VLDB 2026 Research / reviewers in the wild / expert
Oleksandr Kosenkov
dblp:276/2302
· DBLP profile ↗
8ranked-venue papers
6as first author
7since 2021 · last 2026
0000-0002-9971-1130ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 7 · 6 first-author · 6 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Towards a Goal-Centric Assessment of Requirements Engineering Methods for Privacy by Design
Oleksandr Kosenkov, Ehsan Zabardast, Jannik Fischbach, Tony Gorschek, Daniel Méndez 0001 |
REFSQ | 1 |
| 2026 | Privacy by design: Aligning GDPR and software engineering specifications with a requirements engineering approachabstractConsistent requirements and system specifications are essential for the compliance of software systems towards the General Data Protection Regulation (GDPR). Both artefacts need to be “grounded” in the original text and conjointly assure the achievement of privacy by design (PbD). There is little understanding of the perspectives of practitioners on specification objectives and goals to address PbD. Existing approaches to GDPR and PbD do not account for the complex intersection between problem and solution space expressed in GDPR. In this study we explore the demand for conjoint requirements and system specification for PbD and suggest an initial version of an approach to address this demand. We reviewed existing secondary and related primary studies on GDPR compliance and conducted interviews with practitioners to (1) investigate the state-of-practice in requirements and system specifications for GDPR compliance and (2) understand the underlying specification objectives and goals (e.g., traceability). We developed and evaluated an initial version of an approach for requirements and systems specification for PbD, and evaluated it against the specification objectives. The relationship between problem and solution space, as expressed in GDPR, is instrumental in supporting PbD. We demonstrate how our approach, based on the modeling GDPR content with original legal concepts, contributes to specification objectives of capturing legal knowledge, supporting specification transparency for roles involved, and traceability. In addition to assuring traceability, GDPR demands need to be addressed throughout different levels of abstraction in the engineering lifecycle to achieve PbD. Legal knowledge specified in the GDPR text should be captured in specifications to address the demands of different stakeholders and ensure compliance. While our results confirm the suitability of our approach to address practical needs, we also revealed specific needs for the future effective operationalization of our suggested approach. Oleksandr Kosenkov, Ehsan Zabardast, Davide Fucci, Daniel Méndez 0001, Michael Unterkalmsteiner |
Inf. Softw. Technol. | 1 |
| 2025 | Systematic mapping study on requirements engineering for regulatory compliance of software systemsabstractContext: As the diversity and complexity of regulations affecting Software-Intensive Products and Services (SIPS) is increasing, software engineers need to address the growing regulatory scrutiny. We argue that, as with any other non-negotiable requirements, SIPS compliance should be addressed early in SIPS engineering—i.e., during requirements engineering (RE). Objectives: In the conditions of the expanding regulatory landscape, existing research offers scattered insights into regulatory compliance of SIPS. This study addresses the pressing need for a structured overview of the state of the art in software RE and its contribution to regulatory compliance of SIPS. Method: We conducted a systematic mapping study to provide an overview of the current state of research regarding challenges, principles, and practices for regulatory compliance of SIPS related to RE. We focused on the role of RE and its contribution to other SIPS lifecycle process areas. We retrieved 6914 studies published from 2017 (January 1) until 2023 (December 31) from four academic databases, which we filtered down to 280 relevant primary studies. Results: We identified and categorized the RE-related challenges in regulatory compliance of SIPS and their potential connection to six types of principles and practices addressing challenges. We found that about 13.6% of the primary studies considered the involvement of both software engineers and legal experts in developing principles and practices. About 20.7% of primary studies considered RE in connection to other process areas. Most primary studies focused on a few popular regulation fields (privacy, quality) and application domains (healthcare, software development, avionics). Our results suggest that there can be differences in terms of challenges and involvement of stakeholders across different fields of regulation. Conclusion: Our findings highlight the need for an in-depth investigation of stakeholders’ roles, relationships between process areas, and specific challenges for distinct regulatory fields to guide research and practice. Oleksandr Kosenkov, Parisa Elahidoost, Tony Gorschek, Jannik Fischbach, Daniel Méndez 0001, Michael Unterkalmsteiner, Davide Fucci, Rahul Mohanani |
Inf. Softw. Technol. | 1 |
| 2024 | Regulatory Requirements Engineering in Large Enterprises: An Interview Study on the European Accessibility Act
Oleksandr Kosenkov, Michael Unterkalmsteiner, Daniel Méndez 0001, Jannik Fischbach |
PROFES | 1 |
