Lina Marsso

dblp:198/1393 · DBLP profile ↗
← Back
16ranked-venue papers
3as first author
13since 2021 · last 2026
0000-0002-0220-191XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 14 · 3 first-author · 11 since 2021Theory of computation · 4 · 1 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 The SLEEC Framework for Normative Requirements Engineering
abstract
Abstract Autonomous agents are increasingly deployed in sensitive, human-centric domains—such as healthcare, assistive care, and emergency response—where their decision-making must align with complex human norms. These translate into Social, Legal, Ethical, Empathetic, and Cultural (SLEEC) requirements that are often nuanced and context-dependent, challenging traditional software engineering paradigms. Our tutorial paper presents a comprehensive, tool-supported methodology for managing the SLEEC requirements lifecycle, covering elicitation, well-formedness validation, and conformance verification of software design models against SLEEC requirements. We demonstrate the use of our methodology and associated tools through application to a robot-assisted dressing system, providing a guide for researchers and engineers to bridge the gap between abstract human norms and verifiable system designs.
Pedro Ribeiro 0002, Radu Calinescu, Ana Cavalcanti 0001, Marsha Chechik, Sinem Getir, Lina Marsso, Isobel Standen, Beverley A. Townsend
FM (2)6
2025 Effective, Efficient, and Environmentally Friendly Out-of-Model-Scope Detection Methodology
abstract
Integrating deep neural networks (DNNs) in safety-critical systems is widespread, but their reliability depends on accurate performance in real-world environments. Capturing all scenarios in training data is impractical. One solution is to use DNNs within their known range and alert a human operator when encountering unreliable outputs, i.e., out-of-model-scope (OMS) outputs. However, current unsupervised OMS detection methods monitor all neurons, are computationally expensive, and are not robust enough to avoid neuron noises. In this paper, we propose an effective, efficient, and environmentally friendly methodology, EFOMS, that automatically filters unreliable outputs by extending existing OMS detection methods to focus only on significant neurons, thereby filtering out noise from unimportant neurons. EFOMS achieves comparable or better OMS detection quality with significantly reduced computational costs: 45% faster, consuming 30% less energy, producing 30% fewer carbon emissions, and using up to 21% less peak memory.
Ettore Merlo, Clément Benesse, Lina Marsso
ISSRE4
2025 Assessing Visually-Continuous Corruption Robustness of Neural Networks Relative to Human Performance
abstract
Neural Networks (NNs) have surpassed human accuracy in image classification on ImageNet, yet they often lack robustness against image corruption, i.e., corruption robustness, with such robustness being seemingly effortless for human perception. In this paper, we propose visually-continuous corruption robustness (VCR) - an extension of corruption robustness to allow assessing it over the wide and continuous range of changes that correspond to the human perceptive quality (i.e., from the original image to the full distortion of all perceived visual information), along with two novel human-aware metrics for NN evaluation. To compare VCR of NNs with human perception, we conducted extensive experiments on 14 commonly used image corruptions with 7,718 human participants and state-of-the-art robust NN models with different training objectives (e.g., standard, adversarial, corruption robustness), different architectures (e.g., convolution NNs, vision transformers), and different amounts of training data augmentation. Our study showed that: 1) assessing robustness against continuous corruption can reveal insufficient robustness undetected by existing benchmarks; as a result, 2) the gap between NN and human robustness is larger than previously known; and finally, 3) some image corruptions have a similar impact on human perception, offering opportunities for more cost-effective robustness assessments.
