<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Petri Nets as Run-Time Models for Self-Adaptive Cyber-Physical Systems</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Lorenzo Capra</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Michael Köhler-Bußmeier</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Heiko Rölke</string-name>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Jan Sudeikat</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Dipartimento di Informatica, Università degli Studi di Milano</institution>
          ,
          <addr-line>Via Celoria 18, Milano</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Hamburg University of Applied Sciences</institution>
          ,
          <addr-line>Berliner Tor 7, D-20099 Hamburg</addr-line>
          ,
          <country country="DE">Germany</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>University of Applied Science of the Grisons</institution>
          ,
          <addr-line>Pulvermühlestrasse 57, CH-7000 Chur</addr-line>
          ,
          <country country="CH">Switzerland</country>
        </aff>
      </contrib-group>
      <fpage>164</fpage>
      <lpage>181</lpage>
      <abstract>
        <p>In our general research we study adaptive systems of autonomous agents - with a strong emphasis on agents in cyber-physical systems (CPS). To enable adaptivity, we have a special interest in agents that are embedded into an overall structure, called: organisation. Our Sonar formalism is a specification of the organisational structure; it is based on Petri nets. In this contribution we investigate the whole life-cycle of Sonar models, from (i) the analytical usage in the design phase, over (íi) their use as configuration data in the deployment phase, to (iii) their use as a digital twin used for cost-benefit reasoning at run-time during the Sonar-MAPE-Loop. We also present a rule set of transformations for Sonar models. These rules are applicable at diferent phases of the life cycle: They are used by the modeller at design time, e.g. to refine an early, abstract model into a more concrete one; they are also used by the run-time engine, i.e., the Sonar-MAPE-Loop, as adaption operations during a self-modification. Remarkably, these two phases - design and run-time - are intertwined in a cyclic way: Obviously, the Sonarmodel (usually amended by an deployment profile, called cube-protocols) is used to instantiate the running multi-agent system; but, conversely, we use process mining techniques to (i) adjust the deployment profile in a re-configuration phase or (ii) to trigger a complete re-design phase of the Sonar-model.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;Self-adaptation</kwd>
        <kwd>MAPE-loop</kwd>
        <kwd>cyber physical systems</kwd>
        <kwd>multi-agent systems</kwd>
        <kwd>models@run</kwd>
        <kwd>time</kwd>
        <kwd>Petri nets</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        the system’s model into the system so it can be used as knowledge during the MAPE-loop, an approach
known as models at run-time [
        <xref ref-type="bibr" rid="ref19 ref20">19, 20</xref>
        ].
      </p>
      <p>
        In previous work [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ] we identified four research challenges RC1 - RC4 for organisation-based MAS
in the CPS domain, which we recall here in short:
• Mining of Organisational Models (RC1): We will use techniques from process mining [22] to obtain
organisation models. As a speciality we treat mining as an ongoing, i.e., online process, which
takes execution data from logs together with the current organisational model and generates a
more appropriate model as a modification of the current one using incremental techniques like
[23, 24].
• Application Specific Support for Model Transformation (RC2): We need transformations, like
refinement operations, which are specifically designed for organisation models in the domain of
cyber-physical systems.
• Organisation Embedding and Execution Environment (RC3). Here, we study how we integrate
organisation models into a heterogeneous MAS in a (semi-)automated way. We argue that,
especially for adaptive systems, it is desirable to maintain the model as an run-time object to
support reflection and self-modification. This approach is known as models@run.time [
        <xref ref-type="bibr" rid="ref19 ref20">19, 20</xref>
        ].
• Development Support (RC4): For the practical use we have a need for patterns of inter-agent
structures (auctions, voting, social choice, etc.) in order to reflect best practices in industrial MAS
development. We have to study whether it is possible to incorporate these patterns as a kind of
profile when the organisational model is deployed into a MAS.
      </p>
      <p>Here, we study these challenges in the context of our Sonar framework [25, 26]. A Sonar model
is an Org-MAS specification that is designed to support the agents to deal with the system’s tasks. A
Sonar model describes the formal, organisation part of the MAS. More concretely, a Sonar model
is deployed as an Org-MAS, i.e., a network of OPAs (organisational position agents). These OPAs
represent the organisation as a macro structure; they enable the cooperation patterns pre-described by
the organisation and supervise the organisational constraints. They represent a position within the
organisation hierarchy, which comes with roles and obligations. However, the OPAs (organisational
position agents) are not responsible to implement these roles and obligations, because this is the
responsibility of the OMAs (organisational member agents). Each OPA acts as a proxy of its OMA into
the organisation. In the context of CPS the OMA usually represents an entity like a machine.
Example Figure 1 shows our standard example Org-MAS to illustrate the OPA/OMA network. It
consists of a formal organisation containing another organisation as a sub-part. We have the position
executive represented by an OPA. This OPA is connected to Alice, which is an OMA implementing the
position. Note that we allow for OMA-OMA interaction, e.g. between Alice and Bob, but his interaction
is somehow private and has to be distinguished from an ‘oficial’ organisation interaction that takes
places when Alice and Bob communicate via their OPAs Executive Operator . Fiona is an example for
an outside agent not belonging to the Org-MAS, i.e. an agent that neither is an OPA nor an OMA.</p>
      <p>Fiona
Alice
Bob</p>
      <p>Multi-Agent System</p>
      <p>Organisation
Formal Organisation</p>
      <p>Executive</p>
      <p>Sub-Organisation</p>
      <p>Coordinator</p>
      <p>Charly
Operator A</p>
      <p>Operator B</p>
      <p>Group 1</p>
      <p>Group 2</p>
      <p>pos
Deborah</p>
      <p>Elvis
organisation</p>
      <p>agent
organisational
position agent
organisational
member agent
external agent
formal channel
informal channel
organisational
membership
Aim of the Paper In this paper we will address the research challenges from the perspective of the
organisational Sonar-model underlying the systems. We present our vision how the four research
challenges will be addressed in the life-cycle of Sonar-models in an integrated way.</p>
      <p>In Section 2 we explain the general connection between the organisation model with a given
underlying cyber-physical system (CPS). Section 3 describes the use of Sonar-Models, i.e. their life-cycle. As
our MAS is self-adaptive we present basic transformation operations for Sonar-models in Section 4.
Section 5 demonstrates how the self-adaption mechanism exploits our basic transformation operations
in combination with given CPS key performance indicators (KPI) to establish a cost-benefit based
reasoning to enable a goal-directed adaption at run-time. Section 6 illustrates the presented concepts
by studying the price-of-anarchy in organisations for the example of a well-known coordination game:
the battle-of-sexes scenario. The work ends with a conclusion and outlook.</p>
      <p>
        Related Work The central approach to adaptivity in software engineering is known as the MAPE-K
approach, i.e., MAPE with knowledge K, where the knowledge has much in common with the
organisational concepts [
        <xref ref-type="bibr" rid="ref15">15, 27</xref>
        ]. A rational approach to adaption based on cost-benefit reasoning is studied
in [28]. The work presented here also has some connections to our research on adaption state spaces
[29, 30], which we have studied for the self-modifying Petri net class of Hornets [31, 32, 33].
      </p>
      <p>Prominent examples of Org-MAS from the design and implementation perspective are AGR [34],
MOISE [35], and OPERA [36]. An overview is given in the handbook of Dignum et al. [37]. A
complementary approach to organisational design comes from Process Mining [22], which also includes
the mining of structures.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Connecting a CPS with its Organisation</title>
      <p>
        We follow an agent oriented approach to CPS [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. The organisational network of OPAs can be seen as
an overlay onto this CPS, which gives the system a desired structure. Agents are used to control and
represent physical devices (e.g. according to [38]). Thus, each CPS component acts as a member agent,
i.e. an OMA, of the Org-MAS. Let us have a look at the basic perspective on these CPS agents, i.e. to
consider them as a network of autonomous components with sensors and actuators.
