EDBT 2026 Demo / reviewers in the wild / expert
Irune Agirre
dblp:170/0377
· DBLP profile ↗
15ranked-venue papers
4as first author
8since 2021 · last 2026
0000-0002-9507-8841ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 12 · 3 first-author · 7 since 2021Software engineering, systems software and programming languages · 3 · 2 since 2021Security and privacy · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ROSBand: A Bandwidth Regulation Approach on ROS2-Based Systems
Jon Altonaga Puente, Enrico Mezzetti, Irune Agirre, Jaume Abella 0001, Francisco J. Cazorla |
RTAS | 3 |
| 2025 | SAFEXPLAIN: a Complete Approach Towards Trustworthy AI-Based Safety-Critical SystemsabstractAI becomes increasingly important in safetycritical systems, especially in the case of autonomous systems, since navigation relies on AI for object detection and collision avoidance. However, safety-critical systems must adhere to functional safety standards that enforce software to be correct-by-construction, component decomposition to simplify design and validation, and the use of data only for testing purposes not to design the system itself. AI in general, and Deep Learning (DL) in particular have opposed characteristics since they have error rates (e.g., due to mispredictions), AI/DL modules can only be designed and validated monolithically, and they build on data for their design (i.e. for training purposes). Hence, DL solutions are at odds with the development process of safetycritical systems. A number of standards have recently emerged in different domains to reconcile the requirements of safety-critical systems with the characteristics of DL solutions, such as ISO 21448, ISO/IEC TR 5469, and ISO 8800, among others. However, there is a lack of realistic practice to design a DL-based safety-critical system in accordance with those regulations, and existing solutions only cover some aspects in isolation, and are often incompatible among them. SAFEXPLAIN is a 3-year Horizon Europe project addressing this challenge. SAFEXPLAIN, which finishes in September 2025, has already reached its main goals providing specific and complementary solutions to all those challenges so that AIbased safety-critical systems can be designed, implemented and validated adhering to the relevant functional safety standards in domains such as automotive, space and railway. In particular, SAFEXPLAIN provides the concepts, processes, tools and frameworks addressing the challenge end-to-end, from concept to solution. This is proven by the successful application of the SAFEXPLAIN approach in three case studies from the automotive, space and railway domains, whose results will see the light very soon. Jaume Abella 0001, Irune Agirre, Thanh Hai Bui, Frank Geujen, Gabriele Giordana, Carlo Donzella, Francisco J. Cazorla, Enrico Mezzetti, Axel Brando, Javier Fernández 0004, Irune Yarza, Joanes Plazaola, Maria Ulan, Rob Lavreysen, Lucas Tosi, Ilaria Bloise, Lorenzo Feruglio, Ilaria Cinelli, Stefano Lodico, William Guarienti, Giuseppe Nicosia, Valeria Dallara |
DSD | 2 |
| 2025 | Towards a Safe End-to-End AI framework: MISRA C-Compliant YOLO for Object DetectionabstractArtificial Intelligence (AI) has traditionally prioritized high performance over compliance with functional safety standards such as IEC 61508. However, when AI systems are used in safety-related functions, it is essential to demonstrate that errors will not lead to malfunctions. This involves preventing systematic design-time errors and detecting and controlling runtime faults, as specified in IEC 61508. Moreover, ISO/PAS 8800 requires analyzing AI-specific development tools to identify and mitigate potential risks. In this paper, we take a step toward a safe end-to-end AI framework by focusing on systematic error avoidance in the implementation of You Only Look Once (YOLO), a widely used object detection model. A C-based version of YOLO-built on the Darknet framework-is analyzed using the Polyspace static analysis tool to assess MISRA C compliance. We apply corrective actions to eliminate violations, producing a MISRA $\mathbf{C}$-compliant implementation. In addition, we propose a runtime error detection mechanism using dual execution on a diverse platform and validate behavioral consistency using the COCO dataset. This approach supports the development of trustworthy AI systems by addressing both systematic errors and runtime detection. Javier Fernández 0004, Irune Agirre, Irune Yarza, Jon Pérez 0001 |
DSD | 2 |
