EDBT 2026 Demo / reviewers in the wild / expert
Michael Paulitsch
dblp:79/3385
· DBLP profile ↗
34ranked-venue papers
7as first author
14since 2021 · last 2025
0000-0002-9241-5806ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 15 · 3 first-author · 4 since 2021Artificial intelligence and machine learning · 7 · 7 since 2021Security and privacy · 6 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 4 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 4 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | ConDo: Continual Domain Expansion for Absolute Pose RegressionabstractVisual localization is a fundamental machine learning problem. Absolute Pose Regression (APR) trains a scene-dependent model to efficiently map an input image to the camera pose in a pre-defined scene. However, many applications have continually changing environments, where inference data at novel poses or scene conditions (weather, geometry) appear after deployment. Training APR on a fixed dataset leads to overfitting, making it fail catastrophically on challenging novel data. This work proposes Continual Domain Expansion (ConDo), which continually collects unlabeled inference data to update the deployed APR. Instead of applying standard unsupervised domain adaptation methods which are ineffective for APR, ConDo effectively learns from unlabeled data by distilling knowledge from scene-agnostic localization methods. By sampling data uniformly from historical and newly collected data, ConDo can effectively expand the generalization domain of APR. Large-scale benchmarks with various scene types are constructed to evaluate models under practical (long-term) data changes. ConDo consistently and significantly outperforms baselines across architectures, scene types, and data changes. On challenging scenes (Fig.1), it reduces the localization error by >7x (14.8m vs 1.7m). Analysis shows the robustness of ConDo against compute budgets, replay buffer sizes and teacher prediction noise. Comparing to model re-training, ConDo achieves similar performance up to 25x faster. Zijun Li 0006, Zhipeng Cai 0003, Bochun Yang, Xuelun Shen, Xiaoliang Fan, Michael Paulitsch, Cheng Wang 0003 |
AAAI | 7 |
| 2025 | PBR-SR: Mesh PBR Texture Super Resolution from 2D Image PriorsabstractWe present PBR-SR, a novel method for physically based rendering (PBR) texture super resolution (SR). It outputs high-resolution, high-quality PBR textures from low-resolution (LR) PBR input in a zero-shot manner. PBR-SR leverages an off-the-shelf super-resolution model trained on natural images, and iteratively minimizes the deviations between super-resolution priors and differentiable renderings. These enhancements are then back-projected into the PBR map space in a differentiable manner to produce refined, high-resolution textures. To mitigate the effects of view inconsistency and lighting sensitivity inherent to view-based super-resolution, our approach incorporates 2D prior constraints across multi-view renderings, enabling iterative refinement of shared upscaled textures. In parallel, we incorporate identity constraints directly in the PBR texture domain to ensure the upscaled textures remain faithful to the LR input. PBR-SR operates without any additional training or data requirements, relying entirely on pretrained image priors. We demonstrate that our approach produces high-fidelity PBR textures for both artist-designed and AI-generated meshes, outperforming both direct SR models application and prior texture optimization methods. Our results show high-quality outputs in both PBR and rendering evaluations, supporting advanced applications such as relighting. Yujin Chen, Yinyu Nie, Benjamin Ummenhofer, Reiner Birkl, Michael Paulitsch, Matthias Nießner |
NeurIPS | 5 |
| 2025 | HoloScene: Simulation-Ready Interactive 3D Worlds from a Single VideoabstractDigitizing the physical world into accurate simulation‑ready virtual environments offers significant opportunities in a variety of fields such as augmented and virtual reality, gaming, and robotics. However, current 3D reconstruction and scene-understanding methods commonly fall short in one or more critical aspects, such as geometry completeness, object interactivity, physical plausibility, photorealistic rendering, or realistic physical properties for reliable dynamic simulation. To address these limitations, we introduce HoloScene, a novel interactive 3D reconstruction framework that simultaneously achieves these requirements. HoloScene leverages a comprehensive interactive scene-graph representation, encoding object geometry, appearance, and physical properties alongside hierarchical and inter-object relationships. Reconstruction