VLDB 2026 Research / reviewers in the wild / expert
Andrea Morichetta 0001
dblp:133/8167
· DBLP profile ↗
19ranked-venue papers
1as first author
15since 2021 · last 2026
0000-0003-1738-9043ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 9 · 7 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Computer networks · 2 · 2 since 2021Security and privacy · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Object-centric process management: A research manifestoabstractBusiness process management employs process models and event logs to represent the behavior of the information systems under study. Traditional case-centric notions consider the order of activities and events in isolated process instances. The emerging field of object-centric processes challenges this assumption by putting objects in the center. Object-centric process mining and modeling approaches identify the structure of co-evolving data objects that influence the behavior of an information system to provide a comprehensive view of the system behavior. Object-centricity has been investigated independently in process modeling and in process mining, which resulted in the coexistence of seemingly contradictory assumptions and definitions. As a community effort, this research manifesto relates and aligns existing terminologies, definitions, and perspectives to provide a common ground for current and future research in object-centric business process management. Based on the current state of research, we propose a conceptualization that sets process models and event logs in relation to the information system’s behavior and the execution data it generates. The conceptualization aims at aligning different terminologies and, thus, providing a basis to model and analyze behavioral characteristics. Building on this common ground, we identify open research challenges along the most relevant research areas in object-centric process management. For each research area, its current status is investigated and an outline of the most relevant research challenges is presented. Anjo Seidel, Mathias Weske, Marco Montali, Andrey Rivkin, Manfred Reichert, Jan Martijn E. M. van der Werf, Wil M. P. van der Aalst, Marius Breitmayer, Lukas Liß, Jan Niklas van Detten, Amin Jalali 0001, Shahrzad Khayatbashi, Maximilian König, Tom Lichtenstein, Stefanie Rinderle-Ma, Barbara Weber, Pnina Soffer, Lorenzo Rossi 0001, Daniel Calegari, Andrea Delgado 0001, Remco M. Dijkman, Sarah Winkler, Matthias Weidlich 0001, Sander J. J. Leemans, Dirk Fahland, Ava Swevels, Monique Snoeck, Giancarlo Guizzardi, Alessandro Gianola, Avigdor Gal, Ekkart Kindler, Irina A. Lomazova, Barbara Re 0001, Giovanni Meroni, Andrea Morichetta 0001, Alessandro Marcelletti, Sara Pettinari, Boudewijn F. van Dongen, Johannes De Smedt, Majid Rafiei, Julius Köpke, Thomas T. Hildebrandt, Francesca Zerbato, Luise Pufahl, Hajo A. Reijers, Artem Polyvyanyy, Chiara Di Francescomarino, Fabrizio Maria Maggi, Oscar Pastor 0001, Stephan Haarmann, Henderik A. Proper, Xixi Lu 0001, Hugo A. López 0001, Tijs Slaats, Jochen De Weerdt, Massimiliano de Leoni, Niels Martin, Karolin Winter, Nick R. T. P. van Beest, Orlenys López-Pintado, Sebastiaan J. van Zelst, Chiara Ghidini, Arik Senderovich |
Inf. Syst. | 35 |
| 2025 | Alchemist: LLM-Driven Test Generation using Solidity Mutants and the Scientific Method
Morena Barboni, Filippo Lampa, Andrea Morichetta 0001, Andrea Polini, Edward Zulkoski |
ICBC | 3 |
| 2025 | Coordinating REST interactions in service choreographies using blockchainabstractIn Service Oriented Computing (SOC), different services interact and exchange information to reach specific objectives. To model interorganizational SOC systems, choreography modeling languages have emerged to represent the distributed coordination among the involved organizations. From the realization perspective, blockchain technology is emerging as a promising run-time supporting peer-to-peer communication technology without the need for a central coordinator, thanks to its intrinsic security, trust, and decentralization characteristics. However, while blockchain can bring many advantages, technological barriers still limit its adoption in organizations, due to the costly and time-consuming learning process. For this reason, we propose RESTChain, a framework that automatically enables the interactions that take place among the participants in a service choreography exploiting blockchain technology. Starting from a choreography specification, the framework provides a set of mediators and automatically generates a smart contract that coordinates the service interactions. The mediators are software components that are directly connected with the smart contracts and expose REpresentational State Transfer (REST) APIs in compliance with the role played by the organizations in the choreography. In this way, the services deployed by one organization can communicate with the services made available by another organization through the blockchain in a secure and transparent manner. The proposed approach has been implemented on the Layer 2 Polygon blockchain and validated in a market retail case study analyzing its efficiency in terms of time and cost. Francesco Donini, Alessandro Marcelletti, Andrea Morichetta 0001, Andrea Polini |
Blockchain Res. Appl. | 3 |
