Jan-Philipp Steghöfer

dblp:16/7127 · DBLP profile ↗
← Back
56ranked-venue papers
8as first author
23since 2021 · last 2025
0000-0003-1694-0972ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 38 · 4 first-author · 19 since 2021Artificial intelligence and machine learning · 7 · 1 first-author · 2 since 2021Security and privacy · 5 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 5 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 2 since 2021Systems, architecture and hardware · 2Computer networks · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1Theory of computation · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Challenges in AI Projects for Machinery and Plant Engineering
abstract
In our AI projects with machinery and plant engineering customers, we encounter recurring challenges beyond data processing, such as data availability, integration, human involvement, operations, and business considerations. Addressing these challenges is crucial for progress in this domain, yet research support is lacking. We present these challenges, discuss our current solutions, and call on researchers at CAIN and beyond to develop better approaches for the future.
Richard Nordsieck, Jan-Philipp Steghöfer, Manish Bhandari
CAIN2
2025 An Exploratory Study on the Engineering of Security Features
abstract
Software security is of utmost importance for most software systems. Developers must systematically select, plan, design, implement, and especially, maintain and evolve security features-functionalities to mitigate attacks or protect personal data such as cryptography or access control-to ensure the security of their software. Although security features are usually available in libraries, integrating security features requires writing and maintaining additional security-critical code. While there have been studies on the use of such libraries, surprisingly little is known about how developers engineer security features, how they select what security features to implement and which ones may require custom implementation, and the implications for maintenance. As a result, we currently rely on assumptions that are largely based on common sense or individual examples. However, to provide them with effective solutions, researchers need hard empirical data to understand what practitioners need and how they view security-data that we currently lack. To fill this gap, we contribute an exploratory study with 26 knowledgeable industrial participants. We study how security features of software systems are selected and engineered in practice, what their code- level characteristics are, and what challenges practitioners face. Based on the empirical data gathered, we provide insights into engineering practices and validate four common assumptions.
Kevin Hermann, Sven Peldszus, Jan-Philipp Steghöfer, Thorsten Berger
ICSE3
2025 Using boundary objects and methodological island (BOMI) modeling in large-scale agile systems development
abstract
Abstract Large-scale systems development commonly faces the challenge of managing relevant knowledge between different organizational groups, particularly in increasingly agile contexts. Here, there is a conflict between coordination and group autonomy, and it is challenging to determine what necessary coordination information must be shared by what teams or groups, and what can be left to local team management. We introduce a way to manage this complexity using a modeling framework based on two core concepts: methodological islands (i.e., groups using different development methods than the surrounding organization) and boundary objects (i.e., artifacts that create a common understanding across team borders). However, we found that companies often lack a systematic way of assessing coordination issues and the use of boundary objects between methodological islands. As part of an iterative design science study, we have addressed this gap by producing a modeling framework (BOMI: Boundary Objects and Methodological Islands) to better capture and analyze coordination and knowledge management in practice. This framework includes a metamodel, as well as a list of bad smells over this metamodel that can be leveraged to detect inter-team coordination issues. The framework also includes a methodology to suggest concrete modeling steps and broader guidelines to help apply the approach successfully in practice. We have developed Eclipse-based tool support for the BOMI method, allowing for both graphical and textual model creation, and including an implementation of views over BOMI instance models in order to manage model complexity. We have evaluated these artifacts iteratively together with five large-scale companies developing complex systems. In this work, we describe the BOMI framework and its iterative evaluation in several real cases, reporting on lessons learned and identifying future work. We have produced a matured and stable modeling framework which facilitates understanding and reflection over complex organizational configurations, communication, governance, and coordination of knowledge artifacts in large-scale agile system development.
Jörg Holtmann, Jennifer Horkoff, Rebekka Wohlrab, Victoria Vu, Rashidah Kasauli, Salome Maro, Jan-Philipp Steghöfer, Eric Knauss
Softw. Syst. Model.7
2024 No Data Left Behind: Exogenous Variables in Long-Term Forecasting of Nursing Staff Capacity
abstract
Accurate forecasts of nursing staff capacity have the potential to support shift planners in creating optimal schedules for nursing staff, which is crucial for job satisfaction and quality of care provided in hospitals. Recently presented deep learning methods for long-term time series forecasting (LTSF) show promising results on multiple use cases. However, many state-of-the-art LTSF approaches like PatchTST produce univariate forecasts, neglecting potential correlations between different time series such as nursing staff capacities of multiple wards. In this paper, we compare the performance of several LTSF models, namely TSMixer, TiDE, PatchTST, and LightGBM, in forecasting the nursing staff capacity of a ward in a German hospital. These models are benchmarked against traditional approaches, specifically the ARIMA and Naive Seasonal baselines. Additionally, we assess the impact of including exogenous variables from within the hospital as well as external data sources. Our results show that TSMixer outperforms the other models and baselines by up to 57.40 %, with an MAE of 1.126. We find that including exogenous variables improves the performance of TSMixer and LightGBM. To the best of our knowledge, this study is the first to predict nursing staff capacity.
Emily Schiller, Kathrin Ebertsch, Jan-Philipp Steghöfer
DSAA4
2024 Evaluating the Role of Security Assurance Cases in Agile Medical Device Development
abstract
Cybersecurity issues in medical devices threaten patient safety and can cause harm if exploited. Standards and regulations therefore require vendors of such devices to provide an assessment of the cybersecurity risks as well as a description of their mitigation. Security assurance cases (SACs) capture these elements as a structured argument. Compiling an SAC requires taking domain-specific regulations and requirements as well as the way of working into account. In this case study, we evaluate CASCADE, an approach for building SAC in the context of a large medical device manufacturer with an established agile development workflow. We investigate the regulatory context as well as the adaptations needed in the development process. Our results show the suitability of SACs in the medical device industry. We identified 17 use cases in which an SAC supports internal and external needs. The connection to safety assurance can be achieved by incorporating information from the risk assessment matrix into the SAC. Integration into the development process can be achieved by introducing a new role and rules for the design review and the release to production as well as additional criteria for the definition of done. We also show that SACs built with CASCADE fulfill the requirements of relevant standards in the medical domain such as ISO 14971.
