VLDB 2026 Research / reviewers in the wild / expert
Tomás Cerný
dblp:17/8995
· DBLP profile ↗
39ranked-venue papers
6as first author
29since 2021 · last 2026
0000-0002-5882-5502ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 21 · 3 first-author · 19 since 2021Applied, interdisciplinary, general and emerging computing · 10 · 3 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 1 first-authorSecurity and privacy · 2 · 1 since 2021Computer networks · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Organizational Coupling as a Leading Indicator of Microservice Architecture Degradation
Nariman Mani, Jose Sosa Rodriguez, Xiaozhou Li 0002, Tomás Cerný |
ICSA | 4 |
| 2026 | Clear, Actionable and Confidence-Inspiring Recommendations? Comparative Study of AI-Generated and Human-Written PT Reports
Katarína Galanská, Maria Pibilota Murumaa, Vashek Matyas, Agata Kruzikova, Mike Just, Tomás Cerný |
SOUPS | 6 |
| 2026 | Generative AI for software architecture. Applications, challenges, and future directions
Matteo Esposito 0001, Xiaozhou Li 0002, Sergio Moreschini, Noman Ahmad, Tomás Cerný, Karthik Vaidhyanathan, Valentina Lenarduzzi, Davide Taibi 0001 |
J. Syst. Softw. | 5 |
| 2026 | Microservice logs analysis employing AI: A systematic literature review
Md Arfan Uddin, Shakthi Weerasinghe, Darek Gajewski, Melika Akbarsharifi, Roxana Akbarsharifi, Christopher Stoner, Tomás Cerný, Sen He 0002 |
J. Syst. Softw. | 7 |
| 2025 | Empirical Insights into Microservice Language Heterogeneity in PracticeabstractBackground: Microservice architecture has become a mainstream approach for cloud-native systems, transforming industries across diverse business domains over the past decade. While scalability has driven much of its adoption, system heterogeneity is frequently highlighted as a critical advantage. The research community frequently underscores heterogeneity as a priority in proposed solutions and innovations. Aims: This study investigates the real-world significance of heterogeneity in industrial microservice-based systems, seeking to answer: How prevalent is heterogeneity in practice? Are there governance practices to manage it? Is heterogeneity truly the main enabler for independent team operations? Method: We combined industrial expertise with a controlled experiment, incorporating insights directly from practitioners to assess the role and prevalence of heterogeneity in microservice-based systems. Results: Our findings reveal common themes and influential factors guiding heterogeneity-related decisions. We also identify varying governance approaches and highlight where industry practices align-or diverge-from common academic assumptions. Conclusions: This work bridges the gap between academic research and industry realities, providing a grounded understanding of heterogeneity in microservice systems. The results offer a foundation for future research to better address the practical needs of the microservice industry. Amr S. Abdelfattah, Tomás Cerný, Marwa Elsayed |
ESEM | 2 |
| 2025 | Semantic Dependency in Microservice ArchitectureabstractMicroservices have been a key architectural approach for over a decade, transforming system design by promoting decentralization and allowing development teams to work independently on specific microservices. While loosely coupled microservices are ideal, dependencies between them are inevitable. Often, these dependencies go unnoticed by development teams. Although syntactic dependencies can be identified, tracking semantic dependencies — when multiple microservices share similar logic — poses a greater challenge. As systems evolve, changes made to one microservice can trigger ripple effects, jeopardizing system consistency and requiring updates to dependent services, which increases maintenance and operational complexity. Effectively tracking different types of dependencies across microservices is essential for anticipating the impact of such changes. This paper introduces the Semantic Dependency Matrix as an instrument to address these challenges from a semantic perspective. We propose an automated approach to extract and represent these dependencies and demonstrate its effectiveness through a case study. This paper takes a step further by demonstrating the significance of semantic dependencies, even in cases where there are no direct dependencies between microservices. It shows that these hidden dependencies can exist independently of endpoint or data dependencies, revealing critical connections that might otherwise be overlooked. Amr S. Abdelfattah, Kari E. Cordes, Austin Medina, Tomás Cerný |
ICSR | 4 |
| 2025 | Vision: An Extensible Methodology for Formal Software Verification in Microservice SystemsabstractMicroservice systems are becoming increasingly adopted due to their scalability, decentralized development, and support for continuous integration and delivery (CI/CD). However, this decentralized development by separate teams and continuous evolution can introduce miscommunication and incompatible implementations, undermining system maintainability and reliability across aspects from security policy to system architecture. We propose a novel methodology that statically reconstructs microservice source code into a formal system model. From this model, a Satisfiability Modulo Theories (SMT) constraint set can be derived, enabling formal verification. Our methodology is extensible, supporting software verification across multiple cross-cutting concerns. We focus on applying the methodology to verify the system architecture concern, presenting formal reasoning to validate the methodology's correctness and applicability for this concern. Additional concerns such as security policy implementation are considered. Future directions are established to extend and evaluate the methodology. Connor Wojtak, Darek Gajewski, Tomás Cerný |
