<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD Journal Publishing DTD v2.3 20070202//EN" "journalpublishing.dtd">
<article article-type="research-article" dtd-version="2.3" xml:lang="EN" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">
<front>
<journal-meta>
<journal-id journal-id-type="publisher-id">Front. Robot. AI</journal-id>
<journal-title>Frontiers in Robotics and AI</journal-title>
<abbrev-journal-title abbrev-type="pubmed">Front. Robot. AI</abbrev-journal-title>
<issn pub-type="epub">2296-9144</issn>
<publisher>
<publisher-name>Frontiers Media S.A.</publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">866649</article-id>
<article-id pub-id-type="doi">10.3389/frobt.2022.866649</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Robotics and AI</subject>
<subj-group>
<subject>Original Research</subject>
</subj-group>
</subj-group>
</article-categories>
<title-group>
<article-title>On the Modeling and Verification of Collective and Cooperative Systems</article-title>
<alt-title alt-title-type="left-running-head">Aldini</alt-title>
<alt-title alt-title-type="right-running-head">On the Modeling and Verification of Collective and Cooperative Systems</alt-title>
</title-group>
<contrib-group>
<contrib contrib-type="author" corresp="yes">
<name>
<surname>Aldini</surname>
<given-names>Alessandro</given-names>
</name>
<xref ref-type="corresp" rid="c001">&#x2a;</xref>
<uri xlink:href="https://loop.frontiersin.org/people/1563254/overview"/>
</contrib>
</contrib-group>
<aff>
<institution>Department of Pure and Applied Sciences</institution>, <institution>University of Urbino Carlo Bo</institution>, <addr-line>Urbino</addr-line>, <country>Italy</country>
</aff>
<author-notes>
<fn fn-type="edited-by">
<p>
<bold>Edited by:</bold> <ext-link ext-link-type="uri" xlink:href="https://loop.frontiersin.org/people/1385250/overview">Roberto Casadei</ext-link>, University of Bologna, Italy</p>
</fn>
<fn fn-type="edited-by">
<p>
<bold>Reviewed by:</bold> <ext-link ext-link-type="uri" xlink:href="https://loop.frontiersin.org/people/1663704/overview">Michele Loreti</ext-link>, University of Camerino, Italy</p>
<p>
<ext-link ext-link-type="uri" xlink:href="https://loop.frontiersin.org/people/1766158/overview">Erik De Vink</ext-link>, Eindhoven University of Technology, Netherlands</p>
</fn>
<corresp id="c001">&#x2a;Correspondence: Alessandro Aldini, <email>alessandro.aldini@uniurb.it</email>
</corresp>
<fn fn-type="other">
<p>This article was submitted to Multi-Robot Systems, a section of the journal Frontiers in Robotics and AI</p>
</fn>
</author-notes>
<pub-date pub-type="epub">
<day>27</day>
<month>06</month>
<year>2022</year>
</pub-date>
<pub-date pub-type="collection">
<year>2022</year>
</pub-date>
<volume>9</volume>
<elocation-id>866649</elocation-id>
<history>
<date date-type="received">
<day>31</day>
<month>01</month>
<year>2022</year>
</date>
<date date-type="accepted">
<day>27</day>
<month>04</month>
<year>2022</year>
</date>
</history>
<permissions>
<copyright-statement>Copyright &#xa9; 2022 Aldini.</copyright-statement>
<copyright-year>2022</copyright-year>
<copyright-holder>Aldini</copyright-holder>
<license xlink:href="http://creativecommons.org/licenses/by/4.0/">
<p>This is an open-access article distributed under the terms of the Creative Commons Attribution License (CC BY). The use, distribution or reproduction in other forums is permitted, provided the original author(s) and the copyright owner(s) are credited and that the original publication in this journal is cited, in accordance with accepted academic practice. No use, distribution or reproduction is permitted which does not comply with these terms.</p>
</license>
</permissions>
<abstract>
<p>The formal description and verification of networks of cooperative and interacting agents is made difficult by the interplay of several different behavioral patterns, models of communication, scalability issues. In this paper, we will explore the functionalities and the expressiveness of a general-purpose process algebraic framework for the specification and model checking based analysis of collective and cooperative systems. The proposed syntactic and semantic schemes are general enough to be adapted with small modifications to heterogeneous application domains, like, e.g., crowdsourcing systems, trustworthy networks, and distributed ledger technologies.</p>
</abstract>
<kwd-group>
<kwd>collective adaptive systems</kwd>
<kwd>social networks</kwd>
<kwd>process algebra</kwd>
<kwd>model checking</kwd>
<kwd>temporal logics</kwd>
</kwd-group>
<contract-sponsor id="cn001">Dipartimento di Scienze Pure e Applicate, Universit&#xe0; degli Studi di Urbino Carlo Bo<named-content content-type="fundref-id">10.13039/501100016143</named-content>
</contract-sponsor>
</article-meta>
</front>
<body>
<sec id="s1">
<title>1 Introduction</title>
<p>Cooperation activities and collective behaviors are widespread phenomena in several environments, ranging from nature to human social relationships and artificial systems. Therefore, they have cross-cutting implications in different specific fields of knowledge, including, just to cite a few, biology (<xref ref-type="bibr" rid="B21">Crall et al., 2019</xref>; <xref ref-type="bibr" rid="B30">Glen et al., 2019</xref>; <xref ref-type="bibr" rid="B46">Romanov et al., 2022</xref>), sociology (<xref ref-type="bibr" rid="B48">Takano and Ichinose, 2018</xref>; <xref ref-type="bibr" rid="B52">Will et al., 2020</xref>), and robotics (<xref ref-type="bibr" rid="B22">Dai et al., 2016</xref>; <xref ref-type="bibr" rid="B45">Rausch et al., 2020</xref>; <xref ref-type="bibr" rid="B40">Mehmood et al., 2021</xref>). Although different levels of abstraction are involved, information sharing mechanisms form the base for the evolution of biological, social, and engineering systems exhibiting the behaviors specified above. In particular, the efficiency of these mechanisms determines not only the success of individuals but also the fitness of systems of communities of such individuals. This is even more critical whenever:<list list-type="simple">
<list-item>
<p>1. The systems need to be adaptive with respect to dynamically changing environments;</p>
</list-item>
<list-item>
<p>2. A multiplicity of different types of agents collaborate (or compete) to engage in community decision processes (or to achieve individual goals to survive and emerge);</p>
</list-item>
<list-item>
<p>3. Complex tasks are interleaved with frequent mutual interactions.</p>
</list-item>
</list>
</p>
<p>In this respect, one of the main aspects to pay attention to is given by the communication and cooperation models, with a specific emphasis on the information exchange policies, the allocation of tasks and of resources, the synchronization of activities converging to group goals. Moreover, it is worth distinguishing the nature and use of the information that may be subject to exchange, which can derive from the external environment, be processed by every agent in isolation, and/or represent community-based shares.</p>
<p>All these considerations play a role when devising techniques to model, verify, and develop collective and cooperative systems - see, e.g., <xref ref-type="bibr" rid="B24">De Nicola et al. (2020)</xref> and the references therein for a comprehensive overview. In this paper, we concentrate on the issues related to the formal modeling and verification of such systems. To this aim, we propose a general-purpose process algebraic framework that can be instantiated to the various and heterogeneous application domains surveyed above. The basic ingredients of this framework focus on the specification of the autonomous behavior of the agents, the handling of data collected from the environment and shared with the neighbours, the mode of interaction within communities of agents, the topology of the interacting communities, the dynamically changing external environment and system configuration. The flexibility of the approach is the main contribution provided by the framework, which makes it adequate to model and verify both natural and socially collective systems (including social networks as well as crowdsourcing systems), and artificial networks (including P2P and GRID systems, multi-agent systems, and sensor networks).</p>
<p>The kernel of the specification language is based on process algebra and relies only on a few, basic set of operators for the description of the behavioral pattern of agents in isolation. The syntax is left as simple as possible and abstracts away from the overwhelming details of standard parallel composition operators, thus making the process of composing even large networks of agents easy and scalable.</p>
<p>The semantics of the language encodes the mode of communication among agents, through rule schemes that support flexibility and adaptiveness with respect to the specific application domain of interest. Moreover, the framework includes the capability of grouping agents into dynamic communities, and to model local information stored by agents as well as global information shared within a given community of agents. Such an agent/community-oriented modeling framework is equipped with a temporal logic for the specification of properties of agents, communities, and networks. Thus, the flexibility of the modeling paradigm is inherited also by the property specification framework, enabling the definition of various property patterns, ranging from safety to performance.</p>
<p>The rest of the paper is organized as follows. In the next section, the basic syntax and semantics of the modeling framework are presented, by emphasizing the way in which customized semantics rules can be devised depending on the application domain. <xref ref-type="sec" rid="s3">Section 3</xref> defines the temporal logic for property specification. The applicability of this framework to various application domains is illustrated in <xref ref-type="sec" rid="s4">Section 4</xref> via some real-world references and examples. Finally, a discussion on related and future work is the topic of <xref ref-type="sec" rid="s5">Section 5</xref>.</p>
</sec>
<sec id="s2">
<title>2 Modeling Agents and Networks</title>
<p>A key aspect for simplifying as much as possible the description of complex networks of agents is the clear separation between the description of each agent in isolation and the definition of the network of agents. This is even more crucial for formal paradigms like process algebra, which are typically based on a set of algebraic operators that join together the two levels of descriptions surveyed above, i.e., the agent level and the network level.</p>
<p>The separation of concerns between the definition of the system topology and of the behavioral pattern of the agents forming such a topology is a typical approach of architectural description languages&#x2013;see, e.g., <xref ref-type="bibr" rid="B4">Aldini et al. (2010)</xref>&#x2014;and is indeed motivated by usability and scalability issues. Therefore, we base the modeling framework on such a separation.</p>
<sec id="s2-1">
<title>2.1 Modeling Behavioral Patterns and Agents</title>
<p>As a first step, we start with the presentation of a basic calculus&#x2013;see, e.g., <xref ref-type="bibr" rid="B26">Fokkink, (2007)</xref>&#x2014;for the description of the isolated behavior of sequential processes.</p>
<p>Let <italic>Act</italic> be the set of actions, ranged over by <italic>a</italic>, <italic>b</italic>, &#x2026; , including also the special internal action <italic>&#x3c4;</italic>. The set <inline-formula id="inf1">
<mml:math id="m1">
<mml:mi mathvariant="script">L</mml:mi>
</mml:math>
</inline-formula> of process terms of the basic calculus for sequential processes is generated through the following syntax:<disp-formula id="equ1">
<mml:math id="m2">
<mml:mtable class="array">
<mml:mtr>
<mml:mtd columnalign="left">
<mml:mi>P</mml:mi>
<mml:mspace width="0.28em"/>
<mml:mo>&#x2a74;</mml:mo>
<mml:mspace width="0.28em"/>
<mml:munder accentunder="false">
<mml:mrow>
<mml:mn>0</mml:mn>
</mml:mrow>
<mml:mo accent="true">&#x332;</mml:mo>
</mml:munder>
<mml:mo stretchy="false">&#x2223;</mml:mo>
<mml:mi>a</mml:mi>
<mml:mo>.</mml:mo>
<mml:mspace width="0.17em"/>
<mml:mi>P</mml:mi>
<mml:mo stretchy="false">&#x2223;</mml:mo>
<mml:mi>P</mml:mi>
<mml:mo>&#x2b;</mml:mo>
<mml:mi>P</mml:mi>
<mml:mo stretchy="false">&#x2223;</mml:mo>
<mml:mi>B</mml:mi>
</mml:mtd>
</mml:mtr>
</mml:mtable>
</mml:math>
</disp-formula>where we have the constant <inline-formula id="inf2">
<mml:math id="m3">
<mml:munder accentunder="false">
<mml:mrow>
<mml:mn>0</mml:mn>
</mml:mrow>
<mml:mo accent="true">&#x332;</mml:mo>
</mml:munder>
</mml:math>
</inline-formula> for the inactive process, the classical algebraic operators for prefix and nondeterministic choice, and a constant based mechanism for expressing recursive processes, such that a set of constants defining equations of the form <inline-formula id="inf3">
<mml:math id="m4">
<mml:mi>B</mml:mi>
<mml:mrow>
<mml:mover>
<mml:mrow>
<mml:mo>&#x3d;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:mi mathvariant="normal">d</mml:mi>
<mml:mi mathvariant="normal">e</mml:mi>
<mml:mi mathvariant="normal">f</mml:mi>
</mml:mrow>
</mml:mrow>
</mml:mover>
</mml:mrow>
<mml:mi>P</mml:mi>
</mml:math>
</inline-formula> is assumed. As standard, we consider only guarded and closed process terms. The semantics of process terms is expressed in terms of labeled transition systems.</p>
<p>Definition 1. <italic>A labeled transition system (LTS) is a tuple</italic> (<italic>Q</italic>, <italic>q</italic>
<sub>0</sub>, <italic>L</italic>, <italic>R</italic>)<italic>, where</italic> <italic>Q</italic> <italic>is a finite set of states</italic> (<italic>with</italic> <italic>q</italic>
<sub>0</sub> <italic>the initial one</italic>)<italic>,</italic> <italic>L</italic> <italic>is a finite set of labels, and</italic> <italic>R</italic> &#x2286; <italic>Q</italic> &#xd7; <italic>L</italic> &#xd7; <italic>Q</italic> <italic>is a finitely-branching transition relation.</italic>
</p>
<p>As a shorthand, (<italic>q</italic>, <italic>a</italic>, <italic>q</italic>&#x2032;) &#x2208; <italic>R</italic> is denoted by <inline-formula id="inf4">
<mml:math id="m5">
<mml:mi>q</mml:mi>
<mml:mrow>
<mml:mover>
<mml:mrow>
<mml:mo>&#x2192;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:mi>a</mml:mi>
</mml:mrow>
</mml:mrow>
</mml:mover>
</mml:mrow>
<mml:msup>
<mml:mrow>
<mml:mi>q</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
</mml:math>
</inline-formula>. Then, the behavior of process term <italic>P</italic> is defined by the smallest LTS <inline-formula id="inf5">
<mml:math id="m6">
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">L</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>A</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>t</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>R</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula>, where the transitions in <italic>R</italic> are obtained through the application of the operational semantics rules of <xref ref-type="table" rid="T1">Table 1</xref>. The <italic>prefix</italic> rule is at the base of the sequential behavior of processes, stating that <italic>a</italic>. <italic>P</italic> executes <italic>a</italic> and then behaves as <italic>P</italic>. The two <italic>choice</italic> rules express the nondeterministic choice between <italic>P</italic>
<sub>1</sub> and <italic>P</italic>
<sub>2</sub>. The winning process proceeds with its execution, thus disabling once and for all the other one. The <italic>recursion</italic> rule establishes that the process term named <italic>B</italic> and defined as <italic>P</italic>, behaves as <italic>P</italic> itself; naming enables the definition of recursive behaviors.</p>
<table-wrap id="T1" position="float">
<label>TABLE 1</label>
<caption>
<p>Semantics rules of the basic calculus.</p>
</caption>
<table>
<tbody valign="top">
<tr>
<td align="left">
<inline-graphic xlink:href="frobt-09-866649-fx1.tif"/>
</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>Example 1.</p>
<p>As a first running example, we consider a social network in which various agents contribute to the spreading of (possibly fake) news. A detailed version of this system is modeled and analyzed in <xref ref-type="bibr" rid="B6">Aldini, (2022)</xref>, by using a formal framework that turns out to be an instance of that proposed in this work. Here, we start considering a simple, process term:<disp-formula id="equ2">
<mml:math id="m7">
<mml:mi>F</mml:mi>
<mml:mrow>
<mml:mover>
<mml:mrow>
<mml:mo>&#x3d;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:mi mathvariant="normal">d</mml:mi>
<mml:mi mathvariant="normal">e</mml:mi>
<mml:mi mathvariant="normal">f</mml:mi>
</mml:mrow>
</mml:mrow>
</mml:mover>
</mml:mrow>
<mml:mi>n</mml:mi>
<mml:mi>b</mml:mi>
<mml:mi>r</mml:mi>
<mml:mo>.</mml:mo>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mi>e</mml:mi>
<mml:mo>-</mml:mo>
<mml:mi>e</mml:mi>
<mml:mi>v</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>e</mml:mi>
<mml:mo>.</mml:mo>
<mml:mi>F</mml:mi>
<mml:mo>&#x2b;</mml:mo>
<mml:mi>f</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>g</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>t</mml:mi>
<mml:mo>.</mml:mo>
<mml:munder accentunder="false">
<mml:mrow>
<mml:mn>0</mml:mn>
</mml:mrow>
<mml:mo accent="true">&#x332;</mml:mo>
</mml:munder>
</mml:mrow>
</mml:mfenced>
</mml:math>
</disp-formula>
<italic>which models the behavior of a fact checker in such a network. Action</italic> <italic>nbr</italic> <italic>denotes the gathering of shared news from the neighbourhood, action</italic> <italic>forget</italic> <italic>expresses that any shared news is forgotten once and for all, and action</italic> <italic>re</italic>-<italic>evaluate</italic> <italic>denotes that the process of news evaluation is repeated again.</italic>
</p>
<p>As another running example, we will consider a trustworthy network of communities, where agents exchange services and the interactions among agents are enabled/disabled by trust/distrust relations. A detailed version of this system is modeled and analyzed in <xref ref-type="bibr" rid="B5">Aldini, (2018)</xref> through an alternative framework that, similarly as above, is generalized by the current proposal. Here, we start considering a simple, process term:<disp-formula id="equ3">
<mml:math id="m8">
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mover>
<mml:mrow>
<mml:mo>&#x3d;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:mi mathvariant="normal">d</mml:mi>
<mml:mi mathvariant="normal">e</mml:mi>
<mml:mi mathvariant="normal">f</mml:mi>
</mml:mrow>
</mml:mrow>
</mml:mover>
</mml:mrow>
<mml:mi>s</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>d</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">req</mml:mi>
<mml:mo>.</mml:mo>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>c</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">acc</mml:mi>
<mml:mo>.</mml:mo>
<mml:mi>T</mml:mi>
<mml:mo>&#x2b;</mml:mo>
<mml:mi>r</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>c</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">ref</mml:mi>
<mml:mo>.</mml:mo>
<mml:mi>T</mml:mi>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#x2b;</mml:mo>
<mml:mi>l</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>v</mml:mi>
<mml:mi>e</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">com</mml:mi>
<mml:mo>.</mml:mo>
<mml:munder accentunder="false">
<mml:mrow>
<mml:mn>0</mml:mn>
</mml:mrow>
<mml:mo accent="true">&#x332;</mml:mo>
</mml:munder>
</mml:math>
</disp-formula>
<italic>describing the behavior of a trustor, which may ask for services from the unique provider operating in the community to which the trustor belongs. Action</italic> <italic>snd</italic>_<italic>req</italic> <italic>denotes a service request sent to such a provider, which in fact represents the trustee subject of trust evaluation by the trustor; the request can be either accepted</italic> (<italic>action</italic> <italic>rec</italic>_<italic>acc</italic>) <italic>or refused</italic> (<italic>action</italic> <italic>rec</italic>_<italic>ref</italic>)<italic>. Alternatively, the trustor may decide to abandon the community</italic> (<italic>action</italic> <italic>leave</italic>_<italic>com</italic>)<italic>.</italic>
</p>
<p>In the following, an <italic>agent</italic> is any instance of a given process term <italic>P</italic>, which is referred to as the behavioral type (or pattern) of the agent. In other words, an agent represents an element exhibiting the behavior associated with a process term. Agents are associated with a unique identity, which in the following we denote with a natural number for the sake of simplicity. Moreover, each agent is equipped with a local data repository, used to store local parameters as well as data retrieved from sensors or received from the neighborhood. Such a repository is represented as a set of local atomic predicates. By assuming a standard first-order logic interpretation, predicates are of the form <italic>v</italic> &#x3d; <italic>d</italic>, with <italic>v</italic> &#x2208; <italic>VNames</italic> a local variable and <italic>d</italic> a value of the corresponding domain.</p>
<p>Formally, an agent is described by a triple of elements &#x27e8;<italic>id</italic>, <italic>P</italic>, <italic>V</italic>&#x27e9;, where:<list list-type="simple">
<list-item>
<p>&#x2022; <inline-formula id="inf6">
<mml:math id="m9">
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="double-struck">N</mml:mi>
</mml:math>
</inline-formula> is the identity of the agent;</p>
</list-item>
<list-item>
<p>&#x2022; process term <inline-formula id="inf7">
<mml:math id="m10">
<mml:mi>P</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="script">L</mml:mi>
</mml:math>
</inline-formula> is its behavioral type;</p>
</list-item>
<list-item>
<p>&#x2022; function <italic>V</italic>: <italic>VNames</italic>&#x21a6;<italic>D</italic> is the mapping from local variables to values in their corresponding domain <italic>D</italic>.<xref ref-type="fn" rid="fn1">
<sup>1</sup>
</xref>
</p>
</list-item>
</list>
</p>
<p>Given the triple &#x27e8;<italic>id</italic>, <italic>P</italic>, <italic>V</italic>&#x27e9;, as a shorthand we sometimes use the classical dot notation <italic>id</italic>. <italic>P</italic> to denote the local behavior of agent <italic>id</italic>, <italic>id</italic>. <italic>a</italic> to denote an action <italic>a</italic> enabled by the local behavior <italic>P</italic> of agent <italic>id</italic>, and <italic>id</italic>. <italic>v</italic> to denote the value <italic>V</italic>(<italic>v</italic>) of the local variable <italic>v</italic> in the local data repository of agent <italic>id</italic>.</p>
<p>Example 2. <italic>A fact checker named</italic> <italic>id</italic> <italic>of behavioral type</italic> <italic>F</italic> <italic>is described by the triple</italic> &#x27e8;<italic>id</italic>, <italic>F</italic>, <italic>V</italic>&#x27e9;<italic>. The local variables are:</italic> <italic>type</italic>
<italic>, which expresses the level of susceptibility of the agent to accept shared news;</italic> <italic>accept</italic>
<italic>, which is a Boolean modeling whether the news is accepted and in turn shared by the agent;</italic> <italic>threshold</italic>
<italic>, which expresses the minimum number of neighbours that must share the same news in order to consider the news for acceptance.</italic>
</p>
<p>
