{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T10:10:55Z","timestamp":1767262255327,"version":"3.41.0"},"reference-count":60,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2024,10,31]],"date-time":"2024-10-31T00:00:00Z","timestamp":1730332800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"National Science Foundation","award":["CNS-2047971, CCF-1755890, CCF-1618132, CCF-2139845, OAC-2221648"],"award-info":[{"award-number":["CNS-2047971, CCF-1755890, CCF-1618132, CCF-2139845, OAC-2221648"]}]},{"DOI":"10.13039\/100000199","name":"United States Department of Agriculture","doi-asserted-by":"crossref","award":["#2023-67021-38977"],"award-info":[{"award-number":["#2023-67021-38977"]}],"id":[{"id":"10.13039\/100000199","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Cyber-Phys. Syst."],"published-print":{"date-parts":[[2024,10,31]]},"abstract":"<jats:p>\n            Cyber-physical systems interact with the world through software controlling physical effectors. Carefully designed controllers, implemented as safety-critical control software, also interact with other parts of the software suite, and may be difficult to separate, verify, or maintain. Moreover, some software changes, not intended to impact control system performance,\n            <jats:italic>do<\/jats:italic>\n            change controller response through a variety of means including interaction with external libraries or unmodeled changes only existing in the cyber system (e.g., exception handling). As a result, identifying safety-critical control software, its boundaries with other embedded software in the system, and the way in which control software evolves could help developers isolate, test, and verify control implementation, and improve control software development. In this work we present an automated technique, based on a novel application of machine learning, to detect commits related to control software, its changes, and how the control software evolves. We leverage messages from developers (e.g., commit comments), and code changes themselves to understand how control software is refined, extended, and adapted over time. We examine three distinct, popular, real-world, safety-critical autopilots\u2014ArduPilot, Paparazzi UAV, and LibrePilot to test our method demonstrating an effective detection rate of 0.95 for control-related code changes.\n          <\/jats:p>","DOI":"10.1145\/3678259","type":"journal-article","created":{"date-parts":[[2024,7,17]],"date-time":"2024-07-17T16:19:56Z","timestamp":1721233196000},"page":"1-20","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Carving Out Control Code: Automated Identification of Control Software in Autopilot Systems"],"prefix":"10.1145","volume":"8","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-8208-0784","authenticated-orcid":false,"given":"Balaji","family":"Balasubramaniam","sequence":"first","affiliation":[{"name":"Department of Integrated Studies, Kansas State University, Salina, KS, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8221-5352","authenticated-orcid":false,"given":"Iftekhar","family":"Ahmed","sequence":"additional","affiliation":[{"name":"Department of Informatics, University of California, Irvine, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6686-466X","authenticated-orcid":false,"given":"Hamid","family":"Bagheri","sequence":"additional","affiliation":[{"name":"School of Computing, University of Nebraska\u2013Lincoln, Lincoln, NE, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4201-6903","authenticated-orcid":false,"given":"Justin","family":"Bradley","sequence":"additional","affiliation":[{"name":"Department of Computer Science, North Carolina State University, Raleigh, NC, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,11,11]]},"reference":[{"doi-asserted-by":"publisher","key":"e_1_3_2_2_2","DOI":"10.1109\/ACCESS.2024.3387728"},{"doi-asserted-by":"publisher","key":"e_1_3_2_3_2","DOI":"10.1007\/BF00153759"},{"doi-asserted-by":"publisher","key":"e_1_3_2_4_2","DOI":"10.1145\/2884781.2884801"},{"unstructured":"ArduPilot. 