Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Databases and Information Systems (234)
- Programming Languages and Compilers (184)
- Engineering (141)
- Artificial Intelligence and Robotics (134)
- Computer Engineering (125)
-
- Information Security (102)
- Graphics and Human Computer Interfaces (77)
- OS and Networks (76)
- Social and Behavioral Sciences (73)
- Numerical Analysis and Scientific Computing (56)
- Theory and Algorithms (45)
- Business (42)
- Computer and Systems Architecture (39)
- Digital Communications and Networking (38)
- Medicine and Health Sciences (31)
- Communication (29)
- Education (28)
- Health Information Technology (19)
- Systems Architecture (19)
- Sociology (18)
- Gerontology (15)
- Finance and Financial Management (14)
- Public Affairs, Public Policy and Public Administration (14)
- Higher Education (13)
- Social Media (12)
- Transportation (12)
- Technology and Innovation (11)
- Keyword
-
- Deep learning (52)
- Software engineering (45)
- Empirical study (43)
- Machine learning (33)
- Model Check (29)
-
- Software (29)
- Android (27)
- Collaboration (26)
- Deep Learning (24)
- Stack Overflow (22)
- GitHub (21)
- Fuzzing (20)
- Testing (19)
- Data mining (18)
- Programming (18)
- Computer bugs (17)
- Large language models (17)
- Security (17)
- Code search (16)
- Codes (16)
- Empirical Study (16)
- Information retrieval (16)
- Large language model (16)
- Large Language Models (15)
- Software Engineering (15)
- Software testing (15)
- Linear Temporal Logic (14)
- Vulnerability detection (14)
- Large Language Model (13)
- Semantics (13)
- Publication Year
Articles 211 - 240 of 2149
Full-Text Articles in Software Engineering
Lr-Auth: Towards Practical Implementation Of Implicit User Authentication On Earbuds, Changshuo Hu, Xiao Ma, Xinger Huang, Yiran Shen, Dong Ma
Lr-Auth: Towards Practical Implementation Of Implicit User Authentication On Earbuds, Changshuo Hu, Xiao Ma, Xinger Huang, Yiran Shen, Dong Ma
Research Collection School Of Computing and Information Systems
The increasing use of earbuds in applications like immersive entertainment and health monitoring necessitates effective implicit user authentication systems to preserve the privacy of sensitive data and provide personalized experiences. Existing approaches, which leverage physiological cues (e.g., jawbone structure) and behavioral cues (e.g., gait), face challenges such as limited usability, high delay and energy overhead, and significant computational demands, rendering them impractical for resource-constrained earbuds. To address these issues, we present LR-Auth, a lightweight, user-friendly implicit authentication system designed for various earbud usage scenarios. LR-Auth utilizes the modulation of sound frequencies by the user's unique occluded ear canal, generating user-specific …
Large Language Models For Software Engineering: A Systematic Literature Review, Xinyi Hou, Yanjie Zhao, Yue Liu, Zhou Yang, Kailong Wang, Li Li, Xiapu Luo, David Lo, John Grundy, Haoyu Wang
Large Language Models For Software Engineering: A Systematic Literature Review, Xinyi Hou, Yanjie Zhao, Yue Liu, Zhou Yang, Kailong Wang, Li Li, Xiapu Luo, David Lo, John Grundy, Haoyu Wang
Research Collection School Of Computing and Information Systems
Large Language Models (LLMs) have significantly impacted numerous domains, including Software Engineering (SE). Many recent publications have explored LLMs applied to various SE tasks. Nevertheless, a comprehensive understanding of the application, effects, and possible limitations of LLMs on SE is still in its early stages. To bridge this gap, we conducted a Systematic Literature Review (SLR) on LLM4SE, with a particular focus on understanding how LLMs can be exploited to optimize processes and outcomes. We selected and analyzed 395 research articles from January 2017 to January 2024 to answer four key Research Questions (RQs). In RQ1, we categorize different LLMs …
Angels Or Demons: Investigating And Detecting Decentralized Financial Traps On Ethereum Smart Contracts, Jiachi Chen, Jiang Hu, Xin Xia, David Lo, John Grundy, Zhipeng Gao, Ting Chen
Angels Or Demons: Investigating And Detecting Decentralized Financial Traps On Ethereum Smart Contracts, Jiachi Chen, Jiang Hu, Xin Xia, David Lo, John Grundy, Zhipeng Gao, Ting Chen
