Joel Greenyer

dblp:46/1332 · DBLP profile ↗
← Back
25ranked-venue papers
12as first author
6since 2021 · last 2025
0000-0003-0347-0158ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 23 · 12 first-author · 4 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2025 Streamlined Integration of GR(1) Synthesis and Reinforcement Learning for Optimizing Critical Cyber-Physical Systems
Eric Wete, Joel Greenyer, Tom Yaacov, Daniel Kudenko, Wolfgang Nejdl
MODELS2
2023 MDE and Learning for flexible Planning and optimized Execution of Multi-Robot Choreographies
abstract
Multi-Robot systems in automotive are safety-critical systems that consist of collaborating-aware robots and components that interact with external components, the environment, or humans at run-time. This implies a significant complexity for the system engineer to design, model, validate the system, and optimize the cycle time, including considering unexpected events at run-time. This paper addresses this challenge by describing a model-driven engineering approach that formally designs the system under the consideration of uncertainties and at run-time optimizes the system actions using learning-based approaches. We implemented this approach in an industrial-inspired case study of a spot-welding multi-robot cell. Based on the system requirements, we generate valid system strategies that consider unexpected events such as robot interruptions and failures. Considering movement and interruption time models, we implemented a reinforcement learning method to optimize system actions at run-time. We show that via simulations and learning, our approach can be used to synthesize time-efficient schedules for robot task assignments that improve the overall cycle time.
Eric Wete, Joel Greenyer, Andreas Wortmann 0001, Daniel Kudenko, Wolfgang Nejdl
ETFA2
2022 Thirty-One Challenges in Testing Automated Vehicles: Interviews with Experts from Industry and Research
abstract
There is consensus across the automotive industry that Automated Driving Systems and automated vehicles challenge the way how quality assurance and, particularly, testing must be performed. However, there is a lack of up-to-date empirical studies that substantiate this concern. We conducted interviews with several experts from industry and research to systematically identify challenges as well as improvement opportunities in methods and tools. We report in this paper on 31 challenges that we identified in the areas of scenario- and simulation-based testing, test automation, and test execution. One recurrent challenge expressed by many experts is the problem how to translate a desired condition to be tested into an executable scenario model. This is not alone a question of scripting the scenario, but also of considering a vehicle under test that might try to evade the desired test condition.
Felix Beringhoff, Joel Greenyer, Christian Roesener, Matthias Tichy
IV2
2021 Monte Carlo Tree Search and GR(1) Synthesis for Robot Tasks Planning in Automotive Production Lines
abstract
In automotive production cells, complex processes involving multiple robots must be optimized for cycle time. We investigated using symbolic GR(1) controller synthesis for automating multi-robot task planning. Given a specification of the order of tasks and states to avoid, often multiple valid strategies can be computed; in many states there are multiple choices to satisfy the specification, such as choosing different robots to perform a certain task. To determine the best choices under the consideration of movement times and probabilities that robots may be interrupted for repairs or corrections, we combine the execution of the synthesized controller with Monte Carlo Tree Search (MCTS), a heuristic AI-planning technique. The result is a model-at-run-time approach that we present by the example of a multi-robot spot welding cell. We report on experiments showing that the approach (1) can reduce cycle times by choosing time-efficient movement sequences and (2) can choose executions that react efficiently to interruptions by choosing to delay tasks that, if an interruption of one robot should occur later, can be reallocated to another robot. Most interestingly, we found, however, that (3) in some cases there is a conflict between time-efficient movement sequences and ones that may react efficiently to probable future interruptions—and when interruption probabilities are low, increasing the time allocated for MCTS, i.e., increasing the number of sample simulations made by MCTS, does not improve cycle time.
