VLDB 2026 Research / reviewers in the wild / expert
Johannes Holvitie
dblp:118/1364
· DBLP profile ↗
13ranked-venue papers
4as first author
2since 2021 · last 2021
0000-0003-3292-7970ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 8 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 3 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 first-authorArtificial intelligence and machine learning · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2021 | From Setting Up Innovation in a Novel Context To Discovering Sustainable Business - A Framework for Short-Term EventsabstractShort-term events, like hackathons, are commonly applied to innovate on novel subject areas and on ground-breaking technologies. While such events have led to significant successful outcomes for many companies, the big questions facing organisers of these events are: "where do we start?, what should be done towards the hosting of a successful event?, and what should be done when the event is completed?" While several methods and supporting recommendations have been introduced for answering these questions, a common framework for the hosting and management of short-term events is still not available. This is a limitation, as having such a framework would allow organisers to carry out systematic analysis for the subject area, identify the most suitable pre-event analysis and support functions, combine these with the fitting and justified short-term event types, and carry the results of the event to fruitful, sustainable businesses with post-event operations. The opportunity to progress events into business ventures is particularly noteworthy given the rapid changes that are typical in the technology domain, and thus, the need to be both innovative and nimble in responding to such changes and ensuing opportunities. To fill this gap, we introduce an evidence-driven framework for hosting short-term events. Our framework presents several chronological modules coupled together to form a comprehensive, but agile set of practices. A review of the state-of-the-art and a partial empirical trial support the framework’s utility, notwithstanding the need for further work to enhance and trial the framework for organising other events. Mikko Jaakola, Tuisku Polvinen, Johannes Holvitie, Sherlock A. Licorish, Ville Leppänen |
SEAA | 3 |
| 2021 | Security in agile software development: A practitioner surveyabstractContext: Software security engineering provides the means to define, implement and verify security in software products. Software security engineering is performed by following a software security development life cycle model or a security capability maturity model . However, agile software development methods and processes, dominant in the software industry, are viewed to be in conflict with these security practices and the security requirements. Objective: Empirically verify the use and impact of software security engineering activities in the context of agile software development , as practiced by software developer professionals. Method: A survey ( N = 61 ) was performed among software practitioners in Finland regarding their use of 40 common security engineering practices and their perceived security impact, in conjunction with the use of 16 agile software development items and activities. Results: The use of agile items and activities had a measurable effect on the selection of security engineering practices. Perceived impact of the security practices was lower than the rate of use would imply: This was taken to indicate a selection bias, caused by e.g. developers’ awareness of only certain security engineering practices, or by difficulties in applying the security engineering practices into an iterative software development workflow. Security practices deemed to have most impact were proactive and took place in the early phases of software development. Conclusion: Systematic use of agile practices conformed, and was observed to take place in conjunction with the use of security practices. Security activities were most common in the requirement and implementation phases. In general, the activities taking place early in the life cycle were also considered most impactful. A discrepancy between the level of use and the perceived security impact of many security activities was observed. This prompts research and methodological development for better integration of security engineering activities into software development processes, methods, and tools. Kalle Rindell, Jukka Ruohonen, Johannes Holvitie, Sami Hyrynsalmi, Ville Leppänen |
Inf. Softw. Technol. | 3 |
