VLDB 2026 Research / reviewers in the wild / expert
Ajay Chander
dblp:06/5912
· DBLP profile ↗
20ranked-venue papers
10as first author
0since 2021 · last 2020
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 8 · 4 first-authorArtificial intelligence and machine learning · 4 · 2 first-authorHuman-computer interaction and ubiquitous computing · 4 · 1 first-authorSecurity and privacy · 3 · 3 first-authorDatabases, data management, data science and information retrieval · 2Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 2Systems, architecture and hardware · 1 · 1 first-authorTheory of computation · 1 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
5 papers |
Program verification · 40% Programming languages and type systems · 25% Software testing · 18% | |
| Human-computer interaction and pervasive computing
2 papers |
Human-AI interaction · 76% Ubiquitous computing and smart environments · 19% User interface design and tools · 6% | |
| Network and information security
3 papers |
Web and mobile security · 100% | |
| Artificial intelligence
1 paper |
Knowledge representation and reasoning · 100% |
Topics — the 17 heaviest of 19, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Human-AI interaction
explainable AI |
0.4 | 1 | 2020 | Explanation Perspectives from the Cognitive Sciences - A Survey · IJCAI 2020 |
Ubiquitous computing and smart environments
context-aware computing |
0.1 | 1 | 2010 | Optimizing user interaction for web-based mobile tasks · WWW 2010 |
Web and mobile security
web application security |
0.1 | 2 | 2008 | Better abstractions for secure server-side scripting · WWW 2008 Dynamic test input generation for web applications · ISSTA 2008 |
Software testing › test generation
dynamic test generation |
0.1 | 1 | 2008 | Dynamic test input generation for web applications · ISSTA 2008 |
Programming languages and type systems
language design |
0.1 | 1 | 2008 | Better abstractions for secure server-side scripting · WWW 2008 |
Software testing
test generation |
0.1 | 1 | 2008 | Dynamic test input generation for web applications · ISSTA 2008 |
Web and mobile security
browser security |
0.1 | 1 | 2007 | JavaScript instrumentation for browser security · POPL 2007 |
Program analysis
dynamic analysis |
0.1 | 1 | 2007 | JavaScript instrumentation for browser security · POPL 2007 |
Program verification › program logic
hoare logic |
0.1 | 1 | 2007 | Enforcing resource bounds via static verification of dynamic checks · ACM Trans. Program. Lang. Syst. 2007 |
Programming languages and type systems
language semantics |
0.1 | 1 | 2007 | JavaScript instrumentation for browser security · POPL 2007 |
Programming languages and type systems › language semantics › formal semantics
operational semantics |
0.1 | 1 | 2007 | JavaScript instrumentation for browser security · POPL 2007 |
Program analysis
program rewriting |
0.1 | 1 | 2007 | JavaScript instrumentation for browser security · POPL 2007 |
Program verification › quantitative verification
resource bound verification |
0.1 | 1 | 2007 | Enforcing resource bounds via static verification of dynamic checks · ACM Trans. Program. Lang. Syst. 2007 |
Program verification › quantitative verification
resource verification |
0.1 | 1 | 2007 | Enforcing resource bounds via static verification of dynamic checks · ACM Trans. Program. Lang. Syst. 2007 |
Program verification
static verification |
0.1 | 1 | 2007 | Enforcing resource bounds via static verification of dynamic checks · ACM Trans. Program. Lang. Syst. 2007 |
Program verification › code-level verification
java verification |
0.1 | 1 | 2005 | JVer: A Java Verifier · CAV 2005 |
Program verification
dynamic verification |
0.0 | 1 | 2007 | Enforcing resource bounds via static verification of dynamic checks · ACM Trans. Program. Lang. Syst. 2007 |
Methods — techniques the papers use, named apart from their topics
