EDBT 2026 Demo / reviewers in the wild / expert
Jon Pérez 0001
dblp:18/8122 · also Jon Pérez-Cerrolaza
· DBLP profile ↗
25ranked-venue papers
4as first author
9since 2021 · last 2025
0000-0001-6389-648XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 16 · 1 first-author · 7 since 2021Software engineering, systems software and programming languages · 6 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Towards a Safe End-to-End AI framework: MISRA C-Compliant YOLO for Object DetectionabstractArtificial Intelligence (AI) has traditionally prioritized high performance over compliance with functional safety standards such as IEC 61508. However, when AI systems are used in safety-related functions, it is essential to demonstrate that errors will not lead to malfunctions. This involves preventing systematic design-time errors and detecting and controlling runtime faults, as specified in IEC 61508. Moreover, ISO/PAS 8800 requires analyzing AI-specific development tools to identify and mitigate potential risks. In this paper, we take a step toward a safe end-to-end AI framework by focusing on systematic error avoidance in the implementation of You Only Look Once (YOLO), a widely used object detection model. A C-based version of YOLO-built on the Darknet framework-is analyzed using the Polyspace static analysis tool to assess MISRA C compliance. We apply corrective actions to eliminate violations, producing a MISRA $\mathbf{C}$-compliant implementation. In addition, we propose a runtime error detection mechanism using dual execution on a diverse platform and validate behavioral consistency using the COCO dataset. This approach supports the development of trustworthy AI systems by addressing both systematic errors and runtime detection. Javier Fernández 0004, Irune Agirre, Irune Yarza, Jon Pérez 0001 |
DSD | 4 |
| 2025 | Towards robust shielded reinforcement learning through adaptive constraints and exploration: The fear field frameworkabstractMachine Learning (ML) techniques, including Reinforcement Learning (RL), demonstrate potential as decisionmaking controllers.However, enhancing the robustness required for real-world deployment remains imperative.Within the realm of Safe RL, Shielded RL emerges as a solution, employing shields to block actions leading to unsafe states and offering safe alternatives through known policies.Yet, many Shielded RL methods rely on dynamic environment models, which may inaccurately predict future states, compromising controller robustness.We introduce the Fear Field framework to mitigate this issue for discrete Markov Decision Processbased (MDP) shields with strictly connected unsafe state spaces and fully observable states, which adjusts safe operation constraints based on disparities between model predictions and actual environmental dynamics.We employ parallel learning and Curriculum Learning (CL) strategies to mitigate lengthy training times in high state-space size environments.Additionally, an adaptive exploration algorithm enhances convergence rates amidst significant environmental dynamic shifts.In our case study, integrating CL and the adaptive exploration algorithm with the Fear Field framework reduces unsafe state occurrences by two orders of magnitude while enhancing convergence time following sudden environmental changes.The Fear Field framework significantly reduces unsafe states in the Frozen Lake Gridworld environment at low computational expense when model predictions deviate from reality, with negligible costs otherwise. Haritz Odriozola-Olalde, Maider Zamalloa, Nestor Arana-Arexolaleiba, Jon Pérez 0001 |
Eng. Appl. Artif. Intell. | 4 |
| 2025 | Linux for safety-critical systems: A surveyabstractNext-generation safety-critical systems, such as autonomous vehicles, are increasingly complex systems integrating high-performance computing devices, diverse software stacks, machine learning algorithms and software applications of different safety criticality. Industry and academia are showing growing interest in using Linux as a general-purpose operating system in these safety-critical systems due to its widespread adoption in embedded systems and critical domains (e.g., telecommunications, banking) and widespread support of computing devices, software stacks and machine learning software. However, meeting the requirements of safety standards, such as systematic error reduction techniques, random fault tolerance, and temporal and spatial independence, becomes a challenge. This is especially the case when integrating software applications of different safety criticality (mixed criticality). This literature survey examines works that propose, analyze and extend Linux for the development of safety-critical systems. We also identify the main challenges these works focus on. Finally, we also present an overview of the main industry efforts. Markel Galarraga, Charles-Alexis Lefebvre, Jon Pérez 0001, Jose Antonio Pascual |
