Felipe G. Magalhaes

dblp:15/8002 · also Felipe Gohring de Magalhaes, Felipe Göhring de Magalhães · DBLP profile ↗
← Back
18ranked-venue papers
5as first author
11since 2021 · last 2026
0000-0002-0766-1421ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 12 · 4 first-author · 9 since 2021Systems, architecture and hardware · 4 · 1 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Integrating formal methods and automated tools for DO-178C compliance in UAV software
abstract
The development of software for Unmanned Aerial Vehicles (UAVs) is governed by stringent safety-critical regulations, with DO-178C serving as the primary standard for airborne systems. Ensuring compliance requires extensive verification, validation, and traceability across the software lifecycle, which becomes increasingly complex for autonomous and adaptive UAV functions. This paper proposes an integrated methodology for regulatory compliance checking that combines formal methods with automated verification tools to generate certification-ready evidence under DO-178C. Formal methods are applied at multiple levels: Alloy is used for requirements consistency checking, the SPIN model checker for architectural interaction properties, and bounded model checking for code-level analysis. These techniques are integrated with automated toolchains that provide continuous bidirectional traceability, structural coverage analysis, and automated test execution across the software lifecycle. The approach is evaluated on a Design Assurance Level (DAL) B UAV Collision Avoidance System. The case study demonstrates the production of certification-ready evidence bundles, including closed bidirectional traceability from system requirements through high and low-level software requirements to source code and tests, formal proof summaries linked to requirements, and decision coverage reports on mission-critical logic. Results indicate that tightly integrating formal analysis with automated verification improves early defect detection, reduces manual evidence assembly, and strengthens the auditability of DO-178C compliance. The combined use of formal methods and automation offers a scalable pathway for UAVs and other autonomous systems to achieve compliance with evolving safety regulations. The findings highlight that integrating regulatory compliance checking into development processes can simultaneously enhance rigour and efficiency, providing a model for certifiable autonomy software in civil airspace. • Engineered a workflow that combines formal methods with automation for DO-178C UAV compliance. • End-to-end methodology validated on a UAV Collision Avoidance System case study. • Produced certification-ready evidence: traceability, proofs, and coverage. • Improved early defect detection and reduced manual certification effort. • Illustrates a scalable path for certifiable autonomy in safety-critical UAVs.
Rim Zrelli, Henrique Amaral Misson, Sorelle Audrey K. Kamkuimo, Maroua Ben Attia, Abdo Shabah, Felipe G. Magalhaes, Gabriela Nicolescu
Inf. Softw. Technol.6
2026 Automatic translation of natural language requirements into CTL specifications using Large Language Models: A multi-approach evaluation
abstract
Translating natural language (NL) requirements into formal specifications such as Computation Tree Logic (CTL) is essential for improving the efficiency and scalability of formal verification, especially in safety-critical systems. This study evaluates the ability of Large Language Models (LLMs) to automate this process. We compare three approaches: fine-tuning the Mistral model, using GPT-4 in a few-shot learning setup, and a hybrid that feeds a BERT pattern classifier’s prediction to GPT-4. Using the Natural2CTL dataset, we assess strict logical accuracy and an ambiguity-tolerant accuracy, complemented by auxiliary semantic and structural operator similarity measures. Fine-tuning yields the strongest strict correctness and operator-structure fidelity, while the hybrid narrows the gap to fine-tuning and substantially improves over few-shot prompting alone. Residual errors across methods concentrate in path-quantifier selection, temporal granularity, and scoping in multi-clause requirements. Overall, LLMs can draft CTL candidates that are usable after lightweight normalisation, but they should be integrated into human-in-the-loop workflows with basic automated checks before use in high-assurance settings. • Benchmarks three LLM-based methods for NL-to-CTL translation. • Fine-tuned Mistral achieves 47.6% strict logical accuracy and 71.4% ambiguity-tolerant accuracy for CTL specification generation. • GPT-4 few-shot learning offers rapid prototyping but lower syntactic precision. • BERT-GPT hybrid balances pattern recognition and generative translation. • LLM automation reduces expert effort, but expert review remains critical for safety.
