<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Behavior Predictability Despite Non-Determinism in the SAPERE Ecosystem Preliminary Ideas</article-title>
      </title-group>
      <contrib-group>
        <aff id="aff0">
          <label>0</label>
          <institution>Gabriella Castelli, Marco Mamei, Alberto Rosi, Franco Zambonelli Dipartimento di Scienze e Metodi dell'Ingegneria University of Modena and Reggio Emilia</institution>
          ,
          <country country="IT">Italy</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>-How can we have confidence that self organizing systems actually do what we expect them to? In this position paper we overview some mechanisms at the basis of controlling and predicting the behavior of autonomous and self-organizing systems despite components' autonomy and non-deterministic behavior. In particular we focus the analysis on the SAPERE ecosystem as an exemplary model to frame the discussion. We identify three main directions with which to gain confidence on the overall system behavior: (i) confidence from layering, (ii) confidence from large numbers, (iii) confidence form the structure and dynamics of the state space. In the paper we describe this ideas and their implication in the design of self organizing applications.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>I. INTRODUCTION</title>
      <p>The increasing evolution and spread of pervasive
computing technologies is defining the basis for the emergence of a
dense and global decentralized infrastructure for the creation
of general-purpose pervasive services.</p>
      <p>In particular, such novel pervasive application scenarios
call for adopting self-organizing service coordination
approaches comprising autonomous and adaptive components
to interact and coordinate with each other to provide services
and applications.</p>
      <p>
        A number of approaches, taking inspiration from swarm
intelligent examples [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ], [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ], [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ], try to achieve the above
results by making use of a large number of simple
autonomous components, that self-organize to achieve a
desired application. Examples in this direction are the work
on collective robotics [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ], [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], autonomous and adaptive
systems and distributed computing [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ], [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ], [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ].
      </p>
      <p>One of the main scientific questions in this kind of
scenarios is:</p>
      <p>How can we have confidence that self organizing systems
actually do what we expect them to?</p>
      <p>Providing convincing answers to that questions is
fundamental to engineer robust and dependable systems based on
the above self-organizing principles.</p>
      <p>In this position paper we present thee main directions
showing guidelines on to design self organizing applications
so as to retain confidence in their behavior. In particular we
identified three main mechanisms to be considered
1) Confidence from layering. System’s reliable
functionalities are realized on top of the self-aware layer. In
this way the non determinism of the self-aware layer
is shielded from the actual system functionalities.
2) Confidence from large numbers. Systems
functionalities are realized on the basis of the average behavior
of a large set of components. While the behavior
of individual components can be erratic the overall
average behavior is stable.
3) Confidence from the structure and dynamics of the
state space. Analyzing the state space of the overall
system, it is possible to identify more general
mechanisms that guarantees the fulfillment of requested
functionalities.</p>
      <p>
        To ground the discussion we focus the analysis on the
SAPERE model and middleware [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ], as an exemplary
selforganizing ICT system.
      </p>
      <p>Despite this focus, we think that the proposed ideas are
more general and could be fruitfully applied to a wider range
of models and systems.</p>
      <p>In the remaining of this paper we first present the
SAPERE model in order to ground the discussion on a
concrete setting. Then, in Section 3-5 we present the
different approaches to obtain confidence in the behavior of
the systems. Finally, Section 6 concludes discussing some
research directions to exploit these ideas.</p>
      <p>
        II. THE SAPERE MODEL AND MIDDLEWARE
SAPERE takes its primary inspiration from natural
ecosystems, and starts from the consideration that the
dynamics and decentralization of future pervasive networks
will make it suitable to model the overall world of services,
data, and devices as a sort of distributed and
spatiallysituated computational ecosystem. However, unlike the many
proposals that adopt the term ecosystem simply as a mean
to characterize the complexity and dynamics of ICT systems
[
        <xref ref-type="bibr" rid="ref15">15</xref>
        ], SAPERE brings the adoption of natural metaphors
down to the core of its approach, by exploiting
natureinspired mechanisms (and in particular bio-chemical ones
[
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]) for actually ruling the overall system dynamics.
