Preliminary Program
Day 1 (Nov, 24 - Tuesday) :: Industry Day
| Time | Auditorium | Room A | Room B |
| 08:00 - 08:30 | Registration | ||
| 08:30 - 10:30 | Embedded Systems School | ||
| 10:30 - 11:00 | Coffee-Break | ||
| 11:00 -12:10 | Industry Keynote - Ricardo Moraes - "Rethinking Aircraft Systems Engineering in the Era of Cyber Threats” | ||
| 12:10 - 13:30 | Break / Lunch | ||
| 13:30 - 15:30 | Technical Session I | Technical Session II | |
| 15:30 - 16:00 | Coffee-Break | ||
| 16:00 - 17:00 | Keynote - Antonio Augusto Fröhlich - Safety in Physical AI: an Operating Systems Perspective" | ||
| 17:00 - 18:00 | Industry Panel | ||
| 18:30 - 19:10 | Opening Ceremony | ||
| 19:30 | Industry Day Reception — Sponsored by IES | ||
Day 2 (Nov, 25 - Wednesday) :: IES Special Session
| Time | Auditorium | Room A | Room B |
| 08:00 - 08:30 | Registration | ||
| 08:30 - 10:30 | Embedded Systems School | Technical Session III | |
| 10:30 - 11:00 | Coffee-Break | ||
| 11:00 -12:10 | Keynote - Marcus VÖLP - "How to construct dependable operating systems and the hardware it should run on | ||
| 12:10 - 13:30 | Break / Lunch | ||
| 13:30 - 15:30 | Technical Session IV | ESC (Presentation) | IES Special Session |
| 15:30 - 16:00 | Coffee-Break | ||
| 16:00 - 17:00 | Keynote - Raimundo Macêdo - "When Are Failures Observable? System Models, Fault Models, and the Limits of Dependable Distributed Computing" | ||
| 17:00 - 18:40 | Technical Session V | ESC (Presentation) | IES Special Session |
| 18:30 - 20:00 | TPC Meeting + AGO | ||
Day 3 (Nov, 26 - Thursday) :: Satellite Events
| Time | Auditorium | Room A | Room B | Patio |
| 08:00 - 08:30 | Registration | |||
| 08:30 - 10:30 | * Extra Activity (not confirmed) | Technical Session VI | ||
| 10:30 - 11:00 | Coffee-Break | |||
| 11:00 -12:10 | Keynote - Richard West - "DriveOS: A Single ECU Software-Defined Vehicle Management System" | |||
| 12:10 - 13:30 | Break / Lunch | |||
| 13:30 - 15:30 | Technical Session VII | Technical Session VIII | SCoRe Workshop | ESC Demos |
| 15:30 - 16:00 | Coffee-Break | |||
| 16:00 - 17:00 | Keynote - Long Wang - "From Fault Injection to Directed Fuzzing: Making Dependability and Security Testing More Intelligent" | |||
| 17:00 - 18:40 | Technical Session IX | Technical Session X | SCoRe Workshop | ESC Demos |
| 19:30 | Conference Dinner | |||
Day 4 (Nov, 27 - Friday) :: Technical Sessions
| Time | Auditorium | Room A |
| 08:30 - 10:30 | Technical Session XI | Technical Session XII |
| 10:30 - 11:00 | Coffee-Break | |
| 11:00 -12:00 | Technical Session XIII | Technical Session XIV |
| 12:00 - 13:00 | Break / Lunch | |
| 13:10 - 15:30 | Technical Session XV | Technical Session XVI |
| 15:40 - 16:40 | Awards Ceremony & Closing Session |
Session Details:
Keynote Speech:
- Keynote: Ricardo Moraes (EMBRAER) - Rethinking Aircraft Systems Engineering in the Era of Cyber Threats
- Date: Nov, 24.
- Time: 11h -12h
- Bio: Ricardo Moraes dos Santos is an Engineering Supervisor at Embraer with over 15 years of experience in the aerospace industry. He leads Systems Engineering and Product Cybersecurity, with a strong focus on system architecture, Model-Based Systems Engineering (MBSE), and aircraft certification. He has extensive experience in multidisciplinary integration of complex systems and in supporting certification processes with regulatory authorities such as EASA, FAA, and ANAC. He is responsible for driving digital transformation initiatives (MBSE), advancing engineering processes, and strengthening technical governance. A published author (CRC Press) and former INCOSE Brazil President, he combines strong technical leadership with strategic vision and active engagement in the global Systems Engineering community.