| 2023 | SAFEXPLAIN: Safe and Explainable Critical Embedded Systems Based on AIabstractDeep Learning (DL) techniques are at the heart of most future advanced software functions in Critical Autonomous AI-based Systems (CAIS), where they also represent a major competitive factor. Hence, the economic success of CAIS industries (e.g., automotive, space, railway) depends on their ability to design, implement, qualify, and certify DL-based software products under bounded effort/cost. However, there is a fundamental gap between Functional Safety (FUSA) requirements on CAIS and the nature of DL solutions. This gap stems from the development process of DL libraries and affects high-level safety concepts such as (1) explainability and traceability, (2) suitability for varying safety requirements, (3) FUSA-compliant implementations, and (4) real-time constraints. As a matter of fact, the data-dependent and stochastic nature of DL algorithms clashes with current FUSA practice, which instead builds on deterministic, verifiable, and pass/fail test-based software. The SAFEXPLAIN project tackles these challenges and targets by providing a flexible approach to allow the certification - hence adoption - of DL-based solutions in CAIS building on: (1) DL solutions that provide end-to-end traceability, with specific approaches to explain whether predictions can be trusted and strategies to reach (and prove) correct operation, in accordance to certification standards; (2) alternative and increasingly sophisticated design safety patterns for DL with varying criticality and fault tolerance requirements; (3) DL library implementations that adhere to safety requirements; and (4) computing platform configurations, to regain determinism, and probabilistic timing analyses, to handle the remaining non-determinism. Jaume Abella 0001, Jon Pérez 0001, Cristofer Englund, Bahram Zonooz, Gabriele Giordana, Carlo Donzella, Francisco J. Cazorla, Enrico Mezzetti, Isabel Serra, Axel Brando, Irune Agirre, Fernando Eizaguirre, Thanh Hai Bui, Elahe Arani, Fahad Sarfraz, Ajay Balasubramaniam, Ahmed Badar, Ilaria Bloise, Lorenzo Feruglio, Ilaria Cinelli, Davide Brighenti, Davide Cunial |
DATE | 11 |
| 2023 | UP2DATE software updating framework compliance with safety and security regulations and standardsabstractOver-the-air Software Updates (OTASU) in the critical domain are already a reality. OTASU provide huge benefits in terms of user experience, security, and efficiency. However, due to involved risks, safety and security mechanisms and new regulations are needed for their adoption in the critical domain. The automotive industry is already in the race to adopt safe and secure OTASU, as by 2024, compliance to new UN regulations will become compulsory. However, the standards providing the specifications and requirements for OTASU are still in their infancy. Many other dependable system domains, that are now more digital and connected than ever, are following same trends towards OTASU. For instance, OTASU are very likely to be adopted in the railway domain in a near future, as the ability of remotely updating railway equipment considerably reduces maintenance costs and time, improving system availability. This paper describes how the UP2DATE framework adheres to existing and emerging regulations and standards and evaluates them through a railway case-study. Obtained results demonstrate that the proposed updating framework can provide great savings in the installation and maintenance phases of railway signalling devices by reducing the time required for the update and by removing the need for operator presence on-site. Irune Agirre, Alejandro J. Calderón, Irune Yarza, Imanol Mugarza, David García Villaescusa, Lucas Borracci, Patrick Uven, Alvaro Jover-Alvarez |
DSD | 1 |
| 2023 | Software Updates Monitoring & Anomaly Detection
Imanol Etxezarreta, David García Villaescusa, Imanol Mugarza, Irune Yarza, Irune Agirre |
IoTBDS | 5 |
| 2021 | The UP2DATE Baseline Research PlatformsabstractThe UP2DATE H2020 project focuses on highperformance heterogeneous embedded platforms for critical systems. We will develop observability and controllability solutions to support online updates while ensuring safety and security for mixed-criticality tasks. In this paper, we describe the rationale behind the selection of the baseline research platforms which will be used to develop and demonstrate the project concepts, including a performance comparison to identify the most efficient one. Alvaro Jover-Alvarez, Alejandro J. Calderón, Iván Rodriguez, Leonidas Kosmidis, Kazi Asifuzzaman, Patrick Uven, Kim Grüttner, Tomaso Poggi, Irune Agirre |
DATE | 9 |
| 2021 | Towards functional safety compliance of matrix-matrix multiplication for machine learning-based autonomous systems
Javier Fernández 0004, Jon Pérez 0001, Irune Agirre, Imanol Allende, Jaume Abella 0001, Francisco J. Cazorla |
J. Syst. Archit. | 3 |
