Ashish Rajendra Sai

dblp:248/9392 · DBLP profile ↗
← Back
8ranked-venue papers
4as first author
6since 2021 · last 2025
0000-0003-3639-2854ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 4 · 1 first-author · 3 since 2021Security and privacy · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Adding Context to Automated Vulnerability Detection for Teaching Software Security
abstract
Considering the recent developments in the fiel of generative AI, large language models (LLMs) can be leveraged to enhance static application security testing (SAST) tools and teaching about this topic. These models provide contextual information about identified vulnerabilities which can help students to differentiate genuine issues from false alarms while learning about software security. The approach includes analyzing vulnerabilities in android applications using SAST tools, clustering related code functionalities, and generating multi-level summaries for detected vulnerabilities. The process employs advanced clustering techniques and consensus-building methods to ensure accuracy.
Antoine Dorard, Bastian Küppers, Ashish Rajendra Sai, Theodor Schnitzler
ITiCSE (2)3
2025 A Framework and Taxonomy for Characterizing the Applicability of Software Architecture Recovery Approaches: A Tertiary-Mapping Study
abstract
Summary Software architecture assists developers in addressing non‐functional requirements and in maintaining, debugging, and upgrading their software systems. Consequently, consistency between the designed architecture and the implemented software system itself is important; without this consistency the non‐functional requirements targeted may not be addressed and architectural documentation may mis‐direct maintenance efforts that target the associated code‐base. But often, when software is initially implemented or subsequently evolved, the designed architecture and software architecture become inconsistent, with the implemented structure degraded due to issues like developer time‐pressures, or ambiguous communication of the designed architecture. In such cases, Software Architecture Recovery (SAR) or consistency approaches can be applied to reconstruct the architecture of the software system and possibly to compare it to/re‐align it with the designed architecture. Many SAR approaches have been proposed in the research. However, choosing an appropriate architecture recovery approach for software systems is still an open issue. Consequently, this research aims to conduct a tertiary‐mapping study based on available secondary studies of architecture recovery approaches, to uncover important characteristics, towards the selection of appropriate SAR approaches. This research has aggregated 13 secondary studies and 10 primary studies beyond 2020 from 5 databases and, in doing so, identified 111 architecture recovery approaches. Based on these approaches, a taxonomy, containing nine main SAR‐selection categories is proposed and a framework (in the form of a supporting tool to help developers select an appropriate SAR approach) has been developed. Finally, this research identifies six potential open research gaps related to the underlying research that could be helpful for guiding research in the future.
Abdul Qayum, Simon Colreavy-Donnelly, Muslim Chochlov, Jim Buckley, Dayi Lin, Ashish Rajendra Sai
Softw. Pract. Exp.7
2024 Promoting rigor in blockchain energy and environmental footprint research: A systematic literature review
abstract
There is a growing interest in understanding the energy and environmental footprint of digital currencies, specifically in cryptocurrencies such as Bitcoin and Ethereum. These cryptocurrencies are operated by a geographically distributed network of computing nodes, making it hard to estimate their energy consumption accurately. Existing studies, both in academia and industry, attempt to model cryptocurrency energy consumption often based on a number of assumptions, for instance, about the hardware in use or the geographic distribution of the computing nodes. A number of these studies have already been widely criticized for their design choices and subsequent over- or under-estimation of energy use. In this study, we evaluate the reliability of prior models and estimates by leveraging existing scientific literature from fields cognizant of blockchain, such as social energy sciences and information systems. We first design a quality assessment framework based on existing research, and we then conduct a systematic literature review examining scientific and non-academic literature demonstrating common issues and potential avenues of addressing these issues. Our goal with this article is to to advance the field by promoting scientific rigor in studies focusing on blockchain energy footprint. To that end, we provide a novel set of codes of conduct for the five most widely used research methodologies: quantitative energy modeling, literature reviews, data analysis and statistics, case studies, and experiments. We envision that this code of conduct would assist in standardizing the design and assessment of studies focusing on blockchain-based systems' energy and environmental footprint.
Ashish Rajendra Sai, Harald Vranken
Blockchain Res. Appl.1
2023 Determining Optimal Incentive Policy for Decentralized Distributed Systems Using Reinforcement Learning
abstract
Cryptocurrencies have gained a lot of attention in recent years, mostly due to their decentralized manner of operation and their growth in value. However, a major drawback most of them possess is their high energy consumption. Current solutions to this problem have significant limitations: bringing back centralization and/or substituting the required energy with, e.g., storage space. This paper aims to address the problem by investigating the use of a two-level deep reinforcement learning (RL) model to design incentive policies for green mining in cryptocurrencies. This is done by modeling one such energy-intensive cryptocurrency system and creating an RL environment. Finally, by running simulations in an RL environment, we develop and test incentive policies, according to which cryptocurrency participants who primarily use renewable energy for their mining operations are more likely to add new blocks to the blockchain. Our results show that even when the green score of each crypto miner (determined by their use of green energy sources) has relatively small importance (up to 0.3) in their selection probability, miners still shift towards green mining in order to increase their chance of being picked to validate cryptocurrency transactions and receive the corresponding rewards.
