Lecture Notes in Computer Science

Page created by Cathy Barnett
 
CONTINUE READING
Lecture Notes in Computer Science
Lecture Notes in Computer Science                          12853

Founding Editors
Gerhard Goos
   Karlsruhe Institute of Technology, Karlsruhe, Germany
Juris Hartmanis
   Cornell University, Ithaca, NY, USA

Editorial Board Members
Elisa Bertino
   Purdue University, West Lafayette, IN, USA
Wen Gao
   Peking University, Beijing, China
Bernhard Steffen
   TU Dortmund University, Dortmund, Germany
Gerhard Woeginger
   RWTH Aachen, Aachen, Germany
Moti Yung
   Columbia University, New York, NY, USA
Lecture Notes in Computer Science
More information about this subseries at http://www.springer.com/series/7408
Lecture Notes in Computer Science
Ibrahim Habli Mark Sujan
            •           •

Simos Gerasimou Erwin Schoitsch
                •                 •

Friedemann Bitsch (Eds.)

Computer Safety,
Reliability, and Security
SAFECOMP 2021 Workshops
DECSoS, MAPSOD, DepDevOps, USDAI, and WAISE
York, UK, September 7, 2021
Proceedings

123
Lecture Notes in Computer Science
Editors
Ibrahim Habli                                           Mark Sujan
University of York                                      Human Factors Everywhere Ltd.
York, UK                                                Woking, UK
Simos Gerasimou                                         Erwin Schoitsch
University of York                                      AIT Austrian Institute of Technology GmbH
York, UK                                                Vienna, Austria
Friedemann Bitsch
Thales Deutschland GmbH
Ditzingen, Germany

ISSN 0302-9743                      ISSN 1611-3349 (electronic)
Lecture Notes in Computer Science
ISBN 978-3-030-83905-5              ISBN 978-3-030-83906-2 (eBook)
https://doi.org/10.1007/978-3-030-83906-2
LNCS Sublibrary: SL2 – Programming and Software Engineering

© Springer Nature Switzerland AG 2021
This work is subject to copyright. All rights are reserved by the Publisher, whether the whole or part of the
material is concerned, specifically the rights of translation, reprinting, reuse of illustrations, recitation,
broadcasting, reproduction on microfilms or in any other physical way, and transmission or information
storage and retrieval, electronic adaptation, computer software, or by similar or dissimilar methodology now
known or hereafter developed.
The use of general descriptive names, registered names, trademarks, service marks, etc. in this publication
does not imply, even in the absence of a specific statement, that such names are exempt from the relevant
protective laws and regulations and therefore free for general use.
The publisher, the authors and the editors are safe to assume that the advice and information in this book are
believed to be true and accurate at the date of publication. Neither the publisher nor the authors or the editors
give a warranty, expressed or implied, with respect to the material contained herein or for any errors or
omissions that may have been made. The publisher remains neutral with regard to jurisdictional claims in
published maps and institutional affiliations.

This Springer imprint is published by the registered company Springer Nature Switzerland AG
The registered company address is: Gewerbestrasse 11, 6330 Cham, Switzerland
Lecture Notes in Computer Science
Preface

The SAFECOMP workshop day has for many years preceded the SAFECOMP con-
ference, attracting additional participants. The SAFECOMP workshops have become
more attractive since they started generating their own proceedings in the
Springer LNCS series (Springer LNCS vol. 12853, the book in your hands; the main
conference proceedings are published in LNCS vol. 12852). This meant adhering to
Springer’s guidelines, i.e., the respective international Program Committee of each
workshop had to make sure that at least three independent reviewers reviewed the
papers carefully. The selection criteria were different from those for the main confer-
ence since authors were encouraged to submit workshop papers, i.e., on work in
progress and potentially controversial topics. In total, 26 regular papers (out of 34)
were accepted. Additional to the accepted papers were a few invited talks in USDAI,
DepDevOps, and WAISE. All workshops included an introduction written by the
chairs. The workshops were organized as online (virtual) events because of uncer-
tainties around COVID-19 restrictions.
   Four of the five workshops are sequels to earlier workshops, one is new in topic and
organizing committee:
• DECSoS 2021 – 16th Workshop on Dependable Smart Embedded and
  Cyber-Physical Systems and Systems-of-Systems, chaired by Erwin Schoitsch and
  Amund Skavhaug, and supported by ERCIM, EWICS, and European Horizon
  2020/ECSEL JU projects.
• WAISE 2021 – Fourth International Workshop on Artificial Intelligence Safety
  Engineering, chaired by Orlando Avila-García, Mauricio Castillo-Effen, Chih-Hong
  Cheng, Zakaria Chihani, and Simos Gerasimou.
• DepDevOps 2021 - Second International Workshop on Dependable
  Development-Operation Continuum Methods for Dependable Cyber-Physical
  Systems, chaired by Miren Illarramendi, Haris Isakovic, Aitor Arrieta, and Irune
  Agirre.
• USDAI 2021 – Second International Workshop on Underpinnings for Safe
  Distributed AI, chaired by Morten Larsen. This workshop was organized around
  one invited keynote and an online panel.
• MAPSOD 2021 – First International Workshop on Multi-concern Assurance
  Practices in Software Design, chaired by Brahim Hamid, Jason Jaskolka, and Sahar
  Kokaly.
   The workshops provide a truly international platform for academia and industry.
   It has been a pleasure to work with the SAFECOMP chair, John McDermid, the
workshop co-chair, Simos Gerasimou, the publication chair, Friedemann Bitsch, the
program co-chairs, Ibrahim Habli and Mark Sujan, the workshop chairs, the Program
Committees, and the authors. Thank you all for your good cooperation and excellent
work!