| 2018 | Co-creative engineering curriculum design - Case East AfricaabstractThis work-in-progress study reports the first findings from an engineering curriculum design process in an East African context. The design of new programs and teaching practices involves three universities with local faculty designing a new engineering curriculum with external experts involved in the design process. Innovation is something that in addition to societies and industries also the global academia is striving towards, and not only in research but more and more so also in education [1]. The big question, however, is how to achieve this and how to make innovation happen inside the classroom when the faculty needs to push the boundaries of science while at the same time being transformative educators [2]. And all this in a global higher education environment, where well-established institutions are in the cross pressure of neoliberal worldview and the humboldtian ideal of the community of scholars [neoliberal]. On the other end innovation and creativity are argued to be products of co-creation and a non-controlled if not chaotic and emergent environment. Much different from tradition and critical thinking (devils advocate) driven scientific world or establishment that sees cultural change and societal pressure often as a threat to their independence. The empirical part for this study involved several co-creation workshops where students and faculty participated and where co-creative learning methods where tested in a local environment. Although the processes ran parallel and where not coupled together both workshops gave insight on the preconditions of curriculum design and design of learning methods in the context in question. The Northern European university in question was responsible for organizing the workshops in collaboration with East African partners. The results show that there are several constraints for curriculum design and the adoption of new learning methods. The first results using the co-creation model proved, however, useful. The process of curriculum design and implementation will go on for the next two years until year 2020. Ville Taajamaa, Antero Järvi, Samuli Laato, Johannes Holvitie |
FIE | 4 |
| 2018 | Investigating the Effects of Agile Practices and Processes on Technical Debt - The Viewpoint of the Brazilian Software IndustryabstractThe current scenario of software development is characterized by a wide adoption of agile methodologies, which define processes and practices that address a range of problems faced by development teams.However, there is still little information on how these methodologies deal with technical debt(TD).This work presents the results of a replicated survey(originally executed in Finland) whose goal was to investigate which agile practices and processes are sensitive to TD.Despite this replication allows different types of analysis, the focus of this paper will be on the analysis of the effects of the agile practices and processes on TD from the perspective of the Brazilian software industry, where the study was replicated.At total, 62 practitioners from different organizations answered the questionnaire.The results indicated that participants already had a good knowledge about TD, instances of TD reside in the software implementation and are caused due to deficiencies in its architecture, the size of a debt item is proportional to its impact on the project, and, refactoring and iteration have the most positive effect on TD.This replication also contributes to the investigated topic through the accumulation of evidence about the findings, thereby increasing the level of confidence in results. Vivyane Caires, Nicolli Rios, Johannes Holvitie, Ville Leppänen, Manoel G. Mendonça, Rodrigo O. Spínola |
SEKE | 3 |
| 2018 | Technical debt and agile software development practices and processes: An industry practitioner surveyabstractContext: Contemporary software development is typically conducted in dynamic, resource-scarce environments that are prone to the accumulation of technical debt. While this general phenomenon is acknowledged, what remains unknown is how technical debt specifically manifests in and affects software processes, and how the software development techniques employed accommodate or mitigate the presence of this debt. Objectives: We sought to draw on practitioner insights and experiences in order to classify the effects of agile method use on technical debt management, given the popularity and perceived success of agile methods. We explore the breadth of practitioners’ knowledge about technical debt; how technical debt is manifested across the software process; and the perceived effects of common agile software development practices and processes on technical debt. In doing so, we address a research gap in technical debt knowledge and provide novel and actionable managerial recommendations. Method: We designed, tested and executed a multi-national survey questionnaire to address our objectives, receiving 184 responses from practitioners in Brazil, Finland, and New Zealand. Results: Our findings indicate that: 1) Practitioners are aware of technical debt, although, there was under utilization of the concept, 2) Technical debt commonly resides in legacy systems, however, concrete instances of technical debt are hard to conceptualize which makes it problematic to manage, 3) Queried agile practices and processes help to reduce technical debt; in particular, techniques that verify and maintain the structure and clarity of implemented artifacts (e.g., Coding standards and Refactoring) positively affect technical debt management. Conclusions: The fact that technical debt instances tend to have characteristics in common means that a systematic approach to its management is feasible. However, notwithstanding the positive effects of some agile practices on technical debt management, competing stakeholders’ interests remain a concern. Johannes Holvitie, Sherlock A. Licorish, Rodrigo O. Spínola, Sami Hyrynsalmi, Stephen G. MacDonell, Thiago Souto Mendes, Jim Buchan, Ville Leppänen |