MODELS | 3 |
| 2025 | Towards Change Impact Analysis in Microservices-based System EvolutionabstractCloud-native systems are the mainstream for en-terprise solutions, given their scalability, resilience, and other benefits. While the benefits of cloud-native systems fueled by microservices are known, less guidance exists on their evolution. One could assume that since microservices encapsulate their code, code changes remain encapsulated as well; however, the community is becoming more aware of the possible consequences of code change propagation across microservices. Moreover, an active mitigation instrument for negative consequences of change propagation across microservices (i.e., ripple effect) is yet missing, but the microservice community would greatly benefit from it. This paper introduces what it could look like to have an infrastructure to assist with change impact analysis across the entire microservice system and intends to facilitate advance-ments in laying out the foundations and building guidelines on microservice system evolution. It shares a new direction for incremental software architecture reconstruction that could serve as the infrastructure concept and demonstrates early results from prototyping to illustrate the potential impact. Tomás Cerný, Gabriel Goulis, Amr S. Abdelfattah |
SANER | 1 |
| 2025 | Comparison of static analysis architecture recovery tools for microservice applicationsabstractAbstract Architecture recovery tools help software engineers obtain an overview of the structure of their software systems during all phases of the software development life cycle. This is especially important for microservice applications because they consist of multiple interacting microservices, which makes it more challenging to oversee the architecture. Various tools and techniques for architecture recovery (also called architecture reconstruction) have been presented in academic and gray literature sources, but no overview and comparison of their accuracy exists. This paper presents the results of a multivocal literature review with the goal of identifying architecture recovery tools for microservice applications and a comparison of the identified tools’ architectural recovery accuracy. We focused on static tools since they can be integrated into fast-paced CI/CD pipelines. 13 such tools were identified from the literature and nine of them could be executed and compared on their capability of detecting different system characteristics. The best-performing tool exhibited an overall F1-score of 0.86. Additionally, the possibility of combining multiple tools to increase the recovery correctness was investigated, yielding a combination of four individual tools that achieves an F1-score of 0.91. Simon Schneider, Alexander Bakhtin, Xiaozhou Li 0002, Jacopo Soldani, Antonio Brogi, Tomás Cerný, Riccardo Scandariato, Davide Taibi 0001 |
Empir. Softw. Eng. | 6 |
| 2025 | Multivocal study on microservice dependencies
Amr S. Abdelfattah, Tomás Cerný, Md Showkat Hossain Chy, Md Arfan Uddin, Samantha Perry, Cameron Brown, Lauren Goodrich, Miguel Hurtado, Muhid Hassan, Yuanfang Cai, Rick Kazman |
J. Syst. Softw. | 2 |
| 2025 | Change impact analysis in microservice systems: A systematic literature review
Luka Lelovic, Austin Huizinga, Gabriel Goulis, Anshpreet Kaur, Ricardo Boone, Umidjon Muzrapov, Amr S. Abdelfattah, Tomás Cerný |
J. Syst. Softw. | 8 |
| 2024 | On Maintainability and Microservice Dependencies: How Do Changes Propagate?abstractModern software systems evolve rapidly, especially when boosted by continuous integration and delivery. While many tools exist to help manage the maintainability of monolithic systems, gaps remain in assessing changes in decentralized systems, such as those based on microservices. Microservices fuel cloud-native systems, the mainstream direction for most enterprise solutions, which drives motivation for a broader understanding of how changes propagate through such systems. This position paper elaborates on the role of dependencies when dealing with evolution challenges in microservices aiming to support maintainability. It highlights the importance of dependency management in the context of maintainability deterioration. Our proposed perspective refines the approach to maintainability assurance by focusing on the systematic management of dependencies as a more direct method for addressing and understanding change propagation pathways, compared to traditional methods that often only a ddress symptoms like anti-patterns, smells, metrics, or high-level concepts. Tomás Cerný, Md Showkat Hossain Chy, Amr S. Abdelfattah, Jacopo Soldani, Justus Bogner |
CLOSER | 1 |
| 2024 | Service Weaver: A Promising Direction for Cloud-Native Systems?
