2026
A Multi-Agent Reinforcement Learning-Based Resilience Engineering Method for Mobility-as-a-Service
Zhengshu Zhou, Weijie Yu, Tingting Zhao, Qian Long, Yutaka Matsubara, Hiroaki Takada
IEEE Transactions on Network and Service Management
Associate Professor · Graduate School of Informatics, Nagoya University
Publications
This English page focuses on journal articles and international conference papers, while also listing technical documents and dissertation information.
Representative Work
2026
Zhengshu Zhou, Weijie Yu, Tingting Zhao, Qian Long, Yutaka Matsubara, Hiroaki Takada
IEEE Transactions on Network and Service Management
2025
Wenhung Kevin Huang, Yoshinori Terazawa, Yutaka Matsubara, Akihito Iwai
IEEE Embedded Systems Letters
2025
Yuxiao Wu, Yutaka Matsubara, Shoji Kasahara
Electronics
2025
Huanjun Zhang, Yutaka Matsubara
IEEE Access
2025
Misaki Kojima, Naoki Nishida, Yutaka Matsubara
Journal of Logical and Algebraic Methods in Programming
2024
Hiromasa Ito, Yutaka Matsubara, Hiroaki Takada
WSSE 2024
All publications
Contents
2020
Tsunagaru! Kiso Gijutsu IoT Nyumon (Chapter 2: Security)Harumi Watanabe, Makoto Imamura, Kenji Hisazumi (eds.)
Corona Publishing
An introductory textbook chapter on security for IoT systems, explaining basic threats and countermeasures for connected devices. It walks through how attackers can reach devices over the network and what basic defenses such as encryption and authentication do. The chapter is written for students taking their first steps into IoT.
Yutaka Matsubara authored Chapter 2.
2016
HAZOP-Based Security Analysis for Embedded Systems: Case Study of Open Source Immobilizer Protocol StackJingxuan Wei, Yutaka Matsubara, Hiroaki Takada
Recent Advances in Systems Safety and Security, Springer, pp.79-96
A book chapter that applies HAZOP, a systematic hazard analysis technique, to find security weaknesses in an open-source car immobilizer protocol stack. Guide words describing deviations from intended behavior are reinterpreted from a security viewpoint, turning a safety method into a way to find attack-relevant flaws. The chapter is an expanded version of the authors' earlier workshop study.
2024
Comprehensive Dependability for Automated Driving: Lessons from the PEGASUS Project and Level-4 Automated Driving ServicesYutaka Matsubara
Journal of Society of Automotive Engineers of Japan, Jan. 2024 Special Issue on Innovation Governance
A review article discussing how to assure the overall dependability of automated driving, drawing lessons from Germany's PEGASUS project and Level-4 driving services. It looks at both the technical side, such as scenario-based testing, and the societal side, such as rules and governance for operating services. Readers get a broad picture of what dependable automated driving actually requires.
2023
Automotive Control Systems as Distributed Real-Time SystemsHiroaki Takada, Yutaka Matsubara
Systems, Control and Information (ISCIE), Vol.67, No.12
A review article explaining automotive control systems from the viewpoint of distributed real-time systems, where many computers must cooperate under strict timing constraints. It describes how the many electronic control units connected by in-vehicle networks must exchange data and finish computations on time. The article helps readers see why real-time system theory matters for modern cars.
2020
CASE Revolution and Cybersecurity in the Automotive DomainYutaka Matsubara, Ryo Kurachi, Hiroaki Takada
IPSJ Magazine, Vol.61, No.4, pp.338-343
A review article on how the CASE trend (Connected, Autonomous, Shared, Electric) changes cybersecurity requirements for vehicles. As cars connect to networks and receive software updates remotely, attackers gain new entry points, so defenses must span the whole lifecycle from development to operation. The article summarizes these shifts for readers outside the automotive field.
2018
Trends and Prospects in Safety and Security for Connected Cars and SocietyYutaka Matsubara, Ryo Kurachi, Hiroaki Takada
Jidosha Gijutsu, Vol.72, No.5, pp.87-93
A review article surveying safety and security trends for connected cars and the surrounding connected society. It explains why safety, which protects people from failures, and security, which protects systems from attacks, must be considered together once vehicles are networked. Related standards and research directions are also introduced.
2017
Trends and Prospects in Automotive Safety and Security Toward Autonomous DrivingYutaka Matsubara, Ryo Kurachi, Hiroaki Takada
IPSJ Magazine, Vol.58, No.11
A review article surveying automotive safety and security technologies needed to realize autonomous driving. It explains how safety design against failures and defenses against cyber attacks influence each other, and why both are prerequisites for self-driving cars. The article suits readers who want an overview before studying individual technologies.
2017
Automotive Security and IoTYutaka Matsubara
Kinou Zairyo, Jun. 2017 serial article
A review article introducing the current state of automotive security in the context of the IoT era. It describes how connecting cars to networks and smartphones creates new attack paths, and outlines the countermeasures the industry is adopting. The article is written to be accessible to readers outside the software field.
2016
Security and Safety of In-Vehicle DevicesRyo Kurachi, Yutaka Matsubara, Hiroaki Takada
IPSJ Magazine, Vol.57, No.7
A review article explaining the relationship between security and functional safety for in-vehicle devices. It shows that a cyber attack can break the assumptions behind safety design, so security measures must be planned as part of functional safety. Basic attack examples and defense concepts are introduced for non-specialists.
2026
A Multi-Agent Reinforcement Learning Based Resilience Engineering Method for Mobility-as-a-ServiceZhengshu Zhou, Weijie Yu, Tingting Zhao, Qian Long, Yutaka Matsubara, Hiroaki Takada
IEEE Transactions on Network and Service Management, Vol.23, pp.2135-2148
This paper proposes a method that uses multi-agent reinforcement learning to improve the resilience of Mobility-as-a-Service, so that transport services can keep working when disruptions occur. Each agent learns through trial and error how to adjust operations, and together they restore service when parts of the network fail. This helps transport operators prepare for disruptions such as accidents or outages.
2025
Software-Defined Vehicles: Challenges and Orchestrating Mixed-Criticality Services Using Lingua FrancaWenhung Kevin Huang, Yoshinori Terazawa, Yutaka Matsubara, Akihito Iwai
IEEE Embedded Systems Letters
This paper discusses challenges of software-defined vehicles and shows how the Lingua Franca coordination language can orchestrate services with different criticality levels on one platform. Lingua Franca describes the timing relationships between components explicitly, which makes it easier to ensure that safety-critical services are not disturbed by less important ones. This matters as cars consolidate many functions onto a few powerful computers.
2025
Enhancing Account Information Anonymity in Blockchain-Based IoT Access Control Using Zero-Knowledge ProofsYuxiao Wu, Yutaka Matsubara, Shoji Kasahara
Electronics, Vol.14, Issue 14
This paper uses zero-knowledge proofs to hide account information in blockchain-based access control for IoT devices, improving user privacy. Users can prove they have the right to access a device without revealing which account they are, so records on the public blockchain leak less personal information. This addresses the tension between blockchain transparency and privacy.
2025
A COTS-based Lightweight, Low-power and Versatile Companion Computer for Nano UAVsRintaro Okudera, Yixiao Li, Yutaka Matsubara, Hiroaki Takada
Sensors & Transducers, Vol.268, No.1, pp.37-44
This paper presents a small companion computer built from commercial off-the-shelf parts for nano drones, balancing weight, power consumption, and versatility. Using off-the-shelf modules instead of custom hardware keeps the design inexpensive and easy to reproduce while fitting the strict weight and power budget of palm-sized drones. This is an extended journal version of the authors' conference work.
2025
ArchiMate-Based System of Systems Resilience Evaluation ApproachHuanjun Zhang, Yutaka Matsubara
Systems, Vol.13, Issue 5
This paper proposes a way to evaluate the resilience of a system of systems using ArchiMate, a standard enterprise architecture modeling language. Describing the member systems and their dependencies as a model makes it possible to estimate how failures propagate and how well services recover. This gives designers a common notation for discussing resilience.
2025
Consensus Based Resilience Assurance for System of SystemsHuanjun Zhang, Yutaka Matsubara
IEEE Access, Vol.13, pp.20203-20217
This paper proposes a consensus-based process in which the stakeholders of a system of systems agree on how much resilience is enough and how to assure it. Because no single organization controls an SoS, resilience targets must be negotiated rather than imposed, and the paper turns that negotiation into a structured process. This helps independently managed systems cooperate toward dependable services.
2025
Transforming Concurrent Programs with Semaphores into Logically Constrained Term Rewrite SystemsMisaki Kojima, Naoki Nishida, Yutaka Matsubara
Journal of Logical and Algebraic Methods in Programming, Vol.143, pp.1-23
This paper shows how to translate concurrent programs that use semaphores into logically constrained term rewrite systems, a formal model that enables mathematical verification. Once a program is expressed as a rewrite system, existing analysis techniques can rigorously reason about its concurrent behavior. This is the extended journal version of the authors' earlier workshop work.
2025
A Decision Support Scheme for Safe and Efficient Transportation of Hazardous MaterialsZhengshu Zhou, Yutaka Matsubara, Hiroaki Takada
IEEE Transactions on Intelligent Transportation Systems, Vol.26, Issue 1, pp.309-322
This paper proposes a decision support scheme that helps plan hazardous material transportation routes considering both safety and efficiency. Candidate routes and plans are compared from both risk and cost viewpoints, and the trade-offs are presented to decision makers. This supports realistic planning where safety and economics must be balanced.
2024
Multilingual Investigation of Cross-Project Code Clones in Open-Source Software for Internet of Things SystemsWenqing Zhu, Norihiro Yoshida, Yutaka Matsubara, Hiroaki Takada
IEEE Access, Vol.12, pp.179104-179118
This paper investigates code clones (copied code fragments) across open-source IoT projects in multiple programming languages, which matters for propagating bug fixes. When the same code exists in many projects, a bug fixed in one place may remain in others, so knowing where clones are helps maintainers propagate fixes. Covering clones across different languages, which are usually harder to track, is a key feature of the study.
2024
Detecting Concurrency Bugs with Feedback-guided FuzzingHiromasa Ito, Yutaka Matsubara, Hiroaki Takada
IPSJ Journal, Vol.65, No.5, pp.927-941
This paper presents a fuzzing technique guided by feedback about thread interleavings to find concurrency bugs, which are hard to reproduce with ordinary testing. The tool observes which thread execution orders have been explored and steers testing toward unexplored, suspicious ones. This is the extended journal version of the Schfuzz work presented at ENASE 2023.
Japanese only.
2023
A Performance Evaluation of Embedded Multi-core Mixed-criticality System Based on PREEMPT_RT LinuxYixiao Li, Yutaka Matsubara, Hiroaki Takada, Kenji Suzuki, Hideaki Murata
Journal of Information Processing, Vol.31, pp.78-87
This paper evaluates the real-time performance of PREEMPT_RT Linux when running tasks of different criticality levels together on an embedded multi-core processor. The evaluation examines how critical and non-critical tasks interfere with each other when they share cores. The results inform decisions about consolidating functions onto one computer.
2023
Resilience Analysis and Design for Mobility-as-a-Service Based on Enterprise Architecture ModelingZhengshu Zhou, Yutaka Matsubara, Hiroaki Takada
Reliability Engineering & System Safety, Vol.229
This paper proposes an enterprise-architecture-based method to analyze and design the resilience of Mobility-as-a-Service systems. The service is modeled as a whole, covering not only IT systems but also the organizations and business processes around them, so weak points can be found across the entire structure. This supports designing transport services that keep running through failures.
2023
Developing Reliable Digital Healthcare Service Using Semi-Quantitative Functional Resonance AnalysisZhengshu Zhou, Yutaka Matsubara, Hiroaki Takada
Computer Systems Science and Engineering, Vol.45, No.1, pp.35-50
This paper applies a semi-quantitative version of FRAM, a method for analyzing how everyday performance variability interacts, to improve the reliability of digital healthcare services. Assigning rough numeric scores to how much each activity varies helps identify where small everyday variations can combine into service failures. This is useful for services where people, devices, and software work closely together.
2022
Design and Implementation of RTOS-Aware Control-Flow Integrity Mechanism for Microcontroller-Based SystemsTomoaki Kawada, Shinya Honda, Yutaka Matsubara, Hiroaki Takada
Computer Software, Vol.39, No.2
This paper designs a control-flow integrity mechanism, a defense that stops attackers from hijacking program execution, tailored to RTOS-based microcontroller systems. The mechanism is designed to keep protecting the system even when the RTOS switches tasks and handles interrupts, situations that ordinary CFI designs do not consider. This strengthens small embedded devices that are hard to patch after deployment.
Japanese only.
2021
How to Test Middleware with Coverage-based Greybox FuzzingHiromasa Ito, Yutaka Matsubara, Hiroaki Takada
IPSJ Journal, Vol.62, pp.877-890
This paper shows how to apply coverage-based greybox fuzzing, an automated bug-finding technique, to middleware, which is harder to test than standalone programs. The approach prepares harnesses that drive the middleware and uses coverage feedback to steer generated inputs toward unexplored code. This brings a proven bug-finding technique to software it did not directly fit.
Japanese only.
2020
TZmCFI: RTOS-Aware Control-Flow Integrity Using TrustZone for Armv8-MTomoaki Kawada, Shinya Honda, Yutaka Matsubara, Hiroaki Takada
International Journal of Parallel Programming, Vol.49, pp.136-150
This paper presents TZmCFI, a control-flow integrity mechanism for small Arm microcontrollers that uses the TrustZone security feature and works correctly with an RTOS. TrustZone provides an isolated area that attackers cannot tamper with, and the mechanism keeps its protection consistent across task switches and interrupts. This defends small devices that lack the hardware protections of larger computers.
2020
esprof: A Generic Profiling Infrastructure for Multi/Many-Core Embedded SystemsYixiao Li, Yutaka Matsubara, Hiroaki Takada
Computer Software, Vol.37, No.1, pp.1_54-1_67
This paper presents esprof, a general-purpose profiling infrastructure for measuring and analyzing the behavior of multi- and many-core embedded software. It offers a common way to insert measurement points and collect events across different OSes and hardware, instead of building ad-hoc tools each time. The collected data helps developers track down performance bottlenecks.
Japanese only.
2019
Energy-Efficient Intra-Task DVFS Scheduling Using Linear Programming FormulationYang Qin, Gang Zeng, Ryo Kurachi, Yixiao Li, Yutaka Matsubara, Hiroaki Takada
IEEE Access, Vol.7, pp.30536-30547
This paper uses linear programming to decide when to change processor speed within a task (intra-task DVFS) so that energy is saved without missing deadlines. The task is divided into segments and an optimization determines the best speed for each, exploiting the fact that slower execution consumes less energy. Deadlines are treated as constraints, so real-time guarantees are preserved.
2019
Energy-Aware Task Allocation for Heterogeneous Multiprocessor Systems by Using Integer Linear ProgrammingYang Qin, Gang Zeng, Ryo Kurachi, Yutaka Matsubara, Hiroaki Takada
Journal of Information Processing, Vol.27, pp.136-148
This paper formulates energy-aware task allocation on heterogeneous multiprocessors as an integer linear programming problem to minimize energy while meeting deadlines. Formulating the problem mathematically lets a solver find allocations that exploit the different speed and power characteristics of each core. This matters for battery-powered devices that still have timing requirements.
2018
IDH-CAN: A Hardware-Based ID Hopping CAN Mechanism With Enhanced Security for Automotive Real-Time ApplicationsWufei Wu, Ryo Kurachi, Gang Zeng, Yutaka Matsubara, Hiroaki Takada, Renfa Li, Keqin Li
IEEE Access, Vol.6, pp.54607-54623
This paper proposes IDH-CAN, a hardware mechanism that periodically changes CAN message IDs to make attacks on in-vehicle networks harder while preserving real-time behavior. Because CAN messages are normally identified by fixed IDs, hopping them deprives attackers of an easy target. Implementing the hopping in hardware keeps message timing predictable, which is essential for control systems.
2018
Execution-variance-aware Task Allocation for Energy Minimization on the big.LITTLE ArchitectureYang Qin, Gang Zeng, Ryo Kurachi, Yutaka Matsubara, Hiroaki Takada
Sustainable Computing: Informatics and Systems, Vol.20, pp.81-93
This paper allocates tasks on the big.LITTLE architecture, which combines fast and power-efficient cores, considering variations in execution time to minimize energy. Real tasks often finish earlier than their worst-case estimates, and the method exploits this slack when deciding which core runs which task. This saves energy on the kind of processors widely used in smartphones and embedded devices.
2018
A Comparative Analysis of RTOS and Linux Scalability on an Embedded Many-core ProcessorYixiao Li, Yutaka Matsubara, Hiroaki Takada
Journal of Information Processing, Vol.26, pp.225-236
This paper compares how well an RTOS and Linux scale on an embedded many-core processor, providing data for choosing an OS for such platforms. The same measurements are run on both OSes while the number of cores increases, revealing where each design stops scaling. Such data helps developers pick the right OS for many-core embedded platforms.
2018
Safety Analysis Examples in Compliance with ISO 26262 for TOPPERS/ATK2 Conforming to the AUTOSAR OS SpecificationMorio Mori, Hideaki Sato, Akira Yamashita, Yutaka Matsubara, Hiroaki Takada
IPSJ Journal, Vol.59, No.2, pp.785-794
This paper reports safety analysis examples for the TOPPERS/ATK2 automotive OS, conducted to comply with the ISO 26262 functional safety standard. The examples show concretely how to apply safety analysis techniques to an RTOS, a component that many automotive products share. Published examples like these help practitioners facing the same certification work.
Japanese only.
2017
IXM: Rapid Inter-Process Communication Middleware for Robotics SoftwareMidori Sugaya, Yutaka Matsubara, Takuma Sumiya, Miyuki Nakano
IPSJ Journal, Vol.58, No.10, pp.1578-1590
This paper presents IXM, a fast inter-process communication middleware designed for robot control software. By reducing copying and overhead in message exchange, it keeps the delay between sensing and actuation small. This supports building robot systems that respond quickly to their surroundings.
Japanese only.
2017
EV3RT: A Real-time Software Platform for LEGO Mindstorms EV3Yixiao Li, Yutaka Matsubara, Hiroaki Takada
Computer Software, Vol.34, Issue 4, pp.4_91-4_115
This paper presents EV3RT, a real-time software platform that lets developers run RTOS-based applications on the LEGO Mindstorms EV3 robot kit. It brings the TOPPERS RTOS to the EV3 hardware together with device support and a development environment. The platform is widely used in embedded systems education and robot contests.
Japanese only.
2016
CaCAN: Centralized Authentication System in CANRyo Kurachi, Yutaka Matsubara, Hiroaki Takada, Hiroshi Ueda, Satoshi Horihata
IEICE Transactions, Vol.J99-A No.2, pp.118-130
This paper proposes CaCAN, a system in which a central monitor node authenticates messages on the CAN in-vehicle network and removes unauthorized ones. The monitor node checks message authentication codes and neutralizes unauthorized frames before they take effect. Requiring only one added node makes the scheme easy to introduce, and this is the extended journal version of the escar 2014 paper.
Japanese only.
2016
Energy-aware Task Migration for Multiprocessor Real-time SystemsGang Zeng, Yutaka Matsubara, Hiroyuki Tomiyama, Hiroaki Takada
Future Generation Computer Systems, Vol.56, pp.220-228
This paper proposes moving tasks between processors at run time to reduce energy consumption in multiprocessor real-time systems while meeting deadlines. Migration decisions weigh the cost of moving a task against the energy saved by balancing load across processors. This is the extended journal version of the authors' ICESS 2014 conference paper.
