EDBT 2026 Demo / reviewers in the wild / expert
Matteo Camilli
dblp:62/11141
· DBLP profile ↗
38ranked-venue papers
21as first author
28since 2021 · last 2026
0000-0003-2491-5267ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 33 · 18 first-author · 25 since 2021Systems, architecture and hardware · 4 · 2 first-author · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Theory of computation · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Layered Control Loop Architecture for Transparent Self-Adaptation
Martina Missana, Arianna Paone, Andrea Tarabotto, Francesco Renato Negri, Niccolò Nicolosi, Matteo Camilli, Raffaela Mirandola |
ICSA | 6 |
| 2026 | Proactive self-adaptation and assurance of explainable Human-Machine Teaming
Livia Lestingi, Marcello M. Bersani, Matteo Camilli, Raffaela Mirandola, Matteo G. Rossi, Patrizia Scandurra |
J. Syst. Softw. | 3 |
| 2026 | Efficient Self-Adaptation through Explanation-Driven White-Box OptimizationabstractSelf-adaptive systems increasingly rely on black-box predictive models, such as Neural Networks, for decision-making and adaptation planning. In this case, adaptation decisions and their potential impact on the surrounding environment are hard to explain. Further, the opaque nature of these models often involves expensive optimization techniques. The computational complexity is a consequence of the inability to directly observe or comprehend the internal mechanisms of the black-box predictive models. This requires iterative methods to explore a possibly large search space and optimize according to many objectives, creating a critical challenge in balancing effectiveness and cost. In this article, we propose explanation-driven self-adaptation, a novel approach that embeds model-agnostic interpretable machine learning techniques into the feedback loop. In particular, we present XDA-II, an extended version of XDA that integrates multiple explanation sources. This new version combines Partial Dependence Plots and Feature Importance to maintain interpretability while boosting efficiency. Beyond interpretability benefits, explanations become instrumental to guide adaptations through white-box optimization, which is more cost-effective than black-box optimization due to the transparency and predictable mathematical properties of the functions involved. Our empirical evaluation using six study subjects shows that XDA-II achieves more efficient convergence towards optimal adaptation solutions compared to four selected baseline methods including existing black-box methods—random search, NSGA-III, and FITEST—and white-box methods—the predecessor XDA. Francesco Renato Negri, Niccolò Nicolosi, Matteo Camilli, Raffaela Mirandola |
ACM Trans. Auton. Adapt. Syst. | 3 |
| 2025 | Counterfactual Self-adaptation in Cyber-Physical Systems
Ehsan Elahi 0003, Matteo Camilli, Raffaela Mirandola |
SEAA | 2 |
| 2025 | Parametric Falsification of Many Probabilistic Requirements Under FlakinessabstractFalsification is a popular simulation-based testing method for Cyber-Physical Systems to find inputs that violate a formal requirement. It employs optimization algorithms to minimize a robustness metric that defines the satisfaction of a given property over an execution trace. Despite falsification representing an established approach, detecting violations considering many, possibly independent, requirements simultaneously, under flaky simulations is an open problem. We address this problem by proposing a novel approach that combines parametric model checking and many-objective optimization. We use parametric model checking to shift part of the complexity of the problem offline. We pre-compute numeric constraints for the satisfaction of all requirements on a parametric specification of the testing scenario. Flaky violations are then detected using many-objective optimization to explore the space of changing factors in the scenario and push the parameters out of all precomputed constraints. The results of our empirical evaluation using four open-source evaluation subjects with increasing complexity (number of requirements) show that our approach can falsify many requirements simultaneously, without hiding their individual contribution. The effectiveness, in terms of quantity and severity of violations, is significantly higher than random search as well as two selected state-of-the-art baseline approaches. Furthermore, the extra offline computation yields a negligible cost. Matteo Camilli, Raffaela Mirandola |
ICSE | 1 |
