Jianming Chang

dblp:297/3601 · DBLP profile ↗
← Back
11ranked-venue papers
2as first author
11since 2021 · last 2026
0000-0002-0052-6198ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 8 · 2 first-author · 8 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021
YearPublicationVenuePosition
2026 A Reinforcement Learning-Driven Adversarial Attack Methods With Dynamic Perturbation Optimization
Lulu Wang 0001, Xiaoning Du 0001, Jianming Chang, Bixin Li
IEEE Trans. Reliab.4
2026 A Reinforcement Learning-Driven Adversarial Attack Methods With Dynamic Perturbation Optimization
Lulu Wang 0001, Xiaoning Du 0001, Jianming Chang, Bixin Li
IEEE Trans. Reliab.4
2026 Bridging Bug Localization and Issue Fixing: A Hierarchical Localization Framework Leveraging Large Language Models
abstract
Automated issue fixing is a critical task in software debugging and has recently garnered significant attention from academia and industry. However, existing fixing techniques predominantly focus on the repair phase, often overlooking the importance of improving the preceding bug localization phase. As a foundational step in issue fixing, bug localization plays a pivotal role in determining the overall effectiveness of the entire process.To enhance the precision of issue fixing by accurately identifying bug locations in large-scale projects, this paper presents BugCerberus, the first hierarchical bug localization framework powered by three customized large language models. First, BugCerberus analyzes intermediate representations of bug-related programs at file, function, and statement levels and extracts bug-related contextual information from the representations. Second, BugCerberus designs three customized LLMs at each level using bug reports and contexts to learn the patterns of bugs. Finally, BugCerberus hierarchically searches for bug-related code elements through well-tuned models to localize bugs at three levels. With BugCerberus, we further investigate the impact of bug localization on the issue fixing.We evaluate BugCerberus on the widely-used benchmark SWE-bench-lite. The experimental results demonstrate that BugCerberus outperforms all baselines. Specifically, at the fine-grained statement level, BugCerberus surpasses the state-of-the-art in Top-N (N=1, 3, 5, 10) by 16.5%, 5.4%, 10.2%, and 23.1%, respectively. Moreover, in the issue fixing experiments, BugCerberus improves the fix rate of the existing issue fixing approach Agentless by 17.4% compared to the best baseline, highlighting the significant impact of enhanced bug localization on automated issue fixing.
Jianming Chang, Xin Zhou 0014, Lulu Wang 0001, David Lo 0001, Bixin Li
IEEE Trans. Software Eng.1
2025 Towards Task-Harmonious Vulnerability Assessment Based on LLM
abstract
Software vulnerabilities seriously jeopardize software security. It would be highly beneficial if developers could receive severity reminders regarding vulnerabilities when developing software systems. Therefore, when handling numerous vulnerabilities, it's crucial to prioritize the most critical ones and assess their severity early for effective resolution. Vulnerability assessment needs to train multiple assessment tasks simultaneously. Previous works suffer from task-disharmonious issues when conducting vulnerability assessments because they fail to balance the magnitude of gradients across multiple tasks and the conflicts in gradient directions. Additionally, they use identical code embedding for all classifiers without extracting task-related features. In this study, we are the first to conduct vulnerability assessment in a task-harmonious way by harmonizing gradient direction and magnitude, and filtering out task-specific features for each classifier. In addition, we use finer-grained contextual information than existing works by program slicing to further boost the model performance. According to experiment results, our model has demonstrated state-of-the-art performance at both the commit and function levels. Specifically, in function-level tasks, our model achieves an average of 0.819 in F1-Score and 0.742 in MCC, outperforming all baseline models. For commitlevel, our model enhances the average performance of the best baseline model by 29.6 % and 64.7 % in F1-Score and MCC, respectively.
