VLDB 2026 Research / reviewers in the wild / expert
Javier Cámara 0001
dblp:13/2872 · also Javier Cámara Moreno
· DBLP profile ↗
42ranked-venue papers
25as first author
15since 2021 · last 2026
0000-0001-6717-4775ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 33 · 22 first-author · 12 since 2021Systems, architecture and hardware · 4 · 1 first-author · 2 since 2021Security and privacy · 2 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorTheory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Automated Planning for Task-Based Cyber-Physical Systems under Multiple Sources of UncertaintyabstractIn smart Cyber-Physical Systems (sCPS), a critical challenge lies in task planning under uncertainty. There is a broad body of work in the area with approaches able to individually deal with different classes of constraints (e.g., ordering, structural) and uncertainties (e.g., in sensing, actuation, latencies). However, these uncertainties are rarely independent and often compound, affecting the satisfaction of goals and other system properties in subtle and often unpredictable ways. According to the Uncertainty Interaction Problem recently proposed in the literature, approaches are needed to identify multiple sources of uncertainty and quantify their impact. In this article, we deal with two types of uncertainty present in task-based sCPS, namely temporal availability constraints and element reliability . The former refers to the availability of a given system element required to perform a task, which may be unavailable for certain periods of time, while the latter is related to system elements that may fail at some point with some probability. This article presents an approach to consider both uncertainties, employing genetic algorithms to incorporate them effectively into planning for deciding how to best adapt the system to changes at runtime. Our method is evaluated in the domains of electric vehicle charging and healthcare robotics. Our evaluation shows that: (i) the proposed approach outperforms a baseline mixed-integer linear programming (MILP) algorithm capable of generating optimal solutions in the absence of uncertainty, providing more robust solutions to failures, changes in temporal availability, or both sources of uncertainty combined; (ii) both sources of uncertainty have a strong and compound impact on the quality of the solutions provided; and (iii) the proposed approach significantly reduces computational cost, with respect to the MILP-based optimization. Raquel Sánchez-Salas, Javier Troya, Javier Cámara 0001 |
ACM Trans. Auton. Adapt. Syst. | 3 |
| 2025 | Robot Mission Adaptation with Quantitative Guarantees
Ioannis Stefanakos, Javier Cámara 0001, Radu Calinescu |
SEAA | 3 |
| 2025 | Exploring the interaction of design variability and stochastic operational uncertainties in software-intensive systems through the lens of modelingabstractAbstract In software-intensive systems, navigating the complexities that emerge from the interaction of design variability and stochastic operational uncertainties presents a daunting challenge. This paper delves into the dynamics between these two dimensions of uncertainty, offering novel insights about how modeling can contribute to the analysis of their combined impact upon system properties. By elevating the abstraction level at which probabilistic models are conceptualized, our approach enables an integrated analysis framework that considers both structural and quantitative dimensions of design spaces. Through the introduction of novel language constructs, our methodology facilitates the direct referencing of structural relationships within probabilistic behavioral specifications. Furthermore, the adoption of novel quantifiers in probabilistic temporal logic enables evaluating complex properties across diverse design variants, thereby streamlining the assessment of guarantees within the solution space. We demonstrate the feasibility of this approach on four case studies, showcasing its potential to offer comprehensive insights into the trade-offs and decision-making processes inherent in managing different types of structural design variability and operational uncertainties in software-intensive systems. Javier Cámara 0001 |
Softw. Syst. Model. | 1 |
