Public Defense of a Doctoral Dissertation in Computer Science - Guillaume Nguyen
Harmonizing Regulations and Source Code: A Symphony of Compliance for Cyber-Physical Systems
Harmonizing Regulations and Source Code: A Symphony of Compliance for Cyber-Physical Systems
The increasing regulatory pressure on Cyber-Physical Systems (CPS), particularly in Europe, has made compliance a critical yet complex challenge for industry stakeholders. Many of these CPS are often long-lived systems with legacy code and limited (or no) access to representative documentation. This poses a problem when these systems must comply with newer regulatory frameworks. Indeed, current conformity assessment practices rely predominantly on documentation review and operational observations, while the analysis of software artifacts remains underutilized. This situation is compounded by a persistent communication gap between legal experts and engineers, and a lack of systematic traceability between high-level regulatory obligations and low-level technical implementations. Such a disconnect frequently leads to inconsistencies detected late in the development process, increasing correction costs and delaying time-to-market. Furthermore, the growing complexity of regulations, such as the Medical Device Regulation (MDR), contributes to the perception that compliance hinders innovation.
Transitioning from theoretical frameworks to industrial implementation presents significant challenges. During this research, efforts to validate the approach in real-world production environments were hampered by restricted access to sensitive data and architectures, as well as the inherent risks of intrusive analysis in highly interconnected systems. Consequently, this thesis emphasizes a conceptual framework validated through modular prototypes and isolated CPS categories (e.g., medical devices), demonstrating the effectiveness of the proposed methods where full-scale production deployment is not yet feasible.
This thesis addresses these challenges by investigating how regulatory requirements can be transformed into structured, traceable, and partially automatable elements directly linked to software artifacts. The research adopts an industry-grounded exploratory approach structured around three main axes: (1) the formalization of regulatory requirements to bridge the semantic gap between legal and technical domains; (2) the extraction of system functionalities from source code using Large Language Models; and (3) a unified framework, supported by tool prototypes, to bridge expected system behavior and actual implementation through evidence-based assessment.
By combining regulatory analysis, software engineering, and AI-based methods, this work contributes to redefining compliance as a continuous, traceability-driven process. Ultimately, it aims to support a paradigm shift toward “compliant-by-design” systems, enabling earlier detection of discrepancies and better alignment between regulatory intent and technical implementation in complex CPS environments.