      </p>
      <p>Specifically (see Figure 1), SAPERE models a pervasive
service environment as a non-layered spatial substrate, laid
above the actual pervasive network infrastructure. The
substrate embeds the basic laws of nature (or eco-laws) that
rule the activities of the system. It represents the ground on
which individuals of different species (i.e., the components
of the pervasive service ecosystem) interact and combine
with each other (in respect of the eco-laws and typically
based on their spatial relationships), so as to serve their own
individual needs as well as the sustainability of the overall
ecology. Users can access the ecology in a decentralized way
to use and consume data and services, and they can also act
as “prosumers” by injecting new data or service components.</p>
      <p>For the components living in the ecosystem, SAPERE
adopts a common modeling and treatment of services, data,
and devices. All “entities” living in the ecosystem will
have an associated semantic representation (in the case
of pure data items, the entity and its representation will
coincide), which is a basic ingredient for enabling dynamic
unsupervised interactions between components. To account
for the high dynamics of the scenario and for its need of
continuous adaptation, SAPERE will define such annotations
as living, active entities, tightly associated to the component
they describe, and capable of reflecting its current situation
and context. Such Live Semantic Annotations (LSAs) will
thus act as observable interfaces of resources and services,
as well as the basis for enforcing semantic and self-aware
forms of dynamic interactions (both for service
aggregation/composition and for data/knowledge management).</p>
      <p>
        For the eco-laws driving the dynamics of the ecosystem,
SAPERE envisions them to define the basic policies to
drive virtual chemical reactions among the LSAs of the
various individuals of the ecology [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ], [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]. In particular,
the idea is to enforce, on a spatial basis and possibly relying
on diffusive spatial mechanisms [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ], dynamic networking
and composition of data and services. In particular, data
and services (as represented by their associated LSAs) will
be sorts of chemical reagents, and interactions and
compositions will occur via chemical reactions, i.e., semantic
pattern-matching, between LSAs. Such reactions will
contribute establishing virtual chemical bonds between entities
(e.g., relating similar services with each other to produce a
distributed service, or mining related data items) as well
as producing new components (e.g. a composite service
orchestrating the execution of atomic service components or
a high-level knowledge concept derived from the aggregation
of raw data items).
      </p>
      <p>Adaptivity in SAPERE will not be in the capability of
individual components, but rather in the overall dynamics
of the ecosystem. In particular, adaptivity will be ensured
by the fact that any change in the system (as well as any
change in its components, as reflected by dynamic changes
in their LSAs) will reflect in the firing of new chemical
reactions, thus possibly leading to the establishment of new
bonds and/or in the breaking of some existing bonds between
components.</p>
      <p>
        From an implementation viewpoint, SAPERE relies on
lightweight and minimal middleware infrastructure (see
Figure 2). In particular, it reifies LSAs in the form of tuples,
dynamically stored and updated in a system of
highlydistributed tuple spaces spread over the nodes of the network
[
        <xref ref-type="bibr" rid="ref10">10</xref>
        ].
