inria-00626640/en" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>inria-00626640/
          <allowbreak/>en</ref>
        </imprint>
        <meeting id="cid311103">
          <title>International Static Analysis Symposium</title>
          <num>18</num>
          <abbr type="sigle">SAS</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    <biblStruct dedoublkey="4453" subtype="nonparu" id="abstraction-2011-bid36" type="inproceedings" rend="year" n="cite:Zanioli-SAILS">
      <analytic>
        <title level="a">SAILS: static analysis of information leakage with Sample</title>
        <author>
          <persName key="abstraction-2009-idm361193205440">
            <foreName>Matteo</foreName>
            <surname>Zanioli</surname>
            <initial>M.</initial>
          </persName>
          <persName key="abstraction-2008-idm357040857616">
            <foreName>Pietro</foreName>
            <surname>Ferrara</surname>
            <initial>P.</initial>
          </persName>
          <persName>
            <foreName>Agostino</foreName>
            <surname>Cortesi</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <title level="m">Proceedings of the 27th ACM Symposium on Applied Computing (SAC'12)</title>
        <loc>Riva del Garda, Italy</loc>
        <imprint>
          <publisher>
            <orgName>ACM Press</orgName>
          </publisher>
          <dateStruct>
            <year>2012</year>
          </dateStruct>
        </imprint>
        <meeting id="cid23923">
          <title>ACM Symposium on Applied Computing</title>
          <num>27</num>
          <abbr type="sigle">SAC</abbr>
        </meeting>
      </monogr>
      <note type="bnote">to appear</note>
      <affiliation>
        <country>IT</country>
        <country>CH</country>
      </affiliation>
    </biblStruct>
    <biblStruct dedoublkey="3734" id="abstraction-2011-bid37" type="inproceedings" rend="year" n="cite:chen-al:ESOP2011">
      <identifiant type="hal" value="hal-00648039"/>
      <analytic>
        <title level="a">Linear Absolute Value Relation Analysis</title>
        <author>
          <persName key="abstraction-2008-idm357040833344">
            <foreName>Liqian</foreName>
            <surname>Chen</surname>
            <initial>L.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957206736">
            <foreName>Antoine</foreName>
            <surname>Miné</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Ji</foreName>
            <surname>Wang</surname>
            <initial>J.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957220928">
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <editor role="editor">
          <persName key="everest-2006-idm306718613568">
            <foreName>Gilles</foreName>
            <surname>Barthe</surname>
            <initial>G.</initial>
          </persName>
        </editor>
        <title level="m">Proceedings of the 20th European Symposium on Programming (ESOP'11)</title>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">6602</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <year>2011</year>
          </dateStruct>
          <biblScope type="pages">156–175</biblScope>
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://hal.inria.fr/hal-00648039/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>hal-00648039/
          <allowbreak/></ref>
        </imprint>
        <meeting id="cid71137">
          <title>European Symposium on Programming</title>
          <num>20</num>
          <abbr type="sigle">ESOP</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    <biblStruct dedoublkey="4626" id="abstraction-2011-bid19" type="inproceedings" rend="year" n="cite:mine:ESOP2011">
      <identifiant type="hal" value="hal-00648038"/>
      <analytic>
        <title level="a">Static Analysis of Run-Time Errors in Embedded Critical Parallel C Programs</title>
        <author>
          <persName key="abstraction-2007-idm495957206736">
            <foreName>Antoine</foreName>
            <surname>Miné</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <editor role="editor">
          <persName key="everest-2006-idm306718613568">
            <foreName>Gilles</foreName>
            <surname>Barthe</surname>
            <initial>G.</initial>
          </persName>
        </editor>
        <title level="m">Proceedings of the 20th European Symposium on Programming (ESOP'11)</title>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">6602</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <year>2011</year>
          </dateStruct>
          <biblScope type="pages">398–418</biblScope>
