EDBT 2026 Demo / reviewers in the wild / expert
Ali Mohammad Hosseini
dblp:297/5002
· DBLP profile ↗
9ranked-venue papers
9as first author
9since 2021 · last 2025
0000-0003-3323-1924ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 8 · 8 first-author · 8 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 5 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Trustworthy AI for Security Decision-Making in ICSs: Towards Compliance with the EU AI ActabstractIn Industrial Control Systems (ICSs), security is not a fancy add-on feature but a core requirement for functionality, safe operation, and organization business. To keep up with the ever-growing threat landscape and numerous security standards and regulations, leveraging Artificial Intelligence (AI) capabilities, especially Large Language Models (LLMs), seems essential. However, AI systems built using LLMs can introduce new challenges such as data leakage, generating bias and misinformation, and even new security threats. In this paper, we analyze an AI system that leverages LLMs and knowledge graphs to support security decisions in the design of ICSs, ensuring compliance with the IEC 62443-3-3 standard while aligning with the European AI Act to guarantee trustworthiness and meet legal requirements for use in Europe. Ali Mohammad Hosseini, Thilo Sauter, Wolfgang Kastner |
ETFA | 1 |
| 2025 | Ontology Framework Supporting Security-By-Design of Industrial Control SystemsabstractEnsuring cybersecurity in Industrial Control Systems (ICSs) is essential, as cyber-attacks can lead to substantial economic losses and serious safety hazards. Addressing security early in the product and system life cycle is crucial to preventing expensive fixes and severe consequences later. Since requirements engineering and system architecture design are early activities in system development and are interconnected in nature, it is essential to begin integrating security into these activities. IEC 62443 is a widely used ICS cybersecurity standard that provides security requirements and architectural guidance; however, it relies heavily on human experts and manual effort, making the implementation of the standard costly and time-consuming. This article proposes an ontological framework that supports the integrated engineering of security requirements and system architectures, aiming to achieve security by design and conformance with IEC 62443 with reduced reliance on human experts. To evaluate the quality and usability of the proposed ontology, we examine a use case for requirements elicitation and validation scenarios. The findings highlight the potential of ontological approaches in improving ICS cybersecurity, particularly in terms of standard compliance. Ali Mohammad Hosseini, Wolfgang Kastner, Thilo Sauter |
IEEE Trans. Ind. Informatics | 1 |
| 2024 | Towards Enhancing Security of ICS: System Architecture Development using the Asset Administration ShellabstractConsidering security when designing a system is of utmost importance. Integrating security attributes during the design phase provides effective means. However, this process necessitates the collection and utilization of various types of data related to each asset, which should be collected from different sources, such as data sheets. Developing Industrial Control System (ICS) architecture, as an important activity during design time, enhances security by identifying threats, enforcing controls, enabling compliance, resilience, and monitoring through structured, layered design. Thus, this paper explores the incorporation of a Digital Twin into system architecture to improve the security of ICSs. In particular, we investigate the role of the Asset Administration Shell (AAS) as a standardized meta-model in providing necessary information for the development of secure system architectures. After identifying the information required for specific security activities, the current state of AAS and its capability to provide that information is assessed. Ali Mohammad Hosseini, Thilo Sauter, Wolfgang Kastner |
ETFA | 1 |
| 2024 | Integrating Security into Industrial Control System Architecture Based on IEC 42010abstractIndustrial Control Systems (ICS) are increasingly becoming targets for cybercriminals seeking ransom or aiming to cause disruptive chaos because of the potentially devastating impact of ICS malfunction. Following the security-by-design principle, security measures should be integrated into ICS system design as early as possible. System architecture design is one of the earliest activities in the system development life cycle that can play a key role in enhancing security. Hence, this paper proposes an architectural security framework based on IEC 42010, a standard for system architecture description, aiming at integrating security into system architecture. As part of this framework, an ontology is designed to formalize the system architecture described in SysML v2 (Systems Modelling Language version 2) to facilitate automatic reasoning about system design against specified security requirements and rules. To this end, the transformation rules from the textual notation of SysML v2 to OWL (Web Ontology Language) are specified. A use case is presented and analyzed that demonstrates the practicality of the proposed approach in adding security to the system architecture. Ali Mohammad Hosseini, Thilo Sauter, Wolfgang Kastner |
ETFA | 1 |
