VLDB 2026 Research / reviewers in the wild / expert
Marcello Ceci
dblp:65/9927
· DBLP profile ↗
8ranked-venue papers
1as first author
5since 2021 · last 2025
0000-0003-3800-0906ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 7 · 1 first-author · 5 since 2021Artificial intelligence and machine learning · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | LLM-assisted Extraction of Regulatory Requirements: A Case Study on the GDPRabstractModern software systems increasingly rely on personal data. Despite the enforcement of the European General Data Protection Regulation (GDPR) and the growing awareness about privacy and data protection, many individuals’ rights remain unsatisfactorily implemented in software systems. This is partially due to the knowledge gap between legal interpretation and software development.In this paper, we address this gap first by extracting, in close collaboration with legal experts, a list of 108 requirements pertinent to the right of access (ACC) and the right to portability (PRT), two fundamental rights under the GDPR. We further propose the XTRAREG approach, which utilizes large language models (LLMs) and retrieval augmented generation (RAG) to provide automated assistance in extracting privacy requirements from predefined legal sources.Compared to the manually extracted requirements, XTRAREG can automatically generate requirements with an accuracy of 81.8% for ACC and 85.7% for PRT. Our empirical evaluation reveals two notable observations: (i) A skewed performance in terms of coverage in the favor of ACC, indicating the significant impact of abundant training data of the LLM, (ii) despite explicit exposure of legal references through RAG, the LLM generates requirements predominantly from the GDPR. Sallam Abualhaija, Marcello Ceci, Nicolas Sannier, Domenico Bianculli, Salomé Lannier, Martina Siclari, Olivier Voordeckers, Stanislaw Tosza |
RE | 2 |
| 2025 | GDPR Compliance in Privacy Policies of Mobile Apps: An Overview of the State-of-PracticeabstractMobile apps are ubiquitous in our lives as they provide numerous services to support our daily activities. Personalizing such services entail collecting (possibly sensitive) personal information. Mobile apps must therefore comply with privacy regulations like the General Data Protection Regulation (GDPR) enforced in the European Union (EU). To achieve compliance, an app should implement the legal requirements pertinent to data collection and processing according to the GDPR. Privacy policies associated with apps can serve as intermediary instruments connecting between source code and regulations. They explain to app users how activities involving personal data are implemented and provide a detailed view on how legal requirements are operationalized in the app. Incomplete policies can indicate non-compliant apps.This paper sheds light on the state-of-practice of GDPR compliance in two mainstream app markets: the Apple App Store and the Google Play Store. We conducted a study to assess the completeness of 470 apps privacy policies in these stores according to the GDPR. Our analysis shows that, irrespective of the app store, fundamental GDPR requirements (e.g., information pertinent to individuals’ rights and details of data transfer outside EU) are missing in ≈92% of the analyzed policies, revealing potential breaches in the respective apps. Orlando Amaral, Sallam Abualhaija, Nicolas Sannier, Marcello Ceci, Domenico Bianculli |
RE | 4 |
| 2024 | AI-Enabled Regulatory Change Analysis of Legal RequirementsabstractStatutory law is subject to change as legislation develops over time – new regulation can be introduced, while existing regulation can be amended, or repealed. From a requirements engineering (RE) perspective, such change must be dealt with to ensure the compliance of software systems at all times. Understanding the implications of regulatory change on compliance of software requirements requires navigating hundreds of legal provisions. Analyzing instances of regulatory change entirely manually is not only time-consuming, but also risky, since missing a change may result in non-compliant software which can in turn lead to hefty fines. In this paper, we propose MURCIA, an automated approach that leverages recent language models to assist human analysts in analyzing regulatory changes. To build MURCIA, we define a taxonomy that characterizes the regulatory changes at the textual level as well as the changes in the text's meaning and legal interpretation. We evaluate MURCIA on four regulations from the financial domain. Over our evaluation set, MURCIA can identify textual changes with F1 score of 90.5%, and it can provide, according to our taxonomy, the text meaning and legal interpretation with an F1 score of 90.8% and 83.7%, respectively. Sallam Abualhaija, Marcello Ceci, Nicolas Sannier, Domenico Bianculli, Lionel C. Briand, Dirk A. Zetzsche, Marco Bodellini |
RE | 2 |
