EDBT 2026 Demo / reviewers in the wild / expert
Roberto Passerone
dblp:55/2279
· DBLP profile ↗
58ranked-venue papers
5as first author
11since 2021 · last 2026
0000-0001-6315-1023ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 31 · 3 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 11 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 8 · 1 since 2021Theory of computation · 5 · 1 first-authorArtificial intelligence and machine learning · 3 · 2 since 2021Computer networks · 2 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Dynamic Decision and Security Framework for Internet of Vehicles by Enhanced Localization Using Deep Reinforcement LearningabstractWith the increasing complexity and interconnectivity of IoV, protecting in-vehicle networks from cyberattacks and controlling mobile dynamics have become increasingly difficult. Currently, most techniques rely on large amounts of labeled data, which are difficult to obtain and expensive to generate. Furthermore, they are not focused on real-time Intrusion Detection Systems (IDSs) and adaptive decision making. To address these issues, this paper proposes an Adaptive Decision Framework for IoV-IDS (ADFII). To ease a policy update in the ADFII, we use Deep Reinforcement Learning (DRL) as it can generalize the policy to different kinds of vehicles by updating them according to specific variables, and we use Variational Autoencoders (VAEs), which ease the detection of hidden features and generalizes anomalies and new attack patterns. This combination of cores ensures that ADFII is both stable and flexible, helping in the efficient detection of intrusions in IoV environments that are subject to property changes, making the decision-making process more secure and reliable. To learn to detect incursions, navigate, and locate, ADFII only has to learn the right rules for the environment. In tests, ADFII has 7.1%, 3.7%, 4.1%, and 5% improvement, respectively, for better decision-making, reward, faster time, and finding an attack than baseline algorithms. Arash Heidari, Roberto Passerone, Nima Jafari Navimipour, Kyu In Lee |
IEEE Internet Things J. | 3 |
| 2025 | Simple Path Structural Encoding for Graph TransformersabstractGraph transformers extend global self-attention to graph-structured data, achieving notable success in graph learning. Recently, Relative Random Walk Probabilities (RRWP) has been found to further enhance their predictive power by encoding both structural and positional information into the edge representation. However, RRWP cannot always distinguish between edges that belong to different local graph patterns, which reduces its ability to capture the full structural complexity of graphs. This work introduces Simple Path Structural Encoding (SPSE), a novel method that utilizes simple path counts for edge encoding. We show theoretically and experimentally that SPSE overcomes the limitations of RRWP, providing a richer representation of graph structures, particularly in capturing local cyclic patterns. To make SPSE computationally tractable, we propose an efficient approximate algorithm for simple path counting. SPSE demonstrates significant performance improvements over RRWP on various benchmarks, including molecular and long-range graph datasets, achieving statistically significant gains in discriminative tasks. These results pose SPSE as a powerful edge encoding alternative for enhancing the expressivity of graph transformers. Louis Airale, Antonio Longa, Mattia Rigon, Andrea Passerini, Roberto Passerone |
ICML | 5 |
| 2025 | An investigation of visual foundation models robustness
Sandeep Gupta 0002, Roberto Passerone |
Mach. Learn. | 2 |
| 2024 | Architectural Exploration and Design for Ultra-Reliable Low-Latency Indoor Robotics SystemsabstractModern day communication systems are evolving to support computation-intensive and communication-sensitive applications that impose diverse quality of service requirements on the network in terms of latency, reliability, and bandwidth. Applications such as autonomous vehicles, industrial automation, and remote surgery will require ultra-reliable and low-latency communication, paving the way towards resourceful servers closer to user, i.e., multi-access edge computing. However, the stringent requirements on both communication and computation make effective network control difficult. The high dynamicity of the involved processing and interaction patterns requires planning and deployment of architectures with optimal design and cross-optimization of computation and communication re-sources. In this work, we address the design problem with QoS guarantees and architectural exploration and optimization, to provide computing and communication resources, accounting for dynamic mobility, traffic, and application patterns in the context of edge servers. Ayub Shah, Roberto Passerone |
CCNC | 2 |
| 2024 | Toward Simulation-Assisted Architecture Design Space Exploration of Indoor Robotics NetworksabstractIn this paper, we explore the combination of static architectural optimization with dynamic simulation. We describe an architecture through abstract models of components and a set of constraints that drive the design space exploration process to few promising solutions. These are evaluated through simulation to extract detailed performance parameters. The end objective of this work is to then feed back the information in the form of extra constraints to converge to a solution that satisfies the application requirements. We tested and validated the tool extensions, optimizing and analyzing two indoor robotics scenarios for critical performance parameters, i.e., overall throughput and end-to-end delay (E2E). Cristian Bianchi, Ayub Shah, Chiara Marangoni, Roberto Passerone |
WFCS | 4 |
| 2024 | Efficient Encodings for Scalable Exploration of Cyber-Physical System ArchitecturesabstractWe present a methodology for scalable exploration of cyber-physical system architectures. We propose a mathematical formulation of the architecture exploration problem as an optimized mapping problem that includes joint selection of system topologies and components taken from predefined libraries. Using a graph-based representation of an architecture, we introduce novel compact encodings of mapping constraints and path constraints that significantly improve the scalability of the formulation. We use the new encodings to instantiate design requirements, such as interconnection, routing, timing, and energy constraints, on the architecture model. We implement our methods in an extensible architecture exploration toolbox, and provide a pattern-based language for formal, yet flexible, requirement specification. Numerical evaluations on a set of design problems from wireless sensor networks, reconfigurable manufacturing systems, and electrical power systems demonstrate the effectiveness of our approach. Dmitrii Kirov, Pierluigi Nuzzo 0002, Alberto L. Sangiovanni-Vincentelli, Roberto Passerone |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 4 |