| 2025 | A methodology for extracting and decoding smart contracts dataabstractBlockchain technology has been widely adopted to enhance the security and the decentralisation of smart applications in large-scale pervasive systems. In such a context, data extraction is crucial as it provides a better understanding of the system’s behaviours. However, several challenges arise in automatically extracting data, due to the variety of data sources, such as transactions, events, contract storage, and the complexity of the blockchain structure. In particular, retrieving smart contract state changes remains unexplored despite its potential usage for discovering unexpected behaviour. For such reasons, in this work, we propose a novel methodology and a supporting application for extracting smart contract state changes and other execution-related data. The obtained data is then decoded and offered in a standard format to be easily reused. The methodology provides additional functionalities such as transaction filtering and capabilities for querying over extracted data. The effectiveness and the performance of the methodology were evaluated on three real-world projects from different EVM-based blockchains. Flavio Corradini, Alessandro Marcelletti, Andrea Morichetta 0001, Barbara Re 0001 |
Comput. Commun. | 3 |
| 2025 | Blockchain-Based Execution of BPMN Choreographies with Multiple InstancesabstractThe recent growth of blockchain has opened the use of technology for supporting the creation of newkinds of trustable systems. Model-driven engineering methodologies have been conceived to facilitate the automatic generation and deployment of software applications starting from the definition and refinement of abstract specification. BPMN choreography diagrams permit the representation of inter-organisational systems from a high-level perspective, just focusing on message exchange. However, the usage of such models in a blockchain-based setting has been limited to scenarios in which parties are involved in single interactions. This aspect becomes significantly relevant when considering complex applications, particularly those in the realm of the Internet of Things. In these cases, the multiplicity of parties and their actions is crucial and requires novel solutions. In this work, we propose a novel approach for modelling, refining, deploying, and executing a choreography on the blockchain, taking into account those scenarios in which the model includes multiple instances. In particular, the considered models are translated into smart contracts able to correctly manage multiplicity. To demonstrate the approach’s feasibility, we designed and presented a smart thermostat application, which is executed on the Polygon blockchain. Flavio Corradini, Alessandro Marcelletti, Andrea Morichetta 0001, Andrea Polini, Barbara Re 0001, Francesco Tiezzi 0001 |
Distributed Ledger Technol. Res. Pract. | 3 |
| 2025 | Event log extraction methodology for Ethereum applicationsabstractThe adoption of smart contracts in decentralized blockchain-based applications enables reliable and certified audits. These audits allow the extraction of valuable information from blockchains, which can be used to reconstruct the execution of the application and facilitate advanced analyses. One of the most commonly used techniques in this context is process mining, which leverages event logs to trace and accurately represent the process execution of applications. However, extracting execution data from blockchains poses significant challenges, and the current methodologies developed have some limitations. Most approaches are tailored to specific use cases, requiring that analysis techniques are defined during the smart contract’s development. Other techniques are applied a posteriori, relying on blockchain events that often lack a standardized format. This absence of standardization requires complex processing steps to correlate logs with the executed actions and such approaches are not universally applicable to all smart contracts on the blockchain , further limiting their scope. Lastly, none of the existing techniques can extract information from event logs embedded in internal transactions of smart contracts. To address these limitations, we propose EveLog an application-agnostic methodology that can be applied to any EVM-compatible application without predefined constraints. Its primary goal is to extract information from smart contracts, capturing both public and internal transactions, and organizing the results into a structured XES event log. The EveLog methodology consists of five key steps: (i) extraction of data from smart contract transactions, (ii) decoding raw data, (iii) selection of sorting criteria, (iv) construction of traces, and (v) generation of the XES event log. EveLog has been implemented in a client–server application and tested on existing solutions, specifically the CryptoKitties application, a blockchain-based game on the Ethereum blockchain. The study was conducted using 12,996 blocks, including over 8000 real transactions from the Ethereum mainnet. Andrea Morichetta 0001, Yuri Paoloni, Barbara Re 0001 |
Future Gener. Comput. Syst. | 1 |
| 2025 | Wielding Blockchain Transactions for Capture-Replay Testing of Upgradeable Smart ContractsabstractBlockchain technology is increasingly adopted in scenarios requiring trust and data integrity. On the Ethereum blockchain, the proxy pattern has become increasingly popular because it allows smart contract code to evolve while preserving stored data. However, a key challenge remains ensuring that such upgrades do not introduce breaking changes or cause disruptions to other contracts and off-chain systems. In this article, we introduce Catana , a framework that leverages historical transactions for Capture-Replay testing of proxy-based Upgradeable Smart Contracts (USCs). Catana assesses the potential impact of an upgrade by comparing the outcomes of replayed transactions with those from the previous version deployed on the main network. Additionally, it extracts and decodes contract state variables, providing deeper insights into how code changes affect the contract state, and helping developers mitigate issues before deployment. Experiments demonstrate that analyzing storage data accounts for the majority (about 86.5%) of detected disruptive upgrades. We also evaluate different policies for building replay test suites from historical transactions. Results identify a strategy that maximizes effectiveness while requiring a small number of replay test executions. Even a test suite containing just one transaction per each invoked method achieved good effectiveness (about 60%) in detecting disruptive upgrades. Morena Barboni, Guglielmo De Angelis, Andrea Morichetta 0001, Andrea Polini |