is formulated as an energy-based optimization problem, integrating observational data, physical constraints, and generative priors into a unified, coherent objective. Optimization is efficiently performed via a hybrid approach combining sampling-based exploration with gradient-based refinement. The resulting digital twins exhibit complete and precise geometry, physical stability, and realistic rendering from novel viewpoints. Evaluations conducted on multiple benchmark datasets demonstrate superior performance, while practical use-cases in interactive gaming and real-time digital-twin manipulation illustrate HoloScene's broad applicability and effectiveness. Hongchi Xia, Chih-Hao Lin, Hao-Yu Hsu, Quentin Leboutet, Katelyn Gao, Michael Paulitsch, Benjamin Ummenhofer, Shenlong Wang |
NeurIPS | 6 |
| 2024 | L-MAGIC: Language Model Assisted Generation of Images with CoherenceabstractIn the current era of generative AI breakthroughs, generating panoramic scenes from a single input image remains a key challenge. Most existing methods use diffusion-based iterative or simultaneous multi-view inpainting. However, the lack of global scene layout priors leads to subpar outputs with duplicated objects (e.g., multiple beds in a bedroom) or requires time-consuming human text inputs for each view. We propose L-MAGIC, a novel method leveraging large language models for guidance while diffusing multiple coherent views of 360° panoramic scenes. L-MAGIC harnesses pretrained diffusion and language models without fine-tuning, ensuring zero-shot performance. The output quality is further enhanced by super-resolution and multi-view fusion techniques. Extensive experiments demonstrate that the resulting panoramic scenes feature better scene layouts and perspective view rendering quality compared to related works, with >70% preference in human evaluations. Combined with conditional diffusion models, L-MAGIC can accept various input modalities, including but not limited to text, depth maps, sketches, and colored scripts. Applying depth estimation further enables 3D point cloud generation and dynamic scene exploration with fluid camera motion. Code is available at https://github.com/ZhipengCai/L-MAGIC-code-release. Zhipeng Cai 0003, Matthias Müller 0011, Reiner Birkl, Diana Wofk, Shao-Yen Tseng, Junda Cheng, Gabriela Ben Melech Stan, Vasudev Lal, Michael Paulitsch |
CVPR | 9 |
| 2024 | Mesh2NeRF: Direct Mesh Supervision for Neural Radiance Field Representation and Generation
Yujin Chen, Yinyu Nie, Benjamin Ummenhofer, Reiner Birkl, Michael Paulitsch, Matthias Müller 0011, Matthias Nießner |
ECCV (9) | 5 |
| 2024 | MIDGArD: Modular Interpretable Diffusion over Graphs for Articulated DesignsabstractProviding functionality through articulation and interaction with objects is a key objective in 3D generation. We introduce MIDGArD (Modular Interpretable Diffusion over Graphs for Articulated Designs), a novel diffusion-based framework for articulated 3D asset generation. MIDGArD improves over foundational work in the field by enhancing quality, consistency, and controllability in the generation process. This is achieved through MIDGArD's modular approach that separates the problem into two primary components: structure generation and shape generation. The structure generation module of MIDGArD aims at producing coherent articulation features from noisy or incomplete inputs. It acts on the object's structural and kinematic attributes, represented as features of a graph that are being progressively denoised to issue coherent and interpretable articulation solutions. This denoised graph then serves as an advanced conditioning mechanism for the shape generation module, a 3D generative model that populates each link of the articulated structure with consistent 3D meshes. Experiments show the superiority of MIDGArD on the quality, consistency, and interpretability of the generated assets. Importantly, the generated models are fully simulatable, i.e., can be seamlessly integrated into standard physics engines such as MuJoCo, broadening MIDGArD's applicability to fields such as digital content creation, meta realities, and robotics. Quentin Leboutet, Nina Wiedemann, Michael Paulitsch |
NeurIPS | 4 |
| 2023 | BEA: Revisiting anchor-based object detection DNN using Budding Ensemble Architecture
Syed Sha Qutub, Neslihan Kose, Rafael Rosales, Michael Paulitsch, Korbinian Hagn, Florian Geissler, Gereon Hinz, Alois C. Knoll |
BMVC | 4 |
| 2023 | A Low-Cost Strategic Monitoring Approach for Scalable and Interpretable Error Detection in Deep Neural Networks
Florian Geissler, Syed Sha Qutub, Michael Paulitsch, Karthik Pattabiraman |
SAFECOMP | 3 |
