VLDB 2026 Research / reviewers in the wild / expert
Radoslav Ivanov
dblp:144/4256
· DBLP profile ↗
13ranked-venue papers
8as first author
4since 2021 · last 2022
0000-0003-4987-4836ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 4 · 4 first-author · 2 since 2021Theory of computation · 3 · 3 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3Artificial intelligence and machine learning · 2 · 1 since 2021Software engineering, systems software and programming languages · 2 · 2 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | Risk verification of stochastic systems with neural network controllers
Matthew Cleaveland, Lars Lindemann, Radoslav Ivanov, George J. Pappas |
Artif. Intell. | 3 |
| 2021 | Verisig 2.0: Verification of Neural Network Controllers Using Taylor Model PreconditioningabstractAbstract This paper presents Verisig 2.0, a verification tool for closed-loop systems with neural network (NN) controllers. We focus on NNs with tanh/sigmoid activations and develop a Taylor-model-based reachability algorithm through Taylor model preconditioning and shrink wrapping. Furthermore, we provide a parallelized implementation that allows Verisig 2.0 to efficiently handle larger NNs than existing tools can. We provide an extensive evaluation over 10 benchmarks and compare Verisig 2.0 against three state-of-the-art verification tools. We show that Verisig 2.0 is both more accurate and faster, achieving speed-ups of up to 21x and 268x against different tools, respectively. Radoslav Ivanov, Taylor J. Carpenter, James Weimer, Rajeev Alur, George J. Pappas, Insup Lee 0001 |
CAV (1) | 1 |
| 2021 | Verifying the Safety of Autonomous Systems with Neural Network ControllersabstractThis article addresses the problem of verifying the safety of autonomous systems with neural network (NN) controllers. We focus on NNs with sigmoid/tanh activations and use the fact that the sigmoid/tanh is the solution to a quadratic differential equation. This allows us to convert the NN into an equivalent hybrid system and cast the problem as a hybrid system verification problem, which can be solved by existing tools. Furthermore, we improve the scalability of the proposed method by approximating the sigmoid with a Taylor series with worst-case error bounds. Finally, we provide an evaluation over four benchmarks, including comparisons with alternative approaches based on mixed integer linear programming as well as on star sets. Radoslav Ivanov, Taylor J. Carpenter, James Weimer, Rajeev Alur, George J. Pappas, Insup Lee 0001 |
ACM Trans. Embed. Comput. Syst. | 1 |
| 2021 | Compositional Learning and Verification of Neural Network ControllersabstractRecent advances in deep learning have enabled data-driven controller design for autonomous systems. However, verifying safety of such controllers, which are often hard-to-analyze neural networks, remains a challenge. Inspired by compositional strategies for program verification, we propose a framework for compositional learning and verification of neural network controllers. Our approach is to decompose the task (e.g., car navigation) into a sequence of subtasks (e.g., segments of the track), each corresponding to a different mode of the system (e.g., go straight or turn). Then, we learn a separate controller for each mode, and verify correctness by proving that (i) each controller is correct within its mode, and (ii) transitions between modes are correct. This compositional strategy not only improves scalability of both learning and verification, but also enables our approach to verify correctness for arbitrary compositions of the subtasks. To handle partial observability (e.g., LiDAR), we additionally learn and verify a mode predictor that predicts which controller to use. Finally, our framework also incorporates an algorithm that, given a set of controllers, automatically synthesizes the pre- and postconditions required by our verification procedure. We validate our approach in a case study on a simulation model of the F1/10 autonomous car, a system that poses challenges for existing verification tools due to both its reliance on LiDAR observations, as well as the need to prove safety for complex track geometries. We leverage our framework to learn and verify a controller that safely completes any track consisting of an arbitrary sequence of five kinds of track segments. Radoslav Ivanov, Kishor Jothimurugan, Steve Hsu, Shaan Vaidya, Rajeev Alur, Osbert Bastani |
ACM Trans. Embed. Comput. Syst. | 1 |
| 2020 | Case study: verifying the safety of an autonomous racing car with a neural network controllerabstractThis paper describes a verification case study on an autonomous racing car with a neural network (NN) controller. Although several verification approaches have been recently proposed, they have only been evaluated on low-dimensional systems or systems with constrained environments. To explore the limits of existing approaches, we present a challenging benchmark in which the NN takes raw LiDAR measurements as input and outputs steering for the car. We train a dozen NNs using reinforcement learning (RL) and show that the state of the art in verification can handle systems with around 40 LiDAR rays. Furthermore, we perform real experiments to investigate the benefits and limitations of verification with respect to the sim2real gap, i.e., the difference between a system's modeled and real performance. We identify cases, similar to the modeled environment, in which verification is strongly correlated with safe behavior. Finally, we illustrate LiDAR fault patterns that can be used to develop robust and safe RL algorithms. Radoslav Ivanov, Taylor J. Carpenter, James Weimer, Rajeev Alur, George J. Pappas, Insup Lee 0001 |
HSCC | 1 |
