Jennifer Horkoff

dblp:92/5983 · DBLP profile ↗
← Back
71ranked-venue papers
16as first author
28since 2021 · last 2026
0000-0002-2019-5277ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 56 · 10 first-author · 26 since 2021Databases, data management, data science and information retrieval · 9 · 3 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 6 · 4 since 2021Security and privacy · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-authorTheory of computation · 1
YearPublicationVenuePosition
2026 Recommendations for efficient and responsible LLM adoption within industrial software development
abstract
Context: Large language models (LLMs) are observed to have a significant positive impact on various software engineering (SE) activities. With improved accessibility, the adoption of powerful LLMs in industry has surged recently. However, there is a lack of actionable best practices for the efficient and responsible adoption of LLMs within industrial software settings. Objectives: We developed seven actionable recommendations to address this research gap. Methods: We conducted a multi-case study with three organisations that use LLMs within their SE activities and synthesised seven recommendations through qualitative thematic analysis. We conducted a complementary online survey with software practitioners from various industries to evaluate the perceived relevance of our recommendations. Results: Our results and recommendations focus on (i) users’ preference to use LLMs as AI assistants, (ii) the importance of relevant stakeholders’ satisfaction in the LLM-output evaluation, (iii) scoping the applicability of LLMs within SE tasks, (iv) the effect of LLMs on SE workflows, (v) the necessity and directions for developing human oversight mechanisms, and (vi) the necessary skills for practitioners for leveraging LLMs within SE. The online survey indicates a high level of agreement from the participants regarding the perceived relevance of the recommendations. Conclusion: We outline future research directions, including mapping the seven recommendations to the principles of the EU AI Act (AIA) in order to examine how they relate to the current regulatory compliance frameworks.
Krishna Ronanki, Beatriz Cabrero-Daniel, Tomas Herda, Stefan Sitkovich, Jennifer Horkoff, Christian Berger 0001
Inf. Softw. Technol.5
2025 From Machine Learning Documentation to Requirements: Bridging Processes with Requirements Languages
Hans-Martin Heyn, Jennifer Horkoff
PROFES3
2025 Data Annotation: A Requirements Engineering for Machine Learning Systems Perspective
abstract
Data annotation, the systematic labeling of raw data (e.g., images, text) [1] , is foundational to the training of machine learning (ML) models, particularly in supervised learning. While data’s importance is clear, the specific processes and requirements for how this data should be annotated, appear inconsistently defined or informal within existing ML software system (MLS) development methodologies [2] . The effective specification of data annotation requirements, the challenges involved, and the traceability from system requirements to annotation activities represent critical considerations in the ML development lifecycle. Understanding these aspects is pertinent for AI/ML engineers and data scientists, requirements engineers, and organizations developing AI solutions.
Hina Saeeda, Hans-Martin Heyn, Jennifer Horkoff
RE4
2025 Extending Behavior Trees for Robotic Missions with Quality Requirements
Razan Ghzouli, Rebekka Wohlrab, Jennifer Horkoff
REFSQ3
2025 Requirements Representations in Machine Learning-Based Automotive Perception Systems Development for Multi-party Collaboration
Hina Saeeda, Zuzana Rohacova, Oskar Jakobsson, Hans-Martin Heyn, Eric Knauss, Alessia Knauss, Jennifer Horkoff
REFSQ7
2025 Design pattern recognition: a study of large language models
abstract
Abstract Context As Software Engineering (SE) practices evolve due to extensive increases in software size and complexity, the importance of tools to analyze and understand source code grows significantly. Objective This study aims to evaluate the abilities of Large Language Models (LLMs) in identifying DPs in source code, which can facilitate the development of better Design Pattern Recognition (DPR) tools. We compare the effectiveness of different LLMs in capturing semantic information relevant to the DPR task. Methods We studied Gang of Four (GoF) DPs from the P-MARt repository of curated Java projects. State-of-the-art language models, including Code2Vec, CodeBERT, CodeGPT, CodeT5, and RoBERTa, are used to generate embeddings from source code. These embeddings are then used for DPR via a k-nearest neighbors prediction. Precision, recall, and F1-score metrics are computed to evaluate performance. Results RoBERTa is the top performer, followed by CodeGPT and CodeBERT, which showed mean F1 Scores of 0.91, 0.79, and 0.77, respectively. The results show that LLMs without explicit pre-training can effectively store semantics and syntactic information, which can be used in building better DPR tools. Conclusion The performance of LLMs in DPR is comparable to existing state-of-the-art methods but with less effort in identifying pattern-specific rules and pre-training. Factors influencing prediction performance in Java files/programs are analyzed. These findings can advance software engineering practices and show the importance and abilities of LLMs for effective DPR in source code.
Sushant Kumar Pandey, Sivajeet Chand, Jennifer Horkoff, Miroslaw Staron, Miroslaw Ochodek, Darko Durisic
Empir. Softw. Eng.3
2025 Using boundary objects and methodological island (BOMI) modeling in large-scale agile systems development
abstract
Abstract Large-scale systems development commonly faces the challenge of managing relevant knowledge between different organizational groups, particularly in increasingly agile contexts. Here, there is a conflict between coordination and group autonomy, and it is challenging to determine what necessary coordination information must be shared by what teams or groups, and what can be left to local team management. We introduce a way to manage this complexity using a modeling framework based on two core concepts: methodological islands (i.e., groups using different development methods than the surrounding organization) and boundary objects (i.e., artifacts that create a common understanding across team borders). However, we found that companies often lack a systematic way of assessing coordination issues and the use of boundary objects between methodological islands. As part of an iterative design science study, we have addressed this gap by producing a modeling framework (BOMI: Boundary Objects and Methodological Islands) to better capture and analyze coordination and knowledge management in practice. This framework includes a metamodel, as well as a list of bad smells over this metamodel that can be leveraged to detect inter-team coordination issues. The framework also includes a methodology to suggest concrete modeling steps and broader guidelines to help apply the approach successfully in practice. We have developed Eclipse-based tool support for the BOMI method, allowing for both graphical and textual model creation, and including an implementation of views over BOMI instance models in order to manage model complexity. We have evaluated these artifacts iteratively together with five large-scale companies developing complex systems. In this work, we describe the BOMI framework and its iterative evaluation in several real cases, reporting on lessons learned and identifying future work. We have produced a matured and stable modeling framework which facilitates understanding and reflection over complex organizational configurations, communication, governance, and coordination of knowledge artifacts in large-scale agile system development.