Elitsa Pankovska, Ashish Rajendra Sai, Harald Vranken
ICBC2
2021 BoostNSift: A Query Boosting and Code Sifting Technique for Method Level Bug Localization
abstract
Locating bugs is an important, but effort-intensive and time-consuming task, when dealing with large-scale systems. To address this, Information Retrieval (IR) techniques are increasingly being used to suggest potential buggy source code locations, for given bug reports. While IR techniques are very scalable, in practice their effectiveness in accurately localizing bugs in a software system remains low. Results of empirical studies suggest that the effectiveness of bug localization techniques can be augmented by the configuration of queries used to locate buggy code. However, in most IR-based bug localization techniques, presented by researchers, the impact of the queries’ configurations is not fully considered. In a similar vein, techniques consider all code elements as equally suspicious of being buggy while localizing bugs, but this is not always the case either.In this paper, we present a new method-level, information-retrieval-based bug localization technique called "BoostNSift". BoostNSift exploits the important information in queries by ‘boost’ing that information, and then ‘sift’s the identified code elements, based on a novel technique that emphasizes the code elements’ specific relatedness to a bug report over its generic relatedness to all bug reports. To evaluate the performance of BoostNSift, we employed a state-of-the-art empirical design that has been commonly used for evaluating file level IR-based bug localization techniques: 6851 bugs are selected from commonly used Eclipse, AspectJ, SWT, and ZXing benchmarks and made openly available for method-level analyses. The performance of BoostNSift is compared with the openly-available state-of-the-art IR-based BugLocator, BLUiR, and BLIA techniques. Experiments show that BoostNSift improves on BLUiR by up to 324%, on BugLocator by up to 297%, and on BLIA up to 120%, in terms of Mean Reciprocal Rank (MRR). Similar improvements are observed in terms of Mean Average Precision (MAP) and Top-N evaluation measures.
Jim Buckley, James Vincent Patten, Muslim Chochlov, Ashish Rajendra Sai
SCAM5
2021 Taxonomy of centralization in public blockchain systems: A systematic literature review
abstract
Bitcoin introduced delegation of control over a monetary system from a select few to all who participate in that system. This delegation is known as the decentralization of controlling power and is a powerful security mechanism for the ecosystem. After the introduction of Bitcoin, the field of cryptocurrency has seen widespread attention from industry and academia, so much so that the original novel contribution of Bitcoin, i.e., decentralization, may be overlooked, due to decentralizations’ assumed fundamental existence for the functioning of such crypto-assets. However, recent studies have observed a trend of increased centralization in cryptocurrencies such as Bitcoin and Ethereum. As this increased centralization has an impact the security of the blockchain, it is crucial that it is measured, towards adequate control. This research derives an initial taxonomy of centralization present in decentralized blockchains through rigorous synthesis using a systematic literature review. This is followed by iterative refinement through expert interviews. We systematically analyzed 89 research papers published between 2009 and 2019. Our study contributes to the existing body of knowledge by highlighting the multiple definitions and measurements of centralization in the literature. We identify different aspects of centralization and propose an encompassing taxonomy of centralization concerns. This taxonomy is based on empirically observable and measurable characteristics. It consists of 13 aspects of centralization, classified over six architectural layers: Governance, Network, Consensus, Incentive, Operational, and Application. We also discuss how the implications of centralization can vary depending on the aspects studied. We believe that this review and taxonomy provides a comprehensive overview of centralization in decentralized blockchains involving various conceptualizations and measures.
Ashish Rajendra Sai, Jim Buckley, Brian Fitzgerald 0001, Andrew Le Gear
Inf. Process. Manag.1
2020 Inheritance software metrics on smart contracts
abstract
Blockchain systems have gained substantial traction recently, partly due to the potential of decentralized immutable mediation of economic activities. Ethereum is a prominent example that has the provision for executing stateful computing scripts known as Smart Contracts. These smart contracts resemble traditional programs, but with immutability being the core differentiating factor. Given their immutability and potential high monetary value, it becomes imperative to develop high-quality smart contracts. Software metrics have traditionally been an essential tool in determining programming quality. Given the similarity between smart contracts (written in Solidity for Ethereum) and object-oriented (OO) programming, OO metrics would appear applicable. In this paper, we empirically evaluate inheritance-based metrics as applied to smart contracts. We adopt this focus because, traditionally, inheritance has been linked to a more complex codebase which we posit is not the case with Solidity based smart contracts. In this work, we evaluate the hypothesis that, due to the differences in the context of smart contracts and OO programs, it may not be appropriate to use the same interpretation of inheritance based metrics for assessment.
Ashish Rajendra Sai, Conor Holmes, Jim Buckley, Andrew Le Gear
ICPC1
2019 Assessing the security implication of Bitcoin exchange rates
Ashish Rajendra Sai, Jim Buckley, Andrew Le Gear
Comput. Secur.1