VLDB 2026 Research / reviewers in the wild / expert
Daniela Micucci
dblp:54/1189
· DBLP profile ↗
49ranked-venue papers
6as first author
17since 2021 · last 2026
0000-0003-1261-2234ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 34 · 2 first-author · 15 since 2021Artificial intelligence and machine learning · 4 · 2 first-authorSystems, architecture and hardware · 3 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-authorHuman-computer interaction and ubiquitous computing · 2 · 1 since 2021Computer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Exploring Persistent Configuration Decisions for Adaptive Data Provisioning
Giovanni Donato Gallo, Federico Bergamini, Marco Napolitano, Daniela Micucci |
ICSOFT | 4 |
| 2026 | Assessing Task-based Chatbots: Snapshot and Curated Datasets for DialogflowabstractIn recent years, chatbots have gained widespread adoption thanks to their ability to assist users at any time and across diverse domains. However, the lack of large-scale curated datasets limits research on their quality and reliability. This paper presents TOFU-D, a snapshot of 1,788 Dialogflow chatbots from GitHub, and COD, a curated subset of TOFU-D including 185 validated chatbots. The two datasets capture a wide range of domains, languages, and implementation patterns, offering a sound basis for empirical studies on chatbot quality and security. A preliminary assessment using the Botium testing framework and the Bandit static analyzer revealed gaps in test coverage and frequent security vulnerabilities in several chatbots, highlighting the need for systematic, multi-platform research on chatbot quality and security. Elena Masserini, Diego Clerissi, Daniela Micucci, Leonardo Mariani |
MSR | 3 |
| 2026 | Deep Representation Learning for Open Vocabulary Electroencephalography-to-Text DecodingabstractPrevious research has demonstrated the potential of using pre-trained language models for decoding open vocabulary Electroencephalography (EEG) signals captured through a non-invasive Brain-Computer Interface (BCI). However, the impact of embedding EEG signals in the context of language models and the effect of subjectivity, remain unexplored, leading to uncertainty about the best approach to enhance decoding performance. Additionally, current evaluation metrics used to assess decoding effectiveness are predominantly syntactic and do not provide insights into the comprehensibility of the decoded output for human understanding. We present an end-to-end architecture for non-invasive brain recordings that brings modern representational learning approaches to neuroscience. Our proposal introduces the following innovations: 1) an end-to-end deep learning architecture for open vocabulary EEG decoding, incorporating a subject-dependent representation learning module for raw EEG encoding, a BART language model, and a GPT-4 sentence refinement module; 2) a more comprehensive sentence-level evaluation metric based on the BERTScore; 3) an ablation study that analyses the contributions of each module within our proposal, providing valuable insights for future research.We evaluate our approach on two publicly available datasets, ZuCo v1.0 and v2.0, comprising EEG recordings of 30 subjects engaged in natural reading tasks. Our model achieves a BLEU-1 score of 42.75%, a ROUGE-1-F of 33.28%, and a BERTScore-F of 53.86%, achieving an increment over the previous state-of-the-art by 1.40%, 2.59%, and 3.20%, respectively. Hamza Amrani, Daniela Micucci, Paolo Napoletano |
IEEE J. Biomed. Health Informatics | 2 |
| 2025 | Students' Perception of ChatGPT in Software Engineering: Lessons Learned from Five CoursesabstractA few years after their release, Large Language Models (LLMs)-based tools are becoming an essential component of software education, as calculators are used in math courses. When learning software engineering (SE), the challenge is the extent to which LLMs are suitable and easy to use for different software development tasks. In this paper, we report the findings and lessons learned from using LLM-based tools-ChatGPT in particular-in five SE courses from four universities. After instructing students on the LLM potentials in SE and about prompting strategies, we ask participants to complete a survey and be involved in semi-structured interviews. The collected results report (i) indications about the usefulness of the LLM for different tasks, (ii) challenges to prompt the LLM, i.e., interact with it, (iii) challenges to adapt the generated artifacts to their own needs, and (iv) wishes about some valuable features students would like to see in LLM-based tools. Although results vary among different courses, also because of students' seniority and course goals, the perceived usefulness is greater for lowlevel phases (e.g., coding or debugging/fault localization) than for analysis and design phases. Interaction and code adaptation challenges vary among tasks and are mostly related to the need for task-specific prompts, as well as better specification of the development context. Luciano Baresi, Andrea De Lucia, Antinisca Di Marco, Massimiliano Di Penta, Davide Di Ruscio, Leonardo Mariani, Daniela Micucci, Fabio Palomba, Maria Teresa Rossi, Fiorella Zampetti |
CSEE&T | 7 |
| 2025 | Towards the Assessment of Task-based Chatbots: From the TOFU-R Snapshot to the BRASATO Curated DatasetabstractTask-based chatbots are increasingly being used to deliver real services, yet assessing their reliability, security, and robustness remains underexplored, also due to the lack of large-scale, high-quality datasets. The emerging automated quality assessment techniques targeting chatbots often rely on limited pools of subjects, such as custom-made toy examples, or outdated, no longer available, or scarcely popular agents, complicating the evaluation of such techniques. In this paper, we present two datasets and the tool support necessary to create and maintain these datasets. The first dataset is RASA TASK-BASED CHATBOTS FROM GITHUB (TOFU-R), which is a snapshot of the Rasa chatbots available on GitHub, representing the state of the practice in open-source chatbot development with Rasa. The second dataset is BOT RASA COLLECTION (BRASATO), a curated selection of the most relevant chatbots for dialogue complexity, functional complexity, and utility, whose goal is to ease reproducibility and facilitate research on chatbot reliability. Elena Masserini, Diego Clerissi, Daniela Micucci, João R. Campos, Leonardo Mariani |
