Open Access. Powered by Scholars. Published by Universities.®

Software Engineering Commons™

Open Access. Powered by Scholars. Published by Universities.®

Research Collection School Of Computing and Information Systems

Discipline
Keyword
Publication Year

Articles 541 - 570 of 2149

Full-Text Articles in Software Engineering

Does This Apply To Me? An Empirical Study Of Technical Context In Stack Overflow, Akalanka Galappaththi, Sarah Nadi, Christoph Treude May 2022

Does This Apply To Me? An Empirical Study Of Technical Context In Stack Overflow, Akalanka Galappaththi, Sarah Nadi, Christoph Treude

Research Collection School Of Computing and Information Systems

Stack Overflow has become an essential technical resource for developers. However, given the vast amount of knowledge available on Stack Overflow, finding the right information that is relevant for a given task is still challenging, especially when a developer is looking for a solution that applies to their specific requirements or technology stack. Clearly marking answers with their technical context, i.e., the information that characterizes the technologies and assumptions needed for this answer, is potentially one way to improve navigation. However, there is no information about how often such context is mentioned, and what kind of information it might offer. …


Probabilistic Path Prioritization For Hybrid Fuzzing, Lei Zhao, Pengcheng Cao, Yue Duan, Heng Yin, Jifeng Xuan May 2022

Probabilistic Path Prioritization For Hybrid Fuzzing, Lei Zhao, Pengcheng Cao, Yue Duan, Heng Yin, Jifeng Xuan

Research Collection School Of Computing and Information Systems

Hybrid fuzzing that combines fuzzing and concolic execution has become an advanced technique for software vulnerability detection. Based on the observation that fuzzing and concolic execution are complementary in nature, state-of-the-art hybrid fuzzing systems deploy “optimal concolic testing” and “demand launch” strategies. Although these ideas sound intriguing, we point out several fundamental limitations in them, due to unrealistic or oversimplified assumptions. Further, we propose a novel “discriminative dispatch” strategy and design a probabilistic hybrid fuzzing system to better utilize the capability of concolic execution. Specifically, we design a Monte Carlo-based probabilistic path prioritization model to quantify each path’s difficulty, and …


Graphcode2vec: Generic Code Embedding Via Lexical And Program Dependence Analyses, Wei Ma, Mengjie Zhao, Ezekiel Soremekun, Qiang Hu, Jie M. Zhang, Mike Papadakis, Maxime Cordy, Xiaofei Xie, Yves Le Traon May 2022

Graphcode2vec: Generic Code Embedding Via Lexical And Program Dependence Analyses, Wei Ma, Mengjie Zhao, Ezekiel Soremekun, Qiang Hu, Jie M. Zhang, Mike Papadakis, Maxime Cordy, Xiaofei Xie, Yves Le Traon

Research Collection School Of Computing and Information Systems

Code embedding is a keystone in the application of machine learning on several Software Engineering (SE) tasks. To effectively support a plethora of SE tasks, the embedding needs to capture program syntax and semantics in a way that is generic. To this end, we propose the first self-supervised pre-training approach (called Graphcode2vec) which produces task-agnostic embedding of lexical and program dependence features. Graphcode2vec achieves this via a synergistic combination of code analysis and Graph Neural Networks. Graphcode2vec is generic, it allows pre-training, and it is applicable to several SE downstream tasks. We evaluate the effectiveness of Graphcode2vec on four (4) …


Causality-Based Neural Network Repair, Bing Sun, Jun Sun, Long H. Pham, Jie Shi May 2022

Causality-Based Neural Network Repair, Bing Sun, Jun Sun, Long H. Pham, Jie Shi

Research Collection School Of Computing and Information Systems

Neural networks have had discernible achievements in a wide range of applications. The wide-spread adoption also raises the concern of their dependability and reliability. Similar to traditional decision-making programs, neural networks can have defects that need to be repaired. The defects may cause unsafe behaviors, raise security concerns or unjust societal impacts. In this work, we address the problem of repairing a neural network for desirable properties such as fairness and the absence of backdoor. The goal is to construct a neural network that satisfies the property by (minimally) adjusting the given neural network's parameters (i.e., weights). Specifically, we propose …