      </p>
      <p>The active components of the ecosystem (whether
services, software agents, sensing/actuating devices, or data
sources) express their existence via LSAs injected in the
local tuple space associated to their node. Then, they indirectly
interact with each other via such tuple space by observing
and accessing their own LSA.</p>
      <p>In SAPERE an agent can see only its own LSA and
the LSAs that are bonded to. There are not general read
operations. An agent can inject an LSA. This LSA will form
bonds with other LSAs (bond are created by means of
ecolaws – see below). Only after that, that agent can read those
other LSAs.</p>
      <p>The eco-laws represent sorts of virtual chemical reactions
between LSAs, and get activated by processes embedded in
tuple spaces (which make SAPERE tuple spaces different
from traditional tuple spaces). Such processes evaluate the
potentials for establishing new chemical bonds between
LSAs, the need for breaking some, or the need for
generating new LSAs from the combination of existing
ones. In addition, to support distributed spatial interactions,
eco-laws can enforce the diffusion of LSAs to spatially
close tuple spaces, e.g., to those tuple spaces that are
neighbor to each other in the network, according to specific
propagation patterns (gradient-based diffusion, broadcast,
or multicast).</p>
      <p>In this kind of systems, the dynamics in the tuple space
tend to be rather complex, as all the interaction patterns are
reified in pattern matching operations among LSAs and
ecolaws.</p>
      <p>Accordingly, the central question of this paper: how can
we have confidence that self organizing systems actually do
what we expect them to? is very relevant for this kind of
systems.</p>
      <p>In the next sections we present thee main directions
showing guidelines on to design self organizing applications
so as to retain confidence in their behavior: (i) confidence
from layering, (ii) confidence from large numbers, (iii)
confidence form state space analysis.</p>
    </sec>
    <sec id="sec-2">
      <title>III. CONFIDENCE FROM LAYERING</title>
      <p>System’s reliable functionalities are realized on top of the
self-aware layer. In this way the actual system functionalities
are shielded from the non determinism of the self-aware
layer.</p>
      <p>
        This kind of approach toward control is typical in spatial
and amorphous computing [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ], [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ]. A number of
applications in this area are built on the basis of interaction patterns
arising from the creation and diffusion of gradients (a.k.a.
fields) in the environment.
      </p>
      <p>
        Gradients are distributed data structures propagated in a
spatial computer and conveying spatial information about
components. A typical example of the use of gradients is in
crowd steering [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]. In this kind of task, gradients indicating
direction to be followed are spread in the environment.
Agents navigate the space by simply following the gradient
uphill or downhill depending on the application.
      </p>
      <p>Gradients distributed configuration can be maintained by
a set of decentralized autonomous agents that propagate it
in the environment. The typical process at the basis of this
mechanisms is extremely non-deterministic. As the agents
are not centrally coordinated nor synchronized the gradient
can be propagated and maintained with different timings
among different and un predictable network routes (see Fig.
3).</p>
      <p>Is this kind of un-predictability an issue in our crowd
steering applications?</p>
      <p>It is not. Despite the unpredictability in how the gradient
propagates, the final result is that eventually the gradient is
properly laid out (see Fig. 3). In this example a reliable and
dependable service: the steering gradient, is built on top on
an unreliable and unpredictable substrate.</p>
      <p>
        Another similar example is represented by gossip-based
aggregation in sensor network [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. In this kind of systems
global aggregated values are computed in a decentralized
way via the local exchange of messages among distributed
nodes. For example, if nodes have to compute the average
value of some sensed property over an area, they can follow
this simple algorithm:
1) Each node sets its estimated average to its current
sensor readings.
2) Each node selects a neighbor node. The two nodes
exchange their current estimates.
3) Each node updates its estimate as the average of its
current estimate and the neighbor’s one.
4) Nodes cyclically repeat step 2 and 3
      </p>
      <p>
        It is rather easy to show that this algorithm allows each
estimate to rapidly converge to the actual average value [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ].
      </p>
      <p>Also in this case, despite interactions among devices can
follow unpredictable dynamics, the final result is stable.
Accordingly, application built on top of that computed
average do not suffer from unpredictability in that the
computed average “layer” shields the application from
lowlevel unpredictability.</p>
      <p>
        Several other examples of this same behavior can be
found in [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ]. In all of them, different kind of data
decouples application functional requirements form the
unpredictable agent dynamics that produces the data itself.
      </p>
      <sec id="sec-2-1">
        <title>Insights for SAPERE</title>
        <p>
          In SAPERE we developed a number of mechanisms to
support such kind of “stable” data structures. In particular,
a set of eco-laws in SAPERE act as aggregation operators.
These eco-laws basically implement order and duplicate
insensitive aggregation functions such as (min, max, average,
etc.) [
          <xref ref-type="bibr" rid="ref4">4</xref>
          ]. These eco-laws can be used to properly propagate
and maintain a gradient LSA so that is is properly spread
across the network [
          <xref ref-type="bibr" rid="ref18">18</xref>
          ]. Similarly, they can be used to
aggregate distributed LSAs so as to provide a compact
description of environmental properties (in term of a suitable
LSA).
