VLDB 2026 Research / reviewers in the wild / expert
Peter Ulbrich
dblp:32/8549
· DBLP profile ↗
20ranked-venue papers
0as first author
8since 2021 · last 2026
0000-0002-4224-9205ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 5 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 1 since 2021Software engineering, systems software and programming languages · 4 · 2 since 2021Artificial intelligence and machine learning · 1Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | From Timing Budgets to WCETs: Robust SIL- and BSW-Aware Clustering and Allocation for Iterative Automotive Software DevelopmentabstractAutomotive ECUs integrate thousands of AUTOSAR runnables, substantial Basic Software (BSW), and heterogeneous multicore hardware. In iterative software-defined vehicle development, engineers must repeatedly revisit designs while maintaining stable runnable clustering and core allocations, which are expensive structural decisions. Beyond timing, Safety Integrity Levels (SILs), BSW overheads, and per-core memory strongly constrain these decisions, yet are rarely modeled jointly. This paper addresses these challenges through a chain-based analysis model that treats SIL constraints and BSW costs as first-class citizens, as well as an integrated toolchain that constructs job-level data-age constraints, forms SIL-compliant clusters, synthesizes multirate tasks, and maps application and BSW tasks to heterogeneous multicore platforms while checking timing and memory feasibility. A case study based on a real-world motion/drive controller from our industrial partner is described, which serves as the basis for our evaluation. The evaluations are conducted using synthetic systems that reflect the characteristics of the case study. Across 13,825 synthesized systems, SIL/BSW-aware clustering substantially reduces pessimism in analysis. In the industrial configuration, our approach yields a 7% decrease in utilization, demonstrating its practical value. A refinement study, which progressively replaces early budget assumptions with WCET samples, indicates that SIL/BSW-aware clustering preserves structural decisions better than less-informed variants under the same resampling setup. Tobias Denzinger, Matthias Becker 0004, Peter Ulbrich |
ECRTS | 3 |
| 2025 | Path Expressions Revisited - Towards Compiler-enforced Reusable Synchronization PatternsabstractPath expressions (PEs) offer a declarative way to specify synchronization constraints in concurrent programs, but have largely fallen out of favor due to concerns over limited expressiveness, runtime overhead, and poor integration with contemporary languages. In this work, we revisit PEs and argue for their renewed relevance as reusable synchronization patterns. We present a compiler-assisted approach that integrates PEs into C++ using AspectC++, enabling non-invasive synchronization of existing code. Our prototype demonstrates practical integration on a ring buffer and evaluates performance in a real-world concurrency scenario using MySQL's myisamchk utility. Results show that PE-based synchronization can be both expressive and efficient, performing comparably to traditional mechanisms in many cases. While challenges remain particularly around runtime adaptability and scaling under contention, our findings suggest that PEs deserve reconsideration as a practical tool for building reliable, maintainable concurrent software. Thomas Alexander Hövelmann, Olaf Spinczyk, Alexander Krause 0003, Horst Schirmeier, Peter Ulbrich |
PLOS@SOSP | 5 |
| 2025 | Dynamic Fuzzing-Based Whole-System Timing AnalysisabstractWorst-case timing analysis traditionally begins with estimating the worst-case execution time (WCET) of individual tasks using either static analysis or measurement-based techniques. To derive worst-case response times (WCRTs), engineers typically compose these WCETs with bounds on preemption and operating system overheads. However, WCRTs depend on complex system-level interactions, including task communication, OS behavior, and asynchronous events. Compositional analysis often overestimates, assuming that worst-case conditions across components coincide, admitting infeasible global control-flow paths. whole-system Static techniques refine this by modeling the system holistically but require platform-specific tailoring or extensive annotations. A dynamic equivalent has been missing. We present Fret, the first dynamic whole-system approach for estimating WCRTs. Fret employs feedback-guided fuzzing to uncover timing-critical dependencies, including inter-task communication, task/OS interactions, and interrupt effects, without requiring prior knowledge of inputs or states. Implemented using LibAFL and evaluated on FreeRTOS with realistic benchmarks, FRET consistently outperforms state-of-the-art fuzzing strategies in estimating accurate response times. Although not sound, Fret delivers more than timing estimates: it produces actionable artifacts-worst-case inputs, interrupt schedules, and intertask program-flow information-that complement static analyses and support system validation, runtime monitoring, and robust mixed-criticality scheduling. Alwin Berger, Simon Schuster, Peter Wägemann, Peter Ulbrich |
