VLDB 2026 Research / reviewers in the wild / expert
Xabier Larrucea
dblp:46/395
· DBLP profile ↗
28ranked-venue papers
20as first author
6since 2021 · last 2025
0000-0002-6402-922XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 26 · 19 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Towards the Analysis of Software Supply Chain and EU Regulations
Xabier Larrucea, Izaskun Santamaría |
EuroSPI (2) | 1 |
| 2024 | Trustworthy and collaborative traceability management: Experts' feedback on a blockchain-enabled frameworkabstractAbstract Blockchain technology has attracted significant attention in both academia and industry. Recently, the application of blockchain has been advocated in software engineering. The global software engineering paradigm exacerbates trust issues, as distributed and cross‐organizational teams need to share software artifacts. In such a context, there is a need for a decentralized yet reliable traceability knowledge base to keep track of what/how/when/by whom software artifacts were created or changed. This study presents a blockchain‐enabled framework for trustworthy and collaborative traceability management and identifies benefits, challenges, and potential improvements based on the feedback of software engineering experts. A qualitative approach was followed in this study through semistructured interviews with software engineering (SE) experts. Transcripts were analyzed by applying the content analysis technique. The results indicated the emergence of five categories, further grouped into three main categories: experts' perceptions, blockchain‐based software process improvement, and experts' recommendations. In addition, the findings suggested four archetypes of organizations that may be interested in blockchain technology: distributed organizations, organizations with contract‐based projects, organizations in regulated domains, and regulators who may push the use of this technology. Further efforts should be devoted to the integration of the proposal with tools used throughout the software development lifecycle and leveraging the potential of smart contracts in validating the implementation of requirements automatically. Selina Demi, Mary-Luz Sánchez-Gordón, Monica Kristiansen, Xabier Larrucea |
J. Softw. Evol. Process. | 4 |
| 2023 | Integrating privacy debt and VSE's software developmentsabstractAbstract With the advent of regulations protecting users such as the General Data Protection Regulation, security and privacy concerns are playing a new role in small settings such as in very small entities. Their relevance is increasing, and privacy is being considered a Troy horse in software developments. In fact, privacy is a part of software architectural decisions, and they must be considered as a technical debt. The contributions of this paper are the following: a privacy debt definition with a principal and an interest, privacy‐related activities to be considered within the ISO/IEC 29110 basic profile, and the use of the net present value within this context. All these contributions help us to integrate privacy debt and VSE's software developments. Izaskun Santamaría, Xabier Larrucea, Borja Fernández-Gauna |
J. Softw. Evol. Process. | 2 |
| 2022 | Actor-critic continuous state reinforcement learning for wind-turbine control robust optimizationabstractThe control of Variable-Speed Wind-Turbines (VSWT) extracting electrical power from the wind kinetic energy are composed of subsystems that need to be controlled jointly, namely the blade pitch and the generator torque controllers. Previous state of the art approaches decompose the joint control problem into independent control subproblems, each with its own control subgoal, carrying out separately the design and tuning of a parameterized controller for each subproblem. Such approaches neglect interactions among subsystems which can introduce significant effects. This paper applies Actor-Critic Reinforcement Learning (ACRL) for the joint control problem as a whole, carrying out the simultaneous control parameter optimization of both subsystems without neglecting their interactions, aiming for a globally optimal control of the whole system. The innovative control architecture uses an augmented input space so that the parameters can be fine-tuned for each working condition. Validation results conducted on simulation experiments using the state-of-the-art OpenFAST simulator show a significant efficiency improvement relative to the best state of the art controllers used as benchmarks, up to a 22% improvement in the average power error performance after ACRL training. Borja Fernández-Gauna, Manuel Graña, Juan-Luis Osa-Amilibia, Xabier Larrucea |
Inf. Sci. | 4 |
| 2021 | Dealing with Privacy for Protecting Information
Xabier Larrucea, Izaskun Santamaría |
EuroSPI | 1 |
| 2021 | Towards a privacy debtabstractAbstract This study argues the difference between security and privacy and outlines the concept of Privacy Debt as a new Technical Debt. Privacy is gaining momentum in any software system due to mandatory compliance with respect to laws and regulations. There are several types of technical debts within the umbrella of software engineering, and most of them arise during different phases of software development. Several research studies have been focussed on highlighting different types of technical debts. However, authors introduce Privacy Debt as a particular technical debt focussed on privacy management and linked to a perturbative method. Privacy must be considered not only as technical debt requirements but also at design and deployment phases, among others. In addition, this method is illustrated with a use case. Xabier Larrucea, Izaskun Santamaría, Manuel Graña |
