EDBT 2026 Demo / reviewers in the wild / expert
Ludovic Apvrille
dblp:45/1367
· DBLP profile ↗
51ranked-venue papers
9as first author
22since 2021 · last 2026
0000-0002-1167-4639ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 35 · 8 first-author · 17 since 2021Systems, architecture and hardware · 10 · 1 first-author · 3 since 2021Computer networks · 2 · 1 first-authorSecurity and privacy · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Continuous AI Assistance for Model-Driven EngineeringabstractInternational audience Ludovic Apvrille, Bastien Sultan |
MODELSWARD | 1 |
| 2025 | Evict+Spec+Time on RISC-V: Gem5-Based Implementation and Microarchitectural AnalysisabstractMicroarchitectural side-channel attacks are a growing concern and have been widely studied on x86 and ARM architectures, but RISC-V’s susceptibility to similar attacks remains understudied. We present the first implementation and evaluation of the Evict+Spec+Time attack on RISC-V, previously demonstrated only on x86 [2]. This advanced variant of Evict+Time integrates three critical phases: eviction, speculation, and timing. First, the attack forcibly evicts target cache lines using RISC-V’s cbo.flush instruction via the Zicbom extension [6]. Next, it exploits out-of-order execution to manipulate microarchitectural resources such as the reorder buffer, limiting the processor’s ability to mask cache-miss latency. Finally, it infers secret-dependent memory access patterns through precise timing measurements. We validate RISC-V’s vulnerability by recovering secret keys from AES T-table implementations. Using the gem5 simulator [4], we provide the first detailed analysis of microarchitectural behavior during the attack, including cache contention, pipeline stalls, and latency variations. These insights establish foundational guidance for developing RISC-V-specific countermeasures against such attacks. Mahreen Khan, Maria Mushtaq, Renaud Pacalet, Ludovic Apvrille |
DSD | 4 |
| 2025 | Digital Twin and Digital Thread for System Security and Performance applied to an Electrical Vehicle Charging Use CaseabstractSystem security requires a solid foundation in both development and operation. During development, performance trade-offs result in security infrastructures that are more or less effective, but usually imperfect. Hence, during operation, runtime monitoring and anomaly detection continuously check for security issues.In this paper, we show how development and operation can be linked. We demonstrate how information and data from development and operation can be aggregated in a digital twin and/or digital thread which is used as the basis for runtime monitoring and anomaly detection. In particular, we address the trade-off between system security and performance in a concrete smart grid system. Hagen Heermann, Johannes Koch, Christoph Grimm 0001, Daniela Genius, Ludovic Apvrille, Ahlem Mifdaoui, Klaus Schneider 0001 |
FDL | 5 |
| 2025 | Side-Channel Attack Detection Using gem5 and Machine Learning: A Case Study on Fault-Based Attacks in RISC-VabstractMicroarchitectural side-channel attacks pose a significant threat to modern computing architectures. This paper presents a machine learning-based methodology for detecting these attacks using the gem5 simulator, focusing on the recently discovered Flush+Fault attack [6] on RISC-V. Our approach follows a three-phase process. The first phase is data collection, where we simulate attack and non-attack scenarios in gem5 and extract microarchitectural features indicative of side-channel activity. The second phase is the training phase, where we utilize machine learning (ML) techniques to build a classification model capable of distinguishing between normal execution and attack patterns. The last phase is the testing phase, where we evaluate the trained model using various performance metrics to validate its accuracy and precision. To the best of our knowledge, this is the first detection framework for Flush+Fault attacks [6] on RISC-V, showcasing its effectiveness in mitigating emerging threats. Our results indicate that gem5 metrics combined with machine learning models can reliably detect Flush+Fault attacks, achieving 0.99 accuracy with random forest (RF), 0.96 with support vector machine (SVM), and 0.95 with naïve bayes (NB). Moreover, this methodology is adaptable to different side-channel attacks and architectures, making it a promising approach for strengthening microarchitectural security. Mahreen Khan, Maria Mushtaq, Renaud Pacalet, Ludovic Apvrille |
IOLTS | 4 |
| 2025 | Enabling Incremental SysML Model Verification: Managing Variability and Complexity Through Tagging and Model ReductionabstractInternational audience Bastien Sultan, Ludovic Apvrille, Oana Hotescu, Pierre de Saqui-Sannes |
MODELSWARD | 2 |
| 2025 | Assessing Security RISC: Analyzing Flush+Fault Attack on RISC-V Using gem5 SimulatorabstractInternational audience Mahreen Khan, Maria Mushtaq, Renaud Pacalet, Ludovic Apvrille |
