<?xml version="1.0" encoding="utf-8"?>
<raweb xmlns:xlink="http://www.w3.org/1999/xlink" xml:lang="en" year="2018">
  <identification id="antique" isproject="true">
    <shortname>ANTIQUE</shortname>
    <projectName>Static Analysis by Abstract Interpretation</projectName>
    <theme-de-recherche>Proofs and Verification</theme-de-recherche>
    <domaine-de-recherche>Algorithmics, Programming, Software and Architecture</domaine-de-recherche>
    <urlTeam>https://team.inria.fr/antique/</urlTeam>
    <structure_exterieure type="Labs">
      <libelle>Département d'Informatique de l'Ecole Normale Supérieure</libelle>
    </structure_exterieure>
    <structure_exterieure type="Organism">
      <libelle>CNRS</libelle>
    </structure_exterieure>
    <structure_exterieure type="Organism">
      <libelle>Ecole normale supérieure de Paris</libelle>
    </structure_exterieure>
    <header_dates_team>Creation of the Team: 2014 January 01, updated into Project-Team: 2015 April 01</header_dates_team>
    <LeTypeProjet>Project-Team</LeTypeProjet>
    <keywordsSdN>
      <term>A2. - Software</term>
      <term>A2.1. - Programming Languages</term>
      <term>A2.1.1. - Semantics of programming languages</term>
      <term>A2.1.7. - Distributed programming</term>
      <term>A2.1.12. - Dynamic languages</term>
      <term>A2.2.1. - Static analysis</term>
      <term>A2.3. - Embedded and cyber-physical systems</term>
      <term>A2.3.1. - Embedded systems</term>
      <term>A2.3.2. - Cyber-physical systems</term>
      <term>A2.3.3. - Real-time systems</term>
      <term>A2.4. - Formal method for verification, reliability, certification</term>
      <term>A2.4.1. - Analysis</term>
      <term>A2.4.2. - Model-checking</term>
      <term>A2.4.3. - Proofs</term>
      <term>A2.6.1. - Operating systems</term>
      <term>A4.4. - Security of equipment and software</term>
      <term>A4.5. - Formal methods for security</term>
    </keywordsSdN>
    <keywordsSecteurs>
      <term>B1.1. - Biology</term>
      <term>B1.1.8. - Mathematical biology</term>
      <term>B1.1.10. - Systems and synthetic biology</term>
      <term>B5.2. - Design and manufacturing</term>
      <term>B5.2.1. - Road vehicles</term>
      <term>B5.2.2. - Railway</term>
      <term>B5.2.3. - Aviation</term>
      <term>B5.2.4. - Aerospace</term>
      <term>B6.1. - Software industry</term>
      <term>B6.1.1. - Software engineering</term>
      <term>B6.1.2. - Software evolution, maintenance</term>
      <term>B6.6. - Embedded systems</term>
    </keywordsSecteurs>
    <UR name="Paris"/>
  </identification>
  <team id="uid1">
    <person key="antique-2018-idp120512">
      <firstname>Xavier</firstname>
      <lastname>Rival</lastname>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Team leader, Inria, Senior Researcher</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="antique-2018-idp123424">
      <firstname>Vincent</firstname>
      <lastname>Danos</lastname>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>CNRS, Senior Researcher</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="antique-2018-idp126272">
      <firstname>Cezara</firstname>
      <lastname>Drăgoi</lastname>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria, Researcher</moreinfo>
    </person>
    <person key="antique-2018-idp128736">
      <firstname>Jérôme</firstname>
      <lastname>Feret</lastname>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria, Researcher</moreinfo>
    </person>
    <person key="antique-2018-idp131200">
      <firstname>Andreea</firstname>
      <lastname>Beica</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Ecole Normale Supérieure Paris</moreinfo>
    </person>
    <person key="antique-2018-idp133680">
      <firstname>Gaëlle</firstname>
      <lastname>Candel</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Keymetrics</moreinfo>
    </person>
    <person key="antique-2018-idp136112">
      <firstname>Marc</firstname>
      <lastname>Chevalier</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Ecole Normale Supérieure Lyon</moreinfo>
    </person>
    <person key="antique-2018-idp138592">
      <firstname>Hugo</firstname>
      <lastname>Illous</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Ecole Normale Supérieure Paris</moreinfo>
    </person>
    <person key="antique-2018-idp141072">
      <firstname>Huisong</firstname>
      <lastname>Li</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria, until Feb 2018</moreinfo>
    </person>
    <person key="antique-2018-idp143520">
      <firstname>Thibault</firstname>
      <lastname>Suzanne</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Ecole Normale Supérieure Paris</moreinfo>
    </person>
    <person key="antique-2018-idp146000">
      <firstname>Ferdinanda</firstname>
      <lastname>Camporesi</lastname>
      <categoryPro>Technique</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria, until Apr 2018</moreinfo>
    </person>
    <person key="antique-2018-idp148464">
      <firstname>Yves Stan</firstname>
      <lastname>Le Cornec</lastname>
      <categoryPro>Technique</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria</moreinfo>
    </person>
    <person key="antique-2018-idp150928">
      <firstname>Andrei Nicolae</firstname>
      <lastname>Damian</lastname>
      <categoryPro>Stagiaire</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria, from Jun 2018 until Sep 2018</moreinfo>
    </person>
    <person key="antique-2018-idp153408">
      <firstname>Aurelie</firstname>
      <lastname>Faure de Pebeyre</lastname>
      <categoryPro>Stagiaire</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria, until Jun 2018</moreinfo>
    </person>
    <person key="antique-2018-idp155872">
      <firstname>Constantin Alexandru</firstname>
      <lastname>Militaru</lastname>
      <categoryPro>Stagiaire</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria, from Jun 2018 until Sep 2018</moreinfo>
    </person>
    <person key="antique-2018-idp158352">
      <firstname>Amit Kiran</firstname>
      <lastname>Rege</lastname>
      <categoryPro>Stagiaire</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Ecole Normale Supérieure Paris, from Feb 2018 until Jul 2018</moreinfo>
    </person>
    <person key="antique-2018-idp160928">
      <firstname>Albin</firstname>
      <lastname>Salazar</lastname>
      <categoryPro>Stagiaire</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria, from Sep 2018</moreinfo>
    </person>
    <person key="mimove-2018-idp180048">
      <firstname>Nathalie</firstname>
      <lastname>Gaudechoux</lastname>
      <categoryPro>Assistant</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria</moreinfo>
    </person>
    <person key="antique-2018-idp165856">
      <firstname>Pierre</firstname>
      <lastname>Boutillier</lastname>
      <categoryPro>Visiteur</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Harvard Medical School</moreinfo>
    </person>
    <person key="antique-2018-idp168320">
      <firstname>Jiangchao</firstname>
      <lastname>Liu</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Paris</research-centre>
      <moreinfo>Inria, until Mar 2018</moreinfo>
    </person>
  </team>
  <presentation id="uid2">
    <bodyTitle>Overall Objectives</bodyTitle>
    <subsection id="uid3" level="1">
      <bodyTitle>Overall Objectives</bodyTitle>
      <p>Our group focuses on developing <i>automated</i> techniques to compute
<i>semantic properties</i> of programs and other systems with a
computational semantics in general.
Such properties include (but are not limited to) important classes of
correctness properties.</p>
      <p>Verifying safety critical systems (such as avionics systems) is an important
motivation to compute such properties.
Indeed, a fault in an avionics system, such as a runtime error in the
fly-by-wire command software, may cause an accident, with loss of life.
As these systems are also very complex and are developed by large
teams and maintained over long periods, their verification has become
a crucial challenge.
Safety critical systems are not limited to avionics:
software runtime errors in cruise control management systems were
recently blamed for causing <i>unintended acceleration</i> in certain
Toyota models (the case was settled with a 1.2 billion dollars fine in
March 2014, after years of investigation and several trials).
Similarly, other transportation systems (railway), energy production
systems (nuclear power plants, power grid management), medical
systems (pacemakers, surgery and patient monitoring systems), and
value transfers in decentralized systems (smart contracts), rely
on complex software, which should be verified.</p>
      <p>Beyond the field of embedded systems, other pieces of software may cause
very significant harm in the case of bugs, as demonstrated by the Heartbleed
security hole: due to a wrong protocol implementation, many websites could
leak private information, over years.</p>
      <p>An important example of semantic properties is the class of <i>safety</i>
properties.
A safety property typically specifies that some (undesirable) event will
never occur, whatever the execution of the program that is considered.
For instance, the absence of runtime error is a very important safety
property.
Other important classes of semantic properties include <i>liveness</i>
properties (i.e., properties that specify that some desirable event will
eventually occur) such as termination and <i>security</i> properties,
such as the absence of information flows from private to public channels.</p>
      <p>All these software semantic properties are <i>not decidable</i>, as can
be shown by reduction to the halting problem.
Therefore, there is no chance to develop any fully automatic technique
able to decide, for any system, whether or not it satisfies some given
semantic property.</p>
      <p>The classic development techniques used in industry involve testing,
which is not sound, as it only gives information about a usually limited
test sample:
even after successful test-based validation, situations that were
untested may generate a problem.
Furthermore, testing is costly in the long term, as it should be re-done
whenever the system to verify is modified.
Machine-assisted verification is another approach which verifies human
specified properties.
However, this approach also presents a very significant cost, as the
annotations required to verify large industrial applications would be
huge.</p>
      <p>By contrast, the <b>antique</b> group focuses on the design of semantic analysis
techniques that should be <i>sound</i> (i.e., compute semantic properties
that are satisfied by all executions) and <i>automatic</i> (i.e., with no
human interaction), although generally <i>incomplete</i> (i.e., not able
to compute the best —in the sense of: most precise— semantic property).
As a consequence of incompleteness, we may fail to verify a system
that is actually correct.
For instance, in the case of verification of absence of runtime error,
the analysis may fail to validate a program, which is safe, and emit
<i>false alarms</i> (that is reports that possibly dangerous operations
were not proved safe), which need to be discharged manually.
Even in this case, the analysis provides information about the
alarm context, which may help disprove it manually or refine the
analysis.</p>
      <p>The methods developed by the <b>antique</b> group are not limited to the
analysis of software.
We also consider complex biological systems (such as models of
signaling pathways, i.e. cascades of protein interactions, which enable
signal communication among and within cells), described in higher level
languages, and use abstraction techniques to reduce their combinatorial
complexity and capture key properties so as to get a better insight in
the underlying mechanisms of these systems.</p>
    </subsection>
  </presentation>
  <fondements id="uid4">
    <bodyTitle>Research Program</bodyTitle>
    <subsection id="uid5" level="1">
      <bodyTitle>Semantics</bodyTitle>
      <p>Semantics plays a central role in verification since it always serves
as a basis to express the properties of interest, that need to be
verified, but also additional properties, required to prove the
properties of interest, or which may make the design of static analysis
easier.</p>
      <p>For instance, if we aim for a static analysis that should prove the absence
of runtime error in some class of programs, the concrete semantics should
define properly what error states and non error states are, and how program
executions step from a state to the next one.
In the case of a language like C, this includes the behavior of floating
point operations as defined in the IEEE 754 standard.
When considering parallel programs, this includes a model of the scheduler,
and a formalization of the memory model.</p>
      <p>In addition to the properties that are required to express the proof of the
property of interest, it may also be desirable that semantics describe
program behaviors in a finer manner, so as to make static analyses easier
to design.
For instance, it is well known that, when a state property (such as the
absence of runtime error) is valid, it can be established using only a
state invariant (i.e., an invariant that ignores the order in which states
are visited during program executions).
Yet searching for trace invariants (i.e., that take into account some
properties of program execution history) may make the static analysis
significantly easier, as it will allow it to make finer case splits,
directed by the history of program executions.
To allow for such powerful static analyses, we often resort to a
<i>non standard semantics</i>, which incorporates properties that would
normally be left out of the concrete semantics.
</p>
    </subsection>
    <subsection id="uid6" level="1">
      <bodyTitle>Abstract interpretation and static analysis</bodyTitle>
      <p>Once a reference semantics has been fixed and a property of interest has
been formalized, the definition of a static analysis requires the choice
of an <i>abstraction</i>.
The abstraction ties a set of <i>abstract predicates</i> to the concrete
ones, which they denote.
This relation is often expressed with a <i>concretization function</i>
that maps each abstract element to the concrete property it stands for.
Obviously, a well chosen abstraction should allow one to express the property
of interest, as well as all the intermediate properties that are required
in order to prove it (otherwise, the analysis would have no chance to
achieve a successful verification).
It should also lend itself to an efficient implementation, with efficient
data-structures and algorithms for the representation and the manipulation
of abstract predicates.
A great number of abstractions have been proposed for all kinds of
concrete data types, yet the search for new abstractions is a very
important topic in static analysis, so as to target novel kinds of
properties, to design more efficient or more precise static
analyses.</p>
      <p>Once an abstraction is chosen, a set of <i>sound abstract transformers</i>
can be derived from the concrete semantics and that account for individual
program steps, in the abstract level and without forgetting any concrete
behavior.
A static analysis follows as a result of this step by step approximation
of the concrete semantics, when the abstract transformers are all
computable.
This process defines an <i>abstract interpretation</i>  <ref xlink:href="#antique-2018-bid0" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.
The case of loops requires a bit more work as the concrete semantics
typically relies on a fixpoint that may not be computable in finitely
many iterations.
To achieve a terminating analysis we then use <i>widening
operators</i>  <ref xlink:href="#antique-2018-bid0" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, which over-approximate the concrete
union and ensure termination.</p>
      <p>A static analysis defined that way always terminates and produces sound
over-approximations of the programs behaviors.
Yet, these results may not be precise enough for verification.
This is where the art of static analysis design comes into play
through, among others:</p>
      <simplelist>
        <li id="uid7">
          <p noindent="true">the use of more precise, yet still efficient enough abstract domains;</p>
        </li>
        <li id="uid8">
          <p noindent="true">the combination of application-specific abstract domains;</p>
        </li>
        <li id="uid9">
          <p noindent="true">the careful choice of abstract transformers and widening operators.</p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid10" level="1">
      <bodyTitle>Applications of the notion of
abstraction in semantics</bodyTitle>
      <p>In the previous subsections, we sketched the steps in the design of a
static analyzer to infer some family of properties, which should be
implementable, and efficient enough to succeed in verifying non trivial
systems.</p>
      <p>The same principles can be applied successfully to other goals.
In particular, the abstract interpretation framework should be viewed as a
very general tool to <i>compare different semantics</i>, not necessarily
with the goal of deriving a static analyzer.
Such comparisons may be used in order to prove two semantics equivalent
(i.e., one is an abstraction of the other and vice versa), or that a first
semantics is strictly more expressive than another one (i.e., the latter
can be viewed an abstraction of the former, where the abstraction actually
makes some information redundant, which cannot be recovered).
A classical example of such comparison is the classification of semantics
of transition systems  <ref xlink:href="#antique-2018-bid1" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, which provides a better
understanding of program semantics in general.
For instance, this approach can be applied to get a better understanding
of the semantics of a programming language, but also to select which
concrete semantics should be used as a foundation for a static analysis,
or to prove the correctness of a program transformation, compilation or
optimization.
</p>
    </subsection>
    <subsection id="uid11" level="1">
      <bodyTitle>From properties to explanations</bodyTitle>
      <p>In many application domains, we can go beyond the proof that a program satisfies its specification. Abstractions can also offer new perspectives to understand how complex behaviors of programs emerge from simpler computation steps. Abstractions can be used to find compact and readable representations of sets of traces, causal relations, and even proofs. For instance, abstractions may decipher how the collective behaviors of agents emerge from the orchestration of their individual ones in distributed systems (such as consensus protocols, models of signaling pathways). Another application is the assistance for the diagnostic of alarms of a static analyzer.</p>
      <p>Complex systems and software have often times intricate behaviors, leading to executions that are hard to understand for programmers and also difficult to reason about with static analyzers. Shared memory and distributed systems are notorious for being hard to reason about due to the interleaving of actions performed by different processes and the non-determinism of the network that might lose, corrupt, or duplicate messages. Reduction theorems, e.g., Lipton's theorem, have been proposed to facilitate reasoning about concurrency, typically transforming a system into one with a coarse-grained semantics that usually increases the atomic sections. We investigate reduction theorems for distributed systems and ways to compute the coarse-grained counter part of a system automatically. Compared with shared memory concurrency, automated methods to reason about distributed systems have been less investigated in the literature.
