EDBT 2026 Demo / reviewers in the wild / expert
Christian Berger 0001
dblp:98/4996-1
· DBLP profile ↗
54ranked-venue papers
5as first author
22since 2021 · last 2026
0000-0002-4828-1150ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 40 · 3 first-author · 14 since 2021Applied, interdisciplinary, general and emerging computing · 12 · 2 first-author · 8 since 2021Artificial intelligence and machine learning · 9 · 1 first-author · 6 since 2021Systems, architecture and hardware · 4 · 1 since 2021Security and privacy · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Recommendations for efficient and responsible LLM adoption within industrial software developmentabstractContext: Large language models (LLMs) are observed to have a significant positive impact on various software engineering (SE) activities. With improved accessibility, the adoption of powerful LLMs in industry has surged recently. However, there is a lack of actionable best practices for the efficient and responsible adoption of LLMs within industrial software settings. Objectives: We developed seven actionable recommendations to address this research gap. Methods: We conducted a multi-case study with three organisations that use LLMs within their SE activities and synthesised seven recommendations through qualitative thematic analysis. We conducted a complementary online survey with software practitioners from various industries to evaluate the perceived relevance of our recommendations. Results: Our results and recommendations focus on (i) users’ preference to use LLMs as AI assistants, (ii) the importance of relevant stakeholders’ satisfaction in the LLM-output evaluation, (iii) scoping the applicability of LLMs within SE tasks, (iv) the effect of LLMs on SE workflows, (v) the necessity and directions for developing human oversight mechanisms, and (vi) the necessary skills for practitioners for leveraging LLMs within SE. The online survey indicates a high level of agreement from the participants regarding the perceived relevance of the recommendations. Conclusion: We outline future research directions, including mapping the seven recommendations to the principles of the EU AI Act (AIA) in order to examine how they relate to the current regulatory compliance frameworks. Krishna Ronanki, Beatriz Cabrero-Daniel, Tomas Herda, Stefan Sitkovich, Jennifer Horkoff, Christian Berger 0001 |
Inf. Softw. Technol. | 6 |
| 2025 | On Simulation-Guided LLM-based Code Generation for Safe Autonomous Driving SoftwareabstractAutomated Driving System (ADS) is a safety-critical software system responsible for the interpretation of the vehicle’s environment and making decisions accordingly. The unbounded complexity of the driving context, including unforeseeable events, necessitate continuous improvement, often achieved through iterative DevOps processes. However, DevOps processes are themselves complex, making these improvements both time- and resource-intensive. Automation in code generation for ADS using Large Language Models (LLM) is one potential approach to address this challenge. Nevertheless, the development of ADS requires rigorous processes to verify, validate, assess, and qualify the code before it can be deployed in the vehicle and used. In this study, we developed and evaluated a prototype for automatic code generation and assessment using a designed pipeline of a LLM-based agent, simulation model, and rule-based feedback generator in an industrial setup. The LLM-generated code is evaluated automatically in a simulation model against multiple critical traffic scenarios, and an assessment report is provided as feedback to the LLM for modification or bug fixing. We report about the experimental results of the prototype employing Codellama:34b, DeepSeek (r1:32b and Coder:33b), CodeGemma:7b, Mistral:7b, and GPT4 for Adaptive Cruise Control (ACC) and Unsupervised Collision Avoidance by Evasive Manoeuvre (CAEM). We finally assessed the tool with 11 experts at two Original Equipment Manufacturers (OEMs) by conducting an interview study. Ali Nouri, Johan Andersson, Kailash De Jesus Hornig, Zhennan Fei, Emil Knabe, Håkan Sivencrona, Beatriz Cabrero-Daniel, Christian Berger 0001 |
EASE | 8 |
| 2025 | Large Language Models in Code Co-generation for Safe Autonomous Vehicles
Ali Nouri, Beatriz Cabrero-Daniel, Zhennan Fei, Krishna Ronanki, Håkan Sivencrona, Christian Berger 0001 |
SAFECOMP | 6 |
| 2025 | The DevSafeOps dilemma: A systematic literature review on rapidity in safe autonomous driving development and operationabstractDeveloping autonomous driving (AD) systems is challenging due to the complexity of the systems and the need to assure their safe and reliable operation. The widely adopted approach of DevOps seems promising to support the continuous technological progress in AI and the demand for fast reaction to incidents, which necessitate continuous development, deployment, and monitoring. We present a systematic literature review meant to identify, analyse, and synthesise a broad range of existing literature related to usage of DevOps in autonomous driving development. Our results provide a structured overview of challenges and solutions, arising from applying DevOps to safety-related AI-enabled functions. Our results indicate that there are still several open topics to be addressed to enable safe DevOps for the development of safe AD. • Applying DevOps to autonomous driving presents several open topics to be addressed. • DevSafeOps is introduced, adding safety-related activities into DevOps iterative loops. • Our systematic literature review led to 11 challenges in the DevSafeOps loop. • Potential solutions are identified and mapped to challenges in DevSafeOps. Ali Nouri, Beatriz Cabrero-Daniel, Fredrik Törner, Christian Berger 0001 |
J. Syst. Softw. | 4 |
| 2024 | Welcome Your New AI Teammate: On Safety Analysis by Leashing Large Language ModelsabstractDevOps is a necessity in many industries, including the development of Autonomous Vehicles. In those settings, there are iterative activities that reduce the speed of SafetyOps cycles. One of these activities is "Hazard Analysis & Risk Assessment" (HARA), which is an essential step to start the safety requirements specification. As a potential approach to increase the speed of this step in SafetyOps, we have delved into the capabilities of Large Language Models (LLMs). Our objective is to systematically assess their potential for application in the field of safety engineering. To that end, we propose a framework to support a higher degree of automation of HARA with LLMs. Despite our endeavors to automate as much of the process as possible, expert review remains crucial to ensure the validity and correctness of the analysis results, with necessary modifications made accordingly. Ali Nouri, Beatriz Cabrero-Daniel, Fredrik Törner, Håkan Sivencrona, Christian Berger 0001 |
CAIN | 5 |
| 2024 | Prompt Smells: An Omen for Undesirable Generative AI OutputsabstractRecent trends in the world of Generative Artificial Intelligence (GenAI) focus on developing deep learning (DL)-based models capable of learning structures and temporal patterns from supplied training data to generate content in different formats like text, images, or sound. GenAI models have been widely used in various applications, including creating stories, illustrations, poems, articles, computer code, music compositions, and videos [5, 11]. Krishna Ronanki, Beatriz Cabrero-Daniel, Christian Berger 0001 |
CAIN | 3 |
| 2024 | Semantic-Aware Representation of Multi-Modal Data for Data Ingress: A Literature ReviewabstractMachine Learning (ML) is continuously permeating a growing amount of application domains. Generative AI such as Large Language Models (LLMs) also sees broad adoption to process multi-modal data such as text, images, audio, and video. While the trend is to use ever-larger datasets for training, managing this data efficiently has become a significant practical challenge in the industry-double as much data is certainly not double as good. Rather the opposite is important since getting an understanding of the inherent quality and diversity of the underlying data lakes is a growing challenge for application-specific ML as well as for fine-tuning foundation models. Furthermore, information retrieval (IR) from expanding data lakes is complicated by the temporal dimension inherent in time-series data which must be considered to determine its semantic value. This study focuses on the different semantic-aware techniques to extract embeddings from mono-modal, multi-modal, and cross-modal data to enhance IR capabilities in a growing data lake. Articles were collected to summarize information about the state-of-the-art techniques focusing on applications of embedding for three different categories of data modalities. Pierre Lamart, Yinan Yu, Christian Berger 0001 |