Jörg Holtmann, Jennifer Horkoff, Rebekka Wohlrab, Victoria Vu, Rashidah Kasauli, Salome Maro, Jan-Philipp Steghöfer, Eric Knauss
Softw. Syst. Model.2
2024 Automating Requirements Review in the Automotive Sector: A Tailored AI Approach
abstract
Requirements serve as the foundation for defining what a software product should accomplish, highlighting the importance of clear and well-written specifications [1]. Deficient requirements often lead to defects in delivered software, which can be challenging and costly to rectify [2].
Sivajeet Chand, Cristina Martinez Montes, Beatriz Cabrero-Daniel, Jennifer Horkoff
RE5
2024 Scoping of Non-Functional Requirements for Machine Learning Systems
abstract
Machine Learning (ML) systems increasingly perform complex decision-making and prediction tasks—e.g., in autonomous driving—based on patterns inferred from large quantities of data. The inclusion of ML increases the capabilities of software systems, but also introduces or exacerbates challenges. ML systems can be more complex, time-consuming and expensive to specify, develop, and test than traditional systems, and can suffer from issues related to safety, lack of explainability, limited maintainability, and bias [1], [2]. As in other domains, ML systems must satisfy certain quality requirements—known as non-functional requirements (NFRs)—to be considered fit for purpose [1].
Khan Mohammad Habibullah, Juan García-Bellido, Gregory Gay 0002, Jennifer Horkoff
RE4
2024 Operationalizing Machine Learning Using Requirements-Grounded MLOps
Milos Bastajic, Jonatan Boman Karinen, Jennifer Horkoff
REFSQ3
2024 Editorial Special issue on IEEE RE 2023
Fabiano Dalpiaz, Jennifer Horkoff
Requir. Eng.2
2024 Requirements and software engineering for automotive perception systems: an interview study
abstract
Abstract Driving automation systems, including autonomous driving and advanced driver assistance, are an important safety-critical domain. Such systems often incorporate perception systems that use machine learning to analyze the vehicle environment. We explore new or differing topics and challenges experienced by practitioners in this domain, which relate to requirements engineering (RE), quality, and systems and software engineering. We have conducted a semi-structured interview study with 19 participants across five companies and performed thematic analysis of the transcriptions. Practitioners have difficulty specifying upfront requirements and often rely on scenarios and operational design domains (ODDs) as RE artifacts. RE challenges relate to ODD detection and ODD exit detection, realistic scenarios, edge case specification, breaking down requirements, traceability, creating specifications for data and annotations, and quantifying quality requirements. Practitioners consider performance, reliability, robustness, user comfort, and—most importantly—safety as important quality attributes. Quality is assessed using statistical analysis of key metrics, and quality assurance is complicated by the addition of ML, simulation realism, and evolving standards. Systems are developed using a mix of methods, but these methods may not be sufficient for the needs of ML. Data quality methods must be a part of development methods. ML also requires a data-intensive verification and validation process, introducing data, analysis, and simulation challenges. Our findings contribute to understanding RE, safety engineering, and development methodologies for perception systems. This understanding and the collected challenges can drive future research for driving automation and other ML systems.
Khan Mohammad Habibullah, Hans-Martin Heyn, Gregory Gay 0002, Jennifer Horkoff, Eric Knauss, Markus Borg, Alessia Knauss, Håkan Sivencrona, Polly Jing Li
Requir. Eng.4
2023 Automotive Perception Software Development: An Empirical Investigation into Data, Annotation, and Ecosystem Challenges
abstract
Software that contains machine learning algorithms is an integral part of automotive perception, for example, in driving automation systems. The development of such software, specifically the training and validation of the machine learning components, requires large annotated datasets. An industry of data and annotation services has emerged to serve the development of such data-intensive automotive software components. Wide-spread difficulties to specify data and annotation needs challenge collaborations between OEMs (Original Equipment Manufacturers) and their suppliers of software components, data, and annotations.This paper investigates the reasons for these difficulties for practitioners in the Swedish automotive industry to arrive at clear specifications for data and annotations. The results from an interview study show that a lack of effective metrics for data quality aspects, ambiguities in the way of working, unclear definitions of annotation quality, and deficits in the business ecosystems are causes for the difficulty in deriving the specifications. We provide a list of recommendations that can mitigate challenges when deriving specifications and we propose future research opportunities to overcome these challenges. Our work contributes towards the on-going research on accountability of machine learning as applied to complex software systems, especially for high-stake applications such as automated driving.
Hans-Martin Heyn, Khan Mohammad Habibullah, Eric Knauss, Jennifer Horkoff, Markus Borg, Alessia Knauss, Polly Jing Li
CAIN4
2023 TransDPR: Design Pattern Recognition Using Programming Language Models
abstract
Current Design Pattern Recognition (DPR) methods have limitations, such as the reliance on semantic information, limited recognition of novel or modified pattern versions, and other factors. We present an introductory DPR technique by using a Programming Language Model (PLM) called TransDPR, which utilizes a Facebook pre-trained model (TransCoder), which is a Cross-lingual programming Language Model (XLM) based on a transformer architecture. We leverage an n-dimensional vector representation of programs and apply logistic regression to learn design patterns (DPs). Our approach utilizes the GitHub repository to collect singleton and prototype DP programs written in$C$++ source code. Our results indicate that TransDPR achieves 90% accuracy and an F1-score of 0.88 on open-source projects. We evaluate the proposed model on two developed modules from Volvo Cars and invite the original developers to validate the prediction results.