| 2023 | Secrets Leaking Through Quicksand: Covert Channels in Approximate ComputingabstractApproximate computing (AxC) has emerged as an attractive architectural paradigm especially for artificial-intelligence applications, yet its security implications are being neglected. We demonstrate a novel covert channel where the malicious sender modulates transmission by switching between regular and AxC realizations of the same computational task. The malicious receiver identifies the transmitted information by either reading out the workload statistics or by creating controlled congestion. We demonstrate the channel on both an Android simulator and an actual smartphone and systematically study measures to increase its robustness. The achievable transmission rates are comparable with earlier covert channels based on power consumption, but the malicious behavior of our channel is more stealthy and less detectable. Lorenzo Masciullo, Roberto Passerone, Francesco Regazzoni 0001, Ilia Polian |
ETS | 2 |
| 2023 | Comparative evaluation of background-rejection techniques for SPAD-based LiDAR systems
Alessandro Tontini, Leonardo Gasparini, Enrico Manuzzato, Matteo Perenzoni, Roberto Passerone |
Integr. | 5 |
| 2023 | Intermittent Computing Emulation of Ultralow-Power Processors: Evaluation of Backup Strategies for RISC-VabstractWith the progress in energy harvesting circuits and the decrease in power requirements of processing, sensing, and communication hardware, we have the potential of freeing the Internet of Things devices from their batteries. However, removing batteries introduces frequent power failures due to the irregular power availability from the environment. This situation leads devices to compute intermittently under transient environmental power. Intermittent computing requires significant microarchitectural modifications on existing processor designs to ensure automatic computation progress despite the power failures. For example, built-in nonvolatile memory components should be integrated in processor architectures. Consequently, different microarchitectural automatic backup strategies need to be implemented. In this work, we introduce different processor state backup strategies based on an interrupt-based software approach, which do not need modifications to the microarchitecture of existing processors. Therefore, we present a systematic approach to emulate different processor architectures with varying backup strategies under transient power. To justify our claims, we make Ibex RISC-V core, a popular ultralow-power processor architecture, suitable for intermittent computing. This is the first attempt to make a variety of existing and future ultralow-power processor architectures easily exploitable for transiently powered computing systems. Sebin Shaji Philip, Roberto Passerone, Kasim Sinan Yildirim, Davide Brunelli |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2022 | Migration-Aware Optimized Resource Allocation in B5G Edge NetworksabstractThe fifth-generation and beyond (B5G) communication systems are evolving for computation-intensive and communication-sensitive applications with diverse Quality-of-Service (QoS) requirements on processing, bandwidth, latency, and reliability. This work focuses on an ultra-dense edge network with Multi-access Edge Computing (MEC) facilities, serving agents that execute their tasks by touring the cells. Specifically, we propose a novel methodology for optimally and flexibly managing task offloading in the context of heterogeneous computing and communication services required by real-time robotic applications. Differing from many related work, the proposed approach takes the number of admitted service migrations and the QoS upper and lower bounds as binding constraints. We model the QoS evolution based on the agent positions, the MEC servers serving the agents, the QoS requirements, the communication capabilities in the edge network, and the computing capabilities of the servers. The model is formalized as a mixed-integer linear program (MILP) to obtain an optimal schedule for the service migrations and communication and computation bandwidth allocation. Experimental results show that the approach outperforms baseline approaches and can scale to large deployments. Tadeus Prastowo, Ayub Shah, Luigi Palopoli 0002, Roberto Passerone, Giuseppe Piro |
CCNC | 4 |
| 2021 | Robot Motion Planning: can GPUs be a Game Changer?abstractThis paper presents a parallel computing implementation of the Iterative Dynamic Programming (IDP) solution to the multipoint Markov-Dubins problem using GPUs. The multi-point Markov-Dubins problem requires the computation of the shortest path with bounded curvature that connects a sequence of planar points (waypoints). As well as being interesting in its own right, an efficient solution to this problem is key to finding optimal or suboptimal solutions of other problems such as the Dubins Travelling Salesman and the Dubins Orienteering problem. The constraint on the curvature makes the problem highly non-linear and complicates its solution. Classic methods are optimisation-based and cast the problem into the Nonlinear Programming (NLP) or Mixed Integer Nonlinear Programming (MINLP) frameworks, for which existing solutions cannot be significantly parallelised. On the contrary, the IDP solution proposed here is well suited for parallel execution. In the paper, we show that the parallel implementation of the IDP outperforms both the NLP/MINLP methods and the iterative version of the IDP methods in terms of accuracy, computation time and power consumption. Computation time and power consumption will be the main focus of the paper, because they are closely related to the implementation on an embedded platform. Enrico Saccon, Paolo Bevilacqua, Daniele Fontanelli, Marco Frego, Luigi Palopoli 0002, Roberto Passerone |
COMPSAC | 6 |
| 2020 | Optimized Selection of Reliable and Cost-Effective Safety-Critical System ArchitecturesabstractWe address the problem of synthesizing safety-critical embedded and cyber-physical system architectures to minimize a cost function while guaranteeing the desired reliability. We represent a system architecture as a configurable graph in which both the nodes (components) and edges (interconnections) may fail. We then propose a compact analytical formalism to efficiently reason about the reliability of the overall system based on the failure probabilities of the components, and provide expressions of the design constraints that avoid exhaustive enumeration of failure cases on all possible graph configurations. Based on these constraints, we cast the synthesis problem as an optimization problem and propose monolithic and iterative optimization schemes to decrease the problem complexity. We implement the proposed algorithms in the ArchEx framework, leveraging a pattern-based specification language to facilitate problem formulation. Design problems from aircraft electric power distribution networks and reconfigurable industrial manufacturing systems illustrate the effectiveness of our approach. Pierluigi Nuzzo 0002, Nikunj Bajaj, Michael Masin, Dmitrii Kirov, Roberto Passerone, Alberto L. Sangiovanni-Vincentelli |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 5 |
