Alcino Cunha

dblp:65/603 · DBLP profile ↗
← Back
45ranked-venue papers
12as first author
16since 2021 · last 2026
0000-0002-2714-8027ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 35 · 11 first-author · 15 since 2021Theory of computation · 14 · 5 first-author · 7 since 2021Artificial intelligence and machine learning · 5 · 1 since 2021Systems, architecture and hardware · 3Computer networks · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 HyperLasso: Bounded Model Checking of ∀+∃>+-Liveness Hyperproperties
abstract
Abstract This paper presents the first symbolic bounded model checking technique capable of verifying $$\forall ^+\exists ^+$$ ∀ + ∃ + -liveness hyperproperties (expressed in HyperLTL) over arbitrary (non-terminating) reactive systems. Previous bounded procedures for HyperLTL handled only safety hyperproperties or arbitrary properties over terminating systems. We implement our technique as HyperLasso . Our evaluation results show that it consistently outperforms the explicit-state complete model checker AutoHyper (the only existing tool capable of automatically verifying this class of problems) at several complex bug-finding and synthesis problems.
Alcino Cunha, Hugo Pacheco 0001, Nuno Macedo 0001
CAV (1)1
2026 Validating Formal Specifications with LLM-Generated Test Cases
abstract
Abstract Validation is a central activity when developing formal specifications. Similarly to coding, a possible validation technique is to define upfront test cases or scenarios that a future specification should satisfy or not. Unfortunately, specifying such test cases is burdensome and error prone, which could cause users to skip this validation task. This paper reports the results of an empirical evaluation of using pre-trained large language models (LLMs) to automate the generation of test cases from natural language requirements. In particular, we focus on test cases for structural requirements of simple domain models formalized in the Alloy specification language. Our evaluation focuses on the state-of-the-art GPT-5 model, but results from other closed- and open-source LLMs are also reported. The results show that, in this context, GPT-5 is already quite effective at generating positive (and negative) test cases that are syntactically correct and that satisfy (or not) the given requirement, and that can detect many wrong specifications written by humans.
Alcino Cunha, Nuno Macedo 0001
FM (1)1
2024 Alloy Repair Hint Generation Based on Historical Data
abstract
Abstract Platforms to support novices learning to program are often accompanied by automated next-step hints that guide them towards correct solutions. Many of those approaches are data-driven, building on historical data to generate higher quality hints. Formal specifications are increasingly relevant in software engineering activities, but very little support exists to help novices while learning. Alloy is a formal specification language often used in courses on formal software development methods, and a platform—Alloy4Fun—has been proposed to support autonomous learning. While non-data-driven specification repair techniques have been proposed for Alloy that could be leveraged to generate next-step hints, no data-driven hint generation approach has been proposed so far. This paper presents the first data-driven hint generation technique for Alloy and its implementation as an extension to Alloy4Fun, being based on the data collected by that platform. This historical data is processed into graphs that capture past students’ progress while solving specification challenges. Hint generation can be customized with policies that take into consideration diverse factors, such as the popularity of paths in those graphs successfully traversed by previous students. Our evaluation shows that the performance of this new technique is competitive with non-data-driven repair techniques. To assess the quality of the hints, and help select the most appropriate hint generation policy, we conducted a survey with experienced Alloy instructors.
Ana Barros, Henrique Neto, Alcino Cunha, Nuno Macedo 0001, Ana C. R. Paiva
FM (2)3
2024 Alloy Goes Fuzzy
Alcino Cunha, Nuno Macedo 0001, José N. Oliveira
ABZ2
2024 Validating multiple variants of an automotive light system with Alloy 6
abstract
Abstract This paper reports on the development and validation of a formal model for an automotive adaptive exterior lights system (ELS) with multiple variants in 6, which is the most recent version of the lightweight formal specification language that supports mutable relations and temporal logic. We explore different strategies to address variability, one in pure and another through an annotative language extension. We then show how and its can be used to validate systems of this nature, namely by checking that the reference scenarios are admissible, and to automatically verify whether the established requirements hold. A prototype was developed to translate the provided validation sequences into and back to further automate the validation process. The resulting ELS model was validated against the provided validation sequences and verified for most of requirements for all variants.