- Keynote: Antonio Augusto Fröhlich (Federal University of Santa Catarina) - Safety in Physical AI: an Operating Systems Perspective
- Date: Nov, 24.
- Time: 16h - 17h
- Abstract: Artificial Intelligence is rapidly moving out of datacenters and into the physical world. We will soon be living among highly autonomous machines, including humanoid robots, autonomous vehicles, and military systems that, until recently, belonged to science fiction and to our nightmares. As this transition unfolds, safety moves from being a desirable property of individual systems to becoming a fundamental condition for our coexistence of increasingly autonomous machines. Nevertheless, the operating systems that are supporting this revolution have changed surprisingly little beyond the classic task-centric, real-time, network-capable, and cryptographically-enriched services envisioned more than 40 years ago. They provide mechanisms for executing and isolating software, managing resources, and meeting timing constraints, but offer much less support for continuously enforcing the physical safety constraints governing autonomous behavior. This talk explores this challenge from the perspective of SmartData, a concept developed at LISHA/UFSC over the past decade to address some of the fundamental limitations of making Sense–Compute–Communicate–Actuate loops more AI-ready while keeping their safety continuously observable and enforceable. The approach builds safety models around the same physical laws that govern the behavior of the systems, bringing those models into the computing infrastructure rather than leaving safety entirely to application-level logic. Autonomous vehicles being developed at UFSC provide a concrete case background for discussing this perspective and its implications for the operating systems of Physical AI.
- Bio: Antônio Augusto Fröhlich is a full professor at the Federal University of Santa Catarina (UFSC), where he leads the Software and Hardware Integration Laboratory (LISHA) since 2001. He holds a PhD in Computer Engineering from the Technical University of Berlin (2001) and was a visiting researcher at the University of Paderborn (2007), at the University of California, Irvine (2016) and at the University of Luxembourg (2017). He has coordinated several RD&I projects in secure, connected and intelligent cyber-physical systems. Significant contributions from these projects have been incorporated into products developed by partner industries in the sectors of energy, industry automation and mobility.
- Keynote: Marcus VÖLP (Universitè du Luxembourg) - How to construct dependable operating systems and the hardware it should run on
- Date: Nov, 25.
- Time: 11h - 12h
- Abstract: Operating systems today are the backbone for tapping into the computational power of underlying hardware, multiplexing resources and specifically accelerator accesses, connecting to other nodes or network-attached storage, and controlling the physical assets a system is entrusted with. Yet an operating system after all is a software component and can fail in the same way applications do, albeit possibly with system-wide consequences. In this keynote, I would like to share with you some of my thoughts and introduce you to some of the works that my team has “already done” to answer the question posed in the title. However, at the same time, I would like to invite you to a heated discussion and joint system design session answering questions like, “What can we learn from large scale systems for the small?"; "How can we secure timely responses in the presence of attacky?”; “How can we ensure the most fundamental layers survive?” and “How can we provide the illusion of a simple, fault-free system to programmers, even if reality diverges?” Join me in this keynote / interactive discussion on how to construct dependable operating systems and the hardware they run on.
- Bio: Prof. Dr.-Ing. Marcus Völp is full professor and head of the CritiX lab at the Interdisciplinary Centre for Security, Reliability and Trust (SnT) at the University of Luxembourg. He received his PhD in computer science in 2011 from Technische Universität Dresden. His research interests include methods, tools, and system architectures for constructing resilient cyber-physical and embedded systems that are capable of simultaneously guaranteeing a wide range of system properties, including soft and hard real-time guarantees, security guarantees and information flow properties, dependability and, of course, fault and intrusion tolerance and cyber resilience. Application domains of interest include Industry 4.0, cloud, edge, autonomous vehicles, spacecraft and systems software and hardware components such as microkernels and hardware transactional memory.
- Keynote: Raimundo Macêdo (Federal University of Bahia) - When Are Failures Observable? System Models, Fault Models, and the Limits of Dependable Distributed Computing
- Date: Nov, 25.
