Irune Agirre

dblp:170/0377 · DBLP profile ↗
← Back
15ranked-venue papers
4as first author
8since 2021 · last 2026
0000-0002-9507-8841ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 12 · 3 first-author · 7 since 2021Software engineering, systems software and programming languages · 3 · 2 since 2021Security and privacy · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 ROSBand: A Bandwidth Regulation Approach on ROS2-Based Systems
Jon Altonaga Puente, Enrico Mezzetti, Irune Agirre, Jaume Abella 0001, Francisco J. Cazorla
RTAS3
2025 SAFEXPLAIN: a Complete Approach Towards Trustworthy AI-Based Safety-Critical Systems
abstract
AI becomes increasingly important in safetycritical systems, especially in the case of autonomous systems, since navigation relies on AI for object detection and collision avoidance. However, safety-critical systems must adhere to functional safety standards that enforce software to be correct-by-construction, component decomposition to simplify design and validation, and the use of data only for testing purposes not to design the system itself. AI in general, and Deep Learning (DL) in particular have opposed characteristics since they have error rates (e.g., due to mispredictions), AI/DL modules can only be designed and validated monolithically, and they build on data for their design (i.e. for training purposes). Hence, DL solutions are at odds with the development process of safetycritical systems. A number of standards have recently emerged in different domains to reconcile the requirements of safety-critical systems with the characteristics of DL solutions, such as ISO 21448, ISO/IEC TR 5469, and ISO 8800, among others. However, there is a lack of realistic practice to design a DL-based safety-critical system in accordance with those regulations, and existing solutions only cover some aspects in isolation, and are often incompatible among them. SAFEXPLAIN is a 3-year Horizon Europe project addressing this challenge. SAFEXPLAIN, which finishes in September 2025, has already reached its main goals providing specific and complementary solutions to all those challenges so that AIbased safety-critical systems can be designed, implemented and validated adhering to the relevant functional safety standards in domains such as automotive, space and railway. In particular, SAFEXPLAIN provides the concepts, processes, tools and frameworks addressing the challenge end-to-end, from concept to solution. This is proven by the successful application of the SAFEXPLAIN approach in three case studies from the automotive, space and railway domains, whose results will see the light very soon.
Jaume Abella 0001, Irune Agirre, Thanh Hai Bui, Frank Geujen, Gabriele Giordana, Carlo Donzella, Francisco J. Cazorla, Enrico Mezzetti, Axel Brando, Javier Fernández 0004, Irune Yarza, Joanes Plazaola, Maria Ulan, Rob Lavreysen, Lucas Tosi, Ilaria Bloise, Lorenzo Feruglio, Ilaria Cinelli, Stefano Lodico, William Guarienti, Giuseppe Nicosia, Valeria Dallara
DSD2
2025 Towards a Safe End-to-End AI framework: MISRA C-Compliant YOLO for Object Detection
abstract
Artificial Intelligence (AI) has traditionally prioritized high performance over compliance with functional safety standards such as IEC 61508. However, when AI systems are used in safety-related functions, it is essential to demonstrate that errors will not lead to malfunctions. This involves preventing systematic design-time errors and detecting and controlling runtime faults, as specified in IEC 61508. Moreover, ISO/PAS 8800 requires analyzing AI-specific development tools to identify and mitigate potential risks. In this paper, we take a step toward a safe end-to-end AI framework by focusing on systematic error avoidance in the implementation of You Only Look Once (YOLO), a widely used object detection model. A C-based version of YOLO-built on the Darknet framework-is analyzed using the Polyspace static analysis tool to assess MISRA C compliance. We apply corrective actions to eliminate violations, producing a MISRA $\mathbf{C}$-compliant implementation. In addition, we propose a runtime error detection mechanism using dual execution on a diverse platform and validate behavioral consistency using the COCO dataset. This approach supports the development of trustworthy AI systems by addressing both systematic errors and runtime detection.