Jacoby Johnson, Subash Kharel, Alan Mannamplackal, Amr S. Abdelfattah, Tomás Cerný |
CLOSER | 5 |
| 2024 | Case Study: Applying Automated Optimization Tooling to Microservice Environments that Scale Safely at Ancestry.com and the Learnings
Darek Gajewski, Muhammad Ashfakur Rahman Arju, Amr S. Abdelfattah, Tomás Cerný |
ECSA | 4 |
| 2024 | A Dataset of Microservices-based Open-Source ProjectsabstractResearchers in the microservices community often resort to demonstrating the impact of their proposed advancements on custom-made microservices projects. This is a possible source of bias that can reduce the trustworthiness of the results. Moreover, it is hard to compare advances in small projects, often developed due to lack of time. It is common across disciplines to recognize benchmarks that mitigate bias and unify the advancements' impact. To facilitate the identification of available open-source microservice projects (OSS-MS), we performed a comprehensive study to identify, curate, and catalog OSS-MS. We started with 389559 projects and filtered them down to 3804 projects that we manually labeled. After manual labeling, our dataset contains 378 projects with three or more microservices and with over 100 commits. We document the projects from many perspectives, including project size, platform, number of contributors, project purpose, and foundation support. This dataset can serve researchers as a roadmap to identify benchmarks, as our dataset can be used to answer questions such as whether the number of services impacts the issue count. Dario Amoroso d'Aragona, Alexander Bakhtin, Xiaozhou Li 0002, Ruoyu Su, Lauren Adams, Ernesto Aponte, Francis Boyle, Patrick Boyle, Rachel Koerner, Joseph Lee, Fangchao Tian, Yuqing Wang 0002, Jesse Nyyssölä, Ernesto Quevedo Caballero, Md Shahidur Rahaman, Amr S. Abdelfattah, Mika Mäntylä, Tomás Cerný, Davide Taibi 0001 |
MSR | 18 |
| 2024 | Software Architecture Reconstruction for Microservice Systems Using Static Analysis via GraalVM Native ImageabstractMicroservices are the mainstream architecture when designing cloud-native systems. The performance and elastic scalability of such systems are the main attraction for many vendors. Recent advancements improving microservice initialization times are related to the ahead-of-time compilation, which produces self-contained executables, significantly reducing load times. Despite recent advancements and various benefits of cloud-native systems, the evolution of such systems might be threatened by a missing system-centered view. Such a view would guide in a better contextual understanding of individual microservices and their dependencies from the holistic system perspective and aid developers in informed decisions to mitigate ripple effects. One way literature has addressed this gap is by performing Software Architecture Reconstruction (SAR), a process essential for understanding, maintaining, and evolving software systems. This paper questions whether instruments used to produce self-contained executables for microservices can be utilized for SAR, producing system-centered views. We propose a methodology for such a process, implement a proof of concept tool, MicroGraal, for the Java Platform, and assess it through a case study involving a third-party microservice system benchmark. We uncovered a system service dependency graph and a context map, comparing the approach and obtained results with source code analysis. Richard Hutcheson, Austin Blanchard, Noah Lambaria, Jack Hale, David Kozak, Amr S. Abdelfattah, Tomás Cerný |
SANER | 7 |
| 2023 | Filling The Gaps in Microservice Frontend Communication: Case for New Frontend Patterns
Amr S. Abdelfattah, Tomás Cerný |
CLOSER | 2 |
| 2023 | Towards Security-Aware Microservices: On Extracting Endpoint Data Access Operations to Determine Access Rights
Amr S. Abdelfattah, Micah Schiewe, Jacob Curtis, Tomás Cerný, Eunjee Song |
CLOSER | 4 |
| 2023 | Microservices Architecture Language for Describing Service View
Luka Lelovic, Michael Mathews, Amr S. Abdelfattah, Tomás Cerný |
CLOSER | 4 |