      </p>
      <sec id="sec-2-1">
        <title>2.1. The underlying CPS</title>
        <p>The CPS defines some conditions on the systems as it provides the existing sensors and actuators. The
world state is accessible only via the given sensors and the agents can manipulate the world only via
the given actuators.</p>
        <p>We assume that the MAS state is not directly observed, but observed. There are two classes:
1. Boolean observables B : States → B, i.e., B(state) is a state predicate.
2. Quantified observables R : States → R, i.e., R(state) is a key performance indicator (KPI).</p>
        <p>Agents observe the system only by these sensors, i.e., they cannot distinguish states that are
indistinguishable by sensors. For each MAS we assume a given set of state predicates and one of KPIs.</p>
        <p>Actions define the operations in the teamwork protocols: act : States → States. We assume a given
set ACT of actions for our CPS.</p>
        <p>Definition 1.</p>
        <p>A cyber-physical system (CPS) is modelled as the tuple</p>
        <p>CPS = (States, ΦB, ΦR, ACT )
• States is the set of all system states.
• ΦB is a set of Boolean observables B : States → B.
• ΦR is a set of quantified observables R : States → R (performance indicators).
• ACT is a set of actions.</p>
        <p>
          The agents’ activities are structured by agent interaction protocols. It is convenient to use a
multiparty variant of the well-known workflow nets [ 39, 39] to specify these protocols. These nets are
called distributed workflow nets ( Dwfn) [
          <xref ref-type="bibr" rid="ref22">40, 26</xref>
          ]. We assume that each agent activity in the interaction
protocol  is connected to an action, i.e., it has a specified efect on the observables.
        </p>
        <p>These Dwfn are interactions between roles  ⊆ ℛ , where a role induces a fragment [], i.e., a
subnet of the workflow, which contains the part that is assigned to . Agents must have the required
capabilities to implement a role, and the role must own the required rights to execute the actions that
are part of the role fragment.</p>
      </sec>
      <sec id="sec-2-2">
        <title>2.2. The Organisational Overlay: Sonar</title>
        <p>
          In the following we consider a multi-agent perspective for CPS [
          <xref ref-type="bibr" rid="ref4">4</xref>
          ]. Additionally, we use organisations
(here: organisation-based MAS, short: Org-MAS) to structure the systems in the large [
          <xref ref-type="bibr" rid="ref23 ref3">3, 41</xref>
          ]. This
organisational structure of the MAS can be seen as a system overlay [
          <xref ref-type="bibr" rid="ref23 ref3">3, 41</xref>
          ]. We use Sonar as our
organisation framework. In the following, we recall some basics and refer to [
          <xref ref-type="bibr" rid="ref24 ref25">25, 26, 42, 43</xref>
          ] for details.
Sonar-Tasks A central concept for Sonar is that of a task. A task 0 is an obligation for an agent
(generated either from the environment or the MAS itself) to reach a state by taking actions in a way
that (i) satisfies the goal goal (0), which is a formula defined using the boolean observables, and (ii)
optimises the efect on the KPI. We assume a given set 0 of initial tasks. An initial task is triggered by
the observables by if-then rules, denoted as:
        </p>
        <p>if ⟨trigger⟩ then ⟨create initial task 0 ∈ 0 ⟩ end
Here, a trigger is an expression in propositional logic where we have the boolean observables B and
the inequalities (R ≤ ) for each quantified observable R and each value  ∈ Q as logical atoms.
We use (R ≥ ), (R = ), (R &lt; ), etc. as abbreviations. A state  enables the task if its trigger
evaluates to true in .</p>
        <p>The Sonar-Organisation We assume a given cyber-physical system CPS and a set TR of trigger
rules. An organisation Org = (, , ℛ, ) consists of a organisation net  , a set of OPAs , a set
of roles ℛ, and a set of Dwfn  that is based on these roles. Our standard example for a Sonar
organisation is shown in Figure 2. It has one initial task  = task1[Prod,Cons] for the OPA 1, placed
at the top. Here, 1 has the obligation to handle the task via the protocol  [Prod , Cons]. In this
case, Prod and Cons are all the roles in the Dwfn  . The highlighted part of the net describes a
Sonar-Team that has been formed at run-time to handle the task. The existing conflicts have been
resolved by reasoning of the OPAs. Note that conflicts are always internal to OPAs.</p>
        <p>
          The organisation net  = (, ,  ) is a Petri net [
          <xref ref-type="bibr" rid="ref27">45</xref>
          ], where each place is of the form  = task[],
which describes a task or sub-task for the agent  to establish the role part  of the Dwfn . The tasks
are either generated in the environment or they are sub-tasks, generated by the organisation itself. A
place  is a task whenever ∙  = ∅ and we set 0 = 0(Org ) := ∘  := {0 ∈  | ∙ 0 = ∅}.
        </p>
        <p>Each task is handled by the transitions of the organisation net, which are called team-operators. We
have four types of operators:
1. Delegate: The task to implement Dwfn [] is delegated from agent  to . Only the delegation
operation delegates the ownership of a task.
2. Split: The task to implement  = {1, . . . , } in  is split into  sub-tasks to implement {}
in .
3. Refinement: The Dwfn [] is replaced by ′[1, . . . , ], which has to be a behaviour equivalent
refinement, i.e. they are bisimilar.
4. Assign execution: The Dwfn [] is assigned to an agent for execution.</p>
        <p>
          Each team-operator  also imposes a constraint  () ∈ Ψ onto the execution of the generated
teamDwfn  where Ψ denotes a given set of constraints, which could be given in diferent ways, e.g. as a
temporal logic specification or as stochastic constraints as we have done in [
          <xref ref-type="bibr" rid="ref25">43</xref>
          ].
        </p>
        <p>Let  be a set of OPAs. We define  := deleg ∪ split ∪ refine∪ assign as:
deleg := {︀ d ({task[]}, {task[]})</p>
        <p>⃒⃒  ∈  ∧  ∈ () ∧ ,  ∈  ∧  ̸=  ∧  ∈ Ψ }︀
split := {︀ s ({task[1,...,]}, {task[1], . . . , task[]})</p>
        <p>⃒⃒  ∈  ∧ {1, . . . , } ⊆ () ∧  &gt; 1 ∧  ∈  ∧  ∈ Ψ }︀
refine := {︀ r ({task[]}, {task′[]})
⃒⃒ , ′ ∈  ∧  ̸= ′ ∧ [] ≃ ′[] ∧  ∈  ∧  ∈ Ψ
︀}
assign := {︀ e ({task[]}, ∅) | , ′ ∈  ∧  ∈  ∧  ∈ Ψ
︀}</p>
        <p>
          The set of all team operators is  . Each set  ⊆ 
Net  = (, ,  ) where  = ∙  ∪  ∙ . The flow
 = op (,  ) ∈  where op ∈ {d, s, r, e} is given by ∙  :=  and ∙ :=  .
of these operators induces a Sonar-Organisation
 is also encoded in  , i.e., for an operator
Team-Formation within the Sonar-MAPE-Loop
The semantics of a Sonar organisational model
[
          <xref ref-type="bibr" rid="ref22">40</xref>
          ] (i.e. the execution loop, called Sonar-MAPE-Loop) is defined on top of the operational semantics of
Petri nets. Whenever a task is triggered we put a token on the corresponding place. For each task we fire
transitions in the organisation net to handle the task: we delegate it to another OPA, refine the
DWFN,
split the role in the DWFN into sub-roles, or simply execute the task. The resulting structure is called a
team. Formally, a team is a partial run [
          <xref ref-type="bibr" rid="ref28">46</xref>
          ] of the organisation net. Since the team operators assign
execution are the only transitions with empty post-set, the empty marking is only reached whenever all
sub-tasks are assigned. The underlying partial run is called a team . From this team  we can derive
the Dwfn () that defines the interaction among the involved agents. Then, the team develops a
team plan – based on  – via negotiation.
Example For the organisation in Figure 2 the highlighted nodes define such a partial-order run, i.e. a
team . The three transition labelled with a hammer at the agents 21, 2 and 4 show the assignment
operators, so these agents really implement the roles in the team-Dwfn . The team  shown here will
execute a team-Dwfn (), that is generated as the composition of the services of final transitions:
() = (PC 3[Prod 1] ‖ PC 3[Prod 2] ‖ PC [Cons])
The transition labelled with light bulbs denote ‘inner’ agents. They do not participate directly in the
team interaction, but, since the constraints of inner agents have to be fulfilled in the execution of (),
too, these agents fulfil a coordinating purpose.
