Research Theme

Reliability

We organize the reasons a system can be called truly safe and trustworthy, together with the evidence behind them. In the 4th-year & master's seminar, this is covered through topics such as automated driving and safety arguments.

GSNSafety argumentsQuality assurance

What we work on

  • Lay out "why it is safe" in the form of evidence and explanation.
  • Use notations such as GSN to explain the safety of complex systems clearly.
  • Connect to fields such as automated driving and healthcare, where failures have serious consequences.

Papers

Safety Case / Requirements Engineering

Tailoring safety reports to each audience

Stakeholder-Adaptive Safety Report Generation Using RAG and GSN

This study restructures safety evidence organized in GSN to fit stakeholders with different roles, such as executives, engineers, and business units.

GSNRAGSafety reportsRequirements engineering
Show details Hide details

Problem

When everyone receives the same safety report, information gaps arise: it is too technical for executives, yet does not let engineers trace the evidence closely enough.

Approach

Combining RAG with role-specific retrieval control, we generate role-based reports from GSN, safety requirements, and verification results, adjusting the concerns covered, the amount of reference material, and the level of detail.

Key results

An evaluation using automated driving safety documents showed improved accuracy for executive-oriented reports. For engineers, however, the difference from standard retrieval was small, and refining the role definitions remains future work.

Automotive Safety / Empirical Study

How automotive safety standards are adopted

Adoption of Safety Standards in the Japanese Automotive Industry: A Consortium Study

Based on a survey of JASPAR member companies, this study analyzes how widely safety standards such as ISO 26262, SOTIF, and UL 4600 are used in the Japanese automotive industry.

ISO 26262SOTIFUL 4600Automotive safety
Show details Hide details

Problem

The number of automotive safety standards keeps growing, but it has not been well documented which standards companies adopt, at what stage, and how they see the division of responsibility between OEMs and suppliers.

Approach

We surveyed 40 companies in the JASPAR functional safety working group and statistically compared adoption status, reasons for adoption, perceived burden, and role sharing, based on 30 responses from 28 companies.

Key results

We found clear differences: ISO 26262 is well established, SOTIF is in the preparation or introduction stage, and UL 4600 is mostly not yet adopted. For SOTIF in particular, respondents felt the boundary of responsibility between OEMs and suppliers was unclear.

Assurance Case / Automated Driving

Separating agreement from confidence in safety arguments

Strategy-Aware Confidence Assessment with Stakeholder Consensus in Automated Driving Assurance Cases

For safety arguments in automated driving, this study evaluates separately whether stakeholders are convinced (Consensus) and how technically well-founded the argument is (Confidence).

Assurance casesGSNConsensusConfidence
Show details Hide details

Problem

Stakeholders may agree strongly even when the technical evidence is weak, or the evidence may be strong but poorly communicated. Conventional assessment made it hard to tell these cases apart.

Approach

We treat not only GSN goals but also Strategy nodes, which express how claims are decomposed, as sources of uncertainty, and visualize the results as a two-axis dashboard in D-Case Communicator.

Key results

Applied to a SOTIF argument for a Level 4 automated driving service in Shiojiri City, the top-level goal was classified into the "needs attention" region. This made concrete areas for improvement visible, such as insufficient data, acceptance criteria, and scenario coverage.

Ongoing Research

Research topics the lab is working on as of the 2026 academic year.

A model for verifying consistency between SMS and the safety case

We analyze both at the requirements level, define their explicit and semantic links, and evaluate the validity of those links.

Background

Level 4 automated driving requires both an argument that the system is safe (a safety case) and a safety management process (SMS), but the relationship between the two is not clearly defined.

Automated drivingSMSSafety case

Iterative evaluation of consensus building in Level 4 automated driving safety arguments

Using lightweight indicators, namely Confidence, a Consensus Score, and a four-quadrant diagnosis, we analyze the technical reliability of each node separately from stakeholder acceptance. By repeating the evaluation over multiple rounds, we test whether consensus actually progresses.

Background

Even when a safety argument is structured in GSN, experts often disagree on whether the evidence is sufficient. Conventional quantitative confidence assessment is costly in terms of the information it requires and is rarely used in practice.

GSNConsensus buildingConfidence

Finding common ground on balancing multiple criteria in automated driving

We score simulation results for safety, smoothness, and comfort using weights from experts and from non-experts (via AHP pairwise comparison), visualizing the gap in perception and using it to drive improvements.

Background

Safety experts, engineers, and citizens understand safety differently, which creates gaps in agreement when tuning operational parameters.

Automated drivingAHPGSN

Generating assurance cases for OSS releases from public evidence

We structure OSS security requirements as relationships between claims and the evidence that supports them, collect and verify public information, and visualize, for each release, which claims hold and which lack evidence.

Background

The security of OSS cannot be explained just by how many checklist items are met; a single unmet item can undermine an important claim. It is also unclear how much external users can verify from public information.

OSSAssurance casesSupply chain

A tool for automatically generating Safety Status Reports (SSR)

We are developing a tool that uses generative AI to automatically generate SSRs that account for the information and reading time each role needs, such as executives and engineers, aiming to raise the rate of agreement.

Background

An SSR is a document summarizing safety analyses and countermeasures, used to build agreement on safety among diverse stakeholders, including non-experts.

SSRGenerative AIConsensus building

Contact

+81-47-469-5709

matsuno.yutaka(at)nihon-u.ac.jp

* To prevent spam, "@" is written as "(at)". Please replace (at) with @ when sending.

Matsuno Lab, Department of Computer Engineering, College of Science and Technology, Nihon University

Room 243, 4F, Building 2, 7-24-1 Narashinodai, Funabashi, Chiba 274-8501, Japan

Directions