Whenever invariants can be expressed as proofs rather than as tests that may or may not be exhaustive, the mathematical guarantees of model checkers will provide stronger assurances the code is correct.

Making Even Safe Rust a Little Safer: Model Checking Safe and Unsafe Code
Colin Breck


