VLDB 2026 Research / reviewers in the wild / expert
Stefan Kugele
dblp:68/2951
· DBLP profile ↗
26ranked-venue papers
9as first author
8since 2021 · last 2026
0000-0002-9833-4548ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 22 · 9 first-author · 7 since 2021Artificial intelligence and machine learning · 3 · 1 since 2021Theory of computation · 2 · 2 first-authorSystems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Feedback-Guided Knowledge Distillation for RGB-Only 3D Object Detection in Autonomous Driving
Mohamed Chouai, Stefan Kugele |
IV | 2 |
| 2025 | Runtime Monitor Synthesis for Automotive Software Architectures
Fazli Faruk Okumus, João-Vitor Zacchi, Maike Salfeld, Markus Schweizer, Núria Mata, Stefan Kugele |
ECSA | 6 |
| 2024 | Cause-Effect Chain-Based Diagnosis of Automotive Onboard Energy Systems
Stefan Kugele, Lorenz Schreyer, Martin Lamprecht |
ECSA | 1 |
| 2024 | Applying Concept-Based Models for Enhanced Safety ArgumentationabstractWe consider the use of concept bottleneck models (CBMs) to enhance safety argumentation for classification tasks in safety-critical systems. When constructing a safety argumentation for Machine Learning (ML) models, there exists a semantic gap between the specified behaviour, given through class labels at training time, and the learnt behaviour, measured through performance metrics. We address this gap by using CBMs, a class of interpretable ML models in which the predictions rely on a set of human-defined concepts. A Goal Structuring Notation (GSN)-based safety assurance case is constructed including such concepts, allowing traceability between the system specification and the behaviour of the model. As a result, a line of safety argumentation is provided that relies on the interpretable model trained to satisfy the specified safety requirements. João Paulo Costa de Araujo, Balahari Vignesh Balu, Eik Reichmann, Jessica Kelly, Stefan Kugele, Núria Mata, Lars Grunske |
ISSRE | 5 |
| 2023 | Traceability Evaluation in Requirements Engineering According to Automotive SPICEabstractContext: Traceability evaluation is essential for automotive system success, which involves assessing an organisation's ability to track and trace the requirements from the initial conception of the requirement to the delivery of the final product or system. Objectives: This paper presents the development of a graphical user interface which supports the traceability evaluation in PTC Integrity, by displaying the dependency tree, to facilitate consistency and impact analysis in Automotive SPICE standards. Methods: Qualitative and quantitative experimental design and agile development methods were used to identify problems and potential solutions, and user requirements were gathered and analysed thematically. Results: Conceptual ideas for the visualisation and configuration were offered, and keeping the limitations in mind, the dependency tree tool was developed. The scope for future development was also provided. Conclusions: The developed tool is beneficial in automotive development by saving time in impact analysis and improving consistency. Vishakha Rathod, Thomas Cebulla, Stefan Kugele |
RE | 3 |
| 2022 | Defining adaptivity and logical architecture for engineering (smart) self-adaptive cyber-physical systems
Ana Petrovska, Stefan Kugele, Thomas Hutzelmann, Theo Beffart, Sebastian Bergemann, Alexander Pretschner |
Inf. Softw. Technol. | 2 |
| 2021 | Towards a Taxonomy of Autonomous Systems
Stefan Kugele, Ana Petrovska, Ilias Gerostathopoulos |
ECSA | 1 |
| 2021 | Model-based resource analysis and synthesis of service-oriented automotive software architecturesabstractAbstract Context Automotive software architectures describe distributed functionality by an interaction of software components. One drawback of today’s architectures is their strong integration into the onboard communication network based on predefined dependencies at design time. The idea is to reduce this rigid integration and technological dependencies. To this end, service-oriented architecture offers a suitable methodology since network communication is dynamically established at run-time. Aim We target to provide a methodology for analysing hardware resources and synthesising automotive service-oriented architectures based on platform-independent service models. Subsequently, we focus on transforming these models into a platform-specific architecture realisation process following AUTOSAR Adaptive. Approach For the platform-independent part, we apply the concepts of design space exploration and simulation to analyse and synthesise deployment configurations, i. e., mapping services to hardware resources