21
ESEC/FSE 2015 Bergamo, 02/09/2015 Combining Genetic Algorithms and Constraint Programming to Support Stress Testing of Task Deadlines Stefano Di Alesio 1,2 Lionel Briand 2 Shiva Nejati 2 Arnaud Gotlieb 1 1 Certus Centre for Software V&V Simula Research Laboratory Norway 2 Interdisciplinary Centre for Reliability, Security and Trust (SnT) University of Luxembourg Luxembourg 1 2

Combining genetic algoriths and constraint programming to support stress testing of task deadlines

Embed Size (px)

Citation preview

ESEC/FSE 2015

Bergamo, 02/09/2015

Combining Genetic Algorithms and Constraint Programming

to Support Stress Testing of Task Deadlines

Stefano Di Alesio 1,2

Lionel Briand 2

Shiva Nejati 2

Arnaud Gotlieb 1

1 Certus Centre for Software V&V

Simula Research Laboratory

Norway

2 Interdisciplinary Centre for Reliability, Security and Trust (SnT)

University of Luxembourg

Luxembourg

1 2

We present GA+CP: a search strategy to identify

scenarios likely to violate task deadlines in RTES

Stefano Di Alesio โ€“ 2/21

Problem Statement: Stress Testing of Task

Deadlines in Real Time Embedded Systems (RTES)

Key Results: Efficiency, Effectiveness,

Diversity and Scalability

Proposed Solution: Search for worst-case

schedules with a combined GA+CP strategy

Safety-critical RTES have to meet strict Performance

Requirements to be deemed safe for operation

Real-Time Embedded System (RTES)

Embedded SoftwareSensors Actuators

Operating

Environment

Computing Platform

Stefano Di Alesio โ€“ 3/21

Systematic stress and performance testing is highly

recommended when certifying safety-critical RTES

IEC 61508 deems stress testing as

highly recommended for SIL 3-4

Stress Testing: โ€œTesting in which a system is subjected to [โ€ฆ]

harsh inputs [โ€ฆ] with the intention of breaking itโ€

โ€” Boris Beizer

Arrival times for aperiodic tasks Worst-case scenarios

Stefano Di Alesio โ€“ 4/21

0

1

2

3

4

5

6

7

8

9

10

11

12

13

14

RTES usually have concurrent interdependent tasks

executed by a priority-driven preemptive scheduler

๐’‹๐Ÿ

๐’‚๐’•๐Ÿ๐ŸŽ

๐’…๐’๐Ÿ๐ŸŽ

๐’‹๐Ÿ

๐’‚๐’•๐Ÿ๐ŸŽ

๐’…๐’๐Ÿ๐ŸŽ

๐’‹๐ŸŽ

๐’‚๐’•๐ŸŽ๐ŸŽ

๐’…๐’๐ŸŽ๐ŸŽ

๐’“๐Ÿ๐Ÿ

๐’‚๐’•๐Ÿ๐Ÿ๐’‚๐’•๐ŸŽ๐Ÿ

๐’…๐’๐Ÿ๐Ÿ๐’‚๐’•๐Ÿ๐Ÿ

๐’„ = ๐Ÿ

๐’•๐’“๐’Š๐’ˆ๐’ˆ๐’†๐’“๐’๐’๐’„๐’Œ

๐’•๐’“๐’Š๐’ˆ๐’ˆ๐’†๐’“

๐’๐’๐’„๐’Œ

๐’๐’๐’„๐’Œ

๐’๐’๐’„๐’Œ

Stefano Di Alesio โ€“ 5/21

Tasks can trigger other tasks, or share

computational resources with them

Each task has a deadline (i.e., latest

finishing time) w.r.t. its arrival time

Some task properties depend on the

environment, others are design choices

Periodic Triggered Resource Aperiodic

0

1

2

3

4

5

6

7

8

9

Particular sequences of arrival times may

determine scenarios violating task deadlines

๐’‹๐ŸŽ, ๐’‹๐Ÿ, ๐’‹๐Ÿ arrive at ๐’‚๐’•๐ŸŽ, ๐’‚๐’•๐Ÿ, ๐’‚๐’•๐Ÿ and

must finish before ๐’…๐’๐ŸŽ, ๐’…๐’๐Ÿ, ๐’…๐’๐Ÿ

๐’‹๐Ÿ can miss its deadline ๐’…๐’๐Ÿdepending on when ๐’‚๐’•๐Ÿ occurs!