SEAA | 3 |
| 2024 | Predicting and Analyzing Pedestrian Crossing Behavior at Unsignalized CrossingsabstractUnderstanding and predicting pedestrian crossing behavior is essential for enhancing automated driving and improving driving safety. Predicting gap selection behavior and the use of zebra crossing enables driving systems to proactively respond and prevent potential conflicts. This task is particularly challenging at unsignalized crossings due to the ambiguous right of way, requiring pedestrians to constantly interact with vehicles and other pedestrians. This study addresses these challenges by utilizing simulator data to investigate scenarios involving multiple vehicles and pedestrians. We propose and evaluate machine learning models to predict gap selection in non-zebra scenarios and zebra crossing usage in zebra scenarios. We investigate and discuss how pedestrians’ behaviors are influenced by various factors, including pedestrian waiting time, walking speed, the number of unused gaps, the largest missed gap, and the influence of other pedestrians. This research contributes to the evolution of intelligent vehicles by providing predictive models and valuable insights into pedestrian crossing behavior. Chi Zhang 0040, Janis Sprenger, Zhongjun Ni, Christian Berger 0001 |
IV | 4 |
| 2024 | LLMs Can Check Their Own Results to Mitigate Hallucinations in Traffic Understanding Tasks
Malsha Ashani Mahawatta Dona, Beatriz Cabrero-Daniel, Yinan Yu, Christian Berger 0001 |
ICTSS | 4 |
| 2024 | Engineering Safety Requirements for Autonomous Driving with Large Language ModelsabstractChanges and updates in the requirement artifacts, which can be frequent in the automotive domain, are a challenge for SafetyOps. Large Language Models (LLMs), with their impressive natural language understanding and generating capabilities, can play a key role in automatically refining and decomposing requirements after each update. In this study, we propose a prototype of a pipeline of prompts and LLMs that receives an item definition and outputs solutions in the form of safety requirements. This pipeline also performs a review of the requirement dataset and identifies redundant or contradictory requirements. We first identified the necessary characteristics for performing HARA and then defined tests to assess an LLM's capability in meeting these criteria. We used design science with multiple iterations and let experts from different companies evaluate each cycle quantitatively and qualitatively. Finally, the prototype was implemented at a case company and the responsible team evaluated its efficiency. Ali Nouri, Beatriz Cabrero-Daniel, Fredrik Törner, Håkan Sivencrona, Christian Berger 0001 |
RE | 5 |
| 2023 | On STPA for Distributed Development of Safe Autonomous Driving: An Interview StudyabstractSafety analysis is used to identify hazards and build knowledge during the design phase of safety-relevant functions. This is especially true for complex AI-enabled and software intensive systems such as Autonomous Drive (AD). System-Theoretic Process Analysis (STPA) is a novel method applied in safety-related fields like defense and aerospace, which is also becoming popular in the automotive industry. However, STPA assumes prerequisites that are not fully valid in the automotive system engineering with distributed system development and multi-abstraction design levels. This would inhibit software developers from using STPA to analyze their software as part of a bigger system, resulting in a lack of traceability. This can be seen as a maintainability challenge in continuous development and deployment (DevOps). In this paper, STPA’s different guidelines for the automotive industry, e.g. J31887/ISO21448/STPA handbook, are firstly compared to assess their applicability to the distributed development of complex AI-enabled systems like AD. Further, an approach to overcome the challenges of using STPA in a multilevel design context is proposed. By conducting an interview study with automotive industry experts for the development of AD, the challenges are validated and the effectiveness of the proposed approach is evaluated. Ali Nouri, Christian Berger 0001, Fredrik Törner |
SEAA | 2 |
| 2023 | Investigating ChatGPT's Potential to Assist in Requirements Elicitation ProcessesabstractNatural Language Processing (NLP) for Requirements Engineering (RE) (NLP4RE) seeks to apply NLP tools, techniques, and resources to the RE process to increase the quality of the requirements. There is little research involving the utilization of Generative AI-based NLP tools and techniques for requirements elicitation. In recent times, Large Language Models (LLM) like ChatGPT have gained significant recognition due to their notably improved performance in NLP tasks. To explore the potential of ChatGPT to assist in requirements elicitation processes, we formulated six questions to elicit requirements using ChatGPT. Using the same six questions, we conducted interview-based surveys with five RE experts from academia and industry and collected 30 responses containing requirements. The quality of these 36 responses (human-formulated + ChatGPT-generated) was evaluated over seven different requirements quality attributes by another five RE experts through a second round of interview-based surveys. In comparing the quality of requirements generated by ChatGPT with those formulated by human experts, we found that ChatGPT-generated requirements are highly Abstract, Atomic, Consistent, Correct, and Understandable. Based on these results, we present the most pressing issues related to LLMs and what future research should focus on to leverage the emergent behaviour of LLMs more effectively in natural language-based RE activities. Krishna Ronanki, Christian Berger 0001, Jennifer Horkoff |
SEAA | 2 |
| 2023 | AirDnD - Asynchronous In-Range Dynamic and Distributed Network Orchestration FrameworkabstractThe increasing usage of IoT devices has generated an extensive volume of data which resulted in the establishment of data centers with well-structured computing infrastructure. Reducing underutilized resources of such data centers can be achieved by monitoring the tasks and offloading them across various compute units. This approach can also be used in mini mobile data ponds generated by edge devices and smart vehicles. This research aims to improve and utilize the usage of computing resources in distributed edge devices by forming a dynamic mesh network. The nodes in the mesh network shall share their computing tasks with another node that possesses unused computing resources. This proposed method ensures the minimization of data transfer between entities. The proposed AirDnD vision will be applied to a practical scenario relevant to an autonomous vehicle that approaches an intersection commonly known as “looking around the corner” in related literature, collecting essential computational results from nearby vehicles to enhance its perception. The proposed solution consists of three models that transform growing amounts of geographically distributed edge devices into a living organism. Malsha Ashani Mahawatta Dona, Christian Berger 0001, Yinan Yu |
ICDCS | 2 |