| 2023 | Structural Coding: A Low-Cost Scheme to Protect CNNs from Large-Granularity Memory FaultsabstractThe advent of High-Performance Computing has led to the adoption of Convolutional Neural Networks (CNNs) in safety-critical applications such as autonomous vehicles. However, CNNs are vulnerable to DRAM errors corrupting their parameters, thereby degrading their accuracy. Existing techniques for protecting CNNs from DRAM errors are either expensive or fail to protect from large-granularity, multi-bit errors, which occur commonly in DRAMs. Ali Asgari Khoshouyeh, Florian Geissler, Syed Sha Qutub, Michael Paulitsch, Prashant J. Nair, Karthik Pattabiraman |
SC | 4 |
| 2023 | Innovation Practices Track: Testability and Dependability of AI Hardware and Autonomous SystemsabstractTestability and dependability (e.g., safety) of AI hardware (e.g., GPU, AI accelerators) and AI-based autonomous systems has been emerging as an important R&D topic in order to address increasing resiliency. In this session we will invite the industry experts to discuss the various aspects of this new field. Arjun Chaudhuri, Michael Paulitsch |
VTS | 4 |
| 2023 | Mixed precision support in HPC applications: What about reliability?
Alessio Netti, Patrik Omland, Michael Paulitsch, Jorge Parra, Gustavo Espinosa, Udit Kumar Agarwal, Abraham Chan, Karthik Pattabiraman |
J. Parallel Distributed Comput. | 4 |
| 2023 | HPC Hardware Design Reliability Benchmarking With HDFITabstractChips pack ever more, ever smaller transistors. Fault rates increase in turn and become more concerning, particularly at the scale ofHigh-Performance Computing(HPC) systems: on one hand, hardware fault protection is costly - more than 10% silicon area for floating-point units; on the other, HPC users expect correct application output after the anticipated time of computation, but workloads are seldom bit-reproducible and tolerances in output are allowed for. Benign hardware faults causing errors within these tolerances are therefore acceptable: however, with abstract reliability targets such as ’undetected failures per time,’ current HPC system design does not allow for pursuing trade-offs between reliability and performance with respect to faults. To address the above, we propose a user-centric reliability benchmark to specify HPC system reliability targets, allowing for better performance optimizations in hardware design, while meeting HPC user expectations. Our open-sourceHardware Design Fault Injection Toolkit(HDFIT) enables - for the first time - end-to-end hardware design reliability experiments: from netlist-level fault injection to application output error. In a proof of concept we present an HPCgeneral matrix multiply(GEMM) reliability study, targeting a series of popular applications, and using HDFIT to benchmark an open-source GEMM accelerator. Patrik Omland, Alessio Netti, Andrea Baldovin, Michael Paulitsch, Gustavo Espinosa, Jorge Parra, Gereon Hinz, Alois C. Knoll |
IEEE Trans. Parallel Distributed Syst. | 5 |
| 2022 | Hardware Faults that Matter: Understanding and Estimating the Safety Impact of Hardware Faults on Object Detection DNNs
Syed Sha Qutub, Florian Geissler, Ralf Gräfe, Michael Paulitsch, Gereon Hinz, Alois C. Knoll |
SAFECOMP | 5 |
| 2021 | Composable Finite State Machine-based Modeling for Quality-of-Information-aware Cyber-physical SystemsabstractTime plays a major role in the specification of Cyber-physical Systems (CPS) behavior with concurrency, timeliness, asynchrony, and resource limits as their main characteristics. In addition to timeliness , the specification of CPS needs to assess and unambiguously define its behavior with respect to the other Quality-of-Information (QoI) properties: (1) Correctness, (2) Completeness, (3) Consistency, and (4) Accuracy. Very often, CPS need to handle these QoI properties, and any combination thereof, multiple times when performing computation and communication processes. However, a model-driven and systematic approach to specify CPS behavior that jointly considers combined QoI aspects is possible but missing in existing methodologies. As the first contribution of this work, we provide an extension to an established model of computation (MoC) based on “Functions driven by Finite State Machine” (FunState) to enable a model-driven composition mechanism to create CPS behavior specifications from reusable components. Second, we present a novel set of design patterns to illustrate the modeling of QoI-aware CPS specifications that can be applied in several state-of-the-art Electronic System Level (ESL) methodologies. The time semantics of the MoC are formalized using the tagged-signal-model, and the