<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Trusted and Auditable Decision Aids over Data Streams</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Dominic J. Duxbury</string-name>
          <email>dominic.duxbury@manchester.ac.uk</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Norman W. Paton</string-name>
          <email>norman.paton@manchester.ac.uk</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>John A. Keane</string-name>
          <email>john.keane@manchester.ac.uk</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>University of Manchester</institution>
          ,
          <addr-line>M13 9PL, Manchester</addr-line>
          ,
          <country country="UK">UK</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>Data stream management systems exist to support dynamic analysis of streaming data, often to inform decision-making. Decision support systems exist to enable decisions to be made that take into account user priorities. However, although these categories of system are now quite mature, there has been little work investigating their use together. In this paper we bring together a well established streaming platform (Storm) and a widely used decision-support methodology (Analytic Hierarchy Process) to provide dynamic decision support over data streams. In so doing, we also investigate approaches making recommendations auditable (using provenance) and trustable (using explanations). The resulting stream decision support system is illustrated using an application that supports train journey planning.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>INTRODUCTION</title>
      <p>
        Data streams exist as an abstraction to support analysis of
dynamic data as it is produced [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]. Decision Support systems exist
to support users in navigating a space of options [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. These seem
to be complimentary paradigms, which can be brought together
to support decision making with dynamic data. Current practice
in stream data processing makes extensive use of Stream
Processing Engines (SPEs) which provide a framework for acting
upon elements in a stream. For decision support, an interesting
problem is how to build on these capabilities to support real-time
decision support over streams.
      </p>
      <p>
        For real-time decision support systems, the choices made by
decision makers often afect the state of the system. It is therefore
useful to model decision makers as not just users, but as
components of a cyber-physical-social system (CPSS). CPSS span the
physical, information, cognitive and social domains. In the CPSS
ifeld, human users are considered a component of the system;
falling within the cognitive domain [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. Human components can
be a necessary part of a system, such as when making life or
death decisions. Decision support systems are therefore often
vital, as they bridge the information and cognitive domains by
distilling data to assist decision makers.
      </p>
      <p>
        Decision support systems are enabled by decision analysis.
Decision analysis is the field concerned with the study of complex
decisions. Multi-criteria decision analysis is a sub-discipline of
decision analysis comprising techniques for evaluating solutions
with multiple conflicting criteria [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. A common example of this
is purchasing a car; the safest car is not often the cheapest and
so these criteria are conflicting. These criteria can have diferent
importance to diferent decision makers so we require a method
for users to specify their preferences. If the values of these criteria
are also changing then we call the problem dynamic. In this paper
First International Workshop on Data Science for Industry 4.0.
      </p>
      <p>Copyright ©2019 for the individual papers by the papers’ authors. Copying
permitted for private and academic purposes. This volume is published and copyrighted
by its editors.
we outline our approach to building a decision support platform
for these dynamic multi-criteria optimisation problems.</p>
      <p>Decision support systems are only useful if they are trusted
by a decision maker. Trust is especially challenging when
working with dynamic data; a decision maker does not have time to
ascertain if a black box system has made a mistake, and therefore
it is beneficial to provide provenance data to the decision maker,
ensuring that the information motivating a recommendation is
readily available. Data provenance provides a historical record of
data and its origins, which allows the user to assess data quality
and suitability. In addition to the underlying evidence, it is also
important that the user has some understanding of the space of
possible solutions; as a result, some form of explanation
mechanism is required that explains how a recommendation has been
arrived at, and/or describes the relationship between alternative
options.</p>
      <p>All this is required in a context where there may be genuine
uncertainty relating to criteria that inform a recommendation.
As such, it is important for maintaining trust to ensure that the
uncertainty intrinsic in a recommendation is either presented to
a user or able to be reflected within the decision-making process.</p>
      <p>Drawing this together, we have the following 5 desiderata for
dynamic multi-criteria decision support systems:
(1) declarative specification of preferences,
(2) dynamic revision of recommendations,
(3) provenance capturing the data underpinning decisions,
(4) explanation of how a proposal was made, and
(5) explicit support for uncertain data.</p>
      <p>To investigate how these desiderata can be supported in stream
decision support, a running example based on train journey
planning is introduced in Section 2. An architecture for dynamic
decision support is described in Section 3. The application of
the architecture to support the above desiderata is discussed in
Section 4. Section 5 describes some related work, and conclusions
are presented in Section 6.