We take a programming language approach based on high-level programming abstractions. We focus on partially-synchronous communication closed round-based models, introduced in the distributed algorithms community for its simpler proof arguments. The high-level language is compiled into a low-level (asynchronous) programming language. Conversely, systems defined under asynchronous programming paradigms are decompiled into the high-level programming abstractions. The correctness of the compilation/decompilation process is based on reduction theorems (in the spirit of Lipton and Elrad-Francez) that preserve safety and liveness properties.</p>
      <p>In models of signaling pathways, collective behavior emerges from competition for common resources, separation of scales (time/concentration), non linear feedback loops, which are all consequences of mechanistic interactions between individual bio-molecules (e.g., proteins). While more and more details about mechanistic interactions are available in the literature, understanding the behavior of these models at the system level is far from easy. Causal analysis helps explaining how specific events of interest may occur. Model reduction techniques combine methods from different domains such as the analysis of information flow used in communication protocols, and
tropicalization methods that comes from physics. The result is lower dimension systems that preserve the behavior of the initial system while focusing of the elements from which emerges the collective behavior of the system.</p>
      <p>The abstraction of causal traces offer nice representation of scenarios that lead to expected or unexpected events. This is useful to understand the necessary steps in potential scenarios in signaling pathways; this is useful as well to understand the different steps of an intrusion in a protocol. Lastly, traces of computation of a static analyzer can themselves be abstracted, which provides assistance to classify true and false alarms. Abstracted traces are symbolic and compact representations of sets of counter-examples to the specification of a system which help one to either understand the origin of bugs, or to find that some information has been lost in the abstraction leading to false alarms.
</p>
    </subsection>
  </fondements>
  <domaine id="uid12">
    <bodyTitle>Application Domains</bodyTitle>
    <subsection id="uid13" level="1">
      <bodyTitle>Verification of safety critical
embedded software</bodyTitle>
      <p>The verification of safety critical embedded software is a very
important application domain for our group.
First, this field requires a high confidence in software, as a bug may
cause disastrous events.
Thus, it offers an obvious opportunity for a strong impact.
Second, such software usually have better specifications and a better
design than many other families of software, hence are an easier target
for developing new static analysis techniques (which can later be
extended for more general, harder to cope with families of programs).
This includes avionics, automotive and other transportation systems,
medical systems ...</p>
      <p>For instance, the verification of avionics systems represent a very
high percentage of the cost of an airplane (about 30 % of the overall
airplane design cost).
The state of the art development processes mainly resort to testing
in order to improve the quality of software.
Depending on the level of criticality of a software (at the highest levels,
any software failure would endanger the flight) a set of software
requirements are checked with test suites.
This approach is both costly (due to the sheer amount of testing that
needs to be performed) and unsound (as errors may go unnoticed, if they
do not arise on the test suite).</p>
      <p>By contrast, static analysis can ensure higher software quality at a
lower cost.
Indeed, a static analyzer will catch all bugs of a certain kind.
Moreover, a static analysis run typically lasts a few hours, and
can be integrated in the development cycle in a seamless manner.
For instance, <ref xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">Astrée</span></ref> successfully verified the absence of runtime
error in several families of safety critical fly-by-wire avionic
software, in at most a day of computation, on standard hardware.
Other kinds of synchronous embedded software have also been analyzed
with good results.</p>
      <p>In the future, we plan to greatly extend this work so as to verify
<i>other families of embedded software</i> (such as communication,
navigation and monitoring software) and <i>other families of properties</i>
(such as security and liveness properties).</p>
      <p>Embedded software in charge of communication, navigation, and monitoring
typically relies on a <i>parallel</i> structure, where several threads are
executed concurrently, and manage different features (input, output,
user interface, internal computation, logging ...).
This structure is also often found in automotive software.
An even more complex case is that of <i>distributed</i> systems, where
several separate computers are run in parallel and take care of several
sub-tasks of a same feature, such as braking.
Such a logical structure is not only more complex than the synchronous
one, but it also introduces new risks and new families of errors
(deadlocks, data-races...).
Moreover, such less well designed, and more complex embedded software
often utilizes more complex data-structures than synchronous programs
(which typically only use arrays to store previous states)
and may use dynamic memory allocation, or build dynamic structures
inside static memory regions, which are actually even harder to
verify than conventional dynamically allocated data structures.
Complex data-structures also introduce new kinds of risks (the failure
to maintain structural invariants may lead to runtime errors, non
termination, or other software failures).
To verify such programs, we will design additional abstract domains, and
develop new static analysis techniques, in order to support the
analysis of more complex programming language features such as
parallel and concurrent programming with threads and manipulations of
complex data structures.
Due to their size and complexity, the verification of such families of
embedded software is a major challenge for the research community.</p>
      <p>Furthermore, embedded systems also give rise to novel security concerns.
It is in particular the case for some aircraft-embedded computer systems,
which communicate with the ground through untrusted communication media.
Besides, the increasing demand for new capabilities, such as enhanced
on-board connectivity, e.g. using mobile devices, together with the need
for cost reduction, leads to more integrated and interconnected systems.
For instance, modern aircrafts embed a large number of computer systems,
from safety-critical cockpit avionics to passenger entertainment.
Some systems meet both safety and security requirements.
Despite thorough segregation of subsystems and networks, some shared
communication resources raise the concern of possible intrusions.
Because of the size of such systems, and considering that they are evolving
entities, the only economically viable alternative is to perform automatic
analyses.
Such analyses of security and confidentiality properties have never been
achieved on large-scale systems where security properties interact with
other software properties, and even the mapping between high-level models
of the systems and the large software base implementing them has never
been done and represents a great challenge.
Our goal is to prove empirically that the security of such large scale
systems can be proved formally, thanks to the design of dedicated abstract
interpreters.</p>
      <p>The long term goal is to make static analysis more widely applicable
to the verification of industrial software.
</p>
    </subsection>
    <subsection id="uid14" level="1">
      <bodyTitle>Static analysis of software components
and libraries</bodyTitle>
      <p>An important goal of our work is to make static analysis techniques
easier to apply to wider families of software.
Then, in the longer term, we hope to be able to verify less critical,
yet very commonly used pieces of software.
Those are typically harder to analyze than critical software, as their
development process tends to be less rigorous.
In particular, we will target operating systems components and libraries.
As of today, the verification of such programs is considered a major
challenge to the static analysis community.</p>
      <p>As an example, most programming languages offer Application Programming
Interfaces (API) providing ready-to-use abstract data structures (e.g.,
sets, maps, stacks, queues, etc.).
These APIs, are known under the name of containers or collections, and
provide off-the-shelf libraries of high level operations, such as
insertion, deletion and membership checks.
These container libraries give software developers a way of abstracting
from low-level implementation details related to memory management, such
as dynamic allocation, deletion and pointer handling or concurrency
aspects, such as thread synchronization.
Libraries implementing data structures are important building bricks of a
huge number of applications, therefore their verification is paramount.
We are interested in developing static analysis techniques that will prove
automatically the correctness of large audience libraries such as Glib and
Threading Building Blocks.
</p>
    </subsection>
    <subsection id="uid15" level="1">
      <bodyTitle>Models of mechanistic interactions between proteins</bodyTitle>
      <p>Computer Science takes a more and more important role in the design and
the understanding of biological systems such as signaling pathways, self
assembly systems, DNA repair mechanisms.
Biology has gathered large data-bases of facts about mechanistic
interactions between proteins, but struggles to draw an overall picture
of how these systems work as a whole.
High level languages designed in Computer Science allow one to collect these
interactions in integrative models, and provide formal definitions (i.e.,
semantics) for the behavior of these models.
This way, modelers can encode their knowledge, following a bottom-up
discipline, without simplifying <i>a priori</i> the models at the risk
of damaging the key properties of the system.
Yet, the systems that are obtained this way suffer from combinatorial
explosion (in particular, in the number of different kinds of molecular
components, which can arise at run-time), which prevents from a naive
computation of their behavior.</p>
      <p>We develop various analyses based on abstract interpretation, and tailored to
different phases of the modeling process.
We propose automatic static analyses in order to detect inconsistencies in
the early phases of the modeling process.
These analyses are similar to the analysis of classical safety
properties of programs.
They involve both forward and backward reachability analyses as well as
causality analyses, and can be tuned at different levels of abstraction.
We also develop automatic static analyses in order to identify key elements
in the dynamics of these models.
The results of these analyses are sent to another tool,
which is used to automatically simplify models.
The correctness of this simplification process is proved by
the means of abstract interpretation: this ensures formally
that the simplification preserves the quantitative properties
that have been specified beforehand by the modeler.
The whole pipeline is parameterized by a large choice of abstract domains
which exploits different features of the high level description of
models.
</p>
    </subsection>
    <subsection id="uid16" level="1">
      <bodyTitle>Consensus</bodyTitle>
      <p>Fault-tolerant distributed systems provide a dependable service on top of unreliable computers and networks. Famous examples are geo-replicated data-bases, distributed file systems, or blockchains. Fault-tolerant protocols replicate the system and ensure that all (unreliable) replicas are perceived from the outside as one single reliable machine.
To give the illusion of a single reliable machine “consensus” protocols force replicas to agree on the “current state” before making this state visible to an outside observer.
We are interested in (semi-)automatically proving the total correctness of consensus algorithms in the benign case (messages are lost or processes crash) or the Byzantine case (processes may lie about their current state). In order to do this, we first define new reduction theorems to simplify the behaviors of the system and, second, we introduce new static analysis methods to prove the total correctness of adequately simplified systems. We focus on static analysis based Satisfiability Modulo Theories (SMT) solvers which offers a good compromise between automation and expressiveness.
Among our benchmarks are Paxos, PBFT (Practical Byzantine Fault-Tolerance), and blockchain algorithms (Red-Belly, Tendermint, Algorand). These are highly challenging benchmarks, with a lot of non-determinism coming from the interleaving semantics and from the adversarial environment in which correct processes execute, environment that can drop messages, corrupt them, etc. Moreover, these systems were originally designed for a few servers but today are deployed on networks with thousands of nodes. The “optimizations” for scalability can no longer be overlooked and must be considered as integral part of the algorithms, potentially leading to specifications weaker than the so much desired consensus.
</p>
    </subsection>
    <subsection id="uid17" level="1">
      <bodyTitle>Models of growth</bodyTitle>
      <p>In systems and synthetic biology (engineered systems) one would like
study the environment of a given cellular process (such as signaling pathways
mentioned earlier) and the ways in which that process
interacts with different resources provided by the host. To do this, we have built coarse-grained models of cellular physiology which summarize
fundamental processes (transcription, translation, transport, metabolism).
such models describe global growth in mechanistic way and allow one to
plug the model of one's process of interest into a simplified and
yet realistic and reactive model of the process interaction with its
immediate environment. A first ODE-based deterministic version of this model <ref xlink:href="#antique-2018-bid2" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>
explaining the famous bacterial growth laws and how the allocation of resources
to different genomic sectors depends on the growth conditions-
was published in 2015 and has already received nearly 150 citations. The model also allows one
to bridge between population genetic models which describe cells in terms of abstract features and fitness and intra-cellular models. For instance, we find that fastest growing strategies are not evolutionary stable in competitive experiments. We also find that vastly different energy storage strategies exist<ref xlink:href="#antique-2018-bid3" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. In a recent article<ref xlink:href="#antique-2018-bid4" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>
in <i>Nature Communications</i> we build a stochastic version of the above model. We predict the
empirical size and doubling time distributions as a function of growth conditions.
To be able to fit the parameters of the model to available single-cell data (note that the fitting constraints are far tighter than in the deterministic case), we introduce new techniques
for the approximation of reaction-division systems which generalize continuous approximations of Langevin type commonly used for pure reaction systems. We also use cross-correlations to visualize causality and modes in noise propagation in the model (in a way reminiscent to abstract computational traces mentioned earlier). In other work, we show how to connect our new class of models to more traditional ones stemming from “flux balance analysis” by introducing an allocation vector which allows one to assign a formal growth rate to a class of reaction systems <ref xlink:href="#antique-2018-bid5" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.
</p>
    </subsection>
  </domaine>
  <logiciels id="uid18">
    <bodyTitle>New Software and Platforms</bodyTitle>
    <subsection id="uid19" level="1">
      <bodyTitle>APRON</bodyTitle>
      <p><span class="smallcap" align="left">Scientific Description:</span> The APRON library is intended to be a common interface to various underlying libraries/abstract domains and to provide additional services that can be implemented independently from the underlying library/abstract domain, as shown by the poster on the right (presented at the SAS 2007 conference. You may also look at:</p>
      <p noindent="true"><span class="smallcap" align="left">Functional Description:</span> The Apron library is dedicated to the static analysis of the numerical variables of a program by abstract interpretation. Its goal is threefold: provide ready-to-use numerical abstractions under a common API for analysis implementers, encourage the research in numerical abstract domains by providing a platform for integration and comparison of domains, and provide a teaching and demonstration tool to disseminate knowledge on abstract interpretation.</p>
      <simplelist>
        <li id="uid20">
          <p noindent="true">Participants: Antoine Miné and Bertrand Jeannet</p>
        </li>
        <li id="uid21">
          <p noindent="true">Contact: Antoine Miné</p>
        </li>
        <li id="uid22">
          <p noindent="true">URL: <ref xlink:href="http://apron.cri.ensmp.fr/library/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>apron.<allowbreak/>cri.<allowbreak/>ensmp.<allowbreak/>fr/<allowbreak/>library/</ref></p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid23" level="1">
      <bodyTitle>Astrée</bodyTitle>
      <p>
        <i>The AstréeA Static Analyzer of Asynchronous Software</i>
      </p>
      <p noindent="true"><span class="smallcap" align="left">Keywords:</span> Static analysis - Static program analysis - Program verification - Software Verification - Abstraction</p>
      <p noindent="true"><span class="smallcap" align="left">Scientific Description:</span> Astrée analyzes structured C programs, with complex memory usages, but without dynamic memory allocation nor recursion. This encompasses many embedded programs as found in earth transportation, nuclear energy, medical instrumentation, and aerospace applications, in particular synchronous control/command. The whole analysis process is entirely automatic.</p>
      <p>Astrée discovers all runtime errors including:</p>
      <p>undefined behaviors in the terms of the ANSI C99 norm of the C language (such as division by 0 or out of bounds array indexing),</p>
      <p>any violation of the implementation-specific behavior as defined in the relevant Application Binary Interface (such as the size of integers and arithmetic overflows),</p>
      <p>any potentially harmful or incorrect use of C violating optional user-defined programming guidelines (such as no modular arithmetic for integers, even though this might be the hardware choice),</p>
      <p>failure of user-defined assertions.</p>
      <p noindent="true"><span class="smallcap" align="left">Functional Description:</span> Astrée analyzes structured C programs, with complex memory usages, but without dynamic memory allocation nor recursion.
This encompasses many embedded programs as found in earth transportation, nuclear energy, medical instrumentation, and aerospace applications, in particular synchronous control/command. The whole analysis process is entirely automatic.</p>
      <p>Astrée discovers all runtime errors including:
- undefined behaviors in the terms of the ANSI C99 norm of the C
language (such as division by 0 or out of bounds array indexing),
- any violation of the implementation-specific behavior as defined
in the relevant Application Binary Interface (such as the size of
integers and arithmetic overflows),
- any potentially harmful or incorrect use of C violating optional
user-defined programming guidelines (such as no modular arithmetic for
integers, even though this might be the hardware choice),
- failure of user-defined assertions.</p>
      <p>Astrée is a static analyzer for sequential programs based on abstract interpretation.
The Astrée static analyzer aims at proving the absence of runtime errors in programs written in the C programming language.</p>
      <simplelist>
        <li id="uid24">
          <p noindent="true">Participants: Antoine Miné, Jérôme Feret, Laurent Mauborgne, Patrick Cousot, Radhia Cousot and Xavier Rival</p>
        </li>
        <li id="uid25">
          <p noindent="true">Partners: CNRS - ENS Paris - AbsInt Angewandte Informatik GmbH</p>
        </li>
        <li id="uid26">
          <p noindent="true">Contact: Patrick Cousot</p>
        </li>
        <li id="uid27">
          <p noindent="true">URL: <ref xlink:href="http://www.astree.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www.<allowbreak/>astree.<allowbreak/>ens.<allowbreak/>fr/</ref></p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid28" level="1">
      <bodyTitle>AstréeA</bodyTitle>
      <p>
        <i>The AstréeA Static Analyzer of Asynchronous Software</i>
      </p>
      <p noindent="true"><span class="smallcap" align="left">Keywords:</span> Static analysis - Static program analysis</p>
      <p noindent="true"><span class="smallcap" align="left">Scientific Description:</span> AstréeA analyzes C programs composed of a fixed set of threads that communicate through a shared memory and synchronization primitives (mutexes, FIFOs, blackboards, etc.), but without recursion nor dynamic creation of memory, threads nor synchronization objects. AstréeA assumes a real-time scheduler, where thread scheduling strictly obeys the fixed priority of threads. Our model follows the ARINC 653 OS specification used in embedded industrial aeronautic software. Additionally, AstréeA employs a weakly-consistent memory semantics to model memory accesses not protected by a mutex, in order to take into account soundly hardware and compiler-level program transformations (such as optimizations). AstréeA checks for the same run-time errors as Astrée , with the addition of data-races.</p>
      <p noindent="true"><span class="smallcap" align="left">Functional Description:</span> AstréeA is a static analyzer prototype for parallel software based on abstract interpretation.
