VLDB 2026 Research / reviewers in the wild / expert
Alberto Coen-Porisini
dblp:90/5778
· DBLP profile ↗
46ranked-venue papers
9as first author
13since 2021 · last 2026
0000-0002-3788-8926ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 17 · 1 first-author · 6 since 2021Software engineering, systems software and programming languages · 14 · 7 first-authorDatabases, data management, data science and information retrieval · 4Systems, architecture and hardware · 3 · 1 first-author · 2 since 2021Security and privacy · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Ethical treatment of language models against harmful inference-time interventionsabstractOpen-weights large language models and low-cost steering methods are strongly democratising the crafting of custom artificial intelligence-based assistants. This benefit comes with the side effect of expanding the potential risks associated with the harmful, toxic, or other undesired uses of neural language models. Language model immunisation is a quite novel research area that seeks to mitigate these risks. Immunised models are pre-trained models whose weights are hard to fine-tune toward harmful or dual tasks. While existing works on immunisation focus on resistance against full-parameter or parameter-efficient fine-tuning, this paper proposes a candidate strategy to neutralise models against low-cost attacks based on Inference-Time interventions (ITI). The proposed approach is called Ethical Treatment ( E.T. ), 1 1 The term ‘Ethical Treatment’ refers to the technical process of immunising models, not to solving normative ethical questions. and consists of training layer-wise low-rank adaptors to locally neutralise attacks at the decoder-block level of Transformer-based models. Pilot experiments on Llama-3-8B-Instruct demonstrate E.T. ’s effectiveness in reducing ITI-attack success rates while preserving utility on general-purpose tasks. Evaluation across the TinyBenchmarks suite shows that E.T. maintains strong performance on commonsense reasoning, and world knowledge, with primary degradation limited to mathematical reasoning. While not solving the broader immunisation challenge, these results position E.T. as a promising step toward structurally robust open-weight models. 2 2 Code, reproducibility scripts, and compute requirement specification are available at https://github.com/DISTA-HCAI/ET . Jesús Fernando Cevallos Moreno, Alessandra Rizzardi, Sabrina Sicari, Alberto Coen-Porisini |
Eng. Appl. Artif. Intell. | 4 |
| 2025 | Open-FARI: An Open-source testbed for Federated Anomaly detection in the Railway Industrial Internet of ThingsabstractThe paper presents Open-FARI, an open-source testbed for evaluating federated learning algorithms for anomaly detection in the railway Industrial Internet of Things domain. Open-FARI uses synthetic data generation modules trained from real train sensor data to generate realistic sensor data of a fleet of trains. Generated data encompass normal and anomalous data, enabling the evaluation of federated learning algorithms for anomaly detection. The paper addresses the lack of testbeds and datasets tailored to the railway domain, which represents an obstacle to research on Machine Learning-driven solutions in this domain. Alessandra Rizzardi, Raffaele Della Corte, Jesús Fernando Cevallos Moreno, Simona De Vivo, Vittorio Orbinato, Sabrina Sicari, Domenico Cotroneo, Alberto Coen-Porisini |
IWCMC | 8 |
| 2025 | HERO: From High-dimensional network traffic to zERO-Day attack detectionabstractRecent trends in zero-day attack (ZdA) detection use collective anomaly detection to give insights on out-of-distribution anomalies in a zero-shot fashion. Among these, existing frameworks propose the use of specialised labelling strategies to mimic a step-wise abstract anomaly detection algorithm that generalise ZdA-detection over low-dimensional traffic-flow statistics. To enlarge such applicative scenarios, this paper proposes hero , which is compatible with H igh-dimensional raw-network traffic captures when performing z ERO -day attack detection. To reach convergence over such a high-dimensional and noisy input space, hero decouples the representation task and the correspondent gradient updates from the discriminative task, following the neural algorithmic reasoning blueprint. Specifically, a neural processor is first trained on the discriminative task using synthetic data, and the weights are then frozen. A second training phase successfully optimises the encoding and decoding networks using raw-traffic captures and the algorithmically-aligned processor. Experiments with well-known intrusion detection datasets demonstrate the crucial advantage of using a two-stage training framework to achieve convergence. To the best of the authors’ knowledge, hero is the first deep learning-based instrument that performs collective anomaly detection and categorisation over raw network traffic on a zero-shot basis, i.e., without using labels. Jesús Fernando Cevallos Moreno, Alessandra Rizzardi, Sabrina Sicari, Alberto Coen-Porisini |
