VLDB 2026 Research / reviewers in the wild / expert
Negar Ghorbani
dblp:204/3571
· DBLP profile ↗
11ranked-venue papers
5as first author
7since 2021 · last 2025
0000-0002-0528-6138ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 10 · 5 first-author · 7 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Corrigendum to "Bringing architecture-based adaption to the mainstream" [Inf. Softw. Technol. 176 (2024) 107550]
Negar Ghorbani, Joshua Garcia, Sam Malek |
Inf. Softw. Technol. | 1 |
| 2024 | Bringing architecture-based adaption to the mainstream
Negar Ghorbani, Joshua Garcia, Sam Malek |
Inf. Softw. Technol. | 1 |
| 2024 | Darcy: Automatic Architectural Inconsistency Resolution in JavaabstractMany mainstream programming languages lack extensive support for architectural constructs, such as software components, which limits software developers in employing many benefits of architecture-based development. To address this issue, Java, one of the most popular and widely-used programming languages, has introduced the Java Platform Module System (JPMS) in its 9th and subsequent versions. JPMS provides the notion of architectural constructs, i.e., software components, as an encapsulation of modules that helps developers construct and maintain large applications efficiently—as well as improving the encapsulation, security, and maintainability of Java applications in general and the JDK itself. However, ensuring that module declarations reflect the actual usage of modules in an application remains a challenge that results in developers mistakenly introducing inconsistent module dependencies at both compile- and run-time. In this paper, we studied JPMS properties and architectural notions in-depth and defined a defect model consisting of eight inconsistent modular dependencies that may arise in Java applications. Based on this defect model, we also present DARCY, a framework that leverages the defect model and static analysis techniques to automatically detect and repair the specified inconsistent dependencies within Java applications at both compile- and run-time. The results of our experiments, conducted over 52 open-source Java 9+ applications, indicate that architectural inconsistencies are widespread and demonstrate DARCY’s effectiveness for automated resolution of these inconsistencies. Negar Ghorbani, Tarandeep Singh, Joshua Garcia, Sam Malek |
IEEE Trans. Software Eng. | 1 |
| 2023 | DeltaDroid: Dynamic Delivery Testing in AndroidabstractAndroid is a highly fragmented platform with a diverse set of devices and users. To support the deployment of apps in such a heterogeneous setting, Android has introduced dynamic delivery —a new model of software deployment in which optional, device- or user-specific functionalities of an app, called Dynamic Feature Modules (DFMs) , can be installed, as needed, after the app’s initial installation. This model of app deployment, however, has exacerbated the challenges of properly testing Android apps. In this article, we first describe the results of an extensive study in which we formalized a defect model representing the various conditions under which DFM installations may fail. We then present DeltaDroid —a tool aimed at assisting the developers with validating dynamic delivery behavior in their apps by augmenting their existing test suite. Our experimental evaluation using real-world apps corroborates DeltaDroid ’s ability to detect many crashes and unexpected behaviors that the existing automated testing tools cannot reveal. Negar Ghorbani, Reyhaneh Jabbarvand Behrouz, Navid Salehnamadi, Joshua Garcia, Sam Malek |
ACM Trans. Softw. Eng. Methodol. | 1 |
| 2022 | Program merge conflict resolution via neural transformersabstractCollaborative software development is an integral part of the modern software development life cycle, essential to the success of large-scale software projects. When multiple developers make concurrent changes around the same lines of code, a merge conflict may occur. Such conflicts stall pull requests and continuous integration pipelines for hours to several days, seriously hurting developer productivity. To address this problem, we introduce MergeBERT, a novel neural program merge framework based on token-level three-way differencing and a transformer encoder model. By exploiting the restricted nature of merge conflict resolutions, we reformulate the task of generating the resolution sequence as a classification task over a set of primitive merge patterns extracted from real-world merge commit data. Our model achieves 63–68% accuracy for merge resolution synthesis, yielding nearly a 3× performance improvement over existing semi-structured, and 2× improvement over neural program merge tools. Finally, we demonstrate that MergeBERT is sufficiently flexible to work with source code files in Java, JavaScript, TypeScript, and C# programming languages. To measure the practical use of MergeBERT, we conduct a user study to evaluate MergeBERT suggestions with 25 developers from large OSS projects on 122 real-world conflicts they encountered. Results suggest that in practice, MergeBERT resolutions would be accepted at a higher rate than estimated by automatic metrics for precision and accuracy. Additionally, we use participant feedback to identify future avenues for improvement of MergeBERT. Alexey Svyatkovskiy, Sarah Fakhoury, Negar Ghorbani, Todd Mytkowicz, Elizabeth Dinella, Christian Bird, Jinu Jang, Neel Sundaresan, Shuvendu K. Lahiri |
ESEC/SIGSOFT FSE | 3 |
| 2022 | Forecasting Architectural Decay From Evolutionary HistoryabstractAs a software system evolves, its architecture tends to decay, leading to the occurrence of architectural elements that become resistant to maintenance or prone to defects. To address this problem, engineers can significantly benefit from determining which architectural elements will decay before that decay actually occurs. Forecasting decay allows engineers to take steps to prevent decay, such as focusing maintenance resources on the architectural elements most likely to decay. To that end, we construct novel models that predict the quality of an architectural element by utilizing multiple architectural views (both structural and semantic) and architectural metrics as features for prediction. We conduct an empirical study using our prediction models on 38 versions of five systems. Our findings show that we can predict low architectural quality, i.e., architectural decay, with high performance—even for cases of decay that suddenly occur in an architectural module. We further report the factors that best predict architectural quality. Joshua Garcia, Ehsan Kouroshfar, Negar Ghorbani, Sam Malek |
