Moe Thandar Wynn

dblp:96/1121 · also Moe Wynn · DBLP profile ↗
← Back
31ranked-venue papers in the field
3as first author
14since 2021 · last 2026
0000-0002-7205-8821ORCID · verified

Domains — venue-derived; a paper can count in several

Business Process & Enterprise Data · 15 (1 first)Database Systems & Data Management · 11Knowledge Engineering, Semantic Web & Information Systems · 3 (2 first)Data Mining & Knowledge Discovery · 2
YearPublicationVenuePosition
2026 DupliMend: Online Detection and Refinement of Imprecise Activity Labels
Savandi Kalukapuge, Andrzej Janusz, Moe Thandar Wynn
CAiSE (2)3
2026 Paper title: Event log imperfection patterns for process mining: Towards a systematic approach to cleaning event logs
abstract
Process-oriented data mining (process mining) uses algorithms and data (in the form of event logs) to construct models that aim to provide insights into organisational processes. The quality of the data (both form and content) presented to the modeling algorithms is critical to the success of the process mining exercise. Cleaning event logs to address quality issues prior to conducting a process mining analysis is a necessary, but generally tedious and ad hoc task. In this paper we describe a set of data quality issues, distilled from our experiences in conducting process mining analyses, commonly found in process mining event logs or encountered while preparing event logs from raw data sources. We show that patterns are used in a variety of domains as a means for describing commonly encountered problems and solutions. The main contributions of this article are in showing that a patterns-based approach is applicable to documenting commonly encountered event log quality issues, the formulation of a set of components for describing event log quality issues as patterns, and the description of a collection of 11 event log imperfection patterns distilled from our experiences in preparing event logs. We postulate that a systematic approach to using such a pattern repository to identify and repair event log quality issues benefits both the process of preparing an event log and the quality of the resulting event log. The relevance of the pattern-based approach is illustrated via application of the patterns in a case study and through an evaluation by researchers and practitioners in the field.
Robert Andrews 0001, Moe Thandar Wynn
Inf. Syst.2
2026 Process mining between the lines: Extracting object-centric event logs from textual data
abstract
Organizations generate vast amounts of unstructured textual data – a valuable source of information that frequently remains underutilized for process mining. However, textual descriptions often record exceptions and manual activities absent from structured data, and therefore, enable a better understanding of deviations from the expected business process behavior. Importantly, unstructured sources typically retain the object-centric characteristics of real-world processes – information that gets flattened or lost in case-centric event logs. Yet, existing approaches primarily target structured data sources or produce case-centric event logs. To address this gap, we present an automated approach to derive object-centric event logs directly from unstructured textual descriptions. The approach comprises two subcomponents: a collector that identifies events and objects (including their attributes and relationships), and a refiner that consolidates and cleans the extracted information. We instantiate each subcomponent in heuristic and generative implementations and create four pairwise combinations of collector and refiner instances to assess the effectiveness of heuristic natural language processing and generative artificial intelligence techniques. We compare these variants quantitatively and qualitatively in a controlled, artificial setting based on synthesized texts and demonstrate the practical utility on two naturally occurring corpora (fire status updates and a legal judgment). Our results show that the configurations with a generative collector achieve the highest extraction quality. In particular, the fully generative variant produces coherent and standardized event and object labels. Overall, this study fills a notable research gap by enabling the incorporation of textual information into process mining applications. • Proposes an approach to extract object-centric event logs from textual descriptions. • Develops the approach using the Design Science Research methodology. • Implements the approach using heuristic NLP and generative AI techniques. • Evaluates the approach on synthetic and naturalistic textual descriptions. • Confirms the approach’s practical utility on fire status updates and a legal judgment.