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://hal.inria.fr/hal-00648038" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>hal-00648038</ref>
        </imprint>
        <meeting id="cid71137">
          <title>European Symposium on Programming</title>
          <num>20</num>
          <abbr type="sigle">ESOP</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    <biblStruct dedoublkey="2827" id="abstraction-2011-bid39" type="inproceedings" rend="year" n="cite:xisa:popl:11">
      <analytic>
        <title level="a">Calling Contexts Abstraction with Shapes</title>
        <author>
          <persName key="abstraction-2007-idm495957200624">
            <foreName>Xavier</foreName>
            <surname>Rival</surname>
            <initial>X.</initial>
          </persName>
          <persName>
            <foreName>Bor-Yuh Evan</foreName>
            <surname>Chang</surname>
            <initial>B.-Y. E.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <title level="m">Proceedings of the 38th Annual ACM Symposium on Principles Of Programming Languages (POPL'10)</title>
        <loc>Austin, Texas</loc>
        <imprint>
          <publisher>
            <orgName>ACM Press</orgName>
          </publisher>
          <dateStruct>
            <month>January 26–28,</month>
            <year>2011</year>
          </dateStruct>
        </imprint>
        <meeting id="cid22344">
          <title>ACM SIGPLAN SIGACT Symposium on Principles of Programming Languages</title>
          <num>38</num>
          <abbr type="sigle">POPL</abbr>
        </meeting>
      </monogr>
      <affiliation>
        <country>US</country>
      </affiliation>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid17" type="inproceedings" rend="foot" n="footcite:Cousot07-EMSOFT">
      <analytic>
        <title level="a">Proving the Absence of Run-Time Errors in Safety-Critical Avionics Code, invited tutorial</title>
        <author>
          <persName key="abstraction-2007-idm495957220928">
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName key="calvi-2006-idm468055658496">
            <foreName>Christoph M.</foreName>
            <surname>Kirsch</surname>
            <initial>C. M.</initial>
          </persName>
          <persName>
            <foreName>Reinhard</foreName>
            <surname>Wilhelm</surname>
            <initial>R.</initial>
          </persName>
        </editor>
        <title level="m">Proceedings of the Seventh ACM &amp; IEEE International Conference on Embedded Software, EMSOFT'2007</title>
        <imprint>
          <publisher>
            <orgName>ACM Press, New York, USA</orgName>
          </publisher>
          <dateStruct>
            <year>2007</year>
          </dateStruct>
          <biblScope type="pages">7–9</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid2" type="phdthesis" rend="foot" n="footcite:Cousot78-1-TheseEtat">
      <monogr>
        <title level="m">Méthodes itératives de construction et d'approximation de points fixes d'opérateurs monotones sur un treillis, analyse sémantique de programmes (in French)</title>
        <author>
          <persName key="abstraction-2007-idm495957220928">
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="school">Université scientifique et médicale de Grenoble</orgName>
            <address>
              <addrLine>Grenoble, France</addrLine>
            </address>
          </publisher>
          <dateStruct>
            <month>21 March</month>
            <year>1978</year>
          </dateStruct>
        </imprint>
      </monogr>
      <note type="typdoc">Thèse d'État ès sciences mathématiques</note>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid6" type="techreport" rend="foot" n="footcite:CousotR-CRIN-80-P050-jul-1980">
      <monogr>
        <title level="m">Reasoning about program invariance proof methods</title>
        <author>
          <persName key="abstraction-2007-idm495957213728">
            <foreName>Radhia</foreName>
            <surname>Cousot</surname>
            <initial>R.</initial>
          </persName>
        </author>
        <imprint>
          <biblScope type="number">CRIN-80-P050</biblScope>
          <publisher>
            <orgName type="institution">Centre de Recherche en Informatique de Nancy (CRIN), Institut National Polytechnique de Lorraine
            <address><addrLine>Nancy, France</addrLine></address></orgName>
          </publisher>
          <dateStruct>
            <month>July</month>
            <year>1980</year>
          </dateStruct>
        </imprint>
      </monogr>
      <note type="typdoc">Res. rep.</note>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid4" type="incollection" rend="foot" n="footcite:Cousot81-1">
      <analytic>
