Leonardo Montecchi

dblp:30/2196 · DBLP profile ↗
← Back
17ranked-venue papers
6as first author
6since 2021 · last 2026
0000-0002-7603-9695ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 9 · 1 first-author · 4 since 2021Security and privacy · 6 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author · 2 since 2021Systems, architecture and hardware · 2 · 1 first-authorComputer networks · 1 · 1 first-author
YearPublicationVenuePosition
2026 Fragment-Block: A Novel Approach for Managing Variability in Software Product Lines
abstract
ABSTRACT Objective Changes in the functionality of a software product line (SPL) can generate various issues in the SPL source code. Their complexity depends primarily on the amount of changes in the SPL source code and the internal mechanisms for managing variability. Further, modern development frameworks rely on a variety of artefacts besides source code. SPL developers need tools that can consistently search, segment, and analyse the SPL source code, to minimise undesired behaviours and reduce the time to implement new functionalities. Methods We introduce a novel approach and tool to manage SPLs source code. This approach streamlines the search and segmentation processes during source‐code changes. To demonstrate its feasibility, we apply it as a proof of concept to two concrete SPLs: an implementation of the Elevator SPL from FeatureIDE; and a new SPL that includes generic textual artefacts. Further, we position our tool with respect to other existing approaches. Result The results demonstrated the feasibility of our approach. Differently from other tools for variability management, our approach supports both variability in time and variability in space, and supports generic textual artefacts, offering a similar flexibility as conditional compilation. Conclusion We proposed a new approach and tool for managing variability in SPLs. Our proposal leverages the concepts of blocks, features, and fragments to organise variability in textual artefacts, including, but not limited to, source code, A key characteristic of the approach is that it does not rely on any specific IDE, making it broadly applicable across different development contexts.
Junior Cupe Casquina, Leonardo Montecchi
Softw. Pract. Exp.2
2026 Fail-Controlled Classifiers: A Swiss-Army Knife Toward Trustworthy Systems
abstract
ABSTRACT Background Modern critical systems often require to take decisions and classify data and scenarios autonomously without having detrimental effects on people, infrastructures or the environment, ensuring desired dependability attributes. Researchers typically strive to craft classifiers with perfect accuracy, which should be always correct and as such never threaten the encompassing system. Unfortunately, this is a very unrealistic goal, as classification tasks are typically complex and may encounter a wide variety of unexpected operating conditions and unknown inputs. Methods Classifiers should be considered as building blocks that interact with other components that help rejecting those predictions that are suspected to be misclassifications, triggering system‐level mitigation strategies instead. Fail‐Controlled Classifiers (FCCs) are software components that can either correctly classify, misclassify, or reject outputs: ideally, they would reject all and only outputs that correspond to misclassifications. Nine different FCCs are presented: Self‐Checking Classifiers (SCC), Watchdog Timers (WT), Input Processor (IP), Output processor (OP), Safety Wrapper (SW), Recovery Blocks (RB), weighted and non‐weighted Voting (VT, WVT) and Stacking (STK). Results These 9 FCCs are instantiated in experiments with tabular and image classifiers, showing their potential in rejecting most misclassifications and paving the ways for trustworthy decisions to be deployed in critical systems. If the system can tolerate more omissions, the IP FCC is a good choice. On the other hand, if achieving the highest accuracy is the priority, RB FCC performs better. Conclusions Findings show that FCCs do not primarily aim at improving correct classifications, but allow for transforming many misclassifications into rejections, which may be easily handled by the encompassing system and paving the way for trustworthy decisions to be deployed in critical systems.