Rim Zrelli, Henrique Amaral Misson, Marwa Ben Attia, Felipe G. Magalhaes, Abdo Shabah, Gabriela Nicolescu
J. Syst. Softw.4
2025 Dynamic Asynchronous Controller for Integrated Photonic Networks: Introducing CLAP
Felipe G. Magalhaes
RSP1
2024 Natural2CTL: A Dataset for Natural Language Requirements and Their CTL Formal Equivalents
Rim Zrelli, Henrique Amaral Misson, Maroua Ben Attia, Felipe G. Magalhaes, Abdo Shabah, Gabriela Nicolescu
REFSQ4
2024 Advancing Formal Verification: Fine-Tuning LLMs for Translating Natural Language Requirements to CTL Specifications
abstract
In the domain of formal verification, translating natural language (NL) requirements into Computation Tree Logic (CTL) specifications presents a notable challenge due to the disparity between human-readable documents and formal specifications. This paper introduces a novel approach that leverages Large Language Models (LLMs) to automate this translation process, thereby enhancing the accuracy and efficiency of formal verification practices. We fine-tune three state-of-the-art LLMs—LLAMA3, Mistral, and Qwen2—with a particular focus on optimizing the Mistral model due to its superior performance. Our methodology is supported by the Natural2CTL dataset, consisting of 2,095 NL requirements and their corresponding CTL specifications. We employ evaluation metrics such as validation loss, accuracy, semantic similarity, and Structural Operator Jaccard Similarity (SOJS) for a comprehensive assessment of model performance. Additionally, a comparative analysis with human translators, trained in CTL logic, underscores the LLMs’ potential to match or even surpass human accuracy in translating NL requirements into formal specifications. Our findings reveal that the fine-tuned Mistral model significantly outperforms the other LLMs and human participants, demonstrating superior accuracy in generating CTL specifications. This study advances the field of formal verification by proposing a scalable solution to the NL-to-CTL translation challenge, setting a new benchmark for the integration of AI tools in complex specification tasks.
Rim Zrelli, Henrique Amaral Misson, Maroua Ben Attia, Felipe G. Magalhaes, Abdo Shabah, Gabriela Nicolescu
RSP4
2023 Efficient Defense Against Model Stealing Attacks on Convolutional Neural Networks
abstract
Model stealing attacks have become a serious concern for deep learning models, where an attacker can steal a trained model by querying its black-box API. This can lead to intellectual property theft and other security and privacy risks. The current state-of-the-art defenses against model stealing attacks suggest adding perturbations to the prediction probabilities. However, they suffer from heavy computations and make impracticable assumptions about the adversary. They often require the training of auxiliary models. This can be time-consuming and resource-intensive which hinders the deployment of these defenses in real-world applications. In this paper, we propose a simple yet effective and efficient defense alternative. We introduce a heuristic approach to perturb the output probabilities. The proposed defense can be easily integrated into models without additional training. We show that our defense is effective in defending against three state-of-the-art stealing attacks. We evaluate our approach on large and quantized (i.e., compressed) Convolutional Neural Networks (CNNs) trained on several vision datasets. Our technique outperforms the state-of-the-art defenses with a ×37 faster inference latency without requiring any additional model and with a low impact on the model's performance. We validate that our defense is also effective for quantized CNNs targeting edge devices.
Kacem Khaled, Mouna Dhaouadi, Felipe G. Magalhaes, Gabriela Nicolescu
ICMLA3
2023 SerIOS: Enhancing Hardware Security in Integrated Optoelectronic Systems
abstract
Silicon photonics (SiPh) has different applications, from enabling fast and high-bandwidth communication for high-performance computing systems to realizing energy-efficient optical computation for AI hardware accelerators. However, integrating SiPh with electronic sub-systems can introduce new security vulnerabilities that cannot be adequately addressed using existing hardware security solutions for electronic systems. This paper introduces SerIOS, the first framework aimed at enhancing hardware security in optoelectronic systems by leveraging the unique properties of optical lithography. SerIOS employs cryptographic keys generated based on imperfections in the optical lithography process and an online detection mechanism to detect attacks. Simulation and synthesis results demonstrate SerIOS's effectiveness in detecting and preventing attacks, with a small area footprint of less than 15% and a 100% detection rate across various attack scenarios and optoelectronic architectures, including photonic AI accelerators.