        <title level="a">Semantic Foundations of Program Analysis</title>
        <author>
          <persName key="abstraction-2007-idm495957220928">
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Steven S.</foreName>
            <surname>Muchnick</surname>
            <initial>S. S.</initial>
          </persName>
          <persName>
            <foreName>Niel D.</foreName>
            <surname>Jones</surname>
            <initial>N. D.</initial>
          </persName>
        </editor>
        <title level="m">Program Flow Analysis: Theory and Applications</title>
        <imprint>
          <biblScope type="chapter">10</biblScope>
          <publisher>
            <orgName>Prentice-Hall, Inc., Englewood Cliffs, New Jersey</orgName>
          </publisher>
          <dateStruct>
            <year>1981</year>
          </dateStruct>
          <biblScope type="pages">303–342</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid7" type="techreport" rend="foot" n="footcite:CousotR-RR-LRIM-82-02-mar-1981">
      <monogr>
        <title level="m">Proving invariance properties of parallel programs by backward induction</title>
        <author>
          <persName key="abstraction-2007-idm495957213728">
            <foreName>Radhia</foreName>
            <surname>Cousot</surname>
            <initial>R.</initial>
          </persName>
        </author>
        <imprint>
          <biblScope type="number">LRIM-82-02</biblScope>
          <publisher>
            <orgName type="institution">University Paul Verlaine
            <address><addrLine>Metz, France</addrLine></address></orgName>
          </publisher>
          <dateStruct>
            <month>March</month>
            <year>1981</year>
          </dateStruct>
        </imprint>
      </monogr>
      <note type="typdoc">Res. rep.</note>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid5" type="phdthesis" rend="foot" n="footcite:CousotR-TheseEtat-1985">
      <monogr>
        <title level="m">Fondements des méthodes de preuve d'invariance et de fatalité de programmes parallèles (in French)</title>
        <author>
          <persName key="abstraction-2007-idm495957213728">
            <foreName>Radhia</foreName>
            <surname>Cousot</surname>
            <initial>R.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="school">Institut National Polytechnique de Lorraine</orgName>
            <address>
              <addrLine>Nancy, France</addrLine>
            </address>
          </publisher>
          <dateStruct>
            <month>21 November</month>
            <year>1985</year>
          </dateStruct>
        </imprint>
      </monogr>
      <note type="typdoc">Thèse d'État ès sciences mathématiques</note>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid15" type="incollection" rend="foot" n="footcite:Cousot99-3-Marktoberdorf-paper">
      <analytic>
        <title level="a">The Calculational Design of a Generic Abstract Interpreter, invited chapter</title>
        <author>
          <persName key="abstraction-2007-idm495957220928">
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Manfred</foreName>
            <surname>Broy</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>Ralf</foreName>
            <surname>Steinbrüggen</surname>
            <initial>R.</initial>
          </persName>
        </editor>
        <title level="m">Calculational System Design</title>
        <imprint>
          <biblScope type="volume">173</biblScope>
          <publisher>
            <orgName>NATO Science Series, Series F: Computer and Systems Sciences. IOS Press, Amsterdam, The Netherlands</orgName>
          </publisher>
          <dateStruct>
            <year>1999</year>
          </dateStruct>
          <biblScope type="pages">421–505</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid16" type="incollection" rend="foot" n="footcite:CousotCousot04-WCC">
      <analytic>
        <title level="a">Basic Concepts of Abstract Interpretation, invited chapter</title>
        <author>
          <persName key="abstraction-2007-idm495957220928">
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957213728">
            <foreName>Radhia</foreName>
            <surname>Cousot</surname>
            <initial>R.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>René</foreName>
            <surname>Jacquart</surname>
            <initial>R.</initial>
          </persName>
        </editor>
        <title level="m">Building the Information Society</title>
        <imprint>
          <biblScope type="chapter">4</biblScope>
          <publisher>
            <orgName>Kluwer Academic Publishers, Dordrecht, The Netherlands</orgName>
          </publisher>