SECRYPT | 4 |
| 2025 | AMULET: A Mutation Language Enabling Automatic Enrichment of SysML ModelsabstractSysML models are widely used for designing and analyzing complex systems. Model-based design methods often require successive modifications of the models, whether for incrementally refining the design (e.g., in agile development methods) or for testing different design options. Such modifications, or mutations, are also used in mutation-based testing approaches. However, the definition of mutation operators can be a complex issue, and applying them to models is sometimes performed by hand: this is time consuming and error prone. This article addresses this issue thanks to the introduction of AMULET, the first mutation language for SysML. AMULET encompasses the modifications targeting SysML block and state-machine diagrams and is supported by a compiler the article presents. This compiler is integrated in TTool, an open-source SysML toolkit, enabling the full support of design methods including model design, mutation, and verification tasks in a unique toolkit. The article also introduces two case studies providing concrete examples of AMULET use for modeling vulnerabilities and cyber attacks and highlighting the benefits of AMULET for SysML mutations. Bastien Sultan, Léon Frénot, Ludovic Apvrille, Philippe Jaillon, Sophie Coudert |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2024 | Automated Attack Tree Generation Using Artificial Intelligence and Natural Language Processing
Alan Birchler De Allende, Bastien Sultan, Ludovic Apvrille |
CRiSIS | 3 |
| 2024 | AI-Driven Consistency of SysML DiagramsabstractGraphical modeling languages, expected to simplify systems analysis and design, present a challenge in maintaining consistency across their varied views. Traditional rule-based methods for ensuring consistency in languages like UML often fall short in addressing complex semantic dimensions. Moreover, the integration of Large Language Models (LLMs) into Model Driven Engineering (MDE) introduces additional consistency challenges, as LLM's limited output contexts requires the integration of responses. This paper presents a new framework that automates the detection and correction of inconsistencies across different views, leveraging formally defined rules and incorporating OpenAI's GPT, as implemented in TTool. Focusing on the consistency between use case and block diagrams, the framework is evaluated through its application to three case studies, highlighting its potential to significantly enhance consistency management in graphical modeling. Bastien Sultan, Ludovic Apvrille |
MODELS | 2 |
| 2024 | System Architects Are not Alone Anymore: Automatic System Modeling with AI
Ludovic Apvrille, Bastien Sultan |
MODELSWARD | 1 |
| 2024 | Cycle-Accurate Virtual Prototyping with Multiplicity
Daniela Genius, Ludovic Apvrille |
MODELSWARD | 2 |
| 2023 | Introducing A Framework for Single-Human Tracking Using Event-Based CamerasabstractEvent cameras generate data based on the amount of motion present in the captured scene, making them attractive sensors for solving object tracking tasks. In this paper, we present a framework for tracking humans using a single event camera which consists of three components. First, we train a Graph Neural Network (GNN) to recognize a person within the stream of events. Batches of events are represented as spatio-temporal graphs in order to preserve the sparse nature of events and retain their high temporal resolution. Subsequently, the person is localized in a weakly-supervised manner by adopting the well established method of Class Activation Maps (CAM) for our graph-based classification model. Our approach does not require the ground truth position of humans during training. Finally, a Kalman filter is deployed for tracking, which uses the predicted bounding box surrounding the human as measurement. We demonstrate that our approach achieves robust tracking results on test sequences from the Gait3 database, paving the way for further privacy-preserving methods in event-based human tracking. Code, pre-trained models and datasets of our research are publicly available1. Dominik Eisl, Fabian Herzog, Jean-Luc Dugelay, Ludovic Apvrille, Gerhard Rigoll |
ICIP | 4 |
