VLDB 2026 Research / reviewers in the wild / expert
Rodrigo Morales 0001
dblp:161/1076-1 · also Rodrigo Morales Alvarado 0001
· DBLP profile ↗
15ranked-venue papers
11as first author
3since 2021 · last 2026
0000-0002-1350-0560ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 13 · 10 first-author · 2 since 2021Computer networks · 2 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Simply the best - A systematic evaluation approach for third-party libraries based on mobile app quality attributesabstractAbstract Mobile device applications (apps) are complex because they rely on integrating multiple third-party libraries (TPLs). Yet, TPLs ease app development by offering implementations of specific functionality. For example, app developers often use advertising libraries to generate revenue, integrate social networking libraries to simplify login, or include crash reporting libraries to monitor/report crashes in their apps. However, there are multiple TPLs with similar functionalities from which to choose, and developers often cannot foresee all the consequences of using these libraries in their apps. The sizes of apps grow with the addition and usage of TPLs, and so does the number of required permissions and resource consumption. Thus, TPLs may degrade the quality of apps and developers need help measuring and comparing them. We propose EQuAT, an approach for Evaluating Quality Attributes of TPLs that eases the comparison of TPLs. EQuAT takes as input minimal apps that integrate TPLs and playable scenarios to simulate user interaction while exercising a particular functionality of the included TPL. By collecting quality metrics and comparing them using plots, we provide app developers with a systematic approach to rank TPLs based on their preferences. We show how EQuAT helps developers make informed decisions about which libraries to integrate into their apps by validating them against nine TPLs across three categories. Rubén Saborido, Rémy Raes, Rodrigo Morales 0001, Romain Rouvoy, Foutse Khomh, Yann-Gaël Guéhéneuc |
Empir. Softw. Eng. | 3 |
| 2026 | A Systematic Literature Review on Vulnerability Detection Approaches for IoT Mobile ApplicationsabstractInternet of Things (IoT) systems are pervasive and increasingly managed through mobile applications. However, poorly designed mobile applications can expose sensitive information to external adversaries. Mitigating such vulnerabilities requires both developers and researchers to apply well-established practices and design secure systems based on clearly defined approaches for vulnerability detection. Although databases such as Open Worldwide Application Security Project (OWASP) and Common Vulnerabilities and Exposures (CVE) catalog known IoT vulnerabilities, no standardised methodology exists for detecting security weaknesses in IoT Mobile applications (IoTMas) during IoT mobile application development. Building on prior research, our research objectives are to: (1) identify, classify, and prioritize critical security vulnerabilities in IoTMAs, (2) survey existing Vulnerability Detection Approaches (VDAs) for IoT mobile applications, (3) critically evaluate the effectiveness of existing VDAs by analyzing their evaluation methodologies and dataset validation, and (4) formulate evidence-based recommendations based on the limitations of existing methods for detecting security vulnerabilities in IoTMAs. We performed a systematic literature review (SLR) from selected primary studies (PSs). From 856 papers retrieved from six academic databases—Scopus, Springer, and Engineering Village, which hosts Compendex (covering IEEE Xplore and the ACM Digital Library), and Inspec (IET)—we reviewed 39 research papers. Our findings include: (1) identification of 52 security vulnerabilities, eight critical (i.e, reported in at least four studies); (2) discovery of seven distinct VDAs; (3) comprehensive VDAs effectiveness evaluation using empirical metrics, accuracy assessments, reproducibility analysis, comparative studies, and validation across diverse IoTMAs marketplaces; (4) recommendations to guide developers and practitioners in selecting appropriate VDAs, thereby supporting the development of secure IoTMAs and enhanced penetration testing. Our study raises awareness of state-of-the-art VDAs, identifies research gaps in existing approaches, and provides recommendations to enhance existing techniques and guide new development, supporting software engineers in making informed technique selection decisions. Zongo Meyo, Rodrigo Morales 0001, Ildiko Pete, Yann-Gaël Guéhéneuc |
IEEE Internet Things J. | 2 |
