VLDB 2026 Research / reviewers in the wild / expert
Thomas Witte
dblp:73/6141
· DBLP profile ↗
5ranked-venue papers
2as first author
5since 2021 · last 2026
0000-0001-5391-7419ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 4 · 2 first-author · 4 since 2021Security and privacy · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Mapping aids using output-directed programming increase novices' performance in programming mobile robotic systemsabstractAbstract Context: Novices programming robotic systems’ behavior, like quadcopter missions, face several challenges and require adequate support to overcome initial barriers. One approach to support novices is to display multiple representations such as graphical previews along with the code editor. Such supportive representations, however, also pose challenges for novices: finding corresponding information in the code and in the preview. To facilitate this, mapping aids can be implemented to clarify the connections between code and preview and foster a deeper understanding. Using output-directed programming, that is, adding the ability to reverse expression evaluation in the domain-specific language, is a promising basis for easily creating and implementing mapping aids. Objective: We investigated, whether mapping aids based on output-directed programming can improve learning language semantics and overall program correctness and how these mapping aids support novices while implementing quadcopter missions. Method: In our study, we tested $$N=82$$ participants while interacting and learning in an online programming environment. Using our 2x2 between-subject design study, we investigated the effects of two mapping aids: highlighting (supports to find element-based connections in the environment) and dynamic linking (supports finding similarities on the semantic level of the content) on program correctness including a typical error, learning outcomes as well as traces of learning strategies. Results: While highlights were more helpful for implementing the quadcopter missions (mission 1: $$p=.008$$ **, $$\eta ^2_{\small \textit{partial}}=.091$$ ), dynamic linking improved learning outcomes on the comprehension ( $$F(1,75)=5.61$$ , $$p=.020$$ *, $$\eta ^2_{\small \textit{partial}} =.070$$ ) and application level ( $$F(1,75)=4.08$$ , $$p=.047$$ *, $$\eta ^2_{\small \textit{partial}} =.052$$ ). Traces of learning strategies were related to higher program correctness (organizing (changes in the preview)): $$r=.553$$ , $$p<.001$$ ***; elaborating (time engaging in the task)): $$r=.639$$ $$p<.001$$ ***) and higher learning outcomes (organizing: $$r=.400$$ , $$p<.001$$ ***; elaborating : $$r=.404$$ , $$p<.001$$ ***). Conclusions: Implementing mapping aids through output-directed programming supports novices in developing a better semantic understanding of the domain specific language. Depending on the program tasks, different mapping aids might be effective. Based on traces of learning strategies while programming, adaptive interactive programming environments might support users individually. Thomas Witte, Andrea Vogt, Tina Seufert, Matthias Tichy |
Empir. Softw. Eng. | 1 |
| 2026 | Bridging safety and security in complex systems: A model-based approach with SAFT-GT toolchainabstract• The SAFT-GT toolchain enables semi-automatic Attack-Fault Tree generation for enhanced safety and security assessment in self-adaptive systems. • The toolchain efficiently integrates into the feedback loop of self-adaptive systems, allowing for dynamic updates based on security assessments. • A user study with domain experts confirms the toolchain’s relevance and practical applicability in real-world scenarios. • Performance experiments demonstrate that the Attack-Fault Tree generation pipeline operates within feasible time constraints, supporting real-time applications. • The complete toolchain and resources are provided for download, fostering further research and collaboration in the field. In the rapidly evolving landscape of software engineering, the demand for robust and secure systems has become increasingly critical. This is especially true for self-adaptive systems due to their complexity and the dynamic environments in which they operate. To address this issue, we designed and developed the SAFT-GT toolchain that tackles the multifaceted challenges associated with ensuring both safety and security. This paper provides a comprehensive description of the toolchain’s architecture and functionalities, including the Attack-Fault Trees generation and model combination approaches. We emphasize the toolchain’s ability to integrate seamlessly with existing systems, allowing for enhanced safety and security analyses without requiring extensive modifications and domain knowledge. Our proposed approach can address evolving security threats, including both known vulnerabilities and emerging attack vectors that could compromise the system. As a use case for the toolchain, we integrate it into the feedback loop of self-adaptive systems. Finally, to validate the practical applicability of the toolchain, we conducted an extensive user study involving domain experts, whose insights and feedback underscore the toolchain’s relevance and usability in real-world scenarios. Our findings demonstrate the toolchain’s effectiveness in real-world applications while highlighting areas for future improvements. The toolchain and associated resources are available in an open-source repository to promote reproducibility and encourage further research in this field. Irdin Pekaric, Raffaela Groner, Alexander Raschke, Thomas Witte, Jubril Gbolahan Adigun, Michael Felderer, Matthias Tichy |
J. Syst. Softw. | 4 |
| 2023 | Model-Based Generation of Attack-Fault Trees
Raffaela Groner, Thomas Witte, Alexander Raschke, Sophie Hirn, Irdin Pekaric, Markus Frick, Matthias Tichy, Michael Felderer |
SAFECOMP | 2 |
| 2023 | A systematic review on security and safety of self-adaptive systemsabstractCyber–physical systems (CPS) are increasingly self-adaptive, i.e. they have the ability to introspect and change their behavior. This self-adaptation process must be considered when modeling the safety and security aspects of the system. This study collects and compares security attacks and safety hazards on self-adaptive systems (SAS) described in the literature. In addition, mitigation and treatment strategies, as well as the modeling and analysis approaches, are investigated. We conducted a systematic literature review on 21 selected papers. The selection process included a database search on four scientific databases using a common search string (1430 papers), forward and backward snowballing (1402 papers), and filtering the results based on predefined inclusion and exclusion criteria. The coding scheme to analyze the content of the papers was obtained through research questions, existing domain-specific taxonomies, and open coding. Safety and security are not jointly modeled in the context of self-adaptive systems. The adaptation process is often not considered in the attack and hazard analysis due to naïve assumptions and modeling. The proposed approaches are mostly verified and validated through simulation often using simple use cases and scenarios. A thorough and joint modeling approach for safety and security in self-adaptive systems is still an open challenge that needs to be addressed. Further work is needed to address the gap between safety and security modeling in self-adaptive systems. Editor’s note: Open Science material was validated by the Journal of Systems and Software Open Science Board. Irdin Pekaric, Raffaela Groner, Thomas Witte, Jubril Gbolahan Adigun, Alexander Raschke, Michael Felderer, Matthias Tichy |
J. Syst. Softw. | 3 |
| 2022 | Towards Model Co-evolution Across Self-Adaptation Steps for Combined Safety and Security AnalysisabstractSelf-adaptive systems offer several attack surfaces due to the communication via different channels and the different sensors required to observe the environment. Often, attacks cause safety to be compromised as well, making it necessary to consider these two aspects together. Furthermore, the approaches currently used for safety and security analysis do not sufficient take into account the intermediate steps of an adaptation. Current work in this area ignores the fact that a self-adaptive system also reveals possible vulnerabilities (even if only temporarily) during the adaptation. To address this issue, we propose a modeling approach that takes into account the different relevant aspects of a system, its adaptation process, as well as safety hazards and security attacks. We present several models that describe different aspects of a self-adaptive system and we outline our idea of how these models can then be combined into an Attack-Fault Tree. This allows modeling aspects of the system on different levels of abstraction and co-evolve the models using transformations according to the adaptation of the system. Finally, analyses can then be performed as usual on the resulting Attack-Fault Tree. Thomas Witte, Raffaela Groner, Alexander Raschke, Matthias Tichy, Irdin Pekaric, Michael Felderer |
SEAMS | 1 |