J. Syst. Archit. | 3 |
| 2024 | Toward Linux-based safety-critical systems - Execution time variability analysis of Linux system callsabstractModern transportation and industrial domain safety-critical applications, such as autonomous vehicles and collaborative robots, exhibit a combination of escalating software complexity and the need to integrate diverse software stacks and machine learning algorithms, consequently demanding complex high-performance hardware. Linux’s extensive platform support and library ecosystem make it a valuable general-purpose operating system for developing complex software systems. However, because the Linux kernel has not been designed to comply with safety standards, it has a high execution path variability and does not provide execution time guarantees. In this context, several research initiatives have studied the usage of Linux for developing complex safety-related systems, focusing on topics that include its development process, isolation architectures, or test coverage estimation. Nonetheless, execution-time analysis and providing temporal guarantees is still a challenge. This work extends the novel statistical analysis of Linux system call execution paths with the analysis of execution-time variability and proposes a method for estimating the worst-case execution time, forming a sound approach for an in-depth analysis of the Linux kernel execution paths and execution times for safety-related systems. The proposed method is applied to a representative use case that implements an Autonomous Emergency Brake application in an NVIDIA Jetson Nano board connected to the CARLA autonomous driving simulator. Markel Galarraga, Charles-Alexis Lefebvre, Jon Pérez 0001, Jose Antonio Pascual |
J. Syst. Archit. | 3 |
| 2023 | SAFEXPLAIN: Safe and Explainable Critical Embedded Systems Based on AIabstractDeep Learning (DL) techniques are at the heart of most future advanced software functions in Critical Autonomous AI-based Systems (CAIS), where they also represent a major competitive factor. Hence, the economic success of CAIS industries (e.g., automotive, space, railway) depends on their ability to design, implement, qualify, and certify DL-based software products under bounded effort/cost. However, there is a fundamental gap between Functional Safety (FUSA) requirements on CAIS and the nature of DL solutions. This gap stems from the development process of DL libraries and affects high-level safety concepts such as (1) explainability and traceability, (2) suitability for varying safety requirements, (3) FUSA-compliant implementations, and (4) real-time constraints. As a matter of fact, the data-dependent and stochastic nature of DL algorithms clashes with current FUSA practice, which instead builds on deterministic, verifiable, and pass/fail test-based software. The SAFEXPLAIN project tackles these challenges and targets by providing a flexible approach to allow the certification - hence adoption - of DL-based solutions in CAIS building on: (1) DL solutions that provide end-to-end traceability, with specific approaches to explain whether predictions can be trusted and strategies to reach (and prove) correct operation, in accordance to certification standards; (2) alternative and increasingly sophisticated design safety patterns for DL with varying criticality and fault tolerance requirements; (3) DL library implementations that adhere to safety requirements; and (4) computing platform configurations, to regain determinism, and probabilistic timing analyses, to handle the remaining non-determinism. Jaume Abella 0001, Jon Pérez 0001, Cristofer Englund, Bahram Zonooz, Gabriele Giordana, Carlo Donzella, Francisco J. Cazorla, Enrico Mezzetti, Isabel Serra, Axel Brando, Irune Agirre, Fernando Eizaguirre, Thanh Hai Bui, Elahe Arani, Fahad Sarfraz, Ajay Balasubramaniam, Ahmed Badar, Ilaria Bloise, Lorenzo Feruglio, Ilaria Cinelli, Davide Brighenti, Davide Cunial |
DATE | 2 |
