Fredrik Törner

dblp:47/1750 · DBLP profile ↗
← Back
16ranked-venue papers
2as first author
5since 2021 · last 2025
0009-0005-6368-7801ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 13 · 1 first-author · 5 since 2021Security and privacy · 3 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2025 The DevSafeOps dilemma: A systematic literature review on rapidity in safe autonomous driving development and operation
abstract
Developing autonomous driving (AD) systems is challenging due to the complexity of the systems and the need to assure their safe and reliable operation. The widely adopted approach of DevOps seems promising to support the continuous technological progress in AI and the demand for fast reaction to incidents, which necessitate continuous development, deployment, and monitoring. We present a systematic literature review meant to identify, analyse, and synthesise a broad range of existing literature related to usage of DevOps in autonomous driving development. Our results provide a structured overview of challenges and solutions, arising from applying DevOps to safety-related AI-enabled functions. Our results indicate that there are still several open topics to be addressed to enable safe DevOps for the development of safe AD. • Applying DevOps to autonomous driving presents several open topics to be addressed. • DevSafeOps is introduced, adding safety-related activities into DevOps iterative loops. • Our systematic literature review led to 11 challenges in the DevSafeOps loop. • Potential solutions are identified and mapped to challenges in DevSafeOps.
Ali Nouri, Beatriz Cabrero-Daniel, Fredrik Törner, Christian Berger 0001
J. Syst. Softw.3
2024 Welcome Your New AI Teammate: On Safety Analysis by Leashing Large Language Models
abstract
DevOps is a necessity in many industries, including the development of Autonomous Vehicles. In those settings, there are iterative activities that reduce the speed of SafetyOps cycles. One of these activities is "Hazard Analysis & Risk Assessment" (HARA), which is an essential step to start the safety requirements specification. As a potential approach to increase the speed of this step in SafetyOps, we have delved into the capabilities of Large Language Models (LLMs). Our objective is to systematically assess their potential for application in the field of safety engineering. To that end, we propose a framework to support a higher degree of automation of HARA with LLMs. Despite our endeavors to automate as much of the process as possible, expert review remains crucial to ensure the validity and correctness of the analysis results, with necessary modifications made accordingly.
Ali Nouri, Beatriz Cabrero-Daniel, Fredrik Törner, Håkan Sivencrona, Christian Berger 0001
CAIN3
2024 Engineering Safety Requirements for Autonomous Driving with Large Language Models
abstract
Changes and updates in the requirement artifacts, which can be frequent in the automotive domain, are a challenge for SafetyOps. Large Language Models (LLMs), with their impressive natural language understanding and generating capabilities, can play a key role in automatically refining and decomposing requirements after each update. In this study, we propose a prototype of a pipeline of prompts and LLMs that receives an item definition and outputs solutions in the form of safety requirements. This pipeline also performs a review of the requirement dataset and identifies redundant or contradictory requirements. We first identified the necessary characteristics for performing HARA and then defined tests to assess an LLM's capability in meeting these criteria. We used design science with multiple iterations and let experts from different companies evaluate each cycle quantitatively and qualitatively. Finally, the prototype was implemented at a case company and the responsible team evaluated its efficiency.
Ali Nouri, Beatriz Cabrero-Daniel, Fredrik Törner, Håkan Sivencrona, Christian Berger 0001
RE3
2023 On STPA for Distributed Development of Safe Autonomous Driving: An Interview Study
abstract
Safety analysis is used to identify hazards and build knowledge during the design phase of safety-relevant functions. This is especially true for complex AI-enabled and software intensive systems such as Autonomous Drive (AD). System-Theoretic Process Analysis (STPA) is a novel method applied in safety-related fields like defense and aerospace, which is also becoming popular in the automotive industry. However, STPA assumes prerequisites that are not fully valid in the automotive system engineering with distributed system development and multi-abstraction design levels. This would inhibit software developers from using STPA to analyze their software as part of a bigger system, resulting in a lack of traceability. This can be seen as a maintainability challenge in continuous development and deployment (DevOps). In this paper, STPA’s different guidelines for the automotive industry, e.g. J31887/ISO21448/STPA handbook, are firstly compared to assess their applicability to the distributed development of complex AI-enabled systems like AD. Further, an approach to overcome the challenges of using STPA in a multilevel design context is proposed. By conducting an interview study with automotive industry experts for the development of AD, the challenges are validated and the effectiveness of the proposed approach is evaluated.