Research Collection School Of Computing and Information Systems
Decentralized Finance (DeFi) uses blockchain technologies to transform traditional financial activities into decentralized platforms that run without intermediaries and centralized institutions. Smart contracts are programs that run on the blockchain, and by utilizing smart contracts, developers can more easily develop DeFi applications. Some key features of smart contracts—self-executed and immutability—ensure the trustworthiness, transparency and efficiency of DeFi applications and have led to a fast-growing DeFi market. However, misbehaving developers can add traps or backdoor code snippets to a smart contract, which are hard for contract users to discover. We call these code snippets in a DeFi smart contract as “DeFi …
Scoping Software Engineering For Ai: The Tse Perspective, Sebastián Uchitel, Marsha Chechik, Massimiliano Di Penta, Bram Adams, Nazareno Aguirre, Gabriele Bavota, Domenico Bianculli, Kelly Blincoe, Ana Cavalcanti, Yvonne Dittrich, Filomena Ferrucci, Rashina Hoda, Liguo Huang, David Lo, Et Al.
Scoping Software Engineering For Ai: The Tse Perspective, Sebastián Uchitel, Marsha Chechik, Massimiliano Di Penta, Bram Adams, Nazareno Aguirre, Gabriele Bavota, Domenico Bianculli, Kelly Blincoe, Ana Cavalcanti, Yvonne Dittrich, Filomena Ferrucci, Rashina Hoda, Liguo Huang, David Lo, Et Al.
Research Collection School Of Computing and Information Systems
In recent years, important advances in Artificial Intelligence (AI), and, in particular, in Machine Learning (ML), including Deep Learning (DL) and Large Language Models (LLMs), have caused a substantial increase of submissions to all Software Engineering (SE) venues (conferences and journals) related to SE with and for AI. They are commonly referred to as AI for SE and SE for AI.
Generative Ai In Software Engineering Must Be Human-Centered: The Copenhagen Manifesto, D. Russo, S. Van Berkel Baltes, Christoph Treude
Generative Ai In Software Engineering Must Be Human-Centered: The Copenhagen Manifesto, D. Russo, S. Van Berkel Baltes, Christoph Treude
Research Collection School Of Computing and Information Systems
The advent of Generative Artificial Intelligence—systems that can produce human-like content such as text, music, visual art, or source code—marks not only a significant leap for Artificial Intelligence (AI) but also a pivotal moment for software practitioners and researchers. The role of software engineering researchers and practitioners in adopting the technologies that shape our world is critical. Historically, the human aspects of developing software have been treated as secondary to more technical innovations. However, the emergence of Generative AI will simultaneously enhance human capabilities while surfacing complex ethical, social, legal, and technical challenges.While primarily aimed at software engineering (SE) researchers …
Documenting Ethical Considerations In Open Source Ai Models, Haoyu Gao, Mansooreh Zahedi, Christoph Treude, Sarita Rosenstock, Marc Cheong
Documenting Ethical Considerations In Open Source Ai Models, Haoyu Gao, Mansooreh Zahedi, Christoph Treude, Sarita Rosenstock, Marc Cheong
Research Collection School Of Computing and Information Systems
Background: The development of AI-enabled software heavily depends on AI model documentation, such as model cards, due to different domain expertise between software engineers and model developers. From an ethical standpoint, AI model documentation conveys critical information on ethical considerations along with mitigation strategies for downstream developers to ensure the delivery of ethically compliant software. However, knowledge on such documentation practice remains scarce. Aims: The objective of our study is to investigate how developers document ethical aspects of open source AI models in practice, aiming at providing recommendations for future documentation endeavours. Method: We selected three sources of documentation on …
A Survey Of Protocol Fuzzing, Xiaohan Zhang, Cen Zhang, Xinghua Li, Zhengjie Du, Bing Mao, Yeting Li, Pan Li
A Survey Of Protocol Fuzzing, Xiaohan Zhang, Cen Zhang, Xinghua Li, Zhengjie Du, Bing Mao, Yeting Li, Pan Li
Research Collection School Of Computing and Information Systems