Max Fransson, Adam Andersson, Mazen Mohamad, Jan-Philipp Steghöfer
SEAA4
2024 Processes, methods, and tools in model-based engineering - A qualitative multiple-case study
abstract
Research on model-based engineering (MBE) has occasionally touched upon the relationship between development processes and concrete MBE practices. However, the alignment of these elements has rarely been the central focus of these studies. As a result, important questions regarding the alignment of MBE and development processes, as well as the impact of development processes on the utilization and success of MBE, have remained unanswered. To address this research gap, we conducted a multiple-case study involving 14 individuals from nine different companies, conducting a total of 12 interviews. Building upon seven propositions derived from existing literature, our investigation sought to understand how MBE is aligned with the development process and explore the application of MBE in this context. Additionally, we identified challenges and needs in this area. Our findings challenge some previously reported results, such as the perceived conflicts between agile development processes and MBE. Furthermore, we unearthed previously unreported issues, like the importance of considering the perspectives of tool vendors in MBE discussions. Overall, this paper makes a significant contribution by providing a comprehensive and up-to-date perspective on how MBE is integrated into development processes, along with an examination of the social and organizational aspects inherent to these processes. Editor’s note: Open Science material was validated by the Journal of Systems and Software Open Science Board.
Jörg Holtmann, Grischa Liebel, Jan-Philipp Steghöfer
J. Syst. Softw.3
2024 Managing security evidence in safety-critical organizations
abstract
With the increasing prevalence of open and connected products, cybersecurity has become a serious issue in safety-critical domains such as the automotive industry. As a result, regulatory bodies have become more stringent in their requirements for cybersecurity, necessitating security assurance for products developed in these domains. In response, companies have implemented new or modified processes to incorporate security into their product development lifecycle, resulting in a large amount of evidence being created to support claims about the achievement of a certain level of security. However, managing evidence is not a trivial task, particularly for complex products and systems. This paper presents a qualitative interview study conducted in six companies on the maturity of managing security evidence in safety-critical organizations. We find that the current maturity of managing security evidence is insufficient for the increasing requirements set by certification authorities and standardization bodies. Organisations currently fail to identify relevant artifacts as security evidence and manage this evidence on an organizational level. One part of the reason are educational gaps, the other a lack of processes. The impact of AI on the management of security evidence is still an open question.
Mazen Mohamad, Jan-Philipp Steghöfer, Eric Knauss, Riccardo Scandariato
J. Syst. Softw.2
2024 Supporting meta-model-based language evolution and rapid prototyping with automated grammar transformation
abstract
In model-driven engineering, developing a textual domain-specific language (DSL) involves constructing a meta-model, which defines an underlying abstract syntax, and a grammar, which defines the concrete syntax for the DSL. We consider a scenario in which the meta-model is manually maintained, which is common in various contexts, such as blended modeling, in which several concrete syntaxes co-exist in parallel. Language workbenches such as Xtext support such a scenario, but require the grammar to be manually co-evolved, which is laborious and error-prone. In this paper, we present GrammarTransformer, an approach for transforming generated grammars in the context of meta-model-based language evolution. To reduce the effort for language engineers during rapid prototyping and language evolution, it offers a catalog of configurable grammar transformation rules. Once configured, these rules can be automatically applied and re-applied after future evolution steps, greatly reducing redundant manual effort. In addition, some of the supported transformations can globally change the style of concrete syntax elements, further significantly reducing the effort for manual transformations. The grammar transformation rules were extracted from a comparison of generated and existing, expert-created grammars, based on seven available DSLs. An evaluation based on the seven languages shows GrammarTransformer’s ability to modify Xtext-generated grammars in a way that agrees with manual changes performed by an expert and to support language evolution in an efficient way, with only a minimal need to change existing configurations over time.
Jörg Holtmann, Daniel Strüber 0001, Regina Hebig, Jan-Philipp Steghöfer
J. Syst. Softw.5
2024 Systematizing modeler experience (MX) in model-driven engineering success stories
abstract
Abstract Modeling is often associated with complex and heavy tooling, leading to a negative perception among practitioners. However, alternative paradigms, such as everything-as-code or low-code, are gaining acceptance due to their perceived ease of use. This paper explores the dichotomy between these perceptions through the lens of “modeler experience” (MX). MX includes factors such as user experience, motivation, integration, collaboration and versioning, and language complexity. We examine the relationships between these factors and their impact on different modeling usage scenarios. Our findings highlight the importance of considering MX when understanding how developers interact with modeling tools and the complexities of modeling and associated tooling.