        </p>
        <p>As discussed above, despite the dynamics of the SAPERE
eco-system is highly non-deterministic, applications built on
top such LSAs would be stable and predictable.</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>IV. CONFIDENCE FROM LARGE NUMBERS</title>
      <p>Another complementary approach to get confidence over
the behavior of the system is based on adopting a large
number of components to average out unpredictability in
the behavior of components.</p>
      <p>System’s functionalities are realized on the basis of the
average behavior of a large set of components. While the
behavior of individual components can be erratic, the overall
average behavior is stable.</p>
      <p>Algorithms and mechanisms proposed in the vision of
swarm intelligence often rely on this kind of approach.</p>
      <p>
        For example, ant based sorting [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ] is an example of this
technique. One self-organized behavior enabling this kind
of sorting is that individual agents just wander randomly
and pick up and drop items according to the number of
similar surrounding objects. For example, if an individual
agent finds a large cluster of similar items together with
a different one, it will most likely pick up the misplaced
item and start roaming around. That individual will probably
deposit its load in a region containing other items similar
to the one he is carrying. While the low level behavior of
individual agents is largely erratic and non deterministic, it is
possible to show that system evolves to a globally coherent
state in which items are clustered.
      </p>
      <p>
        Another example, very relevant in the context of the
SAPERE vision, is related to artificial chemistry [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ]. This
example matches very closely the working of the SAPERE
ecosystem: a large number of LSAs (metaphorically
chemical components) are subject to a number of Eco-laws
(metaphorically chemical reactions).
      </p>
      <p>If the same eco-law can be applied to multiple LSAs, we
have indeterminism, and thus unpredictability in the way in
which the system will evolve.</p>
      <p>One way to avoid this kind of situations is by relying
– as in chemistry – on large (theoretically Avogadro-like)
numbers of LSA. In this way, all the possible products
of Eco-laws are produced and unpredictability vanishes as
application designers are guaranteed that all the possible
reactions will take place and all the possible products will
appear.</p>
      <p>
        In both the above examples it is possible to see that, if
an application is built on top of such collectively-produced
functionalities, then application’s evolution is predictable
despite the mechanisms underlying non determinism.
In SAPERE we developed algorithms relying on such a
large-number effect [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ]. These algorithms allow to
transform and organize LSAs’ populations in a coherent and
reliable way despite underlying non deterministic pattern
matching.
      </p>
      <p>V. CONFIDENCE FROM THE STRUCTURE AND DYNAMICS</p>
      <p>OF THE STATE SPACE</p>
      <p>Thinking of the system’s behavior in terms of its state
space, it is possible to identify methods and mechanisms to
understand how the system will evolve over time.</p>
      <p>In particular, if we are able to identify some properties of
the system than are maintained by all the possible system
dynamic, then we can confidently build applications on such
properties.</p>
      <p>To ground the discussion, let’s focus on the latter example
in the previous section: we have indeterminism every time an
eco-law can be applied to multiple LSAs. More in general,
in Linda-like systems, unpredictability arises when multiple
pattern matches can fire concurrently. In this case, the system
will evolve differently depending on which pattern matching
is triggered first.</p>
      <p>Thinking of the state space of the system, there are two
cases in which such an indeterminism does not lead to
unpredictability: (i) the state space is modeled so that –
from the application functional requirements’ viewpoint –
all the possible evolution of the system are the same. (ii) The
underlying mechanisms ensure that all the possible states of
the system are actually visited.</p>
      <p>In simple terms: either the system visits only states that
are indistinguishable from each other form the application
viewpoint, or the systems visits all the possible states. In
both the cases, unpredictability vanishes. In the following
of this section, we consider the two cases separately.</p>
      <sec id="sec-3-1">
        <title>A. Indistinguishable States</title>
