VLDB 2026 Research / reviewers in the wild / expert
Chih-Hong Cheng
dblp:64/3701
· DBLP profile ↗
52ranked-venue papers
30as first author
24since 2021 · last 2026
0000-0002-7265-8413ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 31 · 24 first-author · 10 since 2021Systems, architecture and hardware · 17 · 7 first-author · 10 since 2021Artificial intelligence and machine learning · 15 · 3 first-author · 12 since 2021Theory of computation · 7 · 6 first-authorSecurity and privacy · 4 · 2 first-author · 3 since 2021Computer networks · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Quantifying Fidelity: A Decisive Feature Approach to Comparing Synthetic and Real ImageryabstractVirtual testing using synthetic data has become a cornerstone of autonomous vehicle (AV) safety assurance. Despite progress in improving visual realism through advanced simulators and generative AI, recent studies reveal that pixel-level fidelity alone does not ensure reliable transfer from simulation to the real world. What truly matters is whether the system-under-test (SUT) bases its decisions on consistent decision evidence in both real and simulated environments, not just whether images "look real" to humans. To this end this paper proposes a behavior-grounded fidelity measure by introducing Decisive Feature Fidelity (DFF), a new SUT-specific metric that extends the existing fidelity spectrum to capture mechanism parity, that is, agreement in the model-specific decisive evidence that drives the SUT's decisions across domains. DFF leverages explainable-AI methods to identify and compare the decisive features driving the SUT's outputs for matched real-synthetic pairs. We further propose estimators based on counterfactual explanations, along with a DFF-guided calibration scheme to enhance simulator fidelity. Experiments on 2126 matched KITTI-VirtualKITTI2 pairs demonstrate that DFF reveals discrepancies overlooked by conventional output-value fidelity. Furthermore, results show that DFF-guided calibration improves decisive-feature and input-level fidelity without sacrificing output value fidelity across diverse SUTs. Danial Safaei, Siddartha Khastgir, Mohsen Alirezaei, Jeroen Ploeg, Chih-Hong Cheng, Son Tong, Xingyu Zhao 0001 |
IV | 5 |
| 2026 | Revisiting Out-of-Distribution Detection in Real-Time Object Detection: From Benchmark Pitfalls to a New Mitigation ParadigmabstractOut-of-distribution (OoD) inputs pose a persistent challenge to deep learning models, often triggering overconfident predictions on non-target objects. While prior work has primarily focused on refining scoring functions and adjusting test-time thresholds, such algorithmic improvements offer only incremental gains. We argue that a rethinking of the entire development lifecycle is needed to mitigate these risks effectively. This work addresses two overlooked dimensions of OoD detection in object detection. First, we reveal fundamental flaws in widely used evaluation benchmarks: contrary to their design intent, up to 13% of objects in the OoD test sets actually belong to in-distribution classes, and vice versa. These quality issues severely distort the reported performance of existing methods and contribute to their high false positive rates. Second, we introduce a novel training-time mitigation paradigm that operates independently of external OoD detectors. Instead of relying solely on post-hoc scoring, we fine-tune the detector using a carefully synthesized OoD dataset that semantically resembles in-distribution objects. This process shapes a defensive decision boundary by suppressing objectness on OoD objects, leading to a 91% reduction in hallucination error of a YOLO model on BDD-100 K. Our methodology generalizes across detection paradigms such as YOLO, Faster R-CNN, and RT-DETR, and supports few-shot adaptation. Together, these contributions offer a principled and effective way to reduce OoD-induced hallucination in object detectors. Changshun Wu, Weicheng He, Chih-Hong Cheng, Xiaowei Huang 0001, Saddek Bensalem |
IEEE Trans. Pattern Anal. Mach. Intell. | 3 |
| 2026 | Runtime Monitoring Abnormalities in Object Detection With Spatial and Temporal AbstractionsabstractABSTRACT Background Object detection modules are essential functionalities for any autonomous vehicle. However, the performance of such modules implemented using deep neural networks can be unreliable in many cases, which raises the necessity to filter the abnormal outputs for safety considerations. Aims This article aims to develop a logical framework for filtering potentially erroneous object detection results. Materials & Methods Concretely, we consider two types of abstraction, namely spatial abstraction and temporal abstraction, based on the data labels from the training dataset of object detectors, and temporal consistency between a sequence of images. Operated on the training dataset, the construction of spatial abstraction iterates each input, aggregates region‐wise information over its associated labels, and stores the object abstraction. The abstraction is adopted to filter static and spatial abnormalities. The temporal abstraction builds an abstract transformer