| 2025 | Detecting Dependability Failures in Healthcare Scenarios via Digital ShadowsabstractIn healthcare systems, practitioners are responsible for making decisions when a patient’s health, or even life, are at stake. Real-time data-driven modeling, analysis, and prediction approaches, such as the Digital Shadow (DS) paradigm, inform and support decision-makers in such critical situations. We introduce GENGAR, a DS-based methodology to identify critical scenarios in a patient-device-physician (PDP) triad with human agents and cyber-physical devices interacting under uncertainty. The proposed solution relies on automata-based modeling and formal analysis techniques to predict and inform the practitioner of critical contingencies that may compromise patient safety, enhancing the system’s dependability. In particular, it leverages automata learning to infer and evolve a realistic patient model from clinical logs. GENGAR then exploits mutational and searchbased fuzzing to generate scenarios and detect failure cases, i.e., those violating predefined dependability requirements. Failure scenarios are then filtered using qualitative criteria on clinical plausibility, yielding up to $60 \%$ realistic cases. Bruno Guindani, Matteo Camilli, Livia Lestingi, Marcello M. Bersani |
ISSRE | 2 |
| 2025 | Reality Check on Formal Methods in Industry: A Study of Verum DezyneabstractABSTRACT Many of the classical questions reflecting the actionable use of formal methods in the software industry—“do they scale?” or “are they easily integrated?”—remain without a definitive answer, with many potentially adoptable formal notations being exploited in industry, but in a rather stove‐piped and siloed fashion, and with rather few, sometimes anecdotal, success stories to tell. In this article, we strive to provide some more answers to the aforementioned questions on formal methods adoption in industry. We focus our study on a widely adopted formal methods framework in Europe, that is, Verum Dezyne, employed by embedded‐computing and hardware‐programming companies including Thermo‐Fisher, Philips, and more. Results convey a rather interesting story—requiring further study into these matters—but also highlight practical insights for formal practitioners in the field, for example, that formal methods do not disrupt existing processes and scalability issues can be easily addressed by applying mainstream engineering practices, such as decomposition. Michele Chiari, Matteo Camilli, Marcello M. Bersani, Rutger van Beusekom, Damian A. Tamburri |
J. Softw. Evol. Process. | 2 |
| 2025 | Engineering MLOps Pipelines With Data Quality: A Case Study on Tabular Datasets in KaggleabstractABSTRACT Ensuring high‐quality data is crucial for the successful deployment of machine learning models, thereby sustaining the operational pipelines around such models. However, a significant number of practitioners do not currently use data quality checks or measurements as gateways for their model construction and operationalization, indicating a need for greater awareness and adoption of these tools. In this study, we propose an automated approach for automating the process of architecting machine learning pipelines by means of (semi‐)automated data quality checks. We focus on tabular data as a representative of the most widely used structured data formats in said pipelines. Our work is based on a subset of metrics that are particularly relevant in MLOps pipelines, stemming from our engagement with expert practitioners in machine learning operations (MLOps). We selected Deepchecks, a well‐known tool for conducting data quality checks, from a cohort of similar tools to evaluate the quality of datasets collected from Kaggle, a widely used platform for machine learning competitions and data science projects. We also analyze the main features used by Kaggle to rank their datasets and used these features to validate the relevance of our approach. Our approach shows the potential for automated data quality checks to improve the efficiency and effectiveness of MLOps pipelines and their operation, by decreasing the risk of introducing errors and biases into machine learning models in production. Matteo Pancini, Matteo Camilli, Giovanni Quattrocchi, Damian A. Tamburri |
J. Softw. Evol. Process. | 2 |
| 2025 | Many-objective Self-adaptation under Model UncertaintyabstractThe field of uncertainty quantification and mitigation in software-intensive and self-adaptive systems is garnering increased interest, especially with the rise of statistical inference methodologies like Bayesian reasoning. These methods typically address uncertain quality attributes embedded within system models by adjusting model parameters. However, the uncertainty related to selecting a specific system model over plausible alternatives has received limited attention. Our work focuses on self-adaptation, exploring methods to tackle uncertainty in model selection. This includes scenarios where one model is chosen over competing alternatives to encapsulate the system’s understanding and anticipate future observations. Our proposed solution augments the conventional feedback loop of self-adaptive systems by combining Bayesian model averaging to mitigate uncertainty and many-objective optimization to take into account multiple, possibly many, dependability requirements at the same time. We carry out an empirical evaluation to study the effectiveness, cost, and scalability of the proposed approach using two case studies with increasing structural complexity and number of dependability requirements. Results show that our approach based on model averaging is significantly better than model selection in terms of satisfied requirements after adaptation (adaptation success frequency). We also show that our approach can deal with large model spaces ( \(\sim 10^{19}\) ) using efficient sampling methods rather than exhaustive model space exploration. Matteo Camilli, Raffaela Mirandola, Patrizia Scandurra |