Uipdroid: Unrooted Dynamic Monitor Of Android App Uis For Fine-Grained Permission Control, Mulin Duan, Lingxiao Jiang, Lwin Khin Shar, Debin Gao May 2022

Uipdroid: Unrooted Dynamic Monitor Of Android App Uis For Fine-Grained Permission Control, Mulin Duan, Lingxiao Jiang, Lwin Khin Shar, Debin Gao

Research Collection School Of Computing and Information Systems

Proper permission controls in Android systems are important for protecting users' private data when running applications installed on the devices. Currently Android systems require apps to obtain authorization from users at the first time when they try to access users' sensitive data, but every permission is only managed at the application level, allowing apps to (mis)use permissions granted by users at the beginning for different purposes subsequently without informing users. Based on privacy-by-design principles, this paper develops a new permission manager, named UIPDroid, that (1) enforces the users' basic right-to-know through user interfaces whenever an app uses permissions, and (2) …


Feasibility Studies In Indoor Localization Through Intelligent Conversation, Sheshadri Smitha, Linus Cheng, Kotaro Hara May 2022

Feasibility Studies In Indoor Localization Through Intelligent Conversation, Sheshadri Smitha, Linus Cheng, Kotaro Hara

Research Collection School Of Computing and Information Systems

We propose a model to achieve human localization in indoor environments through intelligent conversation between users and an agent. We investigated the feasibility of conversational localization by conducting two studies. First, we conducted a Wizard-of-Oz study with N = 7 participants and studied the feasibility of localizing users through conversation. We identified challenges posed by users’ language and behavior. Second, we collected N = 800 user descriptions of virtual indoor locations from N = 80 Amazon Mechanical Turk participants to analyze user language. We explored the effects of conversational agent behavior and observed that people describe indoor locations differently based …


Benchmarking Library Recognition In Tweets, Ting Zhang, Divya Prabha Chandrasekaran, Ferdian Thung, David Lo May 2022

Benchmarking Library Recognition In Tweets, Ting Zhang, Divya Prabha Chandrasekaran, Ferdian Thung, David Lo

Research Collection School Of Computing and Information Systems

Software developers often use social media (such as Twitter) to shareprogramming knowledge such as new tools, sample code snippets,and tips on programming. One of the topics they talk about is thesoftware library. The tweets may contain useful information abouta library. A good understanding of this information, e.g., on thedeveloper’s views regarding a library can be beneficial to weigh thepros and cons of using the library as well as the general sentimentstowards the library. However, it is not trivial to recognize whethera word actually refers to a library or other meanings. For example,a tweet mentioning the word “pandas" may refer to …


Xai4fl: Enhancing Spectrum-Based Fault Localization With Explainable Artificial Intelligence, Ratnadira Widyasari, Gede Artha Azriadi Prana, Stefanus Agus Haryono, Yuan Tian, Hafil Noer Zachiary, David Lo May 2022

Xai4fl: Enhancing Spectrum-Based Fault Localization With Explainable Artificial Intelligence, Ratnadira Widyasari, Gede Artha Azriadi Prana, Stefanus Agus Haryono, Yuan Tian, Hafil Noer Zachiary, David Lo

Research Collection School Of Computing and Information Systems

Manually finding the program unit (e.g., class, method, or statement) responsible for a fault is tedious and time-consuming. To mitigate this problem, many fault localization techniques have been proposed. A popular family of such techniques is spectrum-based fault localization (SBFL), which takes program execution traces (spectra) of failed and passed test cases as input and applies a ranking formula to compute a suspiciousness score for each program unit. However, most existing SBFL techniques fail to consider two facts: 1) not all failed test cases contribute equally to a considered fault(s), and 2) program units collaboratively contribute to the failure/pass of …


On The Effectiveness Of Pretrained Models For Api Learning, Mohammad Abdul Hadi, Imam Nur Bani Yusuf, Thung Ferdian, Gia Kien Luong, Lingxiao Jiang, Fatemeh H. Fard, David Lo May 2022