| 2020 | UP2DATE: Safe and secure over-the-air software updates on high-performance mixed-criticality systemsabstractFollowing the same trend of consumer electronics, safety-critical industries are starting to adopt Over-The-Air Software Updates (OTASU) on their embedded systems. The motivation behind this trend is twofold. On the one hand, OTASU offer several benefits to the product makers and users by improving or adding new functionality and services to the product without a complete redesign. On the other hand, the increasing connectivity trend makes OTASU a crucial cyber-security demand to download latest security patches. However, the application of OTASU in the safety-critical domain is not free of challenges, specially when considering the dramatic increase of software complexity and the resulting high computing performance demands. This is the mission of UP2DATE, a recently launched project funded within the European H2020 programme focused on new software update architectures for heterogeneous high-performance mixed-criticality systems. This paper gives an overview of UP2DATE and its foundations, which seeks to improve existing OTASU solutions by considering safety, security and availability from the ground up in an architecture that builds around composability and modularity. Irune Agirre, Peio Onaindia, Tomaso Poggi, Irune Yarza, Francisco J. Cazorla, Leonidas Kosmidis, Kim Grüttner, Mohammed Abuteir, Jan Loewe, Juan M. Orbegozo, Stefania Botta |
DSD | 1 |
| 2018 | Fitting Software Execution-Time Exceedance into a Residual Random Fault in ISO-26262abstractCar manufacturers relentlessly replace or augment the functionality of mechanical subsystems with electronic components. Most such subsystems (e.g., steer-by-wire) are safety related, hence, subject to regulation. ISO-26262, the dominant standard for road vehicles, regards software faults as systematic, while differentiating hardware faults between systematic and random. The analysis of systematic faults entails rigorous processes and qualitative considerations. The increasing complexity of modern on-board computers, however, questions the very notion of treating the violation of execution-time envelopes for software programs as a systematic fault. Modern hardware in fact reduces the user's ability to delve deep enough into the fabric of hardware-software interaction to gage its extent of contribution to the worst-case execution time (WCET). Changing the nature of the WCET-analysis problem may help address that challenge effectively. To this end, we propose a solution that should allow ISO-26262 to quantify the likelihood of execution-time exceedance events, relating it to target failure metrics employed in support of certification arguments, similarly to random faults in hardware. To this end, we inject randomization in the timing behavior of the computer hardware to relieve the user from the need to control hard-to-reach low-level parts, and use measurement-based probabilistic timing analysis to quantify, constructively, the failure rates resulting from the likelihood of execution-time exceedance events. Irune Agirre, Francisco J. Cazorla, Jaume Abella 0001, Carles Hernández 0001, Enrico Mezzetti, Mikel Azkarate-askatsua, Tullio Vardanega |
IEEE Trans. Reliab. | 1 |
| 2017 | EPC Enacted: Integration in an Industrial Toolbox and Use against a Railway ApplicationabstractMeasurement-based timing analysis approaches are increasingly making their way into several industrial domains on account of their good cost-benefit ratio. The trustworthiness of those methods, however, suffers from the limitation that their results are only valid for the particular paths and execution conditions that the user is able to explore with the available input vectors. It is generally not possible to guarantee that the collected measurements are fully representative of the worst-case timing behaviour. In the context of measurement-based probabilistic timing analysis, the Extended Path Coverage (EPC) approach has been recently proposed as a means to extend the representativeness of measurement observations, to obtain the same effect of full path coverage. At the time of its first publication, EPC had not reached an implementation maturity that could be trialled industrially. In this work we analyze the practical implications of using EPC with real-world applications, and discuss the challenges in integrating it in an industrial-quality toolchain. We show that we were able to meet EPC requirements and successfully evaluate the technique on a real Railway application, on top of a commercial toolchain and full execution stack. Enrico Mezzetti, Mikel Fernández, Alen Bardizbanyan, Irune Agirre, Jaume Abella 0001, Tullio Vardanega, Francisco J. Cazorla |
RTAS | 4 |
