EDBT 2026 Demo / reviewers in the wild / expert
Arda Goknil
dblp:44/4521 · also Arda Göknil
· DBLP profile ↗
42ranked-venue papers
6as first author
16since 2021 · last 2026
0000-0002-2170-2066ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 31 · 5 first-author · 9 since 2021Artificial intelligence and machine learning · 6 · 6 since 2021Computer networks · 3 · 3 since 2021Systems, architecture and hardware · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1Theory of computation · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | LUMEN: Enhancing IoT System Observability with Multi-Agent Large Language Models and Knowledge GraphsabstractThe rapid expansion of Internet of Things (IoT) systems has transformed industries through real-time monitoring and automation, generating vast and heterogeneous data streams. As IoT networks expand, the increasing volume and diversity of data, spanning real-time telemetry, device logs, and historical records, complicate the management of IoT systems, including system monitoring, analysis, and reasoning. To address this challenge, we introduce LUMEN (Large Language Models as Unified Multi-Agent Systems for IoT ENhancement), a novel approach combining multi-agent Large Language Models (LLMs), knowledge graphs, and heterogeneous databases to enable cognitive digital twins for IoT observability. LUMEN models IoT systems as knowledge graphs, capturing device relationships and metadata while monitoring data is stored in time-series or object databases. Specialized LLM-based agents collaborate dynamically to analyze IoT systems and explain the findings in natural language, generating and executing analysis code when necessary. Integrated with off-the-shelf network monitoring tools, LUMEN facilitates semantic reasoning and human-in-the-loop collaboration, delivering adaptive insights across diverse data contexts. Two industrial case studies demonstrate the ability of LUMEN to automate analysis workflows, enhance system adaptability, and provide interpretable analytics. This work advances IoT observability by integrating LLMs, semantic intelligence, and explainable analytics into a scalable and adaptive solution using a multi-agent architecture for complex IoT systems. Adela-Aniela Nedisan, Arda Goknil, Dumitru Roman, Ahmet Soylu |
ACM Trans. Internet Things | 3 |
| 2026 | Unsupervised Learning and Process Analysis for Sensor Data Validation in the IIoTabstractIntegrating Artificial Intelligence (AI) with the Industrial Internet of Things (IIoT) has transformed industrial processes, enhancing productivity, quality control, and operational efficiency. However, ensuring the precision and reliability of sensor-generated data remains a critical challenge due to the evolving nature of industrial processes and the limitations of conventional validation methods. Traditional rule-based and supervised learning approaches struggle to adapt to process shifts, drifts, and novel anomalies, making sensor data validation an ongoing issue. This article introduces UDAVA (Unsupervised Learning Approach using Process Mining for Sensor Data Validation in IIoT), a novel AI-driven pipeline designed to automate the identification of reference patterns in sensor data and validate subsequent production cycles by recognizing deviations from expected behaviors. UDAVA employs a multi-stage process that includes preprocessing sensor data, clustering recurring patterns, and assessing deviations. It supports semi-supervised learning by integrating manual labels where available, improving interpretability and accuracy. One of UDAVA’s key strengths lies in its ability to extract features from sensor data rather than relying on raw time series similarity, making it robust against noise and diverse process variations. Additionally, UDAVA integrates process mining techniques—process discovery and conformance checking—to enhance its ability to detect even subtle anomalies and deviations in industrial workflows. We conduct a comprehensive evaluation of UDAVA using three industrial datasets, demonstrating its effectiveness in identifying high-level process behaviors, detecting process shifts and drifts, and ensuring data validation across multiple production cycles. The results highlight UDAVA ’s adaptability across different industrial processes, making it a valuable tool for optimizing operations and ensuring sensor data reliability in IIoT environments. Erik Johannes Husom, Arda Goknil, Felix Mannhardt, Simeon Tverdal, Sagar Sen, Phu Hong Nguyen |
ACM Trans. Internet Techn. | 2 |
| 2025 | Developing Multi-Agent LLM Applications Through Continuous Human-LLM Co-ProgrammingabstractThe rapid advancement of Large Language Models (LLMs) has opened new possibilities for intelligent multi-agent systems capable of autonomously performing complex tasks. To build such systems, LLMs can be leveraged for task-solving, tool interaction, and code generation but at the same time their costs and unpredictability have to be properly managed. To do so this paper introduces COPMA, a model-based approach to enabling continuous human-LLM co-programming of multi-agent LLM applications. COPMA uses feature-block models to track application features and their implementations as agents and code blocks. Supported by co-programming patterns, de-velopers are guided in constructing, refining, and refactoring feature implementations via trial-and-errors with LLM agents, leveraging their feedback, suggestions, and code examples. The patterns guide the shift of feature implementations between agents and code to balance flexibility, predictability, and cost. Our experience in developing LLM agents for collecting and reviewing medical research papers demonstrates that human-LLM co-programming can reduce development effort to enable rapid prototyping of multi-agent LLM applications. Arda Goknil, Xiaojun Jiang, Espen Melum, Hyunwhan Joe, Caterina Gazzotti, Valerio Frascolla, Adela-Aniela Nedisan, Phu Nguyen |
CAIN | 2 |