for a relaxed tracking algorithm. Elements being associated together by the abstract transformer can be checked against consistency over their original values. The abstraction helps to monitor temporal abnormality in consecutive frames. We have implemented the overall framework and validated it using publicly available datasets and open‐source object detectors. Results The implemented framework successfully identified most of static/spatial and temporal abnormalities in object detection outputs. Validation on public datasets confirmed the effectiveness of the abstraction‐based approach in filtering unreliable detections. Discussion The results demonstrate that logical abstractions derived from training data labels and temporal sequences provide a viable mechanism for monitoring the reliability of deep neural network‐based object detectors. Conclusion Abstraction‐based monitoring presents a robust and logical framework for enhancing the reliability of object detectors by filtering abnormal detection results. Rongjie Yan, Chengye Li, Chih-Hong Cheng |
Softw. Pract. Exp. | 4 |
| 2025 | Randomized Smoothing Meets Vision-Language ModelsabstractRandomized smoothing (RS) is one of the prominent techniques to ensure the correctness of machine learning models, where point-wise robustness certificates can be derived analytically.While RS is well understood for classification, its application to generative models is unclear, since their outputs are sequences rather than labels.We resolve this by connecting generative outputs to an oracle classification task and showing that RS can still be enabled: the final response can be classified as a discrete action (e.g., service-robot commands in VLAs), as harmful vs. harmless (content moderation or toxicity detection in VLMs), or even applying oracles to cluster answers into semantically equivalent ones.Provided that the error rate for the oracle classifier comparison is bounded, we develop the theory that associates the number of samples with the corresponding robustness radius.We further derive improved scaling laws analytically relating the certified radius and accuracy to the number of samples, showing that the earlier result of 2 to 3 orders of magnitude fewer samples sufficing with minimal loss remains valid even under weaker assumptions.Together, these advances make robustness certification both well-defined and computationally feasible for state-of-the-art VLMs, as validated against recent jailbreak-style adversarial attacks. Emmanouil Seferis, Changshun Wu, Stefanos Kollias, Saddek Bensalem, Chih-Hong Cheng |
EMNLP | 5 |
| 2025 | Rethinking Code Review Workflows with LLM Assistance: An Empirical StudyabstractBackground: Code reviews are a critical yet timeconsuming aspect of modern software development, increasingly challenged by growing system complexity and the demand for faster delivery. Aims: We examine how large language models (LLMs) can support code reviews by addressing common inefficiencies and contextual gaps. Method: At WirelessCar Sweden$A B$, we conducted an exploratory field study to identify current challenges, followed by a field experiment with two LLM-assisted review prototypes: one providing upfront, AIgenerated reviews and another enabling on-demand interaction. Both used a retrieval-augmented generation pipeline to assemble relevant contextual information. Results: The field study revealed frequent context switching, insufficient contextual information, and concerns around false positives. In practice, developers generally preferred the AI-led approach, especially for large or unfamiliar pull requests, though preferences varied with codebase familiarity and review risk. Conclusions: LLM-assisted reviews can reduce cognitive load and improve comprehension, with hybrid proactive/on-demand designs best balancing efficiency, trust, and reviewer control. Fannar Steinn Aðalsteinsson, Björn Borgar Magnússon, Mislav Milicevic, Adam Nirving Davidsson, Chih-Hong Cheng |
ESEM | 5 |
| 2025 | FuzzRisk: Online Collision Risk Estimation for Autonomous Vehicles Based on Depth-Aware Object Detection via Fuzzy InferenceabstractThis paper presents a novel monitoring framework that infers the level of collision risk for autonomous vehicles (AV s) based on their object detection performance. The framework takes two sets of predictions from different algorithms and associates their inconsistencies with the collision risk via fuzzy inference. The first set of predictions is obtained by retrieving safety-critical 2.5D objects from a depth map, and the second set comes from the ordinary AV's 3D object detector. We experimentally validate that, based on Intersection-over-Union (IoU) and a depth discrepancy measure, the inconsis-tencies between the two sets of predictions strongly correlate to the error of the 3D object detector against ground truths. This correlation allows us to construct a fuzzy inference system and map the inconsistency measures to an AV collision risk indicator. In particular, we optimize the fuzzy inference system towards an existing offline metric that matches AV collision rates well. Lastly, we validate our monitor's capability to produce relevant risk estimates with the large-scale nuScenes dataset and demonstrate that it can safeguard an AV in closed-loop simulations. Brian Hsuan-Cheng Liao, Chih-Hong Cheng, Hasan Esen, Alois C. Knoll |