| 2023 | ZEBRA: Z-order Curve-based Event Retrieval Approach to Efficiently Explore Automotive DataabstractEvaluating the performance of software for automated vehicles is predominantly driven by data collected from the real world. While professional test drivers are supported with technical means to semi-automatically annotate driving maneuvers to allow better event identification, simple data loggers in large vehicle fleets typically lack automatic and detailed event classification and hence, extra effort is needed when post-processing such data. Yet, the data quality from professional test drivers is apparently higher than the one from large fleets where labels are missing, but the non-annotated data set from large vehicle fleets is much more representative for typical, realistic driving scenarios to be handled by automated vehicles. However, while growing the data from large fleets is relatively simple, adding valuable annotations during post-processing has become increasingly expensive. In this paper, we leverage Z-order space-filling curves to systematically reduce data dimensionality while preserving domain-specific data properties, which allows us to explore even large-scale field data sets to spot interesting events orders of magnitude faster than processing time-series data directly. Furthermore, the proposed concept is based on an analytical approach, which preserves explainability for the identified events. Christian Berger 0001, Lukas Birkemeyer |
IV | 1 |
| 2023 | Cross or Wait? Predicting Pedestrian Interaction Outcomes at Unsignalized CrossingsabstractPredicting pedestrian behavior when interacting with vehicles is one of the most critical challenges in the field of automated driving. Pedestrian crossing behavior is influenced by various interaction factors, including time to arrival, pedestrian waiting time, the presence of zebra crossing, and the properties and personality traits of both pedestrians and drivers. However, these factors have not been fully explored for use in predicting interaction outcomes. In this paper, we use machine learning to predict pedestrian crossing behavior including pedestrian crossing decision, crossing initiation time (CIT), and crossing duration (CD) when interacting with vehicles at unsignalized crossings. Distributed simulator data are utilized for predicting and analyzing the interaction factors. Compared with the logistic regression baseline model, our proposed neural network model improves the prediction accuracy and F1 score by 4.46% and 3.23%, respectively. Our model also reduces the root mean squared error (RMSE) for CIT and CD by 21.56% and 30.14% compared with the linear regression model. Additionally, we have analyzed the importance of interaction factors, and present the results of models using fewer factors. This provides information for model selection in different scenarios with limited input features. Chi Zhang 0040, Amir Hossein Kalantari, Yue Yang 0043, Zhongjun Ni, Gustav Markkula, Natasha Merat, Christian Berger 0001 |
IV | 7 |
| 2023 | Pedestrian Behavior Prediction Using Deep Learning Methods for Urban Scenarios: A ReviewabstractThe prediction of pedestrian behavior is essential for automated driving in urban traffic and has attracted increasing attention in the vehicle industry. This task is challenging because pedestrian behavior is driven by various factors, including their individual properties, the interactions with other road users, and the interactions with the environment. Deep learning approaches have become increasingly popular because of their superior performance in complex scenarios compared to traditional approaches such as the social force or constant velocity models. In this paper, we provide a comprehensive review of deep learning-based approaches for pedestrian behavior prediction. We review and categorize a large selection of scientific contributions covering both trajectory and intention prediction from the last five years. We categorize existing works by prediction tasks, input data, model features, and network structures. Besides, we provide an overview of existing datasets and the evaluation metrics. We analyze, compare, and discuss the performance of existing work. Finally, we point out the research gaps and outline possible directions for future research. Chi Zhang 0040, Christian Berger 0001 |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2022 | An Industrial Experience Report about Challenges from Continuous Monitoring, Improvement, and Deployment for Autonomous Driving FeaturesabstractUsing continuous development, deployment, and monitoring (CDDM) to understand and improve applications in a customer’s context is widely used for non-safety applications such as smartphone apps or web applications to enable rapid and innovative feature improvements. Having demonstrated its potential in such domains, it may have the potential to also improve the software development for automotive functions as some OEMs described on a high level in their financial company communiqués. However, the application of a CDDM strategy also faces challenges from a process adherence and documentation perspective as required by safety-related products such as autonomous driving systems (ADS) and guided by industry standards such as ISO-26262 [1] and ISO21448 [2]. There are publications on CDDM in safety-relevant contexts that focus on safety-critical functions on a rather generic level and thus, not specifically ADS or automotive, or that are concentrating only on software and hence, missing out the particular context of an automotive OEM: Well-established legacy processes and the need of their adaptations, and aspects originating from the role of being a system integrator for software/software, hardware/hardware, and hardware/software. In this paper, particular challenges from the automotive domain to better adopt CDDM are identified and discussed to shed light on research gaps to enhance CDDM, especially for the software development of safe ADS. The challenges are identified from today’s industrial well-established ways of working by conducting interviews with domain experts and complemented by a literature study. Ali Nouri, Christian Berger 0001, Fredrik Törner |
SEAA | 2 |
| 2022 | Formally Robust and Safe Trajectory Planning and Tracking for Autonomous VehiclesabstractIn this paper, a safe trajectory planning and tracking algorithm for autonomous vehicles is proposed. Specially, the safety problem considers the geometric constraints including the obstacle avoiding and the road side constraints, and the non-convex input constraints defined from the sideslip angle of the wheels and input boundedness. Control barrier function (CBF) is adopted to deal with the state and input constraints and generate nominal trajectory. For this purpose, the nominal dynamics of the autonomous vehicle is defined as the virtual dynamics, from which the CBF safety certificates are derived. By constructing appropriate feedback control, the tracking error of the actual trajectory can be bounded into a tube, which guarantees the geometric safety of the actual vehicle. Two safety certificates, the bearing and the distance safety certificates are derived for multiple-obstacle avoidance. In order to deal with the non-convex input constraints, a safe braking maneuver is carefully considered. The feasible initial velocity set for safe braking is proposed as a part of state constraints. The feasibility and the safety of the overall system is proved. The algorithm to synthesis the CBF certificates for multiple-obstacle avoidance, and the input constraints is proposed. Simulation results from an autonomous vehicle including disturbances demonstrate the feasibility of the algorithm. The software implementation of the proposed algorithm was developed in C++ intended for real-world testing. Yushu Yu, Dan Shan, Ola Benderius, Christian Berger 0001 |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2021 | A Structured Analysis of the Video Degradation Effects on the Performance of a Machine Learning-enabled Pedestrian DetectorabstractMachine Learning (ML)-enabled software systems have been incorporated in many public demonstrations for automated driving (AD) systems. Such solutions have also been considered as a crucial approach to aim at SAE Level 5 systems, where the passengers in such vehicles do not have to interact with the system at all anymore. Already in 2016, Nvidia demonstrated a complete end-to-end approach for training the complete software stack covering perception, planning and decision making, and the actual vehicle control. While such approaches show the great potential of such