RTSS | 4 |
| 2025 | Wasm-IO: Enabling Low-Level Device Interaction in WebAssembly for Industry AutomationabstractCertification on a component level is highly beneficial in industrial automation because it allows for independent verification and updates without compromising the reliability of the overall system. Containerization technologies naturally address this demand by providing isolation between software modules. In particular, WebAssembly-based (Wasm) containerization is gaining popularity in industrial automation due to its inherent advantages, including cross-platform interoperability and secure execution of untrusted third-party code. However, Wasm’s strict sandboxing poses a significant limitation as it severely limits interaction with hardware devices, making it difficult to interface with sensors and actuators. This is a substantial barrier to adoption in industrial automation, where real-time and low-level hardware interactions are critical. To address this challenge, we present Wasm-IO , a framework designed to facilitate peripheral Input/Output (I/O) operations within WebAssembly (Wasm) containers. Wasm-IO allows the development of isolated device drivers in Wasm, explicitly moving hardware interaction to the container level. Our architectural approach facilitates containers with hardware interaction to be independently certified, updated, and maintained without adversely affecting each other. This article elucidates foundational methodologies and practical implementations supporting synchronous and asynchronous I/O operations and methods for embedding platform-independent peripheral configurations within Wasm binaries. Additionally, we present an extended priority model enabling interrupt handling in Wasm while maintaining temporal isolation. Our evaluation demonstrates that Wasm-IO significantly reduces latency and overhead compared to existing methods and traditional user-level driver implementations, effectively addressing certification and functional requirements critical to industrial automation systems. Maximilian Seidler, Alexander Krause 0003, Peter Ulbrich |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2023 | A New Perspective on Criticality: Efficient State Abstraction and Run-Time Monitoring of Mixed-Criticality Real-Time Control Systems
Tim Rheinfels, Maximilian Gaukler, Peter Ulbrich |
ECRTS | 3 |
| 2021 | Taming Non-Deterministic Low-Level I/O: Predictable Multi-Core Real-Time Systems by SoC Co-DesignabstractPredictable and analyzable I/O is one of the considerable challenges in the design of multi-core real-time systems. A common approach to tackle this issue is to partition and schedule I/O transactions such that interference between tasks is minimized. While this works for packet-oriented interfaces with deterministic blocking times, such as ethernet, these techniques are inapplicable to a whole range of I/O devices with nondeterministic behavior that is commonly found in embedded applications. Interfaces, such as SPI, do not allow for fine-grained scheduling and thus exhibit uncontrolled blocking times. Even worse, their configuration and use must be considered as independent transactions requiring costly synchronization between tasks. The resulting detrimental effects are, in particular, pronounced in settings with mixed task requirements on predictability and determinism. All this makes the temporal analysis of such systems cumbersome and overly pessimistic. To solve these issues, we present LOWI/O, an approach to eliminate the interference of low-level non-deterministic I/O interfaces for real-time tasks with high predictability demands (i.e., critical task) while preserving flexibility for tasks with lower requirements (i.e., uncritical tasks). Therefore, we leverage knowledge about the application-specific I/O usage patterns, obtained by static analysis, to derive a tailored hardware architecture. Its key feature is the anticipatory reservation of individual time slots for critical tasks and to mimic preemptivity of I/O units for the remaining system. We have implemented our approach as a toolchain for OSEK-based real-time systems that automatically generates an application-specific SoC design along with a hardware and timing model for subsequent WCET analysis. Our experimental results prove predictable timing for critical tasks with limited impact on uncritical tasks. Steffen Vaas, Peter Ulbrich, Christian Eichler, Peter Wägemann, Marc Reichenbach, Dietmar Fey |
ISORC | 2 |
| 2021 | Annotate once - analyze anywhere: context-aware WCET analysis by user-defined abstractionsabstractThe widespread adoption of cyber-physical systems in the safety-critical (hard real-time) domain is accompanied by a rising degree of code-reuse up to actual software product lines spanning different hardware platforms. Nevertheless, the dominant tools for static worst-case execution-time (WCET) analysis operate on individual, specific system instances at the binary level, further depending on machine-code–level annotations for precise analysis. Thus, this timing verification is neither portable nor reusable. Simon Schuster, Peter Wägemann, Peter Ulbrich, Wolfgang Schröder-Preikschat |