| 2023 | Comparing 2D and Augmented Reality Visualizations for Microservice System Understandability: A Controlled ExperimentabstractMicroservice-based systems are often complex to understand, especially when their sizes grow. Abstracted views help practitioners with the system understanding from a certain perspective. Recent advancement in interactive data visualization begs the question of whether established software engineering models to visualize system design remain the most suited approach for the service-oriented design of microservices. Our recent work proposed presenting a 3D visualization for microservices in augmented reality. This paper analyzes whether such an approach brings any benefits to practitioners when dealing with selected architectural questions related to system design quality. For this purpose, we conducted a controlled experiment involving 20 participants investigating their performance in identifying service dependency, service cardinality, and bottlenecks. Results show that the 3D enables novices to perform as well as experts in the detection of service dependencies, especially in large systems, while no differences are reported for the identification of service cardinality and bottlenecks. We recommend industry and researchers to further investigate AR for microservice architectural analysis, especially to ease the onboarding of new developers in microservice projects. Amr S. Abdelfattah, Tomás Cerný, Davide Taibi 0001, Sira Vegas |
ICPC | 2 |
| 2023 | Metrics and Models for Developer Collaboration Analysis in Microservice-Based Systems. A Systematic Mapping Study
Xiaozhou Li 0002, Amr S. Abdelfattah, Ruoyu Su, Joseph Lee, Ernesto Aponte, Rachel Koerner, Tomás Cerný, Davide Taibi 0001 |
IWSM-Mensura | 7 |
| 2023 | Review of Open Software Bug Datasets
Tomas Holek, Miroslav Bures, Tomás Cerný |
WorldCIST (3) | 3 |
| 2023 | Catalog and detection techniques of microservice anti-patterns and bad smells: A tertiary studyabstractVarious works investigated microservice anti-patterns and bad smells in the past few years. We identified seven secondary publications that summarize these, but they have little overlap in purpose and often use different terms to describe the identified anti-patterns and smells. This work catalogs recurring bad design practices known as anti-patterns and bad smells for microservice architectures, and provides a classification into categories as well as methods for detecting these practices. We conducted a systematic literature review in the form of a tertiary study targeting secondary studies identifying poor design practices for microservices. We provide a comprehensive catalog of 58 disjoint anti-patterns, grouped into five categories, which we derived from 203 originally identified anti-patterns for microservices. The results provide a reference to microservice developers to design better-quality systems and researchers who aim to detect system quality based on anti-patterns. It also serves as an anti-pattern catalog for development-aiding tools, which are not currently available for microservice system development but could mitigate quality degradation throughout system evolution. Tomás Cerný, Amr S. Abdelfattah, Andrea Janes, Davide Taibi 0001 |
J. Syst. Softw. | 1 |
| 2022 | Reconstructing the Holistic Architecture of Microservice Systems using Static Analysis
Vincent Bushong, Dipta Das, Tomás Cerný |
CLOSER | 3 |
| 2022 | Semantic Code Clone Detection Method for Distributed Enterprise Systems
Jan Svacina, Vincent Bushong, Dipta Das, Tomás Cerný |
CLOSER | 4 |
| 2021 | Using Static Analysis to Address Microservice Architecture ReconstructionabstractMicroservice design offers many advantages for enterprise applications, including increased scalability and faster deployment times. Microservices’ independence from one another in development and deployment provides these advantages. This separation, however, results in the absence of a centralized view of the application’s functionality, and each microservice’s data model is isolated and replicated. As a result, it has the potential to deviate from the architectural design’s original intent. To address this, we offer a method for analyzing a microservice mesh and generating a communication diagram, context map, and microservice-specific limited contexts using static code analysis. Vincent Bushong, Dipta Das, Tomás Cerný |
ASE | 4 |
| 2021 | Business Process Extraction Using Static AnalysisabstractBusiness process mining of a large-scale project has many benefits such as finding vulnerabilities, improving processes, collecting data for data science, generating more clear and simple representation, etc. The general way of process mining is to turn event data such as application logs into insights and actions. Observing logs broad enough to depict the whole business logic scenario of a large project can become very costly due to difficult environment setup, unavailability of users, presence of not reachable or hardly reachable log statements, etc. Using static source code analysis to extract logs and arranging them perfect runtime execution order is a potential way to solve the problem and reduce the business process mining operation cost. Md Rofiqul Islam, Tomás Cerný |