| 2023 | Integration of Heterogeneous Components for Co-SimulationabstractBecause of their complexity, embedded systems are designed with sub-systems or components taken in charge by different development teams or entities and with different modeling frameworks and simulation tools, depending on the characteristics of each component. Unfortunately, this diversity of tools and semantics makes the integration of these heterogeneous components difficult. Thus, to evaluate their integration before their hardware or software is available, one solution would be to merge them into a common modeling framework. Yet, such a holistic environment supporting many computation and computation semantics seems hard to settle. Another solution we investigate in this paper is to generically link their respective simulation environments in order to keep the strength and semantics of each component environment.The paper presents a method to simulate heterogeneous components of embedded systems in real-time. These components can be described at any abstraction level. Our main contribution is a generic glue that can analyze in real-time the state of different simulation environments and accordingly enforce the correct communication semantics between components. Once presented in a generic way, our glue is illustrated with Apache Kafka as the communication facility between simulation engines. It is then applied to two model and simulation frameworks: TTool and SystemC. Finally, Zigbee serves as a case study to illustrate the strengths of our approach. Jawher Jerray, Rabéa Ameur-Boulifa, Ludovic Apvrille |
ICSOFT | 3 |
| 2023 | Mutation of Formally Verified SysML ModelsabstractInternational audience Ludovic Apvrille, Bastien Sultan, Oana Hotescu, Pierre de Saqui-Sannes, Sophie Coudert |
MODELSWARD | 1 |
| 2023 | Hierarchical Design of Cyber-Physical SystemsabstractInternational audience Daniela Genius, Ludovic Apvrille |
MODELSWARD | 2 |
| 2023 | Execution trace analysis for a precise understanding of latency violations
Maysam Zoor, Ludovic Apvrille, Renaud Pacalet, Sophie Coudert |
Softw. Syst. Model. | 2 |
| 2022 | SysML Models Verification Relying on Dependency GraphsabstractFormal verification of SysML models contributes to detect design errors early in the life cycle of systems. Incremental modeling of systems leads to repeat verification of systems models parts that were already verified in previous versions of the SysML model. This paper proposes to optimize the verification process by generating first a dependency graph of the SysML model. The dependency generation algorithm is implemented by free SysML tool TTool. An Avionics Full DupleX network serves as case study. Ludovic Apvrille, Pierre de Saqui-Sannes, Oana Hotescu, Alessandro Tempia Calvino |
MODELSWARD | 1 |
| 2022 | Safety, Security and Performance Assessment of Security Countermeasures with SysML-SecabstractInternational audience Bastien Sultan, Ludovic Apvrille, Philippe Jaillon |
MODELSWARD | 2 |
| 2021 | Execution Trace Analysis for a Precise Understanding of Latency ViolationsabstractDespite the amount of proposed works for the verification of diverse model properties, understanding the root cause of latency requirements violation in execution traces is still an open-issue especially for complex HW/SW system-level designs: is it due to an unfavorable real-time scheduling, to contentions on buses, to the characteristics of functional algorithms or hardware components? This identification is particularly at stake when adding new features in a model, e.g., a new security countermeasure. The paper introduces PLAN, a new trace analysis technique whose objective is to classify execution transactions according to their impact on latency. To do so, we rely first on a model transformation that builds up a dependency graph from an allocation model, thus including hardware and software aspects of a system model. Then, from this graph and an execution trace, our analysis can highlight how software or hardware elements contributed to the latency violation. The paper first formalizes the problem before applying our approach to simulation traces of SysML models. A case study defined in the AQUAS European project illustrates the interest ofour approach. Maysam Zoor, Ludovic Apvrille, Renaud Pacalet |
MoDELS | 2 |
| 2021 | Direct Model-checking of SysML ModelsabstractInternational audience Alessandro Tempia Calvino, Ludovic Apvrille |
MODELSWARD | 2 |
| 2021 | Interfacing Digital and Analog Models for Fast Simulation and Virtual PrototypingabstractInternational audience Daniela Genius, Ludovic Apvrille |
MODELSWARD | 2 |
| 2021 | Handling causality and schedulability when designing and prototyping cyber-physical systems
Rodrigo Cortés Porto, Daniela Genius, Ludovic Apvrille |
Softw. Syst. Model. | 3 |
| 2020 | Efficient Scheduling of FPGAs for Cloud Data Center InfrastructuresabstractIn modern cloud data centers, reconfigurable devices can be directly connected to the network of a data center. This configuration enables FPGAs to be rented for acceleration of data-intensive workloads. In this context, novel scheduling solutions are needed to maximize the utilization (profitability) of FPGAs, e.g., reduce latency and resource fragmentation. Algorithms that schedule groups of tasks (clusters, packs), rather than individual tasks (list scheduling), well match the functioning of FPGAs. Here, groups of tasks that execute together are interposed by hardware reconfigurations. In this paper, we propose a heuristic based on a novel method for grouping tasks. These are gathered around a high-latency task that hides the latency of remaining tasks within the same group. We evaluated our solution on a benchmark of almost 30000 random workloads, synthesized from realistic designs (i.e., topology, resource occupancy). For this testbench, on average, our heuristic produces optimum makespan solutions in 71.3% of the cases. It produces solutions for moderately constrained systems (i.e., the deadline falls within 10% of the optimum makespan) in 88.1% of the cases. Matteo Bertolino, Renaud Pacalet, Ludovic Apvrille, Andrea Enrici |
