EDBT 2026 Demo / reviewers in the wild / expert
Pedro Ribeiro 0002
dblp:184/3701 · also Pedro Fernando De Oliveira Salazar Ribeiro
· DBLP profile ↗
20ranked-venue papers
6as first author
10since 2021 · last 2026
0000-0003-4319-4872ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 12 · 3 first-author · 7 since 2021Theory of computation · 10 · 5 first-author · 4 since 2021Artificial intelligence and machine learning · 1Systems, architecture and hardware · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | The SLEEC Framework for Normative Requirements EngineeringabstractAbstract Autonomous agents are increasingly deployed in sensitive, human-centric domains—such as healthcare, assistive care, and emergency response—where their decision-making must align with complex human norms. These translate into Social, Legal, Ethical, Empathetic, and Cultural (SLEEC) requirements that are often nuanced and context-dependent, challenging traditional software engineering paradigms. Our tutorial paper presents a comprehensive, tool-supported methodology for managing the SLEEC requirements lifecycle, covering elicitation, well-formedness validation, and conformance verification of software design models against SLEEC requirements. We demonstrate the use of our methodology and associated tools through application to a robot-assisted dressing system, providing a guide for researchers and engineers to bridge the gap between abstract human norms and verifiable system designs. Pedro Ribeiro 0002, Radu Calinescu, Ana Cavalcanti 0001, Marsha Chechik, Sinem Getir, Lina Marsso, Isobel Standen, Beverley A. Townsend |
FM (2) | 1 |
| 2026 | Verifying Properties of State-Based Models Using Constraint Programming
Victoria Johnson, Pedro Ribeiro 0002, Simon Foster 0001, Peter Nightingale, Felix Ulrich-Oltean |
ABZ | 2 |
| 2026 | Correction: Diagrammatic physical robot models
Alvaro Miyazawa, Sharar Ahmadi, Ana Cavalcanti 0001, James Baxter 0001, Mark Post, Pedro Ribeiro 0002, Jonathan Timmis, Thomas Wright |
Softw. Syst. Model. | 6 |
| 2025 | Specification, validation and verification of social, legal, ethical, empathetic and cultural requirements for autonomous agentsabstractAutonomous agents are increasingly being proposed for use in healthcare, assistive care, education, and other applications governed by complex human-centric norms. To ensure compliance with these norms, the rules they induce need to be unambiguously defined, checked for consistency, and used to verify the agent. In this paper, we introduce a framework for formal specification, validation and verification of social, legal, ethical, empathetic and cultural (SLEEC) rules for autonomous agents. Our framework comprises: (i) a language for specifying SLEEC rules and rule defeaters (that is, circumstances in which a rule does not apply or an alternative form of the rule is required); (ii) a formal semantics (defined in the process algebra tock-CSP) for the language; and (iii) methods for detecting conflicts and redundancy within a set of rules, and for verifying the compliance of an autonomous agent with such rules. We show the applicability of our framework for two autonomous agents from different domains: a firefighter UAV, and an assistive-dressing robot. Sinem Getir, Pedro Ribeiro 0002, Ana Cavalcanti 0001, Radu Calinescu, Colin Paterson, Beverley A. Townsend |
J. Syst. Softw. | 2 |
| 2025 | Diagrammatic physical robot modelsabstractSimulation is a favoured technique in robotics. It is, however, costly, in terms of development time, and its usability is limited by the lack of standardisation and portability of simulators. We present RoboSim, a diagrammatic tool-independent domain-specific language to model robotic platforms and their controllers. It can be regarded as a profile of UML/SysML enriched with time primitives, differential equations, and a mathematical semantics. Our previous work on RoboSim described a notation to specify control software. In this paper, we present a novel notation to describe physical models: block diagrams that can be linked to the platform-independent software model to characterise how services required by the software are realised by actuators and sensors. Behaviours are specified by differential equations, and simulations and mathematical models of the whole system can be generated automatically. Our main contributions are a modular and extensible diagrammatic notation that supports the explicit specification of physical behaviours; a set of validation rules that identify well-formed models; a model-to-model transformation from RoboSim to an input format accepted by several simulators; and a formal semantics for mathematical reasoning. Alvaro Miyazawa, Sharar Ahmadi, Ana Cavalcanti 0001, James Baxter 0001, Mark Post, Pedro Ribeiro 0002, Jonathan Timmis, Thomas Wright |
