VLDB 2026 Research / reviewers in the wild / expert
Rick Salay
dblp:00/1125
· DBLP profile ↗
38ranked-venue papers
15as first author
2since 2021 · last 2022
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 34 · 14 first-author · 2 since 2021Databases, data management, data science and information retrieval · 3 · 3 first-authorSecurity and privacy · 2Artificial intelligence and machine learning · 1Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | If a Human Can See It, So Should Your System: Reliability Requirements for Machine Vision ComponentsabstractMachine Vision Components (MVC) are becoming safety-critical. Assuring their quality, including safety, is essential for their successful deployment. Assurance relies on the availability of precisely specified and, ideally, machine-verifiable requirements. MVCs with state-of-the-art performance rely on machine learning (ML) and training data, but largely lack such requirements. Boyue Caroline Hu, Lina Marsso, Krzysztof Czarnecki 0001, Rick Salay, Huakun Shen, Marsha Chechik |
ICSE | 4 |
| 2022 | Property Satisfiability Analysis for Product Lines of Modelling LanguagesabstractSoftware engineering uses models throughout most phases of the development process. Models are defined using modelling languages. To make these languages applicable to a wider set of scenarios and customizable to specific needs, researchers have proposed using product lines to specify modelling language variants. However, there is currently a lack of efficient techniques for ensuring correctness with respect to properties of the models accepted by a set of language variants. This may prevent detecting problematic combinations of language variants that produce undesired effects at the model level. To attack this problem, we first present a classification of instantiability properties for language product lines. Then, we propose a novel approach to lifting the satisfiability checking of model properties of individual language variants, to the product line level. Finally, we report on an implementation of our proposal in theMerlintool, and demonstrate the efficiency gains of our lifted analysis method compared to an enumerative analysis of each individual language variant. Esther Guerra, Juan de Lara, Marsha Chechik, Rick Salay |
IEEE Trans. Software Eng. | 4 |
| 2020 | Just Enough Formality in Assurance Argument Structures
Torin Viger, Rick Salay, Gehan M. K. Selim, Marsha Chechik |
SAFECOMP | 2 |
| 2020 | Heterogeneous megamodel management using collection operators
Rick Salay, Sahar Kokaly, Alessio Di Sandro, Nick L. S. Fung, Marsha Chechik |
Softw. Syst. Model. | 1 |
| 2020 | A Framework for Temporal Verification Support in Domain-Specific ModellingabstractIn Domain-Specific Modelling (DSM) the general goal is to provide Domain-Specific Modelling Languages (DSMLs) for domain users to model systems using concepts and notations they are familiar with, in their problem domain. Verifying whether a model satisfies a set of requirements is considered to be an important challenge in DSM, but is nevertheless mostly neglected. We present a solution in the form of ProMoBox, a framework that integrates the definition and verification of temporal properties in discrete-time behavioural DSMLs, whose semantics can be described as a schedule of graph rewrite rules. Thanks to the expressiveness of graph rewriting, this covers a very large class of problems. With ProMoBox, the domain user models not only the system with a DSML, but also its properties, input model, run-time state and output trace. A DSML is thus comprised of five sublanguages, which share domain-specific syntax, and are generated from a single metamodel. Generic transformations to and from a verification backbone ensure that both the language engineer and the domain user are shielded from underlying notations and techniques. We explicitly model the ProMoBox framework's process in the paper. Furthermore, we evaluate ProMoBox to assert that it supports the specification and verification of properties in a highly flexible and automated way. Bart Meyers, Hans Vangheluwe, Joachim Denil, Rick Salay |
IEEE Trans. Software Eng. | 4 |
| 2019 | Software Assurance in an Uncertain WorldabstractFrom financial services platforms to social networks to vehicle control, software has come to mediate many activities of daily life. Governing bodies and standards organizations have responded to this trend by creating regulations and standards to address issues such as safety, security and privacy. In this environment, the compliance of software development to standards and regulations has emerged as a key requirement. Compliance claims and arguments are often captured in assurance cases, with linked evidence of compliance. Evidence can come from testcases, verification proofs, human judgment, or a combination of these. That is, experts try to build (safety-critical) systems carefully according to well justified methods and articulate these justifications in an assurance case that is ultimately judged by a human. Yet software is deeply rooted in uncertainty; most complex open-world functionality (e.g., perception of the state of the world by a self-driving vehicle), is either not completely specifiable or it is not cost-effective to do so; software systems are often to be placed into uncertain environments, and there can be uncertainties that need to be We argue that the role of assurance cases is to be the grand unifier for software development, focusing on capturing and managing uncertainty. We discuss three approaches for arguing about safety and security of software under uncertainty, in the absence of fully sound and complete methods: assurance argument rigor, semantic evidence composition and applicability to new kinds of systems, specifically those relying on ML. Marsha Chechik, Rick Salay, Torin Viger, Sahar Kokaly, Mona Rahimi |
