Huafeng Yu

dblp:79/1201 · DBLP profile ↗
← Back
21ranked-venue papers
5as first author
4since 2021 · last 2023
0000-0003-0065-1340ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 11 · 2 first-authorSoftware engineering, systems software and programming languages · 7 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 1 since 2021Theory of computation · 2 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2023 Closed-Loop Analysis of Vision-Based Autonomous Systems: A Case Study
abstract
Abstract Deep neural networks (DNNs) are increasingly used in safety-critical autonomous systems as perception components processing high-dimensional image data. Formal analysis of these systems is particularly challenging due to the complexity of the perception DNNs, the sensors (cameras), and the environment conditions. We present a case study applying formal probabilistic analysis techniques to an experimental autonomous system that guides airplanes on taxiways using a perception DNN. We address the above challenges by replacing the camera and the network with a compact abstraction whose transition probabilities are computed from the confusion matrices measuring the performance of the DNN on a representative image data set. As the probabilities are estimated based on empirical data, and thus are subject to error, we also compute confidence intervals in addition to point estimates for these probabilities and thereby strengthen the soundness of the analysis. We also show how to leverage local, DNN-specific analyses as run-time guards to filter out mis-behaving inputs and increase the safety of the overall system. Our findings are applicable to other autonomous systems that use complex DNNs for perception.
Corina Pasareanu, Ravi Mangal, Divya Gopinath, Sinem Getir, Calum Imrie, Radu Calinescu, Huafeng Yu
CAV (1)7
2023 Feature-Guided Analysis of Neural Networks
abstract
Abstract Applying standard software engineering practices to neural networks is challenging due to the lack of high-level abstractions describing a neural network’s behavior. To address this challenge, we propose to extract high-level task-specific features from the neural network internal representation, based on monitoring the neural network activations. The extracted feature representations can serve as a link to high-level requirements and can be leveraged to enable fundamental software engineering activities, such as automated testing, debugging, requirements analysis, and formal verification, leading to better engineering of neural networks. Using two case studies, we present initial empirical evidence demonstrating the feasibility of our ideas.
Divya Gopinath, Luca Lungeanu, Ravi Mangal, Corina Pasareanu, Siqi Xie, Huafeng Yu
FASE6
2023 Assumption Generation for Learning-Enabled Autonomous Systems
Corina Pasareanu, Ravi Mangal, Divya Gopinath, Huafeng Yu
RV4
2022 Industry-track: Challenges in Rebooting Autonomy with Deep Learned Perception
abstract
Deep learning (DL) models are becoming effective in solving computer-vision tasks such as semantic segmentation, object tracking, and pose estimation on real-world captured images. Reliability analysis of autonomous systems that use these DL models as part of their perception systems have to account for the performance of these models. Autonomous systems with traditional sensors have tried-and-tested reliability assessment processes with modular design, unit tests, system integration, compositional verification, certification, etc. In contrast, DL perception modules relies on data-driven or learned models. These models do not capture uncertainty and often lack robustness. Also, these models are often updated throughout the lifecycle of the product when new data sets become available. However, the integration of an updated DL-based perception requires a reboot and start afresh of the reliability assessment and operation processes for autonomous systems. In this paper, we discuss three challenges related to specifying, verifying, and operating systems that incorporate DL-based perception. We illustrate these challenges through two concrete and open source examples.
Michael Abraham, Aaron Mayne, Tristan Perez, Ítalo Romani de Oliveira, Huafeng Yu, Chiao Hsieh, Yangge Li, Dawei Sun 0007, Sayan Mitra 0001
EMSOFT5
2020 Towards Assurance Evaluation of Autonomous Systems
abstract
Due to the probabilistic and uncertain nature of learning-enabled autonomous systems, new assurance technologies appropriate for such systems are becoming critical for their acceptance. Runtime monitors are among the key assurance technologies to address these challenges. In the DARPA Assured Autonomy program, our Boeing team is performing autonomous platform integration and assurance technology evaluation. In this paper, we present our preliminary evaluation results for runtime monitor technologies, which were developed by our three partner teams during Phase I for learning-enabled autonomous systems. The evaluation was completed using a flight simulator and real platforms. In the evaluation, the demonstrated assurance technologies showed significant promise in addressing the assurance shortfall currently facing learning enabled cyber physical systems, and the evaluation approach defined here provides a solid starting point for evaluations of the maturing assurance technologies in the future phases of the DARPA Assured Autonomy project.