at an early development stage. We refine these configurations to AUTOSAR Adaptive software architecture models representing the necessary input for a subsequent implementation process for the platform-specific part. Result We present deployment configurations that are optimal for the usage of a given set of computing resources currently under consideration for our next generation of E/E architecture. We also provide simulation results that demonstrate the ability of these configurations to meet the run time requirements. Both results helped us to decide whether a particular configuration can be implemented. As a possible software toolchain for this purpose, we finally provide a prototype. Conclusion The use of models and their analysis are proper means to get there, but the quality and speed of development must also be considered. Stefan Kugele, Philipp Obergfell, Eric Sax |
Softw. Syst. Model. | 1 |
| 2020 | Architectural Patterns for Cross-Domain Personalised Automotive FunctionsabstractContext: Future automotive customer functions will be highly personalisable and adapt their settings proactively in an intelligent way. Aim: We aim at designing generic architectural patterns for functional architectures containing machine learning components. Method: We first formalise a new architectural model. Based on this model, we present and discuss three alternative architectural patterns: (1) concurrent learning, (2) end-to-end learning, and (3) user shadow learning. For these patterns, three alternative integration approaches are discussed: (i) centralised holistic approach, (ii) domain-specific approach, and (iii) dedicated approach. Moreover, we conduct an evaluation using real car data for different customer functions. Conclusion: We propose the use of the user shadow learning pattern in the dynamic architectural model. The user shadow learning pattern is not affected by safety constraints, as is usually the case for integrating artificial intelligence, as it only models user behaviour while leaving the original function intact. To integrate the multitude of models, we propose a domain-specific approach. This approach provides a balance between the trade-offs in the dedicated approach and the holistic approach, being high computational overhead and design complexity, respectively. Stefan Kugele, Christoph Segler, Thomas Hubregtsen |
ICSA | 1 |
| 2020 | Playground for Early Automotive Service Architecture Design and EvaluationabstractContext: We consider the structure of service-oriented architectures in vehicular software. Aim: We aim at evaluating the structure and grouping of service architectures. Method: We propose and discuss architectural metrics tailored towards automotive service-oriented architectures. We apply the metrics on an adaptive cruise control case example extracted from the AUTOSAR standard. Results: The application of the proposed metrics to two different service groupings for ACC points clearly to the same service grouping that we consider, after a thorough analysis, to be better with respect to coupling and cohesion attributes. Conclusion: We demonstrate the usefulness of proposed service group metrics in early design phases of the development process and validate the metrics on the case example of an adaptive cruise control function. Vadim Cebotari, Stefan Kugele |
IV | 2 |
| 2019 | Run-Time Safety Monitoring Framework for AI-Based Systems: Automated Driving CasesabstractIntelligent systems based on artificial intelligence techniques are increasing and are recently being accepted in the automotive domain. In the competition of automobile makers to provide fully automated vehicles, it is perceived that artificial intelligence will profoundly influence the automotive electric and electronic architecture in the future. However, while such systems provide highly advanced functions, safety risk increases as AI-based systems may produce uncertain output and behaviour. In this paper, we devise a run-time safety monitoring framework for AI-based intelligence systems focusing on autonomous driving functions. In detail, this paper describes (i) the characteristics of a safety monitoring framework; (ii) the safety monitoring framework itself, and (iii) we develop a prototype and implement the framework for two critical driving functions: Lane detection and object detection. Through an implementation of the framework to a prototypic control environment, we show the possibility of this framework in the real context. Finally, we discuss the techniques used in developing the safety monitoring framework and describes the encountered challenges. Mohd Hafeez Osman, Stefan Kugele, Sina Shafaei |