Comput. Networks | 4 |
| 2025 | Attribute-based policies through microservices in a smart home scenarioabstractApplication containerization allows for efficient resource utilization and improved performance when compared to traditional virtualization techniques . However, managing multiple containers and providing services such as load balancing, fault tolerance and security represent challenging tasks in the emerging microservices architectures. In this context, Kubernetes platform allows to build resilient distributed containers. Besides its efficiency in terms of configuration and architectural resiliency, it must also guarantee the access control to the managed resources. In fact, information must be protected throughout the different microservices which compose an application. To cope with such an issue, this paper proposes the definition of attribute-based policies able to regulate data disclosure within a Kubernetes-based microservices network. Simulations are carried out in a local Minikube environment, considering a smart residence scenario. The investigated metrics include response time , required memory, CPU load, and disk usage. Alessandra Rizzardi, Sabrina Sicari, Alberto Coen-Porisini |
Comput. Commun. | 3 |
| 2024 | RaiIRED: a Node-RED-Based Framework for Modeling Train Control Management SystemsabstractThe modeling and simulation of Internet of Things (IoT) and Industrial IoT (IIoT) systems allow practitioners to obtain valuable insights into the system's behavior before their actual deployment in the field. Early designing permits the analysis of the interactions among the involved entities, evaluating the effects of modifications, and understanding the impact of failures on the system. In particular, this is exacerbated in the context of IoT/IIoT, which is characterized by multiple and heterogeneous subsystems, different processing levels, and communication protocols. In such a direction, recent innovations in IT devices have enabled the rail industry to gather information from Train Control and Monitoring Systems (TCMS) to check conditions constantly and prevent issues, thus improving relia-bility and safety and, in some cases, leading to cost-saving by optimizing maintenance resources. In such a scenario, this paper presents RailRED, a framework for simulating and prototyping a TCMS based on the Node-RED tool. In RaiIRED, the main TCMS subsystems are modeled using Node-RED flows, while the subsystem interconnections are performed through a low footprint and encrypted gateway based on the MQTT protocol. The proposal can also generate diagnostic data that mimic the behavior of a real-world TCMS. RailRED communication latency and its ability to generate diagnostic data have been analyzed, with the latter evaluated by using clusters of diagnostic events collected from a real-world TCMS running on a high-speed train. Alessandra Rizzardi, Raffaele Della Corte, Jesús Fernando Cevallos Moreno, Vittorio Orbinato, Simona De Vivo, Sabrina Sicari, Domenico Cotroneo, Alberto Coen-Porisini |
WiMob | 8 |
| 2024 | ASAP: Automatic Synthesis of Attack Prototypes, an online-learning, end-to-end approachabstractZero-day attack detection and categorization is an open-research field where four main context factors need to be taken into account: novel or zero-day attacks (i) are unlabeled by definition, (ii) may correspond to out-of-distribution data, (iii) can arise concurrently, and (iv) distribution shifts in the feature space need online-learning. Given such constraints, the online detection and categorization of new cyber threats can be modeled as a heterogeneous collective anomaly detection problem, for which no online-learning solutions exist purely based on back-propagation. To this respect, this paper presents an online-learning, end-to-end back-propagation strategy for Automatically Synthesizing the potential signatures or Attack Prototypes of novel cyber threats ( asap ). The presented framework incorporates automatic feature engineering, operating over raw data from the OpenFlow monitoring API and raw bytes of traffic captures. In asap , specialized inductive biases enhance the training data efficiency and accommodate the inference machinery to resource-constrained scenarios such as the Internet of Things. Finally, the validity of this framework is demonstrated in a live training experiment comprising IoT traffic emulation 3 3 To foster research in the field, the source-code of asap alongside instructions to reproduce the experiments are made publicly available among the set of SmartVille NID models in [1] . . Jesús Fernando Cevallos Moreno, Alessandra Rizzardi, Sabrina Sicari, Alberto Coen-Porisini |
Comput. Networks | 4 |