| 2025 | Combining Insights from Multiple Tools to Manage Technical Debt in Industrial C# ProjectsabstractTechnical Debt (TD) is a critical challenge in software development, leading to increased maintenance costs and reduced software quality over time. While considerable research has focused on identifying and managing TD in Java projects, studies on. NET (C#) projects remain limited. Additionally, existing approaches often rely on a single tool for TD detection, overlooking the benefits of combining multiple tools. In this paper, we analyze the effectiveness of Arcan, CodeScene, Designite, and DV8 on four industrial C#. NET 8 software products to address these research gaps. To validate and enrich our findings, we conducted online seminars and interviews with developers, architects, and managers involved in these projects, gathering practitioner insights on TD relevance and tool effectiveness. By leveraging complementary tools and practitioner feedback, we uncover different types of TD, including code-level, design, architectural, and knowledge debt. Our findings highlight each tool's strengths and limitations and demonstrate how integrating their outputs with expert input provides a more comprehensive and actionable TD assessment. Based on these insights, we propose a conceptual model for prioritizing and managing TD, offering guidance for practitioners. Simeon Tverdal, Phu Hong Nguyen, Arda Goknil, Antonio Martini 0001, Merve Astekin, Mili Orucevic, Maren Maritsdatter Kruke, Håvard Stranden |
ICSME | 3 |
| 2025 | Detecting Technical Debt in Source Code Changes Using Large Language Models
Merve Astekin, Arda Goknil, Sagar Sen, Simeon Tverdal, Phu Hong Nguyen |
PROFES | 2 |
| 2025 | Positioning LLM-Enabled Agents as Legal Compliance Aides for Data Pipelines
Adela-Aniela Nedisan, Nikolay Nikolov, Carl-Henrik Lien, Arda Goknil, Sagar Sen, Ahmet Soylu, Dumitru Roman |
RuleML+RR | 4 |
| 2025 | Sustainable LLM Inference for Edge AI: Evaluating Quantized LLMs for Energy Efficiency, Output Accuracy, and Inference LatencyabstractDeploying Large Language Models (LLMs) on edge devices presents significant challenges due to computational constraints, memory limitations, inference speed, and energy consumption. Model quantization has emerged as a key technique to enable efficient LLM inference by reducing model size and computational overhead. In this study, we conduct a comprehensive analysis of 28 quantized LLMs from the Ollama library, which applies by default Post-Training Quantization (PTQ) and weight-only quantization techniques, deployed on an edge device (Raspberry Pi 4 with 4 GB RAM). We evaluate energy efficiency, inference performance, and output accuracy across multiple quantization levels and task types. Models are benchmarked on five standardized datasets (CommonsenseQA, BIG-Bench Hard, TruthfulQA, GSM8K, and HumanEval), and we employ a high-resolution, hardware-based energy measurement tool to capture real-world power consumption. Our findings reveal the trade-offs between energy efficiency, inference speed, and accuracy in different quantization settings, highlighting configurations that optimize LLM deployment for resource-constrained environments. By integrating hardware-level energy profiling with LLM benchmarking, this study provides actionable insights for sustainable AI, bridging a critical gap in existing research on energy-aware LLM deployment. Erik Johannes Husom, Arda Goknil, Merve Astekin, Lwin Khin Shar, Andre KãJPYsen, Sagar Sen, Benedikt Andreas Mithassel, Ahmet Soylu |
ACM Trans. Internet Things | 2 |
| 2024 | Engineering Carbon Emission-aware Machine Learning PipelinesabstractThe proliferation of machine learning (ML) has brought unprecedented advancements in technology, but it has also raised concerns about its environmental impact, particularly concerning carbon emissions. To address the imperative of environmentally responsible ML, we present in this paper a novel ML pipeline, named CEMAI, designed to monitor and analyze carbon emissions across the entire lifecycle of ML model development, from data preparation to training and deployment. Our endeavor involves an exhaustive evaluation process underpinned by three industrial case studies. These case studies are structured around the application of ML models to predict tool wear, estimate remaining useful lifetimes, and detect anomalies in the Industrial Internet of Things (IIoT). Leveraging sensor data originating from CNC machining and broaching operations, our research shows empirically the efficacy of carbon emissions as a dependable metric guiding the configuration of an ML development process. The essence of our approach lies in striking a balance between superior performance and minimal carbon emissions. Our findings reveal the potential to optimize pipeline configurations for ML models in a manner that not only enhances performance but also drastically reduces carbon emissions, thereby underlining the significance of adopting ecologically responsible engineering practices. Erik Johannes Husom, Sagar Sen, Arda Goknil |
CAIN | 3 |
| 2024 | Adaptable Runtime Monitoring for Intermittent SystemsabstractBatteryless energy harvesting devices compute intermittently due to power failures that frequently interrupt the computational activity and lead to charging delays. To ensure functional correctness in intermittent computing, applications must exhibit several unique properties, such as guarantees for computational progress despite power failures and prevention of stale operations caused by charging delays. We observe that current software support for intermittent computing allows for checking only a fixed set of properties and leads to tightly coupled application and property-checking, thus hampering modularity, scalability, and maintainability. Eren Yildiz, Khakim Akhunov, Lorenzo Antonio Riva, Arda Goknil, Ivan Kurtev, Kasim Sinan Yildirim |
EuroSys | 4 |