2</p>
    </sec>
    <sec id="sec-2">
      <title>MOTIVATING EXAMPLE</title>
      <p>To illustrate multi-criteria decision support over streams, we
consider an application relating to train journey planning. We
assume that a user can state where they need to go from and
to, along with the proposed start time. We also assume that the
most suitable journey time for a user may depend on diferent
criteria, specifically the arrival time of the journey, the price of
the journey, and the number of changes.</p>
      <p>For example, in Figure 1, a decision maker must choose a route
from A to F in a way that takes into account price, arrival time
and number of changes.</p>
      <p>Table 1 shows the solutions to this example. We note that
the solution ABF dominates ABDF as it is equal or better for
all criteria values. This leaves us with two potential solutions;
ABF and ACDF . A business person may prefer ABF because it
is quicker, whereas a student may prefer to save money and
take ACDF . There is no optimal solution for everyone and so we
require user specification of criteria preferences (Desiderata 1).</p>
      <p>One such criterion, arrival time, indicates the expected arrival
time of a journey. This is subject to change, as trains may be
delayed or lines closed. Ticket prices are also subject to change
up until the time of purchase. If a train is delayed or the price
increases, the resulting solution may no longer be optimal,
therefore dynamically revising recommendations (Desiderata 2) to
reflect the most recent information is clearly beneficial. The user
may also move between stations as a part of their interaction
with the system; hence requiring an entirely new set of solutions.</p>
      <p>A decision maker may see these solutions and choose option
ACDF because they believe it will only take 10 minutes. However,
this route could unreliable due to engineering works, so it may be
important for the user to understand the source and derivation
of criteria values (Desiderata 3) to improve trustability, or to
understand the uncertainty that is characteristic of this particular
train service (Desiderata 5).</p>
      <p>Finally, after expressing their preferences, accepting criteria
values and understanding uncertain aspects, a user is left with a
recommended journey. It may be dificult to trust this
recommendation without understanding why it was selected. Therefore
we should provide the user with an explanation of where the
recommendation falls in the solution space, so that they can
understand the trade-ofs being made, and how this ties into their
criteria preferences (Desiderata 4).
3</p>
    </sec>
    <sec id="sec-3">
      <title>ARCHITECTURE</title>
      <p>To evaluate our approach, a prototype platform has been
developed. This platform implements our desiderata from Section 1,
whilst providing decision support for train route planning. The
system utilises a micro-services architecture shown in Figure 2.</p>
      <p>The decision maker operates the decision support system
through the user interface. The user inputs details for a planned
trip; an origin station, a destination station and a departure time.
The user also must specify their preferences with regard to the
criteria. This information is sent with a request to open a
websockets connection to the Application Controller. The Application
Controller holds the state of the train journeys (solutions) within
the system. The controller uses the planned trip to build an http
request to send to the Timetable Service.</p>
      <p>Our architecture requires a solution service to generate the
initial solution space. The Timetable Service is the implementation
of the solution service for the train route planning scenario. The
service generates a list of train journeys between the requested
origin and destination stations at the specified departure time.
Initial values are then calculated for all criteria. The Timetable
Service returns an unranked list of train journeys which are passed
from the Application Controller to the Live Train Service. A
streaming component is also required to update the dynamic criteria
and to produce a new ranking in real-time. The Live Train Service
is an implementation of this component for the train scenario.
In this case the live train service must update the expected train
arrival time. The Live Train Service is initialised with a list of train
journeys, which are ranked by the Ranking Service. A stream of
UK wide train updates from National Rail is filtered, and
matching updates are used to update criteria values. The updated list
of train journeys is then re-ranked by the Ranking Service. The
output stream of ranked train journeys is communicated to the
User Interface over web-sockets.</p>
      <p>The Ranking Service accepts a specification of preferences and
a list of solutions, to produce a ranking. This ranking is
calculated through the application of the Analytic Hierarchy Process,
a popular method for multi-criteria decision analysis. The criteria
and criteria behaviour are specified through the configuration.
For example we specify that price is a criterion and should be
minimised. This allows the service to remain generic. The other
generic component is the provenance sub-system. The
provenance sub-system generates, stores and serves provenance data
within the platform. This subsystem is made up of a message
queue, a database (Prov DB) and two services; one for
generating provenance (Prov Generator Service), one for serving it (Prov
Provider Service). The sub-system receives messages from the
streaming service which are processed to produce provenance
graphs.
3.1</p>
    </sec>
    <sec id="sec-4">
      <title>Architecture Components</title>
      <p>In this subsection, we provide further details of the components
in Figure 2.</p>
      <p>Live Train Service. The live train service applies Apache Storm
to transform streams of tuples. Apache Storm is an open source
SPE which utilises three abstractions; spouts, bolts and
topologies. Spouts produce streams. Bolts consume any number of
streams to produce new output streams. A topology describes
a network of spouts and bolts. Within our streaming
component we instrument these operators to extract provenance data.