ISSRE | 3 |
| 2025 | On the Possibility of Breaking Copyleft Licenses When Reusing Code Generated by ChatGPTabstractAI assistants can help developers by recommending code to be included in their implementations (e.g., suggesting the implementation of a method from its signature). Although useful, these recommendations may mirror copyleft code available in public repositories, exposing developers to the risk of reusing code that they are allowed to reuse only under certain constraints (e.g., a specific license for the derivative software). This paper presents a large-scale study about the frequency and magnitude of this phenomenon in ChatGPT. In particular, we generate more than 70,000 method implementations using a range of configurations and prompts, revealing that a larger context increases the likelihood of reproducing copyleft code, but higher temperature settings can mitigate this issue. Gaia Colombo, Leonardo Mariani, Daniela Micucci, Oliviero Riganelli |
ICPC | 3 |
| 2025 | Studying How Configurations Impact Code Generation in LLMs: The Case of ChatGPTabstractLeveraging LLMs for code generation is becoming increasingly common, as tools like ChatGPT can suggest method implementations with minimal input, such as a method signature and brief description. Empirical studies further highlight the effectiveness of LLMs in handling such tasks, demonstrating notable performance in code generation scenarios. However, LLMs are inherently non-deterministic, with their output influenced by parameters such as temperature, which regulates the model's level of creativity, and top-p, which controls the choice of the tokens that shall appear in the output. Despite their significance, the role of these parameters is often overlooked. This paper systematically studies the impact of these parameters, as well as the number of prompt repetitions required to account for non-determinism, in the context of 548 Java methods. We observe significantly different performances across different configurations of ChatGPT, with temperature having a marginal impact compared to the more prominent influence of the top-p parameter. Additionally, we show how creativity can enhance code generation tasks. Finally, we provide concrete recommendations for addressing the non-determinism of the model. Benedetta Donato, Leonardo Mariani, Daniela Micucci, Oliviero Riganelli |
ICPC | 3 |
| 2025 | How low-code platforms support digital twins of processes
Arianna Fedeli, Amleto Di Salle, Daniela Micucci, Luciana Brasil Rebelo dos Santos, Maria Teresa Rossi, Leonardo Mariani, Ludovico Iovino |
Softw. Syst. Model. | 3 |
| 2024 | Anonymizing Test Data in Android: Does It Hurt?abstractFailure data collected from the field (e.g., failure traces, bug reports, and memory dumps) represent an invaluable source of information for developers who need to reproduce and analyze failures. Unfortunately, field data may include sensitive information and thus cannot be collected indiscriminately. Privacy-preserving techniques can address this problem anonymizing data and reducing the risk of disclosing personal information. However, collecting anonymized information may harm reproducibility, that is, the anonymized data may not allow the reproduction of a failure observed in the field. In this paper, we present an empirical investigation about the impact of privacy-preserving techniques on the reproducibility of failures. In particular, we study how five privacy-preserving techniques may impact reproducibilty for 19 bugs in 17 Android applications. Results provide insights on how to select and configure privacy-preserving techniques. Elena Masserini, Davide Ginelli, Daniela Micucci, Daniela Briola, Leonardo Mariani |
AST | 3 |
| 2024 | COBOL: COmmunity-Based Organized LitteringabstractLittering is a major problem that threatens the environment, society, and economy. Keep track, monitor and regularly clean littering sites can be a crucial problem that involves public authorities, municipalities, companies, and citizens. So far approaches have not well leveraged the knowledge and capabilities that derive from the federation of multiple communities, such as cities, public bodies, and organizations. In this paper, we describe the COBOL project, a National PRIN (Progetti di Rilevante Interesse Nazionale) PNRR (Piano Nazionale Ripresa e Resilienza) project funded by the Italian MUR (Ministero dell'Università e della Ricerca) in 2023. The project aims to definite a flexible framework for managing the waste disposal process through a federated learning architecture that collects and integrates the reports (e.g., annotated pictures and user feedback) shared by the communities involved in the waste disposal process. To deliver an advanced waste disposal service based on the direct participation of citizens, COBOL also integrates Model-Driven Engineering principles, Computer Vision techniques, and Self-Adaptation mechanisms. Early results show that reports can be effectively collected and processed with COBOL. Luciano Baresi, Simone Bianco 0001, Amleto Di Salle, Ludovico Iovino, Leonardo Mariani, Daniela Micucci, Luciana Brasil Rebelo dos Santos, Maria Teresa Rossi, Raimondo Schettini |
SEAA | 6 |
| 2024 | Generating Java Methods: An Empirical Assessment of Four AI-Based Code AssistantsabstractAI-based code assistants are promising tools that can facilitate and speed up code development. They exploit machine learning algorithms and natural language processing to interact with developers, suggesting code snippets (e.g., method implementations) that can be incorporated into projects. Recent studies empirically investigated the effectiveness of code assistants using simple exemplary problems (e.g., the re-implementation of well-known algorithms), which fail to capture the spectrum and nature of the tasks actually faced by developers. Vincenzo Corso, Leonardo Mariani, Daniela Micucci, Oliviero Riganelli |
ICPC | 3 |
| 2024 | Analyzing Prompt Influence on Automated Method Generation: An Empirical Study with CopilotabstractGenerative AI is changing the way developers interact with software systems, providing services that can produce and deliver new content, crafted to satisfy the actual needs of developers. For instance, developers can ask for new code directly from within their IDEs by writing natural language prompts, and integrated services based on generative AI, such as Copilot, immediately respond to prompts by providing ready-to-use code snippets. Formulating the prompt appropriately, and incorporating the useful information while avoiding any information overload, can be an important factor in obtaining the right piece of code. The task of designing good prompts is known as prompt engineering. Ionut Daniel Fagadau, Leonardo Mariani, Daniela Micucci, Oliviero Riganelli |
