Jens Nicolay

dblp:82/10404 · DBLP profile ↗
← Back
19ranked-venue papers
5as first author
6since 2021 · last 2026
0000-0003-4653-5820ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 18 · 5 first-author · 6 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Theory of computation · 1
YearPublicationVenuePosition
2026 TurtleTalk: A DSL for Constraint-Based Turtle Graphics in Programmatic CAD
abstract
In programmatic CAD (PCAD), 3D shapes are generally modelled either by position-based composition of simpler shapes, or by direct generation via path-based techniques (e.g., extrusions, sweeps, revolves). While state-of-the-art PCAD tools effectively support position-based modelling, they lack expressive mechanisms for path-based modelling. As a result, shapes that are naturally formed by sweeping a 2D path into a 3D shape are difficult to model and use in these tools. This paper introduces TurtleTalk, a PCAD language that offers rich support for constructing path-based shapes and the composition of path-based and primitive shapes. TurtleTalk is an extension of PrintTalk, a PCAD language featuring constraints for composing constituent shapes into complex 3D models. TurtleTalk takes inspiration from turtle graphics for constructing paths using imperative instructions and uniquely integrates constraints to enable the declarative expression of path properties. Our evaluation shows that combining imperative instructions and declarative constraints facilitates the design of path-based shapes by reducing the need for complex manual calculations, while also enhancing their composability and reusability.
Jef Jacobs, Wolfgang De Meuter, Jens Nicolay
GPCE3
2025 PrintTalk: A Language for Constraint-Based 3D Modelling
Jef Jacobs, Wolfgang De Meuter, Jens Nicolay
CP3
2023 MODINF: Exploiting Reified Computational Dependencies for Information Flow Analysis
abstract
Information Flow Control is important for securing applications, primarily to preserve the confidentiality and integrity of applications and the data they process.Statically determining the flows of information for security purposes helps to secure applications early in the development pipeline.However, a sound and precise static analysis is difficult to scale.Modular static analysis is a technique for improving the scalability of static analysis.In this paper, we present an approach for constructing a modular static analysis for performing Information Flow Control for higher-order, imperative programs.A modular analysis requires information about data dependencies between modules.These dependencies arise as a result of information flows between modules, and therefore we piggy-back an Information Flow Control analysis on top of an existing modular analysis.Additionally, the resulting modular Information Flow Control analysis retains the benefits of its modular character.We validate our approach by performing an Information Flow Control analysis on 9 synthetic benchmark programs that contain both explicit and implicit information flows.
Jens Van der Plas, Jens Nicolay, Wolfgang De Meuter, Coen De Roover
ENASE2
2023 Brigadier: A Datalog-based IAST framework for Node.js Applications
abstract
The NODE.JS runtime, in combination with Node Package Manager (NPM), is a popular ecosystem for building server-side web applications. Both JavaScript’s flexible and dynamic character and the vast amount of NPM libraries available can speed up the development of web applications. However, JavaScript and NODE.JS lack security mechanisms and abstractions. Despite the numerous language-based approaches proposed to protect JavaScript applications, no work supports application-level and business-level security properties. This means that in order to achieve both application-level and business-level security, developers are forced to rely on multiple different, unintegrated and incompatible tools and mechanisms.In this paper, we present BRIGADIER1, an interactive security testing framework for NODE.JS applications that enables the specification of both application-level and business-level security policies. Brigadier provides developers with a Datalog-based policy specification language that features close interoperability with running JavaScript programs under test. Input JavaScript programs are instrumented to emit relevant application events sent to a Datalog engine resulting from the compilation of the policies. We exhibit Brigadier’s expressiveness by implementing three case studies from the literature. We also assess Brigadier’s performance overhead on server-side applications. In our benchmarks, we observed a slowdown factor ranging from∼1.2x to ∼3x, which is acceptable for a testing scenario.
Angel Luis Scull Pupo, Jens Nicolay, Elisa Gonzalez Boix
SANER2
2022 COAST: A Conflict-free Replicated Abstract Syntax Tree
Aäron Munsters, Angel Luis Scull Pupo, Jens Nicolay
ICSOFT3
2021 PrintTalk: a constraint-based imperative DSL for 3D printing
abstract
We present PrintTalk, a DSL to "program" 3D objects, called "gadgets". PrintTalk also features "topologies", which are predefined spacial arrangements of gadgets. Gadgets are composed by executing a gadget script (possibly consisting of subscripts) that 'draws' the gadget in the 3D scene. However, executing the script also returns a number of constraint variables. These variables can be constrained inside the gadget and can also be bound outside the gadget in order to constrain the produced gadgets after the facts. This is the essence of the gadget composition mechanism of PrintTalk.