Sushant Kumar Pandey, Miroslaw Staron, Jennifer Horkoff, Miroslaw Ochodek, Nicholas Mucci, Darko Durisic
ESEM3
2023 Investigating ChatGPT's Potential to Assist in Requirements Elicitation Processes
abstract
Natural Language Processing (NLP) for Requirements Engineering (RE) (NLP4RE) seeks to apply NLP tools, techniques, and resources to the RE process to increase the quality of the requirements. There is little research involving the utilization of Generative AI-based NLP tools and techniques for requirements elicitation. In recent times, Large Language Models (LLM) like ChatGPT have gained significant recognition due to their notably improved performance in NLP tasks. To explore the potential of ChatGPT to assist in requirements elicitation processes, we formulated six questions to elicit requirements using ChatGPT. Using the same six questions, we conducted interview-based surveys with five RE experts from academia and industry and collected 30 responses containing requirements. The quality of these 36 responses (human-formulated + ChatGPT-generated) was evaluated over seven different requirements quality attributes by another five RE experts through a second round of interview-based surveys. In comparing the quality of requirements generated by ChatGPT with those formulated by human experts, we found that ChatGPT-generated requirements are highly Abstract, Atomic, Consistent, Correct, and Understandable. Based on these results, we present the most pressing issues related to LLMs and what future research should focus on to leverage the emergent behaviour of LLMs more effectively in natural language-based RE activities.
Krishna Ronanki, Christian Berger 0001, Jennifer Horkoff
SEAA3
2023 The Effects of Native Language on Requirements Quality
abstract
Context and motivation] More and more often software development projects involve participants of diverse nationalities and languages.Thus, software companies tend to use English as their business language.Moreover, to better prepare for future jobs, students consciously choose university courses in English.[Question/problem] As a result there is an increasing number of software engineers who are working or studying in a language which is not their native language.The question arises whether native language has an effect on the quality of natural language requirements.[Principal ideas/results] From the analysis of the requirements formulated by 44 participants of our empirical study, it follows that native language may have a negative effect on requirements quality, e.g., ambiguity, variability, and grammar issues.Furthermore, different native languages might drive to different quality issues.[Contribution] In order to prevent quality issues, our findings might be used by educators to adjust their materials to cater to different language groups, while practitioners might use them to improve their requirements review process.
Fayona Cowperthwaite, Jennifer Horkoff, Sylwia Kopczynska
FedCSIS2
2023 Design Patterns Understanding and Use in the Automotive Industry: An Interview Study
Sushant Kumar Pandey, Sivajeet Chand, Jennifer Horkoff, Miroslaw Staron
PROFES (1)3
2023 Welcome from the RE 2023 Organizers
abstract
Welcome to the proceedings of the 31st edition of the IEEE International Requirements Conference (RE'23), the flagship conference of the international RE community. RE is where researchers, practitioners and students meet to share the latest advances, challenges and ideas related to software and systems requirements engineering.
Kurt Schneider, Fabiano Dalpiaz, Jennifer Horkoff
RE3
2023 Requirements Engineering for Automotive Perception Systems: An Interview Study
Khan Mohammad Habibullah, Hans-Martin Heyn, Gregory Gay 0002, Jennifer Horkoff, Eric Knauss, Markus Borg, Alessia Knauss, Håkan Sivencrona, Polly Jing Li
REFSQ4
2023 In Memoriam - Professor Aditya Ghose
Joerg Evermann, Jennifer Horkoff, Jeffrey Parsons, Vítor E. Silva Souza
Data Knowl. Eng.2
2023 Preface
Aditya Ghose, Jennifer Horkoff, Vítor E. Silva Souza, Jeffrey Parsons, Joerg Evermann
Data Knowl. Eng.2
2023 Non-functional requirements for machine learning: understanding current use and challenges among practitioners
abstract
Abstract Systems that rely on Machine Learning (ML systems) have differing demands on quality—known as non-functional requirements (NFRs)—from traditional systems. NFRs for ML systems may differ in their definition, measurement, scope, and comparative importance. Despite the importance of NFRs in ensuring the quality ML systems, our understanding of all of these aspects is lacking compared to our understanding of NFRs in traditional domains. We have conducted interviews and a survey to understand how NFRs for ML systems are perceived among practitioners from both industry and academia. We have identified the degree of importance that practitioners place on different NFRs, including cases where practitioners are in agreement or have differences of opinion. We explore how NFRs are defined and measured over different aspects of a ML system (i.e., model, data, or whole system). We also identify challenges associated with NFR definition and measurement. Finally, we explore differences in perspective between practitioners in industry, academia, or a blended context. This knowledge illustrates how NFRs for ML systems are treated in current practice, and helps to guide future RE for ML efforts.
Khan Mohammad Habibullah, Gregory Gay 0002, Jennifer Horkoff
Requir. Eng.3
2023 Philanthropic conference-based requirements engineering in time of pandemic and beyond
Meira Levy, Irit Hadar, Jennifer Horkoff, Jane Huffman Hayes, Barbara Paech, Alex Dekhtyar, Gunter Mussbacher, Elda Paja, Tong Li 0001, Seok-Won Lee, Dongfeng Fang
Requir. Eng.3
2022 Invest in Splitting: User Story Splitting Within the Software Industry
Emanuel Dellsén, Karl Westgårdh, Jennifer Horkoff
REFSQ3
2022 Requirements Engineering for Software-Enabled Art: Challenges and Guidelines
Niklas Möller, Jennifer Horkoff
REFSQ2
2021 A Method for Modeling Data Anomalies in Practice
abstract
As technology has allowed us to collect large amounts of industrial data, it has become critical to analyze and understand the data collected, in particular to find data anomalies. Anomaly analysis allows a company to detect, analyze and understand anomalous or unusual data patterns. This is an important activity to understand, for example, deviations in service which may indicate potential problems, or differing customer behavior which may reveal new business opportunities. Much previous work has focused on anomaly detection, in particular using machine learning. Such approaches allow clustering of data patterns by common attributes, and, although useful, clusters often do not correspond to the root causes of anomalies, meaning that more manual analysis is needed. In this paper we report on a design science study with two different teams, in a partner company which focuses on modeling and understanding the attributes and root causes of data anomalies. After iteration, for each team, we have created general and anomaly-specific UML class diagrams and goal models to capture anomaly details. We use our experiences to create an example taxonomy, classifying anomalies by their root causes, and to create a general method for modeling and understanding data anomalies. This work paves the way for a better understanding of anomalies and their root causes, leading towards creating a training set which may be used for machine learning approaches.