Steven Beland, Isaac Chang, Alexander Chen, Matthew Moser, James L. Paunicka, Douglas Stuart, John Vian, Christina Westover, Huafeng Yu
ICCAD9
2019 Introduction to the Special Issue on Human-interaction-aware Data Analytics for Cyber-physical Systems
abstract
No abstract available.
Tongquan Wei, Junlong Zhou, Rajiv Ranjan 0001, Isaac Triguero, Huafeng Yu, Chun Jason Xue, Schahram Dustdar
ACM Trans. Cyber Phys. Syst.5
2018 IEEE Transactions on Sustainable Computing: Guest Editorial on Special Issue on Sustainable Cyber-Physical Systems
abstract
The papers from this special section addresses the topic of sustainable cyber-physical systems (CPSs). The research on CPSs addresses the close interactions between the cyber computational components and the physical components spanning from mechanical components, energy systems, human activities, to surrounding environment. CPS is expected to play a major role in the development of next-generation smart energy systems and data centers. Innovative computational methodologies such as green and energy efficient cyber-physical system design have become critical to enable the sustainable development of such systems. These technologies can be used to tackle various sustainability challenges, such as the reduction of energy induced from the large scale data center computing infrastructures, the improvement of computational efficiency in smart energy systems and connected vehicle systems, and the exploration of the renewable energy resources to mitigate classical energy usages.
Shiyan Hu 0001, Bei Yu 0001, Huafeng Yu
IEEE Trans. Sustain. Comput.3
2017 Safety Guard: Runtime Enforcement for Safety-Critical Cyber-Physical Systems: Invited
abstract
Due to their safety-critical nature, cyber-physical systems (CPS) must tolerate faults and security attacks to remain fail-operational. However, conventional techniques for improving safety, such as testing and validation, do not meet this requirement, as shown by many of the real-world system failures in recent years, often with major economic and public-safety implications. We aim to improve the safety of critical CPS through synthesis of runtime enforcers, named safety guards, which are reactive components attached to the original systems to protect them against catastrophic failures. That is, even if the system occasionally malfunctions due to unknown defects, transient errors, or malicious attacks, the guard always reacts instantaneously to ensure that the combined system satisfies a predefined set of safety properties, and the deviation from the original system is kept at minimum. We illustrate the main ideas of this approach with examples, discuss the advantages compared to existing approaches, and point out some research challenges.
Meng Wu 0001, Haibo Zeng 0001, Chao Wang 0001, Huafeng Yu
DAC4
2017 Algorithm and hardware implementation for visual perception system in autonomous vehicle: A survey
Weijing Shi, Mohamed Baker Alawieh, Xin Li 0001, Huafeng Yu
Integr.4
2016 Invited - Cooperation or competition?: coexistence of safety and security in next-generation ethernet-based automotive networks
abstract
Safety is traditionally the most relevant property for automotive systems, and it is further enhanced by Advanced Driver Assistance Systems (ADAS) in modern automotive systems. To support ADAS and other advanced autonomous functions, automotive electronic systems become more distributed and connected than ever, with in-vehicle architecture or Vehicle-to-X (V2X) communication. These connections create a variety of interfaces which become breeding grounds for security attacks. Accordingly, security becomes a rising issue for automotive systems. In this paper, we address safety and security together, especially their interactions, in Ethernet-based automotive networks which are believed to be the next-generation automotive networks since they are able to provide high bandwidths, certain timing guarantees, and well-developed technologies. We discuss the interactions between safety and security in three problems: secret key management, frame replication and elimination, and Virtual Local Area Network (VLAN) segmentation. We demonstrate that safety and security can work together, but sometimes there is a trade-off between them. This indicates that safety cannot stand alone without considering security, and network security is a necessary component of system security. Towards safer and securer automotive systems, safety and security should be considered together during design stages of automotive systems.
