Jörn Kohlhammer

dblp:19/4077 · DBLP profile ↗
← Back
41ranked-venue papers
3as first author
19since 2021 · last 2026
0000-0003-1706-8979ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 27 · 1 first-author · 15 since 2021Human-computer interaction and ubiquitous computing · 16 · 2 first-author · 7 since 2021Security and privacy · 8 · 4 since 2021Databases, data management, data science and information retrieval · 2Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 Visual Identification and Comparison of Higher Order Properties in State Transition Sequences
abstract
Abstract The analysis of state transition sequences is a prevalent research topic in many domains. In this context, we introduce the term higher‐order property to describe characteristics of the analyzed data set that span beyond the local neighborhood of a single state. For the analysis of such properties, we elaborate why sequence diagrams are generally preferred over node‐link diagrams in the literature. Consequently, we provide an overview of existing adaptations to node‐link diagrams to trade‐off support for first‐order property analysis in favor of higher‐order property analysis, potentially combining the strengths of both visualization types. To better understand the impact of this tradeoff, we present a comparative study of static sequence diagrams and spline‐based node‐link diagrams for five perception tasks on small‐scale synthetic state transition sequence data. We focus on static stimuli of small‐scale data sets to model the post‐filtering perceptual process rather than an end‐to‐end analytical workflow. The study confirmed hypotheses regarding the superior user performance with the sequence diagram for the perception of higher‐order properties. To demonstrate the relevance of higher‐order property analysis for real‐world problems, we present an application scenario from the cybersecurity domain. Based on the results of our study, we apply a sequence diagram‐based prototype to this application scenario. All supplemental materials are available at https://osf.io/r4ycd/ .
Tobias Mertz, Steven Lamarr Reynolds-Ringer, Jörn Kohlhammer
Comput. Graph. Forum3
2026 From Lines of Code to Lines of Policy? Exploring Software Developers' Perceptions of Their Privacy Policy-Related Activities
Ria Prianka Saha, Daniel Stäcker, Jonas Stromberg, Steven Lamarr Reynolds-Ringer, Kilian Demuth, Frank Nelles, Christian Reuter 0001, Jörn Kohlhammer, Alexander Benlian
Proc. Priv. Enhancing Technol.8
2026 DaV3is: Data Flow-Based Vulnerability Verification Through Visualization
abstract
Vulnerability verification is an important process in ensuring the security of software systems. To support users in this process, we present the design study of DaV$^{3}$3is, which utilizes visual event sequence analysis techniques to enable the comparison and tracing of automatically detected data flows through the software's source code, thereby allowing users to take advantage of sequence similarities to reduce the verification workload. To that end, we characterize the domain problem based on input from domain users, describe our design rationale based on best-practices from the visual analytics literature, and evaluate individual design decisions, usability, and utility in studies with three stakeholder groups. The evaluations yielded overall positive responses, showing the suitability of our design and providing valuable insight for future research.
Tobias Mertz, Steven Lamarr Reynolds-Ringer, Jörn Kohlhammer
IEEE Trans. Vis. Comput. Graph.3
2026 Minding the Gap: A Quantitative Comparison of Distance Perception on Open vs. Closed Circles
abstract
Radial visualizations encode one dimension of a data set with the visual variable angle or arc length. The radial axis conveys a similarity between the positions of the data points, due to the law of proximity. In the literature, two different types of axes are employed in visualizations: open and closed circular axes. Open axes are linear axes bent to form an open circle. A gap between the right and left poles indicates dissimilarity of data points at both poles. Contrarily, closed axes form a full circle. While the choice of the appropriate axis type in the visualization should align with the similarity space, a question arises: Which axis type supports the human perception of proximity better? To answer this question, we conducted a quantitative task-driven experiment (N=28) to evaluate human distance perception on open and closed circular axes. Within four low-level tasks of three types (identify, compare, and summarize), we evaluate accuracy and response time. Based on our results, we provide an empirically grounded guideline for selecting the appropriate axis type. In our extensive post-hoc analysis, we gain preliminary, but valuable insights to inform further research.
Jonas Stromberg, Hendrik Lücke-Tieke, Tobias Mertz, Thorsten May, Jörn Kohlhammer
IEEE Trans. Vis. Comput. Graph.5
2025 Visualizing Extracted Patterns from Dictionary-Based Compression Algorithms
abstract
Modern software systems continuously generate massive amounts of log files in different and varying formats. These logs contain information about the application activities, which is necessary for improvements by analyzing the behavior and maintaining the security and stability of the system. To manage their size, logs are typically stored in compressed form using algorithms that exploit repetitive patterns. This work presents an approach to detecting frequent patterns in textual data that can be registered simultaneously during the file compression process. The log file is visualized with the possibility to explore the extracted patterns using metrics based on such properties as frequency and length of the acquired pattern. This allows an analyst to gain the relevant insights more efficiently reducing the need for manual labor-intensive inspection in the log data. The implemented extension of a dictionary-based compression algorithm has the advantage of recognizing patterns in log files of any format and eliminates the need to manually perform preparation for any preprocessing of log files.
