Mohammad Jamil Ahmad

dblp:324/2765 · DBLP profile ↗
← Back
3ranked-venue papers
2as first author
2since 2021 · last 2025
0000-0002-4038-2379ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 3 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2025 Exploring the generalizability of software vulnerability classes via replication and synthesis
abstract
Despite the increased interest in studying software vulnerabilities, there is a notable lack of studies focused on exploring the generalizability of findings. This paper aims to address this gap by combining replication and synthesis. Thus, our study partially replicates earlier research on vulnerabilities in mission-critical software to explore previously observed phenomena in a different domain. Specifically, this paper focuses on open-source operating systems (OSes) and, in addition to replication, utilizes synthesis to explore the generalizability of findings across other open-source and proprietary OSes. Our results showed that from $76 \%$ to $92 \%$ of security-related bugs in each of the three OSes (Fedora, Red Hat Linux (RHL), and Ubuntu) belonged to only five out of 21 vulnerability classes: Memory Access, Memory Management, Other, Tainted Input, and Information Leak. For RHL, Cryptography replaced Information Leak. The results based on integrative synthesis showed that the dominant classes were consistent across OSes considered in this paper and prior studies. The replication results revealed that Memory Access and Other were among the five dominant classes in both mission-critical software and OSes. The remaining three top vulnerability classes varied due to domains’ specifics. The paper also presents the implications of our findings and the future research directions.
Mohammad Jamil Ahmad, Katerina Goseva-Popstojanova
ISSRE1
2024 The untold impact of learning approaches on software fault-proneness predictions: an analysis of temporal aspects
Mohammad Jamil Ahmad, Katerina Goseva-Popstojanova, Robyn R. Lutz
Empir. Softw. Eng.1
2019 Software Fault Proneness Prediction with Group Lasso Regression: On Factors that Affect Classification Performance
abstract
Machine learning algorithms have been used extensively for software fault proneness prediction. This paper presents the first application of Group Lasso Regression (G-Lasso) for software fault proneness classification and compares its performance to six widely used machine learning algorithms. Furthermore, we explore the effects of two factors on the prediction performance: the effect of imbalance treatment using the Synthetic Minority Over-sampling Technique (SMOTE), and the effect of datasets used in building the prediction models. Our experimental results are based on 22 datasets extracted from open source projects. The main findings include: (1) G-Lasso is robust to imbalanced data and significantly outperforms the other machine learning algorithms with respect to the Recall and G-Score, i.e., the harmonic mean of Recall and (1- False Positive Rate). (2) Even though SMOTE improved the performance of all learners, it did not have statistically significant effect on G-Lasso's Recall and G-Score. Random Forest was in the top performing group of learners for all performance metrics, while Naive Bayes performed the worst of all learners. (3) When using the same change metrics as features, the choice of the dataset had no effect on the performance of most learners, including G-Lasso. Naive Bayes was the most affected, especially when balanced datasets were used.
Katerina Goseva-Popstojanova, Mohammad Jamil Ahmad, Yasser Alshehri
COMPSAC (2)2