Peter Wägemann

dblp:166/6923 · DBLP profile ↗
← Back
25ranked-venue papers
6as first author
15since 2021 · last 2026
0000-0002-3730-533XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 9 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 4 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 2 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Wasm-WCET: Worst-Case Execution-Time Analysis of WebAssembly Modules on Updatable Resource-Constrained Embedded Devices
Maximilian Seidler, Martin Michelis, Peter Wägemann, Rüdiger Kapitza
RTAS3
2026 WasmWeaver: A Framework for Runtime-Aware WebAssembly Program Generation with Reinforcement Learning
Kilian Müller, Siddharth Mane, Peter Wägemann, Norman Franchi
SANER3
2025 Pfip: A Udp/ip Transactional Network Stack for Power-Failure Resilience in Embedded Systems
abstract
Emerging embedded devices in the Battery-Free Internet of Things have the benefit that they harvest their required energy during runtime from the environment (e.g., through solar power). However, from the perspective of the systems networking stacks, the main challenge is resilience against power failures: Existing network stacks for such systems (e.g., LwIP) face the problem that stored data, such as for address translation, is likely to be lost or inconsistent after a power outage. Besides the consistency of data, sending a packet without the knowledge about the required and available energy can result in energy inefficiency when the power failure occurs during sending, because of the energy waste of the incomplete packet. In this paper, we introduce Pfip, a network stack for UDP/IP specifically targeting scenarios with intermittent power supply. PFIP's primary design consideration is to modularize the network stack into distinct transactions in order to result in a state-machine-compliant structure with states and according transitions. The stack is able to introduce checkpoints between transactions to persistently store the stack's state. Besides handling data consistency, we employ code-analysis techniques that determine the energy demand of states/transitions. Combining the energy demand of operations along with the available energy on our hardware platform eventually yields runtime guarantees such that started transactions will safely be completed without facing power failures.
Kai Vogelgesang, Ishwar Mudraje, Luis Gerhorst, Phillip Raffeck, Peter Wägemann, Thorsten Herfet, Wolfgang Schröder-Preikschat
CCNC5
2025 vNV-Heap: An Ownership-Based Virtually Non-Volatile Heap for Embedded Systems
abstract
The Internet of Batteryless Things might revolutionize our understanding of connected devices by harvesting required operational energy from the environment. These systems come with the system-software challenge that the intermittently powered IoT devices have to checkpoint their state in non-volatile memory to later resume with this state when sufficient energy is available. The scarce energy resources demand that only modified data is persisted before a power failure, which requires precise modification tracking.
Markus Elias Gerber, Luis Gerhorst, Ishwar Mudraje, Kai Vogelgesang, Thorsten Herfet, Peter Wägemann
LCTES6
2025 Dynamic Fuzzing-Based Whole-System Timing Analysis
abstract
Worst-case timing analysis traditionally begins with estimating the worst-case execution time (WCET) of individual tasks using either static analysis or measurement-based techniques. To derive worst-case response times (WCRTs), engineers typically compose these WCETs with bounds on preemption and operating system overheads. However, WCRTs depend on complex system-level interactions, including task communication, OS behavior, and asynchronous events. Compositional analysis often overestimates, assuming that worst-case conditions across components coincide, admitting infeasible global control-flow paths. whole-system Static techniques refine this by modeling the system holistically but require platform-specific tailoring or extensive annotations. A dynamic equivalent has been missing. We present Fret, the first dynamic whole-system approach for estimating WCRTs. Fret employs feedback-guided fuzzing to uncover timing-critical dependencies, including inter-task communication, task/OS interactions, and interrupt effects, without requiring prior knowledge of inputs or states. Implemented using LibAFL and evaluated on FreeRTOS with realistic benchmarks, FRET consistently outperforms state-of-the-art fuzzing strategies in estimating accurate response times. Although not sound, Fret delivers more than timing estimates: it produces actionable artifacts-worst-case inputs, interrupt schedules, and intertask program-flow information-that complement static analyses and support system validation, runtime monitoring, and robust mixed-criticality scheduling.