2024. ArduPilot Open Source Autopilot. Retrieved from https:\/\/ardupilot.org\/","key":"e_1_3_2_5_2"},{"doi-asserted-by":"publisher","key":"e_1_3_2_6_2","DOI":"10.1109\/ICCPS48487.2020.00022"},{"doi-asserted-by":"publisher","key":"e_1_3_2_7_2","DOI":"10.1109\/TAES.2022.3162179"},{"doi-asserted-by":"publisher","key":"e_1_3_2_8_2","DOI":"10.1145\/1294948.1294953"},{"unstructured":"Betaflight. 2024. Betaflight Flight Controller Software (Firmware). Retrieved from https:\/\/betaflight.com\/","key":"e_1_3_2_9_2"},{"doi-asserted-by":"publisher","key":"e_1_3_2_10_2","DOI":"10.1109\/ICSE.2013.6606714"},{"doi-asserted-by":"publisher","key":"e_1_3_2_11_2","DOI":"10.1023\/A:1010933404324"},{"unstructured":"Eric Brochu Vlad M. Cora and Nando De Freitas. 2010. A tutorial on Bayesian optimization of expensive cost functions with application to active user modeling and hierarchical reinforcement learning. arXiv:1012.2599. Retrieved from https:\/\/doi.org\/10.48550\/arXiv.1012.2599","key":"e_1_3_2_12_2"},{"doi-asserted-by":"publisher","key":"e_1_3_2_13_2","DOI":"10.1007\/s11859-016-1133-1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_14_2","DOI":"10.1007\/978-3-319-06200-6_1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_15_2","DOI":"10.1109\/TSE.2017.2659747"},{"doi-asserted-by":"publisher","key":"e_1_3_2_16_2","DOI":"10.2514\/6.2009-6233"},{"doi-asserted-by":"publisher","key":"e_1_3_2_17_2","DOI":"10.1007\/978-3-030-05318-5_6"},{"doi-asserted-by":"publisher","key":"e_1_3_2_18_2","DOI":"10.1145\/2568225.2568272"},{"doi-asserted-by":"publisher","key":"e_1_3_2_19_2","DOI":"10.1145\/2372251.2372285"},{"doi-asserted-by":"publisher","key":"e_1_3_2_20_2","DOI":"10.1145\/1985441.1985456"},{"key":"e_1_3_2_21_2","volume-title":"Data Structures and Algorithms in C \\(++\\)","author":"Goodrich Michael T.","year":"2011","unstructured":"Michael T. Goodrich, Roberto Tamassia, and David M. Mount. 2011. Data Structures and Algorithms in C \\(++\\) . John Wiley & Sons."},{"doi-asserted-by":"publisher","key":"e_1_3_2_22_2","DOI":"10.1016\/S0164-1212(00)00031-5"},{"doi-asserted-by":"publisher","key":"e_1_3_2_23_2","DOI":"10.1007\/s100090050008"},{"doi-asserted-by":"publisher","key":"e_1_3_2_24_2","DOI":"10.2514\/6.2016-0482"},{"unstructured":"Daniel Jackson Jonathan DeCastro Soonho Kong Dimitrios Koutentakis A. F. Leong Armando Solar-Lezama Mike Wang and Xin Zhang. 2019. Certified control for self-driving cars. In Proceedings of the DARS 2019: 4th Workshop on the Design and Analysis of Robust Systems. Springer. Retrieved from https:\/\/par.nsf.gov\/servlets\/purl\/10170076","key":"e_1_3_2_25_2"},{"doi-asserted-by":"publisher","key":"e_1_3_2_26_2","DOI":"10.1109\/JPROC.2002.805824"},{"doi-asserted-by":"publisher","key":"e_1_3_2_27_2","DOI":"10.1109\/ETFA46521.2020.9212074"},{"key":"e_1_3_2_28_2","first-page":"913","volume-title":"Proceedings of the 29th {USENIX} Security Symposium ({USENIX} Security 20)","author":"Kim Taegyu","year":"2020","unstructured":"Taegyu Kim, Chung Hwan Kim, Altay Ozen, Fan Fei, Zhan Tu, Xiangyu Zhang, Xinyan Deng, Dave Jing Tian, and Dongyan Xu. 2020. From control model to program: Investigating robotic aerial vehicle accidents with {MAYDAY}. In Proceedings of the 29th {USENIX} Security Symposium ({USENIX} Security 20). {USENIX} Association, Online, 913\u2013930."