Andrey Sadovykh

dblp:65/1566 · DBLP profile ↗
← Back
19ranked-venue papers
5as first author
10since 2021 · last 2025
0000-0003-2384-5447ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 12 · 5 first-author · 7 since 2021Systems, architecture and hardware · 5 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 2Security and privacy · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2025 Multi-Partner Project: A Model-Driven Engineering Framework for Federated Digital Twins of Industrial Systems (MATISSE)
abstract
Digital twins are virtual representations of real-world entities or systems. Their primary goal is to help organizations understand and predict the behaviour and properties of these entities or systems. Additionally, digital twins enhance activities such as monitoring, verification, validation, and testing. However, the inherent complexity of digital twins implies challenges throughout the systems engineering process. This notably includes design, development, and analysis phases, as well as deployment, execution, and maintenance. Moreover, existing approaches, methods, techniques, and tools for modelling, simulating, validating, and monitoring single digital twins must now address the increased complexity in federation scenarios. These scenarios introduce new challenges, such as digital twin identification, shared metadata, cross-digital twin communication and synchronization, and federation governance. The KDT Joint Undertaking MATISSE project tackles these challenges by aiming to provide a model-driven framework for the continuous engineering of federated digital twins. It leverages model-driven engineering techniques and practices as the core enabling technology, with traceability serving as an essential infrastructural service for the digital twins federation. In this paper, we introduce the MATISSE conceptual framework for digital twins, highlighting both the novelty of the project's concept and its technical objectives. As the project is still in its initial phase, we identify key research challenges relevant to the DATE community and propose a preliminary research roadmap. This roadmap addresses traceability and federation mechanisms, the required continuous engineering strategy, and the development of digital twin-based services for verification, validation, prediction, and monitoring. To illustrate our approach, we present two concrete scenarios that demonstrate practical applications of the MATISSE conceptual framework.
Alessio Bucaioni, Romina Eramo, Luca Berardinelli, Hugo Bruneliere, Benoît Combemale, Djamel Eddine Khelladi, Vittoriano Muttillo, Andrey Sadovykh, Manuel Wimmer
DATE8
2025 Automating Performance Testing in CI/CD - Tools Evaluation
Maxim Pinyagin, Andrey Sadovykh
ICTSS2
2025 Extracting Threats from System Descriptions with LLMs Comparing One and Two Agents Strategies
Leonid Zelenskiy, Andrey Sadovykh
ICTSS2
2024 An iterative approach for model-based requirements engineering in large collaborative projects: A detailed experience report
Andrey Sadovykh, Bilal Said, Dragos Truscan, Hugo Bruneliere
Sci. Comput. Program.1
2023 VeriDevOps Software Methodology: Security Verification and Validation for DevOps Practices
abstract
VeriDevOps offers a methodology and a set of integrated mechanisms that significantly improve automation in DevOps to protect systems at operations time and prevent security issues at development time by (1) specifying security requirements, (2) generating trace monitors, (3) locating root causes of vulnerabilities, and (4) identifying security flaws in code and designs. This paper presents a methodology that enhances productivity and enables the continuous integration/delivery of trustworthy systems. We outline the methodology, its application to relevant scenarios, and offer recommendations for engineers and managers adopting the VeriDevOps approach. Practitioners applying the VeriDevOps methodology should include security modeling in the DevOps process, integrate security verification throughout all stages, utilize automated test generation tools for security requirements, and implement a comprehensive security monitoring system, with regular review and update procedures to maintain relevance and effectiveness.