Communication protocols form the bedrock of our interconnected world, yet vulnerabilities within their implementations pose significant security threats. Recent developments have seen a surge in fuzzing-based research dedicated to uncovering these vulnerabilities within protocol implementations. However, there still lacks a systematic overview of protocol fuzzing for answering the essential questions such as what the unique challenges are, how existing works solve them, and so on. To bridge this gap, we conducted a comprehensive investigation of related works from both academia and industry. Our study includes a detailed summary of the specific challenges in protocol fuzzing and provides a systematic categorization …
An Empirical Study Of Api Misuses Of Data-Centric Libraries, Akalanda Galappaththi, Sarah Nadi, Christoph Treude
An Empirical Study Of Api Misuses Of Data-Centric Libraries, Akalanda Galappaththi, Sarah Nadi, Christoph Treude
Research Collection School Of Computing and Information Systems
Developers rely on third-party library Application Programming Interfaces (APIs) when developing software. However, libraries typically come with assumptions and API usage constraints, whose violation results in API misuse. API misuses may result in crashes or incorrect behavior. Even though API misuse is a well-studied area, a recent study of API misuse of deep learning libraries showed that the nature of these misuses and their symptoms are different from misuses of traditional libraries, and as a result highlighted potential shortcomings of current misuse detection tools. We speculate that these observations may not be limited to deep learning API misuses but may …
An Empirical Study Of Automatic Program Repair Techniques For Injection Vulnerabilities, Tingwei Zhu, Tongtong Xu, Kui Liu, Jiayuan Zhou, Xing Hu, Xin Xia, Tian Zhang, David Lo
An Empirical Study Of Automatic Program Repair Techniques For Injection Vulnerabilities, Tingwei Zhu, Tongtong Xu, Kui Liu, Jiayuan Zhou, Xing Hu, Xin Xia, Tian Zhang, David Lo
Research Collection School Of Computing and Information Systems
Injection vulnerabilities are among the most serious and dangerous security defects, as they can be exploited by attackers to inject malicious inputs and carry out cybercrimes. Timely fixing of injection vulnerabilities is crucial. However, manual repairs of injection vulnerabilities often require specialized knowledge and are prone to errors, posing a challenge and a heavy burden on developers. In recent years, Automated Program Repair (APR) techniques have shown promising momentum in automatically fixing general defects. Yet, there has been no research on how APR techniques perform in repairing injection vulnerabilities. Therefore, in this paper, we conduct an empirical study. We first …
Promise And Peril Of Collaborative Code Generation Models : Balancing Effectiveness And Memorization, Zhi Chen, Lingxiao Jiang
Promise And Peril Of Collaborative Code Generation Models : Balancing Effectiveness And Memorization, Zhi Chen, Lingxiao Jiang
Research Collection School Of Computing and Information Systems
In the rapidly evolving field of machine learning, training models with datasets from various locations and organizations presents significant challenges due to privacy and legal concerns. The exploration of effective collaborative training settings, which are capable of leveraging valuable knowledge from distributed and isolated datasets, is increasingly crucial. This study investigates key factors that impact the effectiveness of collaborative training methods in code next-token prediction, as well as the correctness and utility of the generated code, showing the promise of such methods. Additionally, we evaluate the memorization of different participant training data across various collaborative training settings, including centralized, federated, …
Predicting The Limits: Tailoring Unnoticeable Hand Redirection Offsets In Virtual Reality To Individuals' Perceptual Boundaries, Martin Feick, Kora Persephone Regitz, Lukas Gehrke, André Zenner, Anthony Tang, Tobias Patrick Jungbluth, Maurice Rekrut, Antonio Krüger
Predicting The Limits: Tailoring Unnoticeable Hand Redirection Offsets In Virtual Reality To Individuals' Perceptual Boundaries, Martin Feick, Kora Persephone Regitz, Lukas Gehrke, André Zenner, Anthony Tang, Tobias Patrick Jungbluth, Maurice Rekrut, Antonio Krüger