},{"doi-asserted-by":"publisher","key":"e_1_3_2_29_2","DOI":"10.1007\/978-3-030-05318-5_4"},{"doi-asserted-by":"publisher","key":"e_1_3_2_30_2","DOI":"10.1109\/JSTARS.2013.2262926"},{"doi-asserted-by":"publisher","key":"e_1_3_2_31_2","DOI":"10.1016\/j.conengprac.2006.07.003"},{"doi-asserted-by":"publisher","key":"e_1_3_2_32_2","DOI":"10.1109\/CDC51059.2022.9993292"},{"unstructured":"LibrePilot. 2024. LibrePilot. Retrieved from https:\/\/www.librepilot.org\/","key":"e_1_3_2_33_2"},{"doi-asserted-by":"publisher","key":"e_1_3_2_34_2","DOI":"10.1016\/j.infsof.2011.09.007"},{"doi-asserted-by":"publisher","key":"e_1_3_2_35_2","DOI":"10.1109\/CDC.2013.6760105"},{"doi-asserted-by":"publisher","key":"e_1_3_2_36_2","DOI":"10.1016\/j.infsof.2014.05.007"},{"doi-asserted-by":"publisher","key":"e_1_3_2_37_2","DOI":"10.11613\/BM.2012.031"},{"doi-asserted-by":"publisher","key":"e_1_3_2_38_2","DOI":"10.1016\/j.comnet.2023.109626"},{"doi-asserted-by":"publisher","key":"e_1_3_2_39_2","DOI":"10.1109\/WIECON-ECE60392.2023.10456514"},{"issue":"1","key":"e_1_3_2_40_2","article-title":"The weka multilayer perceptron classifier","volume":"7","author":"Morariu Daniel","year":"2018","unstructured":"Daniel Morariu, Radu Cre\u021bulescu, and Macarie Breazu. 2018. The weka multilayer perceptron classifier. International Journal of Advanced Statistics and IT & C for Economics and Life Sciences 7, 1 (2018).","journal-title":"International Journal of Advanced Statistics and IT & C for Economics and Life Sciences"},{"unstructured":"James Newsome and Dawn Xiaodong Song. 2005. Dynamic taint analysis for automatic detection analysis and signature generation of exploits on commodity software. In Proceedings of the Network and Distributed System Security Symposium (NDSS \u201905) Vol. 5. The Internet Society 3\u20134. Retrieved from https:\/\/www.ndss-symposium.org\/ndss2005\/dynamic-taint-analysis-automatic-detection-analysis-and-signaturegeneration-exploits-commodity\/","key":"e_1_3_2_41_2"},{"unstructured":"PaparazziUAV. 2024. PaparazziUAV. Retrieved from https:\/\/wiki.paparazziuav.org\/wiki\/MainPage","key":"e_1_3_2_42_2"},{"issue":"3","key":"e_1_3_2_43_2","doi-asserted-by":"crossref","first-page":"148","DOI":"10.25215\/0303.054","article-title":"Effectiveness of teaching through mind mapping technique","volume":"3","author":"Parikh Nikhilkumar D.","year":"2016","unstructured":"Nikhilkumar D. Parikh. 2016. Effectiveness of teaching through mind mapping technique. The International Journal of Indian Psychology 3, 3 (2016), 148\u2013156.","journal-title":"The International Journal of Indian Psychology"},{"unstructured":"Brian Payne. 2014. GitHub Compare. Retrieved from https:\/\/bayne.github.io\/github-compare\/#!\/compare\/ArduPilot\/ardupilot\/paparazzi\/paparazzi","key":"e_1_3_2_44_2"},{"doi-asserted-by":"publisher","key":"e_1_3_2_45_2","DOI":"10.3390\/make2040031"},{"unstructured":"Pixhawk. 2024. Pixhawk Flight Controller Hardware Project. Retrieved from https:\/\/pixhawk.org\/standards","key":"e_1_3_2_46_2"},{"key":"e_1_3_2_47_2","first-page":"997","volume-title":"Fast Training of Support Vector Machines Using Sequential Minimal Optimization, Advances in Kernel Methods","author":"Platt John C.","year":"1999","unstructured":"John C. Platt. 1999. Fast training of support vector machines using sequential minimal optimization, advances in kernel methods. In Fast Training of Support Vector Machines Using Sequential Minimal Optimization, Advances in Kernel Methods, Vol. 1. IEEE, 997\u20131001."