| 2023 | Automatic ESG Assessment of Companies by Mining and Evaluating Media Coverage Data: NLP Approach and Toolabstract[Context:] Society increasingly values sustainable corporate behaviour, impacting corporate reputation and customer trust. Hence, companies regularly publish sustainability reports to shed light on their impact on environmental, social, and governance (ESG) factors. [Problem:] Sustainability reports are written by companies and therefore considered a company-controlled source. Contrarily, studies reveal that non-corporate channels (e.g., media coverage) represent the main driver for ESG transparency. However, analysing media coverage regarding ESG factors is challenging since (1) the amount of published news articles grows daily, (2) media coverage data does not necessarily deal with an ESG-relevant topic, meaning that it must be carefully filtered, and (3) the majority of media coverage data is unstructured. [Research Goal:] We aim to automatically extract ESG-relevant information from textual media reactions to calculate an ESG score for a given company. Our goal is to reduce the cost of ESG data collection and make ESG information available to the general public. [Contribution:] Our contributions are three-fold: First, we publish a corpus of 432,411 news headlines annotated as being environmental-, governance-, social-related, or ESG-irrelevant. Second, we present our tool-supported approach called ESG-Miner, capable of automatically analysing and evaluating corporate ESG performance headlines. Third, we demonstrate the feasibility of our approach in an experiment and apply the ESG-Miner on 3000 manually labelled headlines. Our approach correctly processes 96.7% of the headlines and shows great performance in detecting environmental-related headlines and their correct sentiment. Jannik Fischbach, Max Adam, Victor Dzhagatspanyan, Daniel Méndez 0001, Julian Frattini, Oleksandr Kosenkov, Parisa Elahidoost |
IEEE Big Data | 6 |
| 2022 | Understanding the Implementation of Technical Measures in the Process of Data Privacy Compliance: A Qualitative StudyabstractBackground: Modern privacy regulations, such as the General Data Protection Regulation (GDPR), address privacy in software systems in a technologically agnostic way by mentioning general ”technical measures” for data privacy compliance rather than dictating how these should be implemented. An understanding of the concept of technical measures and how exactly these can be handled in practice, however, is not trivial due to its interdisciplinary nature and the necessary technical-legal interactions. Alexandra Klymenko, Oleksandr Kosenkov, Stephen Meisenbacher, Parisa Elahidoost, Daniel Méndez 0001, Florian Matthes |
ESEM | 2 |
| 2021 | Vision for an Artefact-based Approach to Regulatory Requirements EngineeringabstractBackground: Nowadays, regulatory requirements engineering (regulatory RE) faces challenges of interdisciplinary nature that cannot be tackled due to existing research gaps. Aims: We envision an approach to solve some of the challenges related to the nature and complexity of regulatory requirements, the necessity for domain knowledge, and the involvement of legal experts in regulatory RE. Method: We suggest the qualitative analysis of regulatory texts combined with the further case study to develop an empirical foundation for our research. Results: We outline our vision for the application of extended artefact-based modeling for regulatory RE. Conclusions: Empirical methodology is an essential instrument to address interdisciplinarity and complexity in regulatory RE. Artefact-based modeling supported by empirical results can solve a particular set of problems while not limiting the application of other methods and tools and facilitating the interaction between different fields of practice and research. Oleksandr Kosenkov, Michael Unterkalmsteiner, Daniel Méndez 0001, Davide Fucci |
ESEM | 1 |
| 2020 | Towards socio-technical requirements engineering for regulatory complianceabstractAs the digital transformation is gaining momentum in the agenda and strategic plans of both the public and the private sector, it is important to analyze how requirements engineering will contribute to the making of the digital world. From the technological perspective, software and systems engineering are `threatened' by the social dynamics and versatility that can be hardly captured with available techniques. From the social perspective, humanity is challenged with a new generation of digital systems, like social media platforms, that have a transformational impact on existing social orders. Public requirements for such systems are hardly well-specified that eventually may result in large-scale disruptions. A more systematic and holistic approach in requirements engineering addressing both the technical and the social aspects of the systems is needed. This paper outlines the hypothesis about the applicability of a socio-technical approach as a single theoretical framework for addressing simultaneously technical and social aspects of existing issues and further planned investigation of this assumption. The hypothesis is made as a part of the future PhD research on regulatory governance of software systems and particularly regulatory compliance and public requirements implementation in the requirements engineering at the particular example of media platforms. Oleksandr Kosenkov |
RE | 1 |