Reyhaneh Kalantari, Julian Oertel, Joeri Exelmans, Satrio Adi Rukmono, Vasco Amaral 0001, Matthias Tichy, Katharina Juhnke, Jan-Philipp Steghöfer, Silvia Abrahão
Softw. Syst. Model.8
2024 Human factors in model-driven engineering: future research goals and initiatives for MDE
Grischa Liebel, Jil Klünder, Regina Hebig, Christopher Lazik, Inês Nunes, Isabella Graßl, Jan-Philipp Steghöfer, Joeri Exelmans, Julian Oertel, Kai Marquardt, Katharina Juhnke, Kurt Schneider, Lucas Gren, Lucia Happe, Marc Herrmann, Marvin Wyrich, Matthias Tichy, Miguel Goulão, Rebekka Wohlrab, Reyhaneh Kalantari, Robert Heinrich, Sandra Greiner 0001, Satrio Adi Rukmono, Shalini Chakraborty, Silvia Abrahão, Vasco Amaral 0001
Softw. Syst. Model.7
2023 Trustful Model-Based Information Exchange in Collaborative Engineering
David Schmelter, Jan-Philipp Steghöfer, Karsten Albers, Mats Ekman, Jörg Teßmer, Raphael Weber
EuroSPI (1)2
2023 Exploiting Meta-Model Structures in the Generation of Xtext Editors
abstract
When generating textual editors for large and highly structured meta-models, it is possible to extend Xtext’s generator capabilities and the default implementations it provides. These extensions provide additional features such as formatters and more precise scoping for cross-references. However, for large metamodels in particular, the realization of such extensions typically is a time-consuming, awkward, and repetitive task. For some of these tasks, we motivate, present, and discuss in this position paper automatic solutions that exploit the structure of the underlying metamodel. Furthermore, we demonstrate how we used them in the development of a textual editor for EATXT, a textual concrete syntax for the automotive architecture description language EAST-ADL. This work in progress contributes to our larger goal of building a language workbench for blended modelling.
Jörg Holtmann, Jan-Philipp Steghöfer
MODELSWARD2
2023 Creating Python-Style Domain Specific Languages: A Semi-Automated Approach and Intermediate Results
abstract
Xtext is a well-known domain-specific language design framework and technology. It automatically generates a textual grammar for a language, given a meta-model specified in Ecore. These generated textual grammars are typically not user-friendly. Python-style languages are popular among developers for their usability and conciseness. We aim to propose a systematic approach to transform a DSL with a generated grammar into a Python-style DSL. To achieve this, we analyze the problems of grammars generated with Xtext, based on a lightweight architecture description language. In response to these problems, we propose a general semi-automated grammar adaptation approach. We apply the approach to two other DSLs to validate the generalization of the approach. We also discuss the limitations of this approach and prospects for the future.
Regina Hebig, Jan-Philipp Steghöfer, Jörg Holtmann
MODELSWARD3
2023 Automated Extraction of Grammar Optimization Rule Configurations for Metamodel-Grammar Co-evolution
abstract
When a language evolves, meta-models and associated gram- mars need to be co-evolved to stay mutually consistent. Previous work has supported the automated migration of a grammar after changes of the meta-model to retain manual optimizations of the grammar, related to syntax aspects such as keywords, brackets, and component order. Yet, doing so required the manual specification of optimization rule con- figurations, which was laborious and error-prone. In this work, to significantly reduce the manual effort during meta-model and grammar co-evolution, we present an automated approach for extracting optimization rule configurations. The inferred configurations can be used to automatically replay optimizations on later versions of the grammar, thus leading to a fully automated migration process for the supported types of changes. We evaluated our approach on six real cases. Full automation was possible for three of them, with agreement rates between ground truth and inferred grammar between 88% and 67% for the remaining ones.
Regina Hebig, Daniel Strüber 0001, Jan-Philipp Steghöfer
SLE4
2023 Blended modeling in commercial and open-source model-driven software engineering tools: A systematic study
Istvan David, Malvina Latifaj, Jakob Pietron, Federico Ciccozzi, Ivano Malavolta, Alexander Raschke, Jan-Philipp Steghöfer, Regina Hebig
Softw. Syst. Model.8
2023 CASCADE: An Asset-driven Approach to Build Security Assurance Cases for Automotive Systems
abstract
Security Assurance Cases (SAC) are structured arguments and evidence bodies used to reason about the security of a certain system. SACs are gaining focus in the automotive industry, as the needs for security assurance are growing in this domain. However, the state-of-the-arts lack a mature approach able to suit the needs of the automotive industry. In this article, we present CASCADE, an asset-driven approach for creating SAC, which is inspired by the upcoming security standard ISO/SAE-21434 as well as the internal needs of automotive Original Equipment Manufacturers (OEMs). CASCADE also differentiates itself from the state-of-the-art by incorporating a way to reason about the quality of the constructed security assurance case. We created the approach by conducting an iterative design science research study. We illustrate the results using the example case of the road vehicle’s headlamp provided in the ISO standard. We also illustrate how our approach aligns well with the structure and content of the ISO/SAE-21434 standard, hence demonstrating the practical applicability of CASCADE in an industrial context.
Mazen Mohamad, Rodi Jolak, Örjan Askerdal, Jan-Philipp Steghöfer, Riccardo Scandariato
ACM Trans. Cyber Phys. Syst.4
2023 FeatRacer: Locating Features Through Assisted Traceability
abstract
Locating features is one of the most common software development activities. It is typically done during maintenance and evolution, when developers need to identify the exact places in a codebase where specific features are implemented. Unfortunately, locating features is laborious and error-prone, since feature knowledge fades, projects are developed by different developers, and features are often scattered across the codebase. Recognizing the need, manyautomated feature location techniqueshave been proposed, which try to retroactively recover features, i.e., very domain-specific information from the codebase. Unfortunately, such techniques require large training datasets, only recover coarse-grained locations and produce too many false positives to be useful in practice. An alternative isrecording features during development, when they are still fresh in a developer's mind. However, recording is easily forgotten and also costly, especially when the software evolves and such recordings need to be updated. We address the infamousfeature location problem(a.k.a.,concern locationorconcept assignment problem) differently. We present FeatRacer, which combines feature recording and automated feature location in a way that allows developers to proactively and continuously record features and their locations during development, while addressing the shortcomings of both strategies. Specifically, FeatRacer relies on embedded code annotations and a machine-learning-based recommender system. When a developer forgets to annotate, FeatRacer reminds the developer about potentially missing features, which it learned from the feature recording practices in the project at hand. FeatRacer also facilitates fine-grained locations as decided by the developer. Our evaluation shows that FeatRacer outperforms traditional automated feature location based on Latent Semantic Indexing (LSI) and Linear Discriminant Analysis (LDA)—two of the most common methods to realize such techniques—when predicting features for 4,650 commit changesets from the histories of 16 open-source projects spanning an average of three years between 1985 and 2015. Compared to the traditional techniques, FeatRacer showed a 3x higher precision and a 4.5x higher recall, with an average precision and recall of 89.6% among all 16 projects. It can accurately predict feature locations within the first five commits of our evaluation projects, being effective already for small datasets. FeatRacer takes on average 1.9ms to learn from past code fragments of a project, and 0.002ms to predict forgotten feature annotations in new code.