          <dateStruct>
            <year>2004</year>
          </dateStruct>
          <biblScope type="pages">359–366</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid10" type="inproceedings" rend="foot" n="footcite:CousotCousot07-RW">
      <analytic>
        <title level="a">Grammar Analysis and Parsing by Abstract Interpretation, invited chapter</title>
        <author>
          <persName key="abstraction-2007-idm495957220928">
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957213728">
            <foreName>Radhia</foreName>
            <surname>Cousot</surname>
            <initial>R.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Thomas W.</foreName>
            <surname>Reps</surname>
            <initial>T. W.</initial>
          </persName>
          <persName>
            <foreName>Mooly</foreName>
            <surname>Sagiv</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>Jörg</foreName>
            <surname>Bauer</surname>
            <initial>J.</initial>
          </persName>
        </editor>
        <title level="m">Program Analysis and Compilation, Theory and Practice: Essays dedicated to Reinhard Wilhelm on the Occasion of his 60th Birthday</title>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">4444</biblScope>
          <publisher>
            <orgName>Springer, Berlin, Germany</orgName>
          </publisher>
          <dateStruct>
            <year>2007</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid11" type="article" rend="foot" n="footcite:CousotCousot09-BISOS">
      <analytic>
        <title level="a">Bi-inductive structural semantics</title>
        <author>
          <persName key="abstraction-2007-idm495957220928">
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957213728">
            <foreName>Radhia</foreName>
            <surname>Cousot</surname>
            <initial>R.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-editorial-board="yes" x-international-audience="yes">
        <title level="j">Information and Computation</title>
        <imprint>
          <biblScope type="volume">207</biblScope>
          <biblScope type="number">2</biblScope>
          <dateStruct>
            <year>2009</year>
          </dateStruct>
          <biblScope type="pages">258–283</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid1" type="inproceedings" rend="foot" n="footcite:CousotCousot77-1">
      <analytic>
        <title level="a">Abstract interpretation: a unified lattice model for static analysis of programs by construction or approximation of fixpoints</title>
        <author>
          <persName key="abstraction-2007-idm495957220928">
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957213728">
            <foreName>Radhia</foreName>
            <surname>Cousot</surname>
            <initial>R.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">Conference Record of the Fourth Annual ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages</title>
        <imprint>
          <publisher>
            <orgName>ACM Press, New York, United States</orgName>
          </publisher>
          <dateStruct>
            <year>1977</year>
          </dateStruct>
          <biblScope type="pages">238–252</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid3" type="inproceedings" rend="foot" n="footcite:CousotCousot79-1-POPL">
      <analytic>
        <title level="a">Systematic design of program analysis frameworks</title>
        <author>
          <persName key="abstraction-2007-idm495957220928">
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957213728">
            <foreName>Radhia</foreName>
            <surname>Cousot</surname>
            <initial>R.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">Conference Record of the Sixth Annual ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages</title>
        <loc>San Antonio, Texas</loc>
        <imprint>
          <publisher>
            <orgName>ACM Press, New York, NY, USA</orgName>
          </publisher>
          <dateStruct>
            <year>1979</year>
          </dateStruct>
          <biblScope type="pages">269–282</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid9" type="inproceedings" rend="foot" n="footcite:CousotCousot80-1-ICALP">
      <analytic>
        <title level="a">Semantic analysis of communicating sequential processes</title>
        <author>
          <persName key="abstraction-2007-idm495957220928">
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957213728">
            <foreName>Radhia</foreName>
            <surname>Cousot</surname>
            <initial>R.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Jaco W.</foreName>