presented model-driven approach enables the composition of multiple design patterns. The main benefits of the presented model-driven approach and design patterns to create CPS specifications are as follows: (a) reduce modeling effort, errors, and time through the reuse of known recipes to re-incurring tasks and allow to automatically generate repetitive control flows based on extended Finite State Machines; (b) increase system robustness and facilitate the creation of holistic QoI management allowing to unambiguously define system behavior for scenarios with single/multiple QoI requirement violations in different models of computation; (c) dynamically validate timing behavior of system implementations to enable a multi-objective optimization of nonfunctional properties that influence CPS timing. We demonstrate the aforementioned benefits through the modeling and evaluation of an infrastructure-assisted automated driving case study using Infrastructure-to-Vehicle (I2V) communications to distribute QoI critical road environment information. Rafael Rosales, Michael Paulitsch |
ACM Trans. Cyber Phys. Syst. | 2 |
| 2019 | Flight Safety Certification Implications for Complex Multi-Core Processor based Avionics SystemsabstractSince the early 1990s, federated avionics architecture - where one computing resource executes only one application, is being replaced by Integrated Modular Avionics (IMA) architectures. IMA architectures employ a partitioned environment that hosts multiple avionics functions of different safety criticalities on a common computing platform. This provides for size, weight, and power savings via denser functional integration. Several cores integrated onto one device allows more functions to be integrated together on one processor and in one piece of equipment. The use of multicore processors in safety-critical avionics applications will provide growth for further integration for the future generations of these systems. Hence aerospace equipment suppliers are interested in using Multi-Core Processors (MCPs) in their systems. With the rapid increase in demand for computational performance and cost optimum, Single-Core Processors (SCPs) are likely to become obsolete. However, with the shift to multi-core processors, compliance to safety requirements is becoming critical. The development and use of increasingly complex electronic hardware by the aviation industry for more of the safety-critical aircraft functions is creating new safety and certification concerns. Jyotika Athavale, Riccardo Mariani, Michael Paulitsch |
IOLTS | 3 |
| 2017 | Contention-Aware Dynamic Memory Bandwidth Isolation with Predictability in COTS Multicores: An Avionics Case StudyabstractAirbus is investigating COTS multicore platforms for safety-critical avionics applications, pursuing helicopter-style autonomous and electric aircraft. These aircraft need to be ultra-lightweight for future mobility in the urban city landscape. As a step towards certification, Airbus identified the need for new methods that preserve the ARINC 653 single core schedule of a Helicopter Terrain Awareness and Warning System (HTAWS) application while scheduling additional safety-critical partitions on the other cores. As some partitions in the HTAWS application are memory-intensive, static memory bandwidth throttling may lead to slow down of such partitions or provide only little remaining bandwidth to the other cores. Thus, there is a need for dynamic memory bandwidth isolation. This poses new challenges for scheduling, as execution times and scheduling become interdependent: scheduling requires execution times as input, which depends on memory latencies and contention from memory accesses of other cores - which are determined by scheduling. Furthermore, execution times depend on memory access patterns. In this paper, we propose a method to solve this problem for slot-based time-triggered systems without requiring application source-code modifications using a number of dynamic memory bandwidth levels. It is NoC and DRAM controller contention-aware and based on the existing interference-sensitive WCET computation and the memory bandwidth throttling mechanism. It constructs schedule tables by assigning partitions and dynamic memory bandwidth to each slot on each core, considering worst case memory access patterns. Then at runtime, two servers - for processing time and memory bandwidth - run on each core, jointly controlling the contention between the cores and the amount of memory accesses per slot. As a proof-of-concept, we use a constraint solver to construct tables. Experiments on the P4080 COTS multicore platform, using a research OS from Airbus and EEMBC benchmarks, demonstrate that our proposed method enables preserving existing schedules on a core while scheduling additional safety-critical partitions on other cores, and meets dynamic memory bandwidth isolation requirements. Ankit Agrawal 0005, Gerhard Fohler, Johannes Freitag, Jan Nowotsch, Sascha Uhrig, Michael Paulitsch |