ACM Trans. Auton. Adapt. Syst. | 1 |
| 2025 | How Toxic Can You Get? Search-Based Toxicity Testing for Large Language ModelsabstractLanguage is a deep-rooted means of perpetration of stereotypes and discrimination. Large Language Models (LLMs), now a pervasive technology in our everyday lives, can cause extensive harm when prone to generating toxic responses. The standard way to address this issue is to align the LLM, which, however, dampens the issue without constituting a definitive solution. Therefore, testing LLM even after alignment efforts remains crucial for detecting any residual deviations with respect to ethical standards. We present EvoTox, an automated testing framework for LLMs’ inclination to toxicity, providing a way to quantitatively assess how much LLMs can be pushed towards toxic responses even in the presence of alignment. The framework adopts an iterative evolution strategy that exploits the interplay between two LLMs, the System Under Test (SUT) and the Prompt Generator steering SUT responses toward higher toxicity. The toxicity level is assessed by an automated oracle based on an existing toxicity classifier. We conduct a quantitative and qualitative empirical evaluation using five state-of-the-art LLMs as evaluation subjects having increasing complexity (7–671B parameters). Our quantitative evaluation assesses the cost-effectiveness of four alternative versions of EvoTox against existing baseline methods, based on random search, curated datasets of toxic prompts, and adversarial attacks. Our qualitative assessment engages human evaluators to rate the fluency of the generated prompts and the perceived toxicity of the responses collected during the testing sessions. Results indicate that the effectiveness, in terms of detected toxicity level, is significantly higher than the selected baseline methods (effect size up to 1.0 against random search and up to 0.99 against adversarial attacks). Furthermore, EvoTox yields a limited cost overhead (from 22% to 35% on average).This work includes examples of toxic degeneration by LLMs, which may be considered profane or offensive to some readers. Reader discretion is advised. Simone Corbo, Luca Bancale, Valeria De Gennaro, Livia Lestingi, Vincenzo Scotti 0001, Matteo Camilli |
IEEE Trans. Software Eng. | 6 |
| 2024 | Integrated QoS- and Vulnerability-Driven Self-adaptation for Microservices Applications
Matteo Camilli, Fabio Luccioletti, Raffaela Mirandola, Patrizia Scandurra |
ICSOC (2) | 1 |
| 2024 | A Conceptual Framework for Quality Assurance of LLM-based Socio-critical SystemsabstractRecent breakthroughs in Artificial Intelligence (AI) obfuscate the boundaries between digital, physical, and social spaces, a trend expected to continue in the foreseeable future. Traditionally, software engineering has prioritized technical aspects, focusing on functional correctness and reliability while often neglecting broader societal implications. With the rise of software agents enabled by Large Language Models (LLMs) and capable of emulating human intelligence and perception, there is a growing recognition of the need for addressing socio-critical issues. Unlike technical challenges, these issues cannot be resolved through traditional, deterministic approaches due to their subjective nature and dependence on evolving factors such as culture and demographics. This paper dives into this problem and advocates the need for revising existing engineering principles and methodologies. We propose a conceptual framework for quality assurance where AI is not only the driver of socio-critical systems but also a fundamental tool in their engineering process. Such framework encapsulates pre-production and runtime workflows where LLM-based agents, so-called artificial doppelgängers, continuously assess and refine socio-critical systems ensuring their alignment with established societal standards. Luciano Baresi, Matteo Camilli, Tommaso Dolci, Giovanni Quattrocchi |
ASE | 2 |