ICPC | 3 |
| 2024 | Automatic testing of runtime enforcers with Test4EnforcersabstractUsers regularly use apps to access services in a range of domains, such as health, productivity, entertainment, and business. The safety and correctness of the runtime behaviour of these apps is thus a key concern for users. Indeed, unreliable apps may generate dissatisfaction, frustration and issues to users. Runtime enforcement techniques can be used to implement software enforcers that monitor executions and apply corrective actions when needed, potentially preventing misbehaviours and failures. However, enforcers might be faulty themselves, applying the wrong actions or missing to apply the right actions. To address this problem, this paper presents Test4Enforcers, an approach to automatically test software enforces. Test4Enforcers relies on an enforcement model describing the strategy that shall be applied at runtime to correct misbehaviors. Test4Enforcers first uses the enforcement model to derive a specification of the test cases that shall be executed to validate any software enforcer implemented from the given model. Then, it automatically turns the test specification into a set of concrete test cases that can be executed against apps augmented with the enforcers. We evaluated Test4Enforces with a set of 3,135 faults injected in the enforcers derived from 13 enforcement models. Results show that Test4Enforcers can automatically reveal 64% of the faults, while existing approches relying on crash detection can only reveal 6% of the faults. Test4Enforcers is also practical since testing an enforcer required 9 min, in the worst case. Oliviero Riganelli, Daniela Micucci, Leonardo Mariani |
J. Syst. Softw. | 2 |
| 2024 | A family of experiments about how developers perceive delayed system response timeabstractAbstract Collecting and analyzing data about developers working on their development tasks can help improve development practices, finally increasing the productivity of teams. Indeed, monitoring and analysis tools have already been used to collect data from productivity tools. Monitoring inevitably consumes resources and, depending on their extensiveness, may significantly slow down software systems, interfering with developers’ activity. There is thus a challenging trade-off between monitoring and validating applications in their operational environment and preventing the degradation of the user experience. The lack of studies about when developers perceive an overhead introduced in an application makes it extremely difficult to fine-tune techniques working in the field. In this paper, we address this challenge by presenting an empirical study that quantifies how developers perceive overhead. The study consists of three replications of an experiment that involved 99 computer science students in total, followed by a small-scale experimental assessment of the key findings with 12 professional developers. Results show that non-negligible overhead can be introduced for a short period into applications without developers perceiving it and that the sequence in which complex operations are executed influences the perception of the system response time. This information can be exploited to design better monitoring techniques. Oscar Cornejo 0001, Daniela Briola, Daniela Micucci, Davide Ginelli, Leonardo Mariani, Adrián Santos Parrilla, Natalia Juristo Juzgado |
Softw. Qual. J. | 3 |
| 2022 | Non-functional Testing of Runtime Enforcers in Android
Oliviero Riganelli, Daniela Micucci, Leonardo Mariani |
ISoLA (1) | 2 |
| 2022 | TkT: Automatic Inference of Timed and Extended Pushdown AutomataabstractTo mitigate the cost of manually producing and maintaining models capturing software specifications,specification miningtechniques can be exploited to automatically derive up-to-date models that faithfully represent the behavior of software systems. So far, specification mining solutions focused on extracting information about the functional behavior of the system, especially in the form of models that represent the ordering of the operations. Well-known examples are finite state models capturing the usage protocol of software interfaces and temporal rules specifying relations among system events. Although the functional behavior of a software system is a primary aspect of concern, there are several other non-functional characteristics that must be typically addressed jointly with the functional behavior of a software system. Efficiency is one of the most relevant characteristics. Indeed, an application that delivers the right functionalities with an inefficient implementation may fail to satisfy the expectations of its users. Interestingly, thetiming behavioris strongly dependent on the functional behavior of a software system. For instance, the timing of an operation depends on the functional complexity and size of the computation that is performed. Consequently, models that combine the functional and timing behaviors, as well as their dependencies, are extremely important to precisely reason on the behavior of software systems. In this paper, we address the challenge of generating models that capture both the functional and timing behavior of a software system from execution traces. The result is theTimed k-Tail (TkT) specification mining technique, which can mine finite state models that capture such an interplay: the functional behavior is represented by the possible order of the events accepted by the transitions, while the timing behavior is represented through clocks and clock constraints of different nature associated with transitions. Our empirical evaluation with several libraries and applications shows thatTkTcan generate accurate models, capable of supporting the identification of timing anomalies due to overloaded environment and performance faults. Furthermore, our study shows thatTkToutperforms state-of-the-art techniques in terms of scalability and accuracy of the mined models. Fabrizio Pastore, Daniela Micucci, Michell Guzmán, Leonardo Mariani |
IEEE Trans. Software Eng. | 2 |