FASE | 2 |
| 2019 | A Safety Analysis Method for Perceptual Components in Automated DrivingabstractThe use of machine learning (ML) is increasing in many sectors of safety-critical software development and in particular, for the perceptual components of automated driving (AD) functionality. Although some traditional safety engineering techniques such as FTA and FMEA are applicable to ML components, the unique characteristics of ML create challenges. In this paper, we propose a novel safety analysis method called Classification Failure Mode Effects Analysis (CFMEA) which is specialized to assess classification-based perception in AD. Specifically, it defines a systematic way to assess the risk due to classification failure under adversarial attacks or varying degrees of classification uncertainty across the perception-control linkage. We first present the theoretical and methodological foundations for CFMEA, and then demonstrate it by applying it to an AD case study using semantic segmentation perception trained with the Cityscapes driving dataset. Finally, we discuss how CFMEA results could be used to improve an ML-model. Rick Salay, Matt Angus, Krzysztof Czarnecki 0001 |
ISSRE | 1 |
| 2019 | Lifting Datalog-based analyses to software product linesabstractApplying program analyses to Software Product Lines (SPLs) has been a fundamental research problem at the intersection of Product Line Engineering and software analysis. Different attempts have been made to ”lift” particular product-level analyses to run on the entire product line. In this paper, we tackle the class of Datalog-based analyses (e.g., pointer and taint analyses), study the theoretical aspects of lifting Datalog inference, and implement a lifted inference algorithm inside the Soufflé Datalog engine. We evaluate our implementation on a set of benchmark product lines. We show significant savings in processing time and fact database size (billions of times faster on one of the benchmarks) compared to brute-force analysis of each product individually. Ramy Shahin, Marsha Chechik, Rick Salay |
ESEC/SIGSOFT FSE | 3 |
| 2019 | Contents for a Model-Based Software Engineering Body of KnowledgeabstractAlthough Model-Based Software Engineering (MBE) is a widely accepted Software Engineering (SE) discipline, no agreed-upon core set of concepts and practices (i.e., a Body of Knowledge) has been defined for it yet. With the goals of characterizing the contents of the MBE discipline, promoting a global consistent view of it, clarifying its scope with regard to other SE disciplines, and defining a foundation for the development of educational curricula on MBE, this paper proposes the contents for a Body of Knowledge for MBE. We also describe the methodology that we have used to come up with the proposed list of contents, as well as the results of a survey study that we conducted to sound out the opinion of the community on the importance of the proposed topics and their level of coverage in the existing SE curricula. Loli Burgueño, Federico Ciccozzi, Michalis Famelis, Gerti Kappel, Leen Lambers, Sébastien Mosser 0001, Richard F. Paige, Alfonso Pierantonio, Arend Rensink, Rick Salay, Gabriele Taentzer, Antonio Vallecillo, Manuel Wimmer |
Softw. Syst. Model. | 10 |
| 2018 | An Automated Vehicle Safety Concept Based on Runtime Restriction of the Operational Design DomainabstractAutomated vehicles need to operate safely in a wide range of environments and hazards. The complex systems that make up an automated vehicle must also ensure safety in the event of system failures. This paper proposes an approach and architectural design for achieving maximum functionality in the case of system failures. The Operational Design Domain (ODD) defines the domain over which the automated vehicle can operate safely. We propose modifying a runtime representation of the ODD based on current system capabilities. This enables the system to react with context-appropriate responses depending on the remaining degraded functionality. In addition to proposing an architectural design, we have implemented the approach to prove its viability. The proof of concept has shown promising directions for future work and moved our automated vehicle research platform closer to achieving level 4 automation. Ian Colwell, Buu Phan, Shahwar Saleem, Rick Salay, Krzysztof Czarnecki 0001 |
Intelligent Vehicles Symposium | 4 |
| 2018 | Model Transformation Product LinesabstractModel transformations enable automation in Model-Driven Engineering (MDE) and are key to its success. The emphasis of MDE on using domain-specific languages has caused a proliferation of meta-models, many of them capturing variants of base languages. In this scenario, developing a transformation for a new meta-model is usually performed manually with no reuse, even if comparable transformations for similar meta-models exist. This is a suboptimal process that precludes a wider adoption of MDE in industry. Juan de Lara, Esther Guerra, Marsha Chechik, Rick Salay |