Mukelabai Mukelabai, Kevin Hermann, Thorsten Berger, Jan-Philipp Steghöfer
IEEE Trans. Software Eng.4
2022 SoK: Security of Microservice Applications: A Practitioners' Perspective on Challenges and Best Practices
abstract
Cloud-based application deployment is becoming increasingly popular among businesses, thanks to the emergence of microservices. However, securing such architectures is a challenging task since traditional security concepts cannot be directly applied to microservice architectures due to their distributed nature. The situation is exacerbated by the scattered nature of guidelines and best practices advocated by practitioners and organizations in this field. In this research paper we aim to shay light over the current microservice security discussions hidden within Grey Literature (GL) sources. Particularly, we identify the challenges that arise when securing microservice architectures, as well as solutions recommended by practitioners to address these issues. For this, we conducted a systematic GL study on the challenges and best practices of microservice security present in the Internet with the goal of capturing relevant discussions in blogs, white papers, and standards. We collected 312 GL sources from which 57 were rigorously classified and analyzed. This analysis on the one hand validated past academic literature studies in the area of microservice security, but it also identified improvements to existing methodologies pointing towards future research directions.
Priyanka Billawa, Anusha Bambhore Tukaram, Nicolás E. Díaz Ferreyra, Jan-Philipp Steghöfer, Riccardo Scandariato, Georg Simhandl
ARES4
2022 TriggerBench: A Performance Benchmark for Serverless Function Triggers
abstract
Serverless computing offers a scalable event-based paradigm for deploying managed cloud-native applications. Function triggers are essential building blocks in serverless, as they initiate any function execution. However, function triggering is insufficiently studied and inherently hard to measure given the distributed, ephemeral, and asynchronous nature of event-based function coordination. To address this gap, we present TriggerBench, a cross-provider benchmark for evaluating serverless function triggers based on distributed tracing. We evaluate the trigger latency (i.e., time to transition between two functions) of eight types of triggers in Microsoft Azure and three in AWS. Our results show that all triggers suffer from long tail latency, storage triggers introduce variable multi-second delays, and HTTP triggers are most suitable for interactive applications. Our insights can guide developers in choosing optimal event or messaging triggers for latency-sensitive applications. Researchers can extend TriggerBench to study the latency, scalability, and reliability of further trigger types and cloud providers.
Joel Scheuner, Marcus Bertilsson, Oskar Grönqvist, Henrik Tao, Henrik Lagergren, Jan-Philipp Steghöfer, Philipp Leitner 0001
IC2E6
2022 TracIMo: a traceability introduction methodology and its evaluation in an Agile development team
Salome Maro, Jan-Philipp Steghöfer, Paolo Bozzelli, Henry Muccini
Requir. Eng.2
2021 The MobSTr Dataset - An Exemplar for Traceability and Model-based Safety Assessment
abstract
The MobSTr dataset contains a number of artifacts for an autonomous driver assistance system, ranging from textual requirements to models for system design and models relevant to safety assurance. The artifacts provided are connected with traceability links created and managed with Eclipse Capra, an open source traceability management tool. The dataset builds upon a custom traceability information model that provides type safety and semantics for the trace links. MobSTr is intended for researchers that work on software and systems traceability as well as on model-based safety assurance. It is already being used in a number of studies, including research on trace link consistency, change impact analysis, and automated analysis of safety and timing requirements.
Jan-Philipp Steghöfer, Björn Koopmann, Jan Steffen Becker, Ingo Stierand, Marc Zeller, Maria Bonner, David Schmelter, Salome Maro
RE1
2021 Design Decisions in the Construction of Traceability Information Models for Safe Automotive Systems
abstract
Traceability management relies on a supporting model, the traceability information model (TIM), that defines which types of relationships exist between which artifacts and contains additional constraints such as multiplicities. Constructing a TIM that is fit for purpose is crucial to ensure that a traceability strategy yields the desired benefits. However, which design decisions are critical in the construction of TIMs and which impact they have on the usefulness and applicability of traceability is still an open question. In this paper, we use two cases of TIMs constructed for safety-critical, automotive systems with industrial safety experts, to identify key design decisions. We also propose a comparison scheme for TIMs based on a systematic literature review and evaluate the two cases as well as TIMs from the literature according to the scheme. Based on our analyses, we thus derive key insights into TIM construction and the design decisions that ensure that a TIM is fit for purpose.
Jan-Philipp Steghöfer, Björn Koopmann, Jan Steffen Becker, Mikaela Törnlund, Yulla Ibrahim, Mazen Mohamad
RE1
2021 Security assurance cases - state of the art of an emerging approach
abstract
Abstract Security Assurance Cases (SAC) are a form of structured argumentation used to reason about the security properties of a system. After the successful adoption of assurance cases for safety, SAC are getting significant traction in recent years, especially in safety-critical industries (e.g., automotive), where there is an increasing pressure to be compliant with several security standards and regulations. Accordingly, research in the field of SAC has flourished in the past decade, with different approaches being investigated. In an effort to systematize this active field of research, we conducted a systematic literature review (SLR) of the existing academic studies on SAC. Our review resulted in an in-depth analysis and comparison of 51 papers. Our results indicate that, while there are numerous papers discussing the importance of SAC and their usage scenarios, the literature is still immature with respect to concrete support for practitioners on how to build and maintain a SAC. More importantly, even though some methodologies are available, their validation and tool support is still lacking.