Huakun Shen, Boyue Caroline Hu, Krzysztof Czarnecki 0001, Lina Marsso, Marsha Chechik
WACV4
2025 Bounded satisfiability checking of $\hbox {FOL}^*$ formulas with aggregations
Nick Feng, Lina Marsso, Yuliia Kholodetska, Marsha Chechik
Formal Methods Syst. Des.2
2024 Analyzing and Debugging Normative Requirements via Satisfiability Checking
abstract
As software systems increasingly interact with humans in application domains such as transportation and healthcare, they raise concerns related to the social, legal, ethical, empathetic, and cultural (SLEEC) norms and values of their stakeholders. Normative non-functional requirements (N-NFRs) are used to capture these concerns by setting SLEEC-relevant boundaries for system behavior. Since N-NFRs need to be specified by multiple stakeholders with widely different, non-technical expertise (ethicists, lawyers, regulators, end users, etc.), N-NFR elicitation is very challenging. To address this difficult task, we introduce N-Check, a novel tool-supported formal approach to N-NFR analysis and debugging. N-Check employs satisfiability checking to identify a broad spectrum of N-NFR well-formedness issues, such as conflicts, redundancy, restrictiveness, and insufficiency, yielding diagnostics that pinpoint their causes in a user-friendly way that enables non-technical stakeholders to understand and fix them. We show the effectiveness and usability of our approach through nine case studies in which teams of ethicists, lawyers, philosophers, psychologists, safety analysts, and engineers used N-Check to analyse and debug 233 N-NFRs, comprising 62 issues for the software underpinning the operation of systems, such as, assistive-care robots and tree-disease detection drones to manufacturing collaborative robots.
Nick Feng, Lina Marsso, Sinem Getir, Yesugen Baatartogtokh, Reem Ayad, Victória Oldemburgo de Mello, Beverley A. Townsend, Isobel Standen, Ioannis Stefanakos, Calum Imrie, Genaína Nunes Rodrigues, Ana Cavalcanti 0001, Radu Calinescu, Marsha Chechik
ICSE2
2024 Diagnosis via Proofs of Unsatisfiability for First-Order Logic with Relational Objects
abstract
Satisfiability-based automated reasoning is an approach that is being successfully used in software engineering to validate complex software, including for safety-critical systems. Such reasoning underlies many validation activities, from requirements analysis to design consistency to test coverage. While generally effective, the back-end constraint solvers are often complex and inevitably error-prone, which threatens the soundness of their application. Thus, such solvers need to be validated, which includes checking correctness and explaining (un)satisfiability results returned by them. In this work, we consider satisfiability analysis based on First-Order Logic with relational objects (FOL*) which has been shown to be effective for reasoning about time- and data-sensitive early system designs. We tackle the challenge of validating the correctness of FOL* unsatisfiability results and deriving diagnoses to explain the causes of the unsatisfiability. Inspired by the concept of proofs of UNSAT from SAT/SMT solvers, we define a proof format and proof rules to track the solvers' reasoning steps as sequences of derivations towards UNSAT. We also propose an algorithm to verify the correctness of FOL* proofs while filtering unnecessary derivations and develop a proof-based diagnosis to explain the cause of unsatisfiability. We implemented the proposed proof support on top of the state-of-the-art FOL* satisfiability checker to generate proofs of UNSAT and validated our approach by applying the proof-based diagnoses to explain the causes of well-formedness issues of normative requirements of software systems.