ICRA | 3 |
| 2025 | Mitigating Hallucinations in YOLO-based Object Detection Models: A Revisit to Out-of-Distribution DetectionabstractObject detection systems must reliably perceive objects of interest without being overly confident to ensure safe decision-making in dynamic environments. Filtering techniques based on out-of-distribution (OoD) detection are commonly added as an extra safeguard to filter hallucinations caused by overconfidence in novel objects. Nevertheless, evaluating YOLO-family detectors and their filters under existing OoD benchmarks often leads to unsatisfactory performance. This paper studies the underlying reasons for performance bottlenecks and proposes a methodology to improve performance fundamentally. Our first contribution is a calibration of all existing evaluation results: Although images in existing OoD benchmark datasets are claimed not to have objects within in-distribution (ID) classes (i.e., categories defined in the training dataset), around 13% of objects detected by the object detector are actually ID objects. Dually, the ID dataset containing OoD objects can also negatively impact the decision boundary of filters. These ultimately lead to a significantly imprecise performance estimation. Our second contribution is to consider the task of hallucination reduction as a joint pipeline of detectors and filters. By developing a methodology to carefully synthesize an OoD dataset that semantically resembles the objects to be detected, and using the crafted OoD dataset in the fine-tuning of YOLO detectors to suppress the objectness score, we achieve a 88% reduction in overall hallucination error with a combined fine-tuned detection and filtering system on the self-driving benchmark BDD-100K. Our code and dataset are available at: https://gricad-gitlab.univ-grenoble-alpes.fr/dnn-safety/m-hood. Weicheng He, Changshun Wu, Chih-Hong Cheng, Xiaowei Huang 0001, Saddek Bensalem |
IROS | 3 |
| 2025 | Runtime Monitoring and Enforcement of Conditional Fairness in Generative AIs
Chih-Hong Cheng, Changshun Wu, Xingyu Zhao 0001, Saddek Bensalem, Harald Ruess |
RV | 1 |
| 2024 | Estimating the Robustness Radius for Randomized Smoothing with 100× Sample EfficiencyabstractRandomized smoothing (RS) has successfully been used to improve the robustness of predictions for deep neural networks (DNNs) by adding random noise to create multiple variations of an input, followed by deciding the consensus. To understand if an RS-enabled DNN is effective in the sampled input domains, it is mandatory to sample data points within the operational design domain, acquire the point-wise certificate regarding robustness radius, and compare it with pre-defined acceptance criteria. Consequently, ensuring that a point-wise robustness certificate for any given data point is obtained relatively cost-effectively is crucial. This work demonstrates that reducing the number of samples by one or two orders of magnitude can still enable the computation of a slightly smaller robustness radius (commonly ≈20% radius reduction) with the same confidence. We provide the mathematical foundation for explaining the phenomenon while experimentally showing promising results on the standard CIFAR-10 and ImageNet datasets. Emmanouil Seferis, Stefanos Kollias, Chih-Hong Cheng |
ECAI | 3 |
| 2024 | EC-IoU: Orienting Safety for Object Detectors via Ego-Centric Intersection-over-UnionabstractThis paper presents Ego-Centric Intersection-over-Union (EC-IoU), addressing the limitation of the standard IoU measure in characterizing safety-related performance for object detectors in navigating contexts. Concretely, we propose a weighting mechanism to refine IoU, allowing it to assign a higher score to a prediction that covers closer points of a ground-truth object from the ego agent’s perspective. The proposed EC-IoU measure can be used in typical evaluation processes to select object detectors with better safety-related performance for downstream tasks. It can also be integrated into common loss functions for model fine-tuning. While geared towards safety, our experiment with the KITTI dataset demonstrates the performance of a model trained on EC-IoU can be better than that of a variant trained on IoU in terms of mean Average Precision as well. Brian Hsuan-Cheng Liao, Chih-Hong Cheng, Hasan Esen, Alois C. Knoll |
IROS | 2 |
