Tim Nelson

dblp:94/4577 · also Timothy Nelson 0001 · DBLP profile ↗
← Back
17ranked-venue papers
7as first author
7since 2021 · last 2026
0000-0002-9377-9943ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 12 · 4 first-author · 6 since 2021Theory of computation · 5 · 1 first-author · 2 since 2021Computer networks · 3 · 2 first-authorSystems, architecture and hardware · 1 · 1 first-authorSecurity and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Diagramming Program Values by Spatial Refinement
abstract
Diagrams enable programmers to reason, debug, and communicate. However, constructing diagrams for programming language data is unnecessarily hard. We present a declarative DSL, Spytial, that captures the essential spatial features of data. We endow Spytial with a spatial semantics, mapping values to the 2D plane, and prove key properties. Spytial uses constraint-solving to make interactive renderings. We show how Spytial can be embedded in three very different languages: Python, Rust, and Pyret. We present a novel counterfactual debugging aid for diagramming errors, combining textual and visual output. We evaluate the language and system for expressiveness, performance, and diagnostic quality. Finally, we also show how Spytial can be used to construct values interactively and visually while preserving spatial constraints.
Siddhartha Prasad, Michael Tu, Karan Kashyap, Tim Nelson, Shriram Krishnamurthi
Proc. ACM Program. Lang.4
2025 A Misconception-Driven Adaptive Tutor for Linear Temporal Logic
abstract
Abstract Linear Temporal Logic (LTL) is used widely in verification, planning, and more. Unfortunately, users often struggle to learn it. To improve their learning, they need drill, instruction, and adaptation to their strengths and weaknesses. Furthermore, this should fit into whatever learning process they are already part of (such as a course). In response, we have built a misconception-based automated tutoring system. It assumes learners have a basic understanding of logic, and focuses on their understanding of LTL operators. Crucially, it takes advantage of multiple years of research (by our team, with collaborators) into misconceptions about LTL amongst both novices and experts. The tutor generates questions using these known learner misconceptions; this enables the tutor to determine which concepts learners are strong and weak on. When learners get a question wrong, they are offered immediate feedback in terms of the concrete error they made. If they consistently demonstrate similar errors, the tool offers them feedback in terms of more general misconceptions, and tailors subsequent question sets to exercise those misconceptions. The tool is hosted for free on-line, is available open source for self-hosting, and offers instructor-friendly features.
Siddhartha Prasad, Ben Greenman, Tim Nelson, Shriram Krishnamurthi
CAV (4)3
2025 Lightweight Diagramming for Lightweight Formal Methods: A Grounded Language Design
Siddhartha Prasad, Ben Greenman, Tim Nelson, Shriram Krishnamurthi
ECOOP3
2025 A Stakeholder-Based Framework to Highlight Tensions when Implementing Privacy Features
Julia Netter, Tim Nelson, Skyler Austen, Eva Lau, Colton Rusch, Malte Schwarzkopf, Kathi Fisler
USENIX Security Symposium2
2024 Misconceptions in Finite-Trace and Infinite-Trace Linear Temporal Logic
abstract
Abstract With the growing use of temporal logics in areas ranging from robot planning to runtime verification, it is critical that users have a clear understanding of what a specification means. Toward this end, we have been developing a catalog of semantic errors and a suite of test instruments targeting various user-groups. The catalog is of interest to educators, to logic designers, to formula authors, and to tool builders, e.g., to identify mistakes. The test instruments are suitable for classroom teaching or self-study. This paper reports on five sets of survey data collected over a three-year span. We study misconceptions about finite-trace $$\textsc {ltl}_{f}$$ L T L f in three ltl-aware audiences, and misconceptions about standard ltl in novices. We find several mistakes, even among experts. In addition, the data supports several categories of errors in both $$\textsc {ltl}_{f}$$ L T L f and ltl that have not been identified in prior work. These findings, based on data from actual users, offer insights into what specific ways temporal logics are tricky and provide a groundwork for future interventions.
Ben Greenman, Siddhartha Prasad, Antonio Di Stasio 0001, Shufang Zhu 0001, Giuseppe De Giacomo, Shriram Krishnamurthi, Marco Montali, Tim Nelson, Milda Zizyte
FM (1)8
2024 Forge: A Tool and Language for Teaching Formal Methods
abstract
This paper presents the design of Forge , a tool for teaching formal methods gradually. Forge is based on the widely-used Alloy language and analysis tool, but contains numerous improvements based on more than a decade of experience teaching Alloy to students. Although our focus has been on the classroom, many of the ideas in Forge likely also apply to training in industry. Forge offers a progression of languages that improve the learning experience by only gradually increasing in expressive power. Forge supports custom visualization of its outputs, enabling the use of widely-understood domain-specific representations. Finally, Forge provides a variety of testing features to ease the transition from programming to formal modeling. We present the motivation for and design of these aspects of Forge, and then provide a substantial evaluation based on multiple years of classroom use.