Alcino Cunha, Nuno Macedo 0001
Int. J. Softw. Tools Technol. Transf.1
2023 An Experimental Evaluation of Tools for Grading Concurrent Programming Exercises
Manuel Barros, Maria Ramos, Alexandre Gomes, Alcino Cunha, José Pereira 0001, Paulo Sérgio Almeida
FORTE4
2023 Adding Records to Alloy
Julien Brunel, David Chemouil, Alcino Cunha, Nuno Macedo 0001
ABZ3
2023 Task Model Design and Analysis with Alloy
Alcino Cunha, Nuno Macedo 0001, Eunsuk Kang
ABZ1
2023 Verifying Temporal Relational Models with Pardinus
Nuno Macedo 0001, Julien Brunel, David Chemouil, Alcino Cunha
ABZ4
2022 Schema-guided Testing of Message-oriented Systems
abstract
Effective testing of message-oriented software requires describing the expected behaviour of the system and the causality relations between messages. This is often achieved with formal specifications based on temporal logics that require both first-order and metric temporal constructs - to specify constraints over data and real time. This paper proposes a technique to automatically generate tests for metric first-order temporal specifications that match well-understood specification patterns. Our approach takes in properties in a high-level specification language and identifies test schemas (strategies) that are likely to falsify the property. Schemas correspond to abstract classes of execution traces, that can be refined by introducing assumptions about the system. At the low level, concrete traces are successively produced for each schema using property-based testing principles. We instantiate this approach for a popular robotic middleware, ROS, and evaluate it on two systems, showing that schema-based test generation is effective for message-oriented software.
André Santos 0001, Alcino Cunha, Nuno Macedo 0001
ENASE2
2022 Verification of railway network models with EVEREST
abstract
Models - at different levels of abstraction and pertaining to different engineering views - are central in the design of railway networks, in particular signalling systems. The design of such systems must follow numerous strict rules, which may vary from project to project and require information from different views. This renders manual verification of railway networks costly and error-prone.
José M. Fonseca 0002, Rafael Costa, José Creissac Campos, Alcino Cunha, Nuno Macedo 0001, José N. Oliveira
MoDELS5
2022 Timely Specification Repair for Alloy 6
Jorge Cerqueira, Alcino Cunha, Nuno Macedo 0001
SEFM2
2022 Quantitative relational modelling with QAlloy
abstract
Alloy is a popular language and tool for formal software design. A key factor to this popularity is its relational logic, an elegant specification language with a minimal syntax and semantics. However, many software problems nowadays involve both structural and quantitative requirements, and Alloy's relational logic is not well suited to reason about the latter. This paper introduces QAlloy, an extension of Alloy with quantitative relations that add integer quantities to associations between domain elements. Having integers internalised in relations, instead of being explicit domain elements like in standard Alloy, allows quantitative requirements to be specified in QAlloy with a similar elegance to structural requirements, with the side-effect of providing basic dimensional analysis support via the type system. The QAlloy Analyzer also implements an SMT-based engine that enables quantities to be unbounded, thus avoiding many problems that may arise with the current bounded integer semantics of Alloy.
José N. Oliveira, Nuno Macedo 0001, Alcino Cunha
ESEC/SIGSOFT FSE4
2022 Pardinus: A Temporal Relational Model Finder
Nuno Macedo 0001, Julien Brunel, David Chemouil, Alcino Cunha
J. Autom. Reason.4
2022 Merging cloned Alloy models with colorful refactorings
abstract
Likewise to code, clone-and-own is a common way to create variants of a model, to explore the impact of different features while exploring the design of a software system. Previously, we have introduced Colorful Alloy, an extension of the popular Alloy language and toolkit to support feature-oriented design, where model elements can be annotated with feature expressions and further highlighted with different colors to ease understanding. In this paper we propose a catalog of refactoring laws for Colorful Alloy models, and show how they can be used to iteratively merge cloned Alloy models into a single feature-annotated colorful model, where the commonalities and differences between the different clones are easily perceived, and more efficient aggregated analyses can be performed. We then show how these refactorings can be composed in an automated merging strategy that can be used to migrate Alloy clones into a Colorful Alloy SPL in a single step. The paper extends a conference version [1] by formalizing the semantics and type system of the improved Colorful Alloy language, allowing the simplification of some rules and the evaluation of their soundness. Additional rules were added to the catalog, and the evaluation extended. The automated merging strategy is also novel.
