<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>June</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>What Can Be Learnt from Engineering Safety Critical Partly-Autonomous Systems when Engineering Recommender Systems</article-title>
      </title-group>
      <contrib-group>
        <aff id="aff0">
          <label>0</label>
          <institution>ICS-IRIT, University of Toulouse</institution>
          ,
          <addr-line>118, route de Narbonne, 31042 Toulouse</addr-line>
          ,
          <country country="FR">France</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Yannick Deleris AIRBUS Operations</institution>
          ,
          <addr-line>316 Route de Bayonne,3 1060 Toulouse</addr-line>
          ,
          <country country="FR">France</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2016</year>
      </pub-date>
      <volume>2</volume>
      <fpage>1</fpage>
      <lpage>24</lpage>
      <abstract>
        <p>Human-Automation Design main target is to design systems in such a way that the couple system operator performs as efficiently as possible. Means for such designs include identifying functions (on the system side) and tasks (on the operator's side) and balancing the allocation of tasks and functions between operators and the systems being operated. Allocating functions to the most suitable actor has been the early driver of function allocation [18]. The philosophy of recommender systems is that the system will provide a set of options for the users to select from. Such behavior can be easily connected to previous work on levels of automation as defined by Sheridan [34] and lessons can be drawn from putting together these two views. When these automations (including the one of recommender systems) are not adequately designed (or correctly understood by the operator), they may result in so called automation surprises [25, 32] that degrade, instead of enhance, the overall performance of the operations. This position paper identifies issues related to bringing recommender systems in the domain of safety critical interactive systems. While their advantages are clearly pointed out by their advocates, limitations are usually hidden or overlooked. We present this argumentation in the case of the ECAM (Electronic Centralised Aircraft Monitor) of which some behavior could be considered as similar to the one of a recommender sys-</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>tem. We also highlight some engineering aspects of
deploying recommender systems in the safety critical domain.</p>
    </sec>
    <sec id="sec-2">
      <title>Author Keywords</title>
      <p>Automation, recommender systems, transparent
automation, operator tasks, performance</p>
    </sec>
    <sec id="sec-3">
      <title>ACM Classification Keywords</title>
      <p>D.2.2 [Design Tools and Techniques]: Computer-aided
software engineering (CASE); H.5.3 [Group and Organization
Interfaces]</p>
    </sec>
    <sec id="sec-4">
      <title>Introduction</title>
      <p>
        Human-Automation Design main target is to design
systems in such a way that the couple system operator
performs as efficiently as possible. Allocating functions to the
most suitable actor has been the early driver of function
allocation as advocated by Fitts [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ]. Such work is known as
MABA-MABA (Men Are Better At âA˘ S¸ Machine Are
Better At) where the underlying philosophy is that automate
as many functions as possible was perceived as adequate
(see for instance [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]). This technology-centered view has
led to unsafe and unusable systems [
        <xref ref-type="bibr" rid="ref32">32</xref>
        ] and it became
clear that the design of usable partly-autonomous systems
is a difficult task.
      </p>
      <p>
        Recommender systems belong to this trend of work on
automation, even though that characteristic is not put forward
or even ignored by their designers and promoters. When
the word automation is connected to recommender systems
it is usually for explaining that the recommender system is
evolving autonomously as in “automated collaborative
filtering” used for instance in GroupLens [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ].
      </p>
      <p>
        When automation is not adequately designed, or correctly
perceived and then understood by the operator, they may
result in so called automation surprises [
        <xref ref-type="bibr" rid="ref33">33</xref>
        ] that degrade,
instead of enhance as expected, the overall performance
of the operations and might lead to incidents or even
accidents [
        <xref ref-type="bibr" rid="ref25">25</xref>
        ]. The issue of usability of recommenders
systems has also been identified in the early days [
        <xref ref-type="bibr" rid="ref35">35</xref>
        ] even
though only perceived as an interactive application being
used by users and not an interaction taking place with a
partly-autonomous system. Work in that domain focuses
on usefulness of the recommender systems and on their
usability or user experience [
        <xref ref-type="bibr" rid="ref20">20</xref>
        ].
      </p>
      <p>This paper argues that having an automation-centered view
on recommender systems helps to identify design issues
related to their user interfaces and could inform design
decisions and evaluation of these systems. Such a
perspective could also help understanding issues that have to be
addressed prior to the deployment of such systems in the
context of safety critical interactive systems.</p>
      <p>The next section proposes a short overview of the main
concepts related to automations and focuses on the human
aspects of automation. Then the paper positions
recommender systems within that context and highlights
similarities with other systems as well as their specificities. The
paper then presents the case study of the ECAM (Electronic
Centralised Aircraft Monitor) and how this system relates to
recommender systems. Last section lists design and
engineering issues related to the deployment of recommender
systems in the area of safety critical interactive systems.