Fahad Ahmed KhoKhar, Tommaso Zoppi, Andrea Ceccarelli, Leonardo Montecchi, Andrea Bondavalli
Softw. Pract. Exp.4
2025 Integrating Attack-Fault Trees in the ODE Metamodel to Support Safety and Security Co-Analysis in the Automotive Domain
abstract
Integrating safety and security in automotive cyber-physical systems (CPS) domains (e.g. autonomous vehicles), is challenging for two main reasons. First, it is still difficult to represent the potential consequences of system failures or malicious attacks. Secondly, these systems must ensure safety and security despite unknowns and uncertainties. A Digital Dependability Identity (DDI) can facilitate this by encapsulating all dependability characteristics (e.g., design, requirements, safety, and security analysis models) of CPS’s components. The Open Dependability Exchange (ODE) metamodel is an implementation of the DDI concept, but has limitations in the interplay between safety and security. ODE is aligned with with ISO 26262 but lacks certain security concepts to be aligned with ISO 21434. Also, ODE supports modeling fault trees, but modeling attack trees and attack-fault trees still not. This paper proposes an extension to the ODE metamodel, aiming to increase coverage of ISO 21434 concepts and allowing the modeling of attack-fault trees. We built these metamodel extensions based on an analysis of the ODE metamodel, industry standards, Microsoft STRIDE model, and HEAVENS security analysis methodologies. We evaluated the proposed extensions in an illustrative example of an autonomous vehicle.
Victor Luiz Grechi, André Luíz de Oliveira, Barbara Gallina, Leonardo Montecchi, Rosana T. V. Braga
COMPSAC4
2025 FaultFlow: An MDE Library for Dependability Evaluation of Component-Based Systems
abstract
We present a Model Driven Engineering (MDE) approach to dependability evaluation of component-based coherent dyadic systems, implemented by the FaultFlow library, combining simple high-level modeling with powerful quantitative evaluation methods. In the functional perspective, distinctive features are: modeling of fault propagations within individual components and between different components, possibly not connected through physical or communication interfaces; support for non-Markovian distributions, both for the times to the occurrence of faults and for the duration of fault-to-failure propagations; derivation of the distribution of the time to the occurrence of a given failure; derivation of fault importance measures, for models where each fault does not propagate into multiple failures and, viceversa, each failure does not act as fault to multiple components, achieving evaluation efficiency even for significantly complex systems with hundreds of different faults. In the implementation perspective, distinctive features are: definition of a custom-made extensible metamodel to specify the system structure and failure logic; automated derivation of metamodel instances from Systems Modeling Language (SysML) Block Definition Diagrams (BDDs) and Stochastic Static Fault Trees (SSFTs); automated derivation of the mentioned dependability measures; open source availability. We illustrate the typical modeling and evaluation workflow with relevant uses cases, comparing functionalities with those of other dependability evaluation tools.
Laura Carnevali, Stefania Cerboni, Leonardo Montecchi, Enrico Vicario
IEEE Trans. Dependable Secur. Comput.3
2024 Fail-Controlled Classifiers: Do they Know when they don't Know?
abstract
Domain experts are desperately looking to solve decision-making problems by designing and training Machine Learning algorithms that can perform classification with the highest possible accuracy. No matter how hard they try, classifiers will always be prone to misclassifications due to a variety of reasons that make the decision boundary unclear. This complicates the integration of classifiers into critical systems, where misclassifications could directly impact people, infrastructures, or the environment. The paper proposes to consider a classifier as a structural part of the system instead of an individual component to be tested in isolation and included in the system afterward. This allows for omitting those predictions that are suspected to be misclassifications, triggering system-level mitigation strategies. The resulting fail-controlled classifiers (FCCs) are software components that can correctly classify, misclassify, or omit outputs: ideally, they would omit all and only outputs that correspond to misclassifications. After presenting the theoretical foundations of FCCs, the paper proposes metrics to quantify their performance, 5 software architectures for FCCs, and an experimental analysis involving tabular data and image classifiers. Overall, this paper advocates the need for a system and software design in which ML classifiers are not separate components, but should rather be considered building blocks that interact with other components for improved performance.
Tommaso Zoppi, Fahad Ahmed KhoKhar, Andrea Ceccarelli, Leonardo Montecchi, Andrea Bondavalli
PRDC4
2022 Stochastic Activity Networks Templates: Supporting Variability in Performability Models
abstract
Model-based evaluation is extensively used to estimate the performance and reliability of dependable systems. Traditionally, these systems were small and self-contained, and the main challenge for model-based evaluation has been the efficiency of the solution process. Recently, the problem of specifying and maintaining complex models has increasingly gained attention, as modern systems are characterized by many components and complex interactions. Components share similarities, but at the same time, also exhibit variations in their behavior due to different configurations or roles in the system. From the modeling perspective, variations lead to replicating and altering a small set of base models multiple times. Variability is taken into account only informally, by defining a sample model and explaining its possible variations. In this article, we address the problem of including variability in performability models, focusing on stochastic activity networks (SANs). We introduce the formal definition of stochastic activity networks templates (SAN-T), a formalism based on SANs with the addition of variability aspects. Differently from other approaches, parameters can also affect the structure of the model, like the number of cases of activities. We apply the SAN-T formalism to the modeling of the backbone network of an environmental monitoring infrastructure. In particular, we show how existing SAN models from the literature can be generalized using the newly introduced formalism.