MoDELS | 4 |
| 2018 | Analysing meta-model product linesabstractModel-driven engineering advocates the use of models to describe and automate many software development tasks. The syntax of modelling languages is defined by meta-models, making them essential artefacts. A combination of product line engineering methods and meta-models has been proposed to enable specification of modelling language variants, e.g., to describe a range of systems. However, there is a lack of techniques for ensuring syntactic correctness of all meta-models within a family (including their OCL constraints), and semantic correctness related to properties of individual instances of the different variants. The absence of verification methods at the product-line level can cause synthesis of ill-formed meta-models and problematic feature combinations whose effect at the instance level may go unnoticed. Esther Guerra, Juan de Lara, Marsha Chechik, Rick Salay |
SLE | 4 |
| 2017 | Software Product Lines with Design Choices: Reasoning about Variability and Design UncertaintyabstractWhen designing changes to a software product line (SPL), developers are faced with uncertainty about deciding among multiple possible SPL designs. Since each SPL design encodes a set of related products, dealing with multiple designs means that developers must reason about sets of sets of products. The additional degree of multiplicity is not well described by existing product line abstractions. In this paper, we propose an approach for dealing with design uncertainty within SPLs using a novel composition of variability modelling with an abstraction for capturing and managing design uncertainty. This allows developers to accurately describe the decisions involved in making changes to an SPL during the design stage and provides them with a framework for SPL design space exploration by analyzing and enforcing SPL properties. Michalis Famelis, Julia Rubin, Krzysztof Czarnecki 0001, Rick Salay, Marsha Chechik |
MoDELS | 4 |
| 2017 | Transformations of Software Product Lines: A Generalizing Framework Based on Category TheoryabstractSoftware product lines are used to manage the development of highly complex software with many variants. In the literature, various forms of rule-based product line modifications have been considered. However, when considered in isolation, their expressiveness for specifying combined modifications of feature models and domain models is limited. In this paper, we present a formal framework for product line transformations that is able to combine several kinds of product line modifications presented in the literature. Moreover, it defines new forms of product line modifications supporting various forms of product lines and transformation rules. Our formalization of product line transformations is based on category theory, and concentrates on properties of product line relations instead of their single elements. Our framework provides improved expressiveness and flexibility of software product line transformations while abstracting from the considered type of model. Gabriele Taentzer, Rick Salay, Daniel Strüber 0001, Marsha Chechik |
MoDELS | 2 |
| 2017 | Safety Case Impact Assessment in Automotive Software Systems: An Improved Model-Based Approach
Sahar Kokaly, Rick Salay, Marsha Chechik, Mark Lawford, T. S. E. Maibaum |
SAFECOMP | 2 |
| 2016 | Model management for regulatory compliance: a position paperabstractSoftware has come to mediate many of the activities in life, including financial service platforms, social networks and vehicle control. As a result, governing bodies have responded to this trend by creating standards and regulations to address issues such as safety and privacy. In this context, the compliance of software development to standards and regulations has emerged as a key issue. For software development organizations, compliance is a complex and costly goal to achieve. They may have to comply with multiple standards due to multiple jurisdictions or to address different aspects of the software and these may overlap and conflict with each other. The evolution of standards must be tracked and changes assessed. Evidence for claims of compliance must be collected and managed. Finally, maintaining families of related software products (product lines) further multiplies the effort. In this paper, we propose to exploit the connection between the field of model management and the problem of compliance management and explore how to use model management techniques to address software compliance management issues. Sahar Kokaly, Rick Salay, Mehrdad Sabetzadeh, Marsha Chechik, T. S. E. Maibaum |
MiSE@ICSE | 2 |
| 2016 | Perspectives of Model Transformation Reuse
Marsha Chechik, Michalis Famelis, Rick Salay, Daniel Strüber 0001 |
IFM | 3 |
| 2016 | A model management approach for assurance case reuse due to system evolution
Sahar Kokaly, Rick Salay, Valentin Cassano, T. S. E. Maibaum, Marsha Chechik |
MoDELS | 2 |
| 2016 | Model transformation intents and their properties
Levi Lucio, Moussa Amrani, Jürgen Dingel, Leen Lambers, Rick Salay, Gehan M. K. Selim, Eugene Syriani, Manuel Wimmer |