Alina Buss, Christoph Kecht, Wolfgang Kratsch, Maximilian Röglinger, Sareh Sadeghianasl, Moe Thandar Wynn
Inf. Syst.6
2026 Domain experts in the loop: Leveraging generative artificial intelligence for interactive data validation in process mining
abstract
Process mining analyzes process execution data to derive insights that support operational process improvement. However, event logs often suffer from poor data quality, typically resulting from process deficiencies, which can lead to inaccurate or misleading insights. To mitigate this risk, domain experts and process analysts engage in data validation during event data preparation to assess whether an event log is fit for its intended analytical purpose. Yet, current practices often fail to sufficiently align event logs with their analytical objectives, commonly formalized as analysis questions. This misalignment impedes the detection of data quality issues, which frequently vary across application domains and analytical contexts. Generative artificial intelligence offers promising capabilities in this regard, including adaptability to diverse contexts, the ability to interpret complex data, and the generation of context-aware recommendations. To leverage this potential, we adopt the Design Science Research paradigm to iteratively develop Artificial Intelligence-Assisted Data Validation For Domain Experts (AID4DE) that integrates domain knowledge — rooted in experts’ practical engagement with operational processes — with generative artificial intelligence support to facilitate interaction with complex event log data. We instantiate AID4DE as an open-source software prototype and evaluate it through a three-phase approach: a competing artifact analysis, 14 semi-structured expert interviews, and a user study involving 18 information systems researchers. Our results show that AID4DE is both applicable and effective in supporting domain experts in data validation, enabling the systematic externalization of domain knowledge and rigorous assessment of event log’s fitness for purpose. • Improved data validation for domain experts through artificial intelligence support. • Artificial intelligence derives event log understanding from semantic visual analysis. • Contextual guidance improves experts’ understanding and validation of event log data. • Instantiated prototype evaluated as useful and applicable in a real-world setting. • Artificial intelligence and domain knowledge support fitness for purpose evaluation.
Julian Dormehl, Robert Andrews 0001, Wolfgang Kratsch, Maximilian Röglinger, Moe Thandar Wynn, Felix Zetzsche
Inf. Syst.5
2026 Object-centric event-data imperfection patterns
abstract
The field of process mining offers a range of techniques for evidence-based improvement of business processes. The quality of the process data used, as stored in so-called event logs, is paramount to the reliability and usefulness of the process mining outcomes. Due to the increased uptake, at scale and for more complex types of applications, the field of process mining has evolved and event logs now need to be object-centric rather than event-centric. To understand and manage the quality problems that can occur in object-centric event logs a systematic approach is required that is different from past investigations into event-centric logs. To this end, we adopt a pattern-based approach, a tried and tested method to characterise problems that are otherwise hard to capture. A new collection of patterns is presented for object-centric logs, where each pattern captures the nature of the problem, how its manifestation can be detected, and how the problem can be remedied. The pattern collection is validated through a multi-prong approach, i.e., evidence-based, literature-based, empirical, and user-based (with the process mining community). The results show that these patterns are perceived as important to identify and that they do occur in practical settings.
Sareh Sadeghianasl, Moe Thandar Wynn, Robert Andrews 0001, Wil M. P. van der Aalst, Jonghyeon Ko
Inf. Syst.2
2025 ThreatTrace: Cyber-Attack Detection Through Trace Abstraction and Soft Clustering
Andrzej Janusz, Savandi Kalukapuge, Moe Thandar Wynn
CAiSE (2)3
2025 Skip Probabilities for Subprocesses
abstract
Conformance checking techniques compare process models of organizational behavior with observed process executions to reveal their deviations. Traditional alignments concern individual activities and provide a single out of potentially infinitely many explanations for observed deviations. Skip alignments lift insights to subprocesses and provide all possible explanations. Though valuable for analysts and process mining tools, there exist no interpretations how likely these deviations are. In this paper, we introduce skip probabilities revealing how likely certain subprocesses deviate w.r.t. an event log of observed process executions. We show the formal derivation of this calculation and demonstrate the feasibility of its computation. By analyzing a realistic case, we empirically show that yet hidden process insights can be derived from skip probabilities and how they contribute to targeted process improvement.