LCTES | 3 |
| 2021 | Constrained Data-Age with Job-Level Dependencies: How to Reconcile Tight Bounds and OverheadsabstractMany industrial real-time systems rely on the implicit register communication paradigm to minimize overheads and ease distributed development. Here, tasks follow a simple input-processing-output scheme, and data is passed without synchronization by the last-is-best semantics. In these systems, the age of data is the primary real-time objective, which is defined by data-flow chains that span from the system's inputs to outputs. Consequently, a real-time analysis aims to provide guarantees on worst-case data age. In general, there are two main approaches: (1) Task-level scheduling such that inter-task communication is arranged at the beginning and end of a task's execution interval, which guarantees a deterministic yet highly pessimistic data age. (2) Job-level dependencies (JLD) that are added at critical points in the schedule to link specific job instances of tasks of a multi-rate data-flow chain, which provides tighter upper bounds on data ages. However, the drawback is that JLDs induce substantial synchronization overheads, impact the overall schedulability, and are much more challenging to implement. In this paper, we address the trade-off between tight data-age guarantees, synchronization overheads, and schedulability in multi-core settings. Our proposed solution is to combine the potential of job-level optimization with the determinism and low overheads of static, task-level approaches. Therefore, we present a novel execution model to efficiently map data-age constrained tasksets with job-level dependencies on event-triggered systems by automated system analysis and transformation. Experimental results of an extensive real-world case study substantiate that our approach can further tighten data-age bounds, reduce overheads, and ease schedulability. Tobias Klaus, Matthias Becker 0004, Wolfgang Schröder-Preikschat, Peter Ulbrich |
RTAS | 4 |
| 2020 | Work In Progress: Control-Flow Migration for Data-Locality Optimisation in Multi-Core Real-Time SystemsabstractMulti-core real-time systems face the challenge of efficiently maintaining consistency of shared data despite concurrent operations. Existing synchronisation techniques ignore data locality, resulting in cache-related execution time overheads. This paper proposes Migration-Based Synchronisation (MBS), a transparent replacement for locks. In MBS, control flows are migrated to data, instead of moving data to control flows. The consequence is an improvement of data locality that reduces the worst-case execution time of critical sections, and indirectly, worst-case blocking bounds. Stefan Reif, Phillip Raffeck, Peter Ulbrich, Wolfgang Schröder-Preikschat |
RTSS | 3 |
| 2019 | Proving Real-Time Capability of Generic Operating Systems by System-Aware Timing AnalysisabstractThe static timing analysis of universal real-time operating systems (RTOS) with generically implemented services requires application and system-context-specific knowledge (e.g., number of currently active tasks) to bound overheads. However, due to the missing notion of OS semantics, contemporary timing analysis tools are unable to exploit such information, resulting in failing or overly pessimistic analysis. To tackle this issue, we present our System-wide WCET Analyses framework (SWAN). SWAN's heart is Platina, a parametric source-level annotation language that facilitates the expression and propagation of context information from the application over the OS down to the machine-code level. Through the expression of semantic interdependencies in a unified and reusable way, analysis pessimism is significantly reduced, as we demonstrate by case studies on FreeRTOS, Linux, and a real-world flight-control system. Just as important as our system-aware timing analysis is the tool support for its practical usability. Therefore, we augmented SWAN by a powerful interactive visualization and annotation environment. This enables developers to quickly identify context-dependent spots that require annotation and thus to cope with large implementations associated with universal RTOSs. Eventually, SWAN allows determining if a generically implemented system is real-time capable and thus timeliness is guaranteed. Simon Schuster, Peter Wägemann, Peter Ulbrich, Wolfgang Schröder-Preikschat |
RTAS | 3 |