| 2024 | NERO: NEural algorithmic reasoning for zeRO-day attack detection in the IoT: A hybrid approachabstractAnomaly detection approaches for network intrusion detection learn to identify deviations from normal behavior on a data-driven basis. However, current approaches strive to infer the degree of abnormality of out-of-distribution samples when these appertain to different zero-day attacks. Inspired by the successes of the neural algorithmic reasoning paradigm to leverage the generalization of rule-based behavior, this paper presents a deep learning strategy for solving zero-day network attack detection and categorization. Moreover, focusing on the particular scenario of the Internet of Things (IoT), the privacy preservation requirement may imply a low training data regime for any learning algorithm. To this respect, the presented framework uses metric-based meta-learning to achieve few-shot learning capabilities. The presented pipeline is called NERO, as it imports the encode-process-decode architecture from the NEural algorithmic reasoning blueprint to converge zeRO-day attack detection policies within constrained training data. Jesús Fernando Cevallos Moreno, Alessandra Rizzardi, Sabrina Sicari, Alberto Coen-Porisini |
Comput. Secur. | 4 |
| 2024 | IoT-driven blockchain to manage the healthcare supply chain and protect medical recordsabstractHealthcare supply chain domain and medical records’ management face numerous challenges that come with new demands, such as customer dissatisfaction, rising healthcare costs, tracking and traceability of drugs, and security and privacy related to the sensitive information managed in such a domain. Executing processes related to healthcare domain in a trusted, secure, efficient, accessible and traceable manner is challenging due to the fragmented nature of the healthcare supply chain, which is prone to systemic errors and redundant efforts that may compromise patient safety and negatively impact health outcomes. To cope with such issues, blockchain technology, combined with the Internet of Things (IoT), can offers a reliable way to track and trace products and protect medical data though a peer-to-peer distributed, secure, and shared ledger. Hence, this paper proposes an IoT-driven blockchain-based architecture to manage the healthcare supply chain and protect medical records from tampering and access violation. Hyperledger Fabric, which is a permissioned blockchain, has been adopted due to the sensitive and private nature of the collected data. The envisioned network has been implemented and performance has been evaluated in terms of execution time, resources consumption and throughput. Alessandra Rizzardi, Sabrina Sicari, Jesús Fernando Cevallos Moreno, Alberto Coen-Porisini |
Future Gener. Comput. Syst. | 4 |
| 2023 | Deep Reinforcement Learning for intrusion detection in Internet of Things: Best practices, lessons learnt, and open challenges
Jesús Fernando Cevallos Moreno, Alessandra Rizzardi, Sabrina Sicari, Alberto Coen-Porisini |
Comput. Networks | 4 |
| 2022 | Security&privacy issues and challenges in NoSQL databases
Sabrina Sicari, Alessandra Rizzardi, Alberto Coen-Porisini |
Comput. Networks | 3 |
| 2022 | Insights into security and privacy towards fog computing evolution
Sabrina Sicari, Alessandra Rizzardi, Alberto Coen-Porisini |
Comput. Secur. | 3 |
| 2022 | Securing the access control policies to the Internet of Things resources through permissioned blockchainabstractAbstract Security and privacy of information transmitted among the devices involved in an Internet of Things (IoT) network represent relevant issues in IoT contexts. Guaranteeing effective control and supervising access permissions to IoT applications is a complex task, mainly due to resources' heterogeneity and scalability requirements. The design and development of highly customizable access control policies, along with an efficient mechanism for ensuring that the rules applied by the IoT platform are not tampered with or violated, will undoubtedly have a significant impact on the diffusion of IoT‐based solutions. In such a direction, the article proposes the integration of a permissioned blockchain within an honest‐but‐curious (i.e., not trusted) IoT distributed middleware layer, which aims to guarantee the correct management of access to resources by the interested parties. The result is a robust and lightweight system, able to manage the data produced by IoT devices, support relevant security features, such as integrity and confidentiality, and resist different kinds of attacks. The use of blockchain will ensure the tamper‐resistance and synchronization of the distributed system, where various stakeholders own applications and IoT platforms. The methodology and the proposed architecture are validated employing a test‐bed. Alessandra Rizzardi, Sabrina Sicari, Daniele Miorandi, Alberto Coen-Porisini |
Concurr. Comput. Pract. Exp. | 4 |
