Leen Lambers

dblp:20/472 · DBLP profile ↗
← Back
44ranked-venue papers
12as first author
12since 2021 · last 2026
0000-0001-6937-5167ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Theory of computation · 22 · 8 first-author · 5 since 2021Software engineering, systems software and programming languages · 21 · 4 first-author · 6 since 2021Databases, data management, data science and information retrieval · 14 · 6 first-author · 2 since 2021
YearPublicationVenuePosition
2026 Taint Analysis for Graph APIs Focusing on Broken Access Control
abstract
We present the first systematic approach to static and dynamic taint analysis for Graph APIs focusing on broken access control. The approach comprises the following. We taint nodes of the Graph API if they represent data requiring specific privileges in order to be retrieved or manipulated, and identify API calls which are related to sources and sinks. Then, we statically analyze whether a tainted information flow between API source and sink calls occurs. To this end, we model the API calls using graph transformation rules. We subsequently use Critical Pair Analysis to automatically analyze potential dependencies between rules representing source calls and rules representing sink calls. We distinguish direct from indirect tainted information flow and argue under which conditions the Critical Pair Analysis is able to detect not only direct, but also indirect tainted flow. The static taint analysis (i) identifies flows that need to be further reviewed, since tainted nodes may be created by an API call and used or manipulated by another API call later without having the necessary privileges, and (ii) can be used to systematically design dynamic security tests for broken access control. The dynamic taint analysis checks if potential broken access control risks detected during the static taint analysis really occur. We apply the approach to a part of the GitHub GraphQL API. The application illustrates that our analysis supports the detection of two types of broken access control systematically: the case where users of the API may not be able to access or manipulate information, although they should be able to do so; and the case where users (or attackers) of the API may be able to access/manipulate information that they should not.
Leen Lambers, Lucas Sakizloglou, Taisiya Khakharova, Fernando Orejas
Log. Methods Comput. Sci.1
2025 Preface for the special issue on "Selected Papers and Tools of the 26th International Conference on Fundamental Approaches to Software Engineering" (FASE 2023)
Carlos Diego Nascimento Damasceno, Marie-Christine Jakobs, Leen Lambers, Sebastián Uchitel
Sci. Comput. Program.3
2024 On the Application of Model-Driven Optimization to Business Processes
Gabriele Taentzer, Jens Kosiol, Leen Lambers
Petri Nets3
2024 Coinductive Techniques for Checking Satisfiability of Generalized Nested Conditions
abstract
Kein CA
Lara Stoltenow, Barbara König 0001, Sven Schneider 0001, Andrea Corradini 0001, Leen Lambers, Fernando Orejas
CONCUR5
2024 Foundations for Query-based Runtime Monitoring of Temporal Properties over Runtime Models
abstract
Abstract In model-driven engineering, runtime monitoring of systems with complex dynamic structures is typically performed via a runtime model capturing a snapshot of the system state: the model is represented as a graph and properties of interest as graph queries which are evaluated over the model online. For temporal properties, history-aware runtime models encode a trace of timestamped snapshots, which is monitored via temporal graph queries. In this case, the query evaluation needs to consider that a trace may be incomplete, thus future changes to the model may affect current answers. So far there is no formal foundation for query-based monitoring over runtime models encoding incomplete traces. In this paper, we present a systematic and formal treatment of incomplete traces. First, we introduce a new definite semantics for a first-order temporal graph logic which only returns answers if no future change to the model will affect them. Then, we adjust the query evaluation semantics of a querying approach we previously presented, which is based on this logic, to the definite semantics of the logic. Lastly, we enable the approach to keep to its efficient query evaluation technique, while returning (the more costly) definite answers.
Lucas Sakizloglou, Holger Giese, Leen Lambers
FASE3
2024 Taint Analysis for Graph APIs Focusing on Broken Access Control
Leen Lambers, Lucas Sakizloglou, Osama Al-Wardi, Taisiya Khakharova
ICGT1
2023 Evaluation diversity for graph conditions
Sven Schneider 0001, Leen Lambers
J. Log. Algebraic Methods Program.2
2023 A graph-based framework for model-driven optimization facilitating impact analysis of mutation operator properties
abstract
Abstract Optimization problems in software engineering typically deal with structures as they occur in the design and maintenance of software systems. In model-driven optimization (MDO), domain-specific models are used to represent these structures while evolutionary algorithms are often used to solve optimization problems. However, designing appropriate models and evolutionary algorithms to represent and evolve structures is not always straightforward. Domain experts often need deep knowledge of how to configure an evolutionary algorithm. This makes the use of model-driven meta-heuristic search difficult and expensive. We present a graph-based framework for MDO that identifies and clarifies core concepts and relies on mutation operators to specify evolutionary change. This framework is intended to help domain experts develop and study evolutionary algorithms based on domain-specific models and operators. In addition, it can help in clarifying the critical factors for conducting reproducible experiments in MDO. Based on the framework, we are able to take a first step toward identifying and studying important properties of evolutionary operators in the context of MDO. As a showcase, we investigate the impact of soundness and completeness at the level of mutation operator sets on the effectiveness and efficiency of evolutionary algorithms.