Nuno Macedo 0001, Alcino Cunha
Sci. Comput. Program.3
2021 Experiences on teaching alloy with an automated assessment platform
Nuno Macedo 0001, Alcino Cunha, José Pereira 0004, Renato Carvalho, Ana C. R. Paiva, Miguel S. Ramalho, Daniel Castro Silva
Sci. Comput. Program.2
2020 Verification of system-wide safety properties of ROS applications
abstract
Robots are currently deployed in safety-critical domains but proper techniques to assess the functional safety of their software are yet to be adopted. This is particularly critical in ROS, where highly configurable robots are built by composing third-party modules. To promote adoption, we advocate the use of lightweight formal methods, automatic techniques with minimal user input and intuitive feedback. This paper proposes a technique to automatically verify system-wide safety properties of ROS-based applications at static time. It is based in the formalization of ROS architectural models and node behaviour in Electrum, over which system-wide specifications are subsequently model checked. To automate the analysis, it is deployed as a plug-in for HAROS, a framework for the assessment of ROS software quality aimed at the ROS community. The technique is evaluated in a real robot, AgRob V16, with positive results.
Renato Carvalho, Alcino Cunha, Nuno Macedo 0001, André Santos 0001
IROS2
2020 Validating the Hybrid ERTMS/ETCS Level 3 concept with Electrum
Alcino Cunha, Nuno Macedo 0001
Int. J. Softw. Tools Technol. Transf.1
2019 Simplifying the Analysis of Software Design Variants with a Colorful Alloy
Nuno Macedo 0001, Alcino Cunha
SETTA3
2018 The electrum analyzer: model checking relational first-order temporal specifications
abstract
This paper presents the Electrum Analyzer, a free-software tool to validate and perform model checking of Electrum specifications. Electrum is an extension of Alloy that enriches its relational logic with LTL operators, thus simplifying the specification of dynamic systems. The Analyzer supports both automatic bounded model checking, with an encoding into SAT, and unbounded model checking, with an encoding into SMV. Instance, or counter-example, traces are presented back to the user in a unified visualizer. Features to speed up model checking are offered, including a decomposed parallel solving strategy and the extraction of symbolic bounds.
Julien Brunel, David Chemouil, Alcino Cunha, Nuno Macedo 0001
ASE3
2018 Teaching how to program using automated assessment and functional glossy games (experience report)
abstract
Our department has long been an advocate of the functional-first school of programming and has been teaching Haskell as a first language in introductory programming course units for 20 years. Although the functional style is largely beneficial, it needs to be taught in an enthusiastic and captivating way to fight the unusually high computer science drop-out rates and appeal to a heterogeneous population of students. This paper reports our experience of restructuring, over the last 5 years, an introductory laboratory course unit that trains hands-on functional programming concepts and good software development practices. We have been using game programming to keep students motivated, and following a methodology that hinges on test-driven development and continuous bidirectional feedback . We summarise successes and missteps, and how we have learned from our experience to arrive at a model for comprehensive and interactive functional game programming assignments and a general functionally-powered automated assessment platform , that together provide a more engaging learning experience for students. In our experience, we have been able to teach increasingly more advanced functional programming concepts while improving student engagement.
José Bacelar Almeida, Alcino Cunha, Nuno Macedo 0001, Hugo Pacheco 0001, José Proença
Proc. ACM Program. Lang.2
2017 Exploiting Partial Knowledge for Efficient Model Analysis
Nuno Macedo 0001, Alcino Cunha, Eduardo Pessoa
ATVA2
2017 Mining the usage patterns of ROS primitives
abstract
The Robot Operating System (ROS) is nowadays one of the most popular frameworks for developing robotic applications. To ensure the (much needed) dependability and safety of such applications we forecast an increasing demand for ROS-specific coding standards, static analyzers, and tools alike. Unfortunately, the development of such standards and tools can be hampered by ROS modularity and configurability, namely the substantial number of primitives (and respective variants) that must, in principle, be considered. To quantify the severity of this problem, we have mined a large number of existing ROS packages to understand how its primitives are used in practice, and to determine which combinations of primitives are most popular. This paper presents and discusses the results of this study, and hopefully provides some guidance for future standardization efforts and tool developers.