ASE | 2 |
| 2021 | Using Version Control and Issue Tickets to detect Code Debt and Economical CostabstractDespite the fact that there are numerous classifications of technical debt based on various criteria, Code Debt or code smells is a category that appears in the majority of current research. One of the primary causes of code debt is the urgency to deliver software quickly, as well as bad coding practices. Among many approaches, static code analysis has received the most attention in studies to detect code-smell/code debt. However, most of them examine the same programming language, although today’s software company utilizes many development stacks with various languages and tools. This problem can be resolved by detecting code debt with Issue/Ticket cards. This paper presents a method for detecting code debt leveraging natural language processing on issue tickets. It also proposes a method for calculating the average amount of time that a code debt was present in the software. This method is implemented utilizing git mining. Noah Lambaria, Amr S. Abdelfattah, Tomás Cerný |
ASE | 4 |
| 2021 | Online Energy Scheduling Policies in Energy Harvesting Enabled D2D CommunicationsabstractEnergy efficiency plays a vital role in device-to-device communications, which has been recognized as a key challenge. In this article, we study the implications of the peak power constraints and processing cost on the energy scheduling policy, and find that the peak power should be used around the time slots of each energy arrival, and the only time slot in which the intermittent communication may occur is the last time slot. A new optimal energy scheduling algorithm is devised based on these observations. Also, we propose a near-optimal energy scheduling algorithm that simultaneously takes into account the peak power constraints and the processing cost. Our simulation results demonstrate the effectiveness of the proposed energy scheduling algorithm and the validity of the mathematical analyses. Jun Huang 0002, Baohua Yu, Cong-Cong Xing, Tomás Cerný, Zhaolong Ning |
IEEE Trans. Ind. Informatics | 4 |
| 2020 | Securing Internet of Things Devices Using The Network ContextabstractInternet of Things (IoT) devices have been widely adopted in recent years. Unlike conventional information systems, IoT solutions have greater access to real-world contextual data and are typically deployed in an environment that cannot be fully controlled, and these circumstances create new challenges and opportunities. In this article, we leverage the knowledge that an IoT device has about its network context to provide an additional security factor. The device periodically scans a network and reports a list of all devices in the network. The server analyzes movements in the network and subsequently reacts to suspicious events. This article describes how our method can detect network changes, retrieved only from scanning devices in the network. To demonstrate the proposed solution, we perform a multiweek case study on a network with hundreds of active devices and confirm that our method can detect network anomalies or changes. Michal Trnka, Jan Svacina, Tomás Cerný, Eunjee Song, Jiman Hong, Miroslav Bures |
IEEE Trans. Ind. Informatics | 3 |
| 2018 | Survey of Authentication and Authorization for the Internet of ThingsabstractThe Internet of Things is currently getting significant interest from the scientific community. Academia and industry are both focused on moving ahead in attempts to enhance usability, maintainability, and security through standardization and development of best practices. We focus on security because of its impact as one of the most limiting factors to wider Internet of Things adoption. Numerous research areas exist in the security domain, ranging from cryptography to network security to identity management. This paper provides a survey of existing research applicable to the Internet of Things environment at the application layer in the areas of identity management, authentication, and authorization. We survey and analyze more than 200 articles, categorize them, and present current trends in the Internet of Things security domain. Michal Trnka, Tomás Cerný, Nathaniel Stickney |