2015
Practical Educational Method of Embedded System with OJLNobuyuki Tachi, Masaki Yamamoto, Norihiro Yoshida, Hiroyuki Takashima, Tomoaki Unagami, Yuki Ando, Yutaka Matsubara, Shinya Honda, Hiroaki Takada
Computer Software, Vol.32, No.2, pp.79-85
This paper reports a practical education method for embedded systems based on OJL (On-the-Job Learning), where students learn through real development projects. Students tackle industry-related development tasks under mentoring, gaining skills that classroom exercises alone cannot teach. The paper shares the course design and the outcomes observed.
Japanese only.
2013
Safety Measures for Software Faults in Embedded SystemsYutaka Matsubara, Hiroaki Takada
Computer Software, Vol.30, No.1, pp.119-129
This paper organizes and discusses safety measures against software faults in embedded systems, such as detecting failures and keeping the system in a safe state. Since testing cannot remove every fault, systems should detect anomalies at run time and move to a safe state before harm occurs. The paper organizes concrete techniques usable in resource-limited embedded systems.
Japanese only.
2013
Safety Analysis Method Based on Hierarchical State Transition Diagram for Embedded SystemsZoohaye Kim, Yutaka Matsubara, Hiroaki Takada
IEICE Transactions, Vol.J96-A No.1, pp.34-48
This paper proposes a safety analysis method that uses hierarchical state transition diagrams to systematically find hazardous behaviors in embedded systems. Organizing states into a hierarchy keeps the analysis manageable even when the system has many states. This helps find dangerous behaviors at the design stage, before accidents can happen.
Japanese only.
2012
schesim: Scheduling Simulator for Real-Time ApplicationsYasumasa Sano, Yutaka Matsubara, Shinya Honda, Hiroaki Takada
IEICE Transactions D, Vol.J95-D No.12, pp.2008-2020
This paper presents schesim, a simulator that reproduces how a real-time scheduler runs application tasks, useful for checking timing behavior before deployment. Developers describe their tasks and scheduling policies, and the simulator shows whether deadlines are met under various conditions. This lets timing behavior be examined without preparing target hardware.
Japanese only.
2012
Safety Analysis Method Focusing on State Transition DiagramsZoohaye Kim, Yutaka Matsubara, Hiroaki Takada
IEICE Transactions, Vol.J95-A No.2, pp.198-209
This paper proposes a safety analysis method that examines state transition diagrams to find conditions under which an embedded system can reach hazardous states. Because state transition diagrams are already common in embedded design, engineers can reuse familiar models for safety analysis instead of building new ones. This helps prevent accidents by catching dangerous conditions at the design stage.
Japanese only.
2011
Practice of a Summer School on Embedded System Technologies by Students and Young EngineersIttetsu Taniguchi, Yuki Ando, Hideki Takase, Takuya Azumi, Yutaka Matsubara, Shintaro Hosoai, Yasuaki Murakami, Midori Sugaya
IPSJ Journal, Vol.52, No.12, pp.3221-3237
This paper reports the practice and outcomes of a summer school on embedded system technologies organized by students and young engineers. Participants design and build an embedded system in a short period, while the young organizers themselves grow by planning and running the school. The paper analyzes the educational effects observed through this practice.
Japanese only.
2011
Probabilistic Analysis of Response Time Considering Initial Phase Distribution of Periodic TasksTakuya Ishikawa, Yutaka Matsubara, Hiroaki Takada
IPSJ Journal, Vol.52, No.12, pp.3192-3204
This paper analyzes the response time of periodic tasks probabilistically, taking into account the distribution of their initial phases (start offsets). Worst-case analysis alone is often too pessimistic, and the probabilistic view estimates how likely each response time actually is. This supports real-time designs that use resources efficiently without giving up timing confidence.
Japanese only.
2011
Hierarchical Scheduling Algorithm with Task Start Delay for Time ProtectionYutaka Matsubara, Shinya Honda, Hiroaki Takada
IPSJ Journal, Vol.52, No.8, pp.2387-2401
This paper proposes a hierarchical scheduling algorithm with task start delay that provides time protection, preventing one application from stealing CPU time from others. Deliberately delaying certain task starts makes each application's CPU budget easier to guarantee within the hierarchical scheduler. This supports consolidating separately developed applications onto one computer without interference.
Japanese only.
2011
Interruptible Priority-Inheritance Spin Lock and Its Hardware ImplementationToshiyuki Ichiba, Yutaka Matsubara, Shinya Honda, Hiroaki Takada
IPSJ ACS, Vol.4, No.3, pp.133-146
This paper proposes a spin lock with priority inheritance that can be interrupted, and implements it in hardware to reduce blocking in multiprocessor real-time systems. Ordinary spin locks can delay interrupts and urgent tasks while waiting, and the proposed lock avoids this by allowing interruption and inheriting priority. A hardware implementation keeps the overhead of the mechanism low.
Japanese only.
2008
Flexible Scheduling Framework for Integrating Real-Time ApplicationsYutaka Matsubara, Shinya Honda, Hiroyuki Tomiyama, Hiroaki Takada
IPSJ Journal Embedded Systems Special Issue, Vol.49, No.10, pp.3508-3519
This paper presents a flexible scheduling framework that lets multiple real-time applications with different scheduling needs run together on one system. Each application keeps its own scheduling policy while the framework arbitrates CPU time among them. This eases integrating software components that were developed separately.
Japanese only.
2007
Real-Time Scheduling Algorithm for Time ProtectionYutaka Matsubara, Shinya Honda, Hiroyuki Tomiyama, Hiroaki Takada
IPSJ ACS, Vol.48 SIG8(ACS18), pp.192-202
This paper proposes a real-time scheduling algorithm that provides time protection, guaranteeing each application its share of CPU time even if another misbehaves. The scheduler enforces a CPU budget for each application, so a fault in one cannot starve the others. This idea underpins safely consolidating multiple functions onto one processor.
Japanese only.
2026
A System-of-Systems Resilience Analysis Framework Based on Stackelberg Evolution GameHuanjun Zhang, Yutaka Matsubara
21st International Conference on System of Systems Engineering (SoSE 2026), Kongsberg, Norway, Jun.-Jul. 2026
This paper proposes a framework that analyzes the resilience of a system of systems using a Stackelberg evolution game, a model of leader-follower strategic interaction. A leading constituent moves first and the others adapt, and analyzing this interaction shows how cooperation and self-interest shape recovery from disruptions. The framework helps designers anticipate how an SoS behaves under stress.
2026
Governance as a Structural Design Variable: An Empirical Study of Performance-Autonomy Value Spaces in Systems of SystemsChihiro Shimoyama, Yutaka Matsubara
21st International Conference on System of Systems Engineering (SoSE 2026), Kongsberg, Norway, Jun.-Jul. 2026
This paper empirically studies how governance choices in a system of systems shape the trade-off between overall performance and the autonomy of member systems. Stronger central control tends to raise overall performance but reduces each member's freedom, and the study maps this value space through experiments. The results help architects choose a governance style deliberately rather than by default.
2026
Outlier-Ratio Feature Augmentation for Graph-based Intrusion Detection in CAN NetworksAkari Sasaki, Ryo Kurachi, Yutaka Matsubara, Hiroaki Takada
IEEE Consumer Communications & Networking Conference (CCNC 2026), Las Vegas, Jan. 2026
This paper improves graph-based intrusion detection for the CAN in-vehicle network by adding outlier-ratio features that highlight abnormal message patterns. Messages are modeled as a graph, and the ratio of outlier messages is added as a feature to help separate attacks from normal traffic. Better detection matters because CAN itself has no built-in security.
2025
A Dynamic Resilience Research for Acknowledged System-of-systems Based on a Stackelberg Evolutionary GameHuanjun Zhang, Yutaka Matsubara
The 9th International Conference on System Reliability and Safety (ICSRS 2025), Italy, Nov 2025
This paper studies the dynamic resilience of an acknowledged system of systems using a Stackelberg evolutionary game model. The game captures how a coordinating leader and independent constituents adjust their strategies over time after disruptions. This dynamic view complements resilience assessments that only look at a single point in time.
2025
Improving Airport Baggage Handling System Efficiency with Simulation-Based DesignChenda Siv, Yutaka Matsubara, Hiroaki Takada
2nd IEOM World Congress on Industrial Engineering and Operations Management, Canada, Oct 2025
This paper uses simulation-based design to analyze and improve the efficiency of an airport baggage handling system. A simulation model of the conveying and sorting process reproduces congestion, letting designers compare layouts and operating policies. Improvement ideas can thus be tried without stopping the real large-scale facility.
2025
SSI-Enabled Authentication and Enhanced Metadata Search in Blockchain-based Decentralized IoT Data PlatformsLuyonghe Li, Yuichiro Yasue, Yutaka Matsubara
IEEE 1st International Workshop on Blockchain for Decentralized Trust and Digital Identity (B4TI) at BCCA 2025, Croatia, Oct 2025
This paper adds self-sovereign identity (SSI) based authentication and better metadata search to blockchain-based decentralized IoT data platforms. With SSI, users control their own identity credentials instead of depending on a central provider, which matches the decentralized nature of the platform. Improved metadata search also makes shared IoT data easier to find and use.
2025
PPDS: A Practical and Privacy-Preserving Data Sharing Model for Blockchain-Based IoT e-Health Systems Using ECC, Zero-Knowledge Proof, and Access ControlYuxiao Wu, Kenta Kawai, Yutaka Matsubara
IEEE International Conference on Blockchain Computing and Applications (BCCA 2025), Croatia, Oct 2025
This paper proposes PPDS, a data sharing model for blockchain-based IoT healthcare systems that protects privacy using elliptic curve cryptography, zero-knowledge proofs, and access control. Health data is sensitive, so the model lets patients share records with the right parties while keeping identities and contents protected. The cryptographic building blocks are combined with practicality on IoT devices in mind.
2025
Towards a Linux-based Unikernel for Resource-Constrained Embedded SystemsYoshifumi Shu, Yutaka Matsubara, Yixiao Li, Hiroaki Takada
The 19th annual workshop on Operating Systems Platforms for Embedded Real-Time applications (OSPERT 2025), Belgium, Jul 2025, pp.23-27
This paper explores building a Linux-based unikernel, a minimal single-purpose OS image, for embedded systems with limited memory and CPU resources. Bundling the application with only the OS features it needs reduces memory footprint while keeping compatibility with Linux software. This would let resource-constrained devices benefit from the large Linux ecosystem.
2025
GLACI: Arbitrary Code Instrumentation Tool for OpenGLShotaro Tsuboi, Yixiao Li, Yutaka Matsubara, Hiroaki Takada
The 20th International Conference on Networking and Services (ICONS 2025), France, Mar 2025
This paper presents GLACI, a tool that inserts arbitrary measurement or debugging code into OpenGL graphics API calls without modifying the application. It intercepts the calls between the application and the graphics driver, so measurement code can be added and removed freely. This helps analyze and debug graphics performance in embedded systems.
Best Paper Award.
2025
Flexible Edge Processing in Blockchain-based Secure IoT Data Distribution FrameworkKenta Kawai, Yuxiao Wu, Yutaka Matsubara, Hiroaki Takada
BRAIN 2025 at PerCom 2025, Washington D.C., Mar 2025
This paper adds flexible edge processing to a blockchain-based framework for secure IoT data distribution, so data can be processed near its source. Processing data near where it is generated reduces network traffic and avoids sending raw personal data to distant servers. The blockchain still guarantees trust in the exchanged results.
2025
A Lightweight, Low-power and Versatile Companion Computer for Nano UAVsRintaro Okudera, Yixiao Li, Yutaka Matsubara, Hiroaki Takada
The 7th International Symposium on Distributed Autonomous Unmanned Systems (DAUS 2025), Granada, Feb 2025, pp.292-295
This paper presents a lightweight, low-power companion computer for nano drones, enabling additional processing on very small aircraft. The design fits within the strict weight and power budget of palm-sized aircraft while remaining versatile. This work later formed the basis of the extended journal version.
2024
Monitor and Analyze Rare ROS2 Performance Issues with A Unified Tracing FrameworkYixiao Li, Yutaka Matsubara, Hiroaki Takada, Satoru Funahashi, Hiroki Kawashima
The 6th International Workshop on Software Science and Engineering (WSSE 2024), Kyoto, Aug 2024
This paper presents a unified tracing framework to monitor and analyze rare performance problems in ROS 2, a widely used robot software platform. The framework records events across the software stack in a unified way, so developers can trace back what happened when a rare slowdown occurs. This helps diagnose performance problems that are hard to reproduce.
2024
Race Directed Fuzzing for More Effective Concurrency TestingHiromasa Ito, Yutaka Matsubara, Hiroaki Takada
The 6th International Workshop on Software Science and Engineering (WSSE 2024), Kyoto, Aug 2024
This paper proposes race directed fuzzing, which steers automated testing toward suspicious thread interleavings to find concurrency bugs more effectively. Instead of exploring interleavings blindly, the method prioritizes ones where data races are likely, spending testing effort where bugs hide. Concurrency bugs are among the hardest to reproduce, which makes such targeting valuable.
2024
AI2X Co-evolution Guidebook and Case Study for Human-centered AI FrameworkAkihisa Morikawa, Yutaka Matsubara, Daichi Mizuguchi, Kiyoshi Fujiwara
SAFECOMP 2024 Position Paper, Florence, Sep 2024
This position paper introduces a guidebook and case study from the AI2X co-evolution project, which aims at human-centered frameworks where AI and society develop together. The guidebook distills how organizations can introduce AI while keeping humans central, and the case study shows the ideas applied in practice. It follows up the project introduction presented at SAFECOMP 2023.
2024
Reaching Consensus on System-of-systems Resilience Assurance: A Case of Mobility as a ServiceHuanjun Zhang, Yutaka Matsubara, Hiroaki Takada
SASSUR 2024 at SAFECOMP 2024, LNCS Vol.14989, pp.200-212, Florence, Sep 2024
This paper proposes a process for stakeholders to reach consensus on resilience assurance of a system of systems, using Mobility-as-a-Service as a case study. The process makes each stakeholder's assumptions and requirements explicit and reconciles them step by step into an agreed argument. It focuses on inter-organizational agreement, not just technology.
2023
A Quantitative Approach for System of Systems’ Resilience Analyzing Based on ArchiMateHuanjun Zhang, Yutaka Matsubara, Hiroaki Takada
DECSoS 2023 at SAFECOMP 2023, LNCS Vol.14489, pp.47-60, Toulouse, Sep 2023
This paper proposes a quantitative method for analyzing the resilience of a system of systems based on ArchiMate architecture models. Assigning quantitative measures to model elements lets designers compare where reinforcement improves resilience most. This supports spending limited resources where they matter.
2023
Toward Human-centered AI Framework: An Introduction to AI2X Co-evolution ProjectYutaka Matsubara, Akihisa Morikawa, Daichi Mizuguchi, Kiyoshi Fujiwara
SAFECOMP 2023 Position Paper, Toulouse, Sep 2023
This position paper introduces the AI2X co-evolution project, which explores frameworks for human-centered AI in society. It outlines why AI systems and the society using them must adapt to each other, and sets out the project's research agenda. The paper positions the challenges of deploying AI safely in society.
2023
Schfuzz: Detecting Concurrency Bugs with Feedback-Guided FuzzingHiromasa Ito, Yutaka Matsubara, Hiroaki Takada
18th International Conference on Evaluation of Novel Approaches to Software Engineering (ENASE 2023), Prague, pp.273-282, Apr 2023
This paper presents Schfuzz, a tool that finds concurrency bugs by fuzzing thread schedules with feedback guidance. Rather than fuzzing input data, Schfuzz fuzzes the order in which threads run, using feedback from past executions to guide exploration. This work formed the basis of the later journal version.
2021
Quantitative Security Assurance Case for In-vehicle Embedded SystemsZhengshu Zhou, Yutaka Matsubara, Hiroaki Takada
CyberSciTech/PICom/DASC/CDBCom 2021, pp.43-50, Oct 2021
This paper proposes building quantitative security assurance cases, structured arguments with numeric evidence, for in-vehicle embedded systems. Adding numeric evidence to the structured argument makes it easier to judge whether security measures are sufficient and to compare alternatives. This helps explain the validity of security decisions to third parties.
2020
Agile Software Design Verification and Validation (V&V) for Automated DrivingYixiao Li, Yutaka Matsubara, Daniel Olbrys, Kazuhiro Kajio, Hiroaki Takada
Proceedings of FISITA 2020, Oct 2020
This paper discusses an agile approach to verification and validation of automated driving software, enabling frequent checks during iterative development. Automating checks and integrating them into each development iteration keeps quality visible as the software evolves rapidly. This aims to reconcile development speed with safety assurance.
2020
Transforming Concurrent Programs with Semaphores into Logically Constrained Term Rewrite SystemsMisaki Kojima, Naoki Nishida, Yutaka Matsubara
Informal Proceedings of WPTE 2020, Jun 2020
This workshop paper presents a translation from concurrent programs using semaphores into logically constrained term rewrite systems for formal analysis. Expressing programs as rewrite systems opens the door to mathematically rigorous verification of concurrent behavior. This work later grew into the extended journal version.
2019
Shadow Exception Stacks: Control-Flow Integrity for Asynchronous Exceptions Using TrustZone for Armv8-MTomoaki Kawada, Shinya Honda, Yutaka Matsubara, Hiroaki Takada
IESS 2019, LNCS Vol.11937, pp.56-71, Friedrichshafen, Nov 2019
This paper proposes shadow exception stacks, which extend control-flow integrity protection to interrupt handling on Arm microcontrollers using TrustZone. Interrupts complicate control-flow protection because they can occur at any moment, and the shadow stacks record return paths safely inside TrustZone. This addresses a gap left by CFI schemes that ignore asynchronous exceptions.
2018
Energy-Aware Task Allocation for Large Task Sets on Heterogeneous Multiprocessor SystemsYang Qin, Gang Zeng, Ryo Kurachi, Yutaka Matsubara, Hiroaki Takada
EUC 2018, pp.158-165, Bucharest, Romania, Oct 2018
This paper proposes an energy-aware method to allocate large sets of tasks on heterogeneous multiprocessors, scaling beyond exact optimization approaches. A heuristic approach finds good allocations quickly where exact optimization would take far too long. This targets realistic embedded systems with large numbers of tasks.
2018
FRAM/STPA: Hazard Analysis Method for FRAM ModelYoshinari Toda, Yutaka Matsubara, Hiroaki Takada
FRAMily 2018, pp.1-17, Cardiff, Jun 2018
This paper proposes FRAM/STPA, a hazard analysis method that applies STPA-style control analysis to FRAM models of everyday performance variability. FRAM shows how variability spreads among functions, while STPA asks which control actions become unsafe, and combining them finds hazards that either method alone may miss. This suits complex systems where people and technology interact.
2017
IDHCC: A Security-Enhanced ID Hopping CAN Controller Design to Guarantee Real-TimeWufei Wu, Ryo Kurachi, Gang Zeng, Yutaka Matsubara, Hiroaki Takada, Renfa Li
CERTS 2017, pp.14-21, Jun 2017
This paper designs IDHCC, a CAN controller that hops message IDs for security while guaranteeing real-time message delivery. The controller changes IDs in a way both sender and receiver can follow, so protection is added without breaking communication. This design study preceded the extended IDH-CAN journal version.
2016
An Evaluation Framework of OS-level Power Managements for the big.LITTLE ArchitectureHideki Takase, Kazumi Aono, Yutaka Matsubara, Kazuyoshi Takagi, Naofumi Takagi
2016 14th IEEE International New Circuits and Systems Conference (NEWCAS 2016), Vancouver, Jun 2016
This paper presents a framework for evaluating OS-level power management schemes on the big.LITTLE architecture, which combines fast and efficient cores. The framework runs different power management policies under the same conditions so their energy and performance can be compared fairly. Such comparisons guide OS design for energy-sensitive devices.
