Thomas S. Heinze

dblp:29/1801 · DBLP profile ↗
← Back
14ranked-venue papers
7as first author
7since 2021 · last 2026
0000-0001-8816-7013ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 12 · 6 first-author · 7 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 A Uniform and Privacy-Preserving Interface for the Clone Detector StoneDetector
Wolfram Amme, Christopher Bärthel, Tim Bögel, Michael A. King, Thomas S. Heinze
ICSOFT5
2026 Generalizability of Deep Learning Models for Java Code Clone Detection
Thomas S. Heinze
ICSOFT1
2026 StoneDetector : Conventional and versatile code clone detection for Java
Thomas S. Heinze, André Schäfer, Wolfram Amme
J. Syst. Softw.1
2025 CloReCo: Benchmarking Platform for Code Clone Detection
Franz Burock, Wolfram Amme, Thomas S. Heinze, Elisabeth Ostryanin
ICSOFT3
2023 Cross-Domain Evaluation of a Deep Learning-Based Type Inference System
abstract
Optional type annotations allow for enriching dynamic programming languages with static typing features like better Integrated Development Environment (IDE) support, more precise program analysis, and early detection and prevention of type-related runtime errors. Machine learning-based type inference promises interesting results for automating this task. However, the practical usage of such systems depends on their ability to generalize across different domains, as they are often applied outside their training domain.In this work, we investigate Type4Py as a representative of state-of-the-art deep learning-based type inference systems, by conducting extensive cross-domain experiments. Thereby, we address the following problems: class imbalances, out-of-vocabulary words, dataset shifts, and unknown classes.To perform such experiments, we use the datasets Many-Types4Py and CrossDomainTypes4Py. The latter we introduce in this paper. Our dataset enables the evaluation of type inference systems in different domains of software projects and has over 1,000,000 type annotations mined on the platforms GitHub and Libraries. It consists of data from the two domains web development and scientific calculation.Through our experiments, we detect that the shifts in the dataset and the long-tailed distribution with many rare and unknown data types decrease the performance of the deep learning-based type inference system drastically. In this context, we test unsupervised domain adaptation methods and fine-tuning to overcome these issues. Moreover, we investigate the impact of out-of-vocabulary words.
Bernd Gruner, Tim Sonnekalb, Thomas S. Heinze, Clemens-Alexander Brust
MSR3
2022 Deep security analysis of program code
abstract
Abstract Due to the continuous digitalization of our society, distributed and web-based applications become omnipresent and making them more secure gains paramount relevance. Deep learning (DL) and its representation learning approach are increasingly been proposed for program code analysis potentially providing a powerful means in making software systems less vulnerable. This systematic literature review (SLR) is aiming for a thorough analysis and comparison of 32 primary studies on DL-based vulnerability analysis of program code. We found a rich variety of proposed analysis approaches, code embeddings and network topologies. We discuss these techniques and alternatives in detail. By compiling commonalities and differences in the approaches, we identify the current state of research in this area and discuss future directions. We also provide an overview of publicly available datasets in order to foster a stronger benchmarking of approaches. This SLR provides an overview and starting point for researchers interested in deep vulnerability analysis on program code.
Tim Sonnekalb, Thomas S. Heinze, Patrick Mäder
Empir. Softw. Eng.2
2021 You Look so Different: Finding Structural Clones and Subclones in Java Source Code
abstract
Code reuse and copying is a widespread practice in software development. Detecting code clones, i.e., identical or similar fragments of code, is thus an important task with many applications, ranging from code search to bug finding and malware detection. In this paper, we propose a new approach to detect code clones in source code. Instead of analyzing the code tokens or syntax, our technique is based upon control flow analysis and dominator trees. In this way, the technique not only detects exact and syntactically similar near-miss code clones but also two new types of clones, which we characterize as structural code clones and subclones. For implementation and evaluation, we have developed the tool StoneDetector, which finds code clones in Java source code. StoneDetector performs competitive with the state of the art as measured on the BigCloneBench benchmark and finds more structural clones and subclones.