Softw. Syst. Model. | 5 |
| 2015 | A Generalized Formal Framework for Partial Modeling
Rick Salay, Marsha Chechik |
FASE | 1 |
| 2015 | MU-MMINT: An IDE for Model UncertaintyabstractDevelopers have to work with ever-present design-time uncertainty, i.e., Uncertainty about selecting among alternative design decisions. However, existing tools do not support working in the presence of uncertainty, forcing developers to either make provisional, premature decisions, or to avoid using the tools altogether until uncertainty is resolved. In this paper, we present a tool, called MU-MMINT, that allows developers to express their uncertainty within software artifacts and perform a variety of model management tasks such as reasoning, transformation and refinement in an interactive environment. In turn, this allows developers to defer the resolution of uncertainty, thus avoiding having to undo provisional decisions. See the companion video: http://youtu.be/kAWUm-iFatM. Michalis Famelis, Naama Ben-David, Alessio Di Sandro, Rick Salay, Marsha Chechik |
ICSE (2) | 4 |
| 2015 | Enriching megamodel management with collection-based operatorsabstractMegamodels are often used in MDE to describe collections of models and relationships between them. Typical collection-based operations - map, reduce, filter - cannot be applied directly to megamodels since these operators need to take relationships between models into consideration. In this paper, we propose adapted versions of these operators, demonstrating them on four megamodeling scenarios. We then analyze their applicability for handling industrial-sized megamodels. Finally, we report on a reference implementation of the operators and experimental results using it. Rick Salay, Sahar Kokaly, Alessio Di Sandro, Marsha Chechik |
MoDELS | 1 |
| 2014 | Lifting model transformations to product linesabstractSoftware product lines and model transformations are two techniques used in industry for managing the development of highly complex software. Product line approaches simplify the handling of software variants while model transformations automate software manipulations such as refactoring, optimization, code generation, etc. While these techniques are well understood independently, combining them to get the benefit of both poses a challenge because most model transformations apply to individual models while model-level product lines represent sets of models. In this paper, we address this challenge by providing an approach for automatically ``lifting'' model transformations so that they can be applied to product lines. We illustrate our approach using a case study and evaluate it through a set of experiments. Rick Salay, Michalis Famelis, Julia Rubin, Alessio Di Sandro, Marsha Chechik |
ICSE | 1 |
| 2014 | Supporting early decision-making in the presence of uncertaintyabstractRequirements Engineering (RE) involves eliciting, understanding, and capturing system requirements, which naturally involves much uncertainty. During RE, analysts choose among alternative requirements, gradually narrowing down the system scope, and it is unlikely that all requirements uncertainties can be resolved before such decisions are made. There is a need for methods to support early requirements decision-making in the presence of uncertainty. We address this need by describing a novel technique for early decision-making and tradeoff analysis using goal models with uncertainty. The technique analyzes goal satisfaction over sets of models that can result from resolving uncertainty. Users make choices over possible analysis results, allowing our tool to find critical uncertainty reductions which must be resolved. An iterative methodology guides the resolution of uncertainties necessary to achieve desired levels of goal satisfaction, supporting trade-off analysis in the presence of uncertainty. Jennifer Horkoff, Rick Salay, Marsha Chechik, Alessio Di Sandro |
RE | 2 |
| 2013 | Change Propagation due to Uncertainty Change
Rick Salay, Jan Gorzny, Marsha Chechik |
FASE | 1 |
| 2013 | Transformation of Models Containing Uncertainty
Michalis Famelis, Rick Salay, Alessio Di Sandro, Marsha Chechik |
MoDELS | 2 |
| 2013 | Managing requirements uncertainty with partial models
Rick Salay, Marsha Chechik, Jennifer Horkoff, Alessio Di Sandro |
Requir. Eng. | 1 |
| 2012 | Language Independent Refinement Using Partial Modeling
Rick Salay, Michalis Famelis, Marsha Chechik |
FASE | 1 |
| 2012 | Partial models: Towards modeling and reasoning with uncertaintyabstractModels are good at expressing information about software but not as good at expressing modelers' uncertainty about it. The highly incremental and iterative nature of software development nonetheless requires the ability to express uncertainty and reason with models containing it. In this paper, we build on our earlier work on expressing uncertainty using partial models, by elaborating an approach to reasoning with such models. We evaluate our approach by experimentally comparing it to traditional strategies for dealing with uncertainty as well as by conducting a case study using open source software. We conclude that we are able to reap the benefits of well-managed uncertainty while incurring minimal additional cost. Michalis Famelis, Rick Salay, Marsha Chechik |
ICSE | 2 |
