Alan Wassyng

dblp:92/3822 · DBLP profile ↗
← Back
32ranked-venue papers
4as first author
9since 2021 · last 2026
0000-0003-4614-3421ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 19 · 3 first-author · 3 since 2021Security and privacy · 8 · 5 since 2021Theory of computation · 3 · 2 first-authorArtificial intelligence and machine learning · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2026 Chaining Unsafe Control Actions in STPA
Nicholas Petrunti, Spencer Deevy, Vera Pantelic, Mark Lawford, Richard F. Paige, Alan Wassyng
SAFECOMP6
2025 Principled Safety Assurance Arguments
Nicholas Annable, Mark Lawford, Richard F. Paige, Alan Wassyng
SAFECOMP4
2024 Simulation-based Analysis of a Novel Loop-based Road Topology for Autonomous Vehicles
abstract
The challenges in implementing SAE Level 4/5 automated vehicles are manifold, with intersection navigation being a pervasive one. We analyze a novel road topology invented by a co-author of this paper, Xiayong Hu. The topology eliminates the need for traditional traffic control and cross-traffic at intersections, potentially improving the safety of autonomous driving systems. The topology, herein called the Zonal Road Topology, consists of unidirectional loops of road with traffic flowing either clockwise or counter-clockwise. Adjacent loops are directionally aligned with one another, allowing vehicles to transfer from one loop to another through a simple lane change. To evaluate the Zonal Road Topology, a one km2pilot-track near Changshu, China is currently being set aside for testing. In parallel, traffic simulations are being performed. To this end, we conduct a simulation-based comparison between the Zonal Road Topology and a traditional road topology for a generic Electric Vehicle (EV) using the Simulation for Urban MObility (SUMO) platform and MATLAB/Simulink. We analyze the topologies in terms of their travel efficiency, safety, energy usage, and capacity. Drive time, number of halts, progress rate, and other metrics are analyzed across varied traffic levels to investigate the advantages and disadvantages of the Zonal Road Topology. Our results indicate that vehicles on the Zonal Road Topology have a lower, more consistent drive time, make more progress, and halt less frequently, while using less energy on average. The Zonal Road Topology also has the capacity to support a greater amount of vehicles. These results become more prominent at higher traffic densities.
Stefan Ramdhan, Winnie Trandinh, Sathurshan Arulmohan, Xiayong Hu, Spencer Deevy, Victor Bandur, Vera Pantelic, Mark Lawford, Alan Wassyng
IV9
2024 Comprehensive Change Impact Analysis Applied to Advanced Automotive Systems
Nicholas Annable, Mehrnoosh Askarpour, Thomas Chiang, Sahar Kokaly, Mark Lawford, Richard F. Paige, S. Ramesh 0002, Alan Wassyng
SAFECOMP8
2023 Redesigning Medical Device Assurance: Separating Technological and Clinical Assurance Cases
Spencer Deevy, Tiago de Moraes Machado, Amen Modhafar, Wesley O'Beirne, Richard F. Paige, Alan Wassyng
SAFECOMP6
2023 Repository mining for changes in Simulink and Stateflow models
Monika Jaskolka, Vera Pantelic, Alan Wassyng, Richard F. Paige, Mark Lawford
Softw. Syst. Model.3
2022 Generating Assurance Cases Using Workflow+ Models
Nicholas Annable, Thomas Chiang, Mark Lawford, Richard F. Paige, Alan Wassyng
SAFECOMP5
2021 Repository Mining for Changes in Simulink Models
abstract
Model-Based Development (MBD) is widely used for embedded controls development, with MATLAB/Simulink being one of the most used environments in the automotive industry. Simulink models are the primary design artifact and as with all software, must be constantly maintained and evolved over their lifetime. It is necessary to develop models that support likely changes in order to assist with evolution/maintenance processes. In order to do so, the types of frequently performed changes must be understood and appropriate language mechanisms must be available to support these changes. However, Simulink model changes are currently not well understood. We analyze a real industrial software repository of our industrial partner and its version control system to provide insights into the likely changes for Simulink. The intent with this analysis includes providing guidance on how Simulink is used in industrial practice and how particular model changes can impact system evolution.
Monika Jaskolka, Vera Pantelic, Alan Wassyng, Mark Lawford, Richard F. Paige
MoDELS3
2021 A formal approach to rigorous development of critical systems
abstract
Abstract Safety critical systems, such as medical, automotive, and avionics systems, play an important role in our daily lives. Increasing demand for new technologies in these safety critical systems requires rapid adoption of commercial hardware and software. However, the adoption of new hardware and software increases life‐threatening vulnerabilities. To aid in the reduction of these vulnerabilities and system failures, this paper proposes a framework based on formal methods for developing safety‐critical systems from requirements analysis to code generation. This framework includes a development process for documenting system requirements using tabular expressions, automatic formal model generation from the documented requirements, verification and validation of the generated formal models using proof techniques and animations, interactive simulation for validating the required behavior of the developed models by enabling domain experts to observe the system states according to, and finally, code generation from the formal model into a desired language. A prototype toolchain is developed to automate this framework. An assessment of the proposed framework is undertaken through a case study: insulin infusion pump (IIP).