The AstréeA prototype is a fork of the Astrée static analyzer that adds support for analyzing parallel embedded C software.</p>
      <simplelist>
        <li id="uid29">
          <p noindent="true">Participants: Antoine Miné, Jérôme Feret, Patrick Cousot, Radhia Cousot and Xavier Rival</p>
        </li>
        <li id="uid30">
          <p noindent="true">Partners: CNRS - ENS Paris - AbsInt Angewandte Informatik GmbH</p>
        </li>
        <li id="uid31">
          <p noindent="true">Contact: Patrick Cousot</p>
        </li>
        <li id="uid32">
          <p noindent="true">URL: <ref xlink:href="http://www.astreea.ens.fr/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www.<allowbreak/>astreea.<allowbreak/>ens.<allowbreak/>fr/</ref></p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid33" level="1">
      <bodyTitle>ClangML</bodyTitle>
      <p><span class="smallcap" align="left">Keyword:</span> Compilation</p>
      <p noindent="true"><span class="smallcap" align="left">Functional Description:</span> ClangML is an OCaml binding with the Clang front-end of the LLVM compiler suite. Its goal is to provide an easy to use solution to parse a wide range of C programs, that can be called from static analysis tools implemented in OCaml, which allows to test them on existing programs written in C (or in other idioms derived from C) without having to redesign a front-end from scratch. ClangML features an interface to a large set of internal AST nodes of Clang , with an easy to use API. Currently, ClangML supports all C language AST nodes, as well as a large part of the C nodes related to C++ and Objective-C.</p>
      <simplelist>
        <li id="uid34">
          <p noindent="true">Participants: Devin Mccoughlin, François Berenger and Pippijn Van Steenhoven</p>
        </li>
        <li id="uid35">
          <p noindent="true">Contact: Xavier Rival</p>
        </li>
        <li id="uid36">
          <p noindent="true">URL: <ref xlink:href="https://github.com/Antique-team/clangml/tree/master/clang" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>github.<allowbreak/>com/<allowbreak/>Antique-team/<allowbreak/>clangml/<allowbreak/>tree/<allowbreak/>master/<allowbreak/>clang</ref></p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid37" level="1">
      <bodyTitle>FuncTion</bodyTitle>
      <p><span class="smallcap" align="left">Scientific Description:</span> FuncTion is based on an extension to liveness properties of the framework to analyze termination by abstract interpretation proposed by Patrick Cousot and Radhia Cousot. FuncTion infers ranking functions using piecewise-defined abstract domains. Several domains are available to partition the ranking function, including intervals, octagons, and polyhedra. Two domains are also available to represent the value of ranking functions: a domain of affine ranking functions, and a domain of ordinal-valued ranking functions (which allows handling programs with unbounded non-determinism).</p>
      <p noindent="true"><span class="smallcap" align="left">Functional Description:</span> FuncTion is a research prototype static analyzer to analyze the termination and functional liveness properties of programs. It accepts programs in a small non-deterministic imperative language. It is also parameterized by a property: either termination, or a recurrence or a guarantee property (according to the classification by Manna and Pnueli of program properties). It then performs a backward static analysis that automatically infers sufficient conditions at the beginning of the program so that all executions satisfying the conditions also satisfy the property.</p>
      <simplelist>
        <li id="uid38">
          <p noindent="true">Participants: Antoine Miné and Caterina Urban</p>
        </li>
        <li id="uid39">
          <p noindent="true">Contact: Caterina Urban</p>
        </li>
        <li id="uid40">
          <p noindent="true">URL: <ref xlink:href="http://www.di.ens.fr/~urban/FuncTion.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www.<allowbreak/>di.<allowbreak/>ens.<allowbreak/>fr/<allowbreak/>~urban/<allowbreak/>FuncTion.<allowbreak/>html</ref></p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid41" level="1">
      <bodyTitle>HOO</bodyTitle>
      <p>
        <i>Heap Abstraction for Open Objects</i>
      </p>
      <p noindent="true"><span class="smallcap" align="left">Functional Description:</span> JSAna with HOO is a static analyzer for JavaScript programs. The primary component, HOO, which is designed to be reusable by itself, is an abstract domain for a dynamic language heap. A dynamic language heap consists of open, extensible objects linked together by pointers. Uniquely, HOO abstracts these extensible objects, where attribute/field names of objects may be unknown. Additionally, it contains features to keeping precise track of attribute name/value relationships as well as calling unknown functions through desynchronized separation.</p>
      <p>As a library, HOO is useful for any dynamic language static analysis. It is designed to allow abstractions for values to be easily swapped out for different abstractions, allowing it to be used for a wide-range of dynamic languages outside of JavaScript.</p>
      <simplelist>
        <li id="uid42">
          <p noindent="true">Participant: Arlen Cox</p>
        </li>
        <li id="uid43">
          <p noindent="true">Contact: Arlen Cox</p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid44" level="1">
      <bodyTitle>MemCAD</bodyTitle>
      <p>
        <i>The MemCAD static analyzer</i>
      </p>
      <p noindent="true"><span class="smallcap" align="left">Keywords:</span> Static analysis - Abstraction</p>
      <p noindent="true"><span class="smallcap" align="left">Functional Description:</span> MemCAD is a static analyzer that focuses on memory abstraction. It takes as input C programs, and computes invariants on the data structures manipulated by the programs. It can also verify memory safety. It comprises several memory abstract domains, including a flat representation, and two graph abstractions with summaries based on inductive definitions of data-structures, such as lists and trees and several combination operators for memory abstract domains (hierarchical abstraction, reduced product). The purpose of this construction is to offer a great flexibility in the memory abstraction, so as to either make very efficient static analyses of relatively simple programs, or still quite efficient static analyses of very involved pieces of code. The implementation consists of over 30 000 lines of ML code, and relies on the ClangML front-end. The current implementation comes with over 300 small size test cases that are used as regression tests.</p>
      <simplelist>
        <li id="uid45">
          <p noindent="true">Participants: Antoine Toubhans, François Berenger, Huisong Li and Xavier Rival</p>
        </li>
        <li id="uid46">
          <p noindent="true">Contact: Xavier Rival</p>
        </li>
        <li id="uid47">
          <p noindent="true">URL: <ref xlink:href="http://www.di.ens.fr/~rival/memcad.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www.<allowbreak/>di.<allowbreak/>ens.<allowbreak/>fr/<allowbreak/>~rival/<allowbreak/>memcad.<allowbreak/>html</ref></p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid48" level="1">
      <bodyTitle>KAPPA</bodyTitle>
      <p>
        <i>A rule-based language for modeling interaction networks</i>
      </p>
      <p noindent="true"><span class="smallcap" align="left">Keywords:</span> Systems Biology - Modeling - Static analysis - Simulation - Model reduction</p>
      <p noindent="true"><span class="smallcap" align="left">Scientific Description:</span> OpenKappa is a collection of tools to build, debug and run models of biological pathways. It contains a compiler for the Kappa Language, a static analyzer (for debugging models), a simulator, a compression tool for causal traces, and a model reduction tool.</p>
      <p noindent="true"><span class="smallcap" align="left">Functional Description:</span> Kappa is provided with the following tools:
- a compiler
- a stochastic simulator
- a static analyzer
- a trace compression algorithm
- an ODE generator.</p>
      <p><span class="smallcap" align="left">Release Functional Description:</span> On line UI,
Simulation is based on a new data-structure (see ESOP 2017 ),
New abstract domains are available in the static analyzer (see SASB 2016),
Local traces (see TCBB 2018),
Reasoning on polymers (see SASB 2018).</p>
      <simplelist>
        <li id="uid49">
          <p noindent="true">Participants: Jean Krivine, Jérôme Feret, Kim Quyen Ly, Pierre Boutillier, Russ Harmer, Vincent Danos and Walter Fontana</p>
        </li>
        <li id="uid50">
          <p noindent="true">Partners: ENS Lyon - Université Paris-Diderot - HARVARD Medical School</p>
        </li>
        <li id="uid51">
          <p noindent="true">Contact: Jérôme Feret</p>
        </li>
        <li id="uid52">
          <p noindent="true">URL: <ref xlink:href="http://www.kappalanguage.org/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www.<allowbreak/>kappalanguage.<allowbreak/>org/</ref></p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid53" level="1">
      <bodyTitle>QUICr</bodyTitle>
      <p><span class="smallcap" align="left">Functional Description:</span> QUICr is an OCaml library that implements a parametric abstract domain for sets. It is constructed as a functor that accepts any numeric abstract domain that can be adapted to the interface and produces an abstract domain for sets of numbers combined with numbers. It is relational, flexible, and tunable. It serves as a basis for future exploration of set abstraction.</p>
      <simplelist>
        <li id="uid54">
          <p noindent="true">Participant: Arlen Cox</p>
        </li>
        <li id="uid55">
          <p noindent="true">Contact: Arlen Cox</p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid56" level="1">
      <bodyTitle>LCertify</bodyTitle>
      <p><span class="smallcap" align="left">Keyword:</span> Compilation</p>
      <p noindent="true"><span class="smallcap" align="left">Scientific Description:</span> The compilation certification process is performed automatically, thanks to a prover designed specifically. The automatic proof is done at a level of abstraction which has been defined so that the result of the proof of equivalence is strong enough for the goals mentioned above and so that the proof obligations can be solved by efficient algorithms.</p>
      <p noindent="true"><span class="smallcap" align="left">Functional Description:</span> Abstract interpretation, Certified compilation, Static analysis, Translation validation, Verifier. The main goal of this software project is to make it possible to certify automatically the compilation of large safety critical software, by proving that the compiled code is correct with respect to the source code: When the proof succeeds, this guarantees semantic equivalence. Furthermore, this approach should allow to meet some domain specific software qualification criteria (such as those in DO-178 regulations for avionics software), since it allows proving that successive development levels are correct with respect to each other i.e., that they implement the same specification. Last, this technique also justifies the use of source level static analyses, even when an assembly level certification would be required, since it establishes separately that the source and the compiled code are equivalent.ntees that no compiler bug did cause incorrect code to be generated.</p>
      <simplelist>
        <li id="uid57">
          <p noindent="true">Participant: Xavier Rival</p>
        </li>
        <li id="uid58">
          <p noindent="true">Partners: CNRS - ENS Paris</p>
        </li>
        <li id="uid59">
          <p noindent="true">Contact: Xavier Rival</p>
        </li>
        <li id="uid60">
          <p noindent="true">URL: <ref xlink:href="http://www.di.ens.fr/~rival/lcertify.html" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www.<allowbreak/>di.<allowbreak/>ens.<allowbreak/>fr/<allowbreak/>~rival/<allowbreak/>lcertify.<allowbreak/>html</ref></p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid61" level="1">
      <bodyTitle>Zarith</bodyTitle>
      <p><span class="smallcap" align="left">Functional Description:</span> Zarith is a small (10K lines) OCaml library that implements arithmetic and logical operations over arbitrary-precision integers. It is based on the GNU MP library to efficiently implement arithmetic over big integers. Special care has been taken to ensure the efficiency of the library also for small integers: small integers are represented as Caml unboxed integers and use a specific C code path. Moreover, optimized assembly versions of small integer operations are provided for a few common architectures.</p>
      <p>Zarith is currently used in the Astrée analyzer to enable the sound analysis of programs featuring 64-bit (or larger) integers. It is also used in the Frama-C analyzer platform developed at CEA LIST and Inria Saclay.</p>
      <simplelist>
        <li id="uid62">
          <p noindent="true">Participants: Antoine Miné, Pascal Cuoq and Xavier Leroy</p>
        </li>
        <li id="uid63">
          <p noindent="true">Contact: Antoine Miné</p>
        </li>
        <li id="uid64">
          <p noindent="true">URL: <ref xlink:href="http://forge.ocamlcore.org/projects/zarith" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>forge.<allowbreak/>ocamlcore.<allowbreak/>org/<allowbreak/>projects/<allowbreak/>zarith</ref></p>
        </li>
      </simplelist>
    </subsection>
  </logiciels>
  <resultats id="uid65">
    <bodyTitle>New Results</bodyTitle>
    <subsection id="uid66" level="1">
      <bodyTitle>A Theoretical Foundation of
Sensitivity in an Abstract Interpretation Framework</bodyTitle>
      <participants>
        <person key="antique-2018-idp120512">
          <firstname>Xavier</firstname>
          <lastname>Rival</lastname>
          <moreinfo>correspondant</moreinfo>
        </person>
        <person key="PASUSERID">
          <firstname>Sukyoung</firstname>
          <lastname>Ryu</lastname>
        </person>
        <person key="PASUSERID">
          <firstname>Se-Won</firstname>
          <lastname>Kim</lastname>
        </person>
      </participants>
      <p>In <ref xlink:href="#antique-2018-bid6" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we formalize a framework to design static
analyses that make use of sensitivity, using the general notion
of cardinal power abstraction.</p>
      <p>Program analyses often utilize various forms of <i>sensitivity</i>
such as context sensitivity, call-site sensitivity, and object sensitivity.
These techniques all allow for more precise program analyses, that
are able to compute more precise program invariants, and to verify
stronger properties.
Despite the fact that sensitivity techniques are now part of the standard
toolkit of static analyses designers and implementers, no comprehensive
frameworks allow the description of all common forms of sensitivity.
As a consequence, the soundness proofs of static analysis tools
involving sensitivity often rely on <i>ad hoc</i> formalization,
which are not always carried out in an abstract interpretation
framework.
Moreover, this also means that opportunities to identify similarities
between analysis techniques to better improve abstractions or to tune
static analysis tools can easily be missed.</p>
      <p>In this work, we formalize a framework for the description
of <i>sensitivity in static analysis</i>.
Our framework is based on a powerful abstract domain construction, and
utilizes reduced cardinal power to tie basic abstract predicates to the
properties analyses are sensitive to.
We formalize this abstraction, and the main abstract operations that
are needed to turn it into a generic abstract domain construction.
We demonstrate that our approach can allow for a more precise
description of program states, and that it can also describe a
large set of sensitivity techniques, both when sensitivity criteria
are static (known before the analysis) or dynamic (inferred as part
of the analysis), and sensitive analysis tuning parameters.
Last, we show that sensitivity techniques used in state of the art
static analysis tools can be described in our framework.
</p>
    </subsection>
    <subsection id="uid67" level="1">
      <bodyTitle>Memory Abstraction</bodyTitle>
      <subsection id="uid68" level="2">
        <bodyTitle>Abstraction of arrays based on non contiguous partitions</bodyTitle>
        <participants>
          <person key="antique-2018-idp168320">
            <firstname>Jiangchao</firstname>
            <lastname>Liu</lastname>
          </person>
          <person key="antique-2018-idp120512">
            <firstname>Xavier</firstname>
            <lastname>Rival</lastname>
            <moreinfo>correspondant</moreinfo>
          </person>
        </participants>
        <p>In <ref xlink:href="#antique-2018-bid7" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we studied the verification of components of
embedded programs that utilize arrays to store dynamically chained
data-structures.
Furthermore, this work constitutes a significant part of Jiangchao Liu's
PhD Thesis (<ref xlink:href="#antique-2018-bid8" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>).</p>
        <p>User-space programs rely on memory allocation primitives when they
need to construct dynamic structures such as lists or trees.
However, low-level OS kernel services and embedded device drivers
typically avoid resorting to an external memory allocator in such
cases, and store structure elements in contiguous arrays instead.
This programming pattern leads to very complex code, based on
data-structures that can be viewed and accessed either as arrays
or as chained dynamic structures.
The code correctness then depends on intricate invariants mixing
both aspects.
We propose a static analysis that is able to verify such programs.
It relies on the combination of abstractions of the allocator array
and of the dynamic structures built inside it.
This approach allows to integrate program reasoning steps inherent
in the array and in the chained structure into a single abstract
interpretation.
We report on the successful verification of several embedded OS
kernel services and drivers.</p>
      </subsection>
      <subsection id="uid69" level="2">
        <bodyTitle>Semantic-Directed Clumping of Disjunctive Abstract States</bodyTitle>
        <participants>
          <person key="antique-2018-idp141072">
            <firstname>Huisong</firstname>
            <lastname>Li</lastname>
          </person>
          <person key="PASUSERID">
            <firstname>Francois</firstname>
            <lastname>Berenger</lastname>
          </person>
          <person key="PASUSERID">
            <firstname>Bor-Yuh Evan</firstname>
            <lastname>Chang</lastname>
          </person>
          <person key="antique-2018-idp120512">
            <firstname>Xavier</firstname>
            <lastname>Rival</lastname>
            <moreinfo>correspondant</moreinfo>
          </person>
        </participants>
        <p>In  <ref xlink:href="#antique-2018-bid9" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we studied the semantic directed clumping
of disjunctive abstract states.
Furthermore, this work constitutes a significant part of Huisong Li's
PhD Thesis (<ref xlink:href="#antique-2018-bid10" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>).</p>
        <p>To infer complex structural invariants, Shape analyses rely on
expressive families of logical properties. Many such analyses
manipulate abstract memory states that consist of separating
conjunctions of basic predicates describing atomic blocks or
summaries. Moreover, they use finite disjunctions of abstract memory
states in order to account for dissimilar shapes. Disjunctions
should be kept small for the sake of scalability, though precision
often requires to keep additional case splits. In this context,
deciding when and how to merge case splits and to replace them with
summaries is critical both for the precision and for the
efficiency. Existing techniques use sets of syntactic rules, which
are tedious to design and prone to failure. In this paper, we design
a semantic criterion to clump abstract states based on their
silhouette which applies not only to the conservative union of
disjuncts, but also to the weakening of separating conjunction of
memory predicates into inductive summaries. Our approach allows to
define union and widening operators that aim at preserving the case
splits that are required for the analysis to succeed. We implement
this approach in the MemCAD analyzer, and evaluate it on real-world
C codes from existing libraries, including programs dealing with
doubly linked lists, red-black trees and AVL-trees.