Jef Jacobs, Jens Nicolay, Christophe De Troyer, Wolfgang De Meuter
DSM@SPLASH2
2019 Effect-Driven Flow Analysis
Jens Nicolay, Quentin Stiévenart, Wolfgang De Meuter, Coen De Roover
VMCAI1
2019 GUARDIAML: Machine Learning-Assisted Dynamic Information Flow Control
abstract
Developing JavaScript and web applications with confidentiality and integrity guarantees is challenging. Information flow control enables the enforcement of such guarantees. However, the integration of this technique into software tools used by developers in their workflow is missing. In this paper we present GUARDIAML, a machine learning-assisted dynamic information flow control tool for JavaScript web applications. GUARDIAML enables developers to detect unwanted information flow from sensitive sources to public sinks. It can handle the DOM and interaction with internal and external libraries and services. Because the specification of sources and sinks can be tedious, GUARDIAML assists in this process by suggesting the tagging of sources and sinks via a machine learning component.
Angel Luis Scull Pupo, Jens Nicolay, Kyriakos Efthymiadis, Ann Nowé, Coen De Roover, Elisa Gonzalez Boix
SANER2
2019 A general method for rendering static analyses for diverse concurrency models modular
Quentin Stiévenart, Jens Nicolay, Wolfgang De Meuter, Coen De Roover
J. Syst. Softw.2
2018 Building IoT Systems Using Distributed First-Class Reactive Programming
abstract
Contemporary IoT systems are challenging to develop, deploy, and maintain. This is because of their ever-increasing scale, dynamic network topologies, heterogeneity and resource constraints of the involved devices, and failures that may occur as a result of these characteristics. Existing approaches are either not at the right level of abstraction, require developers to learn specialized languages, or miss certain key features to address all these challenges in a uniform manner. In this paper we leverage reactive programming and code mobility to support the entire life-cycle of large-scale IoT systems. Our approach is based on existing programming technologies and offers simple and composable abstractions to developers. We implemented our approach in a middleware called Potato and used it to develop and deploy an IoT application on a Raspberry Pi cluster. We found that using Potato reduces much of the accidental complexity associated with developing and deploying IoT systems, resulting in clean and maintainable programs.
Christophe De Troyer, Jens Nicolay, Wolfgang De Meuter
CloudCom2
2018 Practical Information Flow Control for Web Applications
Angel Luis Scull Pupo, Laurent Christophe, Jens Nicolay, Coen De Roover, Elisa Gonzalez Boix
RV3
2017 Mailbox Abstractions for Static Analysis of Actor Programs
abstract
Properties such as the absence of errors or bounds on mailbox sizes are hard to deduce statically for actor-based programs. This is because actor-based programs exhibit several sources of unboundedness, in addition to the non-determinism that is inherent to the concurrent execution of actors. We developed a static technique based on abstract interpretation to soundly reason in a finite amount of time about the possible executions of an actor-based program. We use our technique to statically verify the absence of errors in actor-based programs, and to compute upper bounds on the actors' mailboxes. Sound abstraction of these mailboxes is crucial to the precision of any such technique. We provide several mailbox abstractions and categorize them according to the extent to which they preserve message ordering and multiplicity of messages in a mailbox. We formally prove the soundness of each mailbox abstraction, and empirically evaluate their precision and performance trade-offs on a corpus of benchmark programs. The results show that our technique can statically verify the absence of errors for more benchmark programs than the state-of-the-art analysis.
Quentin Stiévenart, Jens Nicolay, Wolfgang De Meuter, Coen De Roover
ECOOP2
2017 Implementing a performant scheme interpreter for the web in asm.js
abstract
This paper presents the implementation of an efficient interpreter for a Scheme-like language using manually written asm.js code. The asm.js specification defines an optimizable subset of JavaScript that has already served well as a compilation target for web applications where performance is critical. However, its usage as a human-writable language that can be integrated into existing projects to improve performance has remained largely unexplored. We therefore apply this strategy to optimize the implementation of an interpreter. We also discuss the feasibility of this approach, as writing asm.js by hand is generally not its recommended use-case. We therefore present a macro system to solve the challenges we encounter. The resulting interpreter is compared to the original C implementation and its compiled equivalent in asm.js. This way, we evaluate whether manual integration with asm.js provides the necessary performance to bring larger applications and runtimes to the web. We also refactor our implementation to assess how more JavaScript code can cohabit with asm.js code, improving maintainability of the implementation while preserving near-native performance. In the case of our interpreter, this improved maintainability enables adding more complex optimizations. We investigate the addition of function inlining , for which we validate the performance gain.
Noah Van Es, Quentin Stiévenart, Jens Nicolay, Theo D'Hondt, Coen De Roover
Comput. Lang. Syst. Struct.3
2017 Purity analysis for JavaScript through abstract interpretation
abstract
Abstract We present a static analysis for determining whether and to what extent functions in JavaScript programs are pure. To this end, the analysis classifies functions as pure functions, observers, or procedures. A function is pure if none of its executions generate or depend upon externally observable side effects. A function is an observer as soon as one of its executions depends on an external side effect, but none of its executions generate observable side effects. Otherwise, the function is classified as a procedure. Function executions and associated callers are found by traversing all reachable function execution contexts on the call stack at the point where an effect occurs. Our approach is based on a flow analysis that, in addition to computing traditional control and value flow, keeps track of read and write effects. To increase the precision of our purity analysis, we combine it with an intraprocedural analysis that determines freshness of variables and objects. We formalize the core aspects of our technique and discuss its implementation and results on common JavaScript benchmarks. Results show that our approach is capable of determining function purity in the presence of higher‐order functions, dynamic property expressions, and prototypal inheritance. When compared with existing purity analyses, we find that our approach is as precise or more precise than the existing analyses.