Research Collection School Of Computing and Information Systems
Many illusion and interaction techniques in Virtual Reality (VR) rely on Hand Redirection (HR), which has proved to be effective as long as the introduced offsets between the position of the real and virtual hand do not noticeably disturb the user experience. Yet calibrating HR offsets is a tedious and time-consuming process involving psychophysical experimentation, and the resulting thresholds are known to be affected by many variables—limiting HR’s practical utility. As a result, there is a clear need for alternative methods that allow tailoring HR to the perceptual boundaries of individual users. We conducted an experiment with 18 participants combining …
Audio Description Customization, Rosiana Natalie, Ruei-Che Chang, Sheshadri Smitha, Anhong Guo, Kotaro Hara
Audio Description Customization, Rosiana Natalie, Ruei-Che Chang, Sheshadri Smitha, Anhong Guo, Kotaro Hara
Research Collection School Of Computing and Information Systems
Blind and low-vision (BLV) people use audio descriptions (ADs) to access videos. However, current ADs are unalterable by end users, thus are incapable of supporting BLV individuals’ potentially diverse needs and preferences. This research investigates if customizing AD could improve how BLV individuals consume videos. We conducted an interview study (Study 1) with fifteen BLV participants, which revealed desires for customizing properties like length, emphasis, speed, voice, format, tone, and language. At the same time, concerns like interruptions and increased interaction load due to customization emerged. To examine AD customization’s effectiveness and tradeoffs, we designed CustomAD, a prototype that enables …
Demystifying And Extracting Fault-Indicating Information From Logs For Failure Diagnosis, Junjie Huang, Zhihan Jiang, Jinyang Liu, Yintong Huo, Jiazhen Gu, Zhuangbin Chen, Cong Feng, Hui Dong, Zengyin Yang, Michael R. Lyu
Demystifying And Extracting Fault-Indicating Information From Logs For Failure Diagnosis, Junjie Huang, Zhihan Jiang, Jinyang Liu, Yintong Huo, Jiazhen Gu, Zhuangbin Chen, Cong Feng, Hui Dong, Zengyin Yang, Michael R. Lyu
Research Collection School Of Computing and Information Systems
Logs are imperative in the maintenance of online service systems, which often encompass important information for effective failure mitigation. While existing anomaly detection methodologies facilitate the identification of anomalous logs within extensive runtime data, manual investigation of log messages by engineers remains essential to comprehend faults, which is labor-intensive and error-prone. Upon examining the log-based troubleshooting practices at CloudA 1, we find that engineers typically prioritize two categories of log information for diagnosis. These include fault-indicating descriptions, which record abnormal system events, and fault-indicating parameters, which specify the associated entities. Motivated by this finding, we propose an approach to automatically …
Stagedvulbert: Multi-Granular Vulnerability Detection With A Novel Pre-Trained Code Model, Yuan Jiang, Yujian Zhang, Xiaohong Su, Christoph Treude, Tiantian Wang
Stagedvulbert: Multi-Granular Vulnerability Detection With A Novel Pre-Trained Code Model, Yuan Jiang, Yujian Zhang, Xiaohong Su, Christoph Treude, Tiantian Wang
Research Collection School Of Computing and Information Systems
The emergence of pre-trained model-based vulnerability detection methods has significantly advanced the field of automated vulnerability detection. However, these methods still face several challenges, such as difficulty in learning effective feature representations of statements for fine-grained predictions and struggling to process overly long code sequences. To address these issues, this study introduces StagedVulBERT, a novel vulnerability detection framework that leverages a pre-trained code language model and employs a coarse-to-fine strategy. The key innovation and contribution of our research lies in the development of the CodeBERT-HLS component within our framework, specialized in hierarchical, layered, and semantic encoding. This component is designed …
Kpiroot: Efficient Monitoring Metric-Based Root Cause Localization In Large-Scale Cloud Systems, Wenwei Gu, Xinying Sun, Jinyang Liu, Yintong Huo, Zhuangbin Chen, Jianping Zhang, Jiazhen Gu, Yongqiang Yang, Michael R. Lyu