| 2024 | An AI pipeline for garment price projection using computer visionabstractAbstract The fashion industry’s traditional price-setting methods, based on historical sales and Fashion Week trends, are inadequate in the digital era. Rapid changes in collections and consumer preferences necessitate advanced Artificial Intelligence (AI) techniques. These AI methods should analyze data from various sources, including social media and e-commerce, to predict future fashion trends and prices. In this paper, we propose, apply, and assess a data analytics approach, i.e., FashionXpert, employing several image processing and machine learning techniques in an AI pipeline for garment price prediction. It integrates various heterogeneous data sources (e.g., textual and image data from e-stores, brand websites, and social media) to obtain more consistent, accurate, and beneficial information. We evaluated its effectiveness with an industrial data set obtained by a fashion search tool from the electronic commerce sites of clothing brands. FashionXpert predicted garment prices with an average Mean Absolute Error (MAE) of 15.31 EUR on a data set that has a standard deviation of 72.99 EUR. Rodrigo Rico Gómez, Joe Lorentz, Thomas Hartmann 0001, Arda Goknil, Inder Pal Singh, Tayfun Gökmen Halaç, Gülnaz Boruzanli Ekinci |
Neural Comput. Appl. | 4 |
| 2023 | Replay-Driven Continual Learning for the Industrial Internet of ThingsabstractThe Industrial Internet of Things (IIoT) leverages thousands of interconnected sensors and computing devices to monitor and control large and complex industrial processes. Machine learning (ML) applications in IIoT use data acquired from multiple sensors to perform tasks such as predictive maintenance. While remembering useful learning from the past, these applications need to adapt learning for evolving sensor data stemming from changes in industrial processes and environmental conditions. This paper presents a continual learning pipeline to learn from the evolving data while replaying selected parts of the old data. The pipeline is configured to produce ML experiences (e.g., training a baseline neural network model), improve the baseline model with the new data while replaying part of the old data, and infer/predict using a specific model version given a stream of IIoT sensor data. We have evaluated our approach from an AI Engineering perspective using three industrial case studies, i.e., predicting tool wear, remaining useful lifetime, and anomalies from sensor data acquired from CNC machining and broaching operations. Our results show that configuring experiences for replay-driven continual learning allows dynamic maintenance of ML performance on evolving data while minimizing the excessive accumulation of legacy sensor data. Sagar Sen, Simon Myklebust Nielsen, Erik Johannes Husom, Arda Goknil, Simeon Tverdal, Leonardo Sastoque Pinilla |
CAIN | 4 |
| 2023 | AutoConf: Automated Configuration of Unsupervised Learning Systems Using Metamorphic Testing and Bayesian OptimizationabstractUnsupervised learning systems using clustering have gained significant attention for numerous applications due to their unique ability to discover patterns and structures in large unlabeled datasets. However, their effectiveness highly depends on their configuration, which requires domain-specific expertise and often involves numerous manual trials. Specifically, selecting appropriate algorithms and hyperparameters adds to the complexity of the configuration process. In this paper, we propose, apply, and assess an automated approach (AutoConf) for configuring unsupervised learning systems using clustering, leveraging metamorphic testing and Bayesian optimization. Metamorphic testing is utilized to verify the configurations of unsupervised learning systems by applying a series of input transformations. We use Bayesian optimization guided by metamorphic-testing output to automatically identify the optimal configuration. The approach aims to streamline the configuration process and enhance the effectiveness of unsupervised learning systems. It has been evaluated through experiments on six datasets from three domains for anomaly detection. The evaluation results show that our approach can find configurations outperforming the baseline approaches as they achieved a recall of 0.89 and a precision of 0.84 (on average). Lwin Khin Shar, Arda Goknil, Erik Johannes Husom, Sagar Sen, Yan Naing Tun, Kisub Kim |
ASE | 2 |
| 2023 | ETAP: Energy-aware Timing Analysis of Intermittent ProgramsabstractEnergy harvesting battery-free embedded devices rely only on ambient energy harvesting that enables stand-alone and sustainable IoT applications. These devices execute programs when the harvested ambient energy in their energy reservoir is sufficient to operate and stop execution abruptly (and start charging) otherwise. These intermittent programs have varying timing behavior under different energy conditions, hardware configurations, and program structures. This article presents Energy-aware Timing Analysis of intermittent Programs (ETAP), a probabilistic symbolic execution approach that analyzes the timing and energy behavior of intermittent programs at compile time. ETAP symbolically executes the given program while taking time and energy cost models for ambient energy and dynamic energy consumption into account. We evaluate ETAP by comparing the compile-time analysis results of our benchmark codes and real-world application with the results of their executions on real hardware. Our evaluation shows that ETAP’s prediction error rate is between 0.0076% and 10.8%, and it speeds up the timing analysis by at least two orders of magnitude compared to manual testing. Ferhat Erata, Eren Yildiz, Arda Goknil, Kasim Sinan Yildirim, Jakub Szefer, Ruzica Piskac, Gökçin Sezgin |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2023 | Metamorphic Testing for Web System SecurityabstractSecurity testing aims at verifying that the software meets its security properties. In modern Web systems, however, this often entails the verification of the outputs generated when exercising the system with a very large set of inputs. Full automation is thus required to lower costs and increase the effectiveness of security testing. Unfortunately, to achieve such automation, in addition to strategies for automatically deriving test inputs, we need to address the oracle problem, which refers to the challenge, given an input for a system, of distinguishing correct from incorrect behavior (e.g., the response to be received after a specific HTTP GET request). In this paper, we propose Metamorphic Security Testing for Web-interactions (MST-wi), a metamorphic testing approach that integrates test input generation strategies inspired by mutational fuzzing and