Even though those levels can support the understanding
of automation they cannot be used as a mean for
assessing the automation of a system which has to be done at a
much finer grain i.e., “function” by “function”. However, if a
detailed description of the “functions” is provided they make
it possible to support both the decision and the design
process of migrating a function from the operator’s activity to
the system or vice versa.</p>
      <p>HIGH
LOW
10. The computer decides
everything, acts autonomously, ignoring
the human
9. Informs the human only if it, the
computer, decides to
8. Informs the human only if
asked, or
7. Executes automatically, then
necessarily informs the human,
and
6. Allows the human a restricted
time to veto before automatic
execution, or
5. Executes that suggestion if the
human approves, or
4. Suggests one alternative
3. Narrows the selection down to a
few, or
2. The computer offers a complete
set of decision/action alternatives,
or
1. The computer offers no
assistance: human must take all
decisions and actions</p>
      <p>
        As stated in [
        <xref ref-type="bibr" rid="ref27">27</xref>
        ], automated systems can operate at
specific levels within this continuum and automation can be
applied not only to the output functions but also to input
functions. Figure 2 presents the four-stage model of human
information processing as introduced in [
        <xref ref-type="bibr" rid="ref27">27</xref>
        ].
      </p>
      <p>
        The first stage refers to the acquisition and recording of
multiple forms of information. The second one involves
conscious perception, and manipulation of processed and
retrieved information in working memory. The third stage is
where decisions are accomplished by cognitive processes.
The last one contains the implementation of a response or
action consistent with decision made in the previous stage.
The first three stages in that model represent how the
operator processes the information that is rendered by the
interactive system. The last stage identifies the response
from the user that may correspond to providing input to the
controlled system by means of the interactive system (flow
of events from the user towards the controlled system.
The model in Figure 2 (about human information
processing) has a similar counterpart in system’s functions as shown
in Figure 3. Each of these functions can be automated
to different degrees. For instance, the sensory
processing stage (in Figure 2) could be migrated to the
information acquisition stage (in Figure 3) by developing hardware
sensors. The second stage in the human model could be
automated by developing inferential algorithms (as for
instance in recommender systems). The third stage involves
selection from several alternatives which can be easily
implemented with algorithms. The final stage called action
implementation refers to the execution of the choice.
Automation of this stage may involve different levels of
machine execution and could even replace physical effectors
(e.g., hand or voice) of the operator [
        <xref ref-type="bibr" rid="ref28">28</xref>
        ]. The stages of
human information processing as well as their corresponding
classes of system functions are used to analyze and
design which tasks are performed by the human operator and
which functions are performed by the system (also called
function allocation as defined in [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ]).
      </p>
      <p>
        Based on this theoretical framework, several techniques
and methods have been proposed to analyze, design and
evaluate human automation interaction. Proud et al.
proposed the LOA (Level Of Autonomy) Assessment Tool [
        <xref ref-type="bibr" rid="ref30">30</xref>
        ]
(based on a LOA Assessment Scale) which produces
analytical summaries of the appropriate LOA for particular
functions and has been applied to an Autonomous Flight
Management System. Cummings et al. [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ] identified a
refinement mechanism for the decision making step, to help
in deciding which one of the human or of the system should
perform a given decision task. More generally, techniques
based on cognitive task analysis, such as the one proposed
in [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ], help in understanding precisely the different tasks
that are actually performed by the human operator. Model
based approaches take advantage of task analysis and
propose to systematically ensure consistency and
coherence between task models and system behavioral
description [
        <xref ref-type="bibr" rid="ref22">22</xref>
        ]. Johansson et al. [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ] developed a simulation tool
to analyze the effect of the level of automation and
emphasize the importance of a simulation framework to have a
feedback on design choices before deploying the system.
Finally, several techniques have been coined to provide
support for formal verification of human automation
interaction [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ], which aim at providing tools for checking
conformance between what the system has to perform, and what
the user is responsible for. For each of these techniques
and methods, human automation interaction is dealt with as
a whole and thus focusing on goal-related tasks.
      </p>
    </sec>
    <sec id="sec-5">
      <title>Recommender systems as partly-autonomous system</title>
      <p>
        Recommender systems may be based on different
approaches. They may implement content-based filtering,
knowledge-based filtering, collaborative filtering or hybrid
filtering [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. We don’t describe here the various types of
recommender systems in details and encourage the
interested reader to see [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ] for a very detailed and pedagogic
survey. We here focus on content-based approaches for
recommender systems as it is a relevant filtering approach
for interactive cockpits. Figure 4 presents a typical
architecture of a content-based recommender system. The system
stores a set of items and each item is described
according to a set of attributes. In such systems the user is
described according to these attributes too, this description
being named user profile. According to the user profile and
the attributes of the set of items, the systems proposes to
the user a set of recommendations.
      </p>
      <p>
        Recommender Systems and Levels of Automation:
According to the levels of automation presented in
Figure 1 recommender systems typically fall within levels 2
to 4 depending on the number of alternatives presented to
the user. Rules for designing autonomous systems would
thus apply to recommender systems to avoid know issues
such as automation surprises [
        <xref ref-type="bibr" rid="ref32">32</xref>
        ] and [
        <xref ref-type="bibr" rid="ref25">25</xref>
        ]. Issue of
transparency of automation has been also identified for
recommender systems [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] while a process and a notation to
systematically engineer transparency for partly-autonomous
systems was proposed in [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ].