Leonardo Montecchi, Paolo Lollini, Andrea Bondavalli
IEEE Trans. Reliab.1
2020 Model-Driven Fault Injection in Java Source Code
abstract
The injection of software faults in source code requires accurate knowledge of the programming language, both to craft faults and to identify injection locations. As such, fault injection and code mutation tools are typically tailored for a specific language and have limited extensibility. In this paper we present a model-driven approach to craft and inject software faults in source code. While its concrete application is presented for Java, the workflow we propose does not depend on a specific programming language. Following Model-Driven Engineering principles, the faults and the criteria to select injection locations are described using structured, machine-readable specifications based on a domain-specific language. Then, automated transformations craft artifacts based on OCL and Java, which represent the faults to be injected and are able to select the candidate injection locations. Finally, artifacts are executed against the target source code, performing the injection in the desired locations. We devise a supporting tool and exercise the approach injecting 13 different kinds of software faults in the Java source code of six different projects.
Elder Rodrigues Jr., Leonardo Montecchi, Andrea Ceccarelli
ISSRE2
2020 Using Metamodels to Improve Model-Based Testing of Service Orchestrations
abstract
Online model-based testing is one of the most suitable techniques to assess the proper behavior of service orchestrations. However, the diverse panorama in terms of modeling languages and test case generation tools is a limitation to widespread adoption. We advocate that the application of Model-Driven Engineering principles as meta-modeling and model transformation can cope with this problem, improving the interoperability of artifacts in the test case generation process, thus bringing benefits in case of agile development processes, where system and technology evolution is frequent. In this paper, we present our contribution to this idea, introducing i) a reference metamodel, which stores the business process behavior and the information to generate input models for testing tools, and ii) transformations from orchestration languages towards testing tools. The proposed approach is implemented in a testing framework and evaluated on a case study where multiple orchestrations are expressed in two languages. Also, the paper presents how test cases are appropriately generated and successfully executed, starting from an orchestration model as a consequence of successful transformations.
Lucas Leal, Leonardo Montecchi, Andrea Ceccarelli, Eliane Martins
PRDC2
2020 A Template-Based Methodology for the Specification and Automated Composition of Performability Models
abstract
Dependability and performance analysis of modern systems is facing great challenges: their scale is growing, they are becoming massively distributed, interconnected, and evolving. Such complexity makes model-based assessment a difficult and time-consuming task. For the evaluation of large systems, reusable submodels are typically adopted as an effective way to address the complexity and to improve the maintainability of models. When using state-based models, a common approach is to define libraries of generic submodels, and then compose concrete instances by state sharing, following predefined “patterns” that depend on the class of systems being modeled. However, such composition patterns are rarely formalized, or not even documented at all. In this paper, we address this problem using a model-driven approach, which combines a language to specify reusable submodels and composition patterns, and an automated composition algorithm. Clearly defining libraries of reusable submodels, together with patterns for their composition, allows complex models to be automatically assembled, based on a high-level description of the scenario to be evaluated. This paper provides a solution to this problem focusing on: formally defining the concept of model templates, defining a specification language for model templates, defining an automated instantiation and composition algorithm, and applying the approach to a case study of a large-scale distributed system.
Leonardo Montecchi, Paolo Lollini, Andrea Bondavalli
IEEE Trans. Reliab.1
2019 Towards a Structured Specification of Coding Conventions
abstract
Coding conventions are a means to improve the reliability of software systems. They can be established for many reasons, ranging from improving the readability of code to avoiding the introduction of security flaws. However, coding conventions often come in the form of textual documents in natural language, which makes them hard to manage and to enforce. Following model-driven engineering principles, in this paper we propose an approach and language for specifying coding conventions using structured models. We ran a feasibility study, in which we applied our language for specifying 215 coding rules from two popular rulesets. The obtained results are promising and suggest that the proposed approach is feasible. However, they also highlight that many challenges still need to be overcome. We conclude with an overview on the ongoing work for generating automated checkers from such models, and we discuss directions for an objective evaluation of the methodology.