| 2022 | Analysis on functionalities and security features of Internet of Things related protocolsabstractAbstract The Internet of Things (IoT) paradigm is characterized by the adoption of different protocols and standards to enable communications among heterogeneous and, often, resource-constrained devices. The risk of violation is high due to the wireless nature of the communication protocols usually involved in the IoT environments (e.g., e-health, smart agriculture, industry 4.0, military scenarios). For such a reason, proper security countermeasures must be undertaken, in order to prevent and react to malicious attacks, which could hinder the data reliability. In particular, the following requirements should be addressed: authentication, confidentiality, integrity, and authorization. This paper aims at investigating such security features, which are often combined with native functionalities, in the most known IoT-related protocols: MQTT, CoAP, LoRaWAN, AMQP, RFID, ZigBee, and Sigfox. The advantages and weaknesses of each one will be revealed, in order to point out open issues and best practices in the design of efficient and robust IoT network infrastructure. Alessandra Rizzardi, Sabrina Sicari, Alberto Coen-Porisini |
Wirel. Networks | 3 |
| 2020 | 5G In the internet of things era: An overview on security and privacy challenges
Sabrina Sicari, Alessandra Rizzardi, Alberto Coen-Porisini |
Comput. Networks | 3 |
| 2020 | Sticky Policies: A SurveyabstractIn the digital age, where the Internet connects things across the globe and individuals are constantly online, data security and privacy are becoming key drivers (and barriers) of change for adoption of innovative solutions. Traditional approaches, whereby communication links are secured by means of encryption, and access control is run in a static way by a centralized authority, are showing their limits when applied to massive-scale, interconnected and distributed systems. Regulations, while still fragmented, are moving to adapt to changes in technology and society, with the aim to protect confidential information by governments, businesses, and individual citizens. In this landscape, proper mechanisms should be defined to allow a strict control over the data life-cycle and to guarantee the privacy and the application of specific regulations on personal information's disclosure, usage and access. Sticky policies represent one approach to improve owners' control over their data. In such an approach, machine-readable policies are attached to data. They are called 'sticky' in that they travel together with data, as data travels across multiple administrative domains. In this article we survey the state-of-the-art in sticky policies, discussing limitations, open issues, applications and research challenges, with a specific focus on their applicability to Internet of Things, cloud computing, and Content Centric Networking. Daniele Miorandi, Alessandra Rizzardi, Sabrina Sicari, Alberto Coen-Porisini |
IEEE Trans. Knowl. Data Eng. | 4 |
| 2019 | Beyond the smart things: Towards the definition and the performance assessment of a secure architecture for the Internet of Nano-Things
Sabrina Sicari, Alessandra Rizzardi, Giuseppe Piro, Alberto Coen-Porisini, Luigi Alfredo Grieco |
Comput. Networks | 4 |
| 2019 | How to evaluate an Internet of Things system: Models, case studies, and real developmentsabstractSummary The paper proposes the use of Node‐RED, a flow‐based programming tool targeted to Internet of Things (IoT), along with a series of case studies related to different IoT contexts, which demonstrate Node‐RED's potentialities and outcomings toward the realization of well‐structured IoT environments. The analyzed applications potentially include a wide range of domains, ranging from smart cities, smart buildings, smart homes/offices, smart retailing, to smart transportation, smart logistics, smart agriculture, smart health, military scenarios, and so on. The motivations behind the presented work are related to the fact that IoT application fields usually involve the same technologies and communication protocols, which are frequently adopted for totally different purposes. Issues such as systems' interoperabiliy, scalability, security and privacy naturally emerge, due to the huge amount of heterogeneous devices acting in the IoT environment itself and to the wireless nature of information transmissions. As a consequence, it is fundamental to dispose of adequate tools for supporting developers in design the network architecture and messages' exchange, in order to realize efficient and effective IoT network infrastructures. Sabrina Sicari, Alessandra Rizzardi, Alberto Coen-Porisini |
Softw. Pract. Exp. | 3 |
| 2018 | REATO: REActing TO Denial of Service attacks in the Internet of Things
Sabrina Sicari, Alessandra Rizzardi, Daniele Miorandi, Alberto Coen-Porisini |
Comput. Networks | 4 |
| 2018 | A risk assessment methodology for the Internet of Things
Sabrina Sicari, Alessandra Rizzardi, Daniele Miorandi, Alberto Coen-Porisini |
Comput. Commun. | 4 |