ECRTS | 6 |
| 2016 | Poster Abstract: Slot-Level Time-Triggered Scheduling on COTS Multicore Platform with Resource ContentionsabstractIn this work, we present an initial step towards enabling TT scheduling on a real COTS multicore platform P4080. It takes into account inter-core interferences in the on-chip network and the memory sub-system. We propose an approach comprising a runtime mechanism and an offline phase. For the runtime mechanism, we propose two servers running on each core-processing time server and memory access server implemented using built-in hardware monitors. Jointly, the two servers on each core, enforce slot-level offline computed server budget reservations, thereby limiting the maximum inter-core interferences introduced and experienced by each task considering different inter-core interference latencies. In the offline phase, we propose a procedure that can be used by any offline scheduler to compute the bound on variability in execution time of each task while allowing different slot-level memory access server budget reservations. We also did a preliminary bare-metal implementation of our proposed runtime mechanism on a real COTS multicore platform P4080. Overall, our proposed method facilitates integration of COTS multicore platforms in TT systems, while maintaining features of TT architecture like slot-level determinism, clock synchronization, etc. Ankit Agrawal 0005, Gerhard Fohler, Jan Nowotsch, Sascha Uhrig, Michael Paulitsch |
RTAS | 5 |
| 2015 | MPIOV: scaling hardware-based I/O virtualization for mixed-criticality embedded real-time systems using non transparent bridges to (multi-core) multi-processor systems
Daniel Münch, Michael Paulitsch, Oliver Hanka, Andreas Herkersdorf |
DATE | 2 |
| 2015 | Mixed-Criticality Embedded Systems - A Balance Ensuring Partitioning and PerformanceabstractMixed-criticality systems have become a mainstream in industry and research due to their potential to decrease, size, weight, and power. Often research institutions and industry interpret the term 'mixed criticality' differently. Hence research approaches and solutions are hard to deploy to industry. This paper discusses the background, the current state of research and industrial deployment of mixed-criticality systems from an industrial perspective. It presents the background of criticality, the safety and security processes, and some approaches of applications of research to real systems. The focus of this paper is partitioning, which is the separation of different applications of different criticality, and its impact on performance along with possible optimizations. Michael Paulitsch, Oscar Medina Duarte, Hassen Karray, Kevin Mueller, Daniel Münch, Jan Nowotsch |
DSD | 1 |
| 2014 | Monitoring and WCET analysis in COTS multi-core-SoC-based mixed-criticality systemsabstractThe performance and power efficiency of multi-core processors are attractive features for safety-critical applications, for example in avionics. But the inherent use of shared resources complicates timing analysability. In this paper we discuss a novel approach to compute the Worst-Case Execution Time (WCET) of multiple hard real-time applications scheduled on a Commercial Off-The-Shelf (COTS) multi-core processor. The analysis is closely coupled with mechanisms for temporal partitioning as, for instance, required in ARINC 653-based systems. Based on a discussion of the challenges for temporal partitioning and timing analysis in multi-core systems, we deduce a generic architecture model. Considering the requirements for re-usability and incremental development and certification, we use this model to describe our integrated analysis approach. Jan Nowotsch, Michael Paulitsch, Arne Henrichsen, Werner Pongratz, Andreas Schacht |
DATE | 2 |