alleviates the oracle problem in security testing. It enables engineers to specify metamorphic relations (MRs) that capture many security properties of Web systems. To facilitate the specification of such MRs, we provide a domain-specific language accompanied by an Eclipse editor.MST-wiautomatically collects the input data and transforms the MRs into executable Java code to automatically perform security testing. It automatically tests Web systems to detect vulnerabilities based on the relations and collected data. We provide a catalog of 76 system-agnostic MRs to automate security testing in Web systems. It covers 39% of the OWASP security testing activities not automated by state-of-the-art techniques; further, our MRs can automatically discover 102 different types of vulnerabilities, which correspond to 45% of the vulnerabilities due to violations of security design principles according to the MITRE CWE database. We also define guidelines that enable test engineers to improve the testability of the system under test with respect to our approach. We evaluatedMST-wieffectiveness and scalability with two well-known Web systems (i.e., Jenkins and Joomla). It automatically detected 85% of their vulnerabilities and showed a high specificity (99.81% of the generated inputs do not lead to a false positive); our findings include a new security vulnerability detected in Jenkins. Finally, our results demonstrate that the approach scale, thus enabling automated security testing overnight. Nazanin Bayati Chaleshtari, Fabrizio Pastore, Arda Goknil, Lionel C. Briand |
IEEE Trans. Software Eng. | 3 |
| 2022 | UDAVA: an unsupervised learning pipeline for sensor data validation in manufacturingabstractManufacturing has enabled the mechanized mass production of the same (or similar) products by replacing craftsmen with assembly lines of machines. The quality of each product in an assembly line greatly hinges on continual observation and error compensation during machining using sensors that measure quantities such as position and torque of a cutting tool and vibrations due to possible imperfections in the cutting tool and raw material. Patterns observed in sensor data from a (near-)optimal production cycle should ideally recur in subsequent production cycles with minimal deviation. Manually labeling and comparing such patterns is an insurmountable task due to the massive amount of streaming data that can be generated from a production process. We present UDAVA, an unsupervised machine learning pipeline that automatically discovers process behavior patterns in sensor data for a reference production cycle. UDAVA performs clustering of reduced dimensionality summary statistics of raw sensor data to enable high-speed clustering of dense time-series data. It deploys the model as a service to verify batch data from subsequent production cycles to detect recurring behavior patterns and quantify deviation from the reference behavior. We have evaluated UDAVA from an AI Engineering perspective using two industrial case studies. Erik Johannes Husom, Simeon Tverdal, Arda Goknil, Sagar Sen |
CAIN | 3 |
| 2022 | Automatic Generation of Acceptance Test Cases From Use Case Specifications: An NLP-Based ApproachabstractAcceptance testing is a validation activity performed to ensure the conformance of software systems with respect to their functional requirements. In safety critical systems, it plays a crucial role since it is enforced by software standards, which mandate that each requirement be validated by such testing in a clearly traceable manner. Test engineers need to identify all the representative test execution scenarios from requirements, determine the runtime conditions that trigger these scenarios, and finally provide the input data that satisfy these conditions. Given that requirements specifications are typically large and often provided in natural language (e.g., use case specifications), the generation of acceptance test cases tends to be expensive and error-prone. In this paper, we present Use Case Modeling for System-level, Acceptance Tests Generation (UMTG), an approach that supports the generation of executable, system-level, acceptance test cases from requirements specifications in natural language, with the goal of reducing the manual effort required to generate test cases and ensuring requirements coverage. More specifically, UMTG automates the generation of acceptance test cases based on use case specifications and a domain model for the system under test, which are commonly produced in many development environments. Unlike existing approaches, it does not impose strong restrictions on the expressiveness of use case specifications. We rely on recent advances in natural language processing to automatically identify test scenarios and to generate formal constraints that capture conditions triggering the execution of the scenarios, thus enabling the generation of test data. In two industrial case studies, UMTG automatically and correctly translated 95 percent of the use case specification steps into formal constraints required for test data generation; furthermore, it generated test cases that exercise not only all the test scenarios manually implemented by experts, but also some critical scenarios not previously considered. Fabrizio Pastore, Arda Goknil, Lionel C. Briand |
IEEE Trans. Software Eng. | 3 |
| 2020 | Taskify: An Integrated Development Environment to Develop and Debug Intermittent Software for the Batteryless Internet of ThingsabstractBatteryless embedded devices rely only on ambient energy harvesting that enables stand-alone and sustainable applications for the Internet of Things. These devices perform computation, sensing, and communication when the harvested ambient energy in their energy reservoir is sufficient; they die abruptly when the energy drains out completely. This kind of operation, the so-called intermittent execution, dictates a task-based programming model for the development and implementation of intermittent applications. However, today's task-based intermittent programs are tightly-coupled to the underlying run-time environments. This makes their debugging and testing difficult before deploying them into the target platform. To remedy this, we present Taskify, a tool that enables engineers to write and debug task-based intermittent programs in TaskDSL, i.e., a domain-specific language we designed for the development of intermittent programs on any general-purpose computer. Taskify automatically transforms these programs into C programs that can be linked to the underlying run-time environment and deployed into the target platform. Taskify is implemented as an Eclipse plugin. It has been evaluated on three intermittent applications. Murat Mülayim, Arda Goknil, Kasim Sinan Yildirim |