| 2018 | S2 DCC: secure selective dropping congestion control in hybrid wireless multimedia sensor networks
Michele Tortelli, Alessandra Rizzardi, Sabrina Sicari, Luigi Alfredo Grieco, Gennaro Boggia, Alberto Coen-Porisini |
Wirel. Networks | 6 |
| 2017 | Dynamic Policies in Internet of Things: Enforcement and SynchronizationabstractSecurity and privacy represent critical issues for a wide adoption of Internet of Things (IoT) technologies both by industries and people in their every-day life. Besides, the complexity of an IoT system's management resides in the presence of heterogeneous devices, which communicate by means of different protocols and provide information belonging to various application domains. Hence, adequate policies must be correctly distributed and applied to the information made available by the IoT network to secure the data themselves and to regulate the access to the managed resources over the whole IoT system. Policies mainly involve the access to resources and are usually established by system administrators in accordance with the rules of each specific domain. Since IoT concerns multiple application fields and often wide areas, a centralized solution which manages all the required policies would not be neither efficient nor scalable. Therefore, in this paper, a distributed middleware overlying the IoT network is proposed and integrated with a synchronization system for guaranteeing the correct distribution, update, and application of the policies across the entire IoT environment in real-time. Such a distribution and synchronization system has been developed within a policy enforcement framework. The presented solution has been validated by means of a simple yet real prototype; the analyzed metrics regard delay, overhead and robustness of the proposed enforcement and synchronization framework. Sabrina Sicari, Alessandra Rizzardi, Daniele Miorandi, Alberto Coen-Porisini |
IEEE Internet Things J. | 4 |
| 2017 | Security towards the edge: Sticky policy enforcement for networked smart objects
Sabrina Sicari, Alessandra Rizzardi, Daniele Miorandi, Alberto Coen-Porisini |
Inf. Syst. | 4 |
| 2017 | Performance Comparison of Reputation Assessment Techniques Based on Self-Organizing Maps in Wireless Sensor NetworksabstractMany solutions based on machine learning techniques have been proposed in literature aimed at detecting and promptly counteracting various kinds of malicious attack (data violation, clone, sybil, neglect, greed, and DoS attacks), which frequently affect Wireless Sensor Networks (WSNs). Besides recognizing the corrupted or violated information, also the attackers should be identified, in order to activate the proper countermeasures for preserving network’s resources and to mitigate their malicious effects. To this end, techniques adopting Self-Organizing Maps (SOM) for intrusion detection in WSN were revealed to represent a valuable and effective solution to the problem. In this paper, the mechanism, namely, Good Network (GoNe), which is based on SOM and is able to assess the reliability of the sensor nodes, is compared with another relevant and similar work existing in literature. Extensive performance simulations, in terms of nodes’ classification, attacks’ identification, data accuracy, energy consumption, and signalling overhead, have been carried out in order to demonstrate the better feasibility and efficiency of the proposed solution in WSN field. Sabrina Sicari, Alessandra Rizzardi, Luigi Alfredo Grieco, Alberto Coen-Porisini |
Wirel. Commun. Mob. Comput. | 4 |
| 2016 | Security policy enforcement for networked smart objects
Sabrina Sicari, Alessandra Rizzardi, Daniele Miorandi, Cinzia Cappiello, Alberto Coen-Porisini |
Comput. Networks | 5 |
| 2016 | AUPS: An Open Source AUthenticated Publish/Subscribe system for the Internet of Things
Alessandra Rizzardi, Sabrina Sicari, Daniele Miorandi, Alberto Coen-Porisini |
Inf. Syst. | 4 |
| 2016 | A secure and quality-aware prototypical architecture for the Internet of Things
Sabrina Sicari, Alessandra Rizzardi, Daniele Miorandi, Cinzia Cappiello, Alberto Coen-Porisini |
Inf. Syst. | 5 |
| 2015 | Security, privacy and trust in Internet of Things: The road ahead
Sabrina Sicari, Alessandra Rizzardi, Luigi Alfredo Grieco, Alberto Coen-Porisini |
Comput. Networks | 4 |
| 2014 | A NFP Model for Internet of Things applicationsabstractInternet of Things (IoT) involves heterogeneous technologies (i.e., WSN, RFID, actuators) able to exchange data acquired from the environment in order to provide services to the requesting users. In such a scenario the privacy and the quality (i.e., in terms of accuracy, timeliness, completeness) of the handled information represent critical issues. In fact, the provided services must be customized according to the users preferences and habits and have to manage both users personal information and data from different sources, therefore it needs to guarantee privacy and data quality level. This work proposes a UML general conceptual model, which defines the entities involved in the IoT context, their relationships, facing privacy policies definition and data quality assessment. Such a model should represent a starting point for the development of IoT privacy-aware solutions, handling data with a well-defined quality. Sabrina Sicari, Alessandra Rizzardi, Alberto Coen-Porisini, Cinzia Cappiello |