| 2016 | PROXIMA: Improving Measurement-Based Timing Analysis through Randomisation and Probabilistic AnalysisabstractThe use of increasingly complex hardware and software platforms in response to the ever rising performance demands of modern real-time systems complicates the verification and validation of their timing behaviour, which form a time-and-effort-intensive step of system qualification or certification. In this paper we relate the current state of practice in measurement-based timing analysis, the predominant choice for industrial developers, to the proceedings of the PROXIMA (Probabilistic real-time control of mixed-criticality multicore systems) project in that very field. We recall the difficulties that the shift towards more complex computing platforms causes in that regard. Then we discuss the probabilistic approach proposed by PROXIMA to overcome some of those limitations. We present the main principles behind the PROXIMA approach as well as the changes it requires at hardware or software level underneath the application. We also present the current status of the project against its overall goals, and highlight some of the principal confidence-building results achieved so far. Francisco J. Cazorla, Jaume Abella 0001, Jan Andersson, Tullio Vardanega, Francis Vatrinet, Iain Bate, Ian Broster, Mikel Azkarate-askatsua, Franck Wartel, Liliana Cucu-Grosjean, Fabrice Cros, Glenn Farrall, Adriana Gogonel, Andrea Gianarro, Benoit Triquet, Carles Hernández 0001, Code Lo, Cristian Maxim, David Morales, Eduardo Quiñones, Enrico Mezzetti, Leonidas Kosmidis, Irune Agirre, Mikel Fernández, Mladen Slijepcevic, Philippa Conmy, Walid Talaboulma |
DSD | 23 |
| 2015 | IEC-61508 SIL 3 Compliant Pseudo-Random Number Generators for Probabilistic Timing AnalysisabstractProbabilistic Timing Analysis (PTA), especially its measurement based variant (MBPTA), has shown to be competitive with state-of-the-art timing analysis techniques. The use of MBPTA to analyse the timing behaviour of safety-critical systems rests on its ability to derive trustworthy WCET bounds. This ability depends on the soundness of the MBPTA method per se, as well as on the satisfaction of safety requirements placed on the pseudo-random number generator (prng) that plays a key role in the platform-level randomisation needed by MBPTA. This paper presents the design of a low-area, low-power prng that meets IEC-61508 SIL 3 safety requirements and allows for seamless integration in a real-world multicore architecture. This work enables the development and the IEC-61508 certification of mixed-criticality systems that use MBPTA for deriving timing bounds for mixed-criticality software programs running on multicore processors. Irune Agirre, Mikel Azkarate-askatsua, Carles Hernández 0001, Jaume Abella 0001, Jon Pérez 0001, Tullio Vardanega, Francisco J. Cazorla |
DSD | 1 |
| 2015 | A Modular Safety Case for an IEC-61508 Compliant Generic HypervisorabstractThe development of mixed-criticality systems that integrate several functionalities of different criticality levels (e.g., SIL1-4 according to IEC-1508) on the same embedded computing platform provide benefit in terms of cost, size, weight, reliability and scalability. The soaring demand for high performance mixedcriticality system has contributed to their capabilities expansion. This upward trend is subject to certification processes with different levels of rigorousness, which lead to prohibitive cost. This paper presents the modular safety concept of an IEC-61508 generic hypervisor where the minimum reasonable safety arguments and evidences are defined. Additionally, the use of the modularity approach limits the impact of changes to a reduced area of the safety case, enabling in turn the reusability of the safety cases parts. The work described in this paper has been reviewed and approved by a certification body, within the context of a European research project. Asier Larrucea, Jon Pérez 0001, Irune Agirre, Vicent Brocal, Roman Obermaisser |
DSD | 3 |
| 2015 | Temporal independence validation of an IEC-61508 compliant mixed-criticality system based on multicore partitioningabstractThe transition from conventional federated embedded system architectures to mixed-criticality integrated multicore architectures provides benefits in terms of cost, size, weight, scalability and reliability. As a consequence, integrated mixedcriticality solutions are an objective for many embedded systems developers, although the challenges related with the safety certification of multicore approaches may hinder their adoption. Among many other stringent requirements, the safety standards demand to prove that the mixed-criticality systems are free of interferences, thus ensuring the spatial and temporal interdependence among applications. This paper contributes with a measured based temporal independence validation of a partitioned multicore mixed-criticality system. Asier Larrucea, Irune Agirre, Carlos F. Nicolás, Jon Pérez 0001, Mikel Azkarate-askatsua, Ton Trapman |
FDL | 2 |