DSD | 3 |
| 2020 | Efficient and Exact Design Space Exploration for Heterogeneous and Multi-Bus PlatformsabstractDesign Space Exploration of data-flow Systems-on-Chip either focuses on classical shared bus or on complex network-on-chip (NoC) architectures. A lack of research work exists that targets segmented bus architectures. These offer performance improvements (latency, power consumption) with respect to a shared bus, while employing much simpler communication structures and algorithms than a NoC. Despite the lack in the research work, segmented buses are popular in multiprocessor systems and in FPGA interconnects. This paper fills this lack with two contributions. First, we propose a Satisfiability Modulo Theory (SMT) formulation. Secondly, we provide a technique to reduce the design-space explosion problem that is portable to other formulations (e.g., ILP, MILP) and to problems where the scheduling on units (e.g., bus, CPU) is multiplexed in time. We integrated these contributions in a state-of-the-art design tool that we employ for evaluation purposes with a set of streaming applications and a MPSoC platform. The resulting framework can study the performance of fixed interconnects as well as determine the optimal architecture among a set of candidates. Our reduction technique improves considerably the scalability of DSE. For our testbench, we reduce the SMT solver run-time from 20 up to 589 times. Amna Gharbi, Andrea Enrici, Bogdan Uscumlic, Ludovic Apvrille, Renaud Pacalet |
DSD | 4 |
| 2020 | Design Space Exploration with Deterministic Latency Guarantees for Crossbar MPSoC ArchitecturesabstractMPSoC and NoC systems are often used in complex telecommunication systems, which in the 5G era need to enable telecommunication services with unprecedented latency characteristics. Indeed, new services emerge, needing deterministic latency guarantees with virtually no system jitter, during the lifetime of the established telecommunication service. In this work, for the first time, we propose an optimal solution for a design space exploration (DSE) optimization problem, that performs all the traditional DSE tasks, but with end-to-end deterministic latency guarantees. We focus on MPSoC or NoC architectures with crossbars, although this work can be easily extended to more complex architectures. More precisely, our contributions in this work are the following: 1) we propose a novel method for deterministic scheduling in MPSoC and NoC architectures with a crossbar; 2) we propose an optimal solution in the form of an integer linear program (ILP) for DSE problem with end-to-end deterministic latency guarantees; 3) we identify the trade-off between the latency due to the use of crossbar time slots and the application execution time at different processing elements. The numerical results suggest that the proposed deterministic scheduling method can efficiently use all 100% of the crossbar capacity, depending on available application load and system parameters. Bogdan Uscumlic, Andrea Enrici, Renaud Pacalet, Amna Gharbi, Ludovic Apvrille, Lionel Natarianni, Laurent Roullet |
ICC | 5 |
| 2020 | High-level Partitioning and Design Space Exploration for Cyber Physical SystemsabstractInternational audience Daniela Genius, Ilias Bournias, Ludovic Apvrille, Roselyne Chotin |
MODELSWARD | 3 |
| 2020 | Impact of Security Measures on Performance Aspects in SysML ModelsabstractInternational audience Maysam Zoor, Ludovic Apvrille, Renaud Pacalet |
MODELSWARD | 2 |
| 2019 | A Language-Based Multi-View Approach for Combining Functional and Security ModelsabstractThe design flaws and attacks on Cyber-Physical Systems (CPSs) can lead to severe consequences. Thus, security and safety (S&S) issues should be taken into account with functional design as early as possible during the developing process. However, it's rare to see "one-size-fits-all" modeling language and/or design tool. One way to solve this issue is to integrate different nature models into one model system, but this requires a unified semantic among modeling languages. We explore a model-based approach for systems engineering that facilitates the composition of several heterogeneous artifacts (called views) into a sound and consistent system model. Rather than trying to extend either SysML or SysML-sec into more expressive languages to add the missing features, we extract proper subsets of both languages to build a view adequate for conducting a security and safety analysis of Capella (SysML-based) functional models. Our language is generic enough to extract proper subsets of languages and combine them to build views for different experts. Moreover, it maintains a global consistency between the different views. Hui Zhao 0016, Frédéric Mallet, Ludovic Apvrille |
