VLDB 2026 Research / reviewers in the wild / expert
Elda Paja
dblp:01/9836
· DBLP profile ↗
24ranked-venue papers
6as first author
8since 2021 · last 2026
0000-0002-8346-2467ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 13 · 1 first-author · 6 since 2021Databases, data management, data science and information retrieval · 8 · 5 first-authorArtificial intelligence and machine learning · 2 · 2 first-authorHuman-computer interaction and ubiquitous computing · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Security Under Pressure: How Agile Teams Experience and Manage Security Requirements
Dahlia Vingtoft Andreasen, Oksana Kulyk, Elda Paja |
REFSQ | 3 |
| 2026 | Aligning processes with high-level requirements: Goal-model-based compliance checkingabstractContext: Process compliance refers to the alignment between business processes and regulatory requirements. Compliance is challenging because it requires expressing the intent and possible interpretations of laws into formal models, aligning models with foreseeable executions, and inspecting whether these executions could generate violations. While business process compliance has been studied through conformance checking techniques, most regulatory requirements are defined in subjective and high-level terms, limiting the application of rule- and alignment-checking algorithms to restricted cases where requirements are formally specified. Objective: This paper investigates how compliance can be assessed against high-level and non-functional requirements rather than low-level process events. We aim to raise the abstraction level of compliance checking from specific task execution to the satisfaction of high-level business goals and subjective qualities. Method: We propose a framework that links process models with goal models to capture functional decomposition, non-functional requirements, and contribution links, developed iteratively with legal practitioners. Business processes (imperative and declarative) are represented as labeled transition systems (LTS), while goals and qualities are modeled using iStar models. A mapping function synchronizes process activities with goal elements. Compliance is then checked through state reachability, where all qualities are satisfied, with computational support from the Kogi tool. We refine compliance into weak, strong, and monotonic quality satisfaction, also called stability. Results: From a technical view, the framework has demonstrated expressiveness, feasibility, and modularity by distinguishing strong, weak, and monotonic compliance. From a legal perspective, it has shown potential to enhance transparency in evidence-based decision-making and supports the traceability of knowledge bases underpinning system development, as illustrated by the use case from Regulation EC 261/2004. Conclusions: The proposed approach enables compliance checking against high-level and non-functional requirements, showing potential to distinguish among compliant behaviors and increase goal satisfaction traceability compared to rule-based conformance methods. Juanita Caballero-Villalobos, Hubert Baumeister, Elda Paja, Olga Kokoulina, Hugo A. López 0001 |
Inf. Softw. Technol. | 3 |
| 2026 | Consent under control with ProPrivacy: Business process compliance verification for GDPR-consent requirementsabstractContext: Since its enforcement in 2018, the General Data Protection Regulation (GDPR) has continued to shape how organizations, in the European Economic Area, design and operate their data-driven services. Consent management, in particular, remains a cornerstone of compliance, but it has also become increasingly complex with the rise of data-intensive business models, digital health platforms, and AI-powered services. Despite the availability of technical and organizational tools, many companies still struggle to adapt legacy and large-scale processes to meet GDPR’s consent requirements. Knowledge about these processes is often fragmented across organizational silos, and documentation is incomplete, making re-engineering activities both tedious and error-prone. Objectives: Companies relies on experts for the re-engineering and validation of their processes, while a comprehensive method is still missing to support them in verifying the compliance of their processes with consent. To address these challenges, this paper proposes a model-based approach that supports business and privacy experts in aligning operational processes with GDPR consent principles. Methods.: Rather than introducing a new language that would require analysts modeling processes from scratch, our framework, ProPrivacy, builds on the widely adopted Business Process Model and Notation 2.0 (BPMN 2.0) modeling language, allowing analysts to enrich existing models with consent