Alwin Berger, Simon Schuster, Peter Wägemann, Peter Ulbrich
RTSS3
2025 Watwaos: A Framework for Worst-Case-Aware Tailoring and Whole-System Analysis of Energy-Constrained Real-Time Systems
abstract
Emerging embedded systems have to increasingly meet energy constraints besides their timing requirements. While frequency-scaling techniques are well explored, existing operating systems for embedded real-time systems have shortcomings in comprehensively exploiting energy-saving features present in modern system-on-chip (SoC) platforms. Existing systems lack operating-system abstractions to exploit the tradeoff between computing performance and energy efficiency. Consequently, whole-system analysis techniques are not applicable to yield optimal configurations tailored to the applications' requirements. Finally, the complexity of modern energy-saving hardware features creates huge search spaces for optimal configurations. In this paper, we present WATWAOS, a framework for worst-case-aware tailoring and whole-system analysis of energyconstrained real-time systems. WatwaOS acts as both an analysis/tailoring framework and a (generated) real-time operating system. The approach exploits knowledge acquired during wholesystem analysis and applies worst-case-aware tailoring of the system for its runtime. WatwaOS has an awareness of the application's requirements (i.e., deadlines, peripheral devices) and the underlying SoC's energy-saving features. To achieve the tailoring, WATWAOS introduces a concept of hierarchical abstractions, which offer fine-grained power-management decisions. These abstractions are designed to enable merging of their states without loss of accuracy. Static analysis based on these abstractions yields worst-case-optimal (i.e., provably energy minimal) solutions with regard to given deadlines. To tackle the enormous search space of our bilevel problem, WatwaOS employs several concepts to exploit advanced features of mathematical optimizing tools. The evaluations of WATWAOS validate our claim of finding worst-case-optimal solutions within acceptable analysis times.
Tobias Häberlein, Eva Dengler, Phillip Raffeck, Peter Wägemann
RTSS4
2024 WIP: Towards a Transactional Network Stack for Power-Failure Resilience
abstract
Traditionally, consumer communication and networking has been dominated by entertainment applications and voice communication. With smart homes and smart cars, consumer communication evolves more and more towards a basic supply and is used not only for convenience, but also in security-related applications like surveillance or in sensors and actors for window locks or doorbells. Resilience of this basic supply consequently suddenly becomes a hot research area, also in consumer networks. Our work in progress touches a topic within this research area that up to now has majorly been treated as an orphan: Network stacks are neither considered part of the smart device itself, nor are they managed by middleware or applications. After system or power failures, devices are rebooted, network stacks are restarted, and the middleware takes care of registration and inclusion of the platforms. We introduce the first steps into a transactional smart device, which in case of power failure is able to not only restart its operations (literally founded in the operating system) but also its communication. We strive to develop transactional network stacks, semantically based on Petri nets, for technologies such as Bluetooth or Wi-Fi, Such transactional semantics allow us to develop systems with power-failure resilience. Since each transaction consumes a certain amount of energy, static worst-case energy consumption analysis helps to fit the model to the platform and vice versa. We target consumer-grade embedded system-on-chip platforms (i.e., ESP32-C3) with additional non-volatile memory for storing system checkpoints.
Kai Vogelgesang, Phillip Raffeck, Peter Wägemann, Thorsten Herfet, Wolfgang Schröder-Preikschat
CCNC3
2024 Crêpe: Clock-Reconfiguration-Aware Preemption Control in Real-Time Systems with Devices
Eva Dengler, Peter Wägemann
ECRTS2
2024 WoCA: Avoiding Intermittent Execution in Embedded Systems by Worst-Case Analyses with Device States
abstract
Embedded systems with intermittent energy supply can revolutionize the Internet of Things, as they are energy self-sufficient due to energy harvesting. Existing intermittent-computing approaches, running directly from non-volatile memory, allow incremental progress of machine-code instructions. However, this progress does not apply to many devices (e.g., transceivers) having transactional (i.e., all-or-nothing) semantics: Power failures during transactions lead to starvation when frequently experiencing failed attempts. We introduce WoCA, an approach that exploits static, whole-system worst-case analysis for device-driven intermittent computing. With the currently available energy, WoCA enables transactional device uses and guarantees forward progress. WoCA's novel static analysis tracks program-path-sensitive device states and transitions to yield energy bounds. With these bounds, WoCA's runtime decides when to safely execute code between checkpoints. Using WoCA's hardware platform, we validate that WoCA makes more efficient use of available energy compared to worst-case-agnostic approaches, while also giving runtime guarantees.