Jens Nicolay, Quentin Stiévenart, Wolfgang De Meuter, Coen De Roover
J. Softw. Evol. Process.1
2015 Poster: Static Analysis of Concurrent Higher-Order Programs
abstract
Few static analyses support concurrent higher-order programs. Tools for detecting concurrency bugs such as deadlocks and race conditions are nonetheless invaluable to developers. Concurrency can be implemented using a variety of models, each supported by different synchronization primitives. Using this poster, we present an approach for analyzing concurrent higher-order programs in a precise manner through abstract interpretation. We instantiate the approach for two static analyses that are capable of detecting deadlocks and race conditions in programs that rely either on compare-and-swap (cas), or on conventional locks for synchronization. We observe few false positives and false negatives on a corpus of small concurrent programs, with better results for the lock-based analyses. We also observe that these programs lead to a smaller state space to be explored by the analyses. Our results show that the choice of synchronization primitives supported by an abstract interpreter has an important impact on the complexity of the static analyses performed with this abstract interpreter.
Quentin Stiévenart, Jens Nicolay, Wolfgang De Meuter, Coen De Roover
ICSE (2)2
2015 Detecting concurrency bugs in higher-order programs through abstract interpretation
abstract
Manually detecting bugs in concurrent programs is hard due to the myriad of thread interleavings that needs to be accounted for. Higher-order programming features only exacerbate this difficulty. The need for tool support therefore increases as these features become more widespread. We investigate the P(CEK*)S abstract machine as the foundation for tool support for detecting concurrency bugs. This abstract interpreter analyzes multi-threaded, higher-order programs with shared-store concurrency and a compare-and-swap synchronization primitive. In this paper, we evaluate two different approaches to reduce the size of the state space explored by the abstract interpreter. First, we integrate abstract garbage collection into the abstract interpreter, and we observe that it does not reduce the state space as expected. We then evaluate the impact of adding first-class support for locks on the machine's client analyses. To this end, we compare a cas-based and a lock-based formulation of race condition and deadlock detection analyses. We show that adding first-class support for locks not only significantly reduces the number of abstract program states that need to be explored, but also simplifies formulating the client analyses.
Quentin Stiévenart, Jens Nicolay, Wolfgang De Meuter, Coen De Roover
PPDP2
2015 Detecting function purity in JavaScript
abstract
We present an approach to detect function purity in JavaScript. A function is pure if none of its applications cause observable side-effects. The approach is based on a pushdown flow analysis that besides traditional control and value flow also keeps track of write effects. To increase the precision of our purity analysis, we combine it with an intraprocedural analysis to determine freshness of variables and object references. We formalize the core aspects of our analysis, and discuss our implementation used to analyze several common JavaScript benchmarks. Experiments show that our technique is capable of detecting function purity, even in the presence of higher-order functions, dynamic property expressions, and prototypal inheritance.
Jens Nicolay, Carlos Noguera, Coen De Roover, Wolfgang De Meuter
SCAM1
2013 Determining dynamic coupling in JavaScript using object type inference
abstract
Coupling in an object-oriented context is often defined in terms of access to instance variables and methods of other classes. JavaScript, however, lacks static type information and classes, and instead features a flexible object system with prototypal inheritance. In order to determine coupling in JavaScript, we infer object types based on abstract interpretation of a program. Type inference depends on both structure and behavior of objects, and common patterns for expressing classes and modules are supported. We approximate a set of accessed types per function, and classify every access as either local or foreign. Examples demonstrate that our object type inference, together with some additional heuristics concerning property access, enable determining coupling in JavaScript in a meaningful way.
Jens Nicolay, Carlos Noguera, Coen De Roover, Wolfgang De Meuter
SCAM1
2011 Automatic Parallelization of Side-Effecting Higher-Order Scheme Programs
abstract
The multi-core revolution heralds a challenging era for software maintainers. Manually parallelizing large sequential code bases is often infeasible. In this paper, we present a program transformation that automatically parallelizes real-life Scheme programs. The transformation has to be instantiated with an interprocedural dependence analysis that exposes parallelization opportunities in a sequential program. To this end, we extended a state-of-the art analysis that copes with higher-order procedures and side effects. Our parallelizing transformation exploits all opportunities for parallelization that are exposed by the dependence analysis. Experiments demonstrate that this brute-force approach realizes scalable speedups in certain benchmarks, while others would benefit from a more selective parallelization.
Jens Nicolay, Coen De Roover, Wolfgang De Meuter, Viviane Jonckers
SCAM1