Softw. Syst. Model. | 6 |
| 2024 | Laws of Timed State MachinesabstractAbstract State machines are widely used in industry and academia to capture behavioural models of control. They are included in popular notations, such as UML and its variants, and used (sometimes informally) to describe computational artefacts. In this paper, we present laws for state machines that we prove sound with respect to a process algebraic semantics for refinement, and complete, in that they are sufficient to reduce an arbitrary model to a normal form that isolates basic (action and control) elements. We consider two variants of UML-like state machines, both enriched with facilities to deal with time budgets, timeouts and deadlines over triggers and actions. In the first variant, machines are self-contained components, declaring all the variables, events and operations that they require or define. In contrast, in the second variant, machines are open, like in UML for instance. Laws for open state machines do not depend on a specific context of variables, events and operations, and normalization uses a novel operator for open-machine (de)composition. Our laws can be used in behaviour-preservation transformation techniques. Their applications are automated by a model-transformation engine. Ana Cavalcanti 0001, Madiel Conserva Filho, Pedro Ribeiro 0002, Augusto Sampaio 0001 |
Comput. J. | 3 |
| 2024 | Toolkit for specification, validation and verification of social, legal, ethical, empathetic and cultural requirements for autonomous agentsabstractA growing range of applications use AI and other autonomous agents to perform tasks that raise social, legal, ethical, empathetic, and cultural (SLEEC) concerns. To support a framework for the consideration of these concerns, we introduce SLEEC-TK, a toolkit for specification, validation, and verification of SLEEC requirements. SLEEC-TK is an Eclipse-based environment for defining SLEEC rules in a domain-specific language with a timed process algebraic semantics. SLEEC-TK uses model checking to identify redundant and conflicting rules, and to verify conformance of design models with SLEEC rules. We illustrate the use of SLEEC-TK for an assistive-care robot. Sinem Getir, Pedro Ribeiro 0002, Charlie Burholt, Maddie Jones, Ana Cavalcanti 0001, Radu Calinescu |
Sci. Comput. Program. | 2 |
| 2022 | Sound reasoning in tock-CSPabstractAbstract Specifying budgets and deadlines using a process algebra like CSP requires an explicit notion of time. The tock-CSP encoding embeds a rich and flexible approach for modelling discrete-time behaviours with powerful tool support. It uses an event tock, interpreted to mark passage of time. Analysis, however, has traditionally used the standard semantics of CSP, which is inadequate for reasoning about timed refinement. The most recent version of the model checker FDR provides tailored support for tock-CSP, including specific operators, but the standard semantics remains inadequate. In this paper, we characterise tock-CSP as a language in its own right, rich enough to model budgets and deadlines, and reason about Zeno behaviour. We present the first sound tailored semantic model for tock-CSP that captures timewise refinement. It is fully mechanised in Isabelle/HOL and, to enable use of FDR4 to check refinement in this novel model, we use model shifting, which is a technique that explicitly encodes refusals in traces. James Baxter 0001, Pedro Ribeiro 0002, Ana Cavalcanti 0001 |
Acta Informatica | 2 |
| 2022 | Correction to: Sound reasoning in tock-CSP
James Baxter 0001, Pedro Ribeiro 0002, Ana Cavalcanti 0001 |
Acta Informatica | 2 |
| 2022 | Safety assurance of an industrial robotic control system using hardware/software co-verificationabstractAs a general trend in industrial robotics, an increasing number of safety functions are being developed or re-engineered to be handled in software rather than by physical hardware such as safety relays or interlock circuits. This trend reinforces the importance of supplementing traditional, input-based testing and quality procedures which are widely used in industry today, with formal verification and model-checking methods. To this end, this paper focuses on a representative safety-critical system in an ABB industrial paint robot, namely the High-Voltage electrostatic Control system (HVC). The practical convergence of the high-voltage