0

1

2

3

4

5

6

7

8

9

๐’‹๐Ÿ

๐’‚๐’•๐Ÿ

๐’…๐’๐Ÿ

๐’‹๐Ÿ

๐’‚๐’•๐Ÿ

๐’…๐’๐Ÿ

๐’‹๐ŸŽ

๐’‚๐’•๐ŸŽ

๐’…๐’๐ŸŽ

๐’„ = ๐Ÿ

๐’•๐’“๐’Š๐’ˆ๐’ˆ๐’†๐’“

๐’‹๐Ÿ

๐’‚๐’•๐Ÿ

๐’…๐’๐Ÿ

๐’‹๐Ÿ

๐’‚๐’•๐Ÿ

๐’…๐’๐Ÿ

๐’‹๐ŸŽ

๐’‚๐’•๐ŸŽ

๐’…๐’๐ŸŽ

๐’„ = ๐Ÿ

๐’•๐’“๐’Š๐’ˆ๐’ˆ๐’†๐’“

A sequence of arrival times which is likely to violate

a task deadline characterizes a stress test case

Stefano Di Alesio โ€“ 6/21

Periodic Triggered Aperiodic Periodic Triggered Aperiodic

Several techniques have been used for solving this

problem, but each has its own drawbacks

Formal Verification Testing

Scheduling

Theory

Model

Checking

Performance

Engineering

Genetic

Algorithms

Constraint

Programming

BackgroundQueuing

Theory

Fixed-point

Computation

Practice and

ToolsMetaheuristics

Artificial

Intelligence

Key

FeaturesTheorems

Symbolic

Execution

Dynamic

Analysis

Randomized

Search

Complete

Search

Drawbacks AssumptionsComplex

Modeling

Non

SystematicIneffective [1]

Inefficient [1],

Low diversity

Stefano Di Alesio โ€“ 7/21

[1] Di Alesio, S., Nejati, S., Briand, L., and Gotlieb, A. (2013). Stress Testing of Task Deadlines: A Constraint Programming Approach. In

Software Reliability Engineering (ISSRE), 2013 IEEE 24th International Symposium on, pages 158โ€“167. IEEE.

GA is efficient and diverse: quickly generates test

cases involving different interactions between tasks

CP is effective: generates test cases that

are more likely to violate task deadlines

GA + CP

Stefano Di Alesio โ€“ 8/21

[2] Nejati, S., Di Alesio, S., Sabetzadeh, M., Briand, L.: Modeling and Analysis of CPU Usage in Safety-critical Embedded Systems to

Support Stress Testing. In: Model Driven Engineering Languages and Systems (MODELS), pp. 759โ€“775. Springer (2012)

Automated Search

Optimization ProblemFind arrival times that maximize the chance of

violating task deadlines

SolutionsTask arrival times likely to violate

task deadlines

Deadline Misses

Analysis

System Platform

System Design Design and Platform Models Timing and concurrency information about

the RTES software and computing platform

INPUT

OUTPUT๐’‚๐’•๐Ÿ = ๐Ÿ๐Ÿ‘๐’‚๐’•๐Ÿ = ๐Ÿ‘๐Ÿ•โ€ฆ

Stress Test Cases

UML/MARTE Modeling [2]

We cast the generation of stress test cases as an

Optimization Problem over the task arrival times

Genetic Algorithms (GA) +

Constraint Programming (CP)