Felipe G. Magalhaes, Mahdi Nikdast, Gabriela Nicolescu
RSP1
2023 ReDaML: A Modeling Language for DO-178C High-Level Requirements in Airspace Systems
abstract
Software development in critical airspace cyber-physical systems is challenging, mainly because of its safety-critical nature. Safety standards and regulations, such as DO-178C, provide guidelines for the development of software to ensure they adhere to the essential safety requirements in the certification processes. The requirements process proposed in the standard, which is responsible for developing the high-level requirements, is one of the most crucial steps in the life cycle since it serves as the basis for the subsequent processes. Having safety as a major concern, specifying safety requirements is of fundamental importance, allowing engineers to evaluate them and propose measures to mitigate the impact of a system failure, which can be catastrophic. In this paper, we present ReDaML, a domain-specific modelling language designed to support the development of safety-critical software systems, focused on the specification of high-level requirements in accordance with the DO-178C guidelines. Finally, a scenario of applying the approach to an UAS collision avoidance system is demonstrated.
Henrique Amaral Misson, Rim Zrelli, Maroua Ben Attia, Felipe G. Magalhaes, Gabriela Nicolescu
RSP4
2023 Security assessment of a commercial router using physical access: a case study
abstract
Physical access to a device can greatly help in vulnerability research as it opens up new vectors for exploitation. This is especially true for embedded devices, which often come with open serial ports and various types of debugging features. Therefore, security assessments of these devices should take into consideration the hardware components and their means of communication. In this paper, we explore a testing methodology that transforms a black box test into a white box test by using physical access to retrieve the code of the applications running on the device. To demonstrate its advantages, we apply this methodology to assess the security risks on a commercial router. We use it to uncover multiple code execution vulnerabilities in the router's firmware. We discuss secure coding guidelines to remediate those vulnerabilities and the importance of IoT security.
Colin Stephenne, Felipe G. Magalhaes, Frédéric Cuppens, Jean-Yves Ouattara, Militza Jean, Gabriela Nicolescu
RSP2
2022 Careful What You Wish For: on the Extraction of Adversarially Trained Models
abstract
Recent attacks on Machine Learning (ML) models such as evasion attacks with adversarial examples and models stealing through extraction attacks pose several security and privacy threats. Prior work proposes to use adversarial training to secure models from adversarial examples that can evade the classification of a model and deteriorate its performance. However, this protection technique affects the model’s decision boundary and its prediction probabilities, hence it might raise model privacy risks. In fact, a malicious user using only a query access to the prediction output of a model can extract it and obtain a high-accuracy and high-fidelity surrogate model. To have a greater extraction, these attacks leverage the prediction probabilities of the victim model. Indeed, all previous work on extraction attacks do not take into consideration the changes in the training process for security purposes. In this paper, we propose a framework to assess extraction attacks on adversarially trained models with vision datasets. To the best of our knowledge, our work is the first to perform such evaluation. Through an extensive empirical study, we demonstrate that adversarially trained models are more vulnerable to extraction attacks than models obtained under natural training circumstances. They can achieve up to ×1.2 higher accuracy and agreement with a fraction lower than ×0.75 of the queries. We additionally find that the adversarial robustness capability is transferable through extraction attacks, i.e., extracted Deep Neural Networks (DNNs) from robust models show an enhanced accuracy to adversarial examples compared to extracted DNNs from naturally trained (i.e. standard) models.