Phillip Raffeck, Johannes Maier, Peter Wägemann
LCTES3
2024 VeriFence: Lightweight and Precise Spectre Defenses for Untrusted Linux Kernel Extensions
abstract
High-performance IO demands low-overhead communication between user- and kernel space. This demand can no longer be fulfilled by traditional system calls. Linux's extended Berkeley Packet Filter (BPF) avoids user-/kernel transitions by just-in-time compiling user-provided bytecode and executing it in kernel mode with near-native speed. To still isolate BPF programs from the kernel, they are statically analyzed for memory- and type-safety, which imposes some restrictions but allows for good expressiveness and high performance. However, to mitigate the Spectre vulnerabilities disclosed in 2018, defenses which reject potentially-dangerous programs had to be deployed. We find that this affects 31 % to 54 % of programs in a dataset with 844 real-world BPF programs from popular open-source projects. To solve this, users are forced to disable the defenses to continue using the programs, which puts the entire system at risk.
Luis Gerhorst, Henriette Herzog, Peter Wägemann, Maximilian Ott, Rüdiger Kapitza, Timo Hönig
RAID3
2024 TinyBFT: Byzantine Fault-Tolerant Replication for Highly Resource-Constrained Embedded Systems
abstract
Byzantine fault-tolerant (BFT) state-machine replication offers resilience against a wide spectrum of faults including hardware crashes, software failures, and attacks. Unfortunately, having been mostly designed for use on large servers, existing implementations of such replication protocols consume vast amounts of memory and therefore are not available to embedded systems that consist of highly resource-constrained devices. In this paper we address this problem with TinyBFT, the first BFT state-machine replication library specifically developed to run on nodes comprising 1 MB of RAM or less. To achieve this, TinyBFT relies on a memory-efficient implementation of the PBFT protocol that allocates all of its memory statically and thus, in contrast to common state-of-the-art PBFT-based libraries, has a guaranteed worst-case memory consumption that is known at compile time. Experiments show that our library provides sufficiently low latency even on tiny ESP32-C3 microcontrollers.
Harald Böhm, Tobias Distler, Peter Wägemann
RTAS3
2023 FusionClock: Energy-Optimal Clock-Tree Reconfigurations for Energy-Constrained Real-Time Systems
Eva Dengler, Phillip Raffeck, Simon Schuster, Peter Wägemann
ECRTS4
2023 Luci: Loader-based Dynamic Software Updates for Off-the-shelf Shared Objects
Bernhard Heinloth, Peter Wägemann, Wolfgang Schröder-Preikschat
USENIX ATC2
2021 Taming Non-Deterministic Low-Level I/O: Predictable Multi-Core Real-Time Systems by SoC Co-Design
abstract
Predictable and analyzable I/O is one of the considerable challenges in the design of multi-core real-time systems. A common approach to tackle this issue is to partition and schedule I/O transactions such that interference between tasks is minimized. While this works for packet-oriented interfaces with deterministic blocking times, such as ethernet, these techniques are inapplicable to a whole range of I/O devices with nondeterministic behavior that is commonly found in embedded applications. Interfaces, such as SPI, do not allow for fine-grained scheduling and thus exhibit uncontrolled blocking times. Even worse, their configuration and use must be considered as independent transactions requiring costly synchronization between tasks. The resulting detrimental effects are, in particular, pronounced in settings with mixed task requirements on predictability and determinism. All this makes the temporal analysis of such systems cumbersome and overly pessimistic. To solve these issues, we present LOWI/O, an approach to eliminate the interference of low-level non-deterministic I/O interfaces for real-time tasks with high predictability demands (i.e., critical task) while preserving flexibility for tasks with lower requirements (i.e., uncritical tasks). Therefore, we leverage knowledge about the application-specific I/O usage patterns, obtained by static analysis, to derive a tailored hardware architecture. Its key feature is the anticipatory reservation of individual time slots for critical tasks and to mimic preemptivity of I/O units for the remaining system. We have implemented our approach as a toolchain for OSEK-based real-time systems that automatically generates an application-specific SoC design along with a hardware and timing model for subsequent WCET analysis. Our experimental results prove predictable timing for critical tasks with limited impact on uncritical tasks.