Eric Wete, Joel Greenyer, Andreas Wortmann 0001, Oliver Flegel, Martin Klein 0009
MoDELS2
2021 Integrated and Iterative Requirements Analysis and Test Specification: A Case Study at Kostal
abstract
Currently, practitioners follow a top-down approach in automotive development projects. However, recent studies have shown that this top-down approach is not suitable for the implementation and testing of modern automotive systems. Specifically, practitioners increasingly fail to specify requirements and tests for systems with complex component interactions (e.g., e-mobility systems). In this paper, we address this research gap and propose an integrated and iterative scenario-based technique for the specification of requirements and test scenarios. Our idea is to combine both a top-down and a bottom-up integration strategy. For the top-down approach, we use a behavior-driven development (BDD) technique to drive the modeling of high-level system interactions from the user's perspective. For the bottom-up approach, we discovered that natural language processing (NLP) techniques are suited to make textual specifications of existing components accessible to our technique. To integrate both directions, we support the joint execution and automated analysis of system-level interactions and component-level behavior. We demonstrate the feasibility of our approach by conducting a case study at Kostal (Tierl supplier). The case study corroborates, among other things, that our approach supports practitioners in improving requirements and test specifications for integrated system behavior.
Carsten Wiecher, Jannik Fischbach, Joel Greenyer, Andreas Vogelsang, Carsten Wolff, Roman Dumitrescu
MoDELS3
2021 Iterative and Scenario-Based Requirements Specification in a System of Systems Context
Carsten Wiecher, Joel Greenyer, Carsten Wolff, Harald Anacker, Roman Dumitrescu
REFSQ2
2018 Towards Systematic and Automatic Handling of Execution Traces Associated with Scenario-based Models
Joel Greenyer, Daniel Gritzner, David Harel, Assaf Marron
MODELSWARD1
2017 Symbolic Execution for Realizability-Checking of Scenario-Based Specifications
abstract
Scenario-based specification with the Scenario Modeling Language (SML) is an intuitive approach for formally specifying the behavior of reactive systems. SML is close to how humans conceive and communicate requirements, yet SML is executable and simulation and formal realizability checking can find specification flaws early. The realizability checking complexity is, however, exponential in the number of scenarios and variables. Therefore algorithms relying on explicit-state exploration do not scale and, especially when specifications have message parameters and variables over large domains, fail to unfold their potential. In this paper, we present a technique for the symbolic execution of SML specifications that interprets integer message parameters and variables symbolically. It can be used for symbolic realizability checking and interactive symbolic simulation. We implemented the technique in ScenarioTools. Evaluation shows drastic performance improvements over the explicit-state approachfor a range of examples. Moreover, symbolic checking produces more concise counter examples, which eases the comprehension of specification flaws.
Joel Greenyer, Timo Gutjahr
MoDELS1
2017 Distributing Scenario-based Models: A Replicate-and-Project Approach
Shlomi Steinberg, Joel Greenyer, Daniel Gritzner, David Harel, Guy Katz, Assaf Marron
MODELSWARD2
2017 From scenario modeling to scenario programming for reactive systems with dynamic topology
abstract
Software-intensive systems often consist of cooperating reactive components. In mobile and reconfigurable systems, their topology changes at run-time, which influences how the components must cooperate. The Scenario Modeling Language (SML) offers a formal approach for specifying the reactive behavior such systems that aligns with how humans conceive and communicate behavioral requirements. Simulation and formal checks can find specification flaws early. We present a framework for the Scenario-based Programming (SBP) that reflects the concepts of SML in Java and makes the scenario modeling approach available for programming. SBP code can also be generated from SML and extended with platform-specific code, thus streamlining the transition from design to implementation. As an example serves a car-to-x communication system. Demo video and artifact: http://scenariotools.org/esecfse-2017-tool-demo/
Joel Greenyer, Daniel Gritzner, Florian König, Jannik Dahlke, Jianwei Shi 0001, Eric Wete
ESEC/SIGSOFT FSE1
2017 ScenarioTools - A tool suite for the scenario-based modeling and analysis of reactive systems
Joel Greenyer, Daniel Gritzner, Timo Gutjahr, Florian König, Nils Glade, Assaf Marron, Guy Katz
Sci. Comput. Program.1
2015 On-the-Fly Synthesis of Scarcely Synchronizing Distributed Controllers from Scenario-Based Specifications
Christian Brenner 0001, Joel Greenyer, Wilhelm Schäfer
FASE2
2015 Towards Executing Dynamically Updating Finite-State Controllers on a Robot System
abstract
Modern software systems are increasingly required to run for a long time and deliver uninterrupted service. Their requirements or their environments, however, may change. Therefore, these systems must be updated dynamically, at run-time. Typical examples can be found in manufacturing, transportation, or space applications, where stopping the system to deploy updates can be difficult, costly, or simply not possible. In previous work we proposed a model-driven approach that uses automatically synthesized finite-state controllers from scenario-based assume/guarantee specifications to safely and efficiently dynamically update the system. In this paper we describe an execution infrastructure of this approach, which allows us to execute and deploy newly synthesized dynamically updating controllers on embedded devices. We present a prototype implementation in Java for Lego Mind storms robots. This experience gained can lead to a systematic approach to implement dynamic updates in the aforementioned critical software-intensive systems.