We extend the base classes for bolts and spouts to produce two
new provenance aware classes; ProvenanceAwareBolt and
ProvenanceAwareSpout. An example of a bolt extending this class is
shown in Listing 1. Execute defines how a bolt processes each
tuple and declareOutputFields declares the shape of tuples in the
output stream. An operator inheriting from these classes will
write provenance information concerning its inputs and outputs
to the provenance sub-system.</p>
      <p>For the train route scenario we have three operators;
NationalRailSpout, DelayBolt and RankingBolt . The NationalRailSpout
produces a stream of delays, the DelayBolt applies relevant delays
to a list of journeys and the RankingBolt interfaces with the
Ranking Service to calculate a score for each journey. Table 2 shows
the input and output tuples for each operator. We instrument all
the operators to supply us with provenance regarding the history
of solutions, their criteria values and the resulting ranking.
p u b l i c c l a s s E x a m p l e B o l t extends P r o v e n a n c e A w a r e B o l t {
p u b l i c void e x e c u t e ( Tuple t u p l e ) { }
p u b l i c void d e c l a r e O u t p u t F i e l d s ( D e c l a r e r d e c l a r e r ) { }
}</p>
      <p>Listing 1: Code for a provenance aware bolt</p>
      <p>
        Ranking Service. To calculate a recommendation we apply the
Analytic Hierarchy Process (AHP) [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ]. AHP is a structured
technique for organising and analysing complex decisions. AHP
consists of an overall goal, a group of options or alternatives for
reaching the goal and a group of factors or criteria that relate
the alternatives to the goal; the criteria can be further broken
down. These criteria generally have diferent values for diferent
decision makers and so the algorithm requires users to express
their preferences. The user preferences are expressed in the form
of pairwise comparisons. For instance, a decision maker could
express that “Price is more important than Travel Duration”.
Pairwise comparisons are easy for a user to express and model the
users knowledge within the system. The comparisons are then
used to generate weightings for each criteria.
      </p>
      <p>To produce a ranking, criteria values must also be scored. To
do this the values are first normalised according to the range of
values across all solutions using the following formula:
x − minX
N orm(x ) =</p>
      <p>maxX − minX
Where minX and maxX are the smallest and largest criteria values
respectively. The values are then compared pairwise to generate
a comparison matrix. For three solutions S1, S2 and S3 and a
criterion X with normalised criteria values x1, x2, x3, we would
generate a comparison matrix C.</p>
      <p>S1 "
C = S2</p>
      <p>S3</p>
      <p>S1
1
f (x2, x1)
f (x3, x1)</p>
      <p>S2
f (x1, x2)</p>
      <p>1
f (x3, x2)</p>
      <p>S3
f (x1, x3)#
f (x2, x3)
1</p>
      <p>
        We provide two separate formulas for comparing criteria
values, depending on whether the values fall along a linear scale (1)
or an exponential scale (2). These formulas map two normalised
values (x , y) to the fundamental scale proposed by Saaty [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ]. For
the train route planning scenario we apply the first formula (1),
because all criteria form a linear scale. E.g. train prices might be
£10, £15, £20 for three alternative routes and not £10, £100, £1000.
f (x, y) = |(x − y) × 8| + 1 (1)
ex
f (x, y) = ey
(2)
      </p>
      <p>The eigenvalues of the comparison matrix for each criterion
represent the score for the respective criteria value of each
solution. The criteria value scores are then multiplied by the
relevant criteria weightings and summed across each solution. This
process produces the scores which are used to derive a global
ranking.</p>
      <p>The normalisation of criteria values can cause some brittleness
in the results when we only have a small range. If the algorithm
is supplied with two journeys, one costing £50 and another £51
these are seen as the best and worst possible price and so scored
accordingly. It would be beneficial for the algorithm to recognise
that there is little diference between these two prices. We aim
to solve this by allowing those implementing the framework to
specify a range of possible values for a criterion.</p>
      <p>The decision support component operates over web-sockets.
The service requires a configuration file when a connection is
opened, providing information about criteria. Critically the
conifguration indicates the number of criteria and whether numerical
criteria should be maximised or minimised. The configuration
also allows us to indicate how we should compare non numerical
criteria. Once a connection is opened, AHP is applied to a stream
of solutions, producing a stream of rankings.</p>
      <p>
        Provenance Sub-system. The provenance sub-system processes
messages from the streaming system and stores the output in
a database for future querying. To store this data we choose to
conform to the PROV standard [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ]. PROV defines a data model
consisting of a set of vertices and edges for modelling provenance
as graphs. We adapt a subset of these to map to concepts from data
stream analysis. For vertices we use entities, activities and agents.