Mazen Mohamad, Jan-Philipp Steghöfer, Riccardo Scandariato
Empir. Softw. Eng.2
2020 Modeling and Analysis of Boundary Objects and Methodological Islands in Large-Scale Systems Development
Rebekka Wohlrab, Jennifer Horkoff, Rashidah Kasauli, Salome Maro, Jan-Philipp Steghöfer, Eric Knauss
ER5
2020 Charting Coordination Needs in Large-Scale Agile Organisations with Boundary Objects and Methodological Islands
abstract
Large-scale system development companies are increasingly adopting agile methods. While this adoption may improve lead-times, such companies need to balance two trade-offs: (i) the need to have a uniform, consistent development method on system level with the need for specialised methods for teams in different disciplines (e.g., hardware, software, mechanics, sales, support); (ii) the need for comprehensive documentation on system level with the need to have lightweight documentation enabling iterative and agile work. With specialised methods for teams, isolated teams work within larger ecosystems of plan-driven culture, i.e., teams become agile "islands". At the boundaries, these teams share knowledge which needs to be managed well for a correct system to be developed. While it is useful to support diverse and specialised methods, it is important to understand which islands are repeatedly encountered, the reasons or factors triggering their existence, and how best to handle coordination between them. Based on a multiple case study, this work presents a catalogue of islands and the boundary objects between them. We believe this work will be beneficial to practitioners aiming to understand their ecosystems and researchers addressing communication and coordination challenges in large-scale development.
Rashidah Kasauli, Rebekka Wohlrab, Eric Knauss, Jan-Philipp Steghöfer, Jennifer Horkoff, Salome Maro
ICSSP4
2020 Cutting through the Jungle: Disambiguating Model-based Traceability Terminology
abstract
Traceability, a classic requirements engineering topic, is increasingly used in the context of model-based engineering. However, researchers and practitioners lack a concise terminology to discuss aspects of requirements traceability in situations in which engineers heavily rely on models and model-based engineering. While others have previously surveyed the domain, no one has so far provided a clear, unambiguous set of terms that can be used to discuss traceability in such a context. We therefore set out to cut a path through the jungle of terminology for model-based traceability, ground it in established terminology from requirements engineering, and derive an unambiguous set of relevant terms. We also map the terminology used in existing primary and secondary studies to our taxonomy to show differences and commonalities. The contribution of this paper is thus a terminology for model-based traceability that allows requirements engineers and engineers working with models to unambiguously discuss their joint traceability efforts.
Jörg Holtmann, Jan-Philipp Steghöfer, Michael Rath 0002, David Schmelter
RE2
2020 The state of adoption and the challenges of systematic variability management in industry
abstract
Abstract Handling large-scale software variability is still a challenge for many organizations. After decades of research on variability management concepts, many industrial organizations have introduced techniques known from research, but still lament that pure textbook approaches are not applicable or efficient. For instance, software product line engineering—an approach to systematically develop portfolios of products—is difficult to adopt given the high upfront investments; and even when adopted, organizations are challenged by evolving their complex product lines. Consequently, the research community now mainly focuses on re-engineering and evolution techniques for product lines; yet, understanding the current state of adoption and the industrial challenges for organizations is necessary to conceive effective techniques. In this multiple-case study, we analyze the current adoption of variability management techniques in twelve medium- to large-scale industrial cases in domains such as automotive, aerospace or railway systems. We identify the current state of variability management, emphasizing the techniques and concepts they adopted. We elicit the needs and challenges expressed for these cases, triangulated with results from a literature review. We believe our results help to understand the current state of adoption and shed light on gaps to address in industrial practice.
Thorsten Berger, Jan-Philipp Steghöfer, Tewfik Ziadi, Jacques Robin, Jabier Martinez
Empir. Softw. Eng.2
2020 Collaborative traceability management: a multiple case study from the perspectives of organization, process, and culture
abstract
Traceability is crucial for many activities in software and systems engineering including monitoring the development progress, and proving compliance with standards. In practice, the use and maintenance of trace links are challenging as artifacts undergo constant change, and development takes place in distributed scenarios with multiple collaborating stakeholders. Although traceability management in general has been addressed in previous studies, there is a need for empirical insights into the collaborative aspects of traceability management and how it is situated in existing development contexts. The study reported in this paper aims to close this gap by investigating the relation of collaboration and traceability management, based on an understanding of characteristics of the development effort. In our multiple exploratory case study, we conducted semi-structured interviews with 24 individuals from 15 industrial projects. We explored which challenges arise, how traceability management can support collaboration, how collaboration relates to traceability management approaches, and what characteristics of the development effort influence traceability management and collaboration. We found that practitioners struggle with the following challenges: (1) collaboration across team and tool boundaries, (2) conveying the benefits of traceability, and (3) traceability maintenance. If these challenges are addressed, we found that traceability can facilitate communication and knowledge management in distributed contexts. Moreover, there exist multiple approaches to traceability management with diverse collaboration approaches, i.e., requirements-centered, developer-driven, and mixed approaches. While traceability can be leveraged in software development with both agile and plan-driven paradigms, a certain level of rigor is needed to realize its benefits and overcome challenges. To support practitioners, we provide principles of collaborative traceability management. The main contribution of this paper is empirical evidence of how culture, processes, and organization impact traceability management and collaboration, and principles to support practitioners with collaborative traceability management. We show that collaboration and traceability management have the potential to be mutually beneficial—when investing in one, also the other one is positively affected.
Rebekka Wohlrab, Eric Knauss, Jan-Philipp Steghöfer, Salome Maro, Anthony Anjorin, Patrizio Pelliccione
Requir. Eng.3
2020 Introduction to the Special Issue with Selected Papers of The International Conference on Autonomic Computing and Self-Organizing Systems (ACSOS) 2020
abstract
No abstract available.
