Tarannum S. Zaman

dblp:204/3669 · also Tarannum Shaila Zaman · DBLP profile ↗
← Back
11ranked-venue papers
2as first author
9since 2021 · last 2027
0000-0002-8634-524XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 6 · 2 first-author · 4 since 2021Security and privacy · 3 · 3 since 2021Computer networks · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2027 NLP Techniques for software debugging tasks: A systematic literature review covering bug report analysis, bug reproduction, and localization
abstract
Efficient debugging is essential for software maintenance, as identifying, reproducing, and correcting bugs are critical to ensuring software reliability. However, debugging remains a time-consuming and cost-sensitive activity due to the complexities involved in analyzing and resolving bugs throughout the software development lifecycle. Recent advancements in Artificial Intelligence, Machine Learning, and particularly Natural Language Processing (NLP), and Large Language Models (LLM) offer promising opportunities to enhance debugging process. Since bug reports are typically written in natural language, NLP techniques can streamline debugging tasks, such as bug categorization, localization, and resolution. To assess the potential of NLP in debugging, we conduct a Systematic Literature Review (SLR) of 87 research papers published between 2011 and 2025. Our study presents a comprehensive taxonomy of research efforts, evaluates the effectiveness and limitations of various NLP methods, and highlights best practices across key software debugging tasks, including bug reproduction, bug localization, and bug report analysis. Furthermore, we identify significant challenges in real-world applications, including issues with scalability, accuracy, and adaptability to diverse software environments. Finally, we derive seven findings from our result analysis and propose future research directions corresponding to the findings, to advance NLP-driven debugging practices. This study provides a holistic overview of NLP in debugging for researchers, practitioners, and tool developers, helping to uncover trends, address gaps, and inspire new approaches to improving software maintenance workflows.
Lutfun Nahar Lota, Tarannum S. Zaman, Mirza Mohammad Azwad, Labiba Farah, Abrar Chowdhury, Zaarin Anjum, Chadni Islam, Abu Raihan M. Kamal
Sci. Comput. Program.2
2026 From Preventive to Reactive: How AI Coding Assistants Transform Developers' Security Awareness
Faisal Haque Bappy, Tahrim Hossain, Sidratul Muntaher Meheraj, Annoor Sharara Akhand, Tasfia Tabassum, Tarannum S. Zaman, Raiful Hasan, Tariqul Islam 0001
SOUPS6
2026 SysPro: Reproducing system-level concurrency bugs from bug reports
Tarannum S. Zaman, Chadni Islam, Jiangfan Shi, Zihan Shi, Fiona Xian, Tingting Yu 0001
J. Syst. Softw.1
2025 SEAM: A Secure Automated and Maintainable Smart Contract Upgrade Framework
abstract
This work addresses the critical challenges of upgrading smart contracts, which are vital for trust in automated transactions but difficult to modify once deployed. To address this issue, we propose SEAM, a novel framework that automates the conversion of standard Solidity contracts into upgradable versions using the diamond pattern. SEAM simplifies the upgrade process and addresses two key vulnerabilities: function selector clashes and storage slot collisions. Additionally, the framework provides tools for efficiently deploying, modifying, and managing smart contract lifecycles. By enhancing contract security and reducing the learning curve for developers, SEAM lays a robust foundation for more flexible and maintainable blockchain applications.
Tahrim Hossain, Faisal Haque Bappy, Tarannum S. Zaman, Tariqul Islam 0001
CCNC3
2025 CrossLink: A Decentralized Framework for Secure Cross-Chain Smart Contract Execution
abstract
This paper introduces CrossLink, a decentralized framework for secure cross-chain smart contract execution that effectively addresses the inherent limitations of contemporary solutions, which primarily focus on asset transfers and rely on potentially vulnerable centralized intermediaries. Recognizing the escalating demand for seamless interoperability among decentralized applications, CrossLink provides a trustless mechanism for smart contracts across disparate blockchain networks to communicate and interact. At its core, CrossLink utilizes a compact chain for selectively storing authorized contract states and employs a secure inter-chain messaging mechanism to ensure atomic execution and data consistency. By implementing a deposit/collateral fee system and efficient state synchronization, CrossLink enhances security and mitigates vulnerabilities, offering a novel approach to seamless, secure, and decentralized cross-chain interoperability. A formal security analysis further validates CrossLink’s robustness against unauthorized modifications and denial-of-service attacks.