| 2025 | A declarative approach and benchmark tool for controlled evaluation of microservice resiliency patternsabstractAbstract Microservice developers increasingly use resiliency patterns such as Retry and Circuit Breaker to cope with remote services that are likely to fail. However, there is still little research on how the invocation delays typically introduced by those resiliency patterns may impact application performance under varying workloads and failure scenarios. This article presents a novel approach and benchmark tool for experimentally evaluating the performance impact of existing resiliency patterns in a controlled setting. The main novelty of this approach resides in the ability to declaratively specify and automatically generate multiple testing scenarios involving different resiliency patterns, which one can implement using any programming language and resilience library. The article illustrates the benefits of the proposed approach and tool by reporting on an experimental study of the performance impact of the Retry and Circuit Breaker resiliency patterns in two mainstream programming languages (C# and Java) using two popular resilience libraries (Polly and Resilience4j), under multiple service workloads and failure rates. Our results show that, under low to moderate failure rates, both resiliency patterns effectively reduce the load over the application's target service with barely any impact on the application's performance. However, as the failure rate increases, both patterns significantly degrade the application's performance, with their effect varying depending on the service's workload and the patterns' programming language and resilience library. Carlos M. Aderaldo, Thiago M. Costa, Davi M. Vasconcelos, Nabor das Chagas Mendonça, Javier Cámara 0001, David Garlan |
Softw. Pract. Exp. | 5 |
| 2024 | MONDEO-Tactics5G: Multistage botnet detection and tactics for 5G/6G networksabstractMobile malware is a malicious code specifically designed to target mobile devices to perform multiple types of fraud. The number of attacks reported each day is increasing constantly and is causing an impact not only at the end-user level but also at the network operator level. Malware like FluBot contributes to identity theft and data loss but also enables remote Command & Control (C2) operations, which can instrument infected devices to conduct Distributed Denial of Service (DDoS) attacks. Current mobile device-installed solutions are not effective, as the end user can ignore security warnings or install malicious software. This article designs and evaluates MONDEO-Tactics5G - a multistage botnet detection mechanism that does not require software installation on end-user devices, together with tactics for 5G network operators to manage infected devices. We conducted an evaluation that demonstrates high accuracy in detecting FluBot malware, and in the different adaptation strategies to reduce the risk of DDoS while minimising the impact on the clients' satisfaction by avoiding disrupting established sessions. Bruno Sousa, Nuno Antunes, Javier Cámara 0001, Ryan Wagner, Bradley R. Schmerl, David Garlan, Pedro Fidalgo |
Comput. Secur. | 4 |
| 2024 | Towards standarized benchmarks of LLMs in software modeling tasks: a conceptual frameworkabstractAbstract The integration of Large Language Models (LLMs) in software modeling tasks presents both opportunities and challenges. This Expert Voice addresses a significant gap in the evaluation of these models, advocating for the need for standardized benchmarking frameworks. Recognizing the potential variability in prompt strategies, LLM outputs, and solution space, we propose a conceptual framework to assess their quality in software model generation. This framework aims to pave the way for standardization of the benchmarking process, ensuring consistent and objective evaluation of LLMs in software modeling. Our conceptual framework is illustrated using UML class diagrams as a running example. Javier Cámara 0001, Loli Burgueño, Javier Troya |
Softw. Syst. Model. | 1 |
| 2024 | Foreword: SEAMS 2022 Special IssueabstractThe Symposium on Software Engineering for Adaptive and Self-Managing Systems (SEAMS) provides a forum for researchers that propose software engineering methods, techniques, processes, and tools to support the construction of safe, performant, and cost-effective self-adaptive and autonomous systems that provide self-* properties such as self-configuration, self-healing, selfoptimization, and self-protection.The objective of SEAMS is to bring together researchers and practitioners from academia, industry, and government to investigate, discuss, examine, and advance the fundamental principles, state of the art, and the solutions addressing critical challenges of engineering self-adaptive and self-managing systems.SEAMS 2022 was co-located with the 44th International Conference on Software Engineering, in Pittsburgh, USA, in May 2022.The symposium