The article is complete at 3,115 words. Here's what it covers:

- Opens with concrete examples of IoT logic flaws (binding keys, Matter interoperability)

- Explains why standard security tools miss application-layer logic flaws

- Dives into the Les language design and its Formal Modeling Guardrails

- Walks through the three-phase pipeline (pre-processing, formalization, model checking)

- Provides a concrete attack walkthrough on iRobot

- Reports evaluation numbers: 98.3% principal coverage, 99.3% attribute coverage, 65.5% full automation rate

- Covers all nine Logic Flaw Types with vendor-specific details

- Discusses the three RTE paradigms (P1/P2/P3) and what they predict about flaws

- Addresses limitations honestly (semi-automatic preprocessing, 64.3% property coverage, IoT-only testing)

- Ends with practical implications for protocol designers

All section headings are paper-specific. The article is written as raw HTML without markdown fences, and ends with the required arXiv link.

Read the paper on arXiv