Md. Shazibul Islam Shamim

dblp:268/5804 · also Shazibul Islam Shamim · DBLP profile ↗
← Back
7ranked-venue papers
3as first author
7since 2021 · last 2026
0000-0001-8084-5123ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 5 · 2 first-author · 5 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2026 From Industry Claims to Empirical Reality: An Empirical Study of Code Review Agents in Pull Requests
abstract
Autonomous coding agents are generating code at an unprecedented scale, with OpenAI Codex alone creating over 400,000 pull requests (PRs) in two months. As agentic PR volumes increase, code review agents (CRAs) have become routine gatekeepers in development workflows. Industry reports claim that CRAs can manage 80% of PRs in open source repositories without human involvement. As a result, understanding the effectiveness of CRA reviews is crucial for maintaining developmental workflows and preventing wasted effort on abandoned pull requests. However, empirical evidence on how CRA feedback quality affects PR outcomes remains limited. The goal of this paper is to help researchers and practitioners understand when and how CRAs influence PR merge success by empirically analyzing reviewer composition and the signal quality of CRA-generated comments. From AIDev’s 19,450 PRs, we analyze 3,109 unique PRs in Commented review state, comparing human-only versus CRA-only reviews. We examine 98 closed CRA-only PRs to assess whether low signal-to-noise ratios contribute to abandonment. CRA-only PRs achieve a 45.20% merge rate, 23.17 percentage points lower than human-only PRs (68.37%), with significantly higher abandonment. Our signal-to-noise analysis reveals that 60.2% of closed CRA-only PRs fall into the 0–30% signal range, and 12 of 13 CRAs exhibit average signal ratios below 60%, indicating substantial noise in automated review feedback. These findings suggest that CRAs without human oversight often generate low-signal feedback associated with higher abandonment. For practitioners, our results indicate that CRAs should augment rather than replace human reviewers, and that human involvement remains critical for effective and actionable code review.
Kowshik Chowdhury, Dipayan Banik, K. M. Ferdous, Md. Shazibul Islam Shamim
MSR4
2026 Safer Builders, Risky Maintainers: A Comparative Study of Breaking Changes in Human vs Agentic PRs
abstract
AI coding agents are increasingly integrated into modern software engineering workflows, actively collaborating with human developers to create pull requests (PRs) in open-source repositories. Although coding agents improve developer productivity, they often generate code with more bugs and security issues than human-authored code. While human-authored PRs often break backward compatibility, leading to breaking changes, the potential for agentic PRs to introduce breaking changes remains underexplored. The goal of this paper is to help developers and researchers evaluate the reliability of AI-generated PRs by examining the frequency and task contexts in which AI agents introduce breaking changes.
K. M. Ferdous, Dipayan Banik, Kowshik Chowdhury, Md. Shazibul Islam Shamim
MSR4
2025 Authentic Learning Exercise for Kubernetes Misconfigurations: An Experience Report of Student Perceptions
abstract
Kubernetes has become a popular tool for automated container orchestration. Despite reported benefits, practitioners report that the secure configuration of Kubernetes is one of the primary challenges among practitioners. Moreover, there is a significant skill shortage of Kubernetes security experts. Understanding misconfigurations in Kubernetes can help practitioners prevent security incidents. We systematically investigate whether authentic learning can help students learn about misconfigurations in Kubernetes. We conduct an authentic learning exercise and collected responses from 295 students. Based on responses from the students, we find (i) students who have little to no experience in cybersecurity, software quality assurance, or static analysis perceived the authentic learning exercise as useful to learn misconfigurations in Kubernetes, and (ii) students perceptions of authentic learning exercise activities vary based on and educational background. We conclude our paper with recommendations for instructors and researchers.
