VLDB 2026 Research / reviewers in the wild / expert
Joanna M. van de Mortel-Fronczak
dblp:118/6121 · also Asia van de Mortel-Fronczak
· DBLP profile ↗
13ranked-venue papers
0as first author
3since 2021 · last 2023
0000-0002-1381-5132ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 4 · 2 since 2021Human-computer interaction and ubiquitous computing · 4Artificial intelligence and machine learning · 2Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Validating communication of a dynamic traffic management system
J. J. Verbakel, Wan J. Fokkink, Joanna M. van de Mortel-Fronczak, Jacobus E. Rooda |
ICECCS | 3 |
| 2023 | Eclipse ESCET™: The Eclipse Supervisory Control Engineering ToolkitabstractAbstract The Eclipse Supervisory Control Engineering Toolkit (ESCET™) is an open-source project to provide a model-based approach and toolkit for developing supervisory controllers, targeting their entire engineering process. It supports synthesis-based engineering of supervisory controllers for discrete-event systems, combining model-based engineering with computer-aided design to automatically generate correct-by-construction controllers. At its heart is supervisory controller synthesis, a formal technique for the automatic derivation of supervisory controllers from the unrestricted system behavior and system requirements. Vital for the future development of these techniques and tools is the ESCET project’s open environment, allowing industry and academia to collaborate on creating an industrial-strength toolkit. We report on some crucial developments of the toolkit in the context of research projects with Rijkswaterstaat and ASML that have considerably improved its capability to deal with the complexity of real-life systems as well as its usability. Wan J. Fokkink, Martijn A. Goorden, Dennis Hendriks, Dirk A. van Beek, Albert T. Hofkamp, Ferdie F. H. Reijnen, L. F. Pascal Etman, Lars Moormann, Joanna M. van de Mortel-Fronczak, Michel A. Reniers, Jacobus E. Rooda, Bram van der Sanden, Ramon R. H. Schiffelers, Sander Thuijsman, J. J. Verbakel, J. A. Vogel |
TACAS (2) | 9 |
| 2023 | Synthesis and Implementation of Distributed Supervisory Controllers With Communication DelaysabstractThis paper discusses a method to distribute a synthesized supervisor for implementation on multiple physical controllers. Dependency structure matrices are used to determine a distribution of a system. The supervisor is then distributed accordingly, using an existing localization method. Communication delays between the distributed components of a supervisor may affect its behavior, due to changes in the order of events. Therefore, a new delay-robustness check is proposed and where needed mutex locks are employed to make the distributed supervisor delay robust. The controller performance is analyzed and optimized through a parameter study and a mutex implementation evaluation. In a real-life case study, the method is demonstrated by synthesizing, distributing, implementing, and validating a supervisor for a road tunnel.Note to Practitioners—This article is motivated by the desire to bridge the gap between the asynchronous, discrete-event, world of synthesized supervisors and the synchronous, real-time, world of networked PLC controllers. The main focus lies on maintaining the guarantees of supervisor synthesis while taking into account all aspects of real-time implementation, such as cycle-driven code execution and communication delays. Lars Moormann, Reinier H. J. Schouten, Joanna M. van de Mortel-Fronczak, Wan J. Fokkink, Jacobus E. Rooda |
IEEE Trans Autom. Sci. Eng. | 3 |
| 2020 | Data Logging and Reconstruction of Discrete-event System BehaviorabstractIn case of malfunctions or accidents related to an infrastructural system, it is useful to reconstruct and analyze the behavior that led to such an undesired situation. Understanding the behavior can help in improving the plant and the supervisory controller such that this situation is not encountered again. Many computer-controller mechanical systems use programmable logic controllers (PLCs) to implement the supervisory controller and to collect data from the system. Currently, incident analysis for PLCs often consists of plotting actuator and sensor signals to reconstruct and analyze the behavior. This way of analyzing is laborious and difficult to interpret for engineers not familiar with the system. In this paper, a different behavioral reconstruction and analysis method is proposed. In this method, models developed during the design of the supervisory controller are reused. From the collected data, a finite-state automaton is constructed. This automaton can be used for behavioral reconstruction via simulation, which is simpler and more intuitive. Moreover, by comparing the logged behavior with the behavior defined in the available models, faults can be identified. As a proof of concept, the behavior of a real movable bridge has been logged from a PLC, reconstructed, simulated, and analyzed. Ferdie F. H. Reijnen, Joanna M. van de Mortel-Fronczak, Jacobus E. Rooda |
ICARCV | 2 |
| 2020 | The Road Ahead for Supervisor Synthesis
Martijn A. Goorden, Lars Moormann, Ferdie F. H. Reijnen, J. J. Verbakel, Dirk A. van Beek, Albert T. Hofkamp, Joanna M. van de Mortel-Fronczak, Michel A. Reniers, Wan J. Fokkink, Jacobus E. Rooda, L. F. Pascal Etman |
SETTA | 7 |
| 2019 | The Impact of Requirement Splitting on the Efficiency of Supervisory Control Synthesis
Martijn A. Goorden, Joanna M. van de Mortel-Fronczak, Michel A. Reniers, Wan J. Fokkink, Jacobus E. Rooda |
FMICS | 2 |