| 2019 | Coherent Extension, Composition, and Merging Operators in Contract Models for System DesignabstractContract models have been proposed to promote and facilitate reuse and distributed development. In this paper, we cast contract models into a coherent formalism used to derive general results about the properties of their operators. We study several extensions of the basic model, including the distinction between weak and strong assumptions and maximality of the specification. We then analyze the disjunction and conjunction operators, and show how they can be broken up into a sequence of simpler operations. This leads to the definition of a new contract viewpoint merging operator, which better captures the design intent in contrast to the more traditional conjunction. The adjoint operation, which we call separation, can be used to re-partition the specification into different viewpoints. We show the symmetries of these operations with respect to composition and quotient. Roberto Passerone, Inigo Incer, Alberto L. Sangiovanni-Vincentelli |
ACM Trans. Embed. Comput. Syst. | 1 |
| 2018 | Optimized selection of wireless network topologies and components via efficient pruning of feasible pathsabstractWe address the design space exploration of wireless networks to jointly select topology and component sizing. We formulate the exploration problem as an optimized mapping problem, where network elements are associated with components from pre-defined libraries to minimize a cost function under correctness guarantees. We express a rich set of system requirements as mixed integer linear constraints over path variables, denoting the presence or absence of paths between network nodes, and propose an algorithm for efficient, compact encoding of feasible paths that can reduce by orders of magnitude the complexity of the optimization problem. We incorporate our methods in a system-level design space exploration toolbox and evaluate their effectiveness on design examples from data collection and localization networks. Dmitrii Kirov, Pierluigi Nuzzo 0002, Roberto Passerone, Alberto L. Sangiovanni-Vincentelli |
DAC | 3 |
| 2018 | Dependability Assessment of SOA-Based CPS With Contracts and Model-Based Fault InjectionabstractEngineering complex distributed systems is challenging. Recent solutions for the development of cyber-physical systems (CPS) in industry tend to rely on architectural designs based on service orientation, where the constituent components are deployed according to their service behavior and are to be understood as loosely coupled and mostly independent. In this paper, we develop a workflow that combines contract-based and CPS model-based specifications with service orientation, and analyze the resulting model using fault injection to assess the dependability of the systems. Compositionality principles based on the contract specification help us to make the analysis practical. The presented techniques are evaluated on two case studies. Loris Dal Lago, Orlando Ferrante, Roberto Passerone, Alberto Ferrari |
IEEE Trans. Ind. Informatics | 3 |
| 2017 | ArchEx: An Extensible Framework for the Exploration of Cyber-Physical System ArchitecturesabstractWe present ArchEx, a framework for cyber-physical system architecture exploration. We formulate the exploration problem as a mapping problem, where "virtual" components are mapped into "real" components from pre-defined libraries to minimize an objective function while guaranteeing that system requirements are satisfied. ArchEx leverages an extensible set of patterns to enable formal, yet flexible, requirement specification, a graph-based internal representation of the system architecture, and algorithms based on mixed integer linear programming to solve the mapping problem. Its effectiveness is demonstrated on two industrial case studies: an aircraft power distribution network and a reconfigurable automated production line. Dmitrii Kirov, Pierluigi Nuzzo 0002, Roberto Passerone, Alberto L. Sangiovanni-Vincentelli |
DAC | 3 |
| 2017 | A nearly optimal landmark deployment for indoor localisation with limited sensingabstractIndoor applications based on vehicular robotics require accurate, reliable and efficient localisation. In the absence of a GPS signal, an increasingly popular solution is based on fusing information from a dead reckoning system that utilises on-board sensors with absolute position data extracted from the environment. In the application considered in this paper, the information on absolute position is given by visual landmarks deployed on the floor of the environment considered. This solution is inexpensive and provably reliable as long as the landmarks are sufficiently dense. On the other hand, a massive presence of landmark has high deployment and maintenance costs. In this paper, we build on the knowledge of a large number of trajectories (collected from environment observation) and seek the optimal placement that guarantees a localisation accuracy better than a specified value with a minimal number of landmarks. After formulating the problem, we analyse its complexity and describe an efficient greedy placement algorithm. Finally, the proposed approach is validated in realistic use cases. Valerio Magnago, Luigi Palopoli 0002, Roberto Passerone, Daniele Fontanelli, David Macii |
IPIN | 3 |
| 2016 | Statistical characterization of the 2.4 GHz radio channel for WSN in indoor office environmentsabstractIn this paper we present the results and the assessment of a statistical analysis of the wireless sensor networks (WSN) radio channel in indoor office scenarios. The work is based on an extensive set of received signal strength (RSS) measurements collected within different typical indoor spaces and node placement scenarios. Results are compared with corresponding values from the log-distance model, which is the most widely used in WSN simulators. Channel temporal stability is also analyzed. The analysis reveals interesting regularities within the measured data and as expected we observe a highly non-stationary behavior of the RSS. We also propose several improvements for the channel model of WSN simulators based on our observations. They can be beneficial for running more accurate network simulations for such applications as localization. Dmitrii Kirov, Roberto Passerone, Massimo Donelli |
ETFA | 2 |
| 2016 | Routing behavior across WSN simulators: The AODV case studyabstractThe continuous interest in Wireless Sensor Networks (WSN) has led to the development of several applications, from traditional monitoring, to cooperative and distributed control and management systems, to automated industrial machinery and logistics. The design and optimization of specialized WSN platforms and communication protocols typically relies on simulation tools, which have been designed to explore and validate WSN systems before actual implementation and real world deployment. In this paper, we evaluate the performance and the accuracy of mainstream open source simulation tools for WSNs on a realistic multi-hop data passing benchmark which makes use of the Ad-hoc On Demand Distance Vector Routing (AODV) protocol. The simulation results are then compared against measurements on a physical prototype. Our experiments show that the tools produce equivalent and consistent results from a functional point of view. However, their ability to model details of the execution platform and of the communication channel may significantly impact the run-time simulation performance and the accuracy of the simulation results. Ivan Minakov, Roberto Passerone, Alessandra Rizzardi, Sabrina Sicari |