survey · 0.9dynamic analysis · 0.2rewriting · 0.1program instrumentation · 0.1page pre-fetching · 0.1interaction burstiness · 0.1context-sensitive prediction · 0.1static analysis · 0.1linear inequalities · 0.1hoare logic · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2020 | Explanation Perspectives from the Cognitive Sciences - A SurveyabstractWith growing adoption of AI across fields such as healthcare, finance, and the justice system, explaining an AI decision has become more important than ever before. Development of human-centric explainable AI (XAI) systems necessitates an understanding of the requirements of the human-in-the-loop seeking the explanation. This includes the cognitive behavioral purpose that the explanation serves for its recipients, and the structure that the explanation uses to reach those ends. An understanding of the psychological foundations of explanations is thus vital for the development of effective human-centric XAI systems. Towards this end, we survey papers from the cognitive science literature that address the following broad questions: (1) what is an explanation, (2) what are explanations for, and 3) what are the characteristics of good and bad explanations. We organize the insights gained therein by means of highlighting the advantages and shortcomings of various explanation structures and theories, discuss their applicability across different domains, and analyze their utility to various types of humans-in-the-loop. We summarize the key takeaways for human-centric design of XAI systems, and recommend strategies to bridge the existing gap between XAI research and practical needs. We hope this work will spark the development of novel human-centric XAI systems. Ramya Srinivasan 0002, Ajay Chander |
IJCAI | 2 |
| 2019 | Guided play: digital sensing and coaching for stereotypical play behavior in children with autismabstractRestricted and repetitive behaviors (RRBs) are a core symptom and an early marker of autism. Current research and intervention for RRB heavily rely on professional experience and effort. Guided Play is a technology that uses instrumented games and toys as a platform to understand children's play behavior and facilitate behavioral intervention during play. This paper presents the design and implementation of a prototype based on the technology, as well as an evaluation on 6 children with autism. The results show that children with RRBs in physical world activities also exhibit similar patterns in a similar digital activity, and that digital coaching can reduce RRBs by expanding children's play skill repertoire and promoting symbolic play. Ajay Chander, Kanji Uchino |
IUI | 2 |
| 2018 | Evaluating Explanations by Cognitive Value
Ajay Chander, Ramya Srinivasan 0002 |
CD-MAKE | 1 |
| 2018 | Explainable AI: The New 42?
Randy Goebel, Ajay Chander, Katharina Holzinger, Freddy Lécué, Zeynep Akata, Simone Stumpf, Peter Kieseberg, Andreas Holzinger |
CD-MAKE | 2 |
| 2016 | ONE - A Personalized Wellness System
Ajay Chander, Ramya Srinivasan 0002 |
ECAI | 1 |
| 2011 | Optimal Test Input Sequence Generation for Finite State Models and Pushdown SystemsabstractFinite state machines and pushdown systems are frequently used in model based testing. In such testing, the system under test is abstractly modeled as a finite state machine having a finite set of states and a labeled transition relation between the states. A pushdown system, additionally, has an unbounded stack. Test inputs are then generated by enumerating a set of sequences of transitions labels from the model. There has been a lot of research that focussed on generation of test input sequences satisfying various coverage criteria. In this paper, we consider the problem of generating a set of test input sequences that satisfy certain coverage criteria-cover all transition labels or cover all length-n transition label sequences at least once-while minimizing the sum of the length of the sequences in the set. We show that these optimal test input generation problems can be reduced to integer linear programming (ILP) problems. We also prove that our optimal test input generation problems are NP-Complete. We report our experimental results on a prototype implementation for finite states machines. Ajay Chander, Dinakar Dhurjati, Koushik Sen, Dachuan Yu |
ICST | 1 |
| 2010 | Optimizing user interaction for web-based mobile tasksabstractThis paper describes the design and prototype implementation of MIntOS (Mobile Interaction Optimization System), a system for improving mobile interaction in web-based activities. MIntOS monitors users' interactions both for gathering interaction history and for the runtime construction of interaction context. A simple approach based on interaction burstiness is used to break interaction sequences into Trails, which approximates user tasks. Such Trails are used to generate rules for online, context-sensitive prediction of future interaction sequences. Predicted user interaction sequences are then optimized to reduce the amount of user input and user wait time using techniques such as interaction short-cuts, automatic text copying and form-filling, as well as page pre-fetching. Such optimized interaction sequences are, at real-time, recommended to the user through UI enhancements in a non-intrusive manner. Ajay Chander, Hiroshi Inamura |