Tahrim Hossain, Faisal Haque Bappy, Tarannum S. Zaman, Tariqul Islam 0001
ICBC3
2025 Bridging Immutability with Flexibility: A Scheme for Secure and Efficient Smart Contract Upgrades
abstract
The emergence of blockchain technology has revolutionized contract execution through the introduction of smart contracts. Ethereum, the leading blockchain platform, leverages smart contracts to power decentralized applications (DApps), enabling transparent and self-executing systems across various domains. While the immutability of smart contracts enhances security and trust, it also poses significant challenges for updates, defect resolution, and adaptation to changing requirements. Existing upgrade mechanisms are complex, resource-intensive, and costly in terms of gas consumption, often compromising security and limiting practical adoption. To address these challenges, we propose FlexiContracts+, a novel scheme for secure, in-place smart contract upgrades on Ethereum that preserves historical data without relying on multiple contracts or extensive pre-deployment planning. FlexiContracts+ enhances security, simplifies development, reduces engineering overhead, and supports adaptable, expandable smart contracts. Comprehensive testing demonstrates that FlexiContracts+ achieves a practical balance between immutability and flexibility, advancing the capabilities of smart contract systems.
Tahrim Hossain, Sakib Hassan, Faisal Haque Bappy, Muhammad Nur Yanhaona, Tarannum S. Zaman, Tariqul Islam 0001
ICBC5
2024 FASTEN: Towards a FAult-Tolerant and STorage EfficieNt Cloud: Balancing Between Replication and Deduplication
abstract
With the surge in cloud storage adoption, enterprises face challenges managing data duplication and exponential data growth. Deduplication mitigates redundancy, yet maintaining redundancy ensures high availability, incurring storage costs. Balancing these aspects is a significant research concern. We propose FASTEN, a distributed cloud storage scheme ensuring efficiency, security, and high availability. FASTEN achieves fault tolerance by dispersing data subsets optimally across servers and maintains redundancy for high availability. Experimental results show FASTEN's effectiveness in fault tolerance, cost reduction, batch auditing, and file and block-level deduplication. It outperforms existing systems with low time complexity, strong fault tolerance, and commendable deduplication performance.
Md. Nahiduzzaman, Tariqul Islam 0001, Faisal Haque Bappy, Tarannum S. Zaman, Raiful Hasan
CCNC5
2024 ConChain: A Scheme for Contention-Free and Attack Resilient BlockChain
abstract
Although blockchains have become widely popular for their use in cryptocurrencies, they are now becoming pervasive as more traditional applications adopt blockchain to ensure data security. Despite being a secured network, blockchains have some tradeoffs such as high latency, low throughput, and transaction failures. One of the core problems behind these is improper management of “conflicting transactions”, which is also known as “contention”. When there is a large pool of pending transactions in a blockchain and some of them are conflicting, a situation of contention occurs, and as a result, the latency of the network increases, and a substantial amount of resources are wasted which results in low throughput and transaction failures. In this paper, we proposed ConChain, a novel blockchain scheme that combines transaction parallelism and an intelligent dependency manager to minimize conflicting transactions in blockchain networks as well as improve performance. ConChain is also capable of ensuring proper defense against major attacks due to contention.