2015
A Mobile Robot for Fall Detection for Elderly-CareTakuma Sumiya, Yutaka Matsubara, Miyuki Nakano, Midori Sugaya
KES 2015, Vol.60, pp.870-880, Singapore, Sep 2015
This paper presents a mobile robot system that detects falls of elderly people to support care services. A mobile robot can move to check on a person, complementing fixed sensors that cover only part of a home. Combining sensing and robot technology aims to reduce the burden of watching over elderly people.
Invited paper.
2015
HAZOP-based Security Analysis for Embedded Systems: Case Study of Open Source Immobilizer Protocol StackJingxuan Wei, Yutaka Matsubara, Hiroaki Takada
Proceedings of the 3rd International Workshop on Systems Safety & Security (IWSSS2015), Bucharest, Jun 2015
This paper applies HAZOP, a systematic deviation analysis technique, to security analysis of an open-source car immobilizer protocol stack. Guide words describing deviations from intended behavior are reinterpreted for security, turning a safety technique into a way to find attack-relevant weaknesses. This study was later expanded into a book chapter.
2014
CaCAN - Centralized Authentication System in CANRyo Kurachi, Yutaka Matsubara, Hiroaki Takada, Naoki Adachi, Yukihiro Miyashita, Satoshi Horihata
Proceedings of the escar 2014 Europe, pp. 1-9, Hamburg, Nov 2014
This paper presents CaCAN, a centralized message authentication system for the CAN in-vehicle network, at the automotive security conference escar. A monitor node authenticates messages on the bus and neutralizes unauthorized ones, requiring little change to existing vehicle networks. This work was later extended into the journal version.
2014
A Simulation Environment and Preliminary Evaluation for Automotive CAN-Ethernet AVB NetworksKeigo Kawahara, Yutaka Matsubara, Hiroaki Takada
Proceedings of the 1st OMNeT++ Community Summit, pp.xx-xx, Hamburg, Sep 2014
This paper builds a simulation environment for automotive networks combining CAN and Ethernet AVB, and reports a preliminary evaluation. The model reproduces how time-sensitive traffic flows across the two network types, so designs can be examined before building hardware. Ethernet AVB matters as vehicles need more bandwidth for cameras and sensors.
2014
Task Migration for Energy Saving in Real-Time Multiprocessor SystemsGang Zeng, Yutaka Matsubara, Hiroyuki Tomiyama, Hiroaki Takada
Proceedings of the 11th IEEE International Conference on Embedded Software and Systems (ICESS 2014), Paris, Aug 2014
This paper proposes migrating tasks between processors to save energy in real-time multiprocessor systems while keeping deadlines. Moving tasks at run time balances load, so processors can run at lower speeds and consume less energy while deadlines are still met. This work formed the basis of the later journal version.
2014
A Platform for LEGO Mindstorms EV3 Based on an RTOS with MMU SupportYixiao Li, Takuya Ishikawa, Yutaka Matsubara, Hiroaki Takada
OSPERT 2014, pp.51-59, Madrid, Jul 2014
This paper presents a software platform for the LEGO Mindstorms EV3 robot kit based on an RTOS with memory protection (MMU) support. Memory protection via the MMU keeps a faulty program from corrupting the rest of the system, which is unusual for hobby-class robot kits. This platform later evolved into EV3RT.
2013
A Simulation Environment Based on OMNeT++ for Automotive CAN-Ethernet NetworksJun Matsumura, Yutaka Matsubara, Hiroaki Takada, Masaya Oi, Masumi Toyoshima, Akihito Iwai
WATERS 2013, pp.1-6, Paris, Jul 2013
This paper presents a simulation environment based on the OMNeT++ network simulator for automotive networks that combine CAN and Ethernet. Mixed CAN-Ethernet designs were emerging in vehicles, and the environment lets engineers evaluate such network designs on a computer. Communication design can thus be examined without a real car.
2012
Safety Analysis Method Based on Parallel State Transition Diagram for Embedded SystemsZoohaye Kim, Yutaka Matsubara, Hiroaki Takada
SEA 2012, pp.417-425, Las Vegas, Nov 2012
This paper proposes a safety analysis method for embedded systems based on parallel state transition diagrams, handling components that operate concurrently. Unexpected combinations of concurrently operating components are a common source of hazards, and the parallel diagrams make such combinations explicit for analysis. This helps find dangerous behaviors systematically at the design stage.
2012
An Open-Source Flexible Scheduling Simulator for Real-time ApplicationsYutaka Matsubara, Yasumasa Sano, Shinya Honda, Hiroaki Takada
ISORC 2012, pp.16-22, Shenzhen, Jun 2012
This paper presents an open-source simulator that flexibly models schedulers and real-time applications to evaluate timing behavior. Being open source, the simulator can be extended with new scheduling algorithms and reused freely in research and education. It helps developers check timing behavior without target hardware.
2009
Hierarchical Scheduling for Integrating Real-time Applications with Interrupt RoutinesYutaka Matsubara, Shinya Honda, Hiroaki Takada
ISOCC 2009, pp.384-387, Busan, Nov 2009
This paper proposes hierarchical scheduling that integrates multiple real-time applications while properly accounting for interrupt routines. Interrupt handling consumes CPU time at unpredictable moments, so the scheduler treats its influence explicitly when guaranteeing each application's share. This supports consolidating software onto fewer processors.
Invited paper.
2009
History of Summer School on Embedded System Technologies Organized by Students and Young EngineersHideki Takase, Takuya Azumi, Ittetsu Taniguchi, Yutaka Matsubara, Hayato Kanai, Shintaro Hosoai, Midori Sugaya
WESE 2009, pp.19-26, Grenoble, Oct 2009
This paper reports the history and lessons of a summer school on embedded system technologies organized by students and young engineers in Japan. It looks back on how the peer-run format developed and what kept participants engaged. The lessons are useful for others planning hands-on engineering education.
2007
SSEST: Summer School on Embedded System TechnologiesYutaka Matsubara, Midori Sugaya, Ittetsu Taniguchi, Yasuaki Murakami, Hayato Kanai, Hiroaki Takada
APESER 2007, pp.1-8, Hsinchu, Dec 2007
This paper introduces SSEST, a summer school on embedded system technologies run by students and young engineers, and its educational approach. Participants team up to develop an embedded system in a short period, experiencing the process from design to demonstration. The paper shares the curriculum and how the school is run, so similar programs can be built elsewhere.
2025
Co-evolution Guidebook (HMCES Guidebook)Daichi Mizuguchi, Akihisa Morikawa, Yutaka Matsubara, Kiyoshi Fujiwara
HMCES Project
2025
Kyoshinka GuidebookDaichi Mizuguchi, Akihisa Morikawa, Yutaka Matsubara, Kiyoshi Fujiwara
HMCES Project
2025
Enhancing Human-Robot Collaboration through Existing Guidelines: A Case Study ApproachYutaka Matsubara, Akihisa Morikawa, Daichi Mizuguchi, Kiyoshi Fujiwara
HMCES Project
2020
Safety Design Concepts for Statistical Machine Learning Components toward Accordance with Functional Safety StandardsAkihisa Morikawa, Yutaka Matsubara
SEAMS Project
2020
Towards Identifying and Closing Gaps in Assurance of Autonomous Road Vehicles: Technical Notes Part 2Robin Bloomfield, Gareth Fletcher, Heidy Khlaaf, Philippa Ryan, Shuji Kinoshita, Yoshiki Kinoshita, Makoto Takeyama, Yutaka Matsubara, Peter Popov, Kazuki Imai, Yoshinori Tsutake
TIGARS Project
2020
Towards Identifying and Closing Gaps in Assurance of Autonomous Road Vehicles: Technical Notes Part 1Robin Bloomfield, Gareth Fletcher, Heidy Khlaaf, Philippa Ryan, Shuji Kinoshita, Yoshiki Kinoshita, Makoto Takeyama, Yutaka Matsubara, Peter Popov, Kazuki Imai, Yoshinori Tsutake
TIGARS Project
2011
Hierarchical Scheduling for Integrating Embedded Real-Time ApplicationsYutaka Matsubara
Doctoral Dissertation
Recommended by IPSJ SIGEMB.
2011
Recommended Doctoral Thesis DigestYutaka Matsubara
IPSJ SIGEMB recommended thesis announcement
2025
Best Paper Award for GLACI: Arbitrary Code Instrumentation Tool for OpenGLShotaro Tsuboi, Yixiao Li, Yutaka Matsubara, Hiroaki Takada
The 20th International Conference on Systems (ICONS 2025)
2025
Best Young Presentation Award for Real-Time Evaluation of a Full-Scratch Linux-Compatible UnikernelYoshifumi Shu, Yutaka Matsubara, Ryoma Hiraoka, Ryosuke Yamamoto, Hitoshi Yamamoto, Shingo Oidate, Hiroaki Takada
166th IPSJ OS Workshop
2024
TOPPERS of the Year 2024 Activity Division: Support for ET RoboconYoshifumi Shu, Yixiao Li, Yutaka Matsubara
TOPPERS Project
2022
Excellent Paper Award for Software Update Framework for IoT Devices Using BlockchainRyota Nakanishi, Yutaka Matsubara, Hiroaki Takada
DICOMO 2022
2022
Zengo Award for Coverage-based Greybox Fuzzing Applied to MiddlewareHiromasa Ito, Yutaka Matsubara, Hiroaki Takada
ASTER
2021
Best Presentation Award for Resilience Engineering Method for Improving Reliability of MaaSZhengshu Zhou, Yutaka Matsubara, Hiroaki Takada
DSW 2021
2021
Best Poster Bronze Award for Visual Design Tool for AUTOSAR Vehicle-Level SpecificationsMitsutaka Takada, Ryosuke Takahashi, Yutaka Matsubara
SWEST 23
2020
Selected Paper Award for Coverage-based Greybox Fuzzing Applied to MiddlewareHiromasa Ito, Yutaka Matsubara, Hiroaki Takada
IPSJ Journal, Vol.62, No.3
Japanese only.
2019
Software Paper Award for EV3RT: A Real-time Software Platform for LEGO Mindstorms EV3Yixiao Li, Yutaka Matsubara, Hiroaki Takada
JSSST
2015
Student Encouragement Award for Evaluation Environment of Power Management on Heterogeneous Multicore SystemsKazumi Aono, Hideki Takase, Yutaka Matsubara, Kazuyoshi Takagi, Naofumi Takagi
ESS 2015
2014
Best Poster Student Presentation Award for OMNeT++ Simulation Environment for Mixed CAN-Ethernet AVB NetworksKeigo Kawahara, Yutaka Matsubara, Hiroaki Takada
SWEST 16
2011
Excellent Paper Award for Scheduling Simulator with User-Defined Task ProcessingYasumasa Sano, Yutaka Matsubara, Shinya Honda, Hiroaki Takada
IPSJ Embedded System Symposium 2011
2007
Computer Science Area Encouragement AwardYutaka Matsubara
IPSJ 2007
2008
TOPPERS of the Year 2008 for Automotive RTOS with Memory and Time ProtectionHiroyuki Hattori, Shuichi Onishi, Ayumu Kataoka, Yutaka Matsubara, Hiroaki Takada
TOPPERS Project
2008
IP Excellence Award for Open-Source Protected OS: Automotive RTOS with Memory and Time ProtectionHiroyuki Hattori, Shuichi Onishi, Ayumu Kataoka, Yutaka Matsubara, Hiroaki Takada
10th LSI IP Design Award
Newest first
All entries on this page, sorted by publication year, newest first.
2026
A Multi-Agent Reinforcement Learning Based Resilience Engineering Method for Mobility-as-a-ServiceZhengshu Zhou, Weijie Yu, Tingting Zhao, Qian Long, Yutaka Matsubara, Hiroaki Takada
IEEE Transactions on Network and Service Management, Vol.23, pp.2135-2148
This paper proposes a method that uses multi-agent reinforcement learning to improve the resilience of Mobility-as-a-Service, so that transport services can keep working when disruptions occur. Each agent learns through trial and error how to adjust operations, and together they restore service when parts of the network fail. This helps transport operators prepare for disruptions such as accidents or outages.
2026
A System-of-Systems Resilience Analysis Framework Based on Stackelberg Evolution GameHuanjun Zhang, Yutaka Matsubara
21st International Conference on System of Systems Engineering (SoSE 2026), Kongsberg, Norway, Jun.-Jul. 2026
This paper proposes a framework that analyzes the resilience of a system of systems using a Stackelberg evolution game, a model of leader-follower strategic interaction. A leading constituent moves first and the others adapt, and analyzing this interaction shows how cooperation and self-interest shape recovery from disruptions. The framework helps designers anticipate how an SoS behaves under stress.
2026
Governance as a Structural Design Variable: An Empirical Study of Performance-Autonomy Value Spaces in Systems of SystemsChihiro Shimoyama, Yutaka Matsubara
21st International Conference on System of Systems Engineering (SoSE 2026), Kongsberg, Norway, Jun.-Jul. 2026
This paper empirically studies how governance choices in a system of systems shape the trade-off between overall performance and the autonomy of member systems. Stronger central control tends to raise overall performance but reduces each member's freedom, and the study maps this value space through experiments. The results help architects choose a governance style deliberately rather than by default.
2026
Outlier-Ratio Feature Augmentation for Graph-based Intrusion Detection in CAN NetworksAkari Sasaki, Ryo Kurachi, Yutaka Matsubara, Hiroaki Takada
IEEE Consumer Communications & Networking Conference (CCNC 2026), Las Vegas, Jan. 2026
This paper improves graph-based intrusion detection for the CAN in-vehicle network by adding outlier-ratio features that highlight abnormal message patterns. Messages are modeled as a graph, and the ratio of outlier messages is added as a feature to help separate attacks from normal traffic. Better detection matters because CAN itself has no built-in security.
2025
Software-Defined Vehicles: Challenges and Orchestrating Mixed-Criticality Services Using Lingua FrancaWenhung Kevin Huang, Yoshinori Terazawa, Yutaka Matsubara, Akihito Iwai
IEEE Embedded Systems Letters
This paper discusses challenges of software-defined vehicles and shows how the Lingua Franca coordination language can orchestrate services with different criticality levels on one platform. Lingua Franca describes the timing relationships between components explicitly, which makes it easier to ensure that safety-critical services are not disturbed by less important ones. This matters as cars consolidate many functions onto a few powerful computers.
2025
Enhancing Account Information Anonymity in Blockchain-Based IoT Access Control Using Zero-Knowledge ProofsYuxiao Wu, Yutaka Matsubara, Shoji Kasahara
Electronics, Vol.14, Issue 14
This paper uses zero-knowledge proofs to hide account information in blockchain-based access control for IoT devices, improving user privacy. Users can prove they have the right to access a device without revealing which account they are, so records on the public blockchain leak less personal information. This addresses the tension between blockchain transparency and privacy.
2025
A COTS-based Lightweight, Low-power and Versatile Companion Computer for Nano UAVsRintaro Okudera, Yixiao Li, Yutaka Matsubara, Hiroaki Takada
Sensors & Transducers, Vol.268, No.1, pp.37-44
This paper presents a small companion computer built from commercial off-the-shelf parts for nano drones, balancing weight, power consumption, and versatility. Using off-the-shelf modules instead of custom hardware keeps the design inexpensive and easy to reproduce while fitting the strict weight and power budget of palm-sized drones. This is an extended journal version of the authors' conference work.
2025
ArchiMate-Based System of Systems Resilience Evaluation ApproachHuanjun Zhang, Yutaka Matsubara
Systems, Vol.13, Issue 5
This paper proposes a way to evaluate the resilience of a system of systems using ArchiMate, a standard enterprise architecture modeling language. Describing the member systems and their dependencies as a model makes it possible to estimate how failures propagate and how well services recover. This gives designers a common notation for discussing resilience.
2025
Consensus Based Resilience Assurance for System of SystemsHuanjun Zhang, Yutaka Matsubara
IEEE Access, Vol.13, pp.20203-20217
This paper proposes a consensus-based process in which the stakeholders of a system of systems agree on how much resilience is enough and how to assure it. Because no single organization controls an SoS, resilience targets must be negotiated rather than imposed, and the paper turns that negotiation into a structured process. This helps independently managed systems cooperate toward dependable services.
2025
Transforming Concurrent Programs with Semaphores into Logically Constrained Term Rewrite SystemsMisaki Kojima, Naoki Nishida, Yutaka Matsubara
Journal of Logical and Algebraic Methods in Programming, Vol.143, pp.1-23
This paper shows how to translate concurrent programs that use semaphores into logically constrained term rewrite systems, a formal model that enables mathematical verification. Once a program is expressed as a rewrite system, existing analysis techniques can rigorously reason about its concurrent behavior. This is the extended journal version of the authors' earlier workshop work.
2025
A Decision Support Scheme for Safe and Efficient Transportation of Hazardous MaterialsZhengshu Zhou, Yutaka Matsubara, Hiroaki Takada
IEEE Transactions on Intelligent Transportation Systems, Vol.26, Issue 1, pp.309-322
This paper proposes a decision support scheme that helps plan hazardous material transportation routes considering both safety and efficiency. Candidate routes and plans are compared from both risk and cost viewpoints, and the trade-offs are presented to decision makers. This supports realistic planning where safety and economics must be balanced.
2025
A Dynamic Resilience Research for Acknowledged System-of-systems Based on a Stackelberg Evolutionary GameHuanjun Zhang, Yutaka Matsubara
The 9th International Conference on System Reliability and Safety (ICSRS 2025), Italy, Nov 2025
This paper studies the dynamic resilience of an acknowledged system of systems using a Stackelberg evolutionary game model. The game captures how a coordinating leader and independent constituents adjust their strategies over time after disruptions. This dynamic view complements resilience assessments that only look at a single point in time.
2025
Improving Airport Baggage Handling System Efficiency with Simulation-Based DesignChenda Siv, Yutaka Matsubara, Hiroaki Takada
2nd IEOM World Congress on Industrial Engineering and Operations Management, Canada, Oct 2025
This paper uses simulation-based design to analyze and improve the efficiency of an airport baggage handling system. A simulation model of the conveying and sorting process reproduces congestion, letting designers compare layouts and operating policies. Improvement ideas can thus be tried without stopping the real large-scale facility.
2025
SSI-Enabled Authentication and Enhanced Metadata Search in Blockchain-based Decentralized IoT Data PlatformsLuyonghe Li, Yuichiro Yasue, Yutaka Matsubara
IEEE 1st International Workshop on Blockchain for Decentralized Trust and Digital Identity (B4TI) at BCCA 2025, Croatia, Oct 2025
This paper adds self-sovereign identity (SSI) based authentication and better metadata search to blockchain-based decentralized IoT data platforms. With SSI, users control their own identity credentials instead of depending on a central provider, which matches the decentralized nature of the platform. Improved metadata search also makes shared IoT data easier to find and use.
2025
PPDS: A Practical and Privacy-Preserving Data Sharing Model for Blockchain-Based IoT e-Health Systems Using ECC, Zero-Knowledge Proof, and Access ControlYuxiao Wu, Kenta Kawai, Yutaka Matsubara
IEEE International Conference on Blockchain Computing and Applications (BCCA 2025), Croatia, Oct 2025
This paper proposes PPDS, a data sharing model for blockchain-based IoT healthcare systems that protects privacy using elliptic curve cryptography, zero-knowledge proofs, and access control. Health data is sensitive, so the model lets patients share records with the right parties while keeping identities and contents protected. The cryptographic building blocks are combined with practicality on IoT devices in mind.