Philipp Bär, Adam Burke 0001, Moe Thandar Wynn, Sander J. J. Leemans
ICPM3
2025 A Reinforcement Learning Framework for Event Log Anomaly Detection and Repair
abstract
Detecting and repairing anomalies in business process event logs is essential for maintaining process integrity. Building on the observation that real-world anomalies often exhibit specific patterns and extending our earlier semi-supervised, rule-based approach to detect and repair common basic patterns, this paper presents an anomaly detection and repair framework powered by reinforcement learning. The proposed approach automatically learns an intelligent policy to identify and correct typical basic anomaly patterns, moving beyond the limitations of heuristic, rule-based methods. Furthermore, thanks to the flexibility provided by reinforcement learning, the approach can handle more complex patterns formed by combinations of the basic ones. Extensive evaluation using both synthetic and realworld logs demonstrates that the proposed method outperforms traditional trace alignment, edit distance-based techniques, and unsupervised deep learning in the accuracy of anomalous trace repair. It also shows consistent performance across various anomaly types and offers a pattern categorization capability that baseline methods lack.
Jonghyeon Ko, Moe Thandar Wynn, Marco Comuzzi, Fabrizio Maria Maggi
ICPM2
2024 A chance for models to show their quality: Stochastic process model-log dimensions
abstract
Process models describe the desired or observed behaviour of organisations. In stochastic process mining, computational analysis of trace data yields process models which describe process paths and their probability of execution. To understand the quality of these models, and to compare them, quantitative quality measures are used. This research investigates model comparison empirically, using stochastic process models built from real-life logs. The experimental design collects a large number of models generated randomly and using process discovery techniques. Twenty-five different metrics are taken on these models, using both existing process model metrics and new, exploratory ones. The results are analysed quantitatively, making particular use of principal component analysis. Based on this analysis, we suggest three stochastic process model dimensions: adhesion, relevance and simplicity. We also suggest possible metrics for these dimensions, and demonstrate their use on example models.
Adam Burke 0001, Sander J. J. Leemans, Moe Thandar Wynn, Wil M. P. van der Aalst, Arthur H. M. ter Hofstede
Inf. Syst.3
2024 Bot log mining: An approach to the integrated analysis of Robotic Process Automation and process mining
Andreas Egger, Arthur H. M. ter Hofstede, Wolfgang Kratsch, Sander J. J. Leemans, Maximilian Röglinger, Moe Thandar Wynn
Inf. Syst.6
2023 State Snapshot Process Discovery on Career Paths of Qing Dynasty Civil Servants
abstract
In process mining, computational processing of sequential data allows the discovery and analysis of processes followed by organisations. These can be either explicitly understood processes, captured in documents or rules, or implicit process paths known in more informal or emergent ways. This paper examines a long-lived institution of historical interest, the Qing (1644-1911) Chinese civil service, using data assembled by historians on civil officials during the 19th century. Mapping the promotion process by following paths of officials through civil service postings helps illuminate the everyday operation of the institution and the society around it. Two distinctive features of this data set are that it records states, not events, and careers often include holding multiple concurrent roles. The combination is a poor match for existing process discovery techniques. We describe this structure as a state snapshot log, and present a new discovery technique, the State Snapshot miner, for constructing stochastic Petri net models from such logs. A case study shows its use in analysing promotion paths for elite graduates in the Qing civil service.
Adam Burke 0001, Sander J. J. Leemans, Moe Thandar Wynn, Cameron D. Campbell
ICPM3
2022 Stochastic Process Model-Log Quality Dimensions: An Experimental Study
abstract
Stochastic process models are a type of model that explicitly include elements of probability in describing an organization, facilitating different modes of analysis and simulation. Having obtained models of an organizational process, say through process mining, using them well depends on understanding their quality, and being able to compare different models. There may not be a single optimal stochastic model for a process, but tradeoffs between models, decided by their intended use. Reasoning about trade-offs in a precise way requires quantitative measures, and an understanding of how these measures relate, including whether they capture independent underlying properties.This paper is an empirical investigation of measures for stochastic process models built from real-life logs. The experimental design assembles a large collection of models built both randomly and by discovery techniques. A wide spectrum of candidate measures, drawn from and inspired by the process mining literature, are applied using these models. Based on this analysis, three stochastic quality dimensions are proposed: adhesion, entropy and simplicity.