        <p>If the unpredictability in the system evolution involves
states that are indistinguishable from the application
perspective, there are not problems in controlling the system.</p>
        <p>In the SAPERE framework, a typical example of this
case is considering service-oriented scenarios. In this case,
multiple services (e.g., S1 and S2) can expose via the LSA
a given functionality X . Another service can express in
its LSA the fact it wants to bind with X . Indeterminism
in the way which eco-laws are applied does not allow the
programmer to predict whether the service will bind with
S1 or S2. However this is not a problem, since from the
application viewpoint S1 and S2 are indistinguishable as
they provide the same functionality X .</p>
        <p>As another example, the mechanisms that lead to the
diffusion of a gradient in the system can be interpreted as
operations than move the system in the state space to a “point”
corresponding to the state in which the gradient is properly
laid out. Because of the underlying non-determinism the
system may take different trajectories to reach than point,
but eventually the proper state will be reached. Disregarding
transient behaviors, the trajectories followed by the system
are indistinguishable by a “gradient-following” application
– like crowd steering – that only relies on the resulting
gradient.</p>
        <p>From this viewpoint, the case of indistinguishable states
actually generalizes the – confidence from layering –
described in the previous section.</p>
        <p>Following this kind of ideas, when creating an application
in the SAPERE framework, it is important to design LSAs so
that pattern matching can only happen among LSAs that are
equivalent (indistinguishable) from the application
perspective. In general, to achieve this property in open scenarios,
it is important rely on common ontologies or namespaces in
order to actually ensure the complete indistinguishability in
the states of the system that can be possibly reached.</p>
      </sec>
      <sec id="sec-3-2">
        <title>B. All States</title>
        <p>Another condition under which unpredictability vanishes
is in the case the system generates all the possible states.</p>
        <p>To clarify this concept, let us focus on a SAPERE
application in which an agent’s LSA can bind with both
LSA1 and LSA2. However, the two bindings are not
indistinguishable (like the in the previous Section) and the agent
will behave differently depending on which LSAs will be
bound. Looking at Fig. 5, the agent will execute function1
or function2 non deterministically.</p>
        <p>The problem is that since pattern matching is non
deterministic the agent will be bound with LSA1 or LSA2 and
it does not even know that the other LSA (LSA2 or LSA1)
was existing. Looking at Fig. 5, the agent will be never able
to execute function3. Recall from Section 2 that SAPERE
agent cannot read the SAPERE space, they can just perceive
LSAs with which they are bound.</p>
        <p>On the contrary, if the agent could see that both LSA1 and
LSA2 are present in the SAPERE space, then the system
evolution would be predictable and specified by the agent
code: looking at Fig. 5, the agent will deterministically chose
function3.</p>
        <p>
          This situation is the realm of ergodic processes and
systems [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ]. In signal processing, a stochastic process is
said to be ergodic if its statistical properties can be deduced
from a single, sufficiently long sample (realization) of the
process. This implies that an ergodic process visits all the
state space.
        </p>
        <p>In general, pattern matching operations like in SAPERE
are not ergodic as the creation of a bond between two
LSAs can prevent other bonds from being created. When
If(bind with LSA1):</p>
        <p>function1()
If(bind with LSA2):</p>
        <p>function2()
If(there are both LSA1 and LSA2):
function3()</p>
        <p>LSA</p>
        <p>Randomly
selected bond
LSA1</p>
        <p>LSA2
this happens, we have unpredictability in that the system
randomly visit a state excluding the others (see Fig. 4.a).</p>
        <p>To solve this issue and regain predictability the way in
which the pattern matching process applies to eco-laws has
to be changed. The intuition is that if the creation of a bond
between two LSAs does not prevent other bonds from being
created, the ergodicity is restored and the system is again
predictable. Accordingly there are two possibilities:
1) For each eco-law there must exist the opposite
ecolaw that disrupts the bond being created. In this way,
the disruption of a bond allows other kind of bonds
to be realized. Thus it enables the exploration of the
whole state space (see Fig. 4.b).