2025
Towards a Linux-based Unikernel for Resource-Constrained Embedded SystemsYoshifumi Shu, Yutaka Matsubara, Yixiao Li, Hiroaki Takada
The 19th annual workshop on Operating Systems Platforms for Embedded Real-Time applications (OSPERT 2025), Belgium, Jul 2025, pp.23-27
This paper explores building a Linux-based unikernel, a minimal single-purpose OS image, for embedded systems with limited memory and CPU resources. Bundling the application with only the OS features it needs reduces memory footprint while keeping compatibility with Linux software. This would let resource-constrained devices benefit from the large Linux ecosystem.
2025
GLACI: Arbitrary Code Instrumentation Tool for OpenGLShotaro Tsuboi, Yixiao Li, Yutaka Matsubara, Hiroaki Takada
The 20th International Conference on Networking and Services (ICONS 2025), France, Mar 2025
This paper presents GLACI, a tool that inserts arbitrary measurement or debugging code into OpenGL graphics API calls without modifying the application. It intercepts the calls between the application and the graphics driver, so measurement code can be added and removed freely. This helps analyze and debug graphics performance in embedded systems.
Best Paper Award.
2025
Flexible Edge Processing in Blockchain-based Secure IoT Data Distribution FrameworkKenta Kawai, Yuxiao Wu, Yutaka Matsubara, Hiroaki Takada
BRAIN 2025 at PerCom 2025, Washington D.C., Mar 2025
This paper adds flexible edge processing to a blockchain-based framework for secure IoT data distribution, so data can be processed near its source. Processing data near where it is generated reduces network traffic and avoids sending raw personal data to distant servers. The blockchain still guarantees trust in the exchanged results.
2025
A Lightweight, Low-power and Versatile Companion Computer for Nano UAVsRintaro Okudera, Yixiao Li, Yutaka Matsubara, Hiroaki Takada
The 7th International Symposium on Distributed Autonomous Unmanned Systems (DAUS 2025), Granada, Feb 2025, pp.292-295
This paper presents a lightweight, low-power companion computer for nano drones, enabling additional processing on very small aircraft. The design fits within the strict weight and power budget of palm-sized aircraft while remaining versatile. This work later formed the basis of the extended journal version.
2025
Co-evolution Guidebook (HMCES Guidebook)Daichi Mizuguchi, Akihisa Morikawa, Yutaka Matsubara, Kiyoshi Fujiwara
HMCES Project
2025
Kyoshinka GuidebookDaichi Mizuguchi, Akihisa Morikawa, Yutaka Matsubara, Kiyoshi Fujiwara
HMCES Project
2025
Enhancing Human-Robot Collaboration through Existing Guidelines: A Case Study ApproachYutaka Matsubara, Akihisa Morikawa, Daichi Mizuguchi, Kiyoshi Fujiwara
HMCES Project
2025
Best Paper Award for GLACI: Arbitrary Code Instrumentation Tool for OpenGLShotaro Tsuboi, Yixiao Li, Yutaka Matsubara, Hiroaki Takada
The 20th International Conference on Systems (ICONS 2025)
2025
Best Young Presentation Award for Real-Time Evaluation of a Full-Scratch Linux-Compatible UnikernelYoshifumi Shu, Yutaka Matsubara, Ryoma Hiraoka, Ryosuke Yamamoto, Hitoshi Yamamoto, Shingo Oidate, Hiroaki Takada
166th IPSJ OS Workshop
2024
Comprehensive Dependability for Automated Driving: Lessons from the PEGASUS Project and Level-4 Automated Driving ServicesYutaka Matsubara
Journal of Society of Automotive Engineers of Japan, Jan. 2024 Special Issue on Innovation Governance
A review article discussing how to assure the overall dependability of automated driving, drawing lessons from Germany's PEGASUS project and Level-4 driving services. It looks at both the technical side, such as scenario-based testing, and the societal side, such as rules and governance for operating services. Readers get a broad picture of what dependable automated driving actually requires.
2024
Multilingual Investigation of Cross-Project Code Clones in Open-Source Software for Internet of Things SystemsWenqing Zhu, Norihiro Yoshida, Yutaka Matsubara, Hiroaki Takada
IEEE Access, Vol.12, pp.179104-179118
This paper investigates code clones (copied code fragments) across open-source IoT projects in multiple programming languages, which matters for propagating bug fixes. When the same code exists in many projects, a bug fixed in one place may remain in others, so knowing where clones are helps maintainers propagate fixes. Covering clones across different languages, which are usually harder to track, is a key feature of the study.
2024
Detecting Concurrency Bugs with Feedback-guided FuzzingHiromasa Ito, Yutaka Matsubara, Hiroaki Takada
IPSJ Journal, Vol.65, No.5, pp.927-941
This paper presents a fuzzing technique guided by feedback about thread interleavings to find concurrency bugs, which are hard to reproduce with ordinary testing. The tool observes which thread execution orders have been explored and steers testing toward unexplored, suspicious ones. This is the extended journal version of the Schfuzz work presented at ENASE 2023.
Japanese only.
2024
Monitor and Analyze Rare ROS2 Performance Issues with A Unified Tracing FrameworkYixiao Li, Yutaka Matsubara, Hiroaki Takada, Satoru Funahashi, Hiroki Kawashima
The 6th International Workshop on Software Science and Engineering (WSSE 2024), Kyoto, Aug 2024
This paper presents a unified tracing framework to monitor and analyze rare performance problems in ROS 2, a widely used robot software platform. The framework records events across the software stack in a unified way, so developers can trace back what happened when a rare slowdown occurs. This helps diagnose performance problems that are hard to reproduce.
2024
Race Directed Fuzzing for More Effective Concurrency TestingHiromasa Ito, Yutaka Matsubara, Hiroaki Takada
The 6th International Workshop on Software Science and Engineering (WSSE 2024), Kyoto, Aug 2024
This paper proposes race directed fuzzing, which steers automated testing toward suspicious thread interleavings to find concurrency bugs more effectively. Instead of exploring interleavings blindly, the method prioritizes ones where data races are likely, spending testing effort where bugs hide. Concurrency bugs are among the hardest to reproduce, which makes such targeting valuable.
2024
AI2X Co-evolution Guidebook and Case Study for Human-centered AI FrameworkAkihisa Morikawa, Yutaka Matsubara, Daichi Mizuguchi, Kiyoshi Fujiwara
SAFECOMP 2024 Position Paper, Florence, Sep 2024
This position paper introduces a guidebook and case study from the AI2X co-evolution project, which aims at human-centered frameworks where AI and society develop together. The guidebook distills how organizations can introduce AI while keeping humans central, and the case study shows the ideas applied in practice. It follows up the project introduction presented at SAFECOMP 2023.
2024
Reaching Consensus on System-of-systems Resilience Assurance: A Case of Mobility as a ServiceHuanjun Zhang, Yutaka Matsubara, Hiroaki Takada
SASSUR 2024 at SAFECOMP 2024, LNCS Vol.14989, pp.200-212, Florence, Sep 2024
This paper proposes a process for stakeholders to reach consensus on resilience assurance of a system of systems, using Mobility-as-a-Service as a case study. The process makes each stakeholder's assumptions and requirements explicit and reconciles them step by step into an agreed argument. It focuses on inter-organizational agreement, not just technology.
2024
TOPPERS of the Year 2024 Activity Division: Support for ET RoboconYoshifumi Shu, Yixiao Li, Yutaka Matsubara
TOPPERS Project
2023
Automotive Control Systems as Distributed Real-Time SystemsHiroaki Takada, Yutaka Matsubara
Systems, Control and Information (ISCIE), Vol.67, No.12
A review article explaining automotive control systems from the viewpoint of distributed real-time systems, where many computers must cooperate under strict timing constraints. It describes how the many electronic control units connected by in-vehicle networks must exchange data and finish computations on time. The article helps readers see why real-time system theory matters for modern cars.
2023
A Performance Evaluation of Embedded Multi-core Mixed-criticality System Based on PREEMPT_RT LinuxYixiao Li, Yutaka Matsubara, Hiroaki Takada, Kenji Suzuki, Hideaki Murata
Journal of Information Processing, Vol.31, pp.78-87
This paper evaluates the real-time performance of PREEMPT_RT Linux when running tasks of different criticality levels together on an embedded multi-core processor. The evaluation examines how critical and non-critical tasks interfere with each other when they share cores. The results inform decisions about consolidating functions onto one computer.
2023
Resilience Analysis and Design for Mobility-as-a-Service Based on Enterprise Architecture ModelingZhengshu Zhou, Yutaka Matsubara, Hiroaki Takada
Reliability Engineering & System Safety, Vol.229
This paper proposes an enterprise-architecture-based method to analyze and design the resilience of Mobility-as-a-Service systems. The service is modeled as a whole, covering not only IT systems but also the organizations and business processes around them, so weak points can be found across the entire structure. This supports designing transport services that keep running through failures.
2023
Developing Reliable Digital Healthcare Service Using Semi-Quantitative Functional Resonance AnalysisZhengshu Zhou, Yutaka Matsubara, Hiroaki Takada
Computer Systems Science and Engineering, Vol.45, No.1, pp.35-50
This paper applies a semi-quantitative version of FRAM, a method for analyzing how everyday performance variability interacts, to improve the reliability of digital healthcare services. Assigning rough numeric scores to how much each activity varies helps identify where small everyday variations can combine into service failures. This is useful for services where people, devices, and software work closely together.
2023
A Quantitative Approach for System of Systems’ Resilience Analyzing Based on ArchiMateHuanjun Zhang, Yutaka Matsubara, Hiroaki Takada
DECSoS 2023 at SAFECOMP 2023, LNCS Vol.14489, pp.47-60, Toulouse, Sep 2023
This paper proposes a quantitative method for analyzing the resilience of a system of systems based on ArchiMate architecture models. Assigning quantitative measures to model elements lets designers compare where reinforcement improves resilience most. This supports spending limited resources where they matter.
2023
Toward Human-centered AI Framework: An Introduction to AI2X Co-evolution ProjectYutaka Matsubara, Akihisa Morikawa, Daichi Mizuguchi, Kiyoshi Fujiwara
SAFECOMP 2023 Position Paper, Toulouse, Sep 2023
This position paper introduces the AI2X co-evolution project, which explores frameworks for human-centered AI in society. It outlines why AI systems and the society using them must adapt to each other, and sets out the project's research agenda. The paper positions the challenges of deploying AI safely in society.
2023
Schfuzz: Detecting Concurrency Bugs with Feedback-Guided FuzzingHiromasa Ito, Yutaka Matsubara, Hiroaki Takada
18th International Conference on Evaluation of Novel Approaches to Software Engineering (ENASE 2023), Prague, pp.273-282, Apr 2023
This paper presents Schfuzz, a tool that finds concurrency bugs by fuzzing thread schedules with feedback guidance. Rather than fuzzing input data, Schfuzz fuzzes the order in which threads run, using feedback from past executions to guide exploration. This work formed the basis of the later journal version.
2022
Design and Implementation of RTOS-Aware Control-Flow Integrity Mechanism for Microcontroller-Based SystemsTomoaki Kawada, Shinya Honda, Yutaka Matsubara, Hiroaki Takada
Computer Software, Vol.39, No.2
This paper designs a control-flow integrity mechanism, a defense that stops attackers from hijacking program execution, tailored to RTOS-based microcontroller systems. The mechanism is designed to keep protecting the system even when the RTOS switches tasks and handles interrupts, situations that ordinary CFI designs do not consider. This strengthens small embedded devices that are hard to patch after deployment.
Japanese only.
2022
Excellent Paper Award for Software Update Framework for IoT Devices Using BlockchainRyota Nakanishi, Yutaka Matsubara, Hiroaki Takada
DICOMO 2022
2022
Zengo Award for Coverage-based Greybox Fuzzing Applied to MiddlewareHiromasa Ito, Yutaka Matsubara, Hiroaki Takada
ASTER
2021
How to Test Middleware with Coverage-based Greybox FuzzingHiromasa Ito, Yutaka Matsubara, Hiroaki Takada
IPSJ Journal, Vol.62, pp.877-890
This paper shows how to apply coverage-based greybox fuzzing, an automated bug-finding technique, to middleware, which is harder to test than standalone programs. The approach prepares harnesses that drive the middleware and uses coverage feedback to steer generated inputs toward unexplored code. This brings a proven bug-finding technique to software it did not directly fit.
Japanese only.
2021
Quantitative Security Assurance Case for In-vehicle Embedded SystemsZhengshu Zhou, Yutaka Matsubara, Hiroaki Takada
CyberSciTech/PICom/DASC/CDBCom 2021, pp.43-50, Oct 2021
This paper proposes building quantitative security assurance cases, structured arguments with numeric evidence, for in-vehicle embedded systems. Adding numeric evidence to the structured argument makes it easier to judge whether security measures are sufficient and to compare alternatives. This helps explain the validity of security decisions to third parties.
2021
Best Presentation Award for Resilience Engineering Method for Improving Reliability of MaaSZhengshu Zhou, Yutaka Matsubara, Hiroaki Takada
DSW 2021
2021
Best Poster Bronze Award for Visual Design Tool for AUTOSAR Vehicle-Level SpecificationsMitsutaka Takada, Ryosuke Takahashi, Yutaka Matsubara
SWEST 23
2020
Tsunagaru! Kiso Gijutsu IoT Nyumon (Chapter 2: Security)Harumi Watanabe, Makoto Imamura, Kenji Hisazumi (eds.)
Corona Publishing
An introductory textbook chapter on security for IoT systems, explaining basic threats and countermeasures for connected devices. It walks through how attackers can reach devices over the network and what basic defenses such as encryption and authentication do. The chapter is written for students taking their first steps into IoT.
Yutaka Matsubara authored Chapter 2.
2020
CASE Revolution and Cybersecurity in the Automotive DomainYutaka Matsubara, Ryo Kurachi, Hiroaki Takada
IPSJ Magazine, Vol.61, No.4, pp.338-343
A review article on how the CASE trend (Connected, Autonomous, Shared, Electric) changes cybersecurity requirements for vehicles. As cars connect to networks and receive software updates remotely, attackers gain new entry points, so defenses must span the whole lifecycle from development to operation. The article summarizes these shifts for readers outside the automotive field.
2020
TZmCFI: RTOS-Aware Control-Flow Integrity Using TrustZone for Armv8-MTomoaki Kawada, Shinya Honda, Yutaka Matsubara, Hiroaki Takada
International Journal of Parallel Programming, Vol.49, pp.136-150
This paper presents TZmCFI, a control-flow integrity mechanism for small Arm microcontrollers that uses the TrustZone security feature and works correctly with an RTOS. TrustZone provides an isolated area that attackers cannot tamper with, and the mechanism keeps its protection consistent across task switches and interrupts. This defends small devices that lack the hardware protections of larger computers.
2020
esprof: A Generic Profiling Infrastructure for Multi/Many-Core Embedded SystemsYixiao Li, Yutaka Matsubara, Hiroaki Takada
Computer Software, Vol.37, No.1, pp.1_54-1_67
This paper presents esprof, a general-purpose profiling infrastructure for measuring and analyzing the behavior of multi- and many-core embedded software. It offers a common way to insert measurement points and collect events across different OSes and hardware, instead of building ad-hoc tools each time. The collected data helps developers track down performance bottlenecks.
Japanese only.
2020
Agile Software Design Verification and Validation (V&V) for Automated DrivingYixiao Li, Yutaka Matsubara, Daniel Olbrys, Kazuhiro Kajio, Hiroaki Takada
Proceedings of FISITA 2020, Oct 2020
This paper discusses an agile approach to verification and validation of automated driving software, enabling frequent checks during iterative development. Automating checks and integrating them into each development iteration keeps quality visible as the software evolves rapidly. This aims to reconcile development speed with safety assurance.
2020
Transforming Concurrent Programs with Semaphores into Logically Constrained Term Rewrite SystemsMisaki Kojima, Naoki Nishida, Yutaka Matsubara
Informal Proceedings of WPTE 2020, Jun 2020
This workshop paper presents a translation from concurrent programs using semaphores into logically constrained term rewrite systems for formal analysis. Expressing programs as rewrite systems opens the door to mathematically rigorous verification of concurrent behavior. This work later grew into the extended journal version.
2020
Safety Design Concepts for Statistical Machine Learning Components toward Accordance with Functional Safety StandardsAkihisa Morikawa, Yutaka Matsubara
SEAMS Project
2020
Towards Identifying and Closing Gaps in Assurance of Autonomous Road Vehicles: Technical Notes Part 2Robin Bloomfield, Gareth Fletcher, Heidy Khlaaf, Philippa Ryan, Shuji Kinoshita, Yoshiki Kinoshita, Makoto Takeyama, Yutaka Matsubara, Peter Popov, Kazuki Imai, Yoshinori Tsutake
TIGARS Project
2020
Towards Identifying and Closing Gaps in Assurance of Autonomous Road Vehicles: Technical Notes Part 1Robin Bloomfield, Gareth Fletcher, Heidy Khlaaf, Philippa Ryan, Shuji Kinoshita, Yoshiki Kinoshita, Makoto Takeyama, Yutaka Matsubara, Peter Popov, Kazuki Imai, Yoshinori Tsutake
TIGARS Project
2020
Selected Paper Award for Coverage-based Greybox Fuzzing Applied to MiddlewareHiromasa Ito, Yutaka Matsubara, Hiroaki Takada
IPSJ Journal, Vol.62, No.3
Japanese only.
2019
Energy-Efficient Intra-Task DVFS Scheduling Using Linear Programming FormulationYang Qin, Gang Zeng, Ryo Kurachi, Yixiao Li, Yutaka Matsubara, Hiroaki Takada
IEEE Access, Vol.7, pp.30536-30547
This paper uses linear programming to decide when to change processor speed within a task (intra-task DVFS) so that energy is saved without missing deadlines. The task is divided into segments and an optimization determines the best speed for each, exploiting the fact that slower execution consumes less energy. Deadlines are treated as constraints, so real-time guarantees are preserved.
2019
Energy-Aware Task Allocation for Heterogeneous Multiprocessor Systems by Using Integer Linear ProgrammingYang Qin, Gang Zeng, Ryo Kurachi, Yutaka Matsubara, Hiroaki Takada
Journal of Information Processing, Vol.27, pp.136-148
This paper formulates energy-aware task allocation on heterogeneous multiprocessors as an integer linear programming problem to minimize energy while meeting deadlines. Formulating the problem mathematically lets a solver find allocations that exploit the different speed and power characteristics of each core. This matters for battery-powered devices that still have timing requirements.
2019
Shadow Exception Stacks: Control-Flow Integrity for Asynchronous Exceptions Using TrustZone for Armv8-MTomoaki Kawada, Shinya Honda, Yutaka Matsubara, Hiroaki Takada
IESS 2019, LNCS Vol.11937, pp.56-71, Friedrichshafen, Nov 2019
This paper proposes shadow exception stacks, which extend control-flow integrity protection to interrupt handling on Arm microcontrollers using TrustZone. Interrupts complicate control-flow protection because they can occur at any moment, and the shadow stacks record return paths safely inside TrustZone. This addresses a gap left by CFI schemes that ignore asynchronous exceptions.
2019
Software Paper Award for EV3RT: A Real-time Software Platform for LEGO Mindstorms EV3Yixiao Li, Yutaka Matsubara, Hiroaki Takada
JSSST
2018
Trends and Prospects in Safety and Security for Connected Cars and SocietyYutaka Matsubara, Ryo Kurachi, Hiroaki Takada
Jidosha Gijutsu, Vol.72, No.5, pp.87-93
A review article surveying safety and security trends for connected cars and the surrounding connected society. It explains why safety, which protects people from failures, and security, which protects systems from attacks, must be considered together once vehicles are networked. Related standards and research directions are also introduced.