      </p>
      <p>
        Recommender Systems and systems functions: The
recommender system behavior in Figure 4 and the classes
of system functions in Figure 3 can be related as follows:
• Information acquisition: this stage corresponds to
the process in the recommender systems browsing
the internal source of items being candidates for
recommendation. Information can be entirely stored at
initialization or gathered during execution.
• Information analysis: this stage corresponds to the
recommender system process of correlating user
profile with items description.
• Decision and action selection: this stage
corresponds to the filtering process of the recommender
system selecting amongst the list of candidate items
and ranking them before presentation to the operator.
• Action implementation: this stage corresponds to
the presentation on the user interface of the selected
items to the operator. That presentation of
information can be sometimes enriched with argumentation
about the rationale for selecting items [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ]. It is also
important to note that, following that presentation of
information, user interaction is usually available
allowing users to browse the list of recommended items,
to access more information about them and to select
the desired one. Such operator behavior is taken
explicitly into account by the operator behavior model of
Figure 2 and detailed below.
      </p>
      <p>Recommender Systems and operators behavior: As
far as user activity is concerned the operator behavior
described in Figure 2 can be refined for describing interaction
with a recommender system.</p>
      <p>
        According to the four stages of human information
processing proposed in Figure 2 it is easy to relate to the
recommender system behavior:
• Sensory processing: while interacting with the
recommender system this activity would consist in all
operators’ information sensing both from the
recommender and from the system under use.
Localization of the information from the recommender system
might deeply impact that sensing.
• Perception/working memory: at this stage
information from the recommender system will be integrated
with the information presented by the system. It is
important to note that human errors such as
interference, overshooting a stop rule... [
        <xref ref-type="bibr" rid="ref31">31</xref>
        ] and thus should
be avoided (and is not possible detected, recovered
or mitigated).
• Decision making: this corresponds to the decision
of the operator for selecting one of the
recommendations presented by the recommender system (if more
than one is offered).
• Response selection: this is the actual selection of
one of the recommender system recommendation.
As stated above, that stage might involve additional
cycles within this 4 stages model (while operators
interact with the recommender systems e.g. browsing
the recommendation or accessing more information
about a given recommendation).
      </p>
      <p>The mapping between recommender system processes
and Parasuraman’s system functions as well as the
mapping between activities done with recommender systems
and Parasuraman’s stages of human information
processing, provides support to analyze the impact of the level of
automation of the recommender system functions on the
operators’ task.</p>
    </sec>
    <sec id="sec-6">
      <title>Illustrative example</title>
      <p>To exemplify the concept presented above in the context
of a safety critical system, we present a case study from
the avionics domain: the ECAM (Electronic Centralized
Aircraft Monitor) in the Airbus family. The ECAM is a system
that monitors aircraft systems (e.g., the engines) and
relays to the pilots data about their state (e.g., if their use is
limited due to a failure) and the procedures that have to be
achieved by the pilots to recover from the failure.
The ECAM system is composed of several systems. More
particularly, the Flight Warning System (FWS) is in charge
of the processing of data from the monitoring of the aircraft
systems. This processing enables: i) the display of
information about the status of the aircraft systems parameters
(using the System Display (SD)); ii) the display of warnings
about system failures and procedures that have to be
completed by the pilot to process the detected warning (using
the Warning Display (WD)) and iii) the production of aural
and visual alerts (using several lights and loudspeakers in
the cockpit).</p>
      <p>The SD and WD are displayed, in the cockpit of the A380,
on two separated Display Units (DU). These two DUs are
highlighted in Figure 5 and are part of the eight of DUs
composing the Control and Display System (CDS). The
CDS is the interactive system in aircraft cockpits (flight
decks) that offers various operational services of major
importance for flight crew. It displays aircraft parameters, and
enables the flying crew to graphically interact with these
parameters using a keyboard and a mouse (KCCU for
Keyboard and Cursor Control Unit) to control aircraft systems.
As presented in Figure 6, if the ECAM has created,
simultaneously, several warning messages, it sorts them, in order
to obtain a display order, according to three inhibition
mechanisms:
• Their priority: a priority is associated to each warning
message;
• FWS internal behavior: some warning messages
may be inhibited in case of presence of others
warning messages (for instance, the “APU fault” warning
message is not displayed if the “APU fire” is already
detected);
• The current flight phase: some warning messages
are only displayed when the aircraft is in a given flight
phase (for instance, flight management systems
failures are not displayed after landing).
Therefore, the warning messages are displayed (in the
processed display order) to the pilots, within the WD, with three
different colors, representing their priority level:
• Red warnings that require immediate actions from the
pilots (e.g., the loss of an engine);
• Amber warnings that require non-immediate actions
from the pilots (e.g., a fault within the APU);
• Green warnings that only require monitoring from the
pilots but do not present any danger.</p>
      <p>Figure 7 presents an example of the display of warning
messages (one red warning and three amber warnings)
and their associated recovery procedures on the ECAM.
In this example, the red warning (L1 in Figure 7) informs
the pilot that the autopilot is not working anymore.