Nick Feng, Lina Marsso, Marsha Chechik
ASE2
2024 Normative Requirements Operationalization with Large Language Models
abstract
Normative non-functional requirements specify con-straints that a system must observe in order to avoid violations of social, legal, ethical, empathetic, and cultural norms. As these requirements are typically defined by non-technical system stakeholders with different expertise and priorities (ethicists, lawyers, social scientists, etc.), ensuring their well-formedness and consistency is very challenging. Recent research has tackled this challenge using a domain-specific language to specify normative requirements as rules whose consistency can then be analysed with formal methods. In this paper, we propose a complemen-tary approach that uses Large Language Models to extract semantic relationships between abstract representations of system capabilities. These relations, which are often assumed implicitly by non-technical stakeholders (e.g., based on common sense or domain knowledge), are then used to enrich the automated reasoning techniques for eliciting and analyzing the consistency of normative requirements. We show the effectiveness of our approach to normative requirements elicitation and operational-ization through a range of real-world case studies. An extended version of this paper, which includes appendices is available at https://arxiv.org/abs/2404.12335
Nick Feng, Lina Marsso, Sinem Getir, Isobel Standen, Yesugen Baatartogtokh, Reem Ayad, Victória Oldemburgo de Mello, Beverley A. Townsend, Hanne Bartels, Ana Cavalcanti 0001, Radu Calinescu, Marsha Chechik
RE2
2023 Early Verification of Legal Compliance via Bounded Satisfiability Checking
abstract
Abstract Legal properties involve reasoning about data values and time. Metric first-order temporal logic (MFOTL) provides a rich formalism for specifying legal properties. While MFOTL has been successfully used for verifying legal properties over operational systems via runtime monitoring, no solution exists for MFOTL-based verification in early-stage system development captured by requirements. Given a legal property and system requirements, both formalized in MFOTL, the compliance of the property can be verified on the requirements via satisfiability checking. In this paper, we propose a practical, sound, and complete (within a given bound) satisfiability checking approach for MFOTL. The approach, based on satisfiability modulo theories (SMT), employs a counterexample-guided strategy to incrementally search for a satisfying solution. We implemented our approach using the Z3 SMT solver and evaluated it on five case studies spanning the healthcare, business administration, banking and aviation domains. Our results indicate that our approach can efficiently determine whether legal properties of interest are met, or generate counterexamples that lead to compliance violations.
Nick Feng, Lina Marsso, Mehrdad Sabetzadeh, Marsha Chechik
CAV (3)2
2023 Towards a Formal Framework for Normative Requirements Elicitation
abstract
As software and cyber-physical systems interacting with humans become prevalent in domains such as healthcare, education and customer service, software engineers need to consider normative (i.e., social, legal, ethical, empathetic and cultural) requirements. However, their elicitation is challenging, as they must reflect the often conflicting or redundant views of stakeholders ranging from users and operators to lawyers, ethicists and regulators. To address this challenge, we introduce a tool-supported Formal framework for normaTive requirements elicitation (FormaTive). It allows specification of normative rules for a software system in an intuitive high-level language, and automates: (i) the mapping of the rules to an internal formal representation; (ii) their analysis to identify rule conflicts, redundancies, and concerns; and (iii) the synthesis of feedback enabling users to understand and resolve problems.
Nick Feng, Lina Marsso, Sinem Getir, Beverley A. Townsend, Ana Cavalcanti 0001, Radu Calinescu, Marsha Chechik
ASE2
2023 DecompoVision: Reliability Analysis of Machine Vision Components through Decomposition and Reuse
abstract
Analyzing reliability of Machine Vision Components (MVC) against scene changes (such as rain or fog) in their operational environment is crucial for safety-critical applications. Safety analysis relies on the availability of precisely specified and, ideally, machine-verifiable requirements. The state-of-the-art reliability framework ICRAF developed machine-verifiable requirements obtained using human performance data. However, ICRAF is limited to analyzing reliability of MVCs solving simple vision tasks, such as image classification. Yet, many real-world safety-critical systems require solving more complex vision tasks, such as object detection and instance segmentation. Fortunately, many complex vision tasks (which we call “c-tasks”) can be represented as a sequence of simple vision subtasks. For instance, object detection can be decomposed as object localization followed by classification. Based on this fact, in this paper, we show that the analysis of c-tasks can also be decomposed as a sequential analysis of their simple subtasks, which allows us to apply existing techniques for analyzing simple vision tasks. Specifically, we propose a modular reliability framework, DecompoVision, that decomposes: (1) the problem of solving a c-task, (2) the reliability requirements, and (3) the reliability analysis, and, as a result, provides deeper insights into MVC reliability. DecompoVision extends ICRAF to handle complex vision tasks and enables reuse of existing artifacts across different c-tasks. We capture new reliability gaps by checking our requirements on 13 widely used object detection MVCs, and, for the first time, benchmark segmentation MVCs.