โ€ขTriggering Relationship:

๐’•๐’“๐’Š๐’ˆ๐’ˆ๐’†๐’“๐’” ๐’‹๐ŸŽ, ๐’‹๐Ÿโ€ขDependency Relationship:

๐’…๐’†๐’‘๐’†๐’๐’…๐’†๐’๐’• ๐’‹๐Ÿ, ๐’‹๐Ÿ , ๐’…๐’†๐’‘๐’†๐’๐’…๐’†๐’๐’•(๐’‹๐Ÿ, ๐’‹๐Ÿ)โ€ข Impacting Relationship: ๐’Š๐’Ž๐’‘๐’‚๐’„๐’•๐’” ๐’‹๐Ÿ‘, ๐’‹๐Ÿ , ๐’Š๐’Ž๐’‘๐’‚๐’„๐’•๐’” ๐’‹๐Ÿ, ๐’‹๐Ÿ ,๐‘ฐ ๐’‹๐Ÿ = {๐’‹๐Ÿ, ๐’‹๐Ÿ‘}

โ€ขObservation Interval: ๐‘ป = ๐ŸŽ, ๐Ÿ—โ€ขNumber of cores: ๐’„ = ๐Ÿโ€ขSet of Tasks: ๐‘ฑ = {๐’‹๐ŸŽ, ๐’‹๐Ÿ, ๐’‹๐Ÿ, ๐’‹๐Ÿ‘}โ€ขPriority of Tasks: ๐’‘๐’“๐’Š๐’๐’“๐’Š๐’•๐’š ๐’‹๐’Š = ๐’Šโ€ขPeriod of Tasks: ๐’‘๐’†๐’“๐’Š๐’๐’… ๐’‹๐Ÿ = ๐Ÿ“โ€ขMin/Max Inter-arrival time of Tasks:

๐’Ž๐’Š๐’_๐’Š๐’‚ ๐’‹๐ŸŽ = ๐Ÿ“,๐’Ž๐’‚๐’™_๐’Š๐’‚ ๐’‹๐ŸŽ = ๐Ÿ๐ŸŽโ€ขDuration of Tasks: ๐’…๐’–๐’“๐’‚๐’•๐’Š๐’๐’ ๐’‹๐ŸŽ = ๐Ÿ‘โ€ขDeadline of Tasks: ๐’…๐’†๐’‚๐’…๐’๐’Š๐’๐’† ๐’‹๐ŸŽ = ๐Ÿ•

0

1

2

3

4

5

6

7

8

9

๐’•๐’“๐’Š๐’ˆ๐’ˆ๐’†๐’“

๐’‹๐ŸŽ ๐’‹๐Ÿ ๐’‹๐Ÿ‘๐’“๐Ÿ๐Ÿ ๐’‹๐Ÿ

๐’๐’๐’„๐’Œ

๐’๐’๐’„๐’Œ

๐’๐’๐’„๐’Œ

Static Properties depend on the RTES design (are

known), and express constraints on task execution

Stefano Di Alesio โ€“ 9/21

Assumption 1: Time is discretized in time quanta

Assumption 2: The time for switching context between

tasks is negligible w.r.t. a time quantum

๐’„ = ๐Ÿ

Aperiodic Triggered Resource Periodic Aperiodic

Independent Propertiesโ€ขNumber of Task Executions: ๐’•๐’‚๐’”๐’Œ_๐’†๐’™๐’†๐’„๐’–๐’•๐’Š๐’๐’๐’” ๐’‹๐ŸŽ = ๐Ÿ,๐’•๐’‚๐’”๐’Œ_๐’†๐’™๐’†๐’„๐’–๐’•๐’Š๐’๐’๐’” ๐’‹๐Ÿ‘ = ๐Ÿ

โ€ขArrival time of Aperiodic Task Exec.:

