EDBT 2026 Demo / reviewers in the wild / expert
Sahar Kokaly
dblp:136/7646
· DBLP profile ↗
11ranked-venue papers
3as first author
3since 2021 · last 2026
0009-0000-5348-2240ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 8 · 2 first-author · 1 since 2021Security and privacy · 3 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Safety Analysis of Over-the-Air Updates for CPS: A Contract-Driven ApproachabstractOver-the-air (OTA) updates are becoming a standard practice for upgrading Cyber-Physical Systems (CPS) software, allowing software systems to be modified through a wireless network. They are beneficial in several contexts. For example, in the automotive domain, OTA updates enable manufacturers to update vehicle software without physical access. However, the considerable number of products (e.g., vehicles within the fleet) and frequent changes and updates to software components can generate many software configurations that are impossible to analyze beforehand without any automated support. This problem hampers the verification of the system’s safety. This paper proposes a contract-driven framework for reasoning about the safety of OTA updates. Our framework supports (a)contract composition, which enables reasoning about the behavior composition of different software components, and (b) verification ofcomponent substitutability, which allows checking if the software component deployed by an OTA update can replace another component without generating any safety breach.We rigorously define our framework and formally prove that if the OTA update ensures the satisfaction of its contract, the system (safety) properties are preserved. We propose an instance of our solution that targets CPS designed with Simulink®System Composer, a widely used tool for modeling the different components of the system architecture and their interaction. We propose using Simulink®Requirements Tables to express the contracts of CPS components, as they enable engineers to model the system requirements using pre/post-conditions within their Simulink®models. We implemented our solution as a software prototype that extends THEANO, a tool that enables engineers to verify the consistency and completeness of Requirements Tables. We evaluated our solution by considering the Ten Lockheed Martin Cyber-Physical Problems. We defined 20 OTA updates and effectively identified issues in 9 of them. We analyzed and fixed the problems, inspecting each unsafe OTA update to understand the causes of the safety breaches. After fixing the problems, THEANO confirmed the safety of all OTA updates. THEANO required less than a minute to analyze each OTA update, making it practical for industrial applications. Nunzio Marco Bisceglia, Aurora Francesca Zanenga, Mehrnoosh Askarpour, Sahar Kokaly, S. Ramesh 0002, Marsha Chechik, Claudio Menghi |
IEEE Trans. Software Eng. | 4 |
| 2024 | Comprehensive Change Impact Analysis Applied to Advanced Automotive Systems
Nicholas Annable, Mehrnoosh Askarpour, Thomas Chiang, Sahar Kokaly, Mark Lawford, Richard F. Paige, S. Ramesh 0002, Alan Wassyng |
SAFECOMP | 4 |
| 2021 | Towards Certified Analysis of Software Product Line Safety Cases
Ramy Shahin, Sahar Kokaly, Marsha Chechik |
SAFECOMP | 2 |
| 2020 | Heterogeneous megamodel management using collection operators
Rick Salay, Sahar Kokaly, Alessio Di Sandro, Nick L. S. Fung, Marsha Chechik |
Softw. Syst. Model. | 2 |
| 2019 | Software Assurance in an Uncertain WorldabstractFrom financial services platforms to social networks to vehicle control, software has come to mediate many activities of daily life. Governing bodies and standards organizations have responded to this trend by creating regulations and standards to address issues such as safety, security and privacy. In this environment, the compliance of software development to standards and regulations has emerged as a key requirement. Compliance claims and arguments are often captured in assurance cases, with linked evidence of compliance. Evidence can come from testcases, verification proofs, human judgment, or a combination of these. That is, experts try to build (safety-critical) systems carefully according to well justified methods and articulate these justifications in an assurance case that is ultimately judged by a human. Yet software is deeply rooted in uncertainty; most complex open-world functionality (e.g., perception of the state of the world by a self-driving vehicle), is either not completely specifiable or it is not cost-effective to do so; software systems are often to be placed into uncertain environments, and there can be uncertainties that need to be We argue that the role of assurance cases is to be the grand unifier for software development, focusing on capturing and managing uncertainty. We discuss three approaches for arguing about safety and security of software under uncertainty, in the absence of fully sound and complete methods: assurance argument rigor, semantic evidence composition and applicability to new kinds of systems, specifically those relying on ML. Marsha Chechik, Rick Salay, Torin Viger, Sahar Kokaly, Mona Rahimi |
FASE | 4 |
| 2017 | User Experience for Model-Driven Engineering: Challenges and Future DirectionsabstractSince its infancy, Model Driven Engineering (MDE) research has primarily focused on technical issues. Although it is becoming increasingly common for MDE research papers to evaluate their theoretical and practical solutions, extensive usability studies are still uncommon. We observe a scarcity of User eXperience (UX)-related research in the MDE community, and posit that many existing tools and languages have room for improvement with respect to UX [26], [44], [37], where UX is a key focus area in the software development industry. We consider this gap a fundamental problem that needs to be addressed by the community if MDE is to gain widespread use. In this vision paper, we explore how and where UX fits into MDE by considering motivating use cases that revolve around different dimensions of integration: model integration, tool integration, and integration between process and tool support. Based on the literature and our collective experience in research and industrial collaborations, we propose future directions for addressing these challenges. Silvia Abrahão, Francis Bordeleau, Betty H. C. Cheng, Sahar Kokaly, Richard F. Paige, Harald Störrle, Jon Whittle 0001 |
MoDELS | 4 |
| 2017 | Safety Case Impact Assessment in Automotive Software Systems: An Improved Model-Based Approach
Sahar Kokaly, Rick Salay, Marsha Chechik, Mark Lawford, T. S. E. Maibaum |
SAFECOMP | 1 |
| 2016 | Model management for regulatory compliance: a position paperabstractSoftware has come to mediate many of the activities in life, including financial service platforms, social networks and vehicle control. As a result, governing bodies have responded to this trend by creating standards and regulations to address issues such as safety and privacy. In this context, the compliance of software development to standards and regulations has emerged as a key issue. For software development organizations, compliance is a complex and costly goal to achieve. They may have to comply with multiple standards due to multiple jurisdictions or to address different aspects of the software and these may overlap and conflict with each other. The evolution of standards must be tracked and changes assessed. Evidence for claims of compliance must be collected and managed. Finally, maintaining families of related software products (product lines) further multiplies the effort. In this paper, we propose to exploit the connection between the field of model management and the problem of compliance management and explore how to use model management techniques to address software compliance management issues. Sahar Kokaly, Rick Salay, Mehrdad Sabetzadeh, Marsha Chechik, T. S. E. Maibaum |
MiSE@ICSE | 1 |
| 2016 | A model management approach for assurance case reuse due to system evolution
Sahar Kokaly, Rick Salay, Valentin Cassano, T. S. E. Maibaum, Marsha Chechik |
MoDELS | 1 |
| 2015 | Enriching megamodel management with collection-based operatorsabstractMegamodels are often used in MDE to describe collections of models and relationships between them. Typical collection-based operations - map, reduce, filter - cannot be applied directly to megamodels since these operators need to take relationships between models into consideration. In this paper, we propose adapted versions of these operators, demonstrating them on four megamodeling scenarios. We then analyze their applicability for handling industrial-sized megamodels. Finally, we report on a reference implementation of the operators and experimental results using it. Rick Salay, Sahar Kokaly, Alessio Di Sandro, Marsha Chechik |
MoDELS | 2 |
| 2013 | Mapping-Aware Megamodeling: Design Patterns and Laws
Zinovy Diskin, Sahar Kokaly, T. S. E. Maibaum |
SLE | 2 |