DCOSS | 2 |
| 2020 | Metamorphic Security Testing for Web SystemsabstractSecurity testing verifies that the data and the resources of software systems are protected from attackers. Unfortunately, it suffers from the oracle problem, which refers to the challenge, given an input for a system, of distinguishing correct from incorrect behavior. In many situations where potential vulnerabilities are tested, a test oracle may not exist, or it might be impractical due to the many inputs for which specific oracles have to be defined. In this paper, we propose a metamorphic testing approach that alleviates the oracle problem in security testing. It enables engineers to specify metamorphic relations (MRs) that capture security properties of the system. Such MRs are then used to automate testing and detect vulnerabilities. We provide a catalog of 22 system-agnostic MRs to automate security testing in Web systems. Our approach targets 39% of the OWASP security testing activities not automated by state-of-the-art techniques. It automatically detected 10 out of 12 vulnerabilities affecting two widely used systems, one commercial and the other open source (Jenkins). Phu X. Mai, Fabrizio Pastore, Arda Goknil, Lionel C. Briand |
ICST | 3 |
| 2020 | Automating system test case classification and prioritization for use case-driven testing in product lines
Ines Hajri, Arda Goknil, Fabrizio Pastore, Lionel C. Briand |
Empir. Softw. Eng. | 2 |
| 2018 | A Natural Language Programming Approach for Requirements-Based Security TestingabstractTo facilitate communication among stakeholders, software security requirements are typically written in natural language and capture both positive requirements (i.e., what the system is supposed to do to ensure security) and negative requirements (i.e., undesirable behavior undermining security). In this paper, we tackle the problem of automatically generating executable security test cases from security requirements in natural language (NL). More precisely, since existing approaches for the generation of test cases from NL requirements verify only positive requirements, we focus on the problem of generating test cases from negative requirements. We propose, apply and assess Misuse Case Programming (MCP), an approach that automatically generates security test cases from misuse case specifications (i.e., use case specifications capturing the behavior of malicious users). MCP relies on natural language processing techniques to extract the concepts (e.g., inputs and activities) appearing in requirements specifications and generates executable test cases by matching the extracted concepts to the members of a provided test driver API. MCP has been evaluated in an industrial case study, which provides initial evidence of the feasibility and benefits of the approach. Phu X. Mai, Fabrizio Pastore, Arda Goknil, Lionel C. Briand |
ISSRE | 3 |
| 2018 | AlloyInEcore: embedding of first-order relational logic into meta-object facility for automated model reasoningabstractWe present AlloyInEcore, a tool for specifying metamodels with their static semantics to facilitate automated, formal reasoning on models. Software development projects require that software systems be specified in various models (e.g., requirements models, architecture models, test models, and source code). It is crucial to reason about those models to ensure the correct and complete system specifications. AlloyInEcore~allows the user to specify metamodels with their static semantics, while, using the semantics, it automatically detects inconsistent models, and completes partial models. It has been evaluated on three industrial case studies in the automotive domain (https://modelwriter.github.io/AlloyInEcore/). Ferhat Erata, Arda Goknil, Ivan Kurtev, Bedir Tekinerdogan |
ESEC/SIGSOFT FSE | 2 |
| 2018 | Modeling Security and Privacy Requirements: a Use Case-Driven ApproachabstractContext: Modern internet-based services, ranging from food-delivery to home-caring, leverage the availability of multiple programmable devices to provide handy services tailored to end-user needs. These services are delivered through an ecosystem of device-specific software components and interfaces (e.g., mobile and wearable device applications). Since they often handle private information (e.g., location and health status), their security and privacy requirements are of crucial importance. Defining and analyzing those requirements is a significant challenge due to the multiple types of software components and devices integrated into software ecosystems. Each software component presents peculiarities that often depend on the context and the devices the component interact with, and that must be considered when dealing with security and privacy requirements. Objective: In this paper, we propose, apply, and assess a modeling method that supports the specification of security and privacy requirements in a structured and analyzable form. Our motivation is that, in many contexts, use cases are common practice for the elicitation of functional requirements and should also be adapted for describing security requirements. Method: We integrate an existing approach for modeling security and privacy requirements in terms of security threats, their mitigations, and their relations to use cases in a misuse case diagram. We introduce new security-related templates, i.e., a mitigation template and a misuse case template for specifying mitigation schemes and misuse case specifications in a structured and analyzable manner. Natural language processing can then be used to automatically report inconsistencies among artifacts and between the templates and specifications. Results: We successfully applied our approach to an industrial healthcare project and report lessons learned and results from structured interviews with engineers. Conclusion: Since our approach supports the precise specification and analysis of security threats, threat scenarios and their mitigations, it also supports decision making and the analysis of compliance to standards. Phu X. Mai, Arda Goknil, Lwin Khin Shar, Fabrizio Pastore, Lionel C. Briand, Shaban Shaame |