| 2019 | Verisig: verifying safety properties of hybrid systems with neural network controllersabstractThis paper presents Verisig, a hybrid system approach to verifying safety properties of closed-loop systems using neural networks as controllers. We focus on sigmoid-based networks and exploit the fact that the sigmoid is the solution to a quadratic differential equation, which allows us to transform the neural network into an equivalent hybrid system. By composing the network's hybrid system with the plant's, we transform the problem into a hybrid system verification problem which can be solved using state-of-the-art reachability tools. We show that reachability is decidable for networks with one hidden layer and decidable for general networks if Schanuel's conjecture is true. We evaluate the applicability and scalability of Verisig in two case studies, one from reinforcement learning and one in which the neural network is used to approximate a model predictive controller. Radoslav Ivanov, James Weimer, Rajeev Alur, George J. Pappas, Insup Lee 0001 |
HSCC | 1 |
| 2018 | OpenICE-lite: Towards a Connectivity Platform for the Internet of Medical ThingsabstractThe Internet of Medical Things (IoMT) is poised to revolutionize medicine. However, medical device communication, coordination, and interoperability present challenges for IoMT applications due to safety, security, and privacy concerns. These challenges can be addressed by developing an open platform for IoMT that can provide guarantees on safety, security and privacy. As a first step, we introduce OpenICE-lite, a middleware for medical device interoperability that also provides security guarantees and allows other IoMT applications to view/analyze the data in real time. We describe two applications that currently utilize OpenICE-lite, namely (i) a critical pulmonary shunt predictor for infants during surgery; (ii) a remote pulmonary monitoring systems (RePulmo). Implementations of both systems are utilized by the Children's Hospital of Philadelphia (CHOP) as quality improvements to patient care. Radoslav Ivanov, Hung Nguyen 0002, James Weimer, Oleg Sokolsky, Insup Lee 0001 |
ISORC | 1 |
| 2018 | Parameter-Invariant Monitor Design for Cyber-Physical SystemsabstractThe tight interaction between information technology and the physical world inherent in cyber-physical systems (CPS) can challenge traditional approaches for monitoring safety and security. Data collected for robust CPS monitoring is often sparse and may lack rich training data describing critical events/attacks. Moreover, CPS often operate in diverse environments that can have significant inter/intra-system variability. Furthermore, CPS monitors that are not robust to data sparsity and inter/intra-system variability may result in inconsistent performance and may not be trusted for monitoring safety and security. Towards overcoming these challenges, this paper presents recent work on the design of parameter-invariant (PAIN) monitors for CPS. PAIN monitors are designed such that unknown events and system variability minimally affect the monitor performance. This work describes how PAIN designs can achieve a constant false alarm rate (CFAR) in the presence of data sparsity and intra/inter system variance in real-world CPS. To demonstrate the design of PAIN monitors for safety monitoring in CPS with different types of dynamics, we consider systems with networked dynamics, linear-time invariant dynamics, and hybrid dynamics that are discussed through case studies for building actuator fault detection, meal detection in type I diabetes, and detecting hypoxia caused by pulmonary shunts in infants. In all applications, the PAIN monitor is shown to have (significantly) less variance in monitoring performance and (often) outperforms other competing approaches in the literature. Finally, an initial application of PAIN monitoring for CPS security is presented along with challenges and research directions for future security monitoring deployments. James Weimer, Radoslav Ivanov, Sanjian Chen, Alex Roederer, Oleg Sokolsky, Insup Lee 0001 |
Proc. IEEE | 2 |
| 2017 | Security of Cyber-Physical Systems in the Presence of Transient Sensor FaultsabstractThis article is concerned with the security of modern Cyber-Physical Systems in the presence of transient sensor faults. We consider a system with multiple sensors measuring the same physical variable, where each sensor provides an interval with all possible values of the true state. We note that some sensors might output faulty readings and others may be controlled by a malicious attacker. Differing from previous works, in this article, we aim to distinguish between faults and attacks and develop an attack detection algorithm for the latter only. To do this, we note that there are two kinds of faults—transient and permanent; the former are benign and short-lived, whereas the latter may have dangerous consequences on system performance. We argue that sensors have an underlying transient fault model that quantifies the amount of time in which transient faults can occur. In addition, we provide a framework for developing such a model if it is not provided by manufacturers. Attacks can manifest as either transient or permanent faults depending on the attacker’s goal. We provide different techniques for handling each kind. For the former, we analyze the worst-case performance of sensor fusion over time given each sensor’s transient fault model and develop a filtered fusion interval that is guaranteed to contain the true value and is bounded in size. To deal with attacks that do not comply with sensors’ transient fault models, we propose a sound attack detection algorithm based on pairwise inconsistencies between sensor measurements. Finally, we provide a real-data case study on an unmanned ground vehicle to evaluate the various aspects of this article. Junkil Park, Radoslav Ivanov, James Weimer, Miroslav Pajic, Sang Hyuk Son, Insup Lee 0001 |
