VLDB 2026 Research / reviewers in the wild / expert
André Luíz de Oliveira
dblp:57/4649
· DBLP profile ↗
8ranked-venue papers
2as first author
6since 2021 · last 2025
0000-0003-0564-0034ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 4 · 2 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Model-Based Security Assurance Cases for Open and Adaptive Cyber-Physical Systems
Luís Nascimento, André Luíz de Oliveira, Regina Braga 0001, Edelberto Franco Silva, Richard Hawkins 0001, Tim Kelly |
AINA (8) | 2 |
| 2025 | Integrating Attack-Fault Trees in the ODE Metamodel to Support Safety and Security Co-Analysis in the Automotive DomainabstractIntegrating safety and security in automotive cyber-physical systems (CPS) domains (e.g. autonomous vehicles), is challenging for two main reasons. First, it is still difficult to represent the potential consequences of system failures or malicious attacks. Secondly, these systems must ensure safety and security despite unknowns and uncertainties. A Digital Dependability Identity (DDI) can facilitate this by encapsulating all dependability characteristics (e.g., design, requirements, safety, and security analysis models) of CPS’s components. The Open Dependability Exchange (ODE) metamodel is an implementation of the DDI concept, but has limitations in the interplay between safety and security. ODE is aligned with with ISO 26262 but lacks certain security concepts to be aligned with ISO 21434. Also, ODE supports modeling fault trees, but modeling attack trees and attack-fault trees still not. This paper proposes an extension to the ODE metamodel, aiming to increase coverage of ISO 21434 concepts and allowing the modeling of attack-fault trees. We built these metamodel extensions based on an analysis of the ODE metamodel, industry standards, Microsoft STRIDE model, and HEAVENS security analysis methodologies. We evaluated the proposed extensions in an illustrative example of an autonomous vehicle. Victor Luiz Grechi, André Luíz de Oliveira, Barbara Gallina, Leonardo Montecchi, Rosana T. V. Braga |
COMPSAC | 2 |
| 2025 | Usability Evaluation of e-Sinais Educational Software
Quézia M. Filadelfo, Efânio Jeferson A. de Oliveira, Daniela G. da Silveira Freitas, Pablo Freire Matos, Marcelo Meira Alves, André Luíz de Oliveira |
INTERACT (4) | 6 |
| 2025 | Model-driven safety and security co-analysis: A systematic literature reviewabstractFailures in systems that can lead to loss of life, property, and environmental damage, make them safety–critical systems requiring the analysis and demonstration of dependability properties. When those systems can connect/disconnect to each other, it raises security issues, making them also security-critical. Safety and security are crucial in safety- and security-critical design. The complexity of a connected world impacts safety and security, requiring dependability assurance processes in compliance with standards like ISO 26262, ISO 21434, IEC 61511, and IEC 61508. Model-Driven Engineering (MDE) plays a significant role by using models to represent and analyze safety and security properties, facilitating their integration. This study aims to explore the role of MDE in supporting safety and security co-engineering through a Systematic Literature Review. We identified 119 studies that were analyzed and categorized based on the life-cycle phase, risk assessment activity, application domain, methodology type (integrated or unified), methodology goal (co-engineering or cross-fertilization), measurement (qualitative, quantitative, or both), modeling approach, representation, evaluation method, and supporting tools. Though model-driven contributions are less prevalent than model-based ones, tools widely support them. Studies primarily focus on transportation (especially automotive) and industrial domains, but there is potential for broader participation with increasing IoT adoption. Editor’s note: Open Science material was validated by the Journal of Systems and Software Open Science Board . Victor Luiz Grechi, André Luíz de Oliveira, Rosana T. V. Braga |
J. Syst. Softw. | 2 |
| 2024 | From Fault Tree Analysis to Runtime Model-Based Assurance Cases
Luís Nascimento, André Luíz de Oliveira, Regina Braga 0001, Richard Hawkins 0001, Tim Kelly |
AINA (2) | 2 |
| 2023 | Runtime Model-Based Assurance of Open and Adaptive Cyber-Physical Systems
Luís Nascimento, André Luíz de Oliveira, Regina Braga 0001, Richard Hawkins 0001, Tim Kelly |
AINA (1) | 2 |
| 2019 | Variability management in safety-critical systems design and dependability analysisabstractAbstract Safety‐critical systems are of paramount importance for many application domains, where safety properties are a key driver to engineer critical aspects and avoid system failures. For the benefits of large‐scale reuse, software product lines (SPL) have been adopted in critical systems industry. However, the integration of safety analysis in the SPL development process is nontrivial. Also, the different usage contexts of safety‐critical systems complicates component fault modeling tasks and the identification of potential hazards. In this light, better methods become necessary to estimate the impact of dependability properties during Hazard Analysis and Risk Assessment. Existing methods incorporating the analysis of safety properties in SPL are limited as they do not include hazard analysis and component fault modeling. In this paper, we present the novel DEPendable Software Product Line Engineering (DEPendable‐SPLE) approach, which extends traditional SPL processes to support the reuse of safety assets. We also present a detailed analysis of the impact of product and context features on the SPL design, safety analysis, and safety requirements. We applied DEPendable‐SPLE to a realistic case study from the aerospace domain to illustrate how to model and reuse safety properties. DEPendable‐SPLE reduced the effort of safety analysis for certifying system variants. André Luíz de Oliveira, Rosana T. V. Braga, Paulo César Masiero, David Parker 0002, Yiannis Papadopoulos, Ibrahim Habli, Tim Kelly |
J. Softw. Evol. Process. | 1 |
| 2018 | Variability Management in Safety-Critical Software Product Line Engineering
André Luíz de Oliveira, Rosana T. V. Braga, Paulo César Masiero, Yiannis Papadopoulos, Ibrahim Habli, Tim Kelly |
ICSR | 1 |