Inf. Softw. Technol. | 2 |
| 2018 | Change impact analysis for evolving configuration decisions in product line use case modelsabstractProduct Line Engineering is becoming a key practice in many software development environments where complex systems are developed for multiple customers with varying needs. In many business contexts, use cases are the main artifacts for communicating requirements among stakeholders. In such contexts, Product Line (PL) use cases capture variable and common requirements while use case-driven configuration generates Product Specific (PS) use cases for each new customer in a product family. In this paper, we propose, apply, and assess a change impact analysis approach for evolving configuration decisions in PL use case models. Our approach includes: (1) automated support to identify the impact of decision changes on prior and subsequent decisions in PL use case diagrams and (2) automated incremental regeneration of PS use case models from PL use case models and evolving configuration decisions. Our tool support is integrated with IBM Doors. Our approach has been evaluated in an industrial case study, which provides evidence that it is practical and beneficial to analyze the impact of decision changes and to incrementally regenerate PS use case models in industrial settings. Ines Hajri, Arda Goknil, Lionel C. Briand, Thierry Stephany |
J. Syst. Softw. | 2 |
| 2018 | Configuring use case models in product families
Ines Hajri, Arda Goknil, Lionel C. Briand, Thierry Stephany |
Softw. Syst. Model. | 2 |
| 2017 | Incremental Reconfiguration of Product Specific Use Case Models for Evolving Configuration Decisions
Ines Hajri, Arda Goknil, Lionel C. Briand, Thierry Stephany |
REFSQ | 2 |
| 2017 | A tool for automated reasoning about traces based on configurable formal semanticsabstractWe present Tarski, a tool for specifying configurable trace semantics to facilitate automated reasoning about traces. Software development projects require that various types of traces be modeled between and within development artifacts. For any given artifact (e.g., requirements, architecture models and source code), Tarski allows the user to specify new trace types and their configurable semantics, while, using the semantics, it automatically infers new traces based on existing traces provided by the user, and checks the consistency of traces. It has been evaluated on three industrial case studies in the automotive domain (https://modelwriter.github.io/Tarski/). Ferhat Erata, Arda Goknil, Bedir Tekinerdogan, Geylani Kardas |
ESEC/SIGSOFT FSE | 2 |
| 2016 | PUMConf: a tool to configure product specific use case and domain models in a product lineabstractWe present PUMConf, a tool for supporting configuration that currently focuses on requirements and enables effective product line management in the context of use case-driven development. By design, it relies exclusively on variability modeling for artifacts that are commonly used in such contexts (i.e., use case diagram, specifications and domain model). For given Product Line (PL) use case and domain models, PUMConf checks the consistency of the models, interactively receives configuration decisions from analysts, automatically checks decision consistency, and generates Product Specific (PS) use case and domain models from the PL models and decisions. It has been evaluated on an industrial case study in the automotive domain. Ines Hajri, Arda Goknil, Lionel C. Briand, Thierry Stephany |
SIGSOFT FSE | 2 |
| 2015 | Automatic generation of system test cases from use case specificationsabstractIn safety critical domains, system test cases are often derived from functional requirements in natural language (NL) and traceability between requirements and their corresponding test cases is usually mandatory. The definition of test cases is therefore time-consuming and error prone, especially so given the quickly rising complexity of embedded systems in many critical domains. Though considerable research has been devoted to automatic generation of system test cases from NL requirements, most of the proposed approaches re- quire significant manual intervention or additional, complex behavioral modelling. This significantly hinders their applicability in practice. In this paper, we propose Use Case Modelling for System Tests Generation (UMTG), an approach that automatically generates executable system test cases from use case spec- ifications and a domain model, the latter including a class diagram and constraints. Our rationale and motivation are that, in many environments, including that of our industry partner in the reported case study, both use case specifica- tions and domain modelling are common and accepted prac- tice, whereas behavioural modelling is considered a difficult and expensive exercise if it is to be complete and precise. In order to extract behavioral information from use cases and enable test automation, UMTG employs Natural Language Processing (NLP), a restricted form of use case specifica- tions, and constraint solving. Fabrizio Pastore, Arda Goknil, Lionel C. Briand, Muhammad Zohaib Z. Iqbal |
ISSTA | 3 |
| 2015 | Applying product line Use case modeling in an industrial automotive embedded system: Lessons learned and a refined approachabstractIn this paper, we propose, apply, and assess Product line Use case modeling Method (PUM), an approach that supports modeling variability at different levels of granularity in use cases and domain models. Our motivation is that, in many software development environments, use case modeling drives interactions among stakeholders and, therefore, use cases and domain models are common practice for requirements elicitation and analysis. In PUM, we integrate and adapt existing product line extensions for use cases and introduce some template extensions for use case specifications. Variability is captured in use case diagrams while it is reflected at a greater level of detail in use case specifications. Variability in domain concepts is captured in domain models. PUM is supported by a tool relying on Natural Language Processing (NLP). We applied PUM to an industrial automotive embedded system and report lessons learned and results from structured interviews with experienced engineers. Ines Hajri, Arda Goknil, Lionel C. Briand, Thierry Stephany |