IEEE Trans. Software Eng. | 3 |
| 2021 | Flair: efficient analysis of Android inter-component vulnerabilities in response to incremental changes
Hamid Bagheri, Jianghao Wang, Jarod Aerts, Negar Ghorbani, Sam Malek |
Empir. Softw. Eng. | 4 |
| 2020 | Modeling and Evaluation of Service Composition in Commercial Multiclouds Using Timed Colored Petri NetsabstractThe increasing demand for Web services encourages commercial cloud service providers to publish their own services with various functional and nonfunctional capabilities in different cloud platforms. The aggregation of atomic services from multiple service repositories is the main idea of the service composition concept in multiclouds. The cloud Web service composition is a suitable way for satisfying users' complex requests by integrating services from different clouds in order to create a new value-added composite service. The time required to serve a composite service by a multicloud environment is an important parameter, which depends on different factors, ranging from the service composition and selection algorithm to the number of atomic services published in the clouds. In this paper, a model based on timed colored Petri nets (TCPNs) is proposed to evaluate the service composition in multicloud environments while minimizing the number of clouds involved in serving a composite service request. The proposed TCPN graphically models the process of request submission, composite service analysis, service selection, and service provisioning in a multicloud environment. It also assesses both mean response time of the environment and probability of dropping composite requests. The verification of the accuracy of the proposed model is done by comparing the results obtained from the TCPN model, in two different scenarios, with the results from the CloudSim framework. These results confirm that our proposed TCPN model can appropriately model the system and evaluate its performance more efficiently than the CloudSim. Reza Entezari-Maleki, Ehsan Etesami, Negar Ghorbani, Arian Akhavan Niaki, Leonel Sousa, Ali Movaghar-Rahimabadi |
IEEE Trans. Syst. Man Cybern. Syst. | 3 |
| 2019 | Detection and repair of architectural inconsistencies in JavaabstractJava is one of the most widely used programming languages. However, the absence of explicit support for architectural constructs, such as software components, in the programming language itself has prevented software developers from achieving the many benefits that come with architecture-based development. To address this issue, Java 9 has introduced the Java Platform Module System (JPMS), resulting in the first instance of encapsulation of modules with rich software architectural interfaces added to a mainstream programming language. The primary goal of JPMS is to construct and maintain large applications efficiently-as well as improve the encapsulation, security, and maintainability of Java applications in general and the JDK itself. A challenge, however, is that module declarations do not necessarily reflect actual usage of modules in an application, allowing developers to mistakenly specify inconsistent dependencies among the modules. In this paper, we formally define 8 inconsistent modular dependencies that may arise in Java-9 applications. We also present DARCY, an approach that leverages these definitions and static program analyses to automatically (1) detect the specified inconsistent dependencies within Java applications and (2) repair those identified inconsistencies. The results of our experiments, conducted over 38 open-source Java-9 applications, indicate that architectural inconsistencies are widespread and demonstrate the benefits of DARCY in automated detection and repair of these inconsistencies. Negar Ghorbani, Joshua Garcia, Sam Malek |
ICSE | 1 |
| 2018 | A temporal permission analysis and enforcement framework for AndroidabstractPermission-induced attacks, i.e., security breaches enabled by permission misuse, are among the most critical and frequent issues threatening the security of Android devices. By ignoring the temporal aspects of an attack during the analysis and enforcement, the state-of-the-art approaches aimed at protecting the users against such attacks are prone to have low-coverage in detection and high-disruption in prevention of permission-induced attacks. To address this shortcomings, we present Terminator, a temporal permission analysis and enforcement framework for Android. Leveraging temporal logic model checking,Terminator's analyzer identifies permission-induced threats with respect to dynamic permission states of the apps. At runtime, Terminator's enforcer selectively leases (i.e., temporarily grants) permissions to apps when the system is in a safe state, and revokes the permissions when the system moves to an unsafe state realizing the identified threats. The results of our experiments, conducted over thousands of apps, indicate that Terminator is able to provide an effective, yet non-disruptive defense against permission-induced attacks. We also show that our approach, which does not require modification to the Android framework or apps' implementation logic, is highly reliable and widely applicable. Reyhaneh Jabbarvand Behrouz, Negar Ghorbani, Hamid Bagheri, Sam Malek |
ICSE | 3 |
| 2017 | Automatic generation of inter-component communication exploits for Android applicationsabstractAlthough a wide variety of approaches identify vulnerabilities in Android apps, none attempt to determine exploitability of those vulnerabilities. Exploitability can aid in reducing false positives of vulnerability analysis, and can help engineers triage bugs. Specifically, one of the main attack vectors of Android apps is their inter-component communication interface, where apps may receive messages called Intents. In this paper, we provide the first approach for automatically generating exploits for Android apps, called LetterBomb, relying on a combined path-sensitive symbolic execution-based static analysis, and the use of software instrumentation and test oracles. We run LetterBomb on 10,000 Android apps from Google Play, where we identify 181 exploits from 835 vulnerable apps. Compared to a state-of-the-art detection approach for three ICC-based vulnerabilities, LetterBomb obtains 33%-60% more vulnerabilities at a 6.66 to 7 times faster speed. Joshua Garcia, Mahmoud Hammad, Negar Ghorbani, Sam Malek |
ESEC/SIGSOFT FSE | 3 |