| 2023 | Impact of Architectural Smells on Software Performance: an Exploratory StudyabstractArchitectural smells have been studied in the literature looking at several aspects, such as their impact on maintainability as a source of architectural debt, their correlations with code smells, and their evolution in the history of complex projects. The goal of this paper is to extend the study of architectural smells from a different perspective. We focus our attention on software performance, and we aim to quantify the impact of architectural smells as support to explain the root causes of system performance hindrances. Our method consists of a study design matching the occurrence of architectural smells with performance metrics. We exploit state-of-the-art tools for architectural smell detection, software performance profiling, and testing the systems under analysis. The removal of architectural smells generates new versions of systems from which we derive some observations on design changes improving/worsening performance metrics. Our experimentation considers two complex open-source projects, and results show that the detection and removal of two common types of architectural smells yield lower response time (up to ) with a large effect size, i.e., for - of the hotspot methods. The median memory consumption is also lower (up to ) with a large effect size for all the services. Francesca Arcelli Fontana, Matteo Camilli, Davide Rendina, Andrei Gabriel Taraboi, Catia Trubiani |
EASE | 2 |
| 2023 | Architecting Explainable Service Robots
Marcello M. Bersani, Matteo Camilli, Livia Lestingi, Raffaela Mirandola, Matteo G. Rossi, Patrizia Scandurra |
ECSA | 2 |
| 2023 | Engineering Self-adaptive Microservice Applications: An Experience Report
Vincenzo Riccio, Giancarlo Sorrentino, Matteo Camilli, Raffaela Mirandola, Patrizia Scandurra |
ICSOC (1) | 3 |
| 2023 | Risk-driven Online Testing and Test Case Diversity Analysis for ML-enabled Critical SystemsabstractMachine Learning (ML)-enabled systems that run in safety-critical settings expose humans to risks. Hence, it is important to build such systems with strong assurances for domain-specific safety requirements. Simulation as well as metaheuristic optimizing search have proven to be valuable tools for online testing of ML-enabled systems for early detection of hazards. However, the efficient generation of effective test cases remains a challenging issue. In particular, the testing process shall produce as many failures as possible but also unveil diverse sets of failure scenarios.To study this phenomenon, we introduce a risk-driven test case generation and diversity analysis method tailored to ML-enabled systems. Our approach uses an online testing technique based on metaheuristic optimizing search to falsify domain-specific safety requirements. All test cases leading to hazards are then analyzed to assess their diversity by using clustering and interpretable ML. We evaluated our approach in a collaborative robotics case study showing that generating tests considering risk metrics represents an effective strategy. Furthermore, we compare alternative optimizing search algorithms and rank them based on the overall diversity of the test cases, ultimately showing that selecting the testing strategy based on the number of failures only may be misleading. Jubril Gbolahan Adigun, Tom Philip Huck, Matteo Camilli, Michael Felderer |
ISSRE | 3 |
| 2023 | Enforcing Resilience in Cyber-physical Systems via Equilibrium Verification at RuntimeabstractCyber-physical systems often operate in dynamic environments where unexpected events should be managed while guaranteeing acceptable behavior. Providing comprehensive evidence of their dependability under change represents a major open challenge. In this article, we exploit the notion of equilibrium, that is, the ability of the system to maintain an acceptable behavior within its multidimensional viability zone and propose RUNE 2 (RUNtime Equilibrium verification and Enforcement), an approach able to verify at runtime the equilibrium condition and to enforce the system to stay in its viability zone. RUNE 2 includes (i) a system specification that takes into account the uncertainties related to partial knowledge and possible changes; (ii) the computation of the equilibrium condition to define the boundaries of the viability zone; (iii) a runtime equilibrium verification method that leverages Bayesian inference to reason about the ability of the system to remain viable; and (iv) a resilience enforcement mechanism that exploits the posterior knowledge to steer the execution of the system inside the viability zone. We demonstrate both benefits and costs of the proposed approach by conducting an empirical evaluation using two case studies and 24 systems synthetically generated from pseudo-random models with increasing structural complexity. Matteo Camilli, Raffaela Mirandola, Patrizia Scandurra |
ACM Trans. Auton. Adapt. Syst. | 1 |
| 2023 | Actor-Driven Decomposition of Microservices through Multi-level Scalability AssessmentabstractThe microservices architectural style has gained widespread acceptance. However, designing applications according to this style is still challenging. Common difficulties concern finding clear boundaries that guide decomposition while ensuring performance and scalability. With the aim of providing software architects and engineers with a systematic methodology, we introduce a novel actor-driven decomposition strategy to complement the domain-driven design and overcome some of its limitations by reaching a finer modularization yet enforcing performance and scalability improvements. The methodology uses a multi-level scalability assessment framework that supports