Therefore, the first amber warning (L2 in Figure 7) informs the
pilot that the auto-thrust is not working anymore. The
corresponding recovery procedure (L3 in Figure 7) indicates
to the pilot that s/he has to take responsibility for the thrust
by moving the thrust levers. The second amber warning (L4
and L5 in Figure 7) informs the pilot that the flight control
laws are not working anymore. The corresponding recovery
procedures (L6 in Figure 7) indicates to the pilot that s/he
has to take responsibility for the aircraft speed that must be
under 0.82 MACH.
These warnings messages notification are similar to
recommendations in recommender systems (see, for instance,
the one presented in Figure 4) in the sense that the
system sorts the warning messages and their associated
recovery procedures and proposes, to the pilots, an order
for their treatment. In this example, the system indicates
to the pilot that the auto-thrust management function is off
and indicates to the pilot that s/he shall manually move the
thrust levers (lines 2 and 3 in Figure 4). Using
Parasuraman’s models, we can analyze that the system fall within
level 4 of automation (Figure 1). In other cases, the
system may propose a list of prioritized alarms and recovery
procedures, which make the system fall within level 3 of
automation (Figure 1). As inferred in the Parasuraman’s level
of automation, the more alternatives the system proposes,
the less automated.</p>
    </sec>
    <sec id="sec-7">
      <title>Design and engineering issues of recommender systems in safety critical domain</title>
      <p>This section tries to identify the potential of recommender
systems as well as the design issues related to their
engineering.</p>
      <p>
        The classification framework of recommender systems
proposed in [
        <xref ref-type="bibr" rid="ref29">29</xref>
        ] identifies multiple application domains where
recommender systems have been deployed (as an excerpt
is presented in Figure 8).
It is interesting to note that none of them target at critical
or safety critical domain. [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] presents the evaluation of
a recommender system for single pilot operations but no
information is given about the design and development of
the underlying system and nor about its user interface and
interaction techniques.
      </p>
      <p>
        We have considered several engineering approaches to
examine these issues. First, the ICO user interface design
techniques enables to develop usable and reliable
interaction techniques [
        <xref ref-type="bibr" rid="ref24">24</xref>
        ]. Complemented with task modelling
(for describing operators goals and tasks to be performed
to reach these goals), it can be used to analyze user’s task
w.r.t. system’s behavior [
        <xref ref-type="bibr" rid="ref22">22</xref>
        ]. At last, task models can also
be used to assess whether the user or the system should
handle a particular task in a particular context [
        <xref ref-type="bibr" rid="ref22">22</xref>
        ]. All of
these techniques aim at finding the optimal collaboration
solution between the user and the system but were not
applied with a recommender systems, even with the AMAN
(Arrival Manager) advisory tool for air traffic control which
could be also considered as a simple recommender
system [
        <xref ref-type="bibr" rid="ref23">23</xref>
        ].
      </p>
      <p>
        However these approaches do not deal with the possible
dynamic change of behavior of the system, especially if it
has machine learning capabilities (reinjecting operators’
selections in the items information). Additionally, considering
that the safety-critical user interfaces require additional
design and development paths, we identified the following set
of issues that must be considered if the system is (partly)
autonomous:
• What is usability of a recommender system in a
critical context and how to evaluate it (as operators follow
extensive training and have deep knowledge of the
behavior of the supervised systems),
• How to guarantee the safety and dependability of the
possible interactions when browsing recommended
items,
• How to guarantee the safety and dependability of the
underlying recommender system behavior,
• How to analyze and prevent operators’ errors,
• How to assess and design responsibility, authority
and liability between the recommender system and
the operators (for instance in aircraft the entire
authority belong to the captain and not to the first
officer),
• How to design and specify interaction techniques
where autonomous behavior from the system
interfere with operator input (including the question on
how to model that formally [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]),
• How to design interaction so that the operators can
foresee the systems’ future steps and states and the
impact of selecting one recommendation instead of
another one,
• How to design interactions when the automation
(recommendation) can fail and how to notify the operators
about degradation of the recommender system (for
each of the stages in Figure 3),
• How to enhance and evaluate aspects of user
experience, while fulfilling the constraints of a safety-critical
system which has to be secure, safe, reliable and
usable.
      </p>
    </sec>
    <sec id="sec-8">
      <title>Summary and Conclusion</title>
      <p>This position paper proposed to consider recommender
systems as partly-autonomous systems. We have
demonstrated that their behavior is similar to the ones of autonomous
systems and that existing classifications in that domain are
applicable to recommender systems.</p>
      <p>We have shown on a simple example from the aviation
domain that current systems exhibits some of the
characteristics of recommender systems. We have also highlighted
design and development issues that currently prevent
recommender from being deployed in the context of safety critical
systems but we have also highlighted some of the problems
to be addressed.</p>
      <p>
        Future work deals with the definition of engineering
approaches for building reliable and fault-tolerant
recommender systems following what has been done in the past
for interactive cockpit applications as presented in [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]
and [
        <xref ref-type="bibr" rid="ref36">36</xref>
        ]. It is important to note that trade-off between
properties (such as usability and dependability as presented
in [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ]) will also be present in the case of recommender
systems in safety critical applications.