- Time: 16h - 17h
- Abstract: Distributed systems do not observe failures directly; they observe events—or the absence of expected events. Whether such observations indicate a crash, a timing violation, Byzantine behavior, or merely slow execution depends fundamentally on the underlying system model. In this sense, observability precedes detectability: observability concerns whether faulty behavior is distinguishable from admissible behavior under a given model, whereas detectability concerns whether an algorithm can exploit that distinction. This keynote explores the interplay between system and fault models, from classical synchrony and asynchrony to partial synchrony and alternative models of progress. We examine how assumptions about timing, communication, process behavior, redundancy, and application semantics determine which failures are observable and detectable and, ultimately, which distributed problems can be solved. When perfect detection is impossible, weaker guarantees and quantitative measures of detection quality become necessary. Theoretical guarantees, however, are meaningful in practice only when model assumptions adequately represent the execution environment. We therefore consider assumption coverage: the extent to which such assumptions can be justified by design, empirical observation, or runtime evidence. The talk concludes with the Eventual Relative-Speed (ERS) model, which takes a less conventional perspective on fail-silent behavior. Rather than inferring failure directly from elapsed physical time, ERS characterizes process activity through relative logical progress. After stabilization, correct processes remain within a bounded logical divergence; consequently, a process that persistently falls behind the evolving causal structure becomes distinguishable from correct processes. This enables adaptive failure detection based on logical divergence and illustrates the keynote’s central argument: observability, detectability, and computability are inseparable from the system model and the extent to which its assumptions hold in reality.
-
Bio: Dr. Raimundo is a Professor of Computer Science at the Federal University of Bahia (UFBA) in Brazil. He founded and is currently the head of the Distributed Systems Laboratory (LaSiD) at UFBA.
- Keynote: Richard West (Boston University) - DriveOS: A Single ECU Software-Defined Vehicle Management System
- Date: Nov, 26.
- Time: 11h - 12h
- Abstract: Advances in modern automotive systems have led to traditional electronic control units (ECUs) being replaced with software-defined
tasks. This has paved the way for functional consolidation, where chassis, body, powertrain, infotainment, and ADAS services are consolidated onto one or more zonal controllers. Taking this paradigm to the limit, it makes sense to consider whether a central compute platform is able to act as a single ECU for all vehicle functions, thereby reducing the costs and inflexibility of having dozens to hundreds of single fixed-function ECUs. This talk continues a series of presentations on DriveOS, a vehicle management system developed by Drako Tech, for use in electric vehicles. I will provide an update on the progress made with DriveOS, including an overview of past and future challenges, while identifying several key areas of research for future development of similar systems. - Bio: Rich West is a Professor in the Computer Science Department at Boston University, where he works with his research team on real-time and embedded operating systems. His work addresses issues concerning safety, security, predictability and resource management. He has an MS and PhD in Computer Science from the Georgia Institute of Technology, USA, and an MEng in Microelectronics and Software Engineering from the University of Newcastle-upon-Tyne, UK. He also works as the Chief Software Architect at Drako Tech, on the development of DriveOS for next generation vehicles. DriveOS consolidates vehicle functions on a centralized computing platform, by integrating real-time and safety critical services with non-critical software using a in-house partitioning hypervisor.
- Keynote: Long Wang (Tsinghua University) - From Fault Injection to Directed Fuzzing: Making Dependability and Security Testing More Intelligent
- Date: Nov, 26.
- Time: 16h - 17h
- Abstract: Modern computing systems have become increasingly complex, making failure diagnosis and vulnerability discovery difficult due to the enormous space of faults, execution paths, system states, and program inputs. A key question is therefore: how can we make testing more intelligent by guiding it toward the system behaviors that matter most? In this talk, Prof. Wang will present his research journey in dependability and security testing. He first explored targeted fault injection for distributed-system failure diagnosis, followed by techniques for capturing and analyzing service-request execution paths. More recently, he extended these ideas to path-based system analysis, where path tracing supports failure diagnosis and path-aware fault injection helps uncover cross-layer vulnerabilities. Prof. Wang will then discuss how the same principle applies to directed fuzzing. IDFuzz uses information learned from fuzzing executions to guide mutations toward target code, while TrigFuzz goes beyond code reachability by using large language models to identify vulnerability-triggering conditions and guide fuzzing toward inputs that satisfy them. These studies illustrate a common direction: making testing more effective by progressively incorporating richer knowledge of system structure, execution behavior, and program semantics.
- Bio: Dr. Long Wang is the head of the REliability And Security Of Networks and Systems (REASONS) lab at Tsinghua University. His research interests focus on resiliency, security and understanding of systems, services and networks, especially when they are complicated, intelligent, autonomous, dynamic and/or software-defined. The scopes include security and reliability of systems, cloud computing, distributed systems, and system monitoring, measurement, assessment and modeling, as well as big data analytics and machine learning.