VLDB 2026 Research / reviewers in the wild / expert
Paolo Lollini
dblp:43/1911
· DBLP profile ↗
22ranked-venue papers
2as first author
5since 2021 · last 2025
0000-0002-2364-2538ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 7 · 3 since 2021Security and privacy · 5Applied, interdisciplinary, general and emerging computing · 5 · 1 first-author · 2 since 2021Systems, architecture and hardware · 3Computer networks · 3 · 1 first-authorDatabases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Quantitative Comparison of System Architectures for an SAE Level 4 Highway PilotabstractThe development of SAE Level 4 autonomous driving systems requires fault-tolerant architectures to ensure proper operation and robustness under demanding operational conditions. These architectures must gracefully handle hardware and software faults to maintain system functionality for a minimum operational timeframe, ensuring a fail-operational capability. The selection of an appropriate system architecture is crucial for managing the complexity of autonomous driving systems while achieving effective and efficient fault tolerance. This paper presents a preliminary quantitative comparison of different system architectures—symmetric and asymmet-ric—for a reference use case of an SAE Level 4 Highway Pilot. Specifically, we evaluate a Triple Modular Redundancy symmetric architecture, a Channel-Wise Doer/Checker/Fallback asymmetric architecture, and a Layer-Wise Doer/Checker/-Fallback asymmetric architecture. The comparison leverages Stochastic Activity Networks (SAN) modeled in the Mobius tool to assess key dependability metrics, particularly safety and reliability. Our preliminary results provide initial insights into the differences between symmetry and asymmetry in faulttolerant designs, highlighting their potential impact on safetycritical autonomous driving systems. This work contributes to a deeper understanding of architectural trade-offs in the design of dependable autonomous systems and provides guidance to system designers in making informed architectural decisions while strengthening safety argumentation. Manuel Drago, Andrea Bondavalli, Paolo Lollini, Georg Niedrist, Moritz Antlanger |
QRS | 3 |
| 2025 | Analyzing the 2015 Ukraine Power Grid Cyber-Attack: A Quantitative Assessment of Adversary Behavior and Impact*abstractThe security of critical infrastructures, such as power grids, water treatment facilities, transportation networks, financial systems, and communication networks, is essential for social stability. These systems deliver vital services, but are increasingly reliant on digital control mechanisms, making them vulnerable to cyber threats. A successful cyber-attack on any of these infrastructures could lead to widespread disruptions, significant financial losses, and in severe cases, risks to public safety. An effective cyber-security risk assessment process requires structured methodologies that identify vulnerabilities and anticipate adversarial behavior.Traditional risk assessment approaches rely on static and qualitative analyses that focus on known vulnerabilities and configurations, but lack dynamic attack simulation. In contrast, formal modeling and simulation-based techniques provide a quantitative framework to analyze possible attack paths and their likelihood of success. Among these formal methods, the ADVISE (ADversary VIew Security Evaluation) formalism offers a structured approach to assess cyber threats from the perspective of an adversary.This paper explores the application of the formal security evaluation framework, ADVISE, to model and analyze the 2015 Ukraine Power Grid cyber-attack. It specifically highlights the impact and the importance of the execution timing of the attacks, the adversary capabilities, and the effects of countermeasures throughout the progression of cyber-attacks. This framework simulates attack dynamics and quantifies the security risks associated with the Ukrainian Power Grid, thereby complementing the qualitative analyses conducted in previous studies. Marzieh Kordi, Syed Muhammad Fasih Ali, Paolo Lollini, Andrea Bondavalli |
SMC | 3 |
| 2023 | Modeling of GPGPU architectures for performance analysis of CUDA programsabstractGraphics Processing Units (GPUs), originally developed for computer graphics, are now commonly used to accelerate parallel applications. Given that GPUs are designed to be as efficient as possible, evaluating their performance is crucial. This problem has been tackled in the last years by researchers that started to propose solutions such as analytical models and digital simulators, which are, however, often complex to use and/or to adapt to the needs of the user. Thanks to its high flexibility, model-based analysis is widely used to evaluate systems’ properties, including performance. Researchers started working on developing GPU models that can represent both their architecture and the software in execution, but they often use strong assumptions that undermine their usability. In this work we develop a Stochastic Activity Network model to evaluate the performance of CUDA applications running on NVIDIA GPUs. The model takes as input a representation of the program’s instruction, parsed from the CUDA SASS assembly file, and a list of parameters to offer configurability to the user. We tune our model to match the architecture of two different NVIDIA GPUs and simulate the execution of a CUDA program. We then compare the results with those obtained from the execution of the program over the real GPUs. Francesco Terrosi, Francesco Mariotti, Paolo Lollini, Andrea Bondavalli |
