Jeffrey J. Joyce

dblp:46/6199 · also Jeff Joyce · DBLP profile ↗
← Back
12ranked-venue papers
3as first author
4since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 6 · 2 since 2021Systems, architecture and hardware · 3 · 3 first-authorSecurity and privacy · 3 · 2 since 2021Computer networks · 1
YearPublicationVenuePosition
2026 Evaluating AI-supported eliminative argumentation for developing reliable assurance cases
Torin Viger, Logan Murphy, Simon Diemert, Claudio Menghi, Aren A. Babikian, Jeffrey J. Joyce, Alessio Di Sandro, Naweed Anwari, Erin Cyffka, Marsha Chechik
Empir. Softw. Eng.6
2025 Balancing the Risks and Benefits of Using Large Language Models to Support Assurance Case Development
Simon Diemert, Erin Cyffka, Naweed Anwari, Olivia Foster, Torin Viger, Laure Millet, Jeffrey J. Joyce
SAFECOMP7
2024 AI-Supported Eliminative Argumentation: Practical Experience Generating Defeaters to Increase Confidence in Assurance Cases
abstract
Assurance cases (AC) are structured arguments that justify why a system is acceptably safe. Though ACs can increase confidence that systems will operate safely and reliably, they are also susceptible to problems such as reasoning errors and confirmation bias. Recent work proposed AI-Supported Eliminative Argumentation (AI-EA), a framework leveraging Generative AI (GAI) models to support AC development by identifying potential reasons why the argument may be invalid (a.k.a. defeaters) so that they can be mitigated. However, this framework was not implemented and its effectiveness was not assessed empirically.In this practical experience paper, we implement AI-EA, explain and justify our design choices, and report on our practical experience in empirically evaluating its effectiveness in collaboration with experts in the safety domain. Our evaluation considers 171 AI-generated defeaters across two industrial case studies from the nuclear and automotive domains. Our findings show that GAI can generate informative defeaters with few significant hallucinations and that 25% of the generated defeaters were confirmed by developers of each AC to represent reasonable doubts or errors in the argument. Our implementation and data are made publicly available.
Torin Viger, Logan Murphy, Simon Diemert, Claudio Menghi, Jeffrey J. Joyce, Alessio Di Sandro, Marsha Chechik
ISSRE5
2023 Assurance Case Arguments in the Large: The CERN LHC Machine Protection System
Laure Millet, Simon Diemert, Chris Rees, Torin Viger, Marsha Chechik, Claudio Menghi, Jeffrey J. Joyce
SAFECOMP7
2018 Morse: Reducing the Feature Interaction Explosion Problem using Subject Matter Knowledge as Abstract Requirements
abstract
The feature interaction problem appears in many different kinds of complex systems, especially systems whose elements are created or maintained by separate entities - for example, a modern automobile that incorporates electronic systems produced by different suppliers. Cross-cutting concerns, such as safety and security, require a comprehensive analysis of the possible interactions. However, there is a combinatorial explosion in the number of feature combinations to be considered. Our work approaches the feature interaction problem from a novel point of view: we seek to use the abstract subject matter knowledge of domain experts to deduce why some features will NOT interact, rather than trying to discover or resolve the interactions. In this paper, we present a method that can automatically reduce the required number of combinations and situations that have to be evaluated or resolved for feature interactions. Our tool, called Morse, rules out feature combinations that cannot have interactions based on traceable deductions from relatively simple abstract requirements that capture relevant subject matter knowledge. Our method is useful as a means of focusing attention on particular situations where more detailed functional requirements may be needed to avoid unacceptable risk arising from unintended interactions between features. relatively simple abstract requirements that capture relevant subject matter knowledge. Our method is useful as a means of focusing attention on particular situations where more detailed functional requirements may be needed to avoid unacceptable risk arising from unintended interactions between features.
Laure Millet, Nancy A. Day, Jeffrey J. Joyce
RE3
2011 Formal Verification of Real-Time Data Processing of the LHC Beam Loss Monitoring System: A Case Study
Naghmeh Ghafari, Ramana Kumar, Jeffrey J. Joyce, Bernd Dehning, Christos Zamantzas
FMICS3
2008 Modelling feature interactions in the automotive domain
abstract
We propose to use model checking to detect feature interactions in a set of features under design for an automotive embedded system. In this paper, we present (1) the characteristics of the feature interaction problem in the automotive domain that make model checking an appropriate detection technique; (2) our proposal for a general, systematic definition of feature interactions for this domain based on the set of actuators in the vehicle influenced by the features; and (3) our solutions to two modelling issues that arise when creating a description in SMV of the behaviour of an integrated set of automotive features designed in MATLAB's STATEFLOW.
Alma L. Juarez Dominguez, Nancy A. Day, Jeffrey J. Joyce
MiSE3
1998 Refinement of Safety-Related Hazards into Verifiable Code Assertions
Jeffrey J. Joyce
SAFECOMP2
1997 Using a Formal Description Technique to Model Aspects of a Global Air Traffic Telecommunications Network
James H. Andrews, Nancy A. Day, Jeffrey J. Joyce
FORTE3
1993 Linking BDD-Based Symbolic Evaluation to Interactive Theorem-Proving
abstract
A novel approach to formal hardware verification results from the combination of symbolic trajectory evaluation and interactive theorem-pmviug.From symbolic trajectory evaluation we inherit a high degree of automation and accurate models of circuit behavionr and timing.From interactive theorempmving we gain access to powerful mathematical tools such as induction and abstraction.We have prototype a hybrid tool and used this tool to obtain verification results that could not be easily obtained with previously published techniques.
Jeffrey J. Joyce, Carl-Johan H. Seger
DAC1
1989 Formal specification and verification of microprocessor systems
Jeffrey J. Joyce
Integr.1
1988 Formal specification and verification of microprocessor systems
Jeffrey J. Joyce
Microprocess. Microprogramming1