On The Effectiveness Of Pretrained Models For Api Learning, Mohammad Abdul Hadi, Imam Nur Bani Yusuf, Thung Ferdian, Gia Kien Luong, Lingxiao Jiang, Fatemeh H. Fard, David Lo

Research Collection School Of Computing and Information Systems

Developers frequently use APIs to implement certain functionalities, such as parsing Excel Files, reading and writing text files line by line, etc. Developers can greatly benefit from automatic API usage sequence generation based on natural language queries for building applications in a faster and cleaner manner. Existing approaches utilize information retrieval models to search for matching API sequences given a query or use RNN-based encoder-decoder to generate API sequences. As it stands, the first approach treats queries and API names as bags of words. It lacks deep comprehension of the semantics of the queries. The latter approach adapts a neural …


Ptm4tag: Sharpening Tag Recommendation Of Stack Overflow Posts With Pre-Trained Models, Junda He, Bowen Xu, Zhou Yang, Donggyun Han, Chengran Yang, David Lo May 2022

Ptm4tag: Sharpening Tag Recommendation Of Stack Overflow Posts With Pre-Trained Models, Junda He, Bowen Xu, Zhou Yang, Donggyun Han, Chengran Yang, David Lo

Research Collection School Of Computing and Information Systems

Stack Overflow is often viewed as one of the most influential Software Question & Answer (SQA) websites, containing millions of programming-related questions and answers. Tags play a critical role in efficiently structuring the contents in Stack Overflow and are vital to support a range of site operations, e.g., querying relevant contents. Poorly selected tags often introduce extra noise and redundancy, which raises problems like tag synonym and tag explosion. Thus, an automated tag recommendation technique that can accurately recommend high-quality tags is desired to alleviate the problems mentioned above.


Exais: Executable Ai Semantics, Richard Schumi, Jun Sun May 2022

Exais: Executable Ai Semantics, Richard Schumi, Jun Sun

Research Collection School Of Computing and Information Systems

Neural networks can be regarded as a new programming paradigm, i.e., instead of building ever-more complex programs through (often informal) logical reasoning in the programmers' mind, complex 'AI' systems are built by optimising generic neural network models with big data. In this new paradigm, AI frameworks such as TensorFlow and PyTorch play a key role, which is as essential as the compiler for traditional programs. It is known that the lack of a proper semantics for programming languages (such as C), i.e., a correctness specification for compilers, has contributed to many problematic program behaviours and security issues. While it is …


Devops Education: An Interview Study Of Challenges And Recommendations, Marcelo Fernandes, Samuel Ferino, Anny K. Fernandes, Uirá Kulesza, Eduardo Aranha, Christoph Treude May 2022

Devops Education: An Interview Study Of Challenges And Recommendations, Marcelo Fernandes, Samuel Ferino, Anny K. Fernandes, Uirá Kulesza, Eduardo Aranha, Christoph Treude

Research Collection School Of Computing and Information Systems

Over the last years, the software industry has adopted several DevOps technologies related to practices such as continuous integration and continuous delivery. The high demand for DevOps practitioners requires non-trivial adjustments in traditional software engineering courses and educational methodologies. This work presents an interview study with 14 DevOps educators from different universities and countries, aiming to identify the main challenges and recommendations for DevOps teaching. Our study identified 83 challenges, 185 recommendations, and several association links and conflicts between them. Our findings can help educators plan, execute and evaluate DevOps courses. They also highlight several opportunities for researchers to propose …


Github Sponsors: Exploring A New Way To Contribute To Open Source, Naomichi Shimada, Tao Xiao, Hideaki Hata, Christoph Treude, Kenichi Matsumoto May 2022

Github Sponsors: Exploring A New Way To Contribute To Open Source, Naomichi Shimada, Tao Xiao, Hideaki Hata, Christoph Treude, Kenichi Matsumoto