Igor Cherepanov, David Sessler, Jörn Kohlhammer
IV3
2025 Interactive Integration of Heterogeneous Datasets for Analytical Tasks
abstract
Data science is integral. Its importance continues to grow, and so does the need for adequate tools to integrate multiple datasets and audit their transformations. In rapidly evolving fields where data formats frequently change, this task is often performed manually. However, manual data-wrangling tasks are often error-prone and time-consuming for human analysts. In this paper, we propose a semi-automatic data wrangling approach that allows analysts to interactively integrate heterogeneous structured datasets into a unified target data format. This is achieved by abstracting raw data into schemas and transforming relevant attributes into a target data schema. To assist analysts, it also suggests an initial transformation and visualizes the resulting data to verify the transformation. We also provide a use case to demonstrate the capabilities of our interface for wrangling and verification. Supplemental materials are available at https://osf.io/dscfb/?viewonly=7b50be799c8540eaaf50e5b296629530.
Steven Lamarr Reynolds-Ringer, Jonas Stromberg, Hendrik Lücke-Tieke, Thorsten May, Jörn Kohlhammer
IV5
2024 Towards a Quality Approach to Hierarchical Color Maps
abstract
To improve the perception of hierarchical structures in data sets, several color map generation algorithms have been proposed to take this structure into account. But the design of hierarchical color maps elicits different requirements to those of color maps for tabular data. Within this paper, we make an initial effort to put design rules from the color map literature into the context of hierarchical color maps. We investigate the impact of several design decisions and provide recommendations for various analysis scenarios. Thus, we lay the foundation for objective quality criteria to evaluate hierarchical color maps.
Tobias Mertz, Jörn Kohlhammer
IEEE VIS2
2024 RenalViz: Visual analysis of cohorts with chronic kidney disease
abstract
Chronic Kidney Disease (CKD) is a prominent health problem. Progressive CKD leads to impaired kidney function with decreased ability to filter the patients’ blood, concluding in multiple complications, like heart disease and ultimately death from the disease. In previous work, we developed a prototype to support nephrologists in gaining an overview of their CKD patients. The prototype visualizes the patients in cohorts according to their pairwise similarity. The user can interactively modify the similarity by changing the underlying weights of the included features. The work in this paper expands upon this previous work by the enlargement of the data set and the user interface of the application. With a focus on the distinction between individual CKD classes we introduce a color scheme used throughout all visualization. Furthermore, the visualizations were adopted to display the data of several patients at once. This also involved the option to align the visualizations to sentinel points, such as the onset of a particular CKD stage, in order to quantify the progression of all selected patients in relation to this event. The prototype was developed in response to the identified potential for improvement of the earlier application. An additional user study concerning the intuitiveness and usability confirms good results for the prototype and leads to the assessment of an easy-to-use approach.
Markus Höhn, Sarah Schwindt-Drews, Sara Hahn, Sammy Patyna, Stefan Büttner, Jörn Kohlhammer
Comput. Graph.6
2024 A Survey on Progressive Visualization
abstract
Currently, growing data sources and long-running algorithms impede user attention and interaction with visual analytics applications. Progressive visualization (PV) and visual analytics (PVA) alleviate this problem by allowing immediate feedback and interaction with large datasets and complex computations, avoiding waiting for complete results by using partial results improving with time. Yet, creating a progressive visualization requires more effort than a regular visualization but also opens up new possibilities, such as steering the computations towards more relevant parts of the data, thus saving computational resources. However, there is currently no comprehensive overview of the design space for progressive visualization systems. We surveyed the related work of PV and derived a new taxonomy for progressive visualizations by systematically categorizing all PV publications that included visualizations with progressive features. Progressive visualizations can be categorized by well-known visualization taxonomies, but we also found that progressive visualizations can be distinguished by the way they manage their data processing, data domain, and visual update. Furthermore, we identified key properties such as uncertainty, steering, visual stability, and real-time processing that are significantly different with progressive applications. We also collected evaluation methodologies reported by the publications and conclude with statistical findings, research gaps, and open challenges.
Alex Ulmer, Marco Angelini, Jean-Daniel Fekete, Jörn Kohlhammer, Thorsten May
IEEE Trans. Vis. Comput. Graph.4
2023 Exploring the Design of Visualizations of Personal Online Data Based on Users' Mental Models
abstract
As data becomes more and more pervasive in our daily lives, supporting people in getting visual insights into their data is an important challenge to address. However, as data visualization literacy is still low, a gap between designers' mental model and users is not uncommon. To best pick up users where they are, we propose to include the data mental models of users into the design process. In this paper, we present our investigations in this direction by incorporating user sketches of their idea about their personal data stored at online services as a basis of our designs. We present our design study on personal data visualization interfaces resulting in a set of user sketches for three types of user groups and in three visualization interfaces. Finally, we reflect on our learnings and identify pitfalls to support other researchers in applying similar approaches.