André Santos 0001, Alcino Cunha, Nuno Macedo 0001, Rafael Arrais, Filipe Neves dos Santos
IROS2
2017 A Feature-Based Classification of Model Repair Approaches
abstract
Consistency management, the ability to detect, diagnose and handle inconsistencies, is crucial during the development process in Model-driven Engineering (MDE). As the popularity and application scenarios of MDE expanded, a variety of different techniques were proposed to address these tasks in specific contexts. Of the various stages of consistency management, this work focuses on inconsistency handling in MDE, particularly in model repair techniques. This paper proposes a feature-based classification system for model repair techniques, based on an systematic literature review of the area. We expect this work to assist developers and researchers from different disciplines in comparing their work under a unifying framework, and aid MDE practitioners in selecting suitable model repair approaches.
Nuno Macedo 0001, Jorge Tiago, Alcino Cunha
IEEE Trans. Software Eng.3
2016 A framework for quality assessment of ROS repositories
abstract
Robots are being increasingly used in safety-critical contexts, such as transportation and health. The need for flexible behavior in these contexts, due to human interaction factors or unstructured operating environments, led to a transition from hardware- to software-based safety mechanisms in robotic systems, whose reliability and quality is imperative to guarantee. Source code static analysis is a key component in formal software verification. It consists on inspecting code, often using automated tools, to determine a set of relevant properties that are known to influence the occurrence of defects in the final product. This paper presents HAROS, a generic, plug-in-driven, framework to evaluate code quality, through static analysis, in the context of the Robot Operating System (ROS), one of the most widely used robotic middleware. This tool (equipped with plug-ins for computing metrics and conformance to coding standards) was applied to several publicly available ROS repositories, whose results are also reported in the paper, thus providing a first overview of the internal quality of the software being developed in this community.
André Santos 0001, Alcino Cunha, Nuno Macedo 0001, Cláudio Belo Lourenço
IROS2
2016 Lightweight specification and analysis of dynamic systems with rich configurations
abstract
Model-checking is increasingly popular in the early phases of the software development process. To establish the correctness of a software design one must usually verify both structural and behavioral (or temporal) properties. Unfortunately, most specification languages, and accompanying model-checkers, excel only in analyzing either one or the other kind. This limits their ability to verify dynamic systems with rich configurations: systems whose state space is characterized by rich structural properties, but whose evolution is also expected to satisfy certain temporal properties.
Nuno Macedo 0001, Julien Brunel, David Chemouil, Alcino Cunha, Denis Kuperberg
SIGSOFT FSE4
2016 Least-change bidirectional model transformation with QVT-R and ATL
Nuno Macedo 0001, Alcino Cunha
Softw. Syst. Model.2
2015 Exploring Scenario Exploration
Nuno Macedo 0001, Alcino Cunha, Tiago Guimarães
FASE2
2015 Translating between Alloy specifications and UML class diagrams annotated with OCL
Alcino Cunha, Ana Gabriela Garis, Daniel Riesco
Softw. Syst. Model.1
2014 Target Oriented Relational Model Finding
Alcino Cunha, Nuno Macedo 0001, Tiago Guimarães
FASE1
2014 Bidirectional spreadsheet formulas
abstract
Bidirectional transformations have potential applications in a vast number of computer science domains. Spread-sheets, on the other hand, are widely used for developing business applications, but their formulas are unidirectional, in the sense that their result can not be edited and propagated back to their input cells. In this paper, we interpret such formulas as a well-known class of bidirectional transformations that go by the name of lenses. Being aimed at users that are not proficient with programming languages, we devote particular attention to the seamless embedding of the proposed bidirectional mechanism with the typical workflow of spreadsheet environments, allowing users to have a fine control and understanding of the behavior of the derived backward transformations.