Javier Fernández 0004, Irune Agirre, Irune Yarza, Jon Pérez 0001
DSD2
2023 SAFEXPLAIN: Safe and Explainable Critical Embedded Systems Based on AI
abstract
Deep Learning (DL) techniques are at the heart of most future advanced software functions in Critical Autonomous AI-based Systems (CAIS), where they also represent a major competitive factor. Hence, the economic success of CAIS industries (e.g., automotive, space, railway) depends on their ability to design, implement, qualify, and certify DL-based software products under bounded effort/cost. However, there is a fundamental gap between Functional Safety (FUSA) requirements on CAIS and the nature of DL solutions. This gap stems from the development process of DL libraries and affects high-level safety concepts such as (1) explainability and traceability, (2) suitability for varying safety requirements, (3) FUSA-compliant implementations, and (4) real-time constraints. As a matter of fact, the data-dependent and stochastic nature of DL algorithms clashes with current FUSA practice, which instead builds on deterministic, verifiable, and pass/fail test-based software. The SAFEXPLAIN project tackles these challenges and targets by providing a flexible approach to allow the certification - hence adoption - of DL-based solutions in CAIS building on: (1) DL solutions that provide end-to-end traceability, with specific approaches to explain whether predictions can be trusted and strategies to reach (and prove) correct operation, in accordance to certification standards; (2) alternative and increasingly sophisticated design safety patterns for DL with varying criticality and fault tolerance requirements; (3) DL library implementations that adhere to safety requirements; and (4) computing platform configurations, to regain determinism, and probabilistic timing analyses, to handle the remaining non-determinism.
Jaume Abella 0001, Jon Pérez 0001, Cristofer Englund, Bahram Zonooz, Gabriele Giordana, Carlo Donzella, Francisco J. Cazorla, Enrico Mezzetti, Isabel Serra, Axel Brando, Irune Agirre, Fernando Eizaguirre, Thanh Hai Bui, Elahe Arani, Fahad Sarfraz, Ajay Balasubramaniam, Ahmed Badar, Ilaria Bloise, Lorenzo Feruglio, Ilaria Cinelli, Davide Brighenti, Davide Cunial
DATE11
2023 UP2DATE software updating framework compliance with safety and security regulations and standards
abstract
Over-the-air Software Updates (OTASU) in the critical domain are already a reality. OTASU provide huge benefits in terms of user experience, security, and efficiency. However, due to involved risks, safety and security mechanisms and new regulations are needed for their adoption in the critical domain. The automotive industry is already in the race to adopt safe and secure OTASU, as by 2024, compliance to new UN regulations will become compulsory. However, the standards providing the specifications and requirements for OTASU are still in their infancy. Many other dependable system domains, that are now more digital and connected than ever, are following same trends towards OTASU. For instance, OTASU are very likely to be adopted in the railway domain in a near future, as the ability of remotely updating railway equipment considerably reduces maintenance costs and time, improving system availability. This paper describes how the UP2DATE framework adheres to existing and emerging regulations and standards and evaluates them through a railway case-study. Obtained results demonstrate that the proposed updating framework can provide great savings in the installation and maintenance phases of railway signalling devices by reducing the time required for the update and by removing the need for operator presence on-site.
Irune Agirre, Alejandro J. Calderón, Irune Yarza, Imanol Mugarza, David García Villaescusa, Lucas Borracci, Patrick Uven, Alvaro Jover-Alvarez
DSD1
2023 Software Updates Monitoring & Anomaly Detection
Imanol Etxezarreta, David García Villaescusa, Imanol Mugarza, Irune Yarza, Irune Agirre
IoTBDS5
2021 The UP2DATE Baseline Research Platforms
abstract
The UP2DATE H2020 project focuses on highperformance heterogeneous embedded platforms for critical systems. We will develop observability and controllability solutions to support online updates while ensuring safety and security for mixed-criticality tasks. In this paper, we describe the rationale behind the selection of the baseline research platforms which will be used to develop and demonstrate the project concepts, including a performance comparison to identify the most efficient one.