Marija Dutz, Natasa Starcevic, Steven Lamarr Reynolds-Ringer, Jörn Kohlhammer
IV4
2023 LFPeers: Temporal similarity search and result exploration
Madhav Sachdeva, Jan Burmeister, Jörn Kohlhammer, Jürgen Bernard
Comput. Graph.3
2023 COMPO*SED: Composite Parallel Coordinates for Co-Dependent Multi-Attribute Choices
abstract
We propose Composite Parallel Coordinates, a novel parallel coordinates technique to effectively represent the interplay of component alternatives in a system. It builds upon a dedicated data model that formally describes the interaction of components. Parallel coordinates can help decision-makers identify the most preferred solution among a number of alternatives. Multi-component systems require one such multi-attribute choice for each component. Each of these choices might have side effects on the system's operability and performance, making them co-dependent. Common approaches employ complex multi-component models or involve back-and-forth iterations between single components until an acceptable compromise is reached. A simultaneous visual exploration across independently modeled but connected components is needed to make system design more efficient. Using dedicated layout and interaction strategies, our Composite Parallel Coordinates allow analysts to explore both individual properties of components as well as their interoperability and joint performance. We showcase the effectiveness of Composite Parallel Coordinates for co-dependent multi-attribute choices by means of three real-world scenarios from distinct application areas. In addition to the case studies, we reflect on observing two domain experts collaboratively working with the proposed technique and communicating along the way.
Lena Cibulski, Thorsten May, Johanna Schmidt, Jörn Kohlhammer
IEEE Trans. Vis. Comput. Graph.4
2022 Visualization Of Class Activation Maps To Explain AI Classification Of Network Packet Captures
abstract
The classification of internet traffic has become increasingly important due to the rapid growth of today’s networks and application variety. The number of connections and the addition of new applications in our networks causes a vast amount of log data and complicates the search for common patterns by experts. Finding such patterns among specific classes of applications is necessary to fulfill various requirements in network analytics. Supervised deep learning methods learn features from raw data and achieve high accuracy in classification. However, these methods are very complex and are used as black-box models, which weakens the experts’ trust in these classifications. Moreover, by using them as a black-box, new knowledge cannot be obtained from the model predictions despite their excellent performance. Therefore, the explainability of the classifications is crucial. Besides increasing trust, the explanation can be used for model evaluation to gain new insights from the data and to improve the model. In this paper, we present a visual and interactive tool that combines the classification of network data with an explanation technique to form an interface between experts, algorithms, and data.
Igor Cherepanov, Alex Ulmer, Jonathan Geraldi Joewono, Jörn Kohlhammer
VizSec4
2022 Visual Firewall Log Analysis - At the Border Between Analytical and Appealing
abstract
In this paper, we present our design study on developing an interactive visual firewall log analysis system in collaboration with an IT service provider. We describe the human-centered design process, in which we additionally considered hedonic qualities by including the usage of personas, psychological need cards and interaction vocabulary. For the problem characterization we especially focus on the demands of the two main clusters of requirements: high-level overview and low-level analysis, represented by the two defined personas, namely information security officer and network analyst. This resulted in the prototype of a visual analysis system consisting of two interlinked parts. One part addresses the needs for rather strategical tasks while also fulfilling the need for an appealing appearance and interaction. The other part rather addresses the requirements for operational tasks and aims to provide a high level of flexibility. We describe our design journey, the derived domain tasks and task abstractions as well as our visual design decisions, and present our final prototypes based on a usage scenario. We also report on our capstone event, where we conducted an observed experiment and collected feedback from the information security officer. Finally, as a reflection, we propose the extension of a widely used design study process with a track for an additional focus on hedonic qualities.
Marija Schufrin, Hendrik Lücke-Tieke, Jörn Kohlhammer
VizSec3
2022 Uncovering chains of infections through spatio-temporal and visual analysis of COVID-19 contact traces
Dario Antweiler, David Sessler, Maxim Rossknecht, Benjamin Abb, Sebastian Ginzel, Jörn Kohlhammer
Comput. Graph.6
2022 The Effect of Alignment on People's Ability to Judge Event Sequence Similarity
abstract
Event sequences are central to the analysis of data in domains that range from biology and health, to logfile analysis and people's everyday behavior. Many visualization tools have been created for such data, but people are error-prone when asked to judge the similarity of event sequences with basic presentation methods. This article describes an experiment that investigates whether local and global alignment techniques improve people's performance when judging sequence similarity. Participants were divided into three groups (basic versus local versus global alignment), and each participant judged the similarity of 180 sets of pseudo-randomly generated sequences. Each set comprised a target, a correct choice and a wrong choice. After training, the global alignment group was more accurate than the local alignment group (98 versus 93 percent correct), with the basic group getting 95 percent correct. Participants' response times were primarily affected by the number of event types, the similarity of sequences (measured by the Levenshtein distance) and the edit types (nine combinations of deletion, insertion and substitution). In summary, global alignment is superior and people's performance could be further improved by choosing alignment parameters that explicitly penalize sequence mismatches.