Stefan John 0001, Jens Kosiol, Leen Lambers, Gabriele Taentzer
Softw. Syst. Model.3
2021 Evaluation Diversity for Graph Conditions
Sven Schneider 0001, Leen Lambers
ICGT2
2021 A navigational logic for reasoning about graph properties
Marisa Navarro, Fernando Orejas, Elvira Pino, Leen Lambers
J. Log. Algebraic Methods Program.4
2021 A logic-based incremental approach to graph repair featuring delta preservation
abstract
Abstract We introduce a logic-based incremental approach to graph repair, generating a sound and complete (upon termination) overview of least-changing graph repairs from which a user may select a graph repair based on non-formalized further requirements. This incremental approach features delta preservation as it allows to restrict the generation of graph repairs to delta-preserving graph repairs, which do not revert the additions and deletions of the most recent consistency-violating graph update. We specify consistency of graphs using the logic of nested graph conditions, which is equivalent to first-order logic on graphs. Technically, the incremental approach encodes if and how the graph under repair satisfies a graph condition using the novel data structure of satisfaction trees, which are adapted incrementally according to the graph updates applied. In addition to the incremental approach, we also present two state-based graph repair algorithms, which restore consistency of a graph independent of the most recent graph update and which generate additional graph repairs using a global perspective on the graph under repair. We evaluate the developed algorithms using our prototypical implementation in the tool AutoGraph and illustrate our incremental approach using a case study from the graph database domain.
Sven Schneider 0001, Leen Lambers, Fernando Orejas
Int. J. Softw. Tools Technol. Transf.2
2021 Transformation rules with nested application conditions: Critical pairs, initial conflicts & minimality
Leen Lambers, Fernando Orejas
Theor. Comput. Sci.1
2020 Initial Conflicts for Transformation Rules with Nested Application Conditions
Leen Lambers, Fernando Orejas
ICGT1
2020 Preface to the special issue on the 11th International Conference on Graph Transformation
Leen Lambers, Jens H. Weber
J. Log. Algebraic Methods Program.1
2019 A Logic-Based Incremental Approach to Graph Repair
abstract
Graph repair, restoring consistency of a graph, plays a prominent role in several areas of computer science and beyond: For example, in model-driven engineering, the abstract syntax of models is usually encoded using graphs. Flexible edit operations temporarily create inconsistent graphs not representing a valid model, thus requiring graph repair. Similarly, in graph databases—managing the storage and manipulation of graph data—updates may cause that a given database does not satisfy some integrity constraints, requiring also graph repair. We present a logic-based incremental approach to graph repair, generating a sound and complete (upon termination) overview of least-changing repairs. In our context, we formalize consistency by so-called graph conditions being equivalent to first-order logic on graphs. We present two kind of repair algorithms: State-based repair restores consistency independent of the graph update history, whereas delta-based (or incremental) repair takes this history explicitly into account. Technically, our algorithms rely on an existing model generation algorithm for graph conditions implemented in $$\textsc {AutoGraph}$$ . Moreover, the delta-based approach uses the new concept of satisfaction (ST) trees for encoding if and how a graph satisfies a graph condition. We then demonstrate how to manipulate these $$\mathrm {STs}$$ incrementally with respect to a graph update.
Sven Schneider 0001, Leen Lambers, Fernando Orejas
FASE2
2019 Exploring Conflict Reasons for Graph Transformation Systems
Leen Lambers, Jens Kosiol, Daniel Strüber 0001, Gabriele Taentzer
ICGT1
2019 Contents for a Model-Based Software Engineering Body of Knowledge
abstract
Although Model-Based Software Engineering (MBE) is a widely accepted Software Engineering (SE) discipline, no agreed-upon core set of concepts and practices (i.e., a Body of Knowledge) has been defined for it yet. With the goals of characterizing the contents of the MBE discipline, promoting a global consistent view of it, clarifying its scope with regard to other SE disciplines, and defining a foundation for the development of educational curricula on MBE, this paper proposes the contents for a Body of Knowledge for MBE. We also describe the methodology that we have used to come up with the proposed list of contents, as well as the results of a survey study that we conducted to sound out the opinion of the community on the importance of the proposed topics and their level of coverage in the existing SE curricula.
