EDBT 2026 Demo / reviewers in the wild / expert
Niclas Ericsson
dblp:188/9068
· DBLP profile ↗
11ranked-venue papers
5as first author
5since 2021 · last 2025
0000-0002-6657-2496ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 10 · 5 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Machine Learning-Driven Intrusion Detection and Identification in Industrial Control SystemsabstractUsing machine learning to detect and identify cyberattacks in Industrial Control Systems (ICS) offers a promising solution for uncovering zero-day attacks that traditional rulebased models cannot detect. However, applying ML-based intrusion detection in ICS environments presents challenges, including limited availability of attack data and difficulty in accurately identifying attack types. This paper addresses these challenges by proposing two key strategies. First, we demonstrate that the predictable traffic patterns of ICS networks enable the use of semi-supervised learning models for attack detection. We validate this approach using a benchmark dataset, showing that semi-supervised models achieve comparable performance to fully supervised models while relying solely on training with normal network data. Second, we propose a sequence-based approach for attack identification, using temporal data to improve the accuracy of identifying specific attack types. Our experiments reveal that incorporating historical network parameters improves the attack identification. Our research underscores the potential of semisupervised learning for effective attack detection and highlights the importance of incorporating network temporal properties to improve attack identification. Alireza Dehlaghi-Ghadim, Mona Moslemzade, Nima Pattiyampully Dharmapal, Niclas Ericsson, Mahshid Helali Moghadam, Ali Balador, Hans A. Hansson |
PDP | 4 |
| 2024 | Using Decision Support to Fortify Industrial Control System Against CyberattacksabstractThis paper presents a cybersecurity solution designed to fortify Industrial Control Systems (ICS) against cyberattacks. The proposed solution integrates a Network-based Intrusion Detection System (NIDS) with a Decision Support System (DSS), leveraging machine learning to detect anomalies in network data and employing a filtering mechanism to reduce false alarms. The NIDS protects a simulated ICS testbed, detecting anomalies and forwarding them to the DSS for further analysis and selection of mitigation strategies. We outline the system architecture and showcase promising outcomes from a prototype implementation. Our proof of concept evaluation demonstrates high accuracy in detecting attack scenarios. Challenges such as detection delays between attacks and potential mitigations high-light areas for future improvement. This research contributes to bridging the gap between ML-based IDS and security solutions, paving the way for enhanced cybersecurity in ICS environments. Alireza Dehlaghi-Ghadim, Niclas Ericsson, Lars-Göran Magnusson, Mats Eriksson, Mahshid Helali Moghadam, Ali Balador, Hans A. Hansson |
ETFA | 2 |
| 2021 | Exploring ways to improve reuse between Industrial Embedded Systems and Discrete Event SimulatorsabstractIndustrial real-time software is commonly evaluated on real embedded systems, while simulators are less used, since the abstraction level and purpose vary with for example, different programming languages and run-time contexts. This paper extends, applies, and evaluates previous work on a flexible task design that improve code reuse between discrete event simulators and embedded real-time systems. The paper focuses on two parts: (i) The performance cost of the proposed design in practice, by comparing the flexible task design with a traditional threaded approach. (ii) The potential of an alternative way to support legacy code in combination with discrete event simulation. The experiments indicate an almost negligible performance cost with respect to the real-time behavior, i.e., latency and jitter, while enabling improved code reuse between discrete event simulation and industrial embedded real-time systems. Niclas Ericsson, Johan Åkerberg, Mats Björkman, Tomas Lennvall, Stig Larsson 0002, Hongyu Pei Breivold |
ETFA | 1 |
| 2021 | Design considerations introducing analytics as a "dual use" in complex industrial embedded systemsabstractEmbedded systems are today often self-sufficient with limited and predefined communication. However, this traditional view of embedded systems is changing through advancements in technologies such as, communication, cloud technologies, and advanced analytics including machine learning. These advancements have increased the benefits of building Systems of Systems (SoS) that can provide a functionality with unique capabilities that none of the included subsystems can accomplish separately. By this gain of functionality the embedded system is evolving towards a “dual use” purpose11In this paper we define dual usage as a control system having two purposes. In other contexts such as politics, diplomacy and export control, the term “dual-use” refers to technology that can be used for both peaceful and military aims, e.g., nuclear power technology., The use is dual in the sense that the system still needs to handle its original task, e.g., control and protect of an asset, and it must provide information for creating the SoS. Larger installations, e.g., industry plants, power systems and generation, have in most cases a long expected life-cycle, some up to 30–40 years without significant updates, compared to