Valentin Wüstholz

@vwuestholz.bsky.social

Principal Researcher and Co-founder at Diligence Security, previously at Consensys, ETH Zürich, UT Austin, Microsoft Research, and Google

PSA: With the hype around (agentic) formal verification, we should be much more explicit about what aspects of a system were "formally verified". Ask "what specs were verified?", "who reviewed them?", and "how was the verifier validated?" 🙏"formally verified" != "bug free"!

Vibe Verification (n.): Letting an AI agent produce programs, specs, and proofs with minimal human supervision; also the smug feeling when the agent successfully made a formal verification tool emit a green checkmark. Soon coming to nuclear power plants near you? 🙈

Some people are way too excited about AI agents doing formal verification! 😅 Why would agents go through the trouble of finding and proving meaningful specifications when they could just cheat by assuming false, exploiting a soundness bug, or proving a complex tautology?