WFCS | 2 |
| 2016 | A tag contract framework for modeling heterogeneous systems
Thi Thieu Hoa Le, Roberto Passerone, Uli Fahrenberg, Axel Legay |
Sci. Comput. Program. | 2 |
| 2016 | Contract-Based Requirement Modularization via Synthesis of Correct DecompositionsabstractIn distributed development of modern systems, contracts play a vital role in ensuring interoperability of components and adherence to specifications. It is therefore often desirable to verify the satisfaction of an overall property represented as a contract, given the satisfaction of smaller properties also represented as contracts. When the verification result is negative, designers must face the issue of refining the subproperties and components. This is an instance of the classical synthesis problems: “can we construct a model that satisfies some given specification?” In this work, we propose two strategies enabling designers to synthesize or refine a set of contracts so that their composition satisfies a given contract. We develop a generic algebraic method and show how it can be applied in different contract models to support top-down component-based development of distributed systems. Thi Thieu Hoa Le, Roberto Passerone, Uli Fahrenberg, Axel Legay |
ACM Trans. Embed. Comput. Syst. | 2 |
| 2016 | A Comparative Study of Recent Wireless Sensor Network SimulatorsabstractOver recent years, the continuous interest in wireless sensor networks (WSNs) has led to the appearance of new modeling methods and simulation environments for WSN applications. A broad variety of different simulation tools have been designed to explore and validate WSN systems before actual implementation and real-world deployment. These tools address different design aspects and offer various simulation abstractions to represent and model real-world behavior. In this article, we present a comprehensive comparative study of mainstream open-source simulation tools for WSNs. Two benchmark applications are designed to evaluate the frameworks with respect to the simulation runtime performance, network throughput, communication medium modeling, packet reception rate, network latency, and power consumption estimation accuracy. Such metrics are also evaluated against measurements on physical prototypes. Our experiments show that the tools produce equivalent results from a functional point of view and capacity to model communication phenomena, while the ability to model details of the execution platform significantly impacts the runtime simulation performance and the power estimation accuracy. The benchmark applications are also made available in the public domain for further studies. Ivan Minakov, Roberto Passerone, Alessandra Rizzardi, Sabrina Sicari |
ACM Trans. Sens. Networks | 2 |
| 2014 | Design of a Redundant FPGA-Based Safety System for Railroad VehiclesabstractThis paper deals with the design of a safety-critical embedded system for railroad vehicles usually referred to as "dead-man's vigilance device" (DMVD). A DMVD monitors the activity of the operator driving a train to detect his/her possible incapacitation while the vehicle is traveling. The system relies on a redundant and diverse FPGA-based architecture (without using micro-controllers, soft-cores or other software programmable components) to assure good flexibility and to avoid complex and expensive validation and verification activities of software modules, as typically required in safety-oriented applications. The first tests conducted on a prototype confirm that the system behaves correctly both in normal operating conditions and in the presence of single faults. David Macii, Manuel Avancini, Luigi Benciolini, Stefano Dalpez, Michele Corrà, Roberto Passerone |
DSD | 6 |
| 2014 | BCL: A compositional contract language for embedded systemsabstractThe design of large scale complex systems demands the ability to correctly specify and verify as early as possible in the design cycle the interaction of the different components that ensure that the global level requirements are satisfied. We address this issue using an approach based on the notion of contract. In particular, we propose a graphical and text-based language for requirement definition that allows designers to incrementally and hierarchically construct contract specifications for system components by composing a set of simple and intuitive patterns. The patterns have a formal semantics, and are implemented as monitor components in the Simulink framework for runtime verification. The contracts are simulated together with the components to verify both satisfaction and compatibility. A cruise control case study demonstrates the effectiveness of the approach. Orlando Ferrante, Roberto Passerone, Alberto Ferrari, Leonardo Mangeruca, Christos Sofronis |
ETFA | 2 |
| 2014 | 3DV - An embedded, dense stereovision-based depth mapping systemabstractThis paper describes the architecture and hardware implementation of an embedded, low-cost and low-power dense stereo reconstruction system, running at 30 fps at VGA resolution. The processing pipeline includes an initial image rectification stage, a cost generation unit based on the non-parametric census transform, a state-of-the-art Semi-Global cost optimization stage, and a final minimization and noise suppression step. The hardware implementation is based on a Xilinx ZynqTMSystem-on-Chip, which besides the FPGA provides a physical dual-core ARM CPU, which is exploited for control and to deliver output over the integrated Gigabit Ethernet connection. Gabriele Camellini, Mirko Felisa, Paolo Medici, Paolo Zani, Francesco Gregoretti, Claudio Passerone, Roberto Passerone |
Intelligent Vehicles Symposium | 7 |
| 2014 | Refinement-based synthesis of correct contract model decompositionsabstractIn distributed development of modern systems, contracts play a vital role in ensuring interoperability of components and adherence to specifications. It is therefore often desirable to verify the satisfaction of an overall property represented as a contract, given the satisfaction of smaller properties also represented as contracts. When the verification result is negative, designers must face the issue of refining the sub-properties and components. This is an instance of the classical synthesis problems: “can we construct a model that satisfies some given specification?”. In this work, we propose a strategy enabling designers to synthesize or refine a set of contracts so that their composition satisfies a given contract. We develop a generic algebraic method, and show how it can be applied in different contract models to support top-down component-based development of distributed systems. Thi Thieu Hoa Le, Roberto Passerone |
MEMOCODE | 2 |
| 2013 | PASES: An energy-aware design space exploration framework for wireless sensor networks
Ivan Minakov, Roberto Passerone |
J. Syst. Archit. | 2 |
| 2013 | Timed-automata based schedulability analysis for distributed firm real-time systems: a case study