| 2014 | Iterative FPGA Implementation Easing Safety Certification for Mixed-Criticality Embedded Real-Time SystemsabstractThe design and operation of an aircraft, a railway, and a nuclear power station that include either safety-critical or safety-related systems require a proof that its safety is assured. The process providing this proof is called certification. This paper suggests an iterative FPGA implementation and iterative certification concept for FPGA-based systems to provide design-time adaptability while the complexity is still kept low to ease certification. The practical evaluation of this concept demonstrates that reuse at implementation level of a previously implemented part is to 100% usable for iterative certification. Regarding the resource utilization and complexity, the evaluation shows that there are potential savings in resource utilization and complexity compared to conventional run-time configurable designs. Iterative certification reduces the recertification of a whole design to a recertification of the changed part only and a verification tool qualification. It is shown that tool qualification can be accomplished with relatively moderate effort. Therefore, the presented concept substantially eases the certification process when using modular design and building block reuse. Daniel Münch, Michael Paulitsch, Michael Honold, Wolfgang Schlecker, Andreas Herkersdorf |
DSD | 2 |
| 2014 | Multi-core Interference-Sensitive WCET Analysis Leveraging Runtime Resource Capacity EnforcementabstractThe performance and power efficiency of multi-core processors are attractive features for safety-critical applications, as in avionics. But increased integration and average-case performance optimisations pose challenges when deploying them for such domains. In this paper we propose a novel approach to compute an is WCET considering variable access delays due to the concurrent use of shared resources in multi-core processors, particularly focusing on shared interconnects and main memory. Thereby we tackle the problem of temporal partitioning as required by safety-critical applications. In particular, we introduce additional phases to state-of-the-art timing analysis techniques to analyse an application's resource usage and compute an interference delay. We further complement the offline analysis with a runtime monitoring concept to enforce resource usage guarantees. The concepts are evaluated on Free scale's P4080 multi-core processor in combination with SYSGO's commercial real-time operating system Pike OS and Abs Int's timing analysis framework aiT. We abstract real applications' behaviour using a representative task set of the EEMBC Auto bench benchmark suite. Our results show a reduction of up to 53% of the multi-core WCET, while implementing full transparency to the temporal and functional behaviour of applications, enabling the seamless integration of legacy applications. Jan Nowotsch, Michael Paulitsch, Daniel Buhler, Henrik Theiling, Simon Wegener, Michael Schmidt 0007 |
ECRTS | 2 |
| 2013 | Design and implementation of a degraded vision landing aid application on a multicore processor architecture for safety-critical applicationabstractThe progress of silicon integration has led to the ability to integrate complex systems on a single die. Integration of different application software components on a distributed system-on-chip can be demanding unless one follows a structural system integration approach with architectural support by hardware. The ACROSS Multi-Processor System-on-Chip platform provides architectural means for integration, such as well-defined communication interfaces, deterministic communication schedules, fault-containment, and error-confinement support. We present the non-functional requirements of a degraded vision landing system for a helicopter and show how the ACROSS Multi-Processor System-on-Chip research platform alleviates integration of software and system components. We also discuss more general multicore-specific software-related requirements and how the ACROSS MPSoC platform meets these. Hassen Karray, Michael Paulitsch, Bernd Koppenhoefer, Dietmar Geiger |
ISORC | 2 |
| 2013 | Transparent software replication and hardware monitoring leveraging modern System-on-Chip featuresabstractModern Commercial-Off-The-Shelf (COTS) System on-Chip (SoC) devices like multi-core computers have a variety of built-in features like Direct Memory Access (DMA) engines or sophisticated debug units. Using COTS devices in safety-critical environments like avionics requires replication, which can be based on diverse hardware to mitigate faults such as design errors or similar hardware to compensate for permanent and transient hardware faults e.g. due to single-event effects. This paper presents a novel approach of building fault-tolerant board architectures using chip-built-in features like debug units and implementing replication of application software components without the need of adaptation of application software. The advantages of the presented approach are the ability (1) to build fault-tolerant architectures relatively cheaply out of COTS components and (2) to separate the functional program from fault-tolerance-related code and, hence, also to include legacy code transparently. A demonstrator using two modern multicore processors connected by PCIe and debug units proves the feasibility of the described conceptual approach. Additional performance measurements quantify the benefit over commonly deployed software-based approaches. Michael Paulitsch, Jan Nowotsch, Daniel Münch, Ludwig Girbinger |
