Keynote Speakers

Antônio Augusto Fröhlich
Federal University of Santa Catarina, Brazil
Short Bio
Antônio Augusto Fröhlich is a full professor at the Federal University of Santa Catarina (UFSC), where he leads the Software and Hardware Integration Laboratory (LISHA) since 2001. He holds a PhD in Computer Engineering from the Technical University of Berlin (2001) and was a visiting researcher at the University of Paderborn (2007), at the University of California, Irvine (2016) and at the University of Luxembourg (2017). He has coordinated several RD&I projects in secure, connected and intelligent cyber-physical systems. Significant contributions from these projects have been incorporated into products developed by partner industries in the sectors of energy, industry automation and mobility.
Safety in Physical AI: an Operating Systems Perspective
Artificial Intelligence is rapidly moving out of datacenters and into the physical world. We will soon be living among highly autonomous machines, including humanoid robots, autonomous vehicles, and military systems that, until recently, belonged to science fiction and to our nightmares. As this transition unfolds, safety moves from being a desirable property of individual systems to becoming a fundamental condition for our coexistence of increasingly autonomous machines. Nevertheless, the operating systems that are supporting this revolution have changed surprisingly little beyond the classic task-centric, real-time, network-capable, and cryptographically-enriched services envisioned more than 40 years ago. They provide mechanisms for executing and isolating software, managing resources, and meeting timing constraints, but offer much less support for continuously enforcing the physical safety constraints governing autonomous behavior.
This talk explores this challenge from the perspective of SmartData, a concept developed at LISHA/UFSC over the past decade to address some of the fundamental limitations of making Sense–Compute–Communicate–Actuate loops more AI-ready while keeping their safety continuously observable and enforceable. The approach builds safety models around the same physical laws that govern the behavior of the systems, bringing those models into the computing infrastructure rather than leaving safety entirely to application-level logic. Autonomous vehicles being developed at UFSC provide a concrete case background for discussing this perspective and its implications for the operating systems of Physical AI.

Long Wang
Tsinghua University, China
Short Bio
Dr. Long Wang is the head of the REliability And Security Of Networks and Systems (REASONS) lab at Tsinghua University. His research interests focus on resiliency, security and understanding of systems, services and networks, especially when they are complicated, intelligent, autonomous, dynamic and/or software-defined. The scopes include security and reliability of systems, cloud computing, distributed systems, and system monitoring, measurement, assessment and modeling, as well as big data analytics and machine learning.
From Fault Injection to Directed Fuzzing: Making Dependability and Security Testing More Intelligent
Modern computing systems have become increasingly complex, making failure diagnosis and vulnerability discovery difficult due to the enormous space of faults, execution paths, system states, and program inputs. A key question is therefore: how can we make testing more intelligent by guiding it toward the system behaviors that matter most?
In this talk, Prof. Wang will present his research journey in dependability and security testing. He first explored targeted fault injection for distributed-system failure diagnosis, followed by techniques for capturing and analyzing service-request execution paths. More recently, he extended these ideas to path-based system analysis, where path tracing supports failure diagnosis and path-aware fault injection helps uncover cross-layer vulnerabilities.
Prof. Wang will then discuss how the same principle applies to directed fuzzing. IDFuzz uses information learned from fuzzing executions to guide mutations toward target code, while TrigFuzz goes beyond code reachability by using large language models to identify vulnerability-triggering conditions and guide fuzzing toward inputs that satisfy them.
These studies illustrate a common direction: making testing more effective by progressively incorporating richer knowledge of system structure, execution behavior, and program semantics.

Raimundo J. de Macêdo
Federal University of Bahia, Brazil
Short Bio
Dr. Raimundo is a Professor of Computer Science at the Federal University of Bahia (UFBA) in Brazil. He founded and is currently the head of the Distributed Systems Laboratory (LaSiD) at UFBA.
When Are Failures Observable? System Models, Fault Models, and the Limits of Dependable Distributed Computing
Distributed systems do not observe failures directly; they observe events—or the absence of expected events. Whether such observations indicate a crash, a timing violation, Byzantine behavior, or merely slow execution depends fundamentally on the underlying system model. In this sense, observability precedes detectability: observability concerns whether faulty behavior is distinguishable from admissible behavior under a given model, whereas detectability concerns whether an algorithm can exploit that distinction.
This keynote explores the interplay between system and fault models, from classical synchrony and asynchrony to partial synchrony and alternative models of progress. We examine how assumptions about timing, communication, process behavior, redundancy, and application semantics determine which failures are observable and detectable and, ultimately, which distributed problems can be solved. When perfect detection is impossible, weaker guarantees and quantitative measures of detection quality become necessary.
Theoretical guarantees, however, are meaningful in practice only when model assumptions adequately
represent the execution environment. We therefore consider assumption coverage: the extent to which
such assumptions can be justified by design, empirical observation, or runtime evidence.
The talk concludes with the Eventual Relative-Speed (ERS) model, which takes a less conventional perspective on fail-silent behavior. Rather than inferring failure directly from elapsed physical time, ERS characterizes process activity through relative logical progress. After stabilization, correct processes remain within a bounded logical divergence; consequently, a process that persistently falls behind the evolving causal structure becomes distinguishable from correct processes. This enables adaptive failure detection based on logical divergence and illustrates the keynote’s central argument: observability, detectability, and computability are inseparable from the system model and the extent to which its assumptions hold in reality.

Marcus Völp
University of Luxembourg, Luxembourg
Short Bio
Dr. Marcus is a Full Professor of Computer Science (Resilient Computing in Cyber-Physical and Embedded Systems).

Ricardo Moraes
Embraer, Brazil
Short Bio
Ricardo Moraes has over 15 years of experience in the aerospace industry and is an engineering leader with a strong focus on Corporate Strategy for Systems Engineering and MBSE (Model-Based Systems Engineering), Systems Architecture, and Systems of Systems Engineering. He is also an active participant in Aviation-ISAC (Aviation Information Sharing and Analysis Center) initiatives, contributing to industry collaboration on aviation cybersecurity and resilience.
He currently serves as a Senior Lead for Systems Engineering within Embraer’s Chief Engineering Office, where he provides technical leadership and engineering support across the Advanced Design, Commercial Aviation, Executive Aviation, and Defense & Security business units.

Rich West
Boston University, USA
Short Bio
Rich West joined the BU Department of Computer Science in 2000 after completing his PhD at Georgia Tech. Rich is a tinkerer of systems, notably, but not limited to, those in embedded and real-time computing. He likes to take a principled approach to system design, having dabbled in the development of standalone kernels and resource management policies where safety and predictability are paramount. He has studied real-time scheduling and resource management, cache-aware performance of multicore processors, and machine virtualization, amongst other topics. He is currently leading the development of the Quest real-time operating system for multicore processors. Its sister system, Quest-V is a secure and predictable separation kernel that forms a distributed system on a chip, providing efficient, predictable and safe execution of sandboxed guest systems including Linux.