Thi Thieu Hoa Le, Luigi Palopoli 0002, Roberto Passerone, Yusi Ramadian |
Int. J. Softw. Tools Technol. Transf. | 3 |
| 2013 | metroII: A design environment for cyber-physical systemsabstractCyber-Physical Systems are integrations of computation and physical processes and as such, will be increasingly relevant to industry and people. The complexity of designing CPS resides in their heterogeneity. Heterogeneity manifest itself in modeling their functionality as well as in the implementation platforms that include a multiplicity of components such as microprocessors, signal processors, peripherals, memories, sensors and actuators often integrated on a single chip or on a small package such as a multi-chip module. We need a methodology, tools and environments where heterogeneity can be dealt with at all levels of abstraction and where different tools can be integrated. We present here Platform-Based Design as the CPS methodology of choice and metro II, a design environment that supports it. We present the metamodeling approach followed in metro II, how to couple the functionality and implementation platforms of CPS, and the simulation technology that supports the analysis of CPS and of their implementation. We also present examples of use and the integration of metro II with another popular design environment developed at Verimag, BIP. Abhijit Davare, Douglas Densmore, Liangpeng Guo, Roberto Passerone, Alberto L. Sangiovanni-Vincentelli, Alena Simalatsar, Qi Zhu 0002 |
ACM Trans. Embed. Comput. Syst. | 4 |
| 2012 | Design of an innovative proximity detection embedded-system for safety application in industrial machineryabstractSafety of machine operation is an increasingly important matter in industrial applications. In this context, embedded systems have successfully been employed to build active barriers that react in real time to prevent injuries and accidents. In this paper, we present a novel safety barrier, based on the capacitive coupling effect, to detect the proximity of the hands to a dangerous zone. Our study focuses on the safety design phases of the system, according to rule IEC 62061, including safety hazard analysis, SIL allocation, and hardware design applied to a real industrial machine for “stone cutting” purpose. Compliance checking of reliability and safe failure fraction was performed through FMEA methods ensuring that the system can satisfy the SIL 2 safety level constraints. Stefano Dalpez, Alessandro Vaccari 0001, Roberto Passerone, Alberto Penasa |
ETFA | 3 |
| 2012 | Energy-Aware Gas Sensing Using Wireless Sensor Networks
Andrey Somov, Alexander Baranov, Alexey Savkin, Lucia Calliari, Roberto Passerone, Evgeny F. Karpov, Alexey Suchkov |
EWSN | 6 |
| 2012 | Towards Extending Sensor Node Lifetime with Printed Supercapacitors
Andrey Somov, Christine Ho, Roberto Passerone, James W. Evans, Paul K. Wright |
EWSN | 3 |
| 2012 | Integration of correct-by-construction BIP models into the MetroII design space exploration flowabstractDesign correctness and performance are major issues which are usually considered separately, and with different emphasis, by traditional system design flows. In this paper we show that one can meaningfully connect and benefit from the advantages of two design frameworks, with different design goals. We consider BIP for high-level rigorous design and correct-by-construction implementation, and metroII, for low-level platform-based design and performance evaluation. Alena Simalatsar, Liangpeng Guo, Marius Bozga, Roberto Passerone |
ICCD | 4 |
| 2012 | A 33μW 42 GOPS/W 64x64 pixel vision sensor with dynamic background subtraction for scene interpretationabstractA 64x64 pixel vision sensor performs adaptive background subtraction and event detection at very low power consumption. The chip is based on a VLSI-oriented vision algorithm, implemented at pixel-level, mimicking the basic process of pre-attentive visual perception. Anomalous pixel behaviors are detected and coded into a 2-bit/pixel. Each pixel integrates two programmable Switched-Capacitors Low-Pass Filters and two clocked comparators, which are fundamental blocks for the execution of the vision algorithm. The 45T square pixel has a pitch of 26μm and a fill factor of 12%. The vision sensor consumes 33μW at 13 fps and 3.3V. This turns into a computing performance of 42 GOPS/W and 4 GOPS/mm2, which are values aligned with the most advanced computational vision sensors. Nicola Cottini, Massimo Gottardi, Nicola Massari, Roberto Passerone, Zeev Smilansky |
ISLPED | 4 |
| 2012 | Guest Editorial Special Section on Real-Time and (Networked) Embedded Systems IIIabstractThe four papers in this special section present some of the latest developments in the area of real-time and networked embedded systems, from software worst-case execution-time analysis, to predictable software synchronization, to frame scheduling on wireless sensor networks, and finally to the design and implementation of a time-critical control system over real-time Ethernet. Thomas Nolte, Roberto Passerone |
IEEE Trans. Ind. Informatics | 2 |
| 2011 | Power Adaptive Cognitive Pilot Channel for Spectrum Co-existence in Wireless NetworksabstractNext generation wireless networks will be heterogeneous, where several primary users (PU e.g. licensed users) and secondary users (SU e.g. unlicensed users) can operate in the same dynamic and reconfigurable networks at a given time. The major challenge in this heterogeneous radio environment is to enable the coexistence between PU and SU which will further improve the efficient use of radio spectrum. Most of the existing coexistence techniques encounter with challenges due to lack of a priori knowledge about the primary system. Therefore Cognitive pilot channel (CPC) is a proposed approach which could enhance the coexistence by conveying some priori information. However, to achieve a peaceful coexistence it is essential to adopt a mitigation technique according to the CPC information. There is no algorithm has been described so far to integrate the CPC information with existing mitigation technique. In this paper, we proposed a novel power adaptation and integrated zone model (PAIZM) CPC algorithm for peaceful coexistence in heterogeneous networks. Moreover we have implemented and evaluated the PAIZM-CPC model as a coexistence enabler. The results show an enhancement compared with the existing coexistence techniques. Md. Akbar Hossain, Roberto Passerone |
AINA | 2 |