| 2019 | Work-in-Progress: Migration Hints in Real-Time Operating SystemsabstractTask migration is a potent instrument to exploit multi-core processors. Like full preemption, full migration is particularly advantageous as it allows the scheduler to relocate tasks at arbitrary times between cores. However, in hard real-time systems, migration is accompanied by a tremendous drawback: poor predictability and thus inevitable overapproximations in the worst-case execution-time analysis. This is due to the non-constant size of the tasks' resident set and the costs associated with its transfer between cores. As a result, migration is banned in many real-time systems, regressing the developer to a static allocation of tasks to cores with disadvantageous effects on the overall utilization and schedulability. In previous work, we successfully alleviated the shortcomings of full migration in real-time systems by reducing the associated costs and increasing its predictability. By employing static analysis, we were able to identify beneficial migration points and thus generate static schedules migrating tasks at these identified points. In ongoing work, we extend this approach to dynamic scheduling by providing information about advantageous migration points to an operating system which then makes migration decisions at runtime. Phillip Raffeck, Peter Ulbrich, Wolfgang Schröder-Preikschat |
RTSS | 2 |
| 2018 | Whole-System Worst-Case Energy-Consumption Analysis for Energy-Constrained Real-Time SystemsabstractAlthough internal devices (e.g., memory, timers) and external devices (e.g., transceivers, sensors) significantly contribute to the energy consumption of an embedded real-time system, their impact on the worst-case response energy consumption (WCRE) of tasks is usually not adequately taken into account. Most WCRE analysis techniques, for example, only focus on the processor and therefore do not consider the energy consumption of other hardware units. Apart from that, the typical approach for dealing with devices is to assume that all of them are always activated, which leads to high WCRE overestimations in the general case where a system switches off the devices that are currently not needed in order to minimize energy consumption. In this paper, we present SysWCEC, an approach that addresses these problems by enabling static WCRE analysis for entire real-time systems, including internal as well as external devices. For this purpose, SysWCEC introduces a novel abstraction, the power-state-transition graph, which contains information about the worst-case energy consumption of all possible execution paths. To construct the graph, SysWCEC decomposes the analyzed real-time system into blocks during which the set of active devices in the system does not change and is consequently able to precisely handle devices being dynamically activated or deactivated. Peter Wägemann, Christian Dietrich 0001, Tobias Distler, Peter Ulbrich, Wolfgang Schröder-Preikschat |
ECRTS | 4 |
| 2018 | A New Perspective on Quality Evaluation for Control Systems with Stochastic TimingabstractAs control applications are particularly sensitive to timing variations, the Quality of Control (QoC) is degraded by varying execution conditions of the underlying real-time system. In particular, transitions between different execution or environmental conditions pose a significant issue as they may impact the QoC unexpectedly. Maximilian Gaukler, Andreas Michalka, Peter Ulbrich, Tobias Klaus |
HSCC | 3 |
| 2017 | SysWCET: Whole-System Response-Time Analysis for Fixed-Priority Real-Time Systems (Outstanding Paper)abstractThe worst-case response time (WCRT) – the time span from release to completion of a real-time task – is a crucial property of real-time systems. However, WCRT analysis is complex in practice, as it depends not only on the realistic examination of worst-case execution times (WCET), but also on system-level overheads and blocking/preemption times. While the implicit path enumeration technique (IPET) has greatly improved automated WCET analysis, the resulting values still need to be aggregated manually with the system-level overheads – an errorprone and tedious process that yields overly pessimistic results. With SysWCET, we provide an integrated approach for the automated WCRT analysis across multiple threads of execution, locks, interrupt service routines, and the real-time operating system (RTOS) in particular. Our approach spans a single IPET formulation over the whole system and exploits RTOS and scheduler semantics to derive cross-kernel flow facts in order to significantly reduce pessimism in the WCRT analysis. We evaluate our approach with a fully functional implementation of SysWCET for the automotive OSEK-OS standard (ECC1), including threads, alarms, interrupt-service routines, events, and PCP-based resource management. Christian Dietrich 0001, Peter Wägemann, Peter Ulbrich, Daniel Lohmann |
RTAS | 3 |