Steffen Vaas, Peter Ulbrich, Christian Eichler, Peter Wägemann, Marc Reichenbach, Dietmar Fey
ISORC4
2021 Annotate once - analyze anywhere: context-aware WCET analysis by user-defined abstractions
abstract
The widespread adoption of cyber-physical systems in the safety-critical (hard real-time) domain is accompanied by a rising degree of code-reuse up to actual software product lines spanning different hardware platforms. Nevertheless, the dominant tools for static worst-case execution-time (WCET) analysis operate on individual, specific system instances at the binary level, further depending on machine-code–level annotations for precise analysis. Thus, this timing verification is neither portable nor reusable.
Simon Schuster, Peter Wägemann, Peter Ulbrich, Wolfgang Schröder-Preikschat
LCTES2
2019 Proving Real-Time Capability of Generic Operating Systems by System-Aware Timing Analysis
abstract
The static timing analysis of universal real-time operating systems (RTOS) with generically implemented services requires application and system-context-specific knowledge (e.g., number of currently active tasks) to bound overheads. However, due to the missing notion of OS semantics, contemporary timing analysis tools are unable to exploit such information, resulting in failing or overly pessimistic analysis. To tackle this issue, we present our System-wide WCET Analyses framework (SWAN). SWAN's heart is Platina, a parametric source-level annotation language that facilitates the expression and propagation of context information from the application over the OS down to the machine-code level. Through the expression of semantic interdependencies in a unified and reusable way, analysis pessimism is significantly reduced, as we demonstrate by case studies on FreeRTOS, Linux, and a real-world flight-control system. Just as important as our system-aware timing analysis is the tool support for its practical usability. Therefore, we augmented SWAN by a powerful interactive visualization and annotation environment. This enables developers to quickly identify context-dependent spots that require annotation and thus to cope with large implementations associated with universal RTOSs. Eventually, SWAN allows determining if a generically implemented system is real-time capable and thus timeliness is guaranteed.
Simon Schuster, Peter Wägemann, Peter Ulbrich, Wolfgang Schröder-Preikschat
RTAS2
2018 Whole-System Worst-Case Energy-Consumption Analysis for Energy-Constrained Real-Time Systems
abstract
Although internal devices (e.g., memory, timers) and external devices (e.g., transceivers, sensors) significantly contribute to the energy consumption of an embedded real-time system, their impact on the worst-case response energy consumption (WCRE) of tasks is usually not adequately taken into account. Most WCRE analysis techniques, for example, only focus on the processor and therefore do not consider the energy consumption of other hardware units. Apart from that, the typical approach for dealing with devices is to assume that all of them are always activated, which leads to high WCRE overestimations in the general case where a system switches off the devices that are currently not needed in order to minimize energy consumption. In this paper, we present SysWCEC, an approach that addresses these problems by enabling static WCRE analysis for entire real-time systems, including internal as well as external devices. For this purpose, SysWCEC introduces a novel abstraction, the power-state-transition graph, which contains information about the worst-case energy consumption of all possible execution paths. To construct the graph, SysWCEC decomposes the analyzed real-time system into blocks during which the set of active devices in the system does not change and is consequently able to precisely handle devices being dynamically activated or deactivated.
Peter Wägemann, Christian Dietrich 0001, Tobias Distler, Peter Ulbrich, Wolfgang Schröder-Preikschat
ECRTS1
2018 Operating Energy-Neutral Real-Time Systems
abstract
Energy-neutral real-time systems harvest the entire energy they use from their environment. In such systems, energy must be treated as an equally important resource as time, which creates the need to solve a number of problems that so far have not been addressed by traditional real-time systems. In particular, this includes the scheduling of tasks with both time and energy constraints, the monitoring of energy budgets, as well as the survival of blackout periods during which not enough energy is available to keep the system fully operational. In this article, we address these issues presenting E n OS, an operating-system kernel for energy-neutral real-time systems. E n OS considers mixed time criticality levels for different energy criticality modes, which enables a decoupling of time and energy constraints when one is considered less critical than the other. When switching the energy criticality mode, the system also changes the set of executed tasks and is therefore able to dynamically adapt its energy consumption depending on external conditions. By keeping track of the energy budget available, E n OS ensures that in case of a blackout the system state is safely stored to persistent memory, allowing operations to resume at a later point when enough energy is harvested again.
