Skip to content

Navigating Development of Cyber-Physical Systems through Inconsistency Scenarios

· 0 citations · 24 references

TL;DR

Results indicate that inconsistency scenarios effectively raise awareness of inconsistency-related risks, support self-assessment, and facilitate structured discussion of (in)consistency management in complex CPS development contexts.

View source

Similar papers

The Journal of Systems & Software

An interdisciplinary network of influencing factors is derived that makes explicit the dependencies between consistency mechanisms, organizational and technical conditions, and key agility outcomes such as responsiveness, transparency, and the realizability of development increments.

Albert Albers, A. Koziolek, Thomas Alexander Voelk et al. · 0 citations
Preprint Jul 2026

A Conceptual Framework for Refining Influence Knowledge from Simulation Evidence in Cyber-Physical Systems

Cyber-physical systems (CPS) are typically developed by multiple stakeholders who produce artefacts tailored to their specific domains of expertise. The behaviour of these systems emerges from the interaction between those artefacts and their operational environment. Simulation and co-simulation have become essential approaches for analysing CPS behaviour and, through simulation campaigns, developers can explore system responses under changing conditions, including interactions with the environment. However, the lack of details and understanding of some environmentmediated interactions (typically the ones beyond direct sensing and actuation), which remain unmodelled due to their complexity, a lack of time, or a lack of domain experience, hinders the proper comprehension and exploitation of simulation results. To address these limitations, we propose a conceptual framework leveraging the novel concept of Influences to support the iterative and incremental refinement of simulation campaigns and deepen the understanding of the system behaviour. We demonstrate the proposed approach through a case study involving a mobile robot implemented using Simulink/Gazebo co-simulation.

Bárbara da Silva Oliveira, Julien Deantoni, Nicolas Ferry · 0 citations
Review Nov 2026

Accounting for Emergent Behavior in Built Environment Planning and Decision-Making

The built environment increasingly involves tightly coupled physical, spatial, logical, and cyber interactions that can generate unexpected emergent behaviors beyond original system designs. These behaviors introduce uncertainty into construction and infrastructure planning and management, often negatively affecting productivity, safety, and resilience. Although emergent behavior is well-established in systems engineering, its systematic consideration in built environment research remains limited, with existing studies relying on ad hoc, reactive approaches rather than proactive modeling and analysis. This study conducts a literature review of construction and infrastructure engineering and management studies alongside foundational systems engineering research on emergence. Based on this synthesis, a formal taxonomy of emergent behavior in the built environment is developed, identifying four distinctive types based on the nature of underlying interactions, level of complexity, and boundaries of information available. Building on this taxonomy, a three-step framework (i.e., classification, operationalization, and implementation) is proposed to guide the systematic identification and analysis of emergent behaviors. To demonstrate practical relevance, the framework is applied to a case study on heavy equipment planning for debris sorting during demolition operations. The case study empirically identified emergent productivity patterns arising from spatial interactions among excavators and quantifies their impacts across different operational stages using real-world, lab-scale simulation. The findings illustrate how emergent behavior can be incorporated into planning decisions to optimize excavator configurations, thereby enhancing operational efficiency and supporting more sustainable demolition practices.

Hiba Jalloul, Juyeong Choi · 0 citations
Conference Open access 2026

Towards Agentic Support for the Chaos Engineering of Cyber-Physical Systems

: Cyber-Physical Systems (CPS) require rigorous robustness testing, yet this activity remains largely manual and dependent on expert knowledge. Chaos engineering provides a structured methodology through characterizing the system, defining metrics, formulating hypotheses, and planning perturbations. However, it lacks systematic support. This paper investigates how AI can assist the systematic design of chaos engineering experiments for CPS. We show how the different phases of chaos engineering can be adapted to CPS contexts and how they can be effectively and efficiently supported by a multi-agent architecture, with GPT-4o mini powered phase-specific agents providing detailed justifications while keeping a human analyst in the loop either at the phase level or through global iterations. Preliminary results from three industrial case studies show significant benefits from AI assistance, with around 50% efficiency gains in the design phase while improving coverage. Beyond the CPS domain, we also discuss applicability to other target domains (e.g. industrial or financial systems) and properties like secure chaos engineering.

A. Chokki, C. Ponsard, Jean-François Daune · 0 citations
Preprint Aug 2026

JTA: Joint Testability Architecture for Scenario-Based Validation of Safety-Critical Software

Validation adequacy in safety-critical software depends on more than the system under test. Critical scenarios must be constructed under controlled conditions, execution evidence must be aligned into verdict-ready form, and abnormal outcomes must be attributable to actionable causes. Existing testability research remains largely artifact-centric and offers little architectural support for reasoning about the combined capability of the scenario, the test system, and the system under test. Joint Testability Architecture (JTA) addresses this gap by treating those three elements as a single object of analysis and design. It characterizes validation capability along three dimensions--controllability, observability, and isolability--and organizes them through three domains, three bridges, and an analysis-design-evaluation-refinement loop. JTA also introduces scenario contracts, joint capability assessment, validation blind-spot identification, and bridge-oriented design actions that map capability gaps to concrete improvements in control points, evidence organization, and attribution boundaries. An illustrative analysis of ArduPilot failsafe validation shows that link-loss scenarios are comparatively mature, whereas state-estimation anomaly scenarios remain harder to validate because evidence alignment and attribution semantics are weaker. JTA is not a replacement for existing testing or safety-analysis techniques; it provides an architectural basis for modeling, designing, and assessing scenario-based validation in safety-critical software.

Wenyao Xue, Jiandi Wang, Yichen Wang · 0 citations
Open access 2026

A Design Science Approach to Bridging Operational Cyber Detection and Strategic Crisis Management

Cyber threats are increasing in scale and complexity in an increasingly interconnected world, as reflected by several high-profile incidents in recent years. Such crises often require organizations to make difficult decisions under time pressure while balancing competing priorities, uncertainty, and limited resources. Effective cyber incident management therefore depends not only on technical capabilities, but also on the availability of appropriate tools and training for organizational response. This study is based on the premise that access to relevant information during an incident is essential, and that effective information flow is critical for successful coordination and decision-making. To address this, we investigate how operational knowledge can be translated into strategic insight through the design and development of a prototype artifact termed the Cyber Crisis Chess Board. The artifact is intended to support the presentation, analysis, and use of incident-related information, particularly in full-scale cyber exercises involving multiple organizational levels. The study follows a Design Science Research approach. The prototype was evaluated through an applied cyber-range exercise involving seven participants in Gjøvik and a discussion-based session involving 35 participants in Ålesund. Qualitative feedback from the exercise settings and affiliated organizations was synthesized through thematic analysis. The prototype was evaluated in an applied experiment at the ncr, using qualitative feedback from participants as well as input from technology clusters in Norway. The findings were mixed: some participants questioned the usefulness of the tool for training, whereas others expressed strong interest in adopting it within their own exercise settings. Despite this variation, the study demonstrates the technical feasibility of the proof-of-concept artifact in a realistic cyber-range exercise involving a ransomware scenario. The evaluation does not establish effectiveness across all supported incident scenarios, but provides a foundation for further research on organizational cyber crisis management and strategic decision-making support in cyber-range training. Future development should focus on severity-aware escalation, richer situational-awareness information, integration with existing organizational crisis-management systems, and evaluation across additional incident scenarios.

Lundli Sivert, Ehtesham Hashmi, M. Yamin et al. · 0 citations