Chung-Wei Lin, Huafeng Yu
DAC2
2016 Efficient statistical validation of machine learning systems for autonomous driving
abstract
Today's automotive industry is making a bold move to equip vehicles with intelligent driver assistance features. A modern automobile is now equipped with a powerful computing platform to run multiple machine learning algorithms for environment perception (e.g., pedestrian detection) and motion control (e.g., vehicle stabilization). These machine learning systems must be highly robust with extremely small failure rate in order to ensure safe and reliable driving. In this paper, we propose a novel Subset Sampling (SUS) algorithm to efficiently validate a machine learning system. In particular, a Markov Chain Monte Carlo algorithm based on graph mapping is developed to accurately estimate the rare failure rate with a minimal amount of test data, thereby minimizing the validation cost. Our numerical experiments show that SUS achieves 15.2× runtime speed-up over the conventional brute-force Monte Carlo method.
Weijing Shi, Mohamed Baker Alawieh, Xin Li 0001, Huafeng Yu, Nikos Aréchiga, Nobuyuki Tomatsu
ICCAD4
2016 CONVINCE: a cross-layer modeling, exploration and validation framework for next-generation connected vehicles
abstract
Next-generation autonomous and semi-autonomous vehicles will not only precept the environment with their own sensors, but also communicate with other vehicles and surrounding infrastructures for vehicle safety and transportation efficiency. The design, analysis and validation of various vehicle-to-vehicle (V2V) and vehicle-to-infrastructure (V2I) applications involve multiple layers, from V2V/V2I communication networks down to software and hardware of individual vehicles, and concern with stringent requirements on multiple metrics such as timing, security, reliability and fault tolerance. To cope with these challenges, we have been developing CONVINCE, a cross-layer modeling, exploration and validation framework for connected vehicles. The framework includes mathematical models, synthesis and validation algorithms, and a heterogeneous simulator for inter-vehicle communications and intra-vehicle software and hardware in a holistic environment. It explores various design options with respect to constraints and objectives on system safety, security, reliability, cost, etc. A V2V application is used in the case study to demonstrate the effectiveness of the proposed framework.
Bowen Zheng 0001, Chung-Wei Lin, Huafeng Yu, Hengyi Liang, Qi Zhu 0002
ICCAD3
2015 The challenge of interoperability: model-based integration for automotive control software
abstract
Model-Based Engineering (MBE) is a promising approach to cope with the challenges of designing the next-generation automotive systems. The increasing complexity of automotive electronics, the platform, distributed real-time embedded software, and the need for continuous evolution from one generation to the next has necessitated highly productive design approaches. However, heterogeneity, interoperability, and the lack of formal semantic underpinning in modeling, integration, validation and optimization make design automation a big challenge, which becomes a hindrance to the wider application of MBE in the industry. This paper briefly presents the interoperability challenges in the context of MBE and summarizes our current contribution to address these challenges with regard to automotive control software systems. A novel model-based formal integration framework is being developed to enable architecture modeling, timing specification, formal semantics, design by contract and optimization in the system-level design. The main advantages of the proposed approach include its pervasive use of formal methods, architecture analysis and design language (AADL) and associated tools, a novel timing annex for AADL with an expressive timing relationship language, a formal contract language to express component-level requirements and validation of component integration, and the resulting high assurance system delivery.
Huafeng Yu, Prachi Joshi, Jean-Pierre Talpin, Sandeep K. Shukla, Shinichi Shiraishi
DAC1
2015 Timed behavioural modelling and affine scheduling of embedded software architectures in the AADL using Polychrony
Loïc Besnard, Adnan Bouakaz, Paul Le Guernic, Yue Ma 0004, Jean-Pierre Talpin, Huafeng Yu
Sci. Comput. Program.7
2013 Toward polychronous analysis and validation for timed software architectures in AADL
abstract
High-level architecture modeling languages, such as Architecture Analysis & Design Language (AADL), are gradually adopted in the design of embedded systems so that design choice verification, architecture exploration, and system property checking are carried out as early as possible. This paper presents our recent contributions to cope with clock-based timing analysis and validation of software architectures specified in AADL. In order to avoid semantics ambiguities of AADL, we mainly consider the AADL features related to real-time and logical time properties. We endue them with a semantics in the polychronous model of computation; this semantics is quickly reviewed. The semantics enables timing analysis, formal verification and simulation. In addition, thread-level scheduling, based on affine clock relations is also briefly presented here. A tutorial avionic case study, provided by C-S, has been adopted to illustrate our overall contribution.