Elder Rodrigues Jr., Leonardo Montecchi
PRDC2
2018 PrivAPP: An integrated approach for the design of privacy-aware applications
abstract
Summary Nowadays, personal information is collected, stored, and managed through web applications and services. Companies are interested in keeping such information private due to regulation laws and privacy concerns of customers. Furthermore, the reputation of a company can be dependent on privacy protection, ie, the more a company protects the privacy of its customers, the more credibility it gets. This paper proposes an integrated approach that relies on models and design tools to help in the analysis, design, and development of web applications and services with privacy concerns. Using the approach, these applications can be developed consistently with their privacy policies to enforce them, protecting personal information from different sources of privacy violation. The approach is composed of a conceptual model, a reference architecture, and a Unified Modified Language Profile, ie, an extension of the Unified Modified Language for including privacy protection. The idea is to systematize the privacy concepts in the scope of web applications and services, organizing the privacy domain knowledge and providing features and functionalities that must be addressed to protect the privacy of the users in the design and development of web applications. Validation has been performed by analyzing the ability of the approach to model privacy policies from real web applications and by applying it to a simple application example of an online bookstore. Results show that privacy protection can be implemented in a model‐based approach, bringing values for the stakeholders and being an important contribution toward improving the process of designing web applications in the privacy domain.
Tânia Basso, Leonardo Montecchi, Regina Lúcia de Oliveira Moraes, Mário Jino, Andrea Bondavalli
Softw. Pract. Exp.2
2016 A Model-Based Approach to Support Safety-Related Decisions in the Petroleum Domain
abstract
Accidents on petroleum installations can have huge consequences, to mitigate the risk, a number of safety barriers are devised. Faults and unexpected events may cause barriers to temporarily deviate from their nominal state. For safety reasons, a work permit process is in place: decision makers accept or reject work permits based on the current state of barriers. However, this is difficult to estimate, as it depends on a multitude of physical, technical and human factors. Information obtained from different sources needs to be aggregated by humans, typically within a limited amount of time. In this paper we propose an approach to provide an automated decision support to the work permit system, which consists in the evaluation of quantitative measures of the risk associated with the execution of work. The approach relies on state-based stochastic models, which can be automatically composed based on the work permit to be examined.
Leonardo Montecchi, Atle Refsdal, Paolo Lollini, Andrea Bondavalli
DSN1
2016 Modeling QoE in Dependable Tele-Immersive Applications: A Case Study of World Opera
abstract
With the advent of recent technological advances, more demanding tele-immersive applications have started to emerge. In the World Opera application, artists from different opera houses across the globe can participate in a single united performance, and interact almost as if they were co-located. One of the main design challenges in this application domain is to assess to what extent the inevitable failures of some of the numerous and complex hardware, software, and network components affect the quality of experience for the user. This challenge cannot be addressed by traditional system-centric methods for dependability evaluation, which do not take personalized user perspective into account when considering meaningful and acceptable degradation of services. In this paper, we propose a novel method to assess the quality of experience in presence of failures, based on a new metric called perceived reliability. The method takes the human perspective into account and allows considering factors such as human perception of video and audio, characteristics of the audience, as well as performance elements and artistic content. This method can help system designers and engineers compare architectural variants and determine the dependability budget. We show the feasibility of our method by applying it to a World Opera performance. To this end, we construct a SAN-based model and run simulations in the Möbius framework. The obtained results provide useful guidelines for system engineers towards improving the quality of experience of World Opera performances despite the presence of failures.
