Hideyuki Kanuka

dblp:185/2327 · DBLP profile ↗
← Back
15ranked-venue papers
0as first author
9since 2021 · last 2026
0000-0002-8560-8714ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 13 · 9 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Revealing Reversed Causal Effects in Bug-Fix Delays: A LiNGAM-Based Comparison Between OSS and Enterprise Systems
Ryo Masuda, Takahiro Kinoshita, Hideyuki Kanuka, Sien Reeve Ordonez Peralta, Hironori Washizaki, Masanari Kondo
SANER3
2024 Enhancing Source Code Comment Generation via Retrieval-Augmented Generation with Design Document Term Dictionary
abstract
Effective software development depends on clear code comments for better understanding. We introduce a method for generating automated source-code comments using retrieval-augmented generation (RAG) with a design document term dictionary. This method aligns terms and their meanings from design documents with lines of source code, producing comments that clearly reflect the source-code's intent and functionality. Our evaluations on the open-source software iDempiere show significant improvements: context precision increased by 22% and faithfulness by 17 % compared with conventional RAG methods These results confirm our method's validity. Therefore, we plan to explore its application to different software contexts in future work.
Kazu Nishikawa, Genta Koreki, Hideyuki Kanuka
APSEC3
2024 Unraveling the Influences on Bug Fixing Time: A Comparative Analysis of Causal Inference Model
abstract
In this study, we employ causal inference models, specifically Bayesian Networks (BN) and Linear Non-Gaussian Acyclic Models (LiNGAM), to investigate the determinants of Bug Fixing Time (BFT) in software development. Moving beyond traditional statistical analyses, our approach aims to identify the true causal factors influencing BFT. Our findings indicate that ’Reporter Reputation’, ’Severity’, and ’Blocker’ status are significant determinants of BFT, with notable differences between bugs reported by users versus developers. This research challenges existing assumptions about the necessity of comprehensive bug reports and underscores the importance of understanding bug resolution’s complexity and organizational context. By applying causal inference models, we offer actionable insights for improving bug prioritization, operational efficiency, and predictive management of development bottlenecks, enhancing the software development lifecycle. Our study bridges the theoretical and practical aspects of software quality optimization and introduces a novel perspective on managing software development processes. Additionally, our analysis reveals counterintuitive results that further contribute to our understanding of the dynamics influencing BFT.
Sien Reeve Ordonez Peralta, Hironori Washizaki, Yoshiaki Fukazawa, Yuki Noyori, Shuhei Nojiri, Hideyuki Kanuka
EASE6
2024 Test-suite-guided discovery of least privilege for cloud infrastructure as code
Ryo Shimizu, Yuna Nunomura, Hideyuki Kanuka
Autom. Softw. Eng.3
2023 Analysis of Bug Report Qualities with Fixing Time using a Bayesian Network
abstract
Most client software employs a bug-tracking system, which utilizes user-submitted reports (bug reports) that contain information necessary for software developers to fix bugs. The quality of bug reports drastically differs. Bug reports can include severity, priority, and associated issues determined by researching the addressed bug. Herein we investigate the influence of bug report qualities on successfully fixing a bug and estimating the fixing time. We also examine the claim in previous studies that bias and differences in the treatment of bug reports exist due to broad expertness among the reporters. Our approach examines the relationship between the qualities within the bug-fixing cycle and modeling graphical causal dependencies through a Bayesian Network. Bug reports with attachments, dependencies on another bug, and frequent discussions are more likely to be fixed. In addition, bug reports with a high severity tend to be fixed faster. Moreover, the difficulty of the bug itself may influence the fixing rate such that a straightforward bug will be fixed easier and faster regardless of the bug report quality.
Sien Reeve Ordonez Peralta, Hironori Washizaki, Yoshiaki Fukazawa, Yuki Noyori, Shuhei Nojiri, Hideyuki Kanuka
EASE6
2023 Leveraging Execution Trace with ChatGPT: A Case Study on Automated Fault Diagnosis
abstract
ChatGPT possesses the ability to identify potential causes of bugs in a program, which can be used for fault diagnosis. Although ChatGPT cannot always provide accurate responses, it can provide the confidence level that is trained to be correlated with the accuracy of the response, and the confidence level helps verify the accuracy of responses. Through preliminary trials, we found that the explanatory power of potential causes and the confidence level became low even for accurate responses when runtime information is needed to identify the causes of bugs. In this study, we propose a method to construct prompts based on the target program and its execution traces to improve the accuracy of fault diagnosis by ChatGPT. Through case studies using five bugs from Defects4J, we obtained the following two results: (1) For four bugs, the explanatory power of the responses to potential bug causes improved using the information contained in the execution traces. (2) For three bugs, the confidence level was higher for the accurate responses when execution traces were available than when they were not. These results suggest that by using program execution traces in prompts, the accuracy of fault diagnosis by ChatGPT can be improved.