| 2021 | Exception-Driven Fault Localization for Automated Program RepairabstractAutomated Program Repair (APR) techniques typically exploit spectrum-based fault localization (SBFL) to identify the program locations that should be patched, making the effectiveness of APR techniques dependent on the effectiveness of fault localization. Indeed, results show that SBFL often does not localize faults accurately, hindering the effectiveness of APR. In this paper, we propose EXCEPT, a technique that addresses the localization problem by focusing on the semantics of failures rather than on the correlation between the executed statements and the failed tests, as SBFL does. We focus on failures due to exceptions and we exploit their type and source to localize and guess the faults. Experiments with 43 exception-raising faults from the Defects4J benchmark show that EXCEPT can perform better than Ochiai and ssFix. Davide Ginelli, Oliviero Riganelli, Daniela Micucci, Leonardo Mariani |
QRS | 3 |
| 2020 | Personalized Models in Human Activity Recognition using Deep LearningabstractCurrent sensor-based human activity recognition techniques that rely on a user-independent model struggle to generalize to new users and on to changes that a person may make over time to his or her way of carrying out activities. Incremental learning is a technique that allows to obtain personalized models which may improve the performance on the classifiers thanks to a continuous learning based on user data. Finally, deep learning techniques have been proven to be more effective with respect to traditional ones in the generation of user-independent models. The aim of our work is therefore to put together deep learning techniques with incremental learning in order to obtain personalized models that perform better with respect to user-independent model and personalized model obtained using traditional machine learning techniques. The experimentation was done by comparing the results obtained by a technique in the state of the art with those obtained by two neural networks (ResNet and a simplified CNN) on three datasets. The experimentation showed that neural networks adapt faster to a new user than the baseline. Hamza Amrani, Daniela Micucci, Paolo Napoletano |
ICPR | 2 |
| 2020 | CBR: Controlled Burst RecordingabstractCollecting traces from software running in the field is both useful and challenging. Traces may indeed help revealing unexpected usage scenarios, detecting and reproducing failures, and building behavioral models that reflect how the software is actually used. On the other hand, recording traces is an intrusive activity that may annoy users, negatively affecting the usability of the applications, if not properly designed.In this paper we address field monitoring by introducing Controlled Burst Recording, a monitoring solution that can collect comprehensive runtime data without compromising the quality of the user experience. The technique encodes the knowledge extracted from the monitored application as a finite state model that both represents the sequences of operations that can be executed by the users and the corresponding internal computations that might be activated by each operation.Our initial assessment with information extracted from ArgoUML shows that Controlled Burst Recording can reconstruct behavioral information more effectively than competing sampling techniques, with a low impact on the system response time. Oscar Cornejo 0001, Daniela Briola, Daniela Micucci, Leonardo Mariani |
ICST | 3 |
| 2020 | Data loss detector: automatically revealing data loss bugs in Android appsabstractAndroid apps must work correctly even if their execution is interrupted by external events. For instance, an app must work properly even if a phone call is received, or after its layout is redrawn because the smartphone has been rotated. Since these events may require destroying, when the execution is interrupted, and recreating, when the execution is resumed, the foreground activity of the app, the only way to prevent the loss of state information is to save and restore it. This behavior must be explicitly implemented by app developers, who often miss to implement it properly, releasing apps affected by data loss problems, that is, apps that may lose state information when their execution is interrupted. Although several techniques can be used to automatically generate test cases for Android apps, the obtained test cases seldom include the interactions and the checks necessary to exercise and reveal data loss faults. To address this problem, this paper presents Data Loss Detector (DLD), a test case generation technique that integrates an exploration strategy, data-loss-revealing actions, and two customized oracle strategies for the detection of data loss failures. DLD revealed 75% of the faults in a benchmark of 54 Android app releases affected by 110 known data loss faults, and also revealed unknown data loss problems, outperforming competing approaches. Oliviero Riganelli, Simone Paolo Mottadelli, Claudio Rota, Daniela Micucci, Leonardo Mariani |
ISSTA | 4 |
| 2020 | FILO: FIx-LOcus Localization for Backward Incompatibilities Caused by Android Framework UpgradesabstractMobile operating systems evolve quickly, frequently updating the APIs that app developers use to build their apps. Unfortunately, API updates do not always guarantee backward compatibility, causing apps to not longer work properly or even crash when running with an updated system. This paper presents FILO, a tool that assists Android developers in resolving backward compatibility issues introduced by API upgrades. FILO both suggests the method that needs to be modified in the app in order to adapt the app to an upgraded API, and reports key symptoms observed in the failed execution to facilitate the fixing activity. Results obtained with the analysis of 12 actual upgrade problems and the feedback produced by early tool adopters show that FILO can practically support Android developers. FILO can be downloaded from https://gitlab.com/learnERC/filo, and its video demonstration is available at https://youtu.be/WDvkKj-wnlQ. Marco Mobilio, Oliviero Riganelli, Daniela Micucci, Leonardo Mariani |
ASE | 3 |
| 2020 | Test4Enforcers: Test Case Generation for Software Enforcers
Michell Guzmán, Oliviero Riganelli, Daniela Micucci, Leonardo Mariani |
RV | 3 |
| 2020 | In-the-field monitoring of functional calls: Is it feasible?