<italic>A trustor named</italic> <italic>id</italic> <italic>of behavioral type</italic> <italic>T</italic> <italic>is described by the triple</italic> &#x27e8;<italic>id</italic>, <italic>T</italic>, <italic>V</italic>&#x27e9;<italic>. The local variables are:</italic> <italic>&#x3b1;</italic> <italic>and</italic> <italic>&#x3b2;</italic>
<italic>, reporting the number of accepted (respectively, refused) requests, and</italic> <italic>&#x3b8;</italic>
<italic>, which represents the trust threshold employed by the trustor for the trust-based evaluation of the trustee.</italic>
</p>
<p>While it is easy to see that the agent local semantics is given by the semantics of its behavioral type, it is less obvious to determine the agent&#x2019;s behavior in the context of the environment. Such a context affects also the updates applied by the agent to its local repository. Therefore, we need to define formally the interaction semantics for a network of communicating agents.</p>
</sec>
<sec id="s2-2">
<title>2.2 Modeling Networks of Interacting Agents</title>
<p>A network is a set of agents, which are grouped to form (possibly dynamic) communities. Basically, direct interactions among agents are possible only within the same community. However, each agent, in general, may belong to several different communities at the same time. Similarly as in the case of single agents, each community is associated with a global data repository, storing data that can be shared by all the community participants. Such a repository is modeled as a set of global atomic predicates of the form <italic>w</italic> &#x3d; <italic>d</italic>, with <italic>w</italic> &#x2208; <italic>WNames</italic>
<xref ref-type="fn" rid="fn2">
<sup>2</sup>
</xref> a global variable and <italic>d</italic> a value of the corresponding domain.</p>
<p>Formally, a network is a triple of elements <inline-formula id="inf8">
<mml:math id="m11">
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula>, where:<list list-type="simple">
<list-item>
<p>&#x2022; <inline-formula id="inf9">
<mml:math id="m12">
<mml:mi mathvariant="script">S</mml:mi>
</mml:math>
</inline-formula> is the finite set <inline-formula id="inf10">
<mml:math id="m13">
<mml:msubsup>
<mml:mrow>
<mml:mo>&#x22c3;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>&#x3d;</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
<mml:mrow>
<mml:mi>n</mml:mi>
</mml:mrow>
</mml:msubsup>
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>P</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>V</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> of <italic>n</italic> agents in the network, such that <italic>id</italic>
<sub>
<italic>j</italic>
</sub> &#x2260; <italic>id</italic>
<sub>
<italic>k</italic>
</sub> for every pair of indexes <italic>j</italic>, <italic>k</italic>;</p>
</list-item>
<list-item>
<p>&#x2022; function <inline-formula id="inf11">
<mml:math id="m14">
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>:</mml:mo>
<mml:mi>C</mml:mi>
<mml:mi>N</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>m</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>s</mml:mi>
<mml:mo>&#x2192;</mml:mo>
<mml:msup>
<mml:mrow>
<mml:mn>2</mml:mn>
</mml:mrow>
<mml:mrow>
<mml:mi mathvariant="double-struck">N</mml:mi>
</mml:mrow>
</mml:msup>
</mml:math>
</inline-formula> maps every community (with <italic>CNames</italic> being the set of community names) to the set of agents identities forming it, thus representing the network topology;</p>
</list-item>
<list-item>
<p>&#x2022; function <inline-formula id="inf12">
<mml:math id="m15">
<mml:mi mathvariant="script">W</mml:mi>
<mml:mo>:</mml:mo>
<mml:mi>C</mml:mi>
<mml:mi>N</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>m</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>s</mml:mi>
<mml:mo>&#x2192;</mml:mo>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>W</mml:mi>
<mml:mi>N</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>m</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>s</mml:mi>
<mml:mo>&#x21a6;</mml:mo>
<mml:mi>D</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> maps every community to the related mapping from global variables to values in their corresponding domain.</p>
</list-item>
</list>
</p>
<p>The semantics of a network and, in particular, the way in which the constituting agents cooperate and evolve, depend on requirements of the specific scenario under consideration. Hence, (almost all) the rules we are going to introduce are actually schemes of rules including customizable elements. The first, fundamental modeling choice is related to the mode of execution, for which we distinguish two classical, alternative cases: <italic>asynchronous</italic> mode, where every agent may execute an autonomous action while all the others remain idle, and <italic>synchronous</italic> mode, where all the agents involved simultaneously execute one of their enabled actions.</p>
<p>The general semantic rule scheme for the asynchronous mode is as follows:<disp-formula id="equ4">
<mml:math id="m16">
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>a</mml:mi>
<mml:mi>s</mml:mi>
<mml:mi>y</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>c</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mspace width="2em"/>
<mml:mfrac>
<mml:mrow>
<mml:mi>P</mml:mi>
<mml:mrow>
<mml:mover>
<mml:mrow>
<mml:mo>&#x2192;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:mi>a</mml:mi>
</mml:mrow>
</mml:mrow>
</mml:mover>
</mml:mrow>
<mml:msup>
<mml:mrow>
<mml:mi>P</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mspace width="1em"/>
<mml:mo>&#x2227;</mml:mo>
<mml:mspace width="0.3333em" class="nbsp"/>
<mml:mi mathvariant="monospace">c</mml:mi>
<mml:mi mathvariant="monospace">o</mml:mi>
<mml:mi mathvariant="monospace">n</mml:mi>
<mml:mi mathvariant="monospace">d</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mfenced open="{" close="}">
<mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>V</mml:mi>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#x222a;</mml:mo>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mo stretchy="false">&#x232a;</mml:mo>
<mml:mrow>
<mml:mover>
<mml:mrow>
<mml:mo>&#x2192;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:mi>a</mml:mi>
</mml:mrow>
</mml:mrow>
</mml:mover>
</mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mfenced open="{" close="}">
<mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:msup>
<mml:mrow>
<mml:mi>P</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mo>,</mml:mo>
<mml:msup>
<mml:mrow>
<mml:mi>V</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#x222a;</mml:mo>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:msup>
<mml:mrow>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
</mml:mfrac>
</mml:math>
</disp-formula>where the side condition <inline-formula id="inf13">
<mml:math id="m17">
<mml:mi mathvariant="monospace">c</mml:mi>
<mml:mi mathvariant="monospace">o</mml:mi>
<mml:mi mathvariant="monospace">n</mml:mi>
<mml:mi mathvariant="monospace">d</mml:mi>
</mml:math>
</inline-formula> stands for a Boolean formula composed of logical predicates over any combination of identities, communities, local variables, and global variables taken from the current network triple <inline-formula id="inf14">
<mml:math id="m18">
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">{</mml:mo>
<mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>V</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:mrow>
<mml:mo stretchy="false">}</mml:mo>
</mml:mrow>
<mml:mo>&#x222a;</mml:mo>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula>, and stating whether the action <italic>a</italic> offered by the local behavior <italic>P</italic> of agent <italic>id</italic> is enabled in the network environment. Hence, the side condition is actually of the form <inline-formula id="inf15">
<mml:math id="m19">
<mml:mi mathvariant="monospace">c</mml:mi>
<mml:mi mathvariant="monospace">o</mml:mi>
<mml:mi mathvariant="monospace">n</mml:mi>
<mml:mi mathvariant="monospace">d</mml:mi>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>a</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>V</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mo>,</mml:mo>
<mml:msup>
<mml:mrow>
<mml:mi>V</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mo>,</mml:mo>
<mml:msup>
<mml:mrow>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula>. The additional terms <italic>V</italic>&#x2032; and <inline-formula id="inf16">
<mml:math id="m20">
<mml:msup>
<mml:mrow>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
</mml:math>
</inline-formula> depend on <italic>V</italic> and <inline-formula id="inf17">
<mml:math id="m21">
<mml:mi mathvariant="script">W</mml:mi>
</mml:math>
</inline-formula>, respectively, and represent their updated versions by virtue of the execution of the action <italic>a</italic>. More details about these terms and the definition of the side condition will be provided through examples. Notice that, for the sake of readability, in the rule scheme above and in the following ones, the side condition <inline-formula id="inf18">
<mml:math id="m22">
<mml:mi mathvariant="monospace">c</mml:mi>
<mml:mi mathvariant="monospace">o</mml:mi>
<mml:mi mathvariant="monospace">n</mml:mi>
<mml:mi mathvariant="monospace">d</mml:mi>
</mml:math>
</inline-formula> is reported without making the list of arguments explicit.</p>
<p>Example 3. <italic>We present three typical formats for the atomic predicates that can be combined through logical connectives to define the side condition</italic> <inline-formula id="inf19">
<mml:math id="m23">
<mml:mi mathvariant="monospace">c</mml:mi>
<mml:mi mathvariant="monospace">o</mml:mi>
<mml:mi mathvariant="monospace">n</mml:mi>
<mml:mi mathvariant="monospace">d</mml:mi>
</mml:math>
</inline-formula> <italic>in the rule scheme</italic> <italic>async</italic>
<italic>:</italic>
<list list-type="simple">
<list-item>
<p>1. <italic>id</italic>. <italic>v</italic>&#x22c8;<italic>k</italic>
<italic>, with</italic> &#x22c8; <italic>any arithmetic comparison operator and</italic> <italic>k</italic> <italic>a scalar value belonging to the domain of the local variable</italic> <italic>v</italic>
<italic>: such a condition is purely local as it does not depend on the context in which agent</italic> &#x27e8;<italic>id</italic>, <italic>P</italic>, <italic>V</italic>&#x27e9; <italic>operates;</italic>
</p>
</list-item>
<list-item>
<p>2. <inline-formula id="inf20">
<mml:math id="m24">
<mml:mo>&#x2203;</mml:mo>
<mml:mi>G</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi>C</mml:mi>
<mml:mi>N</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>m</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>s</mml:mi>
<mml:mo>:</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>G</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mo>&#x2227;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>.</mml:mo>
<mml:mi>v</mml:mi>
<mml:mo>&#x22c8;</mml:mo>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>G</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>w</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula>
<italic>, which compares the local variable</italic> <italic>v</italic> <italic>of the agent to the global variable</italic> <italic>w</italic> <italic>of a community</italic> <italic>G</italic> <italic>to which the agent belongs</italic> <inline-formula id="inf21">
<mml:math id="m25">
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>G</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula>
<italic>;</italic>
</p>
</list-item>
<list-item>
<p>3. <italic>id</italic>. <italic>v</italic>&#x22c8;<italic>f</italic>(<italic>X</italic>)<italic>, where</italic> <italic>f</italic> <italic>is a scalar function (e.g., min, sum, count) applied to a set</italic> <italic>X</italic> <italic>of local/global variables filtered in a certain way, and returning a value belonging to the domain of variable</italic> <italic>v</italic>
<italic>.</italic>
</p>
</list-item>
</list>
</p>
<p>
<italic>Analogous patterns can be envisioned by defining conditions over</italic> <italic>id</italic> <italic>rather than over</italic> <italic>id</italic>. <italic>v</italic>
<italic>.</italic>
</p>
<p>Later on we will show some exemplifying conditions specifically adapted to the application domains of interest. As stated above, the rule scheme <italic>async</italic> expresses also potential side effects of the execution of the action <italic>a</italic> over the local variables of the agent <italic>id</italic> and/or over the global variables of the network. Formally, the terms <italic>V</italic>&#x2032; and <inline-formula id="inf22">
<mml:math id="m26">
<mml:msup>
<mml:mrow>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
</mml:math>
</inline-formula> represent the updated versions of the terms <italic>V</italic> and <inline-formula id="inf23">
<mml:math id="m27">
<mml:mi mathvariant="script">W</mml:mi>
</mml:math>
</inline-formula>, respectively. On one hand, they may be equal to <italic>V</italic> and <inline-formula id="inf24">
<mml:math id="m28">
<mml:mi mathvariant="script">W</mml:mi>
</mml:math>
</inline-formula>, respectively, to express that no change occurs. On the other hand, they may be defined in terms of updates occurring in <italic>V</italic> and <inline-formula id="inf25">
<mml:math id="m29">
<mml:mi mathvariant="script">W</mml:mi>
</mml:math>
</inline-formula>. To this aim, in the following examples we will use the standard notation <italic>s</italic>&#x2032; &#x3d; <italic>s</italic>[<italic>x</italic>&#x21a6;<italic>d</italic>] to express a mapping <italic>s</italic>&#x2032; equal to <italic>s</italic> in every point but <italic>x</italic>, where <italic>s</italic>&#x2032;(<italic>x</italic>) &#x3d; <italic>d</italic>.</p>
<p>Summarizing, the rule format states that if the agent of the network defined as &#x27e8;<italic>id</italic>, <italic>P</italic>, <italic>V</italic>&#x27e9; enables locally a move, and such a move is permitted by the environmental conditions, then the agent is allowed to evolve and change accordingly the variables under its control.</p>
<p>We point out that, as a special case, ad-hoc actions can be envisioned to model movements to or from communities, which is typical of dynamic scenarios&#x2013;see, e.g., <xref ref-type="bibr" rid="B6">Aldini, (2022)</xref> for a possible semantic characterization. Just notice that such a kind of actions would affect the structure <inline-formula id="inf26">
<mml:math id="m30">
<mml:mi mathvariant="script">G</mml:mi>
</mml:math>
</inline-formula> of the tuple describing the network configuration. As an example, the general semantic rule scheme describing the action of leaving a group is as follows:<disp-formula id="equ5">
<mml:math id="m31">
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>l</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>v</mml:mi>
<mml:mi>e</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mspace width="2em"/>
<mml:mfrac>
<mml:mrow>
<mml:mi>P</mml:mi>
<mml:mrow>
<mml:mover>
<mml:mrow>
<mml:mo>&#x2192;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:mi>l</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>v</mml:mi>
<mml:mi>e</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">com</mml:mi>
</mml:mrow>
</mml:mrow>
</mml:mover>
</mml:mrow>
<mml:msup>
<mml:mrow>
<mml:mi>P</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mspace width="1em"/>
<mml:mo>&#x2227;</mml:mo>
<mml:mspace width="0.3333em" class="nbsp"/>
<mml:mi mathvariant="monospace">c</mml:mi>
<mml:mi mathvariant="monospace">o</mml:mi>
<mml:mi mathvariant="monospace">n</mml:mi>
<mml:mi mathvariant="monospace">d</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mfenced open="{" close="}">
<mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>V</mml:mi>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#x222a;</mml:mo>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mo stretchy="false">&#x232a;</mml:mo>
<mml:mrow>
<mml:mover>
<mml:mrow>
<mml:mo>&#x2192;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:mi>a</mml:mi>
</mml:mrow>
</mml:mrow>
</mml:mover>
</mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mfenced open="{" close="}">
<mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:msup>
<mml:mrow>
<mml:mi>P</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mo>,</mml:mo>
<mml:msup>
<mml:mrow>
<mml:mi>V</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#x222a;</mml:mo>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:msup>
<mml:mrow>
<mml:mi mathvariant="script">G</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mo>,</mml:mo>
<mml:msup>
<mml:mrow>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
</mml:mfrac>
</mml:math>
</disp-formula>where <italic>leave</italic>_<italic>com</italic> is the name of such an action, the side condition <inline-formula id="inf27">
<mml:math id="m32">
<mml:mi mathvariant="monospace">c</mml:mi>
<mml:mi mathvariant="monospace">o</mml:mi>
<mml:mi mathvariant="monospace">n</mml:mi>
<mml:mi mathvariant="monospace">d</mml:mi>
</mml:math>
</inline-formula> specifies the enabling situation and the identification of the community <italic>G</italic> &#x2208; <italic>CNames</italic> that the agent <italic>id</italic> is leaving, <italic>V</italic>&#x2032; and <inline-formula id="inf28">
<mml:math id="m33">
<mml:msup>
<mml:mrow>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
</mml:math>
</inline-formula> express possible updates to the local/global repositories <italic>V</italic> and <inline-formula id="inf29">
<mml:math id="m34">
<mml:mi mathvariant="script">W</mml:mi>
</mml:math>
</inline-formula> due to such a move, and <inline-formula id="inf30">
<mml:math id="m35">
<mml:msup>
<mml:mrow>
<mml:mi mathvariant="script">G</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mo>&#x3d;</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>G</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mo>&#x5c;</mml:mo>
<mml:mrow>
<mml:mo stretchy="false">{</mml:mo>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">}</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> represents the update of the involved community. We can reason analogously for a corresponding action <italic>join</italic>_<italic>com</italic> modeling the entry into a community <italic>G</italic>, in which case we have <inline-formula id="inf31">
<mml:math id="m36">
<mml:msup>
<mml:mrow>
<mml:mi mathvariant="script">G</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mo>&#x3d;</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>G</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mo>&#x222a;</mml:mo>
<mml:mrow>
<mml:mo stretchy="false">{</mml:mo>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">}</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula>.</p>
<p>From the cooperation model standpoint, the rule scheme <italic>async</italic> enables forms of knowledge-based communication. Indeed, if the local repository modification (and/or the side condition <inline-formula id="inf32">
<mml:math id="m37">
<mml:mi mathvariant="monospace">c</mml:mi>
<mml:mi mathvariant="monospace">o</mml:mi>
<mml:mi mathvariant="monospace">n</mml:mi>
<mml:mi mathvariant="monospace">d</mml:mi>
</mml:math>
</inline-formula>) depends on some content deriving from the environment, then a data-driven communication from the environment to such an agent is actually modeled. Analogously, writing to the global repository, to which any other agent may have access, represents a form of community-based multicast communication. Sometimes, these forms of (asynchronous) communication are not enough as two (or more) agents have to synchronize over a certain event. To model such a kind of interaction, the following general semantic rule scheme is needed:<disp-formula id="equ6">
<mml:math id="m38">
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>s</mml:mi>
<mml:mi>y</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>c</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mspace width="2em"/>
<mml:mfrac>
<mml:mrow>
<mml:mi>P</mml:mi>
<mml:mrow>
<mml:mover>
<mml:mrow>
<mml:mo>&#x2192;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:mi>a</mml:mi>
</mml:mrow>
</mml:mrow>
</mml:mover>
</mml:mrow>
<mml:msup>
<mml:mrow>
<mml:mi>P</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mspace width="1em"/>
<mml:mi>Q</mml:mi>
<mml:mrow>
<mml:mover>
<mml:mrow>
<mml:mo>&#x2192;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:mi>b</mml:mi>
</mml:mrow>
</mml:mrow>
</mml:mover>
</mml:mrow>
<mml:msup>
<mml:mrow>
<mml:mi>Q</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mspace width="1em"/>
<mml:mo>&#x2203;</mml:mo>
<mml:mi>G</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi>C</mml:mi>
<mml:mi>N</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>m</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>s</mml:mi>
<mml:mo>.</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>G</mml:mi>
</mml:mrow>
</mml:mfenced>
<mml:mspace width="0.3333em" class="nbsp"/>
<mml:mo>&#x2227;</mml:mo>
<mml:mspace width="0.3333em" class="nbsp"/>
<mml:mi mathvariant="monospace">c</mml:mi>
<mml:mi mathvariant="monospace">o</mml:mi>
<mml:mi mathvariant="monospace">n</mml:mi>
<mml:mi mathvariant="monospace">d</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mfenced open="{" close="}">
<mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>V</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:msub>
<mml:mo stretchy="false">&#x232a;</mml:mo>
<mml:mo>,</mml:mo>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>Q</mml:mi>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>V</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:msub>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#x222a;</mml:mo>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mo stretchy="false">&#x232a;</mml:mo>
<mml:mrow>
<mml:mover>
<mml:mrow>
<mml:mo>&#x2192;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:mi>a</mml:mi>
<mml:mo>&#xd7;</mml:mo>
<mml:mi>b</mml:mi>
</mml:mrow>
</mml:mrow>
</mml:mover>
</mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mfenced open="{" close="}">
<mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msup>
<mml:mrow>
<mml:mi>P</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mo>,</mml:mo>
<mml:msubsup>
<mml:mrow>
<mml:mi>V</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mn>1</mml:mn>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msubsup>
<mml:mo stretchy="false">&#x232a;</mml:mo>
<mml:mo>,</mml:mo>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msup>
<mml:mrow>
<mml:mi>Q</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mo>,</mml:mo>
<mml:msubsup>
<mml:mrow>
<mml:mi>V</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mn>2</mml:mn>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msubsup>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#x222a;</mml:mo>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:msup>
<mml:mrow>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
</mml:mfrac>
</mml:math>
</disp-formula>where the action <italic>a</italic> &#xd7; <italic>b</italic> expresses the simultaneous execution of the actions <italic>a</italic> and <italic>b</italic>, so that the two involved agents evolve synchronously. The form of the side conditions is as discussed above, with the additional constraint that the two agents involved in the (synchronous) communication must be members of the same community, which is formally expressed by the predicate <inline-formula id="inf33">
<mml:math id="m39">
<mml:mo>&#x2203;</mml:mo>