</p>
      </subsection>
    </subsection>
    <subsection id="uid70" level="1">
      <bodyTitle>Static Analysis of JavaScript Code</bodyTitle>
      <subsection id="uid71" level="2">
        <bodyTitle>Weakly Sensitive Analysis for Unbounded Iteration over
JavaScript Objects</bodyTitle>
        <participants>
          <person key="PASUSERID">
            <firstname>Yoonseok</firstname>
            <lastname>Ko</lastname>
          </person>
          <person key="antique-2018-idp120512">
            <firstname>Xavier</firstname>
            <lastname>Rival</lastname>
            <moreinfo>correspondant</moreinfo>
          </person>
          <person key="PASUSERID">
            <firstname>Sukyoung</firstname>
            <lastname>Ryu</lastname>
          </person>
        </participants>
        <p>In  <ref xlink:href="#antique-2018-bid11" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we studied composite object
abstraction for the analysis JavaScript.</p>
        <p>JavaScript framework libraries like jQuery are widely use, but
complicate program analyses. Indeed, they encode clean high-level
constructions such as class inheritance via dynamic object copies
and transformations that are harder to reason about. One common
pattern used in them consists of loops that copy or transform part
or all of the fields of an object. Such loops are challenging to
analyze precisely, due to weak updates and as unrolling techniques
do not always apply. In this work, we observe that precise field
correspondence relations are required for client analyses (e.g., for
call-graph construction), and propose abstractions of objects and
program executions that allow to reason separately about the effect
of distinct iterations without resorting to full unrolling. We
formalize and implement an analysis based on this technique. We
assess the performance and precision on the computation of
call-graph information on examples from jQuery tutorials.
</p>
      </subsection>
    </subsection>
    <subsection id="uid72" level="1">
      <bodyTitle>Communication-closed asynchronous protocols</bodyTitle>
      <participants>
        <person key="PASUSERID">
          <firstname>Andrei</firstname>
          <lastname>Damien</lastname>
        </person>
        <person key="antique-2018-idp126272">
          <firstname>Cezara</firstname>
          <lastname>Drăgoi</lastname>
          <moreinfo>correspondant</moreinfo>
        </person>
        <person key="antique-2018-idp155872">
          <firstname>Alexandru</firstname>
          <lastname>Militaru</lastname>
        </person>
        <person key="PASUSERID">
          <firstname>Josef</firstname>
          <lastname>Widder</lastname>
        </person>
      </participants>
      <p>Fault-tolerant distributed systems are implemented over asynchronous
networks, so that they use algorithms for asynchronous models
with faults. Due to asynchronous communication and the occurrence of
faults (e.g., process crashes or the network dropping messages) the implementations
are hard to understand and analyze. In contrast, synchronous
computation models simplify design and reasoning. In this paper, we
bridge the gap between these two worlds. For a class of asynchronous
protocols, we introduce a procedure that, given an asynchronous protocol,
soundly computes its round-based synchronous counterpart. This
class is defined by properties of the sequential code.
We computed the synchronous counterpart of known consensus and leader
election protocols, such as, Paxos, and Chandra and Toueg’s consensus.
Using Verifast we checked the sequential properties required by
the rewriting. We verified the round-based synchronous counter-part of
Multi-Paxos, and other algorithms, using existing deductive verification
methods for synchronous protocols.
</p>
    </subsection>
    <subsection id="uid73" level="1">
      <bodyTitle>Borel Kernels and their Approximation, Categorically</bodyTitle>
      <participants>
        <person key="PASUSERID">
          <firstname>Fredrik</firstname>
          <lastname>Dahlqvist</lastname>
        </person>
        <person key="PASUSERID">
          <firstname>Alexandra</firstname>
          <lastname>Silva</lastname>
        </person>
        <person key="antique-2018-idp123424">
          <firstname>Vicent</firstname>
          <lastname>Danos</lastname>
          <moreinfo>correspondant</moreinfo>
        </person>
        <person key="PASUSERID">
          <firstname>Ilias</firstname>
          <lastname>Garnier</lastname>
        </person>
      </participants>
      <p>In <ref xlink:href="#antique-2018-bid12" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> is introduced a categorical framework to study the exact and approximate semantics of probabilistic programs. We construct a dagger symmetric monoidal category of Borel kernels where the dagger-structure is given by Bayesian inversion. We show functorial bridges between this category and categories of Banach lattices which formalize the move from kernel-based semantics to predicate transformer (backward) or state transformer (forward) semantics. These bridges are related by natural transformations, and we show in particular that the Radon-Nikodym and Riesz representation theorems-two pillars of probability theory-define natural transformations. With the mathematical infrastructure in place, we present a generic and endogenous approach to approximating kernels on standard Borel spaces which exploits the involutive structure of our category of kernels. The approximation can be formulated in several equivalent ways by using the func-torial bridges and natural transformations described above. Finally, we show that for sensible discretization schemes, every Borel kernel can be approximated by kernels on finite spaces, and that these approximations converge for a natural choice of topology. We illustrate the theory by showing two examples of how approximation can effectively be used in practice: Bayesian inference and the Kleene * operation of ProbNetKAT.
</p>
    </subsection>
    <subsection id="uid74" level="1">
      <bodyTitle>Static analysis of rule-based models</bodyTitle>
      <p>Thanks to rule-based modeling languages, we can assemble
large sets of mechanistic protein-protein interactions within
integrated models. Our goal would be to understand how the behavior
of these systems emerges from these low-level interactions. Yet this
is a quite long term challenge and it is desirable to offer intermediary levels of abstraction, so as to get a better
understanding of the models and to increase our confidence within our mechanistic assumptions. To this extend, static analysis can be used to derive various abstractions of the semantics, each of them offering new perspectives on the models.</p>
      <subsection id="uid75" level="2">
        <bodyTitle>Trace approximation</bodyTitle>
        <participants>
          <person key="antique-2018-idp128736">
            <firstname>Jérôme</firstname>
            <lastname>Feret</lastname>
            <moreinfo>correspondant</moreinfo>
          </person>
          <person key="PASUSERID">
            <firstname>Kim Quyên</firstname>
            <lastname>Lý</lastname>
          </person>
        </participants>
        <p>In <ref xlink:href="#antique-2018-bid13" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we propose an abstract interpretation of the behavior of each protein, in isolation. Given a model written in Kappa, this abstraction computes for each kind of proteins a transition system that describes which conformations this protein may take and how a protein may pass from one conformation to another one. Then, we use simplicial complexes to abstract away the interleaving order of the transformations between conformations that commute. As a result, we get a compact summary of the potential behavior of each protein of the model.</p>
      </subsection>
      <subsection id="uid76" level="2">
        <bodyTitle>Detection of polymer formation</bodyTitle>
        <participants>
          <person key="antique-2018-idp165856">
            <firstname>Pierre</firstname>
            <lastname>Boutillier</lastname>
          </person>
          <person key="antique-2018-idp153408">
            <firstname>Aurélie</firstname>
            <lastname>Faure de Pebeyre</lastname>
          </person>
          <person key="antique-2018-idp128736">
            <firstname>Jérôme</firstname>
            <lastname>Feret</lastname>
            <moreinfo>correspondant</moreinfo>
          </person>
        </participants>
        <p>Rule-based languages, such as Kappa and BNGL, allow for the description of very combinatorial models of interactions between proteins. A huge (when not infinite) number of different kinds of bio-molecular compounds may arise due to proteins with multiple binding and phosphorylation sites. Knowing beforehand whether a model may involve an infinite number of different kinds of bio-molecular compounds is crucial for the modeler. On the first hand, having an infinite number of kinds of bio-molecular compounds is sometimes a hint for modeling flaws: forgetting to specify the conflicts among binding rules is a common mistake. On the second hand, it impacts the choice of the semantics for the models (among stochastic, differential, hybrid).</p>
        <p>In <ref xlink:href="#antique-2018-bid14" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we introduce a data-structure to abstract the potential unbounded polymers that may be formed in a rule-based model. This data-structure is a graph, the nodes and the edges of which are labeled with patterns. By construction, every potentially unbounded polymer is associated to at least one cycle in that graph. This data-structure has two main advantages. Firstly, as opposed to site-graphs, one can reason about cycles without enumerating them (by the means of Tarjan's algorithm for detecting strongly connected components). Secondly, this data-structures may be combined easily with information coming from additional reachability analysis: the edges that are labeled with an overlap that is proved unreachable in the model may be safely discarded.</p>
      </subsection>
      <subsection id="uid77" level="2">
        <bodyTitle>The static analyzer KaSa</bodyTitle>
        <participants>
          <person key="antique-2018-idp165856">
            <firstname>Pierre</firstname>
            <lastname>Boutillier</lastname>
          </person>
          <person key="antique-2018-idp146000">
            <firstname>Ferdinanda</firstname>
            <lastname>Camporesi</lastname>
          </person>
          <person key="PASUSERID">
            <firstname>Jean</firstname>
            <lastname>Coquet</lastname>
          </person>
          <person key="antique-2018-idp128736">
            <firstname>Jérôme</firstname>
            <lastname>Feret</lastname>
            <moreinfo>correspondant</moreinfo>
          </person>
          <person key="PASUSERID">
            <firstname>Kim Quyên</firstname>
            <lastname>Lý</lastname>
          </person>
          <person key="PASUSERID">
            <firstname>Nathalie</firstname>
            <lastname>Théret</lastname>
          </person>
          <person key="PASUSERID">
            <firstname>Pierre</firstname>
            <lastname>Vignet</lastname>
          </person>
        </participants>
        <p>KaSa is a static analyzer for Kappa models. Its goal is two-fold. Firstly, KaSa assists the modeler by warning about potential issues in the model. Secondly, KaSa may provide useful properties to check that what is implemented is what the modeler has in mind and to provide a quick overview of the model for the people who have not written it. The cornerstone of KaSa is a fix-point engine which detects some patterns that may never occur whatever the evolution of the system may be. From this, many useful information may be collected KaSa warns about rules that may never be applied, about potential irreversible transformations of proteins (that may not be reverted even thanks to an arbitrary number of computation steps) and about the potential formation of unbounded molecular compounds. Lastly, KaSa detects potential influences (activation/inhibition relation) between rules.</p>
        <p>In <ref xlink:href="#antique-2018-bid15" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we illustrate the main features of KaSa on a model of the extracellular activation of the transforming growth factor, TGF-b.
</p>
      </subsection>
    </subsection>
    <subsection id="uid78" level="1">
      <bodyTitle>The Kappa platform for rule-based modeling</bodyTitle>
      <participants>
        <person key="antique-2018-idp165856">
          <firstname>Pierre</firstname>
          <lastname>Boutillier</lastname>
        </person>
        <person key="PASUSERID">
          <firstname>Mutaamba</firstname>
          <lastname>Maasha</lastname>
        </person>
        <person key="antique-2018-idp141072">
          <firstname>Xing</firstname>
          <lastname>Li</lastname>
        </person>
        <person key="PASUSERID">
          <firstname>Héctor</firstname>
          <lastname>Medina-Abarca</lastname>
        </person>
        <person key="PASUSERID">
          <firstname>Jean</firstname>
          <lastname>Krivine</lastname>
        </person>
        <person key="antique-2018-idp128736">
          <firstname>Jérôme</firstname>
          <lastname>Feret</lastname>
          <moreinfo>correspondant</moreinfo>
        </person>
        <person key="PASUSERID">
          <firstname>Ioana</firstname>
          <lastname>Cristescu</lastname>
        </person>
        <person key="PASUSERID">
          <firstname>Angus</firstname>
          <lastname>Forbes</lastname>
        </person>
        <person key="PASUSERID">
          <firstname>Walter</firstname>
          <lastname>Fontana</lastname>
        </person>
      </participants>
      <p>In <ref xlink:href="#antique-2018-bid16" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we present an overview of the Kappa platform, an integrated suite of analysis and visualization techniques for building and interactively exploring rule-based models. The main components of the platform are the Kappa Simulator, the Kappa Static Analyzer and the Kappa Story Extractor. In addition to these components, we describe the Kappa User Interface, which includes a range of interactive visualization tools for rule-based models needed to make sense of the complexity of biological systems. We argue that, in this approach, modeling is akin to programming and can likewise benefit from an integrated development environment. Our platform is a step in this direction.</p>
      <p>We discuss details about the computation and rendering of static, dynamic, and causal views of a model, which include the contact map (CM), snapshots at different resolutions, the dynamic influence network (DIN) and causal compression. We provide use cases illustrating how these concepts generate insight. Specifically, we show how the CM and snapshots provide information about systems capable of polymerization, such as Wnt signaling. A well-understood model of the KaiABC oscillator, translated into Kappa from the literature, is deployed to demonstrate the DIN and its use in understanding systems dynamics. Finally, we discuss how pathways might be discovered or recovered from a rule-based model by means of causal compression, as exemplified for early events in EGF signaling.</p>
      <p>The Kappa platform is available via the project website at kappa-language.org. All components of the platform are open source and freely available through the authors' code repositories.
</p>
    </subsection>
    <subsection id="uid79" level="1">
      <bodyTitle>Conservative approximation of
systems of differential equations</bodyTitle>
      <p>We design a tools-kit to reason and abstract the solutions of the systems of differential equations that are described in high-level languages. Our abstractions are conservative in the sense that they provided sound lower and upper bounds for the value of some observables of the system.
Our approach consists, firstly, in inferring structural equalities about combinations of variables and structural inequalities about the value of variable derivatives thanks to symbolic reasoning at the level of the languages and, then, in using these numerical constraints to infer two differential equations for the variables of interest — one for the lower bound and one for the upper bound.</p>
      <p>We focus on the systems of equations that are described in Kappa.
Our goal is to provide a unifying framework that can deal with heterogeneous kinds of abstractions, including truncation, time- and concentration-scale separations, flow-based reduction, symmetries-based reduction.</p>
      <subsection id="uid80" level="2">
        <bodyTitle>Approximation of models of polymers</bodyTitle>
        <participants>
          <person key="PASUSERID">
            <firstname>Ken</firstname>
            <lastname>Chanseau Saint-Germain</lastname>
          </person>
          <person key="antique-2018-idp128736">
            <firstname>Jérôme</firstname>
            <lastname>Feret</lastname>
            <moreinfo>correspondant</moreinfo>
          </person>
        </participants>
        <p>We propose a systematic approach to approximate the behavior of models of polymers synthesis/degradation, described in Kappa. Our abstraction consists in
focusing on the behavior of all the patterns of size less than a given parameter. We infer symbolic equalities and inequalities which intentionally may be understood as algebraic constructions over patterns, and extensionally as sound properties about the concentration of the bio-molecular species that contain these patterns. Then, we derive a system of equations describing the time evolution of a lower and an upper bounds for the concentration of each pattern of interest.</p>
        <p>This work has been presented at VEMDP 2018 (Verification of Engineered Molecular Devices and Programs), in Oxford, 19th July 2018, and at the days “BIOS-IA” of the working group BIOSS, at Pasteur Institute, Paris, 18th December 2018.</p>
      </subsection>
      <subsection id="uid81" level="2">
        <bodyTitle>Approximation based on time- and/or concentration-scale separation</bodyTitle>
        <participants>
          <person key="antique-2018-idp131200">
            <firstname>Andreea</firstname>
            <lastname>Beica</lastname>
          </person>
          <person key="antique-2018-idp128736">
            <firstname>Jérôme</firstname>
            <lastname>Feret</lastname>
            <moreinfo>correspondant</moreinfo>
          </person>
        </participants>
        <p>In <ref xlink:href="#antique-2018-bid17" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we have designed and tested an approximation method for ODE models of biochemical reaction systems, in which the guarantees are our major requirement. Borrowing from tropical analysis techniques, we look at the dominance relations among terms of each species' ODE. These dominance relations can be exploited to simplify the original model, by neglecting the dominated terms. As the dominant subsystems can change during the system's dynamics, depending on which species dominate the others, several possible modes exist. Thus, simpler models consisting of only the dominant subsystems can be assembled into hybrid, piece-wise smooth models, which approximate the behavior of the initial system. By combining the detection of dominated terms with symbolic bounds propagation, we show how to approximate the original model by an assembly of simpler models, consisting in ordinary differential equations that provide time-dependent lower and upper bounds for the concentrations of the initial models species. The utility of our method is twofold. On the one hand, it provides a reduction heuristics that performs without any prior knowledge of the initial system's behavior (i.e., no simulation of the initial system is needed in order to reduce it). On the other hand, our method provides sound interval bounds for each species, and hence can serve to evaluate the faithfulness of tropicalization reduction heuristics for ODE models of biochemical reduction systems. The method is tested on several case studies.