ACM Trans. Internet Techn. | 3 |
| 2024 | Enhanced mutation testing of smart contracts in support of code inspectionabstractSmart contracts hold the potential to revolutionize various industries, but their implementation requires thorough testing due to the associated financial risks. Mutation testing is a powerful technique that can boost the fault-detection capabilities of a test suite, but it can also foster a deeper understanding of smart contract behavior. This work investigates the productivity of mutants with respect to their capabilities in disclosing Solidity issues. Based on these findings, it proposes an enhanced mutation strategy to better assist smart contract auditors during code inspection activities. 9 novel mutation operators are introduced in this paper and 13 existing operators are improved. The results show a $30 \%$ reduction in the number of generated mutants and time savings of $62 \%$, while increasing the set of productive mutants related to issues by $43 \%$ overall. We note that the most valuable type of mutants that could help disclose an issue as a result of manual mutant inspection was increased by $125 \%$. Sebastian Banescu, Morena Barboni, Andrea Morichetta 0001, Andrea Polini, Edward Zulkoski |
ICBC | 3 |
| 2024 | ReSuMo: a regression strategy and tool for mutation testing of solidity smart contracts
Morena Barboni, Andrea Morichetta 0001, Andrea Polini, Francesco Casoni |
Softw. Qual. J. | 2 |
| 2023 | CATANA: Replay Testing for the Ethereum Blockchain
Morena Barboni, Guglielmo De Angelis, Andrea Morichetta 0001, Andrea Polini |
ICTSS | 3 |
| 2023 | A Flexible Approach to Multi-party Business Process Execution on BlockchainabstractIn modern business scenarios, more and more organisations have to deal with the critical requirements of trustworthiness and flexibility, when collaborating in multi-party business processes. This calls for new kinds of systems able to manage collaborative processes in untrusted and dynamic environments. Concerning the collaborative perspective, the Business Process Management discipline has provided effective and standardised solutions for a long time, now. Regarding the trustworthiness perspective, blockchain is advocated as one of the most prominent technologies to guarantee trust in a multi-party setting. However, while the immutability of blockchain provides transparent and secure proof of past business interactions, it hinders the flexibility of the business process execution, as the business logic regulating the process execution is immutably stored in the blockchain. On the other hand, flexibility is a property that is becoming crucial in such a setting due to the high dynamism of the business scenarios. In fact, it permits to modify a process at run-time to deal with internal or external changes. In this paper, we face this issue by proposing an architecture for the flexible blockchain-based execution of multi-party business processes. In our approach, business processes are modelled by BPMN choreography diagrams translated into code, whose execution state is then stored in the blockchain. Flexibility is achieved by decoupling the business process’s logic from its execution state, thus allowing run-time changes to the process execution without losing the fundamental properties of trust provided by the blockchain. To show the effectiveness of our approach, we provide a prototypical implementation, called FlexChain, and we use it on a case study from the healthcare application domain. The results obtained by the analysis of cost for the reported case study show the feasibility of the approach. In particular, major costs to sustain relate to one-time operations, such as the deployment and the run-time update of the model, while the most frequent actions are quite efficient. Flavio Corradini, Alessandro Marcelletti, Andrea Morichetta 0001, Andrea Polini, Barbara Re 0001, Francesco Tiezzi 0001 |
Future Gener. Comput. Syst. | 3 |
| 2022 | SuMo: A mutation testing approach and tool for the Ethereum blockchain
Morena Barboni, Andrea Morichetta 0001, Andrea Polini |
J. Syst. Softw. | 2 |
| 2021 | SuMo: A Mutation Testing Strategy for Solidity Smart ContractsabstractSmart Contracts are software programs that are deployed and executed within a blockchain infrastructure. Due to their immutable nature, directly resulting from the specific characteristics of the deploying infrastructure, smart contracts must be thoroughly tested before their release. Testing is one of the main activities that can help to improve the reliability of a smart contract, so as to possibly prevent considerable loss of valuable assets. It is therefore important to provide the testers with tools that permit them to assess the activity they performed.Mutation testing is a powerful approach for assessing the fault-detection capability of a test suite. In this paper, we propose SuMo, a novel mutation testing tool for Ethereum Smart Contracts. SuMo implements a set of 44 mutation operators that were designed starting from the latest Solidity documentation, and from well-known mutation testing tools. These allow to simulate a wide variety of faults that can be made by smart contract developers. The set of operators was designed to limit the generation of stillborn mutants, which slow down the mutation testing process and limit the usability of the tool. We report a first evaluation of SuMo on open-source projects for which test suites were available. The results we got are encouraging, and they suggest that SuMo can effectively help developers to deliver more reliable smart contracts. Morena Barboni, Andrea Morichetta 0001, Andrea Polini |