Kpiroot: Efficient Monitoring Metric-Based Root Cause Localization In Large-Scale Cloud Systems, Wenwei Gu, Xinying Sun, Jinyang Liu, Yintong Huo, Zhuangbin Chen, Jianping Zhang, Jiazhen Gu, Yongqiang Yang, Michael R. Lyu
Research Collection School Of Computing and Information Systems
To ensure the reliability of cloud systems, their run-time status reflecting the service quality is periodically monitored with monitoring metrics, i.e., KPIs (key performance indicators). When performance issues happen, root cause localization pinpoints the specific KPIs that are responsible for the degradation of overall service quality, facilitating prompt problem diagnosis and resolution. To this end, existing methods generally locate root-cause KPIs by identifying the KPIs that exhibit a similar anomalous trend to the overall service performance. While straightforward, solely relying on the similarity calculation may be ineffective when dealing with cloud systems with complicated interdependent services. Recent deep learning-based methods …
Ocapo: Fine-Grained Occupancy-Aware, Empirically-Driven Pdc Control In Open-Plan, Shared Workspaces, Ravi Anuradha, Dulaj Sanjaya Weerakoon, Archan Misra
Ocapo: Fine-Grained Occupancy-Aware, Empirically-Driven Pdc Control In Open-Plan, Shared Workspaces, Ravi Anuradha, Dulaj Sanjaya Weerakoon, Archan Misra
Research Collection School Of Computing and Information Systems
Passive Displacement Cooling (PDC) is a relatively recent technology gaining attention as a means of significantly reducing building energy consumption overheads, especially in tropical climates. PDC eliminates the use of mechanical fans, instead using chilled-water heat exchangers to perform convective cooling. In this paper, we identify and characterize the impact of several key parameters affecting occupant comfort in a 1000m2 open-floor area (consisting of multiple zones) of a ZEB (Zero Energy Building) deployed with PDC units and tackle the problem of setting the temperature setpoint of the PDC units to assure occupant thermal comfort and yet conserve energy. We tackle …
Foss: Towards Fine-Grained Unknown Class Detection Against The Open-Set Attack Spectrum With Variable Legitimate Traffic, Ziming Zhao, Zhaoxuan Li, Xiaofei Xie, Jiongchi Yu, Fan Zhang, Rui Zhang, Binbin Chen, Xiangyang Luo, Ming Hu, Wenrui Ma
Foss: Towards Fine-Grained Unknown Class Detection Against The Open-Set Attack Spectrum With Variable Legitimate Traffic, Ziming Zhao, Zhaoxuan Li, Xiaofei Xie, Jiongchi Yu, Fan Zhang, Rui Zhang, Binbin Chen, Xiangyang Luo, Ming Hu, Wenrui Ma
Research Collection School Of Computing and Information Systems
Anomaly-based network intrusion detection systems (NIDSs) are essential for ensuring cybersecurity. However, the security communities realize some limitations when they put most existing proposals into practice. The challenges are mainly concerned with (i) fine-grained unknown attack detection and (ii) ever-changing legitimate traffic adaptation. To tackle these problem, we present three key design norms. The core idea is to construct a model to split the data distribution hyperplane and leverage the concept of isolation, as well as advance the incremental model update. We utilize the isolation tree as the backbone to design our model, named FOSS, to echo back three norms. …
Exploring Conversations Between A Practitioner And A Person With Dementia, Kotaro Hara, Rosiana Natalie, Wei Soon Cheong, Jingjing Gu, Qianli Xu
Exploring Conversations Between A Practitioner And A Person With Dementia, Kotaro Hara, Rosiana Natalie, Wei Soon Cheong, Jingjing Gu, Qianli Xu
Research Collection School Of Computing and Information Systems
In social service centers, practitioners engage in conversations with clients with dementia to facilitate their daily activities and provide support when they are distressed. However, the nature of the care demands the practitioner’s active engagement, which becomes difficult to deliver as the number of people who need care expands. Researchers have been investigating the efficacy of developing agents that assume conversational tasks to alleviate this work. To contribute to the future design of agents for caregiving, we collected and analyzed ten conversations between clients with mild dementia and practitioners who provide care. Our analyses of turn-taking dynamics and dialogue acts …