took place toward the end of the COVID-19 pandemic and marked the first chance for an in-person meeting after 2 years of purely digital contacts.Due to uncertainty and a global reluctance to travel, we held the main technical program remotely, while a smaller group met in Pittsburgh and discussed better ways to transfer our community research into practice.We received 49 high-quality submissions belonging to several paper types: Twenty-five submissions were full research papers (eight of them were accepted, with an acceptance rate of 31%, in line with the acceptance rate of prior SEAMS editions).We selected six papers and invited their authors to extend the paper contribution for this special issue.The papers were chosen based on reviewer scores, potential for impact, and stimulating discussions during the conference.The papers for this special issue fall into two broad categories: (1) papers that advance the research of self-adaptation into new domains, such as UAVs teaming with humans, software-defined networks, and edge computing and (2) those that advance the software engineering of self-adaptive systems in the upcoming areas of learning model drift, testing, and proactive prediction of Bradley R. Schmerl, Javier Cámara 0001, Martina Maggio |
ACM Trans. Auton. Adapt. Syst. | 2 |
| 2023 | ExTrA: Explaining architectural design tradeoff spaces via dimensionality reductionabstractIn software design, guaranteeing the correctness of run-time system behavior while achieving an acceptable balance among multiple quality attributes remains a challenging problem. Moreover, providing guarantees about the satisfaction of those requirements when systems are subject to uncertain environments is even more challenging. While recent developments in architectural analysis techniques can assist architects in exploring the satisfaction of quantitative guarantees across the design space, existing approaches are still limited because they do not explicitly link design decisions to satisfaction of quality requirements. Furthermore, the amount of information they yield can be overwhelming to a human designer, making it difficult to see the forest for the trees. In this paper we present ExTrA (Explaining Tradeoffs of software Architecture design spaces), an approach to analyzing architectural design spaces that addresses these limitations and provides a basis for explaining design tradeoffs. Our approach employs dimensionality reduction techniques employed in machine learning pipelines like Principal Component Analysis (PCA) and Decision Tree Learning (DTL) to enable architects to understand how design decisions contribute to the satisfaction of extra-functional properties across the design space. Our results show feasibility of the approach in two case studies and evidence that combining complementary techniques like PCA and DTL is a viable approach to facilitate comprehension of tradeoffs in poorly-understood design spaces. Javier Cámara 0001, Rebekka Wohlrab, David Garlan, Bradley R. Schmerl |
J. Syst. Softw. | 1 |
| 2023 | Explaining quality attribute tradeoffs in automated planning for self-adaptive systemsabstractSelf-adaptive systems commonly operate in heterogeneous contexts and need to consider multiple quality attributes. Human stakeholders often express their quality preferences by defining utility functions, which are used by self-adaptive systems to automatically generate adaptation plans. However, the adaptation space of realistic systems is large and it is obscure how utility functions impact the generated adaptation behavior, as well as structural, behavioral, and quality constraints. Moreover, human stakeholders are often not aware of the underlying tradeoffs between quality attributes. To address this issue, we present an approach that uses machine learning techniques (dimensionality reduction, clustering, and decision tree learning) to explain the reasoning behind automated planning. Our approach focuses on the tradeoffs between quality attributes and how the choice of weights in utility functions results in different plans being generated. We help humans understand quality attribute tradeoffs, identify key decisions in adaptation behavior, and explore how differences in utility functions result in different adaptation alternatives. We present two systems to demonstrate the approach’s applicability and consider its potential application to 24 exemplar self-adaptive systems. Moreover, we describe our assessment of the tradeoff between the information reduction and the amount of explained variance retained by the results obtained with our approach. Rebekka Wohlrab, Javier Cámara 0001, David Garlan, Bradley R. Schmerl |