decision-making over iterative steps. At each iteration, architecture alternatives are quantitatively evaluated at multiple granularity levels. The assessment helps architects to understand the extent to which architecture alternatives increase or decrease performance and scalability. We applied the methodology to drive further decomposition of the core microservices of a real data-intensive smart mobility application and an existing open-source benchmark in the e-commerce domain. The results of an in-depth evaluation show that the approach can effectively support engineers in (i) decomposing monoliths or coarse-grained microservices into more scalable microservices and (ii) comparing among alternative architectures to guide decision-making for their deployment in modern infrastructures that orchestrate lightweight virtualized execution units. Matteo Camilli, Carmine Colarusso, Barbara Russo, Eugenio Zimeo |
ACM Trans. Softw. Eng. Methodol. | 1 |
| 2022 | Microservices Integrated Performance and Reliability TestingabstractContinuous quality assurance for extra-functional properties of modern software systems is today a big challenge as their complexity is constantly increasing to satisfy market demands. This is the case of microservice systems. They provide high control on the scale of operation by means of fine-grained service decomposition, but this demands careful consideration of the relations between performance of individual microservices and service failures. Matteo Camilli, Antonio Guerriero, Andrea Janes, Barbara Russo, Stefano Russo 0001 |
AST | 1 |
| 2022 | XSA: eXplainable Self-AdaptationabstractSelf-adaptive systems increasingly rely on machine learning techniques as black-box models to make decisions even when the target world of interest includes uncertainty and unknowns. Because of the lack of transparency, adaptation decisions, as well as their effect on the world, are hard to explain. This often hinders the ability to trace unsuccessful adaptations back to understandable root causes. In this paper, we introduce our vision of explainable self-adaptation. We demonstrate our vision by instantiating our ideas on a running example in the robotics domain and by showing an automated proof-of-concept process providing human-understandable explanations for successful and unsuccessful adaptations in critical scenarios. Matteo Camilli, Raffaela Mirandola, Patrizia Scandurra |
ASE | 1 |
| 2022 | WeakSATD: Detecting Weak Self-admitted Technical DebtabstractSpeeding up development may produce technical debt, i.e., not-quite-right code for which the effort to make it right increases with time as a sort of interest. Developers may be aware of the debt as they admit it in their code comments. Literature reports that such a self-admitted technical debt survives for a long time in a program, but it is not yet clear its impact on the quality of the code in the long term. We argue that self-admitted technical debt contains a number of different weaknesses that may affect the security of a program. Therefore, the longer a debt is not paid back the higher is the risk that the weaknesses can be exploited. To discuss our claim and rise the developers' awareness of the vulnerability of the self-admitted technical debt that is not paid back, we explore the self-admitted technical debt in the Chromium C-code to detect any known weaknesses. In this preliminary study, we first mine the Common Weakness Enumeration repository to define heuristics for the automatic detection and fix of weak code. Then, we parse the C-code to find self-admitted technical debt and the code block it refers to. Finally, we use the heuristics to find weak code snippets associated to self-admitted technical debt and recommend their potential mitigation to developers. Such knowledge can be used to prioritize self-admitted technical debt for repair. A prototype has been developed and applied to the Chromium code. Initial findings report that 55% of self-admitted technical debt code contains weak code of 14 different types. Barbara Russo, Matteo Camilli, Moritz Mock |
MSR | 2 |
| 2022 | Taming Model Uncertainty in Self-adaptive Systems Using Bayesian Model AveragingabstractResearch on uncertainty quantification and mitigation of software-intensive systems and (self-)adaptive systems, is increasingly gaining momentum, especially with the availability of statistical inference techniques (such as Bayesian reasoning) that make it possible to mitigate uncertain (quality) attributes of the system under scrutiny often encoded in the system model in terms of model parameters. However, to the best of our knowledge, the uncertainty about the choice of a specific system model did not receive the deserved attention. Matteo Camilli, Raffaela Mirandola, Patrizia Scandurra |
SEAMS | 1 |
