VLDB 2026 Research / reviewers in the wild / expert
Sabreen Ahmadjee
dblp:237/9804
· DBLP profile ↗
5ranked-venue papers
4as first author
5since 2021 · last 2026
0000-0003-4553-4770ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 4 · 3 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Security Architectural Approaches and Risk Assessment Methods for Blockchain Systems: A Review and Future DirectionsabstractAmid the widespread use of blockchain technology, the escalating frequency of cyberattacks exploiting its inherent security challenges underscores the critical necessity for a robust and adaptable security risk assessment approach. The distinctive attributes and intricate internal structure of blockchain not only attract malicious actors but also elevate the risk of ill-informed architectural design decisions, potentially introducing security vulnerabilities. This study addresses this imperative by conducting a systematic literature review, classifying publications that elucidate secure architectural design approaches and categorising those that delineate methods for assessing security risks associated with blockchain and smart contracts. The findings reveal four prevalent approaches supporting secure architectural design—decision models, taxonomies, design patterns and guidelines—alongside contributions in blockchain risk assessment encompassing risk identification, analysis and evaluation methods. Furthermore, the study identifies unresolved architectural design challenges and proposes future research directions in this evolving landscape. Sabreen Ahmadjee, Carlos Joseph Mera-Gómez, Rami Bahsoon, Rajkumar Buyya |
Distributed Ledger Technol. Res. Pract. | 1 |
| 2025 | Decision Support Model for Selecting the Optimal Blockchain Oracle Platform: An Evaluation of Key FactorsabstractSmart contract-based applications are executed in a blockchain environment, and they cannot directly access data from external systems, which is required for the service provision of these applications. Instead, smart contracts use agents known as blockchain oracles to collect and provide data feeds to the contracts. The functionality and compatibility with smart contract applications need to be considered when selecting the best-fit oracle platform. As the number of oracle alternatives and their features increases, the decision-making process becomes increasingly complex. Selecting the wrong or sub-optimal oracle is costly and may lead to severe security risks. This article provides a decision support model for the oracle selection problem. The model supports smart contract decision-makers in selecting a secure, cost-effective, and feasible oracle platform for their applications. We interviewed oracle co-founders and smart contracts experts to refine and validate the decision model. Two real-world smart contract application case studies were used to evaluate the model. Our model prioritises and suggests more than one possible oracle platform based on the developer’s required criteria, security assessment and cost analysis. Moreover, this guided decision model serves to reveal issues that may go unnoticed if done haphazardly, reduce decision-making efforts and provide a cost-effective solution. Sabreen Ahmadjee, Carlos Joseph Mera-Gómez, Siamak Farshidi, Rami Bahsoon, Rick Kazman |
ACM Trans. Softw. Eng. Methodol. | 1 |
| 2025 | Evaluating the Need for Explanations in Blockchain Smart Contracts to Reconcile SurprisesabstractSmart contracts on the blockchain play an important role in decentralised systems by automating and executing agreements without the need for intermediaries. As these contracts become integral to various domains, ensuring users’ understanding of their functioning is paramount. This article investigates the need for explanations in smart contracts, drawing inspiration from contract law principles and established practices in Explainable AI (XAI). It introduces key purposes—justification, clarification, compliance and consent to design explainability. Additionally, the study proposes a novel assessment framework informed by the Metacognitive Explanation-Based (MEB) theory to systematically evaluate surprise potential in smart contracts lacking explanations. We use surprise as a guiding factor to systematically identify areas requiring improvement in terms of justification, clarification, compliance and consent. To demonstrate the utility of the assessment approach, we evaluate two decentralised lending projects, uncovering potential surprises. One of the key observations is the lack of setting information, especially concerning compliance, consent and decision justification. This absence of information has heightened the potential for surprises. In the process of validating the explanation purposes, we implement techniques to improve the design of the assessed smart contracts. Further, the research explores the tradeoffs involved in integrating explanations, providing nuanced insights into economic implications such as increased deployment and execution costs. This work contributes to the broader comprehension of smart contract explainability requirements and lays out a theoretical foundation for a generic evaluation method. It aims to facilitate the development of more human-centric and comprehensible smart contracts. Hanouf Al Ghanmi, Sabreen Ahmadjee, Rami Bahsoon |
ACM Trans. Softw. Eng. Methodol. | 2 |
| 2022 | A Study on Blockchain Architecture Design Decisions and Their Security Attacks and ThreatsabstractBlockchain is a disruptive technology intended to implement secure decentralised distributed systems, in which transactional data can be shared, stored, and verified by participants of the system without needing a central authentication/verification authority. Blockchain-based systems have several architectural components and variants, which architects can leverage to build secure software systems. However, there is a lack of studies to assist architects in making architecture design and configuration decisions for blockchain-based systems. This knowledge gap may increase the chance of making unsuitable design decisions and producing configurations prone to potential security risks. To address this limitation, we report our comprehensive systematic literature review to derive a taxonomy of commonly used architecture design decisions in blockchain-based systems. We map each of these decisions to potential security attacks and their posed threats. MITRE’s attack tactic categories and Microsoft STRIDE threat modeling are used to systematically classify threats and their associated attacks to identify potential attacks and threats in blockchain-based systems. Our mapping approach aims to guide architects to make justifiable design decisions that will result in more secure implementations. Sabreen Ahmadjee, Carlos Joseph Mera-Gómez, Rami Bahsoon, Rick Kazman |
ACM Trans. Softw. Eng. Methodol. | 1 |
| 2021 | Assessing Smart Contracts Security Technical DebtsabstractSmart contracts are self-enforcing agreements that are employed to exchange assets without the approval of trusted third parties. This feature has encouraged various sectors to make use of smart contracts when transacting. Experience shows that many deployed contracts are vulnerable to exploitation due to their poor design, which allows attackers to steal valuable assets from the involved parties. Therefore, an assessment approach that allows developers to recognise the consequences of deploying vulnerable contracts is needed. In this paper, we propose a debt-aware approach for assessing security design vulnerabilities in smart contracts. Our assessment approach involves two main steps: (i) identification of design vulnerabilities using security analysis techniques and (ii) an estimation of the ramifications of the identified vulnerabilities leveraging the technical debt metaphor, its principal and interest. We use examples of vulnerable contracts to demonstrate the applicability of our approach. The results show that our assessment approach increases the visibility of security design issues. It also allows developers to concentrate on resolving smart contract vulnerabilities through technical debt impact analysis and prioritisation. Developers can use our approach to inform the design of more secure contracts and for reducing unintentional debts caused by a lack of awareness of security issues. Sabreen Ahmadjee, Carlos Joseph Mera-Gómez, Rami Bahsoon |
TechDebt@ICSE | 1 |