        </p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>3. The Life-Cycle of Sonar-Models</title>
      <p>The life-cycle of Sonar-models is shown in Figure 3. We start with some design goals. These are
used in the design phase to develop a Sonar-organisation model and to generate some assumptions
about the environment, i.e. the CPS. From these assumptions we derive a deployment profile (called
Cube-Protocols) during the configure phase. For example, the Sonar-model specifies the obligatory
nature of the organisational constraints. This might range of a ‘liberal-mode’ (i.e., organisational
constraints are only recommendations for agents), over ‘liberal-with-reputation’ (i.e., agents are free in
their decisions, but their behaviour is evaluated and a mismatch reduces their reputation), to ‘restrictive’
(i.e., for deviation against the organisational constraints is observed – using a sliding time window –
and a violation is blocked). For this example the diferent deployment variants come along with an
increasing implementation complexity.</p>
      <p>
        Both parts, organisation model and deployment configuration profile are used to instantiate the
Org-MAS (here: the OPA/OMA-MAS) together with the digital twin model of the organisation (cf. [
        <xref ref-type="bibr" rid="ref29">47</xref>
        ]).
The latter is used during the planning phase of our Sonar-MAPE-Loop [
        <xref ref-type="bibr" rid="ref25">43</xref>
        ] to predict the costs and
benefits of applying transformation during the self-adaption step of the MAPE-loop (cf. also Sect. 5).
      </p>
      <p>The Loop generates log data, that is used for two purposes. We might update our assumptions
about the environment, which will trigger a re-configuration of the deployment profile, while leaving
the organisation model untouched. The second part uses process mining techniques to update the
organisation model itself, which might trigger a complete re-design.</p>
      <p>Note that we indeed have a live cycle here, as these two phases – design and run-time – are intertwined:
Obviously, the Sonar-model is used to instantiate the running multi-agent system; but, conversely, we
adjust the deployment profile in a re-configuration phase or even start a complete re-design phase of
the Sonar-model.</p>
      <p>
        The areas denoted RC1 to RC4 define research challenges for organisation-based MAS for CPS as
identified in previous work [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ]. From the life-cycle one observes that a Sonar-model is modified at
diferent stages: during the design phase (cf. RC3) and during the re-design triggered by organisational
mining (cf. RC1). Additionally, the Sonar-model is used as a part of the deployment stage (cf. RC4). The
deployed Sonar-model is also object to transformations executed in a self-adaptive way (cf. RC2). These
transformations are executed within the Sonar-MAPE-loop [
        <xref ref-type="bibr" rid="ref25">43</xref>
        ]. We study these transformations in
more detail in Section 4.
      </p>
      <p>Note that the research challenges nicely correspond to aspects of the Sonar live cycle. Therefore, we
claim that the understanding of this live cycle is crucial to tackle our challenges.</p>
    </sec>
    <sec id="sec-4">
      <title>4. Transformation of Sonar-Models by Refinement</title>
      <p>
        The most elementary way to think about designing or re-designing a Sonar-model is given by model
transformations, especially refinement (needed in the design and in the re-design phase) and abstraction
(needed in the re-design phase mainly). We can identify transformations in all components of a
Sonarmodel. These transformations establish the basic transformations used in the self-adaption within the
Sonar-MAPE-loop. Note that there is a notion of an organisation of being well-formed [
        <xref ref-type="bibr" rid="ref22">40</xref>
        ] and we
require these transformations to preserve well-formedness.
      </p>
      <p>For each aspect of the specification Org = (, , ℛ, ) we have specific operations (the complete
list is given in Figure 4). Note that in practice these transformations are triggered by diferent activities:
A transformation of the observables  or positions  is mainly triggered by changes in the underlying
CPS; transformations of the Dwfn in  are usually triggered by process mining; and the change of
the Network  (including modification of the constraints  ()) is triggered by self-observations of the
Org-MAS within the MAPE-Loop.</p>
      <p>Refinements are invertible by nature (maybe together with some book-keeping mechanism).
Therefore, refinement is not only uni-directional from an ever more detailed model. Our approach also includes
the aspects that whenever we have to undo a lot of ‘older’ refinement operations of the past before
we can apply ‘new’ ones, i.e. whenever we have the current organisation Org = (  ∘ · · · ∘  1)(Org 0),
then the transformation gets more involved and has the form:
^(Org ) = ( ′ ∘ · · · ∘
 1′ )(Org ) = (︀ ( ′ ∘ · · · ∘
 1′ ) ∘ ( 1− 1 ∘ · · · ∘
 − 1))︀ (Org 0)</p>
      <p>
        We cannot give a detailed formal specification of all these transformations given in Fig 4. We will
provide a precise notion of an organisation model as an abstract data type together with the specification
of all the refinements mentioned here as operations expressed in Maude [
        <xref ref-type="bibr" rid="ref30">48</xref>
        ] in future work.
1. Observables  and Positions 
a) take/loose responsibility for tasks
b) create/delete observables: B and R
c) create/delete/split/join OPA’s net parts
d) changes access rights to resources
      </p>
      <p>Note: These transformations in the Org-MAS are mainly triggered by the underlying CPS-MAS.
2. Interaction Protocols/Workflows 
a) Refine/Abstract workflow net 
b) Modify role partition  on activities</p>
      <p>Note: These transformations in the Org-MAS are mainly triggered by the organisation mining (cf. RC1).
3. Organisational Network (constraint  modification):
a) Modify the constraint  of an operation
b) Escalate constraint  up- or downwards the network hierarchy</p>
      <p>Note: These transformations in the Org-MAS are mainly triggered by self-observations of the Org-MAS.
4. Organisational Network (structural modifications of  ):
a) add/delete a task delegation operation d ({task[]}, {task[]})
b) add/delete a task split operation s ({task[1,...,]}, {task[1], . . . , task[]})
c) add/delete a task refinement operation r ({task[]}, {task′[]}) for a refinement ′
d) add/delete a task assignment operation e ({task[]}, ∅) (provided that the OPA has the required
capabilities/rights for the role )
Note: These transformations in the Org-MAS are also triggered by self-observations of the Org-MAS, but
usually are carried out with a lesser frequency.</p>
    </sec>
    <sec id="sec-5">
      <title>5. Adaption of Sonar-Models as a Self-X Property</title>
      <p>
        Our model allows for a goal-directed adaptation within the Sonar-MAPE-loop [
        <xref ref-type="bibr" rid="ref25">43</xref>
        ], which we coin as
Self-Modification at Run-Time (SM@RT) in the following.
      </p>
      <sec id="sec-5-1">
        <title>5.1. Transformations as Second-Order Teamwork</title>
        <p>As a special feature the execution of the team-plan may involve transformation statements, which
modify the Sonar-model at run-time and therefore enable the cooperative, self-organised adaption of
the organisation:</p>
        <p>Organisation → Team → Plan → Transformation → new Organisation → ...</p>
        <p>The formalism of Sonar [26] defines a notion of well-formedness to guarantee that each task may be
handled by at least one team etc. Additionally, transformations in well-formed organisations preserve
the well-formedness.</p>
        <p>Our Sonar framework allows us to measure costs and benefits of a transformation. The set of all
possible transformations defines a search space. Obviously, the search space considering all possible
compositions of atomic transformations is much to big for an exhaustive search and we need more
information to overcome this complexity.</p>
        <p>Assume that all transformations are considered with decreasing priority in the cost-benefit reasoning:
^1, ^2, . . . For Sonar, this order is given implicitly by probabilities assigned to teams and second-order
workflows, since probabilities on team operators generate a probability on teams. Every team  defines
a team workflow () and the probabilities within the workflow induce a probability on interaction
traces. Since every trace of a second-order workflow describes a transformation, we obtain a probability
over transformations. Therefore, the enumeration order of transformations is simply from high to low
probability.</p>
      </sec>
      <sec id="sec-5-2">
        <title>5.2. Costs and Benefits of a Transformation</title>
        <p>Firstly, we have a cost measure of transformations. In Sonar a transformation is carried out at run-time
using the standard teamwork; the main diference is that the team executes a second-order Dwfn, where
the actions attached to transitions execute atomic transformation operations as given in Section 4.