</p>
      </subsection>
    </subsection>
    <subsection id="uid82" level="1">
      <bodyTitle>Sources, propagation and consequences of stochasticity in cellular growth</bodyTitle>
      <participants>
        <person key="PASUSERID">
          <firstname>Philipp</firstname>
          <lastname>Thomas</lastname>
        </person>
        <person key="PASUSERID">
          <firstname>Guillaume</firstname>
          <lastname>Terradot</lastname>
        </person>
        <person key="antique-2018-idp123424">
          <firstname>Vicent</firstname>
          <lastname>Danos</lastname>
          <moreinfo>correspondant</moreinfo>
        </person>
        <person key="PASUSERID">
          <firstname>Andrea</firstname>
          <lastname>Weiße</lastname>
        </person>
      </participants>
      <p>Growth impacts a range of phenotypic responses. Identifying the sources of growth variation and their propagation across the cellular machinery can thus unravel mechanisms that underpin cell decisions.</p>
      <p>In <ref xlink:href="#antique-2018-bid4" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we present a stochastic cell model linking gene expression, metabolism and replication to predict growth dynamics in single bacterial cells. Alongside we provide a theory to analyze stochastic chemical reactions coupled with cell divisions, enabling efficient parameter estimation, sensitivity analysis and hypothesis testing. The cell model recovers population-averaged data on growth-dependence of bacterial physiology and how growth variations in single cells change across conditions. We identify processes responsible for this variation and reconstruct the propagation of initial fluctuations to growth and other processes. Finally, we study drug-nutrient interactions and find that antibiotics can both enhance and suppress growth heterogeneity. Our results provide a predictive framework to integrate heterogeneous data and draw testable predictions with implications for antibiotic tolerance, evolutionary and synthetic biology.
</p>
    </subsection>
    <subsection id="uid83" level="1">
      <bodyTitle>Survival of the Fattest: Evolutionary Trade-offs in Cellular Resource Storage</bodyTitle>
      <participants>
        <person key="PASUSERID">
          <firstname>Guillaume</firstname>
          <lastname>Terradot</lastname>
        </person>
        <person key="antique-2018-idp131200">
          <firstname>Andreea</firstname>
          <lastname>Beica</lastname>
        </person>
        <person key="PASUSERID">
          <firstname>Andrea</firstname>
          <lastname>Weiße</lastname>
        </person>
        <person key="antique-2018-idp123424">
          <firstname>Vicent</firstname>
          <lastname>Danos</lastname>
          <moreinfo>correspondant</moreinfo>
        </person>
      </participants>
      <p>Cells derive resources from their environments and use them to fuel the bio-synthetic processes that determine cell growth. Depending on how responsive the bio-synthetic processes are to the availability of intracellular resources, cells can build up different levels of resource storage.</p>
      <p>In <ref xlink:href="#antique-2018-bid3" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we use a recent mathematical model of the coarse-grained mechanisms that drive cellular growth to investigate the effects of cellular resource storage on growth. We show that, on the one hand, there is a cost associated with high levels of storage resulting from the loss of stored resources due to dilution. We further show that, on the other hand, high levels of storage can benefit cells in variable environments by increasing biomass production during transitions from one medium to another. Our results thus suggest that cells may face trade-offs in their maintenance of resource storage based on the frequency of environmental change.
</p>
    </subsection>
    <subsection id="uid84" level="1">
      <bodyTitle>A Genetic Circuit Compiler: Generating Combinatorial Genetic Circuits with Web Semantics and Inference</bodyTitle>
      <participants>
        <person key="PASUSERID">
          <firstname>William</firstname>
          <lastname>Waites</lastname>
        </person>
        <person key="PASUSERID">
          <firstname>Goksel</firstname>
          <lastname>Misirli</lastname>
        </person>
        <person key="PASUSERID">
          <firstname>Matteo</firstname>
          <lastname>Cavaliere</lastname>
        </person>
        <person key="antique-2018-idp123424">
          <firstname>Vicent</firstname>
          <lastname>Danos</lastname>
          <moreinfo>correspondant</moreinfo>
        </person>
      </participants>
      <p>A central strategy of synthetic biology is to understand the basic processes of living creatures through engineering organisms using the same building blocks. Biological machines described in terms of parts can be studied by computer simulation in any of several languages or robotically assembled in vitro. In <ref xlink:href="#antique-2018-bid18" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/> we present a language, the Genetic Circuit Description Language (GCDL) and a compiler, the Genetic Circuit Compiler (GCC). This language describes genetic circuits at a level of granularity appropriate both for automated assembly in the laboratory and deriving simulation code. The GCDL follows Semantic Web practice and the compiler makes novel use of the logical inference facilities that are therefore available. We present the GCDL and compiler structure as a study of a tool for generating κ-language simulations from semantic descriptions of genetic circuits.
</p>
    </subsection>
    <subsection id="uid85" level="1">
      <bodyTitle>An Information-Theoretic Measure for Patterning in Epithelial Tissues</bodyTitle>
      <participants>
        <person key="PASUSERID">
          <firstname>William</firstname>
          <lastname>Waites</lastname>
        </person>
        <person key="PASUSERID">
          <firstname>Matteo</firstname>
          <lastname>Cavaliere</lastname>
        </person>
        <person key="PASUSERID">
          <firstname>Élise</firstname>
          <lastname>Cachat</lastname>
        </person>
        <person key="antique-2018-idp123424">
          <firstname>Vicent</firstname>
          <lastname>Danos</lastname>
          <moreinfo>correspondant</moreinfo>
        </person>
        <person key="PASUSERID">
          <firstname>Jamie A.</firstname>
          <lastname>Davies</lastname>
        </person>
      </participants>
      <p>In <ref xlink:href="#antique-2018-bid19" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>, we present path entropy, an information-theoretic measure that captures the notion of patterning due to phase separation in organic tissues. Recent work has demonstrated, both in silico and in vitro, that phase separation in epithelia can arise simply from the forces at play between cells with differing mechanical properties. These qualitative results give rise to numerous questions about how the degree of patterning relates to model parameters or underlying biophysical properties. Answering these questions requires a consistent and meaningful way of quantifying degree of patterning that we observe. We define a resolution-independent measure that is better suited than image-processing techniques for comparing cellular structures. We show how this measure can be usefully applied in a selection of scenarios from biological experiment and computer simulation, and argue for the establishment of a tissue-graph library to assist with parameter estimation for synthetic morphology.
</p>
    </subsection>
  </resultats>
  <partenariat id="uid86">
    <bodyTitle>Partnerships and Cooperations</bodyTitle>
    <subsection id="uid87" level="1">
      <bodyTitle>National Initiatives</bodyTitle>
      <subsection id="uid88" level="2">
        <bodyTitle>
          <ref xlink:href="http://www.di.ens.fr/~feret/anastasec/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">
            <span class="smallcap" align="left">AnaStaSec</span>
          </ref>
        </bodyTitle>
        <sanspuceslist>
          <li id="uid89">
            <p noindent="true">Title: Static Analysis for Security Properties</p>
          </li>
          <li id="uid90">
            <p noindent="true">Type: ANR générique 2014</p>
          </li>
          <li id="uid91">
            <p noindent="true">Defi: Société de l'information et de la communication</p>
          </li>
          <li id="uid92">
            <p noindent="true">Instrument: ANR grant</p>
          </li>
          <li id="uid93">
            <p noindent="true">Duration: January 2015 - December 2018</p>
          </li>
          <li id="uid94">
            <p noindent="true">Coordinator: Inria Paris-Rocquencourt (France)</p>
          </li>
          <li id="uid95">
            <p noindent="true">Others partners: Airbus France (France), AMOSSYS (France),
CEA LIST (France), Inria Rennes-Bretagne Atlantique (France),
TrustInSoft (France)</p>
          </li>
          <li id="uid96">
            <p noindent="true">Inria contact: Jérôme Feret</p>
          </li>
          <li id="uid97">
            <p noindent="true">See also: <ref xlink:href="http://www.di.ens.fr/~feret/anastasec/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://www.di.ens.fr/ feret/anastasec/</ref></p>
          </li>
          <li id="uid98">
            <p noindent="true">Abstract:
An emerging structure in our information processing-based society
is the notion of trusted complex systems interacting via heterogeneous
networks with an open, mostly untrusted world. This view characterises
a wide variety of systems ranging from the information system of a
company to the connected components of a private house, all of which
have to be connected with the outside.</p>
            <p>It is in particular the case for some aircraft-embedded computer
systems, which communicate with the ground through untrusted
communication media. Besides, the increasing demand for new
capabilities, such as enhanced on-board connectivity, e.g. using
mobile devices, together with the need for cost reduction, leads to
more integrated and interconnected systems. For instance, modern
aircrafts embed a large number of computer systems, from
safety-critical cockpit avionics to passenger entertainment. Some
systems meet both safety and security requirements. Despite thorough
segregation of subsystems and networks, some shared communication
resources raise the concern of possible intrusions.</p>
            <p>Some techniques have been developed and still need to be investigated
to ensure security and confidentiality properties of such
systems. Moreover, most of them are model-based techniques operating
only at architectural level and provide no guarantee on the actual
implementations. However, most security incidents are due to attackers
exploiting subtle implementation-level software
vulnerabilities. Systems should therefore be analyzed at software
level as well (i.e. source or executable code), in order to provide
formal assurance that security properties indeed hold for real
systems.</p>
            <p>Because of the size of such systems, and considering that they are
evolving entities, the only economically viable alternative is to
perform automatic analyses. Such analyses of security and
confidentiality properties have never been achieved on large-scale
systems where security properties interact with other software
properties, and even the mapping between high-level models of the
systems and the large software base implementing them has never been
done and represents a great challenge. The goal of this project is to
develop the new concepts and technologies necessary to meet such a
challenge.</p>
            <p>The project <ref xlink:href="http://www.di.ens.fr/~feret/anastasec/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"><span class="smallcap" align="left">AnaStaSec</span></ref> project will allow for the formal verification
of security properties of software-intensive embedded systems, using
automatic static analysis techniques at different levels of
representation: models, source and binary codes. Among expected
outcomes of the project will be a set of prototype tools, able to deal
with realistic large systems and the elaboration of industrial
security evaluation processes, based on static analysis.</p>
          </li>
        </sanspuceslist>
      </subsection>
      <subsection id="uid99" level="2">
        <bodyTitle>REPAS</bodyTitle>
        <p>The project REPAS, Reliable and Privacy-Aware Software Systems via
Bisimulation Metrics (coordination Catuscia Palamidessi, Inria Saclay),
aims at investigating quantitative notions and tools for proving
program correctness and protecting privacy, focusing on bisimulation
metrics, the natural extension of bisimulation on quantitative systems.
A key application is to develop mechanisms to protect the privacy of
users when their location traces are collected. Partners: Inria (Comete,
Focus), ENS Cachan, ENS Lyon, University of Bologna.</p>
      </subsection>
      <subsection id="uid100" level="2">
        <bodyTitle>SAFTA</bodyTitle>
        <sanspuceslist>
          <li id="uid101">
            <p noindent="true">Title: SAFTA Static Analysis for Fault-Tolerant distributed Algorithms.</p>
          </li>
          <li id="uid102">
            <p noindent="true">Type: ANR JCJC 2018</p>
          </li>
          <li id="uid103">
            <p noindent="true">Duration: February 2018 - February 2022</p>
          </li>
          <li id="uid104">
            <p noindent="true">Coordinator: Cezara Drăgoi, CR Inria</p>
          </li>
          <li id="uid105">
            <p noindent="true">Abstract:
Fault-tolerant distributed data structures are at the core distributed systems. Due to the multiple sources of non-determinism, their development is challenging. The project aims to increase the confidence we have in distributed implementations of data structures. We think that the difficulty does not only come from the algorithms but from the way we think about distributed systems. In this project we investigate partially synchronous communication-closed round based programming abstractions that reduce the number of interleavings, simplifying the reasoning about distributed systems and their proof arguments. We use partial synchrony to define reduction theorems from asynchronous semantics to partially synchronous ones, enabling the transfer of proofs from the synchronous world to the asynchronous one. Moreover, we define a domain specific language, that allows the programmer to focus on the algorithm task, it compiles into efficient asynchronous code, and it is equipped with automated verification engines.</p>
          </li>
        </sanspuceslist>
      </subsection>
      <subsection id="uid106" level="2">
        <bodyTitle>TGFSYSBIO</bodyTitle>
        <sanspuceslist>
          <li id="uid107">
            <p noindent="true">Title: Microenvironment and cancer: regulation of TGF-<formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>β</mi></math></formula> signaling</p>
          </li>
          <li id="uid108">
            <p noindent="true">Type: ANR générique 2014</p>
          </li>
          <li id="uid109">
            <p noindent="true">Defi: Société de l'information et de la communication</p>
          </li>
          <li id="uid110">
            <p noindent="true">Instrument: Plan Cancer 2014-2019</p>
          </li>
          <li id="uid111">
            <p noindent="true">Duration: December 2015 - November 2018</p>
          </li>
          <li id="uid112">
            <p noindent="true">Coordinator: INSERM U1085-IRSET</p>
          </li>
          <li id="uid113">
            <p noindent="true">Others partners: Inria Paris (France), Inria Rennes-Bretagne Atlantique (France),</p>
          </li>
          <li id="uid114">
            <p noindent="true">Inria contact: Jérôme Feret</p>
          </li>
          <li id="uid115">
            <p noindent="true">Abstract:
Most cases of hepatocellular carcinoma (HCC) develop in cirrhosis resulting from chronic liver diseases and the Transforming Growth Factor <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>β</mi></math></formula> (TGF-<formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>β</mi></math></formula>) is widely regarded as both the major pro-fibrogenic agent and a critical inducer of tumor progression and invasion. Targeting the deleterious effects of TGF-<formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>β</mi></math></formula> without affecting its physiological role is the common goal of therapeutic strategies. However, identification of specific targets remains challenging because of the pleiotropic effects of TGF-β linked to the complex nature of its extracellular activation and signaling networks.</p>
            <p>Our project proposes a systemic approach aiming at to identifying the potential targets that regulate the shift from anti- to pro-oncogenic effects of TGF-<formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>β</mi></math></formula>. To that purpose, we will combine a rule-based model (Kappa language) to describe extracellular TGF-beta activation and large-scale state-transition based (Cadbiom formalism) model for TGF-<formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>β</mi></math></formula>-dependent intracellular signaling pathways. The multi-scale integrated model will be enriched with a large-scale analysis of liver tissues using shotgun proteomics to characterize protein networks from tumor microenvironment whose remodeling is responsible for extracellular activation of TGF-<formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>β</mi></math></formula>. The trajectories and upstream regulators of the final model will be analyzed with symbolic model checking techniques and abstract interpretation combined with causality analysis. Candidates will be classified with semantic-based approaches and symbolic bi-clustering technics. All efforts must ultimately converge to experimental validations of hypotheses and we will use our hepatic cellular models (HCC cell lines and hepatic stellate cells) to screen inhibitors on the behaviors of TGF-<formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>β</mi></math></formula> signal.</p>
            <p>The expected results are the first model of extracellular and intracellular TGF-<formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>β</mi></math></formula> system that might permit to analyze the behaviors of TGF-<formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mi>β</mi></math></formula> activity during the course of liver tumor progression and to identify new biomarkers and potential therapeutic targets.</p>
          </li>
        </sanspuceslist>
      </subsection>
      <subsection id="uid116" level="2">
        <bodyTitle>
          <span class="smallcap" align="left">VeriAMOS</span>
        </bodyTitle>
        <sanspuceslist>
          <li id="uid117">
            <p noindent="true">Title: Verification of Abstract Machines for Operating Systems</p>
          </li>
          <li id="uid118">
            <p noindent="true">Type: ANR générique 2018</p>
          </li>
          <li id="uid119">
            <p noindent="true">Defi: Société de l'information et de la communication</p>
          </li>
          <li id="uid120">
            <p noindent="true">Instrument: ANR grant</p>
          </li>
          <li id="uid121">
            <p noindent="true">Duration: January 2019 - December 2022</p>
          </li>
          <li id="uid122">
            <p noindent="true">Coordinator: Inria Paris (France)</p>
          </li>
          <li id="uid123">
            <p noindent="true">Others partners: LIP6 (France), IRISA (France), UGA (France)</p>
          </li>
          <li id="uid124">
            <p noindent="true">Inria contact: Xavier Rival</p>
          </li>
          <li id="uid125">
            <p noindent="true">Abstract:
Operating System (OS) programming is notoriously difficult and error
prone. Moreover, OS bugs can have a serious impact on the functioning
of computer systems. Yet, the verification of OSes is still mostly an
open problem, and has only been done using user-assisted approaches
that require a huge amount of human intervention.
The VeriAMOS proposal relies on a novel approach to automatically and
fully verifying OS services, that combines Domain Specific Languages
(DSLs) and automatic static analysis. In this approach, DSLs provide
language abstraction and let users express complex policies in
high-level simple code. This code is later compiled into low level C
code, to be executed on an abstract machine. Last, the automatic
static analysis verifies structural and robustness properties on
the abstract machine and generated code.