Roy A. Ruddle, Jürgen Bernard, Hendrik Lücke-Tieke, Thorsten May, Jörn Kohlhammer
IEEE Trans. Vis. Comput. Graph.5
2021 User-Centered Design of Visualizations for Software Vulnerability Reports
abstract
Today’s software systems are created by software development processes that naturally include mistakes, some of which can be exploited by attackers and are therefore called vulnerabilities. Automatic software scanners enable developers to analyze their applications to detect vulnerabilities and alert them of their presence. But often these reports are hard to understand, include false positives or overwhelm users due to the sheer number of alerts, since a report may contain hundreds to thousands of vulnerabilities. Developers must undergo a process called vulnerability triage to find the relevant vulnerabilities to fix. This paper presents two interactive visualizations for developers and security experts to gain an overview of the security state of their application. Users can see the distribution of vulnerabilities, find the most relevant ones, and compare differences between application versions. Our visualization design is inspired by an initial preliminary study and has been evaluated by domain experts to investigate the usability and appropriateness.
Steven Lamarr Reynolds-Ringer, Tobias Mertz, Steven Arzt, Jörn Kohlhammer
VizSec4
2021 ProBGP: Progressive Visual Analytics of Live BGP Updates
abstract
Abstract The global routing network is the backbone of the Internet. However, it is quite vulnerable to attacks that cause major disruptions or routing manipulations. Prior related works have visualized routing path changes with node link diagrams, but it requires strong domain expertise to understand if a routing change between autonomous systems is suspicious. Geographic visualization has an advantage over conventional node‐link diagrams by helping uncover such suspicious routes as the user can immediately see if a path is the shortest path to the target or an unreasonable detour. In this paper, we present ProBGP, a web‐based progressive approach to visually analyze BGP update routes. We created a novel progressive data processing algorithm for the geographic approximation of autonomous systems and combined it with a progressively updating visualization. While the newest log data is continuously loaded, our approach also allows querying the entire log recordings since 1999. We present the usefulness of our approach with a real use case of a major route leak from June 2019. We report on multiple interviews with domain experts throughout the development. Finally, we evaluated our algorithm quantitatively against a public peering database and qualitatively against AS network maps.
Alex Ulmer, David Sessler, Jörn Kohlhammer
Comput. Graph. Forum3
2021 A Visualization Interface to Improve the Transparency of Collected Personal Data on the Internet
abstract
Online services are used for all kinds of activities, like news, entertainment, publishing content or connecting with others. But information technology enables new threats to privacy by means of global mass surveillance, vast databases and fast distribution networks. Current news are full of misuses and data leakages. In most cases, users are powerless in such situations and develop an attitude of neglect for their online behaviour. On the other hand, the GDPR (General Data Protection Regulation) gives users the right to request a copy of all their personal data stored by a particular service, but the received data is hard to understand or analyze by the common internet user. This paper presents TransparencyVis - a web-based interface to support the visual and interactive exploration of data exports from different online services. With this approach, we aim at increasing the awareness of personal data stored by such online services and the effects of online behaviour. This design study provides an online accessible prototype and a best practice to unify data exports from different sources.
Marija Schufrin, Steven Lamarr Reynolds-Ringer, Arjan Kuijper, Jörn Kohlhammer
IEEE Trans. Vis. Comput. Graph.4
2020 Information Visualization Interface on Home Router Traffic Data for Laypersons
abstract
With the aim to increase the awareness of the everyday internet user for the own home network traffic, we present two interactive visualization interfaces for visual exploration of home router traffic records. Thereby we differentiate between users with a present intrinsic motivation for the topic and those with absent intrinsic motivation. Therefore, gamification in the first interface is used to maintain motivation of the first type of user, while the storytelling concept based on the hero's journey in the second interface aims at increasing the perceived incentives for the second user group.
Marija Schufrin, David Sessler, Steven Lamarr Reynolds-Ringer, Salmah Ahmad, Tobias Mertz, Jörn Kohlhammer
AVI6
2020 A Visualization Interface to Improve the Transparency of Collected Personal Data on the Internet
Marija Schufrin, Steven Lamarr Reynolds-Ringer, Arjan Kuijper, Jörn Kohlhammer
VizSec4
2020 PAVED: Pareto Front Visualization for Engineering Design
abstract
Abstract Design problems in engineering typically involve a large solution space and several potentially conflicting criteria. Selecting a compromise solution is often supported by optimization algorithms that compute hundreds of Pareto‐optimal solutions, thus informing a decision by the engineer. However, the complexity of evaluating and comparing alternatives increases with the number of criteria that need to be considered at the same time. We present a design study on Pareto front visualization to support engineers in applying their expertise and subjective preferences for selection of the most‐preferred solution. We provide a characterization of data and tasks from the parametric design of electric motors. The requirements identified were the basis for our development of PAVED , an interactive parallel coordinates visualization for exploration of multi‐criteria alternatives. We reflect on our user‐centered design process that included iterative refinement with real data in close collaboration with a domain expert as well as a summative evaluation in the field. The results suggest a high usability of our visualization as part of a real‐world engineering design workflow. Our lessons learned can serve as guidance to future visualization developers targeting multi‐criteria optimization problems in engineering design or alternative domains.