QRS | 3 |
| 2022 | A cyber-physical-social approach for engineering Functional Safety Requirements for automotive systems
Mohamad Gharib, Andrea Ceccarelli, Paolo Lollini, Andrea Bondavalli |
J. Syst. Softw. | 3 |
| 2022 | Stochastic Activity Networks Templates: Supporting Variability in Performability ModelsabstractModel-based evaluation is extensively used to estimate the performance and reliability of dependable systems. Traditionally, these systems were small and self-contained, and the main challenge for model-based evaluation has been the efficiency of the solution process. Recently, the problem of specifying and maintaining complex models has increasingly gained attention, as modern systems are characterized by many components and complex interactions. Components share similarities, but at the same time, also exhibit variations in their behavior due to different configurations or roles in the system. From the modeling perspective, variations lead to replicating and altering a small set of base models multiple times. Variability is taken into account only informally, by defining a sample model and explaining its possible variations. In this article, we address the problem of including variability in performability models, focusing on stochastic activity networks (SANs). We introduce the formal definition of stochastic activity networks templates (SAN-T), a formalism based on SANs with the addition of variability aspects. Differently from other approaches, parameters can also affect the structure of the model, like the number of cases of activities. We apply the SAN-T formalism to the modeling of the backbone network of an environmental monitoring infrastructure. In particular, we show how existing SAN models from the literature can be generalized using the newly introduced formalism. Leonardo Montecchi, Paolo Lollini, Andrea Bondavalli |
IEEE Trans. Reliab. | 2 |
| 2020 | A Template-Based Methodology for the Specification and Automated Composition of Performability ModelsabstractDependability and performance analysis of modern systems is facing great challenges: their scale is growing, they are becoming massively distributed, interconnected, and evolving. Such complexity makes model-based assessment a difficult and time-consuming task. For the evaluation of large systems, reusable submodels are typically adopted as an effective way to address the complexity and to improve the maintainability of models. When using state-based models, a common approach is to define libraries of generic submodels, and then compose concrete instances by state sharing, following predefined “patterns” that depend on the class of systems being modeled. However, such composition patterns are rarely formalized, or not even documented at all. In this paper, we address this problem using a model-driven approach, which combines a language to specify reusable submodels and composition patterns, and an automated composition algorithm. Clearly defining libraries of reusable submodels, together with patterns for their composition, allows complex models to be automatically assembled, based on a high-level description of the scenario to be evaluated. This paper provides a solution to this problem focusing on: formally defining the concept of model templates, defining a specification language for model templates, defining an automated instantiation and composition algorithm, and applying the approach to a case study of a large-scale distributed system. Leonardo Montecchi, Paolo Lollini, Andrea Bondavalli |
IEEE Trans. Reliab. | 2 |
| 2018 | Systems-of-systems modeling using a comprehensive viewpoint-based SysML profileabstractAbstract In recent years, more and more efforts have been devoted in supporting the design of systems‐of‐systems (SoS). Designing such systems is a multidisciplinary problem which involves considering emergent phenomena, assuring the achievement of dependability/security requirements, guaranteeing system responsiveness, and supporting dynamicity/evolution and multicriticality of provided services. A first step towards a viable design approach is to provide a conceptual model of SoS which captures SoS concepts, and their interrelationships aiming at enhancing the understandability of SoS to stakeholders and providing the basis for further automated analysis. In this context, the AMADEOS European project is bringing together researchers and practitioners to provide the support to design SoS starting from the definition of a domain specific ontology serving as a vocabulary for SoS. Our contribution consists in the modeling of the key SoS concepts and relationships defined in AMADEOS adopting a systems modeling language visual modeling language. We propose a systems modeling language profile for SoS, and we show its applicability in a Smart Grid scenario. We show how to use the profile in a model‐driven engineering process to support different types of analyses, and we discuss how to integrate the profile in a user‐friendly model‐driven engineering tool for SoS rapid modeling, validation, code‐generation, and simulation. Marco Mori, Andrea Ceccarelli, Paolo Lollini, Bernhard Frömel, Francesco Brancati, Andrea Bondavalli |