For edges we use wasGeneratedBy, used and wasAssociatedWith.
      </p>
      <p>The PROV data model describes entities as “an immutable
piece of state”, activities as “dynamic aspects of the world which
produce entities” and agents as “parties which take a role in
activities”. We model stream elements as entities, stream operations as
activities and stream operators as agents. Note, we call a set of
inputs and outputs a stream operation. The stream operator refers
to the operator applied to these inputs to produce the outputs.</p>
      <p>Edges describe the relationships between two entities.
wasGeneratedBy links an entity to the activity which generated it. used
links an activity to an entity it consumed. wasAssociatedWith
links an activity to an agent associated with it. We say a stream
element was generated by a stream operation. These operations
used a stream element or window of elements. The operation also
wasAssociatedWith the operator which was applied. An example
provenance graph is shown in Figure 3. This example shows the
derivation for an expected train arrival time. The new arrival time
wasGeneratedBy an operation which used the scheduled arrival
time and the schedule delay. The operation wasAssociatedWith
the delay operator (DelayBolt).
3.2</p>
    </sec>
    <sec id="sec-5">
      <title>Framework Concepts</title>
      <p>In the remainder of this section, we explain what we mean by
explanation and uncertainty and how these concepts surface within
our architecture.</p>
      <p>Explanation. The AHP algorithm outputs a weight vector for
criteria and a score for each solution. Whilst this is useful for
constructing a ranking, these values are dificult for a human
to interpret. Therefore we require some further explanation of
how the system arrived at a recommendation. Fundamentally
we describe explanation as a description of how a set of criteria
preferences are used by AHP to select a solution from a solution
space. Perhaps the most important part, is an explanation of the
trade-ofs and benefits of a recommendation and how this ties
into the specified user preferences. For instance, in the case of
train route planning, a user could specify that price is critical
to them. Assuming the system recommends ABC, the cheapest
option, a simple explanation would be that ABC is the cheapest
train and price is the most important criterion.</p>
      <p>Our recommendations are dynamic and so it is important that
an explanation can be processed by the user quickly. This lead
us towards visual forms of explanation such as bar and spider
charts. Spider charts visualise multi-variate data as a shape
constructed from three or more quantitative variables across axes
stemming from the same point. Typically a chart with a larger
area represents a better solution, but these charts can be
misleading as the order of criteria can greatly afect the area. For this
reason we chose instead to visualise the solution space through
bar charts where the values for each criterion and solution are
plotted side-by-side. Bar charts are one of the most simple forms
of data visualisation, leaving less room for misinterpretation.</p>
      <p>Uncertainty. Uncertainty is modelled using cumulative
probability density functions (CDFs) drawn from historical data. These
functions capture information regarding the potential values of
an uncertain criterion for a particular solution. Arrival time is an
uncertain criterion for train route planning. We derive a CDF of
arrival times for a journey from the historical performance of the
trains travelling the same route. These CDFs are a simple model,
capturing the distribution of potential criteria values. Through
this distribution we can view the probability of the potential
risks (lateness) for a journey. CDFs serve as alternative to criteria
values for uncertain criteria but we require a method of
comparing two CDFs. To do this we extract three key values from the
distribution; optimistic, expected and pessimistic values. For a
CDF f we define optimistic, expected and pessimistic values as
x such that f (x ) = 0.05, f (x ) = 0.5 and f (x ) = 0.95 respectively.
An example for train arrival times is shown in Figure 4. The user
interface allows the decision maker to toggle which of these three
values is fed into the ranking algorithm.
4</p>
    </sec>
    <sec id="sec-6">
      <title>MOTIVATING EXAMPLE APPLICATION</title>
      <p>
        In this section we explain how the user interacts with the system
and how this interface supports the five desiderata from Section 1.
The user interface aims to target end-users, rather than decision
scientists [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]. The user interface for the train route planner is
shown in Figure 5.