ML-enabled systems, there have also been demonstrations where already changes to single pixels in a video frame can potentially lead to completely different decisions with dangerous consequences in the worst case. In this paper, a structured analysis has been conducted to explore video degradation effects on the performance of an ML-enabled pedestrian detector. Firstly, a baseline of applying “You only look once” (YOLO) to 1,026 frames with pedestrian annotations in the KITTI Vision Benchmark Suite has been established. Next, video degradation candidates for each of these frames were generated using the leading video compression codecs libx264, libx265, Nvidia HEVC, and AV1: 52 frames for the various compression presets for color frames, and 52 frames for gray-scale frames resulting in 104 degradation candidates per original KITTI frame and in 426,816 images in total. YOLO was applied to each image to compute the intersection-over-union (IoU) metric to compare the performance with the original baseline. While aggressively lossy compression settings result in significant performance drops as expected, it was also observed that some configurations actually result in slightly better IoU results compared to the baseline. Hence, while related work in literature demonstrated the potentially negative consequences of even simple modifications to video data when using ML-enabled systems, the findings from this work show that carefully chosen lossy video configurations preserve a decent performance of particular ML-enabled systems while allowing for substantial savings when storing or transmitting data. Such aspects are of crucial importance when, for example, video data needs to be collected from multiple vehicles wirelessly, where lossy video codecs are required to cope with bandwidth limitations for example. Christian Berger 0001 |
SEAA | 1 |
| 2021 | Understanding the Impact of Edge Cases from Occluded Pedestrians for ML SystemsabstractMachine learning (ML)-enabled approaches are considered a substantial support technique of detection and classification of obstacles of traffic participants in self-driving vehicles. Major breakthroughs have been demonstrated the past few years, even covering complete end-to-end data processing chain from sensory inputs through perception and planning to vehicle control of acceleration, breaking and steering. YOLO (you-only-look-once) is a state-of-the-art perception neural network (NN) architecture providing object detection and classification through bounding box estimations on camera images. As the NN is trained on well annotated images, in this paper we study the variations of confidence levels from the NN when tested on hand-crafted occlusion added to a test set. We compare regular pedestrian detection to upper and lower body detection. Our findings show that the two NN using only partial information perform similarly well like the NN for the full body when the full body NN’s performance is 0.75 or better. Furthermore and as expected, the network, which is only trained on the lower half body is least prone to disturbances from occlusions of the upper half and vice versa. Jens Henriksson, Christian Berger 0001, Stig Ursing |
SEAA | 2 |
| 2021 | Social-IWSTCNN: A Social Interaction-Weighted Spatio- Temporal Convolutional Neural Network for Pedestrian Trajectory Prediction in Urban Traffic ScenariosabstractPedestrian trajectory prediction in urban scenarios is essential for automated driving. This task is challenging because the behavior of pedestrians is influenced by both their own history paths and the interactions with others. Previous research modeled these interactions with pooling mechanisms or aggregating with hand-crafted attention weights. In this paper, we present the Social Interaction-Weighted Spatio- Temporal Convolutional Neural Network (Social-IWSTCNN), which includes both the spatial and the temporal features. We propose a novel design, namely the Social Interaction Extractor, to learn the spatial and social interaction features of pedestrians. Most previous works used ETH and UCY datasets which include five scenes but do not cover urban traffic scenarios extensively for training and evaluation. In this paper, we use the recently released large-scale Waymo Open Dataset in urban traffic scenarios, which includes 374 urban training scenes and 76 urban testing scenes to analyze the performance of our proposed algorithm in comparison to the state-of-the-art (SOTA) models. The results show that our algorithm outperforms SOTA algorithms such as Social-LSTM, Social-GAN, and Social-STGCNN on both Average Displacement Error (ADE) and Final Displacement Error (FDE). Furthermore, our Social- IWSTCNN is 54.8 times faster in data pre-processing speed, and 4.7 times faster in total test speed than the current best SOTA algorithm Social-STGCNN. Chi Zhang 0040, Christian Berger 0001, Marco Dozza |
IV | 2 |
| 2021 | Performance analysis of out-of-distribution detection on trained neural networks
Jens Henriksson, Christian Berger 0001, Markus Borg, Lars Tornberg, Sankar Raman Sathyamoorthy, Cristofer Englund |
Inf. Softw. Technol. | 2 |
| 2020 | Principles for Re-architecting Software for Heterogeneous PlatformsabstractThe demands on software continues to increase through the constant addition of functionalities and high expectations from users. In particular, performance has been the focus in many projects with the goal of fulfilling complex and hard requirements across a variety of domains. One way to achieve satisfactory levels of performance is through heterogeneous computing, i.e., systems that contain more than one type of processing unit, such as CPUs, GPUs, and FPGAs. However, applications are typically designed to be executed on CPUs, and re-architecting software for execution on such heterogeneous hardware architectures entails several challenges that must be addressed. In this paper, we propose a framework that supports engineers in the process of making architectural decisions to re-architect software for execution on heterogeneous platforms. We present several relevant aspects that should be addressed in the process, along with suggestions on how to create design solutions using different existing approaches. The framework was developed based on multiple interactions with three industrial partners and evaluated through a computer vision application in the automotive domain. Hugo Sica de Andrade, Christian Berger 0001, Ivica Crnkovic, Jan Bosch |
APSEC | 2 |
| 2020 | Continuous Experimentation for Automotive Software on the Example of a Heavy Commercial Vehicle in Daily Operation
Federico Giaimo, Christian Berger 0001 |
ECSA | 2 |
| 2020 | HAFLoop: An architecture for supporting Highly Adaptive Feedback Loops in self-adaptive systems
Edith Zavala, Xavier Franch, Jordi Marco, Christian Berger 0001 |
Future Gener. Comput. Syst. | 4 |
| 2020 | Continuous experimentation and the cyber-physical systems challenge: An overview of the literature and the industrial perspectiveabstractNew software development patterns are emerging aiming at accelerating the process of delivering value. One is Continuous Experimentation, which allows to systematically deploy and run instrumented software variants during development phase in order to collect data from the field of application. While currently this practice is used on a daily basis on web-based systems, technical difficulties challenge its adoption in fields where computational resources are constrained, e.g., cyber–physical systems and the automotive industry. This paper aims at providing an overview of the engagement on the Continuous Experimentation practice in the context of cyber–physical systems. A systematic literature review has been conducted to investigate the link between the practice and the field of application. Additionally, an industrial multiple case study is reported. The study presents the current state-of-the-art regarding Continuous Experimentation in the field of cyber–physical systems. The current perspective of Continuous Experimentation in industry is also reported. The field has not reached maturity yet. More conceptual analyses are found than solution proposals and the state-of-practice is yet to be achieved. However it is expected that in time an increasing number of solutions will be proposed and validated. Federico Giaimo, Hugo Sica de Andrade, Christian Berger 0001 |