๐’‚๐’“๐’“๐’Š๐’—๐’‚๐’_๐’•๐’Š๐’Ž๐’† ๐’‹๐ŸŽ, ๐ŸŽ = ๐ŸŽ,๐’‚๐’“๐’“๐’Š๐’—๐’‚๐’_๐’•๐’Š๐’Ž๐’† ๐’‹๐Ÿ‘, ๐Ÿ = ๐Ÿ•

Dynamic Properties depend on the RTES runtime

behavior, and are not known prior to the analysis

Stefano Di Alesio โ€“ 10/21

Dependent Propertiesโ€ขActive time of Task Executions:

๐’‚๐’„๐’•๐’Š๐’—๐’† ๐’‹๐ŸŽ, ๐ŸŽ, ๐ŸŽ = ๐ŸŽ, ๐’‚๐’„๐’•๐’Š๐’—๐’† ๐’‹๐ŸŽ, ๐ŸŽ, ๐Ÿ = ๐Ÿโ€ขStart/End time of Task Executions:

๐’”๐’•๐’‚๐’“๐’• ๐’‹๐ŸŽ, ๐ŸŽ = ๐ŸŽ, ๐’†๐’๐’… ๐’‹๐ŸŽ, ๐ŸŽ = ๐Ÿ‘โ€ขPreempted Time Quanta in :

๐’‘๐’“๐’†๐’†๐’Ž๐’‘๐’•๐’†๐’… ๐’‹๐ŸŽ, ๐ŸŽ, ๐Ÿ = ๐Ÿ โˆ’ ๐ŸŽ โˆ’ ๐Ÿ = ๐Ÿโ€ขSystem Load: ๐’๐’๐’‚๐’… ๐ŸŽ = ๐Ÿโ€ขDeadline Miss of Task Executions:

๐’…๐’†๐’‚๐’…๐’๐’Š๐’๐’†_๐’Ž๐’Š๐’”๐’” ๐’‹๐ŸŽ, ๐ŸŽ = ๐Ÿ‘ โˆ’ ๐Ÿ” = โˆ’๐Ÿ‘

Independent Properties characterize stress test cases

Dependent Properties characterize the expected reaction of the

system to the events modeled by the Independent properties

0

1

2

3

4

5

6

7

8

9

๐’•๐’“๐’Š๐’ˆ๐’ˆ๐’†๐’“

๐’‹๐ŸŽ ๐’‹๐Ÿ ๐’‹๐Ÿ‘๐’“๐Ÿ๐Ÿ ๐’‹๐Ÿ

๐’๐’๐’„๐’Œ

๐’๐’๐’„๐’Œ

๐’๐’๐’„๐’Œ

๐’„ = ๐Ÿ

Aperiodic Triggered Resource Periodic Aperiodic

Stefano Di Alesio โ€“ 11/21

Both GA and CP cast the search for arrival times that

violate task deadlines as an optimization problem

[3] L. Briand, Y. Labiche, and M. Shousha, โ€œUsing Genetic Algorithms for Early Schedulability Analysis and Stress Testing in Real-Time

Systemsโ€, Genetic Programming and Evolvable Machines, vol. 7 no. 2, pp. 145-170, 2006

[4] Di Alesio, S., Nejati, S., Briand, L., and Gotlieb, A. (2014). Worst-Case Scheduling of Software Tasks โ€“ A Constraint Optimization

Model to Support Performance Testing. In Principles and Practice of Constraint Programming (CP 2014)

Properly rewards scenarios

with deadline misses [3]

Genetic Algorithms [3] Constraint Programming [4]

Static Properties of Tasks Chromosomes Properties Constants

Dynamic Properties of Tasks Chromosomes Genes Variables

OS Scheduler Behavior Chromosomes Evaluation Constraints

Deadline Misses Requirement Fitness Function Objective Function

Efficient and diverse,

but ineffective

Effective, but inefficient

and non-diverse

๐‘ญ๐‘ซ๐‘ด =

๐’‹,๐’Œ

๐Ÿ๐’…๐’†๐’‚๐’…๐’๐’Š๐’๐’†_๐’Ž๐’Š๐’”๐’”(๐’‹,๐’Œ)