Adam Burke 0001, Sander J. J. Leemans, Moe Thandar Wynn, Wil M. P. van der Aalst, Arthur H. M. ter Hofstede
ICPM3
2022 Towards interactive event log forensics: Detecting and quantifying timestamp imperfections
Dominik Andreas Fischer, Kanika Goel 0002, Robert Andrews 0001, Christopher G. J. van Dun, Moe Thandar Wynn, Maximilian Röglinger
Inf. Syst.5
2022 Quality-Informed Process Mining: A Case for Standardised Data Quality Annotations
abstract
Real-life event logs, reflecting the actual executions of complex business processes, are faced with numerous data quality issues. Extensive data sanity checks and pre-processing are usually needed before historical data can be used as input to obtain reliable data-driven insights. However, most of the existing algorithms in process mining, a field focusing on data-driven process analysis, do not take any data quality issues or the potential effects of data pre-processing into account explicitly. This can result in erroneous process mining results, leading to inaccurate, or misleading conclusions about the process under investigation. To address this gap, we propose data quality annotations for event logs, which can be used by process mining algorithms to generate quality-informed insights. Using a design science approach, requirements are formulated, which are leveraged to propose data quality annotations. Moreover, we present the “Quality-Informed visual Miner” plug-in to demonstrate the potential utility and impact of data quality annotations. Our experimental results, utilising both synthetic and real-life event logs, show how the use of data quality annotations by process mining techniques can assist in increasing the reliability of performance analysis results.
Kanika Goel 0002, Sander J. J. Leemans, Niels Martin, Moe Thandar Wynn
ACM Trans. Knowl. Discov. Data4
2020 Workforce Upskilling: A History-Based Approach for Recommending Unfamiliar Process Activities
Anastasiia Pika, Moe Thandar Wynn
CAiSE2
2020 Bot Log Mining: Using Logs from Robotic Process Automation for Process Mining
Andreas Egger, Arthur H. M. ter Hofstede, Wolfgang Kratsch, Sander J. J. Leemans, Maximilian Röglinger, Moe Thandar Wynn
ER6
2020 Identifying Cohorts: Recommending Drill-Downs Based on Differences in Behaviour for Process Mining
Sander J. J. Leemans, Shiva Shabaninejad, Kanika Goel 0002, Hassan Khosravi, Shazia Sadiq, Moe Thandar Wynn
ER6
2019 Directly Follows-Based Process Mining: Exploration & a Case Study
abstract
Many organisations now seek to analyse and improve their processes using event logs from various IT systems supporting their operations. Process mining aims to obtain insights from such process data, using process discovery, conformance checking and performance measures. While many commercial process mining tools feature user-friendly directly follows-based process maps, they typically do not offer a way to assess the quality of the model, leaving users with potentially unreliable insights, which could lead to the wrong conclusion being drawn from these insights. In contrast, academic tools typically provide verifiable results, but are often difficult to use and understand for stakeholders, sometimes overgeneralising behaviour to fit more extensive process model formalisms. In this paper, we bridge this well-known gap between commercial and academic tools by combining sound process discovery, conformance checking and performance capabilities with user-friendly directly follows-based process models. We implemented these techniques in a new process mining tool and applied them to analyse several business processes in a Queensland Government department. We discovered sound directly follows-based process models from their logs, compared them with prescribed models and analysed the performance of these processes. In particular, our conformance checking techniques allowed to pinpoint deviations between prescribed processes and actual recorded behaviour. The outcomes of this case study are now being used to document, review, improve and automate processes.