Inf. Softw. Technol. | 1 |
| 2018 | Diversification and obfuscation techniques for software security: A systematic literature reviewabstractContext: Diversification and obfuscation are promising techniques for securing software and protecting computers from harmful malware. The goal of these techniques is not removing the security holes, but making it difficult for the attacker to exploit security vulnerabilities and perform successful attacks. Objective: There is an increasing body of research on the use of diversification and obfuscation techniques for improving software security; however, the overall view is scattered and the terminology is unstructured. Therefore, a coherent review gives a clear statement of state-of-the-art, normalizes the ongoing discussion and provides baselines for future research. Method: In this paper, systematic literature review is used as the method of the study to select the studies that discuss diversification/obfuscation techniques for improving software security. We present the process of data collection, analysis of data, and report the results. Results: As the result of the systematic search, we collected 357 articles relevant to the topic of our interest, published between the years 1993 and 2017. We studied the collected articles, analyzed the extracted data from them, presented classification of the data, and enlightened the research gaps. Conclusion: The two techniques have been extensively used for various security purposes and impeding various types of security attacks. There exist many different techniques to obfuscate/diversify programs, each of which targets different parts of the programs and is applied at different phases of software development life-cycle. Moreover, we pinpoint the research gaps in this field, for instance that there are still various execution environments that could benefit from these two techniques, including cloud computing, Internet of Things (IoT), and trusted computing. We also present some potential ideas on applying the techniques on the discussed environments. Shohreh Hosseinzadeh, Sampsa Rauti, Samuel Laurén, Jari-Matti Mäkelä, Johannes Holvitie, Sami Hyrynsalmi, Ville Leppänen |
Inf. Softw. Technol. | 5 |
| 2017 | Top Management Support for Software Cost Estimation - A Case Study of the Current Practice and Impacts
Jurka Rahikkala, Sami Hyrynsalmi, Ville Leppänen, Tommi Mikkonen, Johannes Holvitie |
PROFES | 5 |
| 2016 | Exploring the clustering of software vulnerability disclosure notifications across software vendorsabstractThis exploratory empirical paper investigates annual time delays between vulnerability disclosure notifications and acknowledgments by means of network analysis. These delays are approached through a potential clustering effect of vulnerabilities across software vendors. The analysis is based on a projection from bipartite vendor-vulnerability structures to one-mode vendor-vendor networks, while the hypothesized clustering effect is approached with a conventional community detection algorithm. According to the results, (a) vulnerabilities cluster across vendors, (b) which also explains a portion of the time delays, although (c) the clustering is not stable annually. The computed network (d) clusters can be also interpreted by reflecting these against common software security attack surfaces. The results can be used to contemplate (e) practical means with which the efficiency of vulnerability disclosure could be improved. Jukka Ruohonen, Johannes Holvitie, Sami Hyrynsalmi, Ville Leppänen |
AICCSA | 2 |
| 2016 | Adoption and Suitability of Software Development Methods and PracticesabstractIn seeking to complement consultants' and tool vendors' reports, there has been an increasing academic focus on understanding the adoption and use of software development methods and practices. We surveyed practitioners working in Brazil, Finland, and New Zealand in a transnational study to contribute to these efforts. Among our findings we observed that most of the 184 practitioners in our sample focused on a small portfolio of projects that were of short duration. In addition, Scrum and Kanban were used most; however, some practitioners also used conventional methods. Coding Standards, Simple Design and Refactoring were used most by practitioners, and these practices were held to be largely suitable for project and process management. Our evidence points to the need to properly understand and support a wide range of software methods. Sherlock A. Licorish, Johannes Holvitie, Sami Hyrynsalmi, Ville Leppänen, Rodrigo O. Spínola, Thiago Souto Mendes, Stephen G. MacDonell, Jim Buchan |
APSEC | 2 |