ACM Trans. Cyber Phys. Syst. | 2 |
| 2016 | Toward a Hybrid Sensor Fusion Using Probabilistic and Abstract Sensor ModelsabstractSince Cyber Physical Systems (CPS) are widely used inmany safety-critical domains these days, critical properties such as robustness and resilience are required for such systems. To increase the robustness and the resilience of CPS, various sensor fusion techniques have been studied [1], [2],[3], [4]. These fusion techniques are based on certain sensor models, which broadly fall into two categories: probabilistic model and abstract model. The probabilistic sensor model [1] uses certain noise distributions on sensors (e.g., Gaussian), which is wellsuited for analyzing the systems' expected performance inthe average case. However, wrong assumptions on noise distributions may be in danger of being vulnerable to sensor attacks. On the other hand, the abstract sensor model [2] usesthe worst-case error bound of sensors. Thus, this model iswell suited for the systems' worst-case performance, whichis highly relevant to the case of sensor attacks [3].In this work, we study a hybrid sensor fusion that usesboth probabilistic and abstract sensor models to be able tobenefit from both. We demonstrate the validation of ourhybrid sensor fusion technique using an unmanned groundvehicle called Jackal. Minsu Jo, Junkil Park, Young-mi Baek, Radoslav Ivanov, James Weimer, Sang Hyuk Son, Insup Lee 0001 |
RTCSA | 4 |
| 2016 | Attack-Resilient Sensor Fusion for Safety-Critical Cyber-Physical SystemsabstractThis article focuses on the design of safe and attack-resilient Cyber-Physical Systems (CPS) equipped with multiple sensors measuring the same physical variable. A malicious attacker may be able to disrupt system performance through compromising a subset of these sensors. Consequently, we develop a precise and resilient sensor fusion algorithm that combines the data received from all sensors by taking into account their specified precisions. In particular, we note that in the presence of a shared bus, in which messages are broadcast to all nodes in the network, the attacker’s impact depends on what sensors he has seen before sending the corrupted measurements. Therefore, we explore the effects of communication schedules on the performance of sensor fusion and provide theoretical and experimental results advocating for the use of the Ascending schedule, which orders sensor transmissions according to their precision starting from the most precise. In addition, to improve the accuracy of the sensor fusion algorithm, we consider the dynamics of the system in order to incorporate past measurements at the current time. Possible ways of mapping sensor measurement history are investigated in the article and are compared in terms of the confidence in the final output of the sensor fusion. We show that the precision of the algorithm using history is never worse than the no-history one, while the benefits may be significant. Furthermore, we utilize the complementary properties of the two methods and show that their combination results in a more precise and resilient algorithm. Finally, we validate our approach in simulation and experiments on a real unmanned ground robot. Radoslav Ivanov, Miroslav Pajic, Insup Lee 0001 |
ACM Trans. Embed. Comput. Syst. | 1 |
| 2014 | Application of Python to AIMS Data to Analyze Intraoperative Hypotension through Pediatric Blood Pressure CurvesabstractThere is scant data regarding thresholds for intraoperative hypo tension (IOH) in children less than 1 year of age. We used anesthesia information management systems (AIMS) data to develop reference values for normal per operative blood pressures (BPs) and IOH in the infant population undergoing thoracic surgery. Manipulating large data sets such as AIMS vital sign data can be challenging, thus, we developed custom software in Python to organize the data, parse the files, perform the appropriate calculations, and output the information in graphical form. In general, the results show that BP values at each percentile gradually increase as the patient's age increases. We plan to develop a broader set of reference values for normal BPs under anesthesia and thresholds for IOH, irrespective of the type of surgery. These can be used to ascertain the relationship of IOH to morbidity and mortality in the perioperative period and beyond. Deepthi Shashidhar, Mingzhe Lin, Radoslav Ivanov, Insup Lee 0001, Allan F. Simpao, Arul Lingappan, Jorge A. Gálvez, Pablo Laje, Alan W. Flake, Mohamed A. Rehman |
CBMS | 3 |
| 2014 | Attack-resilient sensor fusionabstractThis work considers the problem of attack-resilient sensor fusion in an autonomous system where multiple sensors measure the same physical variable. A malicious attacker may corrupt a subset of these sensors and send wrong measurements to the controller on their behalf, potentially compromising the safety of the system. We formalize the goals and constraints of such an attacker who also wants to avoid detection by the system. We argue that the attacker's capabilities depend on the amount of information she has about the correct sensors' measurements. In the presence of a shared bus where messages are broadcast to all components connected to the network, the attacker may consider all other measurements before sending her own in order to achieve maximal impact. Consequently, we investigate effects of communication schedules on sensor fusion performance. We provide worst- and average-case results in support of the Ascending schedule, where sensors send their measurements in a fixed succession based on their precision, starting from the most precise sensors. Finally, we provide a case study to illustrate the use of this approach. Radoslav Ivanov, Miroslav Pajic, Insup Lee 0001 |
DATE | 1 |