Ali Nouri, Christian Berger 0001, Fredrik Törner
SEAA3
2022 An Industrial Experience Report about Challenges from Continuous Monitoring, Improvement, and Deployment for Autonomous Driving Features
abstract
Using continuous development, deployment, and monitoring (CDDM) to understand and improve applications in a customer’s context is widely used for non-safety applications such as smartphone apps or web applications to enable rapid and innovative feature improvements. Having demonstrated its potential in such domains, it may have the potential to also improve the software development for automotive functions as some OEMs described on a high level in their financial company communiqués. However, the application of a CDDM strategy also faces challenges from a process adherence and documentation perspective as required by safety-related products such as autonomous driving systems (ADS) and guided by industry standards such as ISO-26262 [1] and ISO21448 [2]. There are publications on CDDM in safety-relevant contexts that focus on safety-critical functions on a rather generic level and thus, not specifically ADS or automotive, or that are concentrating only on software and hence, missing out the particular context of an automotive OEM: Well-established legacy processes and the need of their adaptations, and aspects originating from the role of being a system integrator for software/software, hardware/hardware, and hardware/software. In this paper, particular challenges from the automotive domain to better adopt CDDM are identified and discussed to shed light on research gaps to enhance CDDM, especially for the software development of safe ADS. The challenges are identified from today’s industrial well-established ways of working by conducting interviews with domain experts and complemented by a literature study.
Ali Nouri, Christian Berger 0001, Fredrik Törner
SEAA3
2014 Selecting software reliability growth models and improving their predictive accuracy using historical projects data
Rakesh Rana, Miroslaw Staron, Christian Berger 0001, Jörgen Hansson, Martin Nilsson 0002, Fredrik Törner, Wilhelm Meding, Christoffer Höglund
J. Syst. Softw.6
2013 Increasing Efficiency of ISO 26262 Verification and Validation by Combining Fault Injection and Mutation Testing with Model based Development
abstract
The rapid growth of software intensive active safety functions in modern cars resulted in adoption of new safety development standards like ISO 26262 by the automotive industry. Hazard analysis, safety assessment and adequate verification and validation methods for software and car electronics require effort but in the long run save lives. We argue that in the face of complex software development set-up with distributed functionality, Model-Based Development (MBD) and safety criticality of software embedded in modern cars, there is a need for evolving existing methods of MBD and complementing them with methods already used in the development of other systems (Fault Injection and Mutation Testing). Our position is that significant effectiveness and efficiency improvements can be made by applying fault injection techniques combined with mutation testing approach for verification and validation of automotive software at the model level. The improvements include such aspects as identification of safety related defects early in the development process thus providing enough time to remove the defects. The argument is based on our industrial case studies, the studies of ISO 26262 standard and academic experiments with new verification and validation methods applied to models.
Rakesh Rana, Miroslaw Staron, Christian Berger 0001, Jörgen Hansson, Martin Nilsson 0002, Fredrik Törner
ICSOFT6
2013 Evaluating long-term predictive power of standard reliability growth models on automotive systems
abstract
Software is today an integral part of providing improved functionality and innovative features in the automotive industry. Safety and reliability are important requirements for automotive software and software testing is still the main source of ensuring dependability of the software artifacts. Software Reliability Growth Models (SRGMs) have been long used to assess the reliability of software systems; they are also used for predicting the defect inflow in order to allocate maintenance resources. Although a number of models have been proposed and evaluated, much of the assessment of their predictive ability is studied for short term (e.g. last 10% of data). But in practice (in industry) the usefulness of SRGMs with respect to optimal resource allocation depends heavily on the long term predictive power of SRGMs i.e. much before the project is close to completion. The ability to reasonably predict the expected defect inflow provides important insight that can help project and quality managers to take necessary actions related to testing resource allocation on time to ensure high quality software at the release. In this paper we evaluate the long-term predictive power of commonly used SRGMs on four software projects from the automotive sector. The results indicate that Gompertz and Logistic model performs best among the tested models on all fit criterias as well as on predictive power, although these models are not reliable for long-term prediction with partial data.
Rakesh Rana, Miroslaw Staron, Christian Berger 0001, Jörgen Hansson, Martin Nilsson 0002, Fredrik Törner
ISSRE6
2013 Comparing between Maximum Likelihood Estimator and Non-linear Regression Estimation Procedures for NHPP Software Reliability Growth Modelling
abstract
Software Reliability Growth Models (SRGMs) have been used by engineers and managers for tracking and managing the reliability change of software to ensure required standard of quality is achieved before the software is released to the customer. SRGMs can be used during the project to help make testing resource allocation decisions and/ or it can be used after the testing phase to determine the latent faults prediction to assess the maturity of software artifact. A number of SRGMs have been proposed and to apply a given reliability model, defect inflow data is fitted to model equations. Two of the widely known and recommended techniques for parameter estimation are maximum likelihood and method of least squares. In this paper we compare between the two estimation procedures for their applicability in context of NHPP SRGMs. We also highlight a couple of practical considerations, reliability practitioners must be aware of when applying SRGMs.