<mml:mi>G</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi>C</mml:mi>
<mml:mi>N</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>m</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>s</mml:mi>
<mml:mo>.</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>G</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula>. As a special case, it is possible to define an ad-hoc semantic rule scheme modeling a multicast synchronous communication from an agent of a community to the other agents of the same community&#x2013;see, e.g., <xref ref-type="bibr" rid="B5">Aldini, (2018)</xref> for a possible characterization.</p>
<p>We now discuss the case of a purely synchronous mode of execution, which requires a slightly different approach relying on a two-steps semantics. In the first step, the local actions of the agents that are enabled by the environment according to the given side conditions are determined. In the second step, one action per agent is sampled nondeterministically and the system performs a move by simultaneously executing all the sampled actions. By assuming that the network of agents <inline-formula id="inf34">
<mml:math id="m40">
<mml:mi mathvariant="script">S</mml:mi>
</mml:math>
</inline-formula> includes the agent &#x27e8;<italic>id</italic>, <italic>P</italic>, <italic>V</italic>&#x27e9;, the general semantic rule scheme implementing the first step is as follows:<disp-formula id="equ7">
<mml:math id="m41">
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>g</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>b</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>l</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mspace width="2em"/>
<mml:mfrac>
<mml:mrow>
<mml:mi>P</mml:mi>
<mml:mrow>
<mml:mover>
<mml:mrow>
<mml:mo>&#x2192;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:mi>a</mml:mi>
</mml:mrow>
</mml:mrow>
</mml:mover>
</mml:mrow>
<mml:msup>
<mml:mrow>
<mml:mi>P</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mspace width="1em"/>
<mml:mo>&#x2227;</mml:mo>
<mml:mspace width="0.3333em" class="nbsp"/>
<mml:mi mathvariant="monospace">c</mml:mi>
<mml:mi mathvariant="monospace">o</mml:mi>
<mml:mi mathvariant="monospace">n</mml:mi>
<mml:mi mathvariant="monospace">d</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>V</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
</mml:msub>
<mml:mrow>
<mml:mover>
<mml:mrow>
<mml:mo>&#x2192;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:mi>a</mml:mi>
</mml:mrow>
</mml:mrow>
</mml:mover>
</mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:msup>
<mml:mrow>
<mml:mi>P</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mo>,</mml:mo>
<mml:msup>
<mml:mrow>
<mml:mi>V</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:msub>
<mml:mrow>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>&#x5c;</mml:mo>
<mml:mfenced open="{" close="}">
<mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>V</mml:mi>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#x222a;</mml:mo>
<mml:mfenced open="{" close="}">
<mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:msup>
<mml:mrow>
<mml:mi>P</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mo>,</mml:mo>
<mml:msup>
<mml:mrow>
<mml:mi>V</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
</mml:mfenced>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:msup>
<mml:mrow>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:mfrac>
</mml:math>
</disp-formula>Notice that in the conclusion of the rule scheme, the triple of elements describing the agent is decorated with the subscripted context expressing the environment with respect to which the side condition must be evaluated. More precisely, the rule scheme <italic>global</italic> expresses whether the network <inline-formula id="inf35">
<mml:math id="m42">
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> enables the execution of the action <italic>a</italic> offered in isolation by the agent represented by &#x27e8;<italic>id</italic>, <italic>P</italic>, <italic>V</italic>&#x27e9;. This is done through the verification of the side condition <inline-formula id="inf36">
<mml:math id="m43">
<mml:mi mathvariant="monospace">c</mml:mi>
<mml:mi mathvariant="monospace">o</mml:mi>
<mml:mi mathvariant="monospace">n</mml:mi>
<mml:mi mathvariant="monospace">d</mml:mi>
</mml:math>
</inline-formula>, parameterized by the elements of the triple <inline-formula id="inf37">
<mml:math id="m44">
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> representing the environment of &#x27e8;<italic>id</italic>, <italic>P</italic>, <italic>V</italic>&#x27e9;. The rule scheme expresses also what would be the effect of such an execution upon the agent and upon the network. Thus, the same considerations related to the asynchronous case apply as well, the unique difference being that the <italic>global</italic> semantics defines what actions can be potentially performed by the agents in the network. Since every agent is expected to enable at least one action to not block the synchronous evolution of the network, we assume also the following rule:<disp-formula id="equ8">
<mml:math id="m45">
<mml:mtable class="array">
<mml:mtr>
<mml:mtd columnalign="center">
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>e</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mspace width="2em"/>
<mml:mfrac>
<mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>V</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2192;</mml:mo>
<mml:mspace width="-0.17em"/>
<mml:mspace width="-0.17em"/>
<mml:mspace width="-0.17em"/>
<mml:mspace width="-0.17em"/>
<mml:mspace width="-0.17em"/>
<mml:mspace width="-0.17em"/>
<mml:mspace width="-0.17em"/>
<mml:mspace width="-0.17em"/>
<mml:mspace width="-0.17em"/>
<mml:mspace width="-0.17em"/>
<mml:mspace width="-0.17em"/>
<mml:mspace width="-0.17em"/>
<mml:mspace width="-0.17em"/>
<mml:mspace width="-0.17em"/>
</mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>V</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
</mml:msub>
<mml:mrow>
<mml:mover>
<mml:mrow>
<mml:mo>&#x2192;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:mi>&#x3c4;</mml:mi>
</mml:mrow>
</mml:mrow>
</mml:mover>
</mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>V</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:mfrac>
</mml:mtd>
</mml:mtr>
</mml:mtable>
</mml:math>
</disp-formula>the effect of which is to allow the agent to stay idle without blocking the network.</p>
<p>Then, in the second step, the network semantics must express the simultaneous execution of one action per agent. By assuming <inline-formula id="inf38">
<mml:math id="m46">
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>&#x3d;</mml:mo>
<mml:msubsup>
<mml:mrow>
<mml:mo>&#x22c3;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>&#x3d;</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
<mml:mrow>
<mml:mi>n</mml:mi>
</mml:mrow>
</mml:msubsup>
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>P</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>V</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula>, the semantic rule for the second step is as follows:<disp-formula id="equ9">
<mml:math id="m47">
<mml:mtable class="array">
<mml:mtr>
<mml:mtd columnalign="center">
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>n</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>w</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>k</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mspace width="2em"/>
<mml:mfrac>
<mml:mrow>
<mml:msubsup>
<mml:mrow>
<mml:mo>&#x22c0;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>&#x3d;</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
<mml:mrow>
<mml:mi>n</mml:mi>
</mml:mrow>
</mml:msubsup>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>P</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>V</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
<mml:msub>
<mml:mrow>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
</mml:msub>
<mml:mrow>
<mml:mover>
<mml:mrow>
<mml:mo>&#x2192;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>a</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:mrow>
</mml:mover>
</mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msubsup>
<mml:mrow>
<mml:mi>P</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msubsup>
<mml:mo>,</mml:mo>
<mml:msubsup>
<mml:mrow>
<mml:mi>V</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msubsup>
<mml:msub>
<mml:mrow>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi mathvariant="script">S</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
</mml:msub>
</mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:msubsup>
<mml:mrow>
<mml:mo>&#x22c3;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>&#x3d;</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
<mml:mrow>
<mml:mi>n</mml:mi>
</mml:mrow>
</mml:msubsup>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>P</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>V</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo stretchy="false">&#x232a;</mml:mo>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mo stretchy="false">&#x232a;</mml:mo>
<mml:mrow>
<mml:mover>
<mml:mrow>
<mml:mo>&#x2192;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:mi>&#x3c4;</mml:mi>
</mml:mrow>
</mml:mrow>
</mml:mover>
</mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:msubsup>
<mml:mrow>
<mml:mo>&#x22c3;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>&#x3d;</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
<mml:mrow>
<mml:mi>n</mml:mi>
</mml:mrow>
</mml:msubsup>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msubsup>
<mml:mrow>
<mml:mi>P</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msubsup>
<mml:mo>,</mml:mo>
<mml:msubsup>
<mml:mrow>
<mml:mi>V</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msubsup>
<mml:mo stretchy="false">&#x232a;</mml:mo>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mo>&#x220f;</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
</mml:mfrac>
</mml:mtd>
</mml:mtr>
</mml:mtable>
</mml:math>
</disp-formula>
</p>
<p>In practice, in the premise of the rule each agent (indexed by <italic>i</italic>) offers a transition labeled with <italic>a</italic>
<sub>
<italic>i</italic>
</sub> that derives from the application of the rule scheme <italic>global</italic> or <italic>idle</italic>. Then, the conclusion establishes that all these moves are performed synchronously, as modeled by the <italic>&#x3c4;</italic> action. <xref ref-type="fn" rid="fn3">
<sup>3</sup>
</xref> The proposed scheme is intentionally general. More sophisticated variants of the <italic>network</italic> semantic rule are however possible. For instance, only specific agents (e.g., of selected communities) could be engaged in the synchronization and perform a move. Alternatively, each <italic>a</italic>
<sub>
<italic>i</italic>
</sub> in the premise may be replaced by a unique action <italic>a</italic>, expressing that the involved agents must synchronize on the specific action. Such a condition may be too strong, as some agents may be not available to execute the action <italic>a</italic>, thus blocking all the others. However, similarly as discussed above, it is sufficient to use an ad-hoc version of the <italic>idle</italic> semantic rule that adds the action information as a negative premise on <italic>a</italic> and decorates the <italic>&#x3c4;</italic> action with a subscripted <italic>a</italic>. Then, the <italic>network</italic> semantic rule may enable the synchronization of the involved agents that offer either <italic>a</italic> or <italic>&#x3c4;</italic>
<sub>
<italic>a</italic>
</sub>. These variants emphasize the flexibility and the expressiveness of the approach, which make it adequate to deal with even very specific requirements of various application domains.</p>
<p>In any case, independently from the chosen mode of execution, the semantics of a system <inline-formula id="inf39">
<mml:math id="m48">
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> will be given by the smallest LTS with initial state <inline-formula id="inf40">
<mml:math id="m49">
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> and transitions deriving from the application of the SOS rules at hand. We observe that the proposed rule schemes express a general format that may potentially guide the definition of a library of several, alternative rules. Such rules can be customized to deal with a comprehensive set of behavioral models and application domains. Obviously, a tradeoff exists between such an expressive power and the efficiency issues that may arise when checking complex side conditions in order to build the underlying LTS.</p>
<p>Example 4.</p>
<p>
<italic>Assume a social network</italic> <inline-formula id="inf41">
<mml:math id="m50">
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> <italic>of agents adopting the synchronous mode of execution and including the agent</italic> &#x27e8;<italic>id</italic>, <italic>F</italic>, <italic>V</italic>&#x27e9; <italic>of the previous example. One specific instance of the</italic> <italic>global</italic> <italic>rule scheme, which is related to the execution of action</italic> <italic>a</italic> &#x3d; <italic>nbr</italic>
<italic>, may establish that cautious agents (identified by type 2) accept the news whenever the number of neighbours accepting the news is greater than the agent&#x2019;s threshold. This rule can be formalized easily, first of all by setting the following side conditions:</italic>
<disp-formula id="equ10">
<mml:math id="m51">
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>.</mml:mo>
<mml:mi>t</mml:mi>
<mml:mi>y</mml:mi>
<mml:mi>p</mml:mi>
<mml:mi>e</mml:mi>
<mml:mo>&#x3d;</mml:mo>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:mfenced>
<mml:mspace width="0.17em"/>
<mml:mo>&#x2227;</mml:mo>
<mml:mspace width="0.17em"/>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>.</mml:mo>
<mml:mi>t</mml:mi>
<mml:mi>h</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>s</mml:mi>
<mml:mi>h</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>&#x3c;</mml:mo>
<mml:mspace width="0.28em"/>
<mml:mo stretchy="false">&#x2223;</mml:mo>
<mml:mspace width="-0.17em"/>
<mml:mspace width="-0.17em"/>
<mml:mfenced open="{" close="}">
<mml:mrow>
<mml:msup>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mo stretchy="false">&#x2223;</mml:mo>
<mml:msup>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mo>&#x2260;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>&#x2227;</mml:mo>
<mml:msup>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mo>.</mml:mo>
<mml:mi>a</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>p</mml:mi>
<mml:mi>t</mml:mi>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>t</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>e</mml:mi>
<mml:mo>&#x2227;</mml:mo>
<mml:mo>&#x2203;</mml:mo>
<mml:mi>G</mml:mi>
<mml:mo>.</mml:mo>
<mml:msup>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mo>,</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>G</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mfenced>
<mml:mspace width="-0.17em"/>
<mml:mspace width="-0.17em"/>
<mml:mo stretchy="false">&#x2223;</mml:mo>
</mml:mrow>
</mml:mfenced>
</mml:math>
</disp-formula>
</p>
<p>
<italic>Notice that the neighbours of the agent</italic> <italic>id</italic> <italic>are those agents, different from</italic> <italic>id</italic>
<italic>, belonging to communities of which</italic> <italic>id</italic> <italic>is a member. Then, as a side effect, we would also need to update</italic> <italic>V</italic> <italic>with the mapping</italic> <italic>accept</italic> &#x3d; <italic>true</italic>
<italic>, i.e.,</italic> <italic>V</italic>&#x2032; &#x3d; <italic>V</italic>[<italic>accept</italic>&#x21a6;<italic>true</italic>]<italic>.</italic>
</p>
<p>
<italic>As another use case, assume that</italic> <inline-formula id="inf42">
<mml:math id="m52">
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> <italic>is a trustworthy network including the trustor</italic> &#x27e8;<italic>id</italic>, <italic>T</italic>, <italic>V</italic>&#x27e9; <italic>of the previous example. In such a scenario, let us assume the asynchronous mode of execution. In particular, assume by hypothesis that the action</italic> <italic>snd</italic>_<italic>req</italic> <italic>of the trustor must synchronize with a corresponding action</italic> <italic>rcv</italic>_<italic>req</italic> <italic>of the trustee in the same community of the trustor. Therefore, we need one specific instance of the</italic> <italic>sync</italic> <italic>rule scheme with</italic> <italic>a</italic> &#x3d; <italic>snd</italic>_<italic>req</italic> <italic>and</italic> <italic>b</italic> &#x3d; <italic>rcv</italic>_<italic>req</italic>
<italic>. Then, if the interaction must be enabled only if the trustor trusts the trustee, we would need a side condition as follows:</italic>
<disp-formula id="equ11">
<mml:math id="m53">
<mml:msub>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:msub>
<mml:mo>.</mml:mo>
<mml:mi>&#x3b8;</mml:mi>
<mml:mo>&#x2264;</mml:mo>
<mml:mi>f</mml:mi>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:msub>
<mml:mo>.</mml:mo>
<mml:mi>&#x3b1;</mml:mi>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:msub>
<mml:mo>.</mml:mo>
<mml:mi>&#x3b2;</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:math>
</disp-formula>
<italic>where</italic> <italic>f</italic> <italic>is the specific trust function, like, e.g., the probability expectation of the Beta distribution,</italic> <inline-formula id="inf43">
<mml:math id="m54">
<mml:mfrac>
<mml:mrow>
<mml:mi>&#x3b1;</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>&#x3b1;</mml:mi>
<mml:mo>&#x2b;</mml:mo>
<mml:mi>&#x3b2;</mml:mi>
</mml:mrow>
</mml:mfrac>
</mml:math>
</inline-formula>(<xref ref-type="bibr" rid="B35">J&#xf8;sang and Ismail, 2002</xref>)<italic>. Another instance of such a rule scheme is related to the synchronization involving action</italic> <italic>rec</italic>_<italic>acc</italic>
<italic>, the consequence of which would be the update</italic> <italic>&#x3b1;</italic> &#x3d; <italic>&#x3b1;</italic> &#x2b; 1 <italic>in the local repository of the trustor. We can argue analogously in the case of action</italic> <italic>rec</italic>_<italic>ref</italic> <italic>and the related update involving</italic> <italic>&#x3b2;</italic>
<italic>. Finally, one instance of the rule scheme</italic> <italic>async</italic> <italic>would be associated to the execution of action</italic> <italic>leave</italic>_<italic>com</italic>
<italic>. If the agent is expected to leave the community whenever the trustee is not trusted anymore, then a side condition of such a rule would be the predicate</italic> <italic>id</italic>
<italic>&#x3b8;</italic> &#x3e; <italic>f</italic>(<italic>id</italic>.<italic>&#x3b1;</italic>, <italic>id</italic>. <italic>&#x3b2;</italic>)<italic>. Moreover, two side effects would be given by the corresponding update of the community</italic> <inline-formula id="inf44">
<mml:math id="m55">
<mml:mi mathvariant="script">G</mml:mi>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>G</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> <italic>to which the agent belongs and, possibly, the updates</italic> <italic>&#x3b1;</italic> &#x3d; <italic>&#x3b2;</italic> &#x3d; 0<italic>.</italic>
</p>
</sec>
</sec>
<sec id="s3">
<title>3 Model Checking Temporal Properties</title>
<p>The verification of the properties of networks of agents is conducted through model checking (<xref ref-type="bibr" rid="B20">Clarke et al., 1999</xref>). Therefore, we need to define a sufficiently expressive and intuitive logic to reason about the various levels of information that our framework can express. To this aim, in this section we present a temporal logic for the specification of properties of networks, which is an instance of action/state-based logics &#xe0; la CTL (<xref ref-type="bibr" rid="B42">De Nicola and Vaandrager, 1990</xref>; <xref ref-type="bibr" rid="B49">ter Beek et al., 2008</xref>). The logic is rather standard and its main novelties are concerned with the treatment of the atomic formulas, in a way that recalls and favors the agent/community perspective of the modeling language.</p>
<p>The set of formulas <inline-formula id="inf45">
<mml:math id="m56">
<mml:mi mathvariant="script">N</mml:mi>
</mml:math>
</inline-formula> of the network logic we propose is generated through the following syntax:<disp-formula id="equ12">
<mml:math id="m57">
<mml:mtable class="array">
<mml:mtr>
<mml:mtd columnalign="left">
<mml:mi mathvariant="normal">&#x3a6;</mml:mi>
<mml:mspace width="0.28em"/>
<mml:mo>&#x2a74;</mml:mo>
<mml:mspace width="0.28em"/>
<mml:mi>t</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>e</mml:mi>
<mml:mo stretchy="false">&#x2223;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>.</mml:mo>
<mml:mi>a</mml:mi>
<mml:mo stretchy="false">&#x2223;</mml:mo>
<mml:mi>z</mml:mi>
<mml:mo>&#x22c8;</mml:mo>
<mml:mi>r</mml:mi>
<mml:mo stretchy="false">&#x2223;</mml:mo>
<mml:mi mathvariant="normal">&#x3a6;</mml:mi>
<mml:mo>&#x2227;</mml:mo>
<mml:mi mathvariant="normal">&#x3a6;</mml:mi>
<mml:mo stretchy="false">&#x2223;</mml:mo>
<mml:mo>&#xac;</mml:mo>
<mml:mi mathvariant="normal">&#x3a6;</mml:mi>
<mml:mo stretchy="false">&#x2223;</mml:mo>
<mml:mi>A</mml:mi>
<mml:mi>&#x3c0;</mml:mi>
<mml:mo stretchy="false">&#x2223;</mml:mo>
<mml:mi>E</mml:mi>
<mml:mi>&#x3c0;</mml:mi>
</mml:mtd>
</mml:mtr>
<mml:mtr>
<mml:mtd columnalign="left">
<mml:mi>&#x3c0;</mml:mi>
<mml:mspace width="0.28em"/>
<mml:mo>&#x2a74;</mml:mo>
<mml:mspace width="0.28em"/>
<mml:mi mathvariant="normal">&#x3a6;</mml:mi>
<mml:mspace width="0.17em"/>
<mml:mspace width="0.17em"/>
<mml:mi>U</mml:mi>
<mml:mspace width="0.17em"/>
<mml:mi mathvariant="normal">&#x3a6;</mml:mi>
<mml:mo stretchy="false">&#x2223;</mml:mo>
<mml:mi mathvariant="normal">&#x3a6;</mml:mi>
<mml:mspace width="0.17em"/>
<mml:msup>
<mml:mrow>
<mml:mi>U</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2264;</mml:mo>
<mml:mi>k</mml:mi>
</mml:mrow>
</mml:msup>
<mml:mi mathvariant="normal">&#x3a6;</mml:mi>
</mml:mtd>
</mml:mtr>
</mml:mtable>
</mml:math>
</disp-formula>where:<list list-type="simple">
<list-item>
<p>&#x2022; <inline-formula id="inf46">
<mml:math id="m58">
<mml:mi>r</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="double-struck">R</mml:mi>
</mml:math>
</inline-formula>, <inline-formula id="inf47">
<mml:math id="m59">
<mml:mi>k</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="double-struck">N</mml:mi>
</mml:math>
</inline-formula>, and &#x22c8; is any arithmetic comparison operator;</p>
</list-item>
<list-item>
<p>&#x2022; <italic>id</italic>. <italic>a</italic> is the action-based atomic formula, and is satisfied by any state enabling the execution of action <italic>a</italic> &#x2208; <italic>Act</italic> by agent <italic>id</italic>;</p>
</list-item>
<list-item>
<p>&#x2022; <italic>z</italic>&#x22c8;<italic>r</italic> is the state-based atomic formula, and is satisfied by any state in which the evaluation of variable <italic>z</italic> satisfies the condition &#x22c8;<italic>r</italic>;</p>
</list-item>
<list-item>
<p>&#x2022; <italic>A&#x3c0;</italic> and <italic>E&#x3c0;</italic> express the classical universally and existentially quantified path formulas;</p>
</list-item>
<list-item>