requirements. To mitigate verification errors and reduce the effort in analyzing complex models, ProPrivacy then automatically verifies compliance with key GDPR principles related to specific and freely given consent and data minimization. We demonstrate the applicability and scalability of our approach on realistic processes from the healthcare domain, where the management of sensitive data continues to present critical privacy challenges. Conclusions: The results suggest that automated verification of business processes can not only support organizations in achieving compliance with GDPR but also serve as a foundation for certifying accountable and transparent business processes. Marco Robol, Mattia Salnitri, Elda Paja, Paolo Giorgini |
Inf. Softw. Technol. | 3 |
| 2025 | No Silver Bullet: Towards Demonstrating Secure Software Development for Small and Medium Enterprises in a Business-to-Business ModelabstractSoftware developing small and medium enterprises (SMEs) play a crucial role as suppliers to larger corporations and public administration.It is therefore necessary for them to be able to demonstrate that their products meet certain security criteria, both to gain trust of their customers and to comply to standards that demand such a demonstration.In this study we have investigated ways for SMEs to demonstrate their security when operating in a business-tobusiness model, conducting semi-structured interviews (𝑁 = 16) with practitioners from different SMEs in Denmark and validating our findings in a follow-up workshop (𝑁 = 6).Our findings indicate five distinctive security demonstration approaches, namely: Certifications, Reports, Questionnaires, Interactive Sessions and Social Proof.We discuss the challenges, benefits, and recommendations related to these approaches, concluding that none of them is a one-size-fits all solution and that more research into relative advantages of these approaches and their combinations is needed. CCS Concepts• Security and privacy → Social aspects of security and privacy. Raha Asadi, Bodil Biering, Vincent van Dijk, Oksana Kulyk, Elda Paja |
CHI | 5 |
| 2024 | Generative AI in Software Engineering Must Be Human-Centered: The Copenhagen Manifesto
Daniel Russo 0002, Sebastian Baltes, Niels van Berkel, Paris Avgeriou, Fabio Calefato, Beatriz Cabrero-Daniel, Gemma Catolino, Jürgen Cito, Neil A. Ernst, Thomas Fritz 0001, Hideaki Hata, Reid Holmes, Maliheh Izadi, Foutse Khomh, Mikkel Baun Kjærgaard, Grischa Liebel, Alberto Lluch-Lafuente, Stefano Lambiase, Walid Maalej, Gail C. Murphy, Nils Brede Moe, Gabrielle O'Brien, Elda Paja, Mauro Pezzè, John Stouby Persson, Rafael Prikladnicki, Paul Ralph, Martin P. Robillard, Thiago Rocha Silva, Klaas-Jan Stol, Margaret-Anne D. Storey, Viktoria Stray, Paolo Tell, Christoph Treude, Bogdan Vasilescu |
J. Syst. Softw. | 23 |
| 2023 | Philanthropic conference-based requirements engineering in time of pandemic and beyond
Meira Levy, Irit Hadar, Jennifer Horkoff, Jane Huffman Hayes, Barbara Paech, Alex Dekhtyar, Gunter Mussbacher, Elda Paja, Tong Li 0001, Seok-Won Lee, Dongfeng Fang |
Requir. Eng. | 8 |
| 2023 | Consent Verification MonitoringabstractAdvances in personalization of digital services are driven by low-cost data collection and processing, in addition to the wide variety of third-party frameworks for authentication, storage, and marketing. New privacy regulations, such as the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act, increasingly require organizations to explicitly state their data practices in privacy policies. When data practices change, a new version of the policy is released. This can occur a few times a year, when data collection or processing requirements are rapidly changing. Consent evolution raises specific challenges to ensuring GDPR compliance. We propose a formal consent framework to support organizations, data users, and data subjects in their understanding of policy evolution under a consent regime that supports both the retroactive and non-retroactive granting and withdrawal of consent. The contributions include (i) a formal framework to reason about data collection and access under multiple consent granting and revocation scenarios, (ii) a scripting language that implements the consent framework for encoding and executing different scenarios, (iii) five consent evolution use cases that illustrate how organizations would evolve their policies using this framework, and (iv) a scalability evaluation of the reasoning framework. The framework models are used to verify when user consent prevents or detects unauthorized data collection and access. The framework can be integrated into a runtime architecture to monitor policy violations as data practices evolve in real time. The framework was evaluated using the five use cases and a simulation to measure the framework scalability. The simulation results show that the approach is computationally scalable for use in runtime consent monitoring under a standard model of data collection and access and practice and policy evolution. Marco Robol, Travis D. Breaux, Elda Paja, Paolo Giorgini |