      </p>
      <p>For a decision maker planning a train journey, the first task
is to specify the planned trip. The top left corner shows the
trip input form, where the user can input where they wish to
travel From (Origin Station), To (Destination Station) and the
time they are Leaving At (Departure Time). Once these values
are set the user can click Calculate Routes to generate a set of
possible journeys. The next task is for the user to specify their
preferences (Desiderata 1). In our user interface these pairwise
user preferences are located in the bottom left. In Figure 5 the
preferences are set to default, with all criteria equal. Each pair can
be set through a drop-down menu one of five potential values;
(1) X is much more important than Y ,
(2) X is more important than Y ,
(3) X is just as important as Y ,
(4) X is less important than Y ,
(5) X is much less important than Y .</p>
      <p>These preferences can be changed at any point, triggering the
system to re-rank the journeys.</p>
      <p>Once the planned trip and preferences have been detailed
the user is presented with the top five ranked journeys (the
fourth and fifth fall below the fold). Immediately the user can
view criteria values of each journey (Price , Arrival Time and
Transfers ). These values and the resultant ranking are updated
continuously once routes have been calculated (Desiderata 2).
To prevent information overload some extra details are hidden.
Clicking the plus next to Journey Path displays the information
needed to undertake a journey, including the journey path and the
trains of which the journey is composed. Each journey also has
a View Detail button, which allows the user to view provenance
information in a pop-up window (Desiderata 3). The design for
this window is shown in Figure 6. Here the user can view the
history of values for Arrival Time and the data sources.</p>
      <p>The values for each of the criteria are shown in the bar charts
at the top of Figure 5, with the x-axes ordered according to the
ranking. These charts allow the user to visually compare a
recommendation (the furthest left value) to the solution space (all
other values). The charts are also ordered according to the
weighting calculated through AHP, with the most important criteria
appearing on the left. This means a user can both understand
the trade-ofs of a recommendation and how this ties into their
specified preferences (Desiderata 4).</p>
      <p>Finally the user can toggle between Pessimistic , Expected and
Optimistic modes for the predicted arrival time by clicking the
corresponding button. These modes simply change the value
extracted from the CDF, as described in Section 3.2 (Desiderata 5).
Expected values are more useful for users making a journey many
times (such as commuters) whereas pessimistic values would
be more important in a scenario where a user is travelling for
something more time critical (such as a job interview).
5</p>
    </sec>
    <sec id="sec-7">
      <title>RELATED WORK</title>
      <p>This paper has proposed an approach for the integration of
streaming data with decision support methodologies, with a view
to enabling users to make decisions that reflect their priorities in
the context of a changing physical environment. In this section,
we review related work on the intersection of cyber-physical
systems (CPS) with decision support, stream data analytics and
provenance for data streams.</p>
      <p>
        In relation to CPS, decision support is growing in significance.
CPS with key decision support components are being widely
adopted in the medical field ([
        <xref ref-type="bibr" rid="ref19 ref4">4, 19</xref>
        ]). These systems advise
doctors in the diagnosis and treatment of patients. Liu et al. [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]
outlines a framework in the context of command and control;
highlighting how decision support can be integrated within a
larger CPS and the benefits of doing so. Wang [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ] et al. make the
argument for referring to CPS as cyber-physical-social systems
(CPSS). This paper argues the importance of the human aspect
within CPS, identifying that users should be more closely
integrated within the systems they control. Our architecture fulfils
this paradigm by improving extraction of knowledge (pairwise
comparisons) and presentation of knowledge (recommendations).
      </p>
      <p>
        There is a substantial body of work on stream data analyses,
often investigating how specific analyses can be carried out
eficiently on rapidly streaming data (e.g. [
        <xref ref-type="bibr" rid="ref15 ref2">2, 15</xref>
        ]). Here the focus has
been more on the intersection of streaming and decision support
architectures than on algorithms for stream analytics, although
this architectural work would benefit from, and presents specific
requirements for, eficient multi-dimensional optimization over
streams (e.g. [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]).
      </p>
      <p>
        It has been recognised that multi-criteria decision support
systems need to operate in dynamic environments. For example,
Benitez et al. [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] and Raharjo et al. [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ] consider making
incremental responses to changes in criteria, but there has been less
of a focus on responding to changes in criteria values.
      </p>
      <p>
        It has also been recognized that provenance for data streams
is both important for specific streaming applications where
decisions may be audited, but also challenging in relation to
scalability [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]. Previous work has involved designing generic approaches
to collecting and storing provenance data [
        <xref ref-type="bibr" rid="ref12 ref8">8, 12</xref>
        ]. These systems
provide a generic interface for provenance management but no
integration with streaming systems. Lim et al. have looked at
integrating provenance with streaming systems in the context of
sensor networks [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], and Blount et al. provided provenance for
medical event streams [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ]. These papers engineer a solution for
generating and managing provenance specific to their respective
areas rather than seeking to integrate provenance generation
into generic SPEs.
