Rubia Fatima

dblp:210/3743 · DBLP profile ↗
← Back
16ranked-venue papers
7as first author
9since 2021 · last 2025
0000-0002-7144-1925ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 12 · 4 first-author · 7 since 2021Security and privacy · 3 · 3 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Enhancing Literature Quality Assessment Skill in Novice Researchers: A Collaborative Card-Based Learning Approach
abstract
ABSTRACT Assessing the quality and credibility of research is crucial across disciplines. However, training early career scholars in systematic quality appraisal poses challenges. The rise of online grey literature increases the need for nuanced evaluation capabilities. This study aims to impart basic literature quality assessment knowledge in early career software engineering researchers using an interactive card‐based learning activity. The PRISMA abstract quality checklist was adapted into a physical card deck. Sixteen novice researchers participated in a session using the cards to collaborate, discuss, and analyze a sample review paper abstract based on structured criteria. Quantitative feedback was gathered. Survey results indicated the card activity positively enhanced perceived understanding of quality principles, engagement, and assessment skills. Open‐ended feedback highlighted cards improved focus, interactivity, and peer exchanges. This preliminary study provides encouraging evidence that a customized card‐based approach can effectively instill foundational skills for assessing abstract quality while increasing motivation and enjoyment. Further research should evaluate long‐term retention and optimal instructional design parameters.
Affan Yasin, Rubia Fatima, Ira Puspitasari
J. Softw. Evol. Process.2
2024 Re-evaluation of PhishI game and its utilisation in eliciting security requirements
abstract
The COVID-19 pandemic has sparked considerable alarm amongst the general community and has significantly affected the societal attitudes and perceptions. In the current era, social engineers are applying various strategies to exploit human weakness. Phishing, a social engineering technique, is one of the most widely used and effective ways to undermine human assets. In this research study, firstly, we aim to educate the participants regarding phishing attacks; secondly, the dangers associated with excessive online sharing; and thirdly, how to utilise game scenarios developed by the participants to elicit security requirements. We have employed various research methods, such as, survey, observation, personas development, and scenario-based technique to achieve these objectives. Our re-evaluation results show that the PhishI game effectively educates participants regarding phishing attacks and dangers associated with disclosing excessive online information.
Rubia Fatima, Affan Yasin, Lin Liu 0001, Jianmin Wang 0001
Int. J. Inf. Comput. Secur.1
2024 Can serious gaming tactics bolster spear-phishing and phishing resilience? : Securing the human hacking in Information Security
abstract
In the digital age, there is a notable increase in fraudulent activities perpetrated by social engineers who exploit individuals’ limited knowledge of digital devices. These actors strategically manipulate human psychology, targeting IT devices to gain unauthorized access to sensitive data. Our study is centered around two distinct objectives to be accomplished through the utilization of a serious game: (i) The primary objective entails delivering training and educational content to participants with a focus on phishing attacks; (ii) The secondary objective aims to heighten participants’ awareness regarding the perils associated with divulging excessive information online. To address these objectives, we have employed the following techniques and methods: (i) A comprehensive literature review was conducted to establish foundational knowledge in areas such as social engineering, game design, learning principles, human interaction, and game-based learning; (ii) We meticulously aligned the game design with the philosophical concept of social engineering attacks; (iii) We devised and crafted an advanced hybrid version of the game, incorporating the use of QR codes to generate game card data; (iv) We conducted an empirical evaluation encompassing surveys, observations, discussions, and URL assessments to assess the effectiveness of the proposed hybrid game version. Quantitative data and qualitative observations suggest the “PhishDefend Quest” game successfully improved players’ comprehension of phishing threats and how to detect them through an interactive learning experience. The results highlight the potential of serious games to educate people about social engineering risks. Through the evaluation, we can readily arrive at the following conclusions: (i) Game-based learning proves to be a viable approach for educating participants about phishing awareness and the associated risks tied to the unnecessary disclosure of sensitive information online; (ii) Furthermore, game-based learning serves as an effective means of disseminating awareness among participants and players concerning prevalent phishing attacks.