ACM Trans. Softw. Eng. Methodol. | 3 |
| 2022 | #34;You have been in Close Contact with a Person Infected with COVID-19 and you may have been Infected#34;: Understanding Privacy Concerns, Trust and Adoption in Mobile COVID-19 Tracing Across Four CountriesabstractThrough the past two and a half years, COVID-19 has swept through the world and new technologies for mitigating spread, such as exposure notification applications and contact tracing, have been implemented in many countries. However, the uptake has differed from country to country and it has not been clear if culture, death rates or information dissemination have been a factor in their adoption rate. However, these apps introduce issues of trust and privacy protection, which can create challenges in terms of adoptions and daily use. In this paper we present the results from a cross-country survey study of potential barriers to adoption of in particular COVID-19 contact tracing apps. We found that people's existing privacy concerns are an have a reverse correlation with adoption behavior but that the geographical location, as well as other demographics, such as age and gender, do not have significant effect on either adoption of the app or privacy concerns. Instead, a better understanding of what data is collected through the apps lead to a higher level of adoption. We provide suggestions for how to approach the development and deployment of contact tracing apps and more broadly health tracking apps. Oksana Kulyk, Lauren Britton-Steele, Elda Paja, Melanie Duckert, Louise Barkhuus |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2019 | Consent Verification Under Evolving Privacy PoliciesabstractPersonal data provides important business value, for example, in the personalization of services. In addition, companies are moving toward new business models, in which products and services are offered without charge to users, but in exchange for targeted advertising revenue. New privacy regulations require organizations to explicitly state their data practices in privacy policies, including which data types will be collected. By consenting to data collections described in a policy, the user acknowledges that he or she is granting the company the authorizations needed to access their data. When data practices change, a new version of the policy is released. This release can occur a few times a year, when requirements are rapidly changing for the collection and processing of personal data. Furthermore, the user may change his or her privacy consent by opting in or out of the policy. We propose a formal framework to support companies and users in their understanding of policies evolution under consent regime that supports both retroactive and non-retroactive consent and consent revocation. Preliminary results include an ontology for policy evolution, expressed in Description Logic, that can be used to formalize consent and data collection logs and then query for which data types can be legally accessed. Marco Robol, Travis D. Breaux, Elda Paja, Paolo Giorgini |
RE | 3 |
| 2019 | Goal-oriented requirements engineering: an extended systematic mapping studyabstractOver the last two decades, much attention has been paid to the area of goal-oriented requirements engineering (GORE), where goals are used as a useful conceptualization to elicit, model, and analyze requirements, capturing alternatives and conflicts. Goal modeling has been adapted and applied to many sub-topics within requirements engineering (RE) and beyond, such as agent orientation, aspect orientation, business intelligence, model-driven development, and security. Despite extensive efforts in this field, the RE community lacks a recent, general systematic literature review of the area. In this work, we present a systematic mapping study, covering the 246 top-cited GORE-related conference and journal papers, according to Scopus. Our literature map addresses several research questions: we classify the types of papers (e.g., proposals, formalizations, meta-studies), look at the presence of evaluation, the topics covered (e.g., security, agents, scenarios), frameworks used, venues, citations, author networks, and overall publication numbers. For most questions, we evaluate trends over time. Our findings show a proliferation of papers with new ideas and few citations, with a small number of authors and papers dominating citations; however, there is a slight rise in papers which build upon past work (implementations, integrations, and extensions). We see a rise in papers concerning adaptation/variability/evolution and a slight rise in case studies. Overall, interest in GORE has increased. We use our analysis results to make recommendations concerning future GORE research and make our data publicly available. Jennifer Horkoff, Fatma Basak Aydemir, Evellin Cardoso, Tong Li 0001, Alejandro Maté, Elda Paja, Mattia Salnitri, Luca Piras 0003, John Mylopoulos, Paolo Giorgini |