6
      </p>
    </sec>
    <sec id="sec-8">
      <title>CONCLUSIONS</title>
      <p>Decision support systems use user-specified criteria to compare
candidate solutions within a multi-dimensional space of
alternatives. This requirement for user-driven comparison of
candidate outcomes is widely recognised in decision support, and
seems relevant to streaming applications in transport,
healthcare, command and control, etc. In this paper we have identified
ifve desiderata for trusted and auditable decision aids over data
streams, described an architecture that supports these
desiderata, and illustrated its application to an application in journey
planning. Future work includes the evaluation of the approach in
diferent applications, scalability of decision support over
highvelocity data streams, and investigation of diferent approaches
to uncertainty.</p>
    </sec>
    <sec id="sec-9">
      <title>ACKNOWLEDGMENTS</title>
      <p>Dominic Duxbury is supported by an EPSRC iCASE award in
association with BAE Systems. The authors would also like to
recognise Andrew Campbell and Joseph Allen for their assistance
in designing the user interface.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>J.</given-names>
            <surname>BenÃŋtez</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Delgado-GalvÃąn</surname>
          </string-name>
          , J. Izquierdo, and
          <string-name>
            <given-names>R.</given-names>
            <surname>PÃľrez-GarcÃŋa</surname>
          </string-name>
          .
          <year>2012</year>
          .
          <article-title>An approach to AHP decision in a dynamic context</article-title>
          .
          <source>Decision Support Systems</source>
          <volume>53</volume>
          ,
          <issue>3</issue>
          (
          <year>2012</year>
          ),
          <fpage>499</fpage>
          -
          <lpage>506</lpage>
          . DOI:http://dx.doi.org/10.1016/j.dss.
          <year>2012</year>
          .
          <volume>04</volume>
          .015
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>Mohamed</given-names>
            <surname>Medhat</surname>
          </string-name>
          <string-name>
            <surname>Gaber</surname>
          </string-name>
          , Arkady Zaslavsky, and
          <string-name>
            <given-names>Shonali</given-names>
            <surname>Krishnaswamy</surname>
          </string-name>
          .
          <year>2005</year>
          .
          <article-title>Mining Data Streams: A Review</article-title>
          .
          <source>SIGMOD Rec</source>
          .
          <volume>34</volume>
          ,
          <issue>2</issue>
          (
          <year>June 2005</year>
          ),
          <fpage>18</fpage>
          -
          <lpage>26</lpage>
          . DOI: http://dx.doi.org/10.1145/1083784.1083789
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>Salvatore</given-names>
            <surname>Greco</surname>
          </string-name>
          , Matthias Ehrgott, and JoseÌĄ Rui Figueira.
          <year>2016</year>
          .
          <article-title>Multiple Criteria Decision Analysis</article-title>
          . Springer, Springer, New York, NY.
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>Yu</given-names>
            <surname>Jiang</surname>
          </string-name>
          , Houbing Song, Rui Wang, Ming Gu, Jiaguang Sun, and
          <string-name>
            <given-names>Lui</given-names>
            <surname>Sha</surname>
          </string-name>
          .
          <year>2017</year>
          .
          <article-title>Data-centered runtime verification of wireless medical cyber-physical system</article-title>
          .
          <source>IEEE Transactions on Industrial Informatics</source>
          <volume>13</volume>
          ,
          <issue>4</issue>
          (aug
          <year>2017</year>
          ),
          <fpage>1900</fpage>
          -
          <lpage>1909</lpage>
          . DOI: http://dx.doi.org/10.1109/TII.
          <year>2016</year>
          .2573762
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>M.</given-names>
            <surname>Kontaki</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. N.</given-names>
            <surname>Papadopoulos</surname>
          </string-name>
          , and
          <string-name>
            <given-names>Y.</given-names>
            <surname>Manolopoulos</surname>
          </string-name>
          .
          <year>2008</year>
          .
          <article-title>Continuous K-dominant Skyline Computation on Multidimensional Data Streams</article-title>
          .
          <source>In Proceedings of the 2008 ACM Symposium on Applied Computing (SAC '08)</source>
          . ACM, New York, NY, USA,
          <fpage>956</fpage>
          -
          <lpage>960</lpage>
          . DOI:http://dx.doi.org/10.1145/1363686.1363908
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Hyo-Sang</surname>
            <given-names>Lim</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yang-Sae Moon</surname>
            , and
            <given-names>Elisa</given-names>
          </string-name>
          <string-name>
            <surname>Bertino</surname>
          </string-name>
          .
          <year>2010</year>
          .
          <article-title>Provenance-based Trustworthiness Assessment in Sensor Networks</article-title>
          .