Loli Burgueño, Federico Ciccozzi, Michalis Famelis, Gerti Kappel, Leen Lambers, Sébastien Mosser 0001, Richard F. Paige, Alfonso Pierantonio, Arend Rensink, Rick Salay, Gabriele Taentzer, Antonio Vallecillo, Manuel Wimmer
Softw. Syst. Model.5
2019 Automatic verification of behavior preservation at the transformation level for relational model transformation
abstract
The correctness of model transformations is a crucial element for model-driven engineering of high-quality software. In particular, behavior preservation is an important correctness property avoiding the introduction of semantic errors during the model-driven engineering process. Behavior preservation verification techniques show some kind of behavioral equivalence or refinement between source and target model of the transformation. Automatic tool support is available for verifying behavior preservation at the instance level, i.e., for a given source and target model specified by the model transformation. However, until now there is no sound and automatic verification approach available at the transformation level, i.e., for all source and target models. In this article, we extend our results presented in earlier work (Giese and Lambers, in: Ehrig et al (eds) Graph transformations, Springer, Berlin, 2012 ) and outline a new transformation-level approach for the sound and automatic verification of behavior preservation captured by bisimulation resp. simulation for outplace model transformations specified by triple graph grammars and semantic definitions given by graph transformation rules. In particular, we first show how behavior preservation can be modeled in a symbolic manner at the transformation level and then describe that transformation-level verification of behavior preservation can be reduced to invariant checking of suitable conditions for graph transformations. We demonstrate that the resulting checking problem can be addressed by our own invariant checker for an example of a transformation between sequence charts and communicating automata.
Johannes Dyck, Holger Giese, Leen Lambers
Softw. Syst. Model.3
2018 Multi-granular conflict and dependency analysis in software engineering based on graph transformation
abstract
Conflict and dependency analysis (CDA) of graph transformation has been shown to be a versatile foundation for understanding interactions in many software engineering domains, including software analysis and design, model-driven engineering, and testing. In this paper, we propose a novel static CDA technique that is multi-granular in the sense that it can detect all conflicts and dependencies on multiple granularity levels. Specifically, we provide an efficient algorithm suite for computing binary, coarse-grained, and fine-grained conflicts and dependencies: Binary granularity indicates the presence or absence of conflicts and dependencies, coarse granularity focuses on root causes for conflicts and dependencies, and fine granularity shows each conflict and dependency in full detail. Doing so, we can address specific performance and usability requirements that we identified in a literature survey of CDA usage scenarios. In an experimental evaluation, our algorithm suite computes conflicts and dependencies rapidly. Finally, we present a user study, in which the participants found our coarse-grained results more understandable than the fine-grained ones reported in a state-of-the-art tool. Our overall contribution is twofold: (i) we significantly speed up the computation of fine-grained and binary CDA results and, (ii) complement them with coarse-grained ones, which offer usability benefits for numerous use cases.
Leen Lambers, Daniel Strüber 0001, Gabriele Taentzer, Kristopher Born, Jevgenij Huebert
ICSE1
2018 Automated reasoning for attributed graph properties
Sven Schneider 0001, Leen Lambers, Fernando Orejas
Int. J. Softw. Tools Technol. Transf.2
2018 Institutions for navigational logics for graphical structures
Fernando Orejas, Elvira Pino, Marisa Navarro, Leen Lambers
Theor. Comput. Sci.4
2017 Symbolic Model Generation for Graph Properties
Sven Schneider 0001, Leen Lambers, Fernando Orejas
FASE2
2017 Granularity of Conflicts and Dependencies in Graph Transformation Systems
Kristopher Born, Leen Lambers, Daniel Strüber 0001, Gabriele Taentzer
ICGT2
2016 On the Operationalization of Graph Queries with Generalized Discrimination Networks
Thomas Beyhl, Dominique Blouin, Holger Giese, Leen Lambers
ICGT4
2016 Model transformation intents and their properties
Levi Lucio, Moussa Amrani, Jürgen Dingel, Leen Lambers, Rick Salay, Gehan M. K. Selim, Eugene Syriani, Manuel Wimmer
Softw. Syst. Model.4
2014 Tableau-Based Reasoning for Graph Properties
Leen Lambers, Fernando Orejas
ICGT1
2014 ℳ-adhesive transformation systems with nested application conditions. Part 1: parallelism, concurrency and amalgamation
abstract
Nested application conditions generalise the well-known negative application conditions and are important for several application domains. In this paper, we present Local Church–Rosser, Parallelism, Concurrency and Amalgamation Theorems for rules with nested application conditions in the framework of $\mathcal{M}$ -adhesive categories, where $\mathcal{M}$ -adhesive categories are slightly more general than weak adhesive high-level replacement categories. Most of the proofs are based on the corresponding statements for rules without application conditions and two shift lemmas stating that nested application conditions can be shifted over morphisms and rules.