IET Softw. | 1 |
| 2020 | An ICS Based Scenario Generator for Cyber Ranges
Xabier Larrucea, Alberto Molinuevo Martín |
EuroSPI | 1 |
| 2020 | Designing a Cyber Range Exercise for Educational Purposes
Xabier Larrucea, Izaskun Santamaría |
EuroSPI | 1 |
| 2020 | Analysing encryption mechanisms and functional safety in a ROS-based architectureabstractAbstract Robot Operating System (ROS) is a middleware for connecting different components of robots. However, its use is becoming more popular in other domains such as in the automotive sector where initial prototypes have been customized and deployed in cars for demonstrating different functional purposes. Nevertheless, ROS has not been yet tested enough to be used in secure and safety environments. For example, in order to strengthen our ROS architecture, we have encrypted the messages within it. Therefore, this paper analyses the impact of Advanced Encryption Standard (AES) encryption mechanism and the functional safety of our prototype. In this sense, we are considering encrypting messages and we assess the timing constraints, as suggested by the ISO 26262, required for assuring a secure communication between components. Xabier Larrucea, Pablo González-Nalda, Ismael Etxeberria, Mari Carmen Otero |
J. Softw. Evol. Process. | 1 |
| 2020 | Managing security debt across PLC phases in a VSE contextabstractAbstract Nowadays, security and safety aspects are two of the major concerns for any software system development, especially while developing safety critical systems. This is especially relevant for very small entities because they have a limited amount of resources for dealing with all these aspects at the same time. In addition, these systems are highly regulated domains, and they involve a huge set of standards focused on safety and security‐related issues. Therefore, these small entities are not only facing hurdles related to technical aspects but also from the so‐called technical debt when overarching a critical development. This paper extends the assurance cases approach by integrating security aspects within the life cycle, and it proposes a framework for managing the associated security technical debt for very small entities. A tool chain is outlined, and the approach is illustrated with an industrial use case. Xabier Larrucea, Izaskun Santamaría, Borja Fernández-Gauna |
J. Softw. Evol. Process. | 1 |
| 2019 | Dealing with Security in a Real DevOps Environment
Xabier Larrucea, Alberto Berreteaga, Izaskun Santamaría |
EuroSPI | 1 |
| 2019 | Gamification for software process improvement: a practical approachabstractGamification is a research field that is intended to increase motivation, so it is especially indicated in human capital intensive environments such as the software industry. Within Software Engineering, one of the main issues regarding software process improvement (SPI) is personnel motivation in specific SPI initiatives. These issues are stronger in small and medium software development companies where employees have to deal with the pressure of deadlines and occasional work overload. To address the adoption of SPI initiatives, the researchers implemented a defined gamification framework for deployment in SPI efforts in order to increase motivation among software workers and to enhance SPI results. The framework was rolled out in a small Spanish software development organisation, which is conducting internal SPI initiatives. To validate the effectiveness of the implemented framework, a controlled experiment was carried out in which an experimental group adopted SPI improvements using a gamification approach. The implementation results show that the application of the framework does not increase personnel motivation in SPI tasks although it contributes to enhancing the SPI tasks performance. This study discusses the limitations and recommendations to implement appropriately the SPI‐gamification framework in the scope of small and medium software development companies. Eduardo Herranz, Javier García Guzmán, Antonio de Amescua Seco, Xabier Larrucea |
IET Softw. | 4 |
| 2019 | Assessing source code vulnerabilities in a cloud-based system for health systems: OpenNCPabstractHealthcare systems have been improved in order to provide support to cross‐border situations where one citizen from one country travels to another country and requires the use of their health records. Several initiatives have been carried out to tackle this problem. This is the case for the OpenNCP which is supported by the European Commission by providing a common network and an infrastructure to connect different national healthcare systems which most of the times are cloud‐based systems. The OpenNCP plays a key role in communicating health records among European Union's member states, and therefore it manages sensitive information. Therefore, this study provides a security analysis of this platform and a prototype is developed for identifying secure patterns in source code. Xabier Larrucea, Izaskun Santamaría, Ricardo Colomo-Palacios |
IET Softw. | 1 |