J. Softw. Evol. Process. | 3 |
| 2018 | Labelling relevant events to support the crisis management operatorabstractAbstract Thanks to the large availability of portable devices and the growing interest in the Internet of Things, during crises, social networks, or alerts sent through mobile devices or sensor networks are available and can be matched each other to perform situational analysis. However, the inclusion of multiple heterogeneous sources in situational analyses leads to 2 main issues: (1) a source could deliver (voluntarily or erroneously) wrong data damaging the integrity and the correctness of the analysis, and (2) a significant amount of heterogeneous data need to be processed. As a consequence, the crisis management operator faces a large amount of potentially unreliable data. In this paper, we present a relevance labelling strategy to process information gathered from heterogeneous data streams to select the most relevant events. These are presented to the crisis management operator with the highest priority. Our strategy is evaluated using events collected by the Secure! crisis management system, considering 3 real crisis scenarios happened in Italy in 2015. Results show that our strategy is able to correctly identify sets of relevant events, supporting the activities of the crisis management operator. Tommaso Zoppi, Andrea Ceccarelli, Francesco Lo Piccolo, Paolo Lollini, Gabriele Giunta, Vito Morreale, Andrea Bondavalli |
J. Softw. Evol. Process. | 4 |
| 2017 | Dealing with Functional Safety Requirements for Automotive Systems: A Cyber-Physical-Social Approach
Mohamad Gharib, Paolo Lollini, Andrea Ceccarelli, Andrea Bondavalli |
CRITIS | 2 |
| 2017 | Identification of critical situations via Event Processing and Event Trust Analysis
Massimiliano Leone Itria, Melinda Kocsis-Magyar, Andrea Ceccarelli, Paolo Lollini, Gabriele Giunta, Andrea Bondavalli |
Knowl. Inf. Syst. | 4 |
| 2016 | A Model-Based Approach to Support Safety-Related Decisions in the Petroleum DomainabstractAccidents on petroleum installations can have huge consequences, to mitigate the risk, a number of safety barriers are devised. Faults and unexpected events may cause barriers to temporarily deviate from their nominal state. For safety reasons, a work permit process is in place: decision makers accept or reject work permits based on the current state of barriers. However, this is difficult to estimate, as it depends on a multitude of physical, technical and human factors. Information obtained from different sources needs to be aggregated by humans, typically within a limited amount of time. In this paper we propose an approach to provide an automated decision support to the work permit system, which consists in the evaluation of quantitative measures of the risk associated with the execution of work. The approach relies on state-based stochastic models, which can be automatically composed based on the work permit to be examined. Leonardo Montecchi, Atle Refsdal, Paolo Lollini, Andrea Bondavalli |
DSN | 3 |
| 2016 | On the Dependability for Dynamic Software Product Lines: A Comparative Systematic Mapping StudyabstractSoftware Product Lines (SPLs) are techniques where several artefacts are reused (domain), and some are customised (variation points). An SPL can bind variation points statically (compilation time) or dynamically (runtime). Dynamic Software Product Lines (DSPLs) use dynamic binding to adapt to the environment or requirements changes. DSPLs are commonly used to build dependable systems, defined as systems with the ability to avoid more frequent or severe service failures than the acceptable. The main dependability attributes are availability, confidentiality, integrity, reliability, maintainability, and safety. To better understand this context, a Systematic Mapping Study (SMS) was applied searching proposals that include dependability attributes in DSPLs. Our results suggest that few solutions handle dependability in DSPL context. We selected nine primary studies in this regard. We performed a comparative study of the results, analysing other dimensions, and facets, aiming for a better understanding of this research area. Jane Dirce A. Sandim Eleuterio, Felipe Nunes Gaia, Andrea Bondavalli, Paolo Lollini, Genaína Nunes Rodrigues, Cecília M. F. Rubira |
SEAA | 4 |
| 2015 | Continuous and Transparent User Identity Verification for Secure Internet ServicesabstractSession management in distributed Internet services is traditionally based on username and password, explicit logouts and mechanisms of user session expiration using classic timeouts. Emerging biometric solutions allow substituting username and password with biometric data during session establishment, but in such an approach still a single verification is deemed sufficient, and the identity of a user is considered immutable during the entire session. Additionally, the length of the session timeout may impact on the usability of the service and consequent client satisfaction. This paper explores promising alternatives offered by applying biometrics in the management of sessions. A secure protocol is defined for perpetual authentication through continuous user verification. The protocol determines adaptive timeouts based on the quality, frequency and type of biometric data transparently acquired from the user. The functional behavior of the protocol