Kacem Khaled, Gabriela Nicolescu, Felipe G. Magalhaes
PST3
2021 HyCo: A Low-Latency Hybrid Control Plane for Optical Interconnection Networks
abstract
Next-generation multiprocessor systems point to the integration of a large number of cores (e.g., processing and memory) where electrical networks-on-chip (eNoCs) can improve the communication performance. As the number of integrated cores increases, metallic interconnect in eNoCs becomes a bottleneck, leading to communication performance degradation and increased power consumption. Optical interconnection networks (OINs) have emerged to outperform the communication infrastructure in multiprocessor systems. Nevertheless, OINs’ full capability is curbed by high latency electrical controllers required to orchestrate and (re)configure the underlying photonic components, realizing a path between sending and receiving cores. Control techniques impose a high latency to perform the network routing, limiting the full utilization of OINs. In this paper, we design a novel low-latency Hybrid Controller (HyCo) that employs acceleration techniques to reduce its execution time. HyCo is developed based on integrating centralized and distributed control techniques as well as by using pre-calculated network routes and a Bloom filter, all of which result in a considerable reduction in HyCo’s latency. Simulation and prototyping results for networks up to 64×64 indicate a latency smaller than 50 ns, in the worst-case scenario.
Felipe G. Magalhaes, Mahdi Nikdast, Fabiano Hessel, Odile Liboiron-Ladouceur, Gabriela Nicolescu
RSP1
2019 Cache Locking Content Selection Algorithms for ARINC-653 Compliant RTOS
abstract
Avionic software is the subject of stringent real time, determinism and safety constraints. Software designers face several challenges, one of them being the interferences that appear in common situations, such as resource sharing. The interferences introduce non-determinism and delays in execution time. One of the main interference prone resources are cache memories. In single-core processors, caches comprise multiple private levels. This breaks the isolation principle imposed by avionic standards, such as the ARINC-653. This standard defines partitioned architectures where one partition should never directly interfere with another one. In cache-based architectures, one partition can modify the cache content of another partition. In this paper, we propose a method based on cache locking to reduce the non-determinism and the contention on lower level memories while improving the time performances.
Alexy Torres Aurora Dugo, Jean-Baptiste Lefoul, Felipe G. Magalhaes, Dahman Assal, Gabriela Nicolescu
ACM Trans. Embed. Comput. Syst.3
2018 Silicon Photonic Interconnects: Minimizing the Controller Latency
abstract
Silicon photonic interconnects (SPIs) have emerged as a promising solution to outperform the communication infrastructure in multiprocessor systems-on-chip (MPSoCs). Routing a message from one node to another in an MPSoC integrating SPIs, several photonic components (e.g., switching elements) need to be configured to realize an optical path between sending and receiving nodes. Such configurations are performed in an electronic controller, which, if not fast, imposes high latency in SPIs, constraining the application of SPIs in MPSoCs. Realizing a full exploitation of SPIs, this paper presents a look-up-table-based centralized controller (LUCC). We indicate that LUCC has the lowest latency among the state-of-the-art controllers for SPIs while it can be applied to different SPI architectures. Employing acceleration techniques based on off-line routings, we report (simulation and prototyping) a worst-case control latency smaller than 5 ns. Moreover, LUCC is experimentally integrated with a photonic switch in the lab, where we show contention resolution in one clock cycle.
Felipe G. Magalhaes, Mahdi Nikdast, Yule Xiong, Fabiano Hessel, Odile Liboiron-Ladouceur, Gabriela Nicolescu
ACM Great Lakes Symposium on VLSI1
2014 Embedded cluster-based architecture with high level support - presenting the HC-MPSoC
abstract
Multiprocessor System-on-Chip (MPSoC) can be found in almost every market branch and its design typically presents several restrictions such as chip area and energy consumption. State-of-art MPSoCs uses networks-on-chip as the primary communication infrastructure and the tendency is that NoC-based systems will still be used for a long time, thanks to a greater design flexibility and also a high communication bandwidth and parallelism. However, such systems also have certain usage restrictions, such as the location of the tasks that compose the application. Mapping and partitioning techniques seek to solve this problem or at least reduce it to a non critical point by diving tasks along the architecture but are not always completely successful. In this context, cluster-based architectures emerges as a viable alternative to MPSoCs. This type of system typically has a hybrid architecture on its constitution, using more than one communication infrastructure, thus being able to group elements by affinity and still use high-speed communication channels, such as NoCs. In this way, the presented work introduces the HC-MPSoC, an architecture for cluster-based intrachip systems, which uses buses and a NoC in a joint way, forming groups of elements independently distributed throughout the platform. The extensions made on the HellfireOS in order to execute it over the hybrid architecture are also presented. All HC-MPSoC modules as well as the HellfireOS modules and the results obtained using the platform are presented along the text.
