
KeYmaera
or Source 
Overview
Flight control maneuvers are very important systems where correct functioning is crucial. At the same time, their dynamics is so complicated that the analysis of collision avoidance protocols in air traffic management is pretty challenging. These protocols direct aircraft, which are flying close, to flight paths which respect the protected zones of the aircraft.
Flight Dynamics
The dynamics of aircraft depends on several parameters, including positions, linear velocities, angular velocities. It is described in terms of differential equations for flight and computer control algorithms.Classical Collision Avoidance Attempts
Several collision avoidance maneuvers have been proposed to resolve conflicting flight paths. The left figure illustrates the collision that happens in uncontrolled flight. The middle figure illustrates a classical roundabout collision avoidance resolution, which works successfully. The right figure illustrates an unsuccessful choice for classical fixed roundabout collision resolution attempts. It was found by our hybrid systems verification tool.Advanced and Flyable Collision Avoidance Maneuvers
Possible advanced aircraft maneuvers for collision avoidance include the tangential roundabout (left) and flyable roundabout maneuver (right).To prove correctness of those maneuvers, we have proved formulas in differential dynamic logic (dL). For example, the following dL expresses that two aircraft x and y always remain safely separated by the protected zone if they are safely separated initially and follow the tangential roundabout collision avoidance maneuver trm:
Distributed Aircraft Controllers
We have considered a class of distributed collision avoidance controllers designed to work even in environments with arbitrarily many aircraft or UAVs [9]. We have proved that the controllers never allow the aircraft to get too close to one another, even when new planes approach an inprogress avoidance maneuver that the new plane may not be aware of. Because these safety guarantees always hold, the aircraft are protected against unexpected emergent behavior which simulation and testing may miss. This is an important step in formally verified, flyable, and distributed air traffic control.Airborne Collision Avoidance System ACAS X
The nextgeneration Airborne Collision Avoidance System (ACAS X) is intended to be installed on all large aircraft to give advice to pilots and prevent midair collisions with other aircraft. It is currently being developed by the Federal Aviation Administration (FAA). In this paper [10] we determine the geometric configurations under which the advice given by ACAS X is safe under a precise set of assumptions and formally verify these configurations using hybrid systems theorem proving techniques. We conduct an initial examination of the current version of the real ACAS X system and discuss some cases where our safety theorem conflicts with the actual advisory given by that version, demonstrating how formal, hybrid approaches are helping ensure the safety of ACAS X. Our approach is general and could also be used to identify unsafe advice issued by other collision avoidance systems or confirm their safety. An overview and a thorough investigation of the ACAS X decision table subsequently appeared in an invited paper [11]. More details and additional results on the verification of maneuvers that are safeable, so not necessarily safe right now but can still be made safe by a subsequent advisory, can be found in an extended journal version for STTT [12].
Airborne Collision Avoidance Games in ACAS X
The design of aircraft collision avoidance algorithms is a subtle but important challenge that merits the need for provable safety guarantees. Obtaining such guarantees is nontrivial given the unpredictability of the interplay of the intruder aircraft decisions, the ownship pilot reactions, and the subtlety of the continuous motion dynamics of aircraft. Existing collision avoidance systems, such as TCAS and the NextGeneration Airborne Collision Avoidance System ACAS X, have been analyzed assuming severe restrictions on the intruder's flight maneuvers, limiting their safety guarantees in realworld scenarios where the intruder may change its course.
This work takes a conceptually significant and practically relevant departure from existing ACAS X models by generalizing them to hybrid games with firstclass representations of the ownship and intruder decisions coming from two independent players, enabling significantly advanced predictive power. By proving the existence of winning strategies for the resulting Adversarial ACAS X in differential game logic, collisionfreedom is established for the rich encounters of ownship and intruder aircraft with independent decisions along differential equations for flight paths with evolving vertical/horizontal velocities. We present three classes of models of increasing complexity: singleadvisory infinitetime models, bounded time models, and infinite time, multiadvisory models. Within each class of models, we identify symbolic conditions and prove that there then always is a possible ownship maneuver that will prevent a collision between the two aircraft.
More details can be found in ACM TECS [13].Roundabouts
Aircraft collision avoidance maneuvers are important and complex applications. Curved flight exhibits nontrivial continuous behavior. In combination with the control choices during air traffic maneuvers, this yields hybrid systems with challenging interactions of discrete and continuous dynamics. As a case study illustrating the use of a new proof assistant for a logic for nonlinear hybrid systems, we analyze collision freedom of roundabout maneuvers in air traffic control, where appropriate curved flight, good timing, and compatible maneuvering are crucial for guaranteeing safe spatial separation of aircraft throughout their flight. We show that formal verification of hybrid systems can scale to curved flight maneuvers required in aircraft control applications. We introduce a fully flyable variant of the roundabout collision avoidance maneuver and verify safety properties by compositional verification.
Keywords: formal verification of hybrid systems, deduction, air traffic control, logic for hybrid systems
Selected Publications
Also see publications on verification of aerospace systems.