| 2017 | Demystifying Soft-Error Mitigation by Control-Flow Checking - A New Perspective on its EffectivenessabstractSoft errors are a challenging and urging problem in the domain of safety-critical embedded systems. For decades, checking schemes have been investigated and improved to mitigate soft-error effects for the class of control-flow faults, with current industrial standards strongly recommending their use. However, reality looks different: Taking a systems perspective, we implemented four representative Control-Flow Checking (CFC) schemes and put them through their paces in 396 fault-injection campaigns. In contrast to previous work, which typically relied on probability-based vulnerability metrics, we accounted for the influence of memory and time overheads on the fault-space dimensions and applied those in full-scan fault injections. This change in procedure alone severely degraded the perceived effectiveness of CFC. In addition, we expanded the perspective to data-flow faults and their influence on the overall susceptibility, an aspect that so far has been largely ignored. Our results suggest that, without accompanying measures, any improvement regarding control-flow faults is dominated by the increase in data faults caused by the increased attack surface in terms of memory and runtime overhead. Moreover, CFC performance less depended on the detection capabilities than on general aspects of the concrete binary compilation and execution. In conclusion, incorporating CFC is not as straightforward as often assumed and the vulnerability of systems with hardened control-flow may in many cases even be increased by the schemes themselves. Simon Schuster, Peter Ulbrich, Isabella Stilkerich, Christian Dietrich 0001, Wolfgang Schröder-Preikschat |
ACM Trans. Embed. Comput. Syst. | 2 |
| 2016 | From Intent to Effect: Tool-Based Generation of Time-Triggered Real-Time Systems on Multi-core ProcessorsabstractAlthough the manual creation of time-triggered schedules for multi-core real-time systems can be a daunting task, state-of-the-art scheduling algorithms are far from being widely used. This suggests that the availability of sound algorithms is only one side of the story: real-time systems have to be groomed substantially before they can serve as input to available algorithms. Moreover, systems engineers struggle with the temporal effects of their design decisions, in addition to the intended timing properties. Therefore, we believe that appropriate tools are the other side of the story. In this paper, we present the multicore extension of the Real-Time Systems Compiler, a compiler-based tool that analyses given event-triggered real-time systems and transforms them into time-triggered equivalents. We focus on the challenges and pitfalls in the transition from theory to practical implementation and present concrete solutions to resolve them. Existing algorithms need to be adapted for performance and, at model level, bound together appropriately to be applicable, for example. Our experiments substantiate the effectiveness and scalability of our approach, even for large tasks sets. Finally, lessons learned give an insight into implementation and hardware details and their impact on schedulability. Florian Franzmann, Tobias Klaus, Peter Ulbrich, Patrick Deinhardt, Benjamin Steffes, Fabian Scheler, Wolfgang Schröder-Preikschat |
ISORC | 3 |
| 2016 | Closing the loop: towards control-aware design of adaptive real-time systemsabstractThis paper proposes a continuous toolchain from the original control system model to the resulting schedules. As a first step towards control-aware yet adaptive system design, we focused on a global, context-sensitive analysis of control and data flow across control-application layers and threads of execution. This step is of vital importance as these dependencies manifest differently on the various levels of abstraction. Consequently, we extract semantics and internal dependencies directly from control-system models by an extended version of the Real-Time Systems Compiler (RTSC), which is capable of analyzing and transforming real-time applications on the source code level. Tobias Klaus, Florian Franzmann, Maximilian Gaukler, Andreas Michalka, Peter Ulbrich |
RTSS | 5 |
| 2016 | Experiences with software-based soft-error mitigation using AN codes
Martin Hoffmann 0001, Peter Ulbrich, Christian Dietrich 0001, Horst Schirmeier, Daniel Lohmann, Wolfgang Schröder-Preikschat |
Softw. Qual. J. | 2 |
| 2011 | Escaping the Bonds of the Legacy: Step-Wise Migration to a Type-Safe Language in Safety-Critical Embedded SystemsabstractType-safe high-level languages such as Java have not yet found their way into the domain of deeply embedded systems, even though numerous attempts have been made to make these languages cost attractive. One major challenge that remains is the huge existing code base in many industries. Completely reengineering this code base is not viable for cost and time reasons. We present an approach that allows to isolatedly combine legacy software components and safe software components in an embedded system using the two most common communication idioms found in this domain. Our approach allows the developer to freely choose between hardware- and software-based isolation mechanisms. We demonstrate the feasibility of our approach by porting a non-trivial part of a real-world, hard real-time embedded avionics application. Our results show that the cost of this mixed-mode operation is on the same scale as the pure operation. Michael Stilkerich, Jens Schedel, Peter Ulbrich, Wolfgang Schröder-Preikschat, Daniel Lohmann |
ISORC | 3 |
| 2010 | Consistent Product Line Configuration across File Type and Product Line Boundaries
Christoph Elsner, Peter Ulbrich, Daniel Lohmann, Wolfgang Schröder-Preikschat |
SPLC | 2 |