EDBT 2026 Demo / reviewers in the wild / expert
Irune Yarza
dblp:208/7730
· DBLP profile ↗
10ranked-venue papers
1as first author
8since 2021 · last 2025
0000-0002-3607-7443ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 8 · 6 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Security and privacy · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | SAFEXPLAIN: a Complete Approach Towards Trustworthy AI-Based Safety-Critical SystemsabstractAI becomes increasingly important in safetycritical systems, especially in the case of autonomous systems, since navigation relies on AI for object detection and collision avoidance. However, safety-critical systems must adhere to functional safety standards that enforce software to be correct-by-construction, component decomposition to simplify design and validation, and the use of data only for testing purposes not to design the system itself. AI in general, and Deep Learning (DL) in particular have opposed characteristics since they have error rates (e.g., due to mispredictions), AI/DL modules can only be designed and validated monolithically, and they build on data for their design (i.e. for training purposes). Hence, DL solutions are at odds with the development process of safetycritical systems. A number of standards have recently emerged in different domains to reconcile the requirements of safety-critical systems with the characteristics of DL solutions, such as ISO 21448, ISO/IEC TR 5469, and ISO 8800, among others. However, there is a lack of realistic practice to design a DL-based safety-critical system in accordance with those regulations, and existing solutions only cover some aspects in isolation, and are often incompatible among them. SAFEXPLAIN is a 3-year Horizon Europe project addressing this challenge. SAFEXPLAIN, which finishes in September 2025, has already reached its main goals providing specific and complementary solutions to all those challenges so that AIbased safety-critical systems can be designed, implemented and validated adhering to the relevant functional safety standards in domains such as automotive, space and railway. In particular, SAFEXPLAIN provides the concepts, processes, tools and frameworks addressing the challenge end-to-end, from concept to solution. This is proven by the successful application of the SAFEXPLAIN approach in three case studies from the automotive, space and railway domains, whose results will see the light very soon. Jaume Abella 0001, Irune Agirre, Thanh Hai Bui, Frank Geujen, Gabriele Giordana, Carlo Donzella, Francisco J. Cazorla, Enrico Mezzetti, Axel Brando, Javier Fernández 0004, Irune Yarza, Joanes Plazaola, Maria Ulan, Rob Lavreysen, Lucas Tosi, Ilaria Bloise, Lorenzo Feruglio, Ilaria Cinelli, Stefano Lodico, William Guarienti, Giuseppe Nicosia, Valeria Dallara |
DSD | 11 |
| 2025 | Towards a Safe End-to-End AI framework: MISRA C-Compliant YOLO for Object DetectionabstractArtificial Intelligence (AI) has traditionally prioritized high performance over compliance with functional safety standards such as IEC 61508. However, when AI systems are used in safety-related functions, it is essential to demonstrate that errors will not lead to malfunctions. This involves preventing systematic design-time errors and detecting and controlling runtime faults, as specified in IEC 61508. Moreover, ISO/PAS 8800 requires analyzing AI-specific development tools to identify and mitigate potential risks. In this paper, we take a step toward a safe end-to-end AI framework by focusing on systematic error avoidance in the implementation of You Only Look Once (YOLO), a widely used object detection model. A C-based version of YOLO-built on the Darknet framework-is analyzed using the Polyspace static analysis tool to assess MISRA C compliance. We apply corrective actions to eliminate violations, producing a MISRA $\mathbf{C}$-compliant implementation. In addition, we propose a runtime error detection mechanism using dual execution on a diverse platform and validate behavioral consistency using the COCO dataset. This approach supports the development of trustworthy AI systems by addressing both systematic errors and runtime detection. Javier Fernández 0004, Irune Agirre, Irune Yarza, Jon Pérez 0001 |
DSD | 3 |
| 2024 | The METASAT Model-Based Engineering Workflow and Digital Twin ConceptabstractConsidering the complexity in the design of future satellites and the need for compliance with ECSS standards, the METASAT project proposes a novel design methodology based on model-based engineering and supported by open architecture hardware. The initiative highlights the potential of software vir-tualisation layers, like hypervisors, to meet standards compliance on high-performance computing platforms. Our focus is on the development of a toolchain tailored for these advanced hard-ware/software layers. In our view, without such innovation, the satellite industry may face high and unsustainable development costs and timelines, which could affect its competitiveness and reliability. This paper provides an overview of the model-based engineering toolchain, the workflow, and the digital twin concept proposed for the METASAT project. We present the purpose of each component and how they work together in the broader METASAT vision, with the objective of showing how this approach can make the development process more efficient and enhance dependability in the sector. Alejandro J. Calderón, Irune Yarza, Stefano Sinisi, Lorenzo Lazzara, Valerio Di Valerio, Giulia Stazi, Leonidas Kosmidis, Matina Maria Trompouki, Alessandro Ulisse, Aitor Amonarriz, Peio Onaindia |
DATE | 2 |