2) The bonding mechanisms does not prevent other bonds
from happening and thus an LSA can always be bond
with multiple other LSAs at the same time. Also in
this case, all the reactions that could happen, actually
happen and again the whole state space is visited (see
Fig. 4.c).</p>
        <p>It is possible to notice that this ergodic viewpoint
generalizes the – confidence from large numbers – described
in the previous section. In that case, ergodicity is simply
guaranteed by the law of large numbers applied to the
uniform random process that fires eco-laws to different
LSAs. Also in this case all the reactions that could happen,
actually happen because since the number of LSA is large
the probability that one eco-law is excluded form pattern
matching – because of the random schedule – goes to zero.</p>
        <p>There is actually another definition of ergodicity that
B) property_x = ?</p>
        <p>property_x = A
property_x = ?
property_x = B</p>
        <p>Random</p>
        <p>Choice of
which bind to</p>
        <p>trggger
property_x = A
property_x = ?
property_x = B</p>
        <p>Random Choice
of which bind to
trggger
property_x = A
property_x = ?
property_x = B</p>
        <p>Random</p>
        <p>Choice of
which bind to
trggger
property_x = ?
property_x = B</p>
        <p>Bond
disrupted
property_x = A
property_x = ?
property_x = B</p>
        <p>The system
never gets</p>
        <p>here
property_x = A
property_x = ?
property_x = B
property_x = ?
property_x = B</p>
        <p>property_x = A
New bond is property_x = ?
given a
chance</p>
        <p>property_x = B
Also other
bond can be
created</p>
        <p>property_x = A
property_x = ?
property_x = B
states that: a system in which the phase-space averages
correspond to the time averages is called an ergodic.. The
– confidence from large numbers – rely on phase-space
average, while the previous two dynamics possibilities
related to time averages.</p>
        <sec id="sec-3-2-1">
          <title>Insights for SAPERE</title>
          <p>Ergodicity allows a SAPERE agent to see the whole range
of LSAs to be possibly bound. The agent will then decide
how to behave on the basis of such an information. In this
case, despite non determinism in the order in which pattern
matching is fired, the agent is able to act deterministically
by fully analyzing its context (i.e., the kind of bonds that
can be established).</p>
          <p>VI. CONCLUSIONS AND RESEARCH DIRECTIONS
In this position paper we tried to address one of the main
challenges in the development of self-organizing
applications comprising autonomous agents, namely: How can we
have confidence that systems which are self-aware and adapt
according to their beliefs actually do what we expect them
to?.</p>
          <p>We present three main research avenues on which to
ground confidence on the system-level behavior of the
system: (i) confidence via layering, (ii) confidence via large
numbers, (iii) confidence from the structure and dynamics
of the state space (that subsumes also the other two cases).</p>
          <p>Al these mechanisms well apply to the SAPERE model
and can have an impact on similar approaches in different
areas.</p>
          <p>In our future work we will detail and experiment the
presented ideas. In particular we will run experiments using
the SAPERE middleware and simulation tools to gather
statistics on the expected behavior of the systems once the
above control mechanisms are enforced.</p>
          <p>
            In addition we will try to get better theoretical insights
in the system’s dynamic of SAPERE applications. In
particular, we will try to apply techniques such as Petri
nets [
            <xref ref-type="bibr" rid="ref3">3</xref>
            ] and model checking [
            <xref ref-type="bibr" rid="ref7">7</xref>
            ] to formally understand and
describe the possible dynamics of the system.
          </p>
          <p>Acknowledgements: Work supported by the SAPERE
(SelfAware Pervasive Service Ecosystems) project (EU FP7-FET,
Contract No. 256873).</p>
        </sec>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>J.</given-names>
            <surname>Bachrach</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Beal</surname>
          </string-name>
          , and
          <string-name>
            <given-names>T.</given-names>
            <surname>Fujiwara</surname>
          </string-name>
          .
          <article-title>Continuous space-time semantics allow adaptive program execution</article-title>
          .
          <source>In IEEE International Conference on Self-Adaptive and Self-Organizing Systems</source>
          , Boston (CA), USA,
          <year>2007</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>J.-P.</given-names>
            <surname>Banaˆtre</surname>
          </string-name>
          and
          <string-name>
            <given-names>T.</given-names>
            <surname>Priol</surname>
          </string-name>
          .