<p>&#x2022; the two flavours of the <italic>until</italic> operator represent the unique type of path formulas; basically a path satisfies &#x3a6;<sub>1</sub> <italic>U</italic> &#x3a6;<sub>2</sub> if it begins with a finite sequence of states satisfying &#x3a6;<sub>1</sub> followed by a state satisfying &#x3a6;<sub>2</sub> (the <italic>k</italic>-bounded version adds a requirement on the length of such a finite sequence).</p>
</list-item>
</list>
</p>
<p>As mentioned above, the main peculiarities of the logic are given by the atomic formulas, while the composite formulas are standard. The atomic formulas are action-based (<italic>id</italic>.<italic>a</italic>), denoting the execution of an action <italic>a</italic> by the agent <italic>id</italic>, and state-based (<italic>z</italic>&#x22c8;<italic>r</italic>), denoting that the state variable <italic>z</italic> satisfies a certain condition parameterized by <italic>r</italic>.</p>
<p>As far as the semantics of the action-based formula <italic>id</italic>. <italic>a</italic> is concerned, we have to distinguish between the two modes of execution. In the asynchronous setting, <italic>id</italic>. <italic>a</italic> holds in <inline-formula id="inf48">
<mml:math id="m60">
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula>, denoted by <inline-formula id="inf49">
<mml:math id="m61">
<mml:msub>
<mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
<mml:mo>&#x22a7;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi mathvariant="script">N</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>.</mml:mo>
<mml:mi>a</mml:mi>
</mml:math>
</inline-formula>, if either agent <inline-formula id="inf50">
<mml:math id="m62">
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>V</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="script">S</mml:mi>
</mml:math>
</inline-formula> can execute action <italic>a</italic> in <inline-formula id="inf51">
<mml:math id="m63">
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> by virtue of a semantic rule of scheme <italic>async</italic>, or agent <inline-formula id="inf52">
<mml:math id="m64">
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>V</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="script">S</mml:mi>
</mml:math>
</inline-formula> contributes, by offering action <italic>a</italic>, to the execution of a synchronized action <italic>a</italic> &#xd7; <italic>b</italic> in <inline-formula id="inf53">
<mml:math id="m65">
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> by virtue of a semantic rule of scheme <italic>sync</italic>. In the synchronous setting, <italic>id</italic>. <italic>a</italic> holds in <inline-formula id="inf54">
<mml:math id="m66">
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> if agent <inline-formula id="inf55">
<mml:math id="m67">
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>V</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="script">S</mml:mi>
</mml:math>
</inline-formula> contributes, by executing action <italic>a</italic> locally, to the execution of the global, synchronous action <italic>&#x3c4;</italic> enabled in <inline-formula id="inf56">
<mml:math id="m68">
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> by virtue of the semantic rule <italic>network</italic>.</p>
<p>As far as the semantics of the state-based formula <italic>z</italic>&#x22c8;<italic>r</italic> is concerned, we point out that, in our framework, any state of the LTS modeling a network is labeled with different types of information: the identities of the agents forming the system communities, their local repositories, and the global repositories. Hence, in order to allow for the definition of any kind of state-based requirement, we admit <italic>z</italic> to represent combinations of different types of values filtered in a certain way. To this aim, we distinguish the following three cases.</p>
<p>The first case refers to the state-based formulas over global variables. In this case, let <italic>z</italic>&#x2254;<italic>f</italic>{<italic>w</italic> &#x7c; <italic>&#x3d5;</italic>
<sub>
<italic>g</italic>
</sub>}, such that <italic>f</italic> is a scalar function, <italic>w</italic> &#x2208; <italic>WNames</italic>, and <italic>&#x3d5;</italic>
<sub>
<italic>g</italic>
</sub> is a logic formula filtering communities. The intuition is that the values of the global variable <italic>w</italic> taken from those communities that satisfy <italic>&#x3d5;</italic>
<sub>
<italic>g</italic>
</sub> are combined through <italic>f</italic> to obtain the result <italic>z</italic>. The logic formula <italic>&#x3d5;</italic>
<sub>
<italic>g</italic>
</sub> obeys the following syntax:<disp-formula id="equ13">
<mml:math id="m69">
<mml:msub>
<mml:mrow>
<mml:mi>&#x3d5;</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>g</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mspace width="0.28em"/>
<mml:mo>&#x2a74;</mml:mo>
<mml:mspace width="0.28em"/>
<mml:mi>t</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>e</mml:mi>
<mml:mo stretchy="false">&#x2223;</mml:mo>
<mml:mi>c</mml:mi>
<mml:mo>&#x22c8;</mml:mo>
<mml:mi>k</mml:mi>
<mml:mo stretchy="false">&#x2223;</mml:mo>
<mml:mi>w</mml:mi>
<mml:mo>&#x22c8;</mml:mo>
<mml:mi>r</mml:mi>
<mml:mo stretchy="false">&#x2223;</mml:mo>
<mml:mo>&#xac;</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>&#x3d5;</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>g</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo stretchy="false">&#x2223;</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>&#x3d5;</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>g</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2227;</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>&#x3d5;</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>g</mml:mi>
</mml:mrow>
</mml:msub>
</mml:math>
</disp-formula>where <inline-formula id="inf57">
<mml:math id="m70">
<mml:mi>k</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="double-struck">N</mml:mi>
</mml:math>
</inline-formula>, <italic>w</italic> &#x2208; <italic>WNames</italic>, and <inline-formula id="inf58">
<mml:math id="m71">
<mml:mi>r</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="double-struck">R</mml:mi>
</mml:math>
</inline-formula>. A formula <italic>&#x3d5;</italic>
<sub>
<italic>g</italic>
</sub> is a Boolean predicate used to select communities based on conditions over their identity (<italic>c</italic>&#x22c8;<italic>k</italic>, where <italic>c</italic> stands for community)<xref ref-type="fn" rid="fn4">
<sup>4</sup>
</xref>, conditions over the value of their global variables (<italic>w</italic>&#x22c8;<italic>r</italic>), and logical combinations of such atomic conditions. Semantically, the evaluation of <italic>z</italic>&#x2254;<italic>f</italic>{<italic>w</italic> &#x7c; <italic>&#x3d5;</italic>
<sub>
<italic>g</italic>
</sub>} in a network state <inline-formula id="inf59">
<mml:math id="m72">
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> is given by:<disp-formula id="e1">
<mml:math id="m73">
<mml:mi>f</mml:mi>
<mml:mfenced open="{" close="}">
<mml:mrow>
<mml:mspace width="-0.17em"/>
<mml:mo stretchy="false">&#x7c;</mml:mo>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>G</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mfenced>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>w</mml:mi>
</mml:mrow>
</mml:mfenced>
<mml:mspace width="0.17em"/>
<mml:mo stretchy="false">&#x7c;</mml:mo>
<mml:mspace width="0.17em"/>
<mml:mi>G</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi>C</mml:mi>
<mml:mi>N</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>m</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>s</mml:mi>
<mml:mspace width="0.3333em"/>
<mml:mo>&#x2227;</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>G</mml:mi>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#x22a7;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi>g</mml:mi>
</mml:mrow>
</mml:msub>
<mml:msub>
<mml:mrow>
<mml:mi>&#x3d5;</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>g</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo stretchy="false">&#x7c;</mml:mo>
<mml:mspace width="-0.17em"/>
</mml:mrow>
</mml:mfenced>
</mml:math>
<label>(1)</label>
</disp-formula>where <italic>f</italic> works on values of a multiset and the satisfiability relation &#x22a7;<sub>
<italic>g</italic>
</sub> for the atomic formulas generated by <italic>&#x3d5;</italic>
<sub>
<italic>g</italic>
</sub> is defined as follows (the case of the composite formulas is standard):<disp-formula id="equ14">
<mml:math id="m74">
<mml:mtable class="array">
<mml:mtr>
<mml:mtd columnalign="left">
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>G</mml:mi>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#x22a7;</mml:mo>
<mml:mi>t</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>e</mml:mi>
</mml:mtd>
<mml:mtd columnalign="left">
<mml:mi>h</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>d</mml:mi>
<mml:mi>s</mml:mi>
<mml:mspace width="0.3333em"/>
<mml:mi>a</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>w</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>y</mml:mi>
<mml:mi>s</mml:mi>
</mml:mtd>
</mml:mtr>
<mml:mtr>
<mml:mtd columnalign="left">
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>G</mml:mi>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#x22a7;</mml:mo>
<mml:mi>c</mml:mi>
<mml:mo>&#x22c8;</mml:mo>
<mml:mi>k</mml:mi>
</mml:mtd>
<mml:mtd columnalign="left">
<mml:mspace width="0.28em"/>
<mml:mi>iff</mml:mi>
<mml:mspace width="0.28em"/>
<mml:mspace width="0.3333em"/>
<mml:mi>G</mml:mi>
<mml:mo>&#x22c8;</mml:mo>
<mml:mi>k</mml:mi>
</mml:mtd>
</mml:mtr>
<mml:mtr>
<mml:mtd columnalign="left">
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>G</mml:mi>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#x22a7;</mml:mo>
<mml:mi>w</mml:mi>
<mml:mo>&#x22c8;</mml:mo>
<mml:mi>r</mml:mi>
</mml:mtd>
<mml:mtd columnalign="left">
<mml:mspace width="0.28em"/>
<mml:mi>iff</mml:mi>
<mml:mspace width="0.28em"/>
<mml:mspace width="0.3333em"/>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>G</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mfenced>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>w</mml:mi>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#x22c8;</mml:mo>
<mml:mi>r</mml:mi>
</mml:mtd>
</mml:mtr>
</mml:mtable>
</mml:math>
</disp-formula>If the evaluation of <italic>z</italic>&#x2254;<italic>f</italic>{<italic>w</italic> &#x7c; <italic>&#x3d5;</italic>
<sub>
<italic>g</italic>
</sub>} satisfies the condition &#x22c8;<italic>r</italic>, then we have that <italic>z</italic>&#x22c8;<italic>r</italic> holds in <inline-formula id="inf60">
<mml:math id="m75">
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula>, denoted by <inline-formula id="inf61">
<mml:math id="m76">
<mml:msub>
<mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
<mml:mo>&#x22a7;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi mathvariant="script">N</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mi>z</mml:mi>
<mml:mo>&#x22c8;</mml:mo>
<mml:mi>r</mml:mi>
</mml:math>
</inline-formula>. Summarizing, <italic>f</italic> combines the values of the global variable <italic>w</italic> extracted from those communities that satisfy the community predicate <italic>&#x3d5;</italic>
<sub>
<italic>g</italic>
</sub>; then the resulting value is compared to <italic>r</italic>.</p>
<p>The second case refers to the state-based formulas over local variables. In this case, let <italic>z</italic>&#x2254;<italic>f</italic>{<italic>v</italic> &#x7c; <italic>&#x3d5;</italic>
<sub>
<italic>l</italic>
</sub>}, such that <italic>f</italic> is a scalar function, <italic>v</italic> &#x2208; <italic>VNames</italic>, and <italic>&#x3d5;</italic>
<sub>
<italic>l</italic>
</sub> is a logic formula filtering agents. The intuition is that the values of the local variable <italic>v</italic> taken from those agents that satisfy <italic>&#x3d5;</italic>
<sub>
<italic>l</italic>
</sub> are combined through <italic>f</italic> to obtain the result <italic>z</italic>. The logic formula <italic>&#x3d5;</italic>
<sub>
<italic>l</italic>
</sub> obeys the following syntax:<disp-formula id="equ15">
<mml:math id="m77">
<mml:msub>
<mml:mrow>
<mml:mi>&#x3d5;</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>l</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mspace width="0.28em"/>
<mml:mo>&#x2a74;</mml:mo>
<mml:mspace width="0.28em"/>
<mml:mi>t</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>e</mml:mi>
<mml:mo stretchy="false">&#x2223;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mi>e</mml:mi>
<mml:mo>&#x22c8;</mml:mo>
<mml:mi>k</mml:mi>
<mml:mo stretchy="false">&#x2223;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mi>e</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi>G</mml:mi>
<mml:mo stretchy="false">&#x2223;</mml:mo>
<mml:mi>v</mml:mi>
<mml:mo>&#x22c8;</mml:mo>
<mml:mi>r</mml:mi>
<mml:mo stretchy="false">&#x2223;</mml:mo>
<mml:mi>v</mml:mi>
<mml:mo>&#x22c8;</mml:mo>
<mml:mi>z</mml:mi>
<mml:mo stretchy="false">&#x2223;</mml:mo>
<mml:mo>&#xac;</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>&#x3d5;</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>l</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo stretchy="false">&#x2223;</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>&#x3d5;</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>l</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2227;</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>&#x3d5;</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>l</mml:mi>
</mml:mrow>
</mml:msub>
</mml:math>
</disp-formula>where <inline-formula id="inf62">
<mml:math id="m78">
<mml:mi>k</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="double-struck">N</mml:mi>
</mml:math>
</inline-formula>, <italic>G</italic> &#x2208; <italic>CNames</italic>, <italic>v</italic> &#x2208; <italic>VNames</italic>, <inline-formula id="inf63">
<mml:math id="m79">
<mml:mi>r</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="double-struck">R</mml:mi>
</mml:math>
</inline-formula>, and <italic>z</italic>&#x2254;<italic>f</italic>{<italic>w</italic> &#x7c; <italic>&#x3d5;</italic>
<sub>
<italic>g</italic>
</sub>} is any combination of global variables as previously defined. A formula <italic>&#x3d5;</italic>
<sub>
<italic>l</italic>
</sub> is a Boolean predicate used to select agents based on their identity (<italic>ide</italic>&#x22c8;<italic>k</italic>)<xref ref-type="fn" rid="fn5">
<sup>5</sup>
</xref>, community membership (<italic>ide</italic> &#x2208; <italic>G</italic>), evaluation of their local variables compared to constant values (<italic>v</italic>&#x22c8;<italic>r</italic>) or combinations of global variables (<italic>v</italic>&#x22c8;<italic>z</italic>), and logical combinations of such atomic conditions. Semantically, the evaluation of <italic>z</italic>&#x2254;<italic>f</italic>{<italic>v</italic> &#x7c; <italic>&#x3d5;</italic>
<sub>
<italic>l</italic>
</sub>} in a network state <inline-formula id="inf64">
<mml:math id="m80">
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> is given by:<disp-formula id="e2">
<mml:math id="m81">
<mml:mi>f</mml:mi>
<mml:mfenced open="{" close="}">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mspace width="-0.17em"/>
<mml:mo stretchy="false">&#x7c;</mml:mo>
<mml:mi>V</mml:mi>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>v</mml:mi>
</mml:mrow>
</mml:mfenced>
<mml:mspace width="0.17em"/>
<mml:mo stretchy="false">&#x7c;</mml:mo>
<mml:mspace width="0.17em"/>
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>V</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>&#x2227;</mml:mo>
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>V</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:mrow>
</mml:msub>
<mml:msub>
<mml:mrow>
<mml:mo>&#x22a7;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi>l</mml:mi>
</mml:mrow>
</mml:msub>
<mml:msub>
<mml:mrow>
<mml:mi>&#x3d5;</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>l</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo stretchy="false">&#x7c;</mml:mo>
<mml:mspace width="-0.17em"/>
</mml:mrow>
</mml:mfenced>
</mml:math>
<label>(2)</label>
</disp-formula>
</p>
<p>The satisfiability relation &#x22a7;<sub>
<italic>l</italic>
</sub> for the atomic formulas generated by <italic>&#x3d5;</italic>
<sub>
<italic>l</italic>
</sub> is defined as follows (the case of the composite formulas is standard):<disp-formula id="equ16">
<mml:math id="m82">
<mml:mtable class="array">
<mml:mtr>
<mml:mtd columnalign="left">
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>V</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
</mml:msub>
<mml:mo>&#x22a7;</mml:mo>
<mml:mi>t</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>e</mml:mi>
</mml:mtd>
<mml:mtd columnalign="left">
<mml:mi>h</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>d</mml:mi>
<mml:mi>s</mml:mi>
<mml:mspace width="0.3333em"/>
<mml:mi>a</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>w</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>y</mml:mi>
<mml:mi>s</mml:mi>
</mml:mtd>
</mml:mtr>
<mml:mtr>
<mml:mtd columnalign="left">
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>V</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
</mml:msub>
<mml:mo>&#x22a7;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mi>e</mml:mi>
<mml:mo>&#x22c8;</mml:mo>
<mml:mi>k</mml:mi>
</mml:mtd>
<mml:mtd columnalign="left">
<mml:mspace width="0.28em"/>
<mml:mi>iff</mml:mi>
<mml:mspace width="0.28em"/>
<mml:mspace width="0.3333em"/>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>&#x22c8;</mml:mo>
<mml:mi>k</mml:mi>
</mml:mtd>
</mml:mtr>
<mml:mtr>
<mml:mtd columnalign="left">
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>V</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
</mml:msub>
<mml:mo>&#x22a7;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mi>e</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi>G</mml:mi>
</mml:mtd>
<mml:mtd columnalign="left">
<mml:mspace width="0.28em"/>
<mml:mi>iff</mml:mi>
<mml:mspace width="0.28em"/>
<mml:mspace width="0.3333em"/>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>G</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mtd>
</mml:mtr>
<mml:mtr>
<mml:mtd columnalign="left">
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>V</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
</mml:msub>
<mml:mo>&#x22a7;</mml:mo>
<mml:mi>v</mml:mi>
<mml:mo>&#x22c8;</mml:mo>
<mml:mi>r</mml:mi>
</mml:mtd>
<mml:mtd columnalign="left">
<mml:mspace width="0.28em"/>
<mml:mi>iff</mml:mi>
<mml:mspace width="0.28em"/>
<mml:mspace width="0.3333em"/>
<mml:mi>V</mml:mi>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>v</mml:mi>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#x22c8;</mml:mo>
<mml:mi>r</mml:mi>
</mml:mtd>
</mml:mtr>
<mml:mtr>
<mml:mtd columnalign="left">
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>V</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">&#x2329;</mml:mo>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mo stretchy="false">&#x232a;</mml:mo>
</mml:mrow>
</mml:msub>
<mml:mo>&#x22a7;</mml:mo>
<mml:mi>v</mml:mi>
<mml:mo>&#x22c8;</mml:mo>
<mml:mi>z</mml:mi>
</mml:mtd>
<mml:mtd columnalign="left">
<mml:mspace width="0.28em"/>
<mml:mi>iff</mml:mi>
<mml:mspace width="0.28em"/>
<mml:mspace width="0.3333em"/>
<mml:mi>V</mml:mi>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>v</mml:mi>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#x22c8;</mml:mo>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:mfenced>
</mml:mtd>
</mml:mtr>
</mml:mtable>
</mml:math>
</disp-formula>
</p>
<p>Notice that, for the semantics of <italic>v</italic>&#x22c8;<italic>z</italic>, with <italic>z</italic>&#x2254;<italic>f</italic>{<italic>w</italic> &#x7c; <italic>&#x3d5;</italic>
<sub>
<italic>g</italic>
</sub>}, the evaluation of <italic>v</italic> in <inline-formula id="inf65">
<mml:math id="m83">
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> is compared to the evaluation of <italic>z</italic> in the same state, which is computed as stated by <xref ref-type="disp-formula" rid="e1">Eq. 1</xref>. Then, as in the first case, if the evaluation of <italic>z</italic>&#x2254;<italic>f</italic>{<italic>v</italic> &#x7c; <italic>&#x3d5;</italic>
<sub>
<italic>l</italic>
</sub>} in <inline-formula id="inf66">
<mml:math id="m84">
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> satisfies the condition &#x22c8;<italic>r</italic>, we have that <italic>z</italic>&#x22c8;<italic>r</italic> holds in <inline-formula id="inf67">
<mml:math id="m85">
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula>. Summarizing, <italic>f</italic> combines the values of the local variable <italic>v</italic> extracted from those agents that satisfy the local predicate <italic>&#x3d5;</italic>
<sub>
<italic>l</italic>
</sub>; then the resulting value is compared to <italic>r</italic>.</p>
<p>The third case is similar to the previous one and refers to the state-based formulas over identities. In this case, let <italic>z</italic>&#x2254;<italic>f</italic>{<italic>ide</italic> &#x7c; <italic>&#x3d5;</italic>
<sub>
<italic>l</italic>
</sub>}. The intuition is that the values of the identities of those agents that satisfy <italic>&#x3d5;</italic>
<sub>
<italic>l</italic>
</sub> are combined through <italic>f</italic> to obtain the result <italic>z</italic>. Similarly as in the case of <xref ref-type="disp-formula" rid="e2">Eq. 2</xref>, the evaluation of <italic>f</italic>{<italic>ide</italic> &#x7c; <italic>&#x3d5;</italic>
<sub>
<italic>l</italic>
</sub>} in a network state <inline-formula id="inf68">
<mml:math id="m86">
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> is given as follows:<disp-formula id="e3">
<mml:math id="m87">
<mml:mi>f</mml:mi>
<mml:mfenced open="{" close="}">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mspace width="0.17em"/>
<mml:mo stretchy="false">&#x7c;</mml:mo>
<mml:mspace width="0.17em"/>
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>V</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>&#x2227;</mml:mo>
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>V</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:mrow>
</mml:msub>
<mml:msub>
<mml:mrow>
<mml:mo>&#x22a7;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi>l</mml:mi>
</mml:mrow>
</mml:msub>
<mml:msub>
<mml:mrow>
<mml:mi>&#x3d5;</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>l</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:math>
<label>(3)</label>
</disp-formula>
</p>
<p>Notice that <italic>f</italic> applies to identities, which, by their uniqueness, do not form multisets.</p>
<p>Now the semantics for the atomic formulas of <inline-formula id="inf69">
<mml:math id="m88">
<mml:mi mathvariant="script">N</mml:mi>
</mml:math>
</inline-formula> is clarified. Hence, we are ready to define the satisfiability relation, denoted by <inline-formula id="inf70">
<mml:math id="m89">
<mml:msub>
<mml:mrow>
<mml:mo>&#x22a7;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi mathvariant="script">N</mml:mi>
</mml:mrow>
</mml:msub>
</mml:math>
</inline-formula>, for the non-atomic operators of the network logic. For this purpose, given a LTS (<italic>Q</italic>, <italic>q</italic>
<sub>0</sub>, <italic>L</italic>, <italic>R</italic>) we need to define the notion of a path. A path <italic>&#x3c3;</italic> is a (possibly infinite) sequence of transitions of the form:<disp-formula id="equ17">
<mml:math id="m90">
<mml:mi>&#x3c3;</mml:mi>
<mml:mo>&#x2254;</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>q</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mn>0</mml:mn>
</mml:mrow>