RTCSA | 1 |
| 2009 | TTEthernet Dataflow ConceptabstractTTEthernet is a novel communication infrastructures that allows using a single physical communication infrastructure for distributed applications with mixed-criticality requirements, e.g. the command and control systems and audio/video systems. This is achieved via a fault-tolerant self-stabilizing synchronization strategy, which establishes temporal partitioning and, hence, ensures isolation of the critical dataflows from the non-critical dataflows. The focus in this paper is on the dataflow in TTEthernet. For this we take the synchronization as a given and discuss from a TTEthernet user perspective which communication options TTEthernet provides and how they are aligned and realized. While this paper uses TTEthernet as reference communication infrastructure, the methods and strategies presented are valid for any message-based network. Wilfried Steiner, Günther Bauer 0001, Brendan Hall, Michael Paulitsch, Srivatsan Varadarajan |
NCA | 4 |
| 2008 | Non-functional Avionics Requirements
Michael Paulitsch, Harald Ruess, Maria Sorea |
ISoLA | 1 |
| 2008 | Starting and Resolving a Partitioned BRAINabstractTime-triggered communication is a favored design strategy for safety-critical systems. However, the startup of time-triggered systems is a significant concern, since the time-line from which fault-tolerance is supported must be established in segmented mediums, e.g. multi-hop networks. The startup problems are particularly challenging since clique formation, i.e. the establishment of disjoint time-triggered communication sets, may be systematically induced. This paper presents an alternative startup solution based upon a braided-ring architecture called BRAIN (braided ring availability integrity network). Segmentation-induced cliques are particularly prevalent in this architecture, since each node presents a potential medium break. The described strategy dramatically improves startup performance in relation to current approaches by leveraging the cooperative action of adjacent nodes during startup and high-integrity data propagation. Michael Paulitsch, Brendan Hall |
ISORC | 1 |
| 2007 | Insights into the Sensitivity of the BRAIN (Braided Ring Availability Integrity Network) - On Platform Robustness in Extended OperationabstractLow-cost fault-tolerant systems design presents a continual trade-off between improving fault-tolerant properties and accommodating cost constraints. With limited hardware options and to justify the system design rationale, it is necessary to formulate a fault hypothesis to bound failure assumptions. The system must be built on a foundation of real-world relevance and the assumption of coverage of the fault hypothesis. This paper discusses a study that examines the sensitivity of a BRAIN (braided ring availability integrity network) design to different fault types and failure rates in a safety-relevant application. It presents a Markov-based model (using ASSIST, SURE, and STEM analysis tools) and a series of experiments that were run to analyze the overall dependability of the BRAIN approach. The study evaluates the mission reliability and safety in the context of a hypothetical automotive integrated x-by-wire architecture on top of the BRAIN. Drawing from experience in the aerospace domain, the authors investigate the possibility of continued operation for a limited period after a detected critical electronic failure. Continued operation would allow a driver to reach repair facilities rather than stopping the vehicle to call for roadside assistance or "limping home." Michael Paulitsch, Brendan Hall |
DSN | 1 |
| 2006 | The TTA's Approach to Resilience after Transient Upsets
Wilfried Steiner, Michael Paulitsch, Hermann Kopetz |
Real Time Syst. | 2 |