Takafumi Sakura, Ryo Soga, Hideyuki Kanuka, Kazumasa Shimari, Takashi Ishio
ICSME3
2023 Will you use software development support using biosignals? A survey from software developers
abstract
Biosignals reflect the mental states of software developers and could improve support technologies for software development activities.Although several technologies for software development support using biosignals (BioSDS) have been proposed, BioSDS has not yet been deployed in actual software development workplaces.As a prerequisite for industrial deployment, BioSDS must be well understood and accepted by software developers.However, the current level of their acceptance has not been comprehensively assessed.In this study, we conducted a survey to clarify the current level of acceptance of BioSDS and potential attributes that influence the level of acceptance.We defined eleven use-cases based on six previous primary studies related to BioSDS, and then asked developers at Hitachi, a Japanese IT company in the FORTUNE 500, about the level of acceptance of each use-case.Our analysis of eighty-six responses revealed that four out of eleven use-cases had some level of acceptance by software developers.In addition, we found four attributes that affect the level of acceptance: subject to be measured, objectives, interventions, and timing.These findings help to identify barriers to the adoption of BioSDS in the workplace.
Ryo Soga, Hideyuki Kanuka, Takatomi Kubo, Takashi Ishio, Ken-ichi Matsumoto
SEKE2
2022 Risk assessment to design business process incorporating AI tasks
abstract
Minimizing the risk of harm to stakeholders is required when incorporating AI tasks into business processes (BPs). Oneway to reduce the risk is to redundantly incorporate both of AI and human tasks. Multiple BPs incorporating them can be considered and it is not obvious which BP can minimize the risk. In this study, we propose a risk assessment methodto design BPs incorporating AI tasks following the ISO guideline that recommends managing the severity and likelihood of each risk source. A case study showed that the proposed method might be useful for designing BPs incorporating AI tasks.
Ryo Soga, Hideyuki Kanuka, Daisuke Fukui, Masayoshi Mase
APSEC2
2021 Generating Program Identifier Dictionary for Maintaining Legacy Systems
abstract
Descriptions of program identifiers improve the maintainability of programs. Modern software projects maintain proper descriptions by following coding conventions. However, software projects maintained for a long time have two problems: (i) descriptions at incorrect locations and (ii) no descriptions. We propose the method of generating a identifier dictionary for managing identifiers and their descriptions, which enables developers to refer to identifier descriptions from anywhere within programs. The method involves two steps: (i) extracting identifiers and descriptions from design documents and programs and (ii) generating descriptions using information-retrieval and machine-learning methods. We applied the proposed method to COBOL programs and design documents of a legacy system that has been maintained for over 20 years as a case study. The proposed method obtained the descriptions of 83% of identifiers and reduced the cost of locating files to be modified by enhancing search keywords using the identifier dictionary. This means that the proposed method can improve the maintainability of systems maintained over many years.
Ryo Soga, Genta Koreki, Hideyuki Kanuka, Akira Ioku, Jun Maeoka
SoMeT3
2020 A Program Simplification Method for Generating Test Input Values Using Symbolic Execution
abstract
Symbolic execution can automatically generate test input values that cover the execution paths of programs. It enables us to test functions of even huge COBOL legacy programs, but the execution time substantially increases when the number of instructions in the input program is large. In this research, we propose a method that removes instructions that do not affect execution paths using program slicing. Applying the method to three functions in COBOL programs reduced the execution time by up to 70% by removing instructions that manipulate variables not related to the execution paths. This result suggests that our method enables symbolic execution to generate input values even from huge COBOL programs.