Oscar Cornejo 0001, Daniela Briola, Daniela Micucci, Leonardo Mariani |
J. Syst. Softw. | 3 |
| 2019 | FILO: FIx-LOcus Recommendation for Problems Caused by Android Framework UpgradeabstractDealing with the evolution of operating systems is challenging for developers of mobile apps, who have to deal with frequent upgrades that often include backward incompatible changes of the underlying API framework. As a consequence of framework upgrades, apps may show misbehaviours and unexpected crashes once executed within an evolved environment. Identifying the portion of the app that must be modified to correctly execute on a newly released operating system can be challenging. Although incompatibilities are visibile at the level of the interactions between the app and its execution environment, the actual methods to be changed are often located in classes that do not directly interact with any external element. To facilitate debugging activities for problems introduced by backward incompatible upgrades of the operating system, this paper presents FILO, a technique that can recommend the method that must be changed to implement the fix from the analysis of a single failing execution. FILO can also select key symptomatic anomalous events that can help the developer understanding the reason of the failure and facilitate the implementation of the fix. Our evaluation with multiple known compatibility problems introduced by Android upgrades shows that FILO can effectively and efficiently identify the faulty methods in the apps. Marco Mobilio, Oliviero Riganelli, Daniela Micucci, Leonardo Mariani |
ISSRE | 3 |
| 2019 | A benchmark of data loss bugs for Android appsabstractAndroid apps must be able to deal with both stop events, which require immediately stopping the execution of the app without losing state information, and start events, which require resuming the execution of the app at the same point it was stopped. Support to these kinds of events must be explicitly implemented by developers who unfortunately often fail to implement the proper logic for saving and restoring the state of an app. As a consequence apps can lose data when moved to background and then back to foreground (e.g., to answer a call) or when the screen is simply rotated. These faults can be the cause of annoying usability issues and unexpected crashes. This paper presents a public benchmark of 110 data loss faults in Android apps that we systematically collected to facilitate research and experimentation with these problems. The benchmark is available on GitLab and includes the faulty apps, the fixed apps (when available), the test cases to automatically reproduce the problems, and additional information that may help researchers in their tasks. Oliviero Riganelli, Marco Mobilio, Daniela Micucci, Leonardo Mariani |
MSR | 3 |
| 2019 | On the Homogenization of Heterogeneous Inertial-Based Databases for Human Activity RecognitionabstractIn the last years supervised machine learning techniques are largely employed for automatic Human Activity Recognition (HAR) using inertial sensors, such as accelerometer and gyroscope. HAR has many applications in several domains such as, for example, healthcare, sport, and entertainment. Machine learning scientists made available to the community a plenty of labeled databases for benchmarking that, unfortunately, are not consistent, both syntactically (e.g., different sampling frequency) and semantically (e.g., labels with different meanings). Commonly, due to this inconsistency, scientists evaluate their progress on individual databases separately, which corresponds to training and testing using the same database. Coherent merging of existing databases would enable: 1) evaluation of generalization capabilities of methods across databases; 2) use of deep learning techniques that, unlike traditional ones, require much more labeled data for the training process. Moreover, the growth in the daily use of wearable devices will produce a big amount of inertial data which, if not correctly labeled, cannot be efficiently exploited for the study of automatic HAR. In this paper we propose a semi-automatic procedure to coherently merge existing databases based on signal and word similarity. Preliminary experiments demonstrates the effectiveness of the proposed procedure. Anna Ferrari, Marco Mobilio, Daniela Micucci, Paolo Napoletano |
SERVICES | 3 |
| 2019 | A platform for P2P agent-based collaborative applicationsabstractSummary The operational environment can be a valuable source of information about the behavior of software applications and their usage context. Although a single instance of an application has limited evidence of the range of the possible behaviors and situations that might be experienced in the field, the collective knowledge composed by the evidence gathered by the many instances of a same application running in several diverse user environments (eg, a browser) might be an invaluable source of information. This information can be exploited by applications able to autonomously analyze how they behave in the field and adjust their behavior accordingly. Augmenting applications with the capability to collaborate and directly share information about their behavior is challenging because it requires the definition of a fully decentralized and dependable networked infrastructure whose nodes are the user machines. The nodes of the infrastructure must be collaborative, to share information, and autonomous, to exploit the available information to change their behavior, for instance, to better accommodate the needs of the users to prevent known problems. This paper describes the initial results that we obtained with the design and the development of an infrastructure that can enable the execution of collaborative scenarios in a fully decentralized way. Our idea is to combine the agent‐based paradigm, which is well suited to design collaborative and autonomous nodes, and the peer‐to‐peer paradigm, which is well suited to design distributed and dynamic network infrastructures. To demonstrate our idea, we augmented the popular JADE agent‐based platform with a software layer that supports both the creation of a fully decentralized peer‐to‐peer network of JADE platforms and the execution of services within that network, thus enabling JADE multiagent systems (MASs) to behave as peer‐to‐peer networks. The resulting platform can be used to study the design of collaborative applications running in the field. Daniela Briola, Daniela Micucci, Leonardo Mariani |
Softw. Pract. Exp. | 2 |