            <surname>de Bakker</surname>
            <initial>J. W.</initial>
          </persName>
          <persName>
            <foreName>Jan</foreName>
            <surname>van Leeuwen</surname>
            <initial>J.</initial>
          </persName>
        </editor>
        <title level="m">Seventh International Colloquium on Automata, Languages and Programming</title>
        <title level="s">Lecture Notes in Computer Science 85</title>
        <imprint>
          <publisher>
            <orgName>Springer-Verlag, Berlin, Germany</orgName>
          </publisher>
          <dateStruct>
            <month>July</month>
            <year>1980</year>
          </dateStruct>
          <biblScope type="pages">119–133</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid8" type="incollection" rend="foot" n="footcite:CousotCousot84-1">
      <analytic>
        <title level="a">Invariance Proof Methods and Analysis Techniques For Parallel Programs</title>
        <author>
          <persName key="abstraction-2007-idm495957220928">
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957213728">
            <foreName>Radhia</foreName>
            <surname>Cousot</surname>
            <initial>R.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Alan W.</foreName>
            <surname>Biermann</surname>
            <initial>A. W.</initial>
          </persName>
          <persName>
            <foreName>Gérard</foreName>
            <surname>Guiho</surname>
            <initial>G.</initial>
          </persName>
          <persName>
            <foreName>Yves</foreName>
            <surname>Kodratoff</surname>
            <initial>Y.</initial>
          </persName>
        </editor>
        <title level="m">Automatic Program Construction Techniques</title>
        <imprint>
          <biblScope type="chapter">12</biblScope>
          <publisher>
            <orgName>Macmillan, New York, New York, United States</orgName>
          </publisher>
          <dateStruct>
            <year>1984</year>
          </dateStruct>
          <biblScope type="pages">243–271</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid28" type="inproceedings" rend="foot" n="footcite:CousotCousot94-1">
      <analytic>
        <title level="a">Higher-Order Abstract Interpretation (and Application to Comportment Analysis Generalizing Strictness, Termination, Projection and PER Analysis of Functional Languages),
        invited paper</title>
        <author>
          <persName key="abstraction-2007-idm495957220928">
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957213728">
            <foreName>Radhia</foreName>
            <surname>Cousot</surname>
            <initial>R.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">Proceedings of the 1994 International Conference on Computer Languages</title>
        <loc>Toulouse, France</loc>
        <imprint>
          <publisher>
            <orgName>IEEE Computer Society Press, Los Alamitos, California</orgName>
          </publisher>
          <dateStruct>
            <month>16–19 May</month>
            <year>1994</year>
          </dateStruct>
          <biblScope type="pages">95–112</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid14" type="incollection" rend="foot" n="footcite:CousotEtAl05-ESOP">
      <analytic>
        <title level="a">The 
        <span class="smallcap" align="left">Astrée</span>analyser</title>
        <author>
          <persName key="abstraction-2007-idm495957220928">
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957213728">
            <foreName>Radhia</foreName>
            <surname>Cousot</surname>
            <initial>R.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957193264">
            <foreName>Jérôme</foreName>
            <surname>Feret</surname>
            <initial>J.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957210304">
            <foreName>Laurent</foreName>
            <surname>Mauborgne</surname>
            <initial>L.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957206736">
            <foreName>Antoine</foreName>
            <surname>Miné</surname>
            <initial>A.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957203728">
            <foreName>David</foreName>
            <surname>Monniaux</surname>
            <initial>D.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957200624">
            <foreName>Xavier</foreName>
            <surname>Rival</surname>
            <initial>X.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Mooly</foreName>
            <surname>Sagiv</surname>
            <initial>M.</initial>
          </persName>
        </editor>