Eduard Paul Enoiu, Dragos Truscan, Andrey Sadovykh, Wissam Mallouli
ARES3
2023 Detecting Security Requirements in GitHub Issues -Novel Dataset and SmallBERT-based model
abstract
Cloud application security initiates with the analysis of security requirements in DevOps. This involves gathering, managing, and tracking requirements within integrated issue-tracking systems found in repositories like GitHub. DevOps offers advantages in cloud app development, such as accelerated deployment, improved collaboration, and enhanced reliability. In DevOps, while many security verification tools are automated, security requirements analysis often relies on manual procedures. User feedback plays a pivotal role in shaping cloud application requirements, and the industry actively seeks automation solutions to expedite development. Prior research has demonstrated the limited performance of conventional NLP models trained on established datasets, such as PROMISE, when employed in the context of GitHub Issues. Recent studies have explored the integration of deep learning, particularly leveraging modern large language models and transfer learning architectures, to address requirements engineering challenges. However, a significant issue persists - the transferability of these models. While these models excel when applied to datasets similar to those they were trained on, their performance often drastically falls when dealing with external domains.In our paper, we introduce an automated method for classifying requirements within issue trackers. This method utilizes a novel dataset comprising 12,000 security and non-security issues collected from open GitHub repositories. We employed a SmallBERT-based model for training and conducted a series of experiments. Our research reaffirms the challenge related to the transferability of NLP models. Simultaneously, our model yields highly promising results when applied to GitHub Issues, even in challenging scenarios involving issues from projects that were not part of the training dataset and structured requirements texts from the PROMISE dataset. In summary, our approach significantly contributes to enhancing DevOps practices within cloud applications by automating security requirements analysis.
Polina Minina, Andrey Sadovykh
CloudCom2
2023 RQCODE: Security Requirements Formalization with Testing
Ildar Nigmatullin, Andrey Sadovykh, Sophie Ebersold, Nan Messe
ICTSS2
2021 VeriDevOps: Automated Protection and Prevention to Meet Security Requirements in DevOps
abstract
Current software development practices are increasingly based on using both COTS and legacy components which make such systems prone to security vulnerabilities. The modern practice addressing ever changing conditions, DevOps, promotes frequent software deliveries, however, verification methods artifacts should be updated in a timely fashion to cope with the pace of the process. VeriDevOps, Horizon 2020 project, aims at providing a faster feedback loop for verifying the security requirements and other quality attributes of large scale cyber-physical systems. VeriDevOps focuses on optimizing the security verification activities, by automatically creating verifiable models directly from security requirements formulated in natural language, using these models to check security properties on design models and then generating artefacts such as, tests or monitors that can be used later in the DevOps process. The main drivers for these advances are: Natural Language Processing, a combined formal verification and model-based testing approach, and machine-learning-based security monitors. VeriDevOps is in its initial stage - the project started on 1.10.2020 and it will run for three years. In this paper we will present the major conceptual ideas behind the project approach as well as the organizational settings.
Andrey Sadovykh, Gunnar Widforss, Dragos Truscan, Eduard Paul Enoiu, Wissam Mallouli, Rosa Iglesias, Alessandra Bagnato, Olga Hendel
DATE1
2021 AIDOaRt: AI-augmented Automation for DevOps, a Model-based Framework for Continuous Development in Cyber-Physical Systems
abstract
With the emergence of Cyber-Physical Systems (CPS), the increasing complexity in development and operation demands for an efficient engineering process. In the recent years DevOps promotes closer continuous integration of system development and its operational deployment perspectives. In this context, the use of Artificial Intelligence (AI) is beneficial to improve the system design and integration activities, however, it is still limited despite its high potential. AIDOaRT is a 3 years long H2020-ECSEL European project involving 32 organizations, grouped in clusters from 7 different countries, focusing on AI-augmented automation supporting modelling, coding, testing, monitoring and continuous development of Cyber-Physical Systems (CPS). The project proposes to apply Model-Driven Engineering (MDE) principles and techniques to provide a framework offering proper AI-enhanced methods and related tooling for building trustable CPSs. The framework is intended to work within the DevOps practices combining software development and information technology (IT) operations. In this regard, the project points at enabling AI for IT operations (AIOps) to auto-mate decision making process and complete system development tasks. This paper presents an overview of the project with the aim to discuss context, objectives and the proposed approach.