| 2019 | From source code to test cases: A comprehensive benchmark for resource leak detection in Android appsabstractAndroid apps share resources, such as sensors, cameras, and Global Positioning System, that are subject to specific usage policies whose correct implementation is left to programmers. Failing to satisfy these policies may cause resource leaks, that is, apps may acquire but never release resources. This might have different kinds of consequences, such as apps that are unable to use resources or resources that are unnecessarily active wasting battery. Researchers have proposed several techniques to detect and fix resource leaks. However, the unavailability of public benchmarks of faulty apps makes comparison between techniques difficult, if not impossible, and forces researchers to build their own data set to verify the effectiveness of their techniques (thus, making their work burdensome). The aim of our work is to define a public benchmark of Android apps affected by resource leaks. The resulting benchmark, called AppLeak, is publicly available on GitLab and includes faulty apps, versions with bug fixes (when available), test cases to automatically reproduce the leaks, and additional information that may help researchers in their tasks. Overall, the benchmark includes a body of 40 faults that can be exploited to evaluate and compare both static and dynamic analysis techniques for resource leak detection. Oliviero Riganelli, Daniela Micucci, Leonardo Mariani |
Softw. Pract. Exp. | 2 |
| 2019 | Controlling Interactions with Libraries in Android Apps Through Runtime EnforcementabstractAndroid applications are executed on smartphones equipped with a variety of resources that must be properly accessed and controlled, otherwise the correctness of the executions and the stability of the entire environment might be negatively affected. For example, apps must properly acquire, use, and release microphones, cameras, and other multimedia devices, otherwise the behavior of the apps that use the same resources might be compromised. Unfortunately, several apps do not use resources correctly, for instance, due to faults and inaccurate design decisions. By interacting with these apps, users may experience unexpected behaviors, which in turn may cause instability and sporadic failures, especially when resources are accessed. In this article, we present an approach that lets users protect their environment from the apps that use resources improperly by enforcing the correct usage protocol. This is achieved by using software enforcers that can observe executions and change them when necessary. For instance, enforcers can detect that a resource has been acquired but not released and automatically perform the release operation, thus giving the possibility to use that same resource to the other apps. The main idea is that software libraries, in particular, the ones controlling access to resources, can be augmented with enforcers that can be activated and deactivated on demand by users to protect their environment from unwanted app behaviors. We call the software libraries augmented with one or more enforcers proactive libraries , because the activation of the enforcer decorates the library with proactive behaviors that can guarantee the correctness of the execution despite the invocation of the operations implemented by the library. For example, enforcers can detect that a resource has not been released on time and proactively release it. Our experimental results with 27 possible misuses of resources in real Android apps reveal that proactive libraries are able to effectively correct library misuses with negligible runtime overheads. Oliviero Riganelli, Daniela Micucci, Leonardo Mariani |
ACM Trans. Auton. Adapt. Syst. | 2 |
| 2019 | Automatic Software Repair: A SurveyabstractDespite their growing complexity and increasing size, modern software applications must satisfy strict release requirements that impose short bug fixing and maintenance cycles, putting significant pressure on developers who are responsible for timely producing high-quality software. To reduce developers workload, repairing and healing techniques have been extensively investigated as solutions for efficiently repairing and maintaining software in the last few years. In particular, repairing solutions have been able to automatically produce useful fixes for several classes of bugs that might be present in software programs. A range of algorithms, techniques, and heuristics have been integrated, experimented, and studied, producing a heterogeneous and articulated research framework where automatic repair techniques are proliferating. This paper organizes the knowledge in the area by surveying a body of 108 papers about automatic software repair techniques, illustrating the algorithms and the approaches, comparing them on representative examples, and discussing the open challenges and the empirical evidence reported so far. Luca Gazzola, Daniela Micucci, Leonardo Mariani |
IEEE Trans. Software Eng. | 2 |
| 2018 | Automatic software repair: a surveyabstractDebugging software failures is still a painful, time consuming, and expensive process. For instance, recent studies showed that debugging activities often account for about 50% of the overall development cost of software products [3]. There are many factors contributing to the cost of debugging, but the most impacting one is the extensive manual effort that is still required to identify and remove faults. So far, the automation of debugging activities essentially resulted in the development of techniques that provide useful insights about the possible locations of faults, the inputs and states of the application responsible for the failures, as well as the anomalous operations executed during failures. However, developers must still put a relevant effort on the analysis of the failed executions to exactly identify the faults that must be fixed. In addition, these techniques do not help the developers with the synthesis of an appropriate fix. Luca Gazzola, Daniela Micucci, Leonardo Mariani |
ICSE | 2 |
| 2018 | Increasing the Reusability of Enforcers with Lifecycle Events
Oliviero Riganelli, Daniela Micucci, Leonardo Mariani |
ISoLA (4) | 2 |