| 2024 | BAM: Box Abstraction Monitors for Real-time OoD Detection in Object DetectionabstractOut-of-distribution (OoD) detection techniques for deep neural networks (DNNs) become crucial thanks to their filtering of abnormal inputs, especially when DNNs are used in safety-critical applications and interact with an open and dynamic environment. Nevertheless, integrating OoD detection into state-of-the-art (SOTA) object detection DNNs poses significant challenges, partly due to the complexity introduced by the SOTA OoD construction methods, which require the modification of DNN architecture and the introduction of complex loss functions. This paper proposes a simple, yet surprisingly effective, method that requires neither retraining nor architectural change in object detection DNN, called Box Abstraction-based Monitors (BAM). The novelty of BAM stems from using a finite union of convex box abstractions to capture the learned features of objects for in-distribution (ID) data, and an important observation that features from OoD data are more likely to fall outside of these boxes. The union of convex regions within the feature space allows the formation of non-convex and interpretable decision boundaries, overcoming the limitations of VOS-like detectors without sacrificing real-time performance. Experiments integrating BAM into Faster R-CNN-based object detection DNNs demonstrate a considerably improved performance against SOTA OoD detection techniques, with a reduction in the false detection rate of over 10% in most cases. Changshun Wu, Weicheng He, Chih-Hong Cheng, Xiaowei Huang 0001, Saddek Bensalem |
IROS | 3 |
| 2023 | Butterfly Effect Attack: Tiny and Seemingly Unrelated Perturbations for Object DetectionabstractThis work aims to explore and identify tiny and seemingly unrelated perturbations of images in object detection that will lead to performance degradation. While tininess can naturally be defined using$L_{p}$norms, we characterize the degree of “unrelatedness” of an object by the pixel distance between the occurred perturbation and the object. Triggering errors in prediction while satisfying two objectives can be formulated as a multi-objective optimization problem where we utilize genetic algorithms to guide the search. The result successfully demonstrates that (invisible) perturbations on the right part of the image can drastically change the outcome of object detection on the left. An extensive evaluation reaffirms our conjecture that transformer-based object detection networks are more susceptible to butterfly effects in comparison to single-stage object detection networks such as YOLOv5. Nguyen Anh Vu Doan, Arda Yüksel, Chih-Hong Cheng |
DATE | 3 |
| 2023 | Potential-based Credit Assignment for Cooperative RL-based Testing of Autonomous VehiclesabstractWhile autonomous vehicles (AVs) may perform remarkably well in generic real-life cases, their irrational action in some unforeseen cases leads to critical safety concerns. This paper introduces the concept of collaborative reinforcement learning (RL) to generate challenging test cases for AV planning and decision-making module. One of the critical challenges for collaborative RL is the credit assignment problem, where a proper assignment of rewards to multiple agents interacting in the traffic scenario, considering all parameters and timing, turns out to be non-trivial. In order to address this challenge, we propose a novel potential-based reward-shaping approach inspired by counterfactual analysis for solving the credit-assignment problem. The evaluation in a simulated environment demonstrates the superiority of our proposed approach against other methods using local and global rewards. Utku Ayvaz, Chih-Hong Cheng, Hao Shen 0002 |
IJCNN | 2 |
| 2023 | EvCenterNet: Uncertainty Estimation for Object Detection Using Evidential LearningabstractUncertainty estimation is crucial in safety-critical settings such as automated driving as it provides valuable information for several downstream tasks including high-level decision making and path planning. In this work, we propose EvCenterNet, a novel uncertainty-aware 2D object detection framework using evidential learning to directly estimate both classification and regression uncertainties. To employ evidential learning for object detection, we devise a combination of evidential and focal loss functions for the sparse heatmap inputs. We introduce class-balanced weighting for regression and heatmap prediction to tackle the class imbalance encountered by evidential learning. Moreover, we propose a learning scheme to actively utilize the predicted heatmap uncertainties to improve the detection performance by focusing on the most uncertain points. We train our model on the KITTI dataset and evaluate it on challenging out-of-distribution datasets including BDD100K and nuImages. Our experiments demonstrate that our approach improves the precision and minimizes the execution time loss in relation to the base model. Monish R. Nallapareddy, Kshitij Sirohi, Paulo L. J. Drews-Jr, Wolfram Burgard, Chih-Hong Cheng, Abhinav Valada |
IROS | 5 |
| 2023 | Safeguarding Learning-based Control for Smart Energy Systems with Sampling SpecificationsabstractWe study challenges using reinforcement learning in controlling energy systems, where apart from performance requirements, one has additional safety requirements such as avoiding blackouts. We detail how these safety requirements in real-time temporal logic can be strengthened via discretization into linear temporal logic (LTL), such that the satisfaction of the LTL formulae implies the satisfaction of the original safety requirements. The discretization enables advanced engineering methods such as synthesizing shields for safe reinforcement learning as well as formal verification, where for statistical model checking, the probabilistic guarantee acquired by LTL model checking forms a lower bound for the satisfaction of the original real-time safety requirements. Chih-Hong Cheng, Venkatesh Prasad Venkataramanan, Pragya Kirti Gupta, Yun-Fei Hsu, Simon Burton 0001 |