WWW | 2 |
| 2009 | Formal Specification and Analysis of Timing Properties in Software Systems
Musab AlTurki, Dinakar Dhurjati, Dachuan Yu, Ajay Chander, Hiroshi Inamura |
FASE | 4 |
| 2009 | Optimizing user interaction for mobile web browsingabstractThe small form-factor of mobile handsets and the longer, variable latency of cellular networks negatively affect user experience in mobile web related activities. In this paper we describe the design and prototype implementation of a framework for improving mobile web interaction based on monitored interaction history and runtime interaction context. Our framework predicts future interaction sequences and optimizes predicted user interactions with navigation shortcuts and automatic text copying and formfilling Ajay Chander, Hiroshi Inamura |
Mobile HCI | 2 |
| 2008 | JavaScript Instrumentation in Practice
Haruka Kikuchi, Dachuan Yu, Ajay Chander, Hiroshi Inamura, Igor Serikov |
APLAS | 3 |
| 2008 | Dynamic test input generation for web applicationsabstractWeb applications routinely handle sensitive data, and many people rely on them to support various daily activities, so errors can have severe and broad-reaching consequences. Unlike most desktop applications, many web applications are written in scripting languages, such as PHP. The dynamic features commonly supported by these languages significantly inhibit static analysis and existing static analysis of these languages can fail to produce meaningful results on realworld web applications. Gary Wassermann, Dachuan Yu, Ajay Chander, Dinakar Dhurjati, Hiroshi Inamura, Zhendong Su 0001 |
ISSTA | 3 |
| 2008 | Better abstractions for secure server-side scriptingabstractIt is notoriously difficult to program a solid web application. Besides addressing web interactions, state maintenance, and whimsical user navigation behaviors, programmers must also avoid a minefield of security vulnerabilities. The problem is twofold. First, we lack a clear understanding of the new computation model underlying web applications. Second, we lack proper abstractions for hiding common and subtle coding details that are orthogonal to the business functionalities of specific web applications. Dachuan Yu, Ajay Chander, Hiroshi Inamura, Igor Serikov |
WWW | 2 |
| 2007 | JavaScript instrumentation for browser securityabstractIt is well recognized that JavaScript can be exploited to launch browser-based security attacks. We propose to battle such attacks using program instrumentation. Untrusted JavaScript code goes through a rewriting process which identifies relevant operations, modifies questionable behaviors, and prompts the user (a web page viewer) for decisions on how to proceed when appropriate. Our solution is parametric with respect to the security policy-the policy is implemented separately from the rewriting, and the same rewriting process is carried out regardless of which policy is in use. Be-sides providing a rigorous account of the correctness of our solution, we also discuss practical issues including policy management and prototype experiments. A useful by-product of our work is an operational semantics of a core subset of JavaScript, where code embedded in (HTML) documents may generate further document pieces (with new code embedded) at runtime, yielding a form of self-modifying code. Dachuan Yu, Ajay Chander, Nayeem Islam, Igor Serikov |
POPL | 2 |
| 2007 | Enforcing resource bounds via static verification of dynamic checksabstractWe show how to limit a program's resource usage in an efficient way, using a novel combination of dynamic checks and static analysis. Usually, dynamic checking is inefficient due to the overhead of checks, while static analysis is difficult and rejects many safe programs. We propose a hybrid approach that solves these problems. We split each resource-consuming operation into two parts. The first is a dynamic check, called reserve. The second is the actual operation, called consume, which does not perform any dynamic checks. The programmer is then free to hoist and combine reserve operations. Combining reserve operations reduces their overhead, while hoisting reserve operations ensures that the program does not run out of resources at an inconvenient time. A static verifier ensures that the program reserves resources before it consumes them. This verification is both easier and more flexible than an a priori static verification of resource usage. We present a sound and efficient static verifier based on Hoare logic and linear inequalities. As an example, we present a version of tar written in Java. Ajay Chander, David Espinosa, Nayeem Islam, Peter Lee 0001, George C. Necula |