Faisal Haque Bappy, Tariqul Islam 0001, Tarannum S. Zaman, Md Sajidul Islam Sajid, Mir Mehedi Ahsan Pritom
CCNC3
2024 An Efficient and Scalable Auditing Scheme for Cloud Data Storage Using an Enhanced B-Tree
abstract
An efficient, scalable, and provably secure dynamic auditing scheme is highly desirable in the cloud storage environment for verifying the integrity of the outsourced data. Most of the existing work on remote integrity checking focuses on static archival data and therefore cannot be applied to cases where dynamic data updates are more common. Additionally, existing auditing schemes suffer from performance bottlenecks and scalability issues. To address these issues, in this paper, we present a novel dynamic auditing scheme for centralized cloud environments leveraging an enhanced version of the B-tree. Our proposed scheme achieves the immutable characteristic of a decentralized system (i.e., blockchain technology) while effectively addressing the synchronization and performance challenges of such systems. Unlike other static auditing schemes, our scheme supports dynamic insert, update, and delete operations. Also, by leveraging an enhanced B-tree, our scheme maintains a balanced tree after any alteration to a certain file, improving performance significantly. Experimental results show that our scheme outperforms both traditional Merkle Hash Tree-based centralized auditing and decentralized blockchain-based auditing schemes in terms of block modifications (e.g., insert, delete, update), block retrieval, and data verification time.
Tariqul Islam 0001, Faisal Haque Bappy, Md Nafis Ul Haque Shifat, Kamrul Hasan 0008, Tarannum S. Zaman
ICC6
2019 SCMiner: Localizing System-Level Concurrency Faults from Large System Call Traces
abstract
Localizing concurrency faults that occur in production is hard because, (1) detailed field data, such as user input, file content and interleaving schedule, may not be available to developers to reproduce the failure; (2) it is often impractical to assume the availability of multiple failing executions to localize the faults using existing techniques; (3) it is challenging to search for buggy locations in an application given limited runtime data; and, (4) concurrency failures at the system level often involve multiple processes or event handlers (e.g., software signals), which can not be handled by existing tools for diagnosing intra-process(thread-level) failures. To address these problems, we present SCMiner, a practical online bug diagnosis tool to help developers understand how a system-level concurrency fault happens based on the logs collected by the default system audit tools. SCMiner achieves online bug diagnosis to obviate the need for offline bug reproduction. SCMiner does not require code instrumentation on the production system or rely on the assumption of the availability of multiple failing executions. Specifically, after the system call traces are collected, SCMiner uses data mining and statistical anomaly detection techniques to identify the failure-inducing system call sequences. It then maps each abnormal sequence to specific application functions. We have conducted an empirical study on 19 real-world benchmarks. The results show that SCMiner is both effective and efficient at localizing system-level concurrency faults.
Tarannum S. Zaman, Xue Han 0007, Tingting Yu 0001
ASE1
2017 DESCRY: reproducing system-level concurrency failures
abstract
Concurrent systems may fail in the field due to various elusive faults such as race conditions. Reproducing such failures is hard because (1) concurrency failures at the system level often involve multiple processes or event handlers (e.g., software signals), which cannot be handled by existing tools for reproducing intra-process (thread-level) failures; (2) detailed field data, such as user input, file content and interleaving schedule, may not be available to developers; and (3) the debugging environment may differ from the deployed environment, which further complicates failure reproduction. To address these problems, we present DESCRY, the first fully automated tool for reproducing system-level concurrency failures based only on default log messages collected from the field. DESCRY uses a combination of static and dynamic analysis techniques, together with symbolic execution, to synthesize both the failure-inducing data input and the interleaving schedule, and leverages them to deterministically replay the failed execution using existing virtual platforms. We have evaluated DESCRY on 22 real-world multi-process Linux applications with a total of 236,875 lines of code to demonstrate both its effectiveness and its efficiency in reproducing failures that no other tool can reproduce.
Tingting Yu 0001, Tarannum S. Zaman, Chao Wang 0001
ESEC/SIGSOFT FSE2