Zaixing Zhang, Jianming Chang, Tianyuan Hu, Lulu Wang 0001, Bixin Li
ICPC2
2025 "My productivity is boosted, but ..." Demystifying Users' Perception on AI Coding Assistants
abstract
This paper aims to explore fundamental questions in the era when AI coding assistants like GitHub Copilot are widely adopted: what do developers truly value and criticize in AI coding assistants, and what does this reveal about their needs and expectations in real-world software development? Unlike previous studies that conduct observational research in controlled and simulated environments, we analyze extensive, first-hand user reviews of AI coding assistants, which capture developers’ authentic perspectives and experiences drawn directly from their actual day-to-day work contexts. We identify 1,085 AI coding assistants from the Visual Studio Code Marketplace. Although they only account for 1.64% of all extensions, we observe a surge in these assistants: over 90% of them are released within the past two years. We then manually analyze the user reviews sampled from 32 AI coding assistants that have sufficient installations and reviews to construct a comprehensive taxonomy of user concerns and feedback about these assistants. We manually annotate each review’s attitude when mentioning certain aspects of coding assistants, yielding nuanced insights into user satisfaction and dissatisfaction regarding specific features, concerns, and overall tool performance. Built on top of the findings-including how users demand not just intelligent suggestions but also context-aware, customizable, and resource-efficient interactions—we propose five practical implications and suggestions to guide the enhancement of AI coding assistants that satisfy user needs.
Yunbo Lyu, Zhou Yang 0003, Jieke Shi, Jianming Chang, Yue Liu 0011, David Lo 0001
ASE4
2025 HCIA: Hierarchical Change Impact Analysis Based on Hierarchy Program Slices
abstract
Change impact analysis (CIA) is an essential method in software maintenance and evolution. Its accuracy and usability play a crucial role in its application. However, most CIAs are coarse-grained and limited to class and method levels. Despite the fine-grained CIAs’ success in giving the statement-level impact set, they are still limited without the sub-statement level dependency analysis, leading to low precision. Additionally, their unstructured impact sets make it challenging for users to comprehend the impact content. This paper proposes Hierarchical Change Impact Analysis (HCIA), a Hierarchical CIA technique based on the sub-statement level dependence graph. HCIA can perform a forward hierarchy program slicing on the change set from five levels: sub-statement, statement, method, class, and package. Based on the program slices, HCIA calculates the impact factor of the impact sets at the five levels to generate the final impact set. In the experiment, we evaluate the relationship between the impact factor and the actual affected codes and assess the most appropriate size of HCIA impact sets. Furthermore, we evaluate HCIA on 10 open-source projects by comparing our approach with popular CIAs at the five levels. The experimental result shows that HCIA is more accurate than the popular CIAs.
Jianming Chang, Lulu Wang 0001, Zaixing Zhang
Int. J. Softw. Eng. Knowl. Eng.1
2024 Learning Graph-based Patch Representations for Identifying and Assessing Silent Vulnerability Fixes
abstract
Software projects are dependent on many third-party libraries, therefore high-risk vulnerabilities can propagate through the dependency chain to downstream projects. Owing to the subjective nature of patch management, software vendors commonly fix vulnerabilities silently. Silent vulnerability fixes cause downstream software to be unaware of urgent security issues in a timely manner, posing a security risk to the software. Presently, most of the existing works for vulnerability fix identification only consider the changed code as a sequential textual sequence, ignoring the structural information of the code.In this paper, we propose GRAPE, a GRAph-based Patch rEpresentation that aims to 1) provide a unified framework for getting vulnerability fix patches representation; and 2) enhance the understanding of the intent and potential impact of patches by extracting structural information of the code. GRAPE employs a novel joint graph structure (MCPG) to represent the syntactic and semantic information of silent fix patches and embeds both nodes and edges. Subsequently, a carefully designed graph convolutional neural network (NE-GCN) is utilized to fully learn structural features by leveraging the attributes of the nodes and edges. Moreover, we construct a dataset containing 2251 silent fixes. For the experimental section, we evaluated patch representation on three tasks, including vulnerability fix identification, vulnerability types classification, and vulnerability severity classification. Experimental results indicate that, in comparison to baseline methods, GRAPE can more effectively reduce false positives and omissions of vulnerability fixes identification and provide accurate vulnerability assessments.
