Specula: Scaling formal specifications for autonomous model checking of system code | ArxivCSExplorer