        <title level="m">Proceedings of the Fourteenth European Symposium on Programming Languages and Systems, ESOP'2005, Edinburg, Scotland</title>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">3444</biblScope>
          <publisher>
            <orgName>Springer, Berlin, Germany</orgName>
          </publisher>
          <dateStruct>
            <month>2–10 April</month>
            <year>2005</year>
          </dateStruct>
          <biblScope type="pages">21–30</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid18" type="inproceedings" rend="foot" n="footcite:CousotEtAl-TASE07">
      <analytic>
        <title level="a">Varieties of Static Analyzers: A Comparison with 
        <span class="smallcap" align="left">Astrée</span>, invited paper</title>
        <author>
          <persName key="abstraction-2007-idm495957220928">
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957213728">
            <foreName>Radhia</foreName>
            <surname>Cousot</surname>
            <initial>R.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957193264">
            <foreName>Jérôme</foreName>
            <surname>Feret</surname>
            <initial>J.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957210304">
            <foreName>Laurent</foreName>
            <surname>Mauborgne</surname>
            <initial>L.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957206736">
            <foreName>Antoine</foreName>
            <surname>Miné</surname>
            <initial>A.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957203728">
            <foreName>David</foreName>
            <surname>Monniaux</surname>
            <initial>D.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957200624">
            <foreName>Xavier</foreName>
            <surname>Rival</surname>
            <initial>X.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Michael</foreName>
            <surname>Hinchey</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>Jifeng</foreName>
            <surname>He</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Jeff</foreName>
            <surname>Sanders</surname>
            <initial>J.</initial>
          </persName>
        </editor>
        <title level="m">Proceedings of the First IEEE &amp; IFIP International Symposium on Theoretical Aspects of Software Engineering, TASE'07</title>
        <loc>Shanghai, China</loc>
        <imprint>
          <publisher>
            <orgName>IEEE Computer Society Press, Los Alamitos, California, USA</orgName>
          </publisher>
          <dateStruct>
            <month>6–8 June</month>
            <year>2007</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid12" type="article" rend="foot" n="footcite:CousotEtAl-GiorgioLevifestschrift-09">
      <analytic>
        <title level="a">Abstract Interpretation of Resolution-Based Semantics</title>
        <author>
          <persName key="abstraction-2007-idm495957220928">
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957213728">
            <foreName>Radhia</foreName>
            <surname>Cousot</surname>
            <initial>R.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957166016">
            <foreName>Roberto</foreName>
            <surname>Giacobazzi</surname>
            <initial>R.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-editorial-board="yes" x-international-audience="yes">
        <title level="j">Theoretical Computer Science</title>
        <imprint>
          <biblScope type="volume">410</biblScope>
          <biblScope type="number">46</biblScope>
          <dateStruct>
            <month>Nov.</month>
            <year>2009</year>
          </dateStruct>
        </imprint>
      </monogr>
      <affiliation>
        <country>IT</country>
      </affiliation>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid25" type="inproceedings" rend="foot" n="footcite:danos:2010:hal-00520112:1">
      <identifiant type="hal" value="hal-00520112"/>
      <analytic>
        <title level="a">Abstracting the differential semantics of rule-based models: exact and automated model reduction</title>
        <author>
          <persName>
            <foreName>Vincent</foreName>
            <surname>Danos</surname>
            <initial>V.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957193264">
            <foreName>Jérôme</foreName>
            <surname>Feret</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Walter</foreName>
            <surname>Fontana</surname>
            <initial>W.</initial>
          </persName>
          <persName>
            <foreName>Russ</foreName>
            <surname>Harmer</surname>
            <initial>R.</initial>
          </persName>