Jennifer Horkoff, Miroslaw Staron, Wilhelm Meding
SEAA1
2021 Non-functional Requirements for Machine Learning: Understanding Current Use and Challenges in Industry
abstract
Machine Learning (ML) is an application of Artificial Intelligence (AI) that uses big data to produce complex predictions and decision-making systems, which would be challenging to obtain otherwise. To ensure the success of ML-enabled systems, it is essential to be aware of certain qualities of ML solutions (performance, transparency, fairness), known from a Requirement Engineering (RE) perspective as non-functional requirements (NFRs). However, when systems involve ML, NFRs for traditional software may not apply in the same ways; some NFRs may become more prominent or less important; NFRs may be defined over the ML model, data, or the entire system; and NFRs for ML may be measured differently. In this work, we aim to understand the state-of-the-art and challenges of dealing with NFRs for ML in industry. We interviewed ten engineering practitioners working with NFRs and ML. We find examples of (1) the identification and measurement of NFRs for ML, (2) identification of more and less important NFRs for ML, and (3) the challenges associated with NFRs and ML in the industry. This knowledge paints a picture of how ML-related NFRs are treated in practice and helps to guide future RE for ML efforts.
Khan Mohammad Habibullah, Jennifer Horkoff
RE2
2021 Requirements engineering challenges and practices in large-scale agile system development
abstract
Agile methods have become mainstream even in large-scale systems engineering companies that need to accommodate different development cycles of hardware and software. For such companies, requirements engineering is an essential activity that involves upfront and detailed analysis which can be at odds with agile development methods. This paper presents a multiple case study with seven large-scale systems companies, reporting their challenges, together with best practices from industry. We also analyze literature about two popular large-scale agile frameworks, SAFe® and LeSS, to derive potential solutions for the challenges. Our results are based on 20 qualitative interviews, five focus groups, and eight cross-company workshops which we used to both collect and validate our results. We found 24 challenges which we grouped in six themes, then mapped to solutions from SAFe®, LeSS, and our companies, when available. In this way, we contribute a comprehensive overview of RE challenges in relation to large-scale agile system development, evaluate the degree to which they have been addressed, and outline research gaps. We expect these results to be useful for practitioners who are responsible for designing processes, methods, or tools for large scale agile development as well as guidance for researchers.
Rashidah Kasauli, Eric Knauss, Jennifer Horkoff, Grischa Liebel, Francisco Gomes de Oliveira Neto
J. Syst. Softw.3
2020 Modeling and Analysis of Boundary Objects and Methodological Islands in Large-Scale Systems Development
Rebekka Wohlrab, Jennifer Horkoff, Rashidah Kasauli, Salome Maro, Jan-Philipp Steghöfer, Eric Knauss
ER2
2020 Charting Coordination Needs in Large-Scale Agile Organisations with Boundary Objects and Methodological Islands
abstract
Large-scale system development companies are increasingly adopting agile methods. While this adoption may improve lead-times, such companies need to balance two trade-offs: (i) the need to have a uniform, consistent development method on system level with the need for specialised methods for teams in different disciplines (e.g., hardware, software, mechanics, sales, support); (ii) the need for comprehensive documentation on system level with the need to have lightweight documentation enabling iterative and agile work. With specialised methods for teams, isolated teams work within larger ecosystems of plan-driven culture, i.e., teams become agile "islands". At the boundaries, these teams share knowledge which needs to be managed well for a correct system to be developed. While it is useful to support diverse and specialised methods, it is important to understand which islands are repeatedly encountered, the reasons or factors triggering their existence, and how best to handle coordination between them. Based on a multiple case study, this work presents a catalogue of islands and the boundary objects between them. We believe this work will be beneficial to practitioners aiming to understand their ecosystems and researchers addressing communication and coordination challenges in large-scale development.
Rashidah Kasauli, Rebekka Wohlrab, Eric Knauss, Jan-Philipp Steghöfer, Jennifer Horkoff, Salome Maro
ICSSP5
2020 Evaluating the Effects of Different Requirements Representations on Writing Test Cases
Francisco Gomes de Oliveira Neto, Jennifer Horkoff, Richard Berntsson-Svensson, David Issa Mattos, Alessia Knauss
REFSQ2
2019 Challenges of Scaled Agile for Safety-Critical Systems
Jan-Philipp Steghöfer, Eric Knauss, Jennifer Horkoff, Rebekka Wohlrab
PROFES3
2019 Towards Effective Assessment for Social Engineering Attacks
abstract
Social engineering attacks have drawn more and more attention from both academia and industry, due to the serious threats they pose to information security via exploitation of human vulnerabilities. Unlike technology-based attacks, which have been investigated for decades, there is no efficient security requirements analysis approach for dealing with social engineering attacks. One major obstacle to this problem is the uncertainty of human behavior, making it difficult to effectively assess social engineering attacks. In this paper, we investigate the nature of social engineering attacks and identify their essential factors. Based on such findings, we formulate the problem of social engineering attack assessment, which can be quantitatively calculated using probabilistic model checking. Finally, we present a research agenda that details critical research directions and discusses corresponding challenges.
Tong Li 0001, Jennifer Horkoff
RE3
2019 Non-Functional Requirements for Machine Learning: Challenges and New Directions
abstract
Machine Learning (ML) provides approaches which use big data to enable algorithms to "learn", producing outputs which would be difficult to obtain otherwise. Despite the advances allowed by ML, much recent attention has been paid to certain qualities of ML solutions, particularly fairness and transparency, but also qualities such as privacy, security, and testability. From a requirements engineering (RE) perspective, such qualities are also known as non-functional requirements (NFRs). In RE, the meaning of certain NFRs, how to refine those NFRs, and how to use NFRs for design and runtime decision making over traditional software is relatively well established and understood. However, in a context where the solution involves ML, much of our knowledge about NFRs no longer applies. First, the types of NFRs we are concerned with undergo a shift: NFRs like fairness and transparency become prominent, whereas other NFRs such as modularity may become less relevant. The meanings and interpretations of NFRs in an ML context (e.g., maintainability, interoperability, and usability) must be rethought, including how these qualities are decomposed into sub-qualities. Trade-offs between NFRs in an ML context must be re-examined. Beyond the changing landscape of NFRs, we can ask if our known approaches to understanding, formalizing, modeling, and reasoning over NFRs at design and runtime must also be adjusted, or can be applied as-is to this new area? Given these questions, this work outlines challenges and a proposed research agenda for the exploration of NFRs for ML-based solutions.