Research Collection School Of Computing and Information Systems

GitHub Sponsors, launched in 2019, enables donations to individual open source software (OSS) developers. Financial support for OSS maintainers and developers is a major issue in terms of sustaining OSS projects, and the ability to donate to individuals is expected to support the sustainability of developers, projects, and community. In this work, we conducted a mixed-methods study of GitHub Sponsors, including quantitative and qualitative analyses, to understand the characteristics of developers who are likely to receive donations and what developers think about donations to individuals. We found that: (1) sponsored developers are more active than non-sponsored developers, (2) the possibility …


Is Surprisal In Issue Trackers Actionable?, James Caddy, Markus Wagner, Christoph Treude, Earl T. Barr, Miltiadis Allamanis May 2022

Is Surprisal In Issue Trackers Actionable?, James Caddy, Markus Wagner, Christoph Treude, Earl T. Barr, Miltiadis Allamanis

Research Collection School Of Computing and Information Systems

Background. From information theory, surprisal is a measurement of how unexpected an event is. Statistical language models provide a probabilistic approximation of natural languages, and because surprisal is constructed with the probability of an event occuring, it is therefore possible to determine the surprisal associated with English sentences. The issues and pull requests of software repository issue trackers give insight into the development process and likely contain the surprising events of this process. Objective. Prior works have identified that unusual events in software repositories are of interest to developers, and use simple code metrics-based methods for detecting them. In this …


Message From The Nier Chairs Of Icse 2022, Liliana Pasquale, Christoph Treude May 2022

Message From The Nier Chairs Of Icse 2022, Liliana Pasquale, Christoph Treude

Research Collection School Of Computing and Information Systems

It is our honour to welcome you to the ICSE 2022 Track on New Ideas and Emerging results (NIER). NIER is a vibrant forum for forward-looking, innovative research in software engineering. Our aim is to accelerate the exposure of the software engineering community to early yet potentially ground-breaking research results, and to techniques and perspectives that challenge the status quo in the discipline. As also proposed in previous editions of the track, we solicited two types of papers: forward-looking ideas, and thoughtprovoking reflections.


Active Warden Attack: On The (In)Effectiveness Of Android App Repackage-Proofing, Haoyu Ma, Shijia Li, Debin Gao, Daoyuan Wu, Qiaowen Jia, Chunfu Jia May 2022

Active Warden Attack: On The (In)Effectiveness Of Android App Repackage-Proofing, Haoyu Ma, Shijia Li, Debin Gao, Daoyuan Wu, Qiaowen Jia, Chunfu Jia

Research Collection School Of Computing and Information Systems

App repackaging has raised serious concerns to the Android ecosystem with the repackage-proofing technology attracting attention in the Android research community. In this paper, we first show that existing repackage-proofing schemes rely on a flawed security assumption, and then propose a new class of active warden attack that intercepts and falsifies the metrics used by repackage-proofing for detecting the integrity violations during repackaging. We develop a proof-of-concept toolkit to demonstrate that all the existing repackage-proofing schemes can be bypassed by our attack toolkit. On the positive side, our analysis further identifies a new integrity metric in the Android ART runtime …


Who Are The 'Silent Spreaders'?: Contact Tracing In Spatio-Temporal Memory Models, Yue Hu, Budhitama Subagdja, Ah-Hwee Tan, Chai Quek, Quanjun Yin May 2022

Who Are The 'Silent Spreaders'?: Contact Tracing In Spatio-Temporal Memory Models, Yue Hu, Budhitama Subagdja, Ah-Hwee Tan, Chai Quek, Quanjun Yin

Research Collection School Of Computing and Information Systems

The COVID-19 epidemic has swept the world for over two years. However, a large number of infectious asymptomatic COVID-19 cases (ACCs) are still making the breaking up of the transmission chains very difficult. Efforts by epidemiological researchers in many countries have thrown light on the clinical features of ACCs, but there is still a lack of practical approaches to detect ACCs so as to help contain the pandemic. To address the issue of ACCs, this paper presents a neural network model called Spatio-Temporal Episodic Memory for COVID-19 (STEM-COVID) to identify ACCs from contact tracing data. Based on the fusion Adaptive …


Quid Pro Quo: An Exploration Of Reciprocity In Code Review, Carlos Gavidia-Calderon, Donggyun Han, Amel Bennaceur May 2022