MoDELS | 2 |
| 2015 | Change impact analysis for Natural Language requirements: An NLP approachabstractRequirements are subject to frequent changes as a way to ensure that they reflect the current best understanding of a system, and to respond to factors such as new and evolving needs. Changing one requirement in a requirements specification may warrant further changes to the specification, so that the overall correctness and consistency of the specification can be maintained. A manual analysis of how a change to one requirement impacts other requirements is time-consuming and presents a challenge for large requirements specifications. We propose an approach based on Natural Language Processing (NLP) for analyzing the impact of change in Natural Language (NL) requirements. Our focus on NL requirements is motivated by the prevalent use of these requirements, particularly in industry. Our approach automatically detects and takes into account the phrasal structure of requirements statements. We argue about the importance of capturing the conditions under which change should propagate to enable more accurate change impact analysis. We propose a quantitative measure for calculating how likely a requirements statement is to be impacted by a change under given conditions. We conduct an evaluation of our approach by applying it to 14 change scenarios from two industrial case studies. Chetan Arora 0002, Mehrdad Sabetzadeh, Arda Goknil, Lionel C. Briand, Frank Zimmer |
RE | 3 |
| 2015 | NARCIA: an automated tool for change impact analysis in natural language requirementsabstractWe present NARCIA, a tool for analyzing the impact of change in natural language requirements. For a given change in a requirements document, NARCIA calculates quantitative scores suggesting how likely each requirements statement in the document is to be impacted. These scores, computed using Natural Language Processing (NLP), are used for sorting the requirements statements, enabling the user to focus on statements that are most likely to be impacted. To increase the accuracy of change impact analysis, NARCIA provides a mechanism for making explicit the rationale behind changes. NARCIA has been empirically evaluated on two industrial case studies. The results of this evaluation are briefly highlighted. Chetan Arora 0002, Mehrdad Sabetzadeh, Arda Goknil, Lionel C. Briand, Frank Zimmer |
ESEC/SIGSOFT FSE | 3 |
| 2015 | UMTG: a toolset to automatically generate system test cases from use case specificationsabstractWe present UMTG, a toolset for automatically generating executable and traceable system test cases from use case specifications. UMTG employs Natural Language Processing (NLP), a restricted form of use case specifications, and constraint solving. Use cases are expected to follow a template with restriction rules that reduce imprecision and enable NLP. NLP is used to capture the control flow implicitly described in use case specifications. Finally, to generate test input, constraint solving is applied to OCL constraints referring to the domain model of the system. UMTG is integrated with two tools that are widely adopted in industry, IBM Doors and Rhapsody. UMTG has been successfully evaluated on an industrial case study. Fabrizio Pastore, Arda Goknil, Lionel C. Briand, Muhammad Zohaib Z. Iqbal |
ESEC/SIGSOFT FSE | 3 |
| 2014 | Change impact analysis for requirements: A metamodeling approach
Arda Goknil, Ivan Kurtev, Klaas van den Berg, Wietze Spijkerman |
Inf. Softw. Technol. | 1 |
| 2014 | Generation and validation of traces between requirements and architecture based on formal trace semantics
Arda Goknil, Ivan Kurtev, Klaas van den Berg |
J. Syst. Softw. | 1 |
| 2013 | Analysis Support for TADL2 Timing Constraints on EAST-ADL Models
Arda Goknil, Jagadish Suryadevara, Marie-Agnès Peraldi-Frati, Frédéric Mallet |
ECSA | 1 |
| 2013 | A metamodeling approach for reasoning on multiple requirements modelsabstractThe complex software development projects of today may require developers to use multiple requirements engineering approaches. Different teams may have to use different requirements modeling formalisms to express requirements related to their assigned parts of a given project. This situation poses difficulties in achieving interoperability and integration of requirements models for the purpose of reasoning on the overall system requirements. It is challenging to compose distributed models expressed in different notations and to reason on the composed models. In this paper we present a metamodeling approach which allows reasoning about requirements and their relations on the whole/composed models expressed in different requirements modeling approaches. In a previous work we expressed the structure of requirements documents as a requirements metamodel in which the most important elements are requirements relations and their types. The semantics of these elements is given in First Order Logic (FOL) and allows two activities: inferring new relations from the initial set of relations and checking consistency of relations. In this work we use the requirements metamodel as a core metamodel to be specialized for different requirements modeling approaches and notations such as Product-line and SysML. Mainly, the requirements relations in the metamodel are specialized to support relations in different requirements modeling approaches. The specialization allows using the same semantics and reasoning mechanism of the core metamodel for multiple requirements modeling approaches. To illustrate the approach we use an example from automotive domain expressed with two modeling approaches: product-line requirements models and SysML for system requirements. Arda Goknil, Ivan Kurtev, Jean-Vivien Millo |