Lena Cibulski, Hubert Mitterhofer, Thorsten May, Jörn Kohlhammer
Comput. Graph. Forum4
2019 NetCapVis: Web-based Progressive Visual Analytics for Network Packet Captures
abstract
Network traffic log data is a key data source for forensic analysis of cybersecurity incidents. Packet Captures (PCAPs) are the raw information directly gathered from the network device. As the bandwidth and connections to other hosts rise, this data becomes very large quickly. Malware analysts and administrators are using this data frequently for their analysis. However, the currently most used tool Wireshark is displaying the data as a table, making it difficult to get an overview and focus on the significant parts. Also, the process of loading large files into Wireshark takes time and has to be repeated each time the file is closed. We believe that this problem poses an optimal setting for a client-server infrastructure with a progressive visual analytics approach. The processing can be outsourced to the server while the client is progressively updated. In this paper we present NetCapVis, an web-based progressive visual analytics system where the user can upload PCAP files, set initial filters to reduce the data before uploading and then instantly interact with the data while the rest is progressively loaded into the visualizations.
Alex Ulmer, David Sessler, Jörn Kohlhammer
VizSEC3
2019 Visual-Interactive Preprocessing of Multivariate Time Series Data
abstract
Abstract Pre‐processing is a prerequisite to conduct effective and efficient downstream data analysis. Pre‐processing pipelines often require multiple routines to address data quality challenges and to bring the data into a usable form. For both the construction and the refinement of pre‐processing pipelines, human‐in‐the‐loop approaches are highly beneficial. This particularly applies to multivariate time series, a complex data type with multiple values developing over time. Due to the high specificity of this domain, it has not been subject to in‐depth research in visual analytics. We present a visual‐interactive approach for preprocessing multivariate time series data with the following aspects. Our approach supports analysts to carry out six core analysis tasks related to pre‐processing of multivariate time series. To support these tasks, we identify requirements to baseline toolkits that may help practitioners in their choice. We characterize the space of visualization designs for uncertainty‐aware pre‐processing and justify our decisions. Two usage scenarios demonstrate applicability of our approach, design choices, and uncertainty visualizations for the six analysis tasks. This work is one step towards strengthening the visual analytics support for data pre‐processing in general and for uncertainty‐aware pre‐processing of multivariate time series in particular.
Jürgen Bernard, Marco Hutter 0002, Heiko Reinemuth, Hendrik Pfeifer, Christian Bors, Jörn Kohlhammer
Comput. Graph. Forum6
2019 Using Dashboard Networks to Visualize Multiple Patient Histories: A Design Study on Post-Operative Prostate Cancer
abstract
In this design study, we present a visualization technique that segments patients' histories instead of treating them as raw event sequences, aggregates the segments using criteria such as the whole history or treatment combinations, and then visualizes the aggregated segments as static dashboards that are arranged in a dashboard network to show longitudinal changes. The static dashboards were developed in nine iterations, to show 15 important attributes from the patients' histories. The final design was evaluated with five non-experts, five visualization experts and four medical experts, who successfully used it to gain an overview of a 2,000 patient dataset, and to make observations about longitudinal changes and differences between two cohorts. The research represents a step-change in the detail of large-scale data that may be successfully visualized using dashboards, and provides guidance about how the approach may be generalized.
Jürgen Bernard, David Sessler, Jörn Kohlhammer, Roy A. Ruddle
IEEE Trans. Vis. Comput. Graph.3
2018 Visual-Interactive Identification of Anomalous IP-Block Behavior Using Geo-IP Data
abstract
Routing of network packets from one computer to another is the backbone of the internet and impacts the everyday life of many people. Although, this is a fully automated process it has many security issues. IP hijacks and misconfigurations occur very often and are difficult to detect. In the past visual analytics approaches aimed at detecting these phenomenons but only a few of these integrated geographical references. Geo-IP data is being used mostly as a lookup table which is an undervaluation of its capabilities. In this paper we present a visual-interactive system which only relies on Geo-IP data to create more awareness for this data source. We show that looking at Geo-IP data over time in combination with owner and location information of IP blocks already reveals suspicious cases. Together with our design study we also contribute a pre-processing algorithm for the Maxmind GeoIP2 City and ISP databases, to motivate the community to integrate this data source in future approaches.
