VLDB 2026 Research / reviewers in the wild / expert
Hakam W. Alomari
dblp:123/7736
· DBLP profile ↗
8ranked-venue papers
7as first author
3since 2021 · last 2025
0000-0002-8554-3236ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 6 · 6 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | A Slicing-Based Approach for Detecting and Patching Vulnerable Code ClonesabstractCode cloning is a common practice in software development, but it poses significant security risks by propagating vulnerabilities across cloned segments. To address this challenge, we introduce SRCVUL, a scalable, precise detection approach that combines program slicing with Locality-Sensitive Hashing to identify vulnerable code clones and recommend patches. SRCVUL builds a database of vulnerability-related slices by analyzing known vulnerable programs and their corresponding patches, indexing each slice's unique structural characteristics as a vulnerability slicing vector. During clone detection, SRCVUL efficiently matches slicing vectors from target programs with those in the database, recommending patches upon identifying similarities. Our evaluation of SRCVUL against three state-of-the-art vulnerable clone detectors demonstrates its accuracy, efficiency, and scalability, achieving 91 % precision and 75 % recall on established vulnerability databases and open-source repositories. These results highlight SRCVUL's effectiveness in detecting complex vulnerability patterns across diverse codebases. Hakam W. Alomari, Christopher Vendome, Himal Gyawali |
ICPC | 1 |
| 2024 | A Comprehensive Evaluation Framework of Software Visualizations EffectivenessabstractVisualizations are useful in dealing with complex software systems, especially in maintenance and evolution tasks. Software visualization tools can help reduce the cognitive burden on practitioners when trying to understand these systems. However, a major challenge in designing new visualization techniques and tools is evaluating their effectiveness for specific tasks and users. If a visualization tool is not effective for practitioners, they are unlikely to adopt it. Existing evaluation frameworks for visualizations mainly focus on expressiveness, which refers to the ability of the visualization to show all necessary information. However, evaluating the effectiveness of visualizations is an open research problem, especially in terms of quantifying it. To address this problem, we propose a multi-dimensional evaluation framework that focuses on evaluating visualizations in terms of their qualitative, quantitative, and cognitive aspects. The framework includes seven main dimensions and twenty-eight features, with the effectiveness dimension being further subdivided into four sub-dimensions. We validate our framework by using it to evaluate a number of software visualization tools. This validation demonstrates that the framework can be applied to design and evaluate new software visualization techniques and tools. Hakam W. Alomari, Christopher Vendome, Lane Rizkallah |
IEEE Trans. Vis. Comput. Graph. | 1 |
| 2022 | Clone detection through srcClone: A program slicing based approach
Hakam W. Alomari, Matthew Stephan |
J. Syst. Softw. | 1 |
| 2020 | srcClone: Detecting Code Clones via Decompositional SlicingabstractDetecting code clones is an established method for comprehending and maintaining systems. One important but challenging form of code clone detection involves detecting semantic clones, which are those that are semantically similar code segments that differ syntactically. Existing approaches to semantic clone detection do not scale well to large code bases and have room for improvement in their precision and recall. In this paper, we present a scalable slicing-based approach for detecting code clones, including semantic clones. We determine code segment similarity based on their corresponding program slices. We take advantage of a lightweight, publicly available, and scalable program slicing approach to compute the necessary information. Our approach uses dependency analysis to find and measure cloned elements, and provides insights into elements of the code that are affected by an entire clone set/class. We have implemented our approach as a tool called srcClone. We evaluate it by comparing it to two semantic clone detectors in terms of clones, performance, and scalability; and perform recall and precision analysis using established benchmark scenarios. In our evaluation, we illustrate our approach is both relatively scalable and accurate. srcClone can also be used by program analysts to run on non-compilable and incomplete source code, which serves comprehension and maintenance tasks very well. We believe our approach is an important advancement in program comprehension that can help improve clone detection practices and provide developers greater insights into their software. Hakam W. Alomari, Matthew Stephan |
ICPC | 1 |
