. Bibliographie-[-acf-+-98-]-r, R. Alami, S. Chatila, M. Fleury, F. Ghallab et al., An Architecture for Autonomy, The International Journal of Robotics Research, vol.17, issue.4, pp.315-337, 1998.

K. Altisen, A. Clodic, F. Maraninchi, E. Rutten, A. Avi?ienis et al., Using controllersynthesis techniques to build property-enforcing layers Basic concepts and taxonomy of dependable and secure computing Electronic architecture and system engineering for integrated safety systems. Guidelines for establishing dependability requirements and performing hazard analysis Independant safety systems for autonomy, European Symposium on Programming IEEE Transactions on Dependable and Secure Computing Bozga, and J. Sifakis. Modeling heterogeneous real-time components in BIP. In Fourth IEEE International Conference on Software Engineering and Formal Methods, SEFM '06, pp.174-18811, 2003.

]. S. Bdsg-+-10, L. D. Bensalem, M. Silva, F. Gallien, R. Ingrand et al., Rock Solid' software : A verifiable and correct-by-construction controller for rover and spacecraft functional level Robotics and Automation in Space Remote agent experiment DS1 technology validation report, The 10th International Symposium on Artificial IntelligenceCGP99] E.M. Clarke, O. Grumberg, and D.A. Peled. Model checking, 1996.

]. H. Chu11 and . Chu, Test and Evaluation of the Robustness of the Functional Layer of an Autonomous Robot, 2011.

I. [. Ericson, Fault tree analysis -a history, Erb17th International System Safety Conference, 1999.

]. A. Erb89 and . Erb, Safety measures of the electronic interlocking system Elektra, IFAC Workshop, SAFECOMP '89, pp.49-52, 1989.

S. [. Fox and . Das, Safe and sound -Artificial Intelligence in Hazardous Applications, 2000.

M. [. Fleury, R. Herrb, and . Chatila, GenoM : a tool for the specification and the implementation of operating modules in a distributed robot architecture, IEEE/RSJ International Conference on Intelligent Robots and Systems, IROS '97, pp.842-849, 1997.

]. J. Fox01 and . Fox, Engineering safety requirements, safety constraints, and safety-critical requirements Designing Safety into Medical Decisions and Clinical Processes, International Conference on Computer Safety, Reliability and Security, 2001.

B. [. Feather and . Smith, Automatic generation of test oracles: from pilot studies to application, 14th IEEE International Conference on Automated Software Engineering, p.63, 1999.
DOI : 10.1109/ASE.1999.802093

]. E. Gat97 and . Gat, On three-layer architectures, Artificial Intelligence and Mobile Robots, pp.195-210, 1997.

J. Guiochet, D. Martin-guillerez, and D. Powell, Experience with modelbased user-centered risk assessment for service robots, IEEE 12th International Symposium on High-Assurance Systems Engineering, HASE '10, pp.104-113, 2010.
URL : https://hal.archives-ouvertes.fr/hal-01285192

G. [. Guiochet, B. Motet, C. Tondu, and . Baron, Sécurité des systèmes de la robotique médicale. Techniques de l'ingénieur, Sécurité et gestion des risques, pp.1-16, 2007.

D. [. Guiochet and . Powell, Étude et analyse de systèmes indépendants de sécurité-innocuité de type safety bag, LAAS CNRS, 2006.

L. [. Goodloe and . Pike, Monitoring distributed real-time systems : A survey and future directions, 2010.

D. [. Guiochet, E. Powell, J. P. Baudin, and . Blanquart, Online safety monitoring using safety modes, 6th IARP -IEEE/RAS -EURON Joint Workshop on Technical Challenges for Dependable Robots in Human Environments, 2008.
URL : https://hal.archives-ouvertes.fr/hal-00282444

]. S. Hsf-+-09, M. Haddadin, S. Suppa, T. Fuchs, A. Bodenmüller et al., Towards the robotic Co-Worker, 14th International Symposium on Robotics Research, ISSR '09, 2009.

]. H. Hua04 and . Huang, Autonomy Levels For Unmanned Systems (ALFUS) Framework, Numéro NIST Special Publication, 1011.

[. Ieee, Standard for software verification and validation, std 1012-2004, 1012.

[. Ieee, Standard for software and system test documentation, IEEE Std, vol.829, pp.1-118, 2008.

F. [. Ingrand and . Py, Online execution control checking for autonomous systems, 7th International Conference on Intelligent Autonomous Systems, 2002.

]. P. Kle91 and . Klein, The safety bag expert system in the electronic railway interlocking system Elektra, Journal of Expert Systems with Applications, vol.3, issue.4, pp.499-560, 1991.