ACM Trans. Program. Lang. Syst. | 1 |
| 2005 | JVer: A Java Verifier
Ajay Chander, David Espinosa, Nayeem Islam, Peter Lee 0001, George C. Necula |
CAV | 1 |
| 2005 | Enforcing Resource Bounds via Static Verification of Dynamic Checks
Ajay Chander, David Espinosa, Nayeem Islam, Peter Lee 0001, George C. Necula |
ESOP | 1 |
| 2004 | A Distributed High Assurance Reference Monitor
Ajay Chander, Drew Dean, John C. Mitchell |
ISC | 1 |
| 2004 | Reconstructing Trust ManagementabstractWe present a trust management kernel that clearly separates authorization and structured distributed naming. Given an access request and supporting credentials, the kernel determines whether the request is authorized. We prove soundness and completeness of the authorization system without names and prove that naming is orthogonal to authorization in a precise sense. The orthogonality theorem gives us simple soundness and completeness proofs for the entire kernel. The kernel is formally verified in PVS, allowing for the automatic generation of a verified implementation of a reference monitor. By separating naming and authorization primitives, we arrive at a compositional model and avoid concepts such as “speaks-for” that have led to anomalies in logical characterizations of other trust management systems. Ajay Chander, Drew Dean, John C. Mitchell |
J. Comput. Secur. | 1 |
| 2002 | NEVRLATE: Scalable Resource DiscoveryabstractA scalable and expressive peer-to-peer (P2P) networking and computing framework requires efficient resource discovery services. Here we propose NEVRLATE, for Network-Efficient Vast Resource Lookup At The Edge, an efficient organization of directories or directory mirrors, providing a scalable distributed resource discovery service. NEVRLATE organizes directory servers in an approximate two-dimensional grid, or a set of sets of servers, for registration to occur in one 'horizontal' dimension, and lookup to occur in the other 'vertical' dimension. The payoff of organizing n servers into a structure like this is to achieve O(pn) message complexity for registration, and nearly constant complexity lookup. At extra cost NEVRLATE can provide fault tolerance, high availability and security, anonymity, and privacy. The protocol described can be seen as a way to organize Gnutella supernodes, or as a performance extension of Freenet's architecture. In addition, it supports expressive lookup mechanisms, and may provide a basis for a truly scalable worldwide infrastructure for the semantic and the extended web. Ajay Chander, Steven Dawson, Patrick Lincoln, David W. J. Stringer-Calvert |
CCGRID | 1 |
| 2001 | A State-Transition Model of Trust Management and Access ControlabstractWe use a state-transition approach to analyze and compare the core access control mechanisms that are characteristic of a variety of trust management, access control list, and capability-based systems. The framework, which characterizes the set of rights a subject has over an object after any sequence of actions, is based on abstract system states, state transitions, and logical deduction of access control judgments. We present abstract models representing the access control portion of trust management, access control lists, and two versions of capabilities, proving various correspondence and simulation relations between these models. The main results include an equivalence between access control lists (ACLs) and capabilities viewed as rows of the Lampson access matrix and the (proper) subsumption of a form of ACLs by an "unforgeable reference" form of capabilities. The access control mechanism at the heart of distributed trust management systems is formally shown to provide a tractable compromise between unrestricted capability passing from the capability models and easy revocation provided by access control lists. The underlying simulations show how trust management compares with more established access control mechanisms, independent of features such as local name spaces and certificate authorization hierarchies. Ajay Chander, John C. Mitchell, Drew Dean |
CSFW | 1 |