J. Syst. Softw. | 2 |
| 2023 | On the assessment of generative AI in modeling tasks: an experience report with ChatGPT and UMLabstractAbstract Most experts agree that large language models (LLMs), such as those used by Copilot and ChatGPT, are expected to revolutionize the way in which software is developed. Many papers are currently devoted to analyzing the potential advantages and limitations of these generative AI models for writing code. However, the analysis of the current state of LLMs with respect to software modeling has received little attention. In this paper, we investigate the current capabilities of ChatGPT to perform modeling tasks and to assist modelers, while also trying to identify its main shortcomings. Our findings show that, in contrast to code generation, the performance of the current version of ChatGPT for software modeling is limited, with various syntactic and semantic deficiencies, lack of consistency in responses and scalability issues. We also outline our views on how we perceive the role that LLMs can play in the software modeling discipline in the short term, and how the modeling community can help to improve the current capabilities of ChatGPT and the coming LLMs for software modeling. Javier Cámara 0001, Javier Troya, Loli Burgueño, Antonio Vallecillo |
Softw. Syst. Model. | 1 |
| 2022 | Addressing the uncertainty interaction problem in software-intensive systems: challenges and desiderataabstractSoftware-intensive systems are increasingly used to support tasks that are typically characterized by high degrees of uncertainty. The modeling notations employed to design, verify, and operate such systems have increasingly started to capture different types of uncertainty, so that they can be explicitly considered when systems are developed and deployed. While these modeling paradigms consider different sources of uncertainty individually, these sources are rarely independent, and their interactions affect the achievement of system goals in subtle and often unpredictable ways. This vision paper describes the problem of uncertainty interaction in software-intensive systems, illustrating it on examples from relevant application domains. We then identify key open challenges and define desiderata that future modeling notations and model-driven engineering research should consider to address these challenges. Javier Cámara 0001, Radu Calinescu, Betty H. C. Cheng, David Garlan, Bradley R. Schmerl, Javier Troya, Antonio Vallecillo |
MoDELS | 1 |
| 2022 | Security Countermeasure Selection for Component-Based Software-Intensive SystemsabstractGiven the increasing complexity of softwareintensive systems as well as the sophistication and high frequency of cyber-attacks, automated and sound approaches to select countermeasures are required to effectively protect software systems. In this paper, we propose a formal architecturecentered approach to analyze the security of a software-intensive component-based system to find cost-efficient countermeasures that consider both the system architecture and its behavior. We evaluate our approach by applying it on a case study. Charilaos Skandylas, Narges Khakpour, Javier Cámara 0001 |
QRS | 3 |
| 2022 | The uncertainty interaction problem in self-adaptive systems
Javier Cámara 0001, Javier Troya, Antonio Vallecillo, Nelly Bencomo, Radu Calinescu, Betty H. C. Cheng, David Garlan, Bradley R. Schmerl |
Softw. Syst. Model. | 1 |
| 2021 | Explaining Architectural Design Tradeoff Spaces: A Machine Learning Approach
Javier Cámara 0001, Mariana Silva, David Garlan, Bradley R. Schmerl |
ECSA | 1 |
| 2021 | Evolutionary-Guided Synthesis of Verified Pareto-Optimal MDP PoliciesabstractWe present a new approach for synthesising Paretooptimal Markov decision process (MDP) policies that satisfy complex combinations of quality-of-service (QoS) software requirements. These policies correspond to optimal designs or configurations of software systems, and are obtained by translating MDP models of these systems into parametric Markov chains, and using multi-objective genetic algorithms to synthesise Pareto-optimal parameter values that define the required MDP policies. We use case studies from the service-based systems and robotic control software domains to show that our MDP policy synthesis approach can handle a wide range of QoS requirement combinations unsupported by current probabilistic model checkers. Moreover, for requirement combinations supported by these model checkers, our approach generates better Pareto-optimal policy sets according to established quality metrics. Simos Gerasimou, Javier Cámara 0001, Radu Calinescu, Naif Alasmari, Faisal Alhwikem, Xinwei Fang |