| 2022 | Optimization Techniques and Formal Verification for the Software Design of Boolean Algebra Based Safety-Critical SystemsabstractArtificial intelligence, and the ability to learn optimized solutions that comply with a set of safety rules, could facilitate the human-based design process of safety-critical systems. However, the reconciliation of state-of-the-art artificial intelligence technology with current safety standards and safety engineering processes is a challenge to be addressed. In this article, this publication describes a method based on optimization and on formal verification for the design of safety-critical systems that are defined by Boolean algebra. Several diverse optimization techniques and a hybrid of these approaches are used to find an optimized design that considers performance requirements, availability rules, and complies with all defined safety rules. Subsequently, this solution is translated into an alternative knowledge representation that can be formally verified and developed in compliance with currently considered safety standards. This method is evaluated with a simplified safety-critical case study. Jon Pérez 0001, Jose Luis Flores 0001, Christian Blum 0001, Jesús Cerquides, Alex Abuin |
IEEE Trans. Ind. Informatics | 1 |
| 2021 | Estimation of Linux Kernel Execution Path Uncertainty for Safety Software Test CoverageabstractWith the advent of next-generation safety-related systems, different industries face multiple challenges in ensuring the safe operation of these systems according to traditional safety and assurance techniques. The increasing complexity that characterizes these systems hampers the maximum achievable test coverage during system verification and, consequently, it often results in untested behaviors that hinder safety assurance and represent potential risk sources during system operation. In the context of paving the way towards quantifying the risks caused by software malfunction and, hence, towards the safety-compliance of next-generation safety-related systems, this paper studies and provides a method to estimate the probability of Linux kernel execution paths that remain unobserved during the test campaign. Imanol Allende, Nicholas Mc Guire, Jon Pérez 0001, Lisandro Gabriel Monsalve, Javier Fernández 0004, Roman Obermaisser |
DATE | 3 |
| 2021 | Towards Linux based safety systems - A statistical approach for software execution path coverage
Imanol Allende, Nicholas Mc Guire, Jon Pérez 0001, Lisandro Gabriel Monsalve, Roman Obermaisser |
J. Syst. Archit. | 3 |
| 2021 | Towards functional safety compliance of matrix-matrix multiplication for machine learning-based autonomous systems
Javier Fernández 0004, Jon Pérez 0001, Irune Agirre, Imanol Allende, Jaume Abella 0001, Francisco J. Cazorla |
J. Syst. Archit. | 2 |
| 2017 | Modular Development and Certification of Dependable Mixed-Criticality SystemsabstractThe transition from conventional federated architectures to integrated architectures enables the integration of functionalities with different criticality with respect to safety, security and real-time on a single embedded computing platform. Mixed-criticality networks provide safe and predictable communication for functionalities with different criticality, offering benefits regarding spatial and temporal segregation. However, they imply certification challenges due to the increasing demand for features with different criticality, which lead to a significant and potentially unacceptable increase of engineering and certification costs. On the other hand, the traditional certification process relies on the assessment of the entire system where if a requirement changes, the whole system shall be re-attested. This paper analyses modularity from a system-of-system and a product line development perspective and contributes a reusable generic modular safety concept where the safety arguments that a mixed-criticality network must provide to be compliant with the IEC 61508 safety standard are defined. This safety case is used for defining the linking analyses where the way in which two industrial networks fulfil the safety-related arguments stated in the safety concept are analysed. Asier Larrucea, Imanol Martinez, Carlos F. Nicolás, Jon Pérez 0001, Roman Obermaisser |
DSD | 4 |
| 2016 | A Realistic Approach to a Network-on-Chip Cross-Domain PatternabstractThe transition from conventional federated architectures to integrated architectures enables the integration of functionalities with different criticality (such as safety, security and real-time) on a single embedded computing platform. Many embedded systems require distributed subsystems with networks (e.g., EtherCAT or Ethernet) to satisfy computational resource demands and installation requirements and ensure fault-tolerance. The broad trend of the integration of functionalities with different criticality on a single embedded computing platform involves the implementation of safe and predictable communication systems with temporal segregation between different criticality. However, they represent challenges of certification such as the guarantee of non-interference between safety-critical and non-safety-critical communications, which leads to the increase of engineering and certification cost. This paper contributes a network-on-chip cross-domain pattern which provides a generic solution to recurring problems in mixed-criticality networks. In addition, this paper presents a modular safety case for an IEC 61508 compliant mixed-criticality network that is used for defining the linking analysis of the proposed network pattern. On the other hand, this paper also defines the integration of the cross-domain pattern on a simplified wind turbine case study. Asier Larrucea, Hamidreza Ahmadian, Roman Obermaisser, Jon Pérez 0001, Carlos F. Nicolás |