APSEC | 3 |
| 2019 | Harmonizing Safety, Security and Performance Requirements in Embedded SystemsabstractConnected embedded systems have added new conveniences and safety measures to our daily lives -monitoring, automation, entertainment, etc-, but many of them interact with their users in ways where flaws will have grave impacts on personal health, property, privacy, etc, such as systems in the domains of healthcare, automotives, avionics, and other personal devices with access to sensitive information. Designing these systems with a comprehensive model-driven design process, from requirement elicitation to iterative design, can help detect issues, or incongruities within the requirements themselves earlier. This paper discusses how safety, security, and performance requirements should be assured with a systematic design process, and how these properties can support or conflict with each other as detected during the verification process. Ludovic Apvrille, Letitia W. Li |
DATE | 1 |
| 2019 | Odyn: Deadlock Prevention and Hybrid Scheduling Algorithm for Real-Time Dataflow ApplicationsabstractIn recent wireless communication standards (4G, 5G), the growing need for dynamic adjustments of transmission parameters (e.g., modulation, bandwidth, channel coding rate) makes traditional static scheduling approaches less and less efficient. The reason being that precomputed fixed mapping and scheduling prevent the system from dynamically adapting to changes of the operating conditions (e.g. wireless channel quality, available bandwidth). In this paper, we present Odyn, a hybrid approach for the scheduling and memory management of periodic dataflow applications on parallel, heterogeneous, Non-Uniform Memory Architecture (NUMA) platforms. In Odyn, the ordering of tasks and memory allocation are distributed and computed simultaneously at run-time for each Processing Element. Odyn also proposes a mechanism to prevent deadlocks caused by attempts to allocate buffers in size-limited memories. This technique, based on the static computation of exclusion relations among buffers in a target application, removes the need for backtracking that is typical of dynamic scheduling algorithms. We demonstrate the effectiveness of Odyn on a testbench that simulates the interactions of randomly generated concurrent applications. We also demonstrate its deadlock prevention technique on a selection of use cases. Benjamin Dauphin, Renaud Pacalet, Andrea Enrici, Ludovic Apvrille |
DSD | 4 |
| 2019 | Efficient Data-Flow Analysis of UML/SysML Diagrams for Optimized Model Compilation of Hardware-software Systems
Andrea Enrici, Ludovic Apvrille, Renaud Pacalet |
MODELSWARD | 2 |
| 2019 | A Tool for High-level Modeling of Analog/Mixed Signal Embedded SystemsabstractInternational audience Daniela Genius, Rodrigo Cortés Porto, Ludovic Apvrille, François Pêcheux |
MODELSWARD | 3 |
| 2019 | Meta-models Combination for Reusing Verification TechniquesabstractInternational audience Hui Zhao 0016, Ludovic Apvrille, Frédéric Mallet |
MODELSWARD | 2 |
| 2018 | A Model Compilation Approach for Optimized Implementations of Signal-processing SystemsabstractTo meet the computational and flexibility requirements of future 5G networks, the signal-processing functions of baseband stations and user equipments will be accelerated onto programmable, configurable and hard- wired components (e.g., CPUs, FPGAs, hardware accelerators). Such mixed architectures urge the need to automatically generate efficient implementations from high-level models. Existing model-based approaches can generate executable implementations of Systems-on-Chip (SoCs) by translating models into multiple SoC- programming languages (e.g., C/C++, OpenCL, Verilog/VHDL). However, these translations do not typically consider the optimization of non-functional properties (e.g., memory footprint, scheduling). This paper pro- poses a novel approach where system-level models are optimized and compiled into multiple implementations for different SoC architectures. We show the effectiveness of our approach with the compilation of UML/SysML models of a 5G decoder. Our solution generates both a software implementation for a Digital Signal Processor platform and a hardware-software implementation for a platform based on hardware Intellectual Property (IP) blocks. Overall, we achieve a memory footprint reduction of 80.07% in the first case and 88.93% in the second case. Andrea Enrici, Julien Lallet, Imran Latif, Ludovic Apvrille, Renaud Pacalet, Adrien Canuel |
MODELSWARD | 4 |
| 2018 | Multi-level Latency Evaluation with an MDE ApproachabstractInternational audience Daniela Genius, Letitia W. Li, Ludovic Apvrille, Tullio Tanzi |