Tim Nelson, Ben Greenman, Siddhartha Prasad, Tristan Dyer, Ethan Bove, Qianfan Chen, Charles Cutting, Thomas Del Vecchio, Sidney Levine, Julianne Rudner, Ben Ryjikov, Alexander Varga, Andrew Wagner, Luke West, Shriram Krishnamurthi
Proc. ACM Program. Lang.1
2022 Applying cognitive principles to model-finding output: the positive value of negative information
abstract
Model-finders, such as SAT/SMT-solvers and Alloy, are used widely both directly and embedded in domain-specific tools. They support both conventional verification and, unlike other verification tools, property-free exploration. To do this effectively, they must produce output that helps users with these tasks. Unfortunately, the output of model-finders has seen relatively little rigorous human-factors study. Conventionally, these tools tend to show one satisfying instance at a time. Drawing inspiration from the cognitive science literature, we investigate two aspects of model-finder output: how many instances to show at once, and whether all instances must actually satisfy the input constraints. Using both controlled studies and open-ended talk-alouds, we show that there is benefit to showing negative instances in certain settings; the impact of multiple instances is less clear. Our work is a first step in a theoretically grounded approach to understanding how users engage cognitively with model-finder output, and how those tools might better support users in doing so.
Tristan Dyer, Tim Nelson, Kathi Fisler, Shriram Krishnamurthi
Proc. ACM Program. Lang.2
2020 Solver-Aided Multi-Party Configuration
abstract
Configuring a service mesh often involves multiple parties, each of whom is responsible for separate portions of the overall system. This can result in miscommunication, silent and sudden errors, or a failure to meet goals.
Kevin Dackow, Andrew Wagner, Tim Nelson, Shriram Krishnamurthi, Theophilus Benson
HotNets3
2019 The Human in Formal Methods
Shriram Krishnamurthi, Tim Nelson
FM2
2018 CompoSAT: Specification-Guided Coverage for Model Finding
Sorawee Porncharoenwase, Tim Nelson, Shriram Krishnamurthi
FM2
2017 User Studies of Principled Model Finder Output
Natasha Danas, Tim Nelson, Lane Harrison, Shriram Krishnamurthi, Daniel J. Dougherty
SEFM2
2017 The power of "why" and "why not": enriching scenario exploration with provenance
abstract
Scenario-finding tools like the Alloy Analyzer are widely used in numerous concrete domains like security, network analysis, UML analysis, and so on. They can help to verify properties and, more generally, aid in exploring a system's behavior.
Tim Nelson, Natasha Danas, Daniel J. Dougherty, Shriram Krishnamurthi
ESEC/SIGSOFT FSE1
2016 Switches are Monitors Too!: Stateful Property Monitoring as a Switch Design Criterion
abstract
Testing and debugging networks /in situ/ is notoriously difficult. Many vital correctness properties involve histories over multiple packets (e.g., prior established connections). Checking such properties requires /cross-packet state/, which cannot be fully captured on stateless switch hardware.
Tim Nelson, Nicholas DeMarinis, Timothy Adam Hoff, Rodrigo Fonseca, Shriram Krishnamurthi
HotNets1
2015 Static Differential Program Analysis for Software-Defined Networks
Tim Nelson, Andrew D. Ferguson, Shriram Krishnamurthi
FM1
2014 Tierless Programming and Reasoning for Software-Defined Networks
Tim Nelson, Andrew D. Ferguson, Michael J. G. Scheer, Shriram Krishnamurthi
NSDI1
2013 Aluminum: principled scenario exploration through minimality
abstract
Scenario-finding tools such as Alloy are widely used to understand the consequences of specifications, with applications to software modeling, security analysis, and verification. This paper focuses on the exploration of scenarios: which scenarios are presented first, and how to traverse them in a well-defined way. We present Aluminum, a modification of Alloy that presents only minimal scenarios: those that contain no more than is necessary. Aluminum lets users explore the scenario space by adding to scenarios and backtracking. It also provides the ability to find what can consistently be used to extend each scenario. We describe the semantic basis of Aluminum in terms of minimal models of first-order logic formulas. We show how this theory can be implemented atop existing SAT-solvers and quantify both the benefits of minimality and its small computational overhead. Finally, we offer some qualitative observations about scenario exploration in Aluminum.
Tim Nelson, Salman Saghafi, Daniel J. Dougherty, Kathi Fisler, Shriram Krishnamurthi
ICSE1
2010 The Margrave Tool for Firewall Analysis
Tim Nelson, Christopher Barratt, Daniel J. Dougherty, Kathi Fisler, Shriram Krishnamurthi
LISA1