DSD | 4 |
| 2016 | SAFEPOWER Project: Architecture for Safe and Power-Efficient Mixed-Criticality SystemsabstractWith the ever increasing industrial demand for bigger, faster and more efficient systems, a growing number of cores is integrated on a single chip. Additionally, their performance is further maximized by simultaneously executing as many processes as possible not regarding their criticality. Even safety critical domains like railway and avionics apply these paradigms under strict certification regulations. As the number of cores is continuously expanding, the importance of cost-effectiveness grows. One way to increase the cost-efficiency of such System on Chip (SoC) is to enhance the way the SoC handles its power resources. By increasing the power efficiency, the reliability of the SoC is raised, because the lifetime of the battery lengthens. Secondly, by having less energy consumed, the emitted heat is reduced in the SoC which translates into fewer cooling devices. Though energy efficiency has been thoroughly researched, there is no application of those power saving methods in safety critical domains yet. The EU project SAFEPOWER1 targets this research gap and aims to introduce certifiable methods to improve the power efficiency of mixed-criticality real-time systems (MCRTES). This paper will introduce the requirements that a power efficient SoC has to meet and the challenges such a SoC has to overcome. Alina Lenz, Mikel Azkarate-askatsua, Javier Coronel, Alfons Crespo, Simon Davidmann, Juan Carlos Diaz Garcia, Nera González Romero, Kim Grüttner, Roman Obermaisser, Johnny Öberg, Jon Pérez 0001, Ingo Sander, Ingemar Söderquist |
DSD | 11 |
| 2016 | Supporting pattern-based dependability engineering via model-driven development: Approach, tool-support and empirical validation
Brahim Hamid, Jon Pérez 0001 |
J. Syst. Softw. | 2 |
| 2015 | IEC-61508 SIL 3 Compliant Pseudo-Random Number Generators for Probabilistic Timing AnalysisabstractProbabilistic Timing Analysis (PTA), especially its measurement based variant (MBPTA), has shown to be competitive with state-of-the-art timing analysis techniques. The use of MBPTA to analyse the timing behaviour of safety-critical systems rests on its ability to derive trustworthy WCET bounds. This ability depends on the soundness of the MBPTA method per se, as well as on the satisfaction of safety requirements placed on the pseudo-random number generator (prng) that plays a key role in the platform-level randomisation needed by MBPTA. This paper presents the design of a low-area, low-power prng that meets IEC-61508 SIL 3 safety requirements and allows for seamless integration in a real-world multicore architecture. This work enables the development and the IEC-61508 certification of mixed-criticality systems that use MBPTA for deriving timing bounds for mixed-criticality software programs running on multicore processors. Irune Agirre, Mikel Azkarate-askatsua, Carles Hernández 0001, Jaume Abella 0001, Jon Pérez 0001, Tullio Vardanega, Francisco J. Cazorla |
DSD | 5 |
| 2015 | A Modular Safety Case for an IEC-61508 Compliant Generic HypervisorabstractThe development of mixed-criticality systems that integrate several functionalities of different criticality levels (e.g., SIL1-4 according to IEC-1508) on the same embedded computing platform provide benefit in terms of cost, size, weight, reliability and scalability. The soaring demand for high performance mixedcriticality system has contributed to their capabilities expansion. This upward trend is subject to certification processes with different levels of rigorousness, which lead to prohibitive cost. This paper presents the modular safety concept of an IEC-61508 generic hypervisor where the minimum reasonable safety arguments and evidences are defined. Additionally, the use of the modularity approach limits the impact of changes to a reduced area of the safety case, enabling in turn the reusability of the safety cases parts. The work described in this paper has been reviewed and approved by a certification body, within the context of a European research project. Asier Larrucea, Jon Pérez 0001, Irune Agirre, Vicent Brocal, Roman Obermaisser |