J. Syst. Softw. | 3 |
| 2019 | The Automotive Take on Continuous Experimentation: A Multiple Case StudyabstractRecently, an increasingly growing number of companies is focusing on achieving self-driving systems towards SAE level 3 and higher. Such systems will have much more complex capabilities than today's advanced driver assistance systems (ADAS) like adaptive cruise control and lane-keeping assistance. For complex software systems in the Web-application domain, the logical successor for Continuous Integration and Deployment (CI/CD) is known as Continuous Experimentation (CE), where product owners jointly with engineers systematically run A/B experiments on possible new features to get quantifiable data about a feature's adoption from the users. While this methodology is increasingly adopted in software-intensive companies, our study is set out to explore advantages and challenges when applying CE during the development and roll-out of functionalities required for self-driving vehicles. This paper reports about the design and results from a multiple case study that was conducted at four companies including two automotive OEMs with a long history of developing vehicles, a Tier-1 supplier, and a start-up company within the area of automated driving systems. Unanimously, all expect higher quality and fast roll-out cycles to the fleet; as major challenges, however, safety concerns next to organizational structures are mentioned. Federico Giaimo, Hugo Sica de Andrade, Christian Berger 0001 |
SEAA | 3 |
| 2019 | Performance Analysis of Out-of-Distribution Detection on Various Trained Neural NetworksabstractSeveral areas have been improved with Deep Learning during the past years. For non-safety related products adoption of AI and ML is not an issue, whereas in safety critical applications, robustness of such approaches is still an issue. A common challenge for Deep Neural Networks (DNN) occur when exposed to out-of-distribution samples that are previously unseen, where DNNs can yield high confidence predictions despite no prior knowledge of the input. In this paper we analyse two supervisors on two well-known DNNs with varied setups of training and find that the outlier detection performance improves with the quality of the training procedure. We analyse the performance of the supervisor after each epoch during the training cycle, to investigate supervisor performance as the accuracy converges. Understanding the relationship between training results and supervisor performance is valuable to improve robustness of the model and indicates where more work has to be done to create generalized models for safety critical applications. Jens Henriksson, Christian Berger 0001, Markus Borg, Lars Tornberg, Sankar Raman Sathyamoorthy, Cristofer Englund |
SEAA | 2 |
| 2019 | Systematic benchmarking for reproducibility of computer vision algorithms for real-time systems: The example of optic flow estimationabstractUntil now there have been few formalized methods for conducting systematic benchmarking aiming at reproducible results when it comes to computer vision algorithms. This is evident from lists of algorithms submitted to prominent datasets, authors of a novel method in many cases primarily state the performance of their algorithms in relation to a shallow description of the hardware system where it was evaluated. There are significant problems linked to this non-systematic approach of reporting performance, especially when comparing different approaches and when it comes to the reproducibility of claimed results. Furthermore how to conduct retrospective performance analysis such as an algorithm's suitability for embedded real-time systems over time with underlying hardware and software changes in place. This paper proposes and demonstrates a systematic way of addressing such challenges by adopting containerization of software aiming at formalization and reproducibility of benchmarks. Our results show maintainers of broadly accepted datasets in the computer vision community to strive for systematic comparison and reproducibility of submissions to increase the value and adoption of computer vision algorithms in the future. Björnborg Nguyen, Christian Berger 0001, Ola Benderius |
IROS | 2 |
| 2019 | Evolution of Technical Debt: An Exploratory Study
Md. Abdullah Al Mamun 0001, Antonio Martini 0001, Miroslaw Staron, Christian Berger 0001, Jörgen Hansson |
IWSM-Mensura | 4 |
| 2019 | Effects of measurements on correlations of software code metricsabstractSoftware metrics play a significant role in many areas in the life-cycle of software including forecasting defects and foretelling stories regarding maintenance, cost, etc. through predictive analysis. Many studies have found code metrics correlated to each other at such a high level that such correlated code metrics are considered redundant, which implies it is enough to keep track of a single metric from a list of highly correlated metrics. Software is developed incrementally over a period. Traditionally, code metrics are measured cumulatively as cumulative sum or running sum. When a code metric is measured based on the values from individual revisions or commits without consolidating values from past revisions, indicating the natural development of software, this study identifies such a type of measure as organic . Density and average are two other ways of measuring metrics. This empirical study focuses on whether measurement types influence correlations of code metrics. To investigate the objective, this empirical study has collected 24 code metrics classified into four categories, according to the measurement types of the metrics, from 11,874 software revisions (i.e., commits) of 21 open source projects from eight well-known organizations. Kendall’s τ -B is used for computing correlations. To determine whether there is a significant difference between cumulative and organic metrics, Mann-Whitney U test, Wilcoxon signed rank test, and paired-samples sign test are performed. The cumulative metrics are found to be highly correlated to each other with an average coefficient of 0.79. For corresponding organic metrics, it is 0.49. When individual correlation coefficients between these two measure types are compared, correlations between organic metrics are found to be significantly lower (with p < 0.01) than cumulative metrics. Our results indicate that the cumulative nature of metrics makes them highly correlated, implying cumulative measurement is a major source of collinearity between cumulative metrics. Another interesting observation is that correlations between metrics from different categories are weak. Results of this study reveal that measurement types may have a significant impact on the correlations of code metrics and that transforming metrics into a different type can give us metrics with low collinearity. These findings provide us a simple understanding how feature transformation to a different measurement type can produce new non-collinear input features for predictive models. Md. Abdullah Al Mamun 0001, Christian Berger 0001, Jörgen Hansson |
Empir. Softw. Eng. | 2 |
| 2018 | The Best Rated Human-Machine Interface Design for Autonomous Vehicles in the 2016 Grand Cooperative Driving ChallengeabstractThis paper provides an in-depth description of the best rated human-machine interface that was presented during the 2016 Grand Cooperative Driving Challenge. It was demonstrated by the Chalmers Truck Team as the envisioned interface to their open source software framework OpenDLV, which is used to power Chalmers' fleet of self-driving vehicles. The design originates from the postulate that the vehicle is fully autonomous to handle even complex traffic scenarios. Thus, by including external and internal interfaces, and introducing a show, don't tell principle, it aims at fulfilling the needs of the vehicle occupants as well as other participants in the traffic environment. The design also attempts to comply with, and slightly extend, the current traffic rules and legislation for the purpose of being realistic for full-scale implementation. Ola Benderius, Christian Berger 0001, Victor Malmsten-Lundgren |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2017 | Considerations About Continuous Experimentation for Resource-Constrained Platforms in Self-driving Vehicles