Jennifer Horkoff
RE1
2019 Creative goal modeling for innovative requirements
Jennifer Horkoff, Neil A. M. Maiden, David Asboth
Inf. Softw. Technol.1
2019 Special section: Extended papers from REFSQ 2018
Erik Kamsties, Jennifer Horkoff
Inf. Softw. Technol.2
2019 Goal-oriented requirements engineering: an extended systematic mapping study
abstract
Over the last two decades, much attention has been paid to the area of goal-oriented requirements engineering (GORE), where goals are used as a useful conceptualization to elicit, model, and analyze requirements, capturing alternatives and conflicts. Goal modeling has been adapted and applied to many sub-topics within requirements engineering (RE) and beyond, such as agent orientation, aspect orientation, business intelligence, model-driven development, and security. Despite extensive efforts in this field, the RE community lacks a recent, general systematic literature review of the area. In this work, we present a systematic mapping study, covering the 246 top-cited GORE-related conference and journal papers, according to Scopus. Our literature map addresses several research questions: we classify the types of papers (e.g., proposals, formalizations, meta-studies), look at the presence of evaluation, the topics covered (e.g., security, agents, scenarios), frameworks used, venues, citations, author networks, and overall publication numbers. For most questions, we evaluate trends over time. Our findings show a proliferation of papers with new ideas and few citations, with a small number of authors and papers dominating citations; however, there is a slight rise in papers which build upon past work (implementations, integrations, and extensions). We see a rise in papers concerning adaptation/variability/evolution and a slight rise in case studies. Overall, interest in GORE has increased. We use our analysis results to make recommendations concerning future GORE research and make our data publicly available.
Jennifer Horkoff, Fatma Basak Aydemir, Evellin Cardoso, Tong Li 0001, Alejandro Maté, Elda Paja, Mattia Salnitri, Luca Piras 0003, John Mylopoulos, Paolo Giorgini
Requir. Eng.1
2018 What Do Agile Teams Find Important for Their Success?
abstract
Although the general benefits of agile methods have been shown, it is not always clear what makes the application of agile successful or not in a company. With this motivation, we investigate agile success factors, particularly from the viewpoint of teams. We conduct in-company surveys to collect and rank agile team success factors, comparing these results with success factors found in the literature. Our results introduce new success factors not previously discussed in related work. The findings emphasize the importance of team environment, team spirit, and team capability as opposed to previous work which emphasizes project management process and customer involvement. These findings can help find issues and improve the performance of agile teams.
Hiva Alahyari, Jennifer Horkoff, Olliver Matsson, Kim Egenvall
APSEC2
2018 Planning with Strategic Goals
abstract
Strategic goals and strategic planning have received much attention in Management Sciences literature since the 60s. In this work, we are interested in putting strategic planning on a formal, algorithmic footing by offering a formal reasoning technique for automatic generation and selection of strategic plans. Towards this end, in previous work [1] we have introduced the concept of strategic goals and dimensional refinement operators that define strategic goals in terms of domain dimensions from the data warehouses literature. Examples of dimensions for a strategic goal such as "Increase sales in Europe over 2 years" might include time, geography and product type. Here, we propose a formalization of strategic goals and their dimensional refinements that allows one to express a strategic goal model as a planning space that can be achieved across different dimensions. Subsequently, we use automated reasoning solvers to produce optimum strategic plans to achieve such strategic goals. Our proposal is illustrated with an example from the literature.
Evellin Cristine Souza Cardoso, Jennifer Horkoff, Roberto Sebastiani, John Mylopoulos
EDOC2
2018 Experiences Applying \hbox e^3 Value Modeling in a Cross-Company Study
Jennifer Horkoff, Juho Lindman, Imed Hammouda, Eric Knauss
ER1
2018 Efficiency and Effectiveness of Requirements Elicitation Techniques for Children
abstract
[Context] The market for software targeting children, both for education and entertainment, is growing. Existing work, mainly from HCI, has considered the effectiveness of elicitation techniques for eliciting requirements from children as part of a design process. [Objective] However, we are lacking work which compares requirements elicitation techniques when used with children. [Methods] This study compares five elicitation techniques, taking into consideration the effectiveness and efficiency of each technique. Techniques were used with a total of 54 children aged 8-13, eliciting requirements for a museum flight simulator. We compare techniques by looking at the number and type of requirements discovered, perceived participant satisfaction, resources required, perceived usefulness, and requirements coverage of domain specific categories. [Conclusions] We observed notable differences between the techniques, including the effectiveness of observations and relative ineffectiveness of questionnaires. We present a set of guidelines to aid industry in eliciting requirements for child-friendly software.
Jennifer Horkoff, Jerker Ersare, Jonas Kahler, Thorsteinn D. Jorundsson, Imed Hammouda
RE1
2018 T-Reqs: Tool Support for Managing Requirements in Large-Scale Agile System Development
abstract
T-Reqs is a text-based requirements management solution based on the git version control system. It combines useful conventions, templates and helper scripts with powerful existing solutions from the git ecosystem and provides a working solution to address some known requirements engineering challenges in large-scale agile system development. Specifically, it allows agile cross-functional teams to be aware of requirements at system level and enables them to efficiently propose updates to those requirements. Based on our experience with T-Reqs, we i) relate known requirements challenges of large-scale agile system development to tool support; ii) list key requirements for tooling in such a context; and iii) propose concrete solutions for challenges.
Eric Knauss, Grischa Liebel, Jennifer Horkoff, Rebekka Wohlrab, Rashidah Kasauli, Filip Lange, Pierre Gildert
RE3
2018 Involving External Stakeholders in Project Courses
abstract
Problem: The involvement of external stakeholders in capstone projects and project courses is desirable due to its potential positive effects on the students. Capstone projects particularly profit from the inclusion of an industrial partner to make the project relevant and help students acquire professional skills. In addition, an increasing push towards education that is aligned with industry and incorporates industrial partners can be observed. However, the involvement of external stakeholders in teaching moments can create friction and could, in the worst case, lead to frustration of all involved parties. Contribution: We developed a model that allows analysing the involvement of external stakeholders in university courses both in a retrospective fashion, to gain insights from past course instances, and in a constructive fashion, to plan the involvement of external stakeholders. Key Concepts: The conceptual model and the accompanying guideline guide the teachers in their analysis of stakeholder involvement. The model is comprised of several activities (define, execute, and evaluate the collaboration). The guideline provides questions that the teachers should answer for each of these activities. In the constructive use, the model allows teachers to define an action plan based on an analysis of potential stakeholders and the pedagogical objectives. In the retrospective use, the model allows teachers to identify issues that appeared during the project and their underlying causes. Drawing from ideas of the reflective practitioner, the model contains an emphasis on reflection and interpretation of the observations made by the teacher and other groups involved in the courses. Key Lessons: Applying the model retrospectively to a total of eight courses shows that it is possible to reveal hitherto implicit risks and assumptions and to gain a better insight into the interaction between external stakeholders and students. Our empirical data reveals seven recurring risk themes that categorise the different risks appearing in the analysed courses. These themes can also be used to categorise mitigation strategies to address these risks proactively. Additionally, aspects not related to external stakeholders, e.g., about the interaction of the project with other courses in the study programme, have been revealed. The constructive use of the model for one course has proved helpful in identifying action alternatives and finally deciding to not include external stakeholders in the project due to the perceived cost-benefit-ratio. Implications to Practice: Our evaluation shows that the model is a viable and useful tool that allows teachers to reason about and plan the involvement of external stakeholders in a variety of course settings, and in particular in capstone projects.