MODELSWARD | 3 |
| 2018 | Evolving Attacker Perspectives for Secure Embedded System DesignabstractIn our increasingly connected world, security is a growing concern for embedded systems. A systematic design and verification methodology could help detect vulnerabilities before mass production. While Attack Trees help a designer consider the attacks a system will face during a preliminary analysis phase, they can be further integrated into the design phases. We demonstrate that explicitly modeling attacker actions within a system model helps us to evaluate its impact and possible countermeasures. This paper describes how we evolved the SysML-Sec Methodology with ``Attacker Scenarios'' for the improved design of secure embedded systems. Letitia W. Li, Florian Lugou, Ludovic Apvrille |
MODELSWARD | 3 |
| 2017 | Model-Driven Performance Evaluation and Formal Verification for Multi-level Embedded System DesignabstractThe design methodology of an embedded system should start with a system-level partitioning dividing functions into hardware and software. However, since this partitioning decision is taken at a high level of abstraction, we propose regularly validating the selected partitioning during software development. The paper introduces a new model-based engineering process with a supporting toolkit, first performing system-level partitioning, and then assessing the partitioning choices thus obtained at different levels of abstraction during software design. This assessment shall in particular validate the assumptions made on system-level (e.g. on cache miss rates) that cannot be precisely determined without low-level hardware model. High-level partitioning simulations/verification rely on custom model-checkers and abstract models of software and hardware, while low-level prototyping simulations rely on automatically generated C-POSIX software code executing on a cycle-precise virtual prototyping platform. An automotive case study on an automatic braking applicationillustrates our complete approach. Daniela Genius, Letitia W. Li, Ludovic Apvrille |
MODELSWARD | 3 |
| 2017 | Security-aware Modeling and Analysis for HW/SW PartitioningabstractThe rising wave of attacks on communicating embedded systems has exposed their users to risks of informa- tion theft, monetary damage, and personal injury. Through improved modeling and analysis of security, we propose that these flaws could be mitigated. Since HW/SW partitioning, one of the first phases, impacts future integration of security into the system, this phase would benefit from supporting modeling security abstrac- tions and security properties, providing designers with useful partitioning feedback obtained from a security formal analyzer.
In this paper, we present how our toolkit supports security modeling, automated security integration, and formal analysis during the HW/SW partitioning phase for secure communications in embedded systems. We introduce “Cryptographic Configurations”, an abstract representation of security that allows us to verify security formally. Our toolkit further assists designers by automatically adding these security representations based on a mapping and security requirements. Letitia W. Li, Florian Lugou, Ludovic Apvrille |
MODELSWARD | 3 |
| 2017 | A Model-Driven Engineering Methodology to Design Parallel and Distributed Embedded SystemsabstractIn Model-Driven Engineering system-level approaches, the design of communication protocols and patterns is subject to the design of processing operations (computations) and to their mapping onto execution resources. However, this strategy allows us to capture simple communication schemes (e.g., processor-bus-memory) and prevents us from evaluating the performance of both computations and communications (e.g., impact of application traffic patterns onto the communication interconnect) in a single step. To solve these issues, we introduce a novel design approach—the Ψ-chart—where we design communication patterns and protocols independently of a system’s functionality and resources, via dedicated models. At the mapping step, both application and communication models are bound to the platform resources and transformed to explore design alternatives for both computations and communications. We present the Ψ-chart and its implementation (i.e., communication models and Design Space Exploration) in TTool/DIPLODOCUS, a Unified Modeling Language (UML)/SysML framework for the modeling, simulation, formal verification and automatic code generation of data-flow embedded systems. The effectiveness of our solution in terms of better design quality (e.g., portability, time) is demonstrated with the design of the physical layer of a ZigBee (IEEE 802.15.4) transmitter onto a multi-processor architecture. Andrea Enrici, Ludovic Apvrille, Renaud Pacalet |
ACM Trans. Design Autom. Electr. Syst. | 2 |