ASE | 2 |
| 2020 | Quantitative Verification-Aided Machine Learning: A Tandem Approach for Architecting Self-Adaptive IoT SystemsabstractArchitecting IoT systems able to guarantee Quality of Service (QoS) levels can be a challenging task due to the inherent uncertainties (induced by changes in e.g., energy availability, network traffic) that they are subject to. Existing work has shown that machine learning (ML) techniques can be effectively used at run time for selecting self-adaptation patterns that can help maintain adequate QoS levels. However, this class of approach suffers from learning bias, which induces accuracy problems that might lead to sub-optimal (or even unfeasible) adaptations in some situations. To overcome this limitation, we propose an approach for proactive self-adaptation which combines ML and formal quantitative verification (probabilistic model checking). In our approach, ML is tasked with selecting the best adaptation pattern for a given scenario, and quantitative verification checks the feasibility of the adaptation decision, preventing the execution of unfeasible adaptations and providing feedback to the ML engine which helps to achieve faster convergence towards optimal decisions. The results of our evaluation show that our approach is able to produce better decisions than ML and quantitative verification used in isolation. Javier Cámara 0001, Henry Muccini, Karthik Vaidhyanathan |
ICSA | 1 |
| 2020 | Model-Based Analysis of Microservice Resiliency PatternsabstractMicroservice application developers try to mitigate the impact of partial outages typically by implementing service-to-service interactions that use well-known resiliency patterns, such as Retry, Fail Fast, and Circuit Breaker. However, those resiliency patterns-as well as their available open-source implementations-are often documented informally, leaving it up to application developers to figure out when and how to use those patterns in the context of a particular microservice application. In this paper, we take a first step towards improving on this situation by introducing a model checking-based approach in which we use the PRISM probabilistic model checker to analyze the behavior of the Retry and Circuit Breaker resiliency patterns as continuous-time Markov chains (CTMC). This approach has enabled us to quantify the impact of applying each resiliency pattern on multiple quality attributes, as well as to determine how to best tune their parameters to deal with varying service availability conditions, in the context of a simple client-service interaction scenario. Nabor das Chagas Mendonça, Carlos M. Aderaldo, Javier Cámara 0001, David Garlan |
ICSA | 3 |
| 2019 | Synthesizing tradeoff spaces with quantitative guarantees for families of software systems
Javier Cámara 0001, David Garlan, Bradley R. Schmerl |
J. Syst. Softw. | 1 |
| 2018 | MOSAICO: offline synthesis of adaptation strategy repertoires with flexible trade-offs
Javier Cámara 0001, Bradley R. Schmerl, Gabriel A. Moreno, David Garlan |
Autom. Softw. Eng. | 1 |
| 2018 | Reasoning about sensing uncertainty and its reduction in decision-making for self-adaptation
Javier Cámara 0001, Wenxin Peng, David Garlan, Bradley R. Schmerl |
Sci. Comput. Program. | 1 |
| 2018 | Flexible and Efficient Decision-Making for Proactive Latency-Aware Self-AdaptationabstractProactive latency-aware adaptation is an approach for self-adaptive systems that considers both the current and anticipated adaptation needs when making adaptation decisions, taking into account the latency of the available adaptation tactics. Since this is a problem of selecting adaptation actions in the context of the probabilistic behavior of the environment, Markov decision processes (MDPs) are a suitable approach. However, given all the possible interactions between the different and possibly concurrent adaptation tactics, the system, and the environment, constructing the MDP is a complex task. Probabilistic model checking has been used to deal with this problem, but it requires constructing the MDP every time an adaptation decision is made to incorporate the latest predictions of the environment behavior. In this article, we describe PLA-SDP, an approach that eliminates that runtime overhead by constructing most of the MDP offline. At runtime, the adaptation decision is made by solving the MDP through stochastic dynamic programming, weaving in the environment model as the solution is computed. We also present extensions that support different notions of utility, such as maximizing reward gain subject to the satisfaction of a probabilistic constraint, making PLA-SDP applicable to systems with different kinds of adaptation goals. Gabriel A. Moreno, Javier Cámara 0001, David Garlan, Bradley R. Schmerl |