2018
IDH-CAN: A Hardware-Based ID Hopping CAN Mechanism With Enhanced Security for Automotive Real-Time ApplicationsWufei Wu, Ryo Kurachi, Gang Zeng, Yutaka Matsubara, Hiroaki Takada, Renfa Li, Keqin Li
IEEE Access, Vol.6, pp.54607-54623
This paper proposes IDH-CAN, a hardware mechanism that periodically changes CAN message IDs to make attacks on in-vehicle networks harder while preserving real-time behavior. Because CAN messages are normally identified by fixed IDs, hopping them deprives attackers of an easy target. Implementing the hopping in hardware keeps message timing predictable, which is essential for control systems.
2018
Execution-variance-aware Task Allocation for Energy Minimization on the big.LITTLE ArchitectureYang Qin, Gang Zeng, Ryo Kurachi, Yutaka Matsubara, Hiroaki Takada
Sustainable Computing: Informatics and Systems, Vol.20, pp.81-93
This paper allocates tasks on the big.LITTLE architecture, which combines fast and power-efficient cores, considering variations in execution time to minimize energy. Real tasks often finish earlier than their worst-case estimates, and the method exploits this slack when deciding which core runs which task. This saves energy on the kind of processors widely used in smartphones and embedded devices.
2018
A Comparative Analysis of RTOS and Linux Scalability on an Embedded Many-core ProcessorYixiao Li, Yutaka Matsubara, Hiroaki Takada
Journal of Information Processing, Vol.26, pp.225-236
This paper compares how well an RTOS and Linux scale on an embedded many-core processor, providing data for choosing an OS for such platforms. The same measurements are run on both OSes while the number of cores increases, revealing where each design stops scaling. Such data helps developers pick the right OS for many-core embedded platforms.
2018
Safety Analysis Examples in Compliance with ISO 26262 for TOPPERS/ATK2 Conforming to the AUTOSAR OS SpecificationMorio Mori, Hideaki Sato, Akira Yamashita, Yutaka Matsubara, Hiroaki Takada
IPSJ Journal, Vol.59, No.2, pp.785-794
This paper reports safety analysis examples for the TOPPERS/ATK2 automotive OS, conducted to comply with the ISO 26262 functional safety standard. The examples show concretely how to apply safety analysis techniques to an RTOS, a component that many automotive products share. Published examples like these help practitioners facing the same certification work.
Japanese only.
2018
Energy-Aware Task Allocation for Large Task Sets on Heterogeneous Multiprocessor SystemsYang Qin, Gang Zeng, Ryo Kurachi, Yutaka Matsubara, Hiroaki Takada
EUC 2018, pp.158-165, Bucharest, Romania, Oct 2018
This paper proposes an energy-aware method to allocate large sets of tasks on heterogeneous multiprocessors, scaling beyond exact optimization approaches. A heuristic approach finds good allocations quickly where exact optimization would take far too long. This targets realistic embedded systems with large numbers of tasks.
2018
FRAM/STPA: Hazard Analysis Method for FRAM ModelYoshinari Toda, Yutaka Matsubara, Hiroaki Takada
FRAMily 2018, pp.1-17, Cardiff, Jun 2018
This paper proposes FRAM/STPA, a hazard analysis method that applies STPA-style control analysis to FRAM models of everyday performance variability. FRAM shows how variability spreads among functions, while STPA asks which control actions become unsafe, and combining them finds hazards that either method alone may miss. This suits complex systems where people and technology interact.
2017
Trends and Prospects in Automotive Safety and Security Toward Autonomous DrivingYutaka Matsubara, Ryo Kurachi, Hiroaki Takada
IPSJ Magazine, Vol.58, No.11
A review article surveying automotive safety and security technologies needed to realize autonomous driving. It explains how safety design against failures and defenses against cyber attacks influence each other, and why both are prerequisites for self-driving cars. The article suits readers who want an overview before studying individual technologies.
2017
Automotive Security and IoTYutaka Matsubara
Kinou Zairyo, Jun. 2017 serial article
A review article introducing the current state of automotive security in the context of the IoT era. It describes how connecting cars to networks and smartphones creates new attack paths, and outlines the countermeasures the industry is adopting. The article is written to be accessible to readers outside the software field.
2017
IXM: Rapid Inter-Process Communication Middleware for Robotics SoftwareMidori Sugaya, Yutaka Matsubara, Takuma Sumiya, Miyuki Nakano
IPSJ Journal, Vol.58, No.10, pp.1578-1590
This paper presents IXM, a fast inter-process communication middleware designed for robot control software. By reducing copying and overhead in message exchange, it keeps the delay between sensing and actuation small. This supports building robot systems that respond quickly to their surroundings.
Japanese only.
2017
EV3RT: A Real-time Software Platform for LEGO Mindstorms EV3Yixiao Li, Yutaka Matsubara, Hiroaki Takada
Computer Software, Vol.34, Issue 4, pp.4_91-4_115
This paper presents EV3RT, a real-time software platform that lets developers run RTOS-based applications on the LEGO Mindstorms EV3 robot kit. It brings the TOPPERS RTOS to the EV3 hardware together with device support and a development environment. The platform is widely used in embedded systems education and robot contests.
Japanese only.
2017
IDHCC: A Security-Enhanced ID Hopping CAN Controller Design to Guarantee Real-TimeWufei Wu, Ryo Kurachi, Gang Zeng, Yutaka Matsubara, Hiroaki Takada, Renfa Li
CERTS 2017, pp.14-21, Jun 2017
This paper designs IDHCC, a CAN controller that hops message IDs for security while guaranteeing real-time message delivery. The controller changes IDs in a way both sender and receiver can follow, so protection is added without breaking communication. This design study preceded the extended IDH-CAN journal version.
2016
HAZOP-Based Security Analysis for Embedded Systems: Case Study of Open Source Immobilizer Protocol StackJingxuan Wei, Yutaka Matsubara, Hiroaki Takada
Recent Advances in Systems Safety and Security, Springer, pp.79-96
A book chapter that applies HAZOP, a systematic hazard analysis technique, to find security weaknesses in an open-source car immobilizer protocol stack. Guide words describing deviations from intended behavior are reinterpreted from a security viewpoint, turning a safety method into a way to find attack-relevant flaws. The chapter is an expanded version of the authors' earlier workshop study.
2016
Security and Safety of In-Vehicle DevicesRyo Kurachi, Yutaka Matsubara, Hiroaki Takada
IPSJ Magazine, Vol.57, No.7
A review article explaining the relationship between security and functional safety for in-vehicle devices. It shows that a cyber attack can break the assumptions behind safety design, so security measures must be planned as part of functional safety. Basic attack examples and defense concepts are introduced for non-specialists.
2016
CaCAN: Centralized Authentication System in CANRyo Kurachi, Yutaka Matsubara, Hiroaki Takada, Hiroshi Ueda, Satoshi Horihata
IEICE Transactions, Vol.J99-A No.2, pp.118-130
This paper proposes CaCAN, a system in which a central monitor node authenticates messages on the CAN in-vehicle network and removes unauthorized ones. The monitor node checks message authentication codes and neutralizes unauthorized frames before they take effect. Requiring only one added node makes the scheme easy to introduce, and this is the extended journal version of the escar 2014 paper.
Japanese only.
2016
Energy-aware Task Migration for Multiprocessor Real-time SystemsGang Zeng, Yutaka Matsubara, Hiroyuki Tomiyama, Hiroaki Takada
Future Generation Computer Systems, Vol.56, pp.220-228
This paper proposes moving tasks between processors at run time to reduce energy consumption in multiprocessor real-time systems while meeting deadlines. Migration decisions weigh the cost of moving a task against the energy saved by balancing load across processors. This is the extended journal version of the authors' ICESS 2014 conference paper.
2016
An Evaluation Framework of OS-level Power Managements for the big.LITTLE ArchitectureHideki Takase, Kazumi Aono, Yutaka Matsubara, Kazuyoshi Takagi, Naofumi Takagi
2016 14th IEEE International New Circuits and Systems Conference (NEWCAS 2016), Vancouver, Jun 2016
This paper presents a framework for evaluating OS-level power management schemes on the big.LITTLE architecture, which combines fast and efficient cores. The framework runs different power management policies under the same conditions so their energy and performance can be compared fairly. Such comparisons guide OS design for energy-sensitive devices.
2015
Practical Educational Method of Embedded System with OJLNobuyuki Tachi, Masaki Yamamoto, Norihiro Yoshida, Hiroyuki Takashima, Tomoaki Unagami, Yuki Ando, Yutaka Matsubara, Shinya Honda, Hiroaki Takada
Computer Software, Vol.32, No.2, pp.79-85
This paper reports a practical education method for embedded systems based on OJL (On-the-Job Learning), where students learn through real development projects. Students tackle industry-related development tasks under mentoring, gaining skills that classroom exercises alone cannot teach. The paper shares the course design and the outcomes observed.
Japanese only.
2015
A Mobile Robot for Fall Detection for Elderly-CareTakuma Sumiya, Yutaka Matsubara, Miyuki Nakano, Midori Sugaya
KES 2015, Vol.60, pp.870-880, Singapore, Sep 2015
This paper presents a mobile robot system that detects falls of elderly people to support care services. A mobile robot can move to check on a person, complementing fixed sensors that cover only part of a home. Combining sensing and robot technology aims to reduce the burden of watching over elderly people.
Invited paper.
2015
HAZOP-based Security Analysis for Embedded Systems: Case Study of Open Source Immobilizer Protocol StackJingxuan Wei, Yutaka Matsubara, Hiroaki Takada
Proceedings of the 3rd International Workshop on Systems Safety & Security (IWSSS2015), Bucharest, Jun 2015
This paper applies HAZOP, a systematic deviation analysis technique, to security analysis of an open-source car immobilizer protocol stack. Guide words describing deviations from intended behavior are reinterpreted for security, turning a safety technique into a way to find attack-relevant weaknesses. This study was later expanded into a book chapter.
2015
Student Encouragement Award for Evaluation Environment of Power Management on Heterogeneous Multicore SystemsKazumi Aono, Hideki Takase, Yutaka Matsubara, Kazuyoshi Takagi, Naofumi Takagi
ESS 2015
2014
CaCAN - Centralized Authentication System in CANRyo Kurachi, Yutaka Matsubara, Hiroaki Takada, Naoki Adachi, Yukihiro Miyashita, Satoshi Horihata
Proceedings of the escar 2014 Europe, pp. 1-9, Hamburg, Nov 2014
This paper presents CaCAN, a centralized message authentication system for the CAN in-vehicle network, at the automotive security conference escar. A monitor node authenticates messages on the bus and neutralizes unauthorized ones, requiring little change to existing vehicle networks. This work was later extended into the journal version.
2014
A Simulation Environment and Preliminary Evaluation for Automotive CAN-Ethernet AVB NetworksKeigo Kawahara, Yutaka Matsubara, Hiroaki Takada
Proceedings of the 1st OMNeT++ Community Summit, pp.xx-xx, Hamburg, Sep 2014
This paper builds a simulation environment for automotive networks combining CAN and Ethernet AVB, and reports a preliminary evaluation. The model reproduces how time-sensitive traffic flows across the two network types, so designs can be examined before building hardware. Ethernet AVB matters as vehicles need more bandwidth for cameras and sensors.
2014
Task Migration for Energy Saving in Real-Time Multiprocessor SystemsGang Zeng, Yutaka Matsubara, Hiroyuki Tomiyama, Hiroaki Takada
Proceedings of the 11th IEEE International Conference on Embedded Software and Systems (ICESS 2014), Paris, Aug 2014
This paper proposes migrating tasks between processors to save energy in real-time multiprocessor systems while keeping deadlines. Moving tasks at run time balances load, so processors can run at lower speeds and consume less energy while deadlines are still met. This work formed the basis of the later journal version.
2014
A Platform for LEGO Mindstorms EV3 Based on an RTOS with MMU SupportYixiao Li, Takuya Ishikawa, Yutaka Matsubara, Hiroaki Takada
OSPERT 2014, pp.51-59, Madrid, Jul 2014
This paper presents a software platform for the LEGO Mindstorms EV3 robot kit based on an RTOS with memory protection (MMU) support. Memory protection via the MMU keeps a faulty program from corrupting the rest of the system, which is unusual for hobby-class robot kits. This platform later evolved into EV3RT.
2014
Best Poster Student Presentation Award for OMNeT++ Simulation Environment for Mixed CAN-Ethernet AVB NetworksKeigo Kawahara, Yutaka Matsubara, Hiroaki Takada
SWEST 16
2013
Safety Measures for Software Faults in Embedded SystemsYutaka Matsubara, Hiroaki Takada
Computer Software, Vol.30, No.1, pp.119-129
This paper organizes and discusses safety measures against software faults in embedded systems, such as detecting failures and keeping the system in a safe state. Since testing cannot remove every fault, systems should detect anomalies at run time and move to a safe state before harm occurs. The paper organizes concrete techniques usable in resource-limited embedded systems.
Japanese only.
2013
Safety Analysis Method Based on Hierarchical State Transition Diagram for Embedded SystemsZoohaye Kim, Yutaka Matsubara, Hiroaki Takada
IEICE Transactions, Vol.J96-A No.1, pp.34-48
This paper proposes a safety analysis method that uses hierarchical state transition diagrams to systematically find hazardous behaviors in embedded systems. Organizing states into a hierarchy keeps the analysis manageable even when the system has many states. This helps find dangerous behaviors at the design stage, before accidents can happen.
Japanese only.
2013
A Simulation Environment Based on OMNeT++ for Automotive CAN-Ethernet NetworksJun Matsumura, Yutaka Matsubara, Hiroaki Takada, Masaya Oi, Masumi Toyoshima, Akihito Iwai
WATERS 2013, pp.1-6, Paris, Jul 2013
This paper presents a simulation environment based on the OMNeT++ network simulator for automotive networks that combine CAN and Ethernet. Mixed CAN-Ethernet designs were emerging in vehicles, and the environment lets engineers evaluate such network designs on a computer. Communication design can thus be examined without a real car.
2012
schesim: Scheduling Simulator for Real-Time ApplicationsYasumasa Sano, Yutaka Matsubara, Shinya Honda, Hiroaki Takada
IEICE Transactions D, Vol.J95-D No.12, pp.2008-2020
This paper presents schesim, a simulator that reproduces how a real-time scheduler runs application tasks, useful for checking timing behavior before deployment. Developers describe their tasks and scheduling policies, and the simulator shows whether deadlines are met under various conditions. This lets timing behavior be examined without preparing target hardware.
Japanese only.
2012
Safety Analysis Method Focusing on State Transition DiagramsZoohaye Kim, Yutaka Matsubara, Hiroaki Takada
IEICE Transactions, Vol.J95-A No.2, pp.198-209
This paper proposes a safety analysis method that examines state transition diagrams to find conditions under which an embedded system can reach hazardous states. Because state transition diagrams are already common in embedded design, engineers can reuse familiar models for safety analysis instead of building new ones. This helps prevent accidents by catching dangerous conditions at the design stage.
Japanese only.
2012
Safety Analysis Method Based on Parallel State Transition Diagram for Embedded SystemsZoohaye Kim, Yutaka Matsubara, Hiroaki Takada
SEA 2012, pp.417-425, Las Vegas, Nov 2012
This paper proposes a safety analysis method for embedded systems based on parallel state transition diagrams, handling components that operate concurrently. Unexpected combinations of concurrently operating components are a common source of hazards, and the parallel diagrams make such combinations explicit for analysis. This helps find dangerous behaviors systematically at the design stage.
2012
An Open-Source Flexible Scheduling Simulator for Real-time ApplicationsYutaka Matsubara, Yasumasa Sano, Shinya Honda, Hiroaki Takada
ISORC 2012, pp.16-22, Shenzhen, Jun 2012
This paper presents an open-source simulator that flexibly models schedulers and real-time applications to evaluate timing behavior. Being open source, the simulator can be extended with new scheduling algorithms and reused freely in research and education. It helps developers check timing behavior without target hardware.
2011
Practice of a Summer School on Embedded System Technologies by Students and Young EngineersIttetsu Taniguchi, Yuki Ando, Hideki Takase, Takuya Azumi, Yutaka Matsubara, Shintaro Hosoai, Yasuaki Murakami, Midori Sugaya
IPSJ Journal, Vol.52, No.12, pp.3221-3237
This paper reports the practice and outcomes of a summer school on embedded system technologies organized by students and young engineers. Participants design and build an embedded system in a short period, while the young organizers themselves grow by planning and running the school. The paper analyzes the educational effects observed through this practice.
Japanese only.
2011
Probabilistic Analysis of Response Time Considering Initial Phase Distribution of Periodic TasksTakuya Ishikawa, Yutaka Matsubara, Hiroaki Takada
IPSJ Journal, Vol.52, No.12, pp.3192-3204
This paper analyzes the response time of periodic tasks probabilistically, taking into account the distribution of their initial phases (start offsets). Worst-case analysis alone is often too pessimistic, and the probabilistic view estimates how likely each response time actually is. This supports real-time designs that use resources efficiently without giving up timing confidence.
Japanese only.
2011
Hierarchical Scheduling Algorithm with Task Start Delay for Time ProtectionYutaka Matsubara, Shinya Honda, Hiroaki Takada
IPSJ Journal, Vol.52, No.8, pp.2387-2401
This paper proposes a hierarchical scheduling algorithm with task start delay that provides time protection, preventing one application from stealing CPU time from others. Deliberately delaying certain task starts makes each application's CPU budget easier to guarantee within the hierarchical scheduler. This supports consolidating separately developed applications onto one computer without interference.
Japanese only.
2011
Interruptible Priority-Inheritance Spin Lock and Its Hardware ImplementationToshiyuki Ichiba, Yutaka Matsubara, Shinya Honda, Hiroaki Takada
IPSJ ACS, Vol.4, No.3, pp.133-146
This paper proposes a spin lock with priority inheritance that can be interrupted, and implements it in hardware to reduce blocking in multiprocessor real-time systems. Ordinary spin locks can delay interrupts and urgent tasks while waiting, and the proposed lock avoids this by allowing interruption and inheriting priority. A hardware implementation keeps the overhead of the mechanism low.
Japanese only.
2011
Hierarchical Scheduling for Integrating Embedded Real-Time ApplicationsYutaka Matsubara
Doctoral Dissertation
Recommended by IPSJ SIGEMB.
2011
Recommended Doctoral Thesis DigestYutaka Matsubara
IPSJ SIGEMB recommended thesis announcement
2011
Excellent Paper Award for Scheduling Simulator with User-Defined Task ProcessingYasumasa Sano, Yutaka Matsubara, Shinya Honda, Hiroaki Takada
IPSJ Embedded System Symposium 2011
2009
Hierarchical Scheduling for Integrating Real-time Applications with Interrupt RoutinesYutaka Matsubara, Shinya Honda, Hiroaki Takada
ISOCC 2009, pp.384-387, Busan, Nov 2009
This paper proposes hierarchical scheduling that integrates multiple real-time applications while properly accounting for interrupt routines. Interrupt handling consumes CPU time at unpredictable moments, so the scheduler treats its influence explicitly when guaranteeing each application's share. This supports consolidating software onto fewer processors.
Invited paper.
2009
History of Summer School on Embedded System Technologies Organized by Students and Young EngineersHideki Takase, Takuya Azumi, Ittetsu Taniguchi, Yutaka Matsubara, Hayato Kanai, Shintaro Hosoai, Midori Sugaya
WESE 2009, pp.19-26, Grenoble, Oct 2009
This paper reports the history and lessons of a summer school on embedded system technologies organized by students and young engineers in Japan. It looks back on how the peer-run format developed and what kept participants engaged. The lessons are useful for others planning hands-on engineering education.
2008
Flexible Scheduling Framework for Integrating Real-Time ApplicationsYutaka Matsubara, Shinya Honda, Hiroyuki Tomiyama, Hiroaki Takada
IPSJ Journal Embedded Systems Special Issue, Vol.49, No.10, pp.3508-3519
This paper presents a flexible scheduling framework that lets multiple real-time applications with different scheduling needs run together on one system. Each application keeps its own scheduling policy while the framework arbitrates CPU time among them. This eases integrating software components that were developed separately.