| 2011 | Enabling parametric feasibility analysis in real-time calculus driven performance evaluationabstractThis paper advocates a rigorously formal and compositional style for obtaining key performance and/or interface metrics of systems with real-time constraints. We propose a hierarchical approach that couples the independent and different by nature frameworks of Modular Performance Analysis with Real-time Calculus (MPA-RTC) and Parametric Feasibility Analysis (PFA). Recent work on Real-time Calculus (RTC) has established an embedding of state-based component models into RTC-driven performance analysis for dealing with more expressive component models. However, with the obtained analysis infrastructure it is possible to analyze components only for a fixed set of parameters, e.g., fixed CPU speeds, fixed buffer sizes etc., such that a big space of parameters remains unstudied. In this paper, we overcome this limitation by integrating the method of parametric feasibility analysis in an RTC-based modeling environment. Using the PFA tool-flow, we are able to find regions for component parameters that maintain feasibility and worst-case properties. As a result, the proposed analysis infrastructure produces a broader range of valid design candidates, and allows the designer to reason about the system robustness. Alena Simalatsar, Yusi Ramadian, Kai Lampka, Simon Perathoner, Roberto Passerone, Lothar Thiele |
CASES | 5 |
| 2011 | A Modal Interface Theory for Component-based DesignabstractThis paper presents the modal interface theory, a unification of interface automata and modal specifications, two radically dissimilar models for interface theories. Interface automata is a game-based model, which allows the designer to express assum Jean-Baptiste Raclet, Éric Badouel, Albert Benveniste, Benoît Caillaud, Axel Legay, Roberto Passerone |
Fundam. Informaticae | 6 |
| 2011 | Scalable Offline Optimization of Industrial Wireless Sensor NetworksabstractSensor networks are increasingly used to control and monitor industrial and manufacturing processes. In this paper, we consider the problem of optimizing a cost function for wireless sensor networks of this kind under energy consumption constraints. We focus, in particular, on the problem of coverage optimization through scheduling. Following existing approaches, we use a mixed integer linear program formulation. We show how to use partitioning techniques to decompose the problem into separate subproblems, solved individually, overcoming the exponential complexity typical of integer linear programming, while minimizing the loss in optimality. In addition, we evaluate the achieved degree of optimality by computing relatively tight bounds with respect to the optimal solution. Finally, we employ simple but effective heuristics to further improve our solution. The results show that our procedure is very efficient and scalable, and is able to find solutions that are very close to optimal. These characteristics make our approach a perfect fit for large and fixed deployments of wireless sensors, typical in factory automation and industrial applications. To show the generality of the approach, we apply our methodology to three different models of varying complexity. Luigi Palopoli 0002, Roberto Passerone, Tizar Rizano |
IEEE Trans. Ind. Informatics | 2 |
| 2010 | Parametric analysis of distributed firm real-time systems: A case studyabstractA new generation of distributed real-time systems (DRTS) is based on heterogeneous models of computation and communication and is associated with flexible real-time constraints. Classical design flows based on realtime scheduling theory display important limitations related to the restrictive assumption on the system model. On the other hand, formal verification of timed automata is far more general, but it suffers a different limitation: it does not provide any guide on how to choose the design parameters, nor does it permit to gauge the robustness of the design against unknown parameters. In this paper, we advocate the use of formal verification of parametric timed automata as a means to combine the best of the two approaches. The feasibility of the idea is shown on a significant industrial case study. Thi Thieu Hoa Le, Luigi Palopoli 0002, Roberto Passerone, Yusi Ramadian, Alessandro Cimatti |
ETFA | 3 |
| 2010 | Ensuring Correctness in the Specification and Handling of Non-Functional Attributes in High-Integrity Real-Time Embedded SystemsabstractIn high-integrity systems, the focus of the development process is geared to assuring that the assertions made on the system are both correct (i.e., semantically sustainable) and feasible (i.e., true at run time). Some of those assertions take effect in the non-functional domain, that is, in how the system is realized and behaves in time, space and communication during execution; others in the functional domain, and thus concern what outputs the system produces for its inputs. In this paper, we address the problem of achieving correct specification and handling of non-functional attributes, with particular regard to the concurrent structure of the system, the safeness of the interaction protocols engaged in it, and the guarantee that its timing feasibility can be statically verified. Our approach is based on a Model-Driven Engineering methodology, in which correctness can be ensured by construction or verified at a high level of abstraction, while the runtime implementation structure and code are automatically generated. We employ the Ravenscar Computation Model (RCM) and focus, in particular, on aerospace applications, which impose stringent requirements on correctness properties. We discuss an algebraic formalization of our model based on graph theory which we use to prove safe termination in systems compliant with RCM, and show how to use the MAST+ static analyzer to verify the timing aspects. We finally illustrate the results of a prototype tool that was developed for evaluation by major industrial players in the European space industry. Daniela Cancila, Roberto Passerone, Tullio Vardanega, Marco Panunzio |
IEEE Trans. Ind. Informatics | 2 |
| 2009 | UMTS MPSoC design evaluation using a system level design frameworkabstractRapid design space exploration with accurate models is necessary to improve designer productivity at the electronic system level. We describe how to use a new event-based design framework, Metro II, to carry out simulation and design space exploration of multi-core architectures. We illustrate the design methodology on a UMTS data link layer design case study with both a timed and untimed functional model as well as a complete set of MPSoC architectural services. We compare different architectures (including RTOSes) explored with Metro II and quantify the associated simulation overhead. Douglas Densmore, Alena Simalatsar, Abhijit Davare, Roberto Passerone, Alberto L. Sangiovanni-Vincentelli |
DATE | 4 |
| 2009 | Modal interfaces: unifying interface automata and modal specificationsabstractThis paper presents a unification of interface automata and modal specifications, two radically dissimilar models for interface theories. Interface automata is a game-based model, which allows to make assumptions on the environment and propose an optimistic view for composition : two components can be composed if there is an environment where they can work together. Modal specification is a language theoretic account of a fragment of the modal mu-calculus logic that is more complete but which does not allow to distinguish between the environment and the component. Partial unifications of these two frameworks have been explored recently. A first attempt by Larsen et al. considers modal interfaces, an extension of modal specifications that deals with compatibility issues in the composition operator. However, this composition operator is incorrect. A second attempt by Raclet et al. gives a different perspective, and emphasises on conjunction and residuation of modal specifications, including when interfaces have dissimilar alphabets, but disregards interface compatibility. The present paper contributes a thorougher unification of the two theories by correcting the modal interface composition operator presented in the paper by Larsen et al., drawing a complete picture of the modal interface algebra, and pushing even further the comparison between interface automata, modal automata and modal interfaces. Jean-Baptiste Raclet, Éric Badouel, Albert Benveniste, Benoît Caillaud, Axel Legay, Roberto Passerone |