      </p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>Johnny</given-names>
            <surname>Accot</surname>
          </string-name>
          , Stéphane Chatty, Sébastien Maury, and
          <string-name>
            <given-names>Philippe</given-names>
            <surname>Palanque</surname>
          </string-name>
          .
          <year>1997</year>
          .
          <article-title>Formal transducers: models of devices and building bricks for the design of highly interactive systems</article-title>
          .
          <source>In Design, Specification and Verification of Interactive Systems' 97</source>
          . Springer,
          <fpage>143</fpage>
          -
          <lpage>159</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>Johnny</given-names>
            <surname>Accot</surname>
          </string-name>
          , Stéphane Chatty, and
          <string-name>
            <given-names>Philippe</given-names>
            <surname>Palanque</surname>
          </string-name>
          .
          <year>1996</year>
          .
          <article-title>A formal description of low level interaction and its application to multimodal interactive systems</article-title>
          .
          <source>In Design, Specification and Verification of Interactive Systems' 96</source>
          . Springer,
          <fpage>92</fpage>
          -
          <lpage>104</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Julie</surname>
            <given-names>A Adams</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Curtis M Humphrey</surname>
            ,
            <given-names>Michael A Goodrich</given-names>
          </string-name>
          , Joseph L Cooper, Bryan S Morse, Cameron Engh, and
          <string-name>
            <given-names>Nathan</given-names>
            <surname>Rasmussen</surname>
          </string-name>
          .
          <year>2009</year>
          .
          <article-title>Cognitive task analysis for developing unmanned aerial vehicle wilderness search support</article-title>
          .
          <source>Journal of cognitive engineering and decision making 3</source>
          ,
          <issue>1</issue>
          (
          <year>2009</year>
          ),
          <fpage>1</fpage>
          -
          <lpage>26</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>ARINC.</surname>
          </string-name>
          <year>2002</year>
          .
          <article-title>ARINC 661 Cockpit Display System Interfaces to User Systems</article-title>
          .
          <source>ARINC Specification 661</source>
          . (
          <year>2002</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>Rémi</given-names>
            <surname>Bastide</surname>
          </string-name>
          , Philippe Palanque,
          <string-name>
            <surname>Duc-Hoa</surname>
            <given-names>Le</given-names>
          </string-name>
          , Jaime Muñoz, and others.
          <year>1998</year>
          .
          <article-title>Integrating rendering specifications into a formalism for the design of interactive systems</article-title>
          .
          <source>In Design, Specification and Verification of Interactive Systems' 98</source>
          . Springer,
          <fpage>171</fpage>
          -
          <lpage>190</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>Olivier</given-names>
            <surname>Bau</surname>
          </string-name>
          and
          <string-name>
            <given-names>Wendy E</given-names>
            <surname>Mackay</surname>
          </string-name>
          .
          <year>2008</year>
          .
          <article-title>OctoPocus: a dynamic guide for learning gesture-based command sets</article-title>
          .
          <source>In Proceedings of the 21st annual ACM symposium on User interface software and technology. ACM</source>
          ,
          <volume>37</volume>
          -
          <fpage>46</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>R</given-names>
            <surname>Bernhaupt</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M</given-names>
            <surname>Cronel</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F</given-names>
            <surname>Manciet</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C</given-names>
            <surname>Martinie</surname>
          </string-name>
          , and
          <string-name>
            <given-names>P</given-names>
            <surname>Palanque</surname>
          </string-name>
          .
          <year>2015</year>
          .
          <article-title>Transparent Automation for Assessing and Designing better Interactions between Operators and Partly-Autonomous Interactive Systems</article-title>
          .
          <source>In Proceedings of the 5th International Conference on Application and Theory of Automation in Command and Control Systems. ACM</source>
          ,
          <volume>129</volume>
          -
          <fpage>139</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>Jesús</given-names>
            <surname>Bobadilla</surname>
          </string-name>
          , Fernando Ortega, Antonio Hernando, and
          <string-name>
            <given-names>Abraham</given-names>
            <surname>Gutiérrez</surname>
          </string-name>
          .
          <year>2013</year>
          .
          <article-title>Recommender systems survey</article-title>
          .
          <source>Knowledge-Based Systems</source>
          <volume>46</volume>
          (
          <year>2013</year>
          ),
          <fpage>109</fpage>
          -
          <lpage>132</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>Matthew</surname>
            <given-names>L Bolton</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ellen J Bass</surname>
          </string-name>
          ,
          <source>and Radu I Siminiceanu</source>
          .
          <year>2013</year>
          .
          <article-title>Using formal verification to evaluate human-automation interaction: A review</article-title>
          .
          <source>IEEE Transactions on Systems, Man, and Cybernetics: Systems</source>
          <volume>43</volume>
          ,
          <issue>3</issue>
          (
          <year>2013</year>
          ),
          <fpage>488</fpage>
          -
          <lpage>503</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Bureau d'</surname>
          </string-name>
          Enquêtes et d'Analyse.
          <year>2012</year>
          .