Alvaro Jover-Alvarez, Alejandro J. Calderón, Iván Rodriguez, Leonidas Kosmidis, Kazi Asifuzzaman, Patrick Uven, Kim Grüttner, Tomaso Poggi, Irune Agirre
DATE9
2021 Towards functional safety compliance of matrix-matrix multiplication for machine learning-based autonomous systems
Javier Fernández 0004, Jon Pérez 0001, Irune Agirre, Imanol Allende, Jaume Abella 0001, Francisco J. Cazorla
J. Syst. Archit.3
2020 UP2DATE: Safe and secure over-the-air software updates on high-performance mixed-criticality systems
abstract
Following the same trend of consumer electronics, safety-critical industries are starting to adopt Over-The-Air Software Updates (OTASU) on their embedded systems. The motivation behind this trend is twofold. On the one hand, OTASU offer several benefits to the product makers and users by improving or adding new functionality and services to the product without a complete redesign. On the other hand, the increasing connectivity trend makes OTASU a crucial cyber-security demand to download latest security patches. However, the application of OTASU in the safety-critical domain is not free of challenges, specially when considering the dramatic increase of software complexity and the resulting high computing performance demands. This is the mission of UP2DATE, a recently launched project funded within the European H2020 programme focused on new software update architectures for heterogeneous high-performance mixed-criticality systems. This paper gives an overview of UP2DATE and its foundations, which seeks to improve existing OTASU solutions by considering safety, security and availability from the ground up in an architecture that builds around composability and modularity.
Irune Agirre, Peio Onaindia, Tomaso Poggi, Irune Yarza, Francisco J. Cazorla, Leonidas Kosmidis, Kim Grüttner, Mohammed Abuteir, Jan Loewe, Juan M. Orbegozo, Stefania Botta
DSD1
2018 Fitting Software Execution-Time Exceedance into a Residual Random Fault in ISO-26262
abstract
Car manufacturers relentlessly replace or augment the functionality of mechanical subsystems with electronic components. Most such subsystems (e.g., steer-by-wire) are safety related, hence, subject to regulation. ISO-26262, the dominant standard for road vehicles, regards software faults as systematic, while differentiating hardware faults between systematic and random. The analysis of systematic faults entails rigorous processes and qualitative considerations. The increasing complexity of modern on-board computers, however, questions the very notion of treating the violation of execution-time envelopes for software programs as a systematic fault. Modern hardware in fact reduces the user's ability to delve deep enough into the fabric of hardware-software interaction to gage its extent of contribution to the worst-case execution time (WCET). Changing the nature of the WCET-analysis problem may help address that challenge effectively. To this end, we propose a solution that should allow ISO-26262 to quantify the likelihood of execution-time exceedance events, relating it to target failure metrics employed in support of certification arguments, similarly to random faults in hardware. To this end, we inject randomization in the timing behavior of the computer hardware to relieve the user from the need to control hard-to-reach low-level parts, and use measurement-based probabilistic timing analysis to quantify, constructively, the failure rates resulting from the likelihood of execution-time exceedance events.
Irune Agirre, Francisco J. Cazorla, Jaume Abella 0001, Carles Hernández 0001, Enrico Mezzetti, Mikel Azkarate-askatsua, Tullio Vardanega
IEEE Trans. Reliab.1
2017 EPC Enacted: Integration in an Industrial Toolbox and Use against a Railway Application
abstract
Measurement-based timing analysis approaches are increasingly making their way into several industrial domains on account of their good cost-benefit ratio. The trustworthiness of those methods, however, suffers from the limitation that their results are only valid for the particular paths and execution conditions that the user is able to explore with the available input vectors. It is generally not possible to guarantee that the collected measurements are fully representative of the worst-case timing behaviour. In the context of measurement-based probabilistic timing analysis, the Extended Path Coverage (EPC) approach has been recently proposed as a means to extend the representativeness of measurement observations, to obtain the same effect of full path coverage. At the time of its first publication, EPC had not reached an implementation maturity that could be trialled industrially. In this work we analyze the practical implications of using EPC with real-world applications, and discuss the challenges in integrating it in an industrial-quality toolchain. We show that we were able to meet EPC requirements and successfully evaluate the technique on a real Railway application, on top of a commercial toolchain and full execution stack.
