{"id":91,"date":"2026-08-20T07:06:54","date_gmt":"2026-08-20T11:06:54","guid":{"rendered":"https:\/\/blogs.mathworks.com\/engineering\/?p=91"},"modified":"2026-08-20T07:06:54","modified_gmt":"2026-08-20T11:06:54","slug":"how-do-we-know-our-system-will-actually-work","status":"publish","type":"post","link":"https:\/\/blogs.mathworks.com\/engineering\/2026\/08\/20\/how-do-we-know-our-system-will-actually-work\/","title":{"rendered":"How Do We Know Our System Will Actually Work?"},"content":{"rendered":"<div class=\"rtcContent\">\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">I talk about Model-Based Design a lot and in different forums: industries, universities, conferences. I usually position it as a way of ensuring our systems behave as we intended them to.<\/span><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">And almost every time, someone asks the obvious follow-up (paraphrasing a bit): how do I actually know the system behaves the way I intended? <\/span><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">Then I&#8217;ll normally talk about V&amp;V, testing under different conditions, checking your system at different stages of its lifecycle. All of which is true, mind you, albeit fairly abstract. If you already know the answer, it all makes sense. If you don&#8217;t, it probably sounds like engineering word-salad.<\/span><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">So, in this blog, let&#8217;s talk about: desktop simulation (which is sometimes referred to as Model-in-the-Loop (MiL)), Software-in-the-Loop (SiL), Processor-in-the-Loop (PiL), Hardware-in-the-Loop (HiL). What each one actually means, when you&#8217;d reach for each, and why it matters.<\/span><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><img decoding=\"async\" loading=\"lazy\" class=\"imageNode\" style=\"vertical-align: baseline; width: 634px; height: 168px;\" src=\"http:\/\/blogs.mathworks.com\/engineering\/files\/2026\/08\/Verification_1.png\" alt=\"\" width=\"634\" height=\"168\" \/><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">Let&#8217;s look at the temperature control of a battery pack as an example. In this abstracted Simulink block diagram, we have a battery pack (our plant), the load it is driving and a controller that takes in the measured temperature of the pack and provides the appropriate coolant flow. The cooling system is integrated inside the battery pack subsystem.<\/span><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><img decoding=\"async\" loading=\"lazy\" class=\"imageNode\" style=\"vertical-align: baseline; width: 578px; height: 240px;\" src=\"http:\/\/blogs.mathworks.com\/engineering\/files\/2026\/08\/Verification_2.png\" alt=\"\" width=\"578\" height=\"240\" \/><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><\/div>\n<h2 style=\"margin: 20px 10px 5px 4px; padding: 0px; line-height: 25px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 20px; font-weight: bold; text-align: left;\"><span class=\"_richTextNode\">Desktop Simulation <\/span><img decoding=\"async\" loading=\"lazy\" class=\"imageNode\" style=\"vertical-align: baseline; width: 28px; height: 27px;\" src=\"http:\/\/blogs.mathworks.com\/engineering\/files\/2026\/08\/Verification_3.png\" alt=\"\" width=\"28\" height=\"27\" \/><\/h2>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">This is the easy one&#8230; I mean, if you&#8217;re here you probably use Simulink, MATLAB or some other tool to model your systems, right? If so, you&#8217;ve done it! You&#8217;ve modeled your algorithms before you put them on your real system. Here, everything runs in simulation, our controller, our pack, our load, they&#8217;re all in Simulink and Simscape. <\/span><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">Why start with simulating on our desktop? Later stages let you see signals and change things too, but here is where we can do it in isolation. Nothing is constrained by generated code, a target processor or real-time deadlines yet, we are free to focus on the design itself, the control law and the plant dynamics. That isolation is what lets us iterate fastest: change anything and explore the solution space freely. If the loop is unstable, if the controller chatters around the setpoint, if our fallback logic doesn&#8217;t trigger when a sensor drops out&#8230; we can find that out *here*, cheaply, before any hardware constraints cloud the picture.