PRDC | 1 |
| 2023 | Runtime Monitoring DNN-Based Perception - (via the Lens of Formal Methods)
Chih-Hong Cheng, Michael Luttenberger, Rongjie Yan |
RV | 1 |
| 2023 | Are Transformers More Robust? Towards Exact Robustness Verification for Transformers
Brian Hsuan-Cheng Liao, Chih-Hong Cheng, Hasan Esen, Alois C. Knoll |
SAFECOMP | 2 |
| 2022 | Prioritizing Corners in OoD Detectors via Symbolic String Manipulation
Chih-Hong Cheng, Changshun Wu, Emmanouil Seferis, Saddek Bensalem |
ATVA | 1 |
| 2022 | ComOpT: Combination and Optimization for Testing Autonomous Driving SystemsabstractComOpT is an open-source research tool for coverage-driven testing of autonomous driving systems, focusing on planning and control. Starting with (i) a meta-model characterizing discrete conditions to be considered and (ii) constraints specifying the impossibility of certain combinations, ComOpT first generates constraint-feasible abstract scenarios while maximally increasing the coverage of k-way combinatorial testing. Each abstract scenario can be viewed as a conceptual equivalence class, which is then instantiated into multiple concrete scenarios by (1) randomly picking one local map that fulfills the specified geographical condition, and (2) assigning all actors accordingly with parameters within the range. Finally, ComOpT evaluates each concrete scenario against a set of KPIs and performs local scenario variation via spawning a new agent that might lead to a collision at designated points. We use ComOpT to test the Apollo 6 autonomous driving software stack. ComOpT can generate highly diversified scenarios with limited test budgets while uncovering problematic situations such as inabilities to make simple right turns, uncomfortable accelerations, and dangerous driving patterns. ComOpT participated in the 2021 IEEE AI Autonomous Vehicle Testing Challenge and won first place among more than 110 contending teams. Changwen Li, Chih-Hong Cheng, Tiantian Sun, Rongjie Yan |
ICRA | 2 |
| 2022 | Formally Compensating Performance Limitations for Imprecise 2D Object Detection
Tobias Schuster, Emmanouil Seferis, Simon Burton 0001, Chih-Hong Cheng |
SAFECOMP | 4 |
| 2021 | Provably-Robust Runtime Monitoring of Neuron Activation PatternsabstractFor deep neural networks (DNNs) to be used in safety-critical autonomous driving tasks, it is desirable to monitor in operation time if the input for the DNN is similar to the data used in DNN training. While recent results in monitoring DNN activation patterns provide a sound guarantee due to building an abstraction out of the training data set, reducing false positives due to slight input perturbation has been an issue towards successfully adapting the techniques. We address this challenge by integrating formal symbolic reasoning inside the monitor construction process. The algorithm performs a sound worst-case estimate of neuron values with inputs (or features) subject to perturbation, before the abstraction function is applied to build the monitor. The provable robustness is further generalized to cases where monitoring a single neuron can use more than one bit, implying that one can record activation patterns with a fine-grained decision on the neuron value interval. Chih-Hong Cheng |
DATE | 1 |
| 2021 | Continuous Safety Verification of Neural NetworksabstractDeploying deep neural networks (DNNs) as core functions in autonomous driving creates unique verification and validation challenges.In particular, the continuous engineering paradigm of gradually perfecting a DNN-based perception can make the previously established result of safety verification no longer valid.This can occur either due to the newly encountered examples (i.e., input domain enlargement) inside the Operational Design Domain or due to the subsequent parameter fine-tuning activities of a DNN.This paper considers approaches to transfer results established in the previous DNN safety verification problem to the modified problem setting.By considering the reuse of state abstractions, network abstractions, and Lipschitz constants, we develop several sufficient conditions that only require formally analyzing a small part of the DNN in the new problem.The overall concept is evaluated in a 1/10-scaled vehicle that equips a DNN controller to determine the visual waypoint from the perceived image. Chih-Hong Cheng, Rongjie Yan |
DATE | 1 |