Narasimha Raghavan, Leonardo Montecchi, Nicola Nostro, Roman Vitenberg, Hein Meling, Andrea Bondavalli
IEEE Trans. Parallel Distributed Syst.2
2015 Continuous and Transparent User Identity Verification for Secure Internet Services
abstract
Session management in distributed Internet services is traditionally based on username and password, explicit logouts and mechanisms of user session expiration using classic timeouts. Emerging biometric solutions allow substituting username and password with biometric data during session establishment, but in such an approach still a single verification is deemed sufficient, and the identity of a user is considered immutable during the entire session. Additionally, the length of the session timeout may impact on the usability of the service and consequent client satisfaction. This paper explores promising alternatives offered by applying biometrics in the management of sessions. A secure protocol is defined for perpetual authentication through continuous user verification. The protocol determines adaptive timeouts based on the quality, frequency and type of biometric data transparently acquired from the user. The functional behavior of the protocol is illustrated through Matlab simulations, while model-based quantitative analysis is carried out to assess the ability of the protocol to contrast security attacks exercised by different kinds of attackers. Finally, the current prototype for PCs and Android smartphones is discussed.
Andrea Ceccarelli, Leonardo Montecchi, Francesco Brancati, Paolo Lollini, Angelo Marguglio, Andrea Bondavalli
IEEE Trans. Dependable Secur. Comput.2
2013 Meeting the challenges in the design and evaluation of a trackside real-time safety-critical system
abstract
Highly distributed, autonomous and self-powered systems operating in harsh, outdoors environments face several threats in terms of dependability, timeliness and security, due to the challenging operating conditions determined by the environment. Despite such difficulties, there is an increasing demand to deploy these systems to support critical services, thus calling for severe timeliness, safety, and security requirements. Several challenges need to be faced and overcome. First, the designed architecture must be able to cope with the environmental challenges and satisfy dependability, timeliness and security requirements. Second, the assessment of the system must be carried on despite potentially incomplete field-data, and complex cascading effects that small modifications in system properties and operating conditions may have on the targeted metrics. In this paper we present our experience from the EU-funded project ALARP (A railway automatic track warning system based on distributed personal mobile terminals), which aims to build and validate a distributed, real-time, safety-critical system that detects trains approaching a railway worksite and notifies their arrivals to railway trackside workers. The paper describes the challenges we faced, and the solutions we adopted, when architecting and evaluating the ALARP system.
Leonardo Montecchi, Andrea Ceccarelli, Paolo Lollini, Andrea Bondavalli
ISORC1
2012 Model-based analysis of a protocol for reliable communication in railway worksites
abstract
In this paper we perform a model-based analysis of the Timed Reliable Communication (TRC) protocol, which is being used within the EU funded ALARP project for railway worksite com-munication. TRC is a group communication protocol based on IEEE 802.11 networks, targeting safety-critical applications with limited bandwidth requirements. The paper contains an in-depth analysis of the performance and reliability characteristics of the protocol using a Stochastic Activity Networks model. The results are first compared with available experimental measurements for the sake of model validation. The validated model is then used for a thorough analysis of a set of key metrics under different envi-ronment and network conditions. The obtained results allow: i) to assess that the protocol allows to satisfy the ALARP targeted performance and reliability requirements, and ii) to evaluate the existing tradeoffs and help in choosing parameter values for the final implementation.
Leonardo Montecchi, Paolo Lollini, Boris Malinowsky, Jesper Grønbæk, Andrea Bondavalli
MSWiM1
2011 Towards a MDE Transformation Workflow for Dependability Analysis
abstract
In the last ten years, Model Driven Engineering (MDE) approaches have been extensively used for the analysis of extra-functional properties of complex systems, like safety, dependability, security, predictability, quality of service. To this purpose, engineering languages (like UML and AADL) have been extended with additional features to model the required non-functional attributes, and transformations have been used to automatically generate the analysis models to be solved by appropriate analysis tools. In most of the available works, however, the transformations are not inte grated into a more general development process, aimed to support both domain-specific design analysis and verification of extra-functional properties. In this paper we explore this research direction presenting a transformation work flow for dependability analysis that is part of an industrial-quality infrastructure for the specification, analysis and verification of extra-functional properties, currently under development within the ARTEMIS-JU CHESS project. Specifically, the paper provides the following major contributions: i) definition of the required transformation steps to automatically assess the system dependability properties starting from the CHESS Modeling Language, ii) definition of a new Intermediate Dependability Model (IDM) acting as a bridge between the CHESS Modeling Language and the low-level analysis models, iii) definition of transformations from the CHESS Modeling Language to IDM models.
Leonardo Montecchi, Paolo Lollini, Andrea Bondavalli
ICECCS1