We will apply this approach to the automatic, full verification of
input/output schedulers for modern supports like SSDs.</p>
          </li>
        </sanspuceslist>
      </subsection>
    </subsection>
    <subsection id="uid126" level="1">
      <bodyTitle>European Initiatives</bodyTitle>
      <subsection id="uid127" level="2">
        <bodyTitle>FP7 &amp; H2020 Projects</bodyTitle>
        <sanspuceslist>
          <li id="uid128">
            <p noindent="true">Type: IDEAS</p>
          </li>
          <li id="uid129">
            <p noindent="true">Defi:</p>
          </li>
          <li id="uid130">
            <p noindent="true">Instrument: ERC Proof of Concept Grant 2018</p>
          </li>
          <li id="uid131">
            <p noindent="true">Objectif: Static Analysis for the VErification of Spreadsheets</p>
          </li>
          <li id="uid132">
            <p noindent="true">Duration: January 2019 - June 2020</p>
          </li>
          <li id="uid133">
            <p noindent="true">Coordinator: Inria (France)</p>
          </li>
          <li id="uid134">
            <p noindent="true">Partner: None</p>
          </li>
          <li id="uid135">
            <p noindent="true">Inria contact: Xavier Rival</p>
          </li>
          <li id="uid136">
            <p noindent="true">Abstract:
Spreadsheet applications (such as Microsoft Excel + VBA) are heavily
used in a wide range of application domains including engineering,
finance, management, statistics and health.
However, they do not ensure robustness properties, thus spreadsheet
errors are common and potentially costly.
According to estimates, the annual cost of spreadsheet errors is
around 7 billion dollars.
For instance, in 2013, a series of spreadsheet errors at JPMorgan
incurred 6 billion dollars trading losses.
Yet, expert reports estimate about 90 % of the spreadsheets contain
errors.
The MemCAD ERC StG project opened the way to novel formal analysis
techniques for spreadsheet applications.
We propose to leverage these results into a toolbox able to safely
<i>verify</i>, <i>optimize</i> and <i>maintain</i> spreadsheets, so
as to reduce the likelihood of spreadsheet disasters.
This toolbox will be commercialized by the startup <span class="smallcap" align="left">MatrixLead</span>.</p>
          </li>
        </sanspuceslist>
      </subsection>
    </subsection>
    <subsection id="uid137" level="1">
      <bodyTitle>International Research Visitors</bodyTitle>
      <subsection id="uid138" level="2">
        <bodyTitle>Visits of International Scientists</bodyTitle>
        <subsection id="uid139" level="3">
          <bodyTitle>Internships</bodyTitle>
          <p>Jérôme Feret has supervised the M1 Internship of Aurélie Faure de Pebeyre
(AIV Master) and the M2 Internship of Albin Salazar (AIV Master).</p>
          <p>Xavier Rival is supervising M1 Internships of Guillaume Reboullet and of
Luc Chabassier (M1 at DIENS).</p>
          <p>Vincent Danos supervised interns Raja Ben Ali and Jaime Aujaud (L2 Epitech).</p>
        </subsection>
      </subsection>
    </subsection>
  </partenariat>
  <diffusion id="uid140">
    <bodyTitle>Dissemination</bodyTitle>
    <subsection id="uid141" level="1">
      <bodyTitle>Promoting Scientific Activities</bodyTitle>
      <subsection id="uid142" level="2">
        <bodyTitle>Scientific Events Organisation</bodyTitle>
        <subsection id="uid143" level="3">
          <bodyTitle>General Chair, Scientific Chair</bodyTitle>
          <simplelist>
            <li id="uid144">
              <p noindent="true">Jérôme Feret is a guest member of the Steering Committee of the
Conference on Computational Methods in Systems Biology (CMSB).</p>
            </li>
            <li id="uid145">
              <p noindent="true">Jérôme Feret is a member of the Steering Committee of the Workshop
on Static Analysis and Systems Biology (SASB).</p>
            </li>
            <li id="uid146">
              <p noindent="true">Xavier Rival organized the 60th meeting of the IFIP Working Group 2.4
held in Dijon, in July 2018.</p>
            </li>
            <li id="uid147">
              <p noindent="true">Xavier Rival is a member of the Steering Committee of the Static
Analysis Symposium (SAS).</p>
            </li>
            <li id="uid148">
              <p noindent="true">Xavier Rival is a member of the Steering Committee of the Workshop
on Tools for Automatic Program Analysis (TAPAS).</p>
            </li>
          </simplelist>
        </subsection>
      </subsection>
      <subsection id="uid149" level="2">
        <bodyTitle>Scientific Events Selection</bodyTitle>
        <subsection id="uid150" level="3">
          <bodyTitle>Chair of Conference Program Committees</bodyTitle>
          <simplelist>
            <li id="uid151">
              <p noindent="true">Xavier Rival served as Chair of the Artifact
Evaluation Committee of SAS 2018 (Static Analysis Symposium).</p>
            </li>
          </simplelist>
        </subsection>
        <subsection id="uid152" level="3">
          <bodyTitle>Member of the Conference Program Committees</bodyTitle>
          <simplelist>
            <li id="uid153">
              <p noindent="true">Jérôme Feret served as a Member of the Program Committee of
LICS 2018 (Logic in Computer Science).</p>
            </li>
            <li id="uid154">
              <p noindent="true">Jérôme Feret served as a Member of the Program Committee of
VEMDP 2018 (Verification of Engineered Molecular Devices and Programs).</p>
            </li>
            <li id="uid155">
              <p noindent="true">Jérôme Feret served as a Member of the Program Committee of SASB 2018 (Static Analysis and Systems Biology Workshop).</p>
            </li>
            <li id="uid156">
              <p noindent="true">Jérôme Feret served as a Member of the Program
Committee of SAS 2018 (Static Analysis Symposium).</p>
            </li>
            <li id="uid157">
              <p noindent="true">Jérôme Feret served as a Member of the Program Committee
of CMSB 2018 (Computational Methods in Systems Biology).</p>
            </li>
            <li id="uid158">
              <p noindent="true">Jérôme Feret served as a Member of the Program Committee
of VMCAI 2019 (Verification, Model Checking, and Abstract Interpretation)</p>
            </li>
            <li id="uid159">
              <p noindent="true">Jérôme Feret is serving as a Member of the Program Committee
of CIBCB 2019 (Computational Intelligence in Bioinformatics and Computational Biology).</p>
            </li>
            <li id="uid160">
              <p noindent="true">érôme Feret is serving as a Member of the Program Committee of HSB 2019 (Hybrid Systems and Biology).</p>
            </li>
            <li id="uid161">
              <p noindent="true">Jérôme Feret is serving as a Member of the Program Committee
of CMSB 2019 (Computational Methods in Systems Biology).</p>
            </li>
            <li id="uid162">
              <p noindent="true">Xavier Rival served as a Member of the Program
Committee of SAS 2018 (Static Analysis Symposium).</p>
            </li>
            <li id="uid163">
              <p noindent="true">Xavier Rival served as a Member of the Program Committee of
Web Design, Analysis, Programming and Implementation of the
WWW'18 Conference.</p>
            </li>
            <li id="uid164">
              <p noindent="true">Xavier Rival served as a Member of the Extended Review Committee
of PLDI 2018 (Programming Languages Design and Implementation).</p>
            </li>
            <li id="uid165">
              <p noindent="true">Xavier Rival served as a Member of the Program Committee
of APLAS 2018 (Asian Programming Languages And Systems Symposium).</p>
            </li>
            <li id="uid166">
              <p noindent="true">Xavier Rival is serving as a Member of the Committee of POPL 2020
(Principles of Programming Languages).</p>
            </li>
            <li id="uid167">
              <p noindent="true">Cezara Drăgoi served as a member of the Program Committee of Computer Aided Verification CAV'18.</p>
            </li>
            <li id="uid168">
              <p noindent="true">Cezara Drăgoi served as a member of the Program Committee
of VMCAI 2019 (Verification, Model Checking, and Abstract Interpretation).</p>
            </li>
            <li id="uid169">
              <p noindent="true">Cezara Drăgoi served as a member of the Program Committee
of NETYS 2018.</p>
            </li>
          </simplelist>
        </subsection>
        <subsection id="uid170" level="3">
          <bodyTitle>Reviewer</bodyTitle>
          <simplelist>
            <li id="uid171">
              <p noindent="true">Jérôme Feret served as Reviewer for ARSBM 2018 (Automated Reasoning for Systems Biology and Medicine).</p>
            </li>
          </simplelist>
        </subsection>
      </subsection>
      <subsection id="uid172" level="2">
        <bodyTitle>Journal</bodyTitle>
        <subsection id="uid173" level="3">
          <bodyTitle>Member of the Editorial Boards</bodyTitle>
          <simplelist>
            <li id="uid174">
              <p noindent="true">Jérôme Feret serves as a Member of the Editorial Board of the Frontiers
in Genetics journal and the Open Journal of Modeling and Simulation.</p>
            </li>
            <li id="uid175">
              <p noindent="true">Jérôme Feret serves as co-Editor of an Issue of the Theoretical
Computer Science journal, that is composed of papers from SASB 2016,
and is expected to appear in 2019.</p>
            </li>
            <li id="uid176">
              <p noindent="true">Jérôme Feret serves as co-Editor of an Issue of the IEEE/ACM Transactions
on Computational Biology and Bioinformatics, that is composed of papers
from CMSB 2017, and is expected to appear in 2019.</p>
            </li>
            <li id="uid177">
              <p noindent="true">Xavier Rival serves as Editor of an Issue of the Formal Methods
in System Design Journal, that is composed of a selection of papers
from SAS 2016, and appeared in 2018.</p>
            </li>
          </simplelist>
        </subsection>
        <subsection id="uid178" level="3">
          <bodyTitle>Reviewer - Reviewing Activities</bodyTitle>
          <simplelist>
            <li id="uid179">
              <p noindent="true">Jérôme Feret served as a Reviewer for NACO (Natural Computing).</p>
            </li>
            <li id="uid180">
              <p noindent="true">Jérôme Feret served as a Reviewer for ACS Synthetic Biology.</p>
            </li>
            <li id="uid181">
              <p noindent="true">Jérôme Feret served as a Reviewer for TCS (Theoretical
Computer Sciences).</p>
            </li>
            <li id="uid182">
              <p noindent="true">Jérôme Feret served as a Reviewer for TCBB (IEEE/ACM Transactions
on Computational Biology and Bioinformatics).</p>
            </li>
            <li id="uid183">
              <p noindent="true">Jérôme Feret served as a Reviewer for IEEE Transactions on Reliability.</p>
            </li>
            <li id="uid184">
              <p noindent="true">Xavier Rival served as a Reviewer for ACM TOPLAS (Transactions On
Programming Languages and Systems).</p>
            </li>
            <li id="uid185">
              <p noindent="true">Xavier Rival served as a Reviewer for ACM TOPS (Transactions On
Privacy and Security).</p>
            </li>
          </simplelist>
        </subsection>
      </subsection>
      <subsection id="uid186" level="2">
        <bodyTitle>Invited Talks</bodyTitle>
        <simplelist>
          <li id="uid187">
            <p noindent="true">Cezara Drăgoi was invited to give a talk at the workshop on Verification of Distributed Systems, Essaouira, Morocco, 2018.</p>
          </li>
          <li id="uid188">
            <p noindent="true">Cezara Drăgoi was invited to give a talk at the Dagstuhl workshop no 18211 on Formal Methods and Fault-Tolerant Distributed Computing: Forging an Alliance.</p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid189" level="2">
        <bodyTitle>Leadership within the Scientific Community</bodyTitle>
        <p>Xavier Rival is a member of the IFIP Working Group 2.4 on Software
implementation technology.</p>
      </subsection>
      <subsection id="uid190" level="2">
        <bodyTitle>Scientific Expertise</bodyTitle>
        <simplelist>
          <li id="uid191">
            <p noindent="true">Cezara Drăgoi has participated to the recruitment committee for an assistant professor in the Department of Computer Science of École normale supérieure 2018.</p>
          </li>
          <li id="uid192">
            <p noindent="true">Jérôme Feret served as a external Reviewer for research program PRIM 2017 (funded by MIUR, the Italian Ministry for Education, University and Research).</p>
          </li>
          <li id="uid193">
            <p noindent="true">Jérôme Feret has participated to the recruitment committee for an assistant professor in Paris-Diderot University 2018.</p>
          </li>
          <li id="uid194">
            <p noindent="true">Xavier Rival chaired the Hiring Committee for an Assistant Professor position (Tenure track position, Gaspard Monge Chair) at École Polytechnique in 2018.</p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid195" level="2">
        <bodyTitle>Research Administration</bodyTitle>
        <simplelist>
          <li id="uid196">
            <p noindent="true">Jérôme Feret and Xavier Rival are members of the Laboratory Council
of DIENS.</p>
          </li>
          <li id="uid197">
            <p noindent="true">Jérôme Feret is member of PhD Review Committee (CSD) of Inria Paris.</p>
          </li>
          <li id="uid198">
            <p noindent="true">Jérôme Feret is deputy head of study of the Department of Computer Science of École normale supérieure.</p>
          </li>
        </simplelist>
      </subsection>
    </subsection>
    <subsection id="uid199" level="1">
      <bodyTitle>Teaching - Supervision - Juries</bodyTitle>
      <subsection id="uid200" level="2">
        <bodyTitle>Teaching</bodyTitle>
        <sanspuceslist>
          <li id="uid201">
            <p noindent="true">Licence:</p>
            <simplelist>
              <li id="uid202">
                <p noindent="true">Marc Chevalier, Mathematics, 40h, L1, FDV
Bachelor program (Frontiers in Life Sciences (FdV)), Université
Paris-Descartes, France.</p>
              </li>
              <li id="uid203">
                <p noindent="true">Jérôme Feret and Xavier Rival (lectures), and Marc Chevalier (tutorials), “Semantics and Application to Verification”,
36h, L3, at École Normale Supérieure, France.</p>
              </li>
              <li id="uid204">
                <p noindent="true">Xavier Rival,
“Introduction to Static Analysis”,
8h, L3, at École des Mines de Paris, France.</p>
              </li>
              <li id="uid205">
                <p noindent="true">Xavier Rival,
“Programmation Avancée”,
18h, L3, at École Polytechnique, France.</p>
              </li>
            </simplelist>
          </li>
          <li id="uid206">
            <p noindent="true">Master:</p>
            <simplelist>
              <li id="uid207">
                <p noindent="true">Xavier Rival,
“Introduction to Static Analysis”,
24h, Internet of Things Master (retraining curriculum, EXED), France.</p>
              </li>
              <li id="uid208">
                <p noindent="true">Xavier Rival,
“Protocol Safety and Verification”,
12h, M2, Advanced Communication Networks Master, France.</p>
              </li>
              <li id="uid209">
                <p noindent="true">Cezara Drăgoi, Jérôme Feret, Antoine Miné, and Xavier Rival,
“Abstract Interpretation: application to verification and static
analysis”,
72h, M2. Parisian Master of Research in Computer Science (MPRI), France.</p>
              </li>
              <li id="uid210">
                <p noindent="true">Vincent Danos and Jérôme Feret (with Jean Krivine), Computational
Biology, 28h, M1. Interdisciplinary Approaches to Life Science (AIV),
Master Program, Université Paris-Descartes, France.</p>
              </li>
            </simplelist>
          </li>
          <li id="uid211">
            <p noindent="true">Doctorat:</p>
            <simplelist>
              <li id="uid212">
                <p noindent="true">Jérôme Feret, “Intrinsic Coarse-Graining of Models of Signalling pathways", 1h30, aDVANCES IN SYSTEMS AND SYNTHETIC BIOLOGY
Modelling Complex Biological Systems in the Context of Genomics
Thematic Research School, March 2018, Évry, France.</p>
              </li>
            </simplelist>
          </li>
        </sanspuceslist>
      </subsection>
      <subsection id="uid213" level="2">
        <bodyTitle>Supervision</bodyTitle>
        <simplelist>
          <li id="uid214">
            <p noindent="true">PhD in progress:
Marc Chevalier,
Static analysis of Security Properties in Critical Embedded Software.