Peter Wägemann, Tobias Distler, Heiko Janker, Phillip Raffeck, Volkmar Sieh, Wolfgang Schröder-Preikschat
ACM Trans. Embed. Comput. Syst.1
2017 An End-to-End Toolchain: From Automated Cost Modeling to Static WCET and WCEC Analysis
abstract
Reliable and fine-grained cost-models are fundamental for real-time systems to statically predict worst-case execution time (WCET) estimates of program code in order to guarantee timeliness. Analogous considerations hold for energy-constrained systems where worst-case energy consumption (WCEC) values are mandatory to ensure meeting predefined energy budgets. These cost models are generally unavailable for commercial off-the-shelf (COTS) hardware platforms, although static worst-case analysis tools require those models in order to predict the WCET as well as the WCEC of program code. To solve this problem, we present NEO, an end-to-end toolchain to automate cost-model generation for both WCET and WCEC analyses. NEO exploits automatically generated benchmarks, which are input for 1) an instruction-level emulation and 2) automatically conducted execution-time and energy-consumption measurements on the target platform. The gathered values (i.e., occurrences per instruction, execution-time and energyconsumption per benchmark) are combined as mathematical optimization problems. The solutions to the formulated problems, which are designed to reveal the worst-case behavior, yield the respective cost models. To statically determine upper bounds of benchmarks, we integrated the cost models into the stateof-the-art WCET analyzer PLATIN. Our evaluations on COTS hardware reveal that our open-source, end-to-end toolchain NEO yields accurate worst-case bounds.
Volkmar Sieh, Robert Burlacu, Timo Hönig, Heiko Janker, Phillip Raffeck, Peter Wägemann, Wolfgang Schröder-Preikschat
ISORC6
2017 SysWCET: Whole-System Response-Time Analysis for Fixed-Priority Real-Time Systems (Outstanding Paper)
abstract
The worst-case response time (WCRT) – the time span from release to completion of a real-time task – is a crucial property of real-time systems. However, WCRT analysis is complex in practice, as it depends not only on the realistic examination of worst-case execution times (WCET), but also on system-level overheads and blocking/preemption times. While the implicit path enumeration technique (IPET) has greatly improved automated WCET analysis, the resulting values still need to be aggregated manually with the system-level overheads – an errorprone and tedious process that yields overly pessimistic results. With SysWCET, we provide an integrated approach for the automated WCRT analysis across multiple threads of execution, locks, interrupt service routines, and the real-time operating system (RTOS) in particular. Our approach spans a single IPET formulation over the whole system and exploits RTOS and scheduler semantics to derive cross-kernel flow facts in order to significantly reduce pessimism in the WCRT analysis. We evaluate our approach with a fully functional implementation of SysWCET for the automotive OSEK-OS standard (ECC1), including threads, alarms, interrupt-service routines, events, and PCP-based resource management.
Christian Dietrich 0001, Peter Wägemann, Peter Ulbrich, Daniel Lohmann
RTAS2
2017 Demo Abstract: Tooling Support for Benchmarking Timing Analysis
abstract
Precisely evaluating the accuracy of worst-case execution time (WCET) analysis tools through benchmarking is inherently difficult and in general involves a significant amount of manual intervention. In this paper, we address this problem with ALADDIN, a tooling framework that enables fully-automated evaluations of WCET analyzers. To provide comprehensive results based on benchmarks with known WCETs, ALADDIN incorporates the GENE benchmark generator. Our demonstration shows how ALADDIN evaluates two state-of-the-art WCET analyzers: the commercial tool aiT and the open-source tool PLATIN.
