Saima Rafi

dblp:264/2970 · DBLP profile ↗
← Back
23ranked-venue papers
8as first author
21since 2021 · last 2026
0000-0002-9807-6235ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 18 · 8 first-author · 16 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Low-Code and No-Code Tools: A Valuable Aid or a Potential Threat to Professional Developers?
abstract
ABSTRACT Background The rapid adoption of low‐code (LC) and no‐code (NC) tools has transformed the software development landscape, offering faster development cycles and enabling non‐programmers to contribute to software creation. Objective This study systematically maps the effects of LC/NC tools on developers, addressing the critical need to understand whether these tools serve as a valuable aid or a potential threat to their roles. Methods By analyzing how LC/NC tools support development processes, the challenges they present, and their potential to replace traditional developers, this research fills a key knowledge gap by performing a systematic mapping study. Results The findings reveal that while LC/NC tools simplify certain tasks, they do not replace the need for professional developers to handle complex technical challenges, change management, and system integration. Conclusions Rather than posing a threat, these tools complement and enhance developers' expertise, empowering them to focus on more advanced aspects of software creation. This study provides valuable insights for the professional developer community and the broader software industry, advocating for the thoughtful integration of LC/NC tools as powerful aids rather than competitors to professional development.
Saima Rafi, Muhammad Azeem Akbar, Sajjad Mahmood
Softw. Pract. Exp.1
2025 Residual GRU+MHSA: A Lightweight Hybrid Recurrent Attention Model for Cardiovascular Disease Detection
Tejaswani Dash, Gautam Datla, Anudeep Vurity, Tazeem Ahmad, Mohd Adnan, Saima Rafi, Saisha Patro, Saina Patro
IEEE Big Data6
2025 Polypersona: Persona-Grounded LLM for Synthetic Survey Responses
Tejaswani Dash, Dinesh Karri, Anudeep Vurity, Gautam Datla, Tazeem Ahmad, Saima Rafi, Rohith Tangudu
IEEE Big Data6
2025 Venturing ChatGPT's lens to explore human values in software artifacts: a case study of mobile APIs
abstract
Software is designed for humans and must account for their values. However, current research and practice focus on a narrow range of well-explored values, e.g. security, overlooking a more comprehensive perspective. Those exploring a broader array of values rely on manual identification, which is labour-intensive and prone to human bias. Moreover, existing methods offer limited reliability as they fail to explain their findings. In this paper, we propose leveraging the reasoning capabilities of Large Language Models (LLMs) for automated inference about values. This allows for not only detecting values but also explaining how they are expressed in the software. We aim to examine the effectiveness of LLMs, specifically ChatGPT (Chat Generative Pre-Trained Transformer), in automated detection and explanation of values in software artifacts. Using ChatGPT, we investigate how mobile APIs align with human values based on their documentation. Human evaluation of ChatGPT's findings shows a reciprocal shift in understanding values, with both ChatGPT and experts adjusting their assessments through dialogue. While experts recognise ChatGPT's potential for revealing values, emphasis is placed on human involvement to enhance the accuracy of the findings by detecting and eliminating convincing but inaccurate explanations provided by the language model due to potential hallucinations or confabulations.
Davoud Mougouei, Saima Rafi, Mahdi Fahmideh, Elahe Mougouei, Javed Ali Khan, Khanh Hoa Dam, Arif Nurwidyantoro, Michel R. V. Chaudron
Behav. Inf. Technol.2
2024 MLOps-Enabled Security Strategies for Next-Generation Operational Technologies
abstract
In recent years, the significant increase in enterprise data availability and the progress in Artificial Intelligence (AI) have enabled organizations to address real-world issues through Machine Learning (ML). In this regard, machine learning operations (MLOps) have been proven to be a beneficial strategy for evolving ML models from theoretical ideas to practical solutions of business sector issues. With the knowledge of MLOps being vast and scattered, this research work focuses on the application of MLOps methodologies in sophisticated operational technologies, prioritizing the enhancement of security measures. This research work also discusses the specific challenges in securing ML implementations in such settings and underscores the importance of robust MLOps strategies in ensuring effective security protocols. Moreover, it explains current practices and identified improvement areas, highlighting the importance of MLOps in overcoming obstacles and maximizing the value of ML in operational technology contexts.