Hartmut Ehrig, Ulrike Golas, Annegret Habel, Leen Lambers, Fernando Orejas
Math. Struct. Comput. Sci.4
2014 Bridging the gap between formal semantics and implementation of triple graph grammars - Ensuring conformance of relational model transformation specifications and implementations
Holger Giese, Stephan Hildebrandt, Leen Lambers
Softw. Syst. Model.3
2012 Towards Automatic Verification of Behavior Preservation for Model Transformation via Invariant Checking
Holger Giese, Leen Lambers
ICGT2
2012 Toward Bridging the Gap between Formal Foundations and Current Practice for Triple Graph Grammars - Flexible Relations between Source and Target Elements
Ulrike Golas, Leen Lambers, Hartmut Ehrig, Holger Giese
ICGT2
2012 ℳ-Adhesive Transformation Systems with Nested Application Conditions. Part 2: Embedding, Critical Pairs and Local Confluence
abstract
Graph transformation systems have been studied extensively and applied to several areas of computer science like formal language theory, the modeling of databases, concurrent or distributed systems, and visual, logical, and functional programming. In
Hartmut Ehrig, Ulrike Golas, Annegret Habel, Leen Lambers, Fernando Orejas
Fundam. Informaticae4
2012 Lazy Graph Transformation
abstract
Applying an attributed graph transformation rule to a given object graph always implies some kind of constraint solving. In many cases, the given constraints are almost trivial to solve. For instance, this is the case when a rule describes a transfor
Fernando Orejas, Leen Lambers
Fundam. Informaticae2
2012 Attributed graph transformation with inheritance: Efficient conflict detection and local confluence analysis using abstract critical pairs
Ulrike Golas, Leen Lambers, Hartmut Ehrig, Fernando Orejas
Theor. Comput. Sci.2
2011 Modeling with Plausibility Checking: Inspecting Favorable and Critical Signs for Consistency between Control Flow and Functional Behavior
Claudia Ermel, Juergen Gall, Leen Lambers, Gabriele Taentzer
FASE3
2010 Local Confluence for Rules with Nested Application Conditions
Hartmut Ehrig, Annegret Habel, Leen Lambers, Fernando Orejas, Ulrike Golas
ICGT3
2010 Delaying Constraint Solving in Symbolic Graph Transformation
Fernando Orejas, Leen Lambers
ICGT2
2010 Introduction to AGG and EMF Tiger by modeling a Conference Scheduling System
Enrico Biermann, Claudia Ermel, Leen Lambers, Ulrike Golas, Olga Runge, Gabriele Taentzer
Int. J. Softw. Tools Technol. Transf.3
2009 Object Flow Definition for Refined Activity Diagrams
Stefan Jurack, Leen Lambers, Katharina Mehner-Heindl, Gabriele Taentzer, Gerd Wierse
FASE2
2008 A Formal Framework for Developing Adaptable Service-Based Applications
Leen Lambers, Leonardo Mariani, Hartmut Ehrig, Mauro Pezzè
FASE1
2008 Embedding and Confluence of Graph Transformations with Negative Application Conditions
Leen Lambers, Hartmut Ehrig, Ulrike Golas, Fernando Orejas
ICGT1
2008 Behavior Preservation in Model Refactoring Using DPO Transformations with Borrowed Contexts
Guilherme Rangel, Leen Lambers, Barbara König 0001, Hartmut Ehrig, Paolo Baldan
ICGT2
2008 Sufficient Criteria for Consistent Behavior Modeling with Refined Activity Diagrams
Stefan Jurack, Leen Lambers, Katharina Mehner-Heindl, Gabriele Taentzer
MoDELS2
2007 Iterative model-driven development of adaptable service-based applications
abstract
Flexibility and interoperability make web services well suited for designing highly-customizable reactive service-based ap-plications, that is interactive applications that can be rapidly adapted to new requirements and environmental conditions. This is the case, for example of personal data managers that many users tailor to their needs to meet different usage con-ditions and requests. In this paper, we propose a model-based approach that provides users with the ability of rapidly developing, adapt-ing and reconfiguring reactive service-based applications to meet new requirements and needs. Users specify their needs by describing sample executions that include interactions with web services through an intuitive interface. Interac-tions are stored in a visual formalism that integrates live sequence charts with graph transformation systems. Mod-els can be visualized, modified, executed and automatically analyzed to identify inconsistencies.
Leen Lambers, Hartmut Ehrig, Leonardo Mariani, Mauro Pezzè
ASE1
2006 Conflict Detection for Graph Transformation with Negative Application Conditions
Leen Lambers, Hartmut Ehrig, Fernando Orejas
ICGT1