</mml:msub>
<mml:mrow>
<mml:mover>
<mml:mrow>
<mml:mo>&#x2192;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>a</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mn>0</mml:mn>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:mrow>
</mml:mover>
</mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>q</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2026;</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>q</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>j</mml:mi>
<mml:mo>&#x2212;</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:msub>
<mml:mrow>
<mml:mover>
<mml:mrow>
<mml:mo>&#x2192;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>a</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>j</mml:mi>
<mml:mo>&#x2212;</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:mrow>
</mml:mover>
</mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>q</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>j</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2026;</mml:mo>
</mml:math>
</disp-formula>where <inline-formula id="inf71">
<mml:math id="m91">
<mml:msub>
<mml:mrow>
<mml:mi>q</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>j</mml:mi>
<mml:mo>&#x2212;</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:msub>
<mml:mrow>
<mml:mover>
<mml:mrow>
<mml:mo>&#x2192;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>a</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>j</mml:mi>
<mml:mo>&#x2212;</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:mrow>
</mml:mover>
</mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>q</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>j</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2208;</mml:mo>
<mml:mi>R</mml:mi>
</mml:math>
</inline-formula> for each <italic>j</italic> &#x3e; 0. Every state <italic>q</italic>
<sub>
<italic>j</italic>
</sub> in the path is denoted by <italic>&#x3c3;</italic>(<italic>j</italic>). Moreover, we denote with <italic>Path</italic>(<italic>q</italic>) the set of paths starting in state <italic>q</italic> &#x2208; <italic>Q</italic>. The notion of path is needed to formalize the quantified path operators. In particular, the semantics of formula &#x3a6; <italic>U</italic> &#x3a6;&#x2032; states that a path satisfies the formula if it reaches a state that satisfies &#x3a6;&#x2032;, while satisfying &#x3a6; in each intermediate state; note that the path could be empty if its initial state satisfies &#x3a6;&#x2032;. As far as the <italic>k</italic>-bounded version of <italic>U</italic> is concerned, an additional condition must be applied, which expresses that the length of the prefix of the path terminating in the state satisfying &#x3a6;&#x2032; must be <inline-formula id="inf72">
<mml:math id="m92">
<mml:mo>&#x2264;</mml:mo>
<mml:mi>k</mml:mi>
</mml:math>
</inline-formula>. The formal semantics of the composite operators of our network logic is presented in <xref ref-type="table" rid="T2">Table 2</xref>.</p>
<table-wrap id="T2" position="float">
<label>TABLE 2</label>
<caption>
<p>Satisfiability relation of the network logic.</p>
</caption>
<table>
<thead valign="top">
<tr>
<th align="left">
<inline-formula id="inf73">
<mml:math id="m93">
<mml:msub>
<mml:mrow>
<mml:mi mathvariant="italic">q</mml:mi>
<mml:mo>&#x22a7;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi mathvariant="script">N</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mi mathvariant="normal">&#x3a6;</mml:mi>
<mml:mo>&#x2227;</mml:mo>
<mml:msup>
<mml:mrow>
<mml:mi mathvariant="normal">&#x3a6;</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
</mml:math>
</inline-formula>
</th>
<th align="center">
<inline-formula id="inf74">
<mml:math id="m94">
<mml:mi mathvariant="italic">i</mml:mi>
<mml:mi mathvariant="italic">f</mml:mi>
<mml:mi mathvariant="italic">f</mml:mi>
<mml:mspace width="0.3333em"/>
<mml:msub>
<mml:mrow>
<mml:mi>q</mml:mi>
<mml:mo>&#x22a7;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi mathvariant="script">N</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mi mathvariant="normal">&#x3a6;</mml:mi>
<mml:mspace width="0.3333em"/>
<mml:mi>a</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>d</mml:mi>
<mml:mspace width="0.3333em"/>
<mml:msub>
<mml:mrow>
<mml:mi>q</mml:mi>
<mml:mo>&#x22a7;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi mathvariant="script">N</mml:mi>
</mml:mrow>
</mml:msub>
<mml:msup>
<mml:mrow>
<mml:mi mathvariant="normal">&#x3a6;</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
</mml:math>
</inline-formula>
</th>
</tr>
</thead>
<tbody valign="top">
<tr>
<td align="left">
<inline-formula id="inf75">
<mml:math id="m95">
<mml:msub>
<mml:mrow>
<mml:mi>q</mml:mi>
<mml:mo>&#x22a7;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi mathvariant="script">N</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#xac;</mml:mo>
<mml:mi mathvariant="normal">&#x3a6;</mml:mi>
</mml:math>
</inline-formula>
</td>
<td align="left">
<inline-formula id="inf76">
<mml:math id="m96">
<mml:mi>i</mml:mi>
<mml:mi>f</mml:mi>
<mml:mi>f</mml:mi>
<mml:mspace width="0.3333em"/>
<mml:mi>q</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mo>&#x22ad;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi mathvariant="script">N</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mi mathvariant="normal">&#x3a6;</mml:mi>
</mml:math>
</inline-formula>
</td>
</tr>
<tr>
<td align="left">
<inline-formula id="inf77">
<mml:math id="m97">
<mml:msub>
<mml:mrow>
<mml:mi>q</mml:mi>
<mml:mo>&#x22a7;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi mathvariant="script">N</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mi>A</mml:mi>
<mml:mi>&#x3c0;</mml:mi>
</mml:math>
</inline-formula>
</td>
<td align="left">
<inline-formula id="inf78">
<mml:math id="m98">
<mml:mi>i</mml:mi>
<mml:mi>f</mml:mi>
<mml:mi>f</mml:mi>
<mml:mspace width="0.3333em"/>
<mml:mo>&#x2200;</mml:mo>
<mml:mi>&#x3c3;</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi>P</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>h</mml:mi>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>q</mml:mi>
</mml:mrow>
</mml:mfenced>
<mml:mo>:</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>&#x3c3;</mml:mi>
<mml:mo>&#x22a7;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi mathvariant="script">N</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mi>&#x3c0;</mml:mi>
</mml:math>
</inline-formula>
</td>
</tr>
<tr>
<td align="left">
<inline-formula id="inf79">
<mml:math id="m99">
<mml:msub>
<mml:mrow>
<mml:mi>q</mml:mi>
<mml:mo>&#x22a7;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi mathvariant="script">N</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mi>E</mml:mi>
<mml:mi>&#x3c0;</mml:mi>
</mml:math>
</inline-formula>
</td>
<td align="left">
<inline-formula id="inf80">
<mml:math id="m100">
<mml:mi>i</mml:mi>
<mml:mi>f</mml:mi>
<mml:mi>f</mml:mi>
<mml:mspace width="0.3333em"/>
<mml:mo>&#x2203;</mml:mo>
<mml:mi>&#x3c3;</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi>P</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>h</mml:mi>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>q</mml:mi>
</mml:mrow>
</mml:mfenced>
<mml:mo>:</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi>&#x3c3;</mml:mi>
<mml:mo>&#x22a7;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi mathvariant="script">N</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mi>&#x3c0;</mml:mi>
</mml:math>
</inline-formula>
</td>
</tr>
<tr>
<td align="left">
<inline-formula id="inf81">
<mml:math id="m101">
<mml:msub>
<mml:mrow>
<mml:mi>&#x3c3;</mml:mi>
<mml:mo>&#x22a7;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi mathvariant="script">N</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mi mathvariant="normal">&#x3a6;</mml:mi>
<mml:mspace width="0.17em"/>
<mml:mi>U</mml:mi>
<mml:mspace width="0.17em"/>
<mml:msup>
<mml:mrow>
<mml:mi mathvariant="normal">&#x3a6;</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
</mml:math>
</inline-formula>
</td>
<td align="left">
<italic>iff &#x2203; i</italic> &#x2265; 0</td>
</tr>
<tr>
<td align="left"/>
<td align="left">
<inline-formula id="inf82">
<mml:math id="m102">
<mml:mi>&#x3c3;</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#x22a7;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi mathvariant="script">N</mml:mi>
</mml:mrow>
</mml:msub>
<mml:msup>
<mml:mrow>
<mml:mi mathvariant="normal">&#x3a6;</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mo>&#x2227;</mml:mo>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>f</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>r</mml:mi>
<mml:mspace width="0.3333em"/>
<mml:mi>a</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>l</mml:mi>
<mml:mspace width="0.3333em"/>
<mml:mn>0</mml:mn>
<mml:mo>&#x2264;</mml:mo>
<mml:mi>j</mml:mi>
<mml:mo>&#x3c;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mo>:</mml:mo>
<mml:mi>&#x3c3;</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>j</mml:mi>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#x22a7;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi mathvariant="script">N</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mi mathvariant="normal">&#x3a6;</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:math>
</inline-formula>
</td>
</tr>
<tr>
<td align="left">
<inline-formula id="inf83">
<mml:math id="m103">
<mml:msub>
<mml:mrow>
<mml:mi>&#x3c3;</mml:mi>
<mml:mo>&#x22a7;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi mathvariant="script">N</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mi mathvariant="normal">&#x3a6;</mml:mi>
<mml:mspace width="0.17em"/>
<mml:msup>
<mml:mrow>
<mml:mi>U</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2264;</mml:mo>
<mml:mi>k</mml:mi>
</mml:mrow>
</mml:msup>
<mml:mspace width="0.17em"/>
<mml:msup>
<mml:mrow>
<mml:mi mathvariant="normal">&#x3a6;</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
</mml:math>
</inline-formula>
</td>
<td align="left">
<italic>iff &#x2203;</italic> 0 &#x2264; <italic>i</italic> &#x2264; <italic>k</italic>
</td>
</tr>
<tr>
<td align="left"/>
<td align="left">
<inline-formula id="inf84">
<mml:math id="m104">
<mml:mi>&#x3c3;</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#x22a7;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi mathvariant="script">N</mml:mi>
</mml:mrow>
</mml:msub>
<mml:msup>
<mml:mrow>
<mml:mi mathvariant="normal">&#x3a6;</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mo>&#x2227;</mml:mo>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>f</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>r</mml:mi>
<mml:mspace width="0.3333em"/>
<mml:mi>a</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>l</mml:mi>
<mml:mspace width="0.3333em"/>
<mml:mn>0</mml:mn>
<mml:mo>&#x2264;</mml:mo>
<mml:mi>j</mml:mi>
<mml:mo>&#x3c;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mo>:</mml:mo>
<mml:mi>&#x3c3;</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>j</mml:mi>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#x22a7;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi mathvariant="script">N</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mi mathvariant="normal">&#x3a6;</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:math>
</inline-formula>
</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>
<statement>
<p>Example 5. <italic>Let us consider the social network</italic> <inline-formula id="inf85">
<mml:math id="m105">
<mml:mrow>
<mml:mo stretchy="false">&#x27e8;</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">&#x27e9;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> <italic>of the previous example. The following state-based atomic formula</italic> &#x3a6;<italic>:</italic>
<disp-formula id="equ18">
<mml:math id="m106">
<mml:mi>c</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>t</mml:mi>
<mml:mfenced open="{" close="}">
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mi>e</mml:mi>
<mml:mspace width="0.17em"/>
<mml:mo stretchy="false">&#x7c;</mml:mo>
<mml:mspace width="0.17em"/>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mi>e</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#x2227;</mml:mo>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>a</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>p</mml:mi>
<mml:mi>t</mml:mi>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>t</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>e</mml:mi>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#x2227;</mml:mo>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>t</mml:mi>
<mml:mi>y</mml:mi>
<mml:mi>p</mml:mi>
<mml:mi>e</mml:mi>
<mml:mo>&#x3d;</mml:mo>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#x3e;</mml:mo>
<mml:mn>3</mml:mn>
</mml:math>
</disp-formula>
<italic>is true if and only if the number of agents of type 2 belonging to the community 1 of the social network and that are accepting (and sharing) the news, is greater than 3. Then, through formula</italic> <italic>E true U</italic> &#x3a6; <italic>we can evaluate whether a state is reachable that satisfies</italic> &#x3a6;<italic>.</italic>
</p>
<p>
<italic>On the other hand, let us consider the case of the trustworthy network example. Given</italic> <italic>n</italic> <italic>the identity of the trustor of interest, the following composite formula</italic> &#x3a6;<italic>:</italic>
<disp-formula id="equ19">
<mml:math id="m107">
<mml:mi>n</mml:mi>
<mml:mo>.</mml:mo>
<mml:mi>l</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>v</mml:mi>
<mml:mi>e</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">com</mml:mi>
<mml:mo>&#x2227;</mml:mo>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>min</mml:mi>
<mml:mfenced open="{" close="}">
<mml:mrow>
<mml:mi>&#x3b1;</mml:mi>
<mml:mspace width="0.17em"/>
<mml:mo stretchy="false">&#x7c;</mml:mo>
<mml:mspace width="0.17em"/>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mi>e</mml:mi>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>n</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#x2265;</mml:mo>
<mml:mi>k</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:math>
</disp-formula>
<italic>checks whether the agent</italic> <italic>n</italic> <italic>is available to leave the community</italic> (<italic>since the action</italic> <italic>n</italic>. <italic>leave</italic>_<italic>com</italic> <italic>is enabled</italic>) <italic>even if the value of its local variable</italic> <italic>&#x3b1;</italic> <italic>is</italic> <inline-formula id="inf86">
<mml:math id="m108">
<mml:mo>&#x2265;</mml:mo>
<mml:mi>k</mml:mi>
</mml:math>
</inline-formula>
<italic>. Again, through formula</italic> <italic>E true U</italic> &#x3a6; <italic>we check whether such a state is reachable.</italic>
</p>
</statement>
</p>
</sec>
<sec id="s4">
<title>4 Use Cases and Quantitative Extensions</title>
<p>The objective of the proposed framework is to generalize various approaches to the same problem, which differ from each other for the requirements of the application domain. Hence, it would be useful to have a general-purpose approach, with high-level rules and policies, that can be refined and adapted to each specific case.</p>
<p>For example, an instance of the presented general-purpose modeling approach was proposed in previous work (<xref ref-type="bibr" rid="B3">Aldini, 2016</xref>, <xref ref-type="bibr" rid="B5">Aldini, 2018</xref>), in the specific domain of trustworthy networks, in which trust and reputation models are used to govern the interactions among trustors and trustees. Notice that the examples reported in the previous section illustrate a simplification of a trustor agent and associated behavioral rules. As in such examples, the mode of execution is asynchronous and the most interesting rules are those related to the semantic rule scheme <italic>sync</italic>, as it is used to describe trust-based interactions between agents. More precisely, the side conditions of the semantic rules of such a scheme describe both the trust-based communication policies (e.g., a certain interaction from trustor <italic>A</italic> to trustee <italic>B</italic> is enabled if and only if the trust of <italic>A</italic> towards <italic>B</italic> is higher/lower than the trust threshold applied by <italic>A</italic>) and the policies behind the computation of trust values (e.g., the trust from <italic>A</italic> to <italic>B</italic> is computed by combining several variables, including the dispositional trust of <italic>A</italic>, the previous experience with <italic>B</italic>, and the reputation of <italic>B</italic>). The local repositories include any local trust-based information needed to govern the policies above (e.g., the dispositional trust of <italic>A</italic> towards unknown trustees, the trust threshold applied by <italic>A</italic>, and the scores used to adjust trust after each satisfactory/unsatisfactory interaction). The community-based global repositories are used to collect the opinions shared by the agents within each community to form the reputation scores feeding the trust model.</p>
<p>Then, through model checking, properties expressed in our network logic are used to analyze, e.g., how the trust towards a trustee as perceived by a community is determined depending on the services delivered by such an agent. Variants of such properties allow also to investigate the impact of attacks performed, e.g., by injecting false recommendations. The analysis of real-world case studies, like the Trust-Incentive Service Management by <xref ref-type="bibr" rid="B53">Zhang et al. (2007)</xref>, the Reputation-based Framework for Sensor Networks by <xref ref-type="bibr" rid="B29">Ganeriwal et al. (2008)</xref>, and the Robust Reputation System by <xref ref-type="bibr" rid="B12">Buchegger and Boudec, (2004)</xref>, was conducted automatically through the model checker NuSMV (<xref ref-type="bibr" rid="B18">Cimatti et al., 2002</xref>), thanks to a mapping from our specification language to the model of finite state machines used by the software tool.</p>
<p>The proposed modeling approach is general enough to allow for standard extensions to, e.g., probabilistic and stochastic models. For instance, in <xref ref-type="bibr" rid="B6">Aldini, (2022)</xref>, it is extended with probabilities in order to model and analyze the spread of fake news in social networks. The network is divided into communities of agents, which in turn may exhibit different attitudes to share unchecked news or to conduct some fact checking. The examples reported in the previous section illustrate the non-probabilistic behavior of a type of agent susceptible to stimuli from the environment. The local repositories include the variables characterizing the agent&#x2019;s attitute to believe, check, and share news.</p>
<p>The reference model underlying the approach of <xref ref-type="bibr" rid="B6">Aldini, (2022)</xref> is that of fully probabilistic LTSs (PTSs, for short) obeying the generative model of probabilities (<xref ref-type="bibr" rid="B51">Van Glabbeek et al., 1995</xref>). Analogously, our basic calculus is enriched with probabilistic information, similarly as done, e.g., in <xref ref-type="bibr" rid="B7">Baeten et al. (1992)</xref>. For instance, in <italic>a</italic>. <italic>P</italic> action <italic>a</italic> is executed with probability 1, while the choice operator <italic>P</italic> &#x2b; <italic>Q</italic> is replaced by the probabilistic choice operator <italic>P</italic> &#x2b; <sup>
<italic>p</italic>
</sup>
<italic>Q</italic>, with <inline-formula id="inf87">
<mml:math id="m109">
<mml:mi>p</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mfenced open="" close="]">
</mml:mfenced>
<mml:mn>0,1</mml:mn>
<mml:mfenced open="[" close="">
</mml:mfenced>
</mml:math>
</inline-formula>, stating that an action of <italic>P</italic> (respectively, <italic>Q</italic>) is chosen with probability <italic>p</italic> (respectively, 1 &#x2212; <italic>p</italic>). The mode of execution is synchronous: the <italic>global</italic> and <italic>network</italic> semantic rule schemes are extended accordingly to deal properly with such quantitative information in respect of the underlying model of probabilities.<xref ref-type="fn" rid="fn6">
<sup>6</sup>
</xref>.</p>
<p>The verification of PTSs relies on model checking of probabilistic temporal logic formulas (<xref ref-type="bibr" rid="B37">Kwiatkowska et al., 2011</xref>; <xref ref-type="bibr" rid="B16">Chen et al., 2013</xref>), which are described in a version of our logic that replaces the quantified path operators with the PCTL probabilistic (reachability) operator <inline-formula id="inf88">
<mml:math id="m110">
<mml:msub>
<mml:mrow>
<mml:mi mathvariant="script">P</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x22c8;</mml:mo>
<mml:mi>p</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>&#x3c0;</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> (<xref ref-type="bibr" rid="B32">Hansson and Jonsson, 1994</xref>; <xref ref-type="bibr" rid="B11">Bianco and de Alfaro, 1995</xref>). The automated analysis was possible through a mapping to the PRISM model checker (<xref ref-type="bibr" rid="B37">Kwiatkowska et al., 2011</xref>). The goal of the analysis was to estimate the propagation of fake news over the whole network, depending on the topology of the system and the presence of reliable fact checkers.</p>
<p>In the following, we complete such an overview of potential applications, by considering an example based on another instance of our framework.</p>
<sec id="s4-1">
<title>4.1 Use Case: Blockchain Efficiency</title>
<p>In order to show the flexibility of our approach, here we discuss a case study requiring to deal with stochastically timed events. In such a way, our basic process calculus becomes a stochastic process calculus, in which actions are enriched with rates of exponentially distributed random variables that represent the action duration. Thus, such models give rise to stochastic processes in the form of (action-labeled) Continuous Time Markov chains (<xref ref-type="bibr" rid="B19">Clark et al., 2007</xref>). Technically, the operators of our basic calculus are still the same, with the trick of adopting the additional syntax and semantics of the stochastic process algebra PEPA (<xref ref-type="bibr" rid="B34">Hillston, 1996</xref>; <xref ref-type="bibr" rid="B50">Tribastone et al., 2009</xref>). In particular, actions are pairs of the form (<italic>a</italic>, <italic>&#x3bb;</italic>), where <italic>a</italic> &#x2208; <italic>Act</italic> and <inline-formula id="inf89">
<mml:math id="m111">
<mml:mi>&#x3bb;</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:msup>
<mml:mrow>
<mml:mi mathvariant="double-struck">R</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2b;</mml:mo>
</mml:mrow>
</mml:msup>
</mml:math>
</inline-formula> is a positive rate representing the parameter of an exponential probability distribution governing the duration of the timed action. In this setting, the choice operator captures a notion of competition solved via the <italic>race policy</italic>: the action to execute is the one that samples the least duration. We refer to the citations above for all the details about the semantics of stochastic processes. In our use case, we assume the fully asynchronous mode of execution, so that in the following we have to specify the instances of the rule <italic>async</italic> tailored to the given use case.</p>