Stefano Di Alesio โ€“ 12/21

Therefore, we looked into a way to retain the

practical advantages of GA and CP in isolation

Search Space

๐’™๐Ÿ

๐’™๐Ÿ

๐’™๐Ÿ‘

๐’™๐Ÿ’

๐’™๐Ÿ“

๐’™๐Ÿ”

๐’š๐Ÿ

๐’š๐Ÿ

๐’š๐Ÿ‘

๐’š๐Ÿ’

๐’š๐Ÿ“

๐’š๐Ÿ”๐’›๐Ÿ

๐’›๐Ÿ

๐’›๐Ÿ‘

๐’›๐Ÿ’

๐’›๐Ÿ“

๐’›๐Ÿ”๐’šโˆ—

๐’™โˆ—

1. GA-step: ๐’™๐Ÿ, ๐’š๐Ÿ, ๐’›๐Ÿ evolve into ๐’™๐Ÿ”, ๐’š๐Ÿ”, ๐’›๐Ÿ”2. CP-step: ๐’™๐Ÿ”, ๐’š๐Ÿ”, ๐’›๐Ÿ” are optimized into ๐’™โˆ—, ๐’šโˆ—, ๐’›โˆ—

= ๐’›โˆ—

The key idea behind GA+CP is to run complete searches

with CP in the neighborhood of solutions found by GA

2-steps strategy

Stefano Di Alesio โ€“ 13/21

GA+CP only looks in the neighborhood of tasks that

can have an impact on task deadlines in a solution

๐’‹๐Ÿ and ๐’‹๐Ÿ‘ have an indirect impact on ๐’‹๐Ÿ’because they have higher priority than ๐’‹๐Ÿ

๐‘ฑโˆ— ๐’™ = ๐’‹๐Ÿ’๐‘ฐ๐’‹๐Ÿ’ ๐’™ = ๐’‹๐Ÿ , ๐’‹๐Ÿ, ๐’‹๐Ÿ‘, ๐’‹๐Ÿ’๐’‚๐’“๐’“๐’Š๐’—๐’‚๐’_๐’•๐’Š๐’Ž๐’† ๐’‹๐ŸŽ, ๐ŸŽ = ๐ŸŽ๐Ÿ โˆ’ ๐‘ซ โ‰ค ๐’‚๐’“๐’“๐’Š๐’—๐’‚๐’_๐’•๐’Š๐’Ž๐’†(๐’‹๐Ÿ, ๐ŸŽ) โ‰ค ๐Ÿ +๐‘ซ๐Ÿ‘ โˆ’ ๐‘ซ โ‰ค ๐’‚๐’“๐’“๐’Š๐’—๐’‚๐’_๐’•๐’Š๐’Ž๐’†(๐’‹๐Ÿ, ๐ŸŽ) โ‰ค ๐Ÿ‘ +๐‘ซ๐Ÿ” โˆ’ ๐‘ซ โ‰ค ๐’‚๐’“๐’“๐’Š๐’—๐’‚๐’_๐’•๐’Š๐’Ž๐’†(๐’‹๐Ÿ‘, ๐ŸŽ) โ‰ค ๐Ÿ” +๐‘ซ๐Ÿ‘ โˆ’ ๐‘ซ โ‰ค ๐’‚๐’“๐’“๐’Š๐’—๐’‚๐’_๐’•๐’Š๐’Ž๐’†(๐’‹๐Ÿ’, ๐ŸŽ) โ‰ค ๐Ÿ‘ +๐‘ซ

๐’™๐‘ฎ๐‘จ = ๐ŸŽ , ๐Ÿ , ๐Ÿ‘ , ๐Ÿ” , ๐Ÿ‘ ๐’™๐‘ฎ๐‘จ+๐‘ช๐‘ท = ๐ŸŽ , ๐Ÿ , ๐Ÿ‘ , ๐Ÿ’ , ๐Ÿ‘