Valerio Panzica La Manna, Joel Greenyer, Donato Clun, Carlo Ghezzi
MiSE@ICSE2
2015 Towards Application and Evolution of Model-Based Heuristics for Improving SOA Service Design
abstract
Good service design is key to acceptance and success for a service-oriented architecture (SOA) in an enterprise. Enterprises try to achieve good service design by using guidelines which combine experts' experience, company policies and best practices. Applying, evolving and maintaining guidelines overburdens service designers and reviewers due to the amount and volume. This results in inefficient, costly and frustrating processes. Without an automated support, guidelines provide only limited value to the design process. We describe how our design environment prototype addresses these problems and introduce automatic guideline checks using heuristics on service models. Our evaluation confirms applicability and advantages of our tool. We present a selection of heuristics which are used in our tool. As the second contribution we describe our plan of how to support evolution and maintenance of guidelines and heuristics.
Kai Niklas, Joel Greenyer, Kurt Schneider
MiSE@ICSE2
2015 Synthesizing tests for combinatorial coverage of modal scenario specifications
abstract
Software-intensive systems often consist of many components that interact to fulfill complex functionality. Testing these systems is vital, preferably by a minimal set of tests that covers all relevant cases. The behavior is typically specified by scenarios that describe what the system may, must, or must not do. When designing tests, as in the design of the system itself, the challenge is to consider interactions of scenarios. When doing this manually, critical interactions are easily overlooked. Inspired by Combinatorial Test Design, which exploits that bugs are typically found by regarding the interaction of a small set of parameters, we propose a new test coverage criterion based on scenario interactions. Furthermore, we present a novel technique for automatically synthesizing from Modal Sequence Diagram specifications a minimal set of tests that ensures a maximal coverage of possible t-wise scenario interactions. The technique is evaluated on an example specification from an industrial project.
Valerio Panzica La Manna, Itai Segall, Joel Greenyer
MoDELS3
2015 Evaluating a formal scenario-based method for the requirements analysis in automotive software engineering
abstract
Automotive software systems often consist of multiple reactive components that must satisfy complex and safety-critical requirements. In automotive projects, the requirements are usually documented informally and are reviewed manually; this regularly causes inconsistencies to remain hidden until the integration phase, where their repair requires costly iterations. We therefore seek methods for the early automated requirement analysis and evaluated the scenario-based specification approach based on LSCs/MSDs; it promises to support an incremental and precise specification of requirements, and offers automated analysis through scenario execution and formal realizability checking. In a case study, we used ScenarioTools to model and analyze the requirements of a software to control a high-voltage coupling for electric vehicles. Our example contained 36 requirements and assumptions that we could successfully formalize, and we could successfully find specification defects by automated realizability checking. In this paper, we report on lessons learned, tool and method extensions we have introduced, and open challenges.