Tazeem Ahmad, Mohd Adnan, Saima Rafi, Muhammad Azeem Akbar, Ayesha Anwar
EASE3
2024 Towards People Maturity for Secure Development and Operations: A vision
abstract
DevOps (development and operations) is a set of collaborative practices that automate continuous delivery of new software versions with an aim to reduce the development life cycle and produce quality software products. Security is an important attribute of quality software. Software is secure if it does not allow the confidentiality, integrity, and availability of its data, code, or service to be compromised. In order to take full advantage of DevOps, security needs to play an integral part in the development life cycle of a software. The DevSecOps (development, security, and operations) refers to the integrating security practices within the DevOps process. DevSecOps promotes the shifting security to the early stages of a project. Traditionally, security testing is done towards the end of the software lifecycle. However, fixing issues later in the process is more costly than making sure defects do not happen in the beginning. DevSecOps goes beyond automation, continuous integration, testing and delivery processes, since it also encompasses people. In fact, DevSecOps promotes the collaboration between the development, operations, and security teams. When security comes into DevOps routines, people play an even more relevant role involving the collaboration between those teams and security team. In any organization policies, standards, procedures and code of conducts are designed for people to follow. People are executers of policies. The human factor is one of the major forces behind effectiveness, or failure of a security system. Traditionally, the organizations focus on protecting their infrastructure, from security threats and they ignore human behavior that may result in malicious activities during software development process. Human aspect is considered as one of the major reasons of security vulnerability is due to malicious human behavior, who are involved in DevSecOps process; human may make mistakes due to lack of security perceptions, skills, and knowledge.
Muhammad Azeem Akbar, Saima Rafi, Sami Hyrynsalmi, Arif Ali Khan
EASE2
2024 Aligning Academic with Industrial Needs: Investigating DevOps
abstract
Over recent years, DevOps has gained more attention within the software industry, owing to its pivotal role in facilitating continuous software delivery. The significant demand for DevOps practitioners necessitates substantial adjustments in conventional software engineering courses in higher educational institutions. Recent studies have highlighted DevOps principles, challenges, best practices, and tools to facilitate continuous delivery and deployment pipelines from an industrial perspective. As numerous universities are now introducing courses related to DevOps for students majoring in software engineering and computer science, this high demand for DevOps practitioners requires non-trivial adjustments in traditional software engineering courses and educational methodologies, including practices for teaching DevOps, training in DevOps, the level to which DevOps is currently taught and applied to measure the gap between teaching practices compared to industrial requirements. Our vision paper aims to highlight the crucial need for updated policies and tools to improve DevOps training in higher education, providing guidelines. By aligning academic curricula with industry standards, we can ensure students are better equipped for the demands of the workforce, fostering a seamless transition from academia to industry and promoting innovation in software engineering practices.
Saima Rafi, Muhammad Azeem Akbar, Sajjad Mahmood
EASE1
2024 Multi-objective and Randomly Distributed Fuzzy Logic-Based Unequal Clustering in Heterogeneous Wireless Sensor Networks
Mohd Adnan, Tazeem Ahmad, Saima Rafi, Anudeep Vurity
ICCCI (1)3
2024 A Taxonomy on Human Factors that Affect DevOps Adoption
Juanjo Pérez-Sánchez, Saima Rafi, Juan Manuel Carrillo de Gea, Joaquín Nicolás, José Luis Fernández-Alemán
WorldCIST (3)2
2024 Evaluation of requirement engineering best practices for secure software development in GSD: An ISM analysis
abstract
Abstract Technological advancement makes the world a global village. Security is an evergreen and everlasting area, because of the continuous threat from Hackers and Crackers. The immense use of software systems has modernized human society in every aspect. Thus, it is crucial to devise new processes, techniques, and tools to support teams in the development of secure code from the early stages of the software development process, while potentially reducing the costs and shortening the time to market. Considering the significance of software security, it is important to consider the security practices from the early phase of the software development life cycle (SDLC), that is, requirements engineering (RE). Hence, this study aims to identify and categorize RE practices important to apply for secure software development (SSD) in a geographically distributed development environment. To study the RE practices concerning SSD, we conducted a questionnaire survey with industrial experts in the global software development (GSD) context. Furthermore, the interpretive structure modeling (ISM) approach was applied to evaluate the relationship between the RE security practice core categories. This paper identifies 70 practices and classifies them into 11 fundamental dimensions (categories) to assist GSD organizations in specifying the requirements for SSD. The ISM results show that the “Awareness of Secure Requirement Engineering (SRE)” category has the most decisive influence on the other 10 core categories of the identified RE security practices. With the help of empirical evidence and the ISM approach, this work attempts to identify potential security practices and to give a set of secure RE practices that can be used to improve the security of the software development process.