<p>The objective of the case study is to model a network of peers (P2P network) exchanging information about the blocks of a blockchain, which are generated by special agents called miners - see, e.g., <xref ref-type="bibr" rid="B28">Gamage et al. (2020)</xref> for a comprehensive overview of this distributed ledger technology. The blockchain model under consideration is permissionless and based on the proof-of-work mechanism (as in the case, e.g., of Bitcoin). Basically, any peer can mine a new block by solving a cryptographic puzzle called proof-of-work. To this aim, it is essential for the miner to learn information about the most recent block added to the blockchain and the data with which a new block is compiled, which depend on the specific application domain (e.g., virtual currency transactions in the case of Bitcoin). Here, we abstract away from the application domain and we concentrate on the blockchain management.</p>
<p>Peers acting as miners have the following behavioral pattern:<disp-formula id="equ20">
<mml:math id="m112">
<mml:mtable class="matrix">
<mml:mtr>
<mml:mtd columnalign="center">
<mml:mi>M</mml:mi>
<mml:mi>i</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>r</mml:mi>
</mml:mtd>
<mml:mtd columnalign="center">
<mml:mrow>
<mml:mover>
<mml:mrow>
<mml:mo>&#x3d;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:mi mathvariant="normal">d</mml:mi>
<mml:mi mathvariant="normal">e</mml:mi>
<mml:mi mathvariant="normal">f</mml:mi>
</mml:mrow>
</mml:mrow>
</mml:mover>
</mml:mrow>
</mml:mtd>
<mml:mtd columnalign="center">
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>o</mml:mi>
<mml:mi>b</mml:mi>
<mml:mi>s</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">block</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>p</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>p</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">rate</mml:mi>
</mml:mrow>
</mml:mfenced>
<mml:mo>.</mml:mo>
<mml:mi>M</mml:mi>
<mml:mi>i</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>r</mml:mi>
<mml:mo>&#x2b;</mml:mo>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>m</mml:mi>
<mml:mi>i</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>e</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>m</mml:mi>
<mml:mi>i</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>i</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>g</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">rate</mml:mi>
</mml:mrow>
</mml:mfenced>
<mml:mo>.</mml:mo>
<mml:msup>
<mml:mrow>
<mml:mi>M</mml:mi>
<mml:mi>i</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>r</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
</mml:mtd>
</mml:mtr>
<mml:mtr>
<mml:mtd columnalign="center">
<mml:msup>
<mml:mrow>
<mml:mi>M</mml:mi>
<mml:mi>i</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>r</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
</mml:mtd>
<mml:mtd columnalign="center">
<mml:mrow>
<mml:mover>
<mml:mrow>
<mml:mo>&#x3d;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:mi mathvariant="normal">d</mml:mi>
<mml:mi mathvariant="normal">e</mml:mi>
<mml:mi mathvariant="normal">f</mml:mi>
</mml:mrow>
</mml:mrow>
</mml:mover>
</mml:mrow>
</mml:mtd>
<mml:mtd columnalign="center">
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>o</mml:mi>
<mml:mi>b</mml:mi>
<mml:mi>s</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">block</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>r</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>s</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>m</mml:mi>
<mml:mi>e</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">rate</mml:mi>
</mml:mrow>
</mml:mfenced>
<mml:mo>.</mml:mo>
<mml:mi>M</mml:mi>
<mml:mi>i</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>r</mml:mi>
<mml:mo>&#x2b;</mml:mo>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>a</mml:mi>
<mml:mi>d</mml:mi>
<mml:mi>d</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">block</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>p</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>p</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">rate</mml:mi>
</mml:mrow>
</mml:mfenced>
<mml:mo>.</mml:mo>
<mml:mi>M</mml:mi>
<mml:mi>i</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>r</mml:mi>
</mml:mtd>
</mml:mtr>
</mml:mtable>
</mml:math>
</disp-formula>
</p>
<p>A mining node can notice that a new block was mined and propagated through the miner&#x2019;s community (action <italic>obs_block</italic>) and, at the same time, tries to solve the proof-of-work that would allow him to mine the next block (action <italic>mine</italic>) to be added to the blockchain and propagated to the network (action <italic>add_block</italic>). The other ordinary peers advertise and relay to their reference communities any new block added to the blockchain. Hence, they simply act as forwarder nodes:<disp-formula id="equ21">
<mml:math id="m113">
<mml:mtable class="array">
<mml:mtr>
<mml:mtd columnalign="right">
<mml:mi>P</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>r</mml:mi>
</mml:mtd>
<mml:mtd columnalign="center">
<mml:mrow>
<mml:mover>
<mml:mrow>
<mml:mo>&#x3d;</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mrow>
<mml:mi mathvariant="normal">d</mml:mi>
<mml:mi mathvariant="normal">e</mml:mi>
<mml:mi mathvariant="normal">f</mml:mi>
</mml:mrow>
</mml:mrow>
</mml:mover>
</mml:mrow>
</mml:mtd>
<mml:mtd columnalign="left">
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>o</mml:mi>
<mml:mi>b</mml:mi>
<mml:mi>s</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">block</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>p</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>p</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">rate</mml:mi>
</mml:mrow>
</mml:mfenced>
<mml:mo>.</mml:mo>
<mml:mi>P</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>r</mml:mi>
<mml:mo>&#x2b;</mml:mo>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>p</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>p</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">block</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>p</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>p</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">rate</mml:mi>
</mml:mrow>
</mml:mfenced>
<mml:mo>.</mml:mo>
<mml:mi>P</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>r</mml:mi>
</mml:mtd>
</mml:mtr>
</mml:mtable>
</mml:math>
</disp-formula>A peer can notice that a new block was mined (action <italic>obs_block</italic>) and can propagate newly received blocks (action <italic>prop_block</italic>).</p>
<p>As far as the local repositories are concerned, every node shall maintain a local copy of the blockchain; for the sake of simplicity we limit each node to store the last block of the blockchain, which is abstractedly represented by a local counter <italic>block_id</italic> initially set to 0 for every node of the network. As far as the community-based global repositories are concerned, we use a global variable <italic>last_block_id</italic> storing the most recent block propagated in the community. With such additional information in view&#x2013;used to define the local mapping <italic>V</italic> of each node and the global mappings <inline-formula id="inf90">
<mml:math id="m114">
<mml:mi mathvariant="script">W</mml:mi>
</mml:math>
</inline-formula> for the communities&#x2013;we now define the several instances of the semantic rule scheme <italic>async</italic>. For each instance, we specify the action of interest, the enabling conditions, and the side effects:<list list-type="simple">
<list-item>
<p>1. case <italic>a</italic> &#x3d; <italic>obs</italic>_<italic>block</italic>:</p>
<list list-type="simple">
<list-item>
<p>&#x2022; <inline-formula id="inf91">
<mml:math id="m115">
<mml:mo>&#x2203;</mml:mo>
<mml:mi>G</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi>C</mml:mi>
<mml:mi>N</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>m</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>s</mml:mi>
<mml:mo>:</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>G</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mo>&#x2227;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>.</mml:mo>
<mml:mi>b</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>k</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">id</mml:mi>
<mml:mo>&#x3c;</mml:mo>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>G</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>l</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>s</mml:mi>
<mml:mi>t</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">block</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">id</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula>
</p>
</list-item>
<list-item>
<p>&#x2022; <inline-formula id="inf92">
<mml:math id="m116">
<mml:msup>
<mml:mrow>
<mml:mi>V</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>V</mml:mi>
<mml:mrow>
<mml:mo stretchy="false">[</mml:mo>
<mml:mrow>
<mml:mi>b</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>k</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">id</mml:mi>
<mml:mo>&#x21a6;</mml:mo>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>G</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>l</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>s</mml:mi>
<mml:mi>t</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi>b</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>k</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:mrow>
<mml:mo stretchy="false">]</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula>
</p>
</list-item>
<list-item>
<p>&#x2022; <inline-formula id="inf93">
<mml:math id="m117">
<mml:msup>
<mml:mrow>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mo>&#x3d;</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
</mml:math>
</inline-formula>
</p>
</list-item>
</list>
</list-item>
<list-item>
<p>2. case <italic>a</italic> &#x3d; <italic>prop</italic>_<italic>block</italic>:</p>
<list list-type="simple">
<list-item>
<p>&#x2022; <inline-formula id="inf94">
<mml:math id="m118">
<mml:mo>&#x2203;</mml:mo>
<mml:mi>G</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi>C</mml:mi>
<mml:mi>N</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>m</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>s</mml:mi>
<mml:mo>:</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>G</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mo>&#x2227;</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>.</mml:mo>
<mml:mi>b</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>k</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">id</mml:mi>
<mml:mo>&#x3e;</mml:mo>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>G</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>l</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>s</mml:mi>
<mml:mi>t</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi>b</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>k</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula>
</p>
</list-item>
<list-item>
<p>&#x2022; <italic>V</italic>&#x2032; &#x3d; <italic>V</italic>
</p>
</list-item>
<list-item>
<p>&#x2022; <inline-formula id="inf95">
<mml:math id="m119">
<mml:msup>
<mml:mrow>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>G</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mo>&#x3d;</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>G</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">[</mml:mo>
<mml:mrow>
<mml:mi>l</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>s</mml:mi>
<mml:mi>t</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi>b</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>k</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>&#x21a6;</mml:mo>
<mml:mi>V</mml:mi>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>b</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>k</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">id</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:mrow>
<mml:mo stretchy="false">]</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula>
</p>
</list-item>
</list>
</list-item>
<list-item>
<p>3. case <italic>a</italic> &#x3d; <italic>add</italic>_<italic>block</italic>:</p>
<list list-type="simple">
<list-item>
<p>&#x2022; <inline-formula id="inf96">
<mml:math id="m120">
<mml:mo>&#x2203;</mml:mo>
<mml:mi>G</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi>C</mml:mi>
<mml:mi>N</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>m</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>s</mml:mi>
<mml:mo>:</mml:mo>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="script">G</mml:mi>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>G</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mo>&#x2227;</mml:mo>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>.</mml:mo>
<mml:mi>b</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>k</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">id</mml:mi>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mo>&#x3e;</mml:mo>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>G</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>l</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>s</mml:mi>
<mml:mi>t</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi>b</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>k</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula>
</p>
</list-item>
<list-item>
<p>&#x2022; <italic>V</italic>&#x2032; &#x3d; <italic>V</italic>[<italic>block</italic>_<italic>id</italic>&#x21a6;<italic>V</italic>(<italic>block</italic>_<italic>id</italic>) &#x2b; 1]</p>
</list-item>
<list-item>
<p>&#x2022; <inline-formula id="inf97">
<mml:math id="m121">
<mml:msup>
<mml:mrow>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x2032;</mml:mo>
</mml:mrow>
</mml:msup>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>G</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mo>&#x3d;</mml:mo>
<mml:mi mathvariant="script">W</mml:mi>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>G</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mo stretchy="false">[</mml:mo>
<mml:mrow>
<mml:mi>l</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>s</mml:mi>
<mml:mi>t</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi>b</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>k</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mo>&#x21a6;</mml:mo>
<mml:mi>V</mml:mi>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>b</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>k</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">id</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
<mml:mo stretchy="false">]</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula>
</p>
</list-item>
</list>
</list-item>
</list>
</p>
<p>The first case, which refers to the observation of a new block by a node in one of its communities, requires the node to update its local copy of the blockchain. The second case, which refers to the propagation of a new block by a node to one of its communities, requires the node to update the global repository of that community. The third case, which refers to the upload of a new block to the blockchain, requires the miner to update its local copy and to propagate the block. Notice that, by the presence of several potential communities (see the existential quantifier over <italic>G</italic> &#x2208; <italic>CNames</italic>), such cases may enable several different outgoing transitions, one per involved community. Any other action, like action <italic>mine</italic> in our example, does not require side conditions and/or effects, i.e., the <italic>async</italic> rule scheme is applied with <inline-formula id="inf98">
<mml:math id="m122">
<mml:mi mathvariant="monospace">c</mml:mi>
<mml:mi mathvariant="monospace">o</mml:mi>
<mml:mi mathvariant="monospace">n</mml:mi>
<mml:mi mathvariant="monospace">d</mml:mi>
<mml:mo>&#x2254;</mml:mo>
<mml:mi>t</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>e</mml:mi>
</mml:math>
</inline-formula> and no variation of the local/global repositories.</p>
<p>Essentially, the specification requires just to define the behavioral pattern of the node types (<italic>Miner</italic> and <italic>Peer</italic>) and the pre/post-conditions associated with the execution of the relevant actions. Analogously, we now show through a simple example how it is easy to model properties of interest.</p>
<p>Block propagation delays may potentially impair the correctness of the blockchain sharing process, because a miner could mine and propagate a block before learning of a newly mined block that has been added to the blockchain. Such a misalignment problem is known as blockchain fork. To solve the issue, the network abandons the blocks that are not in the longest chain. Hence, performance and correctness are tightly connected, as the speed at which peers learn of new blocks is related to the likelihood of forks in the blockchain. Recently, in <xref ref-type="bibr" rid="B15">Chandrasekaran et al. (2022)</xref> an empirical study of the information propagation delays between nodes in blockchain P2P networks was proposed that emphasizes how the likelihood of forks drastically diminished since 2013. In particular, block propagation delays are estimated in the top four blockchain-based applications, including Bitcoin.</p>
<p>Here, we propose a formal and automated verification of the analysis mentioned above, based on the use of the PRISM model checker<xref ref-type="fn" rid="fn7">
<sup>7</sup>
</xref>. For analysis purposes, we decided to instantiate the rates of the timed actions according to the Bitcoin related estimates of <xref ref-type="bibr" rid="B15">Chandrasekaran et al. (2022)</xref>: the expected time to mine is about 10&#xa0;min, while the mean (respectively, median) end-to-end propagation delay is about 4&#xa0;s (respectively, about 0.4&#xa0;s). Moreover, we modeled various configurations, represented by the topology shown in <xref ref-type="fig" rid="F1">Figure 1</xref>, in which the P2P network radius - represented by the number of involved communities, depicted as clouds - is equal to 6. When a block is advertised in a community, all the members of the community react by experiencing the same delay, so that the overall end-to-end delay of the network depends on the network radius. Two miners are present in the network, while the other peers are either members of a single community or belonging to the intersection of many of them.</p>
<fig id="F1" position="float">
<label>FIGURE 1</label>
<caption>
<p>Example of P2P network with 6 communities; some representative peers are depicted, including 2 miners.</p>
</caption>
<graphic xlink:href="frobt-09-866649-g001.tif"/>
</fig>
<p>For the purpose of model checking, we consider a probabilistic reachability property of the form <inline-formula id="inf99">
<mml:math id="m123">
<mml:msub>
<mml:mrow>
<mml:mi mathvariant="script">P</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mo>&#x22c8;</mml:mo>
<mml:mi>p</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mrow>
<mml:mo stretchy="false">(</mml:mo>
<mml:mrow>
<mml:mi>&#x3c0;</mml:mi>
</mml:mrow>
<mml:mo stretchy="false">)</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula>, where <italic>&#x3c0;</italic> is an <italic>until</italic> formula expressing the reachability of a state in which a peer mines a new block and uses it to extend an obsolete version of the blockchain, thus causing a fork. Formally, if we concentrate on the miner with <italic>id</italic> &#x3d; 1, such a condition is a mixture of action and state based formulas defined as follows:<disp-formula id="equ22">
<mml:math id="m124">
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mn>1</mml:mn>
<mml:mo>.</mml:mo>
<mml:mi>a</mml:mi>
<mml:mi>d</mml:mi>
<mml:mi>d</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">block</mml:mi>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#x2227;</mml:mo>
<mml:mfenced open="(" close=")">
<mml:mrow>
<mml:mi>c</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>t</mml:mi>
<mml:mfenced open="{" close="}">
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mi>e</mml:mi>
<mml:mspace width="0.17em"/>
<mml:mo stretchy="false">&#x7c;</mml:mo>
<mml:mspace width="0.17em"/>
<mml:mi>i</mml:mi>
<mml:mi>d</mml:mi>
<mml:mi>e</mml:mi>
<mml:mo>&#x3d;</mml:mo>
<mml:mn>1</mml:mn>
<mml:mo>&#x2227;</mml:mo>
<mml:mi>b</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>k</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">id</mml:mi>
<mml:mo>&#x3c;</mml:mo>
<mml:mi>max</mml:mi>
<mml:mfenced open="{" close="}">
<mml:mrow>
<mml:mi>l</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>s</mml:mi>
<mml:mi>t</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">block</mml:mi>
<mml:mtext>_</mml:mtext>
<mml:mi mathvariant="italic">id</mml:mi>
<mml:mspace width="0.17em"/>
<mml:mo stretchy="false">&#x7c;</mml:mo>
<mml:mspace width="0.17em"/>
<mml:mi>t</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>e</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mfenced>
<mml:mo>&#x3d;</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:mfenced>
<mml:mo>.</mml:mo>
</mml:math>
</disp-formula>
</p>
<p>The first conjunct holds when the first miner is enabled to update the blockchain. The second conjunct holds when such an update is obsolete as a more recent block is circulating in the network. We can reason analogously for the other miner, and then join the result of the two properties.</p>
<p>In <xref ref-type="fig" rid="F2">Figure 2</xref>, we show the results of such an analysis by considering the four combinations deriving from two different configuration choices. The first dimension is given by the topology specification: in scenarios A and B we have exactly the representative nodes depicted in <xref ref-type="fig" rid="F1">Figure 1</xref>, while in scenarios C and D only the miners and the peers in the intersecting areas between the communities are modeled. Then, in the first two scenarios we measure the fork likelihood in a period of time equal to 100&#xa0;min, while in the other two scenarios we refer to a 1 day interval. The second dimension is given by the propagation delay between each pair of peers, which is chosen to correspond to the mean end-to-end delay measured in <xref ref-type="bibr" rid="B15">Chandrasekaran et al. (2022)</xref> for scenarios A and C, and to the median end-to-end delay measured in <xref ref-type="bibr" rid="B15">Chandrasekaran et al. (2022)</xref> for scenarios B and D. Moreover, each figure presents the results obtained in three different cases: in case (1) both miners experience the same mining delay (10&#xa0;min), in case (2) the second miner is slower (15&#xa0;min), while in the third case the second miner is faster (5&#xa0;min).</p>
<fig id="F2" position="float">
<label>FIGURE 2</label>
<caption>
<p>Relation between blockchain length and fork likelihood: analysis for 4 different scenarios.</p>
</caption>
<graphic xlink:href="frobt-09-866649-g002.tif"/>
</fig>
<p>In general, case (1) emphasizes that the fork probability is negligible, especially in cases (b) and (d). These results confirm the performance shown in <xref ref-type="bibr" rid="B15">Chandrasekaran et al. (2022)</xref>. In detail, cases (2) and (3) reveal that the monitoring of the proof-of-work expected time is critical to maintain the fork likelihood at the desired level. Summarizing, already this simple case study illustrates that our framework is flexible and easy-to-use both from the modeling and the verification standpoints, also in the quantitative setting.</p>
</sec>
</sec>
<sec id="s5">
