VLDB 2026 Research / reviewers in the wild / expert
Glen Horton
dblp:320/9245
· DBLP profile ↗
2ranked-venue papers
0as first author
2since 2021 · last 2023
0000-0001-9741-3212ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Prompting Creative Requirements via Traceable and Adversarial Examples in Deep LearningabstractCreativity focuses on the generation of novel and useful ideas. In this paper, we propose an approach to automatically generating creative requirements candidates via the adversarial examples resulted from applying small changes (perturbations) to the original requirements descriptions. We present an architecture where the perturbator and the classifier positively influence each other. Meanwhile, we ensure that each adversarial example is uniquely traceable to an existing feature of the software, instrumenting explainability. Our experimental evaluation of six datasets shows that around 20% adversarial shift rate is achievable. In addition, a human subject study demonstrates our results are more clear, novel, and useful than the requirements candidates outputted from a state-of-the-art machine learning method. To connect the creative requirements closer with software development, we collaborate with a software development team and show how our results can support behavior-driven development for a web app built by the team. Hemanth Gudaparthi, Nan Niu, Boyang Wang 0007, Tanmay Bhowmik, Hui Liu 0003, Jianzhang Zhang, Juha Savolainen, Glen Horton, Sean Crowe, Thomas Scherz, Lisa Haitz |
RE | 8 |
| 2022 | Detecting Software Security Vulnerabilities Via Requirements Dependency AnalysisabstractCyber attacks targeting software applications have a tremendous impact on our daily life. For example, attackers have utilized vulnerabilities of web applications to steal and gain unauthorized use of sensitive data stored in these systems. Previous studies indicate that security testing is highly precise, and therefore is widely applied to validate individual security requirements. However, dependencies between security requirements may cause additional vulnerabilities. Manual dependency detection faces scalability challenges, e.g., a previous study shows that the pairwise dependency analysis of 40 requirements would take around 12 hours. In this article, we present a novel approach which integrates the interdependency among high-level security requirements, such as those documented in policies, regulations, and standards. We then use automated requirements tracing methods to identify product-level security requirements and their dependencies. Our manual analysis of HIPAA and FIPS 200 leads to the identification of five types of high-level security requirements dependencies, which further inform the automated tracing methods and guide the designs of system-level security tests. Experimental results on five projects in healthcare and education domains show the significant recall improvements at 81 percent. Our case study on a deployed production system uncovers four previously unknown vulnerabilities by using the detected requirements dependencies as test paths, demonstrating our approach's value in connecting requirements engineering with security testing. Wentao Wang 0003, Faryn Dumont, Nan Niu, Glen Horton |
IEEE Trans. Software Eng. | 4 |