Sven Tomforde, Timothy Wood 0001, Jan-Philipp Steghöfer
ACM Trans. Auton. Adapt. Syst.3
2019 Challenges of Scaled Agile for Safety-Critical Systems
Jan-Philipp Steghöfer, Eric Knauss, Jennifer Horkoff, Rebekka Wohlrab
PROFES1
2019 Impact of Gamification on Trace Link Vetting: A Controlled Experiment
Salome Maro, Emil Sundklev, Carl-Oscar Persson, Grischa Liebel, Jan-Philipp Steghöfer
REFSQ5
2018 Tackling combinatorial explosion: a study of industrial needs and practices for analyzing highly configurable systems
abstract
Highly configurable systems are complex pieces of software. To tackle this complexity, hundreds of dedicated analysis techniques have been conceived, many of which able to analyze system properties for all possible system configurations, as opposed to traditional, single-system analyses. Unfortunately, it is largely unknown whether these techniques are adopted in practice, whether they address actual needs, or what strategies practitioners actually apply to analyze highly configurable systems. We present a study of analysis practices and needs in industry. It relied on a survey with 27 practitioners engineering highly configurable systems and follow-up interviews with 15 of them, covering 18 different companies from eight countries. We confirm that typical properties considered in the literature (e.g., reliability) are relevant, that consistency between variability models and artifacts is critical, but that the majority of analyses for specifications of configuration options (a.k.a., variability model analysis) is not perceived as needed. We identified rather pragmatic analysis strategies, including practices to avoid the need for analysis. For instance, testing with experience-based sampling is the most commonly applied strategy, while systematic sampling is rarely applicable. We discuss analyses that are missing and synthesize our insights into suggestions for future research.
Mukelabai Mukelabai, Damir Nesic, Salome Maro, Thorsten Berger, Jan-Philipp Steghöfer
ASE5
2018 Vetting Automatically Generated Trace Links: What Information is Useful to Human Analysts?
abstract
Automated traceability has been investigated for over a decade with promising results. However, a human analyst is needed to vet the generated trace links to ensure their quality. The process of vetting trace links is not trivial and while previous studies have analyzed the performance of the human analyst, they have not focused on the analyst's information needs. The aim of this study is to investigate what context information the human analyst needs. We used design science research, in which we conducted interviews with ten practitioners in the traceability area to understand the information needed by human analysts. We then compared the information collected from the interviews with existing literature. We created a prototype tool that presents this information to the human analyst. To further understand the role of context information, we conducted a controlled experiment with 33 participants. Our interviews reveal that human analysts need information from three different sources: 1) from the artifacts connected by the link, 2) from the traceability information model, and 3) from the tracing algorithm. The experiment results show that the content of the connected artifacts is more useful to the analyst than the contextual information of the artifacts.
Salome Maro, Jan-Philipp Steghöfer, Jane Huffman Hayes, Jane Cleland-Huang, Miroslaw Staron
RE2
2018 Involving External Stakeholders in Project Courses
abstract
Problem: The involvement of external stakeholders in capstone projects and project courses is desirable due to its potential positive effects on the students. Capstone projects particularly profit from the inclusion of an industrial partner to make the project relevant and help students acquire professional skills. In addition, an increasing push towards education that is aligned with industry and incorporates industrial partners can be observed. However, the involvement of external stakeholders in teaching moments can create friction and could, in the worst case, lead to frustration of all involved parties. Contribution: We developed a model that allows analysing the involvement of external stakeholders in university courses both in a retrospective fashion, to gain insights from past course instances, and in a constructive fashion, to plan the involvement of external stakeholders. Key Concepts: The conceptual model and the accompanying guideline guide the teachers in their analysis of stakeholder involvement. The model is comprised of several activities (define, execute, and evaluate the collaboration). The guideline provides questions that the teachers should answer for each of these activities. In the constructive use, the model allows teachers to define an action plan based on an analysis of potential stakeholders and the pedagogical objectives. In the retrospective use, the model allows teachers to identify issues that appeared during the project and their underlying causes. Drawing from ideas of the reflective practitioner, the model contains an emphasis on reflection and interpretation of the observations made by the teacher and other groups involved in the courses. Key Lessons: Applying the model retrospectively to a total of eight courses shows that it is possible to reveal hitherto implicit risks and assumptions and to gain a better insight into the interaction between external stakeholders and students. Our empirical data reveals seven recurring risk themes that categorise the different risks appearing in the analysed courses. These themes can also be used to categorise mitigation strategies to address these risks proactively. Additionally, aspects not related to external stakeholders, e.g., about the interaction of the project with other courses in the study programme, have been revealed. The constructive use of the model for one course has proved helpful in identifying action alternatives and finally deciding to not include external stakeholders in the project due to the perceived cost-benefit-ratio. Implications to Practice: Our evaluation shows that the model is a viable and useful tool that allows teachers to reason about and plan the involvement of external stakeholders in a variety of course settings, and in particular in capstone projects.
Jan-Philipp Steghöfer, Håkan Burden, Regina Hebig, Gül Çalikli, Robert Feldt, Imed Hammouda, Jennifer Horkoff, Eric Knauss, Grischa Liebel
ACM Trans. Comput. Educ.1
2018 Software traceability in the automotive domain: Challenges and solutions
Salome Maro, Jan-Philipp Steghöfer, Miroslaw Staron
J. Syst. Softw.2
2018 Special issue: Trust management
Babak Esfandiari, Jan-Philipp Steghöfer
Web Intell.2
2017 No silver brick: Opportunities and limitations of teaching Scrum with Lego workshops
Jan-Philipp Steghöfer, Håkan Burden, Hiva Alahyari, Dominik Haneberg
J. Syst. Softw.1
2016 Impact of the Use of Industrial Modelling Tools on Modelling Education
abstract
It has been stated that industrial-grade modelling tools are unsuitable for teaching modelling. We assume, however, that the experiences of the teachers and the students is strongly connected to the support available. In this paper, we present our experience with a university course on software modelling. In the first year of the course, we used a commercial modelling tool, in the second year the open-source alternative Papyrus. Our quantitative analysis shows that the industrial-grade modelling tools with all their complexity did not have a negative impact on the students' experience of modelling. We analyse why our experience differs from published accounts and conclude that the availability of a tool champion and tailored instruction material is key. From this, we derive lessons learned and give recommendations on how to successfully use industrial-strength modelling tools in the classroom.
