Skip to content

Author

António Gonçalves

3 papers indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Open access 2026

Systems-of-Systems: Engineering or Construct?

The concept of Systems-of-Systems (SoS) has become increasingly important across domains such as engineering, defence, healthcare, and digital infrastructure, describing complex assemblies of independent systems that collectively deliver capabilities beyond individual components. However, the concept remains debated: are SoS objective engineering entities or “constructs” used to interpret socio-technical complexity? Having its origins in the context of systems engineering and defence acquisition, SoS are defined by its operational and managerial independence, evolutionary development, and emergent behaviour. While these traits distinguish SoS from supersystems, they also reflect how complexity is framed. Two main perspectives are examined. The engineering perspective treats SoS as designable and controllable entities, emphasizing architecture, standards, governance, and lifecycle management approaches. Here, the challenge is extending traditional engineering methods to address scale, decentralization, and emergence. In contrast, the constructivist perspective sees SoS as interpretive frameworks for understanding loosely coupled, evolving systems shaped by organizational and social contexts. In this view, system boundaries, purposes, and identities are fluid and negotiated. Each perspective has implications. Engineering approaches support structure and measurable performance but may overlook human and political dynamics. Constructivist approaches highlight power, incentives, and adaptation but offer less practical design guidance. The paper argues that real-world SoS embody both views, combining engineered structures with emergent, socially shaped dynamics. It proposes a synthesized perspective that understands SoS as socio-technical phenomena—partly designed and partly constructed. This dual view suggests that effective SoS design and management require integrating engineering practices with insights from organizational theory, complexity science, and systems thinking.

Pedro B. Água, A. Correia, António Gonçalves · 0 citations
Conference Jul 2026

Audit-Ready XAI Engineering via Evidence Bundles and Trace-Link Validation

Auditability in high-risk AI requires more than explanation narratives: reviewers must be able to retrieve and verify decision-bound evidence, including the decision record, model/configuration state, explanation artefact, and audit-log event. We propose a lightweight engineering pattern for auditready Explainable AI (XAI) that (i) packages each decision into a compact evidence bundle, (ii) exposes resolvable trace-links to an evidence store, and (iii) validates structural audit readiness through objective, tool-agnostic checks. The check suite covers both run- and decision-level properties, such as evidence presence, bundle completeness, decision coverage, pinning/provenance coverage, trace-link resolution, and audit-log soundness, and can be layered on top of standard Machine Learning Operations (MLOps) tooling. We demonstrate feasibility on a reproducible mini-case (seed-controlled synthetic intrusion detection system (IDS) anomaly detection) and show how the checks support fast localisation of common audit gaps, including missing bindings, stale links, inconsistent pins, and auditor role-based access control (RBAC) resolution failures. In an audited scope of $N=30$ decisions, all required artefacts were present and independently retrievable under an auditor-equivalent access profile, enabling verifiable navigation from decisions to evidence.

António Gonçalves, J. Ameixa, A. Correia · 0 citations
Conference Jul 2026

State of the Art in Critical Infrastructure Protection and Resilience in Portugal: Governance, Incidents, and Gaps

Portugal is expanding its portfolio of recognized critical infrastructures from approximately 150 to more than 400 entities across twelve strategic sectors, reflecting increasing cross-sector interdependence and exposure to hybrid disruptions. Critical infrastructure governance is coordinated by the National Security Office and the National Cybersecurity Center and has been reinforced since 2024 through the establishment of the National Unit for the Protection of Critical Entities. Despite these advances, persistent challenges remain, including fragmented institutional mandates, uneven integration of cyber and physical resilience practices, skills shortages, and dependence on external technological providers. This paper examines how Portugal's critical infrastructure protection and resilience governance is evolving in response to the European Critical Entities Resilience (CER) and NIS2 frameworks. Its novelty lies in combining legal-institutional analysis, incident-based cross-case comparison, and a resilienceassurance framework tailored to CER/NIS2-aligned governance assessment. The study applies a structured review of legal instruments, national strategies, regulatory publications, and publicly documented incidents between 2011 and 2026 in order to synthesize sectoral scope, governance roles, disruption patterns, and assurance gaps across sectors. Findings highlight three recurring governance weaknesses: fragmented institutional coordination, incomplete cyber-physical integration in resilience practices, and the absence of comparable resilience metrics and assurance artifacts. The paper contributes a compact analytical synthesis of Portugal's critical infrastructure governance and proposes a minimal roadmap and assuranceoriented framework to support CER/NIS2-aligned resilience evaluation and continuous improvement.

P. A. P. Costa, António Gonçalves, M. Marques · 0 citations