Neeraj Kumar Singh 0001, Mark Lawford, T. S. E. Maibaum, Alan Wassyng
J. Softw. Evol. Process.4
2020 Systematic Evaluation of (Safety) Assurance Cases
Thomas Chowdhury, Alan Wassyng, Richard F. Paige, Mark Lawford
SAFECOMP2
2020 Change impact analysis in Simulink designs of embedded systems
abstract
This paper presents and evaluates the Boundary Diagram Tool for change impact analysis of large Simulink designs of embedded systems. In our previous work, we developed the Reach/Coreach Tool for model slicing within a single Simulink model. The current work extends the Reach/Coreach Tool to trace the impact of model changes through multiple models comprising an embedded system, including network interfaces. The change impact analysis results are represented using various diagrams motivated by industrial needs. Several techniques are used to improve understanding of impact analyses of large industrial systems. The tool has been integrated into the software development process of a large automotive OEM (Original Equipment Manufacturer) to support the following activities: change request analysis and evaluation, implementation, verification and integration. The tool also aids impact analyses required for compliance with functional safety standards. The tool’s effectiveness has been demonstrated on production-scale models.
Bennett Mackenzie, Vera Pantelic, Gordon Marks, Stephen Wynn-Williams, Gehan M. K. Selim, Mark Lawford, Alan Wassyng, Moustapha Diab, Feisel Weslati
ESEC/SIGSOFT FSE7
2019 Criteria to Systematically Evaluate (Safety) Assurance Cases
abstract
An assurance case (AC) captures explicit reasoning associated with assuring critical properties, such as safety. A vital attribute of an AC is that it facilitates the identification of fallacies in the validity of any claim. There is considerable published research related to confidence in ACs, which primarily relate to a measure of soundness of reasoning. Evaluation of an AC is more general than measuring confidence and considers multiple aspects of the quality of an AC. Evaluation criteria thus play a significant role in making the evaluation process more systematic. This paper contributes to the identification of effective evaluation criteria for ACs, the rationale for their use, and initial tests of the criteria on existing ACs. We classify these criteria as to whether they apply to the structure of the AC, or to the content of the AC. This paper focuses on safety as the critical property to be assured, but only a very small number of the criteria are specific to safety, and can serve as placeholders for evaluation criteria specific to other critical properties. All of the other evaluation criteria are generic. This separation is useful when evaluating ACs developed using different notations, and when evaluating ACs against safety standards. We explore the rationale for these criteria as well as the way they are used by the developers of the AC and also when they are used by a third-party evaluator.
Thomas Chowdhury, Alan Wassyng, Richard F. Paige, Mark Lawford
ISSRE2
2019 Something is Rotten in the State of Documenting Simulink Models
abstract
In this paper we draw on our experience in the automotive industry to portray the clear need for proper documentation of Simulink models when they describe the implementations of embedded systems. We effectively discredit the “model is documentation” motto that has been hounding the model-based paradigm of software development. The state of the art of documentation of Simulink designs of embedded systems, both in academia and industrial practice, is reviewed. We posit that lack of proper documentation is costing industry dearly, and propose that a significant change in development culture is needed to properly position documentation within the software development process. Further, we discuss what is required to foster such a culture.
Vera Pantelic, Alexander Schaap, Alan Wassyng, Victor Bandur, Mark Lawford
MODELSWARD3
2018 Assurance via model transformations and their hierarchical refinement
abstract
Assurance is a demonstration that a complex system (such as a car or a communication network) possesses an importantproperty, such as safety or security, with a high level of confidence. In contrast to currently dominant approaches to building assurance cases, which are focused on goal structuring and/or logical inference, we propose considering assurance as a model transformation (MT) enterprise: saying that a system possesses an assured property amounts to saying that a particular assurance view of the system comprising the assurance data, satisfies acceptance criteria posed as assurance constraints. While the MT realizing this view is very complex, we show that it can be decomposed into elementary MTs via a hierarchy of refinement steps. The transformations at the bottom level are ordinary MTs that can be executed for data specifying the system, thus providing the assurance data to be checked against the assurance constraints. In this way, assurance amounts to traversing the hierarchy from the top to the bottom and assuring the correctness of each MT in the path. Our approach has a precise mathematical foundation (rooted in process algebra and category theory) --- a necessity if we are to model precisely and then analyze our assurance cases. We discuss the practical applicability of the approach, and argue that it has several advantages over existing approaches.
