VLDB 2026 Research / reviewers in the wild / expert
Christian Heinzemann
dblp:76/6761
· DBLP profile ↗
18ranked-venue papers
3as first author
5since 2021 · last 2026
0000-0003-2144-6215ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 8 · 2 first-author · 3 since 2021Systems, architecture and hardware · 5 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 4 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Driving by Disproof: A Practical Model Checking Approach to Fleet Coordination
Lukas König, Christian Schildwächter, Michaela Klauck, Christian Heinzemann |
TACAS (1) | 4 |
| 2024 | Towards Safe Autonomous Driving: Model Checking a Behavior Planner during DevelopmentabstractAbstract Automated driving functions are among the most critical software components to develop. Before deployment in series vehicles, it has to be shown that the functions drive safely and in compliance with traffic rules. Despite the coverage that can be reached with very large amounts of test drives, corner cases remain possible. Furthermore, the development is subject to time-to-delivery constraints due to the highly competitive market, and potential logical errors must be found as early as possible. We describe an approach to improve the development of an actual industrial behavior planner for the Automated Driving Alliance between Bosch and Cariad. The original process landscape for verification and validation is extended with model checking techniques. The idea is to integrate automated extraction mechanisms that, starting from the C++ code of the planner, generate a higher-level model of the underlying logic. This model, composed in closed loop with expressive environment descriptions, can be exhaustively analyzed with model checking. This results, in case of violations, in traces that can be re-executed in system simulators to guide the search for errors. The approach was exemplarily deployed in series development, and successfully found relevant issues in intermediate versions of the planner at development time. Lukas König, Christian Heinzemann, Alberto Griggio, Michaela Klauck, Alessandro Cimatti, Franziska Henze, Stefano Tonetta, Stefan Küperkoch, Dennis Fassbender, Michael Hanselmann |
TACAS (2) | 2 |
| 2022 | Using ontologies for dataset engineering in automotive AI applicationsabstractBasis of a robust safety strategy for an automated driving function based on neural networks is a detailed description of its input domain, i.e. a description of the environment, in which the function is used. This is required to describe its functional system boundaries and to perform a comprehensive safety analysis. Moreover, it allows to tailor datasets specifically designed for safety related validation tests. Ontologies fulfill the task to gather expert knowledge and model information to enable computer aided processing, while using a notion understandable for humans. In this contribution, we propose a methodology for domain analysis to build up an ontology for perception of autonomous vehicles including characteristic features that become important when dealing with neural networks. Additionally, the method is demonstrated by the creation of a synthetic test dataset for an Euro NCAP-like use case. Martin Herrmann, Christian Witt, Laureen Lake, Stefani Guneshka, Christian Heinzemann, Frank Bonarens, Patrick Feifel, Simon Funke |
DATE | 5 |
| 2022 | Towards Safety-Aware Pedestrian Detection in Autonomous SystemsabstractIn this paper, we present a framework to assess the quality of a pedestrian detector in an autonomous driving scenario. To do this, we exploit performance metrics from the domain of computer vision on one side and so-called threat metrics from the motion planning domain on the other side. Based on a reachability analysis that accounts for the uncertainty in future motions of other traffic participants, we can determine the worst-case threat from the planning domain and relate it to the corresponding detection from the visual input. Our evaluation results for a RetinaNet on the Argoverse 1.1 [1] dataset show that already a rather simple threat metric such as time-to-collision (TTC) allows to select potentially dangerous interactions between the ego vehicle and a pedestrian when purely vision-based detections fail, even if they are passed to a subsequent object tracker. In addition, our results show that two different DNNs (Deep Neural Networks) with comparable performance differ significantly in the number of critical scenarios that we can identify with our method. Maria Lyssenko, Christoph Gladisch, Christian Heinzemann, Matthias Woehrle, Rudolph Triebel |
IROS | 3 |