๐’‹๐Ÿ has a direct impact on ๐’‹๐Ÿ’because it depends on ๐’‹๐Ÿ’

Dependent tasks Dependent tasks

Stefano Di Alesio โ€“ 14/21

We compared GA+CP with GA and CP in isolation

on 5 systems from safety-critical domains

RQ1 โ€“ Efficiency: time needed

to generate test cases

RQ2 โ€“ Effectiveness: revealing

power of worst-case scenarios

RQ3 โ€“ Diversity: capability to exercise the

system w.r.t. different patterns (i.e., coverage)

DomainTasks

LogsizePeriodic Aperiodic

ICS: Ignition Control System Automotive 3 3 446.7

CCS: Cruise Control System Automotive 8 3 551.6

UAV: Unmanned Air Vehicle Avionics 12 4 671.5

GAP: Generic Avionics Platform Avionics 15 8 709.4

HPSS: Herschel-Planck Satellite System Aerospace 23 9 836.6

RQ4 โ€“ Scalability: extent to which the

system size affects the efficiency

Stefano Di Alesio โ€“ 15/21

Metricsโ€ขComputation time ๐’•(๐’™) of a solution ๐’™ โˆˆ ๐‘ฟโ€ขSum ๐’”(๐’™) of time quanta in deadline misses

๐’”โˆ— ๐’™๐’”โˆ— ๐‘ฟ๐’”

โˆ—

โ€ขNumber ๐’(๐’™) of tasks that miss a deadline

๐’โˆ— ๐’™๐’โˆ— ๐‘ฟ๐’

โˆ—

โ€ขNumber ๐’Ž(๐’™) of task execs. that miss a deadline

๐’Žโˆ— ๐’™๐’Žโˆ— ๐‘ฟ๐’”

โˆ—

0

1

2

3

4

5

6

7

8

9

๐’‹๐Ÿ

๐’‚๐’•๐Ÿ

๐’…๐’๐Ÿ

๐’‹๐Ÿ

๐’‚๐’•๐Ÿ

๐’…๐’๐Ÿ

๐’‹๐ŸŽ

๐’‚๐’•๐ŸŽ

๐’…๐’๐ŸŽ

๐’„ = ๐Ÿ

๐’•๐’“๐’Š๐’ˆ๐’ˆ๐’†๐’“

๐‘ฟ = ๐’™

๐’™ = ๐Ÿ , ๐Ÿ‘ , ๐Ÿ’

๐’” = ๐Ÿ๐’ = ๐Ÿ๐’Ž = ๐Ÿ

Attributesโ€ขRQ1 โ€“ Efficiency ๐œผ: computation time of the best solution

๐œผ๐’” = ๐’• ๐’™๐’”โˆ— ๐œผ๐’ = ๐’• ๐’™๐’

โˆ— ๐œผ๐’Ž = ๐’• ๐’™๐’Žโˆ—

โ€ขRQ2 โ€“ Effectiveness ๐œฟ: metric value of the best solution

๐œฟ๐’” = ๐’”โˆ— ๐œฟ๐’ = ๐’

โˆ— ๐œฟ๐’Ž = ๐’Žโˆ—

โ€ขRQ3 โ€“ Number ๐‘ต of best solutions

๐‘ต๐’” = ๐‘ฟ๐’”โˆ— ๐‘ต๐’ = ๐‘ฟ๐’