Lulu Wang 0001, Jianming Chang, Bixin Li
ISSRE3
2024 OTCP-ISVM: Online Test Case Prioritization Based on Incremental Support Vector Machine
abstract
As software development technology becomes increasingly mature, the challenge to software testing efficiency is also increasing. Giving developers faster feedback on their code is essential for developing software. Test Case Prioritization (TCP) is one of the most popular techniques to optimize software testing. However, most TCP techniques rely on coverage information extracted from source code or execution history obtained from past executions and cannot be applied to preliminary software testing. What’s more, offline TCP technology cannot provide timely feedback to testers, affecting testing efficiency. To address the problem, this paper proposes a novel online TCP technique based on Incremental Support Vector Machine, which is called OTCP-ISVM. OTCP-ISVM dynamically reprioritizes the test cases when new failures are detected by using support vectors from previous training round and adapting the segmentation hyperplane. We have evaluated OTCP-ISVM on a large-scale project. The experimental results showed that OTCP-ISVM can achieve dynamic prioritization of the test cases. Compared with SVM algorithm and random algorithm, the fault detection speed of OTCP-ISVM algorithm is improved by 22% and 14% respectively.
Huaixu Lin, Bixin Li, Lulu Wang 0001, Jianming Chang
QRS5
2024 Graph-Based Salient Class Classification in Commits
abstract
In software engineering, code review is an important process when a project is to be upgraded. Reviewers need to assess the validity of a commit, even if they are not familiar with the files in the commit. In a typical commit, one or more mainly modified classes referred to as salient classes, may cause modifications in other classes. Salient Class Identification is such a method that can help reviewers review commits more effectively. In this way, after identifying salient classes, reviewers can allocate most of their efforts to analyzing the salient class, comprehending the commit, and providing reasoned assessments. The existing Salient Class Identification model is based on the static features of the code and does not analyze the internal logical information, such as the relationships between statements. We thoroughly consider both internal and external code information in commits, using a detailed Code-Change Dependency Graph (CCDG) to depict the code structure. CCDG includes various node and edge types, supporting complex syntax scenarios, which can capture fine-grained dependencies. Finally, based on a heterogeneous graph neural network, we extract nuanced features embedding from CCDG, which can further boost the performance of our model. The experiment result shows that our model outperforms existing models in Salient Class Identification, achieving an overall $88 \%$ accuracy.
Jiahao Ren, Jianming Chang, Lulu Wang 0001, Zaixing Zhang, Bixin Li
QRS2
2023 Commit Classification via Diff-Code GCN based on System Dependency Graph
abstract
Commit Classification, an automated process of classifying Diff-Code based on their purpose, plays a crucial role in enhancing comprehension and the quality of software. Some previous studies only used commit messages or code metrics to represent diff-code but lacked code context structure characterization. Alternatively, other studies have used Abstract Syntax Trees (ASTs) tokens to represent diff-code but did not consider contextual information like data dependency and control dependency. In this paper, we propose a new commit classification model called Diff-Code GCN (Graph Convolutional Network). Specifically, we firstly build a more detailed system dependency graph (SDG) of the commit, and secondly use program slicing to search the impact scope of diff-code. Thirdly, we extract the scope as a Change Impact Graph (CIG). We utilize GCN to extract contextual information from CIG and combine it with syntactic changed information of ASTs to represent the commit. Finally, we classify the commit into three maintenance categories (corrective, perfective, and adaptive). We evaluate our model based on commonly used datasets and compare our model with popular commit classification approaches. The experiment result well shows that both in within-project and cross-project prediction tasks, our model performs better than baseline models.
Zaixing Zhang, Jianming Chang, Lulu Wang 0001
QRS3
2021 Experience report: investigating bug fixes in machine learning frameworks/libraries
Xiaobing Sun 0001, Tianchi Zhou, Rongcun Wang, Yucong Duan, Lili Bo, Jianming Chang
Frontiers Comput. Sci.6