Jan-Philipp Steghöfer, Håkan Burden, Regina Hebig, Gül Çalikli, Robert Feldt, Imed Hammouda, Jennifer Horkoff, Eric Knauss, Grischa Liebel
ACM Trans. Comput. Educ.7
2018 Holistic security requirements analysis for socio-technical systems
Tong Li 0001, Jennifer Horkoff, John Mylopoulos
Softw. Syst. Model.2
2016 Engineering Requirements with Desiree: An Empirical Evaluation
Feng-Lin Li, Jennifer Horkoff, Lin Liu 0001, Alexander Borgida, Giancarlo Guizzardi, John Mylopoulos
CAiSE2
2016 Security attack analysis using attack patterns
abstract
Discovering potential attacks on a system is an essential step in engineering secure systems, as the identified attacks will determine essential security requirements. The prevalence of Socio-Technical Systems (STSs) makes attack analysis particularly challenging. These systems are composed of people and organizations, their software systems, as well as physical infrastructures. As such, a thorough attack analysis needs to consider strategic (social and organizational) aspects of the involved people and organizations, as well as technical aspects affecting software systems and the physical infrastructure, requiring a large amount of security knowledge which is difficult to acquire. In this paper, we propose a systematic approach to efficiently leverage a comprehensive attack knowledge repository (CAPEC) in order to identify realistic and detailed attack behaviors, avoiding severe repercussions of security breaches. In particular, we propose a systematic method to model CAPEC attack patterns, which has been applied to 102 patterns, in order to semi-automatically select and apply such patterns. Using the CAPEC patterns as part of a systematic and tool-supported process, we can efficiently operationalize attack strategies and identify realistic alternative attacks on an STS. We validate our proposal by performing a case study on a smart grid scenario.
Tong Li 0001, Elda Paja, John Mylopoulos, Jennifer Horkoff, Kristian Beckers
RCIS4
2016 Stimulating Stakeholders' Imagination: New Creativity Triggers for Eliciting Novel Requirements
abstract
Requirements engineering is a creative process in which stakeholders and engineers work together to create ideas for new products, services and systems. Several techniques have proved to be effective for eliciting creative requirements. Yet, most of these techniques are heavy to implement and require long periods of time to be applied correctly. Few lightweight creativity techniques have been developed for use in requirements engineering. One such lightweight technique is the creativity trigger, which provides simple guidance to stakeholders and engineers to help produce creative requirements. While easy to apply, creativity triggers were derived informally from experience of practitioners and have not been validated in a systematic way. This paper reports design and preliminary validation research, that sought to provide empirical foundations for a more complete set of lightweight creativity triggers, to be used by stakeholders and engineers to quickly and simply generate new and useful requirements on products, services and systems.
Corentin Burnay, Jennifer Horkoff, Neil A. M. Maiden
RE2
2016 Goal-Oriented Requirements Engineering: A Systematic Literature Map
abstract
Over the last two decades, much attention has been paid to the area of Goal-Oriented Requirements Engineering(GORE), where goals are used as a useful conceptualization to elicit, model and analyze requirements, capturing alternatives and conflicts. Goal modeling has been adapted and applied to many sub-topics within RE and beyond, such as agent-orientation, aspect-orientation, business intelligence, model-driven development, security, and so on. Despite extensive efforts in this field, the RE community lacks a recent, general systematic literature review of the area. As a first step towards providing a GORE overview, we present a Systematic Literature Map, focusing on GORE-related publications at a high-level, categorizing and analyzing paper information in order to answer several research questions, while omitting a detailed analysis of individual paper quality. Our Literature Map covers the 246 top-cited GORE-related conference and journal papers, according to Scopus, classifying them into a number of descriptive paper types and topics, providing an analysis of the data, which is made publicly available. We use our analysis results to make recommendations concerning future GORE research.
Jennifer Horkoff, Fatma Basak Aydemir, Evellin Cardoso, Tong Li 0001, Alejandro Maté, Elda Paja, Mattia Salnitri, John Mylopoulos, Paolo Giorgini
RE1
2016 Interactive goal model analysis for early requirements engineering
Jennifer Horkoff, Eric S. K. Yu
Requir. Eng.1
2015 Creativity and Goal Modeling for Software Requirements Engineering
abstract
In order to be successful, software (applications) must be both useful and innovative. Techniques for determining the requirements (functions and qualities) of software have traditionally focused on utility, with a prominent body of work using graphical goal modeling and analysis to ensure that system functions meet the needs (goals) of users. However, these techniques are not designed to foster creativity, meaning that resulting systems may be functionally useful but not sufficiently innovative. Further work has focused on creativity workshops for finding and developing software requirements. However, creative outputs are not grounded in user goals, are not amenable to decision support techniques, and cannot be easily captured by non-experts. In this work we report initial progress on a project aiming to combine goal modeling and creativity techniques for enhanced software Requirements Engineering (RE). We apply our methods to a historical case in air traffic control, providing example outcomes, illustrating the benefits of a creativity- and goal-oriented approach to early software development.