Ryo Soga, Tetsuya Yonemitsu, Mitsuo Inagaki, Yasushi Fujisaki, Hiroo Sugou, Hideyuki Kanuka
APSEC6
2020 Test-Based Least Privilege Discovery on Cloud Infrastructure as Code
abstract
Infrastructure as Code (IaC) for cloud is an important practice due to its efficient and reproducible provisioning of cloud environments. On a cloud IaC definition (template), developers need to manage permissions for each cloud services as well as a desired cloud environment. To minimize the risk of cyber-attacks, retaining least privilege, i.e., giving a minimum set of permissions, on IaC templates is important and widely regarded as best practice. However, discovering least privilege on a target IaC template at one time is an error-prone and burdensome task for developers. One reason is that some actions of a cloud service implicitly use other services and require corresponding permissions, which are hard to recognize without actual executions on the cloud and burden the development process with iterations of permission setting and provisioned result checking. In this paper, we present a technique to automatically discover least privilege. Our method incrementally finds the least privilege by the iteration of testing on the cloud and (re)configuring permissions on the basis of test results. We conducted case studies and found that our approach can identify least privilege on Amazon Web Services within a practical time. Our experiments also show that the proposed algorithm can reduce the number of test executions, which directly affects the time and cost on cloud to determine least privilege, by 69.3% and 39.8% compared with the random and heuristic methods, respectively, on average.
Ryo Shimizu, Hideyuki Kanuka
CloudCom2
2019 What are Good Discussions Within Bug Report Comments for Shortening Bug Fixing Time?
abstract
Bugs must be resolved efficiently for developers' limited resources. Bug reports are necessary for the bug modification process. Service user reports a bug as a bug report. Developer read bug reports and fix bugs. The developer can make discussion by posting comments on reported bug reports. There are several researches on the initial report of the bug report so that bugs can be fixed efficiently. But there are few researches on bug report comments. We focus on comments on bug reports. Currently, everyone is free to comment, but the modification time may be affected by how to comment. We investigate the topic of comments of the bug report. As a result of the investigation, the fact that the topics are mixed does not affect the modification time, however we found a tendency to shorten the modification time when the topic of the solution started early.
Yuki Noyori, Hironori Washizaki, Yoshiaki Fukazawa, Keishi Oshima, Hideyuki Kanuka, Shuhei Nojiri, Ryosuke Tsuchiya
QRS5
2018 A Preprocessing Method of Test Input Generation by Symbolic Execution for Enterprise Application
abstract
Techniques for automatically generating test input values by symbolic execution have been studied. However, the existing symbolic execution tool has a problem that it is difficult to apply it to enterprise applications because there are several reasons, for example, that a program using the function of the enterprise application framework can not be analyzed. In this paper, we propose a method for generating test input values for enterprise applications using symbolic execution, without having to modify the symbolic execution tool, by the preprocessing that converts enterprise application programs into programs to be accepted by existing symbolic execution tools. In addition, we implement the proposed method as a test input generation system and show how to combine the proposed preprocessing and existing symbolic execution techniques.
Hiroki Ohbayashi, Hideyuki Kanuka, Chikashi Okamoto
APSEC2
2018 Cloud Security and Privacy Metamodel - Metamodel for Security and Privacy Knowledge in Cloud Services
Hironori Washizaki, Takehisa Kato, Haruhiko Kaiya, Shinpei Ogata, Eduardo B. Fernández, Hideyuki Kanuka, Masayuki Yoshino, Dan Yamamoto, Takao Okubo, Nobukazu Yoshioka, Atsuo Hazeyama
MODELSWARD7
2016 A Metamodel for Security and Privacy Knowledge in Cloud Services
abstract
We propose a metamodel for handling security and privacy in cloud service development and operation. The metamodel is expected to be utilized for building a knowledge base to accumulate, classify and reuse existing cloud security and privacy patterns and practices in a consistent and uniform way. Moreover the metamodel and knowledge base are expected to be utilized for designing and maintaining architectures for cloud service systems incorporating security and privacy.
Hironori Washizaki, Sota Fukumoto, Misato Yamamoto, Masatoshi Yoshizawa, Yoshiaki Fukazawa, Takehisa Kato, Shinpei Ogata, Haruhiko Kaiya, Eduardo B. Fernández, Hideyuki Kanuka, Yuki Kondo, Nobukazu Yoshioka, Takao Okubo, Atsuo Hazeyama
SERVICES10