Federico Giaimo, Christian Berger 0001, Crispin Kirchner |
ECSA | 2 |
| 2017 | Design Criteria to Architect Continuous Experimentation for Self-Driving VehiclesabstractThe software powering today's vehicles surpasses mechatronics as the dominating engineering challenge due to its fast evolving and innovative nature. In addition, the software and system architecture for upcoming vehicles with automated driving functionality is already processing ~750MB/s - corresponding to over 180 simultaneous 4K-video streams from popular video-on-demand services. Hence, self-driving cars will run so much software to resemble "small data centers on wheels" rather than just transportation vehicles. Continuous Integration, Deployment, and Experimentation have been successfully adopted for software-only products as enabling methodology for feedback-based software development. For example, a popular search engine conducts ~250 experiments each day to improve the software based on its users' behavior. This work investigates design criteria for the software architecture and the corresponding software development and deployment process for complex cyber-physical systems, with the goal of enabling Continuous Experimentation as a way to achieve continuous software evolution. Our research involved reviewing related literature on the topic to extract relevant design requirements. The study is concluded by describing the software development and deployment process and software architecture adopted by our self-driving vehicle laboratory, both based on the extracted criteria. Federico Giaimo, Christian Berger 0001 |
ICSA | 2 |
| 2017 | Predicting and Evaluating Software Model Growth in the Automotive IndustryabstractThe size of a software artifact influences the software quality and impacts the development process. In industry, when software size exceeds certain thresholds, memory errors accumulate and development tools might not be able to cope anymore, resulting in a lengthy program start up times, failing builds, or memory problems at unpredictable times. Thus, foreseeing critical growth in software modules meets a high demand in industrial practice. Predicting the time when the size grows to the level where maintenance is needed prevents unexpected efforts and helps to spot problematic artifacts before they become critical.Although the amount of prediction approaches in literature is vast, it is unclear how well they fit with prerequisites and expectations from practice. In this paper, we perform an industrial case study at an automotive manufacturer to explore applicability and usability of prediction approaches in practice. In a first step, we collect the most relevant prediction approaches from literature, including both, approaches using statistics and machine learning. Furthermore, we elicit expectations towards predictions from practitioners using a survey and stakeholder workshops. At the same time, we measure software size of 48 software artifacts by mining four years of revision history, resulting in 4,547 data points. In the last step, we assess the applicability of state-of-the-art prediction approaches using the collected data by systematically analyzing how well they fulfill the practitioners' expectations.Our main contribution is a comparison of commonly used prediction approaches in a real world industrial setting while considering stakeholder expectations. We show that the approaches provide significantly different results regarding prediction accuracy and that the statistical approaches fit our data best. Jan Schroeder, Christian Berger 0001, Alessia Knauss, Harri Preenja, Mohammad Ali 0002, Miroslaw Staron, Thomas Herpel |
ICSME | 2 |
| 2017 | Paving the roadway for safety of automated vehicles: An empirical study on testing challengesabstractThe technology in the area of automated vehicles is gaining speed and promises many advantages. However, with the recent introduction of conditionally automated driving, we have also seen accidents. Test protocols for both, conditionally automated (e.g., on highways) and automated vehicles do not exist yet and leave researchers and practitioners with different challenges. For instance, current test procedures do not suffice for fully automated vehicles, which are supposed to be completely in charge for the driving task and have no driver as a back up. This paper presents current challenges of testing the functionality and safety of automated vehicles derived from conducting focus groups and interviews with 26 participants from five countries having a background related to testing automotive safety-related topics. We provide an overview of the state-of-practice of testing active safety features as well as challenges that needs to be addressed in the future to ensure safety for automated vehicles. The major challenges identified through the interviews and focus groups, enriched by literature on this topic are related to 1) virtual testing and simulation, 2) safety, reliability, and quality, 3) sensors and sensor models, 4)required scenario complexity and amount of test cases, and 5)handover of responsibility between the driver and the vehicle. Alessia Knauss, Jan Schroeder, Christian Berger 0001, Henrik Eriksson |
Intelligent Vehicles Symposium | 3 |
| 2017 | Mastering data complexity for autonomous driving with adaptive point clouds for urban environmentsabstractLiDAR sensors play a crucial role in autonomous driving and advanced driver assistance systems. By firing high-rate laser beams, a LiDAR device is able to project its surroundings as 2D or 3D point cloud, which can be used for different purposes such as object detection, map generation, localization, and navigation. Autonomous vehicles are often equipped with at least one multi-layer LiDAR sensor with 360-degree coverage to include as much information as possible in the point cloud. Such a device generates enormous amount of data which poses a challenge for data storage, real-time computation, and data transmission, as autonomous vehicles are typically resource-constrained systems. This paper proposes a lightweight and adaptive point cloud data structure to reduce the size of a 3D point cloud. The suggested data structure can be flexibly configured with different parameters to adapt for precision, distance coverage, and reflectivity resolution. The precision of the data structure is evaluated using a 16-layer Velodyne LiDAR sensor (VLP-16) to collect data in the city area of AstaZero proving ground and Gothenburg downtown. Our results show that the adaptive data structure can consume only 1/8th of the original point cloud size and hence, it is particularly suitable for applications with limited hardware resources or certain tolerance to precision of the point cloud. The suggested concept is also generalizable to other types of point cloud providing sensors. Christian Berger 0001 |
Intelligent Vehicles Symposium | 2 |
| 2017 | Correlations of software code metrics: an empirical studyabstractBackground: The increasing up-trend of software size brings about challenges related to release planning and maintainability. Foreseeing the growth of software metrics can assist in taking proactive decisions regarding different areas where software metrics play vital roles. For example, source code metrics are used to automatically calculate technical debt related to code quality which may indicate how maintainable a software is. Thus, predicting such metrics can give us an indication of technical debt in the future releases of software. Objective: Estimation or prediction of software metrics can be performed more meaningfully if the relationships between different domains of metrics and relationships between the metrics and different domains are well understood. To understand such relationships, this empirical study has collected 25 metrics classified into four domains from 9572 software revisions of 20 open source projects from 8 well-known companies. Results: We found software size related metrics are most correlated among themselves and with metrics from other domains. Complexity and documentation related metrics are more correlated with size metrics than themselves. Metrics in the duplications domain are observed to be more correlated to themselves on a domain-level. However, a metric to domain level relationship exploration reveals that metrics with most strong correlations are in fact connected to size metrics. The Overall correlation ranking of duplication metrics are least among all domains and metrics. Contribution: Knowledge earned from this research will help to understand inherent relationships between metrics and domains. This knowledge together with metric-level relationships will allow building better predictive models for software code metrics. Md. Abdullah Al Mamun 0001, Christian Berger 0001, Jörgen Hansson |