A transformation is composed similarly to other interaction protocols using process operators (like
sequence ( 1;  2), and-split ( 1‖ 2), or-split ( 1 +  2), etc.) and atomic transformations. We denote
these transformations as a complex composition in the following form:
(1)
^ = ( 2;  5)‖( 4 + ( 4;  6))</p>
        <p>costs(^) = const · | ^|
The costs of such a transformation ^ could be measured by the number of transformation steps |^| to
be performed:</p>
        <p>This measurement treats all transformation steps uniformly; the approach can be generalised to the
weighted sum of all transformation steps whenever we can assign individual costs to transformation
steps.</p>
        <p>As discussed above we will use process mining techniques to identify those transformations that
are suitable to bring the current organisational model ‘closer’ to the observed behaviour as we assume
that the observed behaviour contains valuable hints for the organisation originating from the OMA’s
reasoning processes. This mining will initialise the probabilities of the second-order operators and
second-order workflows. 1 As our basic transformations are mainly refinements and their counterpart
abstractions, we coin this idea under the slogan Mine2Refine .</p>
        <p>
          Secondly, we use a benefit measure, which is the estimated average evaluation of the quantified
observables, i.e., the KPIs R(state). Typical indicators include execution or production time, energy or
resources needed, quality of the process, etc. We obtain the benefit using a simulation of a digital twin
of the organisation model at run-time within the Sonar-MAPE-Loop [
          <xref ref-type="bibr" rid="ref25">43</xref>
          ]. The KPIs are defined by the
underlying CPS.
        </p>
        <p>
          Assume a Sonar-organisation model Org , which is the input of the analysis sketched in Figure 5. The
organisation model is basis to deploy the Sonar-MAPE-Loop. Within the planning phase of the loop we
use a digital twin of the organisation where the decision logic of each OMA is modelled as a stochastic
distribution over actions. The twin model of the organisation is fed into a twin model of the Loop,
which is configured by meta-parameters (cf. [
          <xref ref-type="bibr" rid="ref25 ref29">43, 47</xref>
          ]. The adaption dynamics of this Sonar-MAPE-Loop
twin is considered in the analysis phase, as sketched in the lower part of Figure 5. Here, we extend a
stochastic distribution over tasks to a distribution over teams; together with the stochastic behaviour
model of OMAs (which is part of our digital twin model), we can compute the distribution over team
protocol processes. To simplify the description of benefits, we make the assumption that the efect
of actuators on KPIs is additive in the following. Therefore the concurrently running teams do not
interfere and we can calculate the estimated KPI for the current organisation simply as a stochastic
superposition of the KPI efect of all teams. This estimation of the efect on the  KPIs (key performance
indicators) is the evaluation val (Org ) ∈ R of the current organisation.
        </p>
        <p>
          This simulation evaluates the KPI for the resulting organisation ^(Org ) (as described in [
          <xref ref-type="bibr" rid="ref26">44</xref>
          ]) as well
as the complete dynamics including future transformations as well (cf. [30]).2 This simulation also
anticipates the uncertainty about the environment and the stochastic distributions used [
          <xref ref-type="bibr" rid="ref31">49</xref>
          ].3
The absolute benefit of changing Org to Org ′ is the vector:
benefit(Org , Org ′) := val (Org ′) − val (Org )
(2)
1Note that it is possible to change these probabilities at run-time, too, by the use of second-order operators, teams, and
workflows. This second-order transformations will require a third-order teamwork.
2The study of adaption state spaces (like in [30]) in combination with stochastic distributions of adaptions is subject to
ongoing research. The usage of the rewriting engine Maude [
          <xref ref-type="bibr" rid="ref30">48</xref>
          ] to support analysis is studied in [32, 33].
3The same analysis technique is also used during the design and the deployment phase to select a deployment profile that
corresponds to the best setting of meta-parameters used in the twin model [
          <xref ref-type="bibr" rid="ref29">47</xref>
          ].
        </p>
        <p>As we define the benefit as a vector, a transformation may be an improvement in some
dimensions, while being a worsening in others. This leads to the question under which circumstances a
transformation might be considered as acceptable among the agents.</p>
      </sec>
      <sec id="sec-5-3">
        <title>5.3. Commonly Acceptable Transformation</title>
        <p>As the team agents may have diferent partial views on the system, their evaluation may vary. Therefore,
we only consider the sign of the absolute benefit to obtain a more stable measurement. For a given
indicator  the sign of benefit(Org , Org ′)() indicates whether the adaption increases the KPI :
Δ(Org , Org ′)() := sgn(benefit(Org , Org ′)())
(3)
Therefore, the vector Δ(Org , Org ′) ∈ {− 1, 0, +1} characterises the adaption w.r.t. all  KPI. We
call Δ(Org , Org ′) the trend vector of the adaption. Usually, an adaption leads to non-uniform changes,
where the value increases for some indicators, while decreases for other, which leads to incomparable
vectors (i.e. we have neither Δ(Org , Org ′) ≤ 0 nor Δ(Org , Org ′) ≥ 0).</p>
        <p>The simplest adaptations from Org to Org ′ are those where the OPAs have a common
understanding that efect is positive on all KPI, i.e., whenever Δ(Org , Org ′) ≥ 0. In this case the adaption is
indisputably acceptable among the OPAs.</p>
        <p>Whenever not all efects are positive, i.e., Δ(Org , Org ′) ̸≥ 0, then the agents have to negotiate
whether the adaptation is discarded. Whenever they discard it, the next adaption candidate Org ′ has to
be considered; whenever the OPAs agree not to discard it, then they start to negotiate, i.e., they have to
define additional relationships on incomparable vectors.</p>
        <p>To establish a common believe that the adaption benefit should be considered as an improvement we
have to re-interpret KPIs. This is done by a mapping  from the KPI vector to a lower dimensional one.
(4)
(5)
(6)
A KPI reduction is a mapping  : R → R that preserves the existing ordering (but may add them):
v1 ≤ v2 =⇒ (v1) ≤ (v2)
Intuitively, whenever an OPA considers an adaption to be be an improvement, this will remain true
under any reduction.</p>
        <p>We extend the notation of benefit and trend to reductions:
benefit(Org , Org ′) := (val (Org ′)) − (val (Org ))</p>
        <p>Δ(Org , Org ′)() := sgn(benefit(Org , Org ′)())</p>
        <p>The former notations could be considered as special cases, where the reduction is the identity function.
A KPI reduction  with Δ(Org , Org ′) ≥ 0 is called a compromise. Using this terminology negotiation
among the OPAs is equivalent to agree upon a compromise . Such a compromise must always exists as
shown by the following example.</p>
        <p>Example The most common approach to obtain a compromise is to define exchange rates  for each
KPI, i.e. we have a money-like mechanism to compare KPI. This is expressed by a linear mapping:
money(v) = a · v = ∑︀=1 1 · 1 + · · · +  · , where we require that the exchange rates are positive:
a = (1, . . . , ) ≥ 0 to ensure monotonicity. In this case money : R → R with  = 1, i.e., the
reduction is maximal w.r.t. to the resulting dimension of the KPI vector.</p>
        <p>So, we implement self-adaption as a distributed search among the OPAs for a transformation that
has the best balance of costs and benefits. Of course, in practice, this self-organised transformation is
restricted by the bounds of the agents, i.e. limited or outdated data, imprecise predictions about the
environment, restricted computational power, etc.</p>
      </sec>
    </sec>
    <sec id="sec-6">
      <title>6. Example: A Coordination Game</title>
      <p>The following example for a transformation in Sonar is based on the battle-of-sexes scenario, which is
well-known in game theory. Two agents must choose between two actions, labelled as  and . They
receive a positive reward if they choose the same action and zero otherwise. In this game, the first agent
prefers action , while the second prefers . If we assume that the reward for the preferred outcome is
three times higher than for the other, then the game is specified by the following pay-of matrix.