September 2021                                                        Erwin Schoitsch
Lecture Notes in Computer Science
Organization

EWICS TC7 Chair
Francesca Saglietti   University of Erlangen-Nuremberg, Germany

General Chair
John McDermid         University of York, UK

Program Co-chairs
Ibrahim Habli         University of York, UK
Mark Sujan            Human Factors Everywhere, UK

General Workshop Co-chairs
Simos Gerasimou       University of York, UK
Erwin Schoitsch       AIT Austrian Institute of Technology, Austria

Publication Chair
Friedemann Bitsch     Thales Deutschland GmbH, Germany

Local Organizing Committee
Dawn Forrester        University of York, UK
Sarah Heathwood       University of York, UK
Alex King             University of York, UK

Industry Chair
Simon Burton          Fraunhofer IKS, Germany

Workshop Chairs
DECSoS 2021
Erwin Schoitsch       AIT Austrian Institute of Technology, Austria
Amund Skavhaug        Norwegian University of Science and Technology,
                        Norway
Lecture Notes in Computer Science
viii     Organization

DepDevOps 2021
Haris Isakovic            TU Wien, Austria
Miren Illarramendi        Mondragon University, Spain
Aitor Arrieta             Mondragon University, Spain
Irune Agirre              IKERLAN, Spain

MAPSOD 2021
Jason Jaskolka            Carleton University, Canada
Brahim Hamid              University of Toulouse II, France
Sahar Kokaly              General Motors, Canada

USDAI 2021
Morten Larsen             AnyWi Technologies, The Netherlands

WAISE 2021
Orlando Avila-García      Arquimea Reserch Center, Spain
Mauricio Castillo-Effen   Lockheed Martin, USA
Chih-Hong Cheng           DENSO, Germany
Zakaria Chihani           CEA LIST, France
Simos Gerasimou           University of York, UK
Lecture Notes in Computer Science
Organization   ix

Gold Sponsor

Intel

Supporting Institutions

European Workshop on
Industrial Computer Systems –
Reliability, Safety and Security

University of York

Assuring Autonomy International
Programme

Human Factors Everywhere Ltd

Austrian Institute of Technology

Thales Deutschland GmbH

Lecture Notes in Computer
Science (LNCS)
Lecture Notes in Computer Science
x       Organization

Chartered Institute of
Ergonomics & Human Factors

European Training Network for
Safer Autonomous Systems

Safety-Critical Systems Club

European Network of Clubs for
Reliability and Safety of
Software-Intensive Systems

German Computer Society

Informationstechnische
Gesellschaft
Lecture Notes in Computer Science
Organization   xi

Electronic Components
and Systems for European
Leadership - Austria

ARTEMIS Industry Association

Verband Österreichischer
Software Industrie

Austrian Computer Society

European Research Consortium for
Informatics and Mathematics
Contents

16th International ERCIM/EWICS/ARTEMIS Workshop on
Dependable Smart Embedded Cyber-Physical Systems
and Systems-of-Systems (DECSoS 2021)

Dependable Integration Concepts for Human-Centric AI-Based Systems . . . .                         11
  Georg Macher, Siranush Akarmazyan, Eric Armengaud, Davide Bacciu,
  Calogero Calandra, Herbert Danzinger, Patrizio Dazzi,
  Charalampos Davalas, Maria Carmela De Gennaro, Angela Dimitriou,
  Juergen Dobaj, Maid Dzambic, Lorenzo Giraudi, Sylvain Girbal,
  Dimitrios Michail, Roberta Peroglio, Rosaria Potenza,
  Farank Pourdanesh, Matthias Seidl, Christos Sardianos,
  Konstantinos Tserpes, Jakob Valtl, Iraklis Varlamis, and Omar Veledar

Rule-Based Threat Analysis and Mitigation for the Automotive Domain . . . .                        24
  Abdelkader Magdy Shaaban, Stefan Jaksic, Omar Veledar,
  Thomas Mauthner, Edin Arnautovic, and Christoph Schmittner

Guideline for Architectural Safety, Security and Privacy Implementations
Using Design Patterns: SECREDAS Approach . . . . . . . . . . . . . . . . . . . . . .               39
  Nadja Marko, Joaquim Maria Castella Triginer, Christoph Striecks,
  Tobias Braun, Reinhard Schwarz, Stefan Marksteiner,
  Alexandr Vasenev, Joerg Kemmerich, Hayk Hamazaryan, Lijun Shan,
  and Claire Loiseaux