EDOC | 1 |
| 2013 | Tool Support for the Analysis of TADL2 Timing Constraints Using TimeSquareabstractModeling and analysis of non-functional properties are central concerns in distributed real-time embedded systems. In automotive domain, EAST-ADL is one of the main architectural modeling approaches for real-time embedded systems. In our previous work we introduced the Timing Augmented Description Language V2 (TADL2), which is the new release of the time model for EAST-ADL. It provides new modeling capabilities such as explicit notion of timebase and symbolic timing expressions. In this paper we propose an approach to simulate and analyze TADL2 timing constraints. The formal semantics of TADL2 is given by an exogenous model transformation in QVTo to the Clock Constraint Specification Language (CCSL), a formal language that implements the MARTE Time Model. With this transformation, the analysis of TADL2 constraints become possible through TimeSquare framework dedicated to the analysis of CCSL specifications. The approach is illustrated on the Brake-By-Wire example. Arda Goknil, Julien Deantoni, Marie-Agnès Peraldi-Frati, Frédéric Mallet |
ICECCS | 1 |
| 2012 | A Timing Model for Specifying Multi Clock Automotive Systems: The Timing Augmented Description Language V2
Marie-Agnès Peraldi-Frati, Arda Goknil, Julien Deantoni, Johan Nordlander |
ICECCS | 2 |
| 2012 | Modeling a BSG-E Automotive System with the Timing Augmented Description Language
Marie-Agnès Peraldi-Frati, Arda Goknil, Morayo Adedjouma, Pierre Yves Gueguen |
ISoLA (2) | 2 |
| 2011 | Semantics of trace relations in requirements models for consistency checking and inferencingabstractRequirements traceability is the ability to relate requirements back to stakeholders and forward to corresponding design artifacts, code, and test cases. Although considerable research has been devoted to relating requirements in both forward and backward directions, less attention has been paid to relating requirements with other requirements. Relations between requirements influence a number of activities during software development such as consistency checking and change management. In most approaches and tools, there is a lack of precise definition of requirements relations. In this respect, deficient results may be produced. In this paper, we aim at formal definitions of the relation types in order to enable reasoning about requirements relations. We give a requirements metamodel with commonly used relation types. The semantics of the relations is provided with a formalization in first-order logic. We use the formalization for consistency checking of relations and for inferring new relations. A tool has been built to support both reasoning activities. We illustrate our approach in an example which shows that the formal semantics of relation types enables new relations to be inferred and contradicting relations in requirements documents to be determined. The application of requirements reasoning based on formal semantics resolves many of the deficiencies observed in other approaches. Our tool supports better understanding of dependencies between requirements. Arda Goknil, Ivan Kurtev, Klaas van den Berg, Jan-Willem Veldhuis |
Softw. Syst. Model. | 1 |
| 2009 | Model Driven Development of Semantic Web Enabled Multi-Agent SystemsabstractSemantic Web evolution brought a new vision into agent research. The interpretation of this second generation web will be realized by autonomous computational entities, called agents, to handle the semantic content on behalf of their human users. Surely, Semantic Web environment has specific architectural entities and a different semantic which must be considered to model a Multi-agent System (MAS) within this environment. Hence, in this study, we introduce a MAS development process which supports the Semantic Web environment. Our approach is based on Model Driven Development (MDD) which aims to change the focus of software development from code to models. We first define an architecture for Semantic Web enabled MASs and then provide a MAS metamodel which consists of the first class meta-entities derived from this architecture. We also define a model transformation process for MDD of such MASs. We present a complete transformation process in which the source and the target metamodels, entity mappings between models and the implementation of the transformation for two different real MAS frameworks by using a well-known model transformation language are all included. In addition to the model-to-model transformation, the implementation of the model-to-code transformation is given as the last step of the system development process. The evaluation of the proposed development process by considering its use within the scope of a real commercial software project is also discussed. Geylani Kardas, Arda Goknil, Oguz Dikenelli, N. Yasemin Topaloglu |
Int. J. Cooperative Inf. Syst. | 2 |
| 2007 | Survey of Traceability Approaches in Model-Driven EngineeringabstractModels have been used in various engineering fields to help managing complexity and represent information in different abstraction levels, according to specific notations and stakeholder's viewpoints. Model-Driven Engineering (MDE) gives the basic principles for the use of models as primary artefacts throughout the software development phases and presents characteristics that simplify the engineering of software in various domains, such as Enterprise Computing Systems. Hence, for its successful application, MDE processes must consider traceability practices. They help the understanding, capturing, tracking and verification of software artefacts and their relationships and dependencies with other artefacts during the software life-cycle. In this survey, we discuss the state-of-the-art in traceability approaches in MDE and assess them with respect to five general comparison criteria: representation, mapping, scalability, change impact analysis and tool support. As a complementary result, we have identified some open issues that can be better explored by traceability in MDE. Ismênia Galvão, Arda Goknil |
EDOC | 2 |