          <article-title>Rapport finalAccident survenu le 1er juin 2009 à l'Airbus A330-203 immatriculé F-GZCP exploité par Air France</article-title>
          vol AF 447 Rio de Janeiro-Paris.
          <source>Technical Report. Tech. rep.</source>
          ,
          <string-name>
            <surname>République</surname>
            <given-names>Française</given-names>
          </string-name>
          , Ministère de l'Ecologie, du Développement durable et de l'Énergie.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>Alphonse</given-names>
            <surname>Chapanis</surname>
          </string-name>
          .
          <year>1996</year>
          .
          <article-title>Human factors in systems engineering</article-title>
          . John Wiley &amp; Sons, Inc.
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>Carlos</given-names>
            <surname>Iván</surname>
          </string-name>
          Chesnevar and Ana G Maguitman.
          <year>2004</year>
          .
          <article-title>Arguenet: An argument-based recommender system for solving web search queries</article-title>
          .
          <source>In Intelligent Systems</source>
          ,
          <year>2004</year>
          .
          <source>Proceedings. 2004 2nd International IEEE Conference</source>
          , Vol.
          <volume>1</volume>
          . IEEE,
          <fpage>282</fpage>
          -
          <lpage>287</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Mary L Cummings and Sylvain Bruni</surname>
          </string-name>
          .
          <year>2009</year>
          .
          <article-title>Collaborative Human-Automation Decision Making</article-title>
          . In Springer handbook of automation. Springer,
          <fpage>437</fpage>
          -
          <lpage>447</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Arik-Quang V Dao</surname>
          </string-name>
          , Kolina Koltai,
          <string-name>
            <surname>Samantha D Cals</surname>
          </string-name>
          , Summer L Brandt,
          <string-name>
            <surname>Joel Lachter</surname>
            ,
            <given-names>Michael</given-names>
          </string-name>
          <string-name>
            <surname>Matessa</surname>
            ,
            <given-names>David E Smith</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>Vernol</given-names>
            <surname>Battiste</surname>
          </string-name>
          , and Walter W Johnson.
          <year>2015</year>
          .
          <article-title>Evaluation of a recommender system for single pilot operations</article-title>
          .
          <source>Procedia Manufacturing</source>
          <volume>3</volume>
          (
          <year>2015</year>
          ),
          <fpage>3070</fpage>
          -
          <lpage>3077</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Andy</surname>
            <given-names>Dearden</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>Michael</given-names>
            <surname>Harrison</surname>
          </string-name>
          , and
          <string-name>
            <given-names>Peter</given-names>
            <surname>Wright</surname>
          </string-name>
          .
          <year>2000</year>
          .
          <article-title>Allocation of function: scenarios, context and the economics of effort</article-title>
          .
          <source>International Journal of Human-Computer Studies 52</source>
          ,
          <issue>2</issue>
          (
          <year>2000</year>
          ),
          <fpage>289</fpage>
          -
          <lpage>318</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Camille</surname>
            <given-names>Fayollas</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Jean-Charles</surname>
            <given-names>Fabre</given-names>
          </string-name>
          , Philippe Palanque, Eric Barboni, David Navarre,
          <string-name>
            <given-names>and Yannick</given-names>
            <surname>Deleris</surname>
          </string-name>
          .
          <year>2013</year>
          .
          <article-title>Interactive cockpits as critical applications: a model-based and a fault-tolerant approach</article-title>
          .
          <source>International Journal of Critical Computer-Based Systems 17 4</source>
          ,
          <issue>3</issue>
          (
          <year>2013</year>
          ),
          <fpage>202</fpage>
          -
          <lpage>226</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <surname>Camille</surname>
            <given-names>Fayollas</given-names>
          </string-name>
          , Célia Martinie,
          <string-name>
            <given-names>P Palanque</given-names>
            , Yannick Deleris,
            <surname>J-C Fabre</surname>
          </string-name>
          , and
          <string-name>
            <given-names>David</given-names>
            <surname>Navarre</surname>
          </string-name>
          .
          <year>2014</year>
          .
          <article-title>An Approach for Assessing the Impact of Dependability on Usability: Application to Interactive Cockpits</article-title>
          .
          <source>In Dependable Computing Conference (EDCC)</source>
          ,
          <source>2014 Tenth European. IEEE</source>
          ,
          <fpage>198</fpage>
          -
          <lpage>209</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <surname>Paul</surname>
            <given-names>M</given-names>
          </string-name>
          <string-name>
            <surname>Fitts</surname>
          </string-name>
          .
          <year>1951</year>
          .
          <article-title>Human engineering for an effective air-navigation and traffic-control system</article-title>
          . (
          <year>1951</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <surname>Björn</surname>
            <given-names>Johansson</given-names>
          </string-name>
          , Åsa Fasth, Johan Stahre, Juhani Heilala, Swee Leong,
          <string-name>
            <given-names>Y Tina</given-names>
            <surname>Lee</surname>
          </string-name>
          , and
          <string-name>
            <given-names>Frank</given-names>
            <surname>Riddick</surname>
          </string-name>
          .
          <year>2009</year>
          .