          <article-title>Chemical programming of future service-oriented architectures</article-title>
          .
          <source>Journal of Software</source>
          ,
          <volume>4</volume>
          (
          <issue>7</issue>
          ):
          <fpage>738</fpage>
          -
          <lpage>746</lpage>
          ,
          <year>2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>F.</given-names>
            <surname>Bause</surname>
          </string-name>
          and
          <string-name>
            <given-names>J.</given-names>
            <surname>Kriege</surname>
          </string-name>
          .
          <article-title>Detecting non-ergodic simulation models of logistics networks</article-title>
          .
          <source>In International conference on Performance evaluation methodologies and tools</source>
          , Nantes, France,
          <year>2007</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>N.</given-names>
            <surname>Bicocchi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Mamei</surname>
          </string-name>
          , and
          <string-name>
            <given-names>F.</given-names>
            <surname>Zambonelli</surname>
          </string-name>
          .
          <article-title>Self-organizing virtual macro sensors</article-title>
          .
          <source>ACM Transaction on Autonomous Adaptive Systems</source>
          ,
          <volume>7</volume>
          (
          <issue>1</issue>
          ),
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>R.</given-names>
            <surname>Bird</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            <surname>Stewart</surname>
          </string-name>
          , and
          <string-name>
            <given-names>E. Lightfoot. Transport</given-names>
            <surname>Phenomena</surname>
          </string-name>
          . Wiley,
          <year>1976</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>G.</given-names>
            <surname>Cabri</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Puviani</surname>
          </string-name>
          , and
          <string-name>
            <given-names>F.</given-names>
            <surname>Zambonelli</surname>
          </string-name>
          .
          <article-title>Towards a taxonomy of adaptive agent-based collaboration patterns for autonomic service ensembles</article-title>
          .
          <source>In International Conference on Collaboration Technologies and Systems</source>
          , Philadelphia (PA), USA,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>E.</given-names>
            <surname>Clarke</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Grumberg</surname>
          </string-name>
          , and
          <string-name>
            <given-names>D.</given-names>
            <surname>Peled</surname>
          </string-name>
          . Model Checking. MIT Press,
          <year>1999</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>S.</given-names>
            <surname>Dobson</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Denazis</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Fernandez</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Gaiti</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Gelenbe</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Massacci</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Nixon</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Saffre</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Schmidt</surname>
          </string-name>
          , and
          <string-name>
            <given-names>F.</given-names>
            <surname>Zambonelli</surname>
          </string-name>
          .
          <article-title>A survey of autonomic communications</article-title>
          .
          <source>ACM Transactions on Autonomous and Adaptive Systems</source>
          ,
          <volume>1</volume>
          (
          <issue>2</issue>
          ):
          <fpage>223</fpage>
          -
          <lpage>259</lpage>
          ,
          <year>2006</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>M.</given-names>
            <surname>Mamei</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Menezes</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Tolksdorf</surname>
          </string-name>
          , and
          <string-name>
            <given-names>F.</given-names>
            <surname>Zambonelli</surname>
          </string-name>
          .
          <article-title>Case studies for self-organization in computer science</article-title>
          .
          <source>Journal of Systems Architecture</source>
          ,
          <volume>52</volume>
          :
          <fpage>443</fpage>
          -
          <lpage>460</lpage>
          ,
          <year>2006</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>M.</given-names>
            <surname>Mamei</surname>
          </string-name>
          and
          <string-name>
            <given-names>F.</given-names>
            <surname>Zambonelli</surname>
          </string-name>
          .
          <article-title>Programming pervasive and mobile computing applications: the tota approach</article-title>
          .
          <source>ACM Trans. Software Engineering and Methodology</source>
          ,
          <volume>18</volume>
          (
          <issue>4</issue>
          ),
          <year>2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>M.</given-names>
            <surname>Mamei</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Zambonelli</surname>
          </string-name>
          , and
          <string-name>
            <surname>L. Leonardi.</surname>
          </string-name>
          <article-title>Co-fields: A physically inspired approach to distributed motion coordination</article-title>
          .