]. B. Lci-+-04, R. Lussier, F. Chatila, M. O. Ingrand, D. Killijian et al., On Fault Tolerance and Robustness in Autonomous Systems, 3rd IARP- IEEE/RAS-EURON Joint Workshop on Technical Challenges for Dependable Robots in Human Environments, 2004.

]. N. Lev91 and . Leveson, Software safety in embedded computer systems, Communications of the ACM Magazine, vol.34, issue.2, pp.34-46, 1991.

C. [. Leucker and . Schallhart, A brief account of runtime verification, The Journal of Logic and Algebraic Programming, vol.78, issue.5, pp.293-303, 2009.
DOI : 10.1016/j.jlap.2008.08.004

J. [. Martin-guillerez, D. Guiochet, and . Powell, Experience with a model-based safety analysis process for an autonomous service robot, IARP Workshop on Technical Challenges for Dependable Robots in Human Environments, pp.1-8, 2010.

J. [. Martin-guillerez, D. Guiochet, C. Powell, and . Zanon, A UMLbased method for risk analysis of human-robot interactions, 2nd International Workshop on Software Engineering for Resilient Systems, 2010.
URL : https://hal.archives-ouvertes.fr/hal-01285195

]. A. Mmbg-+-12, J. P. Mekki-mokhtar, J. Blanquart, D. Guiochet, M. Powell et al., Safety trigger conditions for critical autonomous systems, 18th IEEE Pacific Rim International Symposium on Dependable Computing, p.2012

A. Mekki-mokhtar, J. Guiochet, D. Powell, J. Blanquart, and M. Roy, Elicitation of executable safety rules for critical autonomous systems, Embedded Real Time Software and Systems (ERTS2), 2012.
URL : https://hal.archives-ouvertes.fr/hal-01282237

P. [. Muscettola, B. Nayak, B. C. Pell, and . Williams, Remote Agent: to boldly go where no AI system has gone before, Artificial Intelligence, vol.103, issue.1-2, pp.5-47, 1998.
DOI : 10.1016/S0004-3702(98)00068-X

URL : http://doi.org/10.1016/s0004-3702(98)00068-x

C. [. Menzies and . Pecheur, Verification and Validation and Artificial Intelligence, Advances in Computers of Advances in Computers, pp.153-201, 2005.
DOI : 10.1016/S0065-2458(05)65004-8

URL : http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.84.3732

S. [. Medikonda and . Panchumarthy, An Approach to Modeling Software Safety in Safety-Critical Systems, Journal of Computer Science, vol.5, issue.4, pp.311-322, 2009.
DOI : 10.3844/jcssp.2009.311.322

[. Omg, 2nd revised submission to OMG RFP ad/00-09-02 -Unified Modeling Language : Superstructure -version 2.0. Object Management Group, 2003.

]. F. Pi04a, F. Py, and . Ingrand, Dependable execution control for autonomous robots, International Conference IEEE/RSJ on Intelligent Robots and Systems, pp.1136-1141, 2004.

]. F. Pi04b, F. Py, ]. L. Ingrandpnw11, S. Pike, N. Niller et al., Real-time execution control for autonomous systems Runtime verification for ultracritical systems Accurate and autonomous navigation for the ATV, 2nd European Congress on Embedded Real Time Software and Systems ERTS2 '04 2nd International Conference on Runtime Verification, pp.21-23490, 2004.

D. [. Pace, ]. D. Sewardptf02, P. Powell, and . Thévenod-fosse, A safety integrated architecture for an autonomous safety excavator Dependability issues in ai-based autonomous systems for space applications, International Symposium on Automation and Robotics in Construction 2nd IARP-IEEE/RAS joint workshop on Technical Challenge for Dependable Robots in Human Environments, pp.163-177, 2000.

J. [. Rabejac, J. Blanquart, and . Queille, Executable assertions and timed traces for on-line software error detection, Proceedings of Annual Symposium on Fault Tolerant Computing, pp.138-147, 1996.
DOI : 10.1109/FTCS.1996.534602

B. [. Roderick, E. Roberts, D. Atkins, . J. Akin-[-rw89-]-p, W. M. Ramadge et al., The Ranger Robotic Satellite Servicer and Its Autonomous Software-Based Safety System, IEEE Intelligent Systems, vol.19, issue.5, pp.12-1981, 1989.
DOI : 10.1109/MIS.2004.53

]. S. Sai77, W. Saib, and . Vesely, Executable Assertions -An Aid To Reliable Software On-line monitoring : a tutorial Fault tree handbook with aerospace applicaions, 11th Asilomar Conference on Circuits, Systems and Computers. Conference Record, pp.277-28172, 1977.

]. N. The86 and . Theuretzbacher, VOTRICS : Voting Triple Modular Computing System, 16th IEEE symposium on fault-tolerant computing, FTCS'86, pp.144-150, 1986.