TY - GEN
T1 - Cyber-Physical specification mismatch identification with dynamic analysis
AU - Johnson, Taylor T.
AU - Bak, Stanley
AU - Drager, Steven
PY - 2015/4/14
Y1 - 2015/4/14
N2 - Embedded systems use increasingly complex software and are evolving into cyber-physical systems (CPS) with sophisticated interaction and coupling between physical and computational processes. Many CPS operate in safety-critical environments and have stringent certification, reliability, and correctness requirements. These systems undergo changes throughout their lifetimes, where either the software or physical hardware is updated in subsequent design iterations. One source of failure in safety-critical CPS is when there are unstated assumptions in either the physical or cyber parts of the system, and new components do not match those assumptions. In this work, we present an automated method towards identifying unstated assumptions in CPS. Dynamic specifications in the form of candidate invariants of both the software and physical components are identified using dynamic analysis (executing and/or simulating the system implementation or model thereof). A prototype tool called Hynger (for HYbrid iNvariant GEneratoR) was developed that instruments Simulink/Stateflow (SLSF) model diagrams to generate traces in the input format compatible with the Daikon invariant inference tool, which has been extensively applied to software systems. Hynger, in conjunction with Daikon, is able to detect candidate invariants of several CPS case studies. We use the running example of a DC-to-DC power converter, and demonstrate that Hynger can detect a specification mismatch where a tolerance assumed by the software is violated due to a plant change.
AB - Embedded systems use increasingly complex software and are evolving into cyber-physical systems (CPS) with sophisticated interaction and coupling between physical and computational processes. Many CPS operate in safety-critical environments and have stringent certification, reliability, and correctness requirements. These systems undergo changes throughout their lifetimes, where either the software or physical hardware is updated in subsequent design iterations. One source of failure in safety-critical CPS is when there are unstated assumptions in either the physical or cyber parts of the system, and new components do not match those assumptions. In this work, we present an automated method towards identifying unstated assumptions in CPS. Dynamic specifications in the form of candidate invariants of both the software and physical components are identified using dynamic analysis (executing and/or simulating the system implementation or model thereof). A prototype tool called Hynger (for HYbrid iNvariant GEneratoR) was developed that instruments Simulink/Stateflow (SLSF) model diagrams to generate traces in the input format compatible with the Daikon invariant inference tool, which has been extensively applied to software systems. Hynger, in conjunction with Daikon, is able to detect candidate invariants of several CPS case studies. We use the running example of a DC-to-DC power converter, and demonstrate that Hynger can detect a specification mismatch where a tolerance assumed by the software is violated due to a plant change.
KW - Cyber-physical systems
KW - Dynamic analysis
KW - Specifications
UR - https://www.scopus.com/pages/publications/84954153877
U2 - 10.1145/2735960.2735979
DO - 10.1145/2735960.2735979
M3 - Conference contribution
AN - SCOPUS:84954153877
T3 - ACM/IEEE 6th International Conference on Cyber-Physical Systems, ICCPS 2015
SP - 208
EP - 217
BT - ACM/IEEE 6th International Conference on Cyber-Physical Systems, ICCPS 2015
PB - Association for Computing Machinery, Inc
T2 - 6th ACM/IEEE International Conference on Cyber-Physical Systems, ICCPS 2015
Y2 - 14 April 2015 through 16 April 2015
ER -