| 2023 | Formal Verification of Safety and Security Properties in Industry 4.0 ApplicationsabstractWith the advent of Industry 4.0 (I4.0) systems, ensuring the safety and security of these systems' design has become a paramount concern for stakeholders. One concern is the increased costs of fixing errors in later phases, such as integration and operation compared to the design phase. Formal verification techniques offer a rigorous approach to verifying the correctness of system behaviours and properties. This paper explains the fundamental principles of formal verification in safety and security domains. We use a SysML-based environment called AVATAR ("Automated Verification of Real Time Software"). It allows for a formal description and verification of safety and security properties. Specifically, we demonstrate the application of AVATAR in verifying the safety and security properties of a Cobot system architecture upon requirements. Moreover, we evaluate the challenges, opportunities, and limitations of using AVATAR in industrial settings and provide recommendations for its enhancement or designing a new methodology for I4.0 application verification. The results show that formal verification techniques can be enhanced to address safety and security concerns in I4.0 complex and critical systems. Ali Mohammad Hosseini, Thilo Sauter, Wolfgang Kastner |
ETFA | 1 |
| 2023 | A Safety and Security Requirements Management Methodology in Reconfigurable Collaborative Human-Robot ApplicationabstractThe current industry has to adapt to rapidly changing customers' needs. Reconfigurable manufacturing, therefore, provides capacity and functionality on demand which is essential for competitiveness in fast-changing markets. Furthermore, Industry 4.0 or even more so, Industry 5.0 emphasizes human-centred production with collaborative robots, Cobots, to create human-robot interactions. In such scenarios, safety and security are difficult to address due to the intrinsic features of reconfigurable manufacturing, like exposure to numerous requirements changes in a short period. As safety and security can conflict in different phases of the system life-cycle, one of the earliest activities to avoid conflicts is requirements engineering which can significantly diminish the cost and time of fixing issues compared to later phases like operation. This paper proposes a methodology for safety and security requirements interaction management, including conflict detection and resolution, and shows its applicability through a reconfigurable collaborative human-robot use case. Based on the proposed methodology, we detected and resolved two safety and security requirement conflicts. Ali Mohammad Hosseini, Clara Wiederschwinger-Fischer, Mukund Bhole, Wolfgang Kastner, Thilo Sauter, Sebastian Schlund |
WFCS | 1 |
| 2023 | Safety and Security Requirements in AAS Integration: Use Case DemonstrationabstractThe Digital Twin (DT) paradigm has received attention for its potential in diverse industrial sectors like manufacturing, automotive, healthcare, electric grid, and transportation. The Asset Administration Shell (AAS) as an instantiation of the DT paradigm is proposed by Plattform Industrie 4.0, aiming to exchange asset-related data and services from when the asset is produced to its disposal in an interoperable way involving the key stakeholders. In Industrial Control Systems (ICS), AAS integration can bring about new safety and security concerns. Although there are standards covering safety and security separately, no finalised standard supports safety and security in a combined way. The increase in safety and security concerns because of AAS integration and recent cyber attacks that showed security and safety are interconnected, encourage us to explore one of the earliest activities in system development, requirement specification. Therefore, this paper investigates the impact of AAS integration into a use case on safety and security requirements specification according to IEC 62443 and 61511. The results highlight the interconnection of safety and security requirements in the proposed use case due to AAS integration and illustrate security requirements that potentially can affect safety. Ali Mohammad Hosseini, Thilo Sauter, Wolfgang Kastner |
WFCS | 1 |
| 2022 | A Safety and Security Reference Architecture for Asset Administration Shell DesignabstractWith the introduction of Industry 4.0 (I4.0), man-ufacturing systems are moving towards digitalization which is one of the principal visions of I4.0. In industrial automation systems, safety and security are fundamental aspects that will gain even more importance in the future, even more so as systems become more interconnected in I4.0. The Asset Administration Shell (AAS) is one of the key enabling concepts towards the realization of I4.0, and its generic approach ensures applicability in different areas. Nevertheless, the lack of a reference for developing such applications has led to a diverse collection of implementation efforts. This is an interoperability issue that may increase safety and security concerns in future I4.0 applications. This paper proposes a safety and security reference architecture to provide a firm ground for developing safe and secure AAS-based applications in the context of I4.0. It breaks down critical aspects of AAS development into understandable elements to facilitate decision-making for the key stakeholders, from vendors to system integrators to operators who aim to move towards I4.0 realization. Ali Mohammad Hosseini, Thilo Sauter, Wolfgang Kastner |
WFCS | 1 |
| 2021 | Towards Adding Safety and Security Properties to the Industry 4.0 Asset Administration ShellabstractIndustry 4.0 (I4.0) intends to make manufacturing agile, more efficient, and more customer-oriented. Considerable efforts have been made to enhance the safety and security aspects of I4.0 systems. However, the lack of a standard model has prevented the convergence toward safety and security. Plattform Industrie 4.0 has introduced the Asset Administration Shell (AAS) with the Reference Architectural Model Industry (RAMI 4.0) to integrate assets into the world of information. This paper draws the potential capabilities of AAS in bringing safety and security to I4.0 systems. For this goal, a safety and security model is proposed based on RAMI 4.0 to be used as a reference for developing the AAS model. A level control system is used as an illustrative example of an Industrial Control System (ICS) to demonstrate how to respond to I4.0 safety and security challenges using the AAS model. Ali Mohammad Hosseini, Thilo Sauter, Wolfgang Kastner |
WFCS | 1 |