          <persName key="moscova-2006-idm117579657776">
            <foreName>Jean</foreName>
            <surname>Krivine</surname>
            <initial>J.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes" x-invited-conference="yes">
        <editor role="editor">
          <persName key="logical-2006-idm356512386880">
            <foreName>Jean-Pierre</foreName>
            <surname>Jouannaud</surname>
            <initial>J.-P.</initial>
          </persName>
        </editor>
        <title level="m">Proceedings of Logic in Computer Science (LICS 2010), Edinburgh, UK</title>
        <imprint>
          <dateStruct>
            <year>2010</year>
          </dateStruct>
          <biblScope type="pages">362–381</biblScope>
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://hal.inria.fr/hal-00520112" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>hal-00520112</ref>
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://hal.inria.fr/hal-00520112" type="hal" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>hal-00520112</ref>
        </imprint>
      </monogr>
      <affiliation>
        <country>GB</country>
        <country>US</country>
      </affiliation>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid26" type="article" rend="foot" n="footcite:harmer:2010:hal-00520128:1">
      <identifiant type="hal" value="hal-00520128"/>
      <analytic>
        <title level="a">Intrinsic Information carriers in combinatorial dynamical systems</title>
        <author>
          <persName>
            <foreName>Russ</foreName>
            <surname>Harmer</surname>
            <initial>R.</initial>
          </persName>
          <persName>
            <foreName>Vincent</foreName>
            <surname>Danos</surname>
            <initial>V.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957193264">
            <foreName>Jérôme</foreName>
            <surname>Feret</surname>
            <initial>J.</initial>
          </persName>
          <persName key="moscova-2006-idm117579657776">
            <foreName>Jean</foreName>
            <surname>Krivine</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Walter</foreName>
            <surname>Fontana</surname>
            <initial>W.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-editorial-board="yes" x-international-audience="yes">
        <title level="j">Chaos</title>
        <imprint>
          <biblScope type="volume">20</biblScope>
          <biblScope type="number">3</biblScope>
          <dateStruct>
            <year>2010</year>
          </dateStruct>
          <biblScope type="pages">037108</biblScope>
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://hal.inria.fr/hal-00520128" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>hal-00520128</ref>
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://hal.inria.fr/hal-00520128" type="hal" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>hal-00520128</ref>
        </imprint>
      </monogr>
      <affiliation>
        <country>GB</country>
        <country>US</country>
      </affiliation>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid23" type="inproceedings" rend="foot" n="footcite:DANOS:2007:HAL-00164297:1">
      <identifiant type="hal" value="hal-00164297"/>
      <analytic>
        <title level="a">Rule-based modelling of cellular signalling</title>
        <author>
          <persName>
            <foreName>Vincent</foreName>
            <surname>Danos</surname>
            <initial>V.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957193264">
            <foreName>Jérôme</foreName>
            <surname>Feret</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Walter</foreName>
            <surname>Fontana</surname>
            <initial>W.</initial>
          </persName>
          <persName>
            <foreName>Russ</foreName>
            <surname>Harmer</surname>
            <initial>R.</initial>
          </persName>
          <persName key="moscova-2006-idm117579657776">
            <foreName>Jean</foreName>
            <surname>Krivine</surname>
            <initial>J.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">Proceedings of the 18th International Conference on Concurrency Theory (CONCUR'07)</title>
        <loc>Portugal</loc>
        <imprint>
          <biblScope type="volume">4703</biblScope>
          <dateStruct>
            <month>September</month>
            <year>2007</year>
          </dateStruct>
          <biblScope type="pages">17–41</biblScope>
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://hal.archives-ouvertes.fr/hal-00164297/en/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>archives-ouvertes.