Quid Pro Quo: An Exploration Of Reciprocity In Code Review, Carlos Gavidia-Calderon, Donggyun Han, Amel Bennaceur

Research Collection School Of Computing and Information Systems

We explore the role of reciprocity in code review processes. Reciprocity manifests itself in two ways: 1) reviewing code for others translates to accepted code contributions, and 2) having contributions accepted increases the reviews made for others. We use vector autoregressive (VAR) models to explore the causal relation between reviews performed and accepted contributions. After fitting VAR models for 24 active open-source developers, we found evidence of reciprocity in 6 of them. These results suggest reciprocity does play a role in code review, that can potentially be exploited to increase reviewer participation.


Gdefects4dl: A Dataset Of General Real-World Deep Learning Program Defects, Yunkai Liang, Yun Lin, Xuezhi Song, Jun Sun, Zhiyong Feng, Jin Song Dong May 2022

Gdefects4dl: A Dataset Of General Real-World Deep Learning Program Defects, Yunkai Liang, Yun Lin, Xuezhi Song, Jun Sun, Zhiyong Feng, Jin Song Dong

Research Collection School Of Computing and Information Systems

The development of deep learning programs, as a new programming paradigm, is observed to suffer from various defects. Emerging research works have been proposed to detect, debug, and repair deep learning bugs, which drive the need to construct the bug benchmarks. In this work, we present gDefects4DL, a dataset for general bugs of deep learning programs. Comparing to existing datasets, gDefects4DL collects bugs where the root causes and fix solutions can be well generalized to other projects. Our general bugs include deep learning program bugs such as (1) violation of deep learning API usage pattern (e.g., the standard to implement …


On Recruiting Experienced Github Contributors For Interviews And Surveys On Prolific, Felipe Ebert, Alexander Serebrenik, Christoph Treude, Nicole Novielli, Fernando Castor May 2022

On Recruiting Experienced Github Contributors For Interviews And Surveys On Prolific, Felipe Ebert, Alexander Serebrenik, Christoph Treude, Nicole Novielli, Fernando Castor

Research Collection School Of Computing and Information Systems

Software engineering researchers have been using general purpose online tools for crowd-sourcing for quite some time. Those tools can be useful to recruit participants for research studies as they are paid for their time. However, those tools should be used carefully. In this paper, we have described the issues we faced when recruiting participants on Prolific. We used Prolific to recruit open-source developers with experience in submitting and reviewing pull requests (PRs). However, we did not succeed in obtaining valid participants for either the interview or the survey, which led us to change the approach of our study and not …


Unified Route Planning For Shared Mobility: An Insertion-Based Framework, Yongxin Tong, Yuxiang Zeng, Zimu Zhou, Lei Chen, Ke. Xu May 2022

Unified Route Planning For Shared Mobility: An Insertion-Based Framework, Yongxin Tong, Yuxiang Zeng, Zimu Zhou, Lei Chen, Ke. Xu

Research Collection School Of Computing and Information Systems

There has been a dramatic growth of shared mobility applications such as ride-sharing, food delivery, and crowdsourced parcel delivery. Shared mobility refers to transportation services that are shared among users, where a central issue is route planning. Given a set of workers and requests, route planning finds for each worker a route, i.e., a sequence of locations to pick up and drop off passengers/parcels that arrive from time to time, with different optimization objectives. Previous studies lack practicability due to their conflicted objectives and inefficiency in inserting a new request into a route, a basic operation called insertion. In addition, …


Understanding Crowdsourcing Requesters’ Wage Setting Behaviors, Kotaro Hara, Yudai Tanaka May 2022

Understanding Crowdsourcing Requesters’ Wage Setting Behaviors, Kotaro Hara, Yudai Tanaka

Research Collection School Of Computing and Information Systems

Requesters on crowdsourcing platforms like Amazon Mechanical Turk (AMT) compensate workers inadequately. One potential reason for the underpayment is that the AMT’s requester interface provides limited information about estimated wages, preventing requesters from knowing if they are offering a fair piece-rate reward. To assess if presenting wage information affects requesters’ reward setting behaviors, we conducted a controlled study with 63 participants. We had three levels for a between-subjects factor in a mixed design study, where we provided participants with: no wage information, wage point estimate, and wage distribution. Each participant had three stages of adjusting the reward and controlling the …