Boyue Caroline Hu, Lina Marsso, Nikita Dvornik, Huakun Shen, Marsha Chechik
ESEC/SIGSOFT FSE2
2022 Using Formal Conformance Testing to Generate Scenarios for Autonomous Vehicles
abstract
Simulation, a common practice to evaluate au-tonomous vehicles, requires to specify realistic scenarios, in par-ticular critical ones, occurring rarely and potentially dangerous to reproduce on the road. Such scenarios may be either generated randomly, or specified manually. Randomly generating scenarios is easy, but their relevance might be difficult to assess. Manually specified scenarios can focus on a given feature, but their design might be difficult and time-consuming, especially to achieve satisfactory coverage. In this work, we propose an automatic approach to generate a large number of relevant critical scenarios for autonomous driving simulators. The approach is based on the generation of behavioral conformance tests from a formal model (specifying the ground truth configuration with the range of vehicle behaviors) and a test purpose (specifying the critical feature to focus on). The obtained abstract test cases cover, by construction, all possible executions exercising a given feature, and can be automatically translated into the inputs of autonomous driving simulators. We illustrate our approach by generating thousands of behavior trees for the CARLA simulator for several realistic configurations.
Jean-Baptiste Horel, Christian Laugier, Lina Marsso, Radu Mateescu 0001, Lucie Muller, Anshul Paigwar, Alessandro Renzaglia, Wendelin Serwe
DATE3
2022 If a Human Can See It, So Should Your System: Reliability Requirements for Machine Vision Components
abstract
Machine Vision Components (MVC) are becoming safety-critical. Assuring their quality, including safety, is essential for their successful deployment. Assurance relies on the availability of precisely specified and, ideally, machine-verifiable requirements. MVCs with state-of-the-art performance rely on machine learning (ML) and training data, but largely lack such requirements.
Boyue Caroline Hu, Lina Marsso, Krzysztof Czarnecki 0001, Rick Salay, Huakun Shen, Marsha Chechik
ICSE2
2022 What to Check: Systematic Selection of Transformations for Analyzing Reliability of Machine Vision Components
abstract
Machine Vision Components (MVCs) are deployed in safety-critical systems, such as autonomous driving, and their reliability must be checked against scene changes, e.g., rain, that may lead to hazardous situations in the deployment environment. Many scene changes leading to hazardous situations may be hard to reproduce on demand, so existing approaches for MVC reliability analysis use synthetic image transformations to simulate such changes. Therefore, the question of how to select the image transformations to simulate specific hazardous situations is essential to MVC reliability analysis. Yet, this problem has not been addressed by the scientific community so far. In this paper, we propose a framework for mapping between hazardous situations and relevant image transformations using their descriptions. Our framework includes a systematic description mapping process DMaP, a method autoDMaP for automating this process, and coverage metrics measuring how well a list of transformations can simulate a list of hazardous situations. We show the applicability of our framework by mapping hazardous situations from an existing checklist, i.e., CV-HAZOP, to a list of synthetic image transformations from a state-of-the-art transformation library, i.e., Albumentation. As part of evaluation, we conducted an experiment and showed that, compared with the manual, ad-hoc mapping produced by image processing experts, DMaP and autoDMaP resulted in better precision and recall. Additionally, using our new coverage metrics, we found that image transformations considered by state-of-the-art libraries and reliability benchmarks are far from fully simulating the CV-HAZOP hazardous situations, and the MVCs that perform best on these benchmarks have significant reliability gaps against these situations.
Boyue Caroline Hu, Lina Marsso, Krzysztof Czarnecki 0001, Marsha Chechik
ISSRE2
2020 Automated Transition Coverage in Behavioural Conformance Testing
Lina Marsso, Radu Mateescu 0001, Wendelin Serwe
ICTSS1
2019 Asynchronous Testing of Synchronous Components in GALS Systems
Lina Marsso, Radu Mateescu 0001, Ioannis Parissis, Wendelin Serwe
IFM1
2018 TESTOR: A Modular Tool for On-the-Fly Conformance Test Case Generation
Lina Marsso, Radu Mateescu 0001, Wendelin Serwe
TACAS (2)1