Rachel Cleveland, Stefan Mitsch and André Platzer.
Formally verified nextgeneration airborne collision avoidance games in ACAS X.
ACM Trans. Embed. Comput. Syst. 22(1), pp. 10:110:30, 2023. © The authors
[bib  ✂  pdf  doi  mypdf  kyx  arXiv  abstract]

JeanBaptiste Jeannin, Khalil Ghorbal, Yanni Kouskoulas, Aurora Schmidt, Ryan Gardner, Stefan Mitsch, and André Platzer.
A formally verified hybrid system for safe advisories in the nextgeneration airborne collision avoidance system.
STTT 19(6), pp. 717741, 2017.
Special issue for selected papers from TACAS'15. © Springer
[bib  ✂  pdf  doi  kyx  study  TACAS'15  abstract]

JeanBaptiste Jeannin, Khalil Ghorbal, Yanni Kouskoulas, Ryan Gardner, Aurora Schmidt, Erik Zawadzki, and André Platzer.
Formal verification of ACAS X, an industrial airborne collision avoidance system.
In Alain Girault and Nan Guan, editors, International Conference on Embedded Software, EMSOFT'15, Amsterdam, The Netherlands, Proceedings, pp. 127136. IEEE Press, 2015. © IEEE
[bib  ✂  pdf  doi  abstract]

JeanBaptiste Jeannin, Khalil Ghorbal, Yanni Kouskoulas, Ryan Gardner, Aurora Schmidt, Erik Zawadzki, and André Platzer.
A formally verified hybrid system for the nextgeneration airborne collision avoidance system.
In Christel Baier and Cesare Tinelli, editors, Tools and Algorithms for the Construction and Analysis of Systems  21st International Conference, TACAS 2015, London, UK, April 1118, 2015, Proceedings, volume 9035 of LNCS, pp. 2136. Springer, 2015. © Springer
[bib  ✂  pdf  doi  study  TR  STTT'17  abstract]

Sarah M. Loos, David W. Renshaw and André Platzer.
Formal verification of distributed aircraft controllers.
In Calin Belta and Franjo Ivancic, editors, Hybrid Systems: Computation and Control (part of CPS Week 2013), HSCC'13, Philadelphia, PA, USA, April 813, 2013, pp. 125130. ACM, 2013. © ACM
[bib  ✂  pdf  doi  slides  poster  study  TR  abstract]

André Platzer.
Quantified differential invariants.
In Emilio Frazzoli and Radu Grosu, editors, Proceedings of the 14th ACM International Conference on Hybrid Systems: Computation and Control, HSCC 2011, Chicago, USA, April 1214, pp. 6372. ACM, 2011. © ACM
[bib  ✂  pdf  doi  slides  abstract]

André Platzer.
Quantified differential dynamic logic for distributed hybrid systems.
In Anuj Dawar and Helmut Veith, editors, Computer Science Logic, 19th EACSL Annual Conference, CSL 2010, Brno, Czech Republic, August 2327, 2010. Proceedings, volume 6247 of LNCS, pp. 469483. Springer, 2010. © Springer
[bib  ✂  pdf  doi  slides  TR  LMCS'12  abstract]

André Platzer and Edmund M. Clarke.
Formal verification of curved flight collision avoidance maneuvers: A case study.
In Ana Cavalcanti and Dennis Dams, editors, 16th International Symposium on Formal Methods, FM, Eindhoven, Netherlands, Proceedings, volume 5850 of LNCS, pp. 547562. Springer, 2009. © Springer
FM Best Paper Award.
[bib  ✂  pdf  doi  slides  study  TR  abstract]

André Platzer.
Logical Analysis of Hybrid Systems:
Proving Theorems for Complex Dynamics.
Springer, Heidelberg, 2010. 426 pages. ISBN 9783642145087.
[bib  ✂  doi  book  web  errata  abstract]

André Platzer and Edmund M. Clarke.
Formal Verification of Curved Flight Collision Avoidance Maneuvers: A Case Study.
School of Computer Science, Carnegie Mellon University, CMUCS09147, 2009.
[bib  ✂  pdf  FM'09]

André Platzer.
Differential Dynamic Logics:
Automated Theorem Proving for Hybrid Systems.
PhD Thesis, Department of Computing Science, University of Oldenburg, 2008.
ACM Doctoral Dissertation Honorable Mention Award in 2009.
Extended version appeared as book Logical Analysis of Hybrid Systems: Proving Theorems for Complex Dynamics, Springer, 2010.
[bib  ✂  pdf  eprint  slides  book  ebook  abstract]

André Platzer.
Differentialalgebraic dynamic logic for differentialalgebraic programs.
Journal of Logic and Computation 20(1), pp. 309352, 2010.
Special issue for selected papers from TABLEAUX'07. © The author
[bib  ✂  pdf  doi  eprint  study  errata  TABLEAUX'07  abstract]

André Platzer and Edmund M. Clarke.
The image computation problem in hybrid systems model checking.
In Alberto Bemporad, Antonio Bicchi and Giorgio Buttazzo, editors, Hybrid Systems: Computation and Control, 10th International Conference, HSCC 2007, Pisa, Italy, Proceedings, volume 4416 of LNCS, pp. 473486. Springer, 2007, © Springer
[bib  ✂  pdf  doi  slides  tool  abstract]