A game theoretical analysis shows that we have two Nash equilibria for pure
strategies: (, ) and (, ). It can be shown that this game has a unique
equilibrium for mixed strategy, where both agents choose their preferred
action  = 75% of the time.</p>
      <p>(3, 1)
(0, 0)</p>
      <p>(0, 0)
(1, 3)</p>
      <p>
        The game is modelled by a very simple multi-party workflow net (shown in Fig. 6). We use Renew
syntax [
        <xref ref-type="bibr" rid="ref32">50</xref>
        ] to implement the nets. The sources are available at https://github.com/koehler-bussmeier/
bos. For each role (shown on the left and on the right side) the choice between the two options  and 
is resolved by the agent’s decision logic  of the agents and the organisation configuration  . More
concretely, the choice is resolved randomly by the Renew-inscription:
      </p>
      <p>prob = c*p + (1-c)*q; b = Math.random() &lt; prob
Here,  denotes a probability as specified by the organisational  and  is a probability as specified by the
member agents’ decision logic  ; these two probabilities are combined using the so-called organisation
impact , which is a meta parameter of the twin of our Sonar-MAPE-Loop. These values are obtained
by the calls this:getProb(task,p,q); this:getCorg(c).
The Sonar-Organisation The situation described is known as a coordination game because the
agents would benefit from coordinating their actions in advance. In this scenario, the social welfare,
which is the sum of the individual pay-ofs, is 3+1 = 1+3 = 4 in both cases. However, in uncoordinated
games, a mixed strategy is the best choice, and agents only coordinate in 0.75 · 0.25 + 0.75 · 0.25 = 0.375
of the cases, leading to an expected pay-of of (0.75 · 0.25 + 0.75 · 0.25) · 4 = 1.5. The ratio 31+.51 = 2.66..,
called price-of-anarchy, measures the need for an external coordination mechanism.</p>
      <p>
        For MAS, this mechanism is termed an organisation [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ]. The Sonar-Org-MAS of this scenario is
depicted in Fig. 7. The primary purpose of the Sonar-Org-Model is to assemble a team in response to
certain triggers. It determines the workflow net used for the response and the involved agents and sets
constraints on the agents’ decisions, represented by parameters  and  .
      </p>
      <p>The Org-Model specifies three organisational agents (OPAs): 0, 1, and 2. The set of operators
belonging to each OPA is shown by the labelled rectangles in the organisation net. The organisation
manages two tasks which are the places on the top of Fig. 7. Tasks are generated by the environment by
the transitions with the synchronisation channel :start(trigger,wfnName) on the top. It is the OPA 0
that will react to both triggers. The first task triggers the team-formation process for the battle-of-sexes
interaction protocol  . The protocol  defines the interaction of two roles 1 and 2. The team
formation for this task is specified by the bold subnet on the left, which specifies that role 1 is finally
assigned to the agent 1 and 2 to 2. (Please ignore the shaded subnet in the middle for the moment,
since it is not there initially, but will be added as the efect of the transformation.)
Second-Order Workflow for Adaptation Note that the agents can’t do any better than to choose
the mixed strategy of a Nash-equilibrium. But even then they have to pay a price, which is called
the price-of-anarchy as we have seen above. Therefore, whenever the agents already are in a
Nashequilibrium then individual learning is not a source of improvement anymore – instead, we have to
modify the organisational structure.</p>
      <p>In our model the organisation may define constraints that drive the agents choices into a desired (i.e„
cooperative) state. But this depends on the organisational impact mentioned in Sect. 3. Whenever the
impact is low or moderate (which would correspond to the ‘recommendation’ or the ‘reputation’ mode
mentioned above) then the only option of the organisation to improve the pay-of is a regulation of the
available options, i.e., a structural modification of the interaction protocol.</p>
      <p>The right side of the organisation in Fig. 7 handles a another task that triggers the adaptation. It
initiates the team formation for a second-order workflow (cf. Fig. 8), which alters the role fragment so
that the second agent always chooses option  (i.e., we force the second agent to deviate from its current,
optimal mixed strategy). The resulting workflow net is named  ′ in the following. The construction
essentially removes the dashed arcs and the right-most transition and re-normalises the probabilities in
the workflow net of Fig. 6.</p>
      <p>This structural modification is formalised by the subnet modify WFN. Furthermore, this second-order
workflow extends the original organisation model. The shaded area of the organisation net in Fig. 7
shows the nodes that will be added by the second-order protocol. The modification is formalised in the
lower subnet (modify Organisation Model). The efect of this modification is that now there are two
alternative teams that may be generated for the left task: one team will execute the original  and the
new one  ′. Note that for both teams it will be an interaction of the OPAs 1 and 2.</p>
      <p>Since we add new nodes to each agent block the second-order protocol has three roles and these
are assigned to the three agents 0, 1, and 2. This is necessary since a modification of the subnet
 the organisation net in Fig. 7 has to be executed by the OPA  itself, since no other agent is
allowed to manipulate the structure of . The second-order workflow net also has to synchronise the
transformation steps, e.g. we have to add the operator for a task delegation from 0 to 1 (formally:
the transition d ({task0′[1]}, {task1′[1]})) into the subnet of 0 before 1 adds the operator for
task assignment (formally: the transition e ({task1′[1]}, ∅)) to its subnet. For this transformation
the constraint  defines a probability how the conflict on the task place
task0[1,2] is resolved. For a
better interpretation of the simulation results we set the probability to choose the new team is 100%.</p>
      <p>The transformation defined by the subnet</p>
      <p>modify Organisation Model is constructed by elementary
transformations as given in Figure 4 and has the form:
  =
︁(
︁( (︁
add (︁ r ({task0[1,2]}, {task0′[1,2]}) ;</p>
      <p>︁)
add (︁ s ({task0′[1,2]}, {task0′[1], task0′[2]}) ;
︁)
add (︁ d ({task0′[1]}, {task1′[1]}) ;
︁)
add (︁ e ({task1′[1]}, ∅)</p>
      <p>︁)
‖
add (︁ d ({task0′[2]}, {task2′[2]}) ;
︁)
add (︁ e ({task2′[2]}, ∅)
︁) )︁
Analysis of the Model In the following we we will perform a stochastic analysis of our Sonar-model
(i.e. an analysis of the Sonar-MAPE-Loop) as sketched in Figure 5. For a typical cyber-physical systems
(CPS) we would evaluate our models using key performance indicators like throughput, occupation, etc.
To simplify the presentation we use the price-of-anarchy as our only performance indicator. Therefore,
the benefit of the adaptation modelled in this example is the change in this value and the costs are
measured by the number of transitions in the second-order protocol in Fig. 8. As we have already a
one-dimensional KPI vector there is no need for a reduction in this simple scenario.</p>
      <p>During the planning phase of our MAPE-Loop we use a stochastic simulation of our model to predict
the efects of the adaptation. The sources are available at https://github.com/koehler-bussmeier/bos. In
the simulation, we have three phases. Firstly, we initiated the first-order battle-of-sexes workflow

(Fig. 6) 100 times to ensure some statistical stability. Secondly, we generated the adaptation tasks which
triggers the team-based execution of the second-order workflow in Fig. 8. This adaptation results in a
modified version  ′ of the first-order workflow</p>
      <p>, where the second agent persistently chooses option
, and in an adjustment in the organisation so that this protocol would always be adopted from that
point on. As explained above after the transformation the organisation is in a state such that the new
protocol  ′ is always chosen. Finally, we generate another 100 trigger events and the protocol  ′ is
executed the same number of times.</p>
      <p>Typically, we would repeat the simulation multiple times to establish error ranges, but for this
illustrative scenario, we decided to omit this step.</p>
      <p>before and . . .</p>
      <p>after adaptation</p>
      <p>before (expected) after (expected)
outcome</p>
      <p>(, )
(, ) or (, )
(, )
20%
62%
18%
18, 75%
Simulation Results (left) and Expected Values (right) for the Pay-Of before and after our Adaptation</p>
      <p>The simulation results (given in the left columns of Table 1) are in good alignment with the analytical
results (right columns): In the initial configuration of this example, we can expect (, ) in 0.75 · 0.25 =
18, 75% of the cases, with an outcome of (3, 1); for symmetry reasons, we have the same probability
for (, ). In 62.5% of times, the agents will choose opposite options.</p>
      <p>After the adaptation has taken place, we expect that in 0.75 · 1 of interactions, the agents will play
(, ) and in 0.25 · 1 of interactions, the agents will play (, ). This leads to the expected social welfare
of 0.75 · (3 + 1) + 0.25 · (0 + 0) = 3. So, the new price-of-anarchy is 3+1 = 1.33.., which is a substantial
3
improvement from the initial value of 31+.51 = 2.66... We have: benefit(Org , Org ′) = 2.66.. − 1.33.. =
1.33.. &gt; 0 and costs(^) = const · | ^| = const · 8.</p>
      <p>We could also consider an extension of the organisation model where we generate a new protocol
 ′′ from  , which is obtained by deleting the option  for the second agent. The resulting second-order
protocol looks almost identical to the presented one and therefore the transformation costs are identical,
too.</p>
      <p>On the one hand, this adaptation removes an option and therefore the coordination becomes simpler.