<\/span><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">For our battery pack, this is where we can confirm that the coolant flow controller actually holds the pack temperature at setpoint across a realistic profile; or that it fails gracefully if the temperature sensor drops. This is where we&#8217;d also explore different failure modes safely. <\/span><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><img decoding=\"async\" loading=\"lazy\" class=\"imageNode\" style=\"vertical-align: baseline; width: 582px; height: 404px;\" src=\"http:\/\/blogs.mathworks.com\/engineering\/files\/2026\/08\/Verification_4.png\" alt=\"\" width=\"582\" height=\"404\" \/><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><\/div>\n<h2 style=\"margin: 20px 10px 5px 4px; padding: 0px; line-height: 25px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 20px; font-weight: bold; text-align: left;\"><span class=\"_richTextNode\">Software in the Loop (SiL) <\/span><img decoding=\"async\" loading=\"lazy\" class=\"imageNode\" style=\"vertical-align: baseline; width: 16px; height: 23px;\" src=\"http:\/\/blogs.mathworks.com\/engineering\/files\/2026\/08\/Verification_5.png\" alt=\"\" width=\"16\" height=\"23\" \/><\/h2>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">Now generate C from the controller model, compile that generated code for our development machine, and run it against the same plant model. The controller is now the actual software we intend to run on our device (not a Simulink representation of it). <\/span><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">Architecturally, not much changes from our desktop simulation: the same test harness drives the same plant model, and we simply swap the Simulink subsystem that held the controller for a block that runs the generated C code instead. <\/span><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">In my case, this translation from Simulink to C has never been manual. I tend to use tools like Embedded Coder to facilitate that and ensure full traceability of each line of C back to my model&#8217;s blocks. <\/span><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">Why do SiL? Why compare our C to our Simulink response? It allows us to check if the implementation that is going to our embedded hardware matches our Simulink design. This allows us to check for any effect on precision\/ data type conversion\/ quantization errors. We could also check the possible implementations for different hardware.<\/span><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">Again, everything happens on our host machine. But, instead of Simulink, our controller now runs the C code that will go on our hardware (soon!).<\/span><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><img decoding=\"async\" loading=\"lazy\" class=\"imageNode\" style=\"vertical-align: baseline; width: 577px; height: 235px;\" src=\"http:\/\/blogs.mathworks.com\/engineering\/files\/2026\/08\/Verification_6.png\" alt=\"\" width=\"577\" height=\"235\" \/><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><\/div>\n<h2 style=\"margin: 20px 10px 5px 4px; padding: 0px; line-height: 25px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 20px; font-weight: bold; text-align: left;\"><span class=\"_richTextNode\">Processor in the Loop (PiL)<\/span><img decoding=\"async\" loading=\"lazy\" class=\"imageNode\" style=\"vertical-align: baseline; width: 27px; height: 30px;\" src=\"http:\/\/blogs.mathworks.com\/engineering\/files\/2026\/08\/Verification_7.png\" alt=\"\" width=\"27\" height=\"30\" \/><\/h2>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">Now if we are happy that our embedded code matches our design, the next step is to test it on the actual board. Here, the algorithms live on the board, but our plant still lives in simulation.<\/span><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">Why do we want to do PiL? we want to check if the target executes the code reliably and if it produces the same answers as the host. This is where we may find out that the sample rate you assumed at the desktop simulation stage was optimistic. <\/span><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">Also, processors differ in word length, floating-point support, memory hierarchy, and interrupt behavior. Code that comfortably held its sample rate on our desktop may not on a small embedded part.