ACM Trans. Auton. Adapt. Syst. | 2 |
| 2017 | Synthesis and Quantitative Verification of Tradeoff Spaces for Families of Software Systems
Javier Cámara 0001, David Garlan, Bradley R. Schmerl |
ECSA | 1 |
| 2017 | Event-Driven Bandwidth Allocation with Formal Guarantees for Camera NetworksabstractModern computing systems are often formed by multiple components that interact with each other through the use of shared resources (e.g., CPU, network bandwidth, storage). In this paper, we consider a representative scenario of one such system in the context of an Internet of Things application. The system consists of a network of self-adaptive cameras that share a communication channel, transmitting streams of frames to a central node. The cameras can modify a quality parameter to adapt the amount of information encoded and to affect their bandwidth requirements and usage. A critical design choice for such a system is scheduling channel access, i.e., how to determine the amount of channel capacity that should be used by each of the cameras at any point in time. Two main issues have to be considered for the choice of a bandwidth allocation scheme: (i) camera adaptation and network access scheduling may interfere with one another, (ii) bandwidth distribution should be triggered only when necessary, to limit additional overhead. This paper proposes the first formally verified event-triggered adaptation scheme for bandwidth allocation, designed to minimize additional overhead in the network. Desired properties of the system are verified using model checking. The paper also describes experimental results obtained with an implementation of the scheme. Gautham Nayak Seetanadi, Javier Cámara 0001, Luís Almeida 0001, Karl-Erik Årzén, Martina Maggio |
RTSS | 2 |
| 2017 | Robustness-Driven Resilience Evaluation of Self-Adaptive Software SystemsabstractAn increasingly important requirement for certain classes of software-intensive systems is the ability to self-adapt their structure and behavior at run-time when reacting to changes that may occur to the system, its environment, or its goals. A major challenge related to self-adaptive software systems is the ability to provide assurances of their resilience when facing changes. Since in these systems, the components that act as controllers of a target system incorporate highly complex software, there is the need to analyze the impact that controller failures might have on the services delivered by the system. In this paper, we present a novel approach for evaluating the resilience of self-adaptive software systems by applying robustness testing techniques to the controller to uncover failures that can affect system resilience. The approach for evaluating resilience, which is based on probabilistic model checking, quantifies the probability of satisfaction of system properties when the target system is subject to controller failures. The feasibility of the proposed approach is evaluated in the context of an industrial middleware system used to monitor and manage highly populated networks of devices, which was implemented using the Rainbow framework for architecture-based self-adaptation. Javier Cámara 0001, Rogério de Lemos, Nuno Laranjeiro, Rafael Ventura, Marco Vieira |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2016 | Architecture Modeling and Analysis of Security in Android Systems
Bradley R. Schmerl, Jeffrey Gennari, Hamid Bagheri, Sam Malek, Javier Cámara 0001, David Garlan |
ECSA | 6 |
| 2016 | Incorporating architecture-based self-adaptation into an adaptive industrial software system
Javier Cámara 0001, Pedro Correia, Rogério de Lemos, David Garlan, Bradley R. Schmerl, Rafael Ventura |
J. Syst. Softw. | 1 |
| 2016 | Adaptation impact and environment models for architecture-based self-adaptive systems
Javier Cámara 0001, Antónia Lopes, David Garlan, Bradley R. Schmerl |
Sci. Comput. Program. | 1 |
| 2016 | Special section on Foundations of Coordination Languages and Software Architectures
Natallia Kokash, Javier Cámara 0001 |
Sci. Comput. Program. | 2 |