| 2021 | Monitoring Object Detection Abnormalities via Data-Label and Post-Algorithm AbstractionsabstractWhile object detection modules are essential functionalities for any autonomous vehicle, the performance of such modules that are implemented using deep neural networks can be, in many cases, unreliable. In this paper, we develop abstraction-based monitoring as a logical framework for filtering potentially erroneous detection results. Concretely, we consider two types of abstraction, namely data-label abstraction and post-algorithm abstraction. Operated on the training dataset, the construction of data-label abstraction iterates each input, aggregates region-wise information over its associated labels, and stores the vector under a finite history length. Post-algorithm abstraction builds an abstract transformer for the tracking algorithm. Elements being associated together by the abstract transformer can be checked against consistency over their original values. We have implemented the overall framework to a research prototype and validated it using publicly available object detection datasets. Chih-Hong Cheng, Jun Yan 0009, Rongjie Yan |
IROS | 2 |
| 2021 | Mixed-Neighborhood, Multi-speed Cellular Automata for Safety-Aware Pedestrian Prediction
Sebastian vom Dorff, Chih-Hong Cheng, Hasan Esen, Martin Fränzle |
SEFM | 2 |
| 2020 | Towards Safety Verification of Direct Perception Neural NetworksabstractWe study the problem of safety verification of direct perception neural networks, where camera images are used as inputs to produce high-level features for autonomous vehicles to make control decisions. Formal verification of direct perception neural networks is extremely challenging, as it is difficult to formulate the specification that requires characterizing input as constraints, while the number of neurons in such a network can reach millions. We approach the specification problem by learning an input property characterizer which carefully extends a direct perception neural network at close-to-output layers, and address the scalability problem by a novel assume-guarantee based verification approach. The presented workflow is used to understand a direct perception neural network (developed by Audi) which computes the next waypoint and orientation for autonomous vehicles to follow. Chih-Hong Cheng, Chung-Hao Huang, Thomas Brunner, Vahid Hashemi |
DATE | 1 |
| 2020 | Towards Robust Direct Perception Networks for Automated DrivingabstractWe consider the problem of engineering robust direct perception neural networks with the output being regression. Such networks take high dimensional input image data, and they produce affordances such as the curvature of the upcoming road segment or the distance to the front vehicle. Our proposal starts by allowing a neural network prediction to deviate from the label with tolerance Δ. The source of tolerance can be either contractual or from limiting factors where two entities may label the same data with slightly different numerical values. The tolerance motivates the use of a non-standard loss function where the loss is set to 0 so long as the prediction-to-label distance is less than Δ. We further extend the loss function and define a new provably robust criterion that is parametric to the allowed output tolerance Δ, the layer index l where perturbation is considered, and the maximum perturbation amount κ. During training, the robust loss is computed by first propagating symbolic errors from the l̃-th layer (with quantity bounded by κ) to the output layer, followed by computing the overflow between the error bounds and the allowed tolerance. The overall concept is experimented in engineering a direct perception neural network for understanding the central position of the ego-lane in pixel coordinates. Chih-Hong Cheng |
IV | 1 |
| 2020 | Safety-Aware Hardening of 3D Object Detection Neural Network Systems
Chih-Hong Cheng |
SAFECOMP | 1 |
| 2019 | Runtime Monitoring Neuron Activation PatternsabstractFor using neural networks in safety critical domains, it is important to know if a decision made by a neural network is supported by prior similarities in training. We propose runtime neuron activation pattern monitoring - after the standard training process, one creates a monitor by feeding the training data to the network again in order to store the neuron activation patterns in abstract form. In operation, a classification decision over an input is further supplemented by examining if a pattern similar (measured by Hamming distance) to the generated pattern is contained in the monitor. If the monitor does not contain any pattern similar to the generated pattern, it raises a warning that the decision is not based on the training data. Our experiments show that, by adjusting the similarity-threshold for activation patterns, the monitors can report a significant portion of misclassfications to be not supported by training with a small false-positive rate, when evaluated on a test set. Chih-Hong Cheng, Georg Nührenberg, Hirotoshi Yasuoka |
DATE | 1 |