APSEC | 2 |
| 2019 | Anomaly Detection for Advanced Driver Assistance Systems Using Online Feature SelectionabstractContext: As we move towards higher levels of automation in autonomous driving, we see an increase in functionality that either assists or takes over in both normal and emergency scenarios. These new functionalities can be intentionally switched off by the user, but can also be deactivated unintentionally by (i) accident, (ii) a software malfunction, (iii) a hardware defect, or (iv) an intrusion. Aim: In addition to already applied methods at design time, we aim to recognise mistimed and/or unintended deactivation of vehicle functions, in particular, driver assistance functions (ADAS), at run-time. Upon recognition of the occurrence, we propose to inform the user and the original equipment manufacturer (OEM) in order to improve both the future and the current system behaviour, to support development processes, and to support already conducted safety measures. Method: Based on a feature subset, selected by streaming feature selection, we learn the nominal behaviour of the driver in the interaction with ADAS functions in order to find deviations. The approach considers the technical challenges of automotive E/E architectures and is optimised to reduce communication and computational complexity. We evaluate this approach with recorded real car data from customers participating in a field study. Results: Based on eight datasets, we traced a total of 17 state-of-the-art ADAS functions per participant, yielding to a total of 136 runs. We observed that during 24 among them, the user deactivated the functions at least once for more than a few seconds. For 13 of these 24 runs, we were able to detect and flag possible non-nominal behaviour. Conclusion: As at least one participant configured a convincingly large number of ADAS functions, we need a dynamic system to monitor the configuration of these functions actively. Our approach was capable of detecting potential non-nominal behaviour in up to 52% (13/24) out of these reconfigurations. This result is promising and will receive further attention in future work. Christoph Segler, Stefan Kugele, Philipp Obergfell, Mohd Hafeez Osman, Sina Shafaei, Eric Sax, Alois C. Knoll |
IV | 2 |
| 2019 | Automated Trainability Evaluation for Smart Software FunctionsabstractMore and more software-intensive systems employ machine learning and runtime optimization to improve their functionality by providing advanced features (e. g. personal driving assistants or recommendation engines). Such systems incorporate a number of smart software functions (SSFs) which gradually learn and adapt to the users' preferences. A key property of SSFs is their ability to learn based on data resulting from the interaction with the user (implicit and explicit feedback)-which we call trainability. Newly developed and enhanced features in a SSF must be evaluated based on their effect on the trainability of the system. Despite recent approaches for continuous deployment of machine learning systems, trainability evaluation is not yet part of continuous integration and deployment (CID) pipelines. In this paper, we describe the different facets of trainability for the development of SSFs. We also present our approach for automated trainability evaluation within an automotive CID framework which proposes to use automated quality gates for the continuous evaluation of machine learning models. The results from our indicative evaluation based on real data from eight BMW cars highlight the importance of continuous and rigorous trainability evaluation in the development of SSFs. Ilias Gerostathopoulos, Stefan Kugele, Christoph Segler, Tomás Bures, Alois C. Knoll |
ASE | 2 |
| 2019 | Model-Based Resource Analysis and Synthesis of Service-Oriented Automotive Software ArchitecturesabstractAutomotive software architectures describe distributed functionality through an interplay of software components. One drawback of today's architectures is their strong integration into the onboard communication network based on predefined dependencies at design-time. To foster independence, theideaofservice-orientedarchitecture(SOA) providesasuitable prospect as network communication is established dynamically at run-time. Aim: We target to provide a model-based design methodology for analysing and synthesising hardware resources of automotive service-oriented architectures. Approach: For the approach, we apply the concepts of design space exploration and simulation to analyse and synthesise deployment configurations at an early stage of development. Result: We present an architecture candidate for an example function from the domain of automated driving. Based on corresponding simulation results, we gained insights about the feasibility to implement this candidate within our currently considered next E/E architecture generation. Conclusion:Theintroductionofservice-orientedarchitecturesstrictly requires early run-time assessments. In order to get there, the usage of models and model transformations depict reasonable ways by additionally accounting quality and development speed. Philipp Obergfell, Stefan Kugele, Eric Sax |