Alex Ulmer, Marija Schufrin, David Sessler, Jörn Kohlhammer
VizSEC4
2016 Supporting Collaborative Political Decision Making: An Interactive Policy Process Visualization System
abstract
The process of political decision making is often complex and tedious. The policy process consists of multiple steps, most of them are highly iterative. In addition, different stakeholder groups are involved in political decision making and contribute to the process. A series of textual documents accompanies the process. Examples are official documents, discussions, scientific reports, external reviews, newspaper articles, or economic white papers. Experts from the political domain report that this plethora of textual documents often exceeds their ability to keep track of the entire policy process. We present PolicyLine, a visualization system that supports different stakeholder groups in overview-and-detail tasks for large sets of textual documents in the political decision making process. In a longitudinal design study conducted together with domain experts in political decision making, we identified missing analytical functionality on the basis of a problem and domain characterization. In an iterative design phase, we created PolicyLine in close collaboration with the domain experts. Finally, we present the results of three evaluation rounds, and reflect on our collaborative visualization system.
Tobias Ruppert, Andreas Bannach, Jürgen Bernard, Hendrik Lücke-Tieke, Alex Ulmer, Jörn Kohlhammer
VINCI6
2016 Uncovering periodic network signals of cyber attacks
abstract
This paper addresses the problem of detecting the presence of malware that leaveperiodictraces innetworktraffic. This characteristic behavior of malware was found to be surprisingly prevalent in a parallel study. To this end, we propose a visual analytics solution that supports both automatic detection and manual inspection of periodic signals hidden in network traffic. The detected periodic signals are visually verified in an overview using a circular graph and two stacked histograms as well as in detail using deep packet inspection. Our approach offers the capability to detect complex periodic patterns, but avoids the unverifiability issue often encountered in related work. The periodicity assumption imposed on malware behavior is a relatively weak assumption, but initial evaluations with a simulated scenario as well as a publicly available network capture demonstrate its applicability.
Huynh Ngoc Anh, Wee Keong Ng, Alex Ulmer, Jörn Kohlhammer
VizSEC4
2014 Visual Analysis of Sets of Heterogeneous Matrices Using Projection-Based Distance Functions and Semantic Zoom
abstract
Abstract Matrix visualization is an established technique in the analysis of relational data. It is applicable to large, dense networks, where node‐link representations may not be effective. Recently, domains have emerged in which the comparative analysis of sets of matrices of potentially varying size is relevant. For example, to monitor computer network traffic a dynamic set of hosts and their peer‐to‐peer connections on different ports must be analysed. A matrix visualization focused on the display of one matrix at a time cannot cope with this task. We address the research problem of the visual analysis of sets of matrices. We present a technique for comparing matrices of potentially varying size. Our approach considers the rows and/or columns of a matrix as the basic elements of the analysis. We project these vectors for pairs of matrices into a low‐dimensional space which is used as the reference to compare matrices and identify relationships among them. Bipartite graph matching is applied on the projected elements to compute a measure of distance. A key advantage of this measure is that it can be interpreted and manipulated as a visual distance function, and serves as a comprehensible basis for ranking, clustering and comparison in sets of matrices. We present an interactive system in which users may explore the matrix distances and understand potential differences in a set of matrices. A flexible semantic zoom mechanism enables users to navigate through sets of matrices and identify patterns at different levels of detail. We demonstrate the effectiveness of our approach through a case study and provide a technical evaluation to illustrate its strengths.
Michael Behrisch 0001, James Davey, Fabian Fischer 0001, Olivier Thonnard, Tobias Schreck, Daniel A. Keim, Jörn Kohlhammer
Comput. Graph. Forum7
2014 Visual-interactive Exploration of Interesting Multivariate Relations in Mixed Research Data Sets
abstract
Abstract The analysis of research data plays a key role in data‐driven areas of science. Varieties of mixed research data sets exist and scientists aim to derive or validate hypotheses to find undiscovered knowledge. Many analysis techniques identify relations of an entire dataset only. This may level the characteristic behavior of different subgroups in the data. Like automatic subspace clustering, we aim at identifying interesting subgroups and attribute sets. We present a visual‐interactive system that supports scientists to explore interesting relations between aggregated bins of multivariate attributes in mixed data sets. The abstraction of data to bins enables the application of statistical dependency tests as the measure of interestingness. An overview matrix view shows all attributes, ranked with respect to the interestingness of bins. Complementary, a node‐link view reveals multivariate bin relations by positioning dependent bins close to each other. The system supports information drill‐down based on both expert knowledge and algorithmic support. Finally, visual‐interactive subset clustering assigns multivariate bin relations to groups. A list‐based cluster result representation enables the scientist to communicate multivariate findings at a glance. We demonstrate the applicability of the system with two case studies from the earth observation domain and the prostate cancer research domain. In both cases, the system enabled us to identify the most interesting multivariate bin relations, to validate already published results, and, moreover, to discover unexpected relations.