Christian Eichler, Peter Wägemann, Tobias Distler, Wolfgang Schröder-Preikschat
RTAS2
2017 Benchmark Generation for Timing Analysis
abstract
Being able to comprehensively evaluate the individual strengths and weaknesses of worst-case execution time (WCET) analysis tools through benchmarking is essential for improving their accuracy. Unfortunately, a lack of knowledge about the detailed characteristics, actual complexities, and internal structures of existing benchmarks often prevents finegrained assessments, and sometimes even results in misleading conclusions. In this paper we present GENE, a tool that addresses these problems by automatically generating WCET benchmarks with known properties and predefined complexities. Due to the WCETs of benchmarks created by GENE being available, this approach for example makes it possible to precisely determine the accuracy of a WCET analyzer. In addition, the fact that GENE controls the program patterns of a benchmark enables fine-grained evaluations of the particular abilities and deficiencies of different WCET analyzers, as we demonstrate for aiT and PLATIN using multiple hardware platforms.
Peter Wägemann, Tobias Distler, Christian Eichler, Wolfgang Schröder-Preikschat
RTAS1
2016 A Kernel for Energy-Neutral Real-Time Systems with Mixed Criticalities
abstract
Energy-neutral real-time systems harvest the entire energy they use from their environment, making it essential to treat energy as an equally important resource as time. As a result, such systems need to solve a number of problems that so far have not been addressed by traditional real-time systems. In particular, this includes the scheduling of tasks with both time and energy constraints, the monitoring of energy budgets, as well as the survival of blackout periods during which not enough energy is available to keep the system fully operational. In this paper, we address these issues presenting ENOS, an operating-system kernel for energy-neutral real-time systems. ENOS considers mixed time criticality levels for different energy criticality modes, which enables a decoupling of time and energy constraints during phases when one is considered less critical than the other. When switching the energy criticality mode, the system also changes the set of tasks to be executed and is therefore able to dynamically adapt its energy consumption depending on external conditions. By keeping track of the energy budget available, ENOS ensures that in case of a blackout the system state is safely stored to persistent memory, allowing operations to resume at a later point when enough energy is harvested again.
Peter Wägemann, Tobias Distler, Heiko Janker, Phillip Raffeck, Volkmar Sieh
RTAS1
2016 Towards code metrics for benchmarking timing analysis
abstract
Comprehensive evaluations of the effectiveness of worst-case execution time (WCET) analyzers require a selection of benchmarks that pose a challenge to these tools. In this paper, we identify pitfalls that are associated with selecting such benchmarks based on complexity metrics (e.g., the number of loops contained in a program), which in part are caused by the fact that complexity measures are not necessarily stable in the face of compiler optimizations. To address these problems, we are developing a tool that automatically assesses the resilience of a benchmark against compiler optimizations by tracking complexity measures across different optimization levels. In combination with information on the data dependency of control flows, which is also provided by our tool, this allows users to find and discard benchmarks that appear challenging for WCET analyzers at the source-code level, but in fact are trivial at the machine-code level where the actual analysis is performed.
Peter Wägemann, Tobias Distler, Phillip Raffeck, Wolfgang Schröder-Preikschat
RTSS1
2015 Worst-Case Energy Consumption Analysis for Energy-Constrained Embedded Systems
abstract
The fact that energy is a scarce resource in many embedded real-time systems creates the need for energy-aware task schedulers, which not only guarantee timing constraints but also consider energy consumption. Unfortunately, existing approaches to analyze the worst-case execution time (WCET) of a task usually cannot be directly applied to determine its worst-case energy consumption (WCEC) due to execution time and energy consumption not being closely correlated on many state-of-the-art processors. Instead, a WCEC analyzer must take into account the particular energy characteristics of a target platform. In this paper, we present 0g, a comprehensive approach to WCEC analysis that combines different techniques to speed up the analysis and to improve results. If detailed knowledge about the energy costs of instructions on the target platform is available, our tool is able to compute upper bounds for the WCEC by statically analyzing the program code. Otherwise, a novel approach allows 0g to determine the WCEC by measurement after having identified a set of suitable program inputs based on an auxiliary energy model, which specifies the energy consumption of instructions in relation to each other. Our experiments for three target platforms show that 0g provides precise WCEC estimates.
Peter Wägemann, Tobias Distler, Timo Hönig, Heiko Janker, Rüdiger Kapitza, Wolfgang Schröder-Preikschat
ECRTS1