| 2021 | MoMIT: Porting a JavaScript Interpreter on a Quarter CoinabstractThe Internet of Things (IoT) is a network of physical, connected devices providing services through private networks and the Internet. The devices connect through the Internet to Web servers and other devices. One of the popular programming languages for communicating Web pages and Web apps is JavaScript (JS). Hence, the devices would benefit from JS apps. However, porting JS apps to the many IoT devices, e.g., System-on-a-Chip (SoCs) devices (e.g., Arduino Uno), is challenging because of their limited memory, storage, and CPU capabilities. Also, some devices may lack hardware/software capabilities for running JS apps “as is”. Thus, we proposeMoMIT, a multiobjective optimization approach to miniaturize JS apps to run on IoT devices. We implementMoMITusing three different search algorithms. We miniaturize a JS interpreter and measure the characteristics of 23 apps before/after applyingMoMIT. We find reductions of code size, memory usage, and CPU time of 31, 56, and 36 percent, respectively (medians). We show thatMoMITallows apps to run on up to two additional devices in comparison to the original JS interpreter. Rodrigo Morales 0001, Rubén Saborido, Yann-Gaël Guéhéneuc |
IEEE Trans. Software Eng. | 1 |
| 2020 | Order in Chaos: Prioritizing Mobile App Reviews using Consensus AlgorithmsabstractThe continuous growth of the mobile apps industry creates a competition among apps developers. To succeed, app developers must attract and retain users. User reviews provide a wealth of information about bugs to fix and features to add and can help app developers offer high-quality apps. However, apps may receive hundreds of unstructured reviews, which makes transforming them into change requests a difficult task. Approaches exist for analyzing and extracting topics from mobile app reviews, however, prioritizing these reviews has not gained much attention. In this study, we introduce the use of a consensus algorithm to help developers prioritize user reviews for the purpose of app evolution. We evaluate the usefulness of our approach and meaningfulness of its consensus rankings on four Android apps. We compare the rankings against reviews ranked by app developers manually and show that there is a strong correlation between the two (average Kendall rank correlation coefficient = 0.516). Thus, our approach can prioritize user reviews and help developers focus their time/effort on improving their apps instead of on identifying reviews to address in the next release. Layan Etaiwi, Sylvie Hamel, Yann-Gaël Guéhéneuc, William Flageol, Rodrigo Morales 0001 |
COMPSAC | 5 |
| 2020 | RePOR: Mimicking humans on refactoring tasks. Are we there yet?
Rodrigo Morales 0001, Foutse Khomh, Giuliano Antoniol |
Empir. Softw. Eng. | 1 |
| 2020 | Guest Editorial Special Issue on Software Engineering Research and Practices for the Internet of ThingsabstractSoftware engineering is vital for IoT systems to design systems that are secure, interoperable, modifiable, and scalable. However, industry and academia are still working on many crucial questions related to software engineering for IoT systems, for example, regarding the best practices for developing IoT systems, how to select the hardware, communication, and software architectures of IoT systems, which communications protocols are the most suitable for a system, and how to guarantee security and privacy when dealing with consumer products often composing IoT systems. Rodrigo Morales 0001, Rubén Saborido, Shah Rukh Humayoun, Yann-Gaël Guéhéneuc |
IEEE Internet Things J. | 1 |
| 2018 | EARMO: an energy-aware refactoring approach for mobile appsabstractWith millions of smartphones sold every year, the development of mobile apps has grown substantially. The battery power limitation of mobile devices has push developers and researchers to search for methods to improve the energy efficiency of mobile apps. We propose a multiobjective refactoring approach to automatically improve the architecture of mobile apps, while controlling for energy efficiency. In this extended abstract we briefly summarize our work. Rodrigo Morales 0001, Rubén Saborido, Foutse Khomh, Francisco Chicano, Giuliano Antoniol |
ICSE | 1 |
| 2018 | Exact search-space size for the refactoring scheduling problem
Rodrigo Morales 0001, Francisco Chicano, Foutse Khomh, Giuliano Antoniol |
Autom. Softw. Eng. | 1 |
| 2018 | Getting the most from map data structures in Android
Rubén Saborido, Rodrigo Morales 0001, Foutse Khomh, Yann-Gaël Guéhéneuc, Giuliano Antoniol |
Empir. Softw. Eng. | 2 |
| 2018 | Efficient refactoring scheduling based on partial order reduction
Rodrigo Morales 0001, Francisco Chicano, Foutse Khomh, Giuliano Antoniol |
J. Syst. Softw. | 1 |