          <source>In Proceedings of the Seventh International Workshop on Data Management for Sensor Networks (DMSN '10)</source>
          . ACM, New York, NY, USA,
          <fpage>2</fpage>
          -
          <lpage>7</lpage>
          . DOI:http://dx.doi.org/10.1145/1858158. 1858162
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>Zhong</given-names>
            <surname>Liu</surname>
          </string-name>
          , Dong Sheng Yang, Ding Wen, Wei Ming Zhang, and
          <string-name>
            <given-names>Wenji</given-names>
            <surname>Mao</surname>
          </string-name>
          .
          <year>2011</year>
          .
          <article-title>Cyber-physical-social systems for command and control</article-title>
          .
          <source>IEEE Intelligent Systems</source>
          <volume>26</volume>
          ,
          <issue>4</issue>
          (
          <year>2011</year>
          ),
          <fpage>92</fpage>
          -
          <lpage>96</lpage>
          . DOI:http://dx.doi.org/10.1109/MIS.
          <year>2011</year>
          .69
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>Peter</given-names>
            <surname>Macko</surname>
          </string-name>
          and
          <string-name>
            <given-names>Margo</given-names>
            <surname>Seltzer</surname>
          </string-name>
          .
          <year>2012</year>
          .
          <article-title>A General-purpose Provenance Library</article-title>
          .
          <source>In Proceedings of the 4th USENIX Conference on Theory and Practice of Provenance (TaPP'12)</source>
          .
          <source>USENIX Association</source>
          , Berkeley, CA, USA,
          <fpage>6</fpage>
          -
          <lpage>6</lpage>
          . http://dl.acm.org/citation.cfm?id=
          <volume>2342875</volume>
          .
          <fpage>2342881</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>Archan</given-names>
            <surname>Misra</surname>
          </string-name>
          , Marion Blount, Anastasios Kementsietsidis, Daby Sow, and
          <string-name>
            <given-names>Min</given-names>
            <surname>Wang</surname>
          </string-name>
          .
          <year>2008</year>
          .
          <article-title>Advances and Challenges for Scalable Provenance in Stream Processing Systems</article-title>
          .
          <source>In Provenance and Annotation of Data and Processes</source>
          , Juliana Freire, David Koop, and Luc Moreau (Eds.). Springer Berlin Heidelberg, Berlin, Heidelberg,
          <fpage>253</fpage>
          -
          <lpage>265</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Luc</surname>
            <given-names>Moreau</given-names>
          </string-name>
          , Paolo Missier, James Cheney, and
          <string-name>
            <surname>Stian</surname>
          </string-name>
          Soiland-Reyes.
          <year>2013</year>
          .
          <article-title>PROV-N: The Provenance Notation</article-title>
          . World Wide Web Consortium, United States.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>S.</given-names>
            <surname>Muthukrishnan</surname>
          </string-name>
          .
          <year>2005</year>
          .
          <article-title>Data Streams: Algorithms and Applications</article-title>
          . now, 2600 AD Delft,
          <article-title>The Netherlands</article-title>
          . https://ieeexplore.ieee.org/document/8186985
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>Priya</surname>
            . Narasimhan and
            <given-names>Peter</given-names>
          </string-name>
          <string-name>
            <surname>Triantafillou</surname>
          </string-name>
          .
          <year>2012</year>
          .
          <article-title>SPADE: support for provenance auditing in distributed environments</article-title>
          .
          <source>In Proceedings of the 13th International Middleware Conference</source>
          . Springer, Springer, New York, NY,
          <fpage>101</fpage>
          -
          <lpage>120</lpage>
          . https://dl.acm.org/citation.cfm?id=
          <fpage>2442634</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Hendry</surname>
            <given-names>Raharjo</given-names>
          </string-name>
          , Min Xie, and
          <string-name>
            <surname>Aarnout</surname>
            <given-names>C.</given-names>
          </string-name>
          <string-name>
            <surname>Brombacher</surname>
          </string-name>
          .
          <year>2009</year>
          .
          <article-title>On modeling dynamic priorities in the analytic hierarchy process using compositional data analysis</article-title>
          .
          <source>European Journal of Operational Research</source>
          <volume>194</volume>
          ,
          <issue>3</issue>
          (
          <year>2009</year>
          ),
          <fpage>834</fpage>
          -
          <lpage>846</lpage>
          . DOI:http://dx.doi.org/10.1016/j.ejor.
          <year>2008</year>
          .
          <volume>01</volume>
          .012
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>R. W.</given-names>
            <surname>Saaty</surname>
          </string-name>
          .
          <year>1987</year>
          .