produced by the HVC, essential for safe operation, is formally verified using a novel and general co-verification framework where hardware and software models are related via platform mappings. This approach enables the pragmatic combination of highly diverse and specialised tools. The paper's main contribution includes details on how hardware abstraction and verification results can be transferred between tools in order to verify system-level safety properties. It is noteworthy that the HVC application considered in this paper has a rather generic form of a feedback controller. Hence, the co-verification framework and experiences reported here are also highly relevant for any cyber-physical system tracking a setpoint reference. Yvonne Murray, Martin Sirevåg, Pedro Ribeiro 0002, David A. Anisi, Morten Mossige |
Sci. Comput. Program. | 3 |
| 2020 | A Unary Semigroup Trace Algebra
Pedro Ribeiro 0002 |
RAMiCS | 1 |
| 2020 | EditorialabstractNo abstract available. Ana Cavalcanti 0001, Pedro Ribeiro 0002 |
Formal Aspects Comput. | 2 |
| 2019 | Verified simulation for robotics
Ana Cavalcanti 0001, Augusto Sampaio 0001, Alvaro Miyazawa, Pedro Ribeiro 0002, Madiel Conserva Filho, André Didier, Wei Li 0055, Jonathan Timmis |
Sci. Comput. Program. | 4 |
| 2019 | RoboChart: modelling and verification of the functional behaviour of robotic applicationsabstractRobots are becoming ubiquitous: from vacuum cleaners to driverless cars, there is a wide variety of applications, many with potential safety hazards. The work presented in this paper proposes a set of constructs suitable for both modelling robotic applications and supporting verification via model checking and theorem proving. Our goal is to support roboticists in writing models and applying modern verification techniques using a language familiar to them. To that end, we present RoboChart, a domain-specific modelling language based on UML, but with a restricted set of constructs to enable a simplified semantics and automated reasoning. We present the RoboChart metamodel, its well-formedness rules, and its process-algebraic semantics. We discuss verification based on these foundations using an implementation of RoboChart and its semantics as a set of Eclipse plug-ins called RoboTool. Alvaro Miyazawa, Pedro Ribeiro 0002, Wei Li 0055, Ana Cavalcanti 0001, Jonathan Timmis, Jim Woodcock 0001 |
Softw. Syst. Model. | 2 |
| 2019 | Angelic processes for CSP via the UTP
Pedro Ribeiro 0002, Ana Cavalcanti 0001 |
Theor. Comput. Sci. | 1 |
| 2018 | Modelling and Verification for Swarm Robotics
Ana Cavalcanti 0001, Alvaro Miyazawa, Augusto Sampaio 0001, Wei Li 0055, Pedro Ribeiro 0002, Jonathan Timmis |
IFM | 5 |
| 2017 | Modelling and Verification of Timed Robotic Controllers
Pedro Ribeiro 0002, Alvaro Miyazawa, Wei Li 0055, Ana Cavalcanti 0001, Jonathan Timmis |
IFM | 1 |
| 2017 | Automatic property checking of robotic applicationsabstractRobot software controllers are often concurrent and time critical, and requires modern engineering approaches for validation and verification. With this motivation, we have developed a tool and techniques for graphical modelling with support for automatic generation of underlying mathematical definitions for model checking. It is possible to check automatically both general properties, like absence of deadlock, and specific application properties. We cater both for timed and untimed modelling and verification. Our approach has been tried in examples used in a variety of robotic applications. Alvaro Miyazawa, Pedro Ribeiro 0002, Wei Li 0055, Ana Cavalcanti 0001, Jonathan Timmis |
IROS | 2 |
| 2014 | UTP Designs for Binary Multirelations
Pedro Ribeiro 0002, Ana Cavalcanti 0001 |
ICTAC | 1 |
| 2013 | Designs with Angelic NondeterminismabstractHoare and He's Unifying Theories of Programming (UTP) are a predicative relational framework for the definition and combination of refinement languages for a variety of programming paradigms. Previous work has defined a theory for angelic nondeterminism in the UTP; this is basically an encoding of binary multirelations in a predicative model. In the UTP a theory of designs (pre and postcondition pairs) provides, not only a model of terminating programs, but also a stepping stone to define a theory for state-rich reactive processes. In this paper, we cast the angelic nondeterminism theory of the UTP as a theory of designs with the long-term objective of providing a model for well established refinement process algebras like Communicating Sequential Processes (CSP) and Circus. Pedro Ribeiro 0002, Ana Cavalcanti 0001 |
TASE | 1 |