| 2022 | Modeling Performance of Microservices Systems with Growth TheoryabstractCONTEXT: The microservices architectural style is gaining momentum in the IT industry. This style does not guarantee that a target system can continuously meet acceptable performance levels. The ability to study the violations of performance requirements and eventually predict them would help practitioners to tune techniques like dynamic load balancing or horizontal scaling to achieve the resilience property. OBJECTIVE: The goal of this work is to study the violations of performance requirements of microservices through time series analysis and provide practical instruments that can detect resilient and non-resilient microservices and possibly predict their performance behavior. METHOD: to model the occurrences of violations of performance requirements as a stochastic process. We applied our method to an in-vitro e-commerce benchmark and an in-production real-world telecommunication system. We interpreted the resulting growth models to characterize the microservices in terms of their transient performance behavior. RESULTS: Our empirical evaluation shows that, in most of the cases, the non-linear S-shaped growth models capture the occurrences of performance violations of resilient microservices with high accuracy. The bounded nature associated with this models tell that the performance degradation is limited and thus the microservice is able to come back to an acceptable performance level even under changes in the nominal number of concurrent users. We also detect cases where linear models represent a better description. These microservices are not resilient and exhibit constant growth and unbounded performance violations over time. The application of our methodology to a real in-production system identified additional resilience profiles that were not observed in the in-vitro experiments. These profiles show the ability of services to react differently to the same solicitation. We found that when a service is resilient it can either decrease the rate of the violations occurrences in a continuous manner or with repeated attempts (periodical or not). CONCLUSIONS: We showed that growth theory can be successfully applied to study the occurences of performance violations of in-vitro and in-production real-world systems. Furthermore, the cost of our model calibration heuristics, based on the mathematical expression of the selected non-linear growth models, is limited. We discussed how the resulting models can shed some light on the trend of performance violations and help engineers to spot problematic microservice operations that exhibit performance issues. Thus, meaningful insights from the application of growth theory have been derived to characterize the behavior of (non) resilient microservices operations. Matteo Camilli, Barbara Russo |
Empir. Softw. Eng. | 1 |
| 2022 | Scalability testing automation using multivariate characterization and detection of software performance antipatterns
Alberto Avritzer, Ricardo Britto 0001, Catia Trubiani, Matteo Camilli, Andrea Janes, Barbara Russo, André van Hoorn, Robert Heinrich, Martina Rapp, Jörg Henß, Ram Kishan Chalawadi |
J. Syst. Softw. | 4 |
| 2022 | Automated test-based learning and verification of performance models for microservices systemsabstractEffective and automated verification techniques able to provide assurances of performance and scalability are highly demanded in the context of microservices systems. In this paper, we introduce a methodology that applies specification-driven load testing to learn the behavior of the target microservices system under multiple deployment configurations. Testing is driven by realistic workload conditions sampled in production. The sampling produces a formal description of the users’ behavior through a Discrete Time Markov Chain. This model drives multiple load testing sessions that query the system under test and feed a Bayesian inference process which incrementally refines the initial model to obtain a complete specification from run-time evidence as a Continuous Time Markov Chain. The complete specification is then used to conduct automated verification by using probabilistic model checking and to compute a configuration score that evaluates alternative deployment options. This paper introduces the methodology, its theoretical foundation, and the toolchain we developed to automate it. Our empirical evaluation shows its applicability, benefits, and costs on a representative microservices system benchmark. We show that the methodology detects performance issues, traces them back to system-level requirements, and, thanks to the configuration score, provides engineers with insights on deployment options. The comparison between our approach and a selected state-of-the-art baseline shows that we are able to reduce the cost up to 73% in terms of number of tests. The verification stage requires negligible execution time and memory consumption. We observed that the verification of 360 system-level requirements took ∼1 minute by consuming at most 34 KB. The computation of the score involved the verification of ∼7k (automatically generated) properties verified in ∼72 seconds using at most ∼50 KB. Matteo Camilli, Andrea Janes, Barbara Russo |
J. Syst. Softw. | 1 |