Grischa Liebel, Rogardt Heldal, Jan-Philipp Steghöfer
CSEE&T3
2016 Traceability maintenance: factors and guidelines
abstract
Traceability is an important concern for numerous software engineering activities. Establishing traceability links is a challenging and cost-intensive task, which is uneconomical without suitable strategies for maintaining high link quality. Current approaches to Traceability Management (TM), however, often make important assumptions and choices without ensuring that the consequences and implications for traceability maintenance are feasible and desirable in practice.
Salome Maro, Anthony Anjorin, Rebekka Wohlrab, Jan-Philipp Steghöfer
ASE4
2016 An ISO 26262 Compliant Design Flow and Tool for Automotive Multicore Systems
Maria Trei, Salome Maro, Jan-Philipp Steghöfer, Thomas Peikenkamp
PROFES3
2016 Capra: A Configurable and Extendable Traceability Management Tool
abstract
Traceability is a known problem both in academia and industry. One of the main challenges is that there is no one solution that will solve traceability problems for everyone in industry. Traceability needs are dependent on the context of the organization and can differ from project to project in the same organization. To cater for this problem we have developed Capra, an open source, flexible, configurable and extendable traceability management tool. Capra can be tailored according to specific traceability needs of individual projects and organizations.
Salome Maro, Jan-Philipp Steghöfer
RE2
2016 Collaborative Traceability Management: Challenges and Opportunities
abstract
Traceability and trace link management are important for various reasons, including managing knowledge about a complex software system, monitoring the progress of its development, and proving that it is developed in accordance to regulations. However, it is difficult to maintain and use trace links in real-world projects where artifacts undergo constant change and multiple stakeholders are involved. In this paper, we extend the current body of knowledge on traceability management by regarding its collaborative aspects in an industrial setting. Based on 15 industrial cases and semi-structured interviews with 24 practitioners, we identify challenges involved in collaborative traceability management, and how traceability management can be used to enable collaboration. Our findings show that main challenges are boundaries between organizations and tools, a lack of common goals and responsibilities, and the difficulty of collaboratively maintaining trace links. We also identify traceability as an important facilitator for communication and knowledge management across these boundaries.
Rebekka Wohlrab, Jan-Philipp Steghöfer, Eric Knauss, Salome Maro, Anthony Anjorin
RE2
2015 On integrating graphical and textual editors for a UML profile based domain specific language: an industrial experience
abstract
Domain Specific Languages (DSLs) are an established means of reducing the gap between problem and solution domains. DSLs increase productivity and improve quality as they can be tailored to exactly fit the needs of the problem to be solved. A DSL can have multiple notations including textual and graphical notations. In some cases, one of these notations for a DSL is enough but there are many cases where a single notation does not suffice and there is a demand to support multiple notations for the same DSL. UML profile is one of several approaches used to define a DSL, however most UML tools only come with graphical editors. In this paper, we present our approach and industrial experience on integrating textual and graphical editors for a UML profile-based DSL. This work was conducted as part of an explorative study at Ericsson. The main aim of the study was to investigate how to introduce a textual editor to an already existing UML profile-based DSL in an Eclipse environment. We report on the challenges of integrating textual and graphical editors for UML profile-based DSLs in practice, our chosen approach, specific constraints and requirements of the study.
Salome Maro, Jan-Philipp Steghöfer, Anthony Anjorin, Matthias Tichy, Lars Gelin
SLE2
2015 Cooperative Resource Allocation in Open Systems of Systems
abstract
Resource allocation is a common problem in many technical systems. In multi-agent systems, the decentralized or regionalized solution of this problem usually requires the agents to cooperate due to their limited resources and knowledge. At the same time, if these systems are of large scale, scalability issues can be addressed by a self-organizing hierarchical system structure that enables problem decomposition and compartmentalization. In open systems, various uncertainties—introduced by the environment as well as the agents’ possibly self-interested or even malicious behavior—have to be taken into account to be able to allocate the resources according to the actual demand. In this article, we present a trust- and cooperation-based algorithm that solves a dynamic resource allocation problem in open systems of systems. To measure and deal with uncertainties imposed by the environment and the agents at runtime, the algorithm uses the social concept of trust. In a hierarchical setting, we additionally show how agents create constraint models by learning the capabilities of subordinate agents if these are not able or willing to disclose this information. Throughout the article, the creation of power plant schedules in decentralized autonomous power management systems serves as a running example.