| 2012 | The semantics of partial model transformationsabstractModel transformations are traditionally designed to operate on models that do not contain uncertainty. In previous work, we have developed partial models, i.e., models that explicitly capture uncertainty. In this paper, we study the transformation of partial models. We define the notion of correct lifting of transformations so that they can be applied to partial models. For this, we encode transformations as transfer predicates and describe the mechanics of applying transformations using logic. We demonstrate the approach using two example transformations (addition and deletion) and outline a method for testing the application of transformations using a SAT solver. Reflecting on these preliminary attempts, we discuss the main limitations and challenges and outline future steps for our research on partial model transformation. Michalis Famelis, Rick Salay, Marsha Chechik |
MiSE | 2 |
| 2012 | Towards a Methodology for Verifying Partial Model RefinementsabstractModels are good at expressing information that is known but do not typically have support for representing what information a modeler does not know or does not care about at a particular stage in the software development process. Partial models address this by being able to precisely represent uncertainty about model content. In previous work, we have defined a general approach for defining partial model semantics using a first order logic encoding. In this paper, we use this FO encoding to formally define the conditions for partial model refinement in the manner of the refinement of algebraic specifications. We use this approach to verify both manual refinements and automated transformation-based refinements. We illustrate our approach using example models and transformations. Rick Salay, Marsha Chechik, Jan Gorzny |
ICST | 1 |
| 2012 | Managing Related Models in Vehicle Control Software Development
Rick Salay, Shige Wang, Vivien Suen |
MoDELS | 1 |
| 2012 | Managing requirements uncertainty with partial modelsabstractModels are good at expressing information that is known but do not typically have support for representing what information a modeler does not know at a particular phase in the software development process. Partial models address this by being able to precisely represent uncertainty about model content. In previous work, we developed a general approach for defining partial models and applied it to capturing uncertainty, including reasoning over design models containing uncertainty. In this paper, we show how to apply our approach to managing requirements uncertainty. In particular, we address the problem of specifying uncertainty within a requirements model, refining a model as uncertainty reduces and reasoning with traceability relations between models containing uncertainty. We illustrate our approach using the meeting scheduler example. Rick Salay, Marsha Chechik, Jennifer Horkoff |
RE | 1 |
| 2010 | The Model Role Level - A Vision
Rick Salay, John Mylopoulos |
ER | 1 |
| 2009 | Improving Model Quality Using Diagram Coverage Criteria
Rick Salay, John Mylopoulos |
CAiSE | 1 |
| 2009 | Using Macromodels to Manage Collections of Related Models
Rick Salay, John Mylopoulos, Steve M. Easterbrook |
CAiSE | 1 |
| 2009 | Relationship-based change propagation: A case studyabstractSoftware development is an evolutionary process. Requirements of a system are often incomplete or inconsistent, and hence need to be extended or modified over time. Customers may demand new services or goals that often lead to changes in the design and implementation of the system. These changes are typically very expensive. Even if only local modifications are needed, manually applying them is time-consuming and and error-prone. Thus, it is essential to assist users in propagating changes across requirements, design, and implementation artifacts. In this paper, we take a model-based approach and provide an automated algorithm for propagating changes between requirements and design models. The key feature of our work is explicating relationships between models at the requirements and design levels. We provide conditions for checking validity of these relationships both syntactically and semantically. We show how our algorithm utilizes the relationships between models at different levels to localize the regions that should be modified. We use the IBM Trade 6 case study to demonstrate our approach. Marsha Chechik, Winnie Lai, Shiva Nejati 0001, Jordi Cabot, Zinovy Diskin, Steve M. Easterbrook, Mehrdad Sabetzadeh, Rick Salay |
MiSE@ICSE | 8 |
| 2008 | Managing Models through MacromodelingabstractSoftware development involves the creation and use of many related models yet there are few tools that address the issue of how to work with and manage such collections of models, or "multimodels." We propose a formal multimodeling framework that allows specialized model relationship types to be defined on existing types of models and provides a new type of model with a formal semantics called a macromodel. Macromodels can be used to enhance multimodel development, comprehension, consistency management and evolution. A preliminary evaluation of the framework is done using a detailed example from the telecommunications domain. Rick Salay, John Mylopoulos, Steve M. Easterbrook |
ASE | 1 |