| 2023 | UP2DATE software updating framework compliance with safety and security regulations and standardsabstractOver-the-air Software Updates (OTASU) in the critical domain are already a reality. OTASU provide huge benefits in terms of user experience, security, and efficiency. However, due to involved risks, safety and security mechanisms and new regulations are needed for their adoption in the critical domain. The automotive industry is already in the race to adopt safe and secure OTASU, as by 2024, compliance to new UN regulations will become compulsory. However, the standards providing the specifications and requirements for OTASU are still in their infancy. Many other dependable system domains, that are now more digital and connected than ever, are following same trends towards OTASU. For instance, OTASU are very likely to be adopted in the railway domain in a near future, as the ability of remotely updating railway equipment considerably reduces maintenance costs and time, improving system availability. This paper describes how the UP2DATE framework adheres to existing and emerging regulations and standards and evaluates them through a railway case-study. Obtained results demonstrate that the proposed updating framework can provide great savings in the installation and maintenance phases of railway signalling devices by reducing the time required for the update and by removing the need for operator presence on-site. Irune Agirre, Alejandro J. Calderón, Irune Yarza, Imanol Mugarza, David García Villaescusa, Lucas Borracci, Patrick Uven, Alvaro Jover-Alvarez |
DSD | 3 |
| 2023 | Unraveling the Mystery of NVIDIA's Unified Memory for Safety-Critical GPU SystemsabstractIn the domain of safety-critical systems there is an increasing need for more compute-capable and higher performance devices. This comes from the dramatic increase on the software complexity caused by the newest intelligent and autonomous systems. Graphics Processing Units (GPUs), as multi-processing accelerators, are an ideal choice in this aspect due to their ability to handle big amount of data and computations. In order to ease the challenging task of programming such devices, vendors are continuously adding features, such as Unified Memory (UM), which allow the programmers to reduce their developing time on GPU applications. However, the use of GPU poses several challenges on safety-critical systems due to its close source nature and proprietary implementation. Therefore, this paper shows a deeper insight on how this feature works and present a way of exploiting this knowledge to reduce the execution time of applications using NVIDIA's UM feature. We demonstrate that these optimizations can make the data migrations predictable and reduce the required time. Xabier Arauzo, Irune Yarza, Leonidas Kosmidis, Alejandro J. Calderón, Marcos Rodriguez |
DSD | 2 |
| 2023 | Software Updates Monitoring & Anomaly Detection
Imanol Etxezarreta, David García Villaescusa, Imanol Mugarza, Irune Yarza, Irune Agirre |
IoTBDS | 4 |
| 2021 | Legacy software migration based on timing contract aware real-time execution environments
Irune Yarza, Mikel Azkarate-askatsua, Peio Onaindia, Kim Grüttner, Philipp Ittershagen, Wolfgang Nebel |
J. Syst. Softw. | 1 |
| 2021 | Time Measurement and Control Blocks for Bare-Metal C++ ApplicationsabstractPrecisely timed execution of resource constrained bare-metal applications is difficult, because the embedded software developer usually has to implement and check the timeliness of the executed application through manual interaction with timers or counters. In the scope of this work, we propose a combined timing specification and concept for time annotation and control blocks in C++. Our proposed blocks can be used to measure and profile software block execution time. Furthermore, it can be used to control and enforce the software time behavior at runtime. After the application of these time blocks, a trace-based verification against the block-based timing specification can be performed to obtain evidence on the correct implementation and usage of the time blocks on the target platform. We have implemented our time block concept in a C++ library and tested it on an ARM Cortex A9 bare-metal platform. The combined usage of timing specification and our time block library has been successfully evaluated on a critical flight-control software for a multi-rotor system. Friederike Bruns, Irune Yarza, Philipp Ittershagen, Kim Grüttner |
ACM Trans. Embed. Comput. Syst. | 2 |
| 2020 | UP2DATE: Safe and secure over-the-air software updates on high-performance mixed-criticality systemsabstractFollowing the same trend of consumer electronics, safety-critical industries are starting to adopt Over-The-Air Software Updates (OTASU) on their embedded systems. The motivation behind this trend is twofold. On the one hand, OTASU offer several benefits to the product makers and users by improving or adding new functionality and services to the product without a complete redesign. On the other hand, the increasing connectivity trend makes OTASU a crucial cyber-security demand to download latest security patches. However, the application of OTASU in the safety-critical domain is not free of challenges, specially when considering the dramatic increase of software complexity and the resulting high computing performance demands. This is the mission of UP2DATE, a recently launched project funded within the European H2020 programme focused on new software update architectures for heterogeneous high-performance mixed-criticality systems. This paper gives an overview of UP2DATE and its foundations, which seeks to improve existing OTASU solutions by considering safety, security and availability from the ground up in an architecture that builds around composability and modularity. Irune Agirre, Peio Onaindia, Tomaso Poggi, Irune Yarza, Francisco J. Cazorla, Leonidas Kosmidis, Kim Grüttner, Mohammed Abuteir, Jan Loewe, Juan M. Orbegozo, Stefania Botta |
DSD | 4 |
| 2017 | A railway safety and security concept for low-power mixed-criticality systemsabstractMixed-criticality cyber physical system provides great advantages in terms of cost, dependability, scalability and competitiveness. However, especially due to shared resources, the certification of these kind of systems is still challenging. Furthermore if the power management is integrated in the system, compliance with safety and security is even more complex. This paper presents the safety concept of a railway signalling use-case, considering a mixed-criticality object controller which includes a power management approach. The paper presents a proposal of using degraded modes and a safety/security analysis of low power techniques. The concept has been positively assessed by an independent certification body. Ainara Bilbao, Irune Yarza, Jose Luis Montero, Mikel Azkarate-askatsua, Nera González Romero |
INDIN | 2 |