is illustrated through Matlab simulations, while model-based quantitative analysis is carried out to assess the ability of the protocol to contrast security attacks exercised by different kinds of attackers. Finally, the current prototype for PCs and Android smartphones is discussed. Andrea Ceccarelli, Leonardo Montecchi, Francesco Brancati, Paolo Lollini, Angelo Marguglio, Andrea Bondavalli |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2013 | Meeting the challenges in the design and evaluation of a trackside real-time safety-critical systemabstractHighly distributed, autonomous and self-powered systems operating in harsh, outdoors environments face several threats in terms of dependability, timeliness and security, due to the challenging operating conditions determined by the environment. Despite such difficulties, there is an increasing demand to deploy these systems to support critical services, thus calling for severe timeliness, safety, and security requirements. Several challenges need to be faced and overcome. First, the designed architecture must be able to cope with the environmental challenges and satisfy dependability, timeliness and security requirements. Second, the assessment of the system must be carried on despite potentially incomplete field-data, and complex cascading effects that small modifications in system properties and operating conditions may have on the targeted metrics. In this paper we present our experience from the EU-funded project ALARP (A railway automatic track warning system based on distributed personal mobile terminals), which aims to build and validate a distributed, real-time, safety-critical system that detects trains approaching a railway worksite and notifies their arrivals to railway trackside workers. The paper describes the challenges we faced, and the solutions we adopted, when architecting and evaluating the ALARP system. Leonardo Montecchi, Andrea Ceccarelli, Paolo Lollini, Andrea Bondavalli |
ISORC | 3 |
| 2012 | Model-based analysis of a protocol for reliable communication in railway worksitesabstractIn this paper we perform a model-based analysis of the Timed Reliable Communication (TRC) protocol, which is being used within the EU funded ALARP project for railway worksite com-munication. TRC is a group communication protocol based on IEEE 802.11 networks, targeting safety-critical applications with limited bandwidth requirements. The paper contains an in-depth analysis of the performance and reliability characteristics of the protocol using a Stochastic Activity Networks model. The results are first compared with available experimental measurements for the sake of model validation. The validated model is then used for a thorough analysis of a set of key metrics under different envi-ronment and network conditions. The obtained results allow: i) to assess that the protocol allows to satisfy the ALARP targeted performance and reliability requirements, and ii) to evaluate the existing tradeoffs and help in choosing parameter values for the final implementation. Leonardo Montecchi, Paolo Lollini, Boris Malinowsky, Jesper Grønbæk, Andrea Bondavalli |
MSWiM | 2 |
| 2012 | Adaptare: Supporting automatic and dependable adaptation in dynamic environmentsabstractDistributed protocols executing in uncertain environments, like the Internet or ambient computing systems, should dynamically adapt to environment changes in order to preserve Quality of Service (QoS). In earlier work, it was shown that QoS adaptation should be dependable, if correctness of protocol properties is to be maintained. More recently, some ideas concerning specific strategies and methodologies for improving QoS adaptation have been proposed. In this article we describe Adaptare , a complete framework for dependable QoS adaptation. We assume that during its lifetime, a system alternates periods where its temporal behavior is well characterized, with transition periods during which a variation of the environment conditions occurs. Our method is based on the following: if the environment is generically characterized in analytical terms, and we can detect the alternation of these stable and transient phases, we can improve the effectiveness and dependability of QoS adaptation. To prove our point we provide detailed evaluation results of the proposed solutions. Our evaluation is based on synthetic data flows generated from probabilistic distributions, as well as on real data traces collected in various Internet-based environments. We compare our solution with other approaches and we show that Adaptare, albeit more complex, is very effective, allowing protocols to adapt to the available resources in a dependable way. Monica Dixit, António Casimiro, Paolo Lollini, Andrea Bondavalli, Paulo Veríssimo |
ACM Trans. Auton. Adapt. Syst. | 3 |