Nigerian Software Engineer Or American Data Scientist? Github Profile Recruitment Bias In Large Language Models, Takashi Nakano, Kazumasa Shimari, Raula Gaikovina Kula, Christoph Treude, Marc Cheong, Kenichi Matsumoto
Nigerian Software Engineer Or American Data Scientist? Github Profile Recruitment Bias In Large Language Models, Takashi Nakano, Kazumasa Shimari, Raula Gaikovina Kula, Christoph Treude, Marc Cheong, Kenichi Matsumoto
Research Collection School Of Computing and Information Systems
Large Language Models (LLMs) have taken the world by storm, demonstrating their ability not only to automate tedious tasks, but also to show some degree of proficiency in completing software engineering tasks. A key concern with LLMs is their “black-box” nature, which obscures their internal workings and could lead to societal biases in their outputs. In the software engineering context, in this early results paper, we empirically explore how well LLMs can automate recruitment tasks for a geographically diverse software team. We use OpenAI's ChatGPT to conduct an initial set of experiments using GitHub User Profiles from four regions to …
Face It Yourselves: An Llm-Based Two-Stage Strategy To Localize Configuration Errors Via Logs, Shiwen Shi, Yintong Huo, Yuxin Su, Yichen Li, Dan Li, Zibin Zheng
Face It Yourselves: An Llm-Based Two-Stage Strategy To Localize Configuration Errors Via Logs, Shiwen Shi, Yintong Huo, Yuxin Su, Yichen Li, Dan Li, Zibin Zheng
Research Collection School Of Computing and Information Systems
Configurable software systems are prone to configuration errors, resulting in significant losses to companies. However, diagnosing these errors is challenging due to the vast and complex configuration space. These errors pose significant challenges for both experienced maintainers and new end-users, particularly those without access to the source code of the software systems. Given that logs are easily accessible to most end-users, we conduct a preliminary study to outline the challenges and opportunities of utilizing logs in localizing configuration errors. Based on the insights gained from the preliminary study, we propose an LLM-based two-stage strategy for end-users to localize the root-cause …
Neuron Sensitivity Guided Test Case Selection, Dong Huang, Qingwen Bu, Yichao Fu, Yuhao Qing, Xiaofei Xie, Junjie Chen, Heming Cui
Neuron Sensitivity Guided Test Case Selection, Dong Huang, Qingwen Bu, Yichao Fu, Yuhao Qing, Xiaofei Xie, Junjie Chen, Heming Cui
Research Collection School Of Computing and Information Systems
Deep Neural Networks (DNNs) have been widely deployed in software to address various tasks (e.g., autonomous driving, medical diagnosis). However, they can also produce incorrect behaviors that result in financial losses and even threaten human safety. To reveal and repair incorrect behaviors in DNNs, developers often collect rich, unlabeled datasets from the natural world and label them to test DNN models. However, properly labeling a large number of datasets is a highly expensive and time-consuming task. To address the above-mentioned problem, we propose NSS, Neuron Sensitivity Guided Test Case Selection, which can reduce the labeling time by selecting valuable test …
Certified Continual Learning For Neural Network Regression, Hong Long Pham, Jun Sun
Certified Continual Learning For Neural Network Regression, Hong Long Pham, Jun Sun
Research Collection School Of Computing and Information Systems
On the one hand, there has been considerable progress on neural network verification in recent years, which makes certifying neural networks a possibility. On the other hand, neural network in practice are often re-trained over time to cope with new data distribution or for solving different tasks (a.k.a. continual learning). Once re-trained, the verified correctness of the neural network is likely broken, particularly in the presence of the phenomenon known as catastrophic forgetting. In this work, we propose an approach called certified continual learning which improves existing continual learning methods by preserving, as long as possible, the established correctness properties …