Md. Shazibul Islam Shamim, Fan Wu 0013, Hossain Shahriar, Anthony Skjellum, Akond Ashfaque Ur Rahman
CSEE&T1
2025 On Prescription or Off Prescription? An Empirical Study of Community-Prescribed Security Configurations for Kubernetes
abstract
Despite being beneficial for rapid delivery of software, Kubernetes deployments can be susceptible to security attacks, which can cause serious consequences. A systematic characterization of how community-prescribed security configurations, i.e., security configurations that are recommended by security experts, can aid practitioners to secure their Kubernetes deployments. To that end, we conduct an empirical study with 53 security configurations recommended by the Center for Internet Security (CIS), 20 survey respondents, and 544 configuration files obtained from the open source software (OSS) and proprietary domains. From our empirical study, we observe: (i) practitioners can be unaware of prescribed security configurations as$5 \% \sim 40 {\%}$of the survey respondents are unfamiliar with 16 prescribed configurations; and (ii) for Company-A and OSS respectively, 18.0% and 17.9% of the configuration files include at least one violation of prescribed configurations. From our evaluation with 5 static application security testing (SAST) tools we find (i) only Kubescape to support all of the prescribed security configuration categories; (ii) the highest observed precision to be 0.41 and 0.43 respectively, for the Company-A and OSS datasets; and (iii) the highest observed recall to be respectively, 0.53 and 0.65 for the Company-A and OSS datasets. Our findings show a disconnect between what CIS experts recommend for Kubernetes-related configurations and what happens in practice. We conclude the paper by providing recommendations for practitioners and researchers. Dataset used for the paper is publicly available online.
Md. Shazibul Islam Shamim, Hanyang Hu, Akond Ashfaque Ur Rahman
ICSE1
2023 Security Misconfigurations in Open Source Kubernetes Manifests: An Empirical Study
abstract
Context: Kubernetes has emerged as the de-facto tool for automated container orchestration. Business and government organizations are increasingly adopting Kubernetes for automated software deployments. Kubernetes is being used to provision applications in a wide range of domains, such as time series forecasting, edge computing, and high-performance computing. Due to such a pervasive presence, Kubernetes-related security misconfigurations can cause large-scale security breaches. Thus, a systematic analysis of security misconfigurations in Kubernetes manifests, i.e., configuration files used for Kubernetes, can help practitioners secure their Kubernetes clusters. Objective: The goal of this paper is to help practitioners secure their Kubernetes clusters by identifying security misconfigurations that occur in Kubernetes manifests . Methodology: We conduct an empirical study with 2,039 Kubernetes manifests mined from 92 open-source software repositories to systematically characterize security misconfigurations in Kubernetes manifests. We also construct a static analysis tool called Security Linter for Kubernetes Manifests ( SLI-KUBE ) to quantify the frequency of the identified security misconfigurations. Results: In all, we identify 11 categories of security misconfigurations, such as absent resource limit, absent securityContext , and activation of hostIPC . Specifically, we identify 1,051 security misconfigurations in 2,039 manifests. We also observe the identified security misconfigurations affect entities that perform mesh-related load balancing, as well as provision pods and stateful applications. Furthermore, practitioners agreed to fix 60% of 10 misconfigurations reported by us. Conclusion: Our empirical study shows Kubernetes manifests to include security misconfigurations, which necessitates security-focused code reviews and application of static analysis when Kubernetes manifests are developed.
Akond Ashfaque Ur Rahman, Md. Shazibul Islam Shamim, Dibyendu Brinto Bose, Rahul Pandita
ACM Trans. Softw. Eng. Methodol.2
2022 Can We use Authentic Learning to Educate Students about Secure Infrastructure as Code Development?
abstract
Despite yielding benefits for organizations, infrastructure as code (IaC) scripts are susceptible to security weaknesses, such as hard-coded passwords. Existence of such security weaknesses necessitate integration of education materials related to secure development of IaC scripts. In this preliminary work, we describe our experiences of how application of authentic learning helped students learn about secure development of IaC scripts. Our paper shows education materials based on authentic learning to help students learn about secure IaC development.
Akond Ashfaque Ur Rahman, Md. Shazibul Islam Shamim, Hossain Shahriar, Fan Wu 0013
ITiCSE (2)2
2021 Mitigating security attacks in kubernetes manifests for security best practices violation
abstract
Kubernetes is an open-source software system that helps practitioners in automatically deploying, scaling, and managing containerized applications. Information technology (IT) organizations, such as IBM, Spotify, and Capital One, use Kubernetes to manage their containers and reported benefits in the deployment process. However, recent security breaches and survey results among practitioners suggest that Kubernetes deployment can be vulnerable to attacks due to misconfiguration and not following security best practices. This research explores how malicious users can perform potential security exploits from the violations of Kubernetes security best practices. We explore how attacks can be conducted such as denial of service attacks against one of the security best practices violations in Kubernetes manifests. In addition, we are exploring potential exploits in the Kubernetes cluster to propose mitigation strategies to secure the Kubernetes cluster.
Md. Shazibul Islam Shamim
ESEC/SIGSOFT FSE1