| 2005 | Ringing out Fault Tolerance. A New Ring Network for Superior Low-Cost DependabilityabstractDependability properties of bi-directional and braided rings are well recognized in improving communication availability. However, current ring-based topologies have no mechanisms for extreme integrity and have not been considered for emerging high-dependability markets where cost is a significant driver, such as the automotive "by-wire" applications. This paper introduces a braided-ring architecture with superior guardian functionality and complete Byzantine fault tolerance while simultaneously reducing cost. This paper reviews anticipated requirements for high-dependability low-cost applications and emphasizes the need for regular safe testing of core coverage functions. The paper describes the ring's main mechanisms for achieving integrity and availability levels similar to SAFEbus/spl reg/ but at low automotive costs. The paper also presents a mechanism to achieve self-stabilizing TDMA-based communication and design methods for fault-tolerant protocols on a network of simplex nodes. The paper also introduces a new self-checking pair concept that leverages braided-ring properties. This novel message-based self-checking-pair concept allows high-integrity source data at extremely low cost. Brendan Hall, Kevin Driscoll 0001, Michael Paulitsch, Samar Dajani-Brown |
DSN | 3 |
| 2005 | Coverage and the Use of Cyclic Redundancy Codes in Ultra-Dependable SystemsabstractA cyclic redundancy code (CRC), when used properly, can be an effective and relatively inexpensive method to detect data corruption across communication channels. However, some systems use CRCs in ways that violate common assumptions made in analyzing CRC effectiveness, resulting in an overly optimistic prediction of system dependability. CRCs detect errors with some finite probability, which depends on factors including the strength of the particular code used, the bit-error rate, and the message length being checked. Common assumptions also include a passive network inter-stage, explicit data words, memoryless channels, and random independent symbol errors. In this paper we identify some examples of CRC usage that compromise ultra-dependable system design goals, and recommend alternate ways to improve system dependability via architectural approaches rather than error detection coding approaches. Michael Paulitsch, Jennifer Morris, Brendan Hall, Kevin Driscoll 0001, Elizabeth Latronico, Philip Koopman |
DSN | 1 |
| 2003 | Fault-Tolerant Clock Synchronization for Embedded Distributed Multi-Cluster SystemsabstractWhen time-triggered (TT) systems are to be deployed for large embedded real-time (RT) control systems in cars and airplanes, one way to overcome bandwidth limitations and achieve complexity reduction is the organization in clusters of strongly interacting computing nodes with well-defined interfaces. In this case, clock synchronization of different cluster times supports meaningful exchange of time-related data between clusters and allows coordinated control. This paper addresses fault-tolerant clock synchronization of clusters for TT systems that are already internally synchronized. By addressing systematic and stochastic errors of cluster times differently, the influence of systematic errors is eliminated and the quality of synchronization only depends on stochastic errors. Since systematic errors of cluster times are at least an order of magnitude larger than stochastic errors for typical RT embedded control systems, the presented algorithm achieves a significant improvement to known synchronization algorithms. An implementation of the proposed clock synchronization algorithm on top of the Time-Triggered Architecture and experiments show that synchronization is achieved with accuracy values of less than one microsecond. Michael Paulitsch, Wilfried Steiner |
ECRTS | 1 |
| 2002 | The Transition from Asynchronous to Synchronous System Operation: An Approach for Distributed Fault-Tolerant SystemsabstractImmediately after power-up, synchronous distributed systems need some time until essential timing properties, which are required to operate correctly, are established. We say that synchronous systems are initially in asynchronous operation. In this paper, we present an algorithm and architectural guidelines that assure the transition from asynchronous to synchronous operation within a bounded duration even in case of failures. Wilfried Steiner, Michael Paulitsch |
ICDCS | 2 |
| 2000 | An Investigation of Membership and Clique Avoidance in TTP/CabstractAvoiding the partitioning of a cluster into cliques that are not able to communicate with each other is an important issue in the time-triggered communication protocol TTP/C. This is achieved by a mechanism called clique avoidance. The clique avoidance algorithm always selects one partition (clique) to win and causes all nodes of other partitions to shut down. In this paper, we investigate the properties of this algorithm by analyzing its performance, elaborating the properties and showing how the clique avoidance algorithm interacts with the implicit acknowledgement algorithm of TTP/C. Günther Bauer 0001, Michael Paulitsch |
SRDS | 2 |