| 2019 | Evaluating the Impact of Combination of Engagement Strategies in SEP-CyLE on Improve Student Learning of Programming ConceptsabstractProgramming is a skill, often acquired through repeated practice and feedback. During traditional lectures, students not actively engaged in their own learning. It is imperative to pique students motivation and direct their focus on gaining the requisite knowledge. As the class size grows, instructors feedback is delayed that impacts student engagement and learning. Educational researchers have supported using web-based tools to help evaluate student work, provide timely feedback and increase the amount of time they spend improving their skills. Motivated by the previous work, our team has developed the SEP-CyLE (Software Engineering and Programming Cyber Learning Environment) - a cyber learning environment that contains digital learning content of software programming and testing concepts. SEP-CyLE incorporates collaborative learning, social networking and gamification-based learning engagement strategies (LESs) that has led to an improved motivation and understanding of programming concepts. This paper aims to assess the impact of different combinations of these LESs on student learning in the context of CS1 classrooms. We coordinated studies at two universities wherein different combination of LESs were utilized using SEP-CyLE in CS1 classrooms. We analyzed the impact of LESs on students' acquisition of programming concepts, their engagement and usage of SEP-CyLE. The pre and post test results indicated that the assorted LEs have shown a positive impact on student learning across all the institutions. The correlation results demonstrated that there is meaningful relationship between the LEs and the student performance. Mourya Reddy Narasareddygari, Gursimran Singh Walia, Debra M. Duke, Vijayalakshmi Ramasamy, James D. Kiper, Debra Lee Davis, Andrew A. Allen, Hakam W. Alomari |
SIGCSE | 8 |
| 2016 | vizSlice: Visualizing Large Scale Software SlicesabstractProgram slicing has long been used to facilitate program understanding. Several approaches have been suggested for computing slices based on different perspectives, including forward slicing, backward slicing, static slicing, and dynamic slicing. The applications of slicing are numerous, including testing, effort estimation, and impact analysis. Surprisingly, given the maturity of slicing, few approaches exist for visualizing slices. In this paper, we present our tool for visualizing large systems based on program slicing and through two visualization idioms: treemaps and bipartite graphs. In particular, we use treemaps to facilitate slicing-based navigation, and we use bipartite graphs to facilitate visual impact analysis by displaying relationships among system decomposition slices showing the relevant computations involving a given slicing variable. We believe our tool will support various software maintenance tasks, including providing analysts an interactive visualization of the impact of potential changes, thus allowing them to plan maintenance accordingly. Finally, we show that, through the use of both existing scalable slicing and scalable visualization approaches, our tool can facilitate analysis of large software systems. Hakam W. Alomari, Rachel A. Jennings, Paulo Virote de Souza, Matthew Stephan, Gerald C. Gannod |
VISSOFT | 1 |
| 2014 | A Slice-Based Estimation Approach for Maintenance EffortabstractProgram slicing is used as a basis for an approach to estimate maintenance effort. A case study of the GNU Linux kernel with over 900 versions spanning 17 years of history is presented. For each version a system dictionary is built using a lightweight slicing approach and encodes the forward decomposition static slice profiles for all variables in all the files in the system. Changes to the system are then modeled at the behavioral level using the difference between the system dictionaries of two versions. The three different granularities of slice (i.e., line, function, and file) are analyzed. We use a direct extension of srcML to represent computed change information. The retrieved information reflects the fact that additional knowledge of the differences can be automatically derived to help maintainers understand code changes. We consider the hypotheses: (1) The structured format helps create traceability links between the changes and other software artifacts. (2) This model is predictive of maintenance effort. The results demonstrate that the approach accurately predicts effort in a scalable manner. Hakam W. Alomari, Michael L. Collard, Jonathan I. Maletic |
ICSME | 1 |
| 2014 | srcSlice: very efficient and scalable forward static slicingabstractABSTRACT A highly efficient lightweight forward static slicing approach is presented and evaluated. The approach does not compute the program/system dependence graph but instead dependence and control information is computed as needed while computing the slice on a variable. The result is a list of line numbers, dependent variables, aliases, and function calls that are part of the slice for all variables (both local and global) for the entire system. The method is implemented as a tool, calledsrcSlice, on top ofsrcML, an XML representation of source code. The approach is highly scalable and can generate the slices for all variables of the Linux kernel in approximately 20 min on a typical desktop. Benchmark results are compared with theCodeSurferslicing tool from GrammaTech Inc., and the approach compares well with regard to accuracy of slices. Copyright © 2014 John Wiley & Sons, Ltd. Hakam W. Alomari, Michael L. Collard, Jonathan I. Maletic, Nouh Alhindawi, Omar Meqdadi |
J. Softw. Evol. Process. | 1 |