| 2019 | Service level agreement-based GDPR compliance and security assurance in (multi)Cloud-based systemsabstractCompliance with the new European General Data Protection Regulation (Regulation (EU) 2016/679, GDPR) and security assurance are currently two major challenges of Cloud‐based systems. GDPR compliance implies both privacy and security mechanisms definition, enforcement and control, including evidence collection. This study presents a novel DevOps framework aimed at supporting Cloud consumers in designing, deploying and operating (multi)Cloud systems that include the necessary privacy and security controls for ensuring transparency to end‐users, third parties in service provision (if any) and law enforcement authorities. The framework relies on the risk‐driven specification at design time of privacy and security level objectives in the system service level agreement and in their continuous monitoring and enforcement at runtime. Erkuden Rios, Eider Iturbe, Xabier Larrucea, Massimiliano Rak, Wissam Mallouli, Jacek Dominiak, Victor Muntés-Mulero, Peter Matthews, Luis Gonzalez |
IET Softw. | 3 |
| 2019 | Correlations study and clustering from SPI experiences in small settingsabstractAbstract Software Process Improvement (SPI) initiatives have been applied in a wide set of organisations including very small entities (VSE). In fact, this kind of organisations is facing several hurdles when overarching a SPI initiative. In this context, the ISO/IEC 29110 has been used as a lightweight reference model for steering VSEs in their SPI initiatives. The inherent uncertainty behind the SPI curtains blocks the organisations in their investments. Due to these reasons, we need to identify relationships and similarities in order to predict whether a SPI will succeed or not. We propose the use of Self‐Organising Maps for identifying patterns from these SPI studies. The aim of this paper is to identify correlations among SPI studies and to discover patterns from them. Xabier Larrucea, Izaskun Santamaría |
J. Softw. Evol. Process. | 1 |
| 2018 | Approach for Enabling Security Across PLC Phases: An Industrial Use Case
Xabier Larrucea, Félix Nanclares, Izaskun Santamaría, Ricardo Ruiz Nolasco |
EuroSPI | 1 |
| 2017 | Towards a Survival Analysis of Very Small Organisations
Xabier Larrucea, Izaskun Santamaría |
EuroSPI | 1 |
| 2017 | Towards the Integration of Security Practices in the Software Implementation Process of ISO/IEC 29110: A Mapping
Mary-Luz Sánchez-Gordón, Ricardo Colomo-Palacios, Alex Sánchez Gordon, Antonio de Amescua Seco, Xabier Larrucea |
EuroSPI | 5 |
| 2017 | Comparing SPI Survival Studies in Small Settings
Xabier Larrucea, Izaskun Santamaría |
SPICE | 1 |
| 2016 | Modelling and Certifying Safety for Cyber-Physical Systems: An Educational ExperimentabstractModelling and certifying safety systems are not straightforward activities, and they usually require a specific training and experience. The emergence of ISO26262 as a standard for the automotive sector is foreseen as a basic knowledge in the automotive sector. A special attention is required to these safety critical systems and to its related standards. This paper provides a controlled experiment carried out in classroom for teaching and learning safety principles by using Opencert tool. Xabier Larrucea |
SEAA | 1 |
| 2016 | A GSN Approach to SEooC for an Automotive Hall Sensor
Xabier Larrucea, Silvana Mergen, Alastair Walker |
EuroSPI | 1 |
| 2016 | Assessing ISO/IEC29110 by means of ITMark: results from an experience factoryabstractAbstract ISO/IEC 29110 is intended to help very small entities in improving their software processes. However, this standard is not the only initiative devoted to help organizations in these matters. For instance, ITMark is an established method with an important background in terms of number and diversity of assessments. The aim of this paper is to present a method to assess ISO/IEC 29110 by means of the evaluation performed under the ITMark certification schema built upon an experience factory. To do so, in this paper, authors present, firstly, a mapping for ITMark to ISO/IEC 29110 and, secondly, a study to test the applicability of the assessments made by ITMark in the ISO/IEC 29110 environment taking into account the previous mapping. The main conclusion from this industrial experience is that ITMark can be used as a method for assessing very small entities. Copyright © 2016 John Wiley & Sons, Ltd. Xabier Larrucea, Izaskun Santamaría, Ricardo Colomo-Palacios |
J. Softw. Evol. Process. | 1 |
| 2015 | A Tool Suite for Assurance Cases and Evidences: Avionics Experiences
Alejandra Ruiz López, Xabier Larrucea, Huáscar Espinoza |
EuroSPI | 2 |
| 2015 | An Industrial Experience in Cross Domain Assurance Projects
Alejandra Ruiz López, Xabier Larrucea, Huáscar Espinoza, Franck Aime, Cyril Marchand |
EuroSPI | 2 |
| 2014 | An industrial assessment for a multimodel frameworkabstractABSTRACT Software process improvement (SPI) initiatives are facing complex environments where stakeholders need to integrate different reference models in their organizations. There are several approaches to multimodel environments defining some steps or activities that should be carried out for implementing it efficiently inside organizations. This paper presents a report on the use of a multimodel framework integrating three quality reference models in 47 SPI initiatives. Basically, this report is based on statistical data extracted from industrial assessments. Copyright © 2014 John Wiley & Sons, Ltd. Xabier Larrucea, Izaskun Santamaría |
J. Softw. Evol. Process. | 1 |
| 2012 | A Harmonized Multimodel Framework for Safety Environments
Xabier Larrucea, Izaskun Santamaría, Paolo Panaroni |
EuroSPI | 1 |
| 2010 | A Metamodel Integration for Metrics and Processes Correlation
Xabier Larrucea, Eider Iturbe |
ICSOFT (1) | 1 |
| 2009 | Modelling and Deploying Security Policies
Xabier Larrucea, Rubén Alonso |
WEBIST | 1 |