Quantum Relaxation For Solving Multiple Knapsack Problems, Monit Sharma, Jin Yan, Hoong Chuin Lau, Rudy Raymond
Quantum Relaxation For Solving Multiple Knapsack Problems, Monit Sharma, Jin Yan, Hoong Chuin Lau, Rudy Raymond
Research Collection School Of Computing and Information Systems
Combinatorial problems are a common challenge in business, requiring finding optimal solutions under specified constraints. While significant progress has been made with variational approaches such as QAOA, most problems addressed are unconstrained (such as Max-Cut). In this study, we investigate a hybrid quantum-classical method for constrained optimization problems, particularly those with knapsack constraints that occur frequently in financial and supply chain applications. Our proposed method relies firstly on relaxations to local quantum Hamiltonians, defined through commutative maps. Drawing inspiration from quantum random access code (QRAC) concepts, particularly Quantum Random Access Optimizer (QRAO), we explore QRAO's potential in solving large constrained …
Developer Reactions To Protestware In Open Source Software: The Cases Of Color.Js And Es5.Ext, Youmei Fan, Dong Wang, Supatsara Wattanakriengkrai, Hathaichanok Damrongsiri, Christoph Treude, Hideaki Hata, Raula Gaikovina Kula
Developer Reactions To Protestware In Open Source Software: The Cases Of Color.Js And Es5.Ext, Youmei Fan, Dong Wang, Supatsara Wattanakriengkrai, Hathaichanok Damrongsiri, Christoph Treude, Hideaki Hata, Raula Gaikovina Kula
Research Collection School Of Computing and Information Systems
There is growing concern about maintainers self-sabotaging their work in order to take political or economic stances, a practice referred to as “protestware”. Our objective is to understand the discourse around discussions on such an attack, how it is received by the community, and whether developers respond to the attack in a timely manner. We study two notable protestware cases i.e., colors.js and es5-ext. Results indicate that protestware discussions are spread more quickly on the GitHub platform, while security vulnerabilities are faster on social media. By establishing a taxonomy of protestware discussions, we identify posts that express stances and provide …
Enhancing Multi-Agent System Testing With Diversity-Guided Exploration And Adaptive Critical State Exploitation, Xuyan Ma, Yawen Wang, Junjie Wang, Xiaofei Xie
Enhancing Multi-Agent System Testing With Diversity-Guided Exploration And Adaptive Critical State Exploitation, Xuyan Ma, Yawen Wang, Junjie Wang, Xiaofei Xie
Research Collection School Of Computing and Information Systems
Multi-agent systems (MASs) have achieved remarkable success in multi-robot control, intelligent transportation, and multiplayer games, etc. Thorough testing for MAS is urgently needed to ensure its robustness in the face of constantly changing and unexpected scenarios. Existing methods mainly focus on single-agent system testing and cannot be directly applied to MAS testing due to the complexity of MAS. To our best knowledge, there are fewer studies on MAS testing. While several studies have focused on adversarial attacks on MASs, they primarily target failure detection from an attack perspective, i.e., discovering failure scenarios, while ignoring the diversity of scenarios. In this …
Bugs In Pods: Understanding Bugs In Container Runtime Systems, Jiongchi Yu, Xiaofei Xie, Ceng Zhang, Sen Chen
Bugs In Pods: Understanding Bugs In Container Runtime Systems, Jiongchi Yu, Xiaofei Xie, Ceng Zhang, Sen Chen
Research Collection School Of Computing and Information Systems
Container Runtime Systems (CRSs), which form the foundational infrastructure of container clouds, are critically important due to their impact on the quality of container cloud implementations. However, a comprehensive understanding of the quality issues present in CRS implementations remains lacking. To bridge this gap, we conduct the first comprehensive empirical study of CRS bugs. Specifically, we gather 429 bugs from 8,271 commits across dominant CRS projects, including runc, gvisor, containerd, and cri-o. Through manual analysis, we develop taxonomies of CRS bug symptoms and root causes, comprising 16 and 13 categories, respectively. Furthermore, we evaluate the capability of popular testing approaches, …