},{"key":"e_1_3_2_48_2","first-page":"20","volume-title":"Proceedings of the International Conference on Model Driven Engineering Languages and Systems","author":"Porter Joseph","year":"2008","unstructured":"Joseph Porter, G\u00e1bor Karsai, P\u00e9ter V\u00f6lgyesi, Harmon Nine, Peter Humke, Graham Hemingway, Ryan Thibodeaux, and J\u00e1nos Sztipanovits. 2008. Towards model-based integration of tools and techniques for embedded control system design, verification, and implementation. In Proceedings of the International Conference on Model Driven Engineering Languages and Systems. Springer, 20\u201334."},{"unstructured":"PX4. 2024. PX4 Open Source Autopilot. Retrieved from https:\/\/px4.io\/","key":"e_1_3_2_49_2"},{"doi-asserted-by":"publisher","key":"e_1_3_2_50_2","DOI":"10.1109\/ICSE.2013.6606589"},{"unstructured":"Reddit. 2020. Why Enum Type Derives from uint8 \\(\\_\\) t. Retrieved from https:\/\/www.reddit.com\/r\/cpp_questions\/comments\/f6cdop\/why_enum_type_derives_from_uint8_t\/","key":"e_1_3_2_51_2"},{"doi-asserted-by":"publisher","key":"e_1_3_2_52_2","DOI":"10.1201\/9781315218168"},{"doi-asserted-by":"publisher","key":"e_1_3_2_53_2","DOI":"10.1109\/SEAA.2011.59"},{"key":"e_1_3_2_54_2","volume-title":"Handbook of Knowledge Representation","author":"Harmelen Frank Van","year":"2008","unstructured":"Frank Van Harmelen, Vladimir Lifschitz, and Bruce Porter. 2008. Handbook of Knowledge Representation. Elsevier, Amsterdam, The Netherlands."},{"doi-asserted-by":"publisher","key":"e_1_3_2_55_2","DOI":"10.1089\/big.2016.0051"},{"doi-asserted-by":"publisher","key":"e_1_3_2_56_2","DOI":"10.4038\/seajme.v1i1.506"},{"issue":"1","key":"e_1_3_2_57_2","first-page":"26","article-title":"Hyperparameter optimization for machine learning models based on Bayesian optimization","volume":"17","author":"Wu Jia","year":"2019","unstructured":"Jia Wu, Xiu-Yun Chen, Hao Zhang, Li-Dong Xiong, Hang Lei, and Si-Hao Deng. 2019. Hyperparameter optimization for machine learning models based on Bayesian optimization. Journal of Electronic Science and Technology 17, 1 (2019), 26\u201340.","journal-title":"Journal of Electronic Science and Technology"},{"doi-asserted-by":"publisher","key":"e_1_3_2_58_2","DOI":"10.1016\/j.iot.2020.100218"},{"doi-asserted-by":"publisher","key":"e_1_3_2_59_2","DOI":"10.1145\/2597073.2597078"},{"doi-asserted-by":"publisher","key":"e_1_3_2_60_2","DOI":"10.1109\/ACC.2015.7171029"},{"doi-asserted-by":"publisher","key":"e_1_3_2_61_2","DOI":"10.1145\/1595696.1595713"}],"container-title":["ACM Transactions on Cyber-Physical Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3678259","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3678259","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T22:54:09Z","timestamp":1750287249000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3678259"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,10,31]]},"references-count":60,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2024,10,31]]}},"alternative-id":["10.1145\/3678259"],"URL":"https:\/\/doi.org\/10.1145\/3678259","relation":{},"ISSN":["2378-962X","2378-9638"],"issn-type":[{"type":"print","value":"2378-962X"},{"type":"electronic","value":"2378-9638"}],"subject":[],"published":{"date-parts":[[2024,10,31]]},"assertion":[{"value":"2023-10-11","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-06-25","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-11-11","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}