Open-Source Ecosystem
SafeIoT Center: Continuously Verifying and Benchmarking Security and Privacy in IoT Standards and Systems
SafeIoT is a non-profit initially funded by NSF to advance security and privacy assurance for IoT standards and their real-world implementations through open-source tools and community-driven research.
Our Vision
Consumers increasingly rely on IoT products for home safety, health, and everyday convenience. Yet a critical gap persists: popular IoT standards, their open-source implementation, and IoT vendors' implementation lack holistic, rigorous security and privacy verification — from empirical and human-centered evaluation, to vulnerability detection grounded in systematic or mathematical formal methods. The SafeIoT center addresses this gap by establishing a community-driven open-source ecosystem with a CI/CD infrastructure that continuously verifies open-source IoT standards and IoT vendor's implementations, with an initial focus on the Matter standard and SBOM in IoT context.
We envision that every IoT standard and standardization update is accompanied by timely, rigorous, and human-centered security verification — covering specification documents, technical design, implementation, configuration, and cybersecurity labels.
SafeIoT's CI/CD infrastructure will be maintained by a distributed community of contributors from industry, academia, government, and the open-source community, ensuring continuous security assurance as IoT standards and their real-world implementations evolve.
SafeIoT Open-Source CI/CD Pipeline
SafeIoT Center maintains an open-source pipeline that incorporates and operationalizes state-of-the-art tools and systems to continuously verify the security and privacy of IoT standards, such as Matter, and consumer IoT products and systems, such as Google Home, Apple Home, and SmartThings.
Examples of Open-Source Tools Deployed on the SafeIoT CI/CD Pipeline
UMCCI Checker
Automatically identifies security vulnerabilities in IoT vendors' Matter SDK integrations. The flaws it found have been fixed by CSA, Apple, Google, SmartThings, Comcast, and Tuya.
VerioT
Formally verifies the design of standard IoT protocols via automated model checking. Reported 30+ vulnerabilities adopted by 100+ IoT vendors.
P-Verifier
Formally verifies IoT access control policies. Adopted by AWS as part of AWS IoT Device Defender; also adopted by the UK Ministry of Defence.
Lalaine
Verifies cybersecurity labels of mobile apps. Has detected thousands of non-compliant iOS apps from the Apple App Store. Adopted by the FTC.
Support
SafeIoT Center is supported by NSF, UIUC, UNC Charlotte, and Indiana University.
Community Building
SafeIoT Hackathon
As part of the SafeIoT community engagement effort, we host a series of online competitions inviting engineers, researchers, and students to contribute tools and approaches that can be added to the SafeIoT CI/CD pipeline and applied to real-world IoT security and privacy challenges.
Submission Deadline
November 30, 2026 — 11:59pm (AoE)
SafeIoT Hackathon submissions are due by 11:59pm on November 30, 2026, Anywhere on Earth (AoE) — your submission is on time as long as it is still November 30 somewhere in the world (UTC−12).
Info Webinar
September 15th, 2026 — 9–10am CDT
Organizers will host a live session walking through the hackathon — tracks, submission requirements, and evaluation criteria — and answering questions from participants.
- Who Should Join: Students, security researchers, software engineers, and IoT developers.
- What You'll Build: Open-source tools or prototypes that can be integrated into the SafeIoT pipeline to verify specific security or privacy issues in consumer IoT, IoT standards, and implementations of those standards.
- Impact: Your work will directly improve security assurance for IoT standards used by hundreds of millions of consumer devices worldwide.
Hackathon Tracks
Track 1
IoT Vulnerability Detection
Tools and systems that identify vulnerabilities from IoT standards and implementations of those standards, including open-source projects and commodity IoT products such as Google Home, Apple Home, and SmartThings.
Full track requirements →Track 2
IoT SBOM, CBOM, and AI-BOM Verification
Tools and systems that identify security, privacy and compliance issues related to Software Bills of Materials (SBOMs), Cryptographic Bills of Materials (CBOMs), and AI Bills of Materials (AI-BOMs) for IoT systems, products, or open-source projects.
Full track requirements →Competition Rules
The hackathon is a project competition. Any open-source software related to security and privacy in IoT standards and systems is eligible. Your submission must align with one of the two tracks above and show how the tool or approach could fit into the SafeIoT pipeline — see each track for its detailed requirements.
A complete submission has three parts: a scientific paper, a public code repository, and a pitch video. All three are required to be considered for an award.
- Scientific paper, up to 5 pages — a PDF in double-column ACM format presenting your work as a research contribution.
- Code repository — publicly accessible by the deadline, with setup, usage, and reproducibility instructions.
- Pitch video, max 5 minutes — using the official slides template.
Evaluation Criteria
Technical Innovation
How novel the approach is, and what it can verify that existing tools cannot.
Methodological Rigor
Clear rules and ground truth, representative data, comparison against baselines, and quantitative results.
Impact Potential
Usefulness to manufacturers, auditors, regulators, and buyers — and how well it scales across IoT domains.
Clarity and Presentation
A clear end-to-end pipeline, and honesty about what is automated, what needs manual review, and what stays unverifiable.
Prizes
Prizes are awarded across both hackathon tracks combined, not separately per track: first, second, and third place will be selected from all participants. Issuing of the monetary prizes is subject to final security and compliance checks, while the certificates for winners will be guaranteed. To qualify for the award, award winners should agree to deploy their tool/artifacts as open-source components to the SafeIoT CI/CD pipeline, under a permissive open-source license (e.g., MIT, Apache 2.0, or BSD).
Organizers
Luyi Xing
Associate Professor of Computer Science, UIUC
Jean Camp
Distinguished Professor, UNC Charlotte
Xiaojing Liao
Associate Professor of Computer Science, UIUC
Yue Xiao
Assistant Professor of Computer Science, William & Mary
Long Cheng
Associate Professor, Clemson University
Industry Mentor
Brian LaMacchia
Industry Mentor
Hackathon Judges
The judging team will include leading experts from industry and academia, with the full roster to be announced soon.
FAQ
Who can participate?
Anyone with an interest in IoT security — students, professionals, and researchers.
Is it free to enter?
Yes, participation is completely free.
Do I need a team?
You can apply solo or as a team of up to 4.
What background do I need?
Familiarity with software security, systems programming, or IoT is helpful. We will provide onboarding materials and mentor support throughout the event.
Who can I contact with questions?
Please email sdiotsec@gmail.com with any questions.