started in 2017 and supervised by Jérôme Feret</p>
          </li>
          <li id="uid215">
            <p noindent="true">PhD in progress:
Hugo Illous,
Relational Shape Abstraction Based on Separation Logic,
started in 2015 and supervised by Xavier Rival and Matthieu Lemerre (CEA)</p>
          </li>
          <li id="uid216">
            <p noindent="true">PhD in progress:
Olivier Nicole,
Verification of micro-kernels,
started in 2018 and supervised by Xavier Rival and Matthieu Lemerre (CEA)</p>
          </li>
          <li id="uid217">
            <p noindent="true">PhD defended:
Huisong Li,
Disjunctive Shape Abstraction for Shared Data-Structures,
started in 2014 and supervised by Xavier Rival</p>
          </li>
          <li id="uid218">
            <p noindent="true">PhD defended:
Jiangchao Liu,
Static Analysis for Numeric and Structural Properties of Array Contents,
started in 2014 and supervised by Xavier Rival</p>
          </li>
        </simplelist>
      </subsection>
      <subsection id="uid219" level="2">
        <bodyTitle>Juries</bodyTitle>
        <simplelist>
          <li id="uid220">
            <p noindent="true">Xavier Rival served as a Reviewer in the Jury of the PhD of
Ahmad Salim Al-Sibahi (Defense planned for the 11th of January, 2018).</p>
          </li>
        </simplelist>
      </subsection>
    </subsection>
    <subsection id="uid221" level="1">
      <bodyTitle>Popularization</bodyTitle>
      <subsection id="uid222" level="2">
        <bodyTitle>Internal or external Inria responsibilities</bodyTitle>
        <simplelist>
          <li id="uid223">
            <p noindent="true">Xavier Rival is member of the “Bureau du comité des projets” since
October 2018.</p>
          </li>
          <li id="uid224">
            <p noindent="true">Xavier Rival is Chair of the Hiring Committee for Inria researchers
at the center of Paris (CRCN) for 2019.</p>
          </li>
        </simplelist>
      </subsection>
    </subsection>
  </diffusion>
  <biblio id="bibliography" html="bibliography" numero="10" titre="Bibliography">
    
    <biblStruct id="antique-2018-bid28" type="inproceedings" rend="refer" n="refercite:bertrane:2010:inria-00528611:1">
      <analytic>
        <title level="a">Static Analysis and Verification of Aerospace Software by Abstract Interpretation</title>
        <author>
          <persName>
            <foreName>Julien</foreName>
            <surname>Bertrane</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
          <persName>
            <foreName>Radhia</foreName>
            <surname>Cousot</surname>
            <initial>R.</initial>
          </persName>
          <persName key="antique-2018-idp128736">
            <foreName>Jérôme</foreName>
            <surname>Feret</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Laurent</foreName>
            <surname>Mauborgne</surname>
            <initial>L.</initial>
          </persName>
          <persName>
            <foreName>Antoine</foreName>
            <surname>Miné</surname>
            <initial>A.</initial>
          </persName>
          <persName key="antique-2018-idp120512">
            <foreName>Xavier</foreName>
            <surname>Rival</surname>
            <initial>X.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <title level="m">Proceedings of the American Institute of Aeronautics and Astronautics (AIAA Infotech@Aerospace 2010)</title>
        <loc>Atlanta, Georgia, USA</loc>
        <imprint>
          <publisher>
            <orgName>American Institute of Aeronautics and Astronautics</orgName>
          </publisher>
          <dateStruct>
            <year>2010</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid23" type="inproceedings" rend="refer" n="refercite:BlanchetEtAl-PLDI03">
      <analytic>
        <title level="a">A Static Analyzer for Large Safety-Critical Software</title>
        <author>
          <persName key="prosecco-2018-idp167408">
            <foreName>Bruno</foreName>
            <surname>Blanchet</surname>
            <initial>B.</initial>
          </persName>
          <persName>
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
          <persName>
            <foreName>Radhia</foreName>
            <surname>Cousot</surname>
            <initial>R.</initial>
          </persName>
          <persName key="antique-2018-idp128736">
            <foreName>Jérôme</foreName>
            <surname>Feret</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Laurent</foreName>
            <surname>Mauborgne</surname>
            <initial>L.</initial>
          </persName>
          <persName>
            <foreName>Antoine</foreName>
            <surname>Miné</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>David</foreName>
            <surname>Monniaux</surname>
            <initial>D.</initial>
          </persName>
          <persName key="antique-2018-idp120512">
            <foreName>Xavier</foreName>
            <surname>Rival</surname>
            <initial>X.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">Proceedings of the ACM SIGPLAN 2003 Conference on Programming Language Design and Implementation (PLDI'03)</title>
        <imprint>
          <publisher>
            <orgName>ACM Press</orgName>
          </publisher>
          <dateStruct>
            <month>June 7–14</month>
            <year>2003</year>
          </dateStruct>
          <biblScope type="pages">196–207</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid29" type="inproceedings" rend="refer" n="refercite:DBLP:conf/pldi/BouajjaniDES11">
      <identifiant type="doi" value="10.1145/1993498.1993566"/>
      <analytic>
        <title level="a">On inter-procedural analysis of programs with lists and data</title>
        <author>
          <persName>
            <foreName>Ahmed</foreName>
            <surname>Bouajjani</surname>
            <initial>A.</initial>
          </persName>
          <persName key="antique-2018-idp126272">
            <foreName>Cezara</foreName>
            <surname>Dragoi</surname>
            <initial>C.</initial>
          </persName>
          <persName>
            <foreName>Constantin</foreName>
            <surname>Enea</surname>
            <initial>C.</initial>
          </persName>
          <persName>
            <foreName>Mihaela</foreName>
            <surname>Sighireanu</surname>
            <initial>M.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">Proceedings of the 32nd ACM SIGPLAN Conference on Programming Language Design and Implementation, PLDI 2011, San Jose, CA, USA, June 4-8, 2011</title>
        <imprint>
          <dateStruct>
            <year>2011</year>
          </dateStruct>
          <biblScope type="pages">578–589</biblScope>
          <ref xlink:href="https://dl.acm.org/citation.cfm?id=1993498.1993566" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>dl.<allowbreak/>acm.<allowbreak/>org/<allowbreak/>citation.<allowbreak/>cfm?id=1993498.<allowbreak/>1993566</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid22" type="article" rend="refer" n="refercite:Cousot02-TCS">
      <analytic>
        <title level="a">Constructive Design of a Hierarchy of Semantics of a Transition System by Abstract Interpretation</title>
        <author>
          <persName>
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Theoretical Computer Science</title>
        <imprint>
          <biblScope type="volume">277</biblScope>
          <biblScope type="number">1–2</biblScope>
          <dateStruct>
            <year>2002</year>
          </dateStruct>
          <biblScope type="pages">47–103</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid27" type="article" rend="refer" n="refercite:feret-PNAS">
      <analytic>
        <title level="a">Internal coarse-graining of molecular systems</title>
        <author>
          <persName key="antique-2018-idp128736">
            <foreName>Jérôme</foreName>
            <surname>Feret</surname>
            <initial>J.</initial>
          </persName>
          <persName key="antique-2018-idp123424">
            <foreName>Vincent</foreName>
            <surname>Danos</surname>
            <initial>V.</initial>
          </persName>
          <persName>
            <foreName>Jean</foreName>
            <surname>Krivine</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Russ</foreName>
            <surname>Harmer</surname>
            <initial>R.</initial>
          </persName>
          <persName>
            <foreName>Walter</foreName>
            <surname>Fontana</surname>
            <initial>W.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-editorial-board="yes" x-international-audience="yes">
        <title level="j">Proceeding of the national academy of sciences</title>
        <imprint>
          <biblScope type="volume">106</biblScope>
          <biblScope type="number">16</biblScope>
          <dateStruct>
            <month>Apr</month>
            <year>2009</year>
          </dateStruct>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid25" type="inproceedings" rend="refer" n="refercite:mauborgne:rival05">
      <analytic>
        <title level="a">Trace Partitioning in Abstract Interpretation Based Static Analyzers</title>
        <author>
          <persName>
            <foreName>Laurent</foreName>
            <surname>Mauborgne</surname>
            <initial>L.</initial>
          </persName>
          <persName key="antique-2018-idp120512">
            <foreName>Xavier</foreName>
            <surname>Rival</surname>
            <initial>X.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Mooly</foreName>
            <surname>Sagiv</surname>
            <initial>M.</initial>
          </persName>
        </editor>
        <title level="m">Proceedings of the 14th European Symposium on Programming (ESOP'05)</title>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">3444</biblScope>
          <publisher>
            <orgName>Springer-Verlag</orgName>
          </publisher>
          <dateStruct>
            <year>2005</year>
          </dateStruct>
          <biblScope type="pages">5–20</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid26" type="article" rend="refer" n="refercite:Mine-HOSC06">
      <analytic>
        <title level="a">The Octagon Abstract Domain</title>
        <author>
          <persName>
            <foreName>Antoine</foreName>
            <surname>Miné</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Higher-Order and Symbolic Computation</title>
        <imprint>
          <biblScope type="volume">19</biblScope>
          <dateStruct>
            <year>2006</year>
          </dateStruct>
          <biblScope type="pages">31–100</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid24" type="inproceedings" rend="refer" n="refercite:Rival-POPL04">
      <analytic>
        <title level="a">Symbolic Transfer Functions-based Approaches to Certified Compilation</title>
        <author>
          <persName key="antique-2018-idp120512">
            <foreName>Xavier</foreName>
            <surname>Rival</surname>
            <initial>X.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">Conference Record of the 31st Annual ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages</title>
        <imprint>
          <publisher>
            <orgName>ACM Press, New York, United States</orgName>
          </publisher>
          <dateStruct>
            <year>2004</year>
          </dateStruct>
          <biblScope type="pages">1–13</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid10" type="phdthesis" rend="year" n="cite:li:tel-01963082">
      <identifiant type="hal" value="tel-01963082"/>
      <monogr>
        <title level="m">Shape Abstractions with Support for Sharing and Disjunctions</title>
        <author>
          <persName key="antique-2018-idp141072">
            <foreName>Huisong</foreName>
            <surname>Li</surname>
            <initial>H.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="school">ENS Paris - Ecole Normale Supérieure de Paris ; PSL University</orgName>
          </publisher>
          <dateStruct>
            <month>January</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.archives-ouvertes.fr/tel-01963082" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>archives-ouvertes.<allowbreak/>fr/<allowbreak/>tel-01963082</ref>
        </imprint>
      </monogr>
      <note type="typdoc">Theses</note>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid8" type="phdthesis" rend="year" n="cite:liu:tel-01963108">
      <identifiant type="hal" value="tel-01963108"/>
      <monogr>
        <title level="m">Static Analysis on Numeric and Structural Properties of Array Contents</title>
        <author>
          <persName key="antique-2018-idp168320">
            <foreName>Jiangchao</foreName>
            <surname>Liu</surname>
            <initial>J.</initial>
          </persName>
        </author>
        <imprint>
          <publisher>
            <orgName type="school">ENS Paris ; PSL University</orgName>
          </publisher>
          <dateStruct>
            <month>February</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.archives-ouvertes.fr/tel-01963108" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>archives-ouvertes.<allowbreak/>fr/<allowbreak/>tel-01963108</ref>
        </imprint>
      </monogr>
      <note type="typdoc">Theses</note>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid16" type="article" rend="year" n="cite:boutillier:hal-01962663">
      <identifiant type="doi" value="10.1093/bioinformatics/bty272"/>
      <identifiant type="hal" value="hal-01962663"/>
      <analytic>
        <title level="a">The Kappa platform for rule-based modeling</title>
        <author>
          <persName key="antique-2018-idp165856">
            <foreName>Pierre</foreName>
            <surname>Boutillier</surname>
            <initial>P.</initial>
          </persName>
          <persName>
            <foreName>Mutaamba</foreName>
            <surname>Maasha</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>Xing</foreName>
            <surname>Li</surname>
            <initial>X.</initial>
          </persName>
          <persName>
            <foreName>Héctor F</foreName>
            <surname>Medina-Abarca</surname>
            <initial>H. F.</initial>
          </persName>
          <persName>
            <foreName>Jean</foreName>
            <surname>Krivine</surname>
            <initial>J.</initial>
          </persName>
          <persName key="antique-2018-idp128736">
            <foreName>Jérôme</foreName>
            <surname>Feret</surname>
            <initial>J.</initial>
          </persName>
          <persName key="tamis-2018-idp134080">
            <foreName>Ioana</foreName>
            <surname>Cristescu</surname>
            <initial>I.</initial>
          </persName>
          <persName>
            <foreName>Angus G.</foreName>
            <surname>Forbes</surname>
            <initial>A. G.</initial>
          </persName>
          <persName>
            <foreName>Walter</foreName>
            <surname>Fontana</surname>
            <initial>W.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid00243">
        <idno type="issn">1367-4803</idno>
        <title level="j">Bioinformatics</title>
        <imprint>
          <biblScope type="volume">34</biblScope>
          <biblScope type="number">13</biblScope>
          <dateStruct>
            <month>July</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">i583-i592</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01962663" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01962663</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid12" type="article" rend="year" n="cite:dahlqvist:hal-01976416">
      <identifiant type="hal" value="hal-01976416"/>
      <analytic>
        <title level="a">Borel Kernels and their Approximation, Categorically</title>
        <author>
          <persName>
            <foreName>Fredrik</foreName>
            <surname>Dahlqvist</surname>
            <initial>F.</initial>
          </persName>
          <persName>
            <foreName>Alexandra</foreName>
            <surname>Silva</surname>
            <initial>A.</initial>
          </persName>
          <persName key="antique-2018-idp123424">
            <foreName>Vincent</foreName>
            <surname>Danos</surname>
            <initial>V.</initial>
          </persName>
          <persName>
            <foreName>Ilias</foreName>
            <surname>Garnier</surname>
            <initial>I.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid00522">
        <idno type="issn">1571-0661</idno>
        <title level="j">Electronic Notes in Theoretical Computer Science</title>
        <imprint>
          <biblScope type="volume">341</biblScope>
          <dateStruct>
            <month>December</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">91-119</biblScope>
          <ref xlink:href="https://hal.archives-ouvertes.fr/hal-01976416" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>archives-ouvertes.<allowbreak/>fr/<allowbreak/>hal-01976416</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid13" type="article" rend="year" n="cite:feret:hal-01967635">
      <identifiant type="hal" value="hal-01967635"/>
      <analytic>
        <title level="a">Local Traces: An Over-Approximation of the Behavior of the Proteins in Rule-Based Models</title>
        <author>
          <persName key="antique-2018-idp128736">
            <foreName>Jérôme</foreName>
            <surname>Feret</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Kim Quyên</foreName>
            <surname>Lý</surname>
            <initial>K. Q.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid00763">
        <idno type="issn">1545-5963</idno>
        <title level="j">IEEE/ACM Transactions on Computational Biology and Bioinformatics</title>
        <imprint>
          <biblScope type="volume">15</biblScope>
          <biblScope type="number">4</biblScope>
          <dateStruct>
            <month>July</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">1124-1137</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01967635" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01967635</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid6" type="article" rend="year" n="cite:kim:hal-01963069">
      <identifiant type="hal" value="hal-01963069"/>
      <analytic>
        <title level="a">A Theoretical Foundation of Sensitivity in an Abstract Interpretation Framework</title>
        <author>
          <persName>
            <foreName>Se-Won</foreName>
            <surname>Kim</surname>
            <initial>S.-W.</initial>
          </persName>
          <persName key="antique-2018-idp120512">
            <foreName>Xavier</foreName>
            <surname>Rival</surname>
            <initial>X.</initial>
          </persName>
          <persName>
            <foreName>Sukyoung</foreName>
            <surname>Ryu</surname>
            <initial>S.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid00032">
        <idno type="issn">0164-0925</idno>
        <title level="j">ACM Transactions on Programming Languages and Systems (TOPLAS)</title>
        <imprint>
          <biblScope type="volume">40</biblScope>
          <biblScope type="number">3</biblScope>
          <dateStruct>
            <month>August</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">1-44</biblScope>
          <ref xlink:href="https://hal.archives-ouvertes.fr/hal-01963069" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>archives-ouvertes.<allowbreak/>fr/<allowbreak/>hal-01963069</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid7" type="article" rend="year" n="cite:liu:hal-01963049">
      <identifiant type="hal" value="hal-01963049"/>
      <analytic>
        <title level="a">Automatic Verification of Embedded System Code Manipulating Dynamic Structures Stored in Contiguous Regions</title>
        <author>
          <persName key="antique-2018-idp168320">
            <foreName>Jiangchao</foreName>
            <surname>Liu</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Liqian</foreName>
            <surname>Chen</surname>
            <initial>L.</initial>
          </persName>
          <persName key="antique-2018-idp120512">
            <foreName>Xavier</foreName>
            <surname>Rival</surname>
            <initial>X.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid00719">
        <idno type="issn">0278-0070</idno>
        <title level="j">IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems</title>
        <imprint>
          <biblScope type="volume">37</biblScope>
          <biblScope type="number">11</biblScope>
          <dateStruct>
            <month>November</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">2311-2322</biblScope>
          <ref xlink:href="https://hal.archives-ouvertes.fr/hal-01963049" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>archives-ouvertes.<allowbreak/>fr/<allowbreak/>hal-01963049</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid3" type="article" rend="year" n="cite:terradot:hal-01976385">
      <identifiant type="doi" value="10.1016/j.entcs.2018.03.010"/>
      <identifiant type="hal" value="hal-01976385"/>
      <analytic>
        <title level="a">Survival of the Fattest: Evolutionary Trade-offs in Cellular Resource Storage</title>
        <author>
          <persName>
            <foreName>Guillaume</foreName>
            <surname>Terradot</surname>
            <initial>G.</initial>
          </persName>
          <persName key="antique-2018-idp131200">
            <foreName>Andreea</foreName>
            <surname>Beica</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Andrea Y</foreName>
            <surname>Weiße</surname>
            <initial>A. Y.</initial>
          </persName>