| 2024 | Defining a Model for Content Requirements from the Law: An Experience ReportabstractThis paper reports on the experience of building a content model in collaboration with a national financial supervisory authority, with the goal of automating the compliance checking activity performed by the agents of the supervisory authority on fund documentation. The work is focused on modelling content requirements found in the law, i.e., deontic rules prescribing that some information is contained in an official document. For such requirements, the main modelling effort revolves around the required content and its information types. We therefore designed a process to build a content model, elaborating design criteria for the model which partly depend on the use case encompassing compliance checking. We built the content model through iterative interactions between a knowledge engineer and domain experts designed to ensure that the model is not limited to representing only the letter of the law, but rather represents the relevant distinctions in the practice of compliance checking. We drew lessons learned regarding the need for setting up classification criteria for information types and handling the trade-off between expressivity and maintainability of the model. Marcello Ceci, Domenico Bianculli, Lionel C. Briand |
RE | 1 |
| 2021 | An automated framework for the extraction of semantic legal metadata from legal texts
Amin Sleimi, Nicolas Sannier, Mehrdad Sabetzadeh, Lionel C. Briand, Marcello Ceci, John Dann |
Empir. Softw. Eng. | 5 |
| 2020 | Automated Recommendation of Templates for Legal RequirementsabstractContext: In legal requirements elicitation, requirements analysts need to extract obligations from legal texts. However, legal texts often express obligations only indirectly, for example, by attributing a right to the counterpart. This phenomenon has already been described in the Requirements Engineering (RE) literature [1]. Objectives: We investigate the use of requirements templates for the systematic elicitation of legal requirements. Our work is motivated by two observations: (1) The existing literature does not provide a harmonized view on the requirements templates that are useful for legal RE; (2) Despite the promising recent advancements in natural language processing (NLP), automated support for legal RE through the suggestion of requirements templates has not been achieved yet. Our objective is to take steps toward addressing these limitations. Methods: We review and reconcile the legal requirement templates proposed in RE. Subsequently, we conduct a qualitative study to define NLP rules for template recommendation. Results and Conclusions: Our contributions consist of (a) a harmonized list of requirements templates pertinent to legal RE, and (b) rules for the automatic recommendation of such templates. We evaluate our rules through a case study on 400 statements from two legal domains. The results indicate a recall and precision of 82,3% and 79,8%, respectively. We show that introducing some limited interaction with the analyst considerably improves accuracy. Specifically, our human-feedback strategy increases recall by 12% and precision by 10,8%, thus yielding an overall recall of 94,3% and overall precision of 90,6%. Amin Sleimi, Marcello Ceci, Mehrdad Sabetzadeh, Lionel C. Briand, John Dann |
RE | 2 |
| 2019 | A Query System for Extracting Requirements-Related Information from Legal TextsabstractSearching legal texts for relevant information is a complex and expensive activity. The search solutions offered by present-day legal portals are targeted primarily at legal professionals. These solutions are not adequate for requirements analysts whose objective is to extract domain knowledge including stakeholders, rights and duties, and business processes that are relevant to legal requirements. Semantic Web technologies now enable smart search capabilities and can be exploited to help requirements analysts in elaborating legal requirements. In our previous work, we developed an automated framework for extracting semantic metadata from legal texts. In this paper, we investigate the use of our metadata extraction framework as an enabler for smart legal search with a focus on requirements engineering activities. We report on our industrial experience helping the Government of Luxembourg provide an advanced search facility over Luxembourg's Income Tax Law. The experience shows that semantic legal metadata can be successfully exploited for answering requirements engineering-related legal queries. Our results also suggest that our conceptualization of semantic legal metadata can be further improved with new information elements and relations. Amin Sleimi, Marcello Ceci, Nicolas Sannier, Mehrdad Sabetzadeh, Lionel C. Briand, John Dann |
RE | 2 |
| 2011 | FrameNet model of the suspension of normsabstractOne open problem in the AI & Law community is how to provide computers with a basic understanding of legal concepts, and their relationship with legal texts and with the legal lexicon. We propose to add a layer to connect the linguistic description of the provisions to syntactic patterns using FramNet that can be exploited thought NLP tools. A deep-parsing and shallow-semantics approach has been devised to interpret and retrieve the characterizing components of legal modificatory provisions. In this paper we single out the case of efficacy suspension and show how FrameNet approach can provide profit especially to isolate temporal parameters and their interpretation. Monica Palmirani, Marcello Ceci, Daniele Paolo Radicioni, Alessandro Mazzei |
ICAIL | 2 |