โˆ— ๐‘ต๐’Ž = ๐‘ฟ๐’Žโˆ—

โ€ขRQ3 โ€“ Diversity ๐œน: extent to which solutions exercise the

system in different ways

We formalize aspects of practical interest related to

the Research Questions as metrics and attributesPeriodic Triggered Aperiodic

Stefano Di Alesio โ€“ 16/21

High diversity entails that test cases thoroughly

exercise interactions between task executions

0

1

2

3

4

5

6

7

8

9

๐’‹๐ŸŽ

0

1

2

3

4

5

6

7

8

9

๐’‹๐ŸŽ

0

1

2

3

4

5

6

7

8

9

๐’‹๐ŸŽ

0

1

2

3

4

5

6

7

8

9

๐’‹๐ŸŽ

0

1

2

3

4

5

6

7

8

9

0

1

2

3

4

5

6

7

8

9

๐’‹๐ŸŽ๐’‹๐ŸŽ

Diversity ๐œน๐’‰ w.r.t.

execution shift

Diversity ๐œน๐’“ w.r.t.

execution pattern

Diversity ๐œน๐’† w.r.t.

number of executions

๐œน๐’‰ = |๐Ÿ โˆ’ ๐ŸŽ| + |๐Ÿ— โˆ’ ๐Ÿ•| = ๐Ÿ’ ๐œน๐’“ = |๐Ÿ โˆ’ ๐Ÿ“| + |๐Ÿ’ โˆ’ ๐ŸŽ| = ๐Ÿ– ๐œน๐’† = ๐Ÿ โˆ’ ๐Ÿ = ๐Ÿ

Stefano Di Alesio โ€“ 17/21

In GA+CP, we instructed CP to terminate the local

search after two hours

The time taken by CP to terminate the local searches was not significant

with respect to the time taken by GA to generate its solutions

Stefano Di Alesio โ€“ 18/21

GA+CP achieves trade-off between the efficiency

and diversity of GA, and the effectiveness of CP

Wilcoxon rank-sum test (GA+CP vs GA)

Wilcoxon signed-rank test (GA+CP vs CP)

๐œผ ๐‘ฎ๐‘จ + ๐‘ช๐‘ท โ‰ˆ ๐œผ ๐‘ฎ๐‘จ > ๐œผ(๐‘ช๐‘ท)๐œฟ ๐‘ฎ๐‘จ + ๐‘ช๐‘ท โ‰ˆ ๐œฟ ๐‘ช๐‘ท > ๐œฟ(๐‘ฎ๐‘จ)๐œน ๐‘ฎ๐‘จ + ๐‘ช๐‘ท โ‰ˆ ๐œน ๐‘ฎ๐‘จ > ๐œน(๐‘ช๐‘ท)

Stefano Di Alesio โ€“ 19/21

The effect the system size has over the efficiency of

GA+CP (RQ4 โ€“ Scalability) is similar to that of GA

Our experiment was performed on 5 case studies

โ†’ No quantitative scalability study

In our experiments, ๐‘ซ โ‰ˆ๐‘ป

๐Ÿ๐ŸŽ๐ŸŽproved to yield satisfactory results

โ†’ But in larger case studies ๐‘ซ might also have to be larger

CP (โ€ข) GA (โ– ) GA+CP (โ–ฒ)

ICS CCS UAV GAP HPSS ICS CCS UAV GAP HPSS ICS CCS UAV GAP HPSS

Stefano Di Alesio โ€“ 20/21

Future directions include investigating test suite

reduction strategies and multiobjective optimization

Deadline Misses Response TimeCPU Usage

Multiobjective optimization allows to investigate scenarios

where multiple requirements are close to be violated

Find the minimal set of test cases that retain some relevant property

(e.g.: cover all the task executions predicted to miss a deadline)

Execution 1 Execution 2 Execution 3 Execution 4 Execution 5

Test Case 1 X X

Test Case 2 X X

Test Case 3 X X

Test Case 4 X X

In summary, GA+CP casts stress testing of task

deadlines misses as an optimization problem

GA explores the search space, and CP

exploits the solutions found by GA

The CP search is complete, but only along

โ€œpromisingโ€ directions (impacting tasks)

Stefano Di Alesio โ€“ 21/21

Questions?

This design yields trade-off in efficiency,

diversity (GA) and effectiveness (CP)