Keynote Speakers


Safety in Physical AI: an Operating Systems Perspective

Artificial Intelligence is rapidly moving out of datacenters and into the physical world. We will soon be living among highly autonomous machines, including humanoid robots, autonomous vehicles, and military systems that, until recently, belonged to science fiction and to our nightmares. As this transition unfolds, safety moves from being a desirable property of individual systems to becoming a fundamental condition for our coexistence of increasingly autonomous machines. Nevertheless, the operating systems that are supporting this revolution have changed surprisingly little beyond the classic task-centric, real-time, network-capable, and cryptographically-enriched services envisioned more than 40 years ago. They provide mechanisms for executing and isolating software, managing resources, and meeting timing constraints, but offer much less support for continuously enforcing the physical safety constraints governing autonomous behavior.

This talk explores this challenge from the perspective of SmartData, a concept developed at LISHA/UFSC over the past decade to address some of the fundamental limitations of making Sense–Compute–Communicate–Actuate loops more AI-ready while keeping their safety continuously observable and enforceable. The approach builds safety models around the same physical laws that govern the behavior of the systems, bringing those models into the computing infrastructure rather than leaving safety entirely to application-level logic. Autonomous vehicles being developed at UFSC provide a concrete case background for discussing this perspective and its implications for the operating systems of Physical AI.


From Fault Injection to Directed Fuzzing: Making Dependability and Security Testing More Intelligent

Modern computing systems have become increasingly complex, making failure diagnosis and vulnerability discovery difficult due to the enormous space of faults, execution paths, system states, and program inputs. A key question is therefore: how can we make testing more intelligent by guiding it toward the system behaviors that matter most?

In this talk, Prof. Wang will present his research journey in dependability and security testing. He first explored targeted fault injection for distributed-system failure diagnosis, followed by techniques for capturing and analyzing service-request execution paths. More recently, he extended these ideas to path-based system analysis, where path tracing supports failure diagnosis and path-aware fault injection helps uncover cross-layer vulnerabilities.

Prof. Wang will then discuss how the same principle applies to directed fuzzing. IDFuzz uses information learned from fuzzing executions to guide mutations toward target code, while TrigFuzz goes beyond code reachability by using large language models to identify vulnerability-triggering conditions and guide fuzzing toward inputs that satisfy them.

These studies illustrate a common direction: making testing more effective by progressively incorporating richer knowledge of system structure, execution behavior, and program semantics.


When Are Failures Observable? System Models, Fault Models, and the Limits of Dependable Distributed Computing

Distributed systems do not observe failures directly; they observe events—or the absence of expected events. Whether such observations indicate a crash, a timing violation, Byzantine behavior, or merely slow execution depends fundamentally on the underlying system model. In this sense, observability precedes detectability: observability concerns whether faulty behavior is distinguishable from admissible behavior under a given model, whereas detectability concerns whether an algorithm can exploit that distinction.

This keynote explores the interplay between system and fault models, from classical synchrony and asynchrony to partial synchrony and alternative models of progress. We examine how assumptions about timing, communication, process behavior, redundancy, and application semantics determine which failures are observable and detectable and, ultimately, which distributed problems can be solved. When perfect detection is impossible, weaker guarantees and quantitative measures of detection quality become necessary.

Theoretical guarantees, however, are meaningful in practice only when model assumptions adequately
represent the execution environment. We therefore consider assumption coverage: the extent to which
such assumptions can be justified by design, empirical observation, or runtime evidence.

The talk concludes with the Eventual Relative-Speed (ERS) model, which takes a less conventional perspective on fail-silent behavior. Rather than inferring failure directly from elapsed physical time, ERS characterizes process activity through relative logical progress. After stabilization, correct processes remain within a bounded logical divergence; consequently, a process that persistently falls behind the evolving causal structure becomes distinguishable from correct processes. This enables adaptive failure detection based on logical divergence and illustrates the keynote’s central argument: observability, detectability, and computability are inseparable from the system model and the extent to which its assumptions hold in reality.