Jürgen Bernard, Martin Steiger, Sven Widmer, Hendrik Lücke-Tieke, Thorsten May, Jörn Kohlhammer
Comput. Graph. Forum6
2014 Visual Analysis of Time-Series Similarities for Anomaly Detection in Sensor Networks
abstract
Abstract We present a system to analyze time‐series data in sensor networks. Our approach supports exploratory tasks for the comparison of univariate, geo‐referenced sensor data, in particular for anomaly detection. We split the recordings into fixed‐length patterns and show them in order to compare them over time and space using two linked views. Apart from geo‐based comparison across sensors we also support different temporal patterns to discover seasonal effects, anomalies and periodicities. The methods we use are best practices in the information visualization domain. They cover the daily, the weekly and seasonal and patterns of the data. Daily patterns can be analyzed in a clustering‐based view, weekly patterns in a calendar‐based view and seasonal patters in a projection‐based view. The connectivity of the sensors can be analyzed through a dedicated topological network view. We assist the domain expert with interaction techniques to make the results understandable. As a result, the user can identify and analyze erroneous and suspicious measurements in the network. A case study with a domain expert verified the usefulness of our approach.
Martin Steiger, Jürgen Bernard, Sebastian Mittelstädt, Hendrik Lücke-Tieke, Daniel A. Keim, Thorsten May, Jörn Kohlhammer
Comput. Graph. Forum7
2013 MotionExplorer: Exploratory Search in Human Motion Capture Data Based on Hierarchical Aggregation
abstract
We present MotionExplorer, an exploratory search and analysis system for sequences of human motion in large motion capture data collections. This special type of multivariate time series data is relevant in many research fields including medicine, sports and animation. Key tasks in working with motion data include analysis of motion states and transitions, and synthesis of motion vectors by interpolation and combination. In the practice of research and application of human motion data, challenges exist in providing visual summaries and drill-down functionality for handling large motion data collections. We find that this domain can benefit from appropriate visual retrieval and analysis support to handle these tasks in presence of large motion data. To address this need, we developed MotionExplorer together with domain experts as an exploratory search system based on interactive aggregation and visualization of motion states as a basis for data navigation, exploration, and search. Based on an overview-first type visualization, users are able to search for interesting sub-sequences of motion based on a query-by-example metaphor, and explore search results by details on demand. We developed MotionExplorer in close collaboration with the targeted users who are researchers working on human motion synthesis and analysis, including a summative field study. Additionally, we conducted a laboratory design study to substantially improve MotionExplorer towards an intuitive, usable and robust design. MotionExplorer enables the search in human motion capture data with only a few mouse clicks. The researchers unanimously confirm that the system can efficiently support their work.
Jürgen Bernard, Nils Wilhelm, Björn Krüger, Thorsten May, Tobias Schreck, Jörn Kohlhammer
IEEE Trans. Vis. Comput. Graph.6
2012 Semantics Visualization for Fostering Search Result Comprehension
Christian Stab, Kawa Nazemi, Matthias Breyer, Dirk Burkhardt, Jörn Kohlhammer
ESWC5
2012 Using Signposts for Navigation in Large Graphs
abstract
Abstract In this paper we present a new Focus & Context technique for the exploration of large, abstract graphs. Most Focus & Context techniques present context in a visual way. In contrast, our technique uses a symbolic representation: while the focus is a set of visible nodes, labelled signposts provide cues for the context — off‐screen regions of the graph — and indicate the direction of the shortest path linking the visible nodes to these regions. We show how the regions are defined and how they are selected dynamically, depending on the visible nodes. To define the set of visible nodes we use an approach developed by van Ham and Perer that dynamically extracts a subgraph based on an initial focal node and a degree‐of‐interest function. This approach is extended to support multiple focal nodes. With the symbolic visualization, potentially interesting regions of a graph may be represented with a very small visual footprint. We conclude the paper with an initial user study to evaluate the effectiveness of the signposts for navigation tasks.
Thorsten May, Martin Steiger, James Davey, Jörn Kohlhammer
Comput. Graph. Forum4
2011 Visual Analysis of Large Graphs: State-of-the-Art and Future Research Challenges
abstract
Abstract The analysis of large graphs plays a prominent role in various fields of research and is relevant in many important application areas. Effective visual analysis of graphs requires appropriate visual presentations in combination with respective user interaction facilities and algorithmic graph analysis methods. How to design appropriate graph analysis systems depends on many factors, including the type of graph describing the data, the analytical task at hand and the applicability of graph analysis methods. The most recent surveys of graph visualization and navigation techniques cover techniques that had been introduced until 2000 or concentrate only on graph layouts published until 2002. Recently, new techniques have been developed covering a broader range of graph types, such as time‐varying graphs. Also, in accordance with ever growing amounts of graph‐structured data becoming available, the inclusion of algorithmic graph analysis and interaction techniques becomes increasingly important. In this State‐of‐the‐Art Report, we survey available techniques for the visual analysis of large graphs. Our review first considers graph visualization techniques according to the type of graphs supported. The visualization techniques form the basis for the presentation of interaction approaches suitable for visual graph exploration. As an important component of visual graph analysis, we discuss various graph algorithmic aspects useful for the different stages of the visual graph analysis process. We also present main open research challenges in this field.