| 2021 | Uncertainty-aware Exploration in Model-based TestingabstractModern software systems operate in complex and changing environments and are exposed to multiple sources of uncertainty. Testing methods shall be tailored to uncertainty as a first-class concern in order to quantify it and deliver increased confidence in the level of assurance of the final product. In this paper, we introduce novel model-based exploration strategies that generate test cases targeting uncertain components of the system under test. Our testing framework leverages Markov Decision Processes as modeling formalism of choice. The tester explicitly specifies uncertainty by means of beliefs attached to transition probabilities. The structural properties of the model and the uncertainty specification are then exploited to drive the test case generation process. Bayesian inference is used to achieve this objective by updating the initial beliefs through the evidence collected by testing. The proposed uncertainty-aware test selection strategies have been systematically evaluated on three realistic benchmarks and nine synthetic systems exhibiting up to 10k model transitions. We demonstrate the effectiveness of the novel strategies with well-established metrics. Results show they outperform existing testing methods with a gain up to 2.65× in terms of accuracy of the inference process. Matteo Camilli, Angelo Gargantini, Patrizia Scandurra, Catia Trubiani |
ICST | 1 |
| 2021 | Risk-Driven Compliance Assurance for Collaborative AI Systems: A Vision Paper
Matteo Camilli, Michael Felderer, Andrea Giusti 0004, Dominik T. Matt, Anna Perini, Barbara Russo, Angelo Susi |
REFSQ | 1 |
| 2021 | A Multivariate Characterization and Detection of Software Performance AntipatternsabstractContext. Software Performance Antipatterns (SPAs) research has focused on algorithms for the characterization, detection, and solution of antipatterns. However, existing algorithms are based on the analysis of runtime behavior to detect trends on several monitored variables (e.g., response time, CPU utilization, and number of threads) using pre-defined thresholds. Objective. In this paper, we introduce a new approach for SPA characterization and detection designed to support continuous integration/delivery/deployment (CI/CDD) pipelines, with the goal of addressing the lack of computationally efficient algorithms. Alberto Avritzer, Ricardo Britto 0001, Catia Trubiani, Barbara Russo, Andrea Janes, Matteo Camilli, André van Hoorn, Robert Heinrich, Martina Rapp, Jörg Henß |
ICPE | 6 |
| 2020 | Model-Based Testing Under Parametric Variability of Uncertain Beliefs
Matteo Camilli, Barbara Russo |
SEFM | 1 |
| 2020 | Model-based hypothesis testing of uncertain software systemsabstractSummary Nowadays, there exists an increasing demand for reliable software systems able to fulfill their requirements in different operational environments and to cope with uncertainty that can be introduced both at design‐time and at runtime because of the lack of control over third‐party system components and complex interactions among software, hardware infrastructures and physical phenomena. This article addresses the problem of the discrepancy between measured data at runtime and the design‐time formal specification by using aninverse uncertainty quantificationapproach. Namely, we introduce a methodology calledMETRICand its supporting toolchain to quantify and mitigate software system uncertainty during testing by combining (on‐the‐fly)model‐based testingandBayesian inference. Our approach connects probabilistic input/output conformance theory with statistical hypothesis testing in order to assess if the behaviour of the system under test corresponds to its probabilistic formal specification provided in terms of aMarkov decision process. An uncertainty‐aware model‐based test case generation strategy is used as a means to collect evidence from software components affected by sources of uncertainty. Test results serve as input to a Bayesian inference process that updates beliefs on model parameters encoding uncertain quality attributes of the system under test. This article describes our approach from both theoretical and practical perspectives. An extensive empirical evaluation activity has been conducted in order to assess the cost‐effectiveness of our approach. We show that, under same effort constraints, our uncertainty‐aware testing strategy increases the accuracy of the uncertainty quantification process up to 50 times with respect to traditional model‐based testing methods. Matteo Camilli, Angelo Gargantini, Patrizia Scandurra |
Softw. Test. Verification Reliab. | 1 |
| 2019 | PNemu: An Extensible Modeling Library for Adaptable Distributed Systems
Matteo Camilli, Lorenzo Capra, Carlo Bellettini |
Petri Nets | 1 |
| 2019 | HYPpOTesT: Hypothesis Testing Toolkit for Uncertain Service-Based Web Applications
Matteo Camilli, Angelo Gargantini, Rosario Madaudo, Patrizia Scandurra |
IFM | 1 |