Wolfram Amme, Thomas S. Heinze, André Schäfer
ICSME2
2020 Benchmarking Open-Source Static Analyzers for Security Testing for C
Christoph Gentsch, Rohan Krishnamurthy, Thomas S. Heinze
ISoLA (4)3
2018 Static analysis and process model transformation for an advanced business process to Petri net mapping
abstract
Summary Verification of business processes typically relies on Petri net–based process models. While they allow for natural modeling and analysis of aspects such as parallelism and message exchange, such a process model is seldom complete and precise. This is mainly because the available techniques for deriving a Petri net model from the original model neglect process data in favor of feasible verification. In this paper, we present an approach for deriving more precise process models by leveraging a process‐to‐Petri‐net compiler, which takes as input a business process and generates as output a Petri net model for the process. This can be subsequently used for verification. However, in contrast to a conventional compiler, our compiler's objective is not to create the most efficient code but rather to produce a most precise but still effectively verifiable Petri net–based process model.
Thomas S. Heinze, Wolfram Amme, Simon Moser
Softw. Pract. Exp.1
2016 Type safety analysis for Dart
abstract
Optional typing is traditionally viewed as a compromise between static and dynamic type checking, where code without type annotations is not checked until runtime. We demonstrate that optional type annotations in Dart programs can be integrated into a flow analysis to provide static type safety guarantees both for annotated and non-annotated parts of the code. We explore two approaches: one that uses type annotations for filtering, and one that uses them as specifications. What makes this particularly challenging for Dart is that its type system is unsound even for fully annotated code. Experimental results show that the technique is remarkably effective, even without context sensitivity: 99.3% of all property lookup operations are reported type safe in a collection of benchmark programs.
Thomas S. Heinze, Anders Møller, Fabio Strocco
DLS1
2016 Sparse Analysis of Variable Path Predicates Based upon SSA-Form
Thomas S. Heinze, Wolfram Amme
ISoLA (1)1
2014 Portable Green Cloud Services
abstract
Although the areas of cloud computing and green IT are amongst the fastest growing markets in the IT industry, until now there are very few opportunities to combine the potential of both areas. In this paper, we present a method to combine the advantages of both to create standardized and energy efficient cloud services. For their description, we will use the emerging cloud computing standard TOSCA(OASIS, 2013). Thereby, it is possible to create standardized and model-based cloud applications which can be deployed in many cloud environments. We will further show how it is feasible to combine policies with TOSCA to realize energy-efficient management of cloud services. To accomplish this, we will provide ideas on how to extend the TOSCA language as well as the cloud operating environment in order to achieve the goal of portable, energy-efficient cloud services. The core of this work is the identification and integration of the underlying system architecture for a common solution concept. For this, the architectures and necessary adjustments are explained.
Stephan Ulbricht, Wolfram Amme, Thomas S. Heinze, Simon Moser, Hans-Dieter Wehle
CLOSER3
2009 A Restructuring Method for WS-BPEL Business Processes Based on Extended Workflow Graphs
Thomas S. Heinze, Wolfram Amme, Simon Moser
BPM1
2008 Generic CSSA-Based Pattern over Boolean Data for an Improved WS-BPEL to Petri Net Mappping
abstract
Formal methods, like Petri nets, provide a means to analyse BPEL processes, detecting weaknesses and errors in the process model already at design-time. However, in most approaches proposed so far, the analysis is restricted to the control flow only. Analysing quality properties of BPEL processes might therefore yield false-negative results. In this paper, we are presenting an enhanced BPEL to Petri net mapping, that incorporates relevant data aspects by doing a CSSA- based analysis and applying novel Petri net patterns. The resulting formal model allows for a more precise analysis of critical properties, such as controllability and behavioural compatibility.
Thomas S. Heinze, Wolfram Amme, Simon Moser
ICIW1