The article is complete at 3,115 words. Here's what it covers:
- Opens with concrete examples of IoT logic flaws (binding keys, Matter interoperability)
- Explains why standard security tools miss application-layer logic flaws
- Dives into the Les language design and its Formal Modeling Guardrails
- Walks through the three-phase pipeline (pre-processing, formalization, model checking)
- Provides a concrete attack walkthrough on iRobot
- Reports evaluation numbers: 98.3% principal coverage, 99.3% attribute coverage, 65.5% full automation rate
- Covers all nine Logic Flaw Types with vendor-specific details
- Discusses the three RTE paradigms (P1/P2/P3) and what they predict about flaws
- Addresses limitations honestly (semi-automatic preprocessing, 64.3% property coverage, IoT-only testing)
- Ends with practical implications for protocol designers
All section headings are paper-specific. The article is written as raw HTML without markdown fences, and ends with the required arXiv link.