Rafiq Ahmad Khan, Muhammad Azeem Akbar, Saima Rafi, Alaa Omran Almagrabi, Musaad Alzahrani
J. Softw. Evol. Process.3
2024 Trustworthy artificial intelligence: A decision-making taxonomy of potential challenges
abstract
Abstract The significance of artificial intelligence (AI) trustworthiness lies in its potential impacts on society. AI revolutionizes various industries and improves social life, but it also brings ethical harm. However, the challenging factors of AI trustworthiness are still being debated. This research explores the challenging factors and their priorities to be considered in the software process improvement (SPI) manifesto for developing a trustworthy AI system. The multivocal literature review (MLR) and questionnaire‐based survey approaches are used to identify the challenging factors from state‐of‐the‐art literature and industry. Prioritization based taxonomy of the challenges is developed, which reveals that lack of responsible and accountable ethical AI leaders, lack of ethics audits, moral deskilling & debility, lack of inclusivity in AI multistakeholder governance, and lack of scale training programs to sensitize the workforce on ethical issues are the top‐ranked challenging factors to be considered in SPI manifesto. This study's findings suggest revising AI‐based development techniques and strategies, particularly focusing on trustworthiness. In addition, the results of this study encourage further research to support the development and quality assessment of ethics‐aware AI systems.
Muhammad Azeem Akbar, Arif Ali Khan, Sajjad Mahmood, Saima Rafi, Selina Demi
Softw. Pract. Exp.4
2023 Understandings of Ethics in DevOps Teams: A Preliminary Investigation
abstract
Ethics are essential in DevOps for promoting transparency, trust, security, quality, continuous improvement, and user-centricity, as they guide individuals and organizations to make responsible choices and develop high-quality, secure, and reliable software applications. To consider the ethics of the DevOps teams, there is a need to develop standards and a code of conduct. The objective of this research work is to develop robust guidelines to assist software development organizations to consider ethics in the DevOps teams. The empirical study will be performed with industry practitioners, and legislation experts to explore the important areas and practices that need to be followed by the software organizations' work ethics for the DevOps teams. We believe the developed robust guidelines will assist the organization to follow the work ethics while working in a DevOps culture.
Maira Khanam, Saima Rafi, Muhammad Azeem Akbar
EASE2
2023 A systematic decision-making framework for tackling quantum software engineering challenges
abstract
Abstract Quantum computing systems harness the power of quantum mechanics to execute computationally demanding tasks more effectively than their classical counterparts. This has led to the emergence of Quantum Software Engineering (QSE), which focuses on unlocking the full potential of quantum computing systems. As QSE gains prominence, it seeks to address the evolving challenges of quantum software development by offering comprehensive concepts, principles, and guidelines. This paper aims to identify, prioritize, and develop a systematic decision-making framework of the challenging factors associated with QSE process execution. We conducted a literature survey to identify the challenging factors associated with QSE process and mapped them into 7 core categories. Additionally, we used a questionnaire survey to collect insights from practitioners regarding these challenges. To examine the relationships between core categories of challenging factors, we applied Interpretive Structure Modeling (ISM). Lastly, we applied fuzzy TOPSIS to rank the identified challenging factors concerning to their criticality for QSE process. We have identified 22 challenging factors of QSE process and mapped them to 7 core categories. The ISM results indicate that the ‘resources’ category has the most decisive influence on the other six core categories of the identified challenging factors. Moreover, the fuzzy TOPSIS indicates that ‘complex programming’, ‘limited software libraries’, ‘maintenance complexity’, ‘lack of training and workshops’, and ‘data encoding issues’ are the highest priority challenging factor for QSE process execution. Organizations using QSE could consider the identified challenging factors and their prioritization to improve their QSE process.