MoDELS | 2 |
| 2018 | Data-Centric Communication and Containerization for Future Automotive Software ArchitecturesabstractContext: The functional interconnection and data routing in today's automotive electric/electronic architectures has reached a level of complexity which is hardly manageable and error-prone. This circumstance severely hinders short times from development to operation. Aim: The purpose of the study is to evaluate the feasibility of Data Distribution Services in accord with containerization technologies in an agile development process for automotive software. Method: We propose to represent services by means of topics in a data-centric publish-subscribe approach. We conduct performance benchmarks to evaluate its aptitude and present a case study illustrating fail-operational behavior in a setup recreated from highly automated driving. Results: Backed by the results and the case study we show that containerized services, along with data-centric messaging, manage to meet most of our proposed requirements. We furthermore reveal limitations of the used technology stack and discuss remedies to their shortcomings. Stefan Kugele, David Hettler, Jan Peter |
ICSA | 1 |
| 2017 | A graphical modeling tool supporting automated schedule synthesis for time-sensitive networkingabstractTime-Sensitive Networking (TSN) is a set of new standards which is being developed by the Institute of Electrical and Electronics Engineers to support mixed-criticality requirements based on Ethernet technology. These standards have recently raised the attention of real-time domains such as automation and automotive. To support tight timing guarantees, Time-Aware Shaper (IEEE 802.1Qbv) is introduced based on the theory of time-triggered communication. However, the configuration of Time-Aware Shaper requires expertise and is a time consuming procedure. We aim to automate this procedure reducing configuration overhead. A novel graphical modeling is introduced which combines the strengths of model-based and logic programming modeling paradigms. Using the graphical editor, network topology, dataflow based on a publisher and subscriber concept, and the quality of service requirements are specified. Facts for a network knowledge base are automatically derived from the model. This knowledge base is used to generate constraints for schedule synthesis. These constraints are solved using a Satisfiability Modulo Theories solver to find a correct schedule. Moreover, we exploit the solver's capability of producing unsatisfiable cores and use it for network model correction. We annotated all generated schedule constraints and mapped them to the stream names to track the unsatisfiable streams from the solver's output. We gained insightful results showing that this information significantly helps to correct an unsatisfiable network model to find a feasible schedule. Morteza Hashemi Farzaneh, Stefan Kugele, Alois C. Knoll |
ETFA | 2 |
| 2017 | On Service-Orientation for Automotive SoftwareabstractBackground: During the last decades, the functional power and complexity of automotive E/E architectures grew radically and is going to grow further in the future. For highly and fully automated driving, functions with the highest safety integrity level need to be realized, requiring new development methodologies and a new level of formal rigor. Aim: We investigate to what extent SOA concepts are applicable for safety-critical embedded automotive software systems and whether this concept is appealing to E/E architects. Method: We conducted a survey research by interviewing system architects at our industrial partner, then we applied the grounded theory method in order to derive a theory and a set of requirements for an automotive SOA approach. Additionally, we illustrate the approach using a function needed in a highly automated driving scenario. Results: We present a formal service model and an automotive SOA framework. Both aspects, i.e., architecture structuring and formal service description resulted from the analyzed interview data. Limitation: This approach has not been evaluated extensively, yet. Conclusion: Our first results suggest that SOA concepts are indeed successfully applicable in (continuous) automotive software engineering and are a means to cope with complexity and safety requirements. Stefan Kugele, Philipp Obergfell, Manfred Broy, Oliver Creighton, Matthias Traub, Wolfgang Hopfensitz |
