VLDB 2026 Research / reviewers in the wild / expert
Aman Sharma 0001
dblp:211/6908-1
· DBLP profile ↗
2ranked-venue papers
1as first author
2since 2021 · last 2026
0000-0003-2263-7902ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Causes and Canonicalization of Unreproducible Builds in JavaabstractThe increasing complexity of software supply chains and the rise of supply chain attacks have elevated concerns around software integrity. Users and stakeholders face significant challenges in validating that a given software artifact corresponds to its declared source. Reproducible Builds address this challenge by ensuring that independently performed builds from identical source code produce identical binaries. However, achieving reproducibility at scale remains difficult, especially in Java, due to a range of non-deterministic factors and caveats in the build process. In this work, we focus on reproducibility in Java-based software, archetypal of enterprise applications. We introduce a conceptual framework for reproducible builds, we analyze a large dataset from Reproducible Central, and we develop a novel taxonomy of six root causes of unreproducibility. We study actionable mitigations: artifact and bytecode canonicalization using OSS-Rebuild and jNorm respectively. Finally, we presentChains-Rebuild(improvements to OSS-Rebuild), a tool that raises reproducibility success from 9.48% to 26.60% on 12,803 unreproducible artifacts. To sum up, our contributions are the first large-scale taxonomy of build unreproducibility causes in Java, a publicly available dataset of unreproducible builds, andChains-Rebuild, a canonicalization tool for mitigating unreproducible builds in Java. Aman Sharma 0001, Benoit Baudry, Martin Monperrus |
IEEE Trans. Software Eng. | 1 |
| 2023 | Augmenting Diffs With Runtime InformationabstractSource code diffs are used on a daily basis as part of code review, inspection, and auditing. To facilitate understanding, they are typically accompanied by explanations that describe the essence of what is changed in the program. As manually crafting high-quality explanations is a cumbersome task, researchers have proposed automatic techniques to generate code diff explanations. Existing explanation generation methods solely focus on static analysis, i.e., they do not take advantage of runtime information to explain code changes. In this article, we proposeCollector-Sahab, a novel tool that augments code diffs with runtime difference information.Collector-Sahabcompares the program states of the original (old) and patched (new) versions of a program to find unique variable values. Then,Collector-Sahabadds this novel runtime information to the source code diff as shown, for instance, in code reviewing systems. As an evaluation, we runCollector-Sahabon584code diffs for Defects4J bugs and find it successfully augments the code diff for 95% (555/584) of them. We also perform a user study and ask eight participants to score the augmented code diffs generated byCollector-Sahab. Per this user study, we conclude that developers find the idea of adding runtime data to code diffs promising and useful. Overall, our experiments show the effectiveness and usefulness ofCollector-Sahabin augmenting code diffs with runtime difference information.Publicly-available repository:https://github.com/ASSERT-KTH/collector-sahab. Khashayar Etemadi, Aman Sharma 0001, Fernanda Madeiral, Martin Monperrus |
IEEE Trans. Software Eng. | 2 |