| 2016 | Modelling Propagation of Technical DebtabstractNoting the overwhelming speed during software development, and particularly in environments where rapid delivery is the norm, the lack of accumulated technical debt information could result in ineffective management. We introduce technical debt propagation channels in this paper to advance software maintenance research on two accounts: (1) We describe the fundamental components for the channels, allowing identification of distinct channels, and (2) we describe a procedure to identify and abstract technical debt channels in order to produce technical debt propagation models. Our propagation models pursue automation of technical debt information maintenance with program analysis results, and translation of the maintained information between existing-and currently disconnected-technical debt management solutions. We expect the immediate technical debt information to enhance applicability and effectiveness of existing technical debt management approaches. Johannes Holvitie, Sherlock A. Licorish, Ville Leppänen |
SEAA | 1 |
| 2014 | Software implementation knowledge management with technical debt and network analysisabstractModern, fast-phased, iterative and incremental software development constantly struggles with limited resources and a plethora of frequently changing requirements. This environment often requires the development projects to intentionally — for example through implementing quick-and-dirty — or unintentionally — for example through misinterpretation of requirements — deviate from the optimal product state. While most of the deviation is caught through practices like customer reviews, the remainder stays hidden in the product. The undocumented remainder is difficult to remove, it expands uncontrollably and it negatively affects development as deviations are unexpectedly encountered and overcome. The term technical debt describes this process of accumulating hidden work. Management of technical debt can be expected to be a major factor in software development efficiency and sustainability and as such it should be an integral part of the software implementation's knowledge management. In addition to being difficult to capture, the continuous evolution of the implementation makes maintenance of gained information a challenge. This paper discusses applying technical debt management for software implementations including the entry points for knowledge discovery, network analysis for overcoming the maintenance challenges as well as the pursued outcomes. Johannes Holvitie |
RCIS | 1 |
| 2012 | Breaking the Programming Language Barrier: Using Program Visualizations to Transfer Programming Knowledge in One Programming Language to AnotherabstractThe transition from one programming language to another is an issue, which usually needs to be addressed in programming curricula, as the learning is typically started with syntactically easier languages. This study explores the possibility to use a short interactive tutorial with visualization exercises to ease the transition from Python to Java. In the experiment, the students first took a pre-test to measure their earlier programming knowledge with Python. After that, they used the tutorial with visualization exercises for 45 minutes. The tutorial and the exercises were designed to underline the syntactical and structural differences between Python and Java. Finally, the students answered to post-test, which contained questions similar to pre-test, but in Java. The results indicate, that the students were able to obtain similar program comprehension skills in Java that they previously had with Python. Moreover, the students seem to think that using such tutorials is highly beneficial in the transition. Hence, we conclude, that ViLLE can be effectively used to ease the transition from one language to another. Johannes Holvitie, Teemu Rajala, Riku Haavisto, Erkki Kaila, Mikko-Jussi Laakso, Tapio Salakoski |
ICALT | 1 |
| 2011 | Comparing the collaborative and independent viewing of program visualizationsabstractIn this paper, we report a study on the differences of using a program visualization tool collaboratively or independently. We conducted a study, where students were divided randomly into two groups: the treatment group used a visualization tool called ViLLE in collaboration with another student, while the control group used the tool alone. During the study, we recorded screen captures and students' conversations. Our previous results confirmed that the treatment group outperformed the control group in the post-test in questions related to functions and in total score. Thus, we now annotated and tagged students' actions in answering the exercises, trying to find out an explanation for the difference in learning results. The results show, that the students working in collaboration spent more time answering the difficult exercises than the students working alone, and moreover, spent more time in higher level of engagement, both relatively and absolutely measured. Furthermore, we found out that the students working in pairs discussed the most when in the higher level of engagement and that almost all discussion was related to the exercise they were doing. Teemu Rajala, Erkki Kaila, Johannes Holvitie, Riku Haavisto, Mikko-Jussi Laakso, Tapio Salakoski |
FIE | 3 |