| 2016 | SysML Models and Model Transformation for SecurityabstractInternational audience Florian Lugou, Letitia W. Li, Ludovic Apvrille, Rabéa Ameur-Boulifa |
MODELSWARD | 3 |
| 2015 | SysML-Sec - A Model Driven Approach for Designing Safe and Secure SystemsabstractSecurity flaws are open doors to attack embedded systems and must be carefully assessed in order to determine threats to safety and security. Subsequently securing a system, that is, integrating security mechanisms into the system's architecture can itself impact the system's safety, for instance deadlines could be missed due to an increase in computations and communications latencies. SysML-Sec addresses these issues with a model-driven approach that promotes the collaboration between system designers and security experts at all design and development stages, e.g., requirements, attacks, partitioning, design, and validation. A central point of SysML-Sec is its partitioning stage during which safety-related and security-related functions are explored jointly and iteratively with regards to requirements and attacks. Once partitioned, the system is designed in terms of system's functions and security mechanisms, and formally verified from both the safety and the security perspectives. Our paper illustrates the whole methodology with the evaluation of a security mechanism added to an existing automotive system. Yves Roudier, Ludovic Apvrille |
MODELSWARD | 2 |
| 2014 | Safety properties modellingabstractIn critical applications regarding safety, a solution must be validated before it is applied on the field. It is forbidden to test solutions directly on the real system for safety reasons. Any attempt of modification or introduction of a safety system must be approached with the utmost care. The proposed solutions must be validated, and, if possible, formally validated. It is the case of prevention systems for accidents, installed on highways. They also are in charge of gathering information in the case of an accident actually occurring. In this context, we aim to provide an approach to validate the behaviour of a critical system before its effective realisation. The system is modelled by a combination of agents spread around the world and working together in real-time. The agents' behaviour is modelled via an UML SysML model. Thanks to the tools available in the TTool environment and the ones developed only for this purpose, we can animate those agents and confirm, or not, their behaviour on various test situations (applications' rapid prototyping). Since the tests are not covering all the possibilities, we move to, then, verify formally the critical properties. This formal analysis is made possible by the mathematical grounds of the tool we use. The analysed properties are mainly safety properties; results regarding performance results are available as well. Tullio Tanzi, Raoul Textoris, Ludovic Apvrille |
HSI | 3 |
| 2014 | A UML Model-Driven Approach to Efficiently Allocate Complex Communication Schemes
Andrea Enrici, Ludovic Apvrille, Renaud Pacalet |
MoDELS | 2 |
| 2013 | Formal system-level design space explorationabstractSUMMARY DIPLODOCUS is a UML profile intended for the modeling and the formal verification of real‐time and embedded applications commonly executed on complex Systems‐on‐Chip. DIPLODOCUS implements the Y‐chart approach, that is, application and HW architecture (e.g., CPUs, bus, memories) are first described independently and are subsequently related to each other in a mapping stage. Abstract tasks and communication primitives are therefore mapped onto platform elements like buses and CPUs. DIPLODOCUS endows all models with a formal semantics, thereby paving the way for formal proofs both before and after mapping. More concretely, application, architecture, and mapping models can be edited in TTool – an open‐source toolkit – using UML diagrams. Then, pre‐mapping or post‐mapping UML models may be automatically transformed into a LOTOS‐based representation. This specification is in turn amenable to model‐checking techniques to evaluate properties of the system, for example, safety, schedulability, and performance properties. A smart card system serves as case study to illustrate the formal verification capabilities of DIPLODOCUS. Copyright © 2012 John Wiley & Sons, Ltd. Daniel Knorreck, Ludovic Apvrille, Renaud Pacalet |
Concurr. Comput. Pract. Exp. | 2 |
| 2011 | A Formal Methodology Applied to Secure Over-the-Air Automotive ApplicationsabstractThe expected high complexity in future automotive applications will require to frequently update electronic devices supporting those applications. Even if in-car devices are trusted, potential attacks on over the air exchanges impose stringent requirements on both safety and security. To address the formal verification of safety properties, we have previously introduced the AVATAR UML profile whose methodology covers requirement, analysis, design, and formal verification stages [1]. We now propose to extend AVATAR to support both safety and security during all methodological stages, and in the same models. The paper applies the extended AVATAR to an over the-air protocol for trusted firmware updates of in-car control units, with a special focus on design and formal verification stages. Juan Gabriel Pedroza Bernal, Muhammad Sabir Idrees, Ludovic Apvrille, Yves Roudier |