Affan Yasin, Rubia Fatima, Wasif Afzal, Shahid Raza
Inf. Softw. Technol.2
2024 Counteracting sociocultural barriers in global software engineering using group activities
abstract
Abstract In modern times, internationally organized teams face a number of coordination problems owing to their different physical operating locations. These challenges usually come in temporal, cultural, and linguistic forms. To resolve some of these issues, we need more coordination, teamwork, and shared understanding in the requirements engineering phase. Many approaches have been introduced to overcome these challenges associated with global software engineering (GSE). The objective of this research study is to introduce amateurs to GSE and improve their understanding of its associated challenges through an activity‐based learning approach. Our method is primarily targeted toward students who already have theoretical knowledge on the topic but require first‐hand experience with GSE. With the aforementioned motivation in mind, we propose, designe, and empirically evaluate two different activities that can help enhance awareness of GSE challenges. For each activity, we simulate an environment wherein participants are made to go through various constructed coordination challenges related to communication, time management, team mistrust, linguistic barriers, cultural barriers, and distribution of tasks. The effectiveness of our proposed activities, captured by the extent to which participants were able to deal with GSE challenges, was judged through various techniques including (i) observation, (ii) post activities survey questionnaire, and (iii) brainstorming and discussion. We show that the proposed activities were effective in helping students learn and further their understanding of GSE concepts. In particular, discussion sessions and survey questionnaire results reflect their ability to identify critical GSE challenges (specifically related to teams) in a simulated scenario.
Affan Yasin, Rubia Fatima, Javed Ali Khan, Lin Liu 0001, Raian Ali, Jianmin Wang 0001
J. Softw. Evol. Process.2
2024 Gamifying requirements: An empirical analysis of game-based technique for novices
abstract
Abstract Requirements elicitation is a process that involves gathering requirements for a given project. Several studies have been published suggesting strategies to improve the requirements gathering process. Using game‐based and crowd‐based approaches, researchers are extracting requirements that are useful for product development today. This study follows the same line of research. This research study aims to improve the understanding of the requirements gathering process by novices or students through different activities: (I) knowledge of requirements gathering method and (II) techniques or activities viable for software requirements (education). Important methods used to address the above objectives are as follows: (I) a comprehensive review of the literature to understand requirements gathering; (II) designing an activity to embed RE challenges and RE sub‐activities; and (III) experiment, survey, and observation to collect data and to assess the proposed methods' effectiveness. The suggested activity for requirement gathering is based on the game tic‐tac‐toe. The participants suggest that the design of the activity is helpful in brainstorming and is also valuable for identifying requirements; moreover, a post questionnaire has been designed to determine the learning of the participants regarding the proposed activity. We can observe simply from the coefficients that both skills and challenges (as perceived by the participants) have positive impacts on engagement, immersion, and perceived learning. The proposed activity helps novices or students gain (basic) knowledge of the requirements gathering process/technique; the outlined activity can be a way of learning requirements and gathering knowledge (basic). From this study, we conclude that the proposed activity has positive results and is helpful for participants to get a better understanding of the requirements engineering method(s).
Affan Yasin, Rubia Fatima, Javed Ali Khan, Arif Ali Khan
J. Softw. Evol. Process.2
2023 Anomaly Prediction over Human Crowded Scenes via Associate-Based Data Mining and K-Ary Tree Hashing
abstract
Anomaly detection and behavioral recognition are key research areas widely used to improve human safety. However, in recent times, with the extensive use of surveillance systems and the substantial increase in the volume of recorded scenes, the conventional analysis of categorizing anomalous events has proven to be a difficult task. As a result, machine learning researchers require a smart surveillance system to detect anomalies. This research introduces a robust system for predicting pedestrian anomalies. First, we acquired the crowd data as input from two benchmark datasets (including Avenue and ADOC). Then, different denoising techniques (such as frame conversion, background subtraction, and RGB‐to‐binary image conversion) for unfiltered data are carried out. Second, texton segmentation is performed to identify human subjects from acquired denoised data. Third, we used Gaussian smoothing and crowd clustering to analyze the multiple subjects from the acquired data for further estimations. The next step is to perform feature extraction to multiple abstract cues from the data. These bag of features include periodic motion, shape autocorrelation, and motion direction flow. Then, the abstracted features are mapped into a single vector in order to apply data optimization and mining techniques. Next, we apply the associate‐based mining approach for optimized feature selection. Finally, the resultant vector is served to the k‐ary tree hashing classifier to track normal and abnormal activities in pedestrian crowded scenes.