<title>5 Related Work and Conclusions</title>
<p>The aim of the proposed approach is to provide a modeling and analysis framework that can be instantiated to specific application domains. The common feature of such domains is that they are characterized by collections of autonomous, dynamic, and interactive agents exhibiting a wide spectrum of cooperation patterns, as well as both reactive and proactive behaviors. The reported examples emphasize that the considered systems may express social relations of human agents in virtual environments, human&#x2013;computer interactions, and also machine to machine communication. These include online services for smart and sustainable environments, and computer supported cooperative networks.</p>
<p>The verification of coordination and control strategies for cooperative multi-agent systems is of paramount importance even in the setting of inter-robot communications. To this aim, several formal approaches to the design of coordination for robotics emerged in the literature. For instance, the design method proposed in <xref ref-type="bibr" rid="B22">Dai et al. (2016)</xref> employs concurrent finite automata and is based on a top-down approach recalling the separation of concerns adopted in our framework at a higher abstraction level. In <xref ref-type="bibr" rid="B31">Gu et al. (2020)</xref>, the specific problem of synthesising and verifying collision-free paths for autonomous multi-agent systems is dealt with formally through stochastic timed automata and statistical model checking. The verification is conducted automatically through the software tool UPPAAL. In <xref ref-type="bibr" rid="B1">Abd Alrahman and Piterman, (2021)</xref>, reconfigurable multi-agent systems are modeled via finite automata and model checked using a variant of the Linear Temporal Logic (LTL). The authors emphasize that formal paradigms for modeling dynamic multi-agent systems cannot rely (only) on point-to-point communication. Instead, group-based communication is more appropriate, which is exactly one of the principles behind our framework. By following the same basic ideas, formal modeling paradigms and probabilistic model checking techniques are adopted for the analysis of autonomous agents by <xref ref-type="bibr" rid="B47">Sekizawa et al. (2015)</xref> and by <xref ref-type="bibr" rid="B2">Al-Nuaimi et al. (2018)</xref>. Both approaches use the software tool PRISM for the automated analysis, similarly as done in the quantitative extensions of our framework. In general, all the formal approaches mentioned above rely directly on paradigms that are also at the base of our framework, on top of which we defined a high-level process algebraic specification language. The need for high-level languages in this setting is emphasized, e.g., by <xref ref-type="bibr" rid="B23">De Nicola et al. (2018)</xref>; <xref ref-type="bibr" rid="B1">Abd Alrahman and Piterman (2021)</xref>. For instance, we mention the languages ISPL (<xref ref-type="bibr" rid="B38">Lomuscio et al., 2009</xref>) and SCEL (<xref ref-type="bibr" rid="B25">De Nicola et al., 2015</xref>). The semantics of the former is based on concurrent labeled transition systems, which specifically adopt a form of synchronous communication. Interestingly, model checking is based on an epistemic logic encompassing a knowledge operator. On the other hand, the latter naturally supports knowledge-based communication for dynamic systems, in a way that recalls the method used in our framework to support uni/multi-cast communication via local/global repositories. The full semantics of SCEL is not trivial to export to a runtime environment; tool support is given, e.g., by the model checker SPIN and the MAUDE framework.</p>
<p>In the literature, it is worth mentioning that formal, process-algebraic approaches (<xref ref-type="bibr" rid="B39">Loreti and Hillston, 2016</xref>), semi-formal, architectural description approaches (<xref ref-type="bibr" rid="B43">Ozkaya and Kloukinas, 2013</xref>), and combinations of both (<xref ref-type="bibr" rid="B8">Basu et al., 2011</xref>; <xref ref-type="bibr" rid="B33">Hennicker et al., 2014</xref>; <xref ref-type="bibr" rid="B13">Bures et al., 2016</xref>) have been proposed to model and analyze dynamic reconfigurable architectures (<xref ref-type="bibr" rid="B41">De Nicola et al., 2020</xref>) and (self-)adaptive systems (<xref ref-type="bibr" rid="B27">Gabor et al., 2020</xref>). In particular, the language CARMA (<xref ref-type="bibr" rid="B39">Loreti and Hillston, 2016</xref>) is specifically defined to model collective adaptive systems and shares several features with our framework, such as the separation of concerns advocated in <xref ref-type="sec" rid="s2">Section 2</xref>, support for local/global views, and a formal semantics in operational style. The process calculus of CARMA is stochastic and has a Markovian semantics, on which numerical analysis based on simulation can be conducted. Moreover, CARMA is equipped with an architectural-style specification language on top of the calculus. By virtue of its modeling capabilities, CARMA is an ideal candidate for representing an instance of the modeling framework proposed in this paper. The BIP framework of <xref ref-type="bibr" rid="B8">Basu et al. (2011)</xref> proposes synchronous priority-based communication and a rigorous semantics based on finite-state automata and Petri nets. Compositional verification methods are based on static analysis of local/global invariants. For instance, deadlock-freedom is checked for a robot controller. Interestingly, BIP can be part of a software design flow culminating in deployable code generation. The HELENA approach of <xref ref-type="bibr" rid="B33">Hennicker et al. (2014)</xref> formalises the modeling of ensembles (i.e., groups of dynamic collaborating entities) through a class of automata. A mapping towards Promela allows for model checking verification through the SPIN model checker (<xref ref-type="bibr" rid="B36">Klarl, 2015</xref>). The modeling of ensembles is also the goal of the DEECo approach of <xref ref-type="bibr" rid="B13">Bures et al. (2016)</xref>, the operational semantics of which is defined in terms of labeled transition systems. Tool support is provided to enable the verification of reachability properties.</p>
<p>In many of the cases discussed above, classical temporal logics, like LTL and PCTL, support, via model checking, the formal verification of dynamic, multi-agent systems. Sometimes, ad-hoc extensions are used to model specific properties of cyber-physical systems, such as spatial-based conditions (<xref ref-type="bibr" rid="B17">Ciancia et al., 2018</xref>; <xref ref-type="bibr" rid="B44">Platzer et al., 2019</xref>). The property specification language proposed in our work encompasses the features of CTL-like logics, with a specific emphasis on the separation of concerns and local/global views that characterize the modeling style of our framework.</p>
<p>The key factor of the proposed approach that represents the novelty of this paper is given by the flexibility of a high-level framework combining an action-based formalism with data-driven communication mechanisms based on which different, customized semantics can be provided and supported by several automated tools. So, with respect to the state-of-the-art, by itself the proposed approach does not add new theoretical insights and results. Together with the ease of use in modeling both behavioral patterns and property specifications, the flexibility mentioned above makes our framework adequate to model collective adaptive systems and to support those programming frameworks (<xref ref-type="bibr" rid="B9">Beal et al., 2015</xref>; <xref ref-type="bibr" rid="B10">Berndtsson and Mellin, 2018</xref>; <xref ref-type="bibr" rid="B14">Casadei et al., 2018</xref>) used to develop them.</p>
</sec>
</body>
<back>
<sec id="s6">
<title>Data Availability Statement</title>
<p>The raw data supporting the conclusions of this article will be made available by the authors, without undue reservation.</p>
</sec>
<sec id="s7">
<title>Author Contributions</title>
<p>As unique author of the manuscript, AA contributed to all its parts, including design of the study, case study modeling and verification, and writing of all sections.</p>
</sec>
<sec sec-type="COI-statement" id="s8">
<title>Conflict of Interest</title>
<p>The author declares that the research was conducted in the absence of any commercial or financial relationships that could be construed as a potential conflict of interest.</p>
</sec>
<sec sec-type="disclaimer" id="s9">
<title>Publisher&#x2019;s Note</title>
<p>All claims expressed in this article are solely those of the authors and do not necessarily represent those of their affiliated organizations, or those of the publisher, the editors and the reviewers. Any product that may be evaluated in this article, or claim that may be made by its manufacturer, is not guaranteed or endorsed by the publisher.</p>
</sec>
<fn-group>
<fn id="fn1">
<label>1</label>
<p>This can be generalized to consider a separate domain for each variable. By the way, in this paper we assume that <italic>D</italic> is a finite, numerical domain.</p>
</fn>
<fn id="fn2">
<label>2</label>
<p>For the sake of simplicity we a ssume that <italic>WNames</italic> and <italic>VNames</italic> are disjoint.</p>
</fn>
<fn id="fn3">
<label>3</label>
<p>We point out that <inline-formula id="inf100">
<mml:math id="m125">
<mml:mo movablelimits="false" form="prefix">&#x220f;</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
</mml:math>
</inline-formula> is a shorthand expressing the combination of updates <inline-formula id="inf101">
<mml:math id="m126">
<mml:msub>
<mml:mrow>
<mml:mi mathvariant="script">W</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
</mml:math>
</inline-formula> applied to the global data repository <inline-formula id="inf102">
<mml:math id="m127">
<mml:mi mathvariant="script">W</mml:mi>
</mml:math>
</inline-formula> by virtue of the moves performed locally by the <italic>n</italic> agents. It is worth noticing that concurrent accesses to the same global variable may occur whenever no mutual exclusion mechanisms are used explicitly by the agents. It is known that this leads to nondeterministic behaviors. This is reflected correctly by the <italic>network</italic> semantic rule, which, in such a case, would enable multiple outgoing transitions, depending on the nondeterminism influencing the way in which <inline-formula id="inf103">
<mml:math id="m128">
<mml:mi mathvariant="script">W</mml:mi>
</mml:math>
</inline-formula> can be updated. However, if the system at hand implements mutual exclusion mechanisms, these would be modeled at the level of the agents&#x2019; behavior and of the semantics of the <italic>global</italic> rule scheme, so that no nondeterminism about the update of <inline-formula id="inf104">
<mml:math id="m129">
<mml:mi mathvariant="script">W</mml:mi>
</mml:math>
</inline-formula> would emerge by applying the rule <italic>network</italic>.</p>
</fn>
<fn id="fn4">
<label>4</label>
<p>For the sake of simplicity, here we are assuming that <inline-formula id="inf105">
<mml:math id="m130">
<mml:mi>C</mml:mi>
<mml:mi>N</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>m</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>s</mml:mi>
<mml:mo>&#x2286;</mml:mo>
<mml:mi mathvariant="double-struck">N</mml:mi>
</mml:math>
</inline-formula> and the condition <italic>c</italic>&#x22c8;<italic>k</italic> applies to the natural <italic>i</italic> representing the community identity, i.e., <italic>i</italic>&#x22c8;<italic>k</italic>. If using another domain for community names (e.g., strings) then the elements of the term &#x22c8;<italic>k</italic> would change accordingly.</p>
</fn>
<fn id="fn5">
<label>5</label>
<p>We recall that, similarly as argued for the case of communities identities, we have that agents identities are expressed as naturals. While an obvious condition identifying a specific agent is of the form <italic>ide</italic> &#x3d; <italic>n</italic>, with <inline-formula id="inf106">
<mml:math id="m131">
<mml:mi>n</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="double-struck">N</mml:mi>
</mml:math>
</inline-formula>, we could also envision the use of inequality operators if, e.g., the identities are ordered according to some criteria.</p>
</fn>
<fn id="fn6">
<label>6</label>
<p>Models combining nondeterminism and probabilities, like in Markov Decision Processes, can be adopted as well in our approach, by adapting accordingly the semantics.</p>
</fn>
<fn id="fn7">
<label>7</label>
<p>The PRISM source file resulting from our specification is available at: <ext-link ext-link-type="uri" xlink:href="https://github.com/aldinia/prism-bc-specs">https://github.com/aldinia/prism-bc-specs</ext-link>.</p>
</fn>
</fn-group>
<ref-list>
<title>References</title>
<ref id="B1">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Abd Alrahman</surname>
<given-names>Y.</given-names>
</name>
<name>
<surname>Piterman</surname>
<given-names>N.</given-names>
</name>
</person-group> (<year>2021</year>). <article-title>Modelling and Verification of Reconfigurable Multi-Agent Systems</article-title>. <source>Auton. Agent Multi Agent Syst.</source> <volume>35</volume>, <fpage>47</fpage>. <pub-id pub-id-type="doi">10.1007/s10458-021-09521-x</pub-id> </citation>
</ref>
<ref id="B2">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Al-Nuaimi</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Qu</surname>
<given-names>H.</given-names>
</name>
<name>
<surname>Veres</surname>
<given-names>S. M.</given-names>
</name>
</person-group> (<year>2018</year>). &#x201c;<article-title>A Stochastically Verifiable Decision Making Framework for Autonomous Ground Vehicles</article-title>,&#x201d; in <conf-name>2018 IEEE International Conference on Intelligence and Safety for Robotics (ISR)</conf-name>, <fpage>26</fpage>&#x2013;<lpage>33</lpage>. <pub-id pub-id-type="doi">10.1109/iisr.2018.8535911</pub-id> </citation>
</ref>
<ref id="B3">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Aldini</surname>
<given-names>A.</given-names>
</name>
</person-group> (<year>2016</year>). &#x201c;<article-title>A Formal Framework for Modeling Trust and Reputation in Collective Adaptive Systems</article-title>,&#x201d; in <conf-name>Workshop on FORmal Methods for the Quantitative Evaluation of Collective Adaptive SysTems, FORECAST 2016 (Electronic Proceedings in Theoretical Computer Science)</conf-name>, <fpage>19</fpage>&#x2013;<lpage>30</lpage>. <pub-id pub-id-type="doi">10.4204/eptcs.217.4</pub-id> </citation>
</ref>
<ref id="B4">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Aldini</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Bernardo</surname>
<given-names>B.</given-names>
</name>
<name>
<surname>Corradini</surname>
<given-names>F.</given-names>
</name>
</person-group> (<year>2010</year>). <source>A Process Algebraic Approach to Software Architecture Design</source>. <publisher-loc>London</publisher-loc>: <publisher-name>Springer</publisher-name>. </citation>
</ref>
<ref id="B5">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Aldini</surname>
<given-names>A.</given-names>
</name>
</person-group> (<year>2018</year>). <article-title>Design and Verification of Trusted Collective Adaptive Systems</article-title>. <source>Trans. Model. Comput. Simul. (TOMACS)</source> <volume>28</volume>, <fpage>1</fpage>&#x2013;<lpage>27</lpage>. <pub-id pub-id-type="doi">10.1145/3155337</pub-id> </citation>
</ref>
<ref id="B6">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Aldini</surname>
<given-names>A.</given-names>
</name>
</person-group> (<year>2022</year>). &#x201c;<article-title>On the Modeling and Verification of the Spread of Fake News, Algebraically</article-title>,&#x201d; in <conf-name>Journal of Logic and Computation, Special Issue on Reasoning about Social Networks</conf-name>. <pub-id pub-id-type="doi">10.1093/logcom/exac015</pub-id> </citation>
</ref>
<ref id="B7">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Baeten</surname>
<given-names>J. C. M.</given-names>
</name>
<name>
<surname>Bergstra</surname>
<given-names>J. A.</given-names>
</name>
<name>
<surname>Smolka</surname>
<given-names>S. A.</given-names>
</name>
</person-group> (<year>1992</year>). &#x201c;<article-title>Axiomatizing Probabilistic Processes: ACP with Generative Probabilities</article-title>,&#x201d; in <source>CONCUR&#x2019;92</source>. Editor <person-group person-group-type="editor">
<name>
<surname>Cleaveland</surname>
<given-names>W.</given-names>
</name>
</person-group> (<publisher-name>Springer</publisher-name>), <fpage>472</fpage>&#x2013;<lpage>485</lpage>. <pub-id pub-id-type="doi">10.1007/bfb0084810</pub-id> </citation>
</ref>
<ref id="B8">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Basu</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Bensalem</surname>
<given-names>B.</given-names>
</name>
<name>
<surname>Bozga</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Combaz</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Jaber</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Nguyen</surname>
<given-names>T.-H.</given-names>
</name>
<etal/>
</person-group> (<year>2011</year>). <article-title>Rigorous Component-Based System Design Using the BIP Framework</article-title>. <source>IEEE Softw.</source> <volume>28</volume>, <fpage>41</fpage>&#x2013;<lpage>48</lpage>. <pub-id pub-id-type="doi">10.1109/MS.2011.27</pub-id> </citation>
</ref>
<ref id="B9">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Beal</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Pianini</surname>
<given-names>D.</given-names>
</name>
<name>
<surname>Viroli</surname>
<given-names>M.</given-names>
</name>
</person-group> (<year>2015</year>). <article-title>Aggregate Programming for the Internet of Things</article-title>. <source>Computer</source> <volume>48</volume>, <fpage>22</fpage>&#x2013;<lpage>30</lpage>. <pub-id pub-id-type="doi">10.1109/MC.2015.261</pub-id> </citation>
</ref>
<ref id="B10">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Berndtsson</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Mellin</surname>
<given-names>J.</given-names>
</name>
</person-group> (<year>2018</year>). &#x201c;<article-title>ECA Rules</article-title>,&#x201d; in <source>Encyclopedia of Database Systems</source>. Editors <person-group person-group-type="editor">
<name>
<surname>Liu,</surname>
<given-names>L.</given-names>
</name>
<name>
<surname>&#xd6;zsu</surname>
<given-names>M. T.</given-names>
</name>
</person-group>. <edition>Second Edition</edition> (<publisher-name>Springer</publisher-name>). <pub-id pub-id-type="doi">10.1007/978-1-4614-8265-9_504</pub-id> </citation>
</ref>
<ref id="B11">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Bianco</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>de Alfaro</surname>
<given-names>L.</given-names>
</name>
</person-group> (<year>1995</year>). &#x201c;<article-title>Model Checking of Probabilistic and Nondeterministic Systems</article-title>,&#x201d; in <source>Foundations of Software Technology and Theoretical Computer Science</source>. Editor <person-group person-group-type="editor">
<name>
<surname>Thiagarajan</surname>
<given-names>P. S.</given-names>
</name>
</person-group> (<publisher-name>Springer</publisher-name>), <fpage>499</fpage>&#x2013;<lpage>513</lpage>. <pub-id pub-id-type="doi">10.1007/3-540-60692-0_70</pub-id> </citation>
</ref>
<ref id="B12">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Buchegger</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Boudec</surname>
<given-names>J.-Y. L.</given-names>
</name>
</person-group> (<year>2004</year>). &#x201c;<article-title>A Robust Reputation System for Peer-To-Peer and Mobile Ad-Hoc Networks</article-title>,&#x201d; in <conf-name>2nd Workshop on the Economics of Peer-to-Peer Systems</conf-name> (<publisher-name>P2PEcon</publisher-name>). </citation>
</ref>
<ref id="B13">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Bures</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Plasil</surname>
<given-names>F.</given-names>
</name>
<name>
<surname>Kit</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Tuma</surname>
<given-names>P.</given-names>
</name>
<name>
<surname>Hoch</surname>
<given-names>N.</given-names>
</name>
</person-group> (<year>2016</year>). <article-title>Software Abstractions for Component Interaction in the Internet of Things</article-title>. <source>Computer</source> <volume>49</volume>, <fpage>50</fpage>&#x2013;<lpage>59</lpage>. <pub-id pub-id-type="doi">10.1109/mc.2016.377</pub-id> </citation>
</ref>
<ref id="B14">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Casadei</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>Aldini</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Viroli</surname>
<given-names>M.</given-names>
</name>
</person-group> (<year>2018</year>). <article-title>Towards Attack-Resistant Aggregate Computing Using Trust Mechanisms</article-title>. <source>Sci. Comput. Program.</source> <volume>167</volume>, <fpage>114</fpage>&#x2013;<lpage>137</lpage>. <pub-id pub-id-type="doi">10.1016/j.scico.2018.07.006</pub-id> </citation>
</ref>
<ref id="B15">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Chandrasekaran</surname>
<given-names>B.</given-names>
</name>
<name>
<surname>Makkes</surname>
<given-names>M. X.</given-names>
</name>
<name>
<surname>Fechner</surname>
<given-names>J.</given-names>
</name>
</person-group> (<year>2022</year>). &#x201c;<article-title>Calibrating the Performance and Security of Blockchains via Information Propagation Delays</article-title>,&#x201d; in <conf-name>37th ACM/SIGAPP Symposium On Applied Computing - Track on Decentralized Applications with Blockchain, DLT and Crypto-Currencies (ACM)</conf-name>. </citation>
</ref>
<ref id="B16">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Chen</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Forejt</surname>
<given-names>V.</given-names>
</name>
<name>
<surname>Kwiatkowska</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Parker</surname>
<given-names>D.</given-names>
</name>
<name>
<surname>Simaitis</surname>
<given-names>A.</given-names>
</name>
</person-group> (<year>2013</year>). &#x201c;<article-title>PRISM-games: a Model Checker for Stochastic Multi-Player Games</article-title>,&#x201d; in <conf-name>Procs. of the 19th Int. Conf. on Tools and Algorithms for the Construction and Analysis of Systems (TACAS&#x2019;13)</conf-name> (<publisher-name>Springer</publisher-name>). <pub-id pub-id-type="doi">10.1007/978-3-642-36742-7_13</pub-id> </citation>
</ref>
<ref id="B17">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Ciancia</surname>
<given-names>V.</given-names>
</name>
<name>
<surname>Gilmore</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Grilletti</surname>
<given-names>G.</given-names>
</name>
<name>
<surname>Latella</surname>
<given-names>D.</given-names>
</name>
<name>
<surname>Loreti</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Massink</surname>
<given-names>M.</given-names>
</name>
</person-group> (<year>2018</year>). <article-title>Spatio-temporal Model Checking of Vehicular Movement in Public Transport Systems</article-title>. <source>Int. J. Softw. Tools Technol. Transf.</source> <volume>20</volume>, <fpage>289</fpage>&#x2013;<lpage>311</lpage>. <pub-id pub-id-type="doi">10.1007/s10009-018-0483-8</pub-id> </citation>
</ref>