<\/span><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">For our battery pack, this is where we&#8217;d confirm the controller keeps its thermal sample rate on the actual board and the flow rate it computes matches what the host produced. <\/span><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">One caveat: PiL is not (necessarily) real-time. The board and the host exchange data step by step, and the plant, still simulating on the host, simply waits for the board between steps. That makes it a cross-target, co-simulation kind of test, and testing can get slow when the host-side model is heavy. So, the questions we are trying to answer here are mostly functional, rather than temporal. <\/span><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><img decoding=\"async\" loading=\"lazy\" class=\"imageNode\" style=\"vertical-align: baseline; width: 585px; height: 280px;\" src=\"http:\/\/blogs.mathworks.com\/engineering\/files\/2026\/08\/Verification_8.png\" alt=\"\" width=\"585\" height=\"280\" \/><\/div>\n<h2 style=\"margin: 20px 10px 5px 4px; padding: 0px; line-height: 25px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 20px; font-weight: bold; text-align: left;\"><span class=\"_richTextNode\">Hardware in the Loop (HiL) <\/span><img decoding=\"async\" loading=\"lazy\" class=\"imageNode\" style=\"vertical-align: baseline; width: 36px; height: 23px;\" src=\"http:\/\/blogs.mathworks.com\/engineering\/files\/2026\/08\/Verification_9.png\" alt=\"\" width=\"36\" height=\"23\" \/><\/h2>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">Now the plant model moves onto a real-time simulator, for example a <\/span><a href=\"https:\/\/www.speedgoat.com\/\"><span class=\"_richTextNode\" style=\"text-decoration: underline;\">Speedgoat<\/span><\/a><span class=\"_richTextNode\"> system, running in hard real time on hardware built for deterministic execution, and the controller talks to it through its own physical I\/O. <\/span><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">At the system level, the controller no longer sees simulated numbers handed to it on the host\u2019s schedule; it exchanges signals with a plant that is always running and always presenting values for it to react to, on the same kind of interfaces it will meet in the field. Those interfaces are real: analogue channels carrying real voltages, PWM outputs driving a real actuator signal, and CAN, SPI or Modbus traffic arriving over the wire, when it arrives.<\/span><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">Worth noting from a workflow point of view: even though the plant has left the host computer, from the user\u2019s side little changes. The Simulink model on our computer becomes a console onto the target, and we start, stop, tune and log the model running on the real-time hardware much as we would a model running locally. The host is now doing the monitoring and analytics, and the real-time computation is happening on the target. <\/span><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">What&#8217;s the question HiL attempts to answer? <\/span><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">Our algorithm can be right, our code faithful and our processor fast enough, and the loop can still behave differently once every signal path is real. The controller is not waiting for anything; the plant is simply running, and the controller has to react to signals as they actually arrive, with the real timing, delays and jitter of physical interfaces rather than the instantaneous, perfectly ordered exchange it saw at every earlier stage. For our battery pack, HiL is where we&#8217;d find out whether the controller still holds pack temperature once it&#8217;s the real board driving real outputs, with the actual latency of sensor and comms traffic between the pack and the controller, rather than the instantaneous, perfectly ordered exchange every earlier stage assumed.<\/span><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">Something to keep in mind, HiL needs a real-time plant simulator and matching I\/O hardware, which is a genuine capability threshold rather than a line item. How far we can get without it depends heavily on the dynamics. For slow, latency-tolerant systems like the thermal loop in this example, PiL may well be far enough for a research prototype. For fast, latency-sensitive plants, a motor drive being the obvious case, the host will never simulate quickly enough to close the loop, and PiL stops being sufficient long before we reach production. <\/span><\/div>\n<h2 style=\"margin: 20px 10px 5px 4px; padding: 0px; line-height: 25px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 20px; font-weight: bold; text-align: left;\"><img decoding=\"async\" loading=\"lazy\" class=\"imageNode\" style=\"vertical-align: baseline; width: 767px; height: 277px;\" src=\"http:\/\/blogs.mathworks.com\/engineering\/files\/2026\/08\/Verification_10.png\" alt=\"\" width=\"767\" height=\"277\" \/><\/h2>\n<h2 style=\"margin: 20px 10px 5px 4px; padding: 0px; line-height: 25px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 20px; font-weight: bold; text-align: left;\"><span class=\"_richTextNode\">What checks what<\/span><\/h2>\n<ul style=\"margin: 