Japanese only.
2008
TOPPERS of the Year 2008 for Automotive RTOS with Memory and Time ProtectionHiroyuki Hattori, Shuichi Onishi, Ayumu Kataoka, Yutaka Matsubara, Hiroaki Takada
TOPPERS Project
2008
IP Excellence Award for Open-Source Protected OS: Automotive RTOS with Memory and Time ProtectionHiroyuki Hattori, Shuichi Onishi, Ayumu Kataoka, Yutaka Matsubara, Hiroaki Takada
10th LSI IP Design Award
2007
Real-Time Scheduling Algorithm for Time ProtectionYutaka Matsubara, Shinya Honda, Hiroyuki Tomiyama, Hiroaki Takada
IPSJ ACS, Vol.48 SIG8(ACS18), pp.192-202
This paper proposes a real-time scheduling algorithm that provides time protection, guaranteeing each application its share of CPU time even if another misbehaves. The scheduler enforces a CPU budget for each application, so a fault in one cannot starve the others. This idea underpins safely consolidating multiple functions onto one processor.
Japanese only.
2007
SSEST: Summer School on Embedded System TechnologiesYutaka Matsubara, Midori Sugaya, Ittetsu Taniguchi, Yasuaki Murakami, Hayato Kanai, Hiroaki Takada
APESER 2007, pp.1-8, Hsinchu, Dec 2007
This paper introduces SSEST, a summer school on embedded system technologies run by students and young engineers, and its educational approach. Participants team up to develop an embedded system in a short period, experiencing the process from design to demonstration. The paper shares the curriculum and how the school is run, so similar programs can be built elsewhere.
2007
Computer Science Area Encouragement AwardYutaka Matsubara
IPSJ 2007
By research theme
All entries on this page, grouped by the research theme they belong to, newest first. Theme names link to the project descriptions.
Trust in a single computer
2026
Outlier-Ratio Feature Augmentation for Graph-based Intrusion Detection in CAN NetworksAkari Sasaki, Ryo Kurachi, Yutaka Matsubara, Hiroaki Takada
IEEE Consumer Communications & Networking Conference (CCNC 2026), Las Vegas, Jan. 2026
This paper improves graph-based intrusion detection for the CAN in-vehicle network by adding outlier-ratio features that highlight abnormal message patterns. Messages are modeled as a graph, and the ratio of outlier messages is added as a feature to help separate attacks from normal traffic. Better detection matters because CAN itself has no built-in security.
2025
Software-Defined Vehicles: Challenges and Orchestrating Mixed-Criticality Services Using Lingua FrancaWenhung Kevin Huang, Yoshinori Terazawa, Yutaka Matsubara, Akihito Iwai
IEEE Embedded Systems Letters
This paper discusses challenges of software-defined vehicles and shows how the Lingua Franca coordination language can orchestrate services with different criticality levels on one platform. Lingua Franca describes the timing relationships between components explicitly, which makes it easier to ensure that safety-critical services are not disturbed by less important ones. This matters as cars consolidate many functions onto a few powerful computers.
2025
A COTS-based Lightweight, Low-power and Versatile Companion Computer for Nano UAVsRintaro Okudera, Yixiao Li, Yutaka Matsubara, Hiroaki Takada
Sensors & Transducers, Vol.268, No.1, pp.37-44
This paper presents a small companion computer built from commercial off-the-shelf parts for nano drones, balancing weight, power consumption, and versatility. Using off-the-shelf modules instead of custom hardware keeps the design inexpensive and easy to reproduce while fitting the strict weight and power budget of palm-sized drones. This is an extended journal version of the authors' conference work.
2025
Towards a Linux-based Unikernel for Resource-Constrained Embedded SystemsYoshifumi Shu, Yutaka Matsubara, Yixiao Li, Hiroaki Takada
The 19th annual workshop on Operating Systems Platforms for Embedded Real-Time applications (OSPERT 2025), Belgium, Jul 2025, pp.23-27
This paper explores building a Linux-based unikernel, a minimal single-purpose OS image, for embedded systems with limited memory and CPU resources. Bundling the application with only the OS features it needs reduces memory footprint while keeping compatibility with Linux software. This would let resource-constrained devices benefit from the large Linux ecosystem.
2025
GLACI: Arbitrary Code Instrumentation Tool for OpenGLShotaro Tsuboi, Yixiao Li, Yutaka Matsubara, Hiroaki Takada
The 20th International Conference on Networking and Services (ICONS 2025), France, Mar 2025
This paper presents GLACI, a tool that inserts arbitrary measurement or debugging code into OpenGL graphics API calls without modifying the application. It intercepts the calls between the application and the graphics driver, so measurement code can be added and removed freely. This helps analyze and debug graphics performance in embedded systems.
Best Paper Award.
2025
A Lightweight, Low-power and Versatile Companion Computer for Nano UAVsRintaro Okudera, Yixiao Li, Yutaka Matsubara, Hiroaki Takada
The 7th International Symposium on Distributed Autonomous Unmanned Systems (DAUS 2025), Granada, Feb 2025, pp.292-295
This paper presents a lightweight, low-power companion computer for nano drones, enabling additional processing on very small aircraft. The design fits within the strict weight and power budget of palm-sized aircraft while remaining versatile. This work later formed the basis of the extended journal version.
2025
Best Paper Award for GLACI: Arbitrary Code Instrumentation Tool for OpenGLShotaro Tsuboi, Yixiao Li, Yutaka Matsubara, Hiroaki Takada
The 20th International Conference on Systems (ICONS 2025)
2025
Best Young Presentation Award for Real-Time Evaluation of a Full-Scratch Linux-Compatible UnikernelYoshifumi Shu, Yutaka Matsubara, Ryoma Hiraoka, Ryosuke Yamamoto, Hitoshi Yamamoto, Shingo Oidate, Hiroaki Takada
166th IPSJ OS Workshop
2024
Monitor and Analyze Rare ROS2 Performance Issues with A Unified Tracing FrameworkYixiao Li, Yutaka Matsubara, Hiroaki Takada, Satoru Funahashi, Hiroki Kawashima
The 6th International Workshop on Software Science and Engineering (WSSE 2024), Kyoto, Aug 2024
This paper presents a unified tracing framework to monitor and analyze rare performance problems in ROS 2, a widely used robot software platform. The framework records events across the software stack in a unified way, so developers can trace back what happened when a rare slowdown occurs. This helps diagnose performance problems that are hard to reproduce.
2024
TOPPERS of the Year 2024 Activity Division: Support for ET RoboconYoshifumi Shu, Yixiao Li, Yutaka Matsubara
TOPPERS Project
2023
Automotive Control Systems as Distributed Real-Time SystemsHiroaki Takada, Yutaka Matsubara
Systems, Control and Information (ISCIE), Vol.67, No.12
A review article explaining automotive control systems from the viewpoint of distributed real-time systems, where many computers must cooperate under strict timing constraints. It describes how the many electronic control units connected by in-vehicle networks must exchange data and finish computations on time. The article helps readers see why real-time system theory matters for modern cars.
2023
A Performance Evaluation of Embedded Multi-core Mixed-criticality System Based on PREEMPT_RT LinuxYixiao Li, Yutaka Matsubara, Hiroaki Takada, Kenji Suzuki, Hideaki Murata
Journal of Information Processing, Vol.31, pp.78-87
This paper evaluates the real-time performance of PREEMPT_RT Linux when running tasks of different criticality levels together on an embedded multi-core processor. The evaluation examines how critical and non-critical tasks interfere with each other when they share cores. The results inform decisions about consolidating functions onto one computer.
2022
Design and Implementation of RTOS-Aware Control-Flow Integrity Mechanism for Microcontroller-Based SystemsTomoaki Kawada, Shinya Honda, Yutaka Matsubara, Hiroaki Takada
Computer Software, Vol.39, No.2
This paper designs a control-flow integrity mechanism, a defense that stops attackers from hijacking program execution, tailored to RTOS-based microcontroller systems. The mechanism is designed to keep protecting the system even when the RTOS switches tasks and handles interrupts, situations that ordinary CFI designs do not consider. This strengthens small embedded devices that are hard to patch after deployment.
Japanese only.
2021
Best Poster Bronze Award for Visual Design Tool for AUTOSAR Vehicle-Level SpecificationsMitsutaka Takada, Ryosuke Takahashi, Yutaka Matsubara
SWEST 23
2020
TZmCFI: RTOS-Aware Control-Flow Integrity Using TrustZone for Armv8-MTomoaki Kawada, Shinya Honda, Yutaka Matsubara, Hiroaki Takada
International Journal of Parallel Programming, Vol.49, pp.136-150
This paper presents TZmCFI, a control-flow integrity mechanism for small Arm microcontrollers that uses the TrustZone security feature and works correctly with an RTOS. TrustZone provides an isolated area that attackers cannot tamper with, and the mechanism keeps its protection consistent across task switches and interrupts. This defends small devices that lack the hardware protections of larger computers.
2020
esprof: A Generic Profiling Infrastructure for Multi/Many-Core Embedded SystemsYixiao Li, Yutaka Matsubara, Hiroaki Takada
Computer Software, Vol.37, No.1, pp.1_54-1_67
This paper presents esprof, a general-purpose profiling infrastructure for measuring and analyzing the behavior of multi- and many-core embedded software. It offers a common way to insert measurement points and collect events across different OSes and hardware, instead of building ad-hoc tools each time. The collected data helps developers track down performance bottlenecks.
Japanese only.
2019
Energy-Efficient Intra-Task DVFS Scheduling Using Linear Programming FormulationYang Qin, Gang Zeng, Ryo Kurachi, Yixiao Li, Yutaka Matsubara, Hiroaki Takada
IEEE Access, Vol.7, pp.30536-30547
This paper uses linear programming to decide when to change processor speed within a task (intra-task DVFS) so that energy is saved without missing deadlines. The task is divided into segments and an optimization determines the best speed for each, exploiting the fact that slower execution consumes less energy. Deadlines are treated as constraints, so real-time guarantees are preserved.
2019
Energy-Aware Task Allocation for Heterogeneous Multiprocessor Systems by Using Integer Linear ProgrammingYang Qin, Gang Zeng, Ryo Kurachi, Yutaka Matsubara, Hiroaki Takada
Journal of Information Processing, Vol.27, pp.136-148
This paper formulates energy-aware task allocation on heterogeneous multiprocessors as an integer linear programming problem to minimize energy while meeting deadlines. Formulating the problem mathematically lets a solver find allocations that exploit the different speed and power characteristics of each core. This matters for battery-powered devices that still have timing requirements.
2019
Shadow Exception Stacks: Control-Flow Integrity for Asynchronous Exceptions Using TrustZone for Armv8-MTomoaki Kawada, Shinya Honda, Yutaka Matsubara, Hiroaki Takada
IESS 2019, LNCS Vol.11937, pp.56-71, Friedrichshafen, Nov 2019
This paper proposes shadow exception stacks, which extend control-flow integrity protection to interrupt handling on Arm microcontrollers using TrustZone. Interrupts complicate control-flow protection because they can occur at any moment, and the shadow stacks record return paths safely inside TrustZone. This addresses a gap left by CFI schemes that ignore asynchronous exceptions.
2019
Software Paper Award for EV3RT: A Real-time Software Platform for LEGO Mindstorms EV3Yixiao Li, Yutaka Matsubara, Hiroaki Takada
JSSST
2018
IDH-CAN: A Hardware-Based ID Hopping CAN Mechanism With Enhanced Security for Automotive Real-Time ApplicationsWufei Wu, Ryo Kurachi, Gang Zeng, Yutaka Matsubara, Hiroaki Takada, Renfa Li, Keqin Li
IEEE Access, Vol.6, pp.54607-54623
This paper proposes IDH-CAN, a hardware mechanism that periodically changes CAN message IDs to make attacks on in-vehicle networks harder while preserving real-time behavior. Because CAN messages are normally identified by fixed IDs, hopping them deprives attackers of an easy target. Implementing the hopping in hardware keeps message timing predictable, which is essential for control systems.
2018
Execution-variance-aware Task Allocation for Energy Minimization on the big.LITTLE ArchitectureYang Qin, Gang Zeng, Ryo Kurachi, Yutaka Matsubara, Hiroaki Takada
Sustainable Computing: Informatics and Systems, Vol.20, pp.81-93
This paper allocates tasks on the big.LITTLE architecture, which combines fast and power-efficient cores, considering variations in execution time to minimize energy. Real tasks often finish earlier than their worst-case estimates, and the method exploits this slack when deciding which core runs which task. This saves energy on the kind of processors widely used in smartphones and embedded devices.
2018
A Comparative Analysis of RTOS and Linux Scalability on an Embedded Many-core ProcessorYixiao Li, Yutaka Matsubara, Hiroaki Takada
Journal of Information Processing, Vol.26, pp.225-236
This paper compares how well an RTOS and Linux scale on an embedded many-core processor, providing data for choosing an OS for such platforms. The same measurements are run on both OSes while the number of cores increases, revealing where each design stops scaling. Such data helps developers pick the right OS for many-core embedded platforms.
2018
Energy-Aware Task Allocation for Large Task Sets on Heterogeneous Multiprocessor SystemsYang Qin, Gang Zeng, Ryo Kurachi, Yutaka Matsubara, Hiroaki Takada
EUC 2018, pp.158-165, Bucharest, Romania, Oct 2018
This paper proposes an energy-aware method to allocate large sets of tasks on heterogeneous multiprocessors, scaling beyond exact optimization approaches. A heuristic approach finds good allocations quickly where exact optimization would take far too long. This targets realistic embedded systems with large numbers of tasks.
2017
IXM: Rapid Inter-Process Communication Middleware for Robotics SoftwareMidori Sugaya, Yutaka Matsubara, Takuma Sumiya, Miyuki Nakano
IPSJ Journal, Vol.58, No.10, pp.1578-1590
This paper presents IXM, a fast inter-process communication middleware designed for robot control software. By reducing copying and overhead in message exchange, it keeps the delay between sensing and actuation small. This supports building robot systems that respond quickly to their surroundings.
Japanese only.
2017
EV3RT: A Real-time Software Platform for LEGO Mindstorms EV3Yixiao Li, Yutaka Matsubara, Hiroaki Takada
Computer Software, Vol.34, Issue 4, pp.4_91-4_115
This paper presents EV3RT, a real-time software platform that lets developers run RTOS-based applications on the LEGO Mindstorms EV3 robot kit. It brings the TOPPERS RTOS to the EV3 hardware together with device support and a development environment. The platform is widely used in embedded systems education and robot contests.
Japanese only.
2017
IDHCC: A Security-Enhanced ID Hopping CAN Controller Design to Guarantee Real-TimeWufei Wu, Ryo Kurachi, Gang Zeng, Yutaka Matsubara, Hiroaki Takada, Renfa Li
CERTS 2017, pp.14-21, Jun 2017
This paper designs IDHCC, a CAN controller that hops message IDs for security while guaranteeing real-time message delivery. The controller changes IDs in a way both sender and receiver can follow, so protection is added without breaking communication. This design study preceded the extended IDH-CAN journal version.
2016
Security and Safety of In-Vehicle DevicesRyo Kurachi, Yutaka Matsubara, Hiroaki Takada
IPSJ Magazine, Vol.57, No.7
A review article explaining the relationship between security and functional safety for in-vehicle devices. It shows that a cyber attack can break the assumptions behind safety design, so security measures must be planned as part of functional safety. Basic attack examples and defense concepts are introduced for non-specialists.
2016
CaCAN: Centralized Authentication System in CANRyo Kurachi, Yutaka Matsubara, Hiroaki Takada, Hiroshi Ueda, Satoshi Horihata
IEICE Transactions, Vol.J99-A No.2, pp.118-130
This paper proposes CaCAN, a system in which a central monitor node authenticates messages on the CAN in-vehicle network and removes unauthorized ones. The monitor node checks message authentication codes and neutralizes unauthorized frames before they take effect. Requiring only one added node makes the scheme easy to introduce, and this is the extended journal version of the escar 2014 paper.
Japanese only.
2016
Energy-aware Task Migration for Multiprocessor Real-time SystemsGang Zeng, Yutaka Matsubara, Hiroyuki Tomiyama, Hiroaki Takada
Future Generation Computer Systems, Vol.56, pp.220-228
This paper proposes moving tasks between processors at run time to reduce energy consumption in multiprocessor real-time systems while meeting deadlines. Migration decisions weigh the cost of moving a task against the energy saved by balancing load across processors. This is the extended journal version of the authors' ICESS 2014 conference paper.
2016
An Evaluation Framework of OS-level Power Managements for the big.LITTLE ArchitectureHideki Takase, Kazumi Aono, Yutaka Matsubara, Kazuyoshi Takagi, Naofumi Takagi
2016 14th IEEE International New Circuits and Systems Conference (NEWCAS 2016), Vancouver, Jun 2016
This paper presents a framework for evaluating OS-level power management schemes on the big.LITTLE architecture, which combines fast and efficient cores. The framework runs different power management policies under the same conditions so their energy and performance can be compared fairly. Such comparisons guide OS design for energy-sensitive devices.
2015
Practical Educational Method of Embedded System with OJLNobuyuki Tachi, Masaki Yamamoto, Norihiro Yoshida, Hiroyuki Takashima, Tomoaki Unagami, Yuki Ando, Yutaka Matsubara, Shinya Honda, Hiroaki Takada
Computer Software, Vol.32, No.2, pp.79-85
This paper reports a practical education method for embedded systems based on OJL (On-the-Job Learning), where students learn through real development projects. Students tackle industry-related development tasks under mentoring, gaining skills that classroom exercises alone cannot teach. The paper shares the course design and the outcomes observed.
Japanese only.
2015
A Mobile Robot for Fall Detection for Elderly-CareTakuma Sumiya, Yutaka Matsubara, Miyuki Nakano, Midori Sugaya
KES 2015, Vol.60, pp.870-880, Singapore, Sep 2015
This paper presents a mobile robot system that detects falls of elderly people to support care services. A mobile robot can move to check on a person, complementing fixed sensors that cover only part of a home. Combining sensing and robot technology aims to reduce the burden of watching over elderly people.
Invited paper.
2015
Student Encouragement Award for Evaluation Environment of Power Management on Heterogeneous Multicore SystemsKazumi Aono, Hideki Takase, Yutaka Matsubara, Kazuyoshi Takagi, Naofumi Takagi
ESS 2015
2014
CaCAN - Centralized Authentication System in CANRyo Kurachi, Yutaka Matsubara, Hiroaki Takada, Naoki Adachi, Yukihiro Miyashita, Satoshi Horihata
Proceedings of the escar 2014 Europe, pp. 1-9, Hamburg, Nov 2014
This paper presents CaCAN, a centralized message authentication system for the CAN in-vehicle network, at the automotive security conference escar. A monitor node authenticates messages on the bus and neutralizes unauthorized ones, requiring little change to existing vehicle networks. This work was later extended into the journal version.
2014
A Simulation Environment and Preliminary Evaluation for Automotive CAN-Ethernet AVB NetworksKeigo Kawahara, Yutaka Matsubara, Hiroaki Takada
Proceedings of the 1st OMNeT++ Community Summit, pp.xx-xx, Hamburg, Sep 2014
This paper builds a simulation environment for automotive networks combining CAN and Ethernet AVB, and reports a preliminary evaluation. The model reproduces how time-sensitive traffic flows across the two network types, so designs can be examined before building hardware. Ethernet AVB matters as vehicles need more bandwidth for cameras and sensors.