Nuno Macedo 0001, Hugo Pacheco 0001, Nuno Rocha Sousa, Alcino Cunha
VL/HCC4
2013 Implementing QVT-R Bidirectional Model Transformations Using Alloy
Nuno Macedo 0001, Alcino Cunha
FASE2
2013 Model repair and transformation with Echo
abstract
Models are paramount in model-driven engineering. In a software project many models may coexist, capturing different views of the system or different levels of abstraction. A key and arduous task in this development method is to keep all such models consistent, both with their meta-models (and the respective constraints) and among themselves. This paper describes Echo, a tool that aims at simplifying this task by automating inconsistency detection and repair using a solver based engine. Consistency between different models can be specified by bidirectional model transformations, and is guaranteed to be recovered by minimal updates on the inconsistent models. The tool is freely available as an Eclipse plugin, developed on top of the popular EMF framework, and supports constraints and transformations specified in the OMG standard languages OCL and QVT-R, respectively.
Nuno Macedo 0001, Tiago Guimarães, Alcino Cunha
ASE3
2012 Relations as Executable Specifications: Taming Partiality and Non-determinism Using Invariants
Nuno Macedo 0001, Hugo Pacheco 0001, Alcino Cunha
RAMiCS3
2012 Specifying UML Protocol State Machines in Alloy
Ana Gabriela Garis, Ana C. R. Paiva, Alcino Cunha, Daniel Riesco
IFM3
2012 Using Term Rewriting to Solve Bit-Vector Arithmetic Problems - (Poster Presentation)
Iago Abal, Alcino Cunha, Joe Hurd, Jorge Sousa Pinto
SAT2
2011 Calculating with lenses: optimising bidirectional transformations
abstract
This paper presents an equational calculus to reason about bidirectional transformations specified in the point-free style. In particular, it focuses on the so-called lenses as a bidirectional idiom, and shows that many standard laws characterising point-free combinators and recursion patterns are also valid in that setting. A key result is that uniqueness also holds for bidirectional folds and unfolds, thus unleashing the power of fusion as a program optimisation technique. A rewriting system for automatic lens optimisation is also presented, to prove the usefulness of the proposed calculus.
Hugo Pacheco 0001, Alcino Cunha
PEPM2
2011 Translating Alloy Specifications to UML Class Diagrams Annotated with OCL
Ana Gabriela Garis, Alcino Cunha, Daniel Riesco
SEFM2
2011 Transformation of structure-shy programs with application to XPath queries and strategic functions
Alcino Cunha, Joost Visser 0001
Sci. Comput. Program.1
2010 Generic Point-free Lenses
Hugo Pacheco 0001, Alcino Cunha
MPC2
2009 Mapping between Alloy Specifications and Database Implementations
abstract
The emergence of lightweight formal methods tools such as Alloy improves the software design process, by encouraging developers to model and verify their systems before engaging in hideous implementation details. However, an abstract Alloy specification is far from an actual implementation, and manually refining the former into the latter is unfortunately a non-trivial task. This paper identifies a subset of the Alloy language that is equivalent to a relational database schema with the most conventional integrity constraints, namely functional and inclusion dependencies. This semantic correspondence enables both the automatic translation of Alloy specifications into relational database schemas and the reengineering of legacy databases into Alloy. The paper also discusses how to derive an object-oriented application layer to serve as interface to the underlying database.
Alcino Cunha, Hugo Pacheco 0001
SEFM1
2007 Coupled Schema Transformation and Data Conversion for XML and SQL
Pablo Berdaguer, Alcino Cunha, Hugo Pacheco 0001, Joost Visser 0001
PADL2
2007 Transformation of structure-shy programs: applied to XPath queries and strategic functions
abstract
Various programming languages allow the construction of structure-shy programs. Such programs are defined generically for many different datatypes and only specify specific behavior for a few relevant subtypes. Typical examples are XML query languages that allow selection of subdocuments without exhaustively specifying intermediate element tags. Other examples are languages and libraries for polytypic or strategic functional programming and for adaptive object-oriented programming.
Alcino Cunha, Joost Visser 0001
PEPM1
2006 Type-Safe Two-Level Data Transformation
Alcino Cunha, José N. Oliveira, Joost Visser 0001
FM1
2005 Point-free Program Transformation
Alcino Cunha, Jorge Sousa Pinto
Fundam. Informaticae1