Chatbot4qr: Interactive Query Refinement For Technical Question Retrieval, Neng Zhang, Qiao Huang, Xin Xia, Ying Zou, David Lo, Zhenchang Xing Apr 2022

Chatbot4qr: Interactive Query Refinement For Technical Question Retrieval, Neng Zhang, Qiao Huang, Xin Xia, Ying Zou, David Lo, Zhenchang Xing

Research Collection School Of Computing and Information Systems

Technical Q&A sites (e.g., Stack Overflow(SO)) are important resources for developers to search for knowledge about technical problems. Search engines provided in Q&A sites and information retrieval approaches have limited capabilities to retrieve relevant questions when queries are imprecisely specified, such as missing important technical details (e.g., the user's preferred programming languages). Although many automatic query expansion approaches have been proposed to improve the quality of queries by expanding queries with relevant terms, the information missed is not identified. Moreover, without user involvement, the existing query expansion approaches may introduce unexpected terms and lead to undesired results. In this paper, …


Comai: Enabling Lightweight, Collaborative Intelligence By Retrofitting Vision Dnns, Kasthuri Jayarajah, Dhanuja Wanniarachchige, Tarek Abdelzaher, Archan Misra Apr 2022

Comai: Enabling Lightweight, Collaborative Intelligence By Retrofitting Vision Dnns, Kasthuri Jayarajah, Dhanuja Wanniarachchige, Tarek Abdelzaher, Archan Misra

Research Collection School Of Computing and Information Systems

While Deep Neural Network (DNN) models have transformed machine vision capabilities, their extremely high computational complexity and model sizes present a formidable deployment roadblock for AIoT applications. We show that the complexity-vs-accuracy-vs-communication tradeoffs for such DNN models can be significantly addressed via a novel, lightweight form of “collaborative machine intelligence” that requires only runtime changes to the inference process. In our proposed approach, called ComAI, the DNN pipelines of different vision sensors share intermediate processing state with one another, effectively providing hints about objects located within their mutually-overlapping Field-of-Views (FoVs). CoMAI uses two novel techniques: (a) a secondary shallow ML …


Data Source Selection In Federated Learning: A Submodular Optimization Approach, Ruisheng Zhang, Yansheng Wang, Zimu Zhou, Ziyao Ren, Yongxin Tong, Ke Xu Apr 2022

Data Source Selection In Federated Learning: A Submodular Optimization Approach, Ruisheng Zhang, Yansheng Wang, Zimu Zhou, Ziyao Ren, Yongxin Tong, Ke Xu

Research Collection School Of Computing and Information Systems

Federated learning is a new learning paradigm that jointly trains a model from multiple data sources without sharing raw data. For the practical deployment of federated learning, data source selection is compulsory due to the limited communication cost and budget in real-world applications. The necessity of data source selection is further amplified in presence of data heterogeneity among clients. Prior solutions are either low in efficiency with exponential time cost or lack theoretical guarantees. Inspired by the diminishing marginal accuracy phenomenon in federated learning, we study the problem from the perspective of submodular optimization. In this paper, we aim at …


Mrim: Enabling Mixed-Resolution Imaging For Low-Power Pervasive Vision Tasks, Jiyan Wu, Vithurson Subasharan, Tuan Tran, Archan Misra Mar 2022

Mrim: Enabling Mixed-Resolution Imaging For Low-Power Pervasive Vision Tasks, Jiyan Wu, Vithurson Subasharan, Tuan Tran, Archan Misra

Research Collection School Of Computing and Information Systems

While many pervasive computing applications increasingly utilize real-time context extracted from a vision sensing infrastructure, the high energy overhead of DNN-based vision sensing pipelines remains a challenge for sustainable in-the-wild deployment. One common approach to reducing such energy overheads is the capture and transmission of lower-resolution images to an edge node (where the DNN inferencing task is executed), but this results in an accuracy-vs-energy tradeoff, as the DNN inference accuracy typically degrades with a drop in resolution. In this work, we introduce MRIM, a simple but effective framework to tackle this tradeoff. Under MRIM, the vision sensor platform first executes …