WiMob | 3 |
| 2013 | SETA: A secure sharing of tasks in clustered wireless sensor networksabstractSecure data aggregation still represents a very challenging topic in wireless sensor networks' research. In fact, only few solutions exists to face, simultaneously, confidentiality, integrity, adaptive aggregation, and privacy issues. Furthermore, proposals available in literature mainly assume flat network architectures, without leveraging the peculiarities of clustered wireless sensor networks, which are very common in real life deployments. This work tries to bridge the gap by proposing a solution, namely SETA, tailored to a hybrid architecture composed of wireless sensor nodes and wireless mesh routers as cluster heads. In SETA, to lower the processing workload of sensor nodes, only cluster heads are allowed to perform integrity verification checks and message merging operations to face possible network congestions. To prove its effectiveness, it has been compared, using simulations, with respect to DyDAP in several realistic settings. Results have shown that it can provide a slight improvement of the robustness to malicious nodes and of the sensing accuracy, while increasing the overall energy efficiency and decreasing the signaling overhead in the network. Sabrina Sicari, Luigi Alfredo Grieco, Alessandra Rizzardi, Gennaro Boggia, Alberto Coen-Porisini |
WiMob | 5 |
| 2013 | DARE: evaluating Data Accuracy using node REputation
Sabrina Sicari, Alberto Coen-Porisini, Roberto Riggio |
Comput. Networks | 2 |
| 2012 | Towards the Definition of a Framework for Service Development in the Agrofood Domain - A Conceptual Model
Donato Barbagallo, Cinzia Cappiello, Alberto Coen-Porisini, Pietro Colombo, Marco Comerio, Flavio De Paoli, Chiara Francalanci, Sabrina Sicari |
WEBIST | 3 |
| 2012 | Improving data quality using a cross layer protocol in wireless sensor networks
Alberto Coen-Porisini, Sabrina Sicari |
Comput. Networks | 1 |
| 2012 | DyDAP: A dynamic data aggregation scheme for privacy aware wireless sensor networks
Sabrina Sicari, Luigi Alfredo Grieco, Gennaro Boggia, Alberto Coen-Porisini |
J. Syst. Softw. | 4 |
| 2010 | A Meta-model Supporting the Decomposition of Problem DescriptionsabstractProblem frames are an approach to requirements modeling that is gaining increasing attention and popularity. A few meta-models have already been proposed to precisely define the notation and -in some cases- to support the construction of tools. However, the meta-models proposed till now concentrate on modeling the single problem frame, without addressing the whole problem. This is particularly limiting, since one of the strengths of the problem frames approach is in tackling the complexity of problems by guiding their decomposition into sub-problems, and in identifying recurring patterns of elementary problems. In order to support this fundamental activity, a meta-model has to support the notion of sub-problems and sub-domains, moreover it must provide suitable means to represent problems in intermediate situations during the (de)composition phases. This paper presents a meta-model that solves the aforementioned problems and provides a suitable base for the construction of a tool based on the EMF/GEF technology. Luigi Lavazza, Alberto Coen-Porisini, Pietro Colombo, Vieri Del Bianco |
ICSEA | 2 |
| 2009 | Towards a Meta-model for Problem Frames: Conceptual Issues and Tool Building SupportabstractProblem frames are an approach to requirements modeling that is gaining increasing attention and popularity. The approach provides useful concepts and methodological guidelines. However, problem frames are not equipped with an expressive and complete notation and they lack tools support. These limitations can be addressed by introducing a suitable meta-model to formally define the notation. In this way it is also possible to identify the aspects that are not covered by the problem frames notation and to provide hooks for user-defined extensions. The meta-model is also expected to support the underlying analysis methodology. Furthermore, it can provide the basis for building a tool supporting both the editing of problem frames and the other activities associated with the approach (frame concern, composition, etc.). This paper presents a meta-model that addresses the former issues and was used for building a tool with the EMF/GMF technology. Pietro Colombo, Luigi Lavazza, Alberto Coen-Porisini, Vieri Del Bianco |
ICSEA | 3 |