10px 0px 20px; padding-left: 0px; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-size: 14px;\">\n<li style=\"margin-left: 56px; line-height: 21px; min-height: 0px; text-align: left; white-space: pre-wrap;\"><span class=\"_richTextNode\">Desktop Simulation (MiL) checks the <\/span><span class=\"_richTextNode\" style=\"font-weight: bold;\">algorithms against the system architecture<\/span><span class=\"_richTextNode\">. <\/span><\/li>\n<li style=\"margin-left: 56px; line-height: 21px; min-height: 0px; text-align: left; white-space: pre-wrap;\"><span class=\"_richTextNode\">Software in the Loop (SiL) checks the generated<\/span><span class=\"_richTextNode\" style=\"font-weight: bold;\"> code against the algorithms<\/span><span class=\"_richTextNode\">. <\/span><\/li>\n<li style=\"margin-left: 56px; line-height: 21px; min-height: 0px; text-align: left; white-space: pre-wrap;\"><span class=\"_richTextNode\">Processor in the Loop (PiL) checks the <\/span><span class=\"_richTextNode\" style=\"font-weight: bold;\">target performance against the code<\/span><span class=\"_richTextNode\">. <\/span><\/li>\n<li style=\"margin-left: 56px; line-height: 21px; min-height: 0px; text-align: left; white-space: pre-wrap;\"><span class=\"_richTextNode\">Hardware in the Loop (HiL) checks the <\/span><span class=\"_richTextNode\" style=\"font-weight: bold;\">integrated unit against the requirements<\/span><span class=\"_richTextNode\">.<\/span><\/li>\n<\/ul>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">Worth mentioning that when one of these fails, it is worth identifying what we were testing before &#8220;fixing&#8221; that stage. Timing missed at PiL: underspecified processor, or an algorithm doing more than it needs to? Drift at SiL: wrong datatype, or model design leaning on precision it was never going to get? <\/span><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">This, for me, is part of the appeal of Model-Based Design. The models and test harnesses and scenarios you build for desktop simulation aren&#8217;t throwaway. We get to reuse the same ones for SiL, PiL, and HiL, so you&#8217;re checking each stage against a consistent set of conditions rather than rebuilding your tests four times. And because the outputs are all logged the same way, you can line up results from desktop simulation, SiL, PiL, and HiL directly in the <\/span><a href=\"https:\/\/www.mathworks.com\/help\/simulink\/slref\/simulationdatainspector.html\"><span class=\"_richTextNode\">Simulation Data Inspector<\/span><\/a><span class=\"_richTextNode\"> to see exactly where and when two stages diverge, which is what turns &#8220;the board doesn&#8217;t match the host&#8221; from a vague worry into a specific signal at a specific timestep.<\/span><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><img decoding=\"async\" loading=\"lazy\" class=\"imageNode\" style=\"vertical-align: baseline; width: 634px; height: 168px;\" src=\"http:\/\/blogs.mathworks.com\/engineering\/files\/2026\/08\/Verification_1.png\" alt=\"\" width=\"634\" height=\"168\" \/><\/div>\n<h2 style=\"margin: 20px 10px 5px 4px; padding: 0px; line-height: 25px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 20px; font-weight: bold; text-align: left;\"><span class=\"_richTextNode\">So, how do you know your system will actually work?<\/span><\/h2>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">By doing all of these, you reduce the risk of your prototype failing and that matters more the more expensive or safety-critical the thing you&#8217;re building is.<\/span><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\">Which is really what decides how far up the ladder you go. For a research prototype, MiL and SiL with PiL once the target gets involved is probably sufficient. For something heading into production, all four are standard, and in safety critical and regulated domains they underpin certification frameworks like ISO 26262 and DO-178.<\/span><\/div>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><span class=\"_richTextNode\"> Beyond that there&#8217;s more still: virtual ECU testing, multi-node HiL, power HiL where real power electronics are in the loop.