Gerrit Anders, Alexander Schiendorfer, Florian Siefert, Jan-Philipp Steghöfer, Wolfgang Reif
ACM Trans. Auton. Adapt. Syst.4
2014 Synthesised Constraint Models for Distributed Energy Management
abstract
Resource allocation is a task frequently encountered in energy management systems such as the coordination of power generators in a virtual power plant (unit commitment).Standard solutions require fixed parametrised optimisation models that the participants have to stick to without leaving room for tailored behaviour or individual preferences.We present a modelling methodology that allows organisations to specify optimisation goals independently of concrete participants and participants to craft more detailed models and state individual preferences.While considerable efforts have been spent on devising efficient control algorithms and detailed physical models in power management systems, practical aspects of unifying several heterogeneous models for optimisation have been widely ignored -a gap we aim to close.As a by-product, we give a formulation of warm and cold start-up times for power plants that improves existing power plant models.The concepts are detailed with the loaddistribution problem faced in virtual power plants and evaluated on several random instances where we observe that a significant number of soft constraints of individual actors can be satisfied if considered. I. CONSTRAINT OPTIMISATION PROBLEMS IN POWER SYSTEMSR ESOURCE allocation and scheduling are difficult prob- lems that occur frequently in energy systems, be it the coordination of power generation [1], demand-side management, or building control software.In a producer-based view, supply needs to meet the demand as accurately as possible in order to guarantee stability and avoid costs incurred by corrective measures.Similarly, consumers may try to find cost-minimising schedules for processes required throughout a day with respect to time-dependent energy prices.Current initiatives 1 are based on the assumption that groups of prosumers (i.e., energy producers and/or consumers) can form and team up to achieve better prices or production rates for their participants.We also adopt the notion of agents, indicating that the prosumers are in principle autonomous entities, even if they surrender the decision about their power output to the group.A straightforward solution (see, e.g., [2], [3], [4], [5]) to this resource allocation problem is to model the decision making process (e.g., distributing the load in a virtual power plant (VPP) or scheduling energy-consuming domestic processes in a consumer coalition) as a mathematical optimisation problem such as a mixed integer program (MIP), a linear program
Alexander Schiendorfer, Jan-Philipp Steghöfer, Wolfgang Reif
FedCSIS2
2014 Synthesis and Abstraction of Constraint Models for Hierarchical Resource Allocation Problems
abstract
Many resource allocation problems are hard to solve even with state-of-the-art constraint optimisation software upon reaching a certain scale.Our approach to deal with this increasing complexity is to employ a hierarchical "regio-central" mechanism.It requires two techniques: (1) the synthesis of several models of agents providing a certain resource into a centrally and efficiently solvable optimisation problem and (2) the creation of an abstracted version of this centralised model that reduces its complexity when passing it on to higher layers.We present algorithms to create such synthesised and abstracted models in a fully automated way and demonstrate empirically that the obtained solutions are comparable to central solutions but scale better in an example taken from energy management. 15
Alexander Schiendorfer, Jan-Philipp Steghöfer, Wolfgang Reif
ICAART (2)2
2014 PosoMAS: An Extensible, Modular SE Process for Open Self-organising Systems
Jan-Philipp Steghöfer, Hella Ponsar, Benedikt Eberhardinger, Wolfgang Reif
PRIMA1
2013 Synthesis of observers for autonomic evolutionary systems from requirements models
Jan-Philipp Steghöfer, Benedikt Eberhardinger, Florian Nafz, Wolfgang Reif
IM1
2013 Model-driven synthesis of monitoring infrastructure for reliable adaptive multi-agent systems
abstract
Knowledge about the current state of the system serves at least two purposes: it is the basis for decisions to act and adapt to ensure reliable operation and it can be used to verify the correctness of the system at runtime. Both purposes require that current information is available at runtime that can be evaluated. Thus, the system designers have to create a complex monitoring infrastructure that suits the purposes of the system. We propose a combination of proven techniques that can be used as the basis for such a monitoring infrastructure. We combine it with a model-driven approach that allows a model transformation of information contained in the requirements and design documents to implementations of observers and controllers that allow adaptation at runtime based on current information as well as runtime verification. The approach can be easily integrated into an iterative-incremental software engineering process and is illustrated with two complex case studies.
Benedikt Eberhardinger, Jan-Philipp Steghöfer, Florian Nafz, Wolfgang Reif
ISSRE2
2012 A Decentralized Multi-agent Algorithm for the Set Partitioning Problem
Gerrit Anders, Florian Siefert, Jan-Philipp Steghöfer, Wolfgang Reif
PRIMA3
2012 3rd edition of the workshop on trustworthy self-organizing systems (TSOS 2012)
abstract
Nietzsche describes what is at the core of the concept of trust as it is used in agent societies and self-organising systems. Trust describes the expectation of one entity that the other behaves according to a set of rules. If that trust is broken, it is very hard to repair. If it exists, however, it is the basis of cooperation and enables a collective effort that gives a society purpose and allows it to succeed in its respective goals. Self-organisation is often at the root of such collective efforts as it allows the restructuring of a society to adapt to changing objectives, a changing environment, and new cooperation partners. Trust arises in such systems from the interactions of agents and the experiences of attempts to collaborate. It is thus only natural to regard trust and self-organisation together and explore the concepts' relation.
Christian Müller-Schloer, Wolfgang Reif, Jan-Philipp Steghöfer
PST3
2012 On the combination of top-down and bottom-up methodologies for the design of coordination mechanisms in self-organising systems
Jan Sudeikat, Jan-Philipp Steghöfer, Hella Ponsar, Wolfgang Reif, Wolfgang Renz, Thomas Preisler, Peter Salchow
Inf. Softw. Technol.2
2010 A Formal Framework for Compositional Verification of Organic Computing Systems
Florian Nafz, Hella Ponsar, Jan-Philipp Steghöfer, Simon Bäumler, Wolfgang Reif
ATC3
2010 Trustworthy Organic Computing Systems: Challenges and Perspectives
Jan-Philipp Steghöfer, Rolf Kiefhaber, Karin Bee, Yvonne Bernard, Lukas Klejnowski, Wolfgang Reif, Theo Ungerer, Elisabeth André, Jörg Hähner, Christian Müller-Schloer
ATC1
2009 A Universal Self-Organization Mechanism for Role-Based Organic Computing Systems
Florian Nafz, Frank Ortmeier, Hella Ponsar, Jan-Philipp Steghöfer, Wolfgang Reif
ATC4
2008 Implementing Organic Computing Systems with AgentService
Florian Nafz, Frank Ortmeier, Hella Ponsar, Jan-Philipp Steghöfer, Wolfgang Reif
ENASE4