Structured Traceability of Security and Privacy Principles for Designing
Safe Automated Systems . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .   52
   Behnam Asadi Khashooei, Alexandr Vasenev,
   and Hasan Alper Kocademir

Synchronisation of an Automotive Multi-concern Development Process . . . . .                       63
  Martin Skoglund, Fredrik Warg, Hans Hansson,
  and Sasikumar Punnekkat

Offline Access to a Vehicle via PKI-Based Authentication . . . . . . . . . . . . . .               76
  Jakub Arm, Petr Fiedler, and Ondrej Bastan

HEIFU - Hexa Exterior Intelligent Flying Unit . . . . . . . . . . . . . . . . . . . . . .          89
  Dário Pedro, Pedro Lousã, Álvaro Ramos, J. P. Matos-Carvalho,
  Fábio Azevedo, and Luís Campos
xiv         Contents

Testing for IT Security: A Guided Search Pattern for Exploitable
Vulnerability Classes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .   105
  Andreas Neubaum, Loui Al Sardy, Marc Spisländer, Francesca Saglietti,
  and Yves Biener

Formal Modelling of the Impact of Cyber Attacks on Railway Safety . . . . . .                           117
  Ehsan Poorhadi, Elena Troubitysna, and György Dán

LoRaWAN with HSM as a Security Improvement for Agriculture
Applications - Evaluation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .     128
  Reinhard Kloibhofer, Erwin Kristen, and Afshin Ameri E.

2nd International Workshop on Dependable Development-Operation
Continuum Methods for Dependable Cyber-Physical
System (DepDevOps 2021)

Towards Continuous Safety Assessment in Context of DevOps. . . . . . . . . . .                          145
  Marc Zeller

The Digital Twin as a Common Knowledge Base in DevOps to Support
Continuous System Evolution . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .         158
  Joost Mertens and Joachim Denil

1st International Workshop on Multi-concern Assurance Practices
in Software Design (MAPSOD 2021)

An Accountability Approach to Resolve Multi-stakeholder Conflicts . . . . . . .                         175
  Yukiko Yanagisawa and Yasuhiko Yokote

Towards Assurance-Driven Architectural Decomposition
of Software Systems . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .     187
   Ramy Shahin

2nd International Workshop on Underpinnings for Safe Distributed
Artificial Intelligence (USDAI 2021)

Integration of a RTT Prediction into a Multi-path
Communication Gateway . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .         201
   Josef Schmid, Patrick Purucker, Mathias Schneider, Rick vander Zwet,
   Morten Larsen, and Alfred Höß
Contents          xv

4th International Workshop on Artificial Intelligence Safety
Engineering (WAISE 2021)

Improving Robustness of Deep Neural Networks for Aerial Navigation
by Incorporating Input Uncertainty . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .              219
  Fabio Arnez, Huascar Espinoza, Ansgar Radermacher,
  and François Terrier

No Free Lunch: Overcoming Reward Gaming in AI Safety Gridworlds . . . . .                                   226
  Mariya Tsvarkaleva and Louise A. Dennis

Effect of Label Noise on Robustness of Deep Neural Network
Object Detectors . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .      239
   Bishwo Adhikari, Jukka Peltomäki, Saeed Bakhshi Germi, Esa Rahtu,
   and Heikki Huttunen

Human-in-the-Loop Learning Methods Toward Safe DL-Based
Autonomous Systems: A Review . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .                  251
  Prajit T. Rajendran, Huascar Espinoza, Agnes Delaborde,
  and Chokri Mraidha

An Integrated Approach to a Safety Argumentation for AI-Based
Perception Functions in Automated Driving . . . . . . . . . . . . . . . . . . . . . . . .                   265
  Michael Mock, Stephan Scholz, Frédérik Blank, Fabian Hüger,
  Andreas Rohatschek, Loren Schwarz, and Thomas Stauner

Experimental Conformance Evaluation onUBER ATG Safety Case
Framework withANSI/UL 4600 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .                  272
   Kenji Taguchi and Fuyuki Ishikawa

Learning from AV Safety: Hope and Humility Shape Policy and Progress . . .                                  284
  Marjory S. Blumenthal

Levels of Autonomy and Safety Assurance for AI-Based Clinical Decision
Systems . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .   291
  Paul Festor, Ibrahim Habli, Yan Jia, Anthony Gordon, A. Aldo Faisal,
  and Matthieu Komorowski

Certification Game for the Safety Analysis of AI-Based CPS . . . . . . . . . . . .                          297
  Imane Lamrani, Ayan Banerjee, and Sandeep K. S. Gupta

A New Approach to Better Consensus Building and Agreement
Implementation for Trustworthy AI Systems. . . . . . . . . . . . . . . . . . . . . . . .                    311
  Yukiko Yanagisawa and Yasuhiko Yokote

Author Index . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .        323
You can also read