Sander J. J. Leemans, Erik Poppe, Moe Thandar Wynn
ICPM3
2018 Detection and Interactive Repair of Event Ordering Imperfection in Process Logs
Prabhakar M. Dixit, Suriadi Suriadi, Robert Andrews 0001, Moe Thandar Wynn, Arthur H. M. ter Hofstede, Joos C. A. M. Buijs, Wil M. P. van der Aalst
CAiSE4
2018 Are we done with business process compliance: state of the art and challenges ahead
Mustafa Hashmi, Guido Governatori, Brian Lam 0001, Moe Thandar Wynn
Knowl. Inf. Syst.4
2017 Change visualisation: Analysing the resource and timing differences between two event logs
Wei Zhe Low, Wil M. P. van der Aalst, Arthur H. M. ter Hofstede, Moe Thandar Wynn, Jochen De Weerdt
Inf. Syst.4
2017 Event log imperfection patterns for process mining: Towards a systematic approach to cleaning event logs
Suriadi Suriadi, Robert Andrews 0001, Arthur H. M. ter Hofstede, Moe Thandar Wynn
Inf. Syst.4
2016 Evaluating and predicting overall process risk using event logs
Anastasiia Pika, Wil M. P. van der Aalst, Moe Thandar Wynn, Colin J. Fidge, Arthur H. M. ter Hofstede
Inf. Sci.3
2014 An Extensible Framework for Analysing Resource Behaviour Using Event Logs
Anastasiia Pika, Moe Thandar Wynn, Colin J. Fidge, Arthur H. M. ter Hofstede, Michael Leyer, Wil M. P. van der Aalst
CAiSE2
2014 How to guarantee compliance between workflows and product lifecycles?
Arthur H. M. ter Hofstede, Chun Ouyang 0001, Moe Thandar Wynn, Jianmin Wang 0001, Xiaochen Zhu 0001
Inf. Syst.4
2013 Profiling Event Logs to Configure Risk Indicators for Process Delays
Anastasiia Pika, Wil M. P. van der Aalst, Colin J. Fidge, Arthur H. M. ter Hofstede, Moe Thandar Wynn
CAiSE5
2013 Understanding Process Behaviours in a Large Insurance Company in Australia: A Case Study
Suriadi Suriadi, Moe Thandar Wynn, Chun Ouyang 0001, Arthur H. M. ter Hofstede, Nienke J. van Dijk
CAiSE2
2013 Cost-Informed Operational Process Support
Moe Thandar Wynn, Hajo A. Reijers, Michael Adams 0001, Chun Ouyang 0001, Arthur H. M. ter Hofstede, Wil M. P. van der Aalst, Michael Rosemann, Zahirul Hoque
ER1
2009 Workflow simulation for operational decision support
Anne Rozinat, Moe Thandar Wynn, Wil M. P. van der Aalst, Arthur H. M. ter Hofstede, Colin J. Fidge
Data Knowl. Eng.2
2009 Synchronization and Cancelation in Workflows Based on Reset Nets
abstract
Workflow languages offer constructs for coordinating tasks. Among these constructs are various types of splits and joins. One type of join, which shows up in various incarnations, is the OR-join. Different approaches assign a different (often only intuitive) semantics to this type of join, though they do share the common theme that branches that cannot complete will not be waited for. Many systems and languages struggle with the semantics and implementation of the OR-join because its non-local semantics require a synchronization depending on the analysis of future execution paths. The presence of cancelation features, potentially unbounded behavior, and other OR-joins in a workflow further complicates the formal semantics of the OR-join. In this paper, the concept of the OR-join is examined in detail in the context of the workflow language YAWL, a powerful workflow language designed to support a collection of workflow patterns and inspired by Petri nets. The paper provides a suitable (non-local) semantics for an OR-join and gives a concrete algorithm with two optimization techniques to support the implementation. This approach exploits a link that is proposed between YAWL and reset nets, a variant of Petri nets with a special type of arc that can remove all tokens from a place when its transition fires. Through the behavior of reset arcs, the behavior of cancelation regions can be captured in a natural manner.
Moe Thandar Wynn, Wil M. P. van der Aalst, Arthur H. M. ter Hofstede, David Edmond
Int. J. Cooperative Inf. Syst.1
2009 Soundness-preserving reduction rules for reset workflow nets
Moe Thandar Wynn, H. M. W. Verbeek, Wil M. P. van der Aalst, Arthur H. M. ter Hofstede, David Edmond
Inf. Sci.1