| 2021 | Testing Deep Learning-based Visual Perception for Automated DrivingabstractDue to the impressive performance of deep neural networks (DNNs) for visual perception, there is an increased demand for their use in automated systems. However, to use deep neural networks in practice, novel approaches are needed, e.g., for testing. In this work, we focus on the question of how to test deep learning-based visual perception functions for automated driving. Classical approaches for testing are not sufficient: A purely statistical approach based on a dataset split is not enough, as testing needs to address various purposes and not only average case performance. Additionally, a complete specification is elusive due to the complexity of the perception task in the open context of automated driving. In this article, we review and discuss existing work on testing DNNs for visual perception with a special focus on automated driving for test input and test oracle generation as well as test adequacy. We conclude that testing of DNNs in this domain requires several diverse test sets. We show how such tests sets can be constructed based on the presented approaches addressing different purposes based on the presented methods and identify open research questions. Stephanie Abrecht, Lydia Gauerhof, Christoph Gladisch, Konrad Groh, Christian Heinzemann, Matthias Woehrle |
ACM Trans. Cyber Phys. Syst. | 5 |
| 2020 | Scenario-based threat metric evaluation based on the highd datasetabstractScenario-based approaches have gained popularity in the context of automated vehicles. As in any model-based approach, validation to real data needs to be considered. This work studies concrete scenarios based on real data from a large-scale and open road user trajectory dataset. In particular, we detail on cut-ins and (hard) braking maneuvers and study them based on existing threat metrics. In this work, we present the complete workflow starting from the pre-processing and validation of the data, the definition of concrete scenarios based on how we extract them from the dataset and their evaluation based on several threat metrics. We identify peculiarities of the dataset itself, as well as of the driving behavior of vehicles therein. As this work relies on an open dataset, results can be reproduced and readily compared. Patrick Schneider, Martin Butz, Christian Heinzemann, Jens Oehlerking, Matthias Woehrle |
IV | 3 |
| 2019 | Experience Paper: Search-Based Testing in Automated Driving Control ApplicationsabstractAutomated test generation and evaluation in simulation environments is a key technology for verification of automated driving (AD) applications. Search-based testing (SBT) is an approach for automated test generation that leverages optimization to efficiently generate interesting concrete tests from abstract test descriptions. In this experience paper, we report on our observations after successfully applying SBT to AD control applications in several use cases with different characteristics. Based on our experiences, we derive a number of lessons learned that we consider important for the adoption of SBT methods and tools in industrial settings. The key lesson is that SBT finds relevant errors and provides valuable feedback to the developers, but requires tool support for writing specifications. Christoph Gladisch, Thomas Heinz 0001, Christian Heinzemann, Jens Oehlerking, Anne von Vietinghoff, Tim Pfitzer |
ASE | 3 |
| 2019 | Transactional execution of hierarchical reconfigurations in cyber-physical systems
Christian Heinzemann, Steffen Becker 0001, Andreas Volk |
Softw. Syst. Model. | 1 |
| 2018 | vTSL - A Formally Verifiable DSL for Specifying Robot TasksabstractPreprogramming of tasks still plays an important role in complex robotic systems despite the advances in automated planning and symbolic learning. Often, it is desired that end-users implement further tasks to adapt the robotic application to their needs. These user-defined tasks have to meet safety and integrity constraints for protecting the robotic platform and its users. We introduce a verifiable task specification language (vTSL) that enables to automatically prove that a task specification satisfies a set of predefined or task-specific constraints. We illustrate our approach using an example of a self-driving vehicle for intra-logistics and report experiences with two commercial applications. Christian Heinzemann, Ralph Lange |
IROS | 1 |
| 2017 | Provably safe motion of mobile robots in human environmentsabstractMobile robots operating in a shared environment with pedestrians are required to move provably safe to avoid harming pedestrians. Current approaches like safety fields use conservative obstacle models for guaranteeing safety, which leads to degraded performance in populated environments. In this paper, we introduce an online verification approach that uses information about the current pedestrian velocities to compute possible occupancies based on a kinematic model of pedestrian motion. We demonstrate that our method reduces the need for stopping while retaining safety guarantees, and thus goals are reached between 1.4 and 3.5 times faster than the standard ROS navigation stack in the tested scenarios. Stefan B. Liu, Hendrik Roehm, Christian Heinzemann, Ingo Lütkebohle, Jens Oehlerking, Matthias Althoff |
IROS | 3 |