Affan Yasin, Sheikh Badar ud din Tahir, Jaroslav Frnda, Rubia Fatima, Javed Ali Khan, Muhammad Shahid Anwar
Int. J. Intell. Syst.4
2023 Retrieving arXiv, SocArXiv, and SSRN metadata for initial review screening
Rubia Fatima, Affan Yasin, Lin Liu 0001, Jianmin Wang 0001, Wasif Afzal
Inf. Softw. Technol.1
2022 On the utilization of non-quality assessed literature in software engineering research
abstract
Abstract Quality of research and knowledge sources can be a critical factor to judge the quality of the research citing them. The prevailing online dissemination of research via blogs, websites, experience reports, and white papers can be helpful as it minimizes potential publication biases. In this paper, we have (i) identified the body of software engineering (SE) literature that is non‐indexed by Web‐of‐Science but has been used in published SE systematic literature review (SLR) studies (as primary studies); (ii) proposed a checklist‐based method for quality assessment of non‐indexed and grey literature; (iii) empirically evaluated the effectiveness of the proposed method; (iv) searched primary studies retrieved from the SLRs in DBLP and Google Scholar (GS) to verify whether DBLP or Google Scholar can act as viable options to search for non‐indexed Web‐of‐Science (non‐WOS‐indexed) literature. Besides proposing our synthesized checklist method, we found that (i) SE literature reviews use significantly non‐indexed Web‐of‐Science sources; (ii) DBLP only covers a portion of the non‐WOS‐indexed reference, whereas GS has a more complete coverage of the non‐indexed reference in comparison. Preliminary evaluation of the proposed quality assessment point system‐based and checklist‐based methods shows it to be a viable way to assess quality of the non‐indexed and grey literature.
Affan Yasin, Rubia Fatima, Lin Liu 0001, Javed Ali Khan, Raian Ali, Jianmin Wang 0001
J. Softw. Evol. Process.2
2022 Valuating requirements arguments in the online user's forum for requirements decision-making: The CrowdRE-VArg framework
abstract
Abstract User forums enable a large population of crowd‐users to publicly share their experience, useful thoughts, and concerns about the software applications in the form of user reviews. Recent research studies have revealed that end‐user reviews contain rich and pivotal sources of information for the software vendors and developers that can help undertake software evolution and maintenance tasks. However, such user‐generated information is often fragmented, with multiple viewpoints from various stakeholders involved in the ongoing discussions in the Reddit forum. In this article, we proposed a crowd‐based requirements engineering by valuation argumentation (CrowdRE‐VArg) approach that analyzes the end‐users discussion in the Reddit forum and identifies conflict‐free new features, design alternatives, or issues, and reach a rationale‐based requirements decision by gradually valuating the relative strength of their supporting and attacking arguments. The proposed approach helps to negotiate the conflict over the new features or issues between the different crowd‐users on the run by finding a settlement that satisfies the involved crowd‐users in the ongoing discussion in the Reddit forum using argumentation theory. For this purpose, we adopted the bipolar gradual valuation argumentation framework, extended from the abstract argumentation framework and abstract valuation framework. The automated CrowdRE‐VArg approach is illustrated through a sample crowd‐users conversation topic adopted from the Reddit forum about Google Map mobile application. Finally, we applied natural language processing and different machine learning algorithms to support the automated execution of the CrowdRE‐VArg approach. The results demonstrate that the proposed CrowdRE‐VArg approach works as a proof‐of‐concept and automatically identifies prioritized requirements‐related information for software engineers.
Javed Ali Khan, Affan Yasin, Rubia Fatima, Danish Vasan, Arif Ali Khan, Abdul Wahid Khan
Softw. Pract. Exp.3
2020 Google Scholar vs. Dblp vs. Microsoft Academic Search: An Indexing Comparison for Software Engineering Literature
abstract
Background: One of the necessary conditions for any substantial research work is to synthesis the depth and the breath of the existing published literature on that topic. It is, thus, of extreme importance for a researcher to understand and look for both credible and exhaustive information sources. This first (important) step can be made significantly easier if the researcher can employ a more systematic way to extract the maximum of the literature on the topic. Objective: Essentially, the objective of this preliminary study is to rank three freely available academic search engines (Google Scholar, DBLP, Microsoft Academic Search) on the basis of the indexed Software Engineering academic literature they contain. Method: We have used a systematic mapping to conduct the study. Results: After extracting and analyzing 1067 secondary studies (from 18 tertiary studies), we have concluded that Google Scholar has indexed 98.96%, DBLP has indexed 93.43%, and Microsoft Academic Search engine has indexed 97.46% of the secondary studies. Thus, this implies that Google Scholar and Microsoft Academic Search might be a better-suited option for searching for secondary studies.
Rubia Fatima, Affan Yasin, Lin Liu 0001, Jianmin Wang 0001
COMPSAC1
2020 The Use of Grey Literature and Google Scholar in Software Engineering Systematic Literature Reviews
abstract
Objective of the study is to calculate: a) grey literature evidence in the selected Systematic literature reviews (SLRs); b) Google Scholar indexing for the extracted primary studies from the selected SLRs. We have randomly selected 20+ SLRs from Science Direct, IEEE Xplore, Springer Link and ACM. Result: a) Random selection of 20+ SLRs and grey literature calculation verifies that the grey literature percentage ranges around 5.7% to 9.1%; b) The second phase showed that Google Scholar was successful in retrieving around ~91% of the primary studies.