Jennifer Horkoff, Neil A. M. Maiden, James Lockerbie
Creativity & Cognition1
2015 Holistic security requirements analysis: An attacker's perspective
abstract
The ever-growing complexity of systems makes their protection more challenging, as a single vulnerability or exposure of any component of the system can lead to serious security breaches. This problem is exacerbated by the fact that the system development community has not kept up with advances in attack knowledge. In this demo paper, we propose a holistic attack analysis approach to identify and tackle both atomic and multistage attacks, taking into account not only software attacks but also attacks that are targeted at people and hardware. To bridge the knowledge gap between attackers and defenders, we systematically analyze and refine the malicious desires of attackers (i.e., anti-goals), and leverage a comprehensive attack pattern repository (CAPEC) to operationalize attacker goals into concrete attack actions. Based on the results of our attack analysis, appropriate security controls can be selected to effectively tackle potential attacks.
Tong Li 0001, Elda Paja, John Mylopoulos, Jennifer Horkoff, Kristian Beckers
RE4
2015 From Stakeholder Requirements to Formal Specifications Through Refinement
Feng-Lin Li, Jennifer Horkoff, Alexander Borgida, Giancarlo Guizzardi, Lin Liu 0001, John Mylopoulos
REFSQ2
2015 Analyzing and Enforcing Security Mechanisms on Requirements Specifications
Tong Li 0001, Jennifer Horkoff, John Mylopoulos
REFSQ2
2014 Dealing with Security Requirements for Socio-Technical Systems: A Holistic Approach
Tong Li 0001, Jennifer Horkoff
CAiSE2
2014 Evaluating Modeling Languages: An Example from the Requirements Domain
Jennifer Horkoff, Fatma Basak Aydemir, Feng-Lin Li, Tong Li 0001, John Mylopoulos
ER1
2014 An Ontological Interpretation of Non-Functional Requirements
abstract
Non-functional requirements (NFRs) have been the focus of research in Requirements Engineering (RE) for more than 20 years. Despite this attention, their ontological nature is still an open question, thereby hampering efforts to develop concepts, tools and techniques for eliciting, modeling, and analyzing them, in order to produce a specification for a system-to-be. In this paper, we propose to treat NFRs as qualities, based on definitions of the UFO foundational ontology. Furthermore, based on these ontological definitions, we provide guidelines for distinguishing between non-functional and functional requirements, and sketch a syntax of a specification language that can be used for capturing NFRs.
Renata S. S. Guizzardi, Feng-Lin Li, Alexander Borgida, Giancarlo Guizzardi, Jennifer Horkoff, John Mylopoulos
FOIS5
2014 Taking goal models downstream: A systematic roadmap
abstract
Creating and reasoning with goal models is useful for capturing, understanding, and communicating about requirements in the early stages of information system (re)development. However, the utility of goal models is greatly enhanced when an awareness of system intentions can feed into other stages in the requirements analysis process (e.g. requirements elaboration, validation, planning), and can be used as part of the entire system life cycle (e.g., architecture, process design, coding, testing, monitoring, adaptation, and evolution). In order to understand the progress that has been made in integrating goal models with downstream system development, we ask: what approaches exist which map/integrate/transform goal-oriented languages to other software artifacts or languages? To answer this question, we conduct a systematic survey, producing a roadmap of work summarizing 174 publications. Results include a categorization of the “why?” and “how?” for each approach. Findings show that there are a wide variety of proposals with many proposed sources and targets, covering multiple paradigms, motivated by a variety of purposes. We conclude that although much work has been done in this area, the work is fragmented and is often still in a proposal stage.
Jennifer Horkoff, Tong Li 0001, Feng-Lin Li, Mattia Salnitri, Evellin Cardoso, Paolo Giorgini, John Mylopoulos, João Pimentel 0001
RCIS1
2014 Supporting early decision-making in the presence of uncertainty
abstract
Requirements Engineering (RE) involves eliciting, understanding, and capturing system requirements, which naturally involves much uncertainty. During RE, analysts choose among alternative requirements, gradually narrowing down the system scope, and it is unlikely that all requirements uncertainties can be resolved before such decisions are made. There is a need for methods to support early requirements decision-making in the presence of uncertainty. We address this need by describing a novel technique for early decision-making and tradeoff analysis using goal models with uncertainty. The technique analyzes goal satisfaction over sets of models that can result from resolving uncertainty. Users make choices over possible analysis results, allowing our tool to find critical uncertainty reductions which must be resolved. An iterative methodology guides the resolution of uncertainties necessary to achieve desired levels of goal satisfaction, supporting trade-off analysis in the presence of uncertainty.
Jennifer Horkoff, Rick Salay, Marsha Chechik, Alessio Di Sandro
RE1
2014 Non-functional requirements as qualities, with a spice of ontology
abstract
We propose a modeling language for non-functional requirements (NFRs) that views NFRs as requirements over qualities, mapping a software-related domain to a quality space. The language is compositional in that it allows (recursively) complex NFRs to be constructed in several ways. Importantly, the language allows the definition of requirements about the quality of fulfillment of other requirements, thus capturing, among others, the essence of probabilistic and fuzzy goals as proposed in the literature. We also offer a methodology for systematically refining informal NFRs elicited from stakeholders, resulting in unambiguous, de-idealized, and measurable requirements. The proposal is evaluated with a requirements dataset that includes 370 NFRs crossing 15 projects. The results suggest that our framework can adequately handle and clarify NFRs generated in practice.
Feng-Lin Li, Jennifer Horkoff, John Mylopoulos, Renata S. S. Guizzardi, Giancarlo Guizzardi, Alexander Borgida, Lin Liu 0001
RE2
2014 Strategic business modeling: representation and reasoning
Jennifer Horkoff, Daniele Barone, Lei Jiang 0002, Eric S. K. Yu, Daniel Amyot, Alexander Borgida, John Mylopoulos
Softw. Syst. Model.1
2013 Requirements models for design- and runtime: a position paper
abstract
In this position paper we review the history of requirements models and conclude that a goal-oriented perspective offers a suitable abstraction for requirements analysis. We stake positions on the nature of modelling languages in general, and requirements modelling languages in particular. We then sketch some of the desirable features (... “requirements”) of design-time and runtime requirements models and draw conclusions about their similarities and differences.