Tatiana von Landesberger, Arjan Kuijper, Tobias Schreck, Jörn Kohlhammer, Jarke J. van Wijk, Jean-Daniel Fekete, Dieter W. Fellner
Comput. Graph. Forum4
2008 Towards closing the analysis gap: Visual generation of decision supporting schemes from raw data
abstract
Abstract The derivation, manipulation and verification of analytical models from raw data is a process which requires a transformation of information across different levels of abstraction. We introduce a concept for the coupling of data classification and interactive visualization in order to make this transformation visible and steerable for the human user. Data classification techniques generate mappings that formally group data items into categories. Interactive visualization includes the user into an iterative refinement process. The user identifies and selects interesting patterns to define these categories. The following step is the transformation of a visible pattern into the formal definition of a classifier. In the last step the classifier is transformed back into a pattern that is blended with the original data in the same visual display. Our approach allows in intuitive assessment of a formal classifier and its model, the detection of outliers and the handling of noisy data using visual pattern‐matching. We instantiated the concept using decision trees for classification and KVMaps as the visualization technique. The generation of a classifier from visual patterns and its verification is transformed from a cognitive to a mostly pre‐cognitive task.
Thorsten May, Jörn Kohlhammer
Comput. Graph. Forum2
2007 Applying Animation to the Visual Analysis of Financial Time-Dependent Data
abstract
For decades, financial analysts have strived to use modern data visualization tools to improve the timeliness and quality of their analysis. As the amount of data to be processed increases rapidly and requirements on quality of financial analysis rise, the demand for analysis support systems grows. We present a system for the visual analysis of large amounts of time-dependent data using animation. For each data entity, indicators are presented in a scatter-plot framework, displaying the correlation between them. The design of the glyphs illustrates additional data dimensions. The system uses animation to handle the time-dimension of the data. It offers various features, such as focus, zoom, details on demand and time period selection to support the analysis. Financial indicators are used to demonstrate the usability of the system. The animation proves to be a powerful tool for analysing time-dependent processes in cross-sectional data sets and discovering patterns in the data.
Tatiana von Landesberger, Jörn Kohlhammer
IV2
2007 Introduction
Jörn Kohlhammer, Daniel A. Keim, David S. Ebert
Comput. Graph.1
2004 Towards a visualization architecture for time-critical applications
abstract
Time-critical domains, such as emergency management, demand fast decisions from expert users under stress. Our Decision-Centered Visualization (DCV) system supports decision making by integrating domain knowledge and knowledge about human situation awareness for time-critical visualization. Efficient information presentation is vital for the user's situation awareness and, in consequence, to his or her task performance. We address the problem of efficiently visualizing both existing and incoming information by connecting domain data types and presentation requirements of the domain's tasks.
Jörn Kohlhammer, David Zeltzer
IUI1
2003 DCV: a decision-centered visualization system for time-critical applications
abstract
Users of information systems in time-critical domains are under constant pressure to digest and process information that is vital for their task. Thus, the user needs efficient information visualization that avoids displaying information that is not vital at the moment. Decision-centered visualization is an adaptive, interactive visualization system that supports decision making by integrating domain knowledge and knowledge about human decision making with an interactive visualization architecture. An important facet of this system is the representation of the underlaying domain knowledge. We will first describe the main modules and the main structures of the knowledge representation of the DCV system. We then describe how DCV uses the represented domain knowledge to guide the information visualization in time-critical applications.
Jörn Kohlhammer, David Zeltzer
SMC1
2000 The DC-Tree: A Fully Dynamic Index Structure for Data Warehouses
abstract
In a data warehouse, updates are typically collected and performed periodically in a batch mode, e.g., over night. This standard approach of bulk incremental updates to data warehouses has some drawbacks. First, the average runtime for a single update is small but the total runtime for the whole batch of updates may become rather large. Second, the contents of the data warehouse is not always up to date. We introduce the DC-tree, a fully dynamic index structure for data warehouses modeled as a data cube. This new index structure is designed for applications where the above drawbacks of the bulk update approach are critical. The DC-tree is a hierarchical index structure-similar to the X-tree-exploiting the concept hierarchies typically defined for the dimensions of a data cube. We conducted an extensive experimental performance evaluation using the TPC-D benchmark data. Our results demonstrate that the DC-tree yields a significant speed-up compared to the X-tree and the sequential search when processing general range queries on a data cube.
Martin Ester, Jörn Kohlhammer, Hans-Peter Kriegel
ICDE2