          <source>IEEE Pervasive Computing</source>
          ,
          <volume>3</volume>
          (
          <issue>2</issue>
          ):
          <fpage>52</fpage>
          -
          <lpage>61</lpage>
          ,
          <year>2004</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>G.</given-names>
            <surname>Pini</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Brutschy</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Frison</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Roli</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Dorigo</surname>
          </string-name>
          , and
          <string-name>
            <given-names>M.</given-names>
            <surname>Birattari</surname>
          </string-name>
          .
          <article-title>Task partitioning in swarms of robots: An adaptive method for strategy selection</article-title>
          .
          <source>Swarm Intelligence</source>
          ,
          <volume>5</volume>
          (
          <issue>3</issue>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>T.</given-names>
            <surname>Schmickl</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Thenius</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Mslinger</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Timmis</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Tyrrell</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Read</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Hilder</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Halloy</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Campo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Stefanini</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Manfredi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Dipper</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Sutantyo</surname>
          </string-name>
          , and
          <string-name>
            <given-names>S.</given-names>
            <surname>Kernbach</surname>
          </string-name>
          .
          <article-title>Cocoro the self-aware underwater swarm</article-title>
          . In Awarenss Workshop, Ann Arbor (MI), USA,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>A.</given-names>
            <surname>Tchao</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Risoldi</surname>
          </string-name>
          , and
          <string-name>
            <given-names>G.</given-names>
            <surname>Serugendo</surname>
          </string-name>
          .
          <article-title>Modeling self-* systems using chemically-inspired composable patterns</article-title>
          .
          <source>In IEEE International Conference on Self-Adaptive and SelfOrganizing Systems</source>
          , Ann Arbor (MI), USA,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>M.</given-names>
            <surname>Ulieru</surname>
          </string-name>
          and
          <string-name>
            <given-names>S.</given-names>
            <surname>Grobbelaar</surname>
          </string-name>
          .
          <article-title>Engineering industrial ecosystems in a networked world</article-title>
          .
          <source>In 5th IEEE International Conference on Industrial Informatics</source>
          , pages
          <fpage>1</fpage>
          -
          <lpage>7</lpage>
          ,
          <year>June 2007</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>M.</given-names>
            <surname>Viroli</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Casadei</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Montagna</surname>
          </string-name>
          , and
          <string-name>
            <given-names>F.</given-names>
            <surname>Zambonelli</surname>
          </string-name>
          .
          <article-title>Spatial coordination of pervasive services through chemicalinspired tuple spaces</article-title>
          .
          <source>ACM Transactions on Autonomous and Adaptive Systems</source>
          ,
          <volume>6</volume>
          (
          <issue>2</issue>
          ):
          <fpage>14</fpage>
          ,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>M.</given-names>
            <surname>Viroli</surname>
          </string-name>
          , E. Nardini, G. Castelli,
          <string-name>
            <given-names>M.</given-names>
            <surname>Mamei</surname>
          </string-name>
          , and
          <string-name>
            <given-names>F.</given-names>
            <surname>Zambonelli</surname>
          </string-name>
          .
          <article-title>A coordination approach to adaptive pervasive service ecosystems</article-title>
          . In Awarenss Workshop, Ann Arbor (MI), USA,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>M.</given-names>
            <surname>Viroli</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Pianini</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Montagna</surname>
          </string-name>
          , and
          <string-name>
            <given-names>G.</given-names>
            <surname>Stevenson</surname>
          </string-name>
          .
          <article-title>Pervasive ecosystems: a coordination model based on semantic chemistry</article-title>
          .
          <source>In ACM Symposium on Applied Computing (SAC</source>
          <year>2012</year>
          ),
          <source>Riva del Garda</source>
          , Italy,
          <year>2012</year>
          . ACM.
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>P.</given-names>
            <surname>Walters</surname>
          </string-name>
          .
          <article-title>An introduction to ergodic theory</article-title>
          . Springer,
          <year>1982</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>