On the other hand, the coordinated outcome is less desirable. A similar calculation shows that restricting
the agents’ options is not beneficial: Removing option  for the second agent results in a welfare of
0.25 · (3 + 1) + 0.75 · (0 + 0) = 1. This leads to a new price-of-anarchy of 3+1 1 = 4. In this case the
benefit is negative:</p>
      <p>benefit(Org , Org ′) = 2.66.. − 4.0 = − 1.33.. &lt; 0
So, we can observe that simply enforcing some coordinated behaviour is not a good idea unless we
have considered the concrete change for the expected pay-ofs.</p>
    </sec>
    <sec id="sec-7">
      <title>7. Conclusion</title>
      <p>In this paper, we addressed four central research challenges for CPS (which we identified in a previous
publication) from the perspective of the life cycle of Sonar-models. Here, we have shown that the life
cycle addresses all challenges in a uniform and integrated way. Remarkably, design phase and execution
are intertwined in a cyclic way: On the one hand, a Sonar-model is used to instantiate the running
multi-agent system; but, conversely, we use process mining techniques to adjust the deployment at
run-time.</p>
      <p>
        A special focus was put on basic transformation operations as they are used throughout the life cycle,
mainly during design time, but also as the basic operations during the self-adaption, which is performed
at run-time as part of the Sonar-MAPE-Loop. In current work, we integrate the transformation steps
into our development tools. Organisations are represented by an abstract data type and the refinements
are specified as algebraic operations. We are working on a prototype variant expressed in Maude [
        <xref ref-type="bibr" rid="ref30">48</xref>
        ].
      </p>
      <p>In future work we would like to study to which extend it is possible to avoid the ‘expensive’ analysis
of the adaption state space and replace it by a static analysis of the organisation net itself.</p>
      <p>In another thread of research, we consider the evaluation of MAS designs per-se, i.e., the organisation
models themselves. As stated above, for Sonar the probability distributions on second-order teams
induces a probability over transformations. Obviously, a well-designed organisation is supposed to
generate those transformations that are ‘cheap’ and ‘beneficial’ at the same time with a higher probability.
This idea could be used to evaluate the design space of all organisations, i.e., an organisation is better
than another one whenever is has a better expected cost-benefit ratio in average. In future work we
like to interpret the cost-benefit ratio as the reward of a transformation, which will turn the adaption
state space (where states are organisation models and transformations are transitions) into a Markov
Decision Process (MDP).
challenges and research prospects, in: Informatik 2023 - Designing Futures: Zukünfte gestalten,
volume 337 of Lecture Notes in Informatics, 2023, pp. 2003–2014.
[22] W. M. P. van der Aalst, Process Mining: Data Science in Action, 2 ed., Springer, Heidelberg, 2016.</p>
      <p>doi:10.1007/978-3-662-49851-4.
[23] D. Schuster, S. J. van Zelst, W. M. P. van der Aalst, Freezing sub-models during incremental process
discovery, in: A. Ghose, J. Horkof, V. E. Silva Souza, J. Parsons, J. Evermann (Eds.), Conceptual
Modeling, Springer International Publishing, Cham, 2021, pp. 14–24.
[24] D. Schuster, S. J. van Zelst, W. M. P. van der Aalst, Incremental discovery of hierarchical process
models, in: F. Dalpiaz, J. Zdravkovic, P. Loucopoulos (Eds.), Research Challenges in Information
Science, Springer International Publishing, Cham, 2020, pp. 417–433.
[25] M. Köhler-Bußmeier, M. Wester-Ebbinghaus, Sonar* : A multi-agent infrastructure for active
application architectures and inter-organisational information systems, in: L. Braubach, W. van der
Hoek, P. Petta, A. Pokahr (Eds.), Conference on Multi-Agent System Technologies, MATES 2009,
volume 5774 of Lecture Notes in Artificial Intelligence , 2009, pp. 248–257.
[26] M. Köhler-Bußmeier, M. Wester-Ebbinghaus, D. Moldt, A formal model for organisational
structures behind process-aware information systems, Transactions on Petri Nets and Other Models of
Concurrency. Special Issue on Concurrency in Process-Aware Information Systems 5460 (2009)
98–114.
[27] C. Krupitzer, F. M. Roth, S. VanSyckel, G. Schiele, C. Becker, A survey on engineering approaches
for self-adaptive systems, Pervasive Mob. Comput. 17 (2015) 184–206. doi:10.1016/j.pmcj.
2014.09.009.
[28] J. V. D. Donckt, D. Weyns, M. U. Iftikhar, S. S. Buqar, Efective decision making in self-adaptive
systems using cost-benefit analysis at runtime and online learning of adaptation spaces, in: Best
papers of ENASE’18, Springer-Verlag, 2018.
[29] M. Köhler-Bußmeier, Restricting Hornets to support adaptive systems, in: W. van der Aalst, E. Best
(Eds.), PETRI NETS 2017, Lecture Notes in Computer Science, Springer-Verlag, 2017.
[30] M. Köhler-Bußmeier, H. Rölke, Analysing adaption processes of Hornets, Transactions on Petri</p>
      <p>Nets and Other Models of Concurrency XVII 14150 (2023).
[31] M. Köhler-Bußmeier, Hornets: Nets within nets combined with net algebra, in: K. Wolf, G.
Franceschinis (Eds.), International Conference on Application and Theory of Petri Nets (ICATPN’2009),
volume 5606 of Lecture Notes in Computer Science, Springer-Verlag, 2009, pp. 243–262.
[32] L. Capra, M. Köhler-Bußmeier, Modelling adaptive systems with nets-within-nets in maude,
in: Proceedings of the 18th International Conference on Evaluation of Novel Approaches to
Software Engineering - ENASE, Prague, Czech Republic, INSTICC, SciTePress, 2023, pp. 487–496.
doi:10.5220/0011860000003464.
[33] L. Capra, M. Köhler-Bußmeier, Modular rewritable Petri nets: an eficient model for dynamic
distributed systems, Theoretical Computer Science 990 (2024) 114397. doi:https://doi.org/
10.1016/j.tcs.2024.114397.
[34] J. Ferber, O. Gutknecht, F. Michel, From agents to organizations: An organizational view of
multiagent systems, in: P. Giorgini, J. P. Müller, J. Odell (Eds.), Agent-Oriented Software Engineering
IV, volume 2935, 2003, pp. 214–230.
[35] O. Boissier, J. F. Hübner, J. S. Sichman, Using the moise+ for a cooperative framework of MAS
reorganisation, in: A. L. C. Bazzan, S. Labidi (Eds.), Advances in Artificial Intelligence - SBIA 2004,
volume 3171 of Lecture Notes in Computer Science, Springer-Verlag, 2004, pp. 506–515.
[36] V. Dignum, F. Dignum, J.-J. Meyer, An agent-mediated approach to the support of knowledge
sharing in organizations, Knowledge Engineering Review 19 (2004) 147–174.
[37] V. Dignum (Ed.), Handbook of Research on Multi-Agent Systems: Semantics and Dynamics of</p>
      <p>Organizational Models, IGI Global, Information Science Reference, 2009.
[38] Standards Committeeof the IEEE Industrial Electronics Society, IEEE Recommended Practice for
Industrial Agents: Integration of Software Agents and Low-Level Automation Functions, Technical
Report EEE Std 2660.1™-2020, IEEE Industrial Electronics Society, 2020.
[39] W. v. d. Aalst, Verification of workflow nets, in: P. Azeme, G. Balbo (Eds.), Application and theory</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>E. R.</given-names>
            <surname>Grifor</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Greer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D. A.</given-names>
            <surname>Wollman</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. J.</given-names>
            <surname>Burns</surname>
          </string-name>
          ,
          <article-title>Framework for cyber-physical systems</article-title>
          : volume
          <volume>1</volume>
          ,
          <string-name>
            <surname>overview</surname>
          </string-name>
          (
          <year>2017</year>
          ). doi:
          <volume>10</volume>
          .6028/nist.sp.