Zinovy Diskin, T. S. E. Maibaum, Alan Wassyng, Stephen Wynn-Williams, Mark Lawford
MoDELS3
2018 Safe and Secure Automotive Over-the-Air Updates
Thomas Chowdhury, Eric Lesiuta, Kerianne Rikley, Chung-Wei Lin, Eunsuk Kang, BaekGyu Kim, Shinichi Shiraishi, Mark Lawford, Alan Wassyng
SAFECOMP9
2018 Translation of IEC 61131-3 Function Block Diagrams to PVS for Formal Verification with Real-Time Nuclear Application
Josh Newell, Linna Pang, David Tremaine, Alan Wassyng, Mark Lawford
J. Autom. Reason.4
2018 Software engineering practices and Simulink: bridging the gap
Vera Pantelic, Steven M. Postma, Mark Lawford, Monika Jaskolka, Bennett Mackenzie, Alexandre Korobkine, Marc Bender, Jeff Ong, Gordon Marks, Alan Wassyng
Int. J. Softw. Tools Technol. Transf.10
2017 Use of Tabular Expressions for Refinement Automation
Neeraj Kumar Singh 0001, Mark Lawford, T. S. E. Maibaum, Alan Wassyng
MEDI4
2016 Using STPA in an ISO 26262 Compliant Process
Archana Mallya, Vera Pantelic, Morayo Adedjouma, Mark Lawford, Alan Wassyng
SAFECOMP5
2015 Formal verification of function blocks applied to IEC 61131-3
Linna Pang, Chen-Wei Wang, Mark Lawford, Alan Wassyng
Sci. Comput. Program.4
2014 Combining Static and Dynamic Impact Analysis for Large-Scale Enterprise Systems
Alan Wassyng, T. S. E. Maibaum
PROFES2
2014 Envisioning a Requirements Specification Template for Medical Device Software
Hao Wang 0003, Yihai Chen, Ridha Khédri, Alan Wassyng
PROFES4
2012 Who Are We, and What Are We Doing Here?
Alan Wassyng
FM1
2012 Microcontroller Assembly Synthesis from Timed Automaton Task Specifications
Victor Bandur, Wolfram Kahl, Alan Wassyng
FMICS3
2011 Software certification experience in the canadian nuclear industry: lessons for the future
abstract
The computer controlled shutdown systems for the Nuclear Power Generating Station at Darlington, Canada, have been subject to licensing scrutinization on a number of occasions. After the first licence was approved in 1990, the licensee, Ontario Hydro, was given a number of years by the regulator to redesign the shutdown systems so that they would be more maintainable. This paper briefly describes the original certification process, lessons learned, and the subsequent development and certification of the shutdown systems. The development, internal certification processes and the regulator's certification process are briefly described. Although twenty years has elapsed since this work started, and there are new analysis techniques and tools that could be applied today, the original process itself has withstood the test of time extraordinarily well. This paper describes principles that explain why it was so successful, and how we can develop more modern approaches from this experience.
Alan Wassyng, Mark Lawford, T. S. E. Maibaum
EMSOFT1
2010 Certification of Software-Driven Medical Devices
Mark Lawford, T. S. E. Maibaum, Alan Wassyng
ISoLA (2)3
2009 Describing and Analyzing Behaviours over Tabular Specifications Using (Dyn)Alloy
Nazareno Aguirre, Marcelo F. Frias, Mariano M. Moscato, T. S. E. Maibaum, Alan Wassyng
FASE5
2008 Formal Verification of the Implementability of Timing Requirements
Xiayong Hu, Mark Lawford, Alan Wassyng
FMICS3
2006 Software tools for safety-critical software development
Alan Wassyng, Mark Lawford
Int. J. Softw. Tools Technol. Transf.1
2005 Timing Tolerances in Safety-Critical Software
Alan Wassyng, Mark Lawford, Xiayong Hu
FM1
2005 To do or not to do: If the requirements engineering payoff is so good, why aren't more companies doing it?
abstract
One thing that keeps many software-development organizations from doing serious requirements engineering before beginning development is the perception that doing requirements engineering wastes time and delays getting on to the real work, designing and programming. The first third of this paper presents anecdotal and case study evidence that upfront RE pays off big. The second third is a discussion on structural and cultural barriers to industrial adoption of RE practices. The final third is a free-wheeling discussion on these and related issues
Daniel M. Berry, Daniela E. Damian, Anthony Finkelstein, Donald C. Gause, Alan Wassyng
RE6
2005 Tabular Expressions and Their Relational Semantics
Ryszard Janicki, Alan Wassyng
Fundam. Informaticae2