| 2014 | A tool suite for the model-driven software engineering of cyber-physical systemsabstractCyber-physical systems, e.g., autonomous cars or trains, interact with their physical environment. As a consequence, they commonly have to coordinate with other systems via complex message communication while realizing safety-critical and real-time tasks. As a result, those systems should be correct by construction. Software architects can achieve this by using the MechatronicUML process and language. This paper presents the MechatronicUML Tool Suite that offers unique features to support the MechatronicUML modeling and analyses tasks. Stefan Dziwok, Christopher Gerking, Steffen Becker 0001, Sebastian Thiele 0002, Christian Heinzemann, Uwe Pohlmann |
SIGSOFT FSE | 5 |
| 2013 | Durative Graph Transformation Rules for Modelling Real-Time Reconfiguration
Steffen Ziegert, Christian Heinzemann |
ICTAC | 2 |
| 2013 | From timed automata to timed failure propagation graphsabstractEmbedded real-time systems are increasingly applied in safety-critical environments like cars or aircrafts. Even though the system design might be free from flaws, hazardous situations may still be caused at run-time by random faults due to the wear of physical components. Hazard analysis is based on fault trees or failure propagation models. These models are created at least partly manually. They are usually independent from the software models which are used for checking safety and liveness properties to avoid systematic faults. This is particularly bad in cases, where the software model contains manually specified operations to deal with random faults which have been identified by hazard analysis. These operations include replacing the faulty components by reconfiguration. We propose to generate a failure propagation model automatically from the software model to check whether the results of hazard analysis have been properly accounted in the specification of reconfiguration operations. In contrast to other approaches, our approach considers the real-time properties of the system and adds explicit failure propagation times based on using timed automata for model specification. Claudia Priesterjahn, Christian Heinzemann, Wilhelm Schäfer |
ISORC | 2 |
| 2013 | A discipline-spanning development process for self-adaptive mechatronic systemsabstractTechnical systems contain mechanical, electrical, and software parts. Consequently, they are developed by engineers of the respective disciplines. However, current industrial practice as well as existing development processes do not account for the required tight integration between the engineers of the different disciplines. Processes become even more complex, when self-adaptive systems are built. In this paper, we present a development process for self-adaptive mechatronic systems which particularly addresses the integration between the disciplines concerned with the development of software, namely control and software engineering. We illustrate the process by presenting examples from the development of autonomous railway vehicles which build convoys to improve energy efficiency. Christian Heinzemann, Oliver Sudmann, Wilhelm Schäfer, Matthias Tichy |
ICSSP | 1 |
| 2012 | Real-Time Coordination Patterns for Advanced Mechatronic Systems
Stefan Dziwok, Christian Heinzemann, Matthias Tichy |
COORDINATION | 2 |
| 2012 | Runtime safety analysis for safe reconfigurationabstractModern technical systems are increasingly built to exhibit self-x properties as, e.g., self-healing or self-optimization. For this, they require adaptation at runtime. This is even true for embedded or mechatronic systems which often operate in safety-critical environments. There, the effects of the adaptation with respect to safety must be analyzed carefully. However, not all parameters needed for safety analyses, e.g., the concrete system architecture, are known at design time. Consequently, safety analyses need to be executed during runtime. Current approaches of runtime safety analysis typically react to anomalies that already occurred in the system. Thus, unsafe system states cannot be excluded completely. We present a runtime safety analysis that prevents system states with an unacceptable risk that have not yet occurred. For this, we generate the reachable component structures at runtime and analyze them with respect to risk. The system is modified such that component structures with an unacceptable risk are not reachable any more and are thus prevented. Claudia Priesterjahn, Christian Heinzemann, Wilhelm Schäfer, Matthias Tichy |
INDIN | 2 |
| 2009 | Synthesis of timed behavior from scenarios in the Fujaba Real-Time Tool SuiteabstractBased on a well-defined component architecture the tool supports the synthesis of so-called real-time statecharts from timed sequence diagrams. The two step synthesis process addresses the existing scalability problems by a proper decomposition and allows the user to define particular restrictions on the resulting statecharts. Stefan Henkler, Joel Greenyer, Martin Hirsch 0001, Wilhelm Schäfer, Kahtan Alhawash, Tobias Eckardt, Christian Heinzemann, Renate Löffler, Andreas Seibel, Holger Giese |
ICSE | 7 |
| 2008 | BSBC: Towards a Succinct Data Format for XML Streams
Stefan Böttcher, Rita Hartel, Christian Heinzemann |
WEBIST (1) | 3 |