| 2018 | EARMO: An Energy-Aware Refactoring Approach for Mobile AppsabstractThe energy consumption of mobile apps is a trending topic and researchers are actively investigating the role of coding practices on energy consumption. Recent studies suggest that design choices can conflict with energy consumption. Therefore, it is important to take into account energy consumption when evolving the design of a mobile app. In this paper, we analyze the impact of eight type of anti-patterns on a testbed of 20 android apps extracted from F-Droid. We propose EARMO, a novel anti-pattern correction approach that accounts for energy consumption when refactoring mobile anti-patterns. We evaluate EARMO using three multiobjective search-based algorithms. The obtained results show that EARMO can generate refactoring recommendations in less than a minute, and remove a median of 84 percent of anti-patterns. Moreover, EARMO extended the battery life of a mobile phone by up to 29 minutes when running in isolation a refactored multimedia app with default settings (no Wi-Fi, no location services, and minimum screen brightness). Finally, we conducted a qualitative study with developers of our studied apps, to assess the refactoring recommendations made by EARMO. Developers found 68 percent of refactorings suggested by EARMO to be very relevant. Rodrigo Morales 0001, Rubén Saborido, Foutse Khomh, Francisco Chicano, Giuliano Antoniol |
IEEE Trans. Software Eng. | 1 |
| 2017 | On the use of developers' context for automatic refactoring of software anti-patterns
Rodrigo Morales 0001, Zéphyrin Soh, Foutse Khomh, Giuliano Antoniol, Francisco Chicano |
J. Syst. Softw. | 1 |
| 2016 | Finding the Best Compromise Between Design Quality and Testing Effort During RefactoringabstractAnti-patterns are poor design choices that hinder code evolution, and understandability. Practitioners perform refactoring, that are semantic-preserving-code transformations, to correct anti-patterns and to improve design quality. However, manual refactoring is a consuming task and a heavy burden for developers who have to struggle to complete their coding tasks and maintain the design quality of the system at the same time. For that reason, researchers and practitioners have proposed several approaches to bring automated support to developers, with solutions that ranges from single anti-patterns correction, to multiobjective solutions. The latter approaches attempted to reduce refactoring effort, or to improve semantic similarity between classes and methods in addition to removing anti-patterns. To the best of our knowledge, none of the previous approaches have considered the impact of refactoring on another important aspect of software development, which is the testing effort. In this paper, we propose a novel search-based multiobjective approach for removing five well-known anti-patterns and minimizing testing effort. To assess the effectiveness of our proposed approach, we implement three different multiobjective metaheuristics (NSGA-II, SPEA2, MOCell) and apply them to a benchmark comprised of four open-source systems. Results show that MOCell is the metaheuristic that provides the best performance. Rodrigo Morales 0001, Aminata Sabané, Pooya Musavi, Foutse Khomh, Francisco Chicano, Giuliano Antoniol |
SANER | 1 |
| 2015 | Towards a framework for automatic correction of anti-patternsabstractOne of the biggest concerns in software maintenance is design quality; poor design hinders software maintenance and evolution. One way to improve design quality is to detect and correct anti-patterns (i.e., poor solutions to design and implementation problems), for example through refactorings. There are several approaches to detect anti-patterns, that rely on metrics and structural properties. However, finding a specific solution to remove anti-patterns is a challenging task as candidate refactorings can be conflicting and their number very large, making it costly. Hence, development teams often have to prioritize the refactorings to be applied on a system. In addition to this, refactoring is risky, since non-experienced developers can change the behaviour of a system, without a comprehensive test suite. Therefore, there is a need for tools that can automatically remove anti-patterns. We will apply meta-heuristics to propose a technique for automated refactoring that improves design quality. Rodrigo Morales 0001 |
SANER | 1 |
| 2015 | Do code review practices impact design quality? A case study of the Qt, VTK, and ITK projectsabstractCode review is the process of having other team members examine changes to a software system in order to evaluate its technical content and quality. A lightweight variant of this practice, often referred to as Modern Code Review (MCR), is widely adopted by software organizations today. Previous studies have established a relation between the practice of code review and the occurrence of post-release bugs. While the prior work studies the impact of code review practices on software release quality, it is still unclear what impact code review practices have on software design quality. Therefore, using the occurrence of 7 different types of anti-patterns (i.e., poor solutions to design and implementation problems) as a proxy for software design quality, we set out to investigate the relationship between code review practices and software design quality. Through a case study of the Qt, VTK and ITK open source projects, we find that software components with low review coverage or low review participation are often more prone to the occurrence of anti-patterns than those components with more active code review practices. Rodrigo Morales 0001, Shane McIntosh, Foutse Khomh |
SANER | 1 |