Romina Eramo, Vittoriano Muttillo, Luca Berardinelli, Hugo Bruneliere, Abel Gómez 0001, Alessandra Bagnato, Andrey Sadovykh, Antonio Cicchetti
DSD7
2021 Applying Model-based Requirements Engineering in Three Large European Collaborative Projects: An Experience Report
abstract
In this paper, we report on our 5-year’s practical experience of designing, developing and then deploying a Model-based Requirements Engineering (MBRE) approach and language in the context of three different large European collaborative projects providing complex software solutions. Based on data collected both during projects execution and via a survey realized afterwards, we intend to show that such an approach can bring interesting benefits in terms of scalability (e.g., large number of handled requirements), heterogeneity (e.g., partners with different types of RE background), traceability (e.g. from the requirements to the software components), automation (e.g., requirement documentation generation), usefulness or usability. To illustrate our contribution, we exemplify the application of our MBRE approach and language with concrete elements coming from one of these European research projects. We also discuss further the general benefits and current limitations of using this MBRE approach and corresponding language.
Andrey Sadovykh, Dragos Truscan, Hugo Bruneliere
RE1
2019 On the Use of Hackathons to Enhance Collaboration in Large Collaborative Projects : - A Preliminary Case Study of the MegaM@Rt2 EU Project -
abstract
In this paper, we present the MegaM@Rt2 ECSEL project and discuss in details our approach for fostering collaboration in this project. We choose to use an internal hackathon approach that focuses on technical collaboration between case study owners and tool/method providers. The novelty of the approach is that we organize the technical workshop at our regular project progress meetings as a challenge-based contest involving all partners in the project. Case study partners submit their challenges related to the project goals and their use cases in advance. These challenges are concise enough to be experimented within approximately 4 hours. Teams are then formed to address those challenges. The teams include tool/method providers, case study owners and researchers/developers from other consortium members. On the hackathon day, partners work together to come with results addressing the challenges that are both interesting to encourage collaboration and convincing to continue further deeper investigations. Obtained results demonstrate that the hackathon approach stimulated knowledge exchanges among project partners and triggered new collaborations, notably between tool providers and use case owners.
Andrey Sadovykh, Dragos Truscan, Pierluigi Pierini, Gunnar Widforss, Adnan Ashraf, Hugo Bruneliere, Pavel Smrz, Alessandra Bagnato, Wasif Afzal, Alexandra Espinosa Hortelano
DATE1
2019 Showcasing Modelio and pure: variants Integration in REVaMP^2 Project
Alessandra Bagnato, Alexandre Beaufays, Etienne Brosse, Kaïs Chaabouni, Uwe Ryssel, Michael Schulze, Andrey Sadovykh
PROFES7
2018 Sensor-based Database with SensLog: A Case Study of SQL to NoSQL Migration
Prasoon Dadhich, Andrey Sadovykh, Alessandra Bagnato, Michal Kepka, Ondrej Kaas, Karel Charvát
DATA2
2018 1st intl. workshop on variability and evolution of software-intensive systems (varivolution)
abstract
Modern software systems are subject to continuous change and often need to exist in many variants addressing different requirements. Yet, software versions resulting from evolution in time (aka revisions) and variants resulting from evolution in space are managed radically differently, but none of the traditional technologies have been successful in effectively supporting unified revision and variant management in practice.
Lukas Linsbauer, Somayeh Malakuti, Andrey Sadovykh, Felix Schwägerl
SPLC3
2017 The MegaM@Rt2 ECSEL Project: MegaModelling at Runtime - Scalable Model-Based Framework for Continuous Development and Runtime Validation of Complex Systems
abstract
A major challenge for the European electronic industry is to enhance productivity while reducing costs and ensuring quality in development, integration and maintenance. Model-Driven Engineering (MDE) principles and techniques have already shown promising capabilities but still need to scale to support real-world scenarios implied by the full deployment and use of complex electronic components and systems. Moreover, maintaining efficient traceability, integration and communication between two fundamental system life-time phases (design time and runtime) is another challenge facing scalability of MDE. This paper presents an overview of the ECSEL project entitled "MegaModelling at runtime -- Scalable model-based framework for continuous development and runtime validation of complex systems" (MegaM@Rt2), whose aim is to address the above mentioned challenges facing MDE. Driven by both large and small industrial enterprises, with the support of research partners and technology providers, MegaM@Rt2 aims to deliver a framework of tools and methods for: 1) system engineering/design & continuous development, 2) related runtime analysis and 3) global model & traceability management, respectively. The diverse industrial use cases (covering domains such as aeronautics, railway, construction and telecommunications) will integrate and apply such a framework that shall demonstrate the validation of the MegaM@Rt2 solution.