Alexander Borgida, Fabiano Dalpiaz, Jennifer Horkoff, John Mylopoulos
MiSE3
2013 Runtime goal models: Keynote
abstract
Goal models capture stakeholder requirements for a system-to-be, but also circumscribe a space of alternative specifications for fulfilling these requirements. Recent proposals for self-adaptive software systems rely on variants of goal models to support monitoring and adaptation functions. In such cases, goal models serve as mechanisms in terms of which systems reflect upon their requirements during their operation. We argue that existing proposals for using goal models at runtime are using design artifacts for purposes they were not intended, i.e., for reasoning about runtime system behavior. In this paper, we propose a conceptual distinction between Design-time Goal Models (DGMs)-used to design a system-and Runtime Goal Models (RGMs)-used to analyze a system's runtime behavior with respect to its requirements. RGMs extend DGMs with additional state, behavioral and historical information about the fulfillment of goals. We propose a syntactic structure for RGMs, a method for deriving them from DGMs, and runtime algorithms that support their monitoring.
Fabiano Dalpiaz, Alexander Borgida, Jennifer Horkoff, John Mylopoulos
RCIS3
2013 Comparison and evaluation of goal-oriented satisfaction analysis techniques
Jennifer Horkoff, Eric S. K. Yu
Requir. Eng.1
2013 Managing requirements uncertainty with partial models
Rick Salay, Marsha Chechik, Jennifer Horkoff, Alessio Di Sandro
Requir. Eng.3
2012 Managing requirements uncertainty with partial models
abstract
Models are good at expressing information that is known but do not typically have support for representing what information a modeler does not know at a particular phase in the software development process. Partial models address this by being able to precisely represent uncertainty about model content. In previous work, we developed a general approach for defining partial models and applied it to capturing uncertainty, including reasoning over design models containing uncertainty. In this paper, we show how to apply our approach to managing requirements uncertainty. In particular, we address the problem of specifying uncertainty within a requirements model, refining a model as uncertainty reduces and reasoning with traceability relations between models containing uncertainty. We illustrate our approach using the meeting scheduler example.
Rick Salay, Marsha Chechik, Jennifer Horkoff
RE3
2010 Finding Solutions in Goal Models: An Interactive Backward Reasoning Approach
Jennifer Horkoff, Eric S. K. Yu
ER1
2010 Evaluating goal models within the goal-oriented requirement language
abstract
In this article, we introduce the application of rigorous analysis procedures to goal models to provide several benefits beyond the initial act of modeling. Such analysis can allow modelers to assess the satisfaction of goals, facilitate evaluation of high-level design alternatives, help analysts decide on the high-level requirements and design of the system, test the sanity of a model, and support communication and learning. The analysis of goal models can be done in very different ways depending on the nature of the model and the purpose of the analysis. In our work, we use the Goal-oriented Requirement Language (GRL), which is part of the User Requirements Notation (URN). URN, a new Recommendation of the International Telecommunications Union, provides the first standard goal-oriented language. Using GRL, we develop an approach to analysis that can be done by evaluating qualitative or quantitative satisfaction levels of the actors and intentional elements (e.g., goals and tasks) composing the model. Initial satisfaction levels for some of the intentional elements are provided in a strategy and then propagated to the other intentional elements of the model through the various links that connect them. The results allow for an assessment of the relative effectiveness of design alternatives at the requirements level. Although no specific propagation algorithm is imposed in the URN standard, different criteria for defining evaluation mechanisms are described. We provide three algorithms (quantitative, qualitative, and hybrid) as examples, which satisfy the constraints imposed by the standard. These algorithms have been implemented in the open-source jUCMNav tool, an Eclipse-based editor for URN models. The algorithms are presented and compared with the help of a telecommunication system example. © 2010 Wiley Periodicals, Inc.
Daniel Amyot, Sepideh Ghanavati, Jennifer Horkoff, Gunter Mussbacher, Liam Peyton, Eric S. K. Yu
Int. J. Intell. Syst.3
2008 Can Patterns Improve i* Modeling? Two Exploratory Studies
Markus Strohmaier, Jennifer Horkoff, Eric S. K. Yu, Jorge Aranda, Steve M. Easterbrook
REFSQ2
2007 A Framework for Empirical Evaluation of Model Comprehensibility
abstract
If designers of modelling languages want their creations to be used in real software projects, the communication qualities of their languages need to be evaluated, and their proposals must evolve as a result of these evaluations. A key quality of communication artifacts is their comprehensibility. We present a flexible framework to evaluate the comprehensibility of model representations that is grounded on the underlying theory of the language to be evaluated, and on theoretical frameworks in cognitive science.
Jorge Aranda, Neil A. Ernst, Jennifer Horkoff, Steve M. Easterbrook
MiSE@ICSE3
2006 Analyzing trust in technology strategies
abstract
As technology design becomes increasingly motivated by business strategy, technology users become wary of vendor intentions. Conversely, technology producers must determine what strategies they can employ to gain the trust of consumers in order to acquire and retain their business. As a result, both parties have a need to understand how business strategies shape technology design, and how such designs alter relationships among stakeholders. In this work, we use the Trusted Computing domain as an example. Can the technology consumer trust the advertised intentions of Trusted Computing Technology? Can the providers of Trusted Computing gain the trust of consumers? We use the i* Modeling Framework to analyze the links between strategies and technologies in terms of a network of social intentional relationships. By applying the qualitative i* evaluation procedure, we probe the intentions behind the strategies of technology providers, facilitating an analysis of trust.
Jennifer Horkoff, Eric S. K. Yu, Lin Liu 0001
PST1
2005 Do Viewpoints Lead to Better Conceptual Models? An Exploratory Case Study
abstract
The use of viewpoints has long been proposed as a technique to structure evolving requirements models. In theory, viewpoints should provide better stakeholder traceability, and the ability to discover important requirements by comparing viewpoints. However, this theory has never been tested empirically. This paper reports on an exploratory case study of a key hypothesis of the viewpoints theory, namely that by creating separate viewpoint models to represent different stakeholder contributions, and explicitly merging them, important hidden requirements can be discovered. The case study compared two modelling teams using the i* notation to capture requirements for new Web-based counselling services for a large charitable organisation. One team used viewpoints; the other did not. The conclusions include that viewpoint merging improves the understanding of the problem domain, but is very time consuming. The process of merging was more important than the merged product. The study also indicates a need for better model management tools, as both teams encountered difficulty in managing large, evolving models.
Steve M. Easterbrook, Eric S. K. Yu, Jorge Aranda, Yuntian Fan, Jennifer Horkoff, Marcel Leica, Rifat Abdul Qadir
RE5