IWSM-Mensura | 2 |
| 2016 | Unveiling anomalies and their impact on software quality in model-based automotive software revisions with software metrics and domain expertsabstractThe validation of simulation models (e.g., of electronic control units for vehicles) in industry is becoming increasingly challenging due to their growing complexity. To systematically assess the quality of such models, software metrics seem to be promising. In this paper we explore the use of software metrics and outlier analysis as a means to assess the quality of model-based software. More specifically, we investigate how results from regression analysis applied to measurement data received from size and complexity metrics can be mapped to software quality. Using the moving averages approach, models were fit to data received from over 65,000 software revisions for 71 simulation models that represent different electronic control units of real premium vehicles. Consecutive investigations using studentized deleted residuals and Cook’s Distance revealed outliers among the measurements. From these outliers we identified a subset, which provides meaningful information (anomalies) by comparing outlier scores with expert opinions. Eight engineers were interviewed separately for outlier impact on software quality. Findings were validated in consecutive workshops. The results show correlations between outliers and their impact on four of the considered quality characteristics. They also demonstrate the applicability of this approach in industry. Jan Schroeder, Christian Berger 0001, Miroslaw Staron, Thomas Herpel, Alessia Knauss |
ISSTA | 2 |
| 2016 | Analyzing defect inflow distribution and applying Bayesian inference method for software defect prediction in large software projects
Rakesh Rana, Miroslaw Staron, Christian Berger 0001, Jörgen Hansson, Martin Nilsson 0002, Wilhelm Meding |
J. Syst. Softw. | 3 |
| 2015 | Design and Evaluation of a Customizable Multi-Domain Reference Architecture on Top of Product Lines of Self-Driving Heavy Vehicles - An Industrial Case StudyabstractSelf-driving vehicles for commercial use cases like logistics or overcast mines increase their owners' economic competitiveness. Volvo maintains, evolves, and distributes a vehicle control product line for different brands like Volvo Trucks, Renault, and Mack in more than 190 markets world-wide. From the different application domains of their customers originates the need for a multi-domain reference architecture concerned with transport mission planning, execution, and tracking on top of the vehicle control product line. This industrial case study is the first of its kind reporting about the systematic process to design such a reference architecture involving all relevant external and internal stakeholders, development documents, low level artifacts, and literature. Quantitative and qualitative metrics were applied to evaluate non-functional requirements on the reference architecture level before a concrete variant was evaluated using a Volvo FMX truck in an exemplary construction site setting. Jan Schroeder, Daniela Holzner, Christian Berger 0001, Carl-Johan Hoel, Leo Laine, Anders Magnusson |
ICSE (2) | 3 |
| 2015 | Systematic evaluation of three data marshalling approaches for distributed software systemsabstractCyber-physical systems like robots and self-driving vehicles comprise complex software systems. Their software is typically realized as distributed agents that are responsible for dedicated tasks like sensor data handling, sensor data fusion, or action planning. The modular design allows a flexible deployment as well as algorithm encapsulation to exchange software modules where needed. The distributed software exchanges data using a data marshalling layer to serialize and deserialize data structures between a sending and receiving entity. In this article, we are systematically evaluating Google Protobuf, LCM, and our self-adaptive delta marshalling approach by using a generic description language, of which instances are composed at runtime. Our results show that Google Protobuf performs well for small messages composed mainly by integral field types; the self-adaptive data marshalling approach is efficient if four or more fields of type double are present, and LCM outperforms both when a mix of many integral and double fields is used. Hugo Sica de Andrade, Federico Giaimo, Christian Berger 0001, Ivica Crnkovic |
DSM@SPLASH | 3 |
| 2015 | Expectations and Challenges from Scaling Agile in Mechatronics-Driven Companies - A Comparative Case Study
Christian Berger 0001, Ulrik Eklund |
XP | 1 |
| 2014 | Agile Model-Driven Engineering in Mechatronic Systems - An Industrial Case Study
Ulf Eliasson, Rogardt Heldal, Jonn Lantz, Christian Berger 0001 |
MoDELS | 4 |
| 2014 | Visualizing Testing Activities to Support Continuous Integration: A Multiple Case Study
Agneta Nilsson, Jan Bosch, Christian Berger 0001 |
XP | 3 |
| 2014 | Selecting software reliability growth models and improving their predictive accuracy using historical projects data
Rakesh Rana, Miroslaw Staron, Christian Berger 0001, Jörgen Hansson, Martin Nilsson 0002, Fredrik Törner, Wilhelm Meding, Christoffer Höglund |
J. Syst. Softw. | 3 |
| 2013 | Increasing Efficiency of ISO 26262 Verification and Validation by Combining Fault Injection and Mutation Testing with Model based DevelopmentabstractThe rapid growth of software intensive active safety functions in modern cars resulted in adoption of new safety development standards like ISO 26262 by the automotive industry. Hazard analysis, safety assessment and adequate verification and validation methods for software and car electronics require effort but in the long run save lives. We argue that in the face of complex software development set-up with distributed functionality, Model-Based Development (MBD) and safety criticality of software embedded in modern cars, there is a need for evolving existing methods of MBD and complementing them with methods already used in the development of other systems (Fault Injection and Mutation Testing). Our position is that significant effectiveness and efficiency improvements can be made by applying fault injection techniques combined with mutation testing approach for verification and validation of automotive software at the model level. The improvements include such aspects as identification of safety related defects early in the development process thus providing enough time to remove the defects. The argument is based on our industrial case studies, the studies of ISO 26262 standard and academic experiments with new verification and validation methods applied to models. Rakesh Rana, Miroslaw Staron, Christian Berger 0001, Jörgen Hansson, Martin Nilsson 0002, Fredrik Törner |
ICSOFT | 3 |