EMSOFT | 6 |
| 2009 | A Methodology for Power Consumption Evaluation of Wireless Sensor NetworksabstractEnergy consumption is one of the most constraining requirements for the design and implementation of wireless sensor networks. Simulation tools allow one to significantly decrease the effort and time spent to choose the right solution. Existing simulators provide varying degrees of analysis for communication, application and energy domains. However, they do not provide enough flexibility to estimate the consumed power for a wide range of wireless sensor network (WSN) hardware (HW) platforms. In this paper we present a flexible and extensible simulation framework to estimate power consumption of sensor network applications for arbitrary HW platforms. This framework allows designers of sensor networks to estimate power consumption of the explored HW platform which permits the selection of an optimal HW solution and software (SW) implementation for the desired projects. Andrey Somov, Ivan Minakov, Alena Simalatsar, Giorgio Fontana, Roberto Passerone |
ETFA | 5 |
| 2009 | Solving the Wake-Up Scattering Problem Optimally
Luigi Palopoli 0002, Roberto Passerone, Amy L. Murphy, Gian Pietro Picco, Alessandro Giusti |
EWSN | 2 |
| 2009 | Convergence of Distributed WSN Algorithms: The Wake-Up Scattering Problem
Daniele Fontanelli, Luigi Palopoli 0002, Roberto Passerone |
HSCC | 3 |
| 2008 | Functional and structural properties in the Model-Driven Engineering approachabstractIn this paper we discuss the separation between attributes on functionality and on structure following an approach based on model driven engineering (MDE). We adopt a methodological approach based on correctness-by-construction for modeling high-integrity real-time embedded systems. We illustrate how this separation is implemented by a prototype, recently realized by our research team. Software reuse is incremented by using the prototype. This has been confirmed by the evaluation of two teams from major European space industry. We conclude our work by discussing some open problems. Daniela Cancila, Roberto Passerone |
ETFA | 2 |
| 2008 | FZepel: RF-level power consumption measurement (RF-PM) for Zigbee wireless sensor network-towards cross layer optimizationabstractEnergy consumption is one of the most crucial design issues in wireless sensor networks (WSN) and largely depends on energy-efficient communication protocols. In order to improve the lifetime of a WSN, the cross-layer optimization technique can potentially be used to jointly optimize the power consumption behavior between various layers of the protocol stack. In this paper we propose a finite state machine (FSM) based ZigBee power model (FZepel) that can be used for cross-layer stack analysis. FZepel is a primitive execution-based power estimation method. To achieve the desired level of accuracy, we also present an RFlevel power measurement (RF-PM) technique for Zigbee-based wireless sensor networks. Using a PICDEM and a CC2420 communication component, we show how to characterize the state-based machine model of the network coordinator using the RF-PM technique. Md. Rezaul Hoque Khan, Roberto Passerone, David Macii |
ETFA | 2 |
| 2008 | A Contract-based Formalism for the Specification of Heterogeneous Systems (invited)abstractWe present the mathematical formalism and the verification methodology of the contract-based model developed in the framework of the SPEEDS project. SPEEDS aims at developing methods and tools to support ldquospeculative designrdquo, a design methodology in which distributed designers develop different aspects of the overall system, in a concurrent but controlled way. Our generic mathematical model of contract supports this style of development. This is achieved by focusing on behaviors, by supporting the notion of ldquorich componentrdquo where functional and non-functional aspects of the system can be considered and combined, by representing rich components via their set of associated contracts, and by formalizing the process of component composition. Luca Benvenuti, Alberto Ferrari, Leonardo Mangeruca, Emanuele Mazzi, Roberto Passerone, Christos Sofronis |
FDL | 5 |
| 2007 | Refinement preserving approximations for the design and verification of heterogeneous systems
Roberto Passerone, Jerry R. Burch, Alberto L. Sangiovanni-Vincentelli |
Formal Methods Syst. Des. | 1 |
| 2007 | Specification, Synthesis, and Simulation of Transactor ProcessesabstractTransaction-level models promise to be the basis of the verification environment for the whole design process. Realizing this promise requires connecting transaction-level and register-transfer-level (RTL) blocks through a transactor, which translates back and forth between RTL signal-based communication and transaction-level function-call-based communication. Each transactor is associated with a pair of interfaces, one at RTL and one at transaction level. Typically, however, a pair of interfaces is associated with more than one transactor, each assuming a different role in the verification process. In this paper, we propose a methodology in which both the interfaces and their relation are captured by a single formal specification. By using the specification, we show how the code for all the transactors associated with a pair of interfaces can be automatically generated. Our synthesis algorithm avoids the state-explosion problems associated with certain features of the specification formalism, at the expense of a more sophisticated simulation algorithm. We describe three different code-generation techniques targeted at different verification languages: (1) C++; (2) Verilog; and (3) the combination of the two that is compliant with the Standard Co-Emulation Modeling Interface protocol. In addition, we present several case studies demonstrating that automatically generated transactors can indeed replace handcrafted ones in realistic designs. Felice Balarin, Roberto Passerone |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2006 | Functional verification methodology based on formal interface specification and transactor generationabstractTransaction level models promise to be the basis of the verification environment for the whole design process. Realizing this promise requires connecting transaction level and RTL blocks through an object called a transactor, which translates back and forth between RTL signal-based communication, and transaction level function-call based communication. Each transactor is associated with a pair of interfaces, one at RTL and one at transaction level. Typically, however, a pair of interfaces is associated to more than one transactor, each assuming a different role in the verification process. In this paper we propose a methodology in which both the interfaces and their relation are captured by a single formal specification. By using the specification, we show how the code for all the transactors associated with a pair of interfaces can be automatically generated Felice Balarin, Roberto Passerone |