Rakesh Rana, Miroslaw Staron, Christian Berger 0001, Jörgen Hansson, Martin Nilsson 0002, Fredrik Törner
IWSM/Mensura6
2013 Why Do We Not Learn from Defects? - Towards Defect-Driven Software Process Improvement
abstract
In this paper, we put forth the thesis that state-of-the-art defect classification schemes – such as ODC and IEEE Std. 1044 – have failed to meet their target; limited industrial adoption is taken as part of the evidence combined with published studies on model driven software development. Notwithstanding, a number of publications show that defect reports can provide valuable information about common, important, or dangerous problems with software products. In this paper, we present the synthesis of two industrial case studies that illustrate that even expert judgement can be deceptive; demonstrating the need for more objective evidence to allow project stakeholder to make informed decisions, and that defect classification is one effective means to that end. Finally, we propose a roadmap that will contribute to improving the defect classification approach, which in consequence will lead to a wider industrial adoption.
Niklas Mellegård, Miroslaw Staron, Fredrik Törner
MODELSWARD3
2013 Evaluation of Standard Reliability Growth Models in the Context of Automotive Software Systems
Rakesh Rana, Miroslaw Staron, Niklas Mellegård, Christian Berger 0001, Jörgen Hansson, Martin Nilsson 0002, Fredrik Törner
PROFES7
2012 A Light-Weight Defect Classification Scheme for Embedded Automotive Software and Its Initial Evaluation
abstract
Objective: Defect classification is an essential part of software development process models as a means of early identification of patterns in defect inflow profiles. Such classification, however, may often be a tedious task requiring analysis work in addition to what is necessary to resolve the issue. To increase classification efficiency, adapted schemes are needed. In this paper a light-weight defect classification scheme adapted for minimal process footprint -- in terms of learning and classification effort -- is proposed and initially evaluated. Method: A case study was conducted at Volvo Car Corporation to adapt the IEEE Std. 1044 for automotive embedded software. An initial evaluation was conducted by applying the adapted scheme to defects from an existing software product with industry professionals as subjects. Results: The results showed that the classification scheme was quick to learn and understand -- required classification time stabilized around 5-10 minutes already after practicing on 3-5 defects. The results also showed that the patterns in the classified defects were interesting for the professionals, although in order to apply statistical methods more data was needed. Conclusions: We conclude that the adapted classification scheme captures what is currently tacit knowledge and has the potential of revealing patterns in the defects detected in different project phases. Furthermore, we were, in the initial evaluation, able to contribute with new information about the development process. As a result we are currently in the process of incorporating the classification scheme into the company's defect reporting system.
Niklas Mellegård, Miroslaw Staron, Fredrik Törner
ISSRE3
2008 Modelling Support for Design of Safety-Critical Automotive Embedded Systems
Dejiu Chen, Rolf Johansson 0002, Henrik Lönn, Yiannis Papadopoulos, Anders Sandberg, Fredrik Törner, Martin Törngren
SAFECOMP6
2006 An Empirical Quality Assessment of Automotive Use Cases
abstract
As functionality in vehicles grows more complex and development becomes distributed over several geographical sites, elicitation and visualization of requirements become more critical. This paper presents a set of evaluation criteria for the quality of use cases. The criteria are applied to use cases that are currently used in industry and developed according to current industrial practice. The paper presents statistics of quality defects that occur in industry and proposes academic solutions that may be applied to solve them. The study is based on 43 use cases from Volvo Car Corporation spanning three different function areas of a vehicle. The most common quality defect classes of the evaluated use cases are missing elements, irrelevant steps, incorrect linguistics and level of detail. Furthermore, it is concluded that a common taxonomy and cross team reviews are needed to further improve the quality and usefulness of use cases
Fredrik Törner, Martin Ivarsson, Fredrik Pettersson, Peter Öhman
RE1
2006 Assessment of Hazard Identification Methods for the Automotive Domain
Fredrik Törner, Per Johannessen, Peter Öhman
SAFECOMP1
2004 Actuator Based Hazard Analysis for Safety Critical Systems
Per Johannessen, Fredrik Törner, Jan Torin
SAFECOMP2