VTC Fall | 3 |
| 2011 | Car2X Communication: Securing the Last Meter - A Cost-Effective Approach for Ensuring Trust in Car2X Applications Using In-Vehicle Symmetric CryptographyabstractThe effectiveness of Car2X communication strongly relies on trust in received data. Securing in-vehicle communication is an essential yet so far overlooked step to achieve this objective. We present an approach based on the use of symmetric key material protected with inexpensive hardware. We modeled the involved cryptographic and network protocols, showed their applicability to automotive bus systems and conclude about their soundness with analytical and simulation methods. A prototype realization in real vehicles is envisaged as part of an ongoing project. Hendrik Schweppe, Yves Roudier, Benjamin Weyl, Ludovic Apvrille, Dirk Scheuermann |
VTC Fall | 4 |
| 2006 | Abstract Application Modeling for System Design Space ExplorationabstractThe increasing complexity of System-on-Chip (SoC) requires a complete reexamination of design and validation methods prior to final implementation whereas faster system design space exploration is today’s requirement to speed up the design process in order to cope with ‘timeto- market’ constraint. We have introduced SoC modeling approach which mixes simulation and formal modeling and verification methods for efficient design space exploration phase of SoC design cycle. The applications are described as a network of communicating tasks whose behaviors are abstracted. Because applications are abstract, it is possible to significantly increase the speed of simulation, to perform a quick performance analysis and apply static formal analysis techniques at higher level of abstraction. The proposed methodology has been employed in the design of a telecommunication system. A part of the application is modeled as a set of tasks in a modeling language and their behavior is monitored as a waveform of events in a simulation environment. Waseem Muhammad 0001, Ludovic Apvrille, Rabéa Ameur-Boulifa, Sophie Coudert, Renaud Pacalet |
DSD | 2 |
| 2006 | TURTLE-P: a UML profile for the formal validation of critical and distributed systems
Ludovic Apvrille, Pierre de Saqui-Sannes, Ferhat Khendek |
Softw. Syst. Model. | 1 |
| 2004 | Verifying Service Continuity in a Dynamic Reconfiguration Procedure: Application to a Satellite System
Ludovic Apvrille, Pierre de Saqui-Sannes, Patrick Sénac, Christophe Lohr |
Autom. Softw. Eng. | 1 |
| 2004 | TURTLE: A Real-Time UML Profile Supported by a Formal Validation ToolkitabstractWe present a UML 1.5 profile named TURTLE (Timed UML and RT-LOTOS Environment) endowed with a formal semantics given in terms of RT-LOTOS. TURTLE relies on UML's extensibility mechanisms to enhance class and activity diagrams. Class diagrams are extended with specialized classes named Tclasses, which communicate and synchronize through gates. Also, associations between Tclasses are attributed by a composition operator (Parallel, Synchro, Invocation, Sequence, or Preemption) which provides them with a formal semantics. TURTLE extends UML activity diagrams with synchronization actions and temporal operators (deterministic delay, nondeterministic delay, time-limited offer, and time-capture). The real-time dimension of TURTLE has been further improved by the addition of two composition operators, periodic and suspend, as well as suspendable delay, latency, and time-limited offer operators at the activity diagram level. Core characteristics of TURLE are supported by TTool - the TURTLE toolkit - which includes a diagram editor, a RT-LOTOS code generator and a result analyzer. The toolkit reuses RTL, a RT-LOTOS validation tool offering debug-oriented simulation and exhaustive analysis. TTool hides RT-LOTOS to the end-user and allows him/her to directly check TURTLE modeling against logical errors and timing inconsistencies. Besides the foundations of the TURTLE profile, this paper also discusses its application in the context of space-based embedded software. Ludovic Apvrille, Jean-Pierre Courtiat, Christophe Lohr, Pierre de Saqui-Sannes |
IEEE Trans. Software Eng. | 1 |
| 2000 | Implementing a User Level Multimedia Transport Protocol in JavaabstractThe paper assesses the potential of Java for developing both portable and efficient communication software. Specifically, this paper presents and compares implementation of a multimedia transport protocol, POC, using the Java and C languages. Performances measurement are applied to the transport of MPEG streams. Ludovic Apvrille, Laurent Dairaine, Patrick Sénac, Luis Rojas-Cardenas, Michel Diaz |
ISCC | 1 |