| 2018 | Online Model-Based Testing under UncertaintyabstractModern software systems are required to operate in a highly uncertain and changing environment. They have to control the satisfaction of their requirements at run-time, and possibly adapt and cope with situations that have not been completely addressed at design-time. Software engineering methods and techniques are, more than ever, forced to deal with change and uncertainty (lack of knowledge) explicitly. For tackling the challenge posed by uncertainty in delivering more reliable systems, this paper proposes a novel online Model-based Testing technique that complements classic test case generation based on pseudo-random sampling strategies with an uncertainty-aware sampling strategy. To deal with system uncertainty during testing, the proposed strategy builds on an Inverse Uncertainty Quantification approach that is related to the discrepancy between the measured data at run-time (while the system executes) and a Markov Decision Process model describing the behavior of the system under test. To this purpose, a conformance game approach is adopted in which tests feed a Bayesian inference calibrator that continuously learns from test data to tune the system model and the system itself. A comparative evaluation between the proposed uncertainty-aware sampling policy and classical pseudo-random sampling policies is also presented using the Tele Assistance System running example, showing the differences in achieved accuracy and efficiency. Matteo Camilli, Carlo Bellettini, Angelo Gargantini, Patrizia Scandurra |
ISSRE | 1 |
| 2018 | Zone-based formal specification and timing analysis of real-time self-adaptive systems
Matteo Camilli, Angelo Gargantini, Patrizia Scandurra |
Sci. Comput. Program. | 1 |
| 2017 | Towards Inverse Uncertainty Quantification in Software Development (Short Paper)
Matteo Camilli, Angelo Gargantini, Patrizia Scandurra, Carlo Bellettini |
SEFM | 1 |
| 2016 | Distributed CTL model checking using MapReduce: theory and practiceabstractSummary The recent extensive availability of ‘cloud’ computing platforms is very appealing for the formal verification community. In fact, these platforms represent a great opportunity to run massively parallel jobs and analyze ‘big data’ problems, although classical formal verification tools and techniques must undergo a deep technological transformation to take advantage of the available powerful architectures. A distributed approach to verification of computation tree logic formulas on very large state spaces is described. The approach exploits and integrates our parametric state–space builder, designed to ease the adoption of ‘big data’ platforms. The whole framework adopts aMAPREDUCEapproach as the core computational model and can be tailored to different modeling formalisms. This paper includes proofs of correctness, a short theoretical discussion about complexity, and reports a practical experience with some benchmarking Petri net models. The outcomes of several tests are presented, thus showing the convenience of the proposed approach. Copyright © 2015 John Wiley & Sons, Ltd. Carlo Bellettini, Matteo Camilli, Lorenzo Capra, Mattia Monga |
Concurr. Comput. Pract. Exp. | 2 |
| 2015 | Specifying and verifying real-time self-adaptive systemsabstractSelf-adaptive systems autonomously adapt their behavior at run-time to react to internal dynamics and to uncertain and changing environment conditions. Specification and verification of self-adaptive systems are generally very difficult to carry out due to their high complexity, especially when involving time constraints. In the last case, in fact, the correctness of systems depends also on the time associated with events. This paper introduces a formal approach to specify and verify the self-adaptive behavior of real-time systems. Our specification formalism is based on Time-Basic Petri nets, a particular timed extension of Petri nets. We propose adaptation models to realize self-adaptation with temporal constraints and we adopt a zone-based modeling approach to support separation of concerns during the modeling phase. Zones identified during the modeling phase can be then used as modules (TB Petri subnets) either in isolation, to verify intra-zone properties, or all together, to verify inter-zone properties over the entire system model and check that all the temporal deadlines are met. We illustrate our approach by modeling and verifying a time-critical Gas Burner system that exhibits a self-healing behavior. Matteo Camilli, Angelo Gargantini, Patrizia Scandurra |
ISSRE | 1 |
| 2012 | Petri nets state space analysis in the cloudabstractSeveral techniques for addressing the state space explosion problem in model checking have been studied. One of these is to use distributed memory and computation for storing and exploring the state space of the model of a system. In this report, we present and compare different multi-thread, distributed, and cloud approaches to face the state-space explosion problem. The experiments report shows the convenience (in particular) of cloud approaches. Matteo Camilli |
ICSE | 1 |