          <volume>1500</volume>
          -
          <fpage>201</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>P.</given-names>
            <surname>Leitao</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Karnouskos</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Ribeiro</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Lee</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Strasser</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. W.</given-names>
            <surname>Colombo</surname>
          </string-name>
          ,
          <article-title>Smart agents in industrial cyber-physical systems</article-title>
          ,
          <source>Proceedings of the IEEE</source>
          <volume>104</volume>
          (
          <year>2016</year>
          )
          <fpage>1086</fpage>
          -
          <lpage>1101</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>J.</given-names>
            <surname>Sudeikat</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Köhler-Bußmeier</surname>
          </string-name>
          ,
          <article-title>On combining domain modeling and organizational modeling for developing adaptive cyber-physical systems</article-title>
          ,
          <source>in: ICAART'22</source>
          ,
          <year>2022</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>P.</given-names>
            <surname>Leitao</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Karnouskos</surname>
          </string-name>
          , Industrial Agents:
          <article-title>Emerging Applications of Software Agents in Industry</article-title>
          , 1st ed., Elsevier Science Publishers B. V., Amsterdam, The Netherlands,
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>G.</given-names>
            <surname>Weiß</surname>
          </string-name>
          (Ed.),
          <article-title>Multiagent systems: A modern approach to Distributed Artificial Intelligence</article-title>
          , MIT Press,
          <year>1999</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>T.</given-names>
            <surname>Pulikottil</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. A.</given-names>
            <surname>Estrada-Jimenez</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H. Ur</given-names>
            <surname>Rehman</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Mo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Nikghadam-Hojjati</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Barata</surname>
          </string-name>
          ,
          <article-title>Agentbased manufacturing - review and expert evaluation</article-title>
          ,
          <source>The International Journal of Advanced Manufacturing Technology</source>
          <volume>127</volume>
          (
          <year>2023</year>
          )
          <fpage>2151</fpage>
          -
          <lpage>2180</lpage>
          . doi:
          <volume>10</volume>
          .1007/s00170-023-11517-8.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>R.</given-names>
            <surname>Yao</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Hu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Varga</surname>
          </string-name>
          ,
          <article-title>Applications of agent-based methods in multi-energy systems-a systematic literature review</article-title>
          ,
          <source>Energies</source>
          <volume>16</volume>
          (
          <year>2023</year>
          )
          <article-title>2456</article-title>
          . doi:
          <volume>10</volume>
          .3390/en16052456.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>L. A. C.</given-names>
            <surname>Salazar</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Ryashentseva</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Lüder</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Vogel-Heuser</surname>
          </string-name>
          ,
          <article-title>Cyber-physical production systems architecture based on multi-agent's design pattern-comparison of selected approaches mapping four agent patterns</article-title>
          ,
          <source>The International Journal of Advanced Manufacturing Technology</source>
          <volume>105</volume>
          (
          <year>2019</year>
          )
          <fpage>4005</fpage>
          -
          <lpage>4034</lpage>
          . doi:
          <volume>10</volume>
          .1007/s00170-019-03800-4.
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>A.</given-names>
            <surname>Lopez</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Casquero</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Marcos</surname>
          </string-name>
          ,
          <article-title>Design patterns for the implementation of industrial agent-based aass (</article-title>
          <year>2021</year>
          ).
          <source>doi:10.1109/ICPS49255</source>
          .
          <year>2021</year>
          .
          <volume>9468129</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>A.</given-names>
            <surname>López</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Casquero</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Estévez</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Armentia</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Orive</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Marcos</surname>
          </string-name>
          ,
          <article-title>An industrial agent-based customizable platform for i4.0 manufacturing systems</article-title>
          ,
          <source>Computers in Industry</source>
          <volume>146</volume>
          (
          <year>2023</year>
          )
          <article-title>103859</article-title>
          . doi:
          <volume>10</volume>
          .1016/j.compind.
          <year>2023</year>
          .
          <volume>103859</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>A.</given-names>
            <surname>Lober</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Lehmann</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Reichwald</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Ollinger</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Baumgärtel</surname>
          </string-name>
          ,
          <article-title>Flexible skill-based production systems through novel opc ua design approaches</article-title>
          ,
          <source>IFAC-PapersOnLine</source>
          <volume>56</volume>
          (
          <year>2023</year>
          )
          <fpage>3654</fpage>
          -
          <lpage>3659</lpage>
          . doi:
          <volume>10</volume>
          .1016/j.ifacol.
          <year>2023</year>
          .
          <volume>10</volume>
          .1529.
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>IEEE</given-names>
            <surname>Standards Committee</surname>
          </string-name>
          ,
          <string-name>
            <surname>J. Olszewska,</surname>
          </string-name>
          <article-title>IEEE recommended practice for industrial agents: Integration of software agents and low-level automation functions</article-title>
          :
          <source>IEEE standard 2660</source>
          .
          <fpage>1</fpage>
          -
          <lpage>2020</lpage>
          , IEEE Std 2660.
          <fpage>1</fpage>
          -
          <lpage>2020</lpage>
          (
          <year>2021</year>
          )
          <fpage>1</fpage>
          -
          <lpage>43</lpage>
          . doi:
          <volume>10</volume>
          .1109/IEEESTD.
          <year>2021</year>
          .
          <volume>9340089</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>K. M. Carley</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          <string-name>
            <surname>Gasser</surname>
          </string-name>
          ,
          <article-title>Computational organisation theory</article-title>
          ,
          <source>in: [5]</source>
          ,
          <year>1999</year>
          , pp.
          <fpage>229</fpage>
          -
          <lpage>330</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>V.</given-names>
            <surname>Dignum</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Padget</surname>
          </string-name>
          ,
          <article-title>Multiagent organizations</article-title>
          , in: G. Weiss (Ed.),
          <source>Multiagent Systems</source>
          , 2nd ed., Intelligent Robotics; Autonomous Agents Series, MIT Press,
          <year>2013</year>
          , pp.
          <fpage>51</fpage>
          -
          <lpage>98</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>B. H. C.</given-names>
            <surname>Cheng</surname>
          </string-name>
          , R. de Lemos, H. Giese,
          <string-name>
            <given-names>P.</given-names>
            <surname>Inverardi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Magee</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Andersson</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Becker</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Bencomo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Brun</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Cukic</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            <surname>Di Marzo Serugendo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Dustdar</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Finkelstein</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Gacek</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Geihs</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Grassi</surname>
          </string-name>
          , G. Karsai,
          <string-name>
            <given-names>H. M.</given-names>
            <surname>Kienle</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Kramer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Litoiu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Malek</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Mirandola</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H. A.</given-names>
            <surname>Müller</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Park</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Shaw</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Tichy</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Tivoli</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Weyns</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Whittle</surname>
          </string-name>
          ,
          <article-title>Software engineering for self-adaptive systems: A research roadmap</article-title>
          , in: B. H. C. Cheng, R. de Lemos, H. Giese,
          <string-name>
            <given-names>P.</given-names>
            <surname>Inverardi</surname>
          </string-name>
          , J. Magee (Eds.),
          <source>Software Engineering for Self-Adaptive Systems</source>
          , Springer Berlin Heidelberg, Berlin, Heidelberg,
          <year>2009</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>26</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>D.</given-names>
            <surname>Weyns</surname>
          </string-name>
          , I. Gerostathopoulos,
          <string-name>
            <given-names>N.</given-names>
            <surname>Abbas</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Andersson</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Bifl</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Brada</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Bures</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. D.</given-names>
            <surname>Salle</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Galster</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Lago</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            <surname>Lewis</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Litoiu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Musil</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Musil</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Patros</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Pelliccione</surname>
          </string-name>
          ,
          <article-title>Self-adaptation in industry: A survey</article-title>
          ,
          <source>ACM Transactions on Autonomous and Adaptive Systems</source>
          <volume>18</volume>
          (
          <year>2023</year>
          )
          <fpage>1</fpage>
          -
          <lpage>44</lpage>
          . doi:
          <volume>10</volume>
          .1145/3589227.