DATE | 2 |
| 2006 | System level design paradigms: Platform-based design and communication synthesisabstractEmbedded system level design must be based on paradigms that make formal foundations and unification a cornerstone of their construction. Platform-Based designs and communication synthesis are important components of the paradigm shift we advocate.Communication synthesis is a fundamental productivity tool in a design methodology where reuse is enforced. Communication design in a reuse methodology starts with a set of functional requirements and constraints on the interaction among components and then proceeds to build protocols, topology, and physical implementations that satisfy requirements and constraints while optimizing appropriate measures of efficiency of the implementation. Maximum efficiency can be reached when the communication specifications are entered at high levels of abstraction and the design process optimizes the implementation from this specification. Unfortunately, this process is very difficult if it is not cast in a rigorous framework. Platform-Based design helps define a successive refinement process where each step can be carried out automatically and optimized appropriately. We present two cases, an on-chip and a wireless sensor network design, where the resulting methodology gave encouraging results. Alessandro Pinto, Alvise Bonivento, Alberto L. Sangiovanni-Vincentelli, Roberto Passerone, Marco Sgroi |
ACM Trans. Design Autom. Electr. Syst. | 4 |
| 2005 | A formal approach to system level design: metamodels and unified design environmentsabstractThe debate about efficient methods for hardware-software co-design has taken interesting turns over the years. In this paper, we argue that the essential problems to solve are prior to the decision on how to partition the system in hardware-software. We present a formal platform-based design method we have proposed over the years and a design environment, Metropolis, supporting the methodology, which starts by capturing the design specifications at the highest level of abstraction and then proceed toward an efficient implementation by subsequent refinement steps. We present the modeling strategy used in Metropolis based on formal semantics that is general enough to support the models of computation proposed so far and that facilitates the creation of new ones. Nonfunctional and declarative constraints can also be captured using a logic language. Felice Balarin, Roberto Passerone, Alessandro Pinto, Alberto L. Sangiovanni-Vincentelli |
MEMOCODE | 2 |
| 2004 | Conservative approximations for heterogeneous designabstractEmbedded systems are electronic devices that function in the context of a real environment, by sensing and reacting to a set of stimuli. Because of their close interaction with the environment, and to simplify their design, different parts of an embedded system are best described using different notations and different techniques. In this case, we say that the system is heterogeneous.We informally refer to the notation and the rules that are used to specify and verify the elements of heterogeneous system and their collective behavior as a model of computation. In this paper, we focus in particular on abstraction and refinement relationships in the form of conservative approximations. We do so by constructing a framework, called Agent Algebra, where the different models reside and share a common algebraic structure. We compare our techniques to the well established notion of abstract interpretation. We show that, unlike abstract interpretations, conservative approximations preserve refinement verification results from an abstract to a concrete model while avoiding false positives. In addition, we use the inverse of a conservative approximation to identify components that can be used indifferently in several models, thus enabling reuse across domains of computation. Roberto Passerone, Jerry R. Burch, Alberto L. Sangiovanni-Vincentelli |
EMSOFT | 1 |
| 2002 | Convertibility verification and converter synthesis: two faces of the same coinabstractAn essential problem in component-based design is how to compose components designed in isolation. Several approaches have been proposed for specifying component interfaces that capture behavioral aspects such as interaction protocols, and for verifying interface compatibility. Likewise, several approaches have been developed for synthesizing converters between incompatible protocols. In this paper, we introduce the notion of adaptability as the property that two interfaces have when they can be made compatible by communicating through a converter that meets specified requirements. We show that verifying adaptability and synthesizing an appropriate converter are two faces of the same coin: adaptability can be formalized and solved using a game-theoretic framework, and then the converter can be synthesized as a strategy that always wins the game. Finally we show that this framework can be related to the rectification problem in trace theory. Roberto Passerone, Luca de Alfaro, Thomas A. Henzinger, Alberto L. Sangiovanni-Vincentelli |
ICCAD | 1 |
| 1998 | Automatic Synthesis of Interfaces Between Incompatible ProtocolsabstractA t the system level, reusable Intellectual Property (or IP) blo cks can be represented abstractly as blocks that exchange messages. The concrete implementations of these IP blocks m ust exc hange the messages through complex signaling protocols. Interfacing bet ween IP that use different signaling protocols is a tedious and error prone design task. We propose using regular expression based protocol descriptions to sho w ho w to map the message on to a signaling protocol. Given t w o protocols,an algorithm is proposed to build an interface machine. We ha ve implemented our algorithm in a program named PIG that synthesizes a Verilog implementation based on a regular expression protocol description. Roberto Passerone, James A. Rowson, Alberto L. Sangiovanni-Vincentelli |
DAC | 1 |
| 1998 | Modeling reactive systems in JavaabstractWe present an application of the Java TM programming language to specify and implement reactive real-time systems. We have developed and tested a collection of classes and methods to describe concurrent modules and their asynchronous communication by means of signals. The control structures are closely patterned after those of the synchronous language Esterel , succinctly describing concurrency, sequencing and preemption. We show the user-friendliness and efficiency of the proposed technique by using an example from the automotive domain. Claudio Passerone, Claudio Sansoè, Luciano Lavagno, Patrick C. McGeer, Roberto Passerone, Alberto L. Sangiovanni-Vincentelli |
ACM Trans. Design Autom. Electr. Syst. | 6 |