| 2017 | Timed k-Tail: Automatic Inference of Timed AutomataabstractAccurate and up-to-date models describing the behavior of software systems are seldom available in practice. To address this issue, software engineers may use specification mining techniques, which can automatically derive models that capture the behavior of the system under analysis. So far, most specification mining techniques focused on the functional behavior of the systems, with specific emphasis on models that represent the ordering of operations, such as temporal rules and finite state models. Although useful, these models are inherently partial. For instance, they miss the timing behavior, which is extremely relevant for many classes of systems and components, such as shared libraries and user-driven applications. Mining specifications that include both the functional and the timing aspects can improve the applicability of many testing and analysis solutions. This paper addresses this challenge by presenting the Timed k-Tail (TkT) specification mining technique that can mine timed automata from program traces. Since timed automata can effectively represent the interplay between the functional and the timing behavior of a system, TkT could be exploited in those contexts where time-related information is relevant. Our empirical evaluation shows that TkT can efficiently and effectively mine accurate models. The mined models have been used to identify executions with anomalous timing. The evaluation shows that most of the anomalous executions have been correctly identified while producing few false positives. Fabrizio Pastore, Daniela Micucci, Leonardo Mariani |
ICST | 2 |
| 2017 | Verifying Policy Enforcers
Oliviero Riganelli, Daniela Micucci, Leonardo Mariani, Yliès Falcone |
RV | 2 |
| 2017 | BDCI: behavioral driven conflict identificationabstractSource Code Management (SCM) systems support software evolution by providing features, such as version control, branching, and conflict detection. Despite the presence of these features, support to parallel software development is often limited. SCM systems can only address a subset of the conflicts that might be introduced by developers when concurrently working on multiple parallel branches. In fact, SCM systems can detect textual conflicts, which are generated by the concurrent modification of the same program locations, but they are unable to detect higher-order conflicts, which are generated by the concurrent modification of different program locations that generate program misbehaviors once merged. Higher-order conflicts are painful to detect and expensive to fix because they might be originated by the interference of apparently unrelated changes. Fabrizio Pastore, Leonardo Mariani, Daniela Micucci |
ESEC/SIGSOFT FSE | 3 |
| 2013 | A Layered Architecture based on Previsional MechanismsabstractThe paper presents a layered architecture that improves software modularity and reduces computational and communication overhead for systems requiring data from sensors in order to perform domain-related elaborations (e.g., tracking and surveillance systems). Each layer manages hypotheses that are abductions related to objects modeling the ”real world” at a specific abstraction level, from raw data up to domain concepts. Each layer, by analyzing hypotheses coming from the lower layer, abduces new hypotheses regarding objects at a higher level of abstraction (e.g., from image blobs to identified people) and formulates timed previsions about objects. The failure of a prevision causes a hypothesis to flow up-stream. In turn, previsions can flow downstream, so that their verification is delegated to the lower layers. The proposed architectural patterns have been reified in a Java framework, which is being exploited in an experimental multi-camera tracking system. Francesco Fiamberti, Daniela Micucci, Marco Mobilio, Francesco Tisato |
ICSOFT | 2 |
| 2012 | AuDeNTES: Automatic Detection of teNtative plagiarism according to a rEference SolutionabstractIn academic courses, students frequently take advantage of someone else’s work to improve their own evaluations or grades. This unethical behavior seriously threatens the integrity of the academic system, and teachers invest substantial effort in preventing and recognizing plagiarism. When students take examinations requiring the production of computer programs, plagiarism detection can be semiautomated using analysis techniques such as JPlag and Moss. These techniques are useful but lose effectiveness when the text of the exam suggests some of the elements that should be structurally part of the solution. A loss of effectiveness is caused by the many common parts that are shared between programs due to the suggestions in the text of the exam rather than plagiarism. In this article, we present the AuDeNTES anti-plagiarism technique. AuDeNTES detects plagiarism via the code fragments that better represent the individual students’ contributions by filtering from students’ submissions the parts that might be common to many students due to the suggestions in the text of the exam. The filtered parts are identified by comparing students’ submissions against a reference solution, which is a solution of the exam developed by the teachers. Specifically, AuDeNTES first produces tokenized versions of both the reference solution and the programs that must be analyzed. Then, AuDeNTES removes from the tokenized programs the tokens that are included in the tokenized reference solution. Finally, AuDeNTES computes the similarity among the filtered tokenized programs and produces a ranked list of program pairs suspected of plagiarism. An empirical comparison against multiple state-of-the-art plagiarism detection techniques using several sets of real students’ programs collected in early programming courses demonstrated that AuDeNTES identifies more plagiarism cases than the other techniques at the cost of a small additional inspection effort. Leonardo Mariani, Daniela Micucci |
ACM Trans. Comput. Educ. | 2 |
| 2012 | Grounding ecologies on multiple spaces
Francesco Tisato, Carla Simone, Diego Bernini, Marco P. Locatelli, Daniela Micucci |
Pervasive Mob. Comput. | 5 |
| 2011 | An architecture for time-aware systemsabstractThe paper presents a set of architectural abstractions that allow time-related aspects to be explicitly treated as first-class programming concepts at the application level. Both the temporal behavior of an application and the way it deals with information placed in a temporal context can be modeled by means of such abstractions, thus narrowing the semantic gap between specification and implementation. The paper introduces the abstractions by means of a simplified reference problem and presents the validation of a concrete implementation. Francesco Fiamberti, Daniela Micucci, Francesco Tisato |
ETFA | 2 |