<ref id="B18">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Cimatti</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Clarke</surname>
<given-names>E.</given-names>
</name>
<name>
<surname>Giunchiglia</surname>
<given-names>E.</given-names>
</name>
<name>
<surname>Giunchiglia</surname>
<given-names>F.</given-names>
</name>
<name>
<surname>Pistore</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Roveri</surname>
<given-names>M.</given-names>
</name>
<etal/>
</person-group> (<year>2002</year>). &#x201c;<article-title>Nusmv 2: An Opensource Tool for Symbolic Model Checking</article-title>,&#x201d; in <conf-name>14th Conf. on Computer Aided Verification (LNCS)</conf-name>, <fpage>359</fpage>&#x2013;<lpage>364</lpage>. <pub-id pub-id-type="doi">10.1007/3-540-45657-0_29</pub-id> </citation>
</ref>
<ref id="B19">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Clark</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Gilmore</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Hillston</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Tribastone</surname>
<given-names>M.</given-names>
</name>
</person-group> (<year>2007</year>). &#x201c;<article-title>Stochastic Process Algebras</article-title>,&#x201d; in <conf-name>Formal Methods for Performance Evaluation: 7th International School on Formal Methods for the Design of Computer, Communication, and Software Systems, SFM 2007</conf-name> (<publisher-loc>Bertinoro, Italy</publisher-loc>: <publisher-name>Springer</publisher-name>), <fpage>132</fpage>&#x2013;<lpage>179</lpage>. </citation>
</ref>
<ref id="B20">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Clarke</surname>
<given-names>E. M.</given-names>
</name>
<name>
<surname>Grumberg</surname>
<given-names>O.</given-names>
</name>
<name>
<surname>Peled</surname>
<given-names>D. A.</given-names>
</name>
</person-group> (<year>1999</year>). <source>Model Checking</source>. <publisher-loc>Cambridge, MA</publisher-loc>: <publisher-name>MIT Press</publisher-name>. </citation>
</ref>
<ref id="B21">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Crall</surname>
<given-names>J. D.</given-names>
</name>
<name>
<surname>de Bivort</surname>
<given-names>B. L.</given-names>
</name>
<name>
<surname>Dey</surname>
<given-names>B.</given-names>
</name>
<name>
<surname>Ford Versypt</surname>
<given-names>A. N.</given-names>
</name>
</person-group> (<year>2019</year>). <article-title>Social Buffering of Pesticides in Bumblebees: Agent-Based Modeling of the Effects of Colony Size and Neonicotinoid Exposure on Behavior within Nests</article-title>. <source>Front. Ecol. Evol.</source> <volume>7</volume>, <fpage>51</fpage>. <pub-id pub-id-type="doi">10.3389/fevo.2019.00051</pub-id> </citation>
</ref>
<ref id="B22">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Dai</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Benini</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Lin</surname>
<given-names>H.</given-names>
</name>
<name>
<surname>Antsaklis</surname>
<given-names>P. J.</given-names>
</name>
<name>
<surname>Rutherford</surname>
<given-names>M. J.</given-names>
</name>
<name>
<surname>Valavanis</surname>
<given-names>K. P.</given-names>
</name>
</person-group> (<year>2016</year>). &#x201c;<article-title>Learning-based Formal Synthesis of Cooperative Multi-Agent Systems with an Application to Robotic Coordination</article-title>,&#x201d; in <conf-name>2016 24th Mediterranean Conference on Control and Automation (MED)</conf-name>, <fpage>1008</fpage>&#x2013;<lpage>1013</lpage>. <pub-id pub-id-type="doi">10.1109/med.2016.7536071</pub-id> </citation>
</ref>
<ref id="B23">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>De Nicola</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>Di Stefano</surname>
<given-names>L.</given-names>
</name>
<name>
<surname>Inverso</surname>
<given-names>O.</given-names>
</name>
</person-group> (<year>2018</year>). <article-title>Toward Formal Models and Languages for Verifiable Multi-Robot Systems</article-title>. <source>Front. Robot. AI</source> <volume>5</volume>, <fpage>94</fpage>. <pub-id pub-id-type="doi">10.3389/frobt.2018.00094</pub-id> </citation>
</ref>
<ref id="B24">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>De Nicola</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>J&#xe4;hnichen</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Wirsing</surname>
<given-names>M.</given-names>
</name>
</person-group> (<year>2020</year>). <article-title>Rigorous Engineering of Collective Adaptive Systems: Special Section</article-title>. <source>Int. J. Softw. Tools Technol. Transf.</source> <volume>22</volume>, <fpage>389</fpage>&#x2013;<lpage>397</lpage>. <pub-id pub-id-type="doi">10.1007/s10009-020-00555-2</pub-id> </citation>
</ref>
<ref id="B25">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>De Nicola</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>Latella</surname>
<given-names>D.</given-names>
</name>
<name>
<surname>Lafuente</surname>
<given-names>A. L.</given-names>
</name>
<name>
<surname>Loreti</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Margheri</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Massink</surname>
<given-names>M.</given-names>
</name>
<etal/>
</person-group> (<year>2015</year>). <source>The SCEL Language: Design, Implementation, Verification</source>. <publisher-loc>Cham</publisher-loc>: <publisher-name>Springer</publisher-name>, <fpage>3</fpage>&#x2013;<lpage>71</lpage>. </citation>
</ref>
<ref id="B26">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Fokkink</surname>
<given-names>W.</given-names>
</name>
</person-group> (<year>2007</year>). <source>Introduction to Process Algebra</source>. <publisher-loc>Berlin, Heidelberg</publisher-loc>: <publisher-name>Springer</publisher-name>. </citation>
</ref>
<ref id="B27">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Gabor</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Sedlmeier</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Phan</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Ritz</surname>
<given-names>F.</given-names>
</name>
<name>
<surname>Kiermeier</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Belzner</surname>
<given-names>L.</given-names>
</name>
<etal/>
</person-group> (<year>2020</year>). <article-title>The Scenario Coevolution Paradigm: Adaptive Quality Assurance for Adaptive Systems</article-title>. <source>Int. J. Softw. Tools Technol. Transf.</source> <volume>22</volume>, <fpage>457</fpage>&#x2013;<lpage>476</lpage>. <pub-id pub-id-type="doi">10.1007/s10009-020-00560-5</pub-id> </citation>
</ref>
<ref id="B28">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Gamage</surname>
<given-names>H.</given-names>
</name>
<name>
<surname>Weerasinghe</surname>
<given-names>H.</given-names>
</name>
<name>
<surname>Dias</surname>
<given-names>N.</given-names>
</name>
</person-group> (<year>2020</year>). <article-title>A Survey on Blockchain Technology Concepts, Applications, and Issues</article-title>. <source>SN Comput. Sci.</source> <volume>1</volume>, <fpage>114</fpage>. <pub-id pub-id-type="doi">10.1007/s42979-020-00123-0</pub-id> </citation>
</ref>
<ref id="B29">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Ganeriwal</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Balzano</surname>
<given-names>L. K.</given-names>
</name>
<name>
<surname>Srivastava</surname>
<given-names>M. B.</given-names>
</name>
</person-group> (<year>2008</year>). <article-title>Reputation-based Framework for High Integrity Sensor Networks</article-title>. <source>ACM Trans. Sen. Netw.</source> <volume>4</volume>, <fpage>1</fpage>&#x2013;<lpage>37</lpage>. <pub-id pub-id-type="doi">10.1145/1362542.1362546</pub-id> </citation>
</ref>
<ref id="B30">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Glen</surname>
<given-names>C. M.</given-names>
</name>
<name>
<surname>Kemp</surname>
<given-names>M. L.</given-names>
</name>
<name>
<surname>Voit</surname>
<given-names>E. O.</given-names>
</name>
</person-group> (<year>2019</year>). <article-title>Agent-based Modeling of Morphogenetic Systems: Advantages and Challenges</article-title>. <source>PLoS Comput. Biol.</source> <volume>15</volume>, <fpage>e1006577</fpage>&#x2013;<lpage>31</lpage>. <pub-id pub-id-type="doi">10.1371/journal.pcbi.1006577</pub-id> </citation>
</ref>
<ref id="B31">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Gu</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>Enoiu</surname>
<given-names>E.</given-names>
</name>
<name>
<surname>Seceleanu</surname>
<given-names>C.</given-names>
</name>
<name>
<surname>Lundqvist</surname>
<given-names>K.</given-names>
</name>
</person-group> (<year>2020</year>). &#x201c;<article-title>Probabilistic Mission Planning and Analysis for Multi-Agent Systems</article-title>,&#x201d; in <source>Leveraging Applications of Formal Methods, Verification and Validation: Verification Principles</source>. Editors <person-group person-group-type="editor">
<name>
<surname>Margaria,</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Steffen</surname>
<given-names>B.</given-names>
</name>
</person-group> (<publisher-name>Springer</publisher-name>), <fpage>350</fpage>&#x2013;<lpage>367</lpage>. <pub-id pub-id-type="doi">10.1007/978-3-030-61362-4_20</pub-id> </citation>
</ref>
<ref id="B32">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Hansson</surname>
<given-names>H.</given-names>
</name>
<name>
<surname>Jonsson</surname>
<given-names>B.</given-names>
</name>
</person-group> (<year>1994</year>). <article-title>A Logic for Reasoning about Time and Reliability</article-title>. <source>Form. Asp. Comput.</source> <volume>6</volume>, <fpage>512</fpage>&#x2013;<lpage>535</lpage>. <pub-id pub-id-type="doi">10.1007/bf01211866</pub-id> </citation>
</ref>
<ref id="B33">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Hennicker</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>Klarl</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Iida</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Meseguer</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Ogata</surname>
<given-names>K.</given-names>
</name>
</person-group> (<year>2014</year>). &#x201c;<article-title>Foundations for Ensemble Modeling - the Helena Approach</article-title>,&#x201d; in <source>Specification, Algebra, and Software: Essays Dedicated to Kokichi Futatsugi</source> (<publisher-name>Springer</publisher-name>), <fpage>359</fpage>&#x2013;<lpage>381</lpage>. <pub-id pub-id-type="doi">10.1007/978-3-642-54624-2_18</pub-id> </citation>
</ref>
<ref id="B34">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Hillston</surname>
<given-names>J.</given-names>
</name>
</person-group> (<year>1996</year>). <source>A Compositional Approach to Performance Modelling</source>. <publisher-loc>Cambridge</publisher-loc>: <publisher-name>Cambridge University Press</publisher-name>. </citation>
</ref>
<ref id="B35">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>J&#xf8;sang</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Ismail</surname>
<given-names>R.</given-names>
</name>
</person-group> (<year>2002</year>). &#x201c;<article-title>The Beta Reputation System</article-title>,&#x201d; in <conf-name>15th Bled Conference on Electronic Commerce</conf-name>. </citation>
</ref>
<ref id="B36">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Klarl</surname>
<given-names>A.</given-names>
</name>
</person-group> (<year>2015</year>). &#x201c;<article-title>From Helena Ensemble Specifications to Promela Verification Models</article-title>,&#x201d; in <conf-name>22nd International Symposium on Model Checking Software</conf-name> (<publisher-name>Springer</publisher-name>), <fpage>39</fpage>&#x2013;<lpage>45</lpage>. <pub-id pub-id-type="doi">10.1007/978-3-319-23404-5_4</pub-id> </citation>
</ref>
<ref id="B37">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Kwiatkowska</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Norman</surname>
<given-names>G.</given-names>
</name>
<name>
<surname>Parker</surname>
<given-names>D.</given-names>
</name>
</person-group> (<year>2011</year>). &#x201c;<article-title>PRISM 4.0: Verification of Probabilistic Real-Time Systems</article-title>,&#x201d; in <source>Proc. Of the 23rd Int. Conf. on Computer Aided Verification (CAV&#x2019;11)</source>. Editors <person-group person-group-type="editor">
<name>
<surname>Gopalakrishnan,</surname>
<given-names>G.</given-names>
</name>
<name>
<surname>Qadeer</surname>
<given-names>S.</given-names>
</name>
</person-group> (<publisher-name>Springer</publisher-name>). <pub-id pub-id-type="doi">10.1007/978-3-642-22110-1_47</pub-id> </citation>
</ref>
<ref id="B38">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Lomuscio</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Qu</surname>
<given-names>H.</given-names>
</name>
<name>
<surname>Raimondi</surname>
<given-names>F.</given-names>
</name>
</person-group> (<year>2009</year>). &#x201c;<article-title>Mcmas: A Model Checker for the Verification of Multi-Agent Systems</article-title>,&#x201d; in <source>Computer Aided Verification</source>. Editors <person-group person-group-type="editor">
<name>
<surname>Bouajjani,</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Maler</surname>
<given-names>O.</given-names>
</name>
</person-group> (<publisher-name>Springer</publisher-name>), <fpage>682</fpage>&#x2013;<lpage>688</lpage>. <pub-id pub-id-type="doi">10.1007/978-3-642-02658-4_55</pub-id> </citation>
</ref>
<ref id="B39">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Loreti</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Hillston</surname>
<given-names>J.</given-names>
</name>
</person-group> (<year>2016</year>). &#x201c;<article-title>Modelling and Analysis of Collective Adaptive Systems with CARMA and its Tools</article-title>,&#x201d; in <conf-name>Formal Methods for the Quantitative Evaluation of Collective Adaptive Systems: 16th International School on Formal Methods for the Design of Computer, Communication, and Software Systems, SFM 2016</conf-name> (<publisher-name>Springer</publisher-name>), <fpage>83</fpage>&#x2013;<lpage>119</lpage>. <pub-id pub-id-type="doi">10.1007/978-3-319-34096-8_4</pub-id> </citation>
</ref>
<ref id="B40">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Mehmood</surname>
<given-names>U.</given-names>
</name>
<name>
<surname>Stoller</surname>
<given-names>S. D.</given-names>
</name>
<name>
<surname>Grosu</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>Roy</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Damare</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Smolka</surname>
<given-names>S. A.</given-names>
</name>
</person-group> (<year>2021</year>). &#x201c;<article-title>A Distributed Simplex Architecture for Multi-Agent Systems</article-title>,&#x201d; in <source>Dependable Software Engineering. Theories, Tools, and Applications</source>. Editors <person-group person-group-type="editor">
<name>
<surname>Qin</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Woodcock</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Zhang</surname>
<given-names>W.</given-names>
</name>
</person-group> (<publisher-name>Springer</publisher-name>), <fpage>239</fpage>&#x2013;<lpage>257</lpage>. <pub-id pub-id-type="doi">10.1007/978-3-030-91265-9_13</pub-id> </citation>
</ref>
<ref id="B41">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>De Nicola</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>Maggi</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Sifakis</surname>
<given-names>J.</given-names>
</name>
</person-group> (<year>2020</year>). <article-title>The Dream Framework for Dynamic Reconfigurable Architecture Modelling: Theory and Applications</article-title>. <source>Int. J. Softw. Tools Technol. Transf.</source> <volume>22</volume>, <fpage>437</fpage>&#x2013;<lpage>455</lpage>. </citation>
</ref>
<ref id="B42">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>De Nicola</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>Vaandrager</surname>
<given-names>F.</given-names>
</name>
</person-group> (<year>1990</year>). &#x201c;<article-title>Action versus State Based Logics for Transition Systems</article-title>,&#x201d; in <source>Semantics of Systems of Concurrent Processes</source>. Editor <person-group person-group-type="editor">
<name>
<surname>Guessarian</surname>
<given-names>I.</given-names>
</name>
</person-group> (<publisher-name>Springer</publisher-name>), <fpage>407</fpage>&#x2013;<lpage>419</lpage>. <pub-id pub-id-type="doi">10.1007/3-540-53479-2_17</pub-id> </citation>
</ref>
<ref id="B43">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Ozkaya</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Kloukinas</surname>
<given-names>C.</given-names>
</name>
</person-group> (<year>2013</year>). &#x201c;<article-title>Are We There yet? Analyzing Architecture Description Languages for Formal Analysis, Usability, and Realizability</article-title>,&#x201d; in <conf-name>2013 39th Euromicro Conference on Software Engineering and Advanced Applications</conf-name>, <fpage>177</fpage>&#x2013;<lpage>184</lpage>. <pub-id pub-id-type="doi">10.1109/SEAA.2013.34</pub-id> </citation>
</ref>
<ref id="B44">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Platzer</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Parker</surname>
<given-names>D.</given-names>
</name>
<name>
<surname>Wolf</surname>
<given-names>V.</given-names>
</name>
</person-group> (<year>2019</year>). &#x201c;<article-title>The Logical Path to Autonomous Cyber-Physical Systems</article-title>,&#x201d; in <source>Quantitative Evaluation of Systems</source> (<publisher-name>Springer</publisher-name>), <fpage>25</fpage>&#x2013;<lpage>33</lpage>. <pub-id pub-id-type="doi">10.1007/978-3-030-30281-8_2</pub-id> </citation>
</ref>
<ref id="B45">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Rausch</surname>
<given-names>I.</given-names>
</name>
<name>
<surname>Simoens</surname>
<given-names>P.</given-names>
</name>
<name>
<surname>Khaluf</surname>
<given-names>Y.</given-names>
</name>
</person-group> (<year>2020</year>). <article-title>Adaptive Foraging in Dynamic Environments Using Scale-free Interaction Networks</article-title>. <source>Front. Robot. AI</source> <volume>7</volume>, <fpage>86</fpage>. <pub-id pub-id-type="doi">10.3389/frobt.2020.00086</pub-id> </citation>
</ref>
<ref id="B46">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Romanov</surname>
<given-names>G. P.</given-names>
</name>
<name>
<surname>Smirnova</surname>
<given-names>A. A.</given-names>
</name>
<name>
<surname>Zamyatin</surname>
<given-names>V. I.</given-names>
</name>
<name>
<surname>Mukhin</surname>
<given-names>A. M.</given-names>
</name>
<name>
<surname>Kazantsev</surname>
<given-names>F. V.</given-names>
</name>
<name>
<surname>Pshennikova</surname>
<given-names>V. G.</given-names>
</name>
<etal/>
</person-group> (<year>2022</year>). <article-title>Agent-based Modeling of Autosomal Recessive Deafness 1a (Dfnb1a) Prevalence with Regard to Intensity of Selection Pressure in Isolated Human Population</article-title>. <source>Biol. (Basel)</source> <volume>11</volume>, <fpage>257</fpage>. <pub-id pub-id-type="doi">10.3390/biology11020257</pub-id> </citation>
</ref>
<ref id="B47">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Sekizawa</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Otsuki</surname>
<given-names>F.</given-names>
</name>
<name>
<surname>Ito</surname>
<given-names>K.</given-names>
</name>
<name>
<surname>Okano</surname>
<given-names>K.</given-names>
</name>
</person-group> (<year>2015</year>). &#x201c;<article-title>Behavior Verification of Autonomous Robot Vehicle in Consideration of Errors and Disturbances</article-title>,&#x201d; in <conf-name>2015 IEEE 39th Annual Computer Software and Applications Conference</conf-name>, <fpage>550</fpage>&#x2013;<lpage>555</lpage>. <pub-id pub-id-type="doi">10.1109/compsac.2015.268</pub-id>
<volume>3</volume> </citation>
</ref>
<ref id="B48">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Takano</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Ichinose</surname>
<given-names>G.</given-names>
</name>
</person-group> (<year>2018</year>). <article-title>Evolution of Human-like Social Grooming Strategies Regarding Richness and Group Size</article-title>. <source>Front. Ecol. Evol.</source> <volume>6</volume>, <fpage>8</fpage>. <pub-id pub-id-type="doi">10.3389/fevo.2018.00008</pub-id> </citation>
</ref>
<ref id="B49">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>ter Beek</surname>
<given-names>M. H.</given-names>
</name>
<name>
<surname>Fantechi</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Gnesi</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Mazzanti</surname>
<given-names>F.</given-names>
</name>
</person-group> (<year>2008</year>). &#x201c;<article-title>An Action/state-Based Model-Checking Approach for the Analysis of Communication Protocols for Service-Oriented Applications</article-title>,&#x201d; in <conf-name>12th Workshop on Formal Methods for Industrial Critical Systems (LNCS)</conf-name>, <fpage>133</fpage>&#x2013;<lpage>148</lpage>. <pub-id pub-id-type="doi">10.1007/978-3-540-79707-4_11</pub-id> </citation>
</ref>
<ref id="B50">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Tribastone</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Duguid</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Gilmore</surname>
<given-names>S.</given-names>
</name>
</person-group> (<year>2009</year>). <article-title>The PEPA Eclipse Plugin</article-title>. <source>ACE SIGMETRICS Perform. Eval. Rev.</source> <volume>36</volume>, <fpage>28</fpage>&#x2013;<lpage>33</lpage>. <pub-id pub-id-type="doi">10.1145/1530873.1530880</pub-id> </citation>
</ref>
<ref id="B51">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Van Glabbeek</surname>
<given-names>R. J.</given-names>
</name>
<name>
<surname>Smolka</surname>
<given-names>S. A.</given-names>
</name>
<name>
<surname>Steffen</surname>
<given-names>B.</given-names>
</name>
</person-group> (<year>1995</year>). <article-title>Reactive, Generative, and Stratified Models of Probabilistic Processes</article-title>. <source>Inf. Comput.</source> <volume>121</volume>, <fpage>59</fpage>&#x2013;<lpage>80</lpage>. <pub-id pub-id-type="doi">10.1006/inco.1995.1123</pub-id> </citation>
</ref>
<ref id="B52">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Will</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Groeneveld</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Frank</surname>
<given-names>K.</given-names>
</name>
<name>
<surname>M&#xfc;ller</surname>
<given-names>B.</given-names>
</name>
</person-group> (<year>2020</year>). <article-title>Combining Social Network Analysis and Agent-Based Modelling to Explore Dynamics of Human Interaction: A Review</article-title>. <source>Socio-Environmental Syst. Model.</source> <volume>2</volume>, <fpage>16325</fpage>. <pub-id pub-id-type="doi">10.18174/sesmo.2020a16325</pub-id> </citation>
</ref>
<ref id="B53">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Zhang</surname>
<given-names>Y.</given-names>
</name>
<name>
<surname>Lin</surname>
<given-names>L.</given-names>
</name>
<name>
<surname>Huai</surname>
<given-names>J.</given-names>
</name>
</person-group> (<year>2007</year>). <article-title>Balancing Trust and Incentive in Peer-To-Peer Collaborative System</article-title>. <source>J. Netw. Secur.</source> <volume>5</volume>, <fpage>73</fpage>&#x2013;<lpage>81</lpage>. </citation>
</ref>
</ref-list>
</back>
</article>