Samer Zein

dblp:178/8386 · also Samer Zain · DBLP profile ↗
← Back
8ranked-venue papers
4as first author
4since 2021 · last 2027
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 6 · 4 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2027 Adversarial vulnerability under temporal concept drift: A longitudinal study of android malware detection
Ahmed Sabbah, Mohammed Kharma, Radi Jarrar, Samer Zein, David Mohaisen
Expert Syst. Appl.4
2026 Understanding Concept Drift With Deprecated Permissions in Android Malware Detection
abstract
Android's permission system evolves as permissions are deprecated, restricted, or reserved for system use, altering the feature space for malware detection and introducing concept drift. We study how these changes affect machine learning models using a dataset of over 70k applications and 166 permissions. Across ML and DL classifiers, removing restricted permissions without considering time reduces accuracy by 1.3–2.1 percentage points, while excluding deprecated or not-for-third-party permissions has marginal effects. When training on one year and testing on others, dataset balancing improves F1 scores and converts many critical-drift cases into regular drift, but also increases the number of drift-affected years across permission groups. Using Kolmogorov–Smirnov tests (F1, p → 0.05), balancing increases significant drift detections on both real devices and emulators. To examine platform evolution, we introduce Android-version–specific detectors and summarize temporal robustness with the AUT and A-AUT metrics, observing lower forward-transfer performance and greater stability for RF and RNNs. Finally, adversarial abuse of deprecated and restricted permissions yields higher attack success under drift, up to 55%, with reduced impact in later years as the permission space stabilizes. Overall, permission evolution, dataset balance, OS versioning, and adversarial manipulation each induce distinct drift patterns, offering quantitative guidance for designing adaptive, permission-aware malware detection models.
Ahmed Sabbah, Radi Jarrar, Samer Zein, David Mohaisen
IEEE Trans. Dependable Secur. Comput.3
2023 Empirical Observations on Requirements Engineering Practices in Palestine
abstract
Requirements Engineering (RE) is critical to the success of software development projects. Industrial software projects that apply poor RE practices usually suffer from severe quality challenges and even project failures. Even though RE has been drawing more attention in the literature, there is a lack of empirical evidence of RE practices and challenges at industrial contexts. To address this we carried out a study to evaluate the perspectives of software engineers on their RE practices to understand more about how software engineers approach RE process and what are the challenges they face. We conducted a multi-case study by interviewing 8 participants from 5 software development companies in Palestine. Our results show that for all the RE process seems to be fairly systematic with whole team involvement. Further, the agile RE model is the dominant model, and over half reported that key challenges are caused by issues that originated from the client side. Finally, we highlight interesting future RE research from the perspective of industrial practitioners.
Samer Zein, Norsaremah Salleh, John C. Grundy
SoMeT1
2023 Systematic reviews in mobile app software engineering: A tertiary study
abstract
Context: A number of secondary studies in the form of systematic reviews and systematic mapping studies exist in the area of mobile application software engineering. Objective: The focus of this paper is to provide an overview and analysis of these secondary studies of mobile app software engineering for researchers and practitioners. Method: We conducted a systematic tertiary study following the guidelines by Kitchenham et al. to classify and analyze secondary studies in this area. Results: After going through several filtration steps, we identified 24 secondary studies addressing major software engineering phases, such as initiation, requirements engineering , design, development and testing. The majority of the secondary studies focused on testing and design phases. Specific research topics addressed by the included studies were: usability evaluation , test automation, context-aware testing, cloud-based development, architectural models , effort and size estimation models, defect prediction , and GUI testing. We found that the trend in secondary studies is towards more specific areas of mobile application software engineering such as architectural design models, context-aware testing, testing of non-functional requirements, mobile cloud computing , and intelligent mobile applications. Research directions and some identified practices for practitioners were also identified. Conclusions: Mobile application software engineering is an active research area. The area can benefit from additional research in terms of secondary studies targeting evolution, maintenance, requirements engineering, and cross-platform mobile application development. Additionally, some of the secondary studies identify some useful practices for practitioners.
Samer Zein, Norsaremah Salleh, John C. Grundy
Inf. Softw. Technol.1
2020 REST API Auto Generation: A Model-Based Approach
abstract
Most of software products, especially mobile applications (apps) rely on a back-end web services to communicate with a shared data repository. Statistics have demonstrated exponential demand on web services, mainly REST, due to the continuous adoption of IoT (Internet of Things) and Cloud Computing. However, the development of back-end REST web services is not a trivial task, and can be intimidating even for seasoned developers. Despite the fact that there are several studies that focus on automatic generation of REST APIs, we argue that those approaches violate the rules of code flexibility and are not appropriate for novice developers. In this study, we present an approach and a framework, named RAAG (REST Api Auto-Generation), that aims to improve productivity by simplifying the development of REST web services. Our RAAG framework abstracts layers, where code generation has been avoided due its limitations. A preliminary evaluation shows that RAAG can significantly improves development productivity and is easy to operate even by novice developers.
Salah Hussein, Samer Zein, Norsaremah Salleh
SoMeT2
2018 Automatic Generation of Android SQLite Database Components
abstract
Mobile applications (apps) are becoming ubiquitous and at the same time getting more complex to develop. Specific development tools and techniques are always essential to facilitate the development of reliable and cost effective mobile apps. However, a large fraction of Android app developers are known to be novice and come from non-computing background. To assist developers, this paper addresses the problem of automatic generation of Android database components, and presents a technique for creating SQLite database and APIs. The technique is based on a tool named Android SQLite Creator (ASQLC) that can automatically generate Android SQLite database as well as the API classes that perform read/write operation on that database. To evaluate the tool, a preliminary experiment was conducted by junior computer science students in building a small size Android database. This preliminary evaluation shows that our tool can be usable and promising particularly for novice developers.
Iman Musleh, Samer Zein, Mamoun Nawahdah, Norsaremah Salleh
SoMeT2
2016 A systematic mapping study of mobile application testing techniques
Samer Zein, Norsaremah Salleh, John C. Grundy
J. Syst. Softw.1
2015 Mobile Application Testing in Industrial Contexts: An Exploratory Multiple Case-Study
Samer Zein, Norsaremah Salleh, John C. Grundy
SoMeT1