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>J.</given-names>
            <surname>Kephart</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Chess</surname>
          </string-name>
          ,
          <article-title>The vision of autonomic computing</article-title>
          ,
          <source>Computer</source>
          <volume>36</volume>
          (
          <year>2003</year>
          )
          <fpage>41</fpage>
          -
          <lpage>50</lpage>
          . doi:
          <volume>10</volume>
          . 1109/
          <string-name>
            <surname>mc</surname>
          </string-name>
          .
          <year>2003</year>
          .
          <volume>1160055</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>D.</given-names>
            <surname>Weyns</surname>
          </string-name>
          ,
          <article-title>An Introduction to Self-Adaptive Systems: A Contemporary Software Engineering Perspective</article-title>
          , John Wiley &amp; Sons Ltd,
          <year>2020</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>N.</given-names>
            <surname>Bencomo</surname>
          </string-name>
          , R. France, B. Cheng, U. Aßmann (Eds.),
          <article-title>Models@run.time: foundations, applications, and roadmaps</article-title>
          ,
          <source>Lecture Notes in Computer Science</source>
          , Springer, Germany,
          <year>2014</year>
          . doi:
          <volume>10</volume>
          .1007/ 978-3-
          <fpage>319</fpage>
          -08915-7.
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>N.</given-names>
            <surname>Bencomo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Götz</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Song</surname>
          </string-name>
          ,
          <article-title>Models@run.time: a guided tour of the state of the art and research challenges</article-title>
          ,
          <source>Software &amp; Systems Modeling</source>
          <volume>18</volume>
          (
          <year>2019</year>
          )
          <fpage>3049</fpage>
          -
          <lpage>3082</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>J.</given-names>
            <surname>Sudeikat</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Köhler-Bußmeier</surname>
          </string-name>
          ,
          <article-title>Controlled run-time adaptivity in industrial agent systems: of Petri nets</article-title>
          , volume
          <volume>1248</volume>
          of Lecture Notes in Computer Science, Springer-Verlag, Berlin Heidelberg New York,
          <year>1997</year>
          , pp.
          <fpage>407</fpage>
          -
          <lpage>426</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [40]
          <string-name>
            <given-names>M.</given-names>
            <surname>Köhler</surname>
          </string-name>
          ,
          <article-title>A formal model of multi-agent organisations</article-title>
          ,
          <source>Fundamenta Informaticae</source>
          <volume>79</volume>
          (
          <year>2007</year>
          )
          <fpage>415</fpage>
          -
          <lpage>430</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [41]
          <string-name>
            <given-names>J.</given-names>
            <surname>Sudeikat</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Köhler-Bußmeier</surname>
          </string-name>
          ,
          <article-title>Towards integrating multi-agent organizations in OPC UA for developing adaptive cyber-physical systems</article-title>
          , in: D.
          <string-name>
            <surname>Demmler</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          <string-name>
            <surname>Krupka</surname>
          </string-name>
          , H. Federrath (Eds.),
          <volume>52</volume>
          . Jahrestagung der Gesellschaft für Informatik,
          <source>INFORMATIK</source>
          <year>2022</year>
          , Informatik in den Naturwissenschaften,
          <volume>26</volume>
          . -
          <fpage>30</fpage>
          .
          <year>September 2022</year>
          , Hamburg, volume P-326
          <string-name>
            <surname>of</surname>
            <given-names>LNI</given-names>
          </string-name>
          , Gesellschaft für Informatik, Bonn,
          <year>2022</year>
          , pp.
          <fpage>1565</fpage>
          -
          <lpage>1570</lpage>
          . doi:
          <volume>10</volume>
          .18420/inf2022\_
          <fpage>135</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [42]
          <string-name>
            <given-names>M.</given-names>
            <surname>Köhler-Bußmeier</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Sudeikat</surname>
          </string-name>
          ,
          <article-title>Defining adaption measures for organizational multi-agent systems</article-title>
          ,
          <source>International Journal of Parallel, Emergent and Distributed Systems</source>
          (
          <year>2023</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [43]
          <string-name>
            <given-names>M.</given-names>
            <surname>Köhler-Bußmeier</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Sudeikat</surname>
          </string-name>
          ,
          <article-title>Studying the micro-macro-dynamics in MAPE-like adaption processes</article-title>
          ,
          <source>in: 16th International Symposium on Intelligent Distributed Computing (IDC'23)</source>
          , Springer-Verlag,
          <year>2023</year>
          . (to appear).
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [44]
          <string-name>
            <given-names>M.</given-names>
            <surname>Köhler-Bußmeier</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Sudeikat</surname>
          </string-name>
          ,
          <article-title>Balance vs. contingency: Adaption measures for organizational multi-agent systems</article-title>
          , in: K.
          <string-name>
            <surname>Jander</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          <string-name>
            <surname>Braubach</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          Badica (Eds.),
          <source>15th International Symposium on Intelligent Distributed Computing (IDC'22)</source>
          , volume
          <volume>1089</volume>
          <source>of Studies in Computational Intelligence</source>
          , Springer-Verlag,
          <year>2023</year>
          , pp.
          <fpage>224</fpage>
          -
          <lpage>233</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [45]
          <string-name>
            <given-names>W.</given-names>
            <surname>Reisig</surname>
          </string-name>
          ,
          <source>Petri Nets: An Introduction</source>
          , Springer-Verlag, Heidelberg,
          <year>1985</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [46]
          <string-name>
            <given-names>J.</given-names>
            <surname>Esparza</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Heljanko</surname>
          </string-name>
          , Unfoldings - A
          <string-name>
            <surname>Partial-Order Approach</surname>
          </string-name>
          to Model Checking,
          <source>EATCS Monographs in Theoretical Computer Science</source>
          , Springer-Verlag,
          <year>2008</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          [47]
          <string-name>
            <given-names>M.</given-names>
            <surname>Köhler-Bußmeier</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Rölke</surname>
          </string-name>
          ,
          <article-title>Run-time analysis of adaption in multi-agent organisations</article-title>
          ,
          <source>in: Petri Nets and Software Engineering</source>
          <year>2024</year>
          , PNSE'24,
          <string-name>
            <surname>CEUR</surname>
          </string-name>
          ,
          <year>2024</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          [48]
          <string-name>
            <given-names>M.</given-names>
            <surname>Clavel</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Durán</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Eker</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Lincoln</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Martí-Oliet</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Meseguer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C. L.</given-names>
            Talcott (Eds.),
            <surname>All About Maude - A High-Performance Logical</surname>
          </string-name>
          <string-name>
            <surname>Framework</surname>
          </string-name>
          , How to Specify,
          <source>Program and Verify Systems in Rewriting Logic</source>
          , volume
          <volume>4350</volume>
          of Lecture Notes in Computer Science, Springer-Verlag,
          <year>2007</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          [49]
          <string-name>
            <given-names>M.</given-names>
            <surname>Köhler-Bußmeier</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Rölke</surname>
          </string-name>
          ,
          <article-title>Petri-nets@run.time: Handling uncertainty during run-time adaptation using digital twins</article-title>
          ,
          <source>in: Petri Nets and Software Engineering</source>
          <year>2023</year>
          , PNSE'
          <volume>23</volume>
          , volume
          <volume>3430</volume>
          ,
          <string-name>
            <surname>CEUR</surname>
          </string-name>
          ,
          <year>2023</year>
          , pp.
          <fpage>34</fpage>
          -
          <lpage>52</lpage>
          . URL: http://ceur-ws.
          <source>org/</source>
          Vol-
          <volume>3430</volume>
          /.
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          [50]
          <string-name>
            <given-names>O.</given-names>
            <surname>Kummer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Wienberg</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Duvigneau</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Schumacher</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Köhler</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Moldt</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Rölke</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Valk</surname>
          </string-name>
          ,
          <article-title>An extensible editor and simulation engine for Petri nets: Renew</article-title>
          , in: J.
          <string-name>
            <surname>Cortadella</surname>
          </string-name>
          , W. Reisig (Eds.),
          <source>International Conference on Application and Theory of Petri Nets</source>
          <year>2004</year>
          , volume
          <volume>3099</volume>
          of Lecture Notes in Computer Science, Springer-Verlag,
          <year>2004</year>
          , pp.
          <fpage>484</fpage>
          -
          <lpage>493</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>