Controller model recovery

Recover controller models
from compiled FMUs.

CONSTRUCT decompiles controller binaries, maps operations to control semantics, generates Modelica, and compares output traces.

construct / recover

$ construct recover anti_windup_pid.fmu

→ locating controller step routine

→ extracting typed control sketch

→ searching 10,080 candidate mappings

✓ exact mapping found generation 4

evaluations
1,233
mean squared error
5.79e−32
elapsed
0.088 s
output
AntiWindupPID.mo
11controller families
11/11exact mappings
< 0.09smaximum search time
10,080largest search space

Pipeline

Pipeline stages

The pipeline retains intermediate artifacts for inspection.

  1. 01

    FMU

    Compiled controller binary and model description.

  2. 02

    Ghidra

    Headless decompilation extracts operations and data flow.

  3. 03

    Control sketch

    A typed intermediate representation records controller structure.

  4. 04

    GA mapping

    Candidate semantics are searched against observed traces.

  5. 05

    Modelica

    The selected mapping is emitted as Modelica and compared with source traces.

Benchmark suite

Results across 11 controller families

Cases range from stateless gain blocks to controllers with scheduling, saturation, and anti-windup behavior.

Search space

Candidate mappings by controller

log scale

Suite result

11/ 11

11 exact mappings

All generated models matched source outputs within floating-point precision.

Worst MSE2.60e−31

All benchmark runs

Recovery results

Controller Class Search space Generation Evaluations MSE Result

Examples

Controller cases

The cases are grouped by control structure and increase in complexity.

Outputs

Generated artifacts

Running the suite writes decompiled operations, control sketches, search reports, Modelica models, and trace comparisons to the artifacts directory.

uv run construct-demo run-all

artifacts/

├── decompiled/

├── sketches/

├── models/

├── traces/

├── benchmark.json

└── report.html

Source code

Run the benchmark locally

The repository includes the controller examples, pipeline, tests, and benchmark command.

View repository ↗