ICSA | 1 |
| 2016 | Verification of component architectures using mode-based contractsabstractWe consider the problem of achieving a required level of confidence about safety-critical systems consisting of interacting components. Especially, we address restrictions in traditional A/G reasoning techniques which may cause false positives in contract compatibility analyses. Therefore, we introduce interface assertions, i. e., predicate logical formulae over the components' interfaces. We show how to compute interface assertions for architecture configurations based on the interface assertions of the corresponding components and show soundness and relative completeness of the method. Moreover, we introduce mode-based contracts, which - as a special kind of interface assertions - consist of dedicated assume and guarantee pairs. They provide a methodological guidance for developers and facilitate contract specification in contrast to e. g. traditional A/G reasoning. For this concept, we provide algorithms to check under-specification, over-specification, and the fulfillment of specifications. We also sketch how the checks can be operationalized using SMT solvers. Finally, an example demonstrates the approach. Stefan Kugele, Diego Marmsoler, Núria Mata, Kai Werther |
MEMOCODE | 1 |
| 2015 | On the deployment problem of embedded systemsabstractThe quality of today's embedded systems e. g. in vehicles, airplanes, or automation plants is highly influenced by their architecture. In this context, we study the so-called deployment problem. The question is where (i. e., on which execution unit) to deploy which software application or which sensor/actuator shall be connected to which device in an automation plant. First, we introduce a domain-specific constraint and optimization language fitting the needs of our partners. Second, we investigate different approaches to tackle the deployment problem even for industrial size systems. Therefore, we present different solving strategies using (i) multi-objective evolutionary algorithms, (ii) SMT-based, and (iii) ILP-based solving approaches. Furthermore, a combination of the first two is used. We investigate the proposed methods and demonstrate their feasibility using two realistic systems: a civil flight control system (FCS), and a seawater desalination plant. Stefan Kugele, Gheorghe Pucea, Ramona Popa, Laurent Dieudonné, Horst Eckardt |
MEMOCODE | 1 |
| 2012 | A Configuration Approach for IMA Systems
Visar Januzaj, Stefan Kugele, Florian Biechele, Ralf Mauersberger |
SEFM | 2 |
| 2011 | Seamless Testing for Models and Code
Andreas Holzer, Visar Januzaj, Stefan Kugele, Boris Langer, Christian Schallhart, Michael Tautschnig, Helmut Veith |
FASE | 3 |
| 2010 | Seamless Model-Driven Development Put into Practice
Wolfgang Haberl, Markus Herrmannsdoerfer, Stefan Kugele, Michael Tautschnig, Martin Wechs |
ISoLA (1) | 3 |
| 2010 | Timely Time Estimates
Andreas Holzer, Visar Januzaj, Stefan Kugele, Michael Tautschnig |
ISoLA (1) | 3 |
| 2010 | New Challenges in the Development of Critical Embedded Systems - An "aeromotive" Perspective
Visar Januzaj, Stefan Kugele, Boris Langer, Christian Schallhart, Helmut Veith |
ISoLA (1) | 2 |
| 2009 | Towards Resource Consumption-Aware ProgrammingabstractIn order to check the fulfilment of non-functional requirements at an early system design and development stage, we provide a framework that facilitates the combination of platform-independent and platform-specific information in a query-based manner to calculate estimates for the resource consumption of the software under investigation at fine grained levels of code. Based on an already optimised intermediate representation of the source code, using a testing infrastructure for C code, we count the occurrence of instructions during program executions in a platform-independent manner. These instruction counters can be determined at program or function level. By combining these counters with cost information of a hardware platform we can provide resource consumption estimates. This allows the software developer to tailor the code steadily towards the non-functional characteristics of the software. Andreas Holzer, Visar Januzaj, Stefan Kugele |
ICSEA | 3 |
| 2008 | Optimizing Automatic Deployment Using Non-functional Requirement Annotations
Stefan Kugele, Wolfgang Haberl, Michael Tautschnig, Martin Wechs |
ISoLA | 1 |