          <persName key="antique-2018-idp123424">
            <foreName>Vincent</foreName>
            <surname>Danos</surname>
            <initial>V.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid00522">
        <idno type="issn">1571-0661</idno>
        <title level="j">Electronic Notes in Theoretical Computer Science</title>
        <imprint>
          <biblScope type="volume">335</biblScope>
          <dateStruct>
            <month>April</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">91-112</biblScope>
          <ref xlink:href="https://hal.archives-ouvertes.fr/hal-01976385" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>archives-ouvertes.<allowbreak/>fr/<allowbreak/>hal-01976385</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid4" type="article" rend="year" n="cite:thomas:hal-01976406">
      <identifiant type="doi" value="10.1038/s41467-018-06912-9"/>
      <identifiant type="hal" value="hal-01976406"/>
      <analytic>
        <title level="a">Sources, propagation and consequences of stochasticity in cellular growth</title>
        <author>
          <persName>
            <foreName>Philipp</foreName>
            <surname>Thomas</surname>
            <initial>P.</initial>
          </persName>
          <persName>
            <foreName>Guillaume</foreName>
            <surname>Terradot</surname>
            <initial>G.</initial>
          </persName>
          <persName key="antique-2018-idp123424">
            <foreName>Vincent</foreName>
            <surname>Danos</surname>
            <initial>V.</initial>
          </persName>
          <persName>
            <foreName>Andrea Y</foreName>
            <surname>Weiße</surname>
            <initial>A. Y.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid02089">
        <idno type="issn">2041-1723</idno>
        <title level="j">Nature Communications</title>
        <imprint>
          <biblScope type="volume">9</biblScope>
          <biblScope type="number">1</biblScope>
          <dateStruct>
            <month>December</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.archives-ouvertes.fr/hal-01976406" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>archives-ouvertes.<allowbreak/>fr/<allowbreak/>hal-01976406</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid19" type="article" rend="year" n="cite:waites:hal-01976389">
      <identifiant type="doi" value="10.1109/access.2018.2853624"/>
      <identifiant type="hal" value="hal-01976389"/>
      <analytic>
        <title level="a">An Information-Theoretic Measure for Patterning in Epithelial Tissues</title>
        <author>
          <persName>
            <foreName>William</foreName>
            <surname>Waites</surname>
            <initial>W.</initial>
          </persName>
          <persName>
            <foreName>Matteo</foreName>
            <surname>Cavaliere</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>Elise</foreName>
            <surname>Cachat</surname>
            <initial>E.</initial>
          </persName>
          <persName key="antique-2018-idp123424">
            <foreName>Vincent</foreName>
            <surname>Danos</surname>
            <initial>V.</initial>
          </persName>
          <persName>
            <foreName>Jamie A</foreName>
            <surname>Davies</surname>
            <initial>J. A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid02813">
        <idno type="issn">2169-3536</idno>
        <title level="j">IEEE Access</title>
        <imprint>
          <biblScope type="volume">6</biblScope>
          <dateStruct>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">40302-40312</biblScope>
          <ref xlink:href="https://hal.archives-ouvertes.fr/hal-01976389" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>archives-ouvertes.<allowbreak/>fr/<allowbreak/>hal-01976389</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid18" type="article" rend="year" n="cite:waites:hal-01985802">
      <identifiant type="hal" value="hal-01985802"/>
      <analytic>
        <title level="a">A Genetic Circuit Compiler: Generating Combinatorial Genetic Circuits with Web Semantics and Inference</title>
        <author>
          <persName>
            <foreName>William</foreName>
            <surname>Waites</surname>
            <initial>W.</initial>
          </persName>
          <persName>
            <foreName>Göksel</foreName>
            <surname>Mısırlı</surname>
            <initial>G.</initial>
          </persName>
          <persName>
            <foreName>Matteo</foreName>
            <surname>Cavaliere</surname>
            <initial>M.</initial>
          </persName>
          <persName key="antique-2018-idp123424">
            <foreName>Vincent</foreName>
            <surname>Danos</surname>
            <initial>V.</initial>
          </persName>
          <persName>
            <foreName>Anil</foreName>
            <surname>Wipat</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-editorial-board="yes" x-international-audience="yes" id="rid02756">
        <idno type="issn">2161-5063</idno>
        <title level="j">ACS Synthetic Biology</title>
        <imprint>
          <biblScope type="volume">7</biblScope>
          <biblScope type="number">12</biblScope>
          <dateStruct>
            <month>November</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">2812-2823</biblScope>
          <ref xlink:href="https://hal.archives-ouvertes.fr/hal-01985802" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>archives-ouvertes.<allowbreak/>fr/<allowbreak/>hal-01985802</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid17" type="inproceedings" rend="year" n="cite:beica:hal-01962674">
      <identifiant type="hal" value="hal-01962674"/>
      <analytic>
        <title level="a">Tropical Abstraction of Biochemical Reaction Networks with Guarantees</title>
        <author>
          <persName key="antique-2018-idp131200">
            <foreName>Andreea</foreName>
            <surname>Beica</surname>
            <initial>A.</initial>
          </persName>
          <persName key="antique-2018-idp128736">
            <foreName>Jérôme</foreName>
            <surname>Feret</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Tatjana</foreName>
            <surname>Petrov</surname>
            <initial>T.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">SASB'18 - Static Analysis in Systems Biology, affiliated with Static Analysis Symposium</title>
        <loc>Freiburg, Germany</loc>
        <imprint>
          <dateStruct>
            <month>August</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01962674" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01962674</ref>
        </imprint>
        <meeting id="cid623740">
          <title>International Workshop on Static Analysis and Systems Biology</title>
          <num>2018</num>
          <abbr type="sigle">SASB</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid15" type="inproceedings" rend="year" n="cite:boutillier:hal-01888951">
      <identifiant type="doi" value="10.1007/978-3-319-99429-1_17"/>
      <identifiant type="hal" value="hal-01888951"/>
      <analytic>
        <title level="a">KaSa: A Static Analyzer for Kappa</title>
        <author>
          <persName key="antique-2018-idp165856">
            <foreName>Pierre</foreName>
            <surname>Boutillier</surname>
            <initial>P.</initial>
          </persName>
          <persName key="antique-2018-idp146000">
            <foreName>Ferdinanda</foreName>
            <surname>Camporesi</surname>
            <initial>F.</initial>
          </persName>
          <persName>
            <foreName>Jean</foreName>
            <surname>Coquet</surname>
            <initial>J.</initial>
          </persName>
          <persName key="antique-2018-idp128736">
            <foreName>Jérôme</foreName>
            <surname>Feret</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Kim Quyên</foreName>
            <surname>Lý</surname>
            <initial>K. Q.</initial>
          </persName>
          <persName key="dyliss-2018-idp188176">
            <foreName>Nathalie</foreName>
            <surname>Théret</surname>
            <initial>N.</initial>
          </persName>
          <persName key="dyliss-2018-idp177856">
            <foreName>Pierre</foreName>
            <surname>Vignet</surname>
            <initial>P.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <editor role="editor">
          <persName>
            <foreName>Milan</foreName>
            <surname>Češka</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>David</foreName>
            <surname>Šafránek</surname>
            <initial>D.</initial>
          </persName>
        </editor>
        <title level="m">CMSB 2018 - 16th International Conference on Computational Methods in Systems Biology</title>
        <loc>Brno, Czech Republic</loc>
        <title level="s">LNCS</title>
        <imprint>
          <biblScope type="volume">11095</biblScope>
          <publisher>
            <orgName>Springer Verlag</orgName>
          </publisher>
          <dateStruct>
            <month>September</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">285-291</biblScope>
          <ref xlink:href="https://hal-univ-rennes1.archives-ouvertes.fr/hal-01888951" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal-univ-rennes1.<allowbreak/>archives-ouvertes.<allowbreak/>fr/<allowbreak/>hal-01888951</ref>
        </imprint>
        <meeting id="cid115706">
          <title>International Conference on Computational Methods in Systems Biology</title>
          <num>16</num>
          <abbr type="sigle">CMSB</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid14" type="inproceedings" rend="year" n="cite:boutillier:hal-01967632">
      <identifiant type="hal" value="hal-01967632"/>
      <analytic>
        <title level="a">Proving the absence of unbounded polymers in rule-based models</title>
        <author>
          <persName key="antique-2018-idp165856">
            <foreName>Pierre</foreName>
            <surname>Boutillier</surname>
            <initial>P.</initial>
          </persName>
          <persName key="antique-2018-idp128736">
            <foreName>Jérôme</foreName>
            <surname>Feret</surname>
            <initial>J.</initial>
          </persName>
          <persName key="antique-2018-idp153408">
            <foreName>Aurélie</foreName>
            <surname>Faure de Pebeyre</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">Static Analysis and Systems Biology 2018</title>
        <loc>Freiburg im Breisgau, Germany</loc>
        <imprint>
          <dateStruct>
            <month>August</month>
            <year>2018</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01967632" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01967632</ref>
        </imprint>
        <meeting id="cid623740">
          <title>International Workshop on Static Analysis and Systems Biology</title>
          <num>2018</num>
          <abbr type="sigle">SASB</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid21" type="inproceedings" rend="year" n="cite:suzanne:hal-01953358">
      <identifiant type="doi" value="10.1007/978-3-030-02768-1_6"/>
      <identifiant type="hal" value="hal-01953358"/>
      <analytic>
        <title level="a">Relational Thread-Modular Abstract Interpretation Under Relaxed Memory Models</title>
        <author>
          <persName key="antique-2018-idp143520">
            <foreName>Thibault</foreName>
            <surname>Suzanne</surname>
            <initial>T.</initial>
          </persName>
          <persName>
            <foreName>Antoine</foreName>
            <surname>Miné</surname>
            <initial>A.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-scientific-popularization="no" x-international-audience="yes" x-proceedings="yes" x-invited-conference="no" x-editorial-board="yes">
        <title level="m">APLAS 2018 - 16th Asian Symposium on Programming Languages and Systems</title>
        <loc>Wellington, New Zealand</loc>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">11275</biblScope>
          <dateStruct>
            <month>December</month>
            <year>2018</year>
          </dateStruct>
          <biblScope type="pages">109-128</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01953358" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01953358</ref>
        </imprint>
        <meeting id="cid36280">
          <title>Asian Symposium on Programming Languages and Systems</title>
          <num>16</num>
          <abbr type="sigle">APLAS</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid20" type="unpublished" rend="year" n="cite:damian:hal-01991415">
      <identifiant type="hal" value="hal-01991415"/>
      <monogr>
        <title level="m">Communication-closed asynchronous protocols</title>
        <author>
          <persName key="antique-2018-idp150928">
            <foreName>Andrei</foreName>
            <surname>Damian</surname>
            <initial>A.</initial>
          </persName>
          <persName key="antique-2018-idp126272">
            <foreName>Cezara</foreName>
            <surname>Dragoi</surname>
            <initial>C.</initial>
          </persName>
          <persName>
            <foreName>Alexandru</foreName>
            <surname>Militaru</surname>
            <initial>A.</initial>
          </persName>
          <persName>
            <foreName>Josef</foreName>
            <surname>Widder</surname>
            <initial>J.</initial>
          </persName>
        </author>
        <imprint>
          <dateStruct>
            <month>January</month>
            <year>2019</year>
          </dateStruct>
          <ref xlink:href="https://hal.inria.fr/hal-01991415" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01991415</ref>
        </imprint>
      </monogr>
      <note type="bnote">working paper or preprint</note>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid5" type="incollection" rend="foot" n="footcite:beica:hal-01974696">
      <identifiant type="hal" value="hal-01974696"/>
      <analytic>
        <title level="a">Synchronous Balanced Analysis</title>
        <author>
          <persName key="antique-2018-idp131200">
            <foreName>Andreea</foreName>
            <surname>Beica</surname>
            <initial>A.</initial>
          </persName>
          <persName key="antique-2018-idp123424">
            <foreName>Vincent</foreName>
            <surname>Danos</surname>
            <initial>V.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">Proceedings of the International Workshop on Hybrid Systems Biology</title>
        <imprint>
          <publisher>
            <orgName>Springer-Verlag, Berlin, Germany</orgName>
          </publisher>
          <dateStruct>
            <month>September</month>
            <year>2016</year>
          </dateStruct>
          <biblScope type="pages">85-94</biblScope>
          <ref xlink:href="https://hal.archives-ouvertes.fr/hal-01974696" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>archives-ouvertes.<allowbreak/>fr/<allowbreak/>hal-01974696</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid1" type="article" rend="foot" n="footcite:c:97:hierarchy">
      <identifiant type="doi" value="10.1016/S1571-0661(05)80168-9"/>
      <analytic>
        <title level="a">Constructive design of a hierarchy of semantics of a transition system by abstract interpretation</title>
        <author>
          <persName>
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Electr. Notes Theor. Comput. Sci.</title>
        <imprint>
          <biblScope type="volume">6</biblScope>
          <dateStruct>
            <year>1997</year>
          </dateStruct>
          <biblScope type="pages">77–102</biblScope>
          <ref xlink:href="http://dx.doi.org/10.1016/S1571-0661(05)80168-9" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>dx.<allowbreak/>doi.<allowbreak/>org/<allowbreak/>10.<allowbreak/>1016/<allowbreak/>S1571-0661(05)80168-9</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid0" type="inproceedings" rend="foot" n="footcite:cc:popl:77">
      <analytic>
        <title level="a">Abstract interpretation: a unified lattice model for static analysis of programs by construction or approximation of fixpoints</title>
        <author>
          <persName>
            <foreName>Patrick</foreName>
            <surname>Cousot</surname>
            <initial>P.</initial>
          </persName>
          <persName>
            <foreName>Radhia</foreName>
            <surname>Cousot</surname>
            <initial>R.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">Conference Record of the Fourth Annual ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages</title>
        <imprint>
          <publisher>
            <orgName>ACM Press, New York, United States</orgName>
          </publisher>
          <dateStruct>
            <year>1977</year>
          </dateStruct>
          <biblScope type="pages">238–252</biblScope>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid11" type="inproceedings" rend="foot" n="footcite:ko:hal-01648680">
      <identifiant type="doi" value="10.1007/978-3-319-71237-6_8"/>
      <identifiant type="hal" value="hal-01648680"/>
      <analytic>
        <title level="a">Weakly Sensitive Analysis for Unbounded Iteration over JavaScript Objects</title>
        <author>
          <persName key="indes-2018-idp154304">
            <foreName>Yoonseok</foreName>
            <surname>Ko</surname>
            <initial>Y.</initial>
          </persName>
          <persName key="antique-2018-idp120512">
            <foreName>Xavier</foreName>
            <surname>Rival</surname>
            <initial>X.</initial>
          </persName>
          <persName>
            <foreName>Sukyoung</foreName>
            <surname>Ryu</surname>
            <initial>S.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">APLAS 2017 - 15th Asian Symposium on Programming Languages and Systems</title>
        <loc>Suzhou, China</loc>
        <title level="s">LNCS</title>
        <imprint>
          <biblScope type="volume">10695</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>November</month>
            <year>2017</year>
          </dateStruct>
          <biblScope type="pages">148-168</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01648680" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01648680</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid9" type="inproceedings" rend="foot" n="footcite:li:hal-01648679">
      <identifiant type="doi" value="10.1145/3009837.3009881"/>
      <identifiant type="hal" value="hal-01648679"/>
      <analytic>
        <title level="a">Semantic-Directed Clumping of Disjunctive Abstract States *</title>
        <author>
          <persName key="antique-2018-idp141072">
            <foreName>Huisong</foreName>
            <surname>Li</surname>
            <initial>H.</initial>
          </persName>
          <persName>
            <foreName>François</foreName>
            <surname>Bérenger</surname>
            <initial>F.</initial>
          </persName>
          <persName>
            <foreName>Bor-Yuh Evan</foreName>
            <surname>Chang</surname>
            <initial>B.-Y. E.</initial>
          </persName>
          <persName key="antique-2018-idp120512">
            <foreName>Xavier</foreName>
            <surname>Rival</surname>
            <initial>X.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">POPL 2017 - 44th ACM SIGPLAN Symposium on Principles of Programming Languages</title>
        <loc>Paris, France</loc>
        <imprint>
          <biblScope type="volume">52</biblScope>
          <biblScope type="number">1</biblScope>
          <publisher>
            <orgName>ACM</orgName>
          </publisher>
          <dateStruct>
            <month>January</month>
            <year>2017</year>
          </dateStruct>
          <biblScope type="pages">32-45</biblScope>
          <ref xlink:href="https://hal.inria.fr/hal-01648679" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-01648679</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="antique-2018-bid2" type="article" rend="foot" n="footcite:weie:hal-01976394">
      <identifiant type="doi" value="10.1073/pnas.1416533112"/>
      <identifiant type="hal" value="hal-01976394"/>
      <analytic>
        <title level="a">Mechanistic links between cellular trade-offs, gene expression, and growth</title>
        <author>
          <persName>
            <foreName>Andrea Y</foreName>
            <surname>Weiße</surname>
            <initial>A. Y.</initial>
          </persName>
          <persName>
            <foreName>Diego A.</foreName>
            <surname>Oyarzun</surname>
            <initial>D. A.</initial>
          </persName>
          <persName key="antique-2018-idp123424">
            <foreName>Vincent</foreName>
            <surname>Danos</surname>
            <initial>V.</initial>
          </persName>
          <persName>
            <foreName>Peter S</foreName>
            <surname>Swain</surname>
            <initial>P. S.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Proceedings of the National Academy of Sciences of the United States of America </title>
        <imprint>
          <biblScope type="volume">112</biblScope>
          <biblScope type="number">9</biblScope>
          <dateStruct>
            <month>March</month>
            <year>2015</year>
          </dateStruct>
          <biblScope type="pages">E1038-E1047</biblScope>
          <ref xlink:href="https://hal.archives-ouvertes.fr/hal-01976394" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>hal.<allowbreak/>archives-ouvertes.<allowbreak/>fr/<allowbreak/>hal-01976394</ref>
        </imprint>
      </monogr>
    </biblStruct>
  </biblio>
</raweb>