| 2019 | nn-dependability-kit: Engineering Neural Networks for Safety-Critical Autonomous Driving SystemsabstractCan engineering neural networks be approached in a disciplined way similar to how engineers build software for civil aircraft? We present nn-dependability-kit, an open-source toolbox to support safety engineering of neural networks for autonomous driving systems. The rationale behind nn-dependability-kit is to consider a structured approach (via Goal Structuring Notation) to argue the quality of neural networks. In particular, the tool realizes recent scientific results including (a) novel dependability metrics for indicating sufficient elimination of uncertainties in the product life cycle, (b) formal reasoning engine for ensuring that the generalization does not lead to undesired behaviors, and (c) runtime monitoring for reasoning whether a decision of a neural network in operation is supported by prior similarities in the training data. A proprietary version of nn-dependability-kit has been used to improve the quality of a level-3 autonomous driving component developed by Audi for highway maneuvers. Chih-Hong Cheng, Chung-Hao Huang, Georg Nührenberg |
ICCAD | 1 |
| 2018 | Quantitative Projection Coverage for Testing ML-enabled Autonomous Systems
Chih-Hong Cheng, Chung-Hao Huang, Hirotoshi Yasuoka |
ATVA | 1 |
| 2018 | Neural networks for safety-critical applications - Challenges, experiments and perspectivesabstractWe propose a methodology for designing dependable Artificial Neural Networks (ANNs) by extending the concepts of understandability, correctness, and validity that are crucial ingredients in existing certification standards. We apply the concept in a concrete case study for designing a highway ANN-based motion predictor to guarantee safety properties such as impossibility for the ego vehicle to suggest moving to the right lane if there exists another vehicle on its right. Chih-Hong Cheng, Frederik Diehl, Gereon Hinz, Yassine Hamza, Georg Nührenberg, Markus Rickert 0001, Harald Ruess, Michael Truong-Le |
DATE | 1 |
| 2018 | Towards Dependability Metrics for Neural NetworksabstractArtificial neural networks (NN) are instrumental in realizing highly-automated driving functionality. An overarching challenge is to identify best safety engineering practices for NN and other learning-enabled components. In particular, there is an urgent need for an adequate set of metrics for measuring all- important NN dependability attributes. We address this challenge by proposing a number of NN-specific and efficiently computable metrics for measuring NN dependability attributes including robustness, interpretability, completeness, and correctness. Chih-Hong Cheng, Georg Nührenberg, Chung-Hao Huang, Harald Ruess, Hirotoshi Yasuoka |
MEMOCODE | 1 |
| 2017 | Automated Analysis of Multi-View Software ArchitecturesabstractSoftware architectures usually are comprised of different views for capturing static, runtime, and deployment aspects. What is currently missing, however, are formal validation and verification techniques of multi-view architecture in very early phases of the software development lifecycle. The main contribution of this paper therefore is the construction of a single formal model (in Promela) for certain stylized, and widely used, multi-view architectures by suitably interpreting and fusing sub-models from different UML diagrams. Possible counter-examples produced by model checking are fed back as test scenarios for debugging the multi-view architectural model. We have implemented this algorithm as a plug-in for the Enterprise Architect development tool, and successfully used SPIN model checking for debugging some industrial architectural multi-view models by identifying a number of undesirable corner cases. Chih-Hong Cheng, Yassine Hamza, Harald Ruess |
APSEC | 1 |
| 2017 | Maximum Resilience of Artificial Neural Networks
Chih-Hong Cheng, Georg Nührenberg, Harald Ruess |
ATVA | 1 |
| 2017 | Device adapter concept towards enabling plug&produce production environmentsabstractModern manufacturing systems require a transformation from mass production towards mass customization. This results in a trend towards more agile production lines. It also demands a reduction of configuration times when building the production line as well as faster reconfiguration when adding new hardware and product variants to the manufacturing line. This paper introduces the concept of a device adapter that allows the device to be seamlessly plugged into the agile production systems. The device adapter wraps the device functionality and offers it as a service, hiding away the low-level process capability (skill) implementation and allowing to formally represent the production steps. Preliminary tests have been performed on an industrial demonstrator that simulates a real manufacturing process. Kirill Dorofeev, Chih-Hong Cheng, Magno Guedes, Stefan Profanter, Alois Zoitl |
ETFA | 2 |
| 2017 | autoCode4: Structural Controller Synthesis
Chih-Hong Cheng, Edward A. Lee, Harald Ruess |
TACAS (1) | 1 |
| 2016 | Structural Synthesis for GXW Specifications
Chih-Hong Cheng, Yassine Hamza, Harald Ruess |
CAV (1) | 1 |
| 2016 | Compositional Parameter Synthesis
Lacramioara Astefanoaei, Saddek Bensalem, Marius Bozga, Chih-Hong Cheng, Harald Ruess |
FM | 4 |
| 2015 | Formal consistency checking over specifications in natural languages
Rongjie Yan, Chih-Hong Cheng, Yesheng Chai |
DATE | 2 |