2014
Task Migration for Energy Saving in Real-Time Multiprocessor SystemsGang Zeng, Yutaka Matsubara, Hiroyuki Tomiyama, Hiroaki Takada
Proceedings of the 11th IEEE International Conference on Embedded Software and Systems (ICESS 2014), Paris, Aug 2014
This paper proposes migrating tasks between processors to save energy in real-time multiprocessor systems while keeping deadlines. Moving tasks at run time balances load, so processors can run at lower speeds and consume less energy while deadlines are still met. This work formed the basis of the later journal version.
2014
A Platform for LEGO Mindstorms EV3 Based on an RTOS with MMU SupportYixiao Li, Takuya Ishikawa, Yutaka Matsubara, Hiroaki Takada
OSPERT 2014, pp.51-59, Madrid, Jul 2014
This paper presents a software platform for the LEGO Mindstorms EV3 robot kit based on an RTOS with memory protection (MMU) support. Memory protection via the MMU keeps a faulty program from corrupting the rest of the system, which is unusual for hobby-class robot kits. This platform later evolved into EV3RT.
2014
Best Poster Student Presentation Award for OMNeT++ Simulation Environment for Mixed CAN-Ethernet AVB NetworksKeigo Kawahara, Yutaka Matsubara, Hiroaki Takada
SWEST 16
2013
Safety Measures for Software Faults in Embedded SystemsYutaka Matsubara, Hiroaki Takada
Computer Software, Vol.30, No.1, pp.119-129
This paper organizes and discusses safety measures against software faults in embedded systems, such as detecting failures and keeping the system in a safe state. Since testing cannot remove every fault, systems should detect anomalies at run time and move to a safe state before harm occurs. The paper organizes concrete techniques usable in resource-limited embedded systems.
Japanese only.
2013
A Simulation Environment Based on OMNeT++ for Automotive CAN-Ethernet NetworksJun Matsumura, Yutaka Matsubara, Hiroaki Takada, Masaya Oi, Masumi Toyoshima, Akihito Iwai
WATERS 2013, pp.1-6, Paris, Jul 2013
This paper presents a simulation environment based on the OMNeT++ network simulator for automotive networks that combine CAN and Ethernet. Mixed CAN-Ethernet designs were emerging in vehicles, and the environment lets engineers evaluate such network designs on a computer. Communication design can thus be examined without a real car.
2012
schesim: Scheduling Simulator for Real-Time ApplicationsYasumasa Sano, Yutaka Matsubara, Shinya Honda, Hiroaki Takada
IEICE Transactions D, Vol.J95-D No.12, pp.2008-2020
This paper presents schesim, a simulator that reproduces how a real-time scheduler runs application tasks, useful for checking timing behavior before deployment. Developers describe their tasks and scheduling policies, and the simulator shows whether deadlines are met under various conditions. This lets timing behavior be examined without preparing target hardware.
Japanese only.
2012
An Open-Source Flexible Scheduling Simulator for Real-time ApplicationsYutaka Matsubara, Yasumasa Sano, Shinya Honda, Hiroaki Takada
ISORC 2012, pp.16-22, Shenzhen, Jun 2012
This paper presents an open-source simulator that flexibly models schedulers and real-time applications to evaluate timing behavior. Being open source, the simulator can be extended with new scheduling algorithms and reused freely in research and education. It helps developers check timing behavior without target hardware.
2011
Practice of a Summer School on Embedded System Technologies by Students and Young EngineersIttetsu Taniguchi, Yuki Ando, Hideki Takase, Takuya Azumi, Yutaka Matsubara, Shintaro Hosoai, Yasuaki Murakami, Midori Sugaya
IPSJ Journal, Vol.52, No.12, pp.3221-3237
This paper reports the practice and outcomes of a summer school on embedded system technologies organized by students and young engineers. Participants design and build an embedded system in a short period, while the young organizers themselves grow by planning and running the school. The paper analyzes the educational effects observed through this practice.
Japanese only.
2011
Probabilistic Analysis of Response Time Considering Initial Phase Distribution of Periodic TasksTakuya Ishikawa, Yutaka Matsubara, Hiroaki Takada
IPSJ Journal, Vol.52, No.12, pp.3192-3204
This paper analyzes the response time of periodic tasks probabilistically, taking into account the distribution of their initial phases (start offsets). Worst-case analysis alone is often too pessimistic, and the probabilistic view estimates how likely each response time actually is. This supports real-time designs that use resources efficiently without giving up timing confidence.
Japanese only.
2011
Hierarchical Scheduling Algorithm with Task Start Delay for Time ProtectionYutaka Matsubara, Shinya Honda, Hiroaki Takada
IPSJ Journal, Vol.52, No.8, pp.2387-2401
This paper proposes a hierarchical scheduling algorithm with task start delay that provides time protection, preventing one application from stealing CPU time from others. Deliberately delaying certain task starts makes each application's CPU budget easier to guarantee within the hierarchical scheduler. This supports consolidating separately developed applications onto one computer without interference.
Japanese only.
2011
Interruptible Priority-Inheritance Spin Lock and Its Hardware ImplementationToshiyuki Ichiba, Yutaka Matsubara, Shinya Honda, Hiroaki Takada
IPSJ ACS, Vol.4, No.3, pp.133-146
This paper proposes a spin lock with priority inheritance that can be interrupted, and implements it in hardware to reduce blocking in multiprocessor real-time systems. Ordinary spin locks can delay interrupts and urgent tasks while waiting, and the proposed lock avoids this by allowing interruption and inheriting priority. A hardware implementation keeps the overhead of the mechanism low.
Japanese only.
2011
Hierarchical Scheduling for Integrating Embedded Real-Time ApplicationsYutaka Matsubara
Doctoral Dissertation
Recommended by IPSJ SIGEMB.
2011
Recommended Doctoral Thesis DigestYutaka Matsubara
IPSJ SIGEMB recommended thesis announcement
2011
Excellent Paper Award for Scheduling Simulator with User-Defined Task ProcessingYasumasa Sano, Yutaka Matsubara, Shinya Honda, Hiroaki Takada
IPSJ Embedded System Symposium 2011
2009
Hierarchical Scheduling for Integrating Real-time Applications with Interrupt RoutinesYutaka Matsubara, Shinya Honda, Hiroaki Takada
ISOCC 2009, pp.384-387, Busan, Nov 2009
This paper proposes hierarchical scheduling that integrates multiple real-time applications while properly accounting for interrupt routines. Interrupt handling consumes CPU time at unpredictable moments, so the scheduler treats its influence explicitly when guaranteeing each application's share. This supports consolidating software onto fewer processors.
Invited paper.
2009
History of Summer School on Embedded System Technologies Organized by Students and Young EngineersHideki Takase, Takuya Azumi, Ittetsu Taniguchi, Yutaka Matsubara, Hayato Kanai, Shintaro Hosoai, Midori Sugaya
WESE 2009, pp.19-26, Grenoble, Oct 2009
This paper reports the history and lessons of a summer school on embedded system technologies organized by students and young engineers in Japan. It looks back on how the peer-run format developed and what kept participants engaged. The lessons are useful for others planning hands-on engineering education.
2008
Flexible Scheduling Framework for Integrating Real-Time ApplicationsYutaka Matsubara, Shinya Honda, Hiroyuki Tomiyama, Hiroaki Takada
IPSJ Journal Embedded Systems Special Issue, Vol.49, No.10, pp.3508-3519
This paper presents a flexible scheduling framework that lets multiple real-time applications with different scheduling needs run together on one system. Each application keeps its own scheduling policy while the framework arbitrates CPU time among them. This eases integrating software components that were developed separately.
Japanese only.
2008
TOPPERS of the Year 2008 for Automotive RTOS with Memory and Time ProtectionHiroyuki Hattori, Shuichi Onishi, Ayumu Kataoka, Yutaka Matsubara, Hiroaki Takada
TOPPERS Project
2008
IP Excellence Award for Open-Source Protected OS: Automotive RTOS with Memory and Time ProtectionHiroyuki Hattori, Shuichi Onishi, Ayumu Kataoka, Yutaka Matsubara, Hiroaki Takada
10th LSI IP Design Award
2007
Real-Time Scheduling Algorithm for Time ProtectionYutaka Matsubara, Shinya Honda, Hiroyuki Tomiyama, Hiroaki Takada
IPSJ ACS, Vol.48 SIG8(ACS18), pp.192-202
This paper proposes a real-time scheduling algorithm that provides time protection, guaranteeing each application its share of CPU time even if another misbehaves. The scheduler enforces a CPU budget for each application, so a fault in one cannot starve the others. This idea underpins safely consolidating multiple functions onto one processor.
Japanese only.
2007
SSEST: Summer School on Embedded System TechnologiesYutaka Matsubara, Midori Sugaya, Ittetsu Taniguchi, Yasuaki Murakami, Hayato Kanai, Hiroaki Takada
APESER 2007, pp.1-8, Hsinchu, Dec 2007
This paper introduces SSEST, a summer school on embedded system technologies run by students and young engineers, and its educational approach. Participants team up to develop an embedded system in a short period, experiencing the process from design to demonstration. The paper shares the curriculum and how the school is run, so similar programs can be built elsewhere.
Trust in connected devices
2025
Enhancing Account Information Anonymity in Blockchain-Based IoT Access Control Using Zero-Knowledge ProofsYuxiao Wu, Yutaka Matsubara, Shoji Kasahara
Electronics, Vol.14, Issue 14
This paper uses zero-knowledge proofs to hide account information in blockchain-based access control for IoT devices, improving user privacy. Users can prove they have the right to access a device without revealing which account they are, so records on the public blockchain leak less personal information. This addresses the tension between blockchain transparency and privacy.
2025
SSI-Enabled Authentication and Enhanced Metadata Search in Blockchain-based Decentralized IoT Data PlatformsLuyonghe Li, Yuichiro Yasue, Yutaka Matsubara
IEEE 1st International Workshop on Blockchain for Decentralized Trust and Digital Identity (B4TI) at BCCA 2025, Croatia, Oct 2025
This paper adds self-sovereign identity (SSI) based authentication and better metadata search to blockchain-based decentralized IoT data platforms. With SSI, users control their own identity credentials instead of depending on a central provider, which matches the decentralized nature of the platform. Improved metadata search also makes shared IoT data easier to find and use.
2025
PPDS: A Practical and Privacy-Preserving Data Sharing Model for Blockchain-Based IoT e-Health Systems Using ECC, Zero-Knowledge Proof, and Access ControlYuxiao Wu, Kenta Kawai, Yutaka Matsubara
IEEE International Conference on Blockchain Computing and Applications (BCCA 2025), Croatia, Oct 2025
This paper proposes PPDS, a data sharing model for blockchain-based IoT healthcare systems that protects privacy using elliptic curve cryptography, zero-knowledge proofs, and access control. Health data is sensitive, so the model lets patients share records with the right parties while keeping identities and contents protected. The cryptographic building blocks are combined with practicality on IoT devices in mind.
2025
Flexible Edge Processing in Blockchain-based Secure IoT Data Distribution FrameworkKenta Kawai, Yuxiao Wu, Yutaka Matsubara, Hiroaki Takada
BRAIN 2025 at PerCom 2025, Washington D.C., Mar 2025
This paper adds flexible edge processing to a blockchain-based framework for secure IoT data distribution, so data can be processed near its source. Processing data near where it is generated reduces network traffic and avoids sending raw personal data to distant servers. The blockchain still guarantees trust in the exchanged results.
2022
Excellent Paper Award for Software Update Framework for IoT Devices Using BlockchainRyota Nakanishi, Yutaka Matsubara, Hiroaki Takada
DICOMO 2022
2020
Tsunagaru! Kiso Gijutsu IoT Nyumon (Chapter 2: Security)Harumi Watanabe, Makoto Imamura, Kenji Hisazumi (eds.)
Corona Publishing
An introductory textbook chapter on security for IoT systems, explaining basic threats and countermeasures for connected devices. It walks through how attackers can reach devices over the network and what basic defenses such as encryption and authentication do. The chapter is written for students taking their first steps into IoT.
Yutaka Matsubara authored Chapter 2.
2017
Automotive Security and IoTYutaka Matsubara
Kinou Zairyo, Jun. 2017 serial article
A review article introducing the current state of automotive security in the context of the IoT era. It describes how connecting cars to networks and smartphones creates new attack paths, and outlines the countermeasures the industry is adopting. The article is written to be accessible to readers outside the software field.
Trust in systems of systems
2026
A Multi-Agent Reinforcement Learning Based Resilience Engineering Method for Mobility-as-a-ServiceZhengshu Zhou, Weijie Yu, Tingting Zhao, Qian Long, Yutaka Matsubara, Hiroaki Takada
IEEE Transactions on Network and Service Management, Vol.23, pp.2135-2148
This paper proposes a method that uses multi-agent reinforcement learning to improve the resilience of Mobility-as-a-Service, so that transport services can keep working when disruptions occur. Each agent learns through trial and error how to adjust operations, and together they restore service when parts of the network fail. This helps transport operators prepare for disruptions such as accidents or outages.
2026
A System-of-Systems Resilience Analysis Framework Based on Stackelberg Evolution GameHuanjun Zhang, Yutaka Matsubara
21st International Conference on System of Systems Engineering (SoSE 2026), Kongsberg, Norway, Jun.-Jul. 2026
This paper proposes a framework that analyzes the resilience of a system of systems using a Stackelberg evolution game, a model of leader-follower strategic interaction. A leading constituent moves first and the others adapt, and analyzing this interaction shows how cooperation and self-interest shape recovery from disruptions. The framework helps designers anticipate how an SoS behaves under stress.
2026
Governance as a Structural Design Variable: An Empirical Study of Performance-Autonomy Value Spaces in Systems of SystemsChihiro Shimoyama, Yutaka Matsubara
21st International Conference on System of Systems Engineering (SoSE 2026), Kongsberg, Norway, Jun.-Jul. 2026
This paper empirically studies how governance choices in a system of systems shape the trade-off between overall performance and the autonomy of member systems. Stronger central control tends to raise overall performance but reduces each member's freedom, and the study maps this value space through experiments. The results help architects choose a governance style deliberately rather than by default.
2025
ArchiMate-Based System of Systems Resilience Evaluation ApproachHuanjun Zhang, Yutaka Matsubara
Systems, Vol.13, Issue 5
This paper proposes a way to evaluate the resilience of a system of systems using ArchiMate, a standard enterprise architecture modeling language. Describing the member systems and their dependencies as a model makes it possible to estimate how failures propagate and how well services recover. This gives designers a common notation for discussing resilience.
2025
Consensus Based Resilience Assurance for System of SystemsHuanjun Zhang, Yutaka Matsubara
IEEE Access, Vol.13, pp.20203-20217
This paper proposes a consensus-based process in which the stakeholders of a system of systems agree on how much resilience is enough and how to assure it. Because no single organization controls an SoS, resilience targets must be negotiated rather than imposed, and the paper turns that negotiation into a structured process. This helps independently managed systems cooperate toward dependable services.
2025
A Decision Support Scheme for Safe and Efficient Transportation of Hazardous MaterialsZhengshu Zhou, Yutaka Matsubara, Hiroaki Takada
IEEE Transactions on Intelligent Transportation Systems, Vol.26, Issue 1, pp.309-322
This paper proposes a decision support scheme that helps plan hazardous material transportation routes considering both safety and efficiency. Candidate routes and plans are compared from both risk and cost viewpoints, and the trade-offs are presented to decision makers. This supports realistic planning where safety and economics must be balanced.
2025
A Dynamic Resilience Research for Acknowledged System-of-systems Based on a Stackelberg Evolutionary GameHuanjun Zhang, Yutaka Matsubara
The 9th International Conference on System Reliability and Safety (ICSRS 2025), Italy, Nov 2025
This paper studies the dynamic resilience of an acknowledged system of systems using a Stackelberg evolutionary game model. The game captures how a coordinating leader and independent constituents adjust their strategies over time after disruptions. This dynamic view complements resilience assessments that only look at a single point in time.
2025
Improving Airport Baggage Handling System Efficiency with Simulation-Based DesignChenda Siv, Yutaka Matsubara, Hiroaki Takada
2nd IEOM World Congress on Industrial Engineering and Operations Management, Canada, Oct 2025
This paper uses simulation-based design to analyze and improve the efficiency of an airport baggage handling system. A simulation model of the conveying and sorting process reproduces congestion, letting designers compare layouts and operating policies. Improvement ideas can thus be tried without stopping the real large-scale facility.
2025
Co-evolution Guidebook (HMCES Guidebook)Daichi Mizuguchi, Akihisa Morikawa, Yutaka Matsubara, Kiyoshi Fujiwara
HMCES Project
2025
Kyoshinka GuidebookDaichi Mizuguchi, Akihisa Morikawa, Yutaka Matsubara, Kiyoshi Fujiwara
HMCES Project
2025
Enhancing Human-Robot Collaboration through Existing Guidelines: A Case Study ApproachYutaka Matsubara, Akihisa Morikawa, Daichi Mizuguchi, Kiyoshi Fujiwara
HMCES Project
2024
Comprehensive Dependability for Automated Driving: Lessons from the PEGASUS Project and Level-4 Automated Driving ServicesYutaka Matsubara
Journal of Society of Automotive Engineers of Japan, Jan. 2024 Special Issue on Innovation Governance
A review article discussing how to assure the overall dependability of automated driving, drawing lessons from Germany's PEGASUS project and Level-4 driving services. It looks at both the technical side, such as scenario-based testing, and the societal side, such as rules and governance for operating services. Readers get a broad picture of what dependable automated driving actually requires.
2024
AI2X Co-evolution Guidebook and Case Study for Human-centered AI FrameworkAkihisa Morikawa, Yutaka Matsubara, Daichi Mizuguchi, Kiyoshi Fujiwara
SAFECOMP 2024 Position Paper, Florence, Sep 2024
This position paper introduces a guidebook and case study from the AI2X co-evolution project, which aims at human-centered frameworks where AI and society develop together. The guidebook distills how organizations can introduce AI while keeping humans central, and the case study shows the ideas applied in practice. It follows up the project introduction presented at SAFECOMP 2023.
2024
Reaching Consensus on System-of-systems Resilience Assurance: A Case of Mobility as a ServiceHuanjun Zhang, Yutaka Matsubara, Hiroaki Takada
SASSUR 2024 at SAFECOMP 2024, LNCS Vol.14989, pp.200-212, Florence, Sep 2024
This paper proposes a process for stakeholders to reach consensus on resilience assurance of a system of systems, using Mobility-as-a-Service as a case study. The process makes each stakeholder's assumptions and requirements explicit and reconciles them step by step into an agreed argument. It focuses on inter-organizational agreement, not just technology.
2023
Resilience Analysis and Design for Mobility-as-a-Service Based on Enterprise Architecture ModelingZhengshu Zhou, Yutaka Matsubara, Hiroaki Takada
Reliability Engineering & System Safety, Vol.229
This paper proposes an enterprise-architecture-based method to analyze and design the resilience of Mobility-as-a-Service systems. The service is modeled as a whole, covering not only IT systems but also the organizations and business processes around them, so weak points can be found across the entire structure. This supports designing transport services that keep running through failures.
2023
Developing Reliable Digital Healthcare Service Using Semi-Quantitative Functional Resonance AnalysisZhengshu Zhou, Yutaka Matsubara, Hiroaki Takada
Computer Systems Science and Engineering, Vol.45, No.1, pp.35-50
This paper applies a semi-quantitative version of FRAM, a method for analyzing how everyday performance variability interacts, to improve the reliability of digital healthcare services. Assigning rough numeric scores to how much each activity varies helps identify where small everyday variations can combine into service failures. This is useful for services where people, devices, and software work closely together.