Yue Ma 0004, Huafeng Yu, Paul Le Guernic, Jean-Pierre Talpin, Loïc Besnard, Maurice Heitz
DATE2
2013 Exploring system architectures in AADL via Polychrony and SynDEx
Huafeng Yu, Yue Ma 0004, Loïc Besnard, Jean-Pierre Talpin, Paul Le Guernic, Yves Sorel
Frontiers Comput. Sci.1
2013 Polychronous modeling, analysis, verification and simulation for timed software architectures
Huafeng Yu, Yue Ma 0004, Loïc Besnard, Paul Le Guernic, Jean-Pierre Talpin
J. Syst. Archit.1
2011 Polychronous controller synthesis from MARTE CCSL timing specifications
abstract
The UML Profile for Modeling and Analysis of Real-Time and Embedded systems (MARTE) defines a mathematically expressive model of time, the Clock Constraint Specification Language (CCSL), to specify timed annotations on UML diagrams and thus provides them with formally defined timed interpretations. Thanks to its expressive capability, the CCSL allows for the specification of static and dynamic properties, of deterministic and non-deterministic behaviors, or of systems with multiple clock domains. Code generation from such multi-clocked specifications (for the purpose of synthesizing a simulator, for instance) is known to be a difficult issue. We address it by using the approach of controller synthesis. In our framework, a timed CCSL specification is regarded as a property whose satisfaction should be enforced for any UML diagram carrying it as annotation. To do so, CCSL statements are first translated into dynamical polynomial systems. Such systems can be manipulated using the model-checker Sigali to synthesize an executable property (a controller) which enforces the satisfaction of the specified timing constraints on the UML diagram with which it is executed.
Huafeng Yu, Jean-Pierre Talpin, Loïc Besnard, Hervé Marchand, Paul Le Guernic
MEMOCODE1
2008 Modeling and Formal Validation of High-Performance Embedded Systems
abstract
This paper presents an approach for the modeling and formalvalidation of high-performance systems. The approach relies on the repetitive model of computation used to express the parallelism of such systems within the Gaspard framework, which is dedicated to the codesign of high-performance system-on-chip. The system descriptions obtained with this model are then projected on the synchronous model of computation. The result of this projectionconsists of an equational model that allows one to formally analyze clock synchronizability issues so as to guarantee the reliable deployment of systems on platforms.
Abdoulaye Gamatié, Éric Rutten, Huafeng Yu, Pierre Boulet, Jean-Luc Dekeyser
ISPDC3
2007 Model Transformations from a Data Parallel Formalism towards Synchronous Languages
Huafeng Yu, Abdoulaye Gamatié, Éric Rutten, Jean-Luc Dekeyser
FDL1
2006 A flexible method to tolerate value sensor failures
abstract
Tolerating the value failures of sensors is an important problem in automated control processes and plants. In this paper, we address this problem in a theoretical framework in order to demonstrate the feasibility of an automatic method based on discrete controller synthesis. We consider a fault-intolerant program whose job is to control an automated process, here a liquid tank equipped with level sensors that can be subject to value faults. This fault-intolerant program is modeled as a finite labeled transition system. We then specify formally a fault hypothesis, i.e., how many sensors can fail simultaneously. We use discrete controller synthesis to obtain automatically a program, having the same behavior as the initial fault-intolerant one, and satisfying the fault tolerance requirements under the fault hypothesis. We advocate that, thanks to the use of discrete controller synthesis, our method offers flexibility, reliability, separation of concern, and it is automatic.
Alain Girault, Huafeng Yu
ETFA2