Revisiting Neuron Coverage Metrics And Quality Of Deep Neural Networks, Zhou Yang, Jieke Shi, Muhammad Hilmi Asyrofi, David Lo Mar 2022

Revisiting Neuron Coverage Metrics And Quality Of Deep Neural Networks, Zhou Yang, Jieke Shi, Muhammad Hilmi Asyrofi, David Lo

Research Collection School Of Computing and Information Systems

Deep neural networks (DNN) have been widely applied in modern life, including critical domains like autonomous driving, making it essential to ensure the reliability and robustness of DNN-powered systems. As an analogy to code coverage metrics for testing conventional software, researchers have proposed neuron coverage metrics and coverage-driven methods to generate DNN test cases. However, Yan et al. doubt the usefulness of existing coverage criteria in DNN testing. They show that a coverage-driven method is less effective than a gradient-based method in terms of both uncovering defects and improving model robustness. In this paper, we conduct a replication study of …


Hermes: Using Commit-Issue Linking To Detect Vulnerability-Fixing Commits, Truong Giang Nguyen, Hong Jin Kang, David Lo, Abhishek Sharma, Andrew E. Santosa, Asankhaya Sharma, Ming Yi Ang Mar 2022

Hermes: Using Commit-Issue Linking To Detect Vulnerability-Fixing Commits, Truong Giang Nguyen, Hong Jin Kang, David Lo, Abhishek Sharma, Andrew E. Santosa, Asankhaya Sharma, Ming Yi Ang

Research Collection School Of Computing and Information Systems

Software projects today rely on many third-party libraries, and therefore, are exposed to vulnerabilities in these libraries. When a library vulnerability is fixed, users are notified and advised to upgrade to a new version of the library. However, not all vulnerabilities are publicly disclosed, and users may not be aware of vulnerabilities that may affect their applications. Due to the above challenges, there is a need for techniques which can identify and alert users to silent fixes in libraries; commits that fix bugs with security implications that are not officially disclosed. We propose a machine learning approach to automatically identify …


Gender Influence On Communication Initiated Within Student Teams, Rita Garcia, Chieh-Ju Trinity Liao, Ariane Pearce, Christoph Treude Mar 2022

Gender Influence On Communication Initiated Within Student Teams, Rita Garcia, Chieh-Ju Trinity Liao, Ariane Pearce, Christoph Treude

Research Collection School Of Computing and Information Systems

Collaboration is important during software development, but related work has found gender differences can influence the collaboration process, creating inequality in the team’s dynamics. In this paper, we present a gender analysis study that involved 39 students, examining their teams’ online collaborations while contributing to a large open-source software project. Eight teams of 4-6 Software Engineering (SE) students communicated over an online messaging platform, Slack, to complete an eight-week project. The goal of this study is to identify gender differences emerging from team collaboration. A mixed-methods approach was used to collect students’ teamwork experiences and analyse their collaboration. Our research …


Strangan: Adversarially-Learnt Spatial Transformer For Scalable Human Activity Recognition, Abu Zaher Md Faridee, Avijoy Chakma, Archan Misra, Nirmalya Roy Mar 2022

Strangan: Adversarially-Learnt Spatial Transformer For Scalable Human Activity Recognition, Abu Zaher Md Faridee, Avijoy Chakma, Archan Misra, Nirmalya Roy

Research Collection School Of Computing and Information Systems

We tackle the problem of domain adaptation for inertial sensing-based human activity recognition (HAR) applications -i.e., in developing mechanisms that allow a classifier trained on sensor samples collected under a certain narrow context to continue to achieve high activity recognition accuracy even when applied to other contexts. This is a problem of high practical importance as the current requirement of labeled training data for adapting such classifiers to every new individual, device, or on-body location is a major roadblock to community-scale adoption of HAR-based applications. We particularly investigate the possibility of ensuring robust classifier operation, without requiring any new labeled …