Enrico Mezzetti, Mikel Fernández, Alen Bardizbanyan, Irune Agirre, Jaume Abella 0001, Tullio Vardanega, Francisco J. Cazorla
RTAS4
2016 PROXIMA: Improving Measurement-Based Timing Analysis through Randomisation and Probabilistic Analysis
abstract
The use of increasingly complex hardware and software platforms in response to the ever rising performance demands of modern real-time systems complicates the verification and validation of their timing behaviour, which form a time-and-effort-intensive step of system qualification or certification. In this paper we relate the current state of practice in measurement-based timing analysis, the predominant choice for industrial developers, to the proceedings of the PROXIMA (Probabilistic real-time control of mixed-criticality multicore systems) project in that very field. We recall the difficulties that the shift towards more complex computing platforms causes in that regard. Then we discuss the probabilistic approach proposed by PROXIMA to overcome some of those limitations. We present the main principles behind the PROXIMA approach as well as the changes it requires at hardware or software level underneath the application. We also present the current status of the project against its overall goals, and highlight some of the principal confidence-building results achieved so far.
Francisco J. Cazorla, Jaume Abella 0001, Jan Andersson, Tullio Vardanega, Francis Vatrinet, Iain Bate, Ian Broster, Mikel Azkarate-askatsua, Franck Wartel, Liliana Cucu-Grosjean, Fabrice Cros, Glenn Farrall, Adriana Gogonel, Andrea Gianarro, Benoit Triquet, Carles Hernández 0001, Code Lo, Cristian Maxim, David Morales, Eduardo Quiñones, Enrico Mezzetti, Leonidas Kosmidis, Irune Agirre, Mikel Fernández, Mladen Slijepcevic, Philippa Conmy, Walid Talaboulma
DSD23
2015 IEC-61508 SIL 3 Compliant Pseudo-Random Number Generators for Probabilistic Timing Analysis
abstract
Probabilistic Timing Analysis (PTA), especially its measurement based variant (MBPTA), has shown to be competitive with state-of-the-art timing analysis techniques. The use of MBPTA to analyse the timing behaviour of safety-critical systems rests on its ability to derive trustworthy WCET bounds. This ability depends on the soundness of the MBPTA method per se, as well as on the satisfaction of safety requirements placed on the pseudo-random number generator (prng) that plays a key role in the platform-level randomisation needed by MBPTA. This paper presents the design of a low-area, low-power prng that meets IEC-61508 SIL 3 safety requirements and allows for seamless integration in a real-world multicore architecture. This work enables the development and the IEC-61508 certification of mixed-criticality systems that use MBPTA for deriving timing bounds for mixed-criticality software programs running on multicore processors.
Irune Agirre, Mikel Azkarate-askatsua, Carles Hernández 0001, Jaume Abella 0001, Jon Pérez 0001, Tullio Vardanega, Francisco J. Cazorla
DSD1
2015 A Modular Safety Case for an IEC-61508 Compliant Generic Hypervisor
abstract
The development of mixed-criticality systems that integrate several functionalities of different criticality levels (e.g., SIL1-4 according to IEC-1508) on the same embedded computing platform provide benefit in terms of cost, size, weight, reliability and scalability. The soaring demand for high performance mixedcriticality system has contributed to their capabilities expansion. This upward trend is subject to certification processes with different levels of rigorousness, which lead to prohibitive cost. This paper presents the modular safety concept of an IEC-61508 generic hypervisor where the minimum reasonable safety arguments and evidences are defined. Additionally, the use of the modularity approach limits the impact of changes to a reduced area of the safety case, enabling in turn the reusability of the safety cases parts. The work described in this paper has been reviewed and approved by a certification body, within the context of a European research project.
Asier Larrucea, Jon Pérez 0001, Irune Agirre, Vicent Brocal, Roman Obermaisser
DSD3
2015 Temporal independence validation of an IEC-61508 compliant mixed-criticality system based on multicore partitioning
abstract
The transition from conventional federated embedded system architectures to mixed-criticality integrated multicore architectures provides benefits in terms of cost, size, weight, scalability and reliability. As a consequence, integrated mixedcriticality solutions are an objective for many embedded systems developers, although the challenges related with the safety certification of multicore approaches may hinder their adoption. Among many other stringent requirements, the safety standards demand to prove that the mixed-criticality systems are free of interferences, thus ensuring the spatial and temporal interdependence among applications. This paper contributes with a measured based temporal independence validation of a partitioned multicore mixed-criticality system.
Asier Larrucea, Irune Agirre, Carlos F. Nicolás, Jon Pérez 0001, Mikel Azkarate-askatsua, Ton Trapman
FDL2