| 2016 | Analyzing Latency-Aware Self-Adaptation Using Stochastic Games and SimulationsabstractSelf-adaptive systems must decide which adaptations to apply and when. In reactive approaches, adaptations are chosen and executed after some issue in the system has been detected (e.g., unforeseen attacks or failures). In proactive approaches, predictions are used to prepare the system for some future event (e.g., traffic spikes during holidays). In both cases, the choice of adaptation is based on the estimated impact it will have on the system. Current decision-making approaches assume that the impact will be instantaneous, whereas it is common that adaptations take time to produce their impact. Ignoring this latency is problematic because adaptations may not achieve their effect in time for a predicted event. Furthermore, lower impact but quicker adaptations may be ignored altogether, even if over time the accrued impact is actually higher. In this article, we introduce a novel approach to choosing adaptations that considers these latencies. To show how this improves adaptation decisions, we use a two-pronged approach: (i) model checking of Stochastic Multiplayer Games (SMGs) enables us to understand best- and worst-case scenarios of optimal latency-aware and non-latency-aware adaptation without the need to develop specific adaptation algorithms. However, since SMGs do not provide an algorithm to make choices at runtime, we propose a (ii) latency-aware adaptation algorithm to make decisions at runtime. Simulations are used to explore more detailed adaptation behavior and to check if the performance of the algorithm falls within the bounds predicted by SMGs. Our results show that latency awareness improves adaptation outcomes and also allows a larger set of adaptations to be exploited. Javier Cámara 0001, Gabriel A. Moreno, David Garlan, Bradley R. Schmerl |
ACM Trans. Auton. Adapt. Syst. | 1 |
| 2015 | Proactive self-adaptation under uncertainty: a probabilistic model checking approachabstractSelf-adaptive systems tend to be reactive and myopic, adapting in response to changes without anticipating what the subsequent adaptation needs will be. Adapting reactively can result in inefficiencies due to the system performing a suboptimal sequence of adaptations. Furthermore, when adaptations have latency, and take some time to produce their effect, they have to be started with sufficient lead time so that they complete by the time their effect is needed. Proactive latency-aware adaptation addresses these issues by making adaptation decisions with a look-ahead horizon and taking adaptation latency into account. In this paper we present an approach for proactive latency-aware adaptation under uncertainty that uses probabilistic model checking for adaptation decisions. The key idea is to use a formal model of the adaptive system in which the adaptation decision is left underspecified through nondeterminism, and have the model checker resolve the nondeterministic choices so that the accumulated utility over the horizon is maximized. The adaptation decision is optimal over the horizon, and takes into account the inherent uncertainty of the environment predictions needed for looking ahead. Our results show that the decision based on a look-ahead horizon, and the factoring of both tactic latency and environment uncertainty, considerably improve the effectiveness of adaptation decisions. Gabriel A. Moreno, Javier Cámara 0001, David Garlan, Bradley R. Schmerl |
ESEC/SIGSOFT FSE | 2 |
| 2014 | Comparator: A Tool for Quantifying Behavioural Compatibility
Meriem Ouederni, Gwen Salaün, Javier Cámara 0001, Ernesto Pimentel 0001 |
FASE | 3 |
| 2012 | Interactive specification and verification of behavioral adaptation contracts
Javier Cámara 0001, Gwen Salaün, Carlos Canal, Meriem Ouederni |
Inf. Softw. Technol. | 1 |
| 2012 | Structural reconfiguration of systems under behavioral adaptation
Carlos Canal, Javier Cámara 0001, Gwen Salaün |
Sci. Comput. Program. | 2 |
| 2011 | Synthesis of switching controllers using approximately bisimilar multiscale abstractionsabstractWhen available, discrete abstractions provide an appealing approach to controller synthesis. Recently, an approach for computing discrete abstractions of incrementally stable switched systems has been proposed, using the notion of approximate bisimulation. This approach is based on sampling of time and space where the sampling parameters must satisfy some relation in order to achieve a certain precision. Particularly, the smaller the sampling period, the finer the lattice approximating the state-space and the larger the number of states in the abstraction. This renders the use of these abstractions for synthesis of fast switching controllers computationally prohibitive. In this paper, we present a novel class of multiscale discrete abstractions for switched systems that allows us to deal