| 2007 | A Methodological Framework for SysML: a Problem Frames-based ApproachabstractRecently, SysML has been adopted by the Object Management Group as a modelling language for Systems Engineering. SysML is a UML profile that represents a subset of UML 2 with extensions. A wide adoption of the language could be hindered by the lack of a methodology that drives the modelling activities. Problem Frames (PFs) are a rigorous approach to requirements modelling that has the potential to improve the software development process. Unfortunately, PFs are not supported by an intuitive notation and easy to use tools. As a consequence, their adoption in industry is limited. This paper explores the possibility of exploiting the PFs ideas in the context of SysML models. The goal is to provide model-based development processes using SysML with a set of concepts and guidelines that are sound and have already been used and validated. Pietro Colombo, Vieri Del Bianco, Luigi Lavazza, Alberto Coen-Porisini |
APSEC | 4 |
| 2003 | A formal approach for designing CORBA-based applicationsabstractThe design of distributed applications in a CORBA-based environment can be carried out by means of an incremental approach, which starts from the specification and leads to the high-level architectural design. This article discusses a methodology to transform a formal specification written in TRIO into a high-level design document written in an extension of TRIO, named TRIO/CORBA (TC). The TC language is suited to formally describe the high-level architecture of a CORBA-based application. As a result, designers are offered high-level concepts that precisely define the architectural elements of an application. Furthermore, TC offers mechanisms to extend its base semantics, and can be adapted to future developments and enhancements in the CORBA standard. The methodology and the associated language are presented through a case study derived from a real Supervision and Control System. Alberto Coen-Porisini, Matteo Pradella, Matteo G. Rossi, Dino Mandrioli |
ACM Trans. Softw. Eng. Methodol. | 1 |
| 2001 | Using symbolic execution for verifying safety-critical systemsabstractSafety critical systems require to be highly reliable and thus special care is taken when verifying them in order to increase the confidence in their behavior. This paper addresses the problem of formal verification of safety critical systems by providing empirical evidence of the practical applicability of symbolic execution and of its usefulness for checking safety-related properties. In this paper, symbolic execution is used for building an operational model of the software on which safety properties, expressed by means of a Path Description Language (PDL), can be assessed. Alberto Coen-Porisini, Giovanni Denaro, Carlo Ghezzi, Mauro Pezzè |
ESEC / SIGSOFT FSE | 1 |
| 2000 | A formal approach for designing CORBA based applicationsabstractThe design of distributed applications in a CORBA based environment can be carried out by means of an incremental approach, which starts from the specification and leads to the high level architectural design. This is done by introducing in the specification all typical elements of CORBA and by providing a methodological support to the designers. The paper discusses a methodology to transform a formal specification written in TRIO into a high level design document written using an extension of TRIO named TC. The TC language is suited to formally describe the high level architecture of a CORBA based application. The methodology and the associated language are presented by means of an example involving a real Supervision and Control System. Matteo Pradella, Matteo G. Rossi, Dino Mandrioli, Alberto Coen-Porisini |
ICSE | 4 |
| 2000 | Using TRIO for designing a CORBA-based applicationabstractWe report on our experience in the Esprit OpenDREAMS project that targets the domain of Supervision and Control Systems (SCS). During this project we studied how a CORBA-based application can be designed starting from a typical SCS requirement document by integrating a formal approach with some CORBA concepts. We present a case study that shows how an existing object-oriented methodology based on the formal specification language TRIO can be tailored towards supporting CORBA-based applications. The application taken into account is in the field of the Energy Management Systems, namely a diagnostic system for the steam condenser of a thermoelectric power plant. The paper describes how to obtain the architectural design of a CORBA-based application starting from the formal specification of its requirements expressed in TRIO by means of a sequence of transformation steps. At the end of such sequence of steps a complete structure of the application classes, with their mutual relations and their IDL interfaces, is built. Finally, the paper discusses how TRIO can be used to validate the architectural choices made with respect to the application critical requirements. Copyright © 2000 John Wiley & Sons, Ltd. Alberto Coen-Porisini, Dino Mandrioli |