          <allowbreak/>fr/
          <allowbreak/>hal-00164297/
          <allowbreak/>en/
          <allowbreak/></ref>
        </imprint>
      </monogr>
      <affiliation>
        <country>US</country>
      </affiliation>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid22" type="inproceedings" rend="foot" n="footcite:DANOS:2007:INRIA-00528409:1">
      <identifiant type="hal" value="inria-00528409"/>
      <identifiant type="doi" value="10.1.1.139.5120"/>
      <analytic>
        <title level="a">Scalable Simulation of Cellular Signaling Networks</title>
        <author>
          <persName>
            <foreName>Vincent</foreName>
            <surname>Danos</surname>
            <initial>V.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957193264">
            <foreName>Jérôme</foreName>
            <surname>Feret</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Walter</foreName>
            <surname>Fontana</surname>
            <initial>W.</initial>
          </persName>
          <persName key="moscova-2006-idm117579657776">
            <foreName>Jean</foreName>
            <surname>Krivine</surname>
            <initial>J.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Zhong</foreName>
            <surname>Shao</surname>
            <initial>Z.</initial>
          </persName>
        </editor>
        <title level="m">Proceedings of the 5th Asian Symposium on Programming Languages and Systems - APLAS'07</title>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">4807</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <publisher>
            <orgName type="organisation">Shao, Z.</orgName>
          </publisher>
          <dateStruct>
            <year>2007</year>
          </dateStruct>
          <biblScope type="pages">139-157</biblScope>
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://hal.inria.fr/inria-00528409/en/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>inria-00528409/
          <allowbreak/>en/
          <allowbreak/></ref>
        </imprint>
      </monogr>
      <affiliation>
        <country>US</country>
      </affiliation>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid21" type="inproceedings" rend="foot" n="footcite:DANOS:2008:INRIA-00528352:1">
      <identifiant type="hal" value="inria-00528352"/>
      <identifiant type="doi" value="10.1007/978-3-540-78163-9_11"/>
      <analytic>
        <title level="a">Abstract Interpretation of Cellular Signalling Networks</title>
        <author>
          <persName>
            <foreName>Vincent</foreName>
            <surname>Danos</surname>
            <initial>V.</initial>
          </persName>
          <persName key="abstraction-2007-idm495957193264">
            <foreName>Jérôme</foreName>
            <surname>Feret</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Walter</foreName>
            <surname>Fontana</surname>
            <initial>W.</initial>
          </persName>
          <persName key="moscova-2006-idm117579657776">
            <foreName>Jean</foreName>
            <surname>Krivine</surname>
            <initial>J.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Francesco</foreName>
            <surname>Logozzo</surname>
            <initial>F.</initial>
          </persName>
          <persName>
            <foreName>Doron A.</foreName>
            <surname>Peled</surname>
            <initial>D. A.</initial>
          </persName>
          <persName>
            <foreName>Lenore D.</foreName>
            <surname>Zuck</surname>
            <initial>L. D.</initial>
          </persName>
        </editor>
        <title level="m">Proceedings of the 9th International Conference on Verification, Model Checking and Abstract Interpretation - VMCAI'08</title>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">4905</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <year>2008</year>
          </dateStruct>
          <biblScope type="pages">83-97</biblScope>
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://hal.inria.fr/inria-00528352/en/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>inria.
          <allowbreak/>fr/
          <allowbreak/>inria-00528352/
          <allowbreak/>en/
          <allowbreak/></ref>
        </imprint>
      </monogr>
      <affiliation>
        <country>US</country>
      </affiliation>
    </biblStruct>
    <biblStruct id="abstraction-2011-bid20" type="article" rend="foot" n="footcite:DANOS:2004:HAL-00164591:1">
      <identifiant type="hal" value="hal-00164591"/>
      <identifiant type="doi" value="10.1016/j.tcs.2004.03.065"/>
      <analytic>
        <title level="a">Formal Molecular Biology</title>
        <author>
          <persName>
            <foreName>Vincent</foreName>
            <surname>Danos</surname>
            <initial>V.</initial>
          </persName>
          <persName key="comete-2007-idm109955384688">
            <foreName>Cosimo</foreName>
            <surname>Laneve</surname>
            <initial>C.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Theoretical Computer Science</title>
        <imprint>
          <biblScope type="volume">325</biblScope>
          <biblScope type="number">1</biblScope>
          <dateStruct>
            <month>10</month>
            <year>2004</year>
          </dateStruct>
          <biblScope type="pages">69-110</biblScope>
          <ref xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="http://hal.archives-ouvertes.fr/hal-00164591/en/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://
          <allowbreak/>hal.
          <allowbreak/>archives-ouvertes.
          <allowbreak/>fr/
          <allowbreak/>hal-00164591/
          <allowbreak/>en/
          <allowbreak/></ref>
        </imprint>
      </monogr>
    </biblStruct>
  </biblio>
</raweb>