2023
A Quantitative Approach for System of Systems’ Resilience Analyzing Based on ArchiMateHuanjun Zhang, Yutaka Matsubara, Hiroaki Takada
DECSoS 2023 at SAFECOMP 2023, LNCS Vol.14489, pp.47-60, Toulouse, Sep 2023
This paper proposes a quantitative method for analyzing the resilience of a system of systems based on ArchiMate architecture models. Assigning quantitative measures to model elements lets designers compare where reinforcement improves resilience most. This supports spending limited resources where they matter.
2023
Toward Human-centered AI Framework: An Introduction to AI2X Co-evolution ProjectYutaka Matsubara, Akihisa Morikawa, Daichi Mizuguchi, Kiyoshi Fujiwara
SAFECOMP 2023 Position Paper, Toulouse, Sep 2023
This position paper introduces the AI2X co-evolution project, which explores frameworks for human-centered AI in society. It outlines why AI systems and the society using them must adapt to each other, and sets out the project's research agenda. The paper positions the challenges of deploying AI safely in society.
2021
Best Presentation Award for Resilience Engineering Method for Improving Reliability of MaaSZhengshu Zhou, Yutaka Matsubara, Hiroaki Takada
DSW 2021
2020
CASE Revolution and Cybersecurity in the Automotive DomainYutaka Matsubara, Ryo Kurachi, Hiroaki Takada
IPSJ Magazine, Vol.61, No.4, pp.338-343
A review article on how the CASE trend (Connected, Autonomous, Shared, Electric) changes cybersecurity requirements for vehicles. As cars connect to networks and receive software updates remotely, attackers gain new entry points, so defenses must span the whole lifecycle from development to operation. The article summarizes these shifts for readers outside the automotive field.
2020
Towards Identifying and Closing Gaps in Assurance of Autonomous Road Vehicles: Technical Notes Part 2Robin Bloomfield, Gareth Fletcher, Heidy Khlaaf, Philippa Ryan, Shuji Kinoshita, Yoshiki Kinoshita, Makoto Takeyama, Yutaka Matsubara, Peter Popov, Kazuki Imai, Yoshinori Tsutake
TIGARS Project
2020
Towards Identifying and Closing Gaps in Assurance of Autonomous Road Vehicles: Technical Notes Part 1Robin Bloomfield, Gareth Fletcher, Heidy Khlaaf, Philippa Ryan, Shuji Kinoshita, Yoshiki Kinoshita, Makoto Takeyama, Yutaka Matsubara, Peter Popov, Kazuki Imai, Yoshinori Tsutake
TIGARS Project
2018
Trends and Prospects in Safety and Security for Connected Cars and SocietyYutaka Matsubara, Ryo Kurachi, Hiroaki Takada
Jidosha Gijutsu, Vol.72, No.5, pp.87-93
A review article surveying safety and security trends for connected cars and the surrounding connected society. It explains why safety, which protects people from failures, and security, which protects systems from attacks, must be considered together once vehicles are networked. Related standards and research directions are also introduced.
2017
Trends and Prospects in Automotive Safety and Security Toward Autonomous DrivingYutaka Matsubara, Ryo Kurachi, Hiroaki Takada
IPSJ Magazine, Vol.58, No.11
A review article surveying automotive safety and security technologies needed to realize autonomous driving. It explains how safety design against failures and defenses against cyber attacks influence each other, and why both are prerequisites for self-driving cars. The article suits readers who want an overview before studying individual technologies.
Cross-cutting theme
2026
Outlier-Ratio Feature Augmentation for Graph-based Intrusion Detection in CAN NetworksAkari Sasaki, Ryo Kurachi, Yutaka Matsubara, Hiroaki Takada
IEEE Consumer Communications & Networking Conference (CCNC 2026), Las Vegas, Jan. 2026
This paper improves graph-based intrusion detection for the CAN in-vehicle network by adding outlier-ratio features that highlight abnormal message patterns. Messages are modeled as a graph, and the ratio of outlier messages is added as a feature to help separate attacks from normal traffic. Better detection matters because CAN itself has no built-in security.
2025
Transforming Concurrent Programs with Semaphores into Logically Constrained Term Rewrite SystemsMisaki Kojima, Naoki Nishida, Yutaka Matsubara
Journal of Logical and Algebraic Methods in Programming, Vol.143, pp.1-23
This paper shows how to translate concurrent programs that use semaphores into logically constrained term rewrite systems, a formal model that enables mathematical verification. Once a program is expressed as a rewrite system, existing analysis techniques can rigorously reason about its concurrent behavior. This is the extended journal version of the authors' earlier workshop work.
2024
Multilingual Investigation of Cross-Project Code Clones in Open-Source Software for Internet of Things SystemsWenqing Zhu, Norihiro Yoshida, Yutaka Matsubara, Hiroaki Takada
IEEE Access, Vol.12, pp.179104-179118
This paper investigates code clones (copied code fragments) across open-source IoT projects in multiple programming languages, which matters for propagating bug fixes. When the same code exists in many projects, a bug fixed in one place may remain in others, so knowing where clones are helps maintainers propagate fixes. Covering clones across different languages, which are usually harder to track, is a key feature of the study.
2024
Detecting Concurrency Bugs with Feedback-guided FuzzingHiromasa Ito, Yutaka Matsubara, Hiroaki Takada
IPSJ Journal, Vol.65, No.5, pp.927-941
This paper presents a fuzzing technique guided by feedback about thread interleavings to find concurrency bugs, which are hard to reproduce with ordinary testing. The tool observes which thread execution orders have been explored and steers testing toward unexplored, suspicious ones. This is the extended journal version of the Schfuzz work presented at ENASE 2023.
Japanese only.
2024
Race Directed Fuzzing for More Effective Concurrency TestingHiromasa Ito, Yutaka Matsubara, Hiroaki Takada
The 6th International Workshop on Software Science and Engineering (WSSE 2024), Kyoto, Aug 2024
This paper proposes race directed fuzzing, which steers automated testing toward suspicious thread interleavings to find concurrency bugs more effectively. Instead of exploring interleavings blindly, the method prioritizes ones where data races are likely, spending testing effort where bugs hide. Concurrency bugs are among the hardest to reproduce, which makes such targeting valuable.
2023
Schfuzz: Detecting Concurrency Bugs with Feedback-Guided FuzzingHiromasa Ito, Yutaka Matsubara, Hiroaki Takada
18th International Conference on Evaluation of Novel Approaches to Software Engineering (ENASE 2023), Prague, pp.273-282, Apr 2023
This paper presents Schfuzz, a tool that finds concurrency bugs by fuzzing thread schedules with feedback guidance. Rather than fuzzing input data, Schfuzz fuzzes the order in which threads run, using feedback from past executions to guide exploration. This work formed the basis of the later journal version.
2022
Design and Implementation of RTOS-Aware Control-Flow Integrity Mechanism for Microcontroller-Based SystemsTomoaki Kawada, Shinya Honda, Yutaka Matsubara, Hiroaki Takada
Computer Software, Vol.39, No.2
This paper designs a control-flow integrity mechanism, a defense that stops attackers from hijacking program execution, tailored to RTOS-based microcontroller systems. The mechanism is designed to keep protecting the system even when the RTOS switches tasks and handles interrupts, situations that ordinary CFI designs do not consider. This strengthens small embedded devices that are hard to patch after deployment.
Japanese only.
2022
Zengo Award for Coverage-based Greybox Fuzzing Applied to MiddlewareHiromasa Ito, Yutaka Matsubara, Hiroaki Takada
ASTER
2021
How to Test Middleware with Coverage-based Greybox FuzzingHiromasa Ito, Yutaka Matsubara, Hiroaki Takada
IPSJ Journal, Vol.62, pp.877-890
This paper shows how to apply coverage-based greybox fuzzing, an automated bug-finding technique, to middleware, which is harder to test than standalone programs. The approach prepares harnesses that drive the middleware and uses coverage feedback to steer generated inputs toward unexplored code. This brings a proven bug-finding technique to software it did not directly fit.
Japanese only.
2021
Quantitative Security Assurance Case for In-vehicle Embedded SystemsZhengshu Zhou, Yutaka Matsubara, Hiroaki Takada
CyberSciTech/PICom/DASC/CDBCom 2021, pp.43-50, Oct 2021
This paper proposes building quantitative security assurance cases, structured arguments with numeric evidence, for in-vehicle embedded systems. Adding numeric evidence to the structured argument makes it easier to judge whether security measures are sufficient and to compare alternatives. This helps explain the validity of security decisions to third parties.
2020
Tsunagaru! Kiso Gijutsu IoT Nyumon (Chapter 2: Security)Harumi Watanabe, Makoto Imamura, Kenji Hisazumi (eds.)
Corona Publishing
An introductory textbook chapter on security for IoT systems, explaining basic threats and countermeasures for connected devices. It walks through how attackers can reach devices over the network and what basic defenses such as encryption and authentication do. The chapter is written for students taking their first steps into IoT.
Yutaka Matsubara authored Chapter 2.
2020
CASE Revolution and Cybersecurity in the Automotive DomainYutaka Matsubara, Ryo Kurachi, Hiroaki Takada
IPSJ Magazine, Vol.61, No.4, pp.338-343
A review article on how the CASE trend (Connected, Autonomous, Shared, Electric) changes cybersecurity requirements for vehicles. As cars connect to networks and receive software updates remotely, attackers gain new entry points, so defenses must span the whole lifecycle from development to operation. The article summarizes these shifts for readers outside the automotive field.
2020
TZmCFI: RTOS-Aware Control-Flow Integrity Using TrustZone for Armv8-MTomoaki Kawada, Shinya Honda, Yutaka Matsubara, Hiroaki Takada
International Journal of Parallel Programming, Vol.49, pp.136-150
This paper presents TZmCFI, a control-flow integrity mechanism for small Arm microcontrollers that uses the TrustZone security feature and works correctly with an RTOS. TrustZone provides an isolated area that attackers cannot tamper with, and the mechanism keeps its protection consistent across task switches and interrupts. This defends small devices that lack the hardware protections of larger computers.
2020
Agile Software Design Verification and Validation (V&V) for Automated DrivingYixiao Li, Yutaka Matsubara, Daniel Olbrys, Kazuhiro Kajio, Hiroaki Takada
Proceedings of FISITA 2020, Oct 2020
This paper discusses an agile approach to verification and validation of automated driving software, enabling frequent checks during iterative development. Automating checks and integrating them into each development iteration keeps quality visible as the software evolves rapidly. This aims to reconcile development speed with safety assurance.
2020
Transforming Concurrent Programs with Semaphores into Logically Constrained Term Rewrite SystemsMisaki Kojima, Naoki Nishida, Yutaka Matsubara
Informal Proceedings of WPTE 2020, Jun 2020
This workshop paper presents a translation from concurrent programs using semaphores into logically constrained term rewrite systems for formal analysis. Expressing programs as rewrite systems opens the door to mathematically rigorous verification of concurrent behavior. This work later grew into the extended journal version.
2020
Safety Design Concepts for Statistical Machine Learning Components toward Accordance with Functional Safety StandardsAkihisa Morikawa, Yutaka Matsubara
SEAMS Project
2020
Selected Paper Award for Coverage-based Greybox Fuzzing Applied to MiddlewareHiromasa Ito, Yutaka Matsubara, Hiroaki Takada
IPSJ Journal, Vol.62, No.3
Japanese only.
2019
Shadow Exception Stacks: Control-Flow Integrity for Asynchronous Exceptions Using TrustZone for Armv8-MTomoaki Kawada, Shinya Honda, Yutaka Matsubara, Hiroaki Takada
IESS 2019, LNCS Vol.11937, pp.56-71, Friedrichshafen, Nov 2019
This paper proposes shadow exception stacks, which extend control-flow integrity protection to interrupt handling on Arm microcontrollers using TrustZone. Interrupts complicate control-flow protection because they can occur at any moment, and the shadow stacks record return paths safely inside TrustZone. This addresses a gap left by CFI schemes that ignore asynchronous exceptions.
2018
Trends and Prospects in Safety and Security for Connected Cars and SocietyYutaka Matsubara, Ryo Kurachi, Hiroaki Takada
Jidosha Gijutsu, Vol.72, No.5, pp.87-93
A review article surveying safety and security trends for connected cars and the surrounding connected society. It explains why safety, which protects people from failures, and security, which protects systems from attacks, must be considered together once vehicles are networked. Related standards and research directions are also introduced.
2018
IDH-CAN: A Hardware-Based ID Hopping CAN Mechanism With Enhanced Security for Automotive Real-Time ApplicationsWufei Wu, Ryo Kurachi, Gang Zeng, Yutaka Matsubara, Hiroaki Takada, Renfa Li, Keqin Li
IEEE Access, Vol.6, pp.54607-54623
This paper proposes IDH-CAN, a hardware mechanism that periodically changes CAN message IDs to make attacks on in-vehicle networks harder while preserving real-time behavior. Because CAN messages are normally identified by fixed IDs, hopping them deprives attackers of an easy target. Implementing the hopping in hardware keeps message timing predictable, which is essential for control systems.
2018
Safety Analysis Examples in Compliance with ISO 26262 for TOPPERS/ATK2 Conforming to the AUTOSAR OS SpecificationMorio Mori, Hideaki Sato, Akira Yamashita, Yutaka Matsubara, Hiroaki Takada
IPSJ Journal, Vol.59, No.2, pp.785-794
This paper reports safety analysis examples for the TOPPERS/ATK2 automotive OS, conducted to comply with the ISO 26262 functional safety standard. The examples show concretely how to apply safety analysis techniques to an RTOS, a component that many automotive products share. Published examples like these help practitioners facing the same certification work.
Japanese only.
2018
FRAM/STPA: Hazard Analysis Method for FRAM ModelYoshinari Toda, Yutaka Matsubara, Hiroaki Takada
FRAMily 2018, pp.1-17, Cardiff, Jun 2018
This paper proposes FRAM/STPA, a hazard analysis method that applies STPA-style control analysis to FRAM models of everyday performance variability. FRAM shows how variability spreads among functions, while STPA asks which control actions become unsafe, and combining them finds hazards that either method alone may miss. This suits complex systems where people and technology interact.
2017
Trends and Prospects in Automotive Safety and Security Toward Autonomous DrivingYutaka Matsubara, Ryo Kurachi, Hiroaki Takada
IPSJ Magazine, Vol.58, No.11
A review article surveying automotive safety and security technologies needed to realize autonomous driving. It explains how safety design against failures and defenses against cyber attacks influence each other, and why both are prerequisites for self-driving cars. The article suits readers who want an overview before studying individual technologies.
2017
Automotive Security and IoTYutaka Matsubara
Kinou Zairyo, Jun. 2017 serial article
A review article introducing the current state of automotive security in the context of the IoT era. It describes how connecting cars to networks and smartphones creates new attack paths, and outlines the countermeasures the industry is adopting. The article is written to be accessible to readers outside the software field.
2017
IDHCC: A Security-Enhanced ID Hopping CAN Controller Design to Guarantee Real-TimeWufei Wu, Ryo Kurachi, Gang Zeng, Yutaka Matsubara, Hiroaki Takada, Renfa Li
CERTS 2017, pp.14-21, Jun 2017
This paper designs IDHCC, a CAN controller that hops message IDs for security while guaranteeing real-time message delivery. The controller changes IDs in a way both sender and receiver can follow, so protection is added without breaking communication. This design study preceded the extended IDH-CAN journal version.
2016
HAZOP-Based Security Analysis for Embedded Systems: Case Study of Open Source Immobilizer Protocol StackJingxuan Wei, Yutaka Matsubara, Hiroaki Takada
Recent Advances in Systems Safety and Security, Springer, pp.79-96
A book chapter that applies HAZOP, a systematic hazard analysis technique, to find security weaknesses in an open-source car immobilizer protocol stack. Guide words describing deviations from intended behavior are reinterpreted from a security viewpoint, turning a safety method into a way to find attack-relevant flaws. The chapter is an expanded version of the authors' earlier workshop study.
2016
Security and Safety of In-Vehicle DevicesRyo Kurachi, Yutaka Matsubara, Hiroaki Takada
IPSJ Magazine, Vol.57, No.7
A review article explaining the relationship between security and functional safety for in-vehicle devices. It shows that a cyber attack can break the assumptions behind safety design, so security measures must be planned as part of functional safety. Basic attack examples and defense concepts are introduced for non-specialists.
2016
CaCAN: Centralized Authentication System in CANRyo Kurachi, Yutaka Matsubara, Hiroaki Takada, Hiroshi Ueda, Satoshi Horihata
IEICE Transactions, Vol.J99-A No.2, pp.118-130
This paper proposes CaCAN, a system in which a central monitor node authenticates messages on the CAN in-vehicle network and removes unauthorized ones. The monitor node checks message authentication codes and neutralizes unauthorized frames before they take effect. Requiring only one added node makes the scheme easy to introduce, and this is the extended journal version of the escar 2014 paper.
Japanese only.
2015
HAZOP-based Security Analysis for Embedded Systems: Case Study of Open Source Immobilizer Protocol StackJingxuan Wei, Yutaka Matsubara, Hiroaki Takada
Proceedings of the 3rd International Workshop on Systems Safety & Security (IWSSS2015), Bucharest, Jun 2015
This paper applies HAZOP, a systematic deviation analysis technique, to security analysis of an open-source car immobilizer protocol stack. Guide words describing deviations from intended behavior are reinterpreted for security, turning a safety technique into a way to find attack-relevant weaknesses. This study was later expanded into a book chapter.
2014
CaCAN - Centralized Authentication System in CANRyo Kurachi, Yutaka Matsubara, Hiroaki Takada, Naoki Adachi, Yukihiro Miyashita, Satoshi Horihata
Proceedings of the escar 2014 Europe, pp. 1-9, Hamburg, Nov 2014
This paper presents CaCAN, a centralized message authentication system for the CAN in-vehicle network, at the automotive security conference escar. A monitor node authenticates messages on the bus and neutralizes unauthorized ones, requiring little change to existing vehicle networks. This work was later extended into the journal version.
2013
Safety Measures for Software Faults in Embedded SystemsYutaka Matsubara, Hiroaki Takada
Computer Software, Vol.30, No.1, pp.119-129
This paper organizes and discusses safety measures against software faults in embedded systems, such as detecting failures and keeping the system in a safe state. Since testing cannot remove every fault, systems should detect anomalies at run time and move to a safe state before harm occurs. The paper organizes concrete techniques usable in resource-limited embedded systems.
Japanese only.
2013
Safety Analysis Method Based on Hierarchical State Transition Diagram for Embedded SystemsZoohaye Kim, Yutaka Matsubara, Hiroaki Takada
IEICE Transactions, Vol.J96-A No.1, pp.34-48
This paper proposes a safety analysis method that uses hierarchical state transition diagrams to systematically find hazardous behaviors in embedded systems. Organizing states into a hierarchy keeps the analysis manageable even when the system has many states. This helps find dangerous behaviors at the design stage, before accidents can happen.
Japanese only.
2012
Safety Analysis Method Focusing on State Transition DiagramsZoohaye Kim, Yutaka Matsubara, Hiroaki Takada
IEICE Transactions, Vol.J95-A No.2, pp.198-209
This paper proposes a safety analysis method that examines state transition diagrams to find conditions under which an embedded system can reach hazardous states. Because state transition diagrams are already common in embedded design, engineers can reuse familiar models for safety analysis instead of building new ones. This helps prevent accidents by catching dangerous conditions at the design stage.
Japanese only.
2012
Safety Analysis Method Based on Parallel State Transition Diagram for Embedded SystemsZoohaye Kim, Yutaka Matsubara, Hiroaki Takada
SEA 2012, pp.417-425, Las Vegas, Nov 2012
This paper proposes a safety analysis method for embedded systems based on parallel state transition diagrams, handling components that operate concurrently. Unexpected combinations of concurrently operating components are a common source of hazards, and the parallel diagrams make such combinations explicit for analysis. This helps find dangerous behaviors systematically at the design stage.