analytical functions that evolve and change much faster, i.e., requiring new types of data sets from the subsystems, not know at its first deployment. This difference in development cycles calls for new solutions supporting updates related to new requirements inherent in analytical functions. In this paper, within the context of “dual usage” of systems and subsystems, we analyze the impact on an embedded system, new or legacy, when it is required to provide analytic data with high quality. We compare a reference system, implementing all functions in one CPU core, to three other alternative solutions: a) a multi-core system where we are using a separate core for analytics, b) using a separate analytics CPU and c) analytics functionality located in a separate subsystem. Our conclusion is that the choice of analytics information collection method should to be based on intended usage, along with resulting complexity and cost of updates compared to hardware cost. Daniel Hallmans, Kristian Sandström, Stig Larsson 0002, Niclas Ericsson, Thomas Nolte |
ETFA | 4 |
| 2021 | Improving Code Reuse between Industrial Embedded Systems and Discrete Event SimulatorsabstractMost evaluations of industrial real-time software are conducted on real embedded systems. The use of simulators that provides easily reproducible evaluations is often limited, due to different levels of abstraction, e.g., programming languages and run-time contexts. This paper extends previous work on a flexible task design, enabling tasks to be agnostic to run-time context, with evaluations conducted on bare-metal and real-time operating systems. Based on the same design and experiments we extend the proof-of-concept implementation in a discrete event simulation context, executing on a Windows based simulation host. Our experiments show that the flexible task design can be driven in a simulation run-time context, and still support typical industrial constructs. The result indicates that improved code reuse between discrete event simulators and industrial embedded systems is feasible. Niclas Ericsson, Johan Åkerberg, Mats Björkman, Tomas Lennvall, Stig Larsson 0002, Hongyu Pei Breivold |
INDIN | 1 |
| 2020 | A Flexible Task Design for Industrial Embedded SystemsabstractThe run-time context in industrial embedded systems varies from bare-metal microcontrollers, to multicore-processors running real-time operating systems. Due to the longevity of industrial systems, reusability and evolvability are often considered crucial quality attributes. This paper presents a new flexible task design that enables tasks to be agnostic to run-time context. Evaluations of the design were made by conducting experiments using a proof of concept implementation of the proposed design. The experiments were based on typical industrial constructs, such as periodic tasks, and event signaling from interrupts. Findings from the experiments show that tasks can be more agnostic to run-time context and still deliver functionality normally used within industry. The results indicate that it is feasible to improve reusability and evolvability between different run-time contexts, and in addition, support hybrid configurations that can reduce resource usage, since e.g. a thread can be easily shared among several tasks. Niclas Ericsson, Johan Åkerberg, Mats Björkman, Tomas Lennvall, Stig Larsson 0002, Hongyu Pei Breivold |
IECON | 1 |
| 2019 | Experiments on Approaches of Virtualization for Industrial Internet of Things applicationsabstractNew technologies that comes with recent trends like Internet of Things, Cloud and 5G are promoting new platforms and communication solutions. These trends have also started to impact traditional industrial automation systems, since end customers are starting to expect new services, such as, business intelligence and diagnostic information anywhere at any time. Moreover, the cloud providers lease their infrastructure to be used for deployment of applications using virtualization. Therefore, this paper aims at exploring the possibilities of different virtualization platforms offered by various cloud providers and benchmark the technologies with platforms frequently used within industry. The platform performance was evaluated by conducting experiments with an industrial application, focusing on typical industrial aspect such as latency, jitter and availability. In addition to more industrial focused metrics, the findings in comparison with other related experiments indicate that specific application requirements have an effect on performance. Hence, application specific evaluations may be necessary before taking any decision on where an industrial application may be deployed. Gargi Bag, Luka Lednicki, Krister Landernäs, Niclas Ericsson |
ETFA | 4 |