| 2018 | Systematic Model-Based Design and Implementation of Supervisors for Advanced Driver Assistance SystemsabstractThe number of advanced driver assistance systems (ADASs) and the level of automation in modern vehicles is increasing at a rapid pace. Moreover, multiple of these ADASs can be active at the same time and therefore may need to interact with each other. As a consequence, the design of the supervisor layer that is responsible for proper coordination of the control tasks performed by the low-level ADASs controllers is becoming more complex and safety-critical. For this reason, there is a strong need for automated synthesis tools that lead to supervisors that are safe by design. In this paper, we present a systematic approach to model-based supervisor design using discrete-event system representations. In particular, this paper shows that the proposed method is suitable to deal with the multiple and complex systems of interacting ADASs. To be more specific, in contrast to current practice, which often relies on textual specifications and exhaustive testing, the proposed method has four main advantages: 1) it is based on mathematically specified requirements that only allow one interpretation; 2) it prevents blocking situations by design; 3) it guarantees correctness in the sense that the resulting supervisor satisfies all the specified requirements; and 4) code is generated from the obtained supervisor which eliminates the need for manual coding. The proposed method is demonstrated by means of a case study on cruise control and adaptive cruise control. The resulting supervisor is validated by simulations and experiments on a modern passenger vehicle. Based on the results presented in this paper, it can be concluded that the model-based supervisor design, simulation, and implementation method is promising and powerful for future applications in the automated vehicle systems. Tim Korssen, Victor S. Dolk, Joanna M. van de Mortel-Fronczak, Michel A. Reniers, W. P. M. H. Heemels |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2014 | CIF 3: Model-Based Engineering of Supervisory Controllers
Dirk A. van Beek, Wan J. Fokkink, Dennis Hendriks, Albert T. Hofkamp, Jasen Markovski, Joanna M. van de Mortel-Fronczak, Michel A. Reniers |
TACAS | 6 |
| 2009 | Integration and Test Sequencing for Complex SystemsabstractThe integration and test phase of complex manufacturing machines, like an ASML lithographic manufacturing system, is expensive and time consuming. The tests that can be performed at a certain point in time during the integration phase depend on the modules that are integrated and, therefore, on the preceding integration sequence. In this paper, we introduce a mathematical model to describe an overall integration and test sequencing problem, and we propose an algorithm to solve this problem. The method is a combination of integration sequencing and test sequencing. Furthermore, we introduce several strategies that determine when test phases should start. With a case study within the development of a software release that is used to control an ASML lithographic machine, we show that the described method and strategies can be used to solve real-life problems. R. Boumen, Ivo S. M. de Jong, J. M. G. Mestrom, Joanna M. van de Mortel-Fronczak, Jacobus E. Rooda |
IEEE Trans. Syst. Man Cybern. Part A | 4 |
| 2009 | Hierarchical Test Sequencing for Complex SystemsabstractTesting complex systems, such as the ASML TWINSCAN lithographic machine, is expensive and time consuming. In a previous work, a test sequencing method to calculate time-optimal test sequences has been developed. Because complex systems are composed of several subsystems, which are again composed of several modules, there exists a need to hierarchically model test sequencing problems. Such a hierarchical test sequencing problem consists of a high-level model that describes a test sequencing problem at the system level, and one or more low-level models that describe the test sequencing problems at the subsystem or module level. The tests at the system level correspond to the solutions of low-level problems. This paper describes a hierarchical test sequencing model and proposes two algorithms to compute an optimal test sequence. The benefits of hierarchically modeling a problem are less computational effort and less modeling effort, because not all relations are needed. This is illustrated by a small example. The industrial relevance of this method is illustrated on a case study related to a manufacturing testing phase of a lithographic machine. R. Boumen, Sui Ruan, Ivo S. M. de Jong, Joanna M. van de Mortel-Fronczak, Jacobus E. Rooda, Krishna R. Pattipati |
IEEE Trans. Syst. Man Cybern. Part A | 4 |
| 2008 | Test Sequencing in Complex Manufacturing SystemsabstractTesting complex manufacturing systems, such as an ASML lithographic machine, takes up to 45% of the total development time of a system. The problem of which tests must be executed in what sequence to ensure in the shortest possible test time that the system works, which is the test-sequencing problem, was already solved by Pattipati et al. for the diagnosis of systems during operation. Test-sequencing problems during the development and manufacturing phases of systems, however, require a different approach than the test-sequencing problems during operation. In this paper, the test problem description and algorithms developed by Pattipati et al. are extended to solve test-sequencing problems for the development and manufacturing of manufacturing systems. For a case study in the manufacturing process of an ASML lithographic machine, it is shown that solving a test-sequencing problem with this method can reduce the test time by 15% to 30% compared to experts that solve this problem manually. R. Boumen, Ivo S. M. de Jong, J. W. H. Vermunt, Joanna M. van de Mortel-Fronczak, Jacobus E. Rooda |
IEEE Trans. Syst. Man Cybern. Part A | 4 |
| 2008 | Risk-Based Stopping Criteria for Test SequencingabstractTesting complex manufacturing systems, like ASML lithographic machines, can take up to 45% of the total development time. The decision of when to stop testing is often difficult to make because less testing may leave critical faults in the system, while more testing increases time-to-market. In this paper, we solve the problem of deciding when to stop testing by introducing a test-sequencing method that incorporates several stopping criteria. These stopping criteria consist of objectives and constraints on the test cost and the remaining risk cost. For a given problem, a suitable stopping criterion can be chosen. For example, with the risk-based stopping criterion, testing stops when the test time or cost exceeds the risk cost. Furthermore, we show that it also is possible to model reliability problems with this test-sequencing method. The method is demonstrated on ASML systems with two case studies. The first case study was conducted in the test phase during the development of the software that is used to control an ASML lithographic machine. The second case study was conducted on the reliability testing of a lithographic machine. R. Boumen, Ivo S. M. de Jong, J. W. H. Vermunt, Joanna M. van de Mortel-Fronczak, Jacobus E. Rooda |
IEEE Trans. Syst. Man Cybern. Part A | 4 |
| 2005 | Verification of timed chi models using uppaal
Elena M. Bortnik, Dirk A. van Beek, Joanna M. van de Mortel-Fronczak, Jacobus E. Rooda |
ICINCO | 3 |