Secur. Commun. Networks | 2 |
| 2018 | Pattern Matching Based Sensor Identification Layer for an Android PlatformabstractAs sensor‐related technologies have been developed, smartphones obtain more information from internal and external sensors. This interaction accelerates the development of applications in the Internet of Things environment. Due to many attributes that may vary the quality of the IoT system, sensor manufacturers provide their own data format and application even if there is a well‐defined standard, such as ISO/IEEE 11073 for personal health devices. In this paper, we propose a client‐server‐based sensor adaptation layer for an Android platform to improve interoperability among nonstandard sensors. Interoperability is an important quality aspect for the IoT that may have a strong impact on the system especially when the sensors are coming from different sources. Here, the server compares profiles that have clues to identify the sensor device with a data packet stream based on a modified Boyer‐Moore‐Horspool algorithm. Our matching model considers features of the sensor data packet. To verify the operability, we have implemented a prototype of this proposed system. The evaluation results show that the start and end pattern of the data packet are more efficient when the length of the data packet is longer. Hong Min, Taesik Kim, Junyoung Heo, Tomás Cerný, Sriram Sankaran, Bestoun S. Ahmed, Jinman Jung |
Wirel. Commun. Mob. Comput. | 4 |
| 2017 | Aspect-driven Context-aware ServicesabstractNowadays enterprise software solutions must deal with ever-growing complexity and a multitude of business processes.The mainstream system design decomposes the system into small reusable services.While these services isolate certain system logic and address efficient elasticity towards growing user demands, there are multiple issues related to such a design, such as limitations to deal with restated information, information reuse or the ability to address cross-cutting concerns across multiple services.This paper highlights limitations of service-oriented architecture and proposes an alternative decomposition through aspect-driven service-oriented architecture.Such architecture involves adaptive, context-aware services preserving simple maintenance while addressing information reuse and crosscuts across services.The paper provides a formal description of the proposed architecture as well as a demonstration through a case study, showing approach properties and benefits. Karel Cemus, Filip Klimes, Tomás Cerný |
FedCSIS | 3 |
| 2016 | Aspect, Rich, and Anemic Domain Models in Enterprise Information Systems
Karel Cemus, Tomás Cerný, Lubos Matl, Michael J. Donahoo |
SOFSEM | 2 |
| 2016 | Survey on Concern Separation in Service Integration
Tomás Cerný, Michael J. Donahoo |
SOFSEM | 1 |
| 2014 | Efficient Description and Cache Performance in Aspect-Oriented User Interface DesignabstractIncreasing demands on web user interface (UI) usability, adaptability, and dynamic behavior drives ever growing development and maintenance complexity.Conventional design approaches scale poorly with such rising complexity, resulting in rapidly increasing costs.Much of the complexity centers around data presentation and processing.Recent work greatly reduces such data complexity through the application of Aspect-Oriented UI (AOUI) design, which separates various UI concerns; however, rendering in conventional and even AOUI approaches fails to maintain this separation, often resulting in high repetitions of concern fragments due to tangling.Even worse, mixing of dynamic and immutable components greatly limits caching efficacy as each have differing lifetimes.We extend AOUI design to push down concern separation to rendering, which reduces description size, through repetition reduction, and enables separate caching of individual concerns.Our results show considerable size reduction of UI descriptions for data presentations, faster load times and extended caching capabilities. Tomás Cerný, Miroslav Macík, Michael J. Donahoo, Jan Janousek |
FedCSIS | 1 |
| 2014 | Aspect-Driven Design of Information Systems
Karel Cemus, Tomás Cerný |
SOFSEM | 2 |
| 2012 | Towards a Smart, Self-scaling Cooperative Web Cache
Tomás Cerný, Petr Praus, Slávka Jaromerská, Lubos Matl, Michael J. Donahoo |
SOFSEM | 1 |
| 2011 | SScAC: Towards a Framework for Small-Scale Software Architectures Comparison
Petr Praus, Slávka Jaromerská, Tomás Cerný |
SOFSEM | 3 |