DSD | 2 |
| 2015 | Temporal independence validation of an IEC-61508 compliant mixed-criticality system based on multicore partitioningabstractThe transition from conventional federated embedded system architectures to mixed-criticality integrated multicore architectures provides benefits in terms of cost, size, weight, scalability and reliability. As a consequence, integrated mixedcriticality solutions are an objective for many embedded systems developers, although the challenges related with the safety certification of multicore approaches may hinder their adoption. Among many other stringent requirements, the safety standards demand to prove that the mixed-criticality systems are free of interferences, thus ensuring the spatial and temporal interdependence among applications. This paper contributes with a measured based temporal independence validation of a partitioned multicore mixed-criticality system. Asier Larrucea, Irune Agirre, Carlos F. Nicolás, Jon Pérez 0001, Mikel Azkarate-askatsua, Ton Trapman |
FDL | 4 |
| 2014 | A Safety Certification Strategy for IEC-61508 Compliant Industrial Mixed-Criticality Systems Based on Multicore PartitioningabstractThe development of mixed-criticality systems that integrate applications of different criticality levels (safety, security, real-time and non real-time) can provide multiple benefits such as product cost-size-weight reduction, reliability increase and scalability. However, the integration of applications with different criticality levels leads to several challenges with respect to safety certification standards. This paper defines a safety certification strategy for IEC-61508 compliant industrial mixed-criticality systems based on multicore partitioning. This approach is illustrated with a safety concept of a simplified IEC-61508 compliant wind-turbine mixed-criticality system, reviewed and approved by a certification authority. Jon Pérez 0001, Carlos F. Nicolás, Ton Trapman, Jose Miguel Garate |
DSD | 1 |
| 2014 | A novel modeling framework for time-triggered safety-critical embedded systemsabstractThis paper presents the Platform Specific Time Triggered Model (PS-TTM), a SystemC based modeling and simulation framework for time-triggered safety-critical embedded systems. The approach facilitates the modeling of Time-Triggered Architecture (TTA) based embedded systems, following a strict separation between the designs of functionality and platform. The PS-TTM provides a value and time domain deterministic simulation environment for an early functional and temporal assessment of the systems. Moreover, the framework includes a time-triggered automatic test executor that enables to perform non-intrusive simulated fault injection (SFI) to the models. The SFI makes an early dependability assessment possible, what reduces the risk of late and expensive discovery of safety related pitfalls. The feasibility of the proposed framework is illustrated with a case study, based on the modeling, simulation and validation of a simplified railway on-board signaling system. Iban Ayestaran, Carlos F. Nicolás, Jon Pérez 0001, Asier Larrucea, Peter P. Puschner |
FDL | 3 |
| 2014 | Modeling and Simulated Fault Injection for Time-Triggered Safety-Critical Embedded SystemsabstractThe development and certification of safety critical embedded systems require the implementation of fault-tolerance mechanisms to ensure the safe operation of the system even in the presence of faults. These mechanisms need to be verified and validated by means of fault injection. Simulated fault injection enables an early dependability assessment that validates the correct implementation of fault-tolerance mechanisms and reduces the risk of late and expensive discovery of safety related pitfalls. This paper presents a novel modeling and simulation framework for time-triggered safety critical embedded systems. Our approach supports simulated fault injection at different abstraction levels (platform independent and platform specific models) and integrates a time-triggered automatic test executor for the early verification and validation of the systems. The feasibility of the proposed framework is illustrated with a case study where a simplified railway signaling system is modeled and simulated at different levels of abstraction. Iban Ayestaran, Carlos F. Nicolás, Jon Pérez 0001, Asier Larrucea, Peter P. Puschner |
ISORC | 3 |
| 2014 | A Simulated Fault Injection Framework for Time-Triggered Safety-Critical Embedded Systems