Joel Greenyer, Max Haase, Jörg Marhenke, Rene Bellmer
ESEC/SIGSOFT FSE1
2015 All-at-once-synthesis of controllers from scenario-based product line specifications
abstract
Software-intensive systems often consist of multiple components that interact to realize complex requirements. An additional dimension of complexity arises when one designs many variants of a system at once, that is, a software product line (SPL). We propose a scenario-based approach to design SPLs, based on a combination of Modal Sequence Diagrams (MSDs) and a feature model. It consists in associating every MSD to the set of variants that have to satisfy its specification. Variability constitutes a new source of complexity, which can lead to inconsistencies in the specification of one or multiple variants. It is therefore crucial to detect these inconsistencies, and to produce a controller for each variant that makes it behave so that it satisfies its specification. We present a new controller synthesis technique that checks the absence of inconsistencies in all variants at once, thereby more radically exploiting the similarities between them. Our method first translates the MSD specification into a variability-aware Büchi game, and then solves this game for all variants in a single execution. We implemented the approach in ScenarioTools, a software tool which we use to evaluate our algorithms against competing methods.
Maxime Cordy, Jean-Marc Davril, Joel Greenyer, Erika Gressi, Patrick Heymans
SPLC3
2013 Compositional Synthesis of Controllers from Scenario-Based Assume-Guarantee Specifications
Joel Greenyer, Ekkart Kindler
MoDELS1
2013 Incrementally synthesizing controllers from scenario-based product line specifications
abstract
Many software-intensive systems consist of components that interact to fulfill complex functionality. Moreover, often many variants of such systems have to be designed at once. This adds complexity to the design task. Recently, we proposed a scenario-based approach to design product lines, which combines feature diagrams and Modal Sequence Diagrams. We proposed a consistency-checking technique based on a dedicated product line model checker. One limitation of this technique is that it is incomplete, i.e., it may fail to show the consistency of some consistent specifications. In this paper we propose a new game-based approach that overcomes this incompleteness and, in addition, automatically synthesizes controllers for the consistent product specifications. We exploit the fact that many variants are similar and efficiently synthesize product controllers incrementally. We provide a prototype tool and evaluate the efficiency of the approach.
Joel Greenyer, Christian Brenner 0001, Maxime Cordy, Patrick Heymans, Erika Gressi
ESEC/SIGSOFT FSE1
2013 Features meet scenarios: modeling and consistency-checking scenario-based product line specifications
Joel Greenyer, Amir Molzam Sharifloo, Maxime Cordy, Patrick Heymans
Requir. Eng.1
2012 Efficient consistency checking of scenario-based product-line specifications
abstract
Modern technical systems typically consist of multiple components and must provide many functions that are realized by the complex interaction of these components. Moreover, very often not only a single product, but a whole product line with different compositions of components and functions must be developed. To cope with this complexity, it is important that engineers have intuitive, but precise means for specifying the requirements for these systems and have tools for automatically finding inconsistencies within the requirements, because these could lead to costly iterations in the later development. We propose a technique for the scenario-based specification of component interactions based on Modal Sequence Diagrams. Moreover, we developed an efficient technique for automatically finding inconsistencies in the scenario-based specification of many variants at once by exploiting recent advances in the model-checking of product lines. Our evaluation shows benefits of this technique over performing individual consistency checking of each variant specification.
Joel Greenyer, Amir Molzam Sharifloo, Maxime Cordy, Patrick Heymans
RE1
2011 Preventing Information Loss in Incremental Model Synchronization by Reusing Elements
Joel Greenyer, Sebastian Pook, Jan Rieke
ECMFA1
2010 Comparing relational model transformation technologies: implementing Query/View/Transformation with Triple Graph Grammars
Joel Greenyer, Ekkart Kindler
Softw. Syst. Model.1
2009 Synthesis of timed behavior from scenarios in the Fujaba Real-Time Tool Suite
abstract
Based on a well-defined component architecture the tool supports the synthesis of so-called real-time statecharts from timed sequence diagrams. The two step synthesis process addresses the existing scalability problems by a proper decomposition and allows the user to define particular restrictions on the resulting statecharts.
Stefan Henkler, Joel Greenyer, Martin Hirsch 0001, Wilhelm Schäfer, Kahtan Alhawash, Tobias Eckardt, Christian Heinzemann, Renate Löffler, Andreas Seibel, Holger Giese
ICSE2
2007 Reconciling TGGs with QVT
Joel Greenyer, Ekkart Kindler
MoDELS1