| 2011 | Towards a MDE Transformation Workflow for Dependability AnalysisabstractIn the last ten years, Model Driven Engineering (MDE) approaches have been extensively used for the analysis of extra-functional properties of complex systems, like safety, dependability, security, predictability, quality of service. To this purpose, engineering languages (like UML and AADL) have been extended with additional features to model the required non-functional attributes, and transformations have been used to automatically generate the analysis models to be solved by appropriate analysis tools. In most of the available works, however, the transformations are not inte grated into a more general development process, aimed to support both domain-specific design analysis and verification of extra-functional properties. In this paper we explore this research direction presenting a transformation work flow for dependability analysis that is part of an industrial-quality infrastructure for the specification, analysis and verification of extra-functional properties, currently under development within the ARTEMIS-JU CHESS project. Specifically, the paper provides the following major contributions: i) definition of the required transformation steps to automatically assess the system dependability properties starting from the CHESS Modeling Language, ii) definition of a new Intermediate Dependability Model (IDM) acting as a bridge between the CHESS Modeling Language and the low-level analysis models, iii) definition of transformations from the CHESS Modeling Language to IDM models. Leonardo Montecchi, Paolo Lollini, Andrea Bondavalli |
ICECCS | 2 |
| 2011 | The HIDENETS Holistic Approach for the Analysis of Large Critical Mobile SystemsabstractDealing with large, critical mobile systems and infrastructures where ongoing changes and resilience are paramount leads to very complex and difficult challenges for system evaluation. These challenges call for approaches that are able to integrate several evaluation methods for the quantitative assessment of QoS indicators which have been applied so far only to a limited extent. In this paper, we propose the holistic evaluation framework developed during the recently concluded FP6-HIDENETS project. It is based on abstraction and decomposition, and it exploits the interactions among different evaluation techniques including analytical, simulative, and experimental measurement approaches, to manage system complexity. The feasibility of the holistic approach for the analysis of a complete end-to-end scenario is first illustrated presenting two examples where mobility simulation is used in combination with stochastic analytical modeling, and then through the development and implementation of an evaluation workflow integrating several tools and model transformation steps. Andrea Bondavalli, Ossama Hamouda, Mohamed Kaâniche, Paolo Lollini, István Majzik, Hans-Peter Schwefel |
IEEE Trans. Mob. Comput. | 4 |
| 2009 | A Decomposition-Based Modeling Framework for Complex SystemsabstractStochastic model-based approaches are widely used for performability evaluation of complex software/hardware systems. Many techniques have been developed to mitigate the complexity of the associated models, but most of them are domain-specific, and they support the analysis of a limited class of systems. This paper provides a contribution in the definition of a general modeling framework that adopts three different types of decomposition techniques to deal with model complexity. Paolo Lollini, Andrea Bondavalli, Felicita Di Giandomenico |
IEEE Trans. Reliab. | 1 |
| 2008 | Interdependency Analysis in Electric Power Systems
Silvano Chiaradonna, Felicita Di Giandomenico, Paolo Lollini |
CRITIS | 3 |
| 2007 | On a Modeling Framework for the Analysis of Interdependencies in Electric Power SystemsabstractNowadays, economy, security and quality of life heavily depend on the resiliency of a number of critical infrastructures, including the electric power system (EPS), through which vital services are provided. In existing EPS two cooperating infrastructures are involved: the electric infrastructure (EI) for the electricity generation and transportation to final users, and its information-technology based control system (ITCS) devoted to controlling and regulating the EI physical parameters and triggering reconfigurations in emergency situations. This paper proposes a modeling framework to capture EI and ITCS aspects, focusing on their interdependencies that contributed to the occurrence of several cascading failures in the past 40 years. A quite detailed analysis of the EI and ITCS structure and behavior is performed; in particular, the ITCS and EI behaviors are described by discrete and hybrid-state processes, respectively. To substantiate the approach, the implementation of a few basic modeling mechanisms inside an existing multiformalism/ multi-solution tool is also discussed. Silvano Chiaradonna, Paolo Lollini, Felicita Di Giandomenico |
DSN | 2 |
| 2004 | Congestion analysis during outage, congestion treatment and outage recovery for simple GPRS networksabstractThis paper deals with congestion analysis of a simple GPRS network composed by two cells partially overlapping. In particular, we consider that one of the two cells is affected by an outage and we analyze the effectiveness of applying a class of congestion treatment techniques that ultimately results in a switching of users from the congested cell to the other one. For this purpose, we introduce a modelling technique to support a proper calibration of the parameters involved in a reconfiguration action, in order to successfully treat the congestion phenomenon. The effectiveness of a reconfiguration action is evaluated in terms of indicators that represent the quality of service (QoS) perceived by the users in the congested and adjacent cells. Paolo Lollini, Andrea Bondavalli, Felicita Di Giandomenico, Stefano Porcarelli |
ISCC | 1 |