| 2010 | A platform for interoperability via multiple spatial views in open smart spacesabstractThe paper presents an integration platform for space-based interoperability among heterogeneous components in open smart spaces. The key idea is to rely on multiple spaces, be they physical or logical, and on mappings among spaces. Components publish their information on one or more spatial publication contexts, whereas they make subscriptions to one or more spatial subscription contexts. Information is delivered whenever a non-empty intersection among publication and subscription contexts is recognized according to the space mappings. The platform defines basic space models that can be specialized to model domain-specific spaces. The paper presents the basic platform mechanisms and their application in a sample scenario, discusses the benefits of the approach and compares it to significant related works. Diego Bernini, Daniela Micucci, Francesco Tisato |
ISCC | 2 |
| 2010 | Space integration services: a platform for space-aware communicationabstractThe paper presents a platform aimed at supporting space-aware communications in emergency situations. The key idea is to rely on multiple spaces, be they physical or logical, and on mappings among spaces. Thematic information is published in one or more spatial publication contexts, whereas subscribers specify one or more spatial subscription contexts. Information is delivered whenever a non-empty intersection among publication and subscription contexts is recognized according to the space mappings. The platform defines basic space models that can be specialized to model domain-specific spaces. The paper overviews the basic platform mechanisms, sketches their exploitation in a concrete scenario and briefly discusses related works. Diego Bernini, Daniela Micucci, Francesco Tisato |
IWCMC | 2 |
| 2010 | A uniform approach to communication and computationabstractThe paper presents a uniform approach to computing and communication, which seems well-suited to dynamically handle information flows in an emergency management system and overcomes the drawbacks of layered architectures. The overall system is modelled as a computational graph consisting of components and connectors, which are recursively modelled as lower-level graphs. Micro-components, i.e., software modules which can be executed on a single computational node, are the basic building blocks. This paves the way to the design and implementation of adaptive systems where both introspective and domain information are treated in a uniform way to realize context-aware strategies supporting distributed computations and context-aware routing. Francesco Tisato, Daniela Micucci, Diego Bernini |
IWCMC | 2 |
| 2009 | How to localize domain entities: the case of a flooding prediction and risk management systemabstractEmergency management systems reason about contextualized information, i.e., domain entities which have a precise position in a space. Often, domain entities lie on different spaces, e.g., river basins on a geographical space and routes on a topological one. Sometimes the same domain entity lies on two or more different spaces, e.g., a rescue squad may be localized both in a geographical and in a competence space. In such a complex scenario, emerges the need of a general model to specify localized domain entities that preserves the separation between 'what' (domain entity) and 'where' (its location in a space) and that encapsulates the intrinsic structure of the space. The paper presents such a model which relies on a unified paradigm for the definition of spaces. The model has been reified in an exemplified scenario dealing with a flooding prediction and risk management system. Daniela Micucci |
IWCMC | 1 |
| 2005 | Real-time reasoning: the case of surveillance systemsabstractThe paper presents a layered architecture for real-time surveillance systems. Each layer includes objects that model the "real world" at a specific abstraction level, from raw data up to domain concepts. Each layer performs abstractions on perceptions coming from the lower layer and formulates timed hypotheses about domain objects. The failure of a hypothesis causes a perception to flow up-stream. In turn, hypotheses flow down-stream, so that their verification is delegated to the lower layers. The proposed architectural patterns have been reified in a Java framework, which has been used in an experimental multi-camera tracking system. Daniela Micucci, Marco Oldani, Francesco Tisato |
ETFA | 1 |
| 2005 | Network Services via Reflective Architecture
Marzia Adorni, Daniela Micucci, Francesco Tisato, Paolo Losi |
SEKE | 2 |
| 2004 | Time Sensitive Architectures: A Reflective ApproachabstractCurrent design approaches to time-sensitive systems do not provide a coherent architectural framework for "non-functional" time-related requirements. The paper proposes Temporal Reflection as the ability of a system to self-represent, observe and adapt its own temporal behaviour through suitable architectural abstractions. The paper provides the rationale for Temporal Reflection and introduces the related abstractions by exemplifying the design and the implementation of a video player. Daniela Micucci, Sergio Ruocco, Francesco Tisato, Andrea Trentini |
ISORC | 1 |
| 2003 | A Pattern-like Framework to Dynamically Change Components Behaviour
Daniela Micucci, Andrea Trentini |
SEKE | 1 |
| 2003 | An object-oriented software approach for a distributed human tracking motion system
Daniela Micucci |
VCIP | 1 |
| 2002 | Exploiting the kaleidoscope architecture in an industrial environmental monitoring system with heterogeneous devices and a knowledge-based supervisorabstractMonitoring and control systems deal with complicated issues such as integration of heterogeneous components and management of different acquisition devices. The paper introduces the Kaleidoscope reference architecture for monitoring and control systems and exemplifies how it supports these issues. The architecture has been exploited in an indoor environmental monitoring system named RAID (Rilevamento dati Ambientali con Interfaccia DECT). The system is based on innovative sensors and wireless communication. It includes a knowledge-based supervisor aimed at identifying pollutant sources. Finally, it handles the different operating modes supported by physical sensors: low consumption with battery, and high consumption with mains.The paper presents the abstract model for major RAID entities. Then it sketches how abstract entities are mapped into concrete representations. Finally focuses how sensor different operating mode is supported dynamically. Daniela Micucci |
SEKE | 1 |