How Effective Are They? Exploring Large Language Model Based Fuzz Driver Generation, Cen Zhang, Yaowen Zheng, Mingqiang Bai, Yeting Li, Wei Ma, Xiaofei Xie
How Effective Are They? Exploring Large Language Model Based Fuzz Driver Generation, Cen Zhang, Yaowen Zheng, Mingqiang Bai, Yeting Li, Wei Ma, Xiaofei Xie
Research Collection School Of Computing and Information Systems
Fuzz drivers are essential for library API fuzzing. However, automatically generating fuzz drivers is a complex task, as it demands the creation of high-quality, correct, and robust API usage code. An LLM-based (Large Language Model) approach for generating fuzz drivers is a promising area of research. Unlike traditional program analysis-based generators, this text-based approach is more generalized and capable of harnessing a variety of API usage information, resulting in code that is friendly for human readers. However, there is still a lack of understanding regarding the fundamental issues on this direction, such as its e ectiveness and potential challenges. To …
Granular3d: Delving Into Multi-Granularity 3d Scene Graph Prediction, Kaixiang Huang, Jingru Yang, Jin Wang, Shengfeng He, Zhan Wang, Haiyan He, Qifeng Zhang, Guodong Lu
Granular3d: Delving Into Multi-Granularity 3d Scene Graph Prediction, Kaixiang Huang, Jingru Yang, Jin Wang, Shengfeng He, Zhan Wang, Haiyan He, Qifeng Zhang, Guodong Lu
Research Collection School Of Computing and Information Systems
This paper addresses the significant challenges in 3D Semantic Scene Graph (3DSSG) prediction, essential for understanding complex 3D environments. Traditional approaches, primarily using PointNet and Graph Convolutional Networks, struggle with effectively extracting multi-grained features from intricate 3D scenes, largely due to a focus on global scene processing and single-scale feature extraction. To overcome these limitations, we introduce Granular3D, a novel approach that shifts the focus towards multi-granularity analysis by predicting relation triplets from specific sub-scenes. One key is the Adaptive Instance Enveloping Method (AIEM), which establishes an approximate envelope structure around irregular instances, providing shape-adaptive local point cloud sampling, thereby …
An Empirical Study Of Static Analysis Tools For Secure Code Review, Wachiraphan Charoenwet, Patanamon Thongtanunam, Van-Thuan Pham, Christoph Treude
An Empirical Study Of Static Analysis Tools For Secure Code Review, Wachiraphan Charoenwet, Patanamon Thongtanunam, Van-Thuan Pham, Christoph Treude
Research Collection School Of Computing and Information Systems
Early identification of security issues in software development is vital to minimize their unanticipated impacts. Code review is a widely used manual analysis method that aims to uncover security issues along with other coding issues in software projects. While some studies suggest that automated static application security testing tools (SASTs) could enhance security issue identification, there is limited understanding of SAST’s practical effectiveness in supporting secure code review. Moreover, most SAST studies rely on synthetic or fully vulnerable versions of the subject program, which may not accurately represent real-world code changes in the code review process. To address this gap, …
Meta-Learning For Multi-Family Android Malware Classification, Yao Li, Dawei Yuan, Tao Zhang, Haipeng Cai, David Lo, Cuiyun Gao, Xiapu Luo, He Jiang
Meta-Learning For Multi-Family Android Malware Classification, Yao Li, Dawei Yuan, Tao Zhang, Haipeng Cai, David Lo, Cuiyun Gao, Xiapu Luo, He Jiang
Research Collection School Of Computing and Information Systems
With the emergence of smartphones, Android has become a widely used mobile operating system. However, it is vulnerable when encountering various types of attacks. Every day, new malware threatens the security of users' devices and private data. Many methods have been proposed to classify malicious applications, utilizing static or dynamic analysis for classification. However, previous methods still suffer from unsatisfactory performance due to two challenges. First, they are unable to address the imbalanced data distribution problem, leading to poor performance for malware families with few members. Second, they are unable to address the zero-day malware (zero-day malware refers to malicious …