| 2019 | Analyzing availability and QoS of service-oriented cloud for industrial IoT applicationsabstractInternet of Things and cloud services are one of main enablers in fourth industrial revolution. Real-time industrial systems have high availability requirements of 99.9% to 99.999% whereas architectures built on regional cloud services and IoT do not provide similar guarantees or Service Level Agreement. These differences of QoS and SLA availability between Operational Technology and Information Technology has become a main challenge in adoption of Industrial Internet of Things (IIoT) for real-time applications.This work presents an approach to find end-to-end QoS and availability for an IIoT architecture. Device-to-cloud, cloud-to-cloud and inside-cloud experiments have been performed over eight weeks where each experiment have more then four million QoS measurements. Our availability analysis shows that a remote IoT connected to a less busy cloud region gives higher availability as compared to an IoT device inside a busy cloud region. IIoT and regional cloud services provide good QoS with 99% to 99.9% availability for 1sec soft real-time requirements. In 100ms applications, more efforts are required to achieve higher then 95% availability and design industrial SLA. IIoT applications with 10sec latency like machine learning models can get 99.9% availability with cloud. Availability loss due to communication is almost 1% for 100ms applications. These results also provide requirements and future work of industrial edge computing for IIoT on real-time cloud. Jawad Mustafa, Kristian Sandström, Niclas Ericsson, Larisa Rizvanovic |
ETFA | 3 |
| 2017 | Communication middleware technologies for industrial distributed control systems: A literature reviewabstractIndustry 4.0 is the German vision for the future of manufacturing, where smart factories use information and communication technologies to digitise their processes to achieve improved quality, lower costs, and increased efficiency. It is likely to bring a massive change to the way control systems function today. Future distributed control systems are expected to have an increased connectivity to the Internet, in order to capitalize on new offers and research findings related to digitalization, such as cloud, big data, and machine learning. A key technology in the realization of distributed control systems is middleware, which is usually described as a reusable software layer between operating system and distributed applications. Various middleware technologies have been proposed to facilitate communication in industrial control systems and hide the heterogeneity amongst the subsystems, such as OPC UA, DDS, and RT-CORBA. These technologies can significantly simplify the system design and integration of devices despite their heterogeneity. However, each of these technologies has its own characteristics that may work better for particular applications. Selection of the best middleware for a specific application is a critical issue for system designers. In this paper, we conduct a survey on available standard middleware technologies, including OPC UA, DDS, and RT-CORBA, and show new trends for different industrial domains. Ali Balador, Niclas Ericsson, Zeinab Bakhshi |
ETFA | 2 |
| 2017 | Custom simulation of Industrial Wireless Sensor and Actuator Network for improved efficiency during research and developmentabstractTrends like the Cloud, Internet of Things and 5G are pushing for an increase in connectivity, but, introducing a new type of network in an industrial distributed control system is a big investment with high risks. Time to market with sufficient quality is crucial. However, when getting through the Research and Development (R&D) phases, a lot of time is spent on isolated activates, e.g., simulations, collecting requirements, design, coding, debugging, creating testbeds, and performing various tests. Therefore, there is a need to improve efficiency when moving between the R&D phases. For verification and validation of communication software, the most common network evaluation method in industry are real testbeds, mostly since a testbed can be very similar to the deployed system. Testbeds are, however, hard to debug and costly to maintain. Other network evaluation methods like simulators, have some strengths that testbeds are lacking, like repeatability, control over the network, and lower cost. However, code from simulators can seldom be reused, especially in industrial time-sensitive target systems, due to different abstraction levels, run-time behavior and system timing. This paper presents findings from a case study that targets improved efficiency, getting from research theories, to deployed devices in a homogeneous Industrial Wireless Sensor and Actuator Network (IWSAN). We propose a small subset of network simulators features which eases changeability, reuse, and debugging of communication software. The selected simulator features are evaluated with a proof of concept implementation that is customized to a research platform. The findings indicate improved efficiency when moving back and forth between activities in different R&D phases. Niclas Ericsson, Tomas Lennvall, Johan Åkerberg, Mats Björkman |
ETFA | 1 |
| 2016 | Challenges from research to deployment of industrial distributed control systemsabstractA trend in the industrial domain is that the networks are growing and becoming more complex, this is further accelerated by the digitalization trend. In order to address this, there is a need to improve the efficiency when moving between the R&D phases. For example, integrate innovative research findings into industrial systems, shorten time to market, improve product quality and reduce the number of issues. Despite a huge research effort on network simulators and emulators there are still some issues that needs to be addressed. This paper presents challenges that needs to be resolved, in order for the industry to adopt and benefit from using network simulators and emulators. The major challenges streamlining the workflow in and between the different R&D phases while preserving the real-time aspects in the entire industrial distributed control system. Niclas Ericsson, Tomas Lennvall, Johan Åkerberg, Mats Björkman |
INDIN | 1 |