| 2015 | Semantic degrees for Industrie 4.0 engineering: deciding on the degree of semantic formalization to select appropriate technologiesabstractUnder the context of Industrie 4.0 (I4.0), future production systems provide balanced operations between manufacturing flexibility and efficiency, realized in an autonomous, horizontal, and decentralized item-level production control framework. Structured interoperability via precise formulations on an appropriate degree is crucial to achieve software engineering efficiency in the system life cycle. However, selecting the degree of formalization can be challenging, as it crucially depends on the desired common understanding (semantic degree) between multiple parties. In this paper, we categorize different semantic degrees and map a set of technologies in industrial automation to their associated degrees. Furthermore, we created guidelines to assist engineers selecting appropriate semantic degrees in their design. We applied these guidelines on publicly available scenarios to examine the validity of the approach, and identified semantic elements over internally developed use cases concerning plug-and-produce. Chih-Hong Cheng, Tuncay Guelfirat, Christian Messinger, Johannes Schmitt 0001, Matthias Schnelte, Peter Weber |
ESEC/SIGSOFT FSE | 1 |
| 2014 | G4LTL-ST: Automatic Generation of PLC Programs
Chih-Hong Cheng, Chung-Hao Huang, Harald Ruess, Stefan Hauck-Stattelmann |
CAV | 1 |
| 2013 | JBernstein: A Validity Checker for Generalized Polynomial Constraints
Chih-Hong Cheng, Harald Ruess, Natarajan Shankar |
CAV | 1 |
| 2013 | Synthesizing Controllers for Automation Tasks with Performance Guarantees
Chih-Hong Cheng, Michael Geisinger, Christian Buckl |
SPIN | 1 |
| 2012 | MGSyn: Automatic Synthesis for Industrial Automation
Chih-Hong Cheng, Michael Geisinger, Harald Ruess, Christian Buckl, Alois C. Knoll |
CAV | 1 |
| 2012 | Game solving for industrial automation and controlabstractAn ongoing effort within the community of verification and program analysis is to raise the level of abstraction in programming by automatic synthesis. In this paper, we demonstrate how our synthesis engine GAVS+ achieves this goal by automatically creating control code for the FESTO Modular Production System. The overall approach is model-driven: we reinterpret planning domain definition language (PDDL) as a design contract to model two-player games played between control and environment, such that users can describe (i) basic abilities of hardware components, including sensors (as environment moves) and actuators (as control moves), (ii) topologies how components are interconnected, and (iii) desired specification under a restricted class of linear temporal logic. The model is processed by our game-based synthesis engine, from which intermediate code is generated. By mapping each behavioral-level action to a sequence of low-level PLC control commands, we transform the intermediate code into an executable program. The efficiency of our engine enables to synthesize every scenario presented in this paper within seconds. When the specification evolves, this implies a huge time-gain compared to manual program modification. Chih-Hong Cheng, Michael Geisinger, Harald Ruess, Christian Buckl, Alois C. Knoll |
ICRA | 1 |
| 2011 | Algorithms for Synthesizing Priorities in Component-Based Systems
Chih-Hong Cheng, Saddek Bensalem, Yu-Fang Chen 0001, Rongjie Yan, Barbara Jobstmann, Harald Ruess, Christian Buckl, Alois C. Knoll |
ATVA | 1 |
| 2011 | GAVS+: An Open Platform for the Research of Algorithmic Game Solving
Chih-Hong Cheng, Alois C. Knoll, Michael Luttenberger, Christian Buckl |
TACAS | 1 |
| 2011 | Synthesis of Fault-Tolerant Embedded Systems Using Games: From Theory to Practice
Chih-Hong Cheng, Harald Ruess, Alois C. Knoll, Christian Buckl |
VMCAI | 1 |
| 2011 | On the Hardness of Priority Synthesis
Chih-Hong Cheng, Barbara Jobstmann, Christian Buckl, Alois C. Knoll |
CIAA | 1 |
| 2010 | GAVS: Game Arena Visualization and Synthesis
Chih-Hong Cheng, Christian Buckl, Michael Luttenberger, Alois C. Knoll |
ATVA | 1 |
| 2009 | Modeling and Verification for Timing Satisfaction of Fault-Tolerant Systems with FinitenessabstractThe increasing use of model-based tools enables further use of formal verification techniques in the context of distributed real-time systems. To avoid state explosion, it is necessary to construct verification models that focus on the aspects under consideration.In this paper, we discuss how we construct a verification model for timing analysis in distributed real-time systems.We (1) give observations concerning restrictions of timed automata to model these systems,(2) formulate mathematical representations on how to perform model-to-model transformation to derive verification models from system models, and (3) propose some theoretical criteria how to reduce the model size. The latter is in particular important, as for the verification of complex systems, an efficient model reflecting the properties of the system under consideration is equally important to the verification algorithm itself.Finally, we present an extension of the model-based development tool FTOS, designed to develop fault-tolerant systems, to demonstrate our approach. Chih-Hong Cheng, Christian Buckl, Javier Esparza, Alois C. Knoll |
DS-RT | 1 |
| 2008 | Program Repair Suggestions from Graphical State-Transition Specifications
Farn Wang, Chih-Hong Cheng |
FORTE | 2 |