AST | 2 |
| 2021 | Model-driven engineering for multi-party business processes on multiple blockchainsabstractAs a disruptive technology, the blockchain is continuously finding novel application contexts, bringing new opportunities and radical changes. In this paper, we use blockchain as a communication infrastructure to support multi-party business processes. In particular, through smart contracts specifically generated by the mentioned business process, it is possible to derive a trustable infrastructure enabling the interaction among parties. Moreover, the emergence of different blockchain technologies, satisfying different characteristics, gives the possibility to support the same business process dealing with different non-functional needs. In this paper, we propose a novel engineering methodology supported by a practical framework called Multi-Chain. It permits to derive, using a model-driven strategy, a blockchain-based infrastructure, that can be deployed over a specific blockchain technology (e.g., Ethereum or Hyperledger Fabric). The objective is to permit the single definition and multiple deployments of the business process, to deliver the same functionalities, but satisfying different non-functional needs. In such a way, organisations willing to cooperate can select the multi-party business process and the blockchain technology they would like to use to satisfy their needs. Using Multi-Chain, they will be able to automatically derive from a Business Process Modelling Notation (BPMN) choreography diagram a blockchain infrastructure ready to be used. This overcomes the need to get acquainted with many details of the specific technology. Flavio Corradini, Alessandro Marcelletti, Andrea Morichetta 0001, Andrea Polini, Barbara Re 0001, Emanuele Scala, Francesco Tiezzi 0001 |
Blockchain Res. Appl. | 3 |
| 2021 | Well-structuredness, safeness and soundness: A formal classification of BPMN collaborations
Flavio Corradini, Andrea Morichetta 0001, Chiara Muzi, Barbara Re 0001, Francesco Tiezzi 0001 |
J. Log. Algebraic Methods Program. | 2 |
| 2020 | Correctness checking for BPMN collaborations with sub-processes
Flavio Corradini, Andrea Morichetta 0001, Andrea Polini, Barbara Re 0001, Lorenzo Rossi 0001, Francesco Tiezzi 0001 |
J. Syst. Softw. | 2 |
| 2020 | Collaboration vs. choreography conformance in BPMN
Flavio Corradini, Andrea Morichetta 0001, Andrea Polini, Barbara Re 0001, Francesco Tiezzi 0001 |
Log. Methods Comput. Sci. | 2 |
| 2018 | Collaboration vs. Choreography Conformance in BPMN 2.0: From Theory to PracticeabstractThe BPMN 2.0 standard is nowadays largely used to model distributed informative systems in both academic and industrial contexts. The notation makes possible to represent these systems from different perspectives. A local perspective, using collaboration diagrams, to describe the internal behaviour of each component of the systems, and a global perspective, using choreography diagrams, where the interactions between system components are highlighted without exposing their internal structure. In this paper, we propose a formal approach for checking conformance of collaborations, representing possible system implementations, with respect to choreographies, representing global constraints concerning components' interactions. In particular, we provide a direct formal operational semantics for both BPMN collaboration and choreography diagrams, and we formalise the conformance concept by means of two relations defined on top of the semantics. To support the approach into practice we have developed the C 4 tool. Its main characteristic is to make the exploited formal methods transparent to systems designers, thus fostering a wider adoption of them in the development of distributed informative systems. We illustrate the benefits of our approach by means of a simple, yet realistic, example concerning a traveling scenario. Flavio Corradini, Andrea Morichetta 0001, Andrea Polini, Barbara Re 0001, Francesco Tiezzi 0001 |
EDOC | 2 |
| 2013 | Adequate monitoring of service compositionsabstractMonitoring is essential to validate the runtime behaviour of dynamic distributed systems. However, monitors can inform of relevant events as they occur, but by their very nature they will not report about all those events that are not happening. In service-oriented applications it would be desirable to have means to assess the thoroughness of the interactions among the services that are being monitored. In case some events or message sequences or interaction patterns have not been observed for a while, in fact, one could timely check whether this happens because something is going wrong. In this paper, we introduce the novel notion of monitoring adequacy, which is generic and can be defined on different entities. We then define two adequacy criteria for service compositions and implement a proof-of-concept adequate monitoring framework. We validate the approach on two case studies, the Travel Reservation System and the Future Market choreographies. Antonia Bertolino, Eda Marchetti, Andrea Morichetta 0001 |
ESEC/SIGSOFT FSE | 3 |