Score
Designs and produces system-level architectures that ensure safety by organizing components and interfaces, defining clear fault-containment and isolation boundaries, and specifying placement and separation of safety‑critical elements. Builds and analyzes mechanisms for run‑time monitoring and checks, redundancy, graceful degradation, and controlled recovery, and specifies how faults are detected, contained, and mitigated.
This work addresses the limitations of conventional system-on-chip (SoC) architectures that employ isolated, component-level single-event upset (SEU) mitigation techniques, which often neglect critical paths such as interconnects and voting logic, thereby creating single points of failure. To overcome this, the authors propose an overlapping cooperative fault-tolerance strategy that integrates tailored architectural-level protections for processor cores, memory, interconnects, and voting logic, achieving end-to-end, gap-free SEU resilience. Evaluated on a RISC-V microcontroller SoC through both fault-injection simulations and physical implementation, the approach demonstrates over 99.9% fault tolerance at both RTL and post-layout netlist levels. Compared to fine-grained triple modular redundancy and other global redundancy schemes, the proposed method reduces area overhead by 22%, significantly enhancing both reliability and resource efficiency.
Manual integration and verification of security registers in automotive SoCs suffer from high complexity, error-proneness, and low coverage—hindering area-optimized design and ISO 26262 compliance. Method: This paper proposes the first fully automated formal verification framework tailored for parameterized security register libraries. It integrates SystemVerilog Assertions (SVA)-based property checking, RTL-level constraint modeling, and script-driven configuration to enable comprehensive ISO 26262 requirement coverage and early bug detection. Contribution/Results: Compared to conventional manual workflows, the framework improves verification efficiency by over 80%, accelerates bug identification, and significantly reduces human effort and certification risk. Its modular, parameter-aware architecture ensures portability and scalability to other parameterized safety-critical IP components. By enabling automation, reusability, and rigorous compliance, the framework provides a foundational technical enabler for functional safety certification of high-reliability automotive chips.
Current research on the security of LLM-agent systems remains fragmented, lacking a unified framework to explain the common root causes and propagation mechanisms underlying failures such as prompt injection and tool misuse. This work establishes *isolation* as a first-class principle for system security and introduces a boundary-centric taxonomy comprising five boundary types: user–agent, agent–tool, agent–execution, agent–agent, and system–environment. By systematically modeling failure pathways and defense strategies through structured review and cross-domain analysis, the study reveals that security failures predominantly originate from insufficient isolation and follow distinct cross-boundary attack propagation patterns. The paper thus provides a cohesive theoretical foundation and a construction-oriented research agenda centered on isolation for designing highly secure agent systems.
Automotive electronic control units (ECUs) are intricate systems with hundreds of individual functions, numerous software components, and multiple interdependent tasks. A prevalent structural pattern in these systems are so-called cause-effect chains. While significant research efforts have been dedicated to the temporal analysis and optimization of these chains, particularly minimizing data age and function response times, other crucial non-functional properties remain relatively underexplored. In particular, the safety integrity level (SIL) classification substantially influences the system design by determining task colocation strategies. Improper sharing of functions or interweaving tasks with different safety levels can compromise the integrity of critical functions. Additionally, AUTOSAR basic software (BSW) (e.g. OS, runtime environment, communication stacks, or diagnostics) introduces complexity that varies based on task characteristics and SIL categories. Furthermore, memory requirements present another critical challenge, given the diversity of memory architectures and SIL-specific dependencies that strongly constrain task allocations. This paper thoroughly characterizes a real-world automotive application, describing an automotive application based on SIL constraints, the impact of basic software, and memory requirements. In this context, the Driverator configuration framework is introduced for scalable system analysis.
This work addresses the limitations of traditional simulation-based approaches in module-level fault analysis, which are often overly conservative and unable to accurately assess functional safety impacts. The authors propose SafeGen, a novel framework that integrates large language models (LLMs) with document-level hyperknowledge graphs (HyperKGs) to automatically extract verifiable specifications from design and safety documentation, generating semantically precise, design-aware functional safety assertions. By mapping gate-level faults to RTL and leveraging formal property verification (FPV), SafeGen enables semantic-level criticality classification for stuck-at and bridging faults, while supporting end-to-end traceable reasoning across specifications, assertions, and faults. Experimental evaluation on a field-oriented control (FOC) platform demonstrates that the generated assertions outperform those from existing LLM-based methods in quality and provide more semantically interpretable criticality assessments.
This study addresses the challenge of effectively monitoring early-stage agent systems, where structural flaws often obscure task-level errors. The authors propose a three-dimensional (quality, suitability, efficiency) and three-granularity (intra-run, inter-run, structural) monitoring and triaging framework tailored for low-maturity agent systems. They introduce a novel system maturity staging model based on the coefficient of variation and monitoring granularity, integrated with a severity classification adapted from FMEA to guide human review. The resulting transferable monitoring architecture supports document-driven, multi-stage workflows, enhanced by a synthetic testbed with controlled error injection. Experimental results demonstrate that structural defects significantly mask task-level signals; 97% of issues can be automatically traced, with only 2% requiring human intervention, and each granularity level precisely identifies its corresponding defect type (coefficients of variation: 0.02, 1.25, and 0.00, respectively).
This work addresses the challenge of detecting architectural drift—discrepancies between design-time architecture and runtime behavior—in long-lived embedded firmware. The authors propose a practical, hardware-assisted detection approach that captures runtime execution traces, abstracts them into inter-component message interaction sequences, and performs deterministic comparison against design-phase UML sequence diagrams to precisely identify confirmed, missing, extraneous, or inverted behavioral deviations. To facilitate expert review, the method further leverages a constrained large language model to generate human-readable explanatory reports. Integrating runtime trace analysis, deterministic architectural conformance checking, and constraint-guided LLM-based explanation generation for the first time, the approach demonstrates high agreement with expert annotations across 26 industrial cases, substantially reducing manual analysis effort while effectively supporting ISO 26262 safety documentation requirements.
This work addresses the challenge in safety-critical systems where complexity hinders development teams from fully comprehending system behavior and providing trustworthy explanations. To bridge this gap, the paper proposes Behavior-Driven Explainability (BDX), a method that directly translates structured scenarios from Behavior-Driven Development (BDD) into formal behavioral specifications and automatically generates user-oriented explainable outputs. BDX seamlessly integrates system specification with explanation generation, making it applicable across any development phase and abstraction level. The approach is validated through a case study on exception handling in a RISC-V processor, demonstrating that BDX effectively supports explainability requirements early in the design process, thereby significantly enhancing system transparency and trustworthiness.