Wasif Afzal, Hugo Bruneliere, Davide Di Ruscio, Andrey Sadovykh, Silvia Mazzini, Eric Cariou, Dragos Truscan, Jordi Cabot, Daniel Field, Luigi Pomante, Pavel Smrz
DSD4
2014 Multi-cloud and Multi-data Stores - The Challenges Behind Heterogeneous Data Models
abstract
The support to cloud enabled databases varies from one cloud provider to another. Developers face the task of supporting applications living in different clouds, and therefore of supporting different database management systems. To them, the challenge lies in understanding the differences in expressivity between different data stores and their impact on the application. The advent of the NoSQL movement increased the complexity of this task by leveraging the creation of a large number of cloud enabled database management systems employing slightly different data models. In this paper, we will present a model the will allow us to compare the differences in expressivity of the features supported by different databases and consider the impact of these features to different concrete deployment scenarios in multiple clouds. This model is based on the underlying data models adopted by the most used cloud database management systems. It has been developed on the FP7 XXX project and will be the basis of our approach for dealing with these issues.
Marcos Aurélio Almeida da Silva, Andrey Sadovykh
CLOSER2
2011 Specifying Services using the Service Oriented Architecture Modeling Language (SoaML) - A Baseline for Specification of Cloud-based Services
Brian Elvesæter, Arne-Jørgen Berre, Andrey Sadovykh
CLOSER3
2010 WebMov: A Dedicated Framework for the Modelling and Testing of Web Services Composition
abstract
This paper presents a methodology and a set of tools for the modelling, validation and testing of Web service composition, conceived and developed within the French national project WebMov. This methodology includes several modelling techniques, based mainly on some variations of Timed Extended Finite State Machines (TEFSM) formalism, which provide a formal model of the BPEL description of Web services composition. These models are used as a reference for the application of different test generation and passive testing techniques for conformance and robustness checking. The whole WebMov methodology is integrated within a dedicated framework, composed by a set of tools that implement the model representation, the test generation and passive testing algorithms. This framework also permits the interaction of these tools to achieve specific modelling and testing activities in a complementary way. A case study based on a real service, a Travel Reservation Web Service, is presented as well as the results of the application of the proposed WebMov methodology and tools.
Ana R. Cavalli, Tien-Dung Cao, Wissam Mallouli, Eliane Martins, Andrey Sadovykh, Sébastien Salva, Fatiha Zaïdi
ICWS5
2009 Architecture Driven Modernization in Practice - Study Results
abstract
The European Space Agency (ESA) as many other companies is interested in capitalizing its business assets. With the space programmes often lasting 10 to 20 years, the software system migration problems arise frequently. The Object Management Group promotes the model driven architecture (MDA) concept and proposes the architecture driven modernization (ADM) approach for model-based platform migration. SOFTEAM, Fraunhofer FOKUS and GTI6 performed an ESA-funded study on round trip engineering for space systems. During this study the state-of-the-art methods and tools for ADM and MDA were combined with state-of-the-art model based testing (MBT) approaches to safeguard the modernization process. Both techniques were assessed by applying them to a real-life use case - the migration and testing of a distributed archive and versioning system. In this article we overview the combined platform migration and testing methodology used in the project and summarize our experience during its application to the ESApsilas File Archive System. We specially focus on real life experience with MBT and discuss lessons learned.
Andrey Sadovykh, Lionel Vigier, Andreas Hoffmann 0001, Jürgen Großmann, Tom Ritter, Eduardo Gomez, Oleg Estekhin
ICECCS1