Felipe G. Magalhaes, Sergio Johann Filho, Oliver B. Longhi, Fabiano Hessel
RSP1
2014 On the design space exploration through the Hellfire Framework
Alexandra Aguiar, Sergio Johann Filho, Felipe G. Magalhaes, Fabiano Hessel
J. Syst. Archit.3
2013 Customizable RTOS to support communication infrastructures and to improve design space exploration in MPSoCs
abstract
Multiprocessed System-on-Chip (MPSoCs) have become a recurrent implementation alternative to modern embedded systems and, lately, have counted on resources previously available only on general purpose machines. In this context, it is possible to highlight that many techniques formerly adopted in general-purpose computers have been studied and adapted to the embedded reality. Thus, embedded communication infrastructures such as buses and networks-on-Chip (NoCs) are based on general-purpose solutions and are widely accepted for embedded systems. Also, embedded systems make use of Operating Systems (OS), as they provide standard interfaces to access hardware resources, including the communication facilities. However, although the underlying communication infrastructure can differ in order to improve a given metric, such as performance, power or area, it is desirable that the software layer remains the same, especially in terms of the application's and OS's code improving the overall software quality. Still, certain OS parameters can directly influence on the overall system performance. This paper presents a highly configurable Real Time OS (RTOS) that implements a communication protocol to provide a transparent communication interface for both bus- and NoC-based MPSoCs' applications.
Alexandra Aguiar, Sergio Johann Filho, Felipe G. Magalhaes, Fabiano Hessel
RSP3
2013 BaBaNoC: An asynchronous network-on-chip described in Balsa
abstract
The downscaling of silicon technology and the possibility of building MPSoCs, make intrachip communication a mainstream research topic. NoCs are an elegant solution to provide communication scalability and modularity. NoCs are already common in MPSoC design. Moreover, new technology challenges point to a growth in the use of non-synchronous NoCs. However, the design of asynchronous infrastructures with current EDA tools is challenging. That is due to the fact that most of these tools are oriented towards synchronous design. This work proposes and evaluates a fully asynchronous NoC router based on the Balsa language and framework. The design is validates through FPGA synthesis.
Matheus T. Moreira, Felipe G. Magalhaes, Matheus Gibiluka, Fabiano Hessel, Ney Laert Vilar Calazans
RSP2
2012 Task model suitable for dynamic load balancing of real-time applications in NoC-based MPSoCs
abstract
Modern embedded systems implemented through Multiprocessor System-on-Chip (MPSoCs) benefit themselves from resources that were previously available solely in generalpurpose computers. Currently, these systems are able to provide more features at the cost of an increased design complexity. In this scenario, the applications' behaviour has changed. In the past, the majority of applications showed a static behaviour throughout their entire lifetime. Applications could be divided into tasks and mapped onto processing elements at design time. Currently, the applications' dynamic nature imposes that efficient dynamic load balancing techniques with different task mapping strategies must arise, although a fair static mapping still helps increasing the system overall performance. In this paper we present a task model suitable for dynamic load balancing of real-time applications with special support for Network-on-Chip (NoC)-based MPSoCs that aims to stabilize the system load throughout its lifetime. Results show a reduction in both system stabilization time (mean of 47.62%) and deadline misses (mean of 32.28%) for several benchmarks, compared to classic approaches which employ a centralized migration manager.
Sergio Johann Filho, Alexandra Aguiar, Felipe G. Magalhaes, Oliver B. Longhi, Fabiano Hessel
ICCD3