Requir. Eng. | 6 |
| 2017 | Goal Models for Acceptance Requirements Analysis and Gamification Design
Luca Piras 0003, Elda Paja, Paolo Giorgini, John Mylopoulos |
ER | 2 |
| 2017 | Gamification solutions for software acceptance: A comparative study of Requirements Engineering and Organizational Behavior techniquesabstractGamification is a powerful paradigm and a set of best practices used to motivate people carrying out a variety of ICT-mediated tasks. Designing gamification solutions and applying them to a given ICT system is a complex and expensive process (in time, competences and money) as software engineers have to cope with heterogeneous stakeholder requirements on one hand, and Acceptance Requirements on the other, that together ensure effective user participation and a high level of system utilization. As such, gamification solutions require significant analysis and design as well as suitable supporting tools and techniques. In this work, we compare concepts, tools and techniques for gamification design drawn from Software Engineering and Human and Organizational Behaviors. We conduct a comparison by applying both techniques to the specific Meeting Scheduling exemplar used extensively in the Requirements Engineering literature. Luca Piras 0003, Elda Paja, Paolo Giorgini, John Mylopoulos, Roberta Cuel, Diego Ponte |
RCIS | 2 |
| 2016 | Can Goal Reasoning Techniques Be Used for Strategic Decision-Making?
Elda Paja, Alejandro Maté, Carson C. Woo, John Mylopoulos |
ER | 1 |
| 2016 | Security attack analysis using attack patternsabstractDiscovering potential attacks on a system is an essential step in engineering secure systems, as the identified attacks will determine essential security requirements. The prevalence of Socio-Technical Systems (STSs) makes attack analysis particularly challenging. These systems are composed of people and organizations, their software systems, as well as physical infrastructures. As such, a thorough attack analysis needs to consider strategic (social and organizational) aspects of the involved people and organizations, as well as technical aspects affecting software systems and the physical infrastructure, requiring a large amount of security knowledge which is difficult to acquire. In this paper, we propose a systematic approach to efficiently leverage a comprehensive attack knowledge repository (CAPEC) in order to identify realistic and detailed attack behaviors, avoiding severe repercussions of security breaches. In particular, we propose a systematic method to model CAPEC attack patterns, which has been applied to 102 patterns, in order to semi-automatically select and apply such patterns. Using the CAPEC patterns as part of a systematic and tool-supported process, we can efficiently operationalize attack strategies and identify realistic alternative attacks on an STS. We validate our proposal by performing a case study on a smart grid scenario. Tong Li 0001, Elda Paja, John Mylopoulos, Jennifer Horkoff, Kristian Beckers |
RCIS | 2 |
| 2016 | Privacy Requirements: Findings and Lessons Learned in Developing a Privacy PlatformabstractInformation practices and systems that make use of personal and health-related information are governed by European laws and regulations to prevent unauthorized use and disclosure. Failure to comply with these laws and regulations results in huge monetary sanctions, which both private companies and public administrations want to avoid. How to comply with these laws, requires understanding the privacy requirements imposed on information systems. A holistic approach to privacy requirements specification calls for understanding not only the requirements derived from law, but also citizens' needs with respect to privacy. In this paper, we report on our experience in conducting privacy requirements engineering as part of a H2020 European Project, namely VisiOn (Visual Privacy Management in User Centric Open Requirements) for the development of a privacy platform to improve the interaction between Public Administrations (PA) and citizens, while guarding the privacy of the latter. Specifically, we present the process for eliciting, classifying, prioritizing, and validating privacy requirements for the two types of users, namely PA and citizen. The process is applied to different cases spanning from healthcare to other e-governmental initiatives, with the active involvement of the corresponding PAs. We report on findings and lessons learned from this experience. Mohamad Gharib, Mattia Salnitri, Elda Paja, Paolo Giorgini, Haralambos Mouratidis, Michalis Pavlidis, José Fran. Ruiz, Sandra Fernandez, Andrea Della Siria |