<\/span><\/div>\n<h2 style=\"margin: 20px 10px 5px 4px; padding: 0px; line-height: 25px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 20px; font-weight: bold; text-align: left;\"><span class=\"_richTextNode\">Further reading &amp; resources<\/span><\/h2>\n<ul style=\"margin: 10px 0px 20px; padding-left: 0px; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-size: 14px;\">\n<li style=\"margin-left: 56px; line-height: 21px; min-height: 0px; text-align: left; white-space: pre-wrap;\"><a href=\"https:\/\/www.mathworks.com\/help\/ecoder\/ug\/software-and-processor-in-the-loop-sil-and-pil-simulation.html\"><span class=\"_richTextNode\">Test Generated Code with SiL and PiL Simulations<\/span><\/a><span class=\"_richTextNode\"> &#8211; for going deeper on SiL and PiL workflows and testing equivalence between model and generated code <\/span><\/li>\n<li style=\"margin-left: 56px; line-height: 21px; min-height: 0px; text-align: left; white-space: pre-wrap;\"><a href=\"https:\/\/www.mathworks.com\/products\/simulink-real-time.html\"><span class=\"_richTextNode\">Simulink Real Time (for HiL and RCP)<\/span><\/a><span class=\"_richTextNode\">&#8211; for running your plant model in hard real time on Speedgoat target hardware<\/span><\/li>\n<li style=\"margin-left: 56px; line-height: 21px; min-height: 0px; text-align: left; white-space: pre-wrap;\"><a href=\"https:\/\/www.mathworks.com\/products\/simulink-coder.html\"><span class=\"_richTextNode\">Simulink Coder<\/span><\/a><span class=\"_richTextNode\">, <\/span><a href=\"https:\/\/www.mathworks.com\/products\/embedded-coder.html\"><span class=\"_richTextNode\">Embedded Coder<\/span><\/a><span class=\"_richTextNode\">, <\/span><a href=\"https:\/\/www.mathworks.com\/products\/gpu-coder.html\"><span class=\"_richTextNode\">GPU Coder<\/span><\/a><span class=\"_richTextNode\">, <\/span><a href=\"https:\/\/www.mathworks.com\/products\/hdl-coder.html\"><span class=\"_richTextNode\">HDL Coder<\/span><\/a><span class=\"_richTextNode\"> &#8211; code generation tools to produce C\/C++, CUDA and HDL code <\/span><\/li>\n<li style=\"margin-left: 56px; line-height: 21px; min-height: 0px; text-align: left; white-space: pre-wrap;\"><a href=\"https:\/\/www.mathworks.com\/company\/technical-articles\/model-based-design-for-do-178b.html\"><span class=\"_richTextNode\">Model-Based Design for DO-178B<\/span><\/a><span class=\"_richTextNode\"> &#8211; how this maps onto avionics certification.<\/span><\/li>\n<\/ul>\n<div style=\"margin: 2px 10px 9px 4px; padding: 0px; line-height: 21px; min-height: 0px; white-space: pre; color: #212121; font-family: Helvetica, Arial, sans-serif, Helvetica, Arial, sans-serif; font-style: normal; font-size: 14px; font-weight: 400; text-align: left;\"><\/div>\n<\/div>\n<p><script type=\"text\/javascript\">var css = '._richTextNode {white-space: break-spaces;}'; var head = document.head || document.getElementsByTagName('head')[0], style = document.createElement('style'); head.appendChild(style); style.type = 'text\/css'; if (style.styleSheet){ style.styleSheet.cssText = css; } else { style.appendChild(document.createTextNode(css)); }<\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<div class=\"overview-image\"><img src=\"https:\/\/blogs.mathworks.com\/engineering\/files\/2026\/08\/Verification_1.png\" class=\"img-responsive attachment-post-thumbnail size-post-thumbnail wp-post-image\" alt=\"\" decoding=\"async\" loading=\"lazy\" \/><\/div>\n<p>I talk about Model-Based Design a lot and in different forums: industries, universities, conferences. I usually position it as a way of ensuring our systems behave as we intended them to.<br \/>\nAnd&#8230; <a class=\"read-more\" href=\"https:\/\/blogs.mathworks.com\/engineering\/2026\/08\/20\/how-do-we-know-our-system-will-actually-work\/\">read more >><\/a><\/p>\n","protected":false},"author":242,"featured_media":106,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[6,8,5,14],"tags":[],"_links":{"self":[{"href":"https:\/\/blogs.mathworks.com\/engineering\/wp-json\/wp\/v2\/posts\/91"}],"collection":[{"href":"https:\/\/blogs.mathworks.com\/engineering\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.mathworks.com\/engineering\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.mathworks.com\/engineering\/wp-json\/wp\/v2\/users\/242"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.mathworks.com\/engineering\/wp-json\/wp\/v2\/comments?post=91"}],"version-history":[{"count":8,"href":"https:\/\/blogs.mathworks.com\/engineering\/wp-json\/wp\/v2\/posts\/91\/revisions"}],"predecessor-version":[{"id":122,"href":"https:\/\/blogs.mathworks.com\/engineering\/wp-json\/wp\/v2\/posts\/91\/revisions\/122"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.mathworks.com\/engineering\/wp-json\/wp\/v2\/media\/106"}],"wp:attachment":[{"href":"https:\/\/blogs.mathworks.com\/engineering\/wp-json\/wp\/v2\/media?parent=91"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.mathworks.com\/engineering\/wp-json\/wp\/v2\/categories?post=91"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.mathworks.com\/engineering\/wp-json\/wp\/v2\/tags?post=91"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}