| 2013 | Evaluating long-term predictive power of standard reliability growth models on automotive systemsabstractSoftware is today an integral part of providing improved functionality and innovative features in the automotive industry. Safety and reliability are important requirements for automotive software and software testing is still the main source of ensuring dependability of the software artifacts. Software Reliability Growth Models (SRGMs) have been long used to assess the reliability of software systems; they are also used for predicting the defect inflow in order to allocate maintenance resources. Although a number of models have been proposed and evaluated, much of the assessment of their predictive ability is studied for short term (e.g. last 10% of data). But in practice (in industry) the usefulness of SRGMs with respect to optimal resource allocation depends heavily on the long term predictive power of SRGMs i.e. much before the project is close to completion. The ability to reasonably predict the expected defect inflow provides important insight that can help project and quality managers to take necessary actions related to testing resource allocation on time to ensure high quality software at the release. In this paper we evaluate the long-term predictive power of commonly used SRGMs on four software projects from the automotive sector. The results indicate that Gompertz and Logistic model performs best among the tested models on all fit criterias as well as on predictive power, although these models are not reliable for long-term prediction with partial data. Rakesh Rana, Miroslaw Staron, Christian Berger 0001, Jörgen Hansson, Martin Nilsson 0002, Fredrik Törner |
ISSRE | 3 |
| 2013 | Comparing between Maximum Likelihood Estimator and Non-linear Regression Estimation Procedures for NHPP Software Reliability Growth ModellingabstractSoftware Reliability Growth Models (SRGMs) have been used by engineers and managers for tracking and managing the reliability change of software to ensure required standard of quality is achieved before the software is released to the customer. SRGMs can be used during the project to help make testing resource allocation decisions and/ or it can be used after the testing phase to determine the latent faults prediction to assess the maturity of software artifact. A number of SRGMs have been proposed and to apply a given reliability model, defect inflow data is fitted to model equations. Two of the widely known and recommended techniques for parameter estimation are maximum likelihood and method of least squares. In this paper we compare between the two estimation procedures for their applicability in context of NHPP SRGMs. We also highlight a couple of practical considerations, reliability practitioners must be aware of when applying SRGMs. Rakesh Rana, Miroslaw Staron, Christian Berger 0001, Jörgen Hansson, Martin Nilsson 0002, Fredrik Törner |
IWSM/Mensura | 3 |
| 2013 | MDE-based sensor management and verification for a self-driving miniature vehicleabstractInnovations for today's vehicle functions are mainly driven by software. They realize comfort systems like automated parking but also safety systems where sensors are continuously monitoring the vehicle's surroundings to brake autonomously for avoiding collisions with cars, pedestrians, or bicyclists. In simulation environments, various traffic situations with alternative sensor setups are imitated before testing them on prototypical cars. In this paper, we are presenting an MDE approach for managing different sensor setups in a cyber-physical system development environment to leverage automated model verification, support system testing, and enable code generation. For example, the models are used as the single point of truth to configure and generate sensor setups for system validations in a 3D simulation environment. After their validation, a considered sensor configuration is transformed into a constraint-satisfaction model to be solved by the logical programming language Prolog. Based on this transformation, the conformance to the embedded system specification is formally verified and possible pin assignments, for how to connect the required sensors are calculated. The approach was validated during the development of a self-driving miniature vehicle using an STM32F4-based embedded system running the real-time operating system ChibiOS as the software/hardware interface to the sensors and actors. Md. Abdullah Al Mamun 0001, Christian Berger 0001, Jörgen Hansson |
DSM@SPLASH | 2 |
| 2013 | Evaluation of Standard Reliability Growth Models in the Context of Automotive Software Systems
Rakesh Rana, Miroslaw Staron, Niklas Mellegård, Christian Berger 0001, Jörgen Hansson, Martin Nilsson 0002, Fredrik Törner |
PROFES | 4 |
| 2012 | Design considerations for a cyber-physical testing language on the example of autonomous drivingabstractCyber-physical systems are nowadays used as the term for systems which perceive data from their surroundings for algorithmic processing and enrichment by digital information to generate interactions in their specific context. In recent days, a prominent example for these systems are autonomously driving vehicles that continuously have to sense their environment to calculate the next set points for their control algorithms. The development of these complex and interconnected systems requires the combined utilization of simulations and test-runs in reality to assess the system's quality and to increase the developer's and customer's confidence in the resulting implementation. The combination of interactive as well as unattended simulated system tests has to be in tight coordination with their real counterparts to derive reliable results on the one hand and to save valuable resources on the other hand. In this article, the development and test processes of two autonomously driving vehicles are analyzed to derive essential design drivers for a domain-specific language to unify the description, evaluation, and mutual feedback of simulative and real test-runs. Christian Berger 0001 |
DSM@SPLASH | 1 |
| 2011 | Formal specification and systematic model-driven testing of embedded automotive systemsabstractIncreasingly intelligent energy-management and safety systems are developed to realize safe and economic automobiles. The realization of these systems is only possible with complex and distributed software. This development poses a challenge for verification and validation. Upcoming standards like ISO 26262 provide requirements for verification and validation during development phases. Advanced test methods are requested for safety critical functions. Formal specification of requirements and appropriate testing strategies in different stages of the development cycle are part of it. In this paper we present our approach to formalize the requirements specification by test models. These models serve as basis for the following testing activities, including the automated derivation of executable test cases from it. Test cases can be derived statistically, randomly on the basis of operational profiles, and deterministically in order to perform different testing strategies. We have applied our approach with a large German OEM in different development stages of active safety and energy management functionalities. The test cases were executed in model-in-the-loop and in hardware-in-the-loop simulation. Errors were identified with our approach both in the requirement specification and in the implementation that were not discovered before. Sebastian Siegl, Kai-Steffen Jens Hielscher, Reinhard German, Christian Berger 0001 |
DATE | 4 |
| 2010 | Supporting Agile Change Management by Scenario-Based Regression SimulationabstractMany system-development projects today are mainly driven by the complexity of their software interacting with sensors or actuators in an embedded context. Autonomous vehicle development is a domain where it seems inevitably necessary to apply modern development techniques to cope with complexity, increase development efficiency, and ensure appropriate quality. Furthermore, changes that are triggered by customers or inventions of competitors, as well as bugs, enforce a comprehensible, if necessary, yet agile development process with stringent quality management. In this paper, we describe the agile efficiency- and quality-focused change management mainly based on scenario-driven regression simulation used in the CarOLO project for the development of an autonomously driving vehicle to compete in the 2007 Defense Advanced Research Projects Agency (DARPA) Urban Challenge program. The main contribution is the demonstration of the modern software engineering techniques' applicability to develop distributed embedded systems. Christian Berger 0001, Bernhard Rumpe |
IEEE Trans. Intell. Transp. Syst. | 1 |