RE | 3 |
| 2016 | Goal-Oriented Requirements Engineering: A Systematic Literature MapabstractOver the last two decades, much attention has been paid to the area of Goal-Oriented Requirements Engineering(GORE), where goals are used as a useful conceptualization to elicit, model and analyze requirements, capturing alternatives and conflicts. Goal modeling has been adapted and applied to many sub-topics within RE and beyond, such as agent-orientation, aspect-orientation, business intelligence, model-driven development, security, and so on. Despite extensive efforts in this field, the RE community lacks a recent, general systematic literature review of the area. As a first step towards providing a GORE overview, we present a Systematic Literature Map, focusing on GORE-related publications at a high-level, categorizing and analyzing paper information in order to answer several research questions, while omitting a detailed analysis of individual paper quality. Our Literature Map covers the 246 top-cited GORE-related conference and journal papers, according to Scopus, classifying them into a number of descriptive paper types and topics, providing an analysis of the data, which is made publicly available. We use our analysis results to make recommendations concerning future GORE research. Jennifer Horkoff, Fatma Basak Aydemir, Evellin Cardoso, Tong Li 0001, Alejandro Maté, Elda Paja, Mattia Salnitri, John Mylopoulos, Paolo Giorgini |
RE | 6 |
| 2015 | Holistic security requirements analysis: An attacker's perspectiveabstractThe ever-growing complexity of systems makes their protection more challenging, as a single vulnerability or exposure of any component of the system can lead to serious security breaches. This problem is exacerbated by the fact that the system development community has not kept up with advances in attack knowledge. In this demo paper, we propose a holistic attack analysis approach to identify and tackle both atomic and multistage attacks, taking into account not only software attacks but also attacks that are targeted at people and hardware. To bridge the knowledge gap between attackers and defenders, we systematically analyze and refine the malicious desires of attackers (i.e., anti-goals), and leverage a comprehensive attack pattern repository (CAPEC) to operationalize attacker goals into concrete attack actions. Based on the results of our attack analysis, appropriate security controls can be selected to effectively tackle potential attacks. Tong Li 0001, Elda Paja, John Mylopoulos, Jennifer Horkoff, Kristian Beckers |
RE | 2 |
| 2015 | Modelling and reasoning about security requirements in socio-technical systems
Elda Paja, Fabiano Dalpiaz, Paolo Giorgini |
Data Knowl. Eng. | 1 |
| 2013 | Managing Security Requirements Conflicts in Socio-Technical Systems
Elda Paja, Fabiano Dalpiaz, Paolo Giorgini |
ER | 1 |
| 2013 | Specifying and Reasoning over Socio-Technical Security Requirements with STS-Tool
Elda Paja, Fabiano Dalpiaz, Mauro Poggianella, Pierluigi Roberti, Paolo Giorgini |
ER | 1 |
| 2013 | Trust-based specification of sociotechnical systems
Elda Paja, Amit K. Chopra, Paolo Giorgini |
Data Knowl. Eng. | 1 |
| 2012 | STS-tool: Socio-technical Security Requirements through social commitmentsabstractSecurity Requirements Engineering (SRE) deals with the elicitation and analysis of security needs to specify security requirements for the system-to-be. In previous work, we have presented STS-ml, a security requirements modelling language for Socio-Technical Systems (STSs) that elicits security needs, using a goal-oriented approach, and derives the security requirements specification based on these needs. Particularly, STS-ml relates security to the interaction among actors in the STS. In this paper, we present STS-Tool, the modelling and analysis support tool for STS-ml. STS-Tool allows designers to model a STS at a high-level of abstraction, while expressing security needs over the interactions between the actors in the STS, and derive security requirements in terms of social commitments - promises with contractual validity - once the modelling is done. Elda Paja, Fabiano Dalpiaz, Mauro Poggianella, Pierluigi Roberti, Paolo Giorgini |
RE | 1 |
| 2011 | Modeling Design Patterns with Description Logics: A Case Study
Yudistira Asnar, Elda Paja, John Mylopoulos |
CAiSE | 2 |
| 2011 | Sociotechnical Trust: An Architectural Approach
Amit K. Chopra, Elda Paja, Paolo Giorgini |
ER | 2 |