with fast switching while keeping the number of states in the abstraction at a reasonable level. The transitions of our abstractions have various durations: for transitions of longer duration, it is sufficient to consider abstract states on a coarse lattice; for transitions of shorter duration, it becomes necessary to use finer lattices. These finer lattices are effectively used only on a restricted area of the state-space where the fast switching occurs. We show how to use these abstractions for multiscale synthesis of self-triggered switching controllers for reachability specifications under time optimization. We illustrate the merits of our approach by applying it to the boost DC-DC converter. Javier Cámara 0001, Antoine Girard, Gregor Gößler |
HSCC | 1 |
| 2011 | Workshop on assurances for self-adaptive systems (ASAS 2011)abstractAssurances for Self-Adaptive Systems (ASAS) is a workshop that will bring together researchers to discuss software engineering aspects of self-adaptive systems, including methods, architectures, languages, algorithms, techniques, and tools that can be used to support assurances in self-adaptive system development. ASAS is intended as a complement to the efforts started a while ago at the successful FSE workshop series on Self-Healing Systems (WOSS), or the Software Engineering for Adaptive and Self-Managing Systems (SEAMS) symposium. However, in contrast with those events, ASAS is focused on the collection, storage, and analysis of evidence for the provision of assurances that a self-adaptive software system is able to behave functionally and non-functionally according to its specification. Javier Cámara 0001, Rogério de Lemos, Carlo Ghezzi, Antónia Lopes |
SIGSOFT FSE | 1 |
| 2010 | A Case Study in Model-Based Adaptation of Web Services
Javier Cámara 0001, José Antonio Martín, Gwen Salaün, Carlos Canal, Ernesto Pimentel 0001 |
ISoLA (2) | 1 |
| 2009 | ITACA: An integrated toolbox for the automatic composition and adaptation of Web servicesabstractAdaptation is of utmost importance in systems developed by assembling reusable software services accessed through their public interfaces. This process aims at solving, as automatically as possible, mismatch cases which may be given at the different interoperability levels among interfaces by synthesizing a mediating adaptor. In this paper, we present a toolbox that fully supports the adaptation process, including: (i) different methods to construct adaptation contracts involving several services; (ii) simulation and verification techniques which help to identify and correct erroneous behaviours or deadlocking executions; and (iii) techniques for the generation of centralized or distributed adaptor protocols based on the aforementioned contracts. Our toolbox relates our models with implementation platforms, starting with the automatic extraction of behavioural models from existing interface descriptions, until the final adaptor implementation is generated for the target platform. Javier Cámara 0001, José Antonio Martín, Gwen Salaün, Javier Cubo, Meriem Ouederni, Carlos Canal, Ernesto Pimentel 0001 |
ICSE | 1 |
| 2009 | Facilitating Controlled Tests of Website Design Changes: A Systematic Approach
Javier Cámara 0001, Alfred Kobsa |
ICWE | 1 |
| 2008 | Clint: A Composition Language Interpreter (Tool Paper)
Javier Cámara 0001, Gwen Salaün, Carlos Canal |
FASE | 1 |
| 2007 | Context-Based Adaptation of Component Behavioural Interfaces
Javier Cubo, Gwen Salaün, Javier Cámara 0001, Carlos Canal, Ernesto Pimentel 0001 |
COORDINATION | 3 |
| 2007 | Enabling Adaptivity in User Interfaces
Javier Cámara 0001, Carlos Canal, Javier Cubo, Juan Manuel Murillo |
ECSA | 1 |
| 2007 | Run-time Composition and Adaptation of Mismatching Behavioural TransactionsabstractReuse of software entities such as components or web services raise composition issues since, most of the time, they present mismatching behavioural interfaces. Here, we particularly focus on systems for which the number of transactions is unbounded, and unknown in advance. This is typical in pervasive systems where a new client may show up at any moment to request or access a specific service. Hence, we advocate for the use of the pi-calculus to specify component interfaces. The pi-calculus is particularly suitable for creating new component instances and channels dynamically. The unbounded number of transactions and the use of the pi-calculus obliges to apply the composition at run-time. In this paper, we propose a run-time composition engine that solves existing mismatches. Javier Cámara 0001, Gwen Salaün, Carlos Canal |
SEFM | 1 |