          <article-title>The analytic hierarchy process-what it is and how it is used</article-title>
          .
          <source>Mathematical Modelling</source>
          <volume>9</volume>
          ,
          <fpage>3</fpage>
          -
          <lpage>5</lpage>
          (
          <year>1987</year>
          ),
          <fpage>161</fpage>
          -
          <lpage>176</lpage>
          . DOI:http://dx.doi.org/10.1016/
          <fpage>0270</fpage>
          -
          <lpage>0255</lpage>
          (
          <issue>87</issue>
          )
          <fpage>90473</fpage>
          -
          <lpage>8</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Jonathan</surname>
            <given-names>A.</given-names>
          </string-name>
          <string-name>
            <surname>Silva</surname>
          </string-name>
          ,
          <string-name>
            <surname>Elaine R. Faria</surname>
          </string-name>
          , Rodrigo C. Barros,
          <string-name>
            <surname>Eduardo R. Hruschka</surname>
          </string-name>
          ,
          <string-name>
            <surname>André C. P. L. F. de Carvalho</surname>
            , and
            <given-names>João</given-names>
          </string-name>
          <string-name>
            <surname>Gama</surname>
          </string-name>
          .
          <year>2013</year>
          .
          <article-title>Data Stream Clustering: A Survey</article-title>
          .
          <source>ACM Comput. Surv</source>
          .
          <volume>46</volume>
          ,
          <issue>1</issue>
          ,
          <string-name>
            <surname>Article 13</surname>
          </string-name>
          (
          <year>July 2013</year>
          ),
          <volume>31</volume>
          pages. DOI: http://dx.doi.org/10.1145/2522968.2522981
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Sajid</surname>
            <given-names>Siraj</given-names>
          </string-name>
          , Ludmil Mikhailov,
          <string-name>
            <given-names>and John A.</given-names>
            <surname>Keane</surname>
          </string-name>
          .
          <year>2015</year>
          .
          <article-title>PriEsT: an interactive decision support tool to estimate priorities from pairwise comparison judgments</article-title>
          .
          <source>ITOR 22</source>
          ,
          <issue>2</issue>
          (
          <year>2015</year>
          ),
          <fpage>217</fpage>
          -
          <lpage>235</lpage>
          . DOI:http://dx.doi.org/10.1111/itor.12054
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <surname>Min</surname>
            <given-names>Wang</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Marion Blount</surname>
            , John Davis, Archan Misra, and
            <given-names>Daby</given-names>
          </string-name>
          <string-name>
            <surname>Sow</surname>
          </string-name>
          .
          <year>2007</year>
          .
          <article-title>A Time-and-value Centric Provenance Model and Architecture for Medical Event Streams</article-title>
          .
          <source>In Proceedings of the 1st ACM SIGMOBILE International Workshop on Systems and Networking Support for Healthcare and Assisted Living Environments (HealthNet '07)</source>
          . ACM, New York, NY, USA,
          <fpage>95</fpage>
          -
          <lpage>100</lpage>
          . DOI: http://dx.doi.org/10.1145/1248054.1248082
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          <source>[18] Ying Ming Wang and Kwai Sang Chin</source>
          .
          <year>2011</year>
          .
          <article-title>Fuzzy analytic hierarchy process: A logarithmic fuzzy preference programming methodology</article-title>
          .
          <source>International Journal of Approximate Reasoning</source>
          <volume>52</volume>
          ,
          <issue>4</issue>
          (
          <year>2011</year>
          ),
          <fpage>541</fpage>
          -
          <lpage>553</lpage>
          . DOI:http://dx.doi. org/10.1016/j.ijar.
          <year>2010</year>
          .
          <volume>12</volume>
          .004
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <surname>Yin</surname>
            <given-names>Zhang</given-names>
          </string-name>
          , Meikang Qiu,
          <string-name>
            <surname>Chun-Wei</surname>
            <given-names>Tsai</given-names>
          </string-name>
          , Mohammad Mehedi Hassan, and
          <string-name>
            <given-names>Atif</given-names>
            <surname>Alamri</surname>
          </string-name>
          .
          <year>2017</year>
          .
          <article-title>Health-CPS: Healthcare Cyber-Physical System Assisted by Cloud and Big Data</article-title>
          .
          <source>IEEE Systems Journal</source>
          <volume>11</volume>
          ,
          <issue>1</issue>
          (mar
          <year>2017</year>
          ),
          <fpage>88</fpage>
          -
          <lpage>95</lpage>
          . DOI: http://dx.doi.org/10.1109/JSYST.
          <year>2015</year>
          .2460747
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>