Rubia Fatima, Affan Yasin, Lin Liu 0001, Jianmin Wang 0001
COMPSAC1
2020 Understanding Social Engineers Strategies from the Perspective of Sun-Tzu Philosophy
abstract
Human remains susceptible to manipulations, and social engineers are expert of these techniques. To better understand the attack and defense strategies of social engineering attack, there is a need to map social engineering strategies with the war strategies. We can find plenty of war strategist and books on war strategies. By mapping the knowledge, we may get unique ways of defense and can further identify social engineering attack patterns. In this study, we have mapped the principles suggested by Sun-Tzu with social engineering attacks and further mentioned the initial results (by showing examples for each case). We aim to extend this work and further verify the effectiveness of this strategy in near future.
Affan Yasin, Rubia Fatima, Lin Liu 0001, Jianmin Wang 0001, Raian Ali
COMPSAC2
2019 Improving software requirements reasoning by novices: a story-based approach
abstract
Requirements elicitation is one of the essential steps towards software design and construction. Business analysts and stakeholders often face challenges in gathering or conveying key software requirements. There are many methods and tools designed by researchers and practitioners but with the persistent development of new technologies, there is a need to make requirements gathering and design‐rationale process more efficient and adaptable. Storytelling is an emerging concept and researchers are witnessing its effectiveness in education, community building, information system, and requirement elicitation. Objectives of this study are to devise a method for requirements elicitation and improving design‐rationales using story‐based techniques and evaluate the effectiveness of the proposed activity. To answer the research objectives, the authors have conducted open‐ended interviews to get feedback on the proposed method; the authors have case requirement from a running project to map how this method can be useful; and performed empirical evaluation of the proposed card‐based activity. The estimated regression model, in our study, has shown that participants' perception about the simplicity/easiness and the joy of playing the game has an eventual positive effect on requirements elicitation through enhancing user's desire to play the game, which in turn increases the collaborative learning outcomes of the game.
Rubia Fatima, Affan Yasin, Lin Liu 0001, Jianmin Wang 0001, Wasif Afzal, Atif Yasin
IET Softw.1
2019 Improving software security awareness using a serious game
abstract
Protecting people from cyber threats imposes great challenges, not only technically, but also socially. To achieve the intended level of awareness, software security principles need to be shown with concrete examples during security education. This study aims to design a serious game integrating software security knowledge and concepts into the processes to make it more engaging to learn while playing. In this paper, we have: (i) designed a serious game to compensate the deficiencies in the literature; (ii) performed empirical evaluations including survey, brainstorming and observation to the proposed game. Results: Our study shows that: (i) Cyber Security‐Requirements Awareness Game (CSRAG) has a positive effect on players security learning outcomes, level of engagement and participation; (ii) Game‐based learning can be an effective way of teaching security related scenarios.
Affan Yasin, Lin Liu 0001, Tong Li 0001, Rubia Fatima, Jianmin Wang 0001
IET Softw.4
2019 Sharing information online rationally: An observation of user privacy concerns and awareness using serious game
Rubia Fatima, Affan Yasin, Lin Liu 0001, Jianmin Wang 0001, Wasif Afzal, Awaid Yasin
J. Inf. Secur. Appl.1
2019 How persuasive is a phishing email? A phishing game for phishing awareness
abstract
Context: In the current era of digital technology, social engineers are using various tactics to undermine human weaknesses. Social Engineers target human psychology to achieve their target(s) which are in the form of data, account details, or IT devices etc. According to our research, one of the first methods social engineers used to target victims is Phishing/Spear Phishing. Objective: The objective of this study is to utilize serious game to: i) educate players regarding phishing and spear-phishing attacks; ii) make aware and educate players regarding dangers associated with excessive online information disclosure. Method: In order to address the objectives we have: i) performed an in-depth literature review to extract insights related to social engineering, phishing, game design, learning functions, human interaction, and game-based learning etc; ii) proposed and aligned the game design with social engineering ontology concepts; iii) performed an empirical evaluation to evaluate the effectiveness of the designed board game. Conclusion: From this research study, we conclude that: i) PhishI game is useful in educating players regarding excessive online information disclosure and phishing awareness; ii) game-based learning is an effective method for inculcating and general cyber-related awareness in players.
Rubia Fatima, Affan Yasin, Lin Liu 0001, Jianmin Wang 0001
J. Comput. Secur.1