Iban Ayestaran, Carlos F. Nicolás, Jon Pérez 0001, Asier Larrucea, Peter P. Puschner |
SAFECOMP | 3 |
| 2013 | SCA extensions to support safety critical distributed embedded systemsabstractComponent Based Software Engineering (CBSE) is being increasingly applied in the distributed embedded systems (DES) domain as long as these systems are getting more and more complex in terms of flexibility, dynamism or heterogeneity. Besides that, safety critical systems must cope with the fulfillment of safety requirements and certification standards. This factor increases considerably the development cost of safety distributed embedded systems, even more if they must cope with flexibility, dynamism and heterogeneity. This paper focuses on the distribution aspects of such systems, and more specifically on safe communication channels for safety critical distributed systems. The proposed approach describes a certifiable general purpose safety communication layer that could be reused in different systems, thereby reducing the cost of system development and certification. Aitor Agirre, Jon Pérez 0001, Rafael Priego, Marga Marcos, Elisabet Estévez-Estévez |
ETFA | 2 |
| 2013 | R3TOS: A Novel Reliable Reconfigurable Real-Time Operating System for Highly Adaptive, Efficient, and Dependable Computing on FPGAsabstractDespite the clear potential of FPGAs to push the current power wall beyond what is possible with general-purpose processors, as well as to meet ever more exigent reliability requirements, the lack of standard tools and interfaces to develop reconfigurable applications limits FPGAs' user base and makes their programming not productive. R3TOS is our contribution to tackle this problem. It provides systematic OS support for FPGAs, allowing the exploitation of some of the most advanced capabilities of FPGA technology by inexperienced users. What makes R3TOS special is its nonconventional way of exploiting on-chip resources: These are used indistinguishably for carrying out either computation or communication tasks at different times. Indeed, R3TOS does not rely on any static infrastructure apart from its own core circuitry, which is constrained to a specific region within the FPGA where it is implemented. Thus, the rest of the device is kept free of obstacles, with the spare resources ready to be used as and whenever needed. At runtime, the hardware tasks are scheduled and allocated with the dual objective of improving computation density and circumventing damaged resources on the FPGA. Xabier Iturbe, Khaled Benkrid, Chuan Hong, Ali Ebrahim, Raul Torrego, Imanol Martinez, Tughrul Arslan, Jon Pérez 0001 |
IEEE Trans. Computers | 8 |
| 2010 | Modeling Time-Triggered Architecture Based Safety-Critical Embedded Systems Using SystemC
Jon Pérez 0001, Carlos F. Nicolás, Roman Obermaisser, Christian El Salloum |
FDL | 1 |
| 2010 | Executable Time-Triggered Model (E-TTM) for Real-Time Control SystemsabstractThe development of distributed real-time control-systems that must satisfy a certain set of timing constraints with an ever-increasing functionality leads to a considerable complexity growth. Tackling the complexity challenge and providing a consistent notion of time are key challenges, on which this research work is focused. The proposed Executable Time-Triggered Model (E-TTM) provides a deterministic (time and value domain) executable modeling approach for the composable development of distributed real-time control-systems. E-TTM provides a consistent notion of time and supports different strategies to tackle the complexity challenge such as abstraction, partition and segmentation. E-TTM metamodel has been implemented as a C++ library that extends SystemC with the time-triggered Model of Computation (MoC). This approach is illustrated with a case study. Jon Pérez 0001, Antonio Perez, Roman Obermaisser |
ISORC | 1 |
| 2009 | A novel SEU, MBU and SHE handling strategy for Xilinx Virtex-4 FPGAsabstractThis paper presents a new single event upset (SEU), multiple bit upset (MBU) and single hardware error (SHE) mitigation strategy to be used in Virtex-4 FPGAs. This strategy aims to increase not only the effectiveness of traditional triple module redundancy (TMR), but also the overall system availability. Frame readback with ECC detection and frame scrubbing are combined in a dynamically reconfigurable TMR architecture, designed under both spatial and implementation diversification premises. Moreover, since the strategy works on the device's bitstream domain, the basis for Virtex-4 FPGAs bitstream definition are also shown. Xabier Iturbe, Mikel Azkarate-askatsua, Imanol Martinez, Jon Pérez 0001, Armando Astarloa |
FPL | 4 |