          <article-title>Enabling flexible manufacturing systems by using level of automation as design parameter</article-title>
          .
          <source>In Winter Simulation Conference. Winter Simulation Conference</source>
          ,
          <volume>2176</volume>
          -
          <fpage>2184</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <surname>Bart</surname>
            <given-names>P Knijnenburg</given-names>
          </string-name>
          , Martijn C Willemsen, Zeno Gantner, Hakan Soncu, and
          <string-name>
            <given-names>Chris</given-names>
            <surname>Newell</surname>
          </string-name>
          .
          <year>2012</year>
          .
          <article-title>Explaining the user experience of recommender systems</article-title>
          .
          <source>User Modeling and User-Adapted Interaction 22</source>
          ,
          <fpage>4</fpage>
          -
          <lpage>5</lpage>
          (
          <year>2012</year>
          ),
          <fpage>441</fpage>
          -
          <lpage>504</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <surname>Joseph</surname>
            <given-names>A Konstan</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bradley N Miller</surname>
          </string-name>
          , David Maltz, Jonathan L Herlocker,
          <string-name>
            <surname>Lee R Gordon</surname>
            ,
            <given-names>and John</given-names>
          </string-name>
          <string-name>
            <surname>Riedl</surname>
          </string-name>
          .
          <year>1997</year>
          .
          <article-title>GroupLens: applying collaborative filtering to Usenet news</article-title>
          .
          <source>Commun. ACM 40</source>
          ,
          <issue>3</issue>
          (
          <year>1997</year>
          ),
          <fpage>77</fpage>
          -
          <lpage>87</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <surname>Célia</surname>
            <given-names>Martinie</given-names>
          </string-name>
          , Philippe Palanque, Eric Barboni, Marco Winckler, Martina Ragosta, Alberto Pasquini, and
          <string-name>
            <given-names>Paola</given-names>
            <surname>Lanzi</surname>
          </string-name>
          .
          <year>2011</year>
          .
          <article-title>Formal tasks and systems models as a tool for specifying and assessing automation designs</article-title>
          .
          <source>In Proceedings of the 1st International Conference on Application and Theory of Automation in Command and Control Systems</source>
          . IRIT Press,
          <fpage>50</fpage>
          -
          <lpage>59</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <surname>Celia</surname>
            <given-names>Martinie</given-names>
          </string-name>
          , Philippe Palanque, Alberto Pasquini, Martina Ragosta, Eric Rigaud, and
          <string-name>
            <given-names>Sara</given-names>
            <surname>Silvagni</surname>
          </string-name>
          .
          <year>2012</year>
          .
          <article-title>Using complementary models-based approaches for representing and analysing ATM systems' variability</article-title>
          .
          <source>In Proceedings of the 2nd International Conference on Application and Theory of Automation in Command and Control Systems</source>
          . IRIT Press,
          <fpage>146</fpage>
          -
          <lpage>157</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <given-names>David</given-names>
            <surname>Navarre</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Philippe</given-names>
            <surname>Palanque</surname>
          </string-name>
          ,
          <string-name>
            <surname>Jean-Francois Ladry</surname>
            , and
            <given-names>Eric</given-names>
          </string-name>
          <string-name>
            <surname>Barboni</surname>
          </string-name>
          .
          <year>2009</year>
          .
          <article-title>ICOs: A model-based user interface description technique dedicated to interactive systems addressing usability, reliability and scalability</article-title>
          .
          <source>ACM Transactions on Computer-Human Interaction (TOCHI) 16</source>
          ,
          <issue>4</issue>
          (
          <year>2009</year>
          ),
          <fpage>18</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>Everett</given-names>
            <surname>Palmer</surname>
          </string-name>
          .
          <year>1995</year>
          . Oops, it didn't arm'
          <article-title>- A case study of two automation surprises</article-title>
          .
          <source>In International Symposium on Aviation Psychology</source>
          ,
          <volume>8</volume>
          <fpage>th</fpage>
          , Columbus, OH.
          <fpage>227</fpage>
          -
          <lpage>232</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [26]
          <string-name>
            <given-names>Raja</given-names>
            <surname>Parasuraman</surname>
          </string-name>
          and
          <string-name>
            <given-names>Victor</given-names>
            <surname>Riley</surname>
          </string-name>
          .
          <year>1997</year>
          .
          <article-title>Humans and automation: Use, misuse, disuse, abuse</article-title>
          .
          <source>Human Factors: The Journal of the Human Factors and Ergonomics Society</source>
          <volume>39</volume>
          ,
          <issue>2</issue>
          (
          <year>1997</year>
          ),
          <fpage>230</fpage>
          -
          <lpage>253</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [27]
          <string-name>
            <surname>Raja</surname>
            <given-names>Parasuraman</given-names>
          </string-name>
          , Thomas B Sheridan, and
          <string-name>
            <given-names>Christopher D</given-names>
            <surname>Wickens</surname>
          </string-name>
          .
          <year>2000</year>
          .
          <article-title>A model for types and levels of human interaction with automation</article-title>
          .
