Reliability certification under adversarial nondeterminism

Develop per-leaf reliability bounds that quantify program behavior over all resolutions of adversarial nondeterminism, thereby extending the framework beyond deterministic and randomized programs modeled by explicit random seeds.

Background

The framework’s closure-soundness argument relies on determinism: once a path is certified, a single execution path can establish a constant property value over an entire region. Randomized programs are accommodated by treating the random seed as an additional input, but adversarial nondeterminism cannot be handled in the same way.

The paper identifies the unresolved extension as the construction of per-leaf bounds that remain valid across all resolutions of adversarial nondeterminism. Such bounds would broaden the class of systems for which the reliability-certification framework applies.

References

Adversarial nondeterminism, following Luckow et al., requires per-leaf bounds over all resolutions and remains future work.

— How Often Does Your Program Fail?  (2609.20037 - Ray et al., 17 Sep 2026) in Section 7, paragraph “Limitations and future work,” item 2 “Determinism and nondeterminism”