Concurr. Pract. Exp. | 1 |
| 1999 | From Formal Models to Formally Based Methods: An Industrial ExperienceabstractWe address the problem of increasing the impact of formal methods in the practice of industrial computer applications. We summarize the reasons why formal methods so far did not gain widespead use within the industrial environment despite several promising experiences. We suggest an evolutionary rather than revolutionary attitude in the introduction of formal methods in the practice of industrial applications, and we report on our long-standing experience which involves an academic institution. Politecnico di Milano, two main industrial partners, ENEL and CISE, and occasionally a few other industries. Our approach aims at augmenting an existing and fairly deeply rooted informal industrial methodology with our original formalism, the logic specification language TRIO. On the basis of the experiences we gained we argue that our incremental attitude toward the introduction of formal methods within the industry could be effective largely independently from the chosen formalism. Emanuele Ciapessoni, Piergiorgio Mirandola, Alberto Coen-Porisini, Dino Mandrioli, Angelo Morzenti |
ACM Trans. Softw. Eng. Methodol. | 3 |
| 1997 | Specification of Realtime Systems Using ASTRALabstractASTRAL is a formal specification language for real-time systems. It is intended to support formal software development and, therefore, has been formally defined. The structuring mechanisms in ASTRAL allow one to build modularized specifications of complex systems with layering. A real-time system is modeled by a collection of state machine specifications and a single global specification. This paper discusses the rationale of ASTRAL's design. ASTRAL's specification style is illustrated by discussing a telephony example. Composability of one or more ASTRAL system specifications is also discussed by the introduction of a composition section, which provides the needed information to combine two or more ASTRAL system specifications. Alberto Coen-Porisini, Carlo Ghezzi, Richard A. Kemmerer |
IEEE Trans. Software Eng. | 1 |
| 1994 | A Formal Framework for ASTRAL Intralevel Proof ObligationsabstractASTRAL is a formal specification language for real-time systems. It is intended to support formal software development, and therefore has been formally defined. This paper focuses on how to formally prove the mathematical correctness of ASTRAL specifications. ASTRAL is provided with structuring mechanisms that allow one to build modularized specifications of complex systems with layering. In this paper, further details of the ASTRAL environment components and the critical requirements components, which were not fully developed in previous papers, are presented. Formal proofs in ASTRAL can be divided into two categories: interlevel proofs and intralevel proofs. The former deal with proving that the specification of level i+1 is consistent with the specification of level i, and the latter deal with proving that the specification of level i is consistent and satisfies the stated critical requirements. This paper concentrates on intralevel proofs.> Alberto Coen-Porisini, Richard A. Kemmerer, Dino Mandrioli |
IEEE Trans. Software Eng. | 1 |
| 1993 | The Composability of ASTRAL Realtime SpecificationsabstractASTRAL is a formal specification language for realtime systems. It is intended to support formal software development, and therefore has been formally defined. In ASTRAL a realtime system is modeled by a collection of state machine specifications and a single global specification. Alberto Coen-Porisini, Richard A. Kemmerer |
ISSTA | 1 |
| 1993 | Array Representation in Symbolic Execution
Alberto Coen-Porisini, Flavio De Paoli |
Comput. Lang. | 1 |
| 1991 | Software Specialization Via Symbolic ExecutionabstractA technique and an environment-supporting specialization of generalized software components are described. The technique is based on symbolic execution. It allows one to transform a generalized software component into a more specific and more efficient component. Specialization is proposed as a technique that improves software reuse. The idea is that a library of generalized components exists and the environment supports a designer in customizing a generalized component when the need arises for reusing it under more restricted conditions. It is also justified as a reengineering technique that helps optimize a program during maintenance. Specialization is supported by an interactive environment that provides several transformation tools: a symbolic executor/simplifier, an optimizer, and a loop refolder. The conceptual basis for these transformation techniques is described, examples of their application are given, and how they cooperate in a prototype environment for the Ada programming language is outlined.> Alberto Coen-Porisini, Flavio De Paoli, Carlo Ghezzi, Dino Mandrioli |
IEEE Trans. Software Eng. | 1 |