          <source>IEEE Transactions on systems, man, and cybernetics-Part A: Systems and Humans</source>
          <volume>30</volume>
          ,
          <issue>3</issue>
          (
          <year>2000</year>
          ),
          <fpage>286</fpage>
          -
          <lpage>297</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [28]
          <string-name>
            <given-names>Raja</given-names>
            <surname>Parasuraman</surname>
          </string-name>
          and
          <string-name>
            <given-names>Christopher D</given-names>
            <surname>Wickens</surname>
          </string-name>
          .
          <year>2008</year>
          .
          <article-title>Humans: Still vital after all these years of automation</article-title>
          .
          <source>Human Factors: The Journal of the Human Factors and Ergonomics Society</source>
          <volume>50</volume>
          ,
          <issue>3</issue>
          (
          <year>2008</year>
          ),
          <fpage>511</fpage>
          -
          <lpage>520</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          [29]
          <string-name>
            <given-names>Deuk</given-names>
            <surname>Hee Park</surname>
          </string-name>
          , Hyea Kyeong Kim, Il Young Choi, and Jae Kyeong Kim.
          <year>2012</year>
          .
          <article-title>A literature review and classification of recommender systems research</article-title>
          .
          <source>Expert Systems with Applications</source>
          <volume>39</volume>
          ,
          <issue>11</issue>
          (
          <year>2012</year>
          ),
          <fpage>10059</fpage>
          -
          <lpage>10072</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          [30]
          <string-name>
            <surname>Ryan</surname>
            <given-names>W Proud</given-names>
          </string-name>
          , Jeremy J Hart, and Richard B Mrozinski.
          <year>2003</year>
          .
          <article-title>Methods for determining the level of autonomy to design into a human spaceflight vehicle: a function specific approach</article-title>
          .
          <source>Technical Report. DTIC Document.</source>
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          [31]
          <string-name>
            <given-names>James</given-names>
            <surname>Reason</surname>
          </string-name>
          .
          <year>1990</year>
          .
          <article-title>Human error</article-title>
          . Cambridge university press.
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          [32]
          <string-name>
            <surname>Nadine</surname>
            <given-names>B Sarter</given-names>
          </string-name>
          ,
          <string-name>
            <surname>David D Woods</surname>
            , and
            <given-names>Charles E</given-names>
          </string-name>
          <string-name>
            <surname>Billings</surname>
          </string-name>
          .
          <year>1997</year>
          .
          <article-title>Automation surprises</article-title>
          .
          <source>Handbook of human factors and ergonomics 2</source>
          (
          <year>1997</year>
          ),
          <fpage>1926</fpage>
          -
          <lpage>1943</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref33">
        <mixed-citation>
          [33]
          <string-name>
            <surname>Thomas</surname>
            <given-names>B</given-names>
          </string-name>
          <string-name>
            <surname>Sheridan and Raja Parasuraman</surname>
          </string-name>
          .
          <year>2005</year>
          .
          <article-title>Human-automation interaction</article-title>
          .
          <source>Reviews of human factors and ergonomics 1</source>
          ,
          <issue>1</issue>
          (
          <year>2005</year>
          ),
          <fpage>89</fpage>
          -
          <lpage>129</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref34">
        <mixed-citation>
          [34]
          <string-name>
            <surname>Thomas</surname>
            <given-names>B</given-names>
          </string-name>
          <string-name>
            <surname>Sheridan and William L Verplank</surname>
          </string-name>
          .
          <year>1978</year>
          .
          <article-title>Human and computer control of undersea teleoperators</article-title>
          .
          <source>Technical Report. DTIC Document.</source>
        </mixed-citation>
      </ref>
      <ref id="ref35">
        <mixed-citation>
          [35]
          <string-name>
            <given-names>Kirsten</given-names>
            <surname>Swearingen</surname>
          </string-name>
          and
          <string-name>
            <given-names>Rashmi</given-names>
            <surname>Sinha</surname>
          </string-name>
          .
          <year>2001</year>
          .
          <article-title>Beyond algorithms: An HCI perspective on recommender systems</article-title>
          .
          <source>In ACM SIGIR 2001 Workshop on Recommender Systems</source>
          , Vol.
          <volume>13</volume>
          .
          <string-name>
            <surname>Citeseer</surname>
          </string-name>
          ,
          <volume>1</volume>
          -
          <fpage>11</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref36">
        <mixed-citation>
          [36]
          <string-name>
            <given-names>A</given-names>
            <surname>Tankeu-Choitat</surname>
          </string-name>
          , David Navarre,
          <string-name>
            <given-names>P Palanque</given-names>
            , Yannick Deleris,
            <surname>Jean-Charles Fabre</surname>
          </string-name>
          , and
          <string-name>
            <given-names>Camille</given-names>
            <surname>Fayollas</surname>
          </string-name>
          .
          <year>2011</year>
          .
          <article-title>Self-checking components for dependable interactive cockpits using formal description techniques</article-title>
          .
          <source>In Dependable Computing (PRDC)</source>
          ,
          <source>2011 IEEE 17th Pacific Rim International Symposium on. IEEE</source>
          ,
          <fpage>164</fpage>
          -
          <lpage>173</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>