Muhammad Azeem Akbar, Arif Ali Khan, Saima Rafi
Autom. Softw. Eng.3
2022 DevOps Business Model: Work from Home Environment
abstract
DevOps is a culture-oriented software development and operations methodology, and software organizations increasingly adopting it due to its flexibility and good business gains. Especially, in Covid situations DevOps give a good support to software development organizations to carry development and operations activities through cloud-native DevOps in work from home environment and starting new businesses. The technological advancement makes the world a global village, though, there is dire need of guidelines and standards for the adoption of DevOps across the borders and out of office. Considering the significance of DevOps in current era of software business, we plan to develop a roadmap aiming to assist the software development organizations to adopt DevOps process over the globe and in work-from-home format. In this study, we are proposing an initial idea towards the development of robust and comprehensive guide for DevOps adoption in geographically distributed environment.
Saima Rafi, Muhammad Azeem Akbar, Adnan Manzoor
EASE1
2022 DevOps Practitioners' Perceptions of the Low-code Trend
abstract
Background: DevOps is currently one of the main trends in software development. Low-Code is also an emerging tendency that, combined with DevOps, may offer significant value to software businesses by improving the process. However, how DevOps practices and low-code are combined is little known. Aim: This study aims to understand the practitioner's perspectives on low-code trends. Method: Twelve interviews with IT professionals who deal with low-code in the context of DevOps were conducted. Then, a grounded theory approach was used to theme the interview quotes into emergent categories. Results: The main result of this exploratory study reveals that such an approach is the most common response to the skill shortages of software professionals. Conclusion: This study suggests the emergence of DevOps and low-code could significantly contribute to the development of quality products with low-cost and time.
Saima Rafi, Muhammad Azeem Akbar, Mary-Luz Sánchez-Gordón, Ricardo Colomo-Palacios
ESEM1
2022 Change Management in Cloud-Based Offshore Software Development: A Researchers Perspective
Muhammad Azeem Akbar, Saima Rafi, Rafiq Ahmad Khan, Muhammad Tanveer Riaz
PROFES3
2022 Classical to Quantum Software Migration Journey Begins: A Conceptual Readiness Model
Muhammad Azeem Akbar, Saima Rafi, Arif Ali Khan
PROFES2
2022 Towards roadmap to implement blockchain in healthcare systems based on a maturity model
abstract
Abstract Healthcare systems face various issues related to complex networks of intermediaries and a lack of transaction traceability. The most critical issues are the fragmentation of healthcare data, obstacles in providing efficient research and services, lack of clinical trial reporting, high cost and mismanagement of the drug supply chain, patient data security, and fake drugs. Blockchain technology has the potential to address these criticalities as it has in build traceability mechanisms and promises new business models by enabling incentive structures. This potential of blockchain gathers a high interest in the health industry. However, the implementation of blockchain in healthcare faces various issues as well. Currently, there are no practice‐oriented maturity models to improve such an implementation. In this paper, we present a roadmap to develop a maturity model for blockchain in healthcare (MMBH) based on critical barriers (CBs), critical success factors (CSFs), and the best practices for blockchain implementation in healthcare systems. As a first step to develop the MMBH, in this paper, we present the initial results of a systematic literature review (SLR) to identify critical success factors for implementing blockchain in healthcare systems. We also applied fuzzy technique order preference by similarity to ideal solution (TOPSIS) to prioritize the identified CSFs.
Muhammad Azeem Akbar, Víctor Leiva, Saima Rafi, Syed Furqan Qadri, Sajjad Mahmood, Ahmed Alsanad
J. Softw. Evol. Process.3
2022 Selection of DevOps best test practices: A hybrid approach using ISM and fuzzy TOPSIS analysis
abstract
Abstract Testing is a complex phase in DevOps process due to need of an automated process that provides feedback at different strategies of continuous development and operations pipeline. Software organization face several challenges during the testing phase due to lack of understanding on testing best practices for the DevOps paradigm. The objective of this study is to prioritize DevOps best testing practices, which can facilitate the selection of testing practices during DevOps process. To perform this research, we have extended the work done by Hornbeek, using the 15 DevOps testing practices discussed in his study. First, we categorize the test practices against culture, automation, lean, measurement, and sharing (CALMS) pillars of DevOps adoption principles. Next, a questionnaire‐based survey was conducted to collect feedback from industry practitioners on the DevOps test practices and their categorization against CALMS criteria. Finally, we applied Interpretive Structure Modeling (ISM) to find the interrelationship between CALMS criteria, and fuzzy TOPSIS was used to prioritize the DevOps test practices that will assist practitioners to better manage the testing activities during DevOps process.
Saima Rafi, Muhammad Azeem Akbar, Sajjad Mahmood, Ahmed Alsanad, Abdulrahman Alothaim
J. Softw. Evol. Process.1
2021 Prioritization of global software requirements' engineering barriers: An analytical hierarchy process
abstract
Abstract Software industry is adopting global software development (GSD) due to its potential to produce quality products at a lower cost. However, the GSD firms face many challenges that make development activities more complicated, especially related to the requirements engineering (RE) process. The objectives of this article are to investigate and prioritize the barriers faced by the GSD organizations during the RE process. First, we identified 17 barriers related to the RE process in the GSD projects. Next, the identified barriers were further validated with real‐world GSD practitioners using a questionnaire survey. Finally, we applied the analytical hierarchy process to prioritize the investigated barriers with respect to their significance for the RE process in the GSD domain. The results show that coordination is the most significant barrier category for the RE process in GSD projects. Lack of standard and procedure for RE in GSD, lack of synchronized communication infrastructure, and lack of mutual understanding between the overseas RE teams are also high‐ranked barriers for the RE process in GSD. The authors believe that the findings of this study will assist practitioners and researchers in developing effective strategies and plans for the successful implementation of the RE process in the GSD context.
Muhammad Azeem Akbar, Wishal Naveed, Sajjad Mahmood, Saima Rafi, Ahmed Alsanad, Abeer Abdul-Aziz Alsanad, Abdu Gumaei, Abdulrahman Alothaim
IET Softw.4
2021 Readiness model for DevOps implementation in software organizations
abstract
Abstract DevOps is a new software engineering paradigm adopted by various software organizations to develop the quality software within time and budget. The implementation of DevOps practices is critical, and there are no guidelines to assess and improve the DevOps activities in software organizations. Hence, there is a need to develop a readiness model for DevOps (RMDevOps) with an aim to assist the practitioners for implementation of DevOps practices in software firms. To achieve the study objective, we conducted a systematic literature review (SLR) study to identify the critical challenges and associated best practices of DevOps. A total of 18 challenges and 73 best practices were identified from the 69 primary studies. The identified challenges and best practices were further evaluated by conducting a survey with industry practitioners. The RMDevOps was developed based on other well‐established models in software engineering domain, for example, software process improvement readiness model (SPIRM) and software outsourcing vendor readiness model (SOVRM). Finally, case studies were conducted with three different organizations with an aim to validate the developed model. The results show that the RMDevOps is effective to assess and improve the DevOps practices in software organizations.
Saima Rafi, Yu Wu 0001, Muhammad Azeem Akbar, Sajjad Mahmood, Ahmed Alsanad, Abdu Gumaei
J. Softw. Evol. Process.1
2020 RMDevOps: A Road Map for Improvement in DevOps Activities in Context of Software Organizations
abstract
DevOps is a new software engineering paradigm adopted by various software organizations to develop an environment of continuous deployment and delivery within time. Numerous experts are offering their services to help organizations, how to implement DevOps activities in software organization. Though, still there are various issues for software organizations to adopt DevOps activities. To overcome such issues, there must be an approach that could assist software organizations towards better adoption of DevOps activities. The core objective of this research is to design a Readiness Model for DevOps (RMDevOps) to improve the adoption of DevOps activities in a software organization. Based on existing models in other fields of software engineering, we will develop this model. We have conducted a systematic literature review and empirical study on DevOps, for understanding the impact of the success factors of DevOps in the real world and literature. This study covers the first step of development of RMDevOps model, by identifying the success factors of DevOps and presenting the outcomes in the form of robust framework.
Saima Rafi, Yu Wu 0001, Muhammad Azeem Akbar
EASE1
2020 Towards a Hypothetical Framework to Secure DevOps Adoption: Grounded Theory Approach
abstract
Security in DevOps is a challenging feature because traditional existing methods of security are not fulfilling the exact requirements of DevOps. To make DevOps activities successful for organizations this study will help to identify concerns about DevOps security in real world by interviewing the practitioners having DevOps working experience. The Classical grounded theory approach has been used to build our theory. We interviewed 13 practitioners working across five companies from different regions. We contributed to identify security concerns in DevOps and try to present a theoretical model to improve understanding and guidance of DevOps adoption. The security concerns were marked as functional and nonfunctional based